Here is the combofix log:
ComboFix 08-06-04.3 - Snuggle Muffin 2008-06-05 3:43:42.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.715 [GMT -4:00]
Running from: f:\Utilities\combofix.exe
Command switches used :: /killall
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\.#
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\khfccbx.dll
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\qtutv.ini
C:\WINDOWS\system32\qtutv.ini2
C:\WINDOWS\system32\vtutq.dll
C:\WINDOWS\system32\wanpacket.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-05-05 to 2008-06-05 )))))))))))))))))))))))))))))))
.
2008-06-04 18:40 . 2004-08-04 08:00 185,856 –a—— C:\WINDOWS\system32\framedyn.dll
2008-06-04 14:27 . 2008-06-04 14:25 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-06-04 14:25 . 2008-06-04 14:27 d——– C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\.housecall6.6
2008-06-03 15:00 . 2008-06-03 15:00 d——– C:\WINDOWS\RSM
2008-06-03 15:00 . 2008-06-03 15:00 d——– C:\Program Files\MSN Messenger
2008-06-03 14:36 . 2008-06-03 14:36 80 –a—— C:\WINDOWS\RegisterRSM.ini
2008-06-03 14:35 . 2008-06-03 14:39 1,256 –a—— C:\WINDOWS\Monitor.ini
2008-06-03 14:34 . 2008-06-03 14:34 806 –a—— C:\WINDOWS\system32\realspy.lnk
2008-06-03 01:01 . 2008-06-03 14:33 424 –a—— C:\WINDOWS\zipgenius.xml
2008-06-02 11:34 . 2008-06-02 16:58 25,992 –a—— C:\WINDOWS\system32\pgdfgsvc.exe
2008-06-02 01:05 . 2008-06-02 13:02 280 –a—— C:\WINDOWS\system32\PDBootState
2008-06-01 20:38 . 2008-06-01 20:38 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Raxco
2008-06-01 20:38 . 2008-04-10 12:08 71,184 -ra—— C:\WINDOWS\system32\drivers\DefragFS.sys
2008-06-01 10:16 . 2008-06-01 10:16 d——– C:\WINDOWS\system32\NtmsData
2008-05-23 12:45 . 2008-05-23 12:45 d——– C:\Program Files\MySpace
2008-05-22 21:08 . 2008-05-22 21:09 d——– C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\7Wonders
2008-05-20 02:58 . 2008-05-20 02:58 d——– C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\funkitron
2008-05-20 00:19 . 2008-06-04 17:35 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-05-20 00:19 . 2008-05-20 00:19 1,409 –a—— C:\WINDOWS\QTFont.for
2008-05-20 00:18 . 2008-05-20 00:18 313 –a—— C:\WINDOWS\doom3.ini
2008-05-16 16:54 . 2008-05-16 16:56 d——– C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\.SunDownloadManager
2008-05-16 14:29 . 2008-05-16 14:29 d——– C:\Program Files\LiveUpdate
2008-05-16 14:29 . 2004-08-03 23:08 25,600 –a—— C:\WINDOWS\system32\drivers\usbser.sys
2008-05-16 14:29 . 2004-08-03 23:08 25,600 –a–c— C:\WINDOWS\system32\dllcache\usbser.sys
2008-05-16 14:28 . 2008-05-16 14:38 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\BVRP Software
2008-05-16 14:26 . 2006-11-13 14:45 1,419,232 –a—— C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-05-16 14:26 . 2006-10-08 21:51 23,856 –a—— C:\WINDOWS\system32\spupdsvc.exe
2008-05-16 14:26 . 2007-06-18 14:18 23,680 –a—— C:\WINDOWS\system32\drivers\motmodem.sys
2008-05-16 14:26 . 2008-05-16 14:26 0 –ah—– C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-05-16 14:26 . 2008-05-16 14:26 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-05-16 14:25 . 2008-05-16 14:25 d——– C:\Program Files\Common Files\Motorola Shared
2008-05-12 21:51 . 2008-05-12 21:51 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2008-05-12 21:51 . 2008-05-12 21:51 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2008-05-05 11:00 . 2008-05-05 11:00 d——– C:\Program Files\aVis
2008-05-05 10:58 . 2008-05-21 14:12 311 –a—— C:\WINDOWS\SoundGraffiti.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-05 07:49 ——— d—–w C:\Documents and Settings\LocalService.NT AUTHORITY.000\Application Data\VMware
2008-06-05 07:49 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\VMware
2008-06-04 23:39 ——— d—–w C:\Program Files\DivX
2008-06-04 21:25 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\OpenOffice.org2
2008-06-03 05:01 ——— d—–w C:\Program Files\ZipGenius 6
2008-06-03 05:01 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\ZipGenius
2008-06-02 14:56 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\uTorrent
2008-05-16 18:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-05-16 17:37 ——— d—–w C:\Program Files\Planestate
2008-05-05 14:58 ——— d—–w C:\Program Files\Winamp
2008-05-04 15:09 ——— d—–w C:\Program Files\Common Files\NSV
2008-05-04 03:00 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Go Go Gourmet
2008-05-04 02:24 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-05-03 21:51 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-05-03 21:50 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-03 21:18 691,545 —-a-w C:\WINDOWS\unins000.exe
2008-05-01 23:37 ——— d—–w C:\Program Files\Three Rings Design
2008-05-01 23:36 ——— d—–w C:\Program Files\Java
2008-04-26 05:26 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\Darwin
2008-04-26 05:24 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\rionix
2008-04-25 20:31 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\ScreenSeven
2008-04-25 20:19 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\Gamelab
2008-04-25 05:12 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Oberon Games
2008-04-24 21:58 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\BloodTies
2008-04-24 17:12 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\iWin
2008-04-24 17:11 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\iWin
2008-04-24 03:11 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\QB9 S.R.L
2008-04-24 01:40 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\PlayFirst
2008-04-24 01:40 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\PlayFirst
2008-04-23 22:38 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\Valusoft
2008-04-23 22:38 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Valusoft
2008-04-23 07:22 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Zylom
2008-04-23 06:45 126,976 —-a-w C:\WINDOWS\system32\commserv.exe
2008-04-23 06:22 ——— d—–w C:\Program Files\BFG
2008-04-23 06:15 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\GameHouse
2008-04-23 06:14 ——— d—–w C:\Program Files\GameHouse
2008-04-23 06:12 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\MythPeople
2008-04-22 20:01 ——— d—–w C:\Program Files\Evil Player
2008-04-22 02:01 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\Atari
2008-04-21 22:09 ——— d—–w C:\Program Files\Notepad++
2008-04-21 07:45 ——— d—–w C:\Program Files\SommerLine
2008-04-21 04:17 43,520 —-a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-04-21 03:50 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\Auslogics
2008-04-21 03:49 ——— d—–w C:\Program Files\Auslogics
2008-04-18 20:55 ——— d—–w C:\Program Files\Tank O Box
2008-04-18 20:28 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\flightgear.org
2008-04-18 19:49 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\ImgBurn
2008-04-18 19:43 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\VMware
2008-04-18 19:42 ——— d—–w C:\Program Files\ReNamer
2008-04-18 19:19 ——— d—–w C:\Program Files\AceMoney
2008-04-18 18:10 68,096 —-a-w C:\WINDOWS\ScUnin.exe
2008-04-18 18:01 ——— d—–w C:\Program Files\Wizards of the Coast
2008-04-18 17:22 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Ahead
2008-04-18 17:21 ——— d—–w C:\Program Files\Common Files\Ahead
2008-04-18 16:52 249,856 ——w C:\WINDOWS\Setup1.exe
2008-04-18 16:51 ——— d—–w C:\Program Files\Crapsoft
2008-04-18 16:24 ——— d—–w C:\Program Files\TUGZip
2008-04-18 16:24 ——— d—–w C:\Program Files\TPlayer
2008-04-18 16:13 ——— d—–w C:\Program Files\Common Files\VMware
2008-04-18 16:09 ——— d—–w C:\Program Files\ScummVM
2008-04-18 16:00 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\MSN Search Toolbar
2008-04-18 15:58 ——— d—–w C:\Program Files\MSN Toolbar Suite
2008-04-18 15:54 ——— d—–w C:\Program Files\Belarc
2008-04-18 15:54 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\MSN Search Toolbar
2008-04-18 15:45 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
2008-04-18 15:36 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\KompoZer
2008-04-18 15:18 ——— d—–w C:\Program Files\PCPitstop
2008-04-18 15:10 ——— d—–w C:\Program Files\The Great Tree
2008-04-18 05:39 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\HipSoft
2008-04-18 03:28 319 —-a-w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\bbbconfig.dat
2008-04-18 03:11 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\MysteryStudio
2008-04-17 20:28 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\dvdcss
2008-04-17 20:16 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\Ahead
2008-04-16 20:07 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo!
2008-04-16 17:00 230,664 —-a-w C:\WINDOWS\system32\PDBoot.exe
2008-04-14 22:27 ——— d—–w C:\Program Files\Planematrix
2008-04-14 19:44 ——— d—–w C:\Program Files\ChefTec
2008-04-14 19:44 ——— d—–w C:\Program Files\Borland
2008-04-14 19:29 ——— d—–w C:\Program Files\Stardock
2008-04-14 19:16 ——— d—–w C:\Program Files\microsoft frontpage
2008-04-14 03:26 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\Notepad++
2008-04-14 00:52 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\Dev-Cpp
2008-04-14 00:34 ——— d—–w C:\Program Files\Unlocker
2008-04-14 00:31 48,456 —-a-w C:\WINDOWS\system32\UninstallElectricSheep.exe
2008-04-09 20:15 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\MinigolfAdventures
2008-04-09 16:46 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\Teggo
2008-04-09 16:43 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Sandlot Games
2008-04-09 16:30 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\Chicken Chase
2008-04-07 20:13 ——— d—–w C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Application Data\Legends of pirates
2008-04-07 18:59 73,216 ——w C:\WINDOWS\ST6UNST.EXE
2008-04-07 18:19 ——— d—–w C:\Program Files\MP3Gain
2008-04-07 16:57 ——— d—–w C:\Program Files\FreshDevices
2008-04-07 16:36 ——— d—–w C:\Program Files\QuickTime
2008-04-07 16:34 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
2008-04-07 16:23 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-04-07 16:23 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\InstallShield
2008-04-07 15:58 ——— d—–w C:\Program Files\IrfanView
2008-04-07 03:41 ——— d—–w C:\Program Files\Common Files\Logitech
2008-04-06 02:54 ——— d—–w C:\Program Files\WinPcap
2008-04-05 20:05 ——— d—–w C:\Program Files\USB Driver Vers. 3.2
1999-07-07 00:00 6 –sh–r C:\WINDOWS\@desktop@.dat
.
——- Sigcheck ——-
2008-04-04 01:57 502272 6225f14b8ce08ccba8b25ad27843c674 C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1FB63E52-4D6E-48C1-A08F-F630FE50F337}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{46A7C608-FBC5-41E3-9DF6-A53D5930C00A}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CursorXP"="C:\Program Files\CursorXP\CursorXP.exe" [2005-01-19 17:44 140288]
"LogitechSoftwareUpdate"="D:\Program Stuffs\Utilities\Cam\ManifestEngine.exe" [2004-06-01 06:46 196608]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-04-05 15:01 16384]
"SpybotSD TeaTimer"="C:\Program Files\Utilities\Antivirus\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AtiPTA"="atiptaxx.exe" [2006-02-21 21:05 344064 C:\WINDOWS\system32\atiptaxx.exe]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 06:48 157592]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 19:15 106496]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 19:20 77824 C:\WINDOWS\SOUNDMAN.EXE]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-05 01:32 53248]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-05-21 19:11 221184]
"LogitechVideoRepair"="D:\Program Stuffs\Utilities\Cam\ISStart.exe" [2004-06-01 11:09 458752]
"LogitechVideoTray"="D:\Program Stuffs\Utilities\Cam\LogiTray.exe" [2004-06-01 11:03 217088]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-03-01 01:10 15872]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-04-07 12:35 282624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 19:27 9117696]
C:\Documents and Settings\Snuggle Muffin.ZOMGWTFBBQ\Start Menu\Programs\Startup\
Genius Tablet.lnk - C:\gtabnt\GTABLET.EXE [2007-02-28 02:37:21 21504]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
TabUserW.exe.lnk - C:\WINDOWS\system32\WTablet\TabUserW.exe [2008-04-05 14:56:20 114688]
Windows Desktop Search.lnk - C:\Program Files\MSN Toolbar Suite\DS\
02.05.0001.1119\en-us\bin\WindowsSearch.exe [2005-09-20 18:10:04 238080]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoStartMenuPinnedList"= 0 (0x0)
"NoStartMenuMFUprogramsList"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinterTabs"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"NoChangeKeyboardNavigationIndicators"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\
0]
Source= C:\Documents and Settings\Snuggle Muffin\My Documents\My Pictures\gif\PDVD_4067.gif
FriendlyName=
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= C:\Documents and Settings\Snuggle Muffin\My Documents\My Pictures\gif\rhk.gif
FriendlyName=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khfccbx]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
C:\Program Files\Common Files\Stardock\mcpstub.dll 2005-01-31 18:13 49152 C:\Program Files\Common Files\Stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll 2008-04-04 15:31 176128 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Real Spy Monitor"="D:\Program Stuffs\Utilities\xp tools\Real Spy Monitor\winrsm.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
R2 Active Common Service;Active Common Service;C:\WINDOWS\system32\commserv.exe [2008-04-23 02:45]
R2 PD91Agent;PD91Agent;"D:\Program Stuffs\Utilities\perfect disk\PD91Agent.exe" [2008-04-16 13:00]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\NSNDIS5.SYS []
S3 PD91Engine;PD91Engine;"D:\Program Stuffs\Utilities\perfect disk\PD91Engine.exe" [2008-04-16 13:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7fe771ff-03e6-11dd-a770-0013d45eff1b}]
\Shell\AutoRun\command - PortableApps\BlackBox\blackbox.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-05 03:48:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Unlocker\UnlockerHook.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Utilities\Antivirus\Adaware\aawservice.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\wdfmgr.exe
D:\Program Stuffs\Utilities\VMware\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
D:\Program Stuffs\Utilities\Cam\FxSvr2.exe
C:\Program Files\MSN Toolbar Suite\DS\
02.05.0001.1119\en-us\bin\WindowsSearchIndexer.exe
C:\Program Files\MSN Toolbar Suite\SL\
02.05.0001.1119\en-us\msn_sl.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-06-05 3:53:46 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-05 07:53:32
Pre-Run: 4,545,830,912 bytes free
Post-Run: 4,787,118,080 bytes free
293
And here is the hijack this log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 03:54, on 2008-06-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Utilities\Antivirus\Adaware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\WINDOWS\system32\commserv.exe
D:\Program Stuffs\Utilities\perfect disk\PD91Agent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
D:\Program Stuffs\Utilities\VMware\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
D:\Program Stuffs\Utilities\Cam\LogiTray.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Utilities\Antivirus\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
D:\Program Stuffs\Utilities\Cam\FxSvr2.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\windowssearch.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchIndexer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Stuffs\Utilities\Hijak\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\UTILIT~1\ANTIVI~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] D:\Program Stuffs\Utilities\Cam\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] D:\Program Stuffs\Utilities\Cam\LogiTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "D:\Program Stuffs\Utilities\Cam\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Utilities\Antivirus\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - S-1-5-18 Startup: Genius Tablet.lnk = C:\gtabnt\GTABLET.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Genius Tablet.lnk = C:\gtabnt\GTABLET.EXE (User 'Default user')
O4 - Startup: Genius Tablet.lnk = C:\gtabnt\GTABLET.EXE
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
O8 - Extra context menu item: Yoono suggestions - C:\Program Files\Yoono Explorer Bar\Data\yoonoctxmenu.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\UTILIT~1\ANTIVI~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\UTILIT~1\ANTIVI~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Utilities\Antivirus\Adaware\aawservice.exe
O23 - Service: Active Common Service - Unknown owner - C:\WINDOWS\system32\commserv.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - D:\Program Stuffs\Downloads\Ares\chatServer.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - D:\Program Stuffs\Utilities\perfect disk\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - D:\Program Stuffs\Utilities\perfect disk\PD91Engine.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - D:\Program Stuffs\Utilities\VMware\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
O24 - Desktop Component 0: (no name) - C:\Documents and Settings\Snuggle Muffin\My Documents\My Pictures\gif\PDVD_4067.gif
O24 - Desktop Component 1: (no name) - C:\Documents and Settings\Snuggle Muffin\My Documents\My Pictures\gif\rhk.gif
–
End of file - 9103 bytes
So far this appears to have solved the problem!
You are wonderful and I thank you so very much, I will be installing antivirus next.