Rickrides
Topic Starter
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:40:26 PM, on 12/30/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL
= http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://toolbar.aol.com/uninstall.html?base…=tb50-ie-holida
y&browser=ie&instd=27-11-2008
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName
=
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no
file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} -
C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: NRA - {CC0D77AF-731A-4C50-A69D-2BC36ED01A97} - C:\Program
Files\NRA\Toolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware
Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program
Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra button: Create Mobile Favorite -
{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} -
C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -
C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… -
{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -
C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7}
- C:\Program Files\Hewlett-Packard\Smart Web
Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select -
{700259D7-1666-479a-93B1-3250410481E8} - C:\Program
Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games
ActiveX Control) -
http://disney.go.com/pirates/online/testAc…gned/DisneyOnli
neGames.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
-
http://www.update.microsoft.com/microsoftu…trols/en/x86/cl
ient/wuweb_site.cab?1209170590968
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
-
http://www.update.microsoft.com/microsoftu…trols/en/x86/cl
ient/muweb_site.cab?1209170581578
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash
Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} -
http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) -
http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology
Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown
owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner
- C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program
Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA
Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools -
C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools -
C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software,
Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
Here is the combo fix log
ComboFix 08-12-29.02 - Administrator 2008-12-30 15:00:55.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.571 [GMT -8:00]
Running from: F:\ComboFix.exe
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\temp\tn3
c:\windows\system32\a.exe
c:\windows\system32\akgajepj.dll
c:\windows\system32\AutoRun.inf
c:\windows\system32\bajuwuge.dll
c:\windows\system32\bgqtetil.ini
c:\windows\system32\cmtxga.dll
c:\windows\system32\domfpr.dll
c:\windows\system32\drivers\fad.sys
c:\windows\system32\dtsgiroi.dll
c:\windows\system32\duisorvk.ini
c:\windows\system32\egfNUvut.ini
c:\windows\system32\egfNUvut.ini2
c:\windows\system32\eqwpdwiw.dll
c:\windows\system32\fijeoa.dll
c:\windows\system32\gavuzeyi.dll
c:\windows\system32\gsfwfxyj.dll
c:\windows\system32\hpowiax3.dll
c:\windows\system32\iorigstd.ini
c:\windows\system32\jituwuwa.dll
c:\windows\system32\kgmbyy.dll
c:\windows\system32\kipnhg.dll
c:\windows\system32\llcqyb.dll
c:\windows\system32\lpoycr.dll
c:\windows\system32\mhqmkxud.dll
c:\windows\system32\miwajiho.dll
c:\windows\SYSTEM32\mlJDwULE.dll
c:\windows\system32\nnnkJDSm.dll
c:\windows\system32\ntbotibu.dll
c:\windows\system32\orumohuw.ini
c:\windows\system32\qadambhk.dll
c:\windows\system32\rapepute.dll
c:\windows\system32\rqBbdfii.ini
c:\windows\system32\rqBbdfii.ini2
c:\windows\system32\sfbipkgb.dll
c:\windows\system32\sosilore.dll
c:\windows\system32\TDSSmtvd.dat
c:\windows\system32\tojedela.dll
c:\windows\system32\tuhinibo.dll
c:\windows\system32\tuvUNfge.dll
c:\windows\system32\vDKmlnnn.ini
c:\windows\system32\vDKmlnnn.ini2
c:\windows\system32\vtULdBQI.dll
c:\windows\system32\vxljaf.dll
c:\windows\system32\wgkajfdo.dll
c:\windows\system32\wirulxaj.dll
c:\windows\system32\wrxkmwie.dll
c:\windows\system32\xacIkUtv.ini
c:\windows\system32\xacIkUtv.ini2
c:\windows\system32\xsqbop.dll
c:\windows\system32\xwwamtdw.ini
c:\windows\system32\xxywUOHW.dll
c:\windows\system32\xxyxUlIa.dll
c:\windows\system32\xyfcckta.ini
c:\windows\system32\yajosofo.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_TNIDRIVER
——-\Service_TnIDriver
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-30 )))))))))))))))))))))))))))))))
.
2008-12-30 14:22 . 2008-12-30 14:22 d——– C:\VundoFix Backups
2008-12-30 13:05 . 2008-12-30 13:05 d——– c:\documents and settings\Rick\Application Data\Malwarebytes
2008-12-30 13:05 . 2008-12-30 13:05 72,192 –a—— c:\windows\system32\ddcCVLda.dll
2008-12-30 11:05 . 2008-12-30 11:05 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-30 11:05 . 2008-12-30 11:05 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-30 11:05 . 2008-12-30 11:05 d——– c:\documents and settings\Administrator.JULIE-D50TB0WUH\Application Data\Malwarebytes
2008-12-30 11:05 . 2008-12-03 19:54 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-30 11:05 . 2008-12-03 19:54 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-30 09:24 . 2008-12-30 09:24 d——– c:\program files\Trend Micro
2008-12-30 08:01 . 2008-12-30 08:01 d–hs—- c:\documents and settings\LocalService\PrivacIE
2008-12-30 00:21 . 2008-12-30 00:21 d——– c:\program files\CCleaner
2008-12-29 16:45 . 2008-12-29 16:45 d——– c:\documents and settings\Rick\Application Data\PC Tools
2008-12-29 16:45 . 2008-12-29 16:45 d——– c:\documents and settings\All Users\Application Data\PC Tools
2008-12-29 16:45 . 2008-07-28 12:29 160,792 –a—— c:\windows\system32\drivers\pctfw2.sys
2008-12-29 13:30 . 2008-12-29 13:30 d–hs—- c:\documents and settings\Julie\PrivacIE
2008-12-28 22:32 . 2008-04-13 16:12 82,432 –ah—t- c:\windows\system32\2d38355a.dll
2008-12-28 22:32 . 2008-04-13 16:12 82,432 –ah—t- c:\windows\system32\14270c4.dll
2008-12-28 22:20 . 2008-12-28 22:20 d–hs—- c:\documents and settings\Rick\PrivacIE
2008-12-28 22:12 . 2008-12-28 22:14 d–h-c— c:\windows\ie8
2008-12-28 21:15 . 2008-12-28 21:15 d——– c:\documents and settings\Rick\Application Data\HPAppData
2008-12-28 21:15 . 2008-12-28 21:15 d——– c:\documents and settings\All Users\Application Data\HPSSUPPLY
2008-12-28 21:12 . 2008-12-28 21:12 d——– c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-12-28 21:08 . 2008-12-28 21:20 141,188 –a—— c:\windows\hpoins14.dat
2008-12-28 21:08 . 2007-09-19 17:14 2,000 ——— c:\windows\hpomdl14.dat
2008-12-28 16:13 . 2008-12-28 16:13 d——– c:\documents and settings\All Users\Application Data\McAfee
2008-12-28 16:01 . 2008-12-30 15:07 d——– c:\program files\Spyware Doctor
2008-12-28 16:01 . 2008-08-25 12:36 81,288 –a—— c:\windows\system32\drivers\iksyssec.sys
2008-12-28 16:01 . 2008-08-25 12:36 66,952 –a—— c:\windows\system32\drivers\iksysflt.sys
2008-12-28 16:01 . 2008-08-25 12:36 40,840 –a—— c:\windows\system32\drivers\ikfilesec.sys
2008-12-28 16:01 . 2008-06-02 16:19 29,576 –a—— c:\windows\system32\drivers\kcom.sys
2008-12-28 15:54 . 2008-12-28 15:54 d——– c:\program files\Webroot
2008-12-28 15:54 . 2008-12-28 15:54 d——– c:\program files\Common Files\Webroot Shared
2008-12-28 15:54 . 2008-12-28 15:54 d——– c:\documents and settings\Julie\Application Data\Webroot
2008-12-28 15:54 . 2008-12-28 15:54 d——– c:\documents and settings\All Users\Application Data\Webroot
2008-12-28 15:54 . 2007-11-26 14:47 194,888 –a—— c:\windows\Unwash6.exe
2008-12-28 15:03 . 2008-04-13 11:39 14,592 –a—— c:\windows\system32\drivers\kbdhid.sys
2008-12-28 12:40 . 2008-12-28 16:01 d——– c:\documents and settings\Julie\Application Data\PC Tools
2008-12-24 16:41 . 2008-12-24 16:41 d——– c:\program files\2WIRE, Inc
2008-12-24 16:41 . 2006-08-24 13:44 477,696 –a—— c:\windows\system32\drivers\ZD1211BU.sys
2008-12-24 16:41 . 2004-01-14 11:25 81,920 –a—— c:\windows\system32\ZDPN50.DLL
2008-12-24 16:41 . 2005-03-18 15:35 31,744 –a—— c:\windows\system32\drivers\ZDPSp50a64.sys
2008-12-24 16:41 . 2005-06-08 18:44 29,184 –a—— c:\windows\system32\drivers\BRGSp50a64.sys
2008-12-24 16:41 . 2004-03-23 16:38 28,672 –a—— c:\windows\system32\InsDrvZD.dll
2008-12-24 16:41 . 2003-03-14 12:24 24,576 –a—— c:\windows\system32\ZyDelReg.exe
2008-12-24 16:41 . 2005-06-08 18:44 20,608 –a—— c:\windows\system32\drivers\BRGSp50.sys
2008-12-24 16:41 . 2004-10-25 13:40 17,664 –a—— c:\windows\system32\drivers\ZDPSp50.sys
2008-12-24 16:41 . 2004-01-14 11:30 17,151 –a—— c:\windows\system32\ZDPNDIS5.SYS
2008-12-24 16:41 . 2005-07-12 14:44 15,872 –a—— c:\windows\system32\InsDrvZD64.DLL
2008-12-24 15:29 . 2008-12-24 15:29 d——– c:\documents and settings\Administrator.JULIE-D50TB0WUH\Application Data\Apple Computer
2008-12-23 14:55 . 2008-12-29 16:45 d——– c:\program files\Common Files\PC Tools
2008-12-23 14:55 . 2008-12-30 15:08 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-21 16:14 . 2008-12-22 17:33 d——– c:\documents and settings\Administrator.JULIE-D50TB0WUH\Application Data\Lavasoft
2008-12-20 16:16 . 2008-12-20 16:16 d——– c:\documents and settings\Administrator.JULIE-D50TB0WUH\Application Data\alot
2008-12-20 15:37 . 2008-12-30 13:02 d——– c:\documents and settings\Administrator.JULIE-D50TB0WUH
2008-12-20 14:56 . 2008-12-20 14:56 d——– c:\temp\REX81
2008-12-20 14:55 . 2008-12-30 10:51 d——– c:\windows\system32\cap2
2008-12-20 14:55 . 2008-12-20 14:56 d——– c:\windows\system32\ain
2008-12-20 14:55 . 2008-12-30 15:01 d——– C:\Temp
2008-12-17 21:04 . 2008-12-17 21:04 d——– c:\documents and settings\Julie\Application Data\Snapfish
2008-12-17 20:57 . 2008-12-17 20:57 d——– c:\documents and settings\Julie\Application Data\W Photo Studio
2008-12-17 20:56 . 2008-12-17 20:56 d——– c:\program files\Walgreens
2008-12-17 20:56 . 2008-12-17 20:56 d——– c:\documents and settings\Julie\Application Data\Walgreens
2008-12-17 20:56 . 2008-12-17 20:56 d——– c:\documents and settings\All Users\Application Data\Walgreens
2008-12-17 20:43 . 2008-12-17 20:56 d——– c:\documents and settings\Julie\Application Data\W Photo Studio Viewer
2008-12-11 10:44 . 2008-12-11 10:44 d——– c:\program files\DjToneXpress
2008-12-10 22:39 . 2007-03-17 08:11 303,104 -ra—— c:\windows\system32\hpovst10.dll
2008-12-10 22:24 . 2008-12-10 22:24 d——– c:\documents and settings\Rick\Application Data\HP
2008-12-07 13:43 . 2008-12-07 13:43 d——– C:\spoolerlogs
2008-12-06 08:42 . 2008-12-06 08:42 d——– c:\program files\NRA
2008-12-05 18:17 . 2008-12-30 00:31 d——– C:\Nexon
2008-12-05 18:17 . 2008-12-05 18:35 d——– c:\documents and settings\All Users\Application Data\NexonUS
2008-12-02 17:05 . 2008-12-02 17:05 d——– c:\documents and settings\Rick\Application Data\acccore
2008-12-01 21:59 . 2008-12-01 21:59 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-01 21:57 . 2008-12-01 21:57 d——– c:\program files\QuickTime
2008-11-27 02:16 . 2008-11-27 02:16 d——– c:\documents and settings\Julie\Application Data\HP
2008-11-23 22:45 . 2008-11-23 22:45 d——– c:\program files\MSXML 4.0
2008-11-23 21:14 . 2008-11-23 21:14 d——– c:\program files\MSECache
2008-11-23 00:39 . 2008-11-23 00:39 197,976 -ra—— c:\windows\cpnprt2.cid
2008-11-22 22:00 . 2008-11-22 22:00 d——– c:\documents and settings\All Users\Application Data\WEBREG
2008-11-22 21:56 . 2008-12-28 21:12 d——– c:\documents and settings\All Users\Application Data\HP
2008-11-22 21:55 . 2008-11-22 21:55 d——– c:\program files\Common Files\HP
2008-11-22 21:54 . 2008-12-28 21:15 d——– c:\program files\HP
2008-11-22 21:53 . 2008-11-22 21:53 d——– c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-11-22 21:52 . 2007-03-17 08:11 569,344 -ra—— c:\windows\system32\hpotscl3.dll
2008-11-22 21:52 . 2007-03-07 20:20 364,544 -ra—— c:\windows\system32\hppldcoi.dll
2008-11-22 21:52 . 2007-03-07 20:20 309,760 -ra—— c:\windows\system32\difxapi.dll
2008-11-22 21:52 . 2007-03-30 07:07 267,864 -ra—— c:\windows\system32\hpzids01.dll
2008-11-22 21:52 . 2007-03-28 14:01 117,760 –a—— c:\windows\system32\hpzll5ha.dll
2008-11-11 20:50 . 2008-09-04 09:15 1,106,944 —–c— c:\windows\system32\dllcache\msxml3.dll
2008-11-11 20:50 . 2008-10-24 03:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-08 21:26 . 2008-11-08 21:26 d——– c:\program files\Apple Software Update
2008-11-05 18:05 . 2008-11-05 18:05 d——– c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2008-11-04 10:30 . 2008-11-04 10:30 90,112 –a—— c:\windows\system32\QuickTimeVR.qtx
2008-11-04 10:30 . 2008-11-04 10:30 57,344 –a—— c:\windows\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-30 21:27 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-30 21:22 ——— d—–w c:\documents and settings\All Users\Application Data\PCPitstop
2008-12-30 08:24 ——— d—–w c:\documents and settings\Rick\Application Data\Lavasoft
2008-12-29 05:15 ——— d—–w c:\program files\Hewlett-Packard
2008-12-29 04:41 ——— d—–w c:\program files\Yahoo!
2008-12-29 04:04 ——— d—–w c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-25 00:41 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-23 01:33 ——— d—–w c:\documents and settings\Administrator\Application Data\Lavasoft
2008-12-23 00:56 ——— d—–w c:\program files\Google
2008-12-23 00:52 ——— d—–w c:\program files\Common Files\Apple
2008-12-23 00:49 ——— d—–w c:\program files\Java
2008-12-22 00:12 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2008-12-20 23:41 ——— d—–w c:\program files\Common Files\AOL
2008-12-06 07:59 ——— d—–w c:\documents and settings\Rick\Application Data\EVEMon
2008-12-05 04:48 ——— d—–w c:\documents and settings\Julie\Application Data\Move Networks
2008-12-02 06:00 ——— d—–w c:\program files\iTunes
2008-12-02 05:59 ——— d—–w c:\program files\iPod
2008-11-26 00:37 29,704 —-a-w c:\documents and settings\Julie\Application Data\GDIPFONTCACHEV1.DAT
2008-11-01 16:07 ——— d—–w c:\documents and settings\All Users\Application Data\nView_Profiles
2008-06-02 06:10 186 —ha-w c:\documents and settings\Julie\Application Data\hpothb07.dat
2008-09-22 06:05 68,608 –sha-w c:\windows\system32\zerejuhu.dll
2008-05-21 12:37 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008052120080522\index.dat
2008-08-03 15:15 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080320080804\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CC0D77AF-731A-4C50-A69D-2BC36ED01A97}"= "c:\program files\NRA\Toolbar.dll" [2008-12-06 1249280]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-08-25 1168264]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ctmp3"= c:\windows\System32\ctmp3.acm
path=
backup=
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SnagIt 8.lnk]
backup=c:\windows\pss\SnagIt 8.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2006-10-22 12:22 7700480 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\CCP\\EVE\\bin\\ExeFile.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\EVEMon\\EVEMon.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 pctfw2;pctfw2;\??\c:\windows\system32\drivers\pctfw2.sys [2008-12-29 160792]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-12-28 356920]
S1 HPZius122;HPZius122;c:\windows\system32\drivers\HPZius122.sys []
S2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2008-09-26 566120]
S2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2008-09-26 566120]
S2 Viewpoint Manager Service;Viewpoint Manager Service; []
S2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [2008-12-28 598856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2008-12-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-12-30 c:\windows\Tasks\drpjnsxc.job
- c:\windows\SYSTEM32\rundll32.exe [2008-04-13 16:12]
2008-12-18 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 13:21]
2008-12-30 c:\windows\Tasks\wpdvqbmu.job
- c:\windows\SYSTEM32\rundll32.exe [2008-04-13 16:12]
.
- - - - ORPHANS REMOVED - - - -
BHO-{ABA8CE4E-D190-4184-A252-10451F857EDD} - c:\windows\system32\tuvUNfge.dll
BHO-{AD884304-1F74-4CD1-928A-C128F6DA07FD} - c:\windows\system32\nnnlmKDv.dll
BHO-{ce51ca11-ba7d-4c49-8633-2061b30eee63} - c:\windows\system32\domfpr.dll
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = hxxp://toolbar.aol.com/uninstall.html?baseinvocationtype=tb50-ie-holiday&browser=ie&instd=27-11-2008
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
O16 -: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
c:\windows\Downloaded Program Files\imikimi_cab.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-30 15:07:46
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(784)
c:\windows\System32\ctmp3.acm
.
———————— Other Running Processes ————————
.
c:\program files\Spyware Doctor\pctsSvc.exe
.
**************************************************************************
.
Completion time: 2008-12-30 15:10:42 - machine was rebooted [Administrator]
ComboFix-quarantined-files.txt 2008-12-30 23:10:40
Pre-Run: 44,107,530,240 bytes free
Post-Run: 43,981,017,088 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
299 — E O F — 2008-12-18 07:17:25
Scan saved at 3:40:26 PM, on 12/30/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL
= http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://toolbar.aol.com/uninstall.html?base…=tb50-ie-holida
y&browser=ie&instd=27-11-2008
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName
=
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no
file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} -
C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: NRA - {CC0D77AF-731A-4C50-A69D-2BC36ED01A97} - C:\Program
Files\NRA\Toolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware
Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program
Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra button: Create Mobile Favorite -
{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} -
C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -
C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… -
{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -
C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7}
- C:\Program Files\Hewlett-Packard\Smart Web
Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select -
{700259D7-1666-479a-93B1-3250410481E8} - C:\Program
Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games
ActiveX Control) -
http://disney.go.com/pirates/online/testAc…gned/DisneyOnli
neGames.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
-
http://www.update.microsoft.com/microsoftu…trols/en/x86/cl
ient/wuweb_site.cab?1209170590968
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
-
http://www.update.microsoft.com/microsoftu…trols/en/x86/cl
ient/muweb_site.cab?1209170581578
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash
Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} -
http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) -
http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology
Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown
owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner
- C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program
Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA
Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools -
C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools -
C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software,
Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
Here is the combo fix log
ComboFix 08-12-29.02 - Administrator 2008-12-30 15:00:55.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.571 [GMT -8:00]
Running from: F:\ComboFix.exe
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\temp\tn3
c:\windows\system32\a.exe
c:\windows\system32\akgajepj.dll
c:\windows\system32\AutoRun.inf
c:\windows\system32\bajuwuge.dll
c:\windows\system32\bgqtetil.ini
c:\windows\system32\cmtxga.dll
c:\windows\system32\domfpr.dll
c:\windows\system32\drivers\fad.sys
c:\windows\system32\dtsgiroi.dll
c:\windows\system32\duisorvk.ini
c:\windows\system32\egfNUvut.ini
c:\windows\system32\egfNUvut.ini2
c:\windows\system32\eqwpdwiw.dll
c:\windows\system32\fijeoa.dll
c:\windows\system32\gavuzeyi.dll
c:\windows\system32\gsfwfxyj.dll
c:\windows\system32\hpowiax3.dll
c:\windows\system32\iorigstd.ini
c:\windows\system32\jituwuwa.dll
c:\windows\system32\kgmbyy.dll
c:\windows\system32\kipnhg.dll
c:\windows\system32\llcqyb.dll
c:\windows\system32\lpoycr.dll
c:\windows\system32\mhqmkxud.dll
c:\windows\system32\miwajiho.dll
c:\windows\SYSTEM32\mlJDwULE.dll
c:\windows\system32\nnnkJDSm.dll
c:\windows\system32\ntbotibu.dll
c:\windows\system32\orumohuw.ini
c:\windows\system32\qadambhk.dll
c:\windows\system32\rapepute.dll
c:\windows\system32\rqBbdfii.ini
c:\windows\system32\rqBbdfii.ini2
c:\windows\system32\sfbipkgb.dll
c:\windows\system32\sosilore.dll
c:\windows\system32\TDSSmtvd.dat
c:\windows\system32\tojedela.dll
c:\windows\system32\tuhinibo.dll
c:\windows\system32\tuvUNfge.dll
c:\windows\system32\vDKmlnnn.ini
c:\windows\system32\vDKmlnnn.ini2
c:\windows\system32\vtULdBQI.dll
c:\windows\system32\vxljaf.dll
c:\windows\system32\wgkajfdo.dll
c:\windows\system32\wirulxaj.dll
c:\windows\system32\wrxkmwie.dll
c:\windows\system32\xacIkUtv.ini
c:\windows\system32\xacIkUtv.ini2
c:\windows\system32\xsqbop.dll
c:\windows\system32\xwwamtdw.ini
c:\windows\system32\xxywUOHW.dll
c:\windows\system32\xxyxUlIa.dll
c:\windows\system32\xyfcckta.ini
c:\windows\system32\yajosofo.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_TNIDRIVER
——-\Service_TnIDriver
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-30 )))))))))))))))))))))))))))))))
.
2008-12-30 14:22 . 2008-12-30 14:22 d——– C:\VundoFix Backups
2008-12-30 13:05 . 2008-12-30 13:05 d——– c:\documents and settings\Rick\Application Data\Malwarebytes
2008-12-30 13:05 . 2008-12-30 13:05 72,192 –a—— c:\windows\system32\ddcCVLda.dll
2008-12-30 11:05 . 2008-12-30 11:05 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-30 11:05 . 2008-12-30 11:05 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-30 11:05 . 2008-12-30 11:05 d——– c:\documents and settings\Administrator.JULIE-D50TB0WUH\Application Data\Malwarebytes
2008-12-30 11:05 . 2008-12-03 19:54 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-30 11:05 . 2008-12-03 19:54 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-30 09:24 . 2008-12-30 09:24 d——– c:\program files\Trend Micro
2008-12-30 08:01 . 2008-12-30 08:01 d–hs—- c:\documents and settings\LocalService\PrivacIE
2008-12-30 00:21 . 2008-12-30 00:21 d——– c:\program files\CCleaner
2008-12-29 16:45 . 2008-12-29 16:45 d——– c:\documents and settings\Rick\Application Data\PC Tools
2008-12-29 16:45 . 2008-12-29 16:45 d——– c:\documents and settings\All Users\Application Data\PC Tools
2008-12-29 16:45 . 2008-07-28 12:29 160,792 –a—— c:\windows\system32\drivers\pctfw2.sys
2008-12-29 13:30 . 2008-12-29 13:30 d–hs—- c:\documents and settings\Julie\PrivacIE
2008-12-28 22:32 . 2008-04-13 16:12 82,432 –ah—t- c:\windows\system32\2d38355a.dll
2008-12-28 22:32 . 2008-04-13 16:12 82,432 –ah—t- c:\windows\system32\14270c4.dll
2008-12-28 22:20 . 2008-12-28 22:20 d–hs—- c:\documents and settings\Rick\PrivacIE
2008-12-28 22:12 . 2008-12-28 22:14 d–h-c— c:\windows\ie8
2008-12-28 21:15 . 2008-12-28 21:15 d——– c:\documents and settings\Rick\Application Data\HPAppData
2008-12-28 21:15 . 2008-12-28 21:15 d——– c:\documents and settings\All Users\Application Data\HPSSUPPLY
2008-12-28 21:12 . 2008-12-28 21:12 d——– c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-12-28 21:08 . 2008-12-28 21:20 141,188 –a—— c:\windows\hpoins14.dat
2008-12-28 21:08 . 2007-09-19 17:14 2,000 ——— c:\windows\hpomdl14.dat
2008-12-28 16:13 . 2008-12-28 16:13 d——– c:\documents and settings\All Users\Application Data\McAfee
2008-12-28 16:01 . 2008-12-30 15:07 d——– c:\program files\Spyware Doctor
2008-12-28 16:01 . 2008-08-25 12:36 81,288 –a—— c:\windows\system32\drivers\iksyssec.sys
2008-12-28 16:01 . 2008-08-25 12:36 66,952 –a—— c:\windows\system32\drivers\iksysflt.sys
2008-12-28 16:01 . 2008-08-25 12:36 40,840 –a—— c:\windows\system32\drivers\ikfilesec.sys
2008-12-28 16:01 . 2008-06-02 16:19 29,576 –a—— c:\windows\system32\drivers\kcom.sys
2008-12-28 15:54 . 2008-12-28 15:54 d——– c:\program files\Webroot
2008-12-28 15:54 . 2008-12-28 15:54 d——– c:\program files\Common Files\Webroot Shared
2008-12-28 15:54 . 2008-12-28 15:54 d——– c:\documents and settings\Julie\Application Data\Webroot
2008-12-28 15:54 . 2008-12-28 15:54 d——– c:\documents and settings\All Users\Application Data\Webroot
2008-12-28 15:54 . 2007-11-26 14:47 194,888 –a—— c:\windows\Unwash6.exe
2008-12-28 15:03 . 2008-04-13 11:39 14,592 –a—— c:\windows\system32\drivers\kbdhid.sys
2008-12-28 12:40 . 2008-12-28 16:01 d——– c:\documents and settings\Julie\Application Data\PC Tools
2008-12-24 16:41 . 2008-12-24 16:41 d——– c:\program files\2WIRE, Inc
2008-12-24 16:41 . 2006-08-24 13:44 477,696 –a—— c:\windows\system32\drivers\ZD1211BU.sys
2008-12-24 16:41 . 2004-01-14 11:25 81,920 –a—— c:\windows\system32\ZDPN50.DLL
2008-12-24 16:41 . 2005-03-18 15:35 31,744 –a—— c:\windows\system32\drivers\ZDPSp50a64.sys
2008-12-24 16:41 . 2005-06-08 18:44 29,184 –a—— c:\windows\system32\drivers\BRGSp50a64.sys
2008-12-24 16:41 . 2004-03-23 16:38 28,672 –a—— c:\windows\system32\InsDrvZD.dll
2008-12-24 16:41 . 2003-03-14 12:24 24,576 –a—— c:\windows\system32\ZyDelReg.exe
2008-12-24 16:41 . 2005-06-08 18:44 20,608 –a—— c:\windows\system32\drivers\BRGSp50.sys
2008-12-24 16:41 . 2004-10-25 13:40 17,664 –a—— c:\windows\system32\drivers\ZDPSp50.sys
2008-12-24 16:41 . 2004-01-14 11:30 17,151 –a—— c:\windows\system32\ZDPNDIS5.SYS
2008-12-24 16:41 . 2005-07-12 14:44 15,872 –a—— c:\windows\system32\InsDrvZD64.DLL
2008-12-24 15:29 . 2008-12-24 15:29 d——– c:\documents and settings\Administrator.JULIE-D50TB0WUH\Application Data\Apple Computer
2008-12-23 14:55 . 2008-12-29 16:45 d——– c:\program files\Common Files\PC Tools
2008-12-23 14:55 . 2008-12-30 15:08 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-21 16:14 . 2008-12-22 17:33 d——– c:\documents and settings\Administrator.JULIE-D50TB0WUH\Application Data\Lavasoft
2008-12-20 16:16 . 2008-12-20 16:16 d——– c:\documents and settings\Administrator.JULIE-D50TB0WUH\Application Data\alot
2008-12-20 15:37 . 2008-12-30 13:02 d——– c:\documents and settings\Administrator.JULIE-D50TB0WUH
2008-12-20 14:56 . 2008-12-20 14:56 d——– c:\temp\REX81
2008-12-20 14:55 . 2008-12-30 10:51 d——– c:\windows\system32\cap2
2008-12-20 14:55 . 2008-12-20 14:56 d——– c:\windows\system32\ain
2008-12-20 14:55 . 2008-12-30 15:01 d——– C:\Temp
2008-12-17 21:04 . 2008-12-17 21:04 d——– c:\documents and settings\Julie\Application Data\Snapfish
2008-12-17 20:57 . 2008-12-17 20:57 d——– c:\documents and settings\Julie\Application Data\W Photo Studio
2008-12-17 20:56 . 2008-12-17 20:56 d——– c:\program files\Walgreens
2008-12-17 20:56 . 2008-12-17 20:56 d——– c:\documents and settings\Julie\Application Data\Walgreens
2008-12-17 20:56 . 2008-12-17 20:56 d——– c:\documents and settings\All Users\Application Data\Walgreens
2008-12-17 20:43 . 2008-12-17 20:56 d——– c:\documents and settings\Julie\Application Data\W Photo Studio Viewer
2008-12-11 10:44 . 2008-12-11 10:44 d——– c:\program files\DjToneXpress
2008-12-10 22:39 . 2007-03-17 08:11 303,104 -ra—— c:\windows\system32\hpovst10.dll
2008-12-10 22:24 . 2008-12-10 22:24 d——– c:\documents and settings\Rick\Application Data\HP
2008-12-07 13:43 . 2008-12-07 13:43 d——– C:\spoolerlogs
2008-12-06 08:42 . 2008-12-06 08:42 d——– c:\program files\NRA
2008-12-05 18:17 . 2008-12-30 00:31 d——– C:\Nexon
2008-12-05 18:17 . 2008-12-05 18:35 d——– c:\documents and settings\All Users\Application Data\NexonUS
2008-12-02 17:05 . 2008-12-02 17:05 d——– c:\documents and settings\Rick\Application Data\acccore
2008-12-01 21:59 . 2008-12-01 21:59 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-01 21:57 . 2008-12-01 21:57 d——– c:\program files\QuickTime
2008-11-27 02:16 . 2008-11-27 02:16 d——– c:\documents and settings\Julie\Application Data\HP
2008-11-23 22:45 . 2008-11-23 22:45 d——– c:\program files\MSXML 4.0
2008-11-23 21:14 . 2008-11-23 21:14 d——– c:\program files\MSECache
2008-11-23 00:39 . 2008-11-23 00:39 197,976 -ra—— c:\windows\cpnprt2.cid
2008-11-22 22:00 . 2008-11-22 22:00 d——– c:\documents and settings\All Users\Application Data\WEBREG
2008-11-22 21:56 . 2008-12-28 21:12 d——– c:\documents and settings\All Users\Application Data\HP
2008-11-22 21:55 . 2008-11-22 21:55 d——– c:\program files\Common Files\HP
2008-11-22 21:54 . 2008-12-28 21:15 d——– c:\program files\HP
2008-11-22 21:53 . 2008-11-22 21:53 d——– c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-11-22 21:52 . 2007-03-17 08:11 569,344 -ra—— c:\windows\system32\hpotscl3.dll
2008-11-22 21:52 . 2007-03-07 20:20 364,544 -ra—— c:\windows\system32\hppldcoi.dll
2008-11-22 21:52 . 2007-03-07 20:20 309,760 -ra—— c:\windows\system32\difxapi.dll
2008-11-22 21:52 . 2007-03-30 07:07 267,864 -ra—— c:\windows\system32\hpzids01.dll
2008-11-22 21:52 . 2007-03-28 14:01 117,760 –a—— c:\windows\system32\hpzll5ha.dll
2008-11-11 20:50 . 2008-09-04 09:15 1,106,944 —–c— c:\windows\system32\dllcache\msxml3.dll
2008-11-11 20:50 . 2008-10-24 03:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-08 21:26 . 2008-11-08 21:26 d——– c:\program files\Apple Software Update
2008-11-05 18:05 . 2008-11-05 18:05 d——– c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2008-11-04 10:30 . 2008-11-04 10:30 90,112 –a—— c:\windows\system32\QuickTimeVR.qtx
2008-11-04 10:30 . 2008-11-04 10:30 57,344 –a—— c:\windows\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-30 21:27 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-30 21:22 ——— d—–w c:\documents and settings\All Users\Application Data\PCPitstop
2008-12-30 08:24 ——— d—–w c:\documents and settings\Rick\Application Data\Lavasoft
2008-12-29 05:15 ——— d—–w c:\program files\Hewlett-Packard
2008-12-29 04:41 ——— d—–w c:\program files\Yahoo!
2008-12-29 04:04 ——— d—–w c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-25 00:41 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-23 01:33 ——— d—–w c:\documents and settings\Administrator\Application Data\Lavasoft
2008-12-23 00:56 ——— d—–w c:\program files\Google
2008-12-23 00:52 ——— d—–w c:\program files\Common Files\Apple
2008-12-23 00:49 ——— d—–w c:\program files\Java
2008-12-22 00:12 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2008-12-20 23:41 ——— d—–w c:\program files\Common Files\AOL
2008-12-06 07:59 ——— d—–w c:\documents and settings\Rick\Application Data\EVEMon
2008-12-05 04:48 ——— d—–w c:\documents and settings\Julie\Application Data\Move Networks
2008-12-02 06:00 ——— d—–w c:\program files\iTunes
2008-12-02 05:59 ——— d—–w c:\program files\iPod
2008-11-26 00:37 29,704 —-a-w c:\documents and settings\Julie\Application Data\GDIPFONTCACHEV1.DAT
2008-11-01 16:07 ——— d—–w c:\documents and settings\All Users\Application Data\nView_Profiles
2008-06-02 06:10 186 —ha-w c:\documents and settings\Julie\Application Data\hpothb07.dat
2008-09-22 06:05 68,608 –sha-w c:\windows\system32\zerejuhu.dll
2008-05-21 12:37 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008052120080522\index.dat
2008-08-03 15:15 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080320080804\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CC0D77AF-731A-4C50-A69D-2BC36ED01A97}"= "c:\program files\NRA\Toolbar.dll" [2008-12-06 1249280]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-08-25 1168264]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ctmp3"= c:\windows\System32\ctmp3.acm
path=
backup=
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SnagIt 8.lnk]
backup=c:\windows\pss\SnagIt 8.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2006-10-22 12:22 7700480 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\CCP\\EVE\\bin\\ExeFile.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\EVEMon\\EVEMon.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 pctfw2;pctfw2;\??\c:\windows\system32\drivers\pctfw2.sys [2008-12-29 160792]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-12-28 356920]
S1 HPZius122;HPZius122;c:\windows\system32\drivers\HPZius122.sys []
S2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2008-09-26 566120]
S2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2008-09-26 566120]
S2 Viewpoint Manager Service;Viewpoint Manager Service; []
S2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [2008-12-28 598856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2008-12-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-12-30 c:\windows\Tasks\drpjnsxc.job
- c:\windows\SYSTEM32\rundll32.exe [2008-04-13 16:12]
2008-12-18 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 13:21]
2008-12-30 c:\windows\Tasks\wpdvqbmu.job
- c:\windows\SYSTEM32\rundll32.exe [2008-04-13 16:12]
.
- - - - ORPHANS REMOVED - - - -
BHO-{ABA8CE4E-D190-4184-A252-10451F857EDD} - c:\windows\system32\tuvUNfge.dll
BHO-{AD884304-1F74-4CD1-928A-C128F6DA07FD} - c:\windows\system32\nnnlmKDv.dll
BHO-{ce51ca11-ba7d-4c49-8633-2061b30eee63} - c:\windows\system32\domfpr.dll
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = hxxp://toolbar.aol.com/uninstall.html?baseinvocationtype=tb50-ie-holiday&browser=ie&instd=27-11-2008
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
O16 -: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
c:\windows\Downloaded Program Files\imikimi_cab.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-30 15:07:46
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(784)
c:\windows\System32\ctmp3.acm
.
———————— Other Running Processes ————————
.
c:\program files\Spyware Doctor\pctsSvc.exe
.
**************************************************************************
.
Completion time: 2008-12-30 15:10:42 - machine was rebooted [Administrator]
ComboFix-quarantined-files.txt 2008-12-30 23:10:40
Pre-Run: 44,107,530,240 bytes free
Post-Run: 43,981,017,088 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
299 — E O F — 2008-12-18 07:17:25