Pinqvin
2008-04-09, 13:24
So yes, I got this nasty little guy too. Now I've noticed where I got it from and shall hate IE and programs that use IE (this is how I got it) for the rest of my life even more... But anyways, I think I've gotten to the clear waters now, but just want to make sure, since I'm not really good with analyzing hijackthis and ComboFix logs. Well, here they are:
HijackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:11:06, on 9.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Comodo\Firewall\cfp.exe
C:\WINDOWS\system32\kxmixer.exe
C:\PROGRA~1\RCrawler\RCrawler.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
G:\steam\steam.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
C:\Program Files\MAL Updater\MalUpdater.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Hamachi\hamachi.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
E:\Last.fm\LastFMHelper.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\sessmgr.exe
E:\VMware\VMware Player\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [kX Mixer] C:\WINDOWS\system32\kxmixer.exe --startup
O4 - HKLM\..\Run: [Registry Crawler] C:\PROGRA~1\RCrawler\RCrawler.exe -TRAYONLY
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [d4309e3f] rundll32.exe "C:\WINDOWS\system32\mcycjpgm.dll",b
O4 - HKLM\..\Run: Rundll32.exe "C:\WINDOWS\system32\gkaqkdyi.dll",s
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [Steam] "g:\steam\steam.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKCU\..\Run: [XPize Reloader] C:\WINDOWS\XPize\XPizeReloader.exe /S
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [MalUpdater] C:\Program Files\MAL Updater\MalUpdater.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: AutorunsDisabled
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Startup: Last.fm Helper.lnk = E:\Last.fm\LastFMHelper.exe
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: Wowhead Client.lnk = C:\Program Files\Wowhead Client\Wowhead_Client.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5CE72DD0-4695-4D18-A4D3-3367ACD37578} (F-Secure Health Check 1.0) - http://support.f-secure.com/enu/home/onlineservices/fshc/fscax.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1159389203490
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: qoMggffg - qoMggffg.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - E:\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: VNC Server (winvnc) - TightVNC Group - C:\Program Files\TightVNC\WinVNC.exe
--
End of file - 10512 bytes
ComboFix:
ComboFix 08-04-08.9 - Juuso 2008-04-09 12:56:05.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2414 [GMT 3:00]
Running from: C:\Documents and Settings\Juuso\Desktop\ComboFix.exe
[b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMd703ada3.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\FeghPqru.ini
C:\WINDOWS\system32\FeghPqru.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-09 to 2008-04-09 )))))))))))))))))))))))))))))))
.
2008-04-09 11:04 . 2008-04-09 11:04 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\AVG7
2008-04-09 11:00 . 2008-04-09 11:00 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-09 11:00 . 2008-04-09 11:02 <DIR> d-------- C:\Documents and Settings\Juuso\Application Data\AVG7
2008-04-09 10:59 . 2008-04-09 10:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-09 08:20 . 2008-04-09 10:23 294 --ahs---- C:\WINDOWS\system32\mgpjcycm.ini
2008-04-09 08:11 . 2008-04-09 08:11 3,648 --a------ C:\WINDOWS\system32\mauwgyiy.dll
2008-04-08 11:44 . 2008-04-08 12:09 <DIR> d-------- C:\Program Files\Avidemux 2.4
2008-04-08 08:27 . 2008-04-09 10:23 558 --a------ C:\WINDOWS\wininit.ini
2008-04-08 08:06 . 2008-04-08 08:06 294 --ahs---- C:\WINDOWS\system32\kcaggtbb.ini
2008-04-07 20:01 . 2008-04-07 20:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
2008-04-07 20:01 . 2006-03-29 08:51 1,060,864 --a------ C:\WINDOWS\system32\MFC79abd.rra
2008-04-07 20:01 . 2006-03-29 08:50 671,744 --a------ C:\WINDOWS\system32\DolbyHph.dll
2008-04-07 20:01 . 2006-03-29 08:51 499,712 --a------ C:\WINDOWS\system32\msvc9c14.rra
2008-04-07 20:01 . 2006-03-29 08:51 60,416 --a------ C:\WINDOWS\system32\DSETUP.dll
2008-04-07 20:01 . 2006-03-29 08:49 9,856 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2008-04-07 20:01 . 2006-05-05 19:21 4,608 --a------ C:\WINDOWS\system32\drivers\nvport.sys
2008-04-07 19:21 . 2008-04-07 19:21 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-07 19:07 . 2008-04-07 19:07 <DIR> d-------- C:\WINDOWS\nvidia icons
2008-04-07 17:27 . 2008-04-09 12:38 <DIR> d-------- C:\Program Files\DVBViewer
2008-04-07 17:27 . 2008-04-07 17:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CMUV
2008-04-07 16:46 . 2008-04-07 17:31 <DIR> d-------- C:\Program Files\Common Files\TerraTec
2008-04-07 16:44 . 2004-08-03 23:10 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
2008-04-07 16:41 . 2004-08-04 00:56 363,520 --a------ C:\WINDOWS\system32\PsisDecd.dll
2008-04-07 16:11 . 2008-04-07 17:30 <DIR> d-------- C:\Documents and Settings\Juuso\Application Data\TerraTec
2008-04-07 16:09 . 2008-04-07 16:09 <DIR> d-------- C:\TerraTec
2008-04-05 01:02 . 2008-04-05 01:02 <DIR> d-------- C:\Program Files\QT Lite
2008-04-05 01:02 . 2008-03-28 21:07 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-04-05 01:02 . 2008-03-28 21:07 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-04-03 12:28 . 2008-04-09 11:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-03-28 00:38 . 2008-03-28 00:38 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-03-26 17:09 . 2008-03-26 17:09 <DIR> d-------- C:\Logs
2008-03-24 02:06 . 2006-10-26 20:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-03-24 02:05 . 2008-03-24 02:05 <DIR> d-------- C:\Program Files\Microsoft Works
2008-03-24 02:03 . 2008-03-24 02:03 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-03-24 02:01 . 2008-03-24 03:57 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-03-24 02:01 . 2008-03-24 02:01 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-03-24 02:00 . 2008-03-24 02:00 <DIR> dr-h----- C:\MSOCache
2008-03-22 14:20 . 2008-03-22 14:20 <DIR> d-------- C:\Documents and Settings\Juuso\Application Data\InstallShield Installation Information
2008-03-22 13:00 . 2008-03-22 13:00 22,328 --a------ C:\Documents and Settings\Juuso\Application Data\PnkBstrK.sys
2008-03-22 12:59 . 2008-03-22 12:59 669,184 --a------ C:\WINDOWS\system32\pbsvc.exe
2008-03-20 20:30 . 2008-03-20 20:30 <DIR> d-------- C:\Program Files\Futuremark
2008-03-20 17:55 . 2008-03-20 17:55 <DIR> d-------- C:\NVIDIA
2008-03-20 17:55 . 2008-03-24 19:52 442,368 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-03-20 17:55 . 2008-03-24 19:52 17,937 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-03-19 17:06 . 2008-03-19 17:13 <DIR> d-------- C:\Documents and Settings\Juuso\Application Data\Irssi
2008-03-17 19:20 . 2008-03-17 19:20 <DIR> d-------- C:\Program Files\AMX Mod X
2008-03-14 16:41 . 2008-03-14 16:42 <DIR> d-------- C:\Program Files\OpenOffice.org 2.3
2008-03-14 16:40 . 2008-03-14 16:40 <DIR> d-------- C:\Program Files\Windows Installer Clean Up
2008-03-14 16:40 . 2008-03-14 16:40 <DIR> d-------- C:\Program Files\MSECACHE
2008-03-12 14:10 . 2008-03-12 14:10 633,344 --a------ C:\WINDOWS\system32\gpprefcl.dll
2008-03-10 17:29 . 2008-03-10 17:31 <DIR> d-------- C:\Program Files\RCrawler
2008-03-09 23:40 . 2002-07-17 10:20 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL
2008-03-09 23:40 . 2002-07-17 09:53 16,877 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
2008-03-09 23:40 . 2002-07-17 17:22 5,600 --a------ C:\WINDOWS\system\WINASPI.DLL
2008-03-09 23:40 . 2002-07-17 17:22 4,672 --a------ C:\WINDOWS\system\WOWPOST.EXE
2008-03-09 22:14 . 2008-03-09 22:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TrackMania United
2008-03-09 08:04 . 2008-03-09 14:23 <DIR> d-------- C:\Downloads
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-09 10:04 --------- d-----w C:\Documents and Settings\Juuso\Application Data\OpenOffice.org2
2008-04-09 10:04 --------- d-----w C:\Documents and Settings\Juuso\Application Data\Hamachi
2008-04-09 10:03 --------- d-----w C:\Documents and Settings\LocalService\Application Data\VMware
2008-04-09 10:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\VMware
2008-04-09 08:55 --------- d-----w C:\Program Files\RegScrubXP
2008-04-09 08:30 --------- d-----w C:\Program Files\Wowhead Client
2008-04-09 07:27 --------- d-----w C:\Documents and Settings\Juuso\Application Data\uTorrent
2008-04-09 07:27 --------- d-----w C:\Documents and Settings\Juuso\Application Data\foobar2000
2008-04-08 19:32 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-04-08 11:19 --------- d-----w C:\Program Files\MAL Updater
2008-04-08 09:09 --------- d-----w C:\Documents and Settings\Juuso\Application Data\gtk-2.0
2008-04-08 09:05 --------- d-----w C:\Program Files\megui
2008-04-08 04:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-07 17:01 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-04-04 22:02 --------- d-----w C:\Documents and Settings\Juuso\Application Data\Apple Computer
2008-04-04 22:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-04 14:15 --------- d-----w C:\Documents and Settings\Juuso\Application Data\MegauploadToolbar
2008-04-01 15:45 --------- d-----w C:\Program Files\HLSW
2008-03-31 09:32 --------- d-----w C:\Program Files\AlbumArtDownloader
2008-03-29 15:40 118,784 ----a-w C:\WINDOWS\SeaMonkeyUninstall.exe
2008-03-29 15:40 118,784 ----a-w C:\WINDOWS\GREUninstall.exe
2008-03-28 12:23 --------- d-----w C:\Program Files\Java
2008-03-28 12:22 85,752 ----a-w C:\WINDOWS\system32\drivers\cmdGuard.sys
2008-03-27 21:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-25 20:25 --------- d-----w C:\Program Files\mIRC
2008-03-25 16:01 --------- d-----w C:\Program Files\Azureus
2008-03-25 14:30 --------- d-----w C:\Program Files\Driver Cleaner Pro
2008-03-25 07:20 --------- d-----w C:\Program Files\DAEMON Tools Pro
2008-03-24 08:27 442,368 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2008-03-23 23:04 --------- d-----w C:\Program Files\MSBuild
2008-03-23 22:44 --------- d-----w C:\Documents and Settings\Juuso\Application Data\Azureus
2008-03-23 10:15 --------- d-----w C:\Documents and Settings\Juuso\Application Data\AdobeUM
2008-03-22 21:01 --------- d-----w C:\Program Files\PogoSticker
2008-03-22 18:35 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-03-22 18:34 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-22 09:59 66,872 ----a-w C:\WINDOWS\system32\pnkbstra.exe
2008-03-21 14:40 223,424 ----a-w C:\WINDOWS\system32\drivers\truecrypt.sys
2008-03-20 17:31 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-03-20 13:37 8,192 ----a-w C:\WINDOWS\system32\tsbyuv.dll
2008-03-19 18:39 --------- d-----w C:\Documents and Settings\Juuso\Application Data\Bioshock
2008-03-15 12:58 --------- d-----w C:\Program Files\Opera
2008-03-15 12:57 --------- d-----w C:\Program Files\MediaCoder
2008-03-14 22:51 23,800 ----a-w C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-03-14 22:51 139,008 ----a-w C:\WINDOWS\system32\guard32.dll
2008-03-14 22:10 --------- d-----w C:\Documents and Settings\Juuso\Application Data\Notepad++
2008-03-11 06:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-09 20:30 --------- d-----w C:\Program Files\Exact Audio Copy
2008-03-08 18:39 --------- d-----w C:\Program Files\LimeWire
2008-03-08 10:54 --------- d-----w C:\Program Files\kX Audio Driver
2008-03-08 10:20 --------- d-----w C:\Program Files\kX Project
2008-03-04 01:05 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-03-02 09:59 --------- d-----w C:\Program Files\uTorrent
2008-02-26 21:00 --------- d-----w C:\Program Files\TaskSwitchXP
2008-02-26 20:57 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-02-17 08:59 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-15 13:24 --------- d-----w C:\Program Files\Audacity
2008-02-15 13:22 --------- d-----w C:\Program Files\MusicBrainz Picard
2008-02-10 09:13 --------- d-----w C:\Program Files\foobar2000
2008-02-04 15:26 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-01-11 23:07 61,177 ----a-w C:\WINDOWS\system32\x264vfw-uninstall.exe
2007-06-14 22:24 338,253 ----a-w C:\Documents and Settings\Juuso\SNW_2.1.18_CBT.exe
2007-05-20 09:24 3,166,492 ----a-w C:\Documents and Settings\Juuso\Visual Studio.net_2003_pro_full.exe
2007-02-27 10:58 2,265,507 ----a-w C:\Documents and Settings\Juuso\WoW-2.0.8.6403-to-0.0.10.6422-enGB-patch.exe
2006-06-23 06:48 32,768 -c--a-r C:\WINDOWS\inf\UpdateUSB.exe
.
------- Sigcheck -------
2007-06-13 13:23 950784 7dab450e1e61e9e9c1663e76f75ed911 C:\WINDOWS\explorer.exe
2007-06-13 14:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 13:23 950784 7dab450e1e61e9e9c1663e76f75ed911 C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 13:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\XPize\Backup\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@={30351346-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@={30351347-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@={30351348-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@={3035134B-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@={3035134C-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@={3035134D-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@={3035134E-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 10:11 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 10:11 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 10:11 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 10:11 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 10:11 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 10:11 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 10:11 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:00 30208]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 20:25 81920]
"Steam"="g:\steam\steam.exe" [2008-03-28 15:56 1271032]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-03 16:54 486856]
"XPize Reloader"="C:\WINDOWS\XPize\XPizeReloader.exe" [2007-08-17 21:03 114338]
"TaskSwitchXP"="C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-05 01:29 62976]
"MalUpdater"="C:\Program Files\MAL Updater\MalUpdater.exe" [2008-04-08 12:08 1427968]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45 313472]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-04-01 18:35 3587120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidTool.exe" [2006-06-02 16:45 385024]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 16:40 155648]
"WinVNC"="C:\Program Files\TightVNC\WinVNC.exe" [2007-05-07 19:28 589824]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 15:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 15:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 15:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 15:00 455168]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\cfp.exe" [2008-03-15 01:50 1503488]
"kX Mixer"="C:\WINDOWS\system32\kxmixer.exe" [2007-08-24 16:28 500224]
"Registry Crawler"="C:\PROGRA~1\RCrawler\RCrawler.exe" [2004-02-03 10:06 454656]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-03-24 19:52 13524992]
"nwiz"="nwiz.exe" [2008-03-24 19:52 1626112 C:\WINDOWS\system32\nwiz.exe]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 08:00 33648]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-03-24 19:52 86016]
"d4309e3f"="C:\WINDOWS\system32\mcycjpgm.dll" [ ]
"BMd703ada3"="C:\WINDOWS\system32\gkaqkdyi.dll" [ ]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-09 11:00 579072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15:00 30208]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-04-09 11:00 219136]
C:\Documents and Settings\Juuso\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-12-31 22:07:49 624416]
Last.fm Helper.lnk - E:\Last.fm\LastFMHelper.exe [2007-06-28 19:02:25 106496]
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-11-14 18:32:04 393216]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Wowhead Client.lnk - C:\Program Files\Wowhead Client\Wowhead_Client.exe [2008-04-09 11:30:29 165376]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qoMggffg]
qoMggffg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\WINDOWS\system32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"E:\\The All-Seeing Eye\\eye.exe"=
"E:\\Last.fm\\LastFM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"G:\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"G:\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"C:\\WINDOWS\\system32\\pnkbstra.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"G:\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-03-28 15:22]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-03-15 01:51]
R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;C:\Program Files\ASTRA32\ASTRA32.sys [2007-02-22 12:28]
R3 kxwdmdrv;kX WDM Driver Service;C:\WINDOWS\system32\drivers\kx.sys [2007-08-24 16:28]
R3 MTSBDA;Cinergy C BDA service;C:\WINDOWS\system32\DRIVERS\MtsBda.sys [2007-09-30 13:53]
R3 MtsHID;Cinergy C/S2 PCI HID service;C:\WINDOWS\system32\DRIVERS\MtsHid.sys [2006-09-04 14:45]
S3 Ext2FS;Ext2FS;C:\WINDOWS\system32\drivers\Ext2FS.sys [2004-01-23 19:34]
S3 libusb0;LibUsb-Win32 - Kernel Driver 03/09/2005, 0.1.10.1;C:\WINDOWS\system32\DRIVERS\libusb0.sys [2005-03-09 13:50]
S3 PsSdk30;PsSdk30;C:\WINDOWS\system32\Drivers\PsSdk30.drv []
.
Contents of the 'Scheduled Tasks' folder
"2008-04-05 02:10:14 C:\WINDOWS\Tasks\JkDefragCmd.job"
- G:\JkDefrag\JkDefragCmd.exe
"2008-04-09 06:00:00 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-09 13:04:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PsSdk30]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\PsSdk30.drv"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\sessmgr.exe
E:\VMware\VMware Player\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\vmnetdhcp.exe
.
**************************************************************************
.
Completion time: 2008-04-09 13:07:39 - machine was rebooted [Juuso]
ComboFix-quarantined-files.txt 2008-04-09 10:07:35
Pre-Run: 5,387,120,640 bytes free
Post-Run: 5,270,896,640 bytes free
.
2008-04-09 08:44:05 --- E O F ---
HijackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:11:06, on 9.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Comodo\Firewall\cfp.exe
C:\WINDOWS\system32\kxmixer.exe
C:\PROGRA~1\RCrawler\RCrawler.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
G:\steam\steam.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
C:\Program Files\MAL Updater\MalUpdater.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Hamachi\hamachi.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
E:\Last.fm\LastFMHelper.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\sessmgr.exe
E:\VMware\VMware Player\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [kX Mixer] C:\WINDOWS\system32\kxmixer.exe --startup
O4 - HKLM\..\Run: [Registry Crawler] C:\PROGRA~1\RCrawler\RCrawler.exe -TRAYONLY
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [d4309e3f] rundll32.exe "C:\WINDOWS\system32\mcycjpgm.dll",b
O4 - HKLM\..\Run: Rundll32.exe "C:\WINDOWS\system32\gkaqkdyi.dll",s
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [Steam] "g:\steam\steam.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKCU\..\Run: [XPize Reloader] C:\WINDOWS\XPize\XPizeReloader.exe /S
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [MalUpdater] C:\Program Files\MAL Updater\MalUpdater.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: AutorunsDisabled
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Startup: Last.fm Helper.lnk = E:\Last.fm\LastFMHelper.exe
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: Wowhead Client.lnk = C:\Program Files\Wowhead Client\Wowhead_Client.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5CE72DD0-4695-4D18-A4D3-3367ACD37578} (F-Secure Health Check 1.0) - http://support.f-secure.com/enu/home/onlineservices/fshc/fscax.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1159389203490
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: qoMggffg - qoMggffg.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - E:\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: VNC Server (winvnc) - TightVNC Group - C:\Program Files\TightVNC\WinVNC.exe
--
End of file - 10512 bytes
ComboFix:
ComboFix 08-04-08.9 - Juuso 2008-04-09 12:56:05.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2414 [GMT 3:00]
Running from: C:\Documents and Settings\Juuso\Desktop\ComboFix.exe
[b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMd703ada3.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\FeghPqru.ini
C:\WINDOWS\system32\FeghPqru.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-09 to 2008-04-09 )))))))))))))))))))))))))))))))
.
2008-04-09 11:04 . 2008-04-09 11:04 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\AVG7
2008-04-09 11:00 . 2008-04-09 11:00 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-09 11:00 . 2008-04-09 11:02 <DIR> d-------- C:\Documents and Settings\Juuso\Application Data\AVG7
2008-04-09 10:59 . 2008-04-09 10:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-09 08:20 . 2008-04-09 10:23 294 --ahs---- C:\WINDOWS\system32\mgpjcycm.ini
2008-04-09 08:11 . 2008-04-09 08:11 3,648 --a------ C:\WINDOWS\system32\mauwgyiy.dll
2008-04-08 11:44 . 2008-04-08 12:09 <DIR> d-------- C:\Program Files\Avidemux 2.4
2008-04-08 08:27 . 2008-04-09 10:23 558 --a------ C:\WINDOWS\wininit.ini
2008-04-08 08:06 . 2008-04-08 08:06 294 --ahs---- C:\WINDOWS\system32\kcaggtbb.ini
2008-04-07 20:01 . 2008-04-07 20:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
2008-04-07 20:01 . 2006-03-29 08:51 1,060,864 --a------ C:\WINDOWS\system32\MFC79abd.rra
2008-04-07 20:01 . 2006-03-29 08:50 671,744 --a------ C:\WINDOWS\system32\DolbyHph.dll
2008-04-07 20:01 . 2006-03-29 08:51 499,712 --a------ C:\WINDOWS\system32\msvc9c14.rra
2008-04-07 20:01 . 2006-03-29 08:51 60,416 --a------ C:\WINDOWS\system32\DSETUP.dll
2008-04-07 20:01 . 2006-03-29 08:49 9,856 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2008-04-07 20:01 . 2006-05-05 19:21 4,608 --a------ C:\WINDOWS\system32\drivers\nvport.sys
2008-04-07 19:21 . 2008-04-07 19:21 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-07 19:07 . 2008-04-07 19:07 <DIR> d-------- C:\WINDOWS\nvidia icons
2008-04-07 17:27 . 2008-04-09 12:38 <DIR> d-------- C:\Program Files\DVBViewer
2008-04-07 17:27 . 2008-04-07 17:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CMUV
2008-04-07 16:46 . 2008-04-07 17:31 <DIR> d-------- C:\Program Files\Common Files\TerraTec
2008-04-07 16:44 . 2004-08-03 23:10 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
2008-04-07 16:41 . 2004-08-04 00:56 363,520 --a------ C:\WINDOWS\system32\PsisDecd.dll
2008-04-07 16:11 . 2008-04-07 17:30 <DIR> d-------- C:\Documents and Settings\Juuso\Application Data\TerraTec
2008-04-07 16:09 . 2008-04-07 16:09 <DIR> d-------- C:\TerraTec
2008-04-05 01:02 . 2008-04-05 01:02 <DIR> d-------- C:\Program Files\QT Lite
2008-04-05 01:02 . 2008-03-28 21:07 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-04-05 01:02 . 2008-03-28 21:07 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-04-03 12:28 . 2008-04-09 11:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-03-28 00:38 . 2008-03-28 00:38 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-03-26 17:09 . 2008-03-26 17:09 <DIR> d-------- C:\Logs
2008-03-24 02:06 . 2006-10-26 20:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-03-24 02:05 . 2008-03-24 02:05 <DIR> d-------- C:\Program Files\Microsoft Works
2008-03-24 02:03 . 2008-03-24 02:03 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-03-24 02:01 . 2008-03-24 03:57 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-03-24 02:01 . 2008-03-24 02:01 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-03-24 02:00 . 2008-03-24 02:00 <DIR> dr-h----- C:\MSOCache
2008-03-22 14:20 . 2008-03-22 14:20 <DIR> d-------- C:\Documents and Settings\Juuso\Application Data\InstallShield Installation Information
2008-03-22 13:00 . 2008-03-22 13:00 22,328 --a------ C:\Documents and Settings\Juuso\Application Data\PnkBstrK.sys
2008-03-22 12:59 . 2008-03-22 12:59 669,184 --a------ C:\WINDOWS\system32\pbsvc.exe
2008-03-20 20:30 . 2008-03-20 20:30 <DIR> d-------- C:\Program Files\Futuremark
2008-03-20 17:55 . 2008-03-20 17:55 <DIR> d-------- C:\NVIDIA
2008-03-20 17:55 . 2008-03-24 19:52 442,368 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-03-20 17:55 . 2008-03-24 19:52 17,937 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-03-19 17:06 . 2008-03-19 17:13 <DIR> d-------- C:\Documents and Settings\Juuso\Application Data\Irssi
2008-03-17 19:20 . 2008-03-17 19:20 <DIR> d-------- C:\Program Files\AMX Mod X
2008-03-14 16:41 . 2008-03-14 16:42 <DIR> d-------- C:\Program Files\OpenOffice.org 2.3
2008-03-14 16:40 . 2008-03-14 16:40 <DIR> d-------- C:\Program Files\Windows Installer Clean Up
2008-03-14 16:40 . 2008-03-14 16:40 <DIR> d-------- C:\Program Files\MSECACHE
2008-03-12 14:10 . 2008-03-12 14:10 633,344 --a------ C:\WINDOWS\system32\gpprefcl.dll
2008-03-10 17:29 . 2008-03-10 17:31 <DIR> d-------- C:\Program Files\RCrawler
2008-03-09 23:40 . 2002-07-17 10:20 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL
2008-03-09 23:40 . 2002-07-17 09:53 16,877 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
2008-03-09 23:40 . 2002-07-17 17:22 5,600 --a------ C:\WINDOWS\system\WINASPI.DLL
2008-03-09 23:40 . 2002-07-17 17:22 4,672 --a------ C:\WINDOWS\system\WOWPOST.EXE
2008-03-09 22:14 . 2008-03-09 22:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TrackMania United
2008-03-09 08:04 . 2008-03-09 14:23 <DIR> d-------- C:\Downloads
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-09 10:04 --------- d-----w C:\Documents and Settings\Juuso\Application Data\OpenOffice.org2
2008-04-09 10:04 --------- d-----w C:\Documents and Settings\Juuso\Application Data\Hamachi
2008-04-09 10:03 --------- d-----w C:\Documents and Settings\LocalService\Application Data\VMware
2008-04-09 10:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\VMware
2008-04-09 08:55 --------- d-----w C:\Program Files\RegScrubXP
2008-04-09 08:30 --------- d-----w C:\Program Files\Wowhead Client
2008-04-09 07:27 --------- d-----w C:\Documents and Settings\Juuso\Application Data\uTorrent
2008-04-09 07:27 --------- d-----w C:\Documents and Settings\Juuso\Application Data\foobar2000
2008-04-08 19:32 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-04-08 11:19 --------- d-----w C:\Program Files\MAL Updater
2008-04-08 09:09 --------- d-----w C:\Documents and Settings\Juuso\Application Data\gtk-2.0
2008-04-08 09:05 --------- d-----w C:\Program Files\megui
2008-04-08 04:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-07 17:01 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-04-04 22:02 --------- d-----w C:\Documents and Settings\Juuso\Application Data\Apple Computer
2008-04-04 22:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-04 14:15 --------- d-----w C:\Documents and Settings\Juuso\Application Data\MegauploadToolbar
2008-04-01 15:45 --------- d-----w C:\Program Files\HLSW
2008-03-31 09:32 --------- d-----w C:\Program Files\AlbumArtDownloader
2008-03-29 15:40 118,784 ----a-w C:\WINDOWS\SeaMonkeyUninstall.exe
2008-03-29 15:40 118,784 ----a-w C:\WINDOWS\GREUninstall.exe
2008-03-28 12:23 --------- d-----w C:\Program Files\Java
2008-03-28 12:22 85,752 ----a-w C:\WINDOWS\system32\drivers\cmdGuard.sys
2008-03-27 21:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-25 20:25 --------- d-----w C:\Program Files\mIRC
2008-03-25 16:01 --------- d-----w C:\Program Files\Azureus
2008-03-25 14:30 --------- d-----w C:\Program Files\Driver Cleaner Pro
2008-03-25 07:20 --------- d-----w C:\Program Files\DAEMON Tools Pro
2008-03-24 08:27 442,368 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2008-03-23 23:04 --------- d-----w C:\Program Files\MSBuild
2008-03-23 22:44 --------- d-----w C:\Documents and Settings\Juuso\Application Data\Azureus
2008-03-23 10:15 --------- d-----w C:\Documents and Settings\Juuso\Application Data\AdobeUM
2008-03-22 21:01 --------- d-----w C:\Program Files\PogoSticker
2008-03-22 18:35 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-03-22 18:34 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-22 09:59 66,872 ----a-w C:\WINDOWS\system32\pnkbstra.exe
2008-03-21 14:40 223,424 ----a-w C:\WINDOWS\system32\drivers\truecrypt.sys
2008-03-20 17:31 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-03-20 13:37 8,192 ----a-w C:\WINDOWS\system32\tsbyuv.dll
2008-03-19 18:39 --------- d-----w C:\Documents and Settings\Juuso\Application Data\Bioshock
2008-03-15 12:58 --------- d-----w C:\Program Files\Opera
2008-03-15 12:57 --------- d-----w C:\Program Files\MediaCoder
2008-03-14 22:51 23,800 ----a-w C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-03-14 22:51 139,008 ----a-w C:\WINDOWS\system32\guard32.dll
2008-03-14 22:10 --------- d-----w C:\Documents and Settings\Juuso\Application Data\Notepad++
2008-03-11 06:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-09 20:30 --------- d-----w C:\Program Files\Exact Audio Copy
2008-03-08 18:39 --------- d-----w C:\Program Files\LimeWire
2008-03-08 10:54 --------- d-----w C:\Program Files\kX Audio Driver
2008-03-08 10:20 --------- d-----w C:\Program Files\kX Project
2008-03-04 01:05 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-03-02 09:59 --------- d-----w C:\Program Files\uTorrent
2008-02-26 21:00 --------- d-----w C:\Program Files\TaskSwitchXP
2008-02-26 20:57 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-02-17 08:59 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-15 13:24 --------- d-----w C:\Program Files\Audacity
2008-02-15 13:22 --------- d-----w C:\Program Files\MusicBrainz Picard
2008-02-10 09:13 --------- d-----w C:\Program Files\foobar2000
2008-02-04 15:26 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-01-11 23:07 61,177 ----a-w C:\WINDOWS\system32\x264vfw-uninstall.exe
2007-06-14 22:24 338,253 ----a-w C:\Documents and Settings\Juuso\SNW_2.1.18_CBT.exe
2007-05-20 09:24 3,166,492 ----a-w C:\Documents and Settings\Juuso\Visual Studio.net_2003_pro_full.exe
2007-02-27 10:58 2,265,507 ----a-w C:\Documents and Settings\Juuso\WoW-2.0.8.6403-to-0.0.10.6422-enGB-patch.exe
2006-06-23 06:48 32,768 -c--a-r C:\WINDOWS\inf\UpdateUSB.exe
.
------- Sigcheck -------
2007-06-13 13:23 950784 7dab450e1e61e9e9c1663e76f75ed911 C:\WINDOWS\explorer.exe
2007-06-13 14:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 13:23 950784 7dab450e1e61e9e9c1663e76f75ed911 C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 13:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\XPize\Backup\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@={30351346-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@={30351347-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@={30351348-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@={3035134B-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@={3035134C-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@={3035134D-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@={3035134E-7B7D-4FCC-81B4-1E394CA267EB}
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 10:11 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 10:11 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 10:11 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 10:11 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 10:11 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 10:11 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 10:11 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:00 30208]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 20:25 81920]
"Steam"="g:\steam\steam.exe" [2008-03-28 15:56 1271032]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-03 16:54 486856]
"XPize Reloader"="C:\WINDOWS\XPize\XPizeReloader.exe" [2007-08-17 21:03 114338]
"TaskSwitchXP"="C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-05 01:29 62976]
"MalUpdater"="C:\Program Files\MAL Updater\MalUpdater.exe" [2008-04-08 12:08 1427968]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45 313472]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-04-01 18:35 3587120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidTool.exe" [2006-06-02 16:45 385024]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 16:40 155648]
"WinVNC"="C:\Program Files\TightVNC\WinVNC.exe" [2007-05-07 19:28 589824]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 15:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 15:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 15:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 15:00 455168]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\cfp.exe" [2008-03-15 01:50 1503488]
"kX Mixer"="C:\WINDOWS\system32\kxmixer.exe" [2007-08-24 16:28 500224]
"Registry Crawler"="C:\PROGRA~1\RCrawler\RCrawler.exe" [2004-02-03 10:06 454656]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-03-24 19:52 13524992]
"nwiz"="nwiz.exe" [2008-03-24 19:52 1626112 C:\WINDOWS\system32\nwiz.exe]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 08:00 33648]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-03-24 19:52 86016]
"d4309e3f"="C:\WINDOWS\system32\mcycjpgm.dll" [ ]
"BMd703ada3"="C:\WINDOWS\system32\gkaqkdyi.dll" [ ]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-09 11:00 579072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15:00 30208]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-04-09 11:00 219136]
C:\Documents and Settings\Juuso\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-12-31 22:07:49 624416]
Last.fm Helper.lnk - E:\Last.fm\LastFMHelper.exe [2007-06-28 19:02:25 106496]
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-11-14 18:32:04 393216]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Wowhead Client.lnk - C:\Program Files\Wowhead Client\Wowhead_Client.exe [2008-04-09 11:30:29 165376]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qoMggffg]
qoMggffg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\WINDOWS\system32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"E:\\The All-Seeing Eye\\eye.exe"=
"E:\\Last.fm\\LastFM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"G:\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"G:\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"C:\\WINDOWS\\system32\\pnkbstra.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"G:\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-03-28 15:22]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-03-15 01:51]
R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;C:\Program Files\ASTRA32\ASTRA32.sys [2007-02-22 12:28]
R3 kxwdmdrv;kX WDM Driver Service;C:\WINDOWS\system32\drivers\kx.sys [2007-08-24 16:28]
R3 MTSBDA;Cinergy C BDA service;C:\WINDOWS\system32\DRIVERS\MtsBda.sys [2007-09-30 13:53]
R3 MtsHID;Cinergy C/S2 PCI HID service;C:\WINDOWS\system32\DRIVERS\MtsHid.sys [2006-09-04 14:45]
S3 Ext2FS;Ext2FS;C:\WINDOWS\system32\drivers\Ext2FS.sys [2004-01-23 19:34]
S3 libusb0;LibUsb-Win32 - Kernel Driver 03/09/2005, 0.1.10.1;C:\WINDOWS\system32\DRIVERS\libusb0.sys [2005-03-09 13:50]
S3 PsSdk30;PsSdk30;C:\WINDOWS\system32\Drivers\PsSdk30.drv []
.
Contents of the 'Scheduled Tasks' folder
"2008-04-05 02:10:14 C:\WINDOWS\Tasks\JkDefragCmd.job"
- G:\JkDefrag\JkDefragCmd.exe
"2008-04-09 06:00:00 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-09 13:04:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PsSdk30]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\PsSdk30.drv"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\sessmgr.exe
E:\VMware\VMware Player\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\vmnetdhcp.exe
.
**************************************************************************
.
Completion time: 2008-04-09 13:07:39 - machine was rebooted [Juuso]
ComboFix-quarantined-files.txt 2008-04-09 10:07:35
Pre-Run: 5,387,120,640 bytes free
Post-Run: 5,270,896,640 bytes free
.
2008-04-09 08:44:05 --- E O F ---