dvdpenn
ComboFix 09-01-13.03 - David Penn 2009-01-13 15:41:38.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.638 [GMT -8:00]
Running from: d:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: d:\documents and settings\David Penn\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning enabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Created a new restore point
FILE ::
d:\windows\Tasks\bkeudwzr.job
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\windows\system32\autochk.dll
.
((((((((((((((((((((((((( Files Created from 2008-12-13 to 2009-01-13 )))))))))))))))))))))))))))))))
.
2009-01-04 19:48 . 2009-01-04 19:48 21,504 –ahs—- d:\documents and settings\Minquetta\protect.dll
2008-12-28 21:30 . 2008-12-28 21:30 21,504 –ahs—- d:\documents and settings\NetworkService.NT AUTHORITY\protect.dll
2008-12-22 06:21 . 2008-12-22 06:21 d——– d:\program files\Trend Micro
2008-12-21 20:05 . 2008-12-21 20:05 d——– d:\documents and settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-12-21 20:04 . 2008-12-21 20:04 d——– d:\program files\SUPERAntiSpyware
2008-12-21 20:04 . 2008-12-21 20:04 d——– d:\documents and settings\David Penn\Application Data\SUPERAntiSpyware.com
2008-12-21 19:31 . 2008-12-21 19:31 d——– d:\program files\Lavasoft
2008-12-21 19:31 . 2008-12-21 19:31 d——– d:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2008-12-21 16:16 . 2008-12-21 16:16 21,504 –ahs—- d:\documents and settings\LocalService.NT AUTHORITY\protect.dll
2008-12-21 15:52 . 2008-12-21 15:52 21,504 –ahs—- d:\documents and settings\David Penn\protect.dll
2008-12-20 18:56 . 2008-12-20 18:56 d——– d:\program files\Malwarebytes' Anti-Malware
2008-12-20 18:56 . 2008-12-20 18:56 d——– d:\documents and settings\David Penn\Application Data\Malwarebytes
2008-12-20 18:56 . 2008-12-20 18:56 d——– d:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-12-20 18:56 . 2008-12-03 19:53 38,496 –a—— d:\windows\system32\drivers\mbamswissarmy.sys
2008-12-20 18:56 . 2008-12-03 19:53 15,504 –a—— d:\windows\system32\drivers\mbam.sys
2008-12-20 18:09 . 2008-12-20 18:09 0 –a—— d:\windows\nsreg.dat
2008-12-20 18:08 . 2008-12-20 18:08 7,518,240 –a—— D:\Firefox Setup 3.0.5.exe
2008-12-18 06:20 . 2008-12-18 06:20 410,984 –a—— d:\windows\system32\deploytk.dll
2008-12-17 08:53 . 2008-12-17 08:53 d——– d:\documents and settings\All Users.WINDOWS\Application Data\1stWorks
2008-12-17 08:53 . 2007-03-12 14:02 947,472 –a—— d:\windows\system32\msjava.bak
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-13 23:35 68,706 —-a-w d:\documents and settings\David Penn\Application Data\wklnhst.dat
2009-01-13 22:33 ——— d—–w d:\program files\eSignal
2009-01-08 18:00 ——— d—–w d:\documents and settings\LocalService.NT AUTHORITY\Application Data\SACore
2008-12-30 03:05 61,200 —-a-w d:\documents and settings\David Penn\Application Data\GDIPFONTCACHEV1.DAT
2008-12-22 04:04 ——— d—–w d:\program files\Common Files\Wise Installation Wizard
2008-12-18 21:31 ——— d—–w d:\program files\McAfee
2008-12-18 14:19 ——— d—–w d:\program files\Java
2008-12-02 23:48 ——— d—–w d:\program files\Common Files\eSignal
2008-12-02 23:48 ——— d—–w d:\documents and settings\David Penn\Application Data\eSignal
2008-12-02 23:47 ——— d—–w d:\documents and settings\All Users.WINDOWS\Application Data\eSignal
2008-11-27 00:24 ——— d—–w d:\program files\AviSynth 2.5
2008-11-27 00:23 ——— d—–w d:\program files\eRightSoft
2008-10-23 12:36 286,720 —-a-w d:\windows\system32\gdi32.dll
2008-10-16 22:13 202,776 —-a-w d:\windows\system32\wuweb.dll
2008-10-16 22:13 1,809,944 —-a-w d:\windows\system32\wuaueng.dll
2008-10-16 22:12 561,688 —-a-w d:\windows\system32\wuapi.dll
2008-10-16 22:12 323,608 —-a-w d:\windows\system32\wucltui.dll
2008-10-16 22:09 92,696 —-a-w d:\windows\system32\cdm.dll
2008-10-16 22:09 51,224 —-a-w d:\windows\system32\wuauclt.exe
2008-10-16 22:09 43,544 —-a-w d:\windows\system32\wups2.dll
2008-10-16 22:08 34,328 —-a-w d:\windows\system32\wups.dll
2008-10-16 22:06 268,648 —-a-w d:\windows\system32\mucltui.dll
2008-10-16 22:06 208,744 —-a-w d:\windows\system32\muweb.dll
2008-10-16 20:38 826,368 —-a-w d:\windows\system32\wininet.dll
2008-05-21 23:00 3,193,272 —-a-w d:\program files\FileZilla_3.0.10_win32-setup.exe
2008-02-24 19:25 10,420,936 —-a-w d:\program files\xlviewer.exe
2008-01-01 01:49 53,419,796 —-a-w d:\program files\cap2demo.exe
2007-11-19 18:54 299,294,000 -c–a-w d:\program files\ADBEDRWVCS3_WWE.exe
2007-11-06 02:49 1,599,908 —-a-w d:\program files\FXChartInstall.EXE
2007-10-05 13:40 7,417,077 —-a-w d:\program files\FXTS2Install.EXE
2007-04-14 03:29 5,007,104 —-a-w d:\program files\GoogleVideoPlayerSetup.exe
.
((((((((((((((((((((((((((((( snapshot@2009-01-02_17.59.01.18 )))))))))))))))))))))))))))))))))))))))))
.
- 2000-08-31 16:00:00 28,672 —-a-w d:\windows\NIRCMD.exe
+ 2000-08-31 16:00:00 29,696 —-a-w d:\windows\NIRCMD.exe
- 2009-01-02 22:27:59 32,768 -c–a-w d:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-01-13 23:06:02 32,768 -c–a-w d:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-01-02 22:27:59 32,768 -c–a-w d:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-13 23:06:02 32,768 -c–a-w d:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-01-02 22:27:59 32,768 -c–a-w d:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-13 23:06:02 32,768 –sha-w d:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-20 22:20:53 3,380 —-a-w d:\windows\system32\Restore\rstrlog.dat
+ 2009-01-08 15:55:17 202,812 —-a-w d:\windows\system32\Restore\rstrlog.dat
+ 2009-01-13 22:59:18 16,384 —-atw d:\windows\Temp\Perflib_Perfdata_274.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="d:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-27 68856]
"MSMSGS"="d:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"AdobeUpdater"="d:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-11-10 2356088]
"SUPERAntiSpyware"="d:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-12-04 1809648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgrWired"="d:\program files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe" [2004-11-18 86016]
"SoundMAXPnP"="d:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"BJCFD"="d:\program files\BroadJump\Client Foundation\CFD.exe" [2001-10-18 483394]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2005-07-20 7110656]
"NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2005-07-20 86016]
"mcagent_exe"="d:\program files\McAfee.com\Agent\mcagent.exe" [2007-08-03 582992]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2008-12-18 136600]
"HP Software Update"="d:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2005-07-19 53248]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"UFC Media Manager Tray"="d:\program files\Entriq\MediaSphere\EntriqMediaTray.exe" [2008-01-08 374608]
"TkBellExe"="d:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-09 185872]
"nwiz"="nwiz.exe" [2005-07-20 d:\windows\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 d:\windows\LOGI_MWX.EXE]
d:\documents and settings\Minquetta\Start Menu\Programs\Startup\
ChkDisk.dll [2009-01-04 21504]
ChkDisk.lnk - d:\windows\system32\rundll32.exe [2004-08-04 33280]
d:\documents and settings\David Penn\Start Menu\Programs\Startup\
ChkDisk.dll [2008-12-21 21504]
ChkDisk.lnk - d:\windows\system32\rundll32.exe [2004-08-04 33280]
PowerReg Scheduler.exe [2008-01-25 256000]
d:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - d:\program files\Hp\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
Logitech Desktop Messenger.lnk - d:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-09-30 169472]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-03 14:56 352256 d:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Kontiki\\KService.exe"=
"d:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"d:\\Program Files\\eSignal\\winros.exe"=
R1 SASDIFSV;SASDIFSV;d:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-12-04 8944]
R1 SASKUTIL;SASKUTIL;d:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-12-04 55024]
R3 SASENUM;SASENUM;d:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
R4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;d:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-09-29 206096]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2008-01-22 d:\windows\Tasks\McDefragTask.job
- d:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-06-01 d:\windows\Tasks\McQcTask.job
- d:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2009-01-07 d:\windows\Tasks\WebReg Deskjet D4200 series.job
- d:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2007-03-11 21:27]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bloomberg.com/
uInternet Settings,ProxyOverride = *.local
IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage
FF - ProfilePath - d:\documents and settings\David Penn\Application Data\Mozilla\Firefox\Profiles\var9pw1w.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bloomberg.com/
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - component: d:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll
FF - plugin: d:\documents and settings\All Users.WINDOWS\Application Data\Entriq\UFC\3.8.0.24\npEntriqVersionCheckMozillaPlugin.dll
FF - plugin: d:\program files\Entriq\MediaSphere\3.8.0.24\npEntriqMediaMozillaPlugin.dll
FF - plugin: d:\program files\Entriq\MediaSphere\3.8.0.24\npEntriqVersionCheckMozillaPlugin.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-13 15:43:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(684)
d:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Completion time: 2009-01-13 15:45:17
ComboFix-quarantined-files.txt 2009-01-13 23:44:44
ComboFix2.txt 2009-01-13 22:57:35
ComboFix3.txt 2009-01-05 00:13:29
ComboFix4.txt 2009-01-03 02:30:03
ComboFix5.txt 2009-01-13 23:37:46
Pre-Run: 8,477,794,304 bytes free
Post-Run: 8,471,314,432 bytes free
194 — E O F — 2008-12-19 06:13:55
*
HiJack This
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:46:49 PM, on 1/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
D:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
D:\Program Files\Kontiki\KService.exe
D:\Program Files\BroadJump\Client Foundation\CFD.exe
D:\Program Files\McAfee.com\Agent\mcagent.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
D:\Program Files\McAfee\SiteAdvisor\McSACore.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Logitech\MouseWare\system\em_exec.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
D:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
d:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
d:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
D:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
D:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
D:\Program Files\McAfee\MPF\MPFSrv.exe
d:\PROGRA~1\mcafee\msc\mcuimgr.exe
D:\WINDOWS\system32\notepad.exe
D:\WINDOWS\system32\imapi.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bloomberg.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - D:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - D:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: del.icio.us Toolbar Helper - {7AA07AE6-01EF-44EC-93CA-9D7CD41CCDB6} - D:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - d:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar2.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - D:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: del.icio.us - {981FE6A8-260C-4930-960F-C3BC82746CB0} - D:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - D:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - d:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [PRONoMgrWired] D:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [SoundMAXPnP] D:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [BJCFD] D:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mcagent_exe] D:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UFC Media Manager Tray] "D:\Program Files\Entriq\MediaSphere\EntriqMediaTray.exe" /CustomId:UFC
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AdobeUpdater] "D:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: ChkDisk.dll
O4 - Startup: ChkDisk.lnk = ?
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: StumbleUpon - {75C9223A-409A-4795-A3CA-08DE6B075B4B} - D:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1201040555057
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1201040615260
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - d:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - D:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KService - Unknown owner - D:\Program Files\Kontiki\KService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - D:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - D:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - d:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - D:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - d:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - D:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - D:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - D:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
–
End of file - 10069 bytes
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.638 [GMT -8:00]
Running from: d:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: d:\documents and settings\David Penn\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning enabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Created a new restore point
FILE ::
d:\windows\Tasks\bkeudwzr.job
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\windows\system32\autochk.dll
.
((((((((((((((((((((((((( Files Created from 2008-12-13 to 2009-01-13 )))))))))))))))))))))))))))))))
.
2009-01-04 19:48 . 2009-01-04 19:48 21,504 –ahs—- d:\documents and settings\Minquetta\protect.dll
2008-12-28 21:30 . 2008-12-28 21:30 21,504 –ahs—- d:\documents and settings\NetworkService.NT AUTHORITY\protect.dll
2008-12-22 06:21 . 2008-12-22 06:21 d——– d:\program files\Trend Micro
2008-12-21 20:05 . 2008-12-21 20:05 d——– d:\documents and settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-12-21 20:04 . 2008-12-21 20:04 d——– d:\program files\SUPERAntiSpyware
2008-12-21 20:04 . 2008-12-21 20:04 d——– d:\documents and settings\David Penn\Application Data\SUPERAntiSpyware.com
2008-12-21 19:31 . 2008-12-21 19:31 d——– d:\program files\Lavasoft
2008-12-21 19:31 . 2008-12-21 19:31 d——– d:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2008-12-21 16:16 . 2008-12-21 16:16 21,504 –ahs—- d:\documents and settings\LocalService.NT AUTHORITY\protect.dll
2008-12-21 15:52 . 2008-12-21 15:52 21,504 –ahs—- d:\documents and settings\David Penn\protect.dll
2008-12-20 18:56 . 2008-12-20 18:56 d——– d:\program files\Malwarebytes' Anti-Malware
2008-12-20 18:56 . 2008-12-20 18:56 d——– d:\documents and settings\David Penn\Application Data\Malwarebytes
2008-12-20 18:56 . 2008-12-20 18:56 d——– d:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-12-20 18:56 . 2008-12-03 19:53 38,496 –a—— d:\windows\system32\drivers\mbamswissarmy.sys
2008-12-20 18:56 . 2008-12-03 19:53 15,504 –a—— d:\windows\system32\drivers\mbam.sys
2008-12-20 18:09 . 2008-12-20 18:09 0 –a—— d:\windows\nsreg.dat
2008-12-20 18:08 . 2008-12-20 18:08 7,518,240 –a—— D:\Firefox Setup 3.0.5.exe
2008-12-18 06:20 . 2008-12-18 06:20 410,984 –a—— d:\windows\system32\deploytk.dll
2008-12-17 08:53 . 2008-12-17 08:53 d——– d:\documents and settings\All Users.WINDOWS\Application Data\1stWorks
2008-12-17 08:53 . 2007-03-12 14:02 947,472 –a—— d:\windows\system32\msjava.bak
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-13 23:35 68,706 —-a-w d:\documents and settings\David Penn\Application Data\wklnhst.dat
2009-01-13 22:33 ——— d—–w d:\program files\eSignal
2009-01-08 18:00 ——— d—–w d:\documents and settings\LocalService.NT AUTHORITY\Application Data\SACore
2008-12-30 03:05 61,200 —-a-w d:\documents and settings\David Penn\Application Data\GDIPFONTCACHEV1.DAT
2008-12-22 04:04 ——— d—–w d:\program files\Common Files\Wise Installation Wizard
2008-12-18 21:31 ——— d—–w d:\program files\McAfee
2008-12-18 14:19 ——— d—–w d:\program files\Java
2008-12-02 23:48 ——— d—–w d:\program files\Common Files\eSignal
2008-12-02 23:48 ——— d—–w d:\documents and settings\David Penn\Application Data\eSignal
2008-12-02 23:47 ——— d—–w d:\documents and settings\All Users.WINDOWS\Application Data\eSignal
2008-11-27 00:24 ——— d—–w d:\program files\AviSynth 2.5
2008-11-27 00:23 ——— d—–w d:\program files\eRightSoft
2008-10-23 12:36 286,720 —-a-w d:\windows\system32\gdi32.dll
2008-10-16 22:13 202,776 —-a-w d:\windows\system32\wuweb.dll
2008-10-16 22:13 1,809,944 —-a-w d:\windows\system32\wuaueng.dll
2008-10-16 22:12 561,688 —-a-w d:\windows\system32\wuapi.dll
2008-10-16 22:12 323,608 —-a-w d:\windows\system32\wucltui.dll
2008-10-16 22:09 92,696 —-a-w d:\windows\system32\cdm.dll
2008-10-16 22:09 51,224 —-a-w d:\windows\system32\wuauclt.exe
2008-10-16 22:09 43,544 —-a-w d:\windows\system32\wups2.dll
2008-10-16 22:08 34,328 —-a-w d:\windows\system32\wups.dll
2008-10-16 22:06 268,648 —-a-w d:\windows\system32\mucltui.dll
2008-10-16 22:06 208,744 —-a-w d:\windows\system32\muweb.dll
2008-10-16 20:38 826,368 —-a-w d:\windows\system32\wininet.dll
2008-05-21 23:00 3,193,272 —-a-w d:\program files\FileZilla_3.0.10_win32-setup.exe
2008-02-24 19:25 10,420,936 —-a-w d:\program files\xlviewer.exe
2008-01-01 01:49 53,419,796 —-a-w d:\program files\cap2demo.exe
2007-11-19 18:54 299,294,000 -c–a-w d:\program files\ADBEDRWVCS3_WWE.exe
2007-11-06 02:49 1,599,908 —-a-w d:\program files\FXChartInstall.EXE
2007-10-05 13:40 7,417,077 —-a-w d:\program files\FXTS2Install.EXE
2007-04-14 03:29 5,007,104 —-a-w d:\program files\GoogleVideoPlayerSetup.exe
.
((((((((((((((((((((((((((((( snapshot@2009-01-02_17.59.01.18 )))))))))))))))))))))))))))))))))))))))))
.
- 2000-08-31 16:00:00 28,672 —-a-w d:\windows\NIRCMD.exe
+ 2000-08-31 16:00:00 29,696 —-a-w d:\windows\NIRCMD.exe
- 2009-01-02 22:27:59 32,768 -c–a-w d:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-01-13 23:06:02 32,768 -c–a-w d:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-01-02 22:27:59 32,768 -c–a-w d:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-13 23:06:02 32,768 -c–a-w d:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-01-02 22:27:59 32,768 -c–a-w d:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-13 23:06:02 32,768 –sha-w d:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-20 22:20:53 3,380 —-a-w d:\windows\system32\Restore\rstrlog.dat
+ 2009-01-08 15:55:17 202,812 —-a-w d:\windows\system32\Restore\rstrlog.dat
+ 2009-01-13 22:59:18 16,384 —-atw d:\windows\Temp\Perflib_Perfdata_274.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="d:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-27 68856]
"MSMSGS"="d:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"AdobeUpdater"="d:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-11-10 2356088]
"SUPERAntiSpyware"="d:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-12-04 1809648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgrWired"="d:\program files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe" [2004-11-18 86016]
"SoundMAXPnP"="d:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"BJCFD"="d:\program files\BroadJump\Client Foundation\CFD.exe" [2001-10-18 483394]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2005-07-20 7110656]
"NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2005-07-20 86016]
"mcagent_exe"="d:\program files\McAfee.com\Agent\mcagent.exe" [2007-08-03 582992]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2008-12-18 136600]
"HP Software Update"="d:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2005-07-19 53248]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"UFC Media Manager Tray"="d:\program files\Entriq\MediaSphere\EntriqMediaTray.exe" [2008-01-08 374608]
"TkBellExe"="d:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-09 185872]
"nwiz"="nwiz.exe" [2005-07-20 d:\windows\system32\nwiz.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 d:\windows\LOGI_MWX.EXE]
d:\documents and settings\Minquetta\Start Menu\Programs\Startup\
ChkDisk.dll [2009-01-04 21504]
ChkDisk.lnk - d:\windows\system32\rundll32.exe [2004-08-04 33280]
d:\documents and settings\David Penn\Start Menu\Programs\Startup\
ChkDisk.dll [2008-12-21 21504]
ChkDisk.lnk - d:\windows\system32\rundll32.exe [2004-08-04 33280]
PowerReg Scheduler.exe [2008-01-25 256000]
d:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - d:\program files\Hp\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
Logitech Desktop Messenger.lnk - d:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-09-30 169472]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-03 14:56 352256 d:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Kontiki\\KService.exe"=
"d:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"d:\\Program Files\\eSignal\\winros.exe"=
R1 SASDIFSV;SASDIFSV;d:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-12-04 8944]
R1 SASKUTIL;SASKUTIL;d:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-12-04 55024]
R3 SASENUM;SASENUM;d:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
R4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;d:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-09-29 206096]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2008-01-22 d:\windows\Tasks\McDefragTask.job
- d:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-06-01 d:\windows\Tasks\McQcTask.job
- d:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2009-01-07 d:\windows\Tasks\WebReg Deskjet D4200 series.job
- d:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2007-03-11 21:27]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bloomberg.com/
uInternet Settings,ProxyOverride = *.local
IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage
FF - ProfilePath - d:\documents and settings\David Penn\Application Data\Mozilla\Firefox\Profiles\var9pw1w.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bloomberg.com/
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - component: d:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll
FF - plugin: d:\documents and settings\All Users.WINDOWS\Application Data\Entriq\UFC\3.8.0.24\npEntriqVersionCheckMozillaPlugin.dll
FF - plugin: d:\program files\Entriq\MediaSphere\3.8.0.24\npEntriqMediaMozillaPlugin.dll
FF - plugin: d:\program files\Entriq\MediaSphere\3.8.0.24\npEntriqVersionCheckMozillaPlugin.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-13 15:43:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(684)
d:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Completion time: 2009-01-13 15:45:17
ComboFix-quarantined-files.txt 2009-01-13 23:44:44
ComboFix2.txt 2009-01-13 22:57:35
ComboFix3.txt 2009-01-05 00:13:29
ComboFix4.txt 2009-01-03 02:30:03
ComboFix5.txt 2009-01-13 23:37:46
Pre-Run: 8,477,794,304 bytes free
Post-Run: 8,471,314,432 bytes free
194 — E O F — 2008-12-19 06:13:55
*
HiJack This
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:46:49 PM, on 1/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
D:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
D:\Program Files\Kontiki\KService.exe
D:\Program Files\BroadJump\Client Foundation\CFD.exe
D:\Program Files\McAfee.com\Agent\mcagent.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
D:\Program Files\McAfee\SiteAdvisor\McSACore.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Logitech\MouseWare\system\em_exec.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
D:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
d:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
d:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
D:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
D:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
D:\Program Files\McAfee\MPF\MPFSrv.exe
d:\PROGRA~1\mcafee\msc\mcuimgr.exe
D:\WINDOWS\system32\notepad.exe
D:\WINDOWS\system32\imapi.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bloomberg.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - D:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - D:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: del.icio.us Toolbar Helper - {7AA07AE6-01EF-44EC-93CA-9D7CD41CCDB6} - D:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - d:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar2.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - D:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: del.icio.us - {981FE6A8-260C-4930-960F-C3BC82746CB0} - D:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - D:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - d:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [PRONoMgrWired] D:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [SoundMAXPnP] D:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [BJCFD] D:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mcagent_exe] D:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UFC Media Manager Tray] "D:\Program Files\Entriq\MediaSphere\EntriqMediaTray.exe" /CustomId:UFC
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AdobeUpdater] "D:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: ChkDisk.dll
O4 - Startup: ChkDisk.lnk = ?
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: StumbleUpon - {75C9223A-409A-4795-A3CA-08DE6B075B4B} - D:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1201040555057
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1201040615260
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - d:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - D:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KService - Unknown owner - D:\Program Files\Kontiki\KService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - D:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - D:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - d:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - D:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - d:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - D:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - D:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - D:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
–
End of file - 10069 bytes