Thanks very much, the change of name definitely worked. Below is the combofix.txt and updated HJT log.
ComboFix 09-02-19.01 - Mei 2009-02-20 22:56:41.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.671 [GMT 10.5:30]
Running from: c:\documents and settings\[removed]\Desktop\dream.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Mei\Application Data\inst.exe
C:\test.txt
c:\windows\lsass.exe
c:\windows\services.exe
c:\windows\system\oeminfo.ini
c:\windows\system32\AutoRun.inf
c:\windows\system32\drivers\UACtkbgoews.sys
c:\windows\system32\hs78344kjkfd.dll
c:\windows\system32\twain32
c:\windows\system32\twain32\local.ds
c:\windows\system32\twain32\user.ds
c:\windows\system32\twex.exe
c:\windows\system32\UACbftoiyfm.log
c:\windows\system32\UACgelkjljj.log
c:\windows\system32\UACnxmhsxqr.log
c:\windows\system32\UACpkwlsmkv.dll
c:\windows\system32\UACqttrfqqu.dll
c:\windows\system32\UACtsnmngor.dll
c:\windows\system32\UACwpdwqpij.dat
c:\windows\system32\UACxejtkdiq.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-01-20 to 2009-02-20 )))))))))))))))))))))))))))))))
.
2009-02-20 20:24 . 2009-02-20 20:24 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-20 20:24 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-20 20:24 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-20 20:05 . 2009-02-20 20:24 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-20 20:00 . 2009-02-20 20:00 d——– c:\program files\Trend Micro
2009-02-19 10:04 . 2009-02-19 10:05 d——– c:\program files\ERUNT
2009-02-19 00:53 . 2009-02-19 00:53 d——– c:\program files\Spybot - Search & Destroy
2009-02-19 00:53 . 2009-02-19 00:53 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-19 00:51 . 2009-02-19 00:51 23,210 –a—— c:\windows\system32\AAWService_2009_02_19_00_51_39.dmp
2009-02-19 00:04 . 2009-02-19 00:04 23,210 –a—— c:\windows\system32\AAWService_2009_02_19_00_04_47.dmp
2009-02-18 23:58 . 2009-02-18 23:45 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-02-18 23:46 . 2009-02-18 23:45 64,160 –a—— c:\windows\system32\drivers\Lbd.sys
2009-02-18 23:39 . 2009-02-18 23:39 d——– c:\program files\Lavasoft
2009-02-18 23:39 . 2009-02-18 23:39 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-18 23:39 . 2009-02-18 23:39 d–h-c— c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-18 19:13 . 2009-02-19 09:37 d——– c:\documents and settings\Mei\Application Data\Twain
2009-02-18 19:08 . 2009-02-18 19:08 d——– c:\program files\WebShow
2009-02-17 18:57 . 2009-02-19 09:10 5,189 –a—— c:\windows\system32\uacinit.dll
2009-02-17 18:56 . 2009-02-18 22:54 d——– c:\documents and settings\Mei\Application Data\cogad
2009-02-17 18:56 . 2009-02-17 18:56 2 –a—— C:\1615351572
2009-02-17 18:56 . 2009-02-17 18:56 0 -rahs—- C:\khq
2009-02-15 18:06 . 2009-02-15 18:06 d——– c:\documents and settings\Mei\Application Data\Home Sweet Home 2
2009-02-15 09:28 . 2009-02-15 09:28 d——– c:\program files\Vector Magic
2009-02-15 09:02 . 2009-02-15 09:02 d——– c:\documents and settings\All Users\Application Data\ALM
2009-02-14 16:32 . 2009-02-14 16:32 d——– c:\documents and settings\Mei\Application Data\World-LooM
2009-02-14 15:27 . 2009-02-14 15:27 d——– c:\documents and settings\Mei\Application Data\Ludia
2009-02-14 15:27 . 2009-02-14 15:27 d——– c:\documents and settings\All Users\Application Data\Ludia
2009-02-14 15:18 . 2009-02-14 15:58 d——– c:\documents and settings\All Users\Application Data\Vso
2009-02-08 23:08 . 2009-02-08 23:08 d——– c:\windows\system32\Adobe
2009-02-05 22:55 . 2009-02-05 22:55 d——– c:\documents and settings\All Users\Application Data\Absolutist
2009-02-02 06:22 . 2009-02-02 06:22 d——– c:\windows\system32\VirtualExpander
2009-01-28 19:12 . 2009-01-28 19:13 d——– c:\program files\QuickTime
2009-01-26 12:57 . 2004-03-29 10:16 352,256 –a—— c:\windows\esellerateEngine.dll
2009-01-26 12:48 . 2004-03-29 15:23 90,112 –a—— c:\windows\unvise32.exe
2009-01-24 20:00 . 2008-05-06 16:31 45,056 –a—— c:\windows\system32\WNASPI32.DLL
2009-01-24 20:00 . 2008-05-06 16:31 16,512 –a—— c:\windows\system32\drivers\ASPI32.SYS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-19 13:12 ——— d—–w c:\documents and settings\All Users\Application Data\Avg8
2009-02-19 12:55 ——— d—–w c:\program files\Free Download Manager
2009-02-19 12:53 ——— d—–w c:\program files\EA GAMES
2009-02-19 12:46 ——— d—–w c:\program files\Weatherzone Tracker
2009-02-19 12:36 ——— d—–w c:\program files\Google
2009-02-19 12:35 ——— d—–w c:\program files\dvdSanta
2009-02-19 12:34 ——— d—–w c:\program files\Acro Software
2009-02-19 12:28 ——— d—–w c:\documents and settings\Mei\Application Data\Free Download Manager
2009-02-18 22:40 ——— d—–w c:\program files\Mozilla Thunderbird
2009-02-18 08:59 ——— d—–w c:\documents and settings\Mei\Application Data\uTorrent
2009-02-17 09:23 ——— d—–w c:\documents and settings\Mei\Application Data\FileZilla
2009-02-17 08:37 ——— d—–w c:\program files\FileZilla FTP Client
2009-02-14 04:44 47,360 -c–a-w c:\documents and settings\Mei\Application Data\pcouffin.sys
2009-02-14 04:44 47,360 —-a-w c:\windows\system32\drivers\pcouffin.sys
2009-02-14 04:44 ——— d—–w c:\documents and settings\Mei\Application Data\Vso
2009-02-14 04:43 ——— d—–w c:\program files\VSO
2009-02-13 08:50 ——— d—–w c:\program files\Combined Community Codec Pack
2009-01-31 07:55 ——— d—–w c:\program files\Windows Desktop Search
2009-01-31 05:41 ——— d—–w c:\documents and settings\Mei\Application Data\Inkscape
2009-01-28 08:42 ——— d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2009-01-25 23:59 ——— d—–w c:\documents and settings\Mei\Application Data\dvdcss
2009-01-16 05:58 ——— d—–w c:\program files\CCleaner
2009-01-11 00:29 ——— d—–w c:\program files\SystemRequirementsLab
2009-01-11 00:28 ——— d—–w c:\documents and settings\Mei\Application Data\SystemRequirementsLab
2009-01-10 05:08 ——— d—–w c:\documents and settings\All Users\Application Data\Target Photobooks
2009-01-07 02:39 ——— d—–w c:\documents and settings\Mei\Application Data\Zoom Software
2009-01-07 00:42 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-07 00:41 ——— d—–w c:\documents and settings\Mei\Application Data\Intuit
2009-01-07 00:40 ——— d—–w c:\documents and settings\All Users\Application Data\Intuit
2009-01-06 00:58 ——— d—–w c:\program files\Bonjour
2009-01-04 23:32 ——— d—–w c:\documents and settings\Mei\Application Data\vlc
2008-12-31 13:42 ——— d—–w c:\documents and settings\Mei\Application Data\BonkEnc
2008-12-31 04:10 ——— d—–w c:\documents and settings\Mei\Application Data\gtk-2.0
2008-12-31 02:57 ——— d—–w c:\program files\Common Files\Adobe
2008-12-31 02:51 ——— d—–w c:\program files\Common Files\Macrovision Shared
2008-12-25 13:38 6,301,344 —-a-w c:\windows\system32\drivers\nv4_mini.sys
2007-01-17 10:12 24,192 -c–a-w c:\documents and settings\Mei\usbsermptxp.sys
2007-01-17 10:12 22,768 -c–a-w c:\documents and settings\Mei\usbsermpt.sys
2006-05-21 05:20 774,144 -c–a-w c:\program files\RngInterstitial.dll
2008-02-13 11:37 88 –sh–r c:\windows\system32\AA69F0DB21.sys
2008-02-13 11:51 2,516 –sha-w c:\windows\system32\KGyGaAvL.sys
2008-09-13 01:06 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091320080914\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"InternodeUsage"="c:\progra~1\INTERN~2\mum.exe" [2008-10-02 1339904]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-11-23 67128]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-24 2147672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"hplampc"="c:\windows\system32\hplampc.exe" [2002-01-17 40448]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-26 13680640]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2004-03-24 1294446]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-11 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-26 86016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-18 509784]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-18 c:\windows\LOGI_MWX.EXE]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
"nwiz"="nwiz.exe" [2008-12-26 c:\windows\system32\nwiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
"SoundMan"="SOUNDMAN.EXE" [2004-01-09 c:\windows\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Exif Launcher S.lnk - c:\program files\FinePixViewerS\QuickDCF2.exe [2007-12-11 303104]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-05-12 73728]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-23 67128]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-11-23 805392]
Media Key.lnk - c:\program files\Media Key\MagicKey.exe [2007-12-15 159744]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2006-05-21 122880]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 03:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\figinuli.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.wmv3"= c:\progra~1\COMBIN~1\Filters\wmv9vcm.dll
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\Last.fm\\LastFM.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\xampp\\apache\\bin\\apache.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Mei\\My Documents\\My Programs\\perfect dark.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-18 64160]
R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2006-05-14 75904]
R1 kbfilter;Keyboard Filter Driver;c:\windows\system32\drivers\kbfilter.sys [2007-12-15 12856]
R1 UsbFltr;WayTechUSBFilterDriver;c:\windows\system32\drivers\UsbFltr.sys [2007-12-15 9291]
R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\apache.exe [2008-06-15 17408]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-19 950096]
S3 ETDrv;ETDrv;c:\windows\system32\drivers\ETDrv.sys [2008-01-11 170128]
S3 hp4200c;%usbscan.SvcDesc%;c:\windows\system32\drivers\hp4200c.sys [2006-05-26 9312]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2008-11-19 7808]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - e:\wd_windows_tools\WDSetup.exe
.
Contents of the 'Scheduled Tasks' folder
2009-02-18 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-18 23:45]
2009-01-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-01-25 c:\windows\Tasks\RegistrySmart Scheduled Scan.job
- c:\program files\RegistrySmart\RegistrySmart.exe []
2009-01-25 c:\windows\Tasks\RegistrySmart Scheduled Scan.job
- c:\program files\RegistrySmart []
.
- - - - ORPHANS REMOVED - - - -
BHO-{C5BF49A2-94F3-42BD-F434-3604812C8955} - c:\windows\system32\hs78344kjkfd.dll
HKLM-Run-Cmaudio - cmicnfg.cpl
SharedTaskScheduler-{C5BF49A2-94F3-42BD-F434-3604812C8955} - c:\windows\system32\hs78344kjkfd.dll
Notify-avgrsstarter - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.au/ig
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = ;localhost;*.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: microsoft.com\office
TCP: {CB70EEC9-3211-4B04-8B84-DDA1F06F0D12} = 10.1.1.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Mei\Application Data\Mozilla\Firefox\Profiles\of2c0vdy.Meikochan\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/ig
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-20 23:02:48
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
c:\windows\explorer.exe [2008] 0x8689AB28
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1085031214-261478967-839522115-1002\Software\SecuROM\License information*]
"datasecu"=hex:99,73,97,fd,bb,27,25,8f,ce,1c,99,5a,0d,2e,3e,b2,6b,f5,2b,f6,d2,
18,ea,67,bf,7b,55,5d,4a,19,91,92,4e,95,71,44,31,f6,11,cc,89,12,18,88,dd,be,\
"rkeysecu"=hex:f3,2c,95,cb,cb,12,d9,61,20,0f,30,b5,5d,f0,03,18
[HKEY_USERS\S-1-5-21-1085031214-261478967-839522115-1002\Software\Sony Creative Software\M*e*d*i*a* *M*a*n*a*g*e*r* *f*o*r* *P*S*P*"!\2.5]
"FRT"="g4Z/8jxNiXRA4zMIrKp6T9XeeZF1IsRHEibO6PaFgdWwOEfTuCvcFA=="
"PLCK"="irVS7F8HY6r376LuJ+QRV/LRmbdyf59T"
"Percents"="0 0.0648 0.2294 0.5104 0.7684 0.854 0.8573 "
"Increment"=".004464"
"PHSH"=""
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):Dc,89,d3,a3,f6,41,a8,bb,5d,86,7a,7b,43,bb,dc,ff,09,5d,aa,dd,52,
14,d3,3b,65,81,92,99,74,77,a0,c2,9a,93,d3,28,41,c0,8c,c8,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f3452cc9-d04e-498e-914b-bb3a7f60098b}]
@Denied: (Full) (Everyone)
"Model"=dword:0000009e
"Therad"=dword:00000014
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(488)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
———————— Other Running Processes ————————
.
c:\program files\Ahead\InCD\incdsrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\xampp\mysql\bin\mysqld-nt.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PSIService.exe
c:\windows\system32\rundll32.exe
c:\program files\Media Key\OSD.exe
c:\program files\Secunia\PSI\psi.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
.
**************************************************************************
.
Completion time: 2009-02-20 23:10:08 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-20 12:40:05
ComboFix2.txt 2007-08-05 07:37:19
Pre-Run: 92,568,440,832 bytes free
Post-Run: 92,505,067,520 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
312 — E O F — 2009-02-11 12:17:58
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:21:03 PM, on 20/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\xampp\apache\bin\apache.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\xampp\mysql\bin\mysqld-nt.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\xampp\apache\bin\apache.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\INTERN~2\mum.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Media Key\MagicKey.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Media Key\OSD.EXE
C:\Program Files\Secunia\PSI\psi.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [hplampc] C:\WINDOWS\system32\hplampc.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [InternodeUsage] C:\PROGRA~1\INTERN~2\mum.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe
O4 - Global Startup: Exif Launcher S.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Media Key.lnk = C:\Program Files\Media Key\MagicKey.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1229176476203
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{CB70EEC9-3211-4B04-8B84-DDA1F06F0D12}: NameServer = 10.1.1.1
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\figinuli.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\xampp\apache\bin\apache.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: mysql - Unknown owner - C:\xampp\mysql\bin\mysqld-nt.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
–
End of file - 9088 bytes