I could use some help in removing this trojan. here are my combofix and hijackthis logs.
ComboFix 09-03-18.01 - Administrator 2009-03-19 16:19:33.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1564 [GMT -5:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
- Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\audiosr.dll . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2009-02-19 to 2009-03-19 )))))))))))))))))))))))))))))))
.
2009-03-15 19:22 . 2009-03-15 19:22 d-------- c:\program files\AVG
2009-03-15 19:22 . 2009-03-19 15:59 d-------- c:\documents and settings\All Users\Application Data\avg8
2009-03-04 16:58 . 2009-03-04 16:58 d-------- c:\documents and settings\Administrator\Application Data\fretsonfire
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-19 19:13 --------- d–h–w c:\program files\InstallShield Installation Information
2009-03-19 19:13 --------- d-----w c:\program files\Common Files\InstallShield
2009-02-26 20:28 --------- d-----w c:\program files\Microsoft Silverlight
2009-02-10 12:32 --------- d-----w c:\documents and settings\Administrator\Application Data\uTorrent
2009-02-05 17:22 --------- d-----w c:\program files\Free 3D Earth Screensaver
2009-02-05 17:22 --------- d-----w c:\documents and settings\Administrator\Application Data\TERMINAL Studio
2009-02-03 20:31 --------- d-----w c:\documents and settings\Administrator\Application Data\ScanSoft
2009-01-31 05:13 --------- d-----w c:\documents and settings\Administrator\Application Data\Windows Search
2009-01-31 04:38 --------- d-----w c:\program files\AGEIA Technologies
2009-01-31 04:37 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-09-05 15:38 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090520080906\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{89E3F184-32DA-426F-A643-3A42F83C5CCC}]
2008-12-04 11:22 116480 --a------ c:\windows\system32\audiosr.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ctfmon.exe”=“c:\windows\system32\ctfmon.exe” [2008-04-13 15360]
“H/PC Connection Agent”=“c:\program files\Microsoft ActiveSync\wcescomm.exe” [2006-11-13 1289000]
“BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe” [2007-08-03 202024]
“Nero PhotoShow Media Manager”=“c:\progra~1\Nero\PHOTOS~1\data\Xtras\mssysmgr.exe” [2007-04-27 312848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“IgfxTray”=“c:\windows\system32\igfxtray.exe” [2004-09-30 155648]
“HotKeysCmds”=“c:\windows\system32\hkcmd.exe” [2004-09-30 126976]
“zBrowser Launcher”=“c:\program files\Logitech\iTouch\iTouch.exe” [2003-12-01 892928]
“SSBkgdUpdate”=“c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe” [2003-10-14 155648]
“PaperPort PTD”=“c:\program files\ScanSoft\PaperPort\pptd40nt.exe” [2004-04-14 57393]
“IndexSearch”=“c:\program files\ScanSoft\PaperPort\IndexSearch.exe” [2004-04-14 40960]
“NeroFilterCheck”=“c:\program files\Common Files\Nero\Lib\NeroCheck.exe” [2007-03-01 153136]
“SecurDisc”=“c:\program files\Nero\Nero8\InCD\NBHGui.exe” [2007-08-04 2043688]
“InCD”=“c:\program files\Nero\Nero8\InCD\InCD.exe” [2007-08-04 1056552]
“NBKeyScan”=“c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe” [2007-08-08 1828136]
“Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2008-06-12 34672]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2008-01-03 13508608]
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2008-01-03 86016]
“SkyTel”=“SkyTel.EXE” [2006-05-16 c:\windows\SkyTel.exe]
“RTHDCPL”=“RTHDCPL.EXE” [2006-09-05 c:\windows\RTHDCPL.EXE]
“Logitech Utility”=“Logi_MwX.Exe” [2003-11-07 c:\windows\LOGI_MWX.EXE]
“nwiz”=“nwiz.exe” [2008-01-03 c:\windows\system32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
“{56F9679E-7826-4C84-81F3-532071A8BCC5}”= “c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll” [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“msacm.ac3filter”= ac3filter.acm
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“c:\Program Files\Messenger\msmsgs.exe”=
“c:\Program Files\uTorrent\uTorrent.exe”=
“c:\program files\Microsoft ActiveSync\rapimgr.exe”= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
“c:\program files\Microsoft ActiveSync\wcescomm.exe”= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
“c:\program files\Microsoft ActiveSync\WCESMgr.exe”= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“26675:TCP”= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 ldecydkl;ldecydkl;c:\windows\system32\drivers\ldecydkl.sys [2001-08-17 23424]
R3 LCcfltr;Logitech USB Filter Driver;c:\windows\system32\drivers\LCcfltr.sys [2008-09-07 14092]
S3 DX4323;Dynex Wireless N USB Adapter Driver;c:\windows\system32\DRIVERS\DX4323.sys → c:\windows\system32\DRIVERS\DX4323.sys [?]
.
Contents of the ‘Scheduled Tasks’ folder
2009-03-19 c:\windows\Tasks\AdwareAlert Scheduled Scan.job
- c:\program files\AdwareAlert\AdwareAlert.exe
2009-03-19 c:\windows\Tasks\AdwareAlert Scheduled Scan.job
- c:\program files\AdwareAlert
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.facebook.com/home.php#/home.php?ref=home
.
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-19 16:22:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3735933683-4267067709-2261568873-500\Software\SecuROM!CAUTION! NEVER A OR CHANGE ANY KEY*]
“??”=hex:90,c0,ed,a2,2d,44,93,ec,9a,31,10,da,28,5d,cb,f4,b2,c2,ba,37,cd,7d,54,
47,56,60,60,b4,7f,89,f3,00,67,73,71,28,3b,19,1b,7d,f7,b8,98,fa,23,c6,8e,43,
“??”=hex:7a,1a,d1,56,79,f0,1a,5b,09,a2,1b,54,71,ac,71,32
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\brss01a.exe
c:\program files\Nero\Nero8\InCD\InCDsrv.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\searchindexer.exe
c:\program files\Logitech\MouseWare\system\EM_EXEC.EXE
c:\windows\system32\rundll32.exe
c:\progra~1\MICROS~3\rapimgr.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
.
.
Completion time: 2009-03-19 16:24:57 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-19 21:24:54
ComboFix2.txt 2009-03-19 21:14:36
ComboFix3.txt 2009-03-19 21:05:44
ComboFix4.txt 2009-03-19 19:05:29
Pre-Run: 27,532,787,712 bytes free
Post-Run: 27,511,791,616 bytes free
132 — E O F — 2009-03-11 08:00:58