Kalessin
Topic Starter
Hi all, I hope you can help me 
Yesterday my antivirus program AVG told me I've been infected with 4 trojans. I've run Super Anti Spyware, CCleaner, ComboFix, SDFix from safe mode, Adaware, Spybot, Combofix, Prevx trial version and Trojan Remover - they seem to have removed 3 of the trojans identified, but Spybot is still detecting win32.delf.uc on my computer. I've Googled mercilessly but cannot find a method to remove it.
Here is my Combofix log followed by HijackThis report. Please help me, I hate reinstalling Windows and I would really rather not resort to that, but I bank online and I can't pay any of my online bills if there's any chance my PC is compromised!
EDIT: Malwarebyte's Anti-Malware log posted as well.
ComboFix 08-09-16.05 - Anonymous Mute 2008-09-19 9:04:24.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.631 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\5.tmp
C:\WINDOWS\system32\7.tmp
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\wanpacket.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_NPF
——-\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-08-19 to 2008-09-19 )))))))))))))))))))))))))))))))
.
2008-09-19 08:41 . 2008-09-19 08:41 d——– C:\Program Files\PrevxCSI
2008-09-19 08:41 . 2008-09-19 08:41 d——– C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-09-19 08:41 . 2008-09-19 08:41 17,408 –a—— C:\WINDOWS\system32\drivers\pxark.sys
2008-09-18 21:53 . 2008-09-18 22:03 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-18 21:52 . 2008-09-18 21:53 d——– C:\Program Files\Trojan Remover
2008-09-18 21:49 . 2006-05-25 15:52 162,304 –a—— C:\WINDOWS\system32\ztvunrar36.dll
2008-09-18 21:49 . 2003-02-02 20:06 153,088 –a—— C:\WINDOWS\system32\unrar3.dll
2008-09-18 21:49 . 2005-08-26 01:50 77,312 –a—— C:\WINDOWS\system32\ztvunace26.dll
2008-09-18 21:49 . 2002-03-06 01:00 75,264 –a—— C:\WINDOWS\system32\unacev2.dll
2008-09-18 21:49 . 2006-06-19 13:01 69,632 –a—— C:\WINDOWS\system32\ztvcabinet.dll
2008-09-18 21:48 . 2008-09-18 21:52 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Simply Super Software
2008-09-18 21:48 . 2008-09-18 21:48 d——– C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-09-18 21:40 . 2008-09-18 21:40 d——– C:\Documents and Settings\Administrator\Application Data\HPAppData
2008-09-18 21:06 . 2008-09-18 21:06 d——– C:\Program Files\Lavasoft
2008-09-18 21:06 . 2008-09-18 21:08 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-18 21:03 . 2008-09-18 21:03 88 –a—— C:\WINDOWS\system32\4.tmp
2008-09-18 21:03 . 2008-09-18 21:03 0 –a—— C:\WINDOWS\system32\8.tmp
2008-09-18 20:39 . 2008-09-18 20:39 d——– C:\WINDOWS\ERUNT
2008-09-18 20:02 . 2008-09-18 20:04 d——– C:\Program Files\Spybot - Search & Destroy
2008-09-18 20:02 . 2008-09-18 20:47 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-18 19:51 . 2008-09-18 19:51 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-09-18 19:36 . 2008-09-18 19:36 d——– C:\Autoruns
2008-09-18 19:26 . 2008-09-18 19:26 d——– C:\Program Files\CCleaner
2008-09-18 18:36 . 2008-09-18 18:36 d——– C:\Downloads
2008-09-18 18:36 . 2008-09-18 18:37 d——– C:\Documents and Settings\Anonymous Mute\Application Data\GetRightToGo
2008-09-18 18:33 . 2008-09-18 18:33 135,896 –a—— C:\WINDOWS\system32\89.tmp
2008-09-18 18:33 . 2008-09-18 18:33 88 –a—— C:\WINDOWS\system32\86.tmp
2008-09-18 18:33 . 2008-09-18 18:33 0 –a—— C:\WINDOWS\system32\8A.tmp
2008-09-18 18:00 . 2008-09-18 18:00 135,896 –a—— C:\WINDOWS\system32\81.tmp
2008-09-18 18:00 . 2008-09-18 18:00 88 –a—— C:\WINDOWS\system32\7E.tmp
2008-09-18 18:00 . 2008-09-18 18:00 0 –a—— C:\WINDOWS\system32\82.tmp
2008-09-18 17:10 . 2008-09-18 17:10 d——– C:\WINDOWS\system32\wTR19
2008-09-18 17:10 . 2008-09-18 17:10 d——– C:\Temp\dax41
2008-09-18 17:10 . 2008-09-18 17:10 d——– C:\Temp
2008-09-18 17:10 . 2008-09-18 23:00 d–h—– C:\$AVG8.VAULT$
2008-09-17 10:18 . 2008-09-17 10:18 d——– C:\Program Files\iTunes
2008-09-17 10:18 . 2008-09-17 10:18 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Program Files\Common Files\Apple
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Program Files\Bonjour
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Program Files\Apple Software Update
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-09-17 10:01 . 2008-09-17 10:01 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Apple Computer
2008-09-17 10:00 . 2008-09-17 10:18 d——– C:\Program Files\iPod
2008-09-17 10:00 . 2004-12-18 20:32 38,229 ——— C:\WINDOWS\system32\drivers\StMp3Rec.sys
2008-09-15 11:33 . 2008-09-15 11:33 d——– C:\Program Files\MSXML 4.0
2008-09-13 11:58 . 2008-09-13 11:58 d——– C:\Documents and Settings\All Users\Application Data\Age of Empires 3
2008-09-12 18:04 . 2005-05-26 15:34 2,297,552 –a—— C:\WINDOWS\system32\d3dx9_26.dll
2008-09-12 18:00 . 2008-09-12 18:00 d——– C:\Program Files\Microsoft Games
2008-09-09 12:33 . 2006-10-26 19:56 32,592 –a—— C:\WINDOWS\system32\msonpmon.dll
2008-09-09 12:32 . 2008-09-09 12:32 d——– C:\Program Files\MSBuild
2008-09-09 12:32 . 2008-09-09 12:32 d——– C:\Program Files\Microsoft Works
2008-09-09 12:29 . 2008-09-09 12:31 d——– C:\WINDOWS\SHELLNEW
2008-09-09 12:28 . 2008-09-09 12:28 dr-h—– C:\MSOCache
2008-09-09 12:28 . 2008-09-15 11:37 d——– C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-09 12:11 . 2008-09-09 12:11 d——– C:\Program Files\uTorrent
2008-09-09 12:11 . 2008-09-18 18:42 d——– C:\Documents and Settings\Anonymous Mute\Application Data\uTorrent
2008-09-06 15:09 . 2008-09-06 15:09 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts
2008-09-01 14:10 . 2008-09-01 14:10 d——– C:\Program Files\Winamp Toolbar
2008-09-01 14:10 . 2008-09-01 14:10 d——– C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
2008-09-01 14:09 . 2008-09-18 17:17 d——– C:\Program Files\Winamp Remote
2008-09-01 14:09 . 2008-09-01 14:12 d——– C:\Documents and Settings\All Users\Application Data\OrbNetworks
2008-08-29 21:53 . 2008-08-29 21:53 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Media Player Classic
2008-08-29 10:18 . 2008-08-29 10:18 87,336 –a—— C:\WINDOWS\system32\dns-sd.exe
2008-08-29 09:53 . 2008-08-29 09:53 61,440 –a—— C:\WINDOWS\system32\dnssd.dll
2008-08-28 07:25 . 2008-08-28 07:42 d——– C:\WINDOWS\system32\CatRoot_bak
2008-08-26 16:33 . 2008-05-01 15:30 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-26 11:56 . 2008-09-19 09:03 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Affinegy
2008-08-26 11:51 . 2008-08-26 11:51 d——– C:\Program Files\WinPcap
2008-08-26 11:51 . 2008-05-26 16:09 27,072 –a—— C:\WINDOWS\system32\drivers\AFGSp50.sys
2008-08-26 11:50 . 2008-08-26 11:51 d——– C:\Program Files\Virgin Broadband Wireless
2008-08-26 11:50 . 2008-08-26 11:51 d——– C:\Documents and Settings\All Users\Application Data\Affinegy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-18 16:17 ——— d—–w C:\Program Files\QuickTime Alternative
2008-09-17 19:57 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\dvdcss
2008-09-17 09:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-12 17:04 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-12 16:58 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-09-01 13:11 ——— d—–w C:\Program Files\Winamp
2008-08-29 08:10 97,928 —-a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-27 14:19 ——— d—–w C:\Program Files\Black Isle
2008-08-15 13:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\WEBREG
2008-08-15 13:16 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\HP
2008-08-15 13:08 ——— d—–w C:\Program Files\HP
2008-08-15 13:08 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\HPAppData
2008-08-15 13:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-08-15 13:07 ——— d—–w C:\Program Files\Common Files\HP
2008-08-15 13:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-08-15 13:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\HP
2008-08-15 13:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-08-11 13:05 ——— d—–w C:\Program Files\Common Files\Motive
2008-08-11 13:04 ——— d—–w C:\Program Files\BroadJump
2008-07-25 08:49 ——— d—–w C:\Program Files\SystemRequirementsLab
2008-07-25 08:49 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\SystemRequirementsLab
2008-07-23 17:55 ——— d—–w C:\Program Files\Bethesda Softworks
2008-07-18 21:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 21:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 21:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-09 07:26 10,520 —-a-w C:\WINDOWS\system32\avgrsstx.dll
2008-07-08 12:45 114,812 —-a-w C:\WINDOWS\UninstallFirefox.exe
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:23 74,240 —-a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
.
——- Sigcheck ——-
2007-06-13 11:23 1040896 c8b31abad6ff805b8523518bbf30fa0e C:\WINDOWS\explorer.exe
2007-06-13 12:26 1040896 cc66b4f6687ce1ec4b6323699cdb7243 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2001-08-23 13:00 1008640 bb52d95207f2a62e74eadd95ea62fc99 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-04 00:56 1039872 437d3c266afcff71493da4d93b119f31 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2004-08-04 00:56 1039872 0c32b430255559c08ed248ffe150120f C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2008-04-14 01:12 1041408 ffafdb19d4d95d6a2642561f04cecf68 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\explorer.exe
2007-06-13 11:23 1040896 3e6e83b5857ad75b825d27f12348c92c C:\WINDOWS\system32\dllcache\explorer.exe
2001-08-23 13:00 20992 d251ecfb24c053d1fc02f089d549402b C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2004-08-04 00:56 23040 738656e6cd41ced9984620573b658a02 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-14 01:12 23040 5bdd0885c900a8abd194efe178c8efa8 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ctfmon.exe
2004-08-04 00:56 23040 e273553dad628deee738df0b802005b4 C:\WINDOWS\system32\ctfmon.exe
2005-06-11 01:17 65536 2ed7b15f45085d1fdaed38d6dbda06e1 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2001-08-23 13:00 58880 9f3b98fc030ad21d7bb2cd2a971cdffa C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 00:56 65536 5282516d73a172fa7d6fb6173c7c4788 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2004-08-04 00:56 65536 df95c84584886ac4911b6a16f9c0a3ed C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
2008-04-14 01:12 65536 e5dad9026407ec59da31f4f3c4b400c9 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\spoolsv.exe
2005-06-11 00:53 65536 329566c51f9b520a0b38b1186396859a C:\WINDOWS\system32\spoolsv.exe
2001-08-23 13:00 29184 581b86fc07cb97da3ebcfe8255ca43a5 C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
2004-08-04 00:56 32256 013ce0a33c846a2e88dcfdeed04932c2 C:\WINDOWS\ServicePackFiles\i386\userinit.exe
2008-04-14 01:12 33792 896d1f6cfbaac70b94224b7045047ae1 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\userinit.exe
2004-08-04 00:56 32256 bd51869c20f259975070db33bfe88c57 C:\WINDOWS\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2008-07-16 1266992]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 23040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-29 1235736]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 13529088]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 385104]
"Wireless Manager"="C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 593920]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"QuickTime Task"="C:\Program Files\QuickTime Alternative\QTTask.exe" [2008-09-06 421888]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2008-09-15 920144]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 23040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Micronet Wireless Network Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Micronet Wireless Network Utility.lnk
backup=C:\WINDOWS\pss\Micronet Wireless Network Utility.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SATARAID5.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SATARAID5.lnk
backup=C:\WINDOWS\pss\SATARAID5.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 00:56 23040 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2007-03-11 21:34 57344 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2008-05-16 14:01 13529088 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2008-05-16 14:01 86016 C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
–a—— 2008-04-01 02:54 516096 C:\Program Files\Winamp Remote\bin\OrbTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2004-02-22 23:44 41073 C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2008-08-04 00:02 44032 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2008-05-16 14:01 1638400 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-ra—— 2005-06-20 14:42 86016 C:\WINDOWS\soundman.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Black Isle\\Baldur's Gate\\BGMain2.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\Black Isle\\BGII - SoA\\BGMain.exe"=
"C:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;C:\WINDOWS\system32\DRIVERS\nvcchflt.sys [2005-02-12 16640]
R0 pxark;pxark;C:\WINDOWS\system32\drivers\pxark.sys [2008-09-19 17408]
R0 Si3132r5;SiI-3132 SoftRaid 5 Controller;C:\WINDOWS\system32\DRIVERS\Si3132r5.sys [2005-04-19 181760]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-29 97928]
R2 AffinegyService;AffinegyService;C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe [2008-05-26 151552]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
R2 CSIScanner;CSIScanner;C:\Program Files\PrevxCSI\prevxcsi.exe [2008-09-19 618040]
R3 AFGSp50;AFGSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\AFGSp50.sys [2008-05-26 27072]
S3 AFGMp50;AFGMp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\AFGMp50.sys [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\autorun.exe
\Shell\directx\command - E:\DirectX9\dxsetup.exe
\Shell\setup\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Anonymous Mute\Application Data\Mozilla\Firefox\Profiles\hp1bb83z.default\
FF -: plugin - C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 5.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJava14.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJPI142_04.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPOJI610.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPAdbESD.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-19 09:08:06
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
C:\WINDOWS\TEMP\d50b34c8-8fa5-42ec-ac76-68510b73a734.tmp 0 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Virgin Broadband Wireless\ndis_events.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-09-19 9:10:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-19 08:09:57
Pre-Run: 92,568,535,040 bytes free
Post-Run: 92,500,774,912 bytes free
295 — E O F — 2008-09-15 10:37:32
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:25:45, on 19/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {36DBC179-A19F-48F2-B16A-6A3E19B42A87} - C:\WINDOWS\system32\ipv6monl.dll
O2 - BHO: Rmn plugin - {47D92EB6-E52C-4cda-92A6-2369963F4913} - jetaccss.dll (file missing)
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5E7C73D1-2855-4D62-94D4-1CB98B0221FF} - C:\WINDOWS\system32\crypt3.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Wireless Manager] "C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" startup
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Winamp; Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1215515032654
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1215515372342
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
–
End of file - 7153 bytes
Malwarebytes' Anti-Malware 1.28
Database version: 1173
Windows 5.1.2600 Service Pack 2
19/09/2008 13:28:05
mbam-log-2008-09-19 (13-28-05).txt
Scan type: Quick Scan
Objects scanned: 47063
Time elapsed: 3 minute(s), 26 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{47d92eb6-e52c-4cda-92a6-2369963f4913} (Spyware.Banker) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{36dbc179-a19f-48f2-b16a-6a3e19b42a87} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{36dbc179-a19f-48f2-b16a-6a3e19b42a87} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5e7c73d1-2855-4d62-94d4-1cb98b0221ff} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MRSoft (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\WINDOWS\system32\wTR19 (Trojan.Agent) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\jetaccss.dll (Spyware.Banker) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\crypt3.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wTR19\wTR191065.exe (Trojan.Agent) -> Quarantined and deleted successfully.
Yesterday my antivirus program AVG told me I've been infected with 4 trojans. I've run Super Anti Spyware, CCleaner, ComboFix, SDFix from safe mode, Adaware, Spybot, Combofix, Prevx trial version and Trojan Remover - they seem to have removed 3 of the trojans identified, but Spybot is still detecting win32.delf.uc on my computer. I've Googled mercilessly but cannot find a method to remove it.
Here is my Combofix log followed by HijackThis report. Please help me, I hate reinstalling Windows and I would really rather not resort to that, but I bank online and I can't pay any of my online bills if there's any chance my PC is compromised!
EDIT: Malwarebyte's Anti-Malware log posted as well.
ComboFix 08-09-16.05 - Anonymous Mute 2008-09-19 9:04:24.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.631 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\5.tmp
C:\WINDOWS\system32\7.tmp
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\wanpacket.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_NPF
——-\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-08-19 to 2008-09-19 )))))))))))))))))))))))))))))))
.
2008-09-19 08:41 . 2008-09-19 08:41 d——– C:\Program Files\PrevxCSI
2008-09-19 08:41 . 2008-09-19 08:41 d——– C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-09-19 08:41 . 2008-09-19 08:41 17,408 –a—— C:\WINDOWS\system32\drivers\pxark.sys
2008-09-18 21:53 . 2008-09-18 22:03 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-18 21:52 . 2008-09-18 21:53 d——– C:\Program Files\Trojan Remover
2008-09-18 21:49 . 2006-05-25 15:52 162,304 –a—— C:\WINDOWS\system32\ztvunrar36.dll
2008-09-18 21:49 . 2003-02-02 20:06 153,088 –a—— C:\WINDOWS\system32\unrar3.dll
2008-09-18 21:49 . 2005-08-26 01:50 77,312 –a—— C:\WINDOWS\system32\ztvunace26.dll
2008-09-18 21:49 . 2002-03-06 01:00 75,264 –a—— C:\WINDOWS\system32\unacev2.dll
2008-09-18 21:49 . 2006-06-19 13:01 69,632 –a—— C:\WINDOWS\system32\ztvcabinet.dll
2008-09-18 21:48 . 2008-09-18 21:52 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Simply Super Software
2008-09-18 21:48 . 2008-09-18 21:48 d——– C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-09-18 21:40 . 2008-09-18 21:40 d——– C:\Documents and Settings\Administrator\Application Data\HPAppData
2008-09-18 21:06 . 2008-09-18 21:06 d——– C:\Program Files\Lavasoft
2008-09-18 21:06 . 2008-09-18 21:08 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-18 21:03 . 2008-09-18 21:03 88 –a—— C:\WINDOWS\system32\4.tmp
2008-09-18 21:03 . 2008-09-18 21:03 0 –a—— C:\WINDOWS\system32\8.tmp
2008-09-18 20:39 . 2008-09-18 20:39 d——– C:\WINDOWS\ERUNT
2008-09-18 20:02 . 2008-09-18 20:04 d——– C:\Program Files\Spybot - Search & Destroy
2008-09-18 20:02 . 2008-09-18 20:47 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-18 19:51 . 2008-09-18 19:51 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-09-18 19:36 . 2008-09-18 19:36 d——– C:\Autoruns
2008-09-18 19:26 . 2008-09-18 19:26 d——– C:\Program Files\CCleaner
2008-09-18 18:36 . 2008-09-18 18:36 d——– C:\Downloads
2008-09-18 18:36 . 2008-09-18 18:37 d——– C:\Documents and Settings\Anonymous Mute\Application Data\GetRightToGo
2008-09-18 18:33 . 2008-09-18 18:33 135,896 –a—— C:\WINDOWS\system32\89.tmp
2008-09-18 18:33 . 2008-09-18 18:33 88 –a—— C:\WINDOWS\system32\86.tmp
2008-09-18 18:33 . 2008-09-18 18:33 0 –a—— C:\WINDOWS\system32\8A.tmp
2008-09-18 18:00 . 2008-09-18 18:00 135,896 –a—— C:\WINDOWS\system32\81.tmp
2008-09-18 18:00 . 2008-09-18 18:00 88 –a—— C:\WINDOWS\system32\7E.tmp
2008-09-18 18:00 . 2008-09-18 18:00 0 –a—— C:\WINDOWS\system32\82.tmp
2008-09-18 17:10 . 2008-09-18 17:10 d——– C:\WINDOWS\system32\wTR19
2008-09-18 17:10 . 2008-09-18 17:10 d——– C:\Temp\dax41
2008-09-18 17:10 . 2008-09-18 17:10 d——– C:\Temp
2008-09-18 17:10 . 2008-09-18 23:00 d–h—– C:\$AVG8.VAULT$
2008-09-17 10:18 . 2008-09-17 10:18 d——– C:\Program Files\iTunes
2008-09-17 10:18 . 2008-09-17 10:18 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Program Files\Common Files\Apple
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Program Files\Bonjour
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Program Files\Apple Software Update
2008-09-17 10:17 . 2008-09-17 10:17 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-09-17 10:01 . 2008-09-17 10:01 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Apple Computer
2008-09-17 10:00 . 2008-09-17 10:18 d——– C:\Program Files\iPod
2008-09-17 10:00 . 2004-12-18 20:32 38,229 ——— C:\WINDOWS\system32\drivers\StMp3Rec.sys
2008-09-15 11:33 . 2008-09-15 11:33 d——– C:\Program Files\MSXML 4.0
2008-09-13 11:58 . 2008-09-13 11:58 d——– C:\Documents and Settings\All Users\Application Data\Age of Empires 3
2008-09-12 18:04 . 2005-05-26 15:34 2,297,552 –a—— C:\WINDOWS\system32\d3dx9_26.dll
2008-09-12 18:00 . 2008-09-12 18:00 d——– C:\Program Files\Microsoft Games
2008-09-09 12:33 . 2006-10-26 19:56 32,592 –a—— C:\WINDOWS\system32\msonpmon.dll
2008-09-09 12:32 . 2008-09-09 12:32 d——– C:\Program Files\MSBuild
2008-09-09 12:32 . 2008-09-09 12:32 d——– C:\Program Files\Microsoft Works
2008-09-09 12:29 . 2008-09-09 12:31 d——– C:\WINDOWS\SHELLNEW
2008-09-09 12:28 . 2008-09-09 12:28 dr-h—– C:\MSOCache
2008-09-09 12:28 . 2008-09-15 11:37 d——– C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-09 12:11 . 2008-09-09 12:11 d——– C:\Program Files\uTorrent
2008-09-09 12:11 . 2008-09-18 18:42 d——– C:\Documents and Settings\Anonymous Mute\Application Data\uTorrent
2008-09-06 15:09 . 2008-09-06 15:09 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts
2008-09-01 14:10 . 2008-09-01 14:10 d——– C:\Program Files\Winamp Toolbar
2008-09-01 14:10 . 2008-09-01 14:10 d——– C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
2008-09-01 14:09 . 2008-09-18 17:17 d——– C:\Program Files\Winamp Remote
2008-09-01 14:09 . 2008-09-01 14:12 d——– C:\Documents and Settings\All Users\Application Data\OrbNetworks
2008-08-29 21:53 . 2008-08-29 21:53 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Media Player Classic
2008-08-29 10:18 . 2008-08-29 10:18 87,336 –a—— C:\WINDOWS\system32\dns-sd.exe
2008-08-29 09:53 . 2008-08-29 09:53 61,440 –a—— C:\WINDOWS\system32\dnssd.dll
2008-08-28 07:25 . 2008-08-28 07:42 d——– C:\WINDOWS\system32\CatRoot_bak
2008-08-26 16:33 . 2008-05-01 15:30 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-26 11:56 . 2008-09-19 09:03 d——– C:\Documents and Settings\Anonymous Mute\Application Data\Affinegy
2008-08-26 11:51 . 2008-08-26 11:51 d——– C:\Program Files\WinPcap
2008-08-26 11:51 . 2008-05-26 16:09 27,072 –a—— C:\WINDOWS\system32\drivers\AFGSp50.sys
2008-08-26 11:50 . 2008-08-26 11:51 d——– C:\Program Files\Virgin Broadband Wireless
2008-08-26 11:50 . 2008-08-26 11:51 d——– C:\Documents and Settings\All Users\Application Data\Affinegy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-18 16:17 ——— d—–w C:\Program Files\QuickTime Alternative
2008-09-17 19:57 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\dvdcss
2008-09-17 09:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-12 17:04 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-12 16:58 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-09-01 13:11 ——— d—–w C:\Program Files\Winamp
2008-08-29 08:10 97,928 —-a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-27 14:19 ——— d—–w C:\Program Files\Black Isle
2008-08-15 13:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\WEBREG
2008-08-15 13:16 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\HP
2008-08-15 13:08 ——— d—–w C:\Program Files\HP
2008-08-15 13:08 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\HPAppData
2008-08-15 13:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-08-15 13:07 ——— d—–w C:\Program Files\Common Files\HP
2008-08-15 13:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-08-15 13:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\HP
2008-08-15 13:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-08-11 13:05 ——— d—–w C:\Program Files\Common Files\Motive
2008-08-11 13:04 ——— d—–w C:\Program Files\BroadJump
2008-07-25 08:49 ——— d—–w C:\Program Files\SystemRequirementsLab
2008-07-25 08:49 ——— d—–w C:\Documents and Settings\Anonymous Mute\Application Data\SystemRequirementsLab
2008-07-23 17:55 ——— d—–w C:\Program Files\Bethesda Softworks
2008-07-18 21:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 21:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 21:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-09 07:26 10,520 —-a-w C:\WINDOWS\system32\avgrsstx.dll
2008-07-08 12:45 114,812 —-a-w C:\WINDOWS\UninstallFirefox.exe
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:23 74,240 —-a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
.
——- Sigcheck ——-
2007-06-13 11:23 1040896 c8b31abad6ff805b8523518bbf30fa0e C:\WINDOWS\explorer.exe
2007-06-13 12:26 1040896 cc66b4f6687ce1ec4b6323699cdb7243 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2001-08-23 13:00 1008640 bb52d95207f2a62e74eadd95ea62fc99 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-04 00:56 1039872 437d3c266afcff71493da4d93b119f31 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2004-08-04 00:56 1039872 0c32b430255559c08ed248ffe150120f C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2008-04-14 01:12 1041408 ffafdb19d4d95d6a2642561f04cecf68 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\explorer.exe
2007-06-13 11:23 1040896 3e6e83b5857ad75b825d27f12348c92c C:\WINDOWS\system32\dllcache\explorer.exe
2001-08-23 13:00 20992 d251ecfb24c053d1fc02f089d549402b C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2004-08-04 00:56 23040 738656e6cd41ced9984620573b658a02 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-14 01:12 23040 5bdd0885c900a8abd194efe178c8efa8 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ctfmon.exe
2004-08-04 00:56 23040 e273553dad628deee738df0b802005b4 C:\WINDOWS\system32\ctfmon.exe
2005-06-11 01:17 65536 2ed7b15f45085d1fdaed38d6dbda06e1 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2001-08-23 13:00 58880 9f3b98fc030ad21d7bb2cd2a971cdffa C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 00:56 65536 5282516d73a172fa7d6fb6173c7c4788 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2004-08-04 00:56 65536 df95c84584886ac4911b6a16f9c0a3ed C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
2008-04-14 01:12 65536 e5dad9026407ec59da31f4f3c4b400c9 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\spoolsv.exe
2005-06-11 00:53 65536 329566c51f9b520a0b38b1186396859a C:\WINDOWS\system32\spoolsv.exe
2001-08-23 13:00 29184 581b86fc07cb97da3ebcfe8255ca43a5 C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
2004-08-04 00:56 32256 013ce0a33c846a2e88dcfdeed04932c2 C:\WINDOWS\ServicePackFiles\i386\userinit.exe
2008-04-14 01:12 33792 896d1f6cfbaac70b94224b7045047ae1 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\userinit.exe
2004-08-04 00:56 32256 bd51869c20f259975070db33bfe88c57 C:\WINDOWS\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2008-07-16 1266992]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 23040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-29 1235736]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 13529088]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 385104]
"Wireless Manager"="C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 593920]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"QuickTime Task"="C:\Program Files\QuickTime Alternative\QTTask.exe" [2008-09-06 421888]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2008-09-15 920144]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 23040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Micronet Wireless Network Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Micronet Wireless Network Utility.lnk
backup=C:\WINDOWS\pss\Micronet Wireless Network Utility.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SATARAID5.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SATARAID5.lnk
backup=C:\WINDOWS\pss\SATARAID5.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 00:56 23040 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2007-03-11 21:34 57344 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2008-05-16 14:01 13529088 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2008-05-16 14:01 86016 C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
–a—— 2008-04-01 02:54 516096 C:\Program Files\Winamp Remote\bin\OrbTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2004-02-22 23:44 41073 C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2008-08-04 00:02 44032 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2008-05-16 14:01 1638400 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-ra—— 2005-06-20 14:42 86016 C:\WINDOWS\soundman.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Black Isle\\Baldur's Gate\\BGMain2.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\Black Isle\\BGII - SoA\\BGMain.exe"=
"C:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;C:\WINDOWS\system32\DRIVERS\nvcchflt.sys [2005-02-12 16640]
R0 pxark;pxark;C:\WINDOWS\system32\drivers\pxark.sys [2008-09-19 17408]
R0 Si3132r5;SiI-3132 SoftRaid 5 Controller;C:\WINDOWS\system32\DRIVERS\Si3132r5.sys [2005-04-19 181760]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-29 97928]
R2 AffinegyService;AffinegyService;C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe [2008-05-26 151552]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
R2 CSIScanner;CSIScanner;C:\Program Files\PrevxCSI\prevxcsi.exe [2008-09-19 618040]
R3 AFGSp50;AFGSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\AFGSp50.sys [2008-05-26 27072]
S3 AFGMp50;AFGMp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\AFGMp50.sys [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\autorun.exe
\Shell\directx\command - E:\DirectX9\dxsetup.exe
\Shell\setup\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Anonymous Mute\Application Data\Mozilla\Firefox\Profiles\hp1bb83z.default\
FF -: plugin - C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 5.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJava14.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPJPI142_04.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2_04\bin\NPOJI610.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPAdbESD.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-19 09:08:06
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
C:\WINDOWS\TEMP\d50b34c8-8fa5-42ec-ac76-68510b73a734.tmp 0 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Virgin Broadband Wireless\ndis_events.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-09-19 9:10:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-19 08:09:57
Pre-Run: 92,568,535,040 bytes free
Post-Run: 92,500,774,912 bytes free
295 — E O F — 2008-09-15 10:37:32
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:25:45, on 19/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {36DBC179-A19F-48F2-B16A-6A3E19B42A87} - C:\WINDOWS\system32\ipv6monl.dll
O2 - BHO: Rmn plugin - {47D92EB6-E52C-4cda-92A6-2369963F4913} - jetaccss.dll (file missing)
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5E7C73D1-2855-4D62-94D4-1CB98B0221FF} - C:\WINDOWS\system32\crypt3.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Wireless Manager] "C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" startup
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Winamp; Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1215515032654
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1215515372342
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
–
End of file - 7153 bytes
Malwarebytes' Anti-Malware 1.28
Database version: 1173
Windows 5.1.2600 Service Pack 2
19/09/2008 13:28:05
mbam-log-2008-09-19 (13-28-05).txt
Scan type: Quick Scan
Objects scanned: 47063
Time elapsed: 3 minute(s), 26 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{47d92eb6-e52c-4cda-92a6-2369963f4913} (Spyware.Banker) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{36dbc179-a19f-48f2-b16a-6a3e19b42a87} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{36dbc179-a19f-48f2-b16a-6a3e19b42a87} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5e7c73d1-2855-4d62-94d4-1cb98b0221ff} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MRSoft (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\WINDOWS\system32\wTR19 (Trojan.Agent) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\jetaccss.dll (Spyware.Banker) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\crypt3.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wTR19\wTR191065.exe (Trojan.Agent) -> Quarantined and deleted successfully.