sindbad
2008-05-29, 18:52
good thing i came here as i see many have this issue
so i did download combofix and here is the report
should i follow the same steps at other threads or just wait?
ComboFix 08-05-28.8 - Sinbad 2008-05-29 18:34:18.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1524 [GMT 3:00]
Running from: C:\Documents and Settings\Sinbad\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMf3dcbdb3.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\cbuhltmr.dll
C:\WINDOWS\system32\dkcptjgr.ini
C:\WINDOWS\system32\hbmevdrl.ini
C:\WINDOWS\system32\hufixtcp.dll
C:\WINDOWS\system32\jhqlgbft.ini
C:\WINDOWS\system32\kwjsvbic.ini
C:\WINDOWS\system32\leleaatu.dll
C:\WINDOWS\system32\ljJDUnLC.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\qhrghtyp.dll
C:\WINDOWS\system32\sbhmjoom.dll
C:\WINDOWS\system32\slmqxyvr.dll
C:\WINDOWS\system32\sswcyxie.dll
C:\WINDOWS\system32\tnqtihfv.dll
C:\WINDOWS\system32\uFehknpo.ini
C:\WINDOWS\system32\uFehknpo.ini2
C:\WINDOWS\system32\uplylimn.ini
C:\WINDOWS\system32\vfhitqnt.ini
C:\WINDOWS\system32\wcpcvubx.dll
C:\WINDOWS\system32\xaopcdwv.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-29 )))))))))))))))))))))))))))))))
.
2008-05-29 16:33 . 2008-05-29 16:33 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-29 16:33 . 2008-05-29 17:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-27 21:49 . 2008-05-27 21:49 <DIR> d-------- C:\Documents and Settings\Administrator
2008-05-26 22:54 . 2008-05-26 22:54 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-26 22:54 . 2008-05-27 22:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-26 11:58 . 2008-05-26 11:58 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-05-23 13:11 . 2008-05-23 13:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-22 14:23 . 2008-05-22 14:23 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-05-19 17:57 . 2008-05-23 12:46 <DIR> d-------- C:\Program Files\vPlug Files Center
2008-05-19 17:53 . 2008-05-19 17:53 0 --a------ C:\WINDOWS\graphedit.INI
2008-05-19 17:33 . 2008-05-19 17:50 <DIR> d-------- C:\dvbdream
2008-05-16 20:21 . 2008-05-16 20:21 <DIR> d-------- C:\WINDOWS\nvidia icons
2008-05-12 17:09 . 2008-05-29 11:09 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-10 18:37 . 2008-05-10 18:37 <DIR> dr-h----- C:\Documents and Settings\Sinbad\Application Data\SecuROM
2008-05-10 18:37 . 2008-05-10 18:37 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-05-03 16:28 . 2008-05-03 16:28 <DIR> d-------- C:\Program Files\Stardock
2008-05-03 16:28 . 2008-05-03 16:28 <DIR> d-------- C:\Program Files\Common Files\Stardock
2008-05-03 16:00 . 2008-05-04 15:24 <DIR> d-------- C:\Program Files\Google
2008-05-02 21:08 . 2008-05-29 09:33 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-02 21:08 . 2008-05-02 21:08 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-02 21:08 . 2008-05-02 21:08 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-02 21:08 . 2008-05-02 21:08 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-02 21:07 . 2008-05-02 21:07 <DIR> d-------- C:\Program Files\AVG
2008-05-02 21:07 . 2008-05-02 21:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-02 10:58 . 2008-05-02 10:58 <DIR> d-------- C:\Program Files\CCleaner
2008-04-30 03:58 . 2008-04-30 03:58 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-29 11:58 --------- d-----w C:\Program Files\FlashGet
2008-05-27 19:31 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-26 17:43 --------- d-----w C:\Program Files\Advanced System Optimizer
2008-05-18 11:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-12 18:05 --------- d-----w C:\Documents and Settings\Sinbad\Application Data\Xfire
2008-05-12 17:28 --------- d-----w C:\Program Files\Xfire
2008-05-11 15:11 --------- d-----w C:\Documents and Settings\Sinbad\Application Data\LimeWire
2008-05-10 09:46 --------- d-----w C:\Program Files\Winamp
2008-05-02 19:46 6,554,496 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-04-30 17:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-25 09:20 --------- d-----w C:\Program Files\BuddyCheck
2008-04-23 12:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ubisoft
2008-04-21 16:19 35,131 ----a-w C:\Program Files\PICT0460.jpg
2008-04-19 18:13 --------- d-----w C:\Program Files\WMV9_VCM
2008-04-10 09:47 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-04-08 15:00 --------- d-----w C:\Program Files\Java
2008-04-04 16:58 --------- d-----w C:\Program Files\PQDVD
2008-04-01 12:31 --------- d-----w C:\Documents and Settings\Sinbad\Application Data\Command & Conquer 3 Kane's Wrath
2008-04-01 12:19 --------- d-----w C:\Program Files\SCC-TDS
2008-03-30 16:43 --------- d-----w C:\Documents and Settings\Sinbad\Application Data\Nuotex
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{687436DD-201E-4305-B4F2-D528588D9E08}]
C:\WINDOWS\system32\opnkheFu.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 12:21 16270848 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 13:04 2879488 C:\WINDOWS\SkyTel.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-29 18:21 185896]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-02 21:07 1177368]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 02:56 15360]
C:\Documents and Settings\Sinbad\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2008-05-03 16:28:01 3444008]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Server4PC.lnk - C:\Program Files\TechniSat DVB\bin\Server4PC.exe [2008-01-06 18:46:41 328968]
Sonic CinePlayer Quick Launch.lnk - C:\Program Files\Common Files\Sonic Shared\cinetray.exe [2002-09-18 14:16:30 98304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"E:\\Games\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\DVBViewerTE\\ts_winlirc.exe"=
"C:\\Program Files\\SCC-TDS\\Command & Conquer 3 - Tiberium Wars\\RetailExe\\1.8\\cnc3game.dat"=
"E:\\Games\\Universe At War Earth Assault\\UAWEA.exe"=
"F:\\Games\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"D:\\Games\\Wizet\\Maplestory\\Patcher.exe"=
"D:\\Games\\Wizet\\Maplestory\\MapleStory.exe"=
"E:\\Games\\SACC-Sniper Wolf\\Tom Clancy's Rainbow Six Vegas 2\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"E:\\Games\\SACC-Sniper Wolf\\Tom Clancy's Rainbow Six Vegas 2\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\RainbowSixVegas2_SADS.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-02 21:08]
R1 Cinemsup;Cinemsup;C:\WINDOWS\system32\drivers\cinemsup.sys [2002-07-19 08:10]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-02 21:07]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-02 21:07]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-02 21:08]
R3 SKYNET;TechniSat DVB-PC TV Star PCI;C:\WINDOWS\system32\DRIVERS\SkyNET.SYS [2007-10-01 20:54]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{de2b67da-ec2c-11dc-a9ee-00d0d7152d87}]
\Shell\AutoRun\command - H:\launcher.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e0bba3cf-22bc-11dd-aa8e-00d0d7152d87}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-29 18:37:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-05-29 18:40:22 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-29 15:40:19
Pre-Run: 3,335,565,312 bytes free
Post-Run: 3,254,067,200 bytes free
168 --- E O F --- 2008-05-17 07:18:37
so i did download combofix and here is the report
should i follow the same steps at other threads or just wait?
ComboFix 08-05-28.8 - Sinbad 2008-05-29 18:34:18.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1524 [GMT 3:00]
Running from: C:\Documents and Settings\Sinbad\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMf3dcbdb3.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\cbuhltmr.dll
C:\WINDOWS\system32\dkcptjgr.ini
C:\WINDOWS\system32\hbmevdrl.ini
C:\WINDOWS\system32\hufixtcp.dll
C:\WINDOWS\system32\jhqlgbft.ini
C:\WINDOWS\system32\kwjsvbic.ini
C:\WINDOWS\system32\leleaatu.dll
C:\WINDOWS\system32\ljJDUnLC.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\qhrghtyp.dll
C:\WINDOWS\system32\sbhmjoom.dll
C:\WINDOWS\system32\slmqxyvr.dll
C:\WINDOWS\system32\sswcyxie.dll
C:\WINDOWS\system32\tnqtihfv.dll
C:\WINDOWS\system32\uFehknpo.ini
C:\WINDOWS\system32\uFehknpo.ini2
C:\WINDOWS\system32\uplylimn.ini
C:\WINDOWS\system32\vfhitqnt.ini
C:\WINDOWS\system32\wcpcvubx.dll
C:\WINDOWS\system32\xaopcdwv.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-29 )))))))))))))))))))))))))))))))
.
2008-05-29 16:33 . 2008-05-29 16:33 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-29 16:33 . 2008-05-29 17:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-27 21:49 . 2008-05-27 21:49 <DIR> d-------- C:\Documents and Settings\Administrator
2008-05-26 22:54 . 2008-05-26 22:54 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-26 22:54 . 2008-05-27 22:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-26 11:58 . 2008-05-26 11:58 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-05-23 13:11 . 2008-05-23 13:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-22 14:23 . 2008-05-22 14:23 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-05-19 17:57 . 2008-05-23 12:46 <DIR> d-------- C:\Program Files\vPlug Files Center
2008-05-19 17:53 . 2008-05-19 17:53 0 --a------ C:\WINDOWS\graphedit.INI
2008-05-19 17:33 . 2008-05-19 17:50 <DIR> d-------- C:\dvbdream
2008-05-16 20:21 . 2008-05-16 20:21 <DIR> d-------- C:\WINDOWS\nvidia icons
2008-05-12 17:09 . 2008-05-29 11:09 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-10 18:37 . 2008-05-10 18:37 <DIR> dr-h----- C:\Documents and Settings\Sinbad\Application Data\SecuROM
2008-05-10 18:37 . 2008-05-10 18:37 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-05-03 16:28 . 2008-05-03 16:28 <DIR> d-------- C:\Program Files\Stardock
2008-05-03 16:28 . 2008-05-03 16:28 <DIR> d-------- C:\Program Files\Common Files\Stardock
2008-05-03 16:00 . 2008-05-04 15:24 <DIR> d-------- C:\Program Files\Google
2008-05-02 21:08 . 2008-05-29 09:33 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-02 21:08 . 2008-05-02 21:08 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-02 21:08 . 2008-05-02 21:08 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-02 21:08 . 2008-05-02 21:08 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-02 21:07 . 2008-05-02 21:07 <DIR> d-------- C:\Program Files\AVG
2008-05-02 21:07 . 2008-05-02 21:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-02 10:58 . 2008-05-02 10:58 <DIR> d-------- C:\Program Files\CCleaner
2008-04-30 03:58 . 2008-04-30 03:58 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-29 11:58 --------- d-----w C:\Program Files\FlashGet
2008-05-27 19:31 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-26 17:43 --------- d-----w C:\Program Files\Advanced System Optimizer
2008-05-18 11:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-12 18:05 --------- d-----w C:\Documents and Settings\Sinbad\Application Data\Xfire
2008-05-12 17:28 --------- d-----w C:\Program Files\Xfire
2008-05-11 15:11 --------- d-----w C:\Documents and Settings\Sinbad\Application Data\LimeWire
2008-05-10 09:46 --------- d-----w C:\Program Files\Winamp
2008-05-02 19:46 6,554,496 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-04-30 17:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-25 09:20 --------- d-----w C:\Program Files\BuddyCheck
2008-04-23 12:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ubisoft
2008-04-21 16:19 35,131 ----a-w C:\Program Files\PICT0460.jpg
2008-04-19 18:13 --------- d-----w C:\Program Files\WMV9_VCM
2008-04-10 09:47 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-04-08 15:00 --------- d-----w C:\Program Files\Java
2008-04-04 16:58 --------- d-----w C:\Program Files\PQDVD
2008-04-01 12:31 --------- d-----w C:\Documents and Settings\Sinbad\Application Data\Command & Conquer 3 Kane's Wrath
2008-04-01 12:19 --------- d-----w C:\Program Files\SCC-TDS
2008-03-30 16:43 --------- d-----w C:\Documents and Settings\Sinbad\Application Data\Nuotex
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{687436DD-201E-4305-B4F2-D528588D9E08}]
C:\WINDOWS\system32\opnkheFu.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 12:21 16270848 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 13:04 2879488 C:\WINDOWS\SkyTel.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-29 18:21 185896]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-02 21:07 1177368]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 02:56 15360]
C:\Documents and Settings\Sinbad\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2008-05-03 16:28:01 3444008]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Server4PC.lnk - C:\Program Files\TechniSat DVB\bin\Server4PC.exe [2008-01-06 18:46:41 328968]
Sonic CinePlayer Quick Launch.lnk - C:\Program Files\Common Files\Sonic Shared\cinetray.exe [2002-09-18 14:16:30 98304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"E:\\Games\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\DVBViewerTE\\ts_winlirc.exe"=
"C:\\Program Files\\SCC-TDS\\Command & Conquer 3 - Tiberium Wars\\RetailExe\\1.8\\cnc3game.dat"=
"E:\\Games\\Universe At War Earth Assault\\UAWEA.exe"=
"F:\\Games\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"D:\\Games\\Wizet\\Maplestory\\Patcher.exe"=
"D:\\Games\\Wizet\\Maplestory\\MapleStory.exe"=
"E:\\Games\\SACC-Sniper Wolf\\Tom Clancy's Rainbow Six Vegas 2\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"E:\\Games\\SACC-Sniper Wolf\\Tom Clancy's Rainbow Six Vegas 2\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\RainbowSixVegas2_SADS.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-02 21:08]
R1 Cinemsup;Cinemsup;C:\WINDOWS\system32\drivers\cinemsup.sys [2002-07-19 08:10]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-02 21:07]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-02 21:07]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-02 21:08]
R3 SKYNET;TechniSat DVB-PC TV Star PCI;C:\WINDOWS\system32\DRIVERS\SkyNET.SYS [2007-10-01 20:54]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{de2b67da-ec2c-11dc-a9ee-00d0d7152d87}]
\Shell\AutoRun\command - H:\launcher.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e0bba3cf-22bc-11dd-aa8e-00d0d7152d87}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-29 18:37:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-05-29 18:40:22 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-29 15:40:19
Pre-Run: 3,335,565,312 bytes free
Post-Run: 3,254,067,200 bytes free
168 --- E O F --- 2008-05-17 07:18:37