Combofix log:
ComboFix 07-12-12.3 - Dell 3000 2007-12-12 11:44:45.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.130 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Dell 3000\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\opnvmwvi.exe
C:\pgdxf.exe
C:\WINDOWS\system32\crehcjid.dll
C:\WINDOWS\system32\rrutv.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\opnvmwvi.exe
C:\pgdxf.exe
C:\WINDOWS\system32\crehcjid.dll
C:\WINDOWS\system32\drivers\ip6fw.sys
C:\WINDOWS\system32\rrutv.ini
.
((((((((((((((((((((((((( Files Created from 2007-11-12 to 2007-12-12 )))))))))))))))))))))))))))))))
.
2007-11-20 19:43 . 2007-12-09 14:27 d——– C:\HiJackThis!
2007-11-20 19:05 . 2004-08-03 23:00 29,056 –a–c— C:\WINDOWS\system32\dllcache\ip6fw.sys
2007-11-20 18:52 . 2007-11-20 18:52 d——– C:\Program Files\Security Task Manager
2007-11-20 18:52 . 2007-12-01 12:04 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2007-11-20 08:30 . 2007-11-20 08:30 d——– C:\Documents and Settings\All Users\Application Data\Uniblue
2007-11-20 08:28 . 2007-11-20 08:28 d——– C:\Program Files\Uniblue
2007-11-20 08:28 . 2007-11-20 08:28 d——– C:\Documents and Settings\Dell 3000\Application Data\Uniblue
2007-11-20 00:22 . 2007-11-20 00:22 d——– C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2007-11-19 22:31 . 2007-11-19 22:31 d——– C:\Program Files\uTorrent
2007-11-19 22:31 . 2007-11-20 08:20 d——– C:\Documents and Settings\Dell 3000\Application Data\uTorrent
2007-11-19 15:48 . 2001-08-17 13:52 18,688 –a—— C:\WINDOWS\system32\drivers\cdaudio.sys
2007-11-19 15:48 . 2001-08-17 13:52 18,688 –a–c— C:\WINDOWS\system32\dllcache\cdaudio.sys
2007-11-19 15:48 . 2007-12-12 11:34 16,768 –a—— C:\WINDOWS\system32\tcpip_patcher.sys
2007-11-19 15:48 . 2007-11-19 15:48 2 –a—— C:\144094129
2007-11-19 15:47 . 2004-08-03 23:00 8,192 –a—— C:\WINDOWS\system32\drivers\changer.sys
2007-11-19 15:47 . 2004-08-03 23:00 8,192 –a–c— C:\WINDOWS\system32\dllcache\changer.sys
2007-11-19 11:33 . 2001-08-17 13:48 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2007-11-19 11:33 . 2001-08-17 13:48 12,160 –a–c— C:\WINDOWS\system32\dllcache\mouhid.sys
2007-11-19 11:33 . 2001-08-17 14:02 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2007-11-19 11:33 . 2001-08-17 14:02 9,600 –a–c— C:\WINDOWS\system32\dllcache\hidusb.sys
2007-11-19 04:55 . 2007-11-19 04:55 d——– C:\Program Files\OpenOffice.org 2.3
2007-11-19 04:55 . 2007-06-14 16:53 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-20 02:40 ——— d—–w C:\Program Files\QuickTime
2007-11-19 10:55 ——— d—–w C:\Program Files\Java
2007-11-18 20:51 ——— d—–w C:\Program Files\Common Files\Adobe
2007-11-13 00:25 ——— d—–w C:\Program Files\LimeWire
2006-10-07 17:42 19,552 —-a-w C:\Documents and Settings\Dell 3000\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\144094129 —-
C:\144094129\
((((((((((((((((((((((((((((( snapshot@2007-12-09_14.16.28.89 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-27 09:58:11 140,288 —-a-w C:\WINDOWS\catchme.exe
+ 2007-12-10 01:04:27 142,336 —-a-w C:\WINDOWS\catchme.exe
+ 2007-12-12 17:34:37 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_5e0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-25 18:11]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-05-29 19:34]
"Walgreens PhotoShow Media Manager"="C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe" [2006-04-20 00:35]
"Uniblue SpyEraser"="C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" [2007-10-16 09:26]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-08-06 00:34]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 08:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 08:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 08:36]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 04:06]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-06-14 18:32]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-05-29 19:34]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-11-04 14:04:48]
KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 13:12:08]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crehcjid]
crehcjid.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pØø]
pØø
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pˆø]
pˆø
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\À0ø]
À0ø
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ÀØø]
ÀØø
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Àˆø]
Àˆø
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
R0 ElbyVCD;ElbyVCD;C:\WINDOWS\system32\DRIVERS\ElbyVCD.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2007-11-20 14:31:13 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-12 11:47:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-12 11:47:48
.
2007-11-20 02:54:32 — E O F —
Kaspersky Scan Report:
KASPERSKY ONLINE SCANNER REPORT
Wednesday, December 12, 2007 12:51:06 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 12/12/2007
Kaspersky Anti-Virus database records: 481021
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
Scan Statistics
Total number of scanned objects 49812
Number of viruses found 17
Number of infected objects 44
Number of suspicious objects 0
Duration of the scan process 00:41:15
Infected Object Name Virus Name Last Action
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\AntiPhishing\07FB382D-AA75-4683-82F4-EAB265A275CB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1c63d9248f8a5783e517a07313c09667_b02f3eff-22ba-45a8-89bf-c072e87aef3e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1db11ddebb19db5da0b161f9f006a650_b02f3eff-22ba-45a8-89bf-c072e87aef3e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b1c56d93c1a5cae90e7aec681b82542_b02f3eff-22ba-45a8-89bf-c072e87aef3e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2dfae571038bf70c3e453cf7467dbd02_b02f3eff-22ba-45a8-89bf-c072e87aef3e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2e06950d113362e3ce8fcf8f8916014a_b02f3eff-22ba-45a8-89bf-c072e87aef3e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5aa4c211043faf52570fcccf440fdf3f_b02f3eff-22ba-45a8-89bf-c072e87aef3e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\62cef024fcbaf916ad456f7f6ea72429_b02f3eff-22ba-45a8-89bf-c072e87aef3e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\675e8a3e834d443df8d44a2a84e1a6b2_b02f3eff-22ba-45a8-89bf-c072e87aef3e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\690b802928235e8068267fd10b69b81c_b02f3eff-22ba-45a8-89bf-c072e87aef3e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7a14c0ee12d7f7500c4bed971ea12d6f_b02f3eff-22ba-45a8-89bf-c072e87aef3e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\abbb56faed88809166d3e9cc98c0dbb9_b02f3eff-22ba-45a8-89bf-c072e87aef3e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c159f5336fe1de9fe566bec2cd16a2d8_b02f3eff-22ba-45a8-89bf-c072e87aef3e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c909fc4270c636fae17e1d0bfe534d57_b02f3eff-22ba-45a8-89bf-c072e87aef3e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d45f6cde67cfb281a9dbc2f0e37f04ef_b02f3eff-22ba-45a8-89bf-c072e87aef3e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dd5f6c051aaf22ec055c066a93bfde89_b02f3eff-22ba-45a8-89bf-c072e87aef3e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\SecTaskMan\ianurdtd.dll.q_8043A42_q Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\Documents and Settings\All Users\Application Data\SecTaskMan\ostkcvgl.exe.q_8041641_q Infected: Trojan.Win32.Obfuscated.kp skipped
C:\Documents and Settings\Dell 3000\Application Data\Mozilla\Firefox\Profiles\0vmwstm5.default\cert8.db Object is locked skipped
C:\Documents and Settings\Dell 3000\Application Data\Mozilla\Firefox\Profiles\0vmwstm5.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Dell 3000\Application Data\Mozilla\Firefox\Profiles\0vmwstm5.default\history.dat Object is locked skipped
C:\Documents and Settings\Dell 3000\Application Data\Mozilla\Firefox\Profiles\0vmwstm5.default\key3.db Object is locked skipped
C:\Documents and Settings\Dell 3000\Application Data\Mozilla\Firefox\Profiles\0vmwstm5.default\parent.lock Object is locked skipped
C:\Documents and Settings\Dell 3000\Application Data\Mozilla\Firefox\Profiles\0vmwstm5.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Dell 3000\Application Data\Mozilla\Firefox\Profiles\0vmwstm5.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Dell 3000\Application Data\MySpace\IM\Logs\MySpaceIM-20071212-113539.log Object is locked skipped
C:\Documents and Settings\Dell 3000\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Dell 3000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Dell 3000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Dell 3000\Local Settings\Application Data\Mozilla\Firefox\Profiles\0vmwstm5.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Dell 3000\Local Settings\Application Data\Mozilla\Firefox\Profiles\0vmwstm5.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Dell 3000\Local Settings\Application Data\Mozilla\Firefox\Profiles\0vmwstm5.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Dell 3000\Local Settings\Application Data\Mozilla\Firefox\Profiles\0vmwstm5.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Dell 3000\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dell 3000\Local Settings\Temp\me_4pdJNbsMmsg2yXu Object is locked skipped
C:\Documents and Settings\Dell 3000\Local Settings\Temp\me_ifCp58J4PbloJha Object is locked skipped
C:\Documents and Settings\Dell 3000\Local Settings\Temp\me_NBFrd3ZuzWMh5Gq Object is locked skipped
C:\Documents and Settings\Dell 3000\Local Settings\Temp\me_PsGemKqDSn5KglO Object is locked skipped
C:\Documents and Settings\Dell 3000\Local Settings\Temp\me_r5rzmoRT8YBt2s0 Object is locked skipped
C:\Documents and Settings\Dell 3000\Local Settings\Temp\~DF7EB3.tmp Object is locked skipped
C:\Documents and Settings\Dell 3000\Local Settings\Temporary Internet Files\AntiPhishing\07FB382D-AA75-4683-82F4-EAB265A275CB.dat Object is locked skipped
C:\Documents and Settings\Dell 3000\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\LegalXP\Legal XP.rar/Legal XP/MGVPatch/keyfinder.exe/data.rar/xpkey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\LegalXP\Legal XP.rar/Legal XP/MGVPatch/keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\LegalXP\Legal XP.rar/Legal XP/MGVPatch/keyfinder.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\LegalXP\Legal XP.rar/Legal XP/MGVPatch/keyfinder.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\LegalXP\Legal XP.rar/Legal XP/MGVPatch/Port_RockXP_v4.exe/data0000.cab/rock.exe/pwdump2/samdump.dll Infected: not-a-virus:PSWTool.Win32.PWDump.2 skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\LegalXP\Legal XP.rar/Legal XP/MGVPatch/Port_RockXP_v4.exe/data0000.cab/rock.exe/pwdump2/pwdump2.exe Infected: not-a-virus:PSWTool.Win32.PWDump.2 skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\LegalXP\Legal XP.rar/Legal XP/MGVPatch/Port_RockXP_v4.exe/data0000.cab/rock.exe Infected: not-a-virus:PSWTool.Win32.PWDump.2 skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\LegalXP\Legal XP.rar/Legal XP/MGVPatch/Port_RockXP_v4.exe/data0000.cab/RockXP4.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\LegalXP\Legal XP.rar/Legal XP/MGVPatch/Port_RockXP_v4.exe/data0000.cab Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\LegalXP\Legal XP.rar/Legal XP/MGVPatch/Port_RockXP_v4.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\LegalXP\Legal XP.rar RAR: infected - 10 skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\Microsoft_Windows_XP_Pro_Essential_1.1.iso/$OEM$/$$/System32/cmdow.exe Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\Microsoft_Windows_XP_Pro_Essential_1.1.iso ISO image: infected - 1 skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\Windows XP SP2 Keygen + Key Changer + Windows Genuine Validation.rar/Windows XP SP2 Keygen.EXE Infected: Trojan-Dropper.Win32.VB.tr skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\Windows XP SP2 Keygen + Key Changer + Windows Genuine Validation.rar/Windows Genuine Validation.EXE Infected: Trojan-Dropper.Win32.VB.tr skipped
C:\Documents and Settings\Dell 3000\My Documents\Downloads\Windows XP SP2 Keygen + Key Changer + Windows Genuine Validation.rar RAR: infected - 2 skipped
C:\Documents and Settings\Dell 3000\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Dell 3000\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.me Object is locked skipped
C:\Program Files\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.mm Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\BWKDLogs\BWTargetInf.log Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chandir.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chandir.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chn.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chn.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\D0000000.FCS Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\inuse.txt Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\L0000005.FCS Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\main.log Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_die.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_die.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_dnd.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_dnd.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_ext.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_ext.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_rcv.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_rcv.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\storydb.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\storydb.idx Object is locked skipped
C:\Program Files\Mozilla Firefox\patch.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\qoobox\Quarantine\C\opnvmwvi.exe.vir Infected: Trojan-Downloader.Win32.Agent.ffn skipped
C:\qoobox\Quarantine\C\pgdxf.exe.vir Infected: Trojan-Clicker.Win32.Costrat.by skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\crehcjid.dll.vir Infected: Email-Worm.Win32.Locksky.bp skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\drivers\runtime2.sys.vir Infected: Rootkit.Win32.Agent.jp skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\mafdtugy.dll.vir Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\vkeivblb.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\qoobox\Quarantine\catchme2007-12-09_141510.40.zip/jkkjgec.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.arv skipped
C:\qoobox\Quarantine\catchme2007-12-09_141510.40.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP139\A0024930.exe Infected: Trojan-Dropper.Win32.Agent.csv skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP140\A0035972.sys Infected: Trojan-Downloader.Win32.Agent.acl skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP140\A0035973.exe Infected: Backdoor.Win32.Rbot.gen skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP141\A0035990.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP141\A0035997.sys Infected: Trojan-Downloader.Win32.Agent.dpe skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP142\A0036006.sys Infected: Trojan-Downloader.Win32.Agent.dpe skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP142\A0036972.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP142\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP143\A0037025.sys Infected: Trojan-Downloader.Win32.Agent.dpe skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP144\A0037042.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP144\A0037043.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP144\A0037049.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.arv skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP144\A0037064.sys Infected: Rootkit.Win32.Agent.jp skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP145\A0039086.sys Infected: Trojan-Downloader.Win32.Agent.acl skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP145\A0039087.exe Infected: Trojan-Downloader.Win32.Agent.ffn skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP145\A0039088.exe Infected: Trojan-Clicker.Win32.Costrat.by skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP145\A0039089.dll Infected: Email-Worm.Win32.Locksky.bp skipped
C:\System Volume Information\_restore{29334045-D869-487E-A8E7-F35F280E9433}\RP145\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{71CACAE3-6E6D-413B-9FAD-B706CF1343B8}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_5e0.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
New HJT Report:
Logfile of HijackThis v1.99.1
Scan saved at 12:56:28 PM, on 12/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\HiJackThis!\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=552…cid={SUB_CLCID}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [Walgreens PhotoShow Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O20 - Winlogon Notify: crehcjid - crehcjid.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)