Groundhogie
Okay, everything went as planned with ComboFix.
Here is the CF log, followed by the HJT log as you instructed earlier.
Edit: Quick point of interest. I am no longer locked out of my desktop properties after the ComboFix scan, I'm able to change my desktop backround again!
ComboFix 09-09-20.04 - Tom Corrgan 21/09/2009 23:45.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1478 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Tom Corrgan\Application Data\wiaserva.log
C:\install.exe
c:\windows\Installer\90b64e.msp
c:\windows\system32\41.exe
c:\windows\system32\AcroIEHelpe006.dll
c:\windows\system32\bin
c:\windows\system32\bin\FileSystem_Steam.dll
c:\windows\system32\bin\friendsUI.dll
c:\windows\system32\bin\mss32_s.dll
c:\windows\system32\bin\nattypeprobe.dll
c:\windows\system32\bin\p2pcore.dll
c:\windows\system32\bin\p2pvoice.dll
c:\windows\system32\bin\ServerBrowser.dll
c:\windows\system32\bin\shaders\D3D10Overlay.fxo
c:\windows\system32\bin\SteamService.dll
c:\windows\system32\bin\SteamService.exe
c:\windows\system32\bin\vaudio_speex.dll
c:\windows\system32\bin\vgui2.dll
c:\windows\system32\UAs
c:\windows\system32\UAs\200984144724_mcinfo_UAs001.dat
c:\windows\system32\UAs\AcroRd32_UAs001.dat
c:\windows\system32\UAs\Ares_UAs001.dat
c:\windows\system32\UAs\Ares_UAs002.dat
c:\windows\system32\UAs\AUMgr_UAs001.dat
c:\windows\system32\UAs\brastia_UAs001.dat
c:\windows\system32\UAs\ccleaner_UAs001.dat
c:\windows\system32\UAs\core_UAs001.dat
c:\windows\system32\UAs\crashreporter_UAs001.dat
c:\windows\system32\UAs\dlm_UAs001.dat
c:\windows\system32\UAs\dwwin_UAs001.dat
c:\windows\system32\UAs\Explorer_UAs001.dat
c:\windows\system32\UAs\Explorer_UAs002.dat
c:\windows\system32\UAs\Explorer_UAs003.dat
c:\windows\system32\UAs\Explorer_UAs004.dat
c:\windows\system32\UAs\fallout3_UAs001.dat
c:\windows\system32\UAs\fallout3_UAs002.dat
c:\windows\system32\UAs\fallout3_UAs003.dat
c:\windows\system32\UAs\firefox_UAs001.dat
c:\windows\system32\UAs\firefox_UAs002.dat
c:\windows\system32\UAs\gfwlclient_UAs001.dat
c:\windows\system32\UAs\gfwlclient_UAs002.dat
c:\windows\system32\UAs\gfwlclient_UAs003.dat
c:\windows\system32\UAs\GFWLClient_UAs004.dat
c:\windows\system32\UAs\GFWLClient_UAs005.dat
c:\windows\system32\UAs\iexplore_UAs001.dat
c:\windows\system32\UAs\iexplore_UAs002.dat
c:\windows\system32\UAs\iexplore_UAs003.dat
c:\windows\system32\UAs\IEXPLORE_UAs004.dat
c:\windows\system32\UAs\IEXPLORE_UAs005.dat
c:\windows\system32\UAs\IEXPLORE_UAs006.dat
c:\windows\system32\UAs\iexplore_UAs007.dat
c:\windows\system32\UAs\iexplore_UAs008.dat
c:\windows\system32\UAs\javaw_UAs001.dat
c:\windows\system32\UAs\jre-6u15-windows-i586-iftw_UAs001.dat
c:\windows\system32\UAs\jucheck_UAs001.dat
c:\windows\system32\UAs\jusched_UAs001.dat
c:\windows\system32\UAs\left4dead_UAs001.dat
c:\windows\system32\UAs\left4dead_UAs002.dat
c:\windows\system32\UAs\mbam_UAs001.dat
c:\windows\system32\UAs\mcinfo_UAs001.dat
c:\windows\system32\UAs\mcupdate_UAs001.dat
c:\windows\system32\UAs\mpftray_UAs001.dat
c:\windows\system32\UAs\opera_UAs001.dat
c:\windows\system32\UAs\opera_UAs002.dat
c:\windows\system32\UAs\photoshop album starter edition_UAs001.dat
c:\windows\system32\UAs\photoshop album starter edition_UAs002.dat
c:\windows\system32\UAs\RealPlay_UAs001.dat
c:\windows\system32\UAs\setup_UAs001.dat
c:\windows\system32\UAs\setup_UAs002.dat
c:\windows\system32\UAs\sims3launcher_UAs001.dat
c:\windows\system32\UAs\sims3launcher_UAs002.dat
c:\windows\system32\UAs\sims3launcher_UAs003.dat
c:\windows\system32\UAs\softwareupdate_UAs001.dat
c:\windows\system32\UAs\softwareupdate_UAs002.dat
c:\windows\system32\UAs\ssupdate_UAs001.dat
c:\windows\system32\UAs\steam_UAs001.dat
c:\windows\system32\UAs\steam_UAs002.dat
c:\windows\system32\UAs\steam_UAs003.dat
c:\windows\system32\UAs\steam_UAs004.dat
c:\windows\system32\UAs\SUPERAntiSpyware_UAs001.dat
c:\windows\system32\UAs\SUPERAntiSpyware_UAs002.dat
c:\windows\system32\UAs\SUPERAntiSpyware_UAs003.dat
c:\windows\system32\UAs\wgasetup_UAs001.dat
c:\windows\system32\UAs\wgatray_UAs001.dat
c:\windows\system32\UAs\winarps32_UAs001.dat
c:\windows\system32\UAs\winupdate_UAs001.dat
c:\windows\system32\UAs\wmplayer_UAs001.dat
c:\windows\system32\UAs\wmplayer_UAs002.dat
c:\windows\system32\UAs\xpnetdiag_UAs001.dat
c:\windows\system32\grpconv.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\grpconv.exe
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((( Files Created from 2009-08-21 to 2009-09-21 )))))))))))))))))))))))))))))))
.
2009-09-21 22:47 . 2008-04-14 00:12 50176 —-a-w- c:\windows\system32\proquota.exe
2009-09-21 20:53 . 2009-07-03 17:09 915456 —-a-w- c:\windows\system32\wininet.dll
2009-09-21 20:53 . 2009-07-03 17:09 915456 —-a-w- c:\windows\system32\dllcache\wininet.dll
2009-09-15 00:00 . 2009-09-15 00:00 ——– d—–w- c:\program files\ESET
2009-09-14 00:07 . 2009-09-14 00:07 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-09-14 00:07 . 2009-09-15 19:57 ——– d—–w- c:\documents and settings\Tom Corrgan\Application Data\SUPERAntiSpyware.com
2009-09-14 00:07 . 2009-09-15 19:57 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-09-13 22:26 . 2009-09-13 22:26 ——– d—–w- c:\program files\Trend Micro
2009-09-13 22:19 . 2009-09-13 22:19 ——– d—–w- c:\program files\CleanUp!
2009-09-09 20:13 . 2009-06-21 21:44 153088 ——w- c:\windows\system32\dllcache\triedit.dll
2009-08-31 01:57 . 2009-08-31 01:57 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-08-27 22:36 . 2009-08-27 22:36 195912 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-21 21:24 . 2008-02-14 13:05 ——– d—–w- c:\program files\Steam
2009-09-21 21:10 . 2008-04-07 15:17 ——– d—–w- c:\program files\Nokia
2009-09-21 21:10 . 2007-05-26 16:39 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-09-21 20:45 . 2004-08-11 16:00 21504 —-a-w- c:\windows\system32\sysp.tmp
2009-09-21 20:45 . 2004-08-11 16:00 993792 —-a-w- c:\windows\system32\sysk.tmp
2009-09-15 19:57 . 2007-08-05 05:32 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-09-14 02:01 . 2007-12-27 22:43 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-09-04 14:38 . 2007-05-29 16:25 ——– d—–w- c:\documents and settings\Tom Corrgan\Application Data\AdobeUM
2009-08-31 01:57 . 2007-06-15 11:11 ——– d—–w- c:\program files\DivX
2009-08-27 18:25 . 2009-05-02 17:14 ——– d—–w- c:\program files\Microsoft Games for Windows - LIVE
2009-08-16 15:15 . 2007-05-26 16:47 38256 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-14 18:42 . 2009-08-14 18:42 551408 —-a-w- c:\windows\system32\mss32_s.dll
2009-08-14 18:42 . 2009-08-14 18:42 1082616 —-a-w- c:\windows\system32\GameOverlayUI.exe
2009-08-14 18:42 . 2009-08-14 18:42 402680 —-a-w- c:\windows\system32\vstdlib_s.dll
2009-08-14 18:42 . 2009-08-14 18:42 3348976 —-a-w- c:\windows\system32\steamclient.dll
2009-08-14 18:42 . 2009-08-14 18:42 275704 —-a-w- c:\windows\system32\tier0_s.dll
2009-08-14 18:42 . 2009-08-14 18:42 242936 —-a-w- c:\windows\system32\GameOverlayRenderer.dll
2009-08-14 18:42 . 2009-08-14 18:42 122864 —-a-w- c:\windows\system32\CSERHelper.dll
2009-08-14 18:42 . 2009-08-14 18:42 2888976 —-a-w- c:\windows\system32\Steam.dll
2009-08-14 18:42 . 2009-08-14 18:42 3101944 —-a-w- c:\windows\system32\SteamUI.dll
2009-08-14 18:42 . 2009-08-14 18:42 283336 —-a-w- c:\windows\system32\WriteMiniDump.exe
2009-08-07 18:51 . 2009-08-07 18:51 15308424 —-a-w- c:\windows\system32\xlive.dll
2009-08-07 18:51 . 2009-08-07 18:51 13642888 —-a-w- c:\windows\system32\xlivefnt.dll
2009-08-05 09:01 . 2004-08-11 16:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 13:47 . 2007-05-26 16:43 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-08-04 13:45 . 2009-08-04 13:45 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-04 13:45 . 2009-08-04 13:45 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-04 13:45 . 2009-08-04 13:45 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-04 13:45 . 2009-08-04 13:45 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-04 13:45 . 2009-08-04 13:45 ——– d—–w- c:\program files\AVG
2009-08-04 13:45 . 2009-08-04 13:45 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-08-04 13:40 . 2009-08-04 13:40 ——– d—–w- c:\documents and settings\Tom Corrgan\Application Data\AVG8
2009-08-02 23:09 . 2009-05-24 23:52 2087 —-a-w- c:\windows\system32\urhtps.dat
2009-07-17 19:01 . 2004-08-11 16:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 22:43 . 2004-08-11 16:00 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2009-05-01 20:01 915456 —-a-w- c:\windows\system32\osysw.dat
2009-07-03 17:09 . 2004-08-11 16:00 915456 —-a-w- c:\windows\system32\sysw.tmp
2009-06-25 08:25 . 2004-08-11 16:00 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-11 16:00 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-11 16:00 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-11 16:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-08-11 16:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-11 16:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2004-08-11 16:00 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\opera\program\plugins\ssldivx.dll
2007-11-11 15:38 . 2007-06-28 00:26 88 –sh–r- c:\windows\system32\8469EBF268.sys
2007-11-11 15:39 . 2007-06-28 00:26 3764 -csha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 218032]
"igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2009-05-14 1103216]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-06-12 700416]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-10-14 122880]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 86960]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-09-10 218032]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-13 185896]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-16 2007832]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CtHelper.exe [2006-12-12 19456]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\Ctxfihlp.exe [2008-10-07 23552]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
NETGEAR WG111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v2\WG111v2.exe [2006-5-17 2297856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-04 13:45 11952 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"IDriverT"=3 (0x3)
"aawservice"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\BitZip\\bitzip.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Steam\\SteamApps\\groundhogie\\team fortress 2\\hl2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Bethesda Softworks\\Fallout 3\\Fallout3.exe"=
"c:\\Program Files\\Steam\\steam.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\left 4 dead\\left4dead.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12602:TCP"= 12602:TCP:BitComet 12602 TCP
"12602:UDP"= 12602:UDP:BitComet 12602 UDP
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [04/08/2009 14:45 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [04/08/2009 14:45 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [04/08/2009 14:45 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [04/08/2009 14:45 297752]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [08/10/2008 02:21 171032]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [08/10/2008 02:21 1324056]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [08/10/2008 02:21 72728]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [27/03/2006 18:53 167808]
S0 etbcxd;etbcxd;c:\windows\system32\drivers\bqtularb.sys –> c:\windows\system32\drivers\bqtularb.sys [?]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [22/12/2008 22:08 79360]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [08/10/2008 02:21 171032]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [08/10/2008 02:21 1324056]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [08/10/2008 02:21 72728]
S3 XDva037;XDva037;\??\c:\windows\system32\XDva037.sys –> c:\windows\system32\XDva037.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.ie/
uInternet Connection Wizard,ShellNext = hxxp://www.google.ie/ig/dell?hl=en&client;=dell-row&channel;=ie&ibd;=1070526
IE: &Search;
IE: Download with &Shareaza; - c:\program files\Gnutella Turbo\Plugins\RazaWebHook.dll/3000
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-21 23:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-2938773245-2729800120-3568571596-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:92,c8,a5,3b,72,4e,85,d1,d9,ae,fe,42,46,59,82,7e,02,be,07,da,30,71,b6,
ef,e4,0a,65,16,e6,7b,7a,96,4e,d7,c4,df,97,e4,df,a4,5b,31,c0,8d,9a,16,a7,67,\
"??"=hex:25,65,bb,27,8b,92,55,34,10,3f,d9,49,2f,0e,31,37
[HKEY_USERS\S-1-5-21-2938773245-2729800120-3568571596-1005\Software\SecuROM\License information*]
"datasecu"=hex:32,88,4b,24,79,05,52,26,7f,ce,ea,4d,a2,87,db,3e,b2,2c,b0,c9,41,
76,f4,e6,db,6c,ba,b5,09,4d,b0,4e,8f,4f,de,7d,d6,22,21,0f,84,42,80,b8,65,de,\
"rkeysecu"=hex:82,c3,15,4f,bb,1d,3b,7f,84,f5,53,93,76,d6,d1,ff
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(668)
c:\windows\system32\RtlGina2.dll
.
Completion time: 2009-09-21 23:48
ComboFix-quarantined-files.txt 2009-09-21 22:48
Pre-Run: 131,250,442,240 bytes free
Post-Run: 131,207,835,648 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
314 — E O F — 2009-09-10 02:02
And here is the frest HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:54:34, on 21/09/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Electronic Arts\EADM\Core.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.ie/ig/dell?hl=en&client;=dell-row&channel;=ie&ibd;=1070526
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.ie/ig/dell?hl=en&cli;…amp;ibd=1070526
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
O8 - Extra context menu item: Download with &Shareaza; - res://C:\Program Files\Gnutella Turbo\Plugins\RazaWebHook.dll/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
–
End of file - 8155 bytes
Here is the CF log, followed by the HJT log as you instructed earlier.
Edit: Quick point of interest. I am no longer locked out of my desktop properties after the ComboFix scan, I'm able to change my desktop backround again!
ComboFix 09-09-20.04 - Tom Corrgan 21/09/2009 23:45.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1478 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Tom Corrgan\Application Data\wiaserva.log
C:\install.exe
c:\windows\Installer\90b64e.msp
c:\windows\system32\41.exe
c:\windows\system32\AcroIEHelpe006.dll
c:\windows\system32\bin
c:\windows\system32\bin\FileSystem_Steam.dll
c:\windows\system32\bin\friendsUI.dll
c:\windows\system32\bin\mss32_s.dll
c:\windows\system32\bin\nattypeprobe.dll
c:\windows\system32\bin\p2pcore.dll
c:\windows\system32\bin\p2pvoice.dll
c:\windows\system32\bin\ServerBrowser.dll
c:\windows\system32\bin\shaders\D3D10Overlay.fxo
c:\windows\system32\bin\SteamService.dll
c:\windows\system32\bin\SteamService.exe
c:\windows\system32\bin\vaudio_speex.dll
c:\windows\system32\bin\vgui2.dll
c:\windows\system32\UAs
c:\windows\system32\UAs\200984144724_mcinfo_UAs001.dat
c:\windows\system32\UAs\AcroRd32_UAs001.dat
c:\windows\system32\UAs\Ares_UAs001.dat
c:\windows\system32\UAs\Ares_UAs002.dat
c:\windows\system32\UAs\AUMgr_UAs001.dat
c:\windows\system32\UAs\brastia_UAs001.dat
c:\windows\system32\UAs\ccleaner_UAs001.dat
c:\windows\system32\UAs\core_UAs001.dat
c:\windows\system32\UAs\crashreporter_UAs001.dat
c:\windows\system32\UAs\dlm_UAs001.dat
c:\windows\system32\UAs\dwwin_UAs001.dat
c:\windows\system32\UAs\Explorer_UAs001.dat
c:\windows\system32\UAs\Explorer_UAs002.dat
c:\windows\system32\UAs\Explorer_UAs003.dat
c:\windows\system32\UAs\Explorer_UAs004.dat
c:\windows\system32\UAs\fallout3_UAs001.dat
c:\windows\system32\UAs\fallout3_UAs002.dat
c:\windows\system32\UAs\fallout3_UAs003.dat
c:\windows\system32\UAs\firefox_UAs001.dat
c:\windows\system32\UAs\firefox_UAs002.dat
c:\windows\system32\UAs\gfwlclient_UAs001.dat
c:\windows\system32\UAs\gfwlclient_UAs002.dat
c:\windows\system32\UAs\gfwlclient_UAs003.dat
c:\windows\system32\UAs\GFWLClient_UAs004.dat
c:\windows\system32\UAs\GFWLClient_UAs005.dat
c:\windows\system32\UAs\iexplore_UAs001.dat
c:\windows\system32\UAs\iexplore_UAs002.dat
c:\windows\system32\UAs\iexplore_UAs003.dat
c:\windows\system32\UAs\IEXPLORE_UAs004.dat
c:\windows\system32\UAs\IEXPLORE_UAs005.dat
c:\windows\system32\UAs\IEXPLORE_UAs006.dat
c:\windows\system32\UAs\iexplore_UAs007.dat
c:\windows\system32\UAs\iexplore_UAs008.dat
c:\windows\system32\UAs\javaw_UAs001.dat
c:\windows\system32\UAs\jre-6u15-windows-i586-iftw_UAs001.dat
c:\windows\system32\UAs\jucheck_UAs001.dat
c:\windows\system32\UAs\jusched_UAs001.dat
c:\windows\system32\UAs\left4dead_UAs001.dat
c:\windows\system32\UAs\left4dead_UAs002.dat
c:\windows\system32\UAs\mbam_UAs001.dat
c:\windows\system32\UAs\mcinfo_UAs001.dat
c:\windows\system32\UAs\mcupdate_UAs001.dat
c:\windows\system32\UAs\mpftray_UAs001.dat
c:\windows\system32\UAs\opera_UAs001.dat
c:\windows\system32\UAs\opera_UAs002.dat
c:\windows\system32\UAs\photoshop album starter edition_UAs001.dat
c:\windows\system32\UAs\photoshop album starter edition_UAs002.dat
c:\windows\system32\UAs\RealPlay_UAs001.dat
c:\windows\system32\UAs\setup_UAs001.dat
c:\windows\system32\UAs\setup_UAs002.dat
c:\windows\system32\UAs\sims3launcher_UAs001.dat
c:\windows\system32\UAs\sims3launcher_UAs002.dat
c:\windows\system32\UAs\sims3launcher_UAs003.dat
c:\windows\system32\UAs\softwareupdate_UAs001.dat
c:\windows\system32\UAs\softwareupdate_UAs002.dat
c:\windows\system32\UAs\ssupdate_UAs001.dat
c:\windows\system32\UAs\steam_UAs001.dat
c:\windows\system32\UAs\steam_UAs002.dat
c:\windows\system32\UAs\steam_UAs003.dat
c:\windows\system32\UAs\steam_UAs004.dat
c:\windows\system32\UAs\SUPERAntiSpyware_UAs001.dat
c:\windows\system32\UAs\SUPERAntiSpyware_UAs002.dat
c:\windows\system32\UAs\SUPERAntiSpyware_UAs003.dat
c:\windows\system32\UAs\wgasetup_UAs001.dat
c:\windows\system32\UAs\wgatray_UAs001.dat
c:\windows\system32\UAs\winarps32_UAs001.dat
c:\windows\system32\UAs\winupdate_UAs001.dat
c:\windows\system32\UAs\wmplayer_UAs001.dat
c:\windows\system32\UAs\wmplayer_UAs002.dat
c:\windows\system32\UAs\xpnetdiag_UAs001.dat
c:\windows\system32\grpconv.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\grpconv.exe
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((( Files Created from 2009-08-21 to 2009-09-21 )))))))))))))))))))))))))))))))
.
2009-09-21 22:47 . 2008-04-14 00:12 50176 —-a-w- c:\windows\system32\proquota.exe
2009-09-21 20:53 . 2009-07-03 17:09 915456 —-a-w- c:\windows\system32\wininet.dll
2009-09-21 20:53 . 2009-07-03 17:09 915456 —-a-w- c:\windows\system32\dllcache\wininet.dll
2009-09-15 00:00 . 2009-09-15 00:00 ——– d—–w- c:\program files\ESET
2009-09-14 00:07 . 2009-09-14 00:07 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-09-14 00:07 . 2009-09-15 19:57 ——– d—–w- c:\documents and settings\Tom Corrgan\Application Data\SUPERAntiSpyware.com
2009-09-14 00:07 . 2009-09-15 19:57 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-09-13 22:26 . 2009-09-13 22:26 ——– d—–w- c:\program files\Trend Micro
2009-09-13 22:19 . 2009-09-13 22:19 ——– d—–w- c:\program files\CleanUp!
2009-09-09 20:13 . 2009-06-21 21:44 153088 ——w- c:\windows\system32\dllcache\triedit.dll
2009-08-31 01:57 . 2009-08-31 01:57 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-08-27 22:36 . 2009-08-27 22:36 195912 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-21 21:24 . 2008-02-14 13:05 ——– d—–w- c:\program files\Steam
2009-09-21 21:10 . 2008-04-07 15:17 ——– d—–w- c:\program files\Nokia
2009-09-21 21:10 . 2007-05-26 16:39 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-09-21 20:45 . 2004-08-11 16:00 21504 —-a-w- c:\windows\system32\sysp.tmp
2009-09-21 20:45 . 2004-08-11 16:00 993792 —-a-w- c:\windows\system32\sysk.tmp
2009-09-15 19:57 . 2007-08-05 05:32 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-09-14 02:01 . 2007-12-27 22:43 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-09-04 14:38 . 2007-05-29 16:25 ——– d—–w- c:\documents and settings\Tom Corrgan\Application Data\AdobeUM
2009-08-31 01:57 . 2007-06-15 11:11 ——– d—–w- c:\program files\DivX
2009-08-27 18:25 . 2009-05-02 17:14 ——– d—–w- c:\program files\Microsoft Games for Windows - LIVE
2009-08-16 15:15 . 2007-05-26 16:47 38256 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-14 18:42 . 2009-08-14 18:42 551408 —-a-w- c:\windows\system32\mss32_s.dll
2009-08-14 18:42 . 2009-08-14 18:42 1082616 —-a-w- c:\windows\system32\GameOverlayUI.exe
2009-08-14 18:42 . 2009-08-14 18:42 402680 —-a-w- c:\windows\system32\vstdlib_s.dll
2009-08-14 18:42 . 2009-08-14 18:42 3348976 —-a-w- c:\windows\system32\steamclient.dll
2009-08-14 18:42 . 2009-08-14 18:42 275704 —-a-w- c:\windows\system32\tier0_s.dll
2009-08-14 18:42 . 2009-08-14 18:42 242936 —-a-w- c:\windows\system32\GameOverlayRenderer.dll
2009-08-14 18:42 . 2009-08-14 18:42 122864 —-a-w- c:\windows\system32\CSERHelper.dll
2009-08-14 18:42 . 2009-08-14 18:42 2888976 —-a-w- c:\windows\system32\Steam.dll
2009-08-14 18:42 . 2009-08-14 18:42 3101944 —-a-w- c:\windows\system32\SteamUI.dll
2009-08-14 18:42 . 2009-08-14 18:42 283336 —-a-w- c:\windows\system32\WriteMiniDump.exe
2009-08-07 18:51 . 2009-08-07 18:51 15308424 —-a-w- c:\windows\system32\xlive.dll
2009-08-07 18:51 . 2009-08-07 18:51 13642888 —-a-w- c:\windows\system32\xlivefnt.dll
2009-08-05 09:01 . 2004-08-11 16:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 13:47 . 2007-05-26 16:43 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-08-04 13:45 . 2009-08-04 13:45 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-04 13:45 . 2009-08-04 13:45 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-04 13:45 . 2009-08-04 13:45 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-04 13:45 . 2009-08-04 13:45 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-04 13:45 . 2009-08-04 13:45 ——– d—–w- c:\program files\AVG
2009-08-04 13:45 . 2009-08-04 13:45 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-08-04 13:40 . 2009-08-04 13:40 ——– d—–w- c:\documents and settings\Tom Corrgan\Application Data\AVG8
2009-08-02 23:09 . 2009-05-24 23:52 2087 —-a-w- c:\windows\system32\urhtps.dat
2009-07-17 19:01 . 2004-08-11 16:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 22:43 . 2004-08-11 16:00 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2009-05-01 20:01 915456 —-a-w- c:\windows\system32\osysw.dat
2009-07-03 17:09 . 2004-08-11 16:00 915456 —-a-w- c:\windows\system32\sysw.tmp
2009-06-25 08:25 . 2004-08-11 16:00 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-11 16:00 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-11 16:00 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-11 16:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-08-11 16:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-11 16:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2004-08-11 16:00 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\opera\program\plugins\ssldivx.dll
2007-11-11 15:38 . 2007-06-28 00:26 88 –sh–r- c:\windows\system32\8469EBF268.sys
2007-11-11 15:39 . 2007-06-28 00:26 3764 -csha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 218032]
"igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2009-05-14 1103216]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-06-12 700416]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-10-14 122880]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 86960]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-09-10 218032]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-13 185896]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-16 2007832]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CtHelper.exe [2006-12-12 19456]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\Ctxfihlp.exe [2008-10-07 23552]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
NETGEAR WG111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v2\WG111v2.exe [2006-5-17 2297856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-04 13:45 11952 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"IDriverT"=3 (0x3)
"aawservice"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\BitZip\\bitzip.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Steam\\SteamApps\\groundhogie\\team fortress 2\\hl2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Bethesda Softworks\\Fallout 3\\Fallout3.exe"=
"c:\\Program Files\\Steam\\steam.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\left 4 dead\\left4dead.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12602:TCP"= 12602:TCP:BitComet 12602 TCP
"12602:UDP"= 12602:UDP:BitComet 12602 UDP
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [04/08/2009 14:45 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [04/08/2009 14:45 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [04/08/2009 14:45 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [04/08/2009 14:45 297752]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [08/10/2008 02:21 171032]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [08/10/2008 02:21 1324056]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [08/10/2008 02:21 72728]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [27/03/2006 18:53 167808]
S0 etbcxd;etbcxd;c:\windows\system32\drivers\bqtularb.sys –> c:\windows\system32\drivers\bqtularb.sys [?]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [22/12/2008 22:08 79360]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [08/10/2008 02:21 171032]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [08/10/2008 02:21 1324056]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [08/10/2008 02:21 72728]
S3 XDva037;XDva037;\??\c:\windows\system32\XDva037.sys –> c:\windows\system32\XDva037.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.ie/
uInternet Connection Wizard,ShellNext = hxxp://www.google.ie/ig/dell?hl=en&client;=dell-row&channel;=ie&ibd;=1070526
IE: &Search;
IE: Download with &Shareaza; - c:\program files\Gnutella Turbo\Plugins\RazaWebHook.dll/3000
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-21 23:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-2938773245-2729800120-3568571596-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:92,c8,a5,3b,72,4e,85,d1,d9,ae,fe,42,46,59,82,7e,02,be,07,da,30,71,b6,
ef,e4,0a,65,16,e6,7b,7a,96,4e,d7,c4,df,97,e4,df,a4,5b,31,c0,8d,9a,16,a7,67,\
"??"=hex:25,65,bb,27,8b,92,55,34,10,3f,d9,49,2f,0e,31,37
[HKEY_USERS\S-1-5-21-2938773245-2729800120-3568571596-1005\Software\SecuROM\License information*]
"datasecu"=hex:32,88,4b,24,79,05,52,26,7f,ce,ea,4d,a2,87,db,3e,b2,2c,b0,c9,41,
76,f4,e6,db,6c,ba,b5,09,4d,b0,4e,8f,4f,de,7d,d6,22,21,0f,84,42,80,b8,65,de,\
"rkeysecu"=hex:82,c3,15,4f,bb,1d,3b,7f,84,f5,53,93,76,d6,d1,ff
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(668)
c:\windows\system32\RtlGina2.dll
.
Completion time: 2009-09-21 23:48
ComboFix-quarantined-files.txt 2009-09-21 22:48
Pre-Run: 131,250,442,240 bytes free
Post-Run: 131,207,835,648 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
314 — E O F — 2009-09-10 02:02
And here is the frest HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:54:34, on 21/09/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Electronic Arts\EADM\Core.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.ie/ig/dell?hl=en&client;=dell-row&channel;=ie&ibd;=1070526
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.ie/ig/dell?hl=en&cli;…amp;ibd=1070526
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
O8 - Extra context menu item: Download with &Shareaza; - res://C:\Program Files\Gnutella Turbo\Plugins\RazaWebHook.dll/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
–
End of file - 8155 bytes