it complicated, hehe
this is the new report:
Scanner results
Scan taken on 22 Apr 2008 03:39:35 (GMT) A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing
ComboFix 08-04-20.5 - Administrator 2008-04-22 13:56:55.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.264 [GMT -7:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\Documents and Settings\Administrator\5262.bat
C:\Documents and Settings\Administrator\winlogo.exe
C:\sqmdata00.sqm
C:\sqmdata01.sqm
C:\sqmdata02.sqm
C:\sqmdata03.sqm
C:\sqmdata04.sqm
C:\sqmnoopt00.sqm
C:\sqmnoopt01.sqm
C:\sqmnoopt02.sqm
C:\sqmnoopt03.sqm
C:\sqmnoopt04.sqm
C:\WINDOWS\system32\8840.bat
C:\WINDOWS\system32\cyohljcf.ini
C:\WINDOWS\system32\fxpnfwgs.ini
C:\WINDOWS\system32\jixxiqyg.ini
C:\WINDOWS\system32\rwwnw64d.exe
E:\RavMon.exe
.
/wow section - STAGE 41
pv: No matching processes found
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\5262.bat
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\DW_Start.lnk
C:\Documents and Settings\Administrator\winlogo.exe
C:\sdfix
C:\sdfix\SDFix\apps\assosfix.reg
C:\sdfix\SDFix\apps\cliptext.exe
C:\sdfix\SDFix\apps\download.exe
C:\sdfix\SDFix\apps\dummy.sys
C:\sdfix\SDFix\apps\Enable_Command_Prompt.reg
C:\sdfix\SDFix\apps\ERDNT.E_E
C:\sdfix\SDFix\apps\ERDNTDOS.LOC
C:\sdfix\SDFix\apps\ERDNTWIN.LOC
C:\sdfix\SDFix\apps\ERUNT.EXE
C:\sdfix\SDFix\apps\ERUNT.LOC
C:\sdfix\SDFix\apps\fix.reg
C:\sdfix\SDFix\apps\FixBH.reg
C:\sdfix\SDFix\apps\FixComponents.reg
C:\sdfix\SDFix\apps\FIXCU.reg
C:\sdfix\SDFix\apps\FIXLM.reg
C:\sdfix\SDFix\apps\FixPath.exe
C:\sdfix\SDFix\apps\FixRedir.reg
C:\sdfix\SDFix\apps\FixSchedule.reg
C:\sdfix\SDFix\apps\FixWebCheck.reg
C:\sdfix\SDFix\apps\fixXP.reg
C:\sdfix\SDFix\apps\FixXPsp2.reg
C:\sdfix\SDFix\apps\grep.exe
C:\sdfix\SDFix\apps\HPFix.reg
C:\sdfix\SDFix\apps\HPFix2.reg
C:\sdfix\SDFix\apps\HPFix3.reg
C:\sdfix\SDFix\apps\HPFix4.reg
C:\sdfix\SDFix\apps\HPFix5.reg
C:\sdfix\SDFix\apps\HPFix6.reg
C:\sdfix\SDFix\apps\HPFix7.reg
C:\sdfix\SDFix\apps\isadmin.exe
C:\sdfix\SDFix\apps\leg2.txt
C:\sdfix\SDFix\apps\legacy.txt
C:\sdfix\SDFix\apps\legacybk.txt
C:\sdfix\SDFix\apps\locate.com
C:\sdfix\SDFix\apps\LS.exe
C:\sdfix\SDFix\apps\MD5File.exe
C:\sdfix\SDFix\apps\MyGcpvFix.reg
C:\sdfix\SDFix\apps\MyGkFix2.reg
C:\sdfix\SDFix\apps\Process.exe
C:\sdfix\SDFix\apps\procs.exe
C:\sdfix\SDFix\apps\psservice.exe
C:\sdfix\SDFix\apps\Rem.txt
C:\sdfix\SDFix\apps\Rem2.txt
C:\sdfix\SDFix\apps\Replace\regedit.exe
C:\sdfix\SDFix\apps\Replace\W2K.exe
C:\sdfix\SDFix\apps\Replace\w2k\beep.sys
C:\sdfix\SDFix\apps\Replace\w2k\null.sys
C:\sdfix\SDFix\apps\Replace\XP.exe
C:\sdfix\SDFix\apps\Replace\xp\beep.sys
C:\sdfix\SDFix\apps\Replace\xp\null.sys
C:\sdfix\SDFix\apps\Reset_AppInit_DLLs.reg
C:\sdfix\SDFix\apps\RestartIt!.exe
C:\sdfix\SDFix\apps\Restore_SecurityCenter.reg
C:\sdfix\SDFix\apps\Restore_SharedAccess.reg
C:\sdfix\SDFix\apps\sc.exe
C:\sdfix\SDFix\apps\sed.exe
C:\sdfix\SDFix\apps\SF.exe
C:\sdfix\SDFix\apps\shutdown.exe
C:\sdfix\SDFix\apps\srv2.txt
C:\sdfix\SDFix\apps\srv2bk.txt
C:\sdfix\SDFix\apps\svc.txt
C:\sdfix\SDFix\apps\svcbk.txt
C:\sdfix\SDFix\apps\swreg.exe
C:\sdfix\SDFix\apps\swsc.exe
C:\sdfix\SDFix\apps\unzip.exe
C:\sdfix\SDFix\apps\vfind.exe
C:\sdfix\SDFix\apps\WINMSG.EXE
C:\sdfix\SDFix\apps\winsec.reg
C:\sdfix\SDFix\apps\zip.exe
C:\sdfix\SDFix\backups\backupreg.zip
C:\sdfix\SDFix\backups\backups.zip
C:\sdfix\SDFix\backups\catchme.log
C:\sdfix\SDFix\backups\HOSTS
C:\sdfix\SDFix\catchme.exe
C:\sdfix\SDFix\dummy.sys
C:\sdfix\SDFix\Report.txt
C:\sdfix\SDFix\RunThis.bat
C:\sdfix\SDFix\SDFIX_ReadMe_Online.url
C:\sqmdata00.sqm
C:\sqmdata01.sqm
C:\sqmdata02.sqm
C:\sqmdata03.sqm
C:\sqmdata04.sqm
C:\sqmnoopt00.sqm
C:\sqmnoopt01.sqm
C:\sqmnoopt02.sqm
C:\sqmnoopt03.sqm
C:\sqmnoopt04.sqm
C:\Temp\wdlw14
C:\Temp\wdlw14\maxN1bo.log
C:\WINDOWS\system32\8840.bat
C:\WINDOWS\system32\bharebio07
C:\WINDOWS\system32\cyohljcf.ini
C:\WINDOWS\system32\fxpnfwgs.ini
C:\WINDOWS\system32\HBL
C:\WINDOWS\system32\HBL\HTgn1dll.exe
C:\WINDOWS\system32\jixxiqyg.ini
C:\WINDOWS\system32\MId2
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\Rtmp
C:\WINDOWS\system32\Rtmp\cegmgr76.exe
C:\WINDOWS\system32\rwwnw64d.exe
C:\WINDOWS\system32\spol3
.
((((((((((((((((((((((((( Files Created from 2008-03-22 to 2008-04-22 )))))))))))))))))))))))))))))))
.
2008-04-22 03:58 . 2008-04-22 03:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-04-22 00:22 . 2008-04-22 00:22 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-20 13:34 . 2008-04-20 13:34 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-04-20 13:16 . 2008-04-20 13:16 <DIR> d-------- C:\Program Files\WinPcap
2008-04-19 13:36 . 2008-04-19 13:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-04-19 13:35 . 2008-04-19 13:35 <DIR> d-------- C:\Program Files\NCH Software
2008-04-19 13:22 . 2008-04-19 13:22 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\NCH Swift Sound
2008-04-19 13:22 . 2008-04-19 13:22 26,112 --a------ C:\WINDOWS\system32\drivers\nchssvad.sys
2008-04-19 13:13 . 2008-04-19 13:13 <DIR> d-------- C:\My Intranet
2008-04-18 01:50 . 2008-04-18 01:50 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-04-18 01:50 . 2008-04-21 03:13 1,481 --a------ C:\WINDOWS\mozver.dat
2008-04-08 14:58 . 2008-04-08 14:58 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\ESET
2008-04-08 13:29 . 2008-04-22 13:58 <DIR> d-------- C:\Temp
2008-04-07 18:26 . 2008-03-03 14:25 5,702 --ah----- C:\WINDOWS\nod32restoretemdono.reg
2008-04-07 18:26 . 2008-03-03 18:21 568 --ah----- C:\WINDOWS\nod32fixtemdono.reg
2008-04-07 17:17 . 2008-04-07 21:46 <DIR> d-------- C:\Program Files\real
2008-04-07 08:39 . 2008-04-07 18:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-04-05 21:41 . 2008-04-05 21:41 <DIR> d--hs---- C:\WINDOWS\system32\pas
2008-04-05 19:56 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2008-04-05 19:53 . 2008-04-05 19:53 <DIR> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-04-05 19:44 . 2008-04-05 19:53 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-05 02:41 . 2008-04-08 15:09 <DIR> d-------- C:\Program Files\ESET
2008-04-05 02:41 . 2008-04-08 14:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-04-04 16:16 . 2008-04-04 16:16 6,144 --ahs---- C:\WINDOWS\Thumbs.db
2008-04-04 16:15 . 2008-04-04 16:15 5,120 --ahs---- C:\WINDOWS\system32\Thumbs.db
2008-04-04 16:11 . 2007-11-29 20:00 843,690 --a------ C:\WINDOWS\another dream.scr
2008-04-04 16:11 . 2001-01-12 23:37 294,912 --a------ C:\WINDOWS\Helios.scr
2008-04-04 15:55 . 2008-04-04 15:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-03 02:42 . 2008-04-22 14:26 24 --a------ C:\WINDOWS\LogonStudio.ini
2008-04-03 02:39 . 2000-05-17 10:52 187,392 --a------ C:\WINDOWS\system32\JPGUtils.dll
2008-04-02 23:39 . 2008-04-02 23:39 <DIR> d-------- C:\Documents and Settings\Guest
2008-04-02 23:39 . 2008-04-22 14:25 1,024 --ah----- C:\Documents and Settings\Guest\ntuser.dat.LOG
2008-04-02 22:06 . 2008-04-22 01:22 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-04-02 05:21 . 2008-04-02 05:21 <DIR> d-------- C:\WINDOWS\Sun
2008-04-02 03:51 . 2008-04-02 21:58 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-04-02 03:23 . 2008-04-02 03:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Azureus
2008-04-02 03:22 . 2008-04-20 08:43 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Azureus
2008-04-01 16:03 . 2008-04-01 16:03 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-01 16:03 . 2004-08-03 18:07 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-04-01 13:54 . 2008-04-22 08:36 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-04-01 13:44 . 2008-04-01 13:44 <DIR> d-------- C:\Documents and Settings\Administrator\Incomplete
2008-04-01 13:43 . 2008-04-15 20:27 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-03-31 02:11 . 2008-02-22 03:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-31 02:08 . 2008-03-31 02:11 <DIR> d-------- C:\Program Files\Java
2008-03-31 01:39 . 2008-03-31 01:39 <DIR> d-------- C:\Program Files\Common Files\Java
2008-03-31 01:39 . 2008-04-17 20:34 <DIR> d-------- C:\games
2008-03-30 12:49 . 2008-03-30 12:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\vlc
2008-03-30 01:54 . 2008-03-30 01:54 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Vso
2008-03-30 01:54 . 2008-03-30 01:54 81,920 --a------ C:\Documents and Settings\Administrator\Application Data\ezpinst.exe
2008-03-30 01:54 . 2008-03-30 01:54 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-03-30 01:54 . 2008-03-30 01:54 47,360 --a------ C:\Documents and Settings\Administrator\Application Data\pcouffin.sys
2008-03-30 01:53 . 2004-05-26 22:37 719,872 --a------ C:\WINDOWS\system32\devil.dll
2008-03-30 01:53 . 2006-09-16 20:44 314,368 --a------ C:\WINDOWS\system32\avisynth.dll
2008-03-30 00:11 . 2004-08-04 01:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-03-30 00:11 . 2004-08-04 01:56 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-03-30 00:11 . 2004-08-03 23:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-03-30 00:11 . 2004-08-03 23:58 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-03-30 00:10 . 2004-08-04 00:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-03-30 00:10 . 2004-08-04 00:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-03-29 20:35 . 2008-03-29 20:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\National Instruments
2008-03-29 19:50 . 2008-03-29 19:50 <DIR> d-------- C:\Program Files\HI-TECH Software
2008-03-29 19:11 . 2008-03-29 19:50 <DIR> d-------- C:\Program Files\Common Files\Merge Modules
2008-03-29 19:06 . 2008-03-29 19:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\National Instruments
2008-03-29 19:03 . 2008-03-29 19:03 <DIR> d-------- C:\WINDOWS\system32\cvirte
2008-03-29 19:00 . 2008-03-29 19:44 <DIR> d-------- C:\Program Files\National Instruments
2008-03-29 14:09 . 2008-04-22 02:43 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-03-29 02:10 . 2008-03-29 02:10 120 --a------ C:\WINDOWS\d4s.hst
2008-03-29 01:56 . 2008-03-29 01:57 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Ahead
2008-03-28 16:23 . 2008-03-28 16:23 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-03-28 16:21 . 2008-03-28 16:21 <DIR> d-------- C:\Program Files\Ringz Studio
2008-03-28 16:21 . 2008-03-28 16:21 <DIR> d-------- C:\Program Files\Common Files\Real
2008-03-28 16:21 . 2008-03-28 16:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-28 09:56 . 2008-03-29 23:49 <DIR> d-------- C:\Documents and Settings\Administrator\Contacts
2008-03-28 09:55 . 2008-04-05 19:46 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-03-28 06:05 . 2007-07-30 20:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-03-28 06:05 . 2007-07-30 20:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-03-28 06:05 . 2007-07-30 20:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-03-28 02:10 . 2008-04-05 19:56 <DIR> d-------- C:\Program Files\Windows Live
2008-03-28 02:10 . 2008-04-10 09:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-28 02:09 . 2007-07-30 20:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-03-28 02:09 . 2007-07-30 20:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-03-28 02:09 . 2007-07-30 20:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-03-28 02:09 . 2007-07-30 20:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-03-28 02:09 . 2007-07-30 20:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-03-28 01:59 . 2008-03-28 01:59 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2008-03-28 01:58 . 2008-04-06 09:04 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-03-28 01:49 . 2003-06-18 18:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-03-28 01:49 . 2008-03-28 01:49 376 --a------ C:\WINDOWS\ODBC.INI
2008-03-28 01:48 . 2008-03-28 01:48 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-03-28 01:47 . 2008-03-28 01:47 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-03-28 01:46 . 2008-04-04 16:15 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-03-28 01:40 . 2008-03-28 01:40 <DIR> dr-h----- C:\MSOCache
2008-03-28 01:27 . 2008-03-28 01:27 <DIR> d-------- C:\Program Files\VideoLAN
2008-03-28 01:26 . 2008-03-28 01:26 0 --a------ C:\WINDOWS\nsreg.dat
2008-03-28 01:17 . 2008-03-28 01:17 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2008-03-28 01:03 . 2004-02-09 13:06 15,360 --a------ C:\WINDOWS\system32\drivers\NetMotCM.sys
2008-03-28 01:02 . 2008-03-30 00:15 <DIR> d-------- C:\USB driver
2008-03-27 23:55 . 2008-03-27 23:55 72 --a------ C:\WINDOWS\WB.ini
2008-03-27 23:38 . 2005-01-22 19:05 20,480 --a------ C:\WINDOWS\system32\wbload.dll
2008-03-27 22:55 . 2008-03-27 23:58 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-03-27 22:43 . 2008-03-27 22:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-03-27 22:39 . 2008-03-27 22:39 <DIR> d-------- C:\Program Files\Nero
2008-03-27 22:39 . 2008-03-27 22:43 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-03-27 22:39 . 2008-03-27 22:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-03-27 22:23 . 2008-03-27 22:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-03-27 22:22 . 2008-03-27 22:22 <DIR> d-------- C:\Program Files\Yahoo!
2008-03-27 22:18 . 2008-03-27 22:18 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-03-27 22:16 . 2008-03-27 22:16 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-03-27 22:16 . 2008-03-27 22:17 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-03-27 21:53 . 2006-09-05 10:58 61,536 -ra------ C:\WINDOWS\system32\drivers\se58bus.sys
2008-03-27 21:53 . 2006-09-05 10:58 5,872 -ra------ C:\WINDOWS\system32\drivers\se58whnt.sys
2008-03-27 21:53 . 2006-09-05 10:58 5,872 -ra------ C:\WINDOWS\system32\drivers\se58wh.sys
2008-03-27 21:13 . 2008-03-27 21:13 <DIR> d-------- C:\WINDOWS\speech
2008-03-27 21:13 . 2008-04-19 23:34 <DIR> d-------- C:\Program Files\mtd2002
2008-03-27 20:53 . 2008-04-06 21:35 <DIR> d-------- C:\Program Files\Common Files\Stardock
2008-03-27 20:51 . 2008-04-19 21:55 <DIR> d-------- C:\Program Files\Stardock
2008-03-27 20:51 . 2007-07-11 16:06 42,672 --a------ C:\WINDOWS\system32\wbsys.dll
2008-03-27 20:49 . 2008-04-20 13:13 <DIR> d-------- C:\prog
2008-03-27 20:41 . 2008-03-27 20:41 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-03-27 20:38 . 2008-03-27 20:38 <DIR> d-------- C:\Program Files\Realtek
2008-03-27 20:38 . 2006-10-16 16:10 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-03-27 20:37 . 2008-03-05 19:07 520,192 --a------ C:\WINDOWS\RtlExUpd.dll
2008-03-27 20:37 . 2008-03-27 20:37 315,392 --a------ C:\WINDOWS\HideWin.exe
2008-03-27 20:27 . 2002-11-21 16:07 765,952 --a------ C:\WINDOWS\system\crlds3d.dll
2008-03-27 20:27 . 2003-10-09 19:52 475,788 --a------ C:\WINDOWS\system32\drivers\ALCXWDM.SYS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-04 23:03 5,512,704 ----a-w C:\WINDOWS\system32\logonuiX.exe
2008-03-27 04:56 --------- d-----w C:\Program Files\microsoft frontpage
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-12 02:54 4,687,872 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-03-07 01:14 16,858,112 ----a-w C:\WINDOWS\RTHDCPL.exe
2008-03-01 11:56 71,176 ----a-w C:\WINDOWS\system32\drivers\epfw.sys
2008-03-01 11:56 54,280 ----a-w C:\WINDOWS\system32\drivers\epfwtdi.sys
2008-03-01 11:56 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwndis.sys
2008-03-01 11:53 29,704 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2008-03-01 11:52 39,944 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2005-10-12 23:04 131,072 ----a-w C:\Program Files\internet explorer\plugins\LV80ActiveXControl.dll
2007-02-08 18:48 133,920 ----a-w C:\Program Files\internet explorer\plugins\LV82ActiveXControl.dll
.
------- Sigcheck -------
2004-08-03 18:07 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\svchost.exe
2004-08-03 18:07 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\dllcache\svchost.exe
2004-08-03 18:07 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll
2004-08-03 18:07 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\dllcache\ws2_32.dll
2004-08-03 18:07 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\winlogon.exe
2004-08-03 18:07 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\dllcache\winlogon.exe
2004-08-03 18:07 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\dllcache\ndis.sys
2004-08-03 18:07 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys
2004-08-03 18:07 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\dllcache\ip6fw.sys
2004-08-03 18:07 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys
2007-06-13 03:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\explorer.exe
2007-06-13 04:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-03 18:07 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2007-06-13 03:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\system32\dllcache\explorer.exe
2004-08-03 18:07 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\ctfmon.exe
2004-08-03 18:07 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\dllcache\ctfmon.exe
.
((((((((((((((((((((((((((((( snapshot@2008-04-22_ 1.36.34.60 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-10-23 15:34:19 1,022,976 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\browseui.dll
+ 2006-10-23 15:34:19 151,040 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\cdfview.dll
+ 2006-10-23 15:34:20 1,054,208 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\danim.dll
+ 2006-10-23 15:34:20 357,888 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\dxtmsft.dll
+ 2006-10-23 15:34:20 205,312 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\dxtrans.dll
+ 2006-10-23 15:34:20 55,808 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\extmgr.dll
+ 2006-10-23 11:02:37 18,432 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\iedw.exe
+ 2006-10-23 15:34:20 251,904 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\iepeers.dll
+ 2006-10-23 15:34:20 96,256 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\inseng.dll
+ 2006-10-23 15:34:20 15,872 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\jsproxy.dll
+ 2006-10-23 15:34:22 3,061,248 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\mshtml.dll
+ 2006-10-23 15:34:21 448,512 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\mshtmled.dll
+ 2006-10-23 15:34:21 146,432 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\msrating.dll
+ 2006-10-23 15:34:21 532,480 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\mstime.dll
+ 2006-10-23 15:34:21 39,424 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\pngfilt.dll
+ 2006-10-23 15:34:22 1,497,600 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\shdocvw.dll
+ 2006-10-23 15:34:22 474,112 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\shlwapi.dll
+ 2006-10-23 15:34:22 615,936 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\urlmon.dll
+ 2006-10-23 15:34:22 664,576 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\wininet.dll
+ 2006-10-23 11:01:24 248,320 ----a-w C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\xpsp3res.dll
+ 2005-10-12 23:12:25 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB925454\spmsg.dll
+ 2005-10-12 23:12:26 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB925454\spuninst.exe
+ 2005-10-12 23:12:25 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB925454\update\spcustom.dll
+ 2005-10-12 23:12:29 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB925454\update\update.exe
+ 2005-10-12 23:12:34 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB925454\update\updspapi.dll
- 2008-04-22 08:30:24 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-22 21:25:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2004-08-04 01:07:00 1,016,832 ----a-w C:\WINDOWS\system32\browseui.dll
+ 2006-10-23 15:17:51 1,022,976 ----a-w C:\WINDOWS\system32\browseui.dll
- 2004-08-04 01:07:00 150,528 ----a-w C:\WINDOWS\system32\cdfview.dll
+ 2006-10-23 15:17:51 151,040 ----a-w C:\WINDOWS\system32\cdfview.dll
- 2004-08-04 01:07:00 1,053,696 ----a-w C:\WINDOWS\system32\danim.dll
+ 2006-10-23 15:17:51 1,054,208 ----a-w C:\WINDOWS\system32\danim.dll
- 2004-08-04 01:07:00 1,016,832 -c--a-w C:\WINDOWS\system32\dllcache\browseui.dll
+ 2006-10-23 15:17:51 1,022,976 -c--a-w C:\WINDOWS\system32\dllcache\browseui.dll
- 2004-08-04 01:07:00 150,528 -c--a-w C:\WINDOWS\system32\dllcache\cdfview.dll
+ 2006-10-23 15:17:51 151,040 -c--a-w C:\WINDOWS\system32\dllcache\cdfview.dll
- 2004-08-04 01:07:00 1,053,696 -c--a-w C:\WINDOWS\system32\dllcache\danim.dll
+ 2006-10-23 15:17:51 1,054,208 -c--a-w C:\WINDOWS\system32\dllcache\danim.dll
- 2004-08-04 01:07:00 357,888 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2006-10-23 15:17:52 357,888 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2004-08-04 01:07:00 201,728 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2006-10-23 15:17:52 205,312 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
- 2004-08-04 01:07:00 55,808 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2006-10-23 15:17:52 55,808 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2004-08-04 01:07:00 18,432 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
+ 2006-10-23 11:00:41 18,432 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
- 2004-08-04 01:07:00 249,344 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
+ 2006-10-23 15:17:52 251,392 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
- 2004-08-04 01:07:00 96,256 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
+ 2006-10-23 15:17:52 96,256 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
- 2004-08-04 01:07:00 15,872 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2006-10-23 15:17:52 16,384 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
- 2004-08-04 01:07:00 3,003,392 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2006-10-23 15:17:52 3,055,104 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
- 2004-08-04 01:07:00 448,512 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2006-10-23 15:17:52 448,512 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2004-08-04 01:07:00 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2006-10-23 15:17:52 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
- 2004-08-04 01:07:00 530,432 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2006-10-23 15:17:52 532,480 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
- 2004-08-04 01:07:00 39,424 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2006-10-23 15:17:52 39,424 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
- 2006-09-04 06:08:01 1,494,016 -c--a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
+ 2006-10-23 15:17:53 1,494,528 -c--a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
- 2005-09-02 23:52:06 473,600 -c--a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
+ 2006-10-23 15:17:53 474,112 -c--a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
- 2004-08-04 01:07:00 601,088 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2006-10-23 15:17:53 613,888 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
- 2004-08-04 01:07:00 656,384 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2006-10-23 15:17:53 658,944 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
- 2004-08-04 01:07:00 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2006-10-23 15:17:52 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2004-08-04 01:07:00 201,728 ----a-w C:\WINDOWS\system32\dxtrans.dll
+ 2006-10-23 15:17:52 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
- 2004-08-04 01:07:00 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
+ 2006-10-23 15:17:52 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
- 2004-08-04 01:07:00 249,344 ----a-w C:\WINDOWS\system32\iepeers.dll
+ 2006-10-23 15:17:52 251,392 ----a-w C:\WINDOWS\system32\iepeers.dll
- 2004-08-04 01:07:00 96,256 ----a-w C:\WINDOWS\system32\inseng.dll
+ 2006-10-23 15:17:52 96,256 ----a-w C:\WINDOWS\system32\inseng.dll
- 2004-08-04 01:07:00 15,872 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2006-10-23 15:17:52 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
- 2004-08-04 01:07:00 3,003,392 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2006-10-23 15:17:52 3,055,104 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2004-08-04 01:07:00 448,512 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2006-10-23 15:17:52 448,512 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2004-08-04 01:07:00 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
+ 2006-10-23 15:17:52 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
- 2004-08-04 01:07:00 530,432 ----a-w C:\WINDOWS\system32\mstime.dll
+ 2006-10-23 15:17:52 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
- 2004-08-04 01:07:00 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2006-10-23 15:17:52 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
- 2006-09-04 06:08:01 1,494,016 ----a-w C:\WINDOWS\system32\shdocvw.dll
+ 2006-10-23 15:17:53 1,494,528 ----a-w C:\WINDOWS\system32\shdocvw.dll
- 2005-09-02 23:52:06 473,600 ----a-w C:\WINDOWS\system32\shlwapi.dll
+ 2006-10-23 15:17:53 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
- 2004-08-04 01:07:00 601,088 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2006-10-23 15:17:53 613,888 ----a-w C:\WINDOWS\system32\urlmon.dll
- 2004-08-04 01:07:00 656,384 ----a-w C:\WINDOWS\system32\wininet.dll
+ 2006-10-23 15:17:53 658,944 ----a-w C:\WINDOWS\system32\wininet.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mtd2002Svr"="C:\Program Files\mtd2002\mtdserver.exe" [2002-10-05 14:05 544768]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-01-19 13:49 4670968]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-02-10 11:55 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-02-10 11:51 118784]
"SoundMan"="SOUNDMAN.EXE" [2006-07-21 17:14 86016 C:\WINDOWS\SoundMan.exe]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 16:57 153136]
"SecurDisc"="C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 16:55 1628208]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 16:55 1057328]
"StormCodec_Helper"="C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" [2006-11-26 11:30 97357]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"LogonStudio"="C:\Program Files\Stardock\Object Desktop\LogonStudio\logonstudio.exe" [2002-09-03 19:38 987187]
"PC Auto Shutdown"="C:\prog\PC Auto Shutdown\AutoShutdown.exe" [2006-11-24 10:11 359679]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-03-01 04:54 1443072]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2008-04-19 21:55:37 3581680]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonuiX.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccdeeCV]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll 2007-09-23 11:10 229376 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\mtd2002\\mtdserver.exe"=
"C:\\games\\kag\\_AG.exe"=
"C:\\prog\\lime\\LimeWire\\LimeWire.exe"=
"C:\\prog\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R2 cvintdrv;cvintdrv;C:\WINDOWS\system32\drivers\cvintdrv.sys [2007-02-21 11:00]
R2 mxssvr;NI Configuration Manager;"C:\Program Files\National Instruments\MAX\nimxs.exe" [2006-07-15 20:47]
R2 NITaggerService;National Instruments Variable Engine;"C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe" [2006-07-25 18:36]
R2 PCAutoShutdown_Service;PCAutoShutdown_Service;C:\prog\PC Auto Shutdown\ShutdownService.exe [2006-11-06 16:31]
S2 NOD32FiXTemDono;Eset Nod32 Boot;C:\WINDOWS\system32\regedt32.exe [2004-08-03 18:07]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-01-25 10:31]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{96d4a4c2-029b-11dd-a634-000f9fc9d761}]
\Shell\AutoRun\command - E:\RavMon.exe
\Shell\explore\Command - E:\RavMon.exe -e
\Shell\open\Command - E:\RavMon.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-22 14:26:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Stardock\ObjectDock\DockShellHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2008-04-22 14:32:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-22 21:32:45
ComboFix2.txt 2008-04-22 08:37:11
Pre-Run: 93,059,457,024 bytes free
Post-Run: 93,061,652,480 bytes free
496 --- E O F --- 2008-04-22 17:52:41
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:34:06 PM, on 4/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\prog\PC Auto Shutdown\ShutdownService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\prog\PC Auto Shutdown\AutoShutdown.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.094\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [SecurDisc] "C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe"
O4 - HKLM\..\Run: [InCD] "C:\Program Files\Nero\Nero 7\InCD\InCD.exe"
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\Stardock\Object Desktop\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [PC Auto Shutdown] C:\prog\PC Auto Shutdown\AutoShutdown.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [mtd2002Svr] "C:\Program Files\mtd2002"\mtdserver.exe -f
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: fccdeeCV - C:\WINDOWS\
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments, Inc. - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments, Inc. - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: PCAutoShutdown_Service - Unknown owner - C:\prog\PC Auto Shutdown\ShutdownService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
--
End of file - 6386 bytes