COMBO FIX LOG:
ComboFix 08-09-16.05 - Administrator 2008-09-19 14:14:31.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.716 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt
C:\WINDOWS\BM0bd97de8.txt
C:\WINDOWS\BM0bd97de8.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aaowqujw.dll
C:\WINDOWS\system32\aggadrhs.ini
C:\WINDOWS\system32\cjuhymne.ini
C:\WINDOWS\system32\ebeedccdf6_d.dll
C:\WINDOWS\system32\ebgduaxj.dll
C:\WINDOWS\system32\enmyhujc.dll
C:\WINDOWS\system32\etujolsq.dll
C:\WINDOWS\system32\euqhvjia.dll
C:\WINDOWS\system32\frgknaod.dll
C:\WINDOWS\system32\hkaawcnq.dll
C:\WINDOWS\system32\kbeoordc.ini
C:\WINDOWS\system32\lsernpfr.ini
C:\WINDOWS\system32\ltgkyhrc.ini
C:\WINDOWS\system32\lVwFLkkj.ini
C:\WINDOWS\system32\lVwFLkkj.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nljwhgjr.dll
C:\WINDOWS\system32\olsmodye.ini
C:\WINDOWS\system32\onmblqkj.dll
C:\WINDOWS\system32\oseyiclp.dll
C:\WINDOWS\system32\pulnlxkq.ini
C:\WINDOWS\system32\qncwaakh.ini
C:\WINDOWS\system32\rpfapu.dll
C:\WINDOWS\system32\shrdagga.dll
C:\WINDOWS\system32\thivwtqc.dll
C:\WINDOWS\system32\tliqxabs.dll
C:\WINDOWS\system32\vpvxce.dll
C:\WINDOWS\system32\xxyvvTmN.dll
C:\WINDOWS\system32\ygdemnwf.ini
C:\WINDOWS\system32\ynkqyf.dll
.
((((((((((((((((((((((((( Files Created from 2008-08-19 to 2008-09-19 )))))))))))))))))))))))))))))))
.
2008-09-18 00:11 . 2004-08-04 13:00 605,696 –a—— C:\WINDOWS\system32\dllcache\getuname.dll
2008-09-18 00:11 . 2004-08-04 13:00 343,040 –a—— C:\WINDOWS\system32\dllcache\mspaint.exe
2008-09-18 00:11 . 2004-08-04 13:00 214,528 –a—— C:\WINDOWS\system32\dllcache\wordpad.exe
2008-09-18 00:11 . 2004-08-04 13:00 114,688 –a—— C:\WINDOWS\system32\dllcache\calc.exe
2008-09-18 00:11 . 2004-08-04 13:00 102,912 –a—— C:\WINDOWS\system32\dllcache\clipbrd.exe
2008-09-18 00:11 . 2004-08-04 13:00 80,384 –a—— C:\WINDOWS\system32\dllcache\charmap.exe
2008-09-18 00:11 . 2004-08-04 13:00 5,632 –a—— C:\WINDOWS\system32\dllcache\write.exe
2008-09-17 23:53 . 2008-09-17 23:59 96,976 –a—— C:\WINDOWS\system32\drivers\klin.dat
2008-09-17 23:53 . 2008-09-17 23:59 87,855 –a—— C:\WINDOWS\system32\drivers\klick.dat
2008-09-17 23:52 . 2008-09-19 14:17 2,195,232 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-17 23:52 . 2008-09-19 14:17 40,992 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-17 23:52 . 2008-09-19 14:17 8,564 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-17 23:52 . 2008-09-19 14:17 2,516 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-17 23:46 . 2008-09-17 23:46 d——– C:\Program Files\Trend Micro
2008-09-17 23:32 . 2008-09-17 23:32 d——– C:\Program Files\DAEMON Tools Toolbar
2008-09-17 23:32 . 2008-09-17 23:32 d——– C:\Program Files\DAEMON Tools Lite
2008-09-17 23:27 . 2008-09-17 23:27 113,152 –a—— C:\WINDOWS\system32\qfhwamim.dll
2008-09-17 23:27 . 2008-09-17 23:27 113,152 –a—— C:\WINDOWS\system32\mygzms.dll
2008-09-17 22:00 . 2008-09-17 22:01 d——– C:\$WIN_NT$.~BT
2008-09-17 17:49 . 2004-08-04 13:00 472,007 -ra—— C:\txtsetup.sif
2008-09-17 17:49 . 2004-08-04 13:00 260,272 -ra—— C:\$LDR$
2008-09-17 17:09 . 2008-09-17 17:09 d——– C:\My Documents
2008-09-17 14:54 . 2008-09-17 14:54 d——– C:\Documents and Settings\Administrator\Application Data\Leadertech
2008-09-17 12:42 . 2008-09-17 12:42 113,152 –a—— C:\WINDOWS\system32\xmfjcq.dll
2008-09-17 12:42 . 2008-09-17 12:42 113,152 –a—— C:\WINDOWS\system32\mnllpisv.dll
2008-09-17 12:24 . 2008-09-17 12:24 113,152 –a—— C:\WINDOWS\system32\onuvlvpg.dll
2008-09-17 12:24 . 2008-09-17 12:24 113,152 –a—— C:\WINDOWS\system32\hlqgzh.dll
2008-09-16 20:01 . 2008-09-16 20:01 d——– C:\Program Files\BillP Studios
2008-09-16 20:01 . 2008-09-16 20:01 d——– C:\Documents and Settings\Administrator\Application Data\WinPatrol
2008-09-16 12:16 . 2008-09-16 12:16 113,152 –a—— C:\WINDOWS\system32\vouzoc.dll
2008-09-16 12:16 . 2008-09-16 12:16 113,152 –a—— C:\WINDOWS\system32\viqbbvce.dll
2008-09-16 12:00 . 2008-09-16 12:01 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-14 12:19 . 2008-09-14 12:19 111,616 –a—— C:\WINDOWS\system32\wzzqif.dll
2008-09-14 12:19 . 2008-09-14 12:19 111,616 –a—— C:\WINDOWS\system32\ourgidvg.dll
2008-09-13 20:23 . 2008-09-13 20:23 d——– C:\Documents and Settings\Administrator\Application Data\MSNInstaller
2008-09-12 12:11 . 2008-09-19 14:13 112,640 –a—— C:\WINDOWS\system32\jdmhoj.dll
2008-09-12 12:11 . 2008-09-19 14:13 112,640 –a—— C:\WINDOWS\system32\arkmrhxq.dll
2008-09-11 03:05 . 2008-09-18 00:14 4,566 –a—— C:\WINDOWS\imsins.BAK
2008-09-09 17:33 . 2008-09-10 23:19 d——– C:\Program Files\Zylom Games
2008-09-09 17:33 . 2008-09-09 17:33 d——– C:\Documents and Settings\All Users\Application Data\Zylom
2008-09-08 17:37 . 2008-09-08 17:37 319 –a—— C:\WINDOWS\game.ini
2008-09-08 17:15 . 2008-09-08 17:15 d–hs—- C:\WINDOWS\ftpcache
2008-09-06 21:48 . 2008-09-06 21:48 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-09-06 20:41 . 2008-09-10 23:20 d——– C:\Program Files\Yahoo!
2008-09-06 20:41 . 2008-09-06 20:41 23 –a—— C:\WINDOWS\system32\dfadddac9_d.ocx
2008-09-05 20:10 . 2008-09-06 21:50 d——– C:\Program Files\Kaspersky Lab
2008-09-05 20:10 . 2008-09-19 14:09 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-05 19:47 . 2008-09-05 19:47 d——– C:\Program Files\Microsoft ActiveSync
2008-09-05 19:47 . 2005-10-21 02:47 30,592 ——— C:\WINDOWS\system32\drivers\rndismpx.sys
2008-09-05 19:47 . 2005-10-21 02:47 12,800 ——— C:\WINDOWS\system32\drivers\usb8023x.sys
2008-09-05 19:05 . 2004-08-03 22:58 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-09-05 19:05 . 2004-08-03 22:58 14,848 –a—— C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-09-05 18:55 . 2006-11-06 18:04 28,672 –a—— C:\WINDOWS\system32\drivers\wceusbsh.sys
2008-09-05 18:55 . 2006-11-06 18:04 28,672 –a—— C:\WINDOWS\system32\dllcache\wceusbsh.sys
2008-09-05 11:51 . 2008-09-05 11:54 8,260 –a—— C:\WINDOWS\system32\EPPICResdb0001
2008-09-05 11:49 . 2004-08-03 22:58 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2008-09-05 11:49 . 2004-08-03 22:58 15,104 –a—— C:\WINDOWS\system32\dllcache\usbscan.sys
2008-09-05 11:30 . 2008-09-05 11:30 d——– C:\EPSON
2008-09-04 12:27 . 2008-09-06 13:52 d——– C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-09-01 18:34 . 2008-09-01 18:34 d——– C:\Program Files\ProtectDisc Driver Installer
2008-09-01 14:42 . 2008-09-01 14:42 d——– C:\Program Files\Trymedia
2008-09-01 14:42 . 2008-09-01 14:42 d——– C:\Documents and Settings\All Users\Application Data\Ludia
2008-08-31 23:44 . 2008-08-31 23:44 d——– C:\WINDOWS\95FC26FB19FD4A96BBB1B1062E8648F5.TMP
2008-08-29 22:43 . 2008-09-18 19:54 d——– C:\WINDOWS\system32\CatRoot_bak
2008-08-27 18:49 . 2008-08-31 11:55 d——– C:\Documents and Settings\All Users\Application Data\Ubisoft
2008-08-27 18:48 . 2008-08-27 18:48 22,328 –a—— C:\Documents and Settings\Administrator\Application Data\PnkBstrK.sys
2008-08-24 11:43 . 2003-03-24 16:52 94,208 –a—— C:\WINDOWS\system32\dllcache\fpencode.dll
2008-08-24 11:43 . 2008-08-24 11:43 376 –a—— C:\WINDOWS\ODBC.INI
2008-08-24 11:42 . 2008-08-24 11:42 d——– C:\WINDOWS\ShellNew
2008-08-24 11:41 . 2008-08-24 11:41 d——– C:\Documents and Settings\Administrator\Application Data\Microsoft Web Folders
2008-08-21 12:30 . 2008-08-21 12:30 dr-h—– C:\Documents and Settings\Administrator\Application Data\SecuROM
2008-08-21 12:05 . 2008-08-31 11:55 d——– C:\Program Files\Ubisoft
2008-08-20 01:17 . 2008-08-20 01:17 d——– C:\Program Files\Common Files\DirectX
2008-08-19 15:06 . 2008-08-20 07:53 d——– C:\Program Files\Crazy Machines II Demo
2008-08-19 15:02 . 2008-08-19 15:02 d——– C:\WINDOWS\EFC1B35CFFF241D8A70ACE6037F8040B.TMP
2008-08-19 15:02 . 2008-08-19 15:02 d——– C:\Program Files\OpenAL
2008-08-19 15:02 . 2008-08-31 20:29 418,480 –a—— C:\WINDOWS\system32\wrap_oal.dll
2008-08-19 15:02 . 2008-08-31 20:29 115,432 –a—— C:\WINDOWS\system32\OpenAL32.dll
2008-08-19 14:17 . 2008-08-19 14:55 d——– C:\Documents and Settings\All Users\Application Data\Firefly Studios
2008-08-19 14:16 . 2008-08-19 15:37 107,888 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2008-08-19 14:15 . 2008-08-19 14:15 d——– C:\WINDOWS\8AFFD400A2D54216A1AC62EC637F73EE.TMP
2008-08-19 14:09 . 2008-08-19 14:09 d——– C:\WINDOWS\system32\AGEIA
2008-08-19 14:09 . 2008-09-17 21:09 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-08-19 14:09 . 2008-08-19 14:09 d——– C:\Program Files\AGEIA Technologies
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-17 23:05 112,144 —-a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-09-17 22:34 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-17 20:10 ——— d—–w C:\Program Files\Intel
2008-09-17 17:55 ——— d—–w C:\Program Files\Windows Live
2008-09-17 17:16 ——— d—–w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-09-07 00:36 ——— d—–w C:\Program Files\Rockstar Games
2008-09-05 10:34 ——— d—–w C:\Program Files\epson
2008-08-24 10:34 ——— d—–w C:\Program Files\microsoft frontpage
2008-08-21 11:12 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-08-21 11:11 ——— d—–w C:\Program Files\Google
2008-08-18 21:58 ——— d—–w C:\Program Files\SystemRequirementsLab
2008-08-18 21:56 ——— d—–w C:\Documents and Settings\Administrator\Application Data\SystemRequirementsLab
2008-08-18 10:32 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Sonic
2008-08-15 21:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trymedia
2008-08-12 10:38 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Template
2008-08-11 20:57 ——— d—–w C:\Program Files\NOS
2008-08-11 20:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\NOS
2008-08-10 21:28 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-08-10 21:27 ——— d—–w C:\Program Files\QuickTime
2008-08-10 21:27 ——— d—–w C:\Program Files\Apple Software Update
2008-08-10 21:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-10 21:26 ——— d—–w C:\Program Files\Common Files\Apple
2008-08-10 21:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2008-08-08 11:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\Entriq
2008-08-03 22:04 ——— d—–w C:\Program Files\WinZip Self-Extractor
2008-08-03 22:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZipSE
2008-08-03 21:58 717,296 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-08-03 21:57 ——— d—–w C:\Documents and Settings\Administrator\Application Data\DAEMON Tools
2008-08-02 17:50 ——— dcsh–w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-02 17:47 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-01 16:43 ——— d—–w C:\Program Files\Paradox Interactive
2008-07-31 13:43 ——— d—–w C:\Program Files\Kontiki
2008-07-31 13:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-07-31 13:37 ——— d—–w C:\Program Files\Windows Media Connect 2
2008-07-28 19:52 ——— d—–w C:\Program Files\FirstClass
2008-07-28 19:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\FirstClass
2008-07-28 19:52 ——— d—–w C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-07-27 14:40 ——— d—–w C:\Documents and Settings\Administrator\Application Data\ArcSoft
2008-07-19 12:52 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Smart Panel
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54d0ab77-24ca-4c48-9980-9a34591b6785}]
2008-09-17 23:27 113152 –a—— C:\WINDOWS\system32\mygzms.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus Photo RX620 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE" [2004-05-19 98304]
"Auto EPSON Stylus Photo RX620 Series on JENSLAPTOP"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE" [2004-05-19 98304]
"Auto EPSON Stylus Photo RX620 Series on DAVIDS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE" [2004-05-19 98304]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-26 218376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^MagicDisc.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\MagicDisc.lnk
backup=C:\WINDOWS\pss\MagicDisc.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ATI CATALYST System Tray.lnk
backup=C:\WINDOWS\pss\ATI CATALYST System Tray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Sonic CinePlayer Quick Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Sonic CinePlayer Quick Launch.lnk
backup=C:\WINDOWS\pss\Sonic CinePlayer Quick Launch.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-06-12 02:38 34672 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
–a—— 2008-07-22 20:42 116040 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
–a—— 2005-05-13 00:23 32768 C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
–a—— 2005-05-12 21:05 344064 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 08:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
–a—— 2008-08-08 13:11 490952 C:\Program Files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
–a—— 2005-02-25 05:33 127037 C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
–a—— 2006-11-13 13:39 1289000 C:\Program Files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a—— 2004-07-27 16:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
–a—— 2004-07-27 16:50 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Portfolio]
–a—— 2000-07-13 21:00 311350 C:\Program Files\Microsoft Works\wkssb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
–a—— 2000-07-13 21:00 28739 C:\Program Files\Microsoft Works\WkDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2008-05-16 14:01 13529088 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2008-05-16 14:01 86016 C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
–a—— 2005-03-07 04:52 276480 C:\Program Files\PDF Complete\pdfsty.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTHOSTTR]
–a—— 2005-04-08 19:08 73728 C:\Program Files\HPQ\HP ProtectTools Security Manager\pthosttr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WorksFUD]
–a—— 2000-07-13 21:00 24576 C:\Program Files\Microsoft Works\wkfud.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
–a—— 2005-01-08 01:07 61952 C:\WINDOWS\system32\HdAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2008-05-16 14:01 1630208 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
–a—— 2005-07-13 11:37 14679552 C:\WINDOWS\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"pdfcDispatcher"=2 (0x2)
"LightScribeService"=2 (0x2)
"KService"=2 (0x2)
"iPod Service"=3 (0x3)
"hpqwmi"=3 (0x3)
"getPlus® Helper"=3 (0x3)
"ATI Smart"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"NVSvc"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\FirstClass\\fcc32.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Disabled:ActiveSync Service
R2 acedrv11;acedrv11;C:\WINDOWS\system32\drivers\acedrv11.sys [2008-01-23 501560]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 24344]
S4 getPlus® Helper;getPlus® Helper;C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-06-26 31592]
S4 pdfcDispatcher;PDF Document Manager;C:\Program Files\PDF Complete\pdfsvc.exe [2005-03-07 476160]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\Setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bea14416-557a-11dd-a6f9-001560a20bd7}]
\Shell\AutoRun\command - G:\qa8sywva.cmd
\Shell\explore\Command - G:\qa8sywva.cmd
\Shell\open\Command - G:\qa8sywva.cmd
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
BHO-{DABB1C43-1596-49C4-9E4D-51AE7A1518BB} - C:\WINDOWS\system32\jkkHaBsT.dll
HKLM-Run-08ea4e74 - C:\WINDOWS\system32\crhykgtl.dll
ShellExecuteHooks-{DABB1C43-1596-49C4-9E4D-51AE7A1518BB} - C:\WINDOWS\system32\jkkHaBsT.dll
Notify-jkkHaBsT - jkkHaBsT.dll
MSConfigStartUp-08ea4e74 - C:\WINDOWS\system32\hkaawcnq.dll
MSConfigStartUp-BM0bd97de8 - C:\WINDOWS\system32\ebgduaxj.dll
MSConfigStartUp-iTunesHelper - C:\Program Files\iTunes\iTunesHelper.exe
MSConfigStartUp-uTorrent - C:\Program Files\uTorrent\uTorrent.exe
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\f55pz7gc.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.co.uk/
FF -: plugin - C:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava14.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJPI150.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPOJI610.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-19 14:18:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="C:\Program Files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-09-19 14:21:04 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-19 13:21:00
Pre-Run: 114,917,072,896 bytes free
Post-Run: 136,623,468,544 bytes free
340 — E O F — 2008-09-18 18:46:04
NEW HIJACKTHIS LOG:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:24:22, on 19/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: {5876b195-43a9-0899-84c4-ac4277ba0d45} - {54d0ab77-24ca-4c48-9980-9a34591b6785} - C:\WINDOWS\system32\mygzms.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [EPSON Stylus Photo RX620 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE /P31 "EPSON Stylus Photo RX620 Series" /O6 "USB001" /M "Stylus Photo RX620"
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo RX620 Series on JENSLAPTOP] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE /P50 "Auto EPSON Stylus Photo RX620 Series on JENSLAPTOP" /O21 "\\JENSLAPTOP\EPSONSty" /M "Stylus Photo RX620"
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo RX620 Series on DAVIDS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE /P46 "Auto EPSON Stylus Photo RX620 Series on DAVIDS" /O16 "\\DAVIDS\Printer" /M "Stylus Photo RX620"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
–
End of file - 4429 bytes