momak
2008-04-09, 20:49
Hello:)
My computer isinfected,and I have logs from Avg,combofix,and Hijack.
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 04/08/2008 at 11:50 PM
Application Version : 4.0.1154
Core Rules Database Version : 3433
Trace Rules Database Version: 1425
Scan type : Complete Scan
Total Scan Time : 01:37:27
Memory items scanned : 160
Memory threats detected : 0
Registry items scanned : 5228
Registry threats detected : 0
File items scanned : 23352
File threats detected : 19
Adware.Tracking Cookie
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@statcounter[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@track.adform[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@partners.webmasterplan[2].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@eas.apm.emediate[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@atdmt[2].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@mediaprovider.adservinginternational[2].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@tacoda[2].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@adtech[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@tradedoubler[3].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@mediaplex[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@ad.yieldmanager[2].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@doubleclick[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@adbrite[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@toplist[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@tradedoubler[2].txt
Adware.SXGAdvisor-A
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP85\A0012256.DLL
Trojan.Unclassified/GTS
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP85\A0012257.DLL
Trojan.Unclassified/Multi-Dropper
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP87\A0013981.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP87\A0013982.EXE
ComboFix 08-04-08.1 - HP_Administrator 2008-04-09 15:33:03.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1571 [GMT 2:00]
Running from: C:\Documents and Settings\HP_Administrator\Desktop\Spywarefri\SWF_CF.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-09 to 2008-04-09 )))))))))))))))))))))))))))))))
.
2008-04-08 19:09 . 2008-04-08 19:09 3,710 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-08 17:55 . 2008-04-08 17:55 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Symantec
2008-04-08 17:50 . 2008-04-08 17:50 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\TmpRecentIcons
2008-04-07 16:32 . 2008-04-07 16:32 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-04-07 15:35 . 2008-04-07 15:35 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-04-06 23:04 . 2008-04-06 23:04 <DIR> d-------- C:\Program Files\PC-Cleaner
2008-04-06 22:49 . 2008-04-06 22:49 <DIR> d-------- C:\Documents and Settings\IKA\Application Data\SUPERAntiSpyware.com
2008-04-06 22:42 . 2008-04-06 22:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\mbsjyzar
2008-04-06 22:42 . 2008-04-06 21:18 159,744 --a------ C:\WINDOWS\apoxqwfv.exe
2008-04-03 13:57 . 2008-04-03 13:57 <DIR> d-------- C:\Sun
2008-04-03 13:34 . 2008-04-03 13:41 8 --a------ C:\WINDOWS\system32\nvModes.dat
2008-04-03 13:32 . 2008-04-03 13:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-04-03 13:16 . 2008-04-03 13:16 <DIR> d-------- C:\WINDOWS\nview
2008-04-03 13:16 . 2007-12-05 02:53 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-04-03 13:16 . 2007-12-05 01:41 356,352 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-04-03 13:16 . 2008-04-03 13:24 163,353 --a------ C:\WINDOWS\system32\nvapps.xml
2008-04-03 13:16 . 2007-12-05 01:41 17,737 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-04-03 13:04 . 2008-04-03 13:07 <DIR> d-------- C:\Program Files\NVIDIA Corporation
2008-04-03 13:04 . 2008-04-03 13:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
2008-04-03 13:04 . 2006-03-29 08:50 671,744 --a------ C:\WINDOWS\system32\DolbyHph.dll
2008-04-03 13:04 . 2006-03-29 08:51 60,416 --a------ C:\WINDOWS\system32\DSETUP.dll
2008-04-03 13:04 . 2006-03-29 08:49 9,856 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2008-04-03 13:04 . 2006-05-05 19:21 4,608 --a------ C:\WINDOWS\system32\drivers\nvport.sys
2008-04-01 21:52 . 2008-04-01 22:05 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-04-01 21:51 . 2008-04-01 21:51 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-01 19:57 . 2008-04-01 19:59 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Vso
2008-04-01 19:57 . 2004-05-04 11:53 1,645,320 --a------ C:\WINDOWS\gdiplus.dll
2008-04-01 19:57 . 2006-05-20 16:16 1,184,984 --a------ C:\WINDOWS\system32\wvc1dmod.dll
2008-04-01 19:57 . 2006-05-11 19:21 626,688 --a------ C:\WINDOWS\system32\vp7vfw.dll
2008-04-01 19:57 . 2006-09-29 12:24 217,127 --a------ C:\WINDOWS\system32\drv43260.dll
2008-04-01 19:57 . 2006-09-29 12:25 208,935 --a------ C:\WINDOWS\system32\drv33260.dll
2008-04-01 19:57 . 2006-09-29 12:26 176,165 --a------ C:\WINDOWS\system32\drv23260.dll
2008-04-01 19:57 . 2007-03-18 20:37 65,602 --a------ C:\WINDOWS\system32\cook3260.dll
2008-04-01 19:57 . 2008-04-01 19:57 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-04-01 19:57 . 2008-04-01 19:57 47,360 --a------ C:\Documents and Settings\HP_Administrator\Application Data\pcouffin.sys
2008-04-01 19:56 . 2008-04-01 19:57 <DIR> d-------- C:\Program Files\VSO
2008-03-29 22:13 . 2007-07-30 20:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-03-29 22:13 . 2007-07-30 20:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-03-29 18:53 . 2008-03-29 19:01 <DIR> d-------- C:\Program Files\NCH Swift Sound
2008-03-29 18:53 . 2008-03-29 18:53 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\NCH Swift Sound
2008-03-29 18:53 . 2008-03-29 18:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-03-28 13:28 . 2008-03-29 17:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-25 21:56 . 2008-03-25 21:56 32 --a------ C:\WINDOWS\go
2008-03-24 23:13 . 2008-03-24 23:13 <DIR> d-------- C:\WINDOWS\ShellNew
2008-03-24 23:07 . 2008-03-24 23:07 0 --a------ C:\Documents and Settings\IKA\Application Data\wklnhst.dat
2008-03-24 02:58 . 2008-03-30 00:05 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-23 20:17 . 2008-03-29 17:04 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-03-23 20:13 . 2008-03-23 20:13 <DIR> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-03-23 20:07 . 2007-07-30 20:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-03-23 19:56 . 2008-03-29 17:04 <DIR> d----c--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-23 19:56 . 2008-03-23 19:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-16 20:45 . 2008-04-02 14:04 <DIR> d-------- C:\Program Files\Total Video Converter
2008-03-11 22:12 . 2008-03-11 22:12 <DIR> d-------- C:\Program Files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-08 18:59 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-08 15:56 --------- d-----w C:\Program Files\Java
2008-04-04 10:34 --------- d-----w C:\Program Files\Norton Internet Security
2008-04-03 11:05 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-01 19:41 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\SUPERAntiSpyware.com
2008-03-29 16:59 --------- d-----w C:\Program Files\CCleaner
2008-03-29 15:04 --------- d-----w C:\Program Files\QuickTime
2008-03-29 15:04 --------- d-----w C:\Program Files\iTunes
2008-03-29 15:04 --------- d-----w C:\Program Files\iPod
2008-03-29 15:04 --------- d-----w C:\Program Files\Bonjour
2008-03-29 15:04 --------- d-----w C:\Program Files\Apple Software Update
2008-03-29 15:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-08 14:23 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Apple Computer
2008-03-08 14:21 --------- d-----w C:\Program Files\Common Files\Apple
2008-02-28 23:31 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\InterVideo
2008-02-28 22:04 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Leadertech
2008-02-28 20:40 --------- d-----w C:\Program Files\Mv2Player
2008-02-22 22:40 --------- d-----w C:\Documents and Settings\LocalService\Application Data\DivX
2008-02-22 22:28 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Media Player Classic
2008-02-22 17:17 --------- d-----w C:\Program Files\K-Lite Video Conversion Pack
2008-02-22 17:11 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-02-22 12:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-22 11:24 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\HPQ
2008-02-21 23:29 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-21 14:28 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-02-21 13:49 --------- d-----w C:\Program Files\Google
2008-02-21 13:31 --------- d-----w C:\Program Files\MSXML 4.0
2008-02-21 12:50 139,264 ----a-w C:\WINDOWS\system32\hpzjrd01.dll
2008-02-21 12:44 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-21 12:30 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\HP
2008-02-21 12:18 --------- d-----w C:\Program Files\Common Files\Real
2008-02-21 12:01 --------- d-----w C:\Program Files\SymNetDrv
2008-02-21 12:01 --------- d-----w C:\Program Files\Symantec
2008-02-21 11:52 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Symantec
2008-02-21 11:51 1,755 --sha-r C:\WINDOWS\system32\drivers\103C_HP_CPC_EP201AA-ABY m7340.dk_YC_0Pavi_QCZB612_E61DKemMPC4_48_IAMETHYST-M_SMSI_V1.0_B3.48_T060324_WXP2_L409_M2047_J250_7AMD_8Athlon 64_92.19_#060526_N10EC8139_Z_G_OHL-DT-ST DVDRRW GSA-H20L_D_HST3250823AS_F.MRK
2008-01-11 05:53 44,544 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-10 12:16 159,839 ----a-w C:\WINDOWS\system32\xvidvfw.dll
2008-01-10 12:15 755,027 ----a-w C:\WINDOWS\system32\xvidcore.dll
2005-05-12 05:36 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2D97AD74-0CBD-443C-82E7-74093471B3B7}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 14:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 01:24 1694208]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-04-01 22:05 1481968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-06 06:56 64512]
"ftutil2"="ftutil2.dll" [2004-06-08 07:05 106496 C:\WINDOWS\system32\ftutil2.dll]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04 52736]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 09:19 77312 C:\WINDOWS\arpwrmsg.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 22:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 08:35 49152]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 23:14 237568]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-02-07 11:59 49768]
"URLLSTCK.exe"="c:\Program Files\Norton Internet Security\UrlLstCk.exe" [2005-03-30 02:03 22656]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 07:12 49152]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2008-02-21 14:01 100056]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 17:44 61440]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 07:23:26 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"k06SJe0wvR"= C:\Documents and Settings\All Users\Application Data\mbsjyzar\yryranqx.exe
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"qdnkewfa"= {B9BE6D68-5EF7-43E2-826C-418D80DD499D} - C:\WINDOWS\qdnkewfa.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geBUNDsQ]
geBUNDsQ.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.ac3acm"= ac3acm.acm
"msacm.lameacm"= lameACM.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
R0 dontgo;Promise Removable Disk Control Driver;C:\WINDOWS\system32\DRIVERS\DontGo.sys [2004-06-30 06:25]
R2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-08-03 18:46]
R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-10-03 22:57]
S3 WN5301;LIteon Wireless PCI Network Adapter Service;C:\WINDOWS\system32\DRIVERS\wn5301.sys [2005-10-05 19:44]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-02 14:20:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-04 18:48:56 C:\WINDOWS\Tasks\Norton AntiVirus - Skan Denne computer - HP_Administrator.job"
- c:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/task:
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-09 15:34:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\nview.dll
.
Completion time: 2008-04-09 15:35:18
ComboFix-quarantined-files.txt 2008-04-09 13:35:08
ComboFix2.txt 2008-04-08 17:38:03
ComboFix3.txt 2008-04-07 14:04:39
ComboFix4.txt 2008-03-29 07:35:34
Pre-Run: 220,942,233,600 bytes free
Post-Run: 220,930,600,960 bytes free
.
2008-03-29 22:05:33 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:37:09, on 09-04-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\HP_Administrator\Desktop\Spywarefri\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dk.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2D97AD74-0CBD-443C-82E7-74093471B3B7} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKLM\..\Policies\Explorer\Run: [k06SJe0wvR] C:\Documents and Settings\All Users\Application Data\mbsjyzar\yryranqx.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: geBUNDsQ - geBUNDsQ.dll (file missing)
O21 - SSODL: qdnkewfa - {B9BE6D68-5EF7-43E2-826C-418D80DD499D} - C:\WINDOWS\qdnkewfa.dll (file missing)
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
--
End of file - 7943 bytes
Thanks
My computer isinfected,and I have logs from Avg,combofix,and Hijack.
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 04/08/2008 at 11:50 PM
Application Version : 4.0.1154
Core Rules Database Version : 3433
Trace Rules Database Version: 1425
Scan type : Complete Scan
Total Scan Time : 01:37:27
Memory items scanned : 160
Memory threats detected : 0
Registry items scanned : 5228
Registry threats detected : 0
File items scanned : 23352
File threats detected : 19
Adware.Tracking Cookie
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@statcounter[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@track.adform[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@partners.webmasterplan[2].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@eas.apm.emediate[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@atdmt[2].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@mediaprovider.adservinginternational[2].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@tacoda[2].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@adtech[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@tradedoubler[3].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@mediaplex[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@ad.yieldmanager[2].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@doubleclick[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@adbrite[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@toplist[1].txt
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@tradedoubler[2].txt
Adware.SXGAdvisor-A
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP85\A0012256.DLL
Trojan.Unclassified/GTS
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP85\A0012257.DLL
Trojan.Unclassified/Multi-Dropper
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP87\A0013981.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP87\A0013982.EXE
ComboFix 08-04-08.1 - HP_Administrator 2008-04-09 15:33:03.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1571 [GMT 2:00]
Running from: C:\Documents and Settings\HP_Administrator\Desktop\Spywarefri\SWF_CF.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-09 to 2008-04-09 )))))))))))))))))))))))))))))))
.
2008-04-08 19:09 . 2008-04-08 19:09 3,710 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-08 17:55 . 2008-04-08 17:55 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Symantec
2008-04-08 17:50 . 2008-04-08 17:50 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\TmpRecentIcons
2008-04-07 16:32 . 2008-04-07 16:32 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-04-07 15:35 . 2008-04-07 15:35 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-04-06 23:04 . 2008-04-06 23:04 <DIR> d-------- C:\Program Files\PC-Cleaner
2008-04-06 22:49 . 2008-04-06 22:49 <DIR> d-------- C:\Documents and Settings\IKA\Application Data\SUPERAntiSpyware.com
2008-04-06 22:42 . 2008-04-06 22:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\mbsjyzar
2008-04-06 22:42 . 2008-04-06 21:18 159,744 --a------ C:\WINDOWS\apoxqwfv.exe
2008-04-03 13:57 . 2008-04-03 13:57 <DIR> d-------- C:\Sun
2008-04-03 13:34 . 2008-04-03 13:41 8 --a------ C:\WINDOWS\system32\nvModes.dat
2008-04-03 13:32 . 2008-04-03 13:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-04-03 13:16 . 2008-04-03 13:16 <DIR> d-------- C:\WINDOWS\nview
2008-04-03 13:16 . 2007-12-05 02:53 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-04-03 13:16 . 2007-12-05 01:41 356,352 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-04-03 13:16 . 2008-04-03 13:24 163,353 --a------ C:\WINDOWS\system32\nvapps.xml
2008-04-03 13:16 . 2007-12-05 01:41 17,737 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-04-03 13:04 . 2008-04-03 13:07 <DIR> d-------- C:\Program Files\NVIDIA Corporation
2008-04-03 13:04 . 2008-04-03 13:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
2008-04-03 13:04 . 2006-03-29 08:50 671,744 --a------ C:\WINDOWS\system32\DolbyHph.dll
2008-04-03 13:04 . 2006-03-29 08:51 60,416 --a------ C:\WINDOWS\system32\DSETUP.dll
2008-04-03 13:04 . 2006-03-29 08:49 9,856 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2008-04-03 13:04 . 2006-05-05 19:21 4,608 --a------ C:\WINDOWS\system32\drivers\nvport.sys
2008-04-01 21:52 . 2008-04-01 22:05 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-04-01 21:51 . 2008-04-01 21:51 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-01 19:57 . 2008-04-01 19:59 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Vso
2008-04-01 19:57 . 2004-05-04 11:53 1,645,320 --a------ C:\WINDOWS\gdiplus.dll
2008-04-01 19:57 . 2006-05-20 16:16 1,184,984 --a------ C:\WINDOWS\system32\wvc1dmod.dll
2008-04-01 19:57 . 2006-05-11 19:21 626,688 --a------ C:\WINDOWS\system32\vp7vfw.dll
2008-04-01 19:57 . 2006-09-29 12:24 217,127 --a------ C:\WINDOWS\system32\drv43260.dll
2008-04-01 19:57 . 2006-09-29 12:25 208,935 --a------ C:\WINDOWS\system32\drv33260.dll
2008-04-01 19:57 . 2006-09-29 12:26 176,165 --a------ C:\WINDOWS\system32\drv23260.dll
2008-04-01 19:57 . 2007-03-18 20:37 65,602 --a------ C:\WINDOWS\system32\cook3260.dll
2008-04-01 19:57 . 2008-04-01 19:57 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-04-01 19:57 . 2008-04-01 19:57 47,360 --a------ C:\Documents and Settings\HP_Administrator\Application Data\pcouffin.sys
2008-04-01 19:56 . 2008-04-01 19:57 <DIR> d-------- C:\Program Files\VSO
2008-03-29 22:13 . 2007-07-30 20:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-03-29 22:13 . 2007-07-30 20:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-03-29 18:53 . 2008-03-29 19:01 <DIR> d-------- C:\Program Files\NCH Swift Sound
2008-03-29 18:53 . 2008-03-29 18:53 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\NCH Swift Sound
2008-03-29 18:53 . 2008-03-29 18:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-03-28 13:28 . 2008-03-29 17:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-25 21:56 . 2008-03-25 21:56 32 --a------ C:\WINDOWS\go
2008-03-24 23:13 . 2008-03-24 23:13 <DIR> d-------- C:\WINDOWS\ShellNew
2008-03-24 23:07 . 2008-03-24 23:07 0 --a------ C:\Documents and Settings\IKA\Application Data\wklnhst.dat
2008-03-24 02:58 . 2008-03-30 00:05 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-23 20:17 . 2008-03-29 17:04 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-03-23 20:13 . 2008-03-23 20:13 <DIR> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-03-23 20:07 . 2007-07-30 20:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-03-23 19:56 . 2008-03-29 17:04 <DIR> d----c--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-23 19:56 . 2008-03-23 19:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-16 20:45 . 2008-04-02 14:04 <DIR> d-------- C:\Program Files\Total Video Converter
2008-03-11 22:12 . 2008-03-11 22:12 <DIR> d-------- C:\Program Files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-08 18:59 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-08 15:56 --------- d-----w C:\Program Files\Java
2008-04-04 10:34 --------- d-----w C:\Program Files\Norton Internet Security
2008-04-03 11:05 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-01 19:41 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\SUPERAntiSpyware.com
2008-03-29 16:59 --------- d-----w C:\Program Files\CCleaner
2008-03-29 15:04 --------- d-----w C:\Program Files\QuickTime
2008-03-29 15:04 --------- d-----w C:\Program Files\iTunes
2008-03-29 15:04 --------- d-----w C:\Program Files\iPod
2008-03-29 15:04 --------- d-----w C:\Program Files\Bonjour
2008-03-29 15:04 --------- d-----w C:\Program Files\Apple Software Update
2008-03-29 15:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-08 14:23 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Apple Computer
2008-03-08 14:21 --------- d-----w C:\Program Files\Common Files\Apple
2008-02-28 23:31 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\InterVideo
2008-02-28 22:04 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Leadertech
2008-02-28 20:40 --------- d-----w C:\Program Files\Mv2Player
2008-02-22 22:40 --------- d-----w C:\Documents and Settings\LocalService\Application Data\DivX
2008-02-22 22:28 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Media Player Classic
2008-02-22 17:17 --------- d-----w C:\Program Files\K-Lite Video Conversion Pack
2008-02-22 17:11 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-02-22 12:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-22 11:24 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\HPQ
2008-02-21 23:29 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-21 14:28 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-02-21 13:49 --------- d-----w C:\Program Files\Google
2008-02-21 13:31 --------- d-----w C:\Program Files\MSXML 4.0
2008-02-21 12:50 139,264 ----a-w C:\WINDOWS\system32\hpzjrd01.dll
2008-02-21 12:44 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-21 12:30 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\HP
2008-02-21 12:18 --------- d-----w C:\Program Files\Common Files\Real
2008-02-21 12:01 --------- d-----w C:\Program Files\SymNetDrv
2008-02-21 12:01 --------- d-----w C:\Program Files\Symantec
2008-02-21 11:52 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Symantec
2008-02-21 11:51 1,755 --sha-r C:\WINDOWS\system32\drivers\103C_HP_CPC_EP201AA-ABY m7340.dk_YC_0Pavi_QCZB612_E61DKemMPC4_48_IAMETHYST-M_SMSI_V1.0_B3.48_T060324_WXP2_L409_M2047_J250_7AMD_8Athlon 64_92.19_#060526_N10EC8139_Z_G_OHL-DT-ST DVDRRW GSA-H20L_D_HST3250823AS_F.MRK
2008-01-11 05:53 44,544 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-10 12:16 159,839 ----a-w C:\WINDOWS\system32\xvidvfw.dll
2008-01-10 12:15 755,027 ----a-w C:\WINDOWS\system32\xvidcore.dll
2005-05-12 05:36 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2D97AD74-0CBD-443C-82E7-74093471B3B7}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 14:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 01:24 1694208]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-04-01 22:05 1481968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-06 06:56 64512]
"ftutil2"="ftutil2.dll" [2004-06-08 07:05 106496 C:\WINDOWS\system32\ftutil2.dll]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04 52736]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 09:19 77312 C:\WINDOWS\arpwrmsg.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 22:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 08:35 49152]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 23:14 237568]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-02-07 11:59 49768]
"URLLSTCK.exe"="c:\Program Files\Norton Internet Security\UrlLstCk.exe" [2005-03-30 02:03 22656]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 07:12 49152]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2008-02-21 14:01 100056]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 17:44 61440]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 07:23:26 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"k06SJe0wvR"= C:\Documents and Settings\All Users\Application Data\mbsjyzar\yryranqx.exe
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"qdnkewfa"= {B9BE6D68-5EF7-43E2-826C-418D80DD499D} - C:\WINDOWS\qdnkewfa.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geBUNDsQ]
geBUNDsQ.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.ac3acm"= ac3acm.acm
"msacm.lameacm"= lameACM.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
R0 dontgo;Promise Removable Disk Control Driver;C:\WINDOWS\system32\DRIVERS\DontGo.sys [2004-06-30 06:25]
R2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-08-03 18:46]
R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-10-03 22:57]
S3 WN5301;LIteon Wireless PCI Network Adapter Service;C:\WINDOWS\system32\DRIVERS\wn5301.sys [2005-10-05 19:44]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-02 14:20:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-04 18:48:56 C:\WINDOWS\Tasks\Norton AntiVirus - Skan Denne computer - HP_Administrator.job"
- c:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/task:
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-09 15:34:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\nview.dll
.
Completion time: 2008-04-09 15:35:18
ComboFix-quarantined-files.txt 2008-04-09 13:35:08
ComboFix2.txt 2008-04-08 17:38:03
ComboFix3.txt 2008-04-07 14:04:39
ComboFix4.txt 2008-03-29 07:35:34
Pre-Run: 220,942,233,600 bytes free
Post-Run: 220,930,600,960 bytes free
.
2008-03-29 22:05:33 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:37:09, on 09-04-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\HP_Administrator\Desktop\Spywarefri\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dk.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2D97AD74-0CBD-443C-82E7-74093471B3B7} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKLM\..\Policies\Explorer\Run: [k06SJe0wvR] C:\Documents and Settings\All Users\Application Data\mbsjyzar\yryranqx.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: geBUNDsQ - geBUNDsQ.dll (file missing)
O21 - SSODL: qdnkewfa - {B9BE6D68-5EF7-43E2-826C-418D80DD499D} - C:\WINDOWS\qdnkewfa.dll (file missing)
O23 - Service: Automatisk LiveUpdate-planlægning - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
--
End of file - 7943 bytes
Thanks