Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:16, on 2008-02-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Parental Control\ParentalControl.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\MSI\Common\RaUI.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = wlan.pcci.edu
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {8396A2B4-C0F4-4BDF-B6DF-DFC6030CC2BD} - C:\WINDOWS\system32\bitsprx.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mm_server] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ParentalControl] C:\Program Files\Parental Control\ParentalControl.Exe /SERVICE
O4 - HKLM\..\Run: [RegistrySmart] C:\Program Files\RegistrySmart\RegistrySmart.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: TimeLeft.lnk = C:\Program Files\TimeLeft3\TimeLeft.exe
O4 - Global Startup: MSI Wireless Utility.lnk = C:\Program Files\MSI\Common\RaUI.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1162325755270
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1162325746407
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Sophos AutoUpdate Service - Sony Corporation - (no file)
–
End of file - 6026 bytes
ComboFix 08-02-22 - Lumpy 2008-02-21 20:53:39.2 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Lumpy\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\jautoexp.dat
C:\WINDOWS\pss\PowerReg Scheduler.exeStartup
C:\WINDOWS\system32\bitsprx.dll
C:\WINDOWS\system32\epfrqijs.dll
C:\WINDOWS\system32\Process.exe
C:\WINDOWS\system32\WS2Fix.exe
C:\WINDOWS\Tasks\AF11FA32918A6C12.job
E:\autorun.exe
G:\DirectX
G:\setup.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\safe cash bash extra
C:\Documents and Settings\All Users\Application Data\safe cash bash extra\build amen nurb
C:\WINDOWS\jautoexp.dat
C:\WINDOWS\pss\PowerReg Scheduler.exeStartup
C:\WINDOWS\system32\epfrqijs.dll
C:\WINDOWS\system32\Process.exe
C:\WINDOWS\system32\WS2Fix.exe
C:\WINDOWS\Tasks\AF11FA32918A6C12.job
C:\WINDOWS\system32\bitsprx.dll . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_ESFJTGGI
——-\esfjtggi
((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 )))))))))))))))))))))))))))))))
.
2008-02-19 23:38 . 2008-02-19 23:38 d——– C:\Program Files\Trend Micro
2008-02-19 22:56 . 2008-02-19 22:56 d——– C:\Program Files\RegistrySmart
2008-02-19 22:56 . 2008-02-19 23:03 d——– C:\Documents and Settings\Lumpy\Application Data\RegistrySmart
2008-02-18 21:09 . 2008-02-18 21:09 3,226 –a—— C:\WINDOWS\system32\tmp.reg
2008-02-18 21:04 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-02-18 21:04 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-02-18 21:04 . 2008-02-16 19:46 85,504 –a—— C:\WINDOWS\system32\VACFix.exe
2008-02-18 21:04 . 2008-02-08 10:37 82,432 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-02-18 21:04 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-02-18 09:42 . 2008-02-18 09:45 d——– C:\Program Files\Parental Control
2008-02-18 09:42 . 2008-02-18 09:42 d——– C:\Documents and Settings\Lumpy\Application Data\ParentalControl
2008-02-18 09:42 . 2008-02-21 21:03 d——– C:\Documents and Settings\All Users\Application Data\ParentalControl
2008-02-02 12:21 . 2008-02-02 12:21 d——– C:\Program Files\KONAMI
2008-01-23 22:49 . 2008-01-23 22:49 d——– C:\Documents and Settings\All Users\Application Data\Motive
2008-01-23 22:49 . 2005-07-12 00:28 69,632 –a—— C:\WINDOWS\system32\MCCDevice.dll
2008-01-23 22:49 . 2005-07-12 00:28 6,048 –a—— C:\WINDOWS\system32\MCC16.dll
2008-01-23 22:48 . 2008-01-29 09:48 d——– C:\Program Files\Common Files\Motive
2008-01-23 22:48 . 2008-01-23 22:49 29,540,732 –a—— C:\BellSouthIW.re~
2008-01-23 22:48 . 2002-02-13 19:53 6,345 -ra—— C:\WINDOWS\system32\DevMngr.vxd
2008-01-22 17:12 . 2003-02-28 18:26 139,536 –a—— C:\WINDOWS\system32\javaee.dll
2008-01-22 17:12 . 2003-02-28 18:26 46,352 –a—— C:\WINDOWS\setdebug.exe
2008-01-22 17:12 . 2003-02-28 16:54 7,315 –a—— C:\WINDOWS\system32\javasup.vxd
2008-01-22 17:12 . 2003-02-28 16:38 113 –a—— C:\WINDOWS\system32\zonedon.reg
2008-01-22 17:12 . 2003-02-28 16:38 113 –a—— C:\WINDOWS\system32\zonedoff.reg
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 01:17 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\AVG7
2008-02-21 17:46 ——— d—–w C:\Program Files\e-Sword
2008-02-20 13:42 ——— d—–w C:\Program Files\Incomplete
2008-02-20 13:35 ——— d—–w C:\Program Files\LimeWire
2008-02-08 12:12 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-08 05:21 ——— d—–w C:\Program Files\DivX
2008-01-12 01:14 ——— d—–w C:\Program Files\MSXML 6.0
2008-01-12 00:47 ——— d—–w C:\Program Files\MSXML 4.0
2008-01-07 21:39 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools
2008-01-07 21:37 ——— d—–w C:\Program Files\DAEMON Tools Lite
2008-01-06 04:39 715,248 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-12-26 06:22 ——— d—–w C:\Program Files\Java
2007-12-26 06:04 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\Grisoft
2007-12-26 05:40 ——— d—–w C:\Program Files\Serif
2007-12-26 05:32 ——— d—–w C:\Program Files\EA GAMES
2007-12-26 05:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2007-12-26 05:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-26 05:22 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-26 05:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-26 05:19 ——— d—–w C:\Program Files\Microsoft Games
2007-12-25 05:20 ——— d—–w C:\Program Files\Silent Hill
2007-12-25 05:18 720,896 —-a-w C:\WINDOWS\iun6002ev.exe
2007-12-24 21:50 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\DAEMON Tools Pro
2007-12-24 19:29 ——— d—–w C:\Documents and Settings\Lumpy\Application Data\IGN_DLM
2007-10-10 18:15 34,768 —-a-w C:\Documents and Settings\Lumpy\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8396A2B4-C0F4-4BDF-B6DF-DFC6030CC2BD}]
2004-08-04 00:56 84992 –a—— C:\WINDOWS\system32\bitsprx.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-03 07:54 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-08-12 21:10 335872]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 16:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-12 19:51 185896]
"mm_server"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe" [2005-03-09 19:10 102400]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-24 03:24 282624]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-08 11:02 579072]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25 6731312]
"ParentalControl"="C:\Program Files\Parental Control\ParentalControl.exe" [2007-06-26 01:30 6088192]
"RegistrySmart"="C:\Program Files\RegistrySmart\RegistrySmart.exe" [2008-02-13 09:08 4351216]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-25 23:22 219136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 00:56 53760 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\Lumpy\Start Menu\Programs\Startup\
TimeLeft.lnk - C:\Program Files\TimeLeft3\TimeLeft.exe [2007-01-11 03:56:51 1046016]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
MSI Wireless Utility.lnk - C:\Program Files\MSI\Common\RaUI.exe [2007-07-10 12:32:15 425984]
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-02-05 14:29:20 54512]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableClock"= 0 (0x0)
"NoDispCPL"= 0 (0x0)
"DisableRegistryTools"= 0 (0x0)
"DisableTaskMgr"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoMultiIE"= 0 (0x0)
"LWA"= 0 (0x0)
"LWB"= 0 (0x0)
"LWC"= 0 (0x0)
"LWD"= 0 (0x0)
"LWE"= 0 (0x0)
"LWF"= 0 (0x0)
"LWG"= 0 (0x0)
"LWH"= 0 (0x0)
"LWI"= 0 (0x0)
"LWJ"= 0 (0x0)
"LWK"= 0 (0x0)
"LWL"= 0 (0x0)
"LWM"= 0 (0x0)
"LWN"= 0 (0x0)
"LWO"= 0 (0x0)
"LWP"= 0 (0x0)
"LWQ"= 0 (0x0)
"LWR"= 0 (0x0)
"LWS"= 0 (0x0)
"LWT"= 0 (0x0)
"LWU"= 0 (0x0)
"LWV"= 0 (0x0)
"LWW"= 0 (0x0)
"LWX"= 0 (0x0)
"LWY"= 0 (0x0)
"LWZ"= 0 (0x0)
"NoRun"= 0 (0x0)
"NoFind"= 0 (0x0)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoUpdate Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk
backup=C:\WINDOWS\pss\AutoUpdate Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
backup=C:\WINDOWS\pss\Billminder.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
backup=C:\WINDOWS\pss\Quicken Startup.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Wireless-B Notebook Adapter Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless-B Notebook Adapter Utility.lnk
backup=C:\WINDOWS\pss\Wireless-B Notebook Adapter Utility.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2007-03-12 12:49 153136 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitDownload]
C:\Program Files\BitDownload\BitDownload.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
–a—— 2005-02-08 04:00 98304 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2006-09-25 14:54 229952 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
–a—— 2005-03-09 19:10 11776 C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2007-03-09 17:53 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-09-24 03:24 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RavAV]
C:\WINDOWS\AdobeR.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-03-14 02:43 83608 C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2007-05-12 19:51 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"WebClient"=2 (0x2)
"TapiSrv"=3 (0x3)
"SharedAccess"=2 (0x2)
"SCardSvr"=3 (0x3)
"SamSs"=2 (0x2)
"RemoteAccess"=2 (0x2)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)
"mnmsrvc"=3 (0x3)
"Irmon"=2 (0x2)
"iPod Service"=3 (0x3)
"ImapiService"=3 (0x3)
"ERSvc"=2 (0x2)
R0 esfjtggi;esfjtggi;C:\WINDOWS\system32\drivers\thfhjgha.dat []
R1 cp_drv;Crawler Parental Control Driver;C:\Documents and Settings\All Users\Application Data\ParentalControl\cp_drv.sys [2008-02-18 09:43]
R1 cp_tdifw_drv;cp_tdifw_drv;C:\Documents and Settings\All Users\Application Data\ParentalControl\cp_tdifw_drv.sys [2008-02-18 09:43]
R3 axsaki;axsaki;C:\WINDOWS\system32\DRIVERS\axsaki.sys [2003-03-30 21:38]
R3 axskbus;axskbus;C:\WINDOWS\system32\DRIVERS\axskbus.sys [2003-03-28 11:58]
S3 atimtai;atimtai;C:\WINDOWS\system32\DRIVERS\atimtai.sys [2001-08-17 12:48]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2750b1c1-69f7-11db-acb2-806d6172696f}]
\Shell\AutoRun\command - D:\BellSouth.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{529bcb50-b591-11db-9520-000f663bf8c6}]
\Shell\AutoRun\command - E:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{80514710-a727-11dc-9749-0019db91814c}]
\Shell\AutoRun\command - Desktop.ini
\Shell\explore\Command - Desktop.ini
\Shell\open\Command - Desktop.ini
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a09be9c0-689e-11db-9428-000f663bf8c6}]
\Shell\AutoRun\command - F:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a09be9c1-689e-11db-9428-000f663bf8c6}]
\Shell\AutoRun\command - Copy of Desktop.ini
\Shell\explore\Command - Copy of Desktop.ini
\Shell\open\Command - Copy of Desktop.ini
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a78c7c83-a82a-11dc-974c-0019db91814c}]
\Shell\AutoRun\command - Copy of Desktop.ini
\Shell\explore\Command - Copy of Desktop.ini
\Shell\open\Command - Copy of Desktop.ini
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b802da00-f2a5-11db-95ec-0008749c80da}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
*Newly Created Service* - ESFJTGGI
.
Contents of the 'Scheduled Tasks' folder
"2008-02-18 22:26:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-10-17 22:32:12 C:\WINDOWS\Tasks\Low Battery Alarm Program.job"
"2008-02-22 03:03:34 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
- C:\Program Files\RegistrySmart\RegistrySmart.ex
- C:\Program Files\RegistrySmart
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-21 21:02:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
.
**************************************************************************
.
Completion time: 2008-02-21 21:05:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-22 03:05:52
ComboFix2.txt 2008-02-22 01:22:00
ComboFix3.txt 2008-02-20 15:02:54
.
2008-02-13 13:21:10 — E O F —
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
2008-02-21 23:04
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 22/02/2008
Kaspersky Anti-Virus database records: 575350
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
Scan Statistics:
Total number of scanned objects: 66723
Number of viruses found: 14
Number of infected objects: 35
Number of suspicious objects: 0
Duration of the scan process: 01:37:23
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Lumpy\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\cert8.db Object is locked skipped
C:\Documents and Settings\Lumpy\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Lumpy\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\history.dat Object is locked skipped
C:\Documents and Settings\Lumpy\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\key3.db Object is locked skipped
C:\Documents and Settings\Lumpy\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\parent.lock Object is locked skipped
C:\Documents and Settings\Lumpy\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Lumpy\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Lumpy\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Application Data\Mozilla\Firefox\Profiles\3hko5y20.default\XUL.mfl Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\History\History.IE5\MSHist012008022120080222\index.dat Object is locked skipped
C:\Documents and Settings\Lumpy\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lumpy\My Documents\filelib\Gangsters2Setup-dm(2).exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Documents and Settings\Lumpy\My Documents\filelib\Gangsters2Setup-dm.exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Documents and Settings\Lumpy\My Documents\filelib\GettysburgSetup-dm.exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Documents and Settings\Lumpy\My Documents\filelib\ResidentEvil3-dm.exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Documents and Settings\Lumpy\My Documents\Greek\Parsing Sheets\Rom. 6.12-18.xls Object is locked skipped
C:\Documents and Settings\Lumpy\My Documents\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Lumpy\My Documents\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Lumpy\My Documents\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Lumpy\My Documents\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Lumpy\ntuser.dat Object is locked skipped
C:\Documents and Settings\Lumpy\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\e-Sword\2000+ Bible Illustrations.top Object is locked skipped
C:\Program Files\e-Sword\markup.ovl Object is locked skipped
C:\Program Files\e-Sword\study.not Object is locked skipped
C:\Program Files\LimeWire\DAEMONTools-Pro-Cracked-V-4.10.218[clean]\DTPro4100218Basic.exe/data0000.cab/wr-1-922.exe Infected: Trojan-Downloader.Win32.Small.gll skipped
C:\Program Files\LimeWire\DAEMONTools-Pro-Cracked-V-4.10.218[clean]\DTPro4100218Basic.exe/data0000.cab/DTPRO4~1.EXE/data0000.cab/is151099.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\LimeWire\DAEMONTools-Pro-Cracked-V-4.10.218[clean]\DTPro4100218Basic.exe/data0000.cab/DTPRO4~1.EXE/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\LimeWire\DAEMONTools-Pro-Cracked-V-4.10.218[clean]\DTPro4100218Basic.exe/data0000.cab/DTPRO4~1.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\LimeWire\DAEMONTools-Pro-Cracked-V-4.10.218[clean]\DTPro4100218Basic.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\LimeWire\DAEMONTools-Pro-Cracked-V-4.10.218[clean]\DTPro4100218Basic.exe Rsrc-Package: infected - 5 skipped
C:\Program Files\Mozilla Firefox\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\QooBox\Quarantine\C\Program Files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL.vir Infected: not-a-virus:AdWare.Win32.MyWay.c skipped
C:\QooBox\Quarantine\catchme2008-02-21_210217.96.zip/bitsprx.dll Infected: Trojan.Win32.Pakes.cdw skipped
C:\QooBox\Quarantine\catchme2008-02-21_210217.96.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP104\A0016593.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP105\A0016640.dll Infected: not-a-virus:AdTool.Win32.WhenU.r skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP105\A0016641.exe Infected: not-a-virus:AdTool.Win32.WhenU.s skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP106\A0016788.dll Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP118\A0020423.dll Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP118\A0020424.dll Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP118\A0020425.dll Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP121\A0020574.DLL Infected: not-a-virus:AdWare.Win32.MyWay.c skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP122\change.log Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP70\A0009364.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP75\A0010902.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP76\A0010914.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP77\A0010927.exe Infected: not-a-virus:AdWare.Win32.Agent.zk skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP82\A0012142.dll Infected: not-a-virus:AdWare.Win32.TrafficSol.q skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP86\A0012338.EXE Infected: not-a-virus:AdWare.Win32.MyWay.b skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP86\A0012339.DLL Infected: not-a-virus:AdWare.Win32.MyWay.f skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP88\A0012669.DLL Infected: not-a-virus:AdWare.Win32.MyWay.c skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012695.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012696.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012697.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012698.exe/data0000.cab/wr-1-922.exe Infected: Trojan-Downloader.Win32.Small.gll skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012698.exe/data0000.cab/crack.exe/data0000.cab/is151099.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012698.exe/data0000.cab/crack.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012698.exe/data0000.cab/crack.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012698.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012698.exe Rsrc-Package: infected - 5 skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012699.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012700.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012701.dll Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012702.dll Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012703.dll Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012704.exe Object is locked skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012705.exe Infected: Trojan.Win32.Obfuscated.en skipped
C:\System Volume Information\_restore{427102C8-30E8-471B-B3F1-139C0D7583E0}\RP89\A0012706.dll Infected: not-a-virus:AdWare.Win32.AdvertMen.a skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\bitsprx.dll Infected: Trojan.Win32.Pakes.cdw skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.