[Resolved] Serious Issue (HELP HELP HELP)
22 min read
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Profiler\LWEmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\symantecupdate20071208.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wi-compact.com/Forum/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [exflashservice] "C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" "5000"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ManualRun] "D:\AUTORUN\AutoRun"
O4 - HKLM\..\Run: [BtcMouseMaestro] "C:\Program Files\MMaestro\KMaestro.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [GoogleUpdate] C:\Program Files\Internet Explorer\Down(0).EXE
O4 - HKLM\..\Run: [Service32] C:\WINDOWS\system32\schost.exe
O4 - HKLM\..\Run: [MSUpdater] System32i.exe
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\RunServices: [MSUpdater] System32i.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech Profiler.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NetmanConnections (NetworkConnections) - Unknown owner - C:\WINDOWS\system32\wonlog.ini
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: wampapache - Unknown owner - C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld (file missing)
Fortunately, problems #1, #2, and #3 have ceased. Anything here?
Steve
* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
- Doubleclick the drweb-cureit.exe file and Allow to run the express scan
- This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
- Once the short scan has finished, mark the drives that you want to scan.
- Select all drives. A red dot shows which drives have been chosen.
- Click the green arrow at the right, and the scan will start.
- Click 'Yes to all' if it asks if you want to cure/move the file.
- When the scan has finished, look if you can click next icon next to the files found: [external image: Posted Image]
- If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
[external image: Posted Image]
This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples) - After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
- Save the report to your desktop. The report will be called DrWeb.csv
- Close Dr.Web Cureit.
- Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
- After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.
Please do not delete anything unless instructed to.
Next:
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)
It's normal after running ATF cleaner that the PC will be slower to boot the first time.
Next:
Download ComboFix from Here to your Desktop.
- Double click combofix.exe and follow the prompts.
- When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
ComboFix 07-12-09.1 - Kampfzentrum 2007-12-10 16:29:19.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1477 [GMT -6:00]
Running from: F:\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000009_.tmp.dll
C:\WINDOWS\system32\_000010_.tmp.dll
C:\WINDOWS\system32\drivers\sfsync02.sys
C:\WINDOWS\system32\gjkkj.ini2
C:\WINDOWS\system32\hgjlm.ini
C:\WINDOWS\system32\hgjlm.ini2
C:\WINDOWS\system32\mljgh.dll
C:\WINDOWS\system32\pqstv.ini2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_SFSYNC02
——-\sfsync02
((((((((((((((((((((((((( Files Created from 2007-11-10 to 2007-12-10 )))))))))))))))))))))))))))))))
.
2007-12-10 05:16 . 2007-12-10 05:16 d——– C:\Program Files\PM Studios
2007-12-09 21:30 . 2007-12-09 21:44 d——– C:\Documents and Settings\Kampfzentrum\DoctorWeb
2007-12-09 21:30 . 2007-12-09 21:31 77,824 –a—-t- C:\WINDOWS\system32\DRWEBSP.DLL
2007-12-09 21:29 . 2007-12-10 16:30 d——– C:\Program Files\DrWeb
2007-12-09 21:28 . 2007-12-09 21:28 d——– C:\Documents and Settings\Kampfzentrum\Application Data\InstallShield
2007-12-09 20:38 . 2007-12-09 20:38 d——– C:\Program Files\ATF Cleaner
2007-12-09 19:32 . 2007-12-09 19:32 426 –a—— C:\WINDOWS\system32\temp.dat
2007-12-09 19:18 . 2007-12-09 19:18 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 18:30 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Program Files\Spybot
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-09 17:34 . 2007-12-09 19:18 d——– C:\Documents and Settings\Kampfzentrum\Application Data\AdwareAlert
2007-12-09 16:05 . 2000-02-22 21:38 206,272 –a—— C:\WINDOWS\system32\drivers\udfreadr.BAK
2007-12-09 15:57 . 2002-02-22 18:02 206,208 –a—— C:\WINDOWS\system32\drivers\udfreadr.sys
2007-12-09 15:57 . 2002-02-22 18:10 90,112 –a—— C:\WINDOWS\system32\udfrunin.exe
2007-12-09 07:13 . 2007-09-06 05:09 801,144 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-12-09 07:13 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-12-09 07:13 . 2007-09-06 05:00 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-12-09 07:13 . 2007-09-06 05:05 94,416 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-09 07:13 . 2007-09-06 05:05 92,848 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-09 07:13 . 2007-09-06 05:02 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-09 07:13 . 2007-09-06 05:00 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-09 07:13 . 2007-09-06 05:03 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-09 07:12 . 2007-12-09 07:12 d——– C:\Program Files\Alwil Software
2007-12-08 22:52 . 2007-12-09 18:42 108,336 –a—— C:\WINDOWS\mswinsck.ocx
2007-12-08 22:34 . 2007-12-08 22:34 d–h—– C:\Program Files\WinfiX
2007-12-08 20:25 . 2007-12-08 20:25 80,448 –a—— C:\WINDOWS\system32\dmsfwfmj.#ll
2007-12-08 19:34 . 2007-12-08 19:34 98,304 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\WINDOWS\system32\ageia
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\Program Files\AGEIA Technologies
2007-12-08 16:47 . 2007-04-04 18:53 81,768 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-12-08 16:25 . 2007-12-08 16:25 35,840 –a—— C:\WINDOWS\system32\byxvvut.#ll
2007-12-08 14:48 . 2007-12-08 14:48 d——– C:\Documents and Settings\Kampfzentrum\Application Data\KALiNKOsoft
2007-12-08 14:48 . 2007-12-08 14:48 36,864 –a—— C:\WINDOWS\system32\dxinputdll.dll
2007-12-04 18:26 . 2007-12-04 18:27 d——– C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
2007-12-04 18:25 . 2007-12-04 18:25 d——– C:\Documents and Settings\Kampfzentrum\Application Data\GlobalSCAPE
2007-12-03 21:27 . 2007-12-03 21:27 d——– C:\Program Files\LSoft Technologies
2007-12-01 13:58 . 2007-12-01 13:59 d——– C:\Program Files\FPXpress
2007-12-01 13:21 . 2004-11-22 20:56 913,560 –a—— C:\WINDOWS\system32\wodFtpDLX.ocx
2007-12-01 13:21 . 2007-12-05 10:44 13 –a—— C:\WINDOWS\system32\WinSys32.crc
2007-12-01 13:20 . 2007-12-09 08:09 d——– C:\Program Files\CoffeeCup Software
2007-12-01 13:20 . 1999-03-22 12:29 233,472 –a—— C:\WINDOWS\system32\Ilda32.dll
2007-12-01 13:20 . 1998-06-17 04:00 18,944 –a—— C:\WINDOWS\system32\BORLNDMM.DLL
2007-12-01 12:44 . 2007-12-01 12:44 149,916 –a—— C:\tmp.exe
2007-12-01 07:42 . 2007-12-01 07:42 d——– C:\Program Files\AceBIT
2007-12-01 07:42 . 2003-08-29 16:36 1,079,808 –a—— C:\WINDOWS\system32\we.dll
2007-12-01 07:42 . 2003-07-22 03:40 430,080 –a—— C:\WINDOWS\system32\wodSFTP.ocx
2007-12-01 07:42 . 2003-07-22 03:38 425,984 –a—— C:\WINDOWS\system32\wodKeys.dll
2007-12-01 07:42 . 2003-07-22 03:37 385,024 –a—— C:\WINDOWS\system32\wodSFTP.dll
2007-12-01 06:22 . 2007-12-09 20:10 d——– C:\Program Files\Spyware Doctor
2007-12-01 06:22 . 2007-12-01 06:22 d——– C:\Documents and Settings\Kampfzentrum\Application Data\PC Tools
2007-12-01 06:22 . 2007-10-18 00:16 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-01 06:22 . 2007-10-18 00:15 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-01 06:22 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-01 06:22 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-01 06:20 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-29 17:15 . 2007-11-29 17:15 d——– C:\Program Files\PremiumSoft
2007-11-28 20:18 . 2007-11-28 20:22 d——– C:\Program Files\wamp
2007-11-28 15:59 . 2007-12-09 10:24 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-11-28 15:59 . 2007-11-28 15:59 1,409 –a—— C:\WINDOWS\QTFont.for
2007-11-28 15:58 . 2007-11-28 15:59 d——– C:\Program Files\iTunes
2007-11-28 15:58 . 2007-11-28 15:58 d——– C:\Program Files\iPod
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Program Files\phpDesigner 2008
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Documents and Settings\Kampfzentrum\Application Data\phpDesigner 2008
2007-11-27 21:29 . 2007-11-27 21:29 d——– C:\Program Files\7-Zip
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Windows Script Control
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Common Files\e.World
2007-11-27 21:09 . 2007-11-27 21:09 0 –a—— C:\WINDOWS\system32\UNWISE.INI
2007-11-27 21:08 . 2007-11-27 21:09 d——– C:\Program Files\PHPMaker 5
2007-11-27 21:08 . 2002-07-26 17:02 153,088 –a—— C:\WINDOWS\system32\UNWISE.EXE
2007-11-24 16:08 . 2007-11-24 16:09 d——– C:\Program Files\CrystalButton2
2007-11-22 22:32 . 2007-12-08 19:21 d——– C:\Program Files\Ubisoft
2007-11-18 13:05 . 2007-11-18 13:05 150,643 –ah—– C:\_crash.dmp
2007-11-18 13:05 . 2007-11-18 13:05 58,902 –ah—– C:\report.zip
2007-11-14 23:43 . 2007-11-14 23:43 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-11-14 23:43 . 2007-11-14 23:43 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-10 03:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 01:16 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Azureus
2007-12-09 14:39 ——— d—–w C:\Program Files\Babylon
2007-12-09 04:19 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Vso
2007-12-08 21:17 ——— d—–w C:\Program Files\Azureus
2007-11-28 21:57 ——— d—–w C:\Program Files\QuickTime
2007-11-26 02:17 ——— d—–w C:\Program Files\Soulseek
2007-11-24 03:35 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-23 04:32 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-17 22:21 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\BitTorrent
2007-11-13 23:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-04 15:03 ——— d—–w C:\Program Files\AIM
2007-11-04 15:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Aim
2007-11-04 13:03 ——— d—–w C:\Program Files\Common Files\Apple
2007-11-04 13:03 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-10-28 21:28 ——— d—–w C:\Program Files\WorkTime
2007-10-27 21:23 22,746,840 —-a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_10_27_16_22_24_full.dmp.zip
2007-10-26 03:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Babylon
2007-10-26 02:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Babylon
2007-10-25 02:46 ——— d—–w C:\Program Files\Text to Speech Maker
2007-10-25 02:35 ——— d—–w C:\Program Files\NCT
2007-10-25 02:11 ——— d—–w C:\Program Files\GameSpy Arcade
2007-10-25 01:23 ——— d—–w C:\Program Files\VirtualDJ
2007-10-25 01:21 ——— d—–w C:\Program Files\RegHealer
2007-10-20 12:15 ——— d—–w C:\Program Files\Magic Video Converter
2007-10-14 13:25 ——— d—–w C:\Program Files\Xilisoft
2007-10-14 13:05 ——— d—–w C:\Program Files\FileSee
2007-10-14 01:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\SongbirdVLC
2007-10-14 01:18 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Songbird
2007-10-13 21:15 ——— d—–w C:\Program Files\Soulseek-Test
2007-02-05 13:56 87,608 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\ezpinst.exe
2007-02-05 13:56 47,360 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\pcouffin.sys
2007-06-13 11:26 1,397,760 –sha-r C:\WINDOWS\system32\System32i.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f7486279-8be6-4505-8f3c-b26c2cd92eee}]
C:\WINDOWS\system32\dmsfwfmj.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AutoCAD Digital Signatures Icon Overlay Handler]
@={36A21736-36C2-4C11-8ACB-D4136F2B57BD}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 1 (GFS Unread Stub)]
@={99FD978C-D287-4F50-827F-B2C658EDA8E7}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2 (GFS Stub)]
@={AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)]
@={920E6DB1-9907-4370-B3A0-BAFC03D81399}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 3 (GFS Folder)]
@={16F3DD56-1AF5-4347-846D-7C10C4192619}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 4 (GFS Unread Mark)]
@={2916C86E-86A6-43FE-8112-43ABE6BF8DCC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Offline Files]
[HKEY_CLASSES_ROOT\CLSID\{36A21736-36C2-4C11-8ACB-D4136F2B57BD}]
2006-03-04 23:55 185448 –a—— C:\WINDOWS\system32\AcSignIcon.dll
[HKEY_CLASSES_ROOT\CLSID\{99FD978C-D287-4F50-827F-B2C658EDA8E7}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{920E6DB1-9907-4370-B3A0-BAFC03D81399}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{16F3DD56-1AF5-4347-846D-7C10C4192619}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 16:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSUpdater"="System32i.exe" [2007-06-13 05:26 C:\WINDOWS\system32\System32i.exe]
"exflashservice"="C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" [2006-05-02 03:26]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 11:12]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 02:22 C:\WINDOWS\soundman.exe]
"ManualRun"="D:\AUTORUN\AutoRun" []
"BtcMouseMaestro"="C:\Program Files\MMaestro\KMaestro.exe" [2005-11-09 03:18]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 19:30]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"GoogleUpdate"="C:\Program Files\Internet Explorer\Down(0).EXE" [2007-11-22 08:55]
"Wise-FTP Scheduler"="" []
"Service32"="C:\WINDOWS\system32\schost.exe" []
"AGEIA PhysX SysTray"="C:\Program Files\AGEIA Technologies\TrayIcon.exe" [2006-03-20 13:43]
"SpIDerNT"="C:\PROGRA~1\DrWeb\spiderui.exe" [2007-10-01 16:17]
"DrWebScheduler"="C:\Program Files\DrWeb\DRWEBSCD.EXE" [2007-09-19 16:04]
"SpIDerMail"="C:\Program Files\DrWeb\spiderml.exe" [2007-11-26 18:21]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"MSUpdater"="System32i.exe" [2007-06-13 05:26 C:\WINDOWS\system32\System32i.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech Profiler.lnk - C:\Program Files\Logitech\Profiler\LWEmon.exe [2007-08-26 17:34:21]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxvvut]
byxvvut.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2006-01-12 20:52 483328 –a—— C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 02:06 40048 –a—— C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
2007-09-06 05:06 79224 –a—— C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe –force_start_minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CrawlerNotes]
c:\progra~1\crawler\notes\cnotes.exe /notes
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
C:\Program Files\Electronic Arts\EA Link\Core.exe -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-27 02:47 31016 –a—— C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-15 13:11 267048 –a—— C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinnacle Game Profiler]
C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
2007-11-02 17:24 1065800 –a—— C:\Program Files\Spyware Doctor\SDTrayApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wise-FTP Scheduler]
2003-08-29 16:35 1246720 –a—— C:\Program Files\AceBIT\WISE-FTP\WF_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
R1 UdfReadr;UdfReadr;C:\WINDOWS\system32\drivers\UdfReadr.sys
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
R2 SPIDER;SpIDer Guard File System Monitor;\??\C:\PROGRA~1\DrWeb\spider.sys
R2 SPIDERNT;SpIDer Guard for Windows;C:\PROGRA~1\DrWeb\spidernt.exe
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
R3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S2 NetworkConnections;NetmanConnections;C:\WINDOWS\system32\wonlog.ini
S3 Hpzodisft_;Hpzodisft_;C:\WINDOWS\system32\bootok.exe
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys
S3 wampapache;wampapache;"C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice
S3 wampmysqld;wampmysqld;"C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
aeyfoc REG_MULTI_SZ aeyfoc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe1dd150-ed26-11db-8902-001a703119a4}]
\Shell\AutoRun\command - G:\setupSNK.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1D072F95-FA9D-5367-BDD9-91013F603BE4}]
C:\Program Files\WinfiX\server.exe s
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CAC7B150-B41B-B8F0-F160-F2F006DD303D}]
C:\WINDOWS\msmg.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-10 09:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\DOCUME~1\KAMPFZ~1\LOCALS~1\Temp\ppeulkwv.dll
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-10 16:37:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
GoogleUpdate = C:\Program Files\Internet Explorer\Down(0).EXE??l???????????????????G?o?o?g?l?e?U?p?d?a?t?e?????r???????????????????????e???????????????????????r
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-10 16:39:40 - machine was rebooted
.
— E O F —
Please go to http://virusscan.jotti.org , click on Browse, and upload the following file for analysis:
C:\WINDOWS\system32\System32i.exe
Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If Jotti is too busy you can try these.
http://www.kaspersky.com/scanforvirus.html
http://www.virustotal.com/en/indexf.html
File::
C:\WINDOWS\system32\dmsfwfmj.#ll
C:\WINDOWS\system32\byxvvut.#ll
C:\WINDOWS\system32\System32i.exe
C:\WINDOWS\system32\schost.exe
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f7486279-8be6-4505-8f3c-b26c2cd92eee}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSUpdater"=-
"ManualRun"=-
"Service32"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"MSUpdater"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxvvut]
Save this as Save this as "CFScript"
[external image: Posted Image]
Refering to the picture above, drag CFScript.txt into ComboFix.exe
Then post the results log and a new HijackThis log.
Also please describe how your computer behaves at the moment.
A-Squared Found nothing
AntiVir Found BDS/Ciadoor.GN.614
ArcaVir Found Trojan.Ciadoor.Gn
Avast Found nothing
AVG Antivirus Found BackDoor.Generic9.DYV
BitDefender Found DeepScan:Generic.Malware.G!SKI!!FLMPWBVPkprng.A4673D80
ClamAV Found PUA.Packed.Themida
CPsecure Found BackDoor.W32.Ciadoor.gn
Dr.Web Found nothing
F-Prot Antivirus Found Possibly a new variant of W32/NewMalware-Mr-T-Inspector!Maximus
F-Secure Anti-Virus Found Backdoor.Win32.Ciadoor.gn
Fortinet Found W32/Ciadoor.GN!tr.bdr
Ikarus Found MemScanBackdoor.VB.EV
Kaspersky Anti-Virus Found Backdoor.Win32.Ciadoor.gn
NOD32 Found nothing
Norman Virus Control Found Banker.gen4
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing
OK, here is ComboFix Report:
ComboFix 07-12-09.1 - Kampfzentrum 2007-12-10 17:46:42.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1440 [GMT -6:00]
Running from: F:\ComboFix.exe
Command switches used :: F:\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\byxvvut.#ll
C:\WINDOWS\system32\dmsfwfmj.#ll
C:\WINDOWS\system32\schost.exe
C:\WINDOWS\system32\System32i.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\byxvvut.#ll
C:\WINDOWS\system32\dmsfwfmj.#ll
C:\WINDOWS\system32\System32i.exe
.
((((((((((((((((((((((((( Files Created from 2007-11-10 to 2007-12-10 )))))))))))))))))))))))))))))))
.
2007-12-10 05:16 . 2007-12-10 05:16 d——– C:\Program Files\PM Studios
2007-12-09 21:30 . 2007-12-09 21:44 d——– C:\Documents and Settings\Kampfzentrum\DoctorWeb
2007-12-09 21:30 . 2007-12-09 21:31 77,824 –a—-t- C:\WINDOWS\system32\DRWEBSP.DLL
2007-12-09 21:29 . 2007-12-10 16:30 d——– C:\Program Files\DrWeb
2007-12-09 21:28 . 2007-12-09 21:28 d——– C:\Documents and Settings\Kampfzentrum\Application Data\InstallShield
2007-12-09 20:38 . 2007-12-09 20:38 d——– C:\Program Files\ATF Cleaner
2007-12-09 19:32 . 2007-12-09 19:32 426 –a—— C:\WINDOWS\system32\temp.dat
2007-12-09 19:18 . 2007-12-09 19:18 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 18:30 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Program Files\Spybot
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-09 17:34 . 2007-12-09 19:18 d——– C:\Documents and Settings\Kampfzentrum\Application Data\AdwareAlert
2007-12-09 16:05 . 2000-02-22 21:38 206,272 –a—— C:\WINDOWS\system32\drivers\udfreadr.BAK
2007-12-09 15:57 . 2002-02-22 18:02 206,208 –a—— C:\WINDOWS\system32\drivers\udfreadr.sys
2007-12-09 15:57 . 2002-02-22 18:10 90,112 –a—— C:\WINDOWS\system32\udfrunin.exe
2007-12-09 07:13 . 2007-09-06 05:09 801,144 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-12-09 07:13 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-12-09 07:13 . 2007-09-06 05:00 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-12-09 07:13 . 2007-09-06 05:05 94,416 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-09 07:13 . 2007-09-06 05:05 92,848 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-09 07:13 . 2007-09-06 05:02 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-09 07:13 . 2007-09-06 05:00 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-09 07:13 . 2007-09-06 05:03 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-09 07:12 . 2007-12-09 07:12 d——– C:\Program Files\Alwil Software
2007-12-08 22:52 . 2007-12-09 18:42 108,336 –a—— C:\WINDOWS\mswinsck.ocx
2007-12-08 22:34 . 2007-12-08 22:34 d–h—– C:\Program Files\WinfiX
2007-12-08 19:34 . 2007-12-08 19:34 98,304 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\WINDOWS\system32\ageia
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\Program Files\AGEIA Technologies
2007-12-08 16:47 . 2007-04-04 18:53 81,768 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-12-08 14:48 . 2007-12-08 14:48 d——– C:\Documents and Settings\Kampfzentrum\Application Data\KALiNKOsoft
2007-12-08 14:48 . 2007-12-08 14:48 36,864 –a—— C:\WINDOWS\system32\dxinputdll.dll
2007-12-04 18:26 . 2007-12-04 18:27 d——– C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
2007-12-04 18:25 . 2007-12-04 18:25 d——– C:\Documents and Settings\Kampfzentrum\Application Data\GlobalSCAPE
2007-12-03 21:27 . 2007-12-03 21:27 d——– C:\Program Files\LSoft Technologies
2007-12-01 13:58 . 2007-12-01 13:59 d——– C:\Program Files\FPXpress
2007-12-01 13:21 . 2004-11-22 20:56 913,560 –a—— C:\WINDOWS\system32\wodFtpDLX.ocx
2007-12-01 13:21 . 2007-12-05 10:44 13 –a—— C:\WINDOWS\system32\WinSys32.crc
2007-12-01 13:20 . 2007-12-09 08:09 d——– C:\Program Files\CoffeeCup Software
2007-12-01 13:20 . 1999-03-22 12:29 233,472 –a—— C:\WINDOWS\system32\Ilda32.dll
2007-12-01 13:20 . 1998-06-17 04:00 18,944 –a—— C:\WINDOWS\system32\BORLNDMM.DLL
2007-12-01 12:44 . 2007-12-01 12:44 149,916 –a—— C:\tmp.exe
2007-12-01 07:42 . 2007-12-01 07:42 d——– C:\Program Files\AceBIT
2007-12-01 07:42 . 2003-08-29 16:36 1,079,808 –a—— C:\WINDOWS\system32\we.dll
2007-12-01 07:42 . 2003-07-22 03:40 430,080 –a—— C:\WINDOWS\system32\wodSFTP.ocx
2007-12-01 07:42 . 2003-07-22 03:38 425,984 –a—— C:\WINDOWS\system32\wodKeys.dll
2007-12-01 07:42 . 2003-07-22 03:37 385,024 –a—— C:\WINDOWS\system32\wodSFTP.dll
2007-12-01 06:22 . 2007-12-09 20:10 d——– C:\Program Files\Spyware Doctor
2007-12-01 06:22 . 2007-12-01 06:22 d——– C:\Documents and Settings\Kampfzentrum\Application Data\PC Tools
2007-12-01 06:22 . 2007-10-18 00:16 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-01 06:22 . 2007-10-18 00:15 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-01 06:22 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-01 06:22 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-01 06:20 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-29 17:15 . 2007-11-29 17:15 d——– C:\Program Files\PremiumSoft
2007-11-28 20:18 . 2007-11-28 20:22 d——– C:\Program Files\wamp
2007-11-28 15:59 . 2007-12-09 10:24 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-11-28 15:59 . 2007-11-28 15:59 1,409 –a—— C:\WINDOWS\QTFont.for
2007-11-28 15:58 . 2007-11-28 15:59 d——– C:\Program Files\iTunes
2007-11-28 15:58 . 2007-11-28 15:58 d——– C:\Program Files\iPod
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Program Files\phpDesigner 2008
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Documents and Settings\Kampfzentrum\Application Data\phpDesigner 2008
2007-11-27 21:29 . 2007-11-27 21:29 d——– C:\Program Files\7-Zip
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Windows Script Control
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Common Files\e.World
2007-11-27 21:09 . 2007-11-27 21:09 0 –a—— C:\WINDOWS\system32\UNWISE.INI
2007-11-27 21:08 . 2007-11-27 21:09 d——– C:\Program Files\PHPMaker 5
2007-11-27 21:08 . 2002-07-26 17:02 153,088 –a—— C:\WINDOWS\system32\UNWISE.EXE
2007-11-24 16:08 . 2007-11-24 16:09 d——– C:\Program Files\CrystalButton2
2007-11-22 22:32 . 2007-12-08 19:21 d——– C:\Program Files\Ubisoft
2007-11-18 13:05 . 2007-11-18 13:05 150,643 –ah—– C:\_crash.dmp
2007-11-18 13:05 . 2007-11-18 13:05 58,902 –ah—– C:\report.zip
2007-11-14 23:43 . 2007-11-14 23:43 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-11-14 23:43 . 2007-11-14 23:43 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-10 03:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 01:16 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Azureus
2007-12-09 14:39 ——— d—–w C:\Program Files\Babylon
2007-12-09 04:19 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Vso
2007-12-08 21:17 ——— d—–w C:\Program Files\Azureus
2007-11-28 21:57 ——— d—–w C:\Program Files\QuickTime
2007-11-26 02:17 ——— d—–w C:\Program Files\Soulseek
2007-11-24 03:35 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-24 03:33 107,832 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-11-23 04:32 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-17 22:21 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\BitTorrent
2007-11-13 23:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-04 15:03 ——— d—–w C:\Program Files\AIM
2007-11-04 15:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Aim
2007-11-04 13:03 ——— d—–w C:\Program Files\Common Files\Apple
2007-11-04 13:03 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-10-29 00:03 172,032 —-a-w C:\WINDOWS\system32\Down(0).exe
2007-10-28 21:28 ——— d—–w C:\Program Files\WorkTime
2007-10-27 21:23 22,746,840 —-a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_10_27_16_22_24_full.dmp.zip
2007-10-26 03:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Babylon
2007-10-26 02:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Babylon
2007-10-25 02:46 ——— d—–w C:\Program Files\Text to Speech Maker
2007-10-25 02:35 ——— d—–w C:\Program Files\NCT
2007-10-25 02:11 ——— d—–w C:\Program Files\GameSpy Arcade
2007-10-25 01:23 ——— d—–w C:\Program Files\VirtualDJ
2007-10-25 01:21 ——— d—–w C:\Program Files\RegHealer
2007-10-20 12:15 ——— d—–w C:\Program Files\Magic Video Converter
2007-10-14 13:25 ——— d—–w C:\Program Files\Xilisoft
2007-10-14 13:05 ——— d—–w C:\Program Files\FileSee
2007-10-14 01:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\SongbirdVLC
2007-10-14 01:18 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Songbird
2007-10-13 21:15 ——— d—–w C:\Program Files\Soulseek-Test
2007-02-05 13:56 87,608 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\ezpinst.exe
2007-02-05 13:56 47,360 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f7486279-8be6-4505-8f3c-b26c2cd92eee}]
C:\WINDOWS\system32\dmsfwfmj.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AutoCAD Digital Signatures Icon Overlay Handler]
@={36A21736-36C2-4C11-8ACB-D4136F2B57BD}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 1 (GFS Unread Stub)]
@={99FD978C-D287-4F50-827F-B2C658EDA8E7}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2 (GFS Stub)]
@={AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)]
@={920E6DB1-9907-4370-B3A0-BAFC03D81399}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 3 (GFS Folder)]
@={16F3DD56-1AF5-4347-846D-7C10C4192619}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 4 (GFS Unread Mark)]
@={2916C86E-86A6-43FE-8112-43ABE6BF8DCC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Offline Files]
[HKEY_CLASSES_ROOT\CLSID\{36A21736-36C2-4C11-8ACB-D4136F2B57BD}]
2006-03-04 23:55 185448 –a—— C:\WINDOWS\system32\AcSignIcon.dll
[HKEY_CLASSES_ROOT\CLSID\{99FD978C-D287-4F50-827F-B2C658EDA8E7}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{920E6DB1-9907-4370-B3A0-BAFC03D81399}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{16F3DD56-1AF5-4347-846D-7C10C4192619}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 16:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSUpdater"="System32i.exe" []
"exflashservice"="C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" [2006-05-02 03:26]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 11:12]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 02:22 C:\WINDOWS\soundman.exe]
"ManualRun"="D:\AUTORUN\AutoRun" []
"BtcMouseMaestro"="C:\Program Files\MMaestro\KMaestro.exe" [2005-11-09 03:18]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 19:30]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"GoogleUpdate"="C:\Program Files\Internet Explorer\Down(0).EXE" [2007-11-22 08:55]
"Wise-FTP Scheduler"="" []
"Service32"="C:\WINDOWS\system32\schost.exe" []
"AGEIA PhysX SysTray"="C:\Program Files\AGEIA Technologies\TrayIcon.exe" [2006-03-20 13:43]
"SpIDerNT"="C:\PROGRA~1\DrWeb\spiderui.exe" [2007-10-01 16:17]
"DrWebScheduler"="C:\Program Files\DrWeb\DRWEBSCD.EXE" [2007-09-19 16:04]
"SpIDerMail"="C:\Program Files\DrWeb\spiderml.exe" [2007-11-26 18:21]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"MSUpdater"="System32i.exe" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech Profiler.lnk - C:\Program Files\Logitech\Profiler\LWEmon.exe [2007-08-26 17:34:21]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxvvut]
byxvvut.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2006-01-12 20:52 483328 –a—— C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 02:06 40048 –a—— C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
2007-09-06 05:06 79224 –a—— C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe –force_start_minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CrawlerNotes]
c:\progra~1\crawler\notes\cnotes.exe /notes
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
C:\Program Files\Electronic Arts\EA Link\Core.exe -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-27 02:47 31016 –a—— C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-15 13:11 267048 –a—— C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinnacle Game Profiler]
C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
2007-11-02 17:24 1065800 –a—— C:\Program Files\Spyware Doctor\SDTrayApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wise-FTP Scheduler]
2003-08-29 16:35 1246720 –a—— C:\Program Files\AceBIT\WISE-FTP\WF_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
R1 UdfReadr;UdfReadr;C:\WINDOWS\system32\drivers\UdfReadr.sys
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
R2 SPIDER;SpIDer Guard File System Monitor;\??\C:\PROGRA~1\DrWeb\spider.sys
R2 SPIDERNT;SpIDer Guard for Windows;C:\PROGRA~1\DrWeb\spidernt.exe
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
R3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S2 NetworkConnections;NetmanConnections;C:\WINDOWS\system32\wonlog.ini
S3 Hpzodisft_;Hpzodisft_;C:\WINDOWS\system32\bootok.exe
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys
S3 wampapache;wampapache;"C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice
S3 wampmysqld;wampmysqld;"C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
aeyfoc REG_MULTI_SZ aeyfoc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e7bbac42-b3cf-11db-8b54-806d6172696f}]
\Shell\AutoRun\command - D:\Autorun\UbiAutorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe1dd150-ed26-11db-8902-001a703119a4}]
\Shell\AutoRun\command - G:\setupSNK.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1D072F95-FA9D-5367-BDD9-91013F603BE4}]
C:\Program Files\WinfiX\server.exe s
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CAC7B150-B41B-B8F0-F160-F2F006DD303D}]
C:\WINDOWS\msmg.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-10 09:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-10 17:49:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
GoogleUpdate = C:\Program Files\Internet Explorer\Down(0).EXE??l???????????????????G?o?o?g?l?e?U?p?d?a?t?e?????r???????????????????????e???????????????????????r
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-10 17:50:09
C:\ComboFix2.txt … 2007-12-10 16:39
.
— E O F —
And - in final - here is the HiJackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 5:51:40 PM, on 12/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Internet Explorer\IExPlOrE.ExE
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\DrWeb\spidernt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\MMaestro\KMaestro.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Internet Explorer\Down(0).EXE
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\PROGRA~1\DrWeb\spiderui.exe
C:\Program Files\DrWeb\spiderml.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Profiler\LWEmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wi-compact.com/Forum/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [exflashservice] "C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" "5000"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BtcMouseMaestro] "C:\Program Files\MMaestro\KMaestro.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [GoogleUpdate] C:\Program Files\Internet Explorer\Down(0).EXE
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [SpIDerNT] C:\PROGRA~1\DrWeb\spiderui.exe /agent
O4 - HKLM\..\Run: [DrWebScheduler] "C:\Program Files\DrWeb\DRWEBSCD.EXE"
O4 - HKLM\..\Run: [SpIDerMail] "C:\Program Files\DrWeb\spiderml.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech Profiler.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NetmanConnections (NetworkConnections) - Unknown owner - C:\WINDOWS\system32\wonlog.ini
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SpIDer Guard for Windows (SPIDERNT) - Doctor Web, Ltd. - C:\PROGRA~1\DrWeb\spidernt.exe
O23 - Service: wampapache - Unknown owner - C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld (file missing)
Thanks.
File::
C:\WINDOWS\system32\WinSys32.crc
C:\WINDOWS\system32\Down(0).exe
C:\WINDOWS\system32\dmsfwfmj.dll
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f7486279-8be6-4505-8f3c-b26c2cd92eee}]
Save this as Save this as "CFScript"
[external image: Posted Image]
Refering to the picture above, drag CFScript.txt into ComboFix.exe
Then post the results log and a new HijackThis log.
Also please describe how your computer behaves at the moment.
ComboFix 07-12-09.1 - Kampfzentrum 2007-12-10 18:34:06.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1484 [GMT -6:00]
Running from: F:\ComboFix.exe
Command switches used :: F:\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\dmsfwfmj.dll
C:\WINDOWS\system32\Down(0).exe
C:\WINDOWS\system32\WinSys32.crc
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\Down(0).exe
C:\WINDOWS\system32\WinSys32.crc
.
((((((((((((((((((((((((( Files Created from 2007-11-11 to 2007-12-11 )))))))))))))))))))))))))))))))
.
2007-12-10 05:16 . 2007-12-10 05:16 d——– C:\Program Files\PM Studios
2007-12-09 21:30 . 2007-12-09 21:44 d——– C:\Documents and Settings\Kampfzentrum\DoctorWeb
2007-12-09 21:30 . 2007-12-09 21:31 77,824 –a—-t- C:\WINDOWS\system32\DRWEBSP.DLL
2007-12-09 21:29 . 2007-12-10 16:30 d——– C:\Program Files\DrWeb
2007-12-09 21:28 . 2007-12-09 21:28 d——– C:\Documents and Settings\Kampfzentrum\Application Data\InstallShield
2007-12-09 20:38 . 2007-12-09 20:38 d——– C:\Program Files\ATF Cleaner
2007-12-09 19:32 . 2007-12-09 19:32 426 –a—— C:\WINDOWS\system32\temp.dat
2007-12-09 19:18 . 2007-12-09 19:18 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 18:30 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Program Files\Spybot
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-09 17:34 . 2007-12-09 19:18 d——– C:\Documents and Settings\Kampfzentrum\Application Data\AdwareAlert
2007-12-09 16:05 . 2000-02-22 21:38 206,272 –a—— C:\WINDOWS\system32\drivers\udfreadr.BAK
2007-12-09 15:57 . 2002-02-22 18:02 206,208 –a—— C:\WINDOWS\system32\drivers\udfreadr.sys
2007-12-09 15:57 . 2002-02-22 18:10 90,112 –a—— C:\WINDOWS\system32\udfrunin.exe
2007-12-09 07:13 . 2007-09-06 05:09 801,144 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-12-09 07:13 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-12-09 07:13 . 2007-09-06 05:00 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-12-09 07:13 . 2007-09-06 05:05 94,416 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-09 07:13 . 2007-09-06 05:05 92,848 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-09 07:13 . 2007-09-06 05:02 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-09 07:13 . 2007-09-06 05:00 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-09 07:13 . 2007-09-06 05:03 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-09 07:12 . 2007-12-09 07:12 d——– C:\Program Files\Alwil Software
2007-12-08 22:52 . 2007-12-09 18:42 108,336 –a—— C:\WINDOWS\mswinsck.ocx
2007-12-08 22:34 . 2007-12-08 22:34 d–h—– C:\Program Files\WinfiX
2007-12-08 19:34 . 2007-12-08 19:34 98,304 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\WINDOWS\system32\ageia
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\Program Files\AGEIA Technologies
2007-12-08 16:47 . 2007-04-04 18:53 81,768 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-12-08 14:48 . 2007-12-08 14:48 d——– C:\Documents and Settings\Kampfzentrum\Application Data\KALiNKOsoft
2007-12-08 14:48 . 2007-12-08 14:48 36,864 –a—— C:\WINDOWS\system32\dxinputdll.dll
2007-12-04 18:26 . 2007-12-04 18:27 d——– C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
2007-12-04 18:25 . 2007-12-04 18:25 d——– C:\Documents and Settings\Kampfzentrum\Application Data\GlobalSCAPE
2007-12-03 21:27 . 2007-12-03 21:27 d——– C:\Program Files\LSoft Technologies
2007-12-01 13:58 . 2007-12-01 13:59 d——– C:\Program Files\FPXpress
2007-12-01 13:21 . 2004-11-22 20:56 913,560 –a—— C:\WINDOWS\system32\wodFtpDLX.ocx
2007-12-01 13:20 . 2007-12-09 08:09 d——– C:\Program Files\CoffeeCup Software
2007-12-01 13:20 . 1999-03-22 12:29 233,472 –a—— C:\WINDOWS\system32\Ilda32.dll
2007-12-01 13:20 . 1998-06-17 04:00 18,944 –a—— C:\WINDOWS\system32\BORLNDMM.DLL
2007-12-01 12:44 . 2007-12-01 12:44 149,916 –a—— C:\tmp.exe
2007-12-01 07:42 . 2007-12-01 07:42 d——– C:\Program Files\AceBIT
2007-12-01 07:42 . 2003-08-29 16:36 1,079,808 –a—— C:\WINDOWS\system32\we.dll
2007-12-01 07:42 . 2003-07-22 03:40 430,080 –a—— C:\WINDOWS\system32\wodSFTP.ocx
2007-12-01 07:42 . 2003-07-22 03:38 425,984 –a—— C:\WINDOWS\system32\wodKeys.dll
2007-12-01 07:42 . 2003-07-22 03:37 385,024 –a—— C:\WINDOWS\system32\wodSFTP.dll
2007-12-01 06:22 . 2007-12-09 20:10 d——– C:\Program Files\Spyware Doctor
2007-12-01 06:22 . 2007-12-01 06:22 d——– C:\Documents and Settings\Kampfzentrum\Application Data\PC Tools
2007-12-01 06:22 . 2007-10-18 00:16 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-01 06:22 . 2007-10-18 00:15 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-01 06:22 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-01 06:22 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-01 06:20 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-29 17:15 . 2007-11-29 17:15 d——– C:\Program Files\PremiumSoft
2007-11-28 20:18 . 2007-11-28 20:22 d——– C:\Program Files\wamp
2007-11-28 15:59 . 2007-12-09 10:24 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-11-28 15:59 . 2007-11-28 15:59 1,409 –a—— C:\WINDOWS\QTFont.for
2007-11-28 15:58 . 2007-11-28 15:59 d——– C:\Program Files\iTunes
2007-11-28 15:58 . 2007-11-28 15:58 d——– C:\Program Files\iPod
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Program Files\phpDesigner 2008
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Documents and Settings\Kampfzentrum\Application Data\phpDesigner 2008
2007-11-27 21:29 . 2007-11-27 21:29 d——– C:\Program Files\7-Zip
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Windows Script Control
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Common Files\e.World
2007-11-27 21:09 . 2007-11-27 21:09 0 –a—— C:\WINDOWS\system32\UNWISE.INI
2007-11-27 21:08 . 2007-11-27 21:09 d——– C:\Program Files\PHPMaker 5
2007-11-27 21:08 . 2002-07-26 17:02 153,088 –a—— C:\WINDOWS\system32\UNWISE.EXE
2007-11-24 16:08 . 2007-11-24 16:09 d——– C:\Program Files\CrystalButton2
2007-11-22 22:32 . 2007-12-08 19:21 d——– C:\Program Files\Ubisoft
2007-11-18 13:05 . 2007-11-18 13:05 150,643 –ah—– C:\_crash.dmp
2007-11-18 13:05 . 2007-11-18 13:05 58,902 –ah—– C:\report.zip
2007-11-14 23:43 . 2007-11-14 23:43 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-11-14 23:43 . 2007-11-14 23:43 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-10 03:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 01:16 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Azureus
2007-12-09 14:39 ——— d—–w C:\Program Files\Babylon
2007-12-09 04:19 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Vso
2007-12-08 21:17 ——— d—–w C:\Program Files\Azureus
2007-11-28 21:57 ——— d—–w C:\Program Files\QuickTime
2007-11-26 02:17 ——— d—–w C:\Program Files\Soulseek
2007-11-24 03:35 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-24 03:33 107,832 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-11-23 04:32 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-17 22:21 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\BitTorrent
2007-11-13 23:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-04 15:03 ——— d—–w C:\Program Files\AIM
2007-11-04 15:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Aim
2007-11-04 13:03 ——— d—–w C:\Program Files\Common Files\Apple
2007-11-04 13:03 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-10-28 21:28 ——— d—–w C:\Program Files\WorkTime
2007-10-27 21:23 22,746,840 —-a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_10_27_16_22_24_full.dmp.zip
2007-10-26 03:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Babylon
2007-10-26 02:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Babylon
2007-10-25 02:46 ——— d—–w C:\Program Files\Text to Speech Maker
2007-10-25 02:35 ——— d—–w C:\Program Files\NCT
2007-10-25 02:11 ——— d—–w C:\Program Files\GameSpy Arcade
2007-10-25 01:23 ——— d—–w C:\Program Files\VirtualDJ
2007-10-25 01:21 ——— d—–w C:\Program Files\RegHealer
2007-10-20 12:15 ——— d—–w C:\Program Files\Magic Video Converter
2007-10-14 13:25 ——— d—–w C:\Program Files\Xilisoft
2007-10-14 13:05 ——— d—–w C:\Program Files\FileSee
2007-10-14 01:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\SongbirdVLC
2007-10-14 01:18 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Songbird
2007-10-13 21:15 ——— d—–w C:\Program Files\Soulseek-Test
2007-02-05 13:56 87,608 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\ezpinst.exe
2007-02-05 13:56 47,360 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AutoCAD Digital Signatures Icon Overlay Handler]
@={36A21736-36C2-4C11-8ACB-D4136F2B57BD}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 1 (GFS Unread Stub)]
@={99FD978C-D287-4F50-827F-B2C658EDA8E7}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2 (GFS Stub)]
@={AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)]
@={920E6DB1-9907-4370-B3A0-BAFC03D81399}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 3 (GFS Folder)]
@={16F3DD56-1AF5-4347-846D-7C10C4192619}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 4 (GFS Unread Mark)]
@={2916C86E-86A6-43FE-8112-43ABE6BF8DCC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Offline Files]
[HKEY_CLASSES_ROOT\CLSID\{36A21736-36C2-4C11-8ACB-D4136F2B57BD}]
2006-03-04 23:55 185448 –a—— C:\WINDOWS\system32\AcSignIcon.dll
[HKEY_CLASSES_ROOT\CLSID\{99FD978C-D287-4F50-827F-B2C658EDA8E7}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{920E6DB1-9907-4370-B3A0-BAFC03D81399}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{16F3DD56-1AF5-4347-846D-7C10C4192619}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 16:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"exflashservice"="C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" [2006-05-02 03:26]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 11:12]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 02:22 C:\WINDOWS\soundman.exe]
"BtcMouseMaestro"="C:\Program Files\MMaestro\KMaestro.exe" [2005-11-09 03:18]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 19:30]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"GoogleUpdate"="C:\Program Files\Internet Explorer\Down(0).EXE" [2007-11-22 08:55]
"Wise-FTP Scheduler"="" []
"AGEIA PhysX SysTray"="C:\Program Files\AGEIA Technologies\TrayIcon.exe" [2006-03-20 13:43]
"SpIDerNT"="C:\PROGRA~1\DrWeb\spiderui.exe" [2007-10-01 16:17]
"DrWebScheduler"="C:\Program Files\DrWeb\DRWEBSCD.EXE" [2007-09-19 16:04]
"SpIDerMail"="C:\Program Files\DrWeb\spiderml.exe" [2007-11-26 18:21]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech Profiler.lnk - C:\Program Files\Logitech\Profiler\LWEmon.exe [2007-08-26 17:34:21]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2006-01-12 20:52 483328 –a—— C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 02:06 40048 –a—— C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
2007-09-06 05:06 79224 –a—— C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe –force_start_minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CrawlerNotes]
c:\progra~1\crawler\notes\cnotes.exe /notes
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
C:\Program Files\Electronic Arts\EA Link\Core.exe -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-27 02:47 31016 –a—— C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-15 13:11 267048 –a—— C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinnacle Game Profiler]
C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
2007-11-02 17:24 1065800 –a—— C:\Program Files\Spyware Doctor\SDTrayApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wise-FTP Scheduler]
2003-08-29 16:35 1246720 –a—— C:\Program Files\AceBIT\WISE-FTP\WF_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
R1 UdfReadr;UdfReadr;C:\WINDOWS\system32\drivers\UdfReadr.sys
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
R2 SPIDER;SpIDer Guard File System Monitor;\??\C:\PROGRA~1\DrWeb\spider.sys
R2 SPIDERNT;SpIDer Guard for Windows;C:\PROGRA~1\DrWeb\spidernt.exe
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
R3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S2 NetworkConnections;NetmanConnections;C:\WINDOWS\system32\wonlog.ini
S3 Hpzodisft_;Hpzodisft_;C:\WINDOWS\system32\bootok.exe
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys
S3 wampapache;wampapache;"C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice
S3 wampmysqld;wampmysqld;"C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
aeyfoc REG_MULTI_SZ aeyfoc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe1dd150-ed26-11db-8902-001a703119a4}]
\Shell\AutoRun\command - G:\setupSNK.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1D072F95-FA9D-5367-BDD9-91013F603BE4}]
C:\Program Files\WinfiX\server.exe s
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CAC7B150-B41B-B8F0-F160-F2F006DD303D}]
C:\WINDOWS\msmg.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-10 09:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-10 18:35:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
GoogleUpdate = C:\Program Files\Internet Explorer\Down(0).EXE??l???????????????????G?o?o?g?l?e?U?p?d?a?t?e?????r???????????????????????e???????????????????????r
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-10 18:36:59
C:\ComboFix2.txt … 2007-12-10 17:50
C:\ComboFix3.txt … 2007-12-10 16:39
.
— E O F —
And HiJackThis:
Logfile of HijackThis v1.99.1
Scan saved at 6:38:05 PM, on 12/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Internet Explorer\IExPlOrE.ExE
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\DrWeb\spidernt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\MMaestro\KMaestro.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Internet Explorer\Down(0).EXE
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\PROGRA~1\DrWeb\spiderui.exe
C:\Program Files\DrWeb\spiderml.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Profiler\LWEmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wi-compact.com/Forum/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [exflashservice] "C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" "5000"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BtcMouseMaestro] "C:\Program Files\MMaestro\KMaestro.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [GoogleUpdate] C:\Program Files\Internet Explorer\Down(0).EXE
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [SpIDerNT] C:\PROGRA~1\DrWeb\spiderui.exe /agent
O4 - HKLM\..\Run: [DrWebScheduler] "C:\Program Files\DrWeb\DRWEBSCD.EXE"
O4 - HKLM\..\Run: [SpIDerMail] "C:\Program Files\DrWeb\spiderml.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech Profiler.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NetmanConnections (NetworkConnections) - Unknown owner - C:\WINDOWS\system32\wonlog.ini
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SpIDer Guard for Windows (SPIDERNT) - Doctor Web, Ltd. - C:\PROGRA~1\DrWeb\spidernt.exe
O23 - Service: wampapache - Unknown owner - C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld (file missing)
My computer seems to be running pretty nice. I cannot say that anything is wrong with it. Should I run a virus scan? Is Virtumonde still in here?
- Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
- WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
- Please do not re-connect your machine back to the Internet until Combofix has completely finished.
Open notepad and copy/paste the text in the quotebox below into it:
File::
C:\WINDOWS\system32\Down(0).exe
C:\WINDOWS\system32\WinSys32.crc
Save this as Save this as "CFScript"
[external image: Posted Image]
Refering to the picture above, drag CFScript.txt into ComboFix.exe
Then post the results log and a new HijackThis log.
Also please describe how your computer behaves at the moment.
"The instruction at "0x7c9111e0" referenced memory at "0x0020006b". The memory could not be "read".
Also, everytime I run ComboFix I get a IE shortcut placed on my menu.
Here we go again:
ComboFix 07-12-09.1 - Kampfzentrum 2007-12-10 20:16:15.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1532 [GMT -6:00]
Running from: F:\ComboFix.exe
Command switches used :: F:\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\Down(0).exe
C:\WINDOWS\system32\WinSys32.crc
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\sfsync02.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_SFSYNC02
——-\sfsync02
((((((((((((((((((((((((( Files Created from 2007-11-11 to 2007-12-11 )))))))))))))))))))))))))))))))
.
2007-12-10 05:16 . 2007-12-10 05:16 d——– C:\Program Files\PM Studios
2007-12-09 21:30 . 2007-12-09 21:44 d——– C:\Documents and Settings\Kampfzentrum\DoctorWeb
2007-12-09 21:30 . 2007-12-09 21:31 77,824 –a—-t- C:\WINDOWS\system32\DRWEBSP.DLL
2007-12-09 21:29 . 2007-12-10 18:43 d——– C:\Program Files\DrWeb
2007-12-09 21:28 . 2007-12-09 21:28 d——– C:\Documents and Settings\Kampfzentrum\Application Data\InstallShield
2007-12-09 20:38 . 2007-12-09 20:38 d——– C:\Program Files\ATF Cleaner
2007-12-09 19:32 . 2007-12-09 19:32 426 –a—— C:\WINDOWS\system32\temp.dat
2007-12-09 19:18 . 2007-12-09 19:18 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 18:30 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Program Files\Spybot
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-09 17:34 . 2007-12-09 19:18 d——– C:\Documents and Settings\Kampfzentrum\Application Data\AdwareAlert
2007-12-09 16:05 . 2000-02-22 21:38 206,272 –a—— C:\WINDOWS\system32\drivers\udfreadr.BAK
2007-12-09 15:57 . 2002-02-22 18:02 206,208 –a—— C:\WINDOWS\system32\drivers\udfreadr.sys
2007-12-09 15:57 . 2002-02-22 18:10 90,112 –a—— C:\WINDOWS\system32\udfrunin.exe
2007-12-09 07:13 . 2007-09-06 05:09 801,144 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-12-09 07:13 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-12-09 07:13 . 2007-09-06 05:00 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-12-09 07:13 . 2007-09-06 05:05 94,416 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-09 07:13 . 2007-09-06 05:05 92,848 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-09 07:13 . 2007-09-06 05:02 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-09 07:13 . 2007-09-06 05:00 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-09 07:13 . 2007-09-06 05:03 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-09 07:12 . 2007-12-09 07:12 d——– C:\Program Files\Alwil Software
2007-12-08 22:52 . 2007-12-09 18:42 108,336 –a—— C:\WINDOWS\mswinsck.ocx
2007-12-08 22:34 . 2007-12-08 22:34 d–h—– C:\Program Files\WinfiX
2007-12-08 19:34 . 2007-12-08 19:34 98,304 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\WINDOWS\system32\ageia
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\Program Files\AGEIA Technologies
2007-12-08 16:47 . 2007-04-04 18:53 81,768 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-12-08 14:48 . 2007-12-08 14:48 d——– C:\Documents and Settings\Kampfzentrum\Application Data\KALiNKOsoft
2007-12-08 14:48 . 2007-12-08 14:48 36,864 –a—— C:\WINDOWS\system32\dxinputdll.dll
2007-12-04 18:26 . 2007-12-04 18:27 d——– C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
2007-12-04 18:25 . 2007-12-04 18:25 d——– C:\Documents and Settings\Kampfzentrum\Application Data\GlobalSCAPE
2007-12-03 21:27 . 2007-12-03 21:27 d——– C:\Program Files\LSoft Technologies
2007-12-01 13:58 . 2007-12-01 13:59 d——– C:\Program Files\FPXpress
2007-12-01 13:21 . 2004-11-22 20:56 913,560 –a—— C:\WINDOWS\system32\wodFtpDLX.ocx
2007-12-01 13:20 . 2007-12-09 08:09 d——– C:\Program Files\CoffeeCup Software
2007-12-01 13:20 . 1999-03-22 12:29 233,472 –a—— C:\WINDOWS\system32\Ilda32.dll
2007-12-01 13:20 . 1998-06-17 04:00 18,944 –a—— C:\WINDOWS\system32\BORLNDMM.DLL
2007-12-01 12:44 . 2007-12-01 12:44 149,916 –a—— C:\tmp.exe
2007-12-01 07:42 . 2007-12-01 07:42 d——– C:\Program Files\AceBIT
2007-12-01 07:42 . 2003-08-29 16:36 1,079,808 –a—— C:\WINDOWS\system32\we.dll
2007-12-01 07:42 . 2003-07-22 03:40 430,080 –a—— C:\WINDOWS\system32\wodSFTP.ocx
2007-12-01 07:42 . 2003-07-22 03:38 425,984 –a—— C:\WINDOWS\system32\wodKeys.dll
2007-12-01 07:42 . 2003-07-22 03:37 385,024 –a—— C:\WINDOWS\system32\wodSFTP.dll
2007-12-01 06:22 . 2007-12-09 20:10 d——– C:\Program Files\Spyware Doctor
2007-12-01 06:22 . 2007-12-01 06:22 d——– C:\Documents and Settings\Kampfzentrum\Application Data\PC Tools
2007-12-01 06:22 . 2007-10-18 00:16 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-01 06:22 . 2007-10-18 00:15 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-01 06:22 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-01 06:22 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-01 06:20 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-29 17:15 . 2007-11-29 17:15 d——– C:\Program Files\PremiumSoft
2007-11-28 20:18 . 2007-11-28 20:22 d——– C:\Program Files\wamp
2007-11-28 15:59 . 2007-12-09 10:24 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-11-28 15:59 . 2007-11-28 15:59 1,409 –a—— C:\WINDOWS\QTFont.for
2007-11-28 15:58 . 2007-11-28 15:59 d——– C:\Program Files\iTunes
2007-11-28 15:58 . 2007-11-28 15:58 d——– C:\Program Files\iPod
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Program Files\phpDesigner 2008
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Documents and Settings\Kampfzentrum\Application Data\phpDesigner 2008
2007-11-27 21:29 . 2007-11-27 21:29 d——– C:\Program Files\7-Zip
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Windows Script Control
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Common Files\e.World
2007-11-27 21:09 . 2007-11-27 21:09 0 –a—— C:\WINDOWS\system32\UNWISE.INI
2007-11-27 21:08 . 2007-11-27 21:09 d——– C:\Program Files\PHPMaker 5
2007-11-27 21:08 . 2002-07-26 17:02 153,088 –a—— C:\WINDOWS\system32\UNWISE.EXE
2007-11-24 16:08 . 2007-11-24 16:09 d——– C:\Program Files\CrystalButton2
2007-11-22 22:32 . 2007-12-08 19:21 d——– C:\Program Files\Ubisoft
2007-11-18 13:05 . 2007-11-18 13:05 150,643 –ah—– C:\_crash.dmp
2007-11-18 13:05 . 2007-11-18 13:05 58,902 –ah—– C:\report.zip
2007-11-14 23:43 . 2007-11-14 23:43 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-11-14 23:43 . 2007-11-14 23:43 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-11 00:42 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Azureus
2007-12-10 03:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-09 14:39 ——— d—–w C:\Program Files\Babylon
2007-12-09 04:19 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Vso
2007-12-08 21:17 ——— d—–w C:\Program Files\Azureus
2007-11-28 21:57 ——— d—–w C:\Program Files\QuickTime
2007-11-26 02:17 ——— d—–w C:\Program Files\Soulseek
2007-11-24 03:35 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-23 04:32 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-17 22:21 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\BitTorrent
2007-11-13 23:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-04 15:03 ——— d—–w C:\Program Files\AIM
2007-11-04 15:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Aim
2007-11-04 13:03 ——— d—–w C:\Program Files\Common Files\Apple
2007-11-04 13:03 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-10-28 21:28 ——— d—–w C:\Program Files\WorkTime
2007-10-26 03:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Babylon
2007-10-26 02:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Babylon
2007-10-25 02:46 ——— d—–w C:\Program Files\Text to Speech Maker
2007-10-25 02:35 ——— d—–w C:\Program Files\NCT
2007-10-25 02:11 ——— d—–w C:\Program Files\GameSpy Arcade
2007-10-25 01:23 ——— d—–w C:\Program Files\VirtualDJ
2007-10-25 01:21 ——— d—–w C:\Program Files\RegHealer
2007-10-20 12:15 ——— d—–w C:\Program Files\Magic Video Converter
2007-10-14 13:25 ——— d—–w C:\Program Files\Xilisoft
2007-10-14 13:05 ——— d—–w C:\Program Files\FileSee
2007-10-14 01:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\SongbirdVLC
2007-10-14 01:18 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Songbird
2007-10-13 21:15 ——— d—–w C:\Program Files\Soulseek-Test
2007-02-05 13:56 87,608 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\ezpinst.exe
2007-02-05 13:56 47,360 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((( snapshot@2007-12-10_16.38.35.60 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-11 02:19:59 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_5e0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AutoCAD Digital Signatures Icon Overlay Handler]
@={36A21736-36C2-4C11-8ACB-D4136F2B57BD}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 1 (GFS Unread Stub)]
@={99FD978C-D287-4F50-827F-B2C658EDA8E7}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2 (GFS Stub)]
@={AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)]
@={920E6DB1-9907-4370-B3A0-BAFC03D81399}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 3 (GFS Folder)]
@={16F3DD56-1AF5-4347-846D-7C10C4192619}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 4 (GFS Unread Mark)]
@={2916C86E-86A6-43FE-8112-43ABE6BF8DCC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Offline Files]
[HKEY_CLASSES_ROOT\CLSID\{36A21736-36C2-4C11-8ACB-D4136F2B57BD}]
2006-03-04 23:55 185448 –a—— C:\WINDOWS\system32\AcSignIcon.dll
[HKEY_CLASSES_ROOT\CLSID\{99FD978C-D287-4F50-827F-B2C658EDA8E7}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{920E6DB1-9907-4370-B3A0-BAFC03D81399}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{16F3DD56-1AF5-4347-846D-7C10C4192619}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CLASSES_ROOT\CLSID\{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 16:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"exflashservice"="C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" [2006-05-02 03:26]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 11:12]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 02:22 C:\WINDOWS\soundman.exe]
"BtcMouseMaestro"="C:\Program Files\MMaestro\KMaestro.exe" [2005-11-09 03:18]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 19:30]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"GoogleUpdate"="C:\Program Files\Internet Explorer\Down(0).EXE" [2007-11-22 08:55]
"Wise-FTP Scheduler"="" []
"AGEIA PhysX SysTray"="C:\Program Files\AGEIA Technologies\TrayIcon.exe" [2006-03-20 13:43]
"SpIDerNT"="C:\PROGRA~1\DrWeb\spiderui.exe" [2007-10-01 16:17]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech Profiler.lnk - C:\Program Files\Logitech\Profiler\LWEmon.exe [2007-08-26 17:34:21]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2006-01-12 20:52 483328 –a—— C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 02:06 40048 –a—— C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
2007-09-06 05:06 79224 –a—— C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe –force_start_minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CrawlerNotes]
c:\progra~1\crawler\notes\cnotes.exe /notes
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
C:\Program Files\Electronic Arts\EA Link\Core.exe -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-27 02:47 31016 –a—— C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-15 13:11 267048 –a—— C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinnacle Game Profiler]
C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
2007-11-02 17:24 1065800 –a—— C:\Program Files\Spyware Doctor\SDTrayApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wise-FTP Scheduler]
2003-08-29 16:35 1246720 –a—— C:\Program Files\AceBIT\WISE-FTP\WF_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
R1 UdfReadr;UdfReadr;C:\WINDOWS\system32\drivers\UdfReadr.sys
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
R2 SPIDER;SpIDer Guard File System Monitor;\??\C:\PROGRA~1\DrWeb\spider.sys
R2 SPIDERNT;SpIDer Guard for Windows;C:\PROGRA~1\DrWeb\spidernt.exe
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
R3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S2 NetworkConnections;NetmanConnections;C:\WINDOWS\system32\wonlog.ini
S3 Hpzodisft_;Hpzodisft_;C:\WINDOWS\system32\bootok.exe
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys
S3 wampapache;wampapache;"C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice
S3 wampmysqld;wampmysqld;"C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
aeyfoc REG_MULTI_SZ aeyfoc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe1dd150-ed26-11db-8902-001a703119a4}]
\Shell\AutoRun\command - G:\setupSNK.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1D072F95-FA9D-5367-BDD9-91013F603BE4}]
C:\Program Files\WinfiX\server.exe s
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CAC7B150-B41B-B8F0-F160-F2F006DD303D}]
C:\WINDOWS\msmg.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-10 09:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\DOCUME~1\KAMPFZ~1\LOCALS~1\Temp\ppeulkwv.dll
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-10 20:20:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
GoogleUpdate = C:\Program Files\Internet Explorer\Down(0).EXE??l???????????????????G?o?o?g?l?e?U?p?d?a?t?e?????r???????????????????????e???????????????????????r
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-10 20:22:18 - machine was rebooted
C:\ComboFix2.txt … 2007-12-10 18:37
C:\ComboFix3.txt … 2007-12-10 17:50
.
— E O F —
Scan saved at 6:55:12 PM, on 12/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IExPlOrE.ExE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\MMaestro\KMaestro.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Internet Explorer\Down(0).EXE
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Profiler\LWEmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat.exe
C:\DOCUME~1\KAMPFZ~1\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\DOCUME~1\KAMPFZ~1\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wi-compact.com/Forum/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [exflashservice] "C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" "5000"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BtcMouseMaestro] "C:\Program Files\MMaestro\KMaestro.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [GoogleUpdate] C:\Program Files\Internet Explorer\Down(0).EXE
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech Profiler.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NetmanConnections (NetworkConnections) - Unknown owner - C:\WINDOWS\system32\wonlog.ini
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: wampapache - Unknown owner - C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld (file missing)
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI