jhazel3
2008-06-26, 05:13
Hi I have windows home xp service pack 2 2002 version I have cleaned with pc tools AVG and Spybot and the web hijackers just instantly reload and trojans also
here are my logs
jhazel3@put yahoo here
ComboFix 08-06-20.4 - jim 2008-06-25 14:02:13.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.242 [GMT -4:00]
Running from: C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\SpeedRunner
C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\SpeedRunner\config.cfg
C:\Program Files\Common Files\fnts~1
C:\Program Files\Common Files\fnts~1\F?nts\
C:\Program Files\Common Files\scurit~1
C:\Program Files\Spcron
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS1\444.470
C:\WINDOWS1\444.471
C:\WINDOWS1\BMabe41b4a.xml
C:\WINDOWS1\cookies.ini
C:\WINDOWS1\ctfmon32.exe
C:\WINDOWS1\ctrlpan.dll
C:\WINDOWS1\directx32.exe
C:\WINDOWS1\dnsrelay.dll
C:\WINDOWS1\editpad.exe
C:\WINDOWS1\explore.exe
C:\WINDOWS1\explorer32.exe
C:\WINDOWS1\funniest.exe
C:\WINDOWS1\funny.exe
C:\WINDOWS1\gfmnaaa.dll
C:\WINDOWS1\helpcvs.exe
C:\WINDOWS1\inetinf.exe
C:\WINDOWS1\internet.exe
C:\WINDOWS1\mainms.vpi
C:\WINDOWS1\megavid.cdt
C:\WINDOWS1\msconfd.dll
C:\WINDOWS1\msspi.dll
C:\WINDOWS1\mswsc10.dll
C:\WINDOWS1\mswsc20.dll
C:\WINDOWS1\muotr.so
C:\WINDOWS1\pskt.ini
C:\WINDOWS1\qttasks.exe
C:\WINDOWS1\quicken.exe
C:\WINDOWS1\rundll16.exe
C:\WINDOWS1\rundll32.vbe
C:\WINDOWS1\searchword.dll
C:\WINDOWS1\sistem.exe
C:\WINDOWS1\svchost32.exe
C:\WINDOWS1\svcinit.exe
C:\WINDOWS1\system32\drivers\compbattt.sys
C:\WINDOWS1\system32\efhkj.ini
C:\WINDOWS1\system32\efhkj.ini2
C:\WINDOWS1\system32\hjsikxxc.ini
C:\WINDOWS1\system32\imlyrrxd.ini
C:\WINDOWS1\system32\mcrh.tmp
C:\WINDOWS1\system32\MSINET.oca
C:\WINDOWS1\system32\scbzzwhzdpv.dll
C:\WINDOWS1\system32\winpfz33.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_COMPBATTT
-------\Service_compbattt
((((((((((((((((((((((((( Files Created from 2008-05-25 to 2008-06-25 )))))))))))))))))))))))))))))))
.
2008-06-25 06:18 . 2008-06-25 06:18 64,179 --a------ C:\WINDOWS1\system32\mwialkiggbwxcuakv.exe
2008-06-24 18:16 . 2008-06-24 18:16 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-24 18:16 . 2008-06-24 18:16 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS1\Application Data\Spybot - Search & Destroy
2008-06-24 07:51 . 2008-06-24 07:51 <DIR> d-------- C:\Program Files\BChanger
2008-06-22 17:32 . 2008-06-22 17:32 <DIR> d-------- C:\Program Files\GetModule
2008-06-22 17:02 . 2008-06-22 17:02 <DIR> d--h----- C:\$AVG8.VAULT$
2008-06-22 16:59 . 2008-06-22 16:59 <DIR> d--hs---- C:\FOUND.000
2008-06-22 16:36 . 2008-06-22 16:36 <DIR> d-------- C:\WINDOWS1\system32\drivers\Avg
2008-06-22 16:36 . 2008-06-22 16:36 <DIR> d-------- C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\AVGTOOLBAR
2008-06-22 16:36 . 2008-06-22 16:36 96,520 --a------ C:\WINDOWS1\system32\drivers\avgldx86.sys
2008-06-22 16:36 . 2008-06-22 16:36 75,272 --a------ C:\WINDOWS1\system32\drivers\avgtdix.sys
2008-06-22 16:36 . 2008-06-22 16:36 10,520 --a------ C:\WINDOWS1\system32\avgrsstx.dll
2008-06-22 16:35 . 2008-06-22 16:35 <DIR> d-------- C:\Program Files\AVG
2008-06-22 16:35 . 2008-06-22 16:35 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS1\Application Data\avg8
2008-06-22 13:39 . 2008-06-23 00:50 3,078 --a------ C:\WINDOWS1\system32\tmp.reg
2008-06-22 13:38 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS1\system32\VCCLSID.exe
2008-06-22 13:38 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS1\system32\SrchSTS.exe
2008-06-22 13:38 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS1\system32\VACFix.exe
2008-06-22 13:38 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS1\system32\IEDFix.exe
2008-06-22 13:38 . 2008-06-15 15:28 81,920 --a------ C:\WINDOWS1\system32\IEDFix.C.exe
2008-06-22 13:38 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS1\system32\404Fix.exe
2008-06-22 13:38 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS1\system32\Process.exe
2008-06-22 13:38 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS1\system32\dumphive.exe
2008-06-22 13:38 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS1\system32\WS2Fix.exe
2008-06-21 20:58 . 2008-06-21 20:58 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-06-21 20:58 . 2008-06-21 20:58 <DIR> d-------- C:\Documents and Settings\Administrator
2008-06-21 17:46 . 2008-06-21 17:46 9,662 --a------ C:\WINDOWS1\system32\ZoneAlarmIconUS.ico
2008-06-21 17:20 . 2008-06-21 17:20 <DIR> d-------- C:\WINDOWS1\rzzi
2008-06-21 17:20 . 2008-06-21 17:20 <DIR> d-------- C:\Program Files\Common Files\rzzi
2008-06-21 17:14 . 2008-06-21 17:14 <DIR> d-------- C:\Program Files\iCheck
2008-06-21 17:14 . 2008-06-21 17:14 <DIR> d-------- C:\Program Files\GetPack
2008-06-21 17:08 . 2008-06-21 17:08 <DIR> d-------- C:\Program Files\Sacor
2008-06-21 17:03 . 2008-06-21 17:03 <DIR> d-------- C:\Program Files\mjc
2008-06-21 17:02 . 2008-06-21 17:02 <DIR> d--hs---- C:\WINDOWS1\TmFuY3kg
2008-06-21 17:01 . 2008-06-21 17:01 <DIR> d-------- C:\WINDOWS1\system32\netrax06
2008-06-21 17:01 . 2008-06-21 17:01 <DIR> d-------- C:\WINDOWS1\system32\eb10
2008-06-21 17:01 . 2008-06-21 17:01 <DIR> d-------- C:\WINDOWS1\system32\bgi
2008-06-21 17:01 . 2008-06-21 17:01 <DIR> d-------- C:\WINDOWS1\system32\axc
2008-06-21 17:01 . 2008-06-21 17:01 <DIR> d-------- C:\WINDOWS1\system32\1049a
2008-06-21 17:01 . 2008-06-21 17:01 <DIR> d-------- C:\Temp\itmp4
2008-06-21 17:01 . 2008-06-21 17:01 114,688 --a------ C:\Documents and Settings\All Users.WINDOWS1\Application Data\gbczotcp.dll
2008-06-21 17:00 . 2008-06-21 17:00 <DIR> d-------- C:\Program Files\Common Files\AutoEnginuity
2008-06-21 17:00 . 2008-06-21 17:00 <DIR> d-------- C:\Program Files\AutoEnginuity
2008-06-20 20:28 . 2008-06-20 20:28 <DIR> d-------- C:\Program Files\uTorrent
2008-06-20 20:27 . 2008-06-20 20:27 <DIR> d-------- C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\uTorrent
2008-06-20 19:25 . 2008-06-20 19:25 <DIR> d-------- C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Downloads
2008-06-20 19:25 . 2008-06-20 19:25 <DIR> d-------- C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\NewsLeecher
2008-06-18 22:12 . 2008-06-18 22:12 <DIR> d-------- C:\Program Files\NewsBinGN
2008-06-18 22:12 . 2008-06-18 22:12 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS1\Application Data\NewsBin
2008-06-18 21:53 . 2008-06-18 21:53 <DIR> d-------- C:\Program Files\NewsLeecher
2008-06-18 19:56 . 2008-06-18 19:57 <DIR> d-------- C:\Program Files\Binary Boy
2008-06-18 19:18 . 2004-07-14 12:54 676,864 --a------ C:\WINDOWS1\system32\drivers\hardlock.sys
2008-06-18 19:18 . 2008-06-18 19:18 47,616 --a------ C:\WINDOWS1\system32\drivers\Haspnt.sys
2008-06-18 19:18 . 2008-06-18 19:18 6,656 --a------ C:\WINDOWS1\system32\haspvdd.dll
2008-06-18 19:18 . 2006-08-09 23:46 2,577 --a------ C:\WINDOWS1\system32\config.hsp
2008-06-18 19:18 . 2008-06-18 19:18 383 --a------ C:\WINDOWS1\system32\haspdos.sys
2008-06-18 19:17 . 2008-06-18 19:17 <DIR> d-------- C:\Program Files\Common Files\ALLDATA Shared
2008-06-18 19:17 . 2008-06-18 19:17 <DIR> d-------- C:\ALLDATAW
2008-06-18 19:17 . 2006-01-26 14:12 327,680 --------- C:\WINDOWS1\system32\haspms32.dll
2008-06-18 19:17 . 2003-04-18 15:29 44,544 --------- C:\WINDOWS1\system32\msxml4a.dll
2008-06-18 18:30 . 2008-06-18 18:30 <DIR> d-------- C:\Program Files\7-Zip
2008-06-17 22:44 . 2008-06-17 22:44 <DIR> d-------- C:\Program Files\Alcohol Soft
2008-06-17 22:39 . 2008-06-17 22:39 716,272 --a------ C:\WINDOWS1\system32\drivers\sptd.sys
2008-06-17 21:54 . 2008-06-17 21:54 <DIR> d-------- C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\Forte
2008-06-17 21:53 . 2008-06-17 21:53 <DIR> d-------- C:\Program Files\Agent
2008-06-14 22:51 . 2008-06-14 22:51 <DIR> d-------- C:\Program Files\Client
2008-06-11 03:27 . 2008-06-13 09:10 272,128 --------- C:\WINDOWS1\system32\dllcache\bthport.sys
2008-06-07 21:23 . 2004-08-17 23:14 442,368 -ra------ C:\WINDOWS1\system32\vp6vfw.dll
2008-06-07 18:25 . 2008-06-07 18:25 <DIR> d-------- C:\Netsetup
2008-05-29 18:47 . 2008-05-29 18:47 <DIR> d-------- C:\Documents and Settings\Alyssia\Application Data\acccore
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-13 13:10 272,128 ------w C:\WINDOWS1\system32\drivers\bthport.sys
2008-05-22 01:02 --------- d-----w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\acccore
2008-05-22 01:01 --------- d-----w C:\Program Files\AIMTunes
2008-05-22 01:00 --------- d-----w C:\Documents and Settings\All Users.WINDOWS1\Application Data\AOL Downloads
2008-05-22 00:59 --------- d-----w C:\Documents and Settings\All Users.WINDOWS1\Application Data\Viewpoint
2008-05-22 00:59 --------- d-----w C:\Documents and Settings\All Users.WINDOWS1\Application Data\AOL OCP
2008-05-22 00:59 --------- d-----w C:\Documents and Settings\All Users.WINDOWS1\Application Data\AOL
2008-05-17 18:21 --------- d-----w C:\Program Files\Western Digital Technologies
2008-05-11 00:21 --------- d-----w C:\Program Files\AIM6
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS1\system32\drivers\RMCast.sys
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS1\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS1\system32\quartz.dll
2008-05-07 05:18 1,287,680 ------w C:\WINDOWS1\system32\dllcache\quartz.dll
2008-04-24 02:16 3,591,680 ----a-w C:\WINDOWS1\system32\dllcache\mshtml.dll
2008-04-22 07:40 625,664 ------w C:\WINDOWS1\system32\dllcache\iexplore.exe
2008-04-22 07:39 70,656 ------w C:\WINDOWS1\system32\dllcache\ie4uinit.exe
2008-04-22 07:39 13,824 ------w C:\WINDOWS1\system32\dllcache\ieudinit.exe
2008-04-20 05:07 161,792 ----a-w C:\WINDOWS1\system32\dllcache\ieakui.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS1\system32\msjint40.dll
2008-03-27 08:12 151,583 ------w C:\WINDOWS1\system32\dllcache\msjint40.dll
2007-05-21 23:26 633,856 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\EscapeToNorrath.exe
2007-05-21 23:25 633,856 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\_scapeToNorrath.exe
2007-02-25 16:46 92,064 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\mqdmmdm.sys
2007-02-25 16:46 9,232 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\mqdmmdfl.sys
2007-02-25 16:46 79,328 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\mqdmserd.sys
2007-02-25 16:46 66,656 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\mqdmbus.sys
2007-02-25 16:46 6,208 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\mqdmcmnt.sys
2007-02-25 16:46 5,936 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\mqdmwhnt.sys
2007-02-25 16:46 4,048 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\mqdmcr.sys
2007-02-25 16:46 25,600 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\usbsermptxp.sys
2007-02-25 16:46 22,768 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\usbsermpt.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3670A914-63C2-4E67-8C9B-370AE1922143}]
2008-06-19 10:21 36864 --a------ C:\Program Files\BChanger\bchanger.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8C13E23C-7B8A-0658-FF34-71A2E4E84892}]
C:\WINDOWS1\system32\gdsxuef.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8D524C93-D2F3-4F75-A1DA-1C3E66F8B77A}]
C:\WINDOWS1\system32\jkhfe.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{98dbbf16-ca43-4c33-be80-99e6694468a4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A90BD234-2A69-4EBA-A8FE-BAC927C212CD}]
C:\WINDOWS1\system32\geeba.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bc97b254-b2b9-4d40-971d-78e0978f5f26}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e873aa24-1a96-4a8a-86bc-2b4733c05448}]
C:\WINDOWS1\system32\fpgtdlcg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E9383002-FC55-4330-B9C9-67E03BC5C840}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fec3c4df-4545-2fe3-ea4e-24f1067fffa1}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS1\system32\ctfmon.exe" [2004-08-04 03:56 15360]
"PowerPanel Personal Edition User Interaction"="C:\Program Files\CyberPower PowerPanel Personal Edition\pppeuser.exe" [2005-10-24 10:26 262144]
"PCTAVApp"="C:\Program Files\PC Tools AntiVirus\PCTAV.exe" [2006-08-15 21:59 1110016]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 17:57 1103480]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-03-25 16:21 50528]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-03-20 12:49 217544]
"mjc"="C:\Program Files\mjc\mjc.exe" [2008-06-21 17:03 145408]
"GetPack19"="C:\Program Files\GetPack\GetPack19.exe" [2008-06-17 05:56 350208]
"Crao"="C:\PROGRA~1\COMMON~1\FNTS~1\dvdplay.exe" [ ]
"Ylhxiz"="C:\Program Files\Common Files\s?curity\r?gsvr32.exe" [ ]
"GetModule19"="C:\Program Files\GetModule\GetModule19.exe" [2008-06-17 05:58 351744]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"SpeedRunner"="C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\SpeedRunner\SpeedRunner.exe" [ ]
"SfKg6wIP"="C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\Microsoft\Windows\obnaw.exe" [ ]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingB9652"="command" []
"SpybotDeletingD7735"="del" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2007-03-01 14:34 35928]
"SansaDispatch"="C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe" [2007-10-22 12:52 75584]
"RegistryMechanic"="C:\Program Files\Registry Mechanic\regmech.exe" [2006-04-05 09:56 2177256]
"Lexmark X74-X75"="C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 15:09 57344]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-10 13:46 1838592]
"CARPService"="carpserv.exe" [2001-12-23 20:02 4608 C:\WINDOWS1\system32\carpserv.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"a8d728d6"="C:\WINDOWS1\system32\dxrrylmi.dll" [ ]
"BMabe41b4a"="C:\WINDOWS1\system32\qnrwrpnt.dll" [ ]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-22 16:35 1177368]
"{0caabaf0-1a92-6e16-27c8-58c705def711}"="C:\WINDOWS1\system32\scbzzwhzdpv.dll" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA9986"="command" []
"SpybotDeletingA5258"="command" []
"SpybotDeletingC3620"="del" []
"SpybotDeletingA7011"="command" []
"SpybotDeletingC8501"="del" []
"SpybotDeletingA8329"="command" []
"SpybotDeletingC9191"="del" []
"SpybotDeletingA2114"="command" []
"SpybotDeletingA9089"="command" []
"SpybotDeletingC1771"="del" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [2007-01-12 14:06 2115728]
C:\Documents and Settings\Guest.WINDOWS1\Start Menu\Programs\Startup\
OpenOffice.org 2.1.lnk - C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe [2006-11-27 16:45:48 393216]
C:\Documents and Settings\Nancy\Start Menu\Programs\Startup\
Event Reminder.lnk - C:\pmw\PMREMIND.EXE [1998-05-18 12:41:00 255408]
C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Start Menu\Programs\Startup\
OpenOffice.org 2.1.lnk - C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe [2006-11-27 16:45:48 393216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"gbczotcp"= {dca236f8-fbdd-4c06-84f2-9202b29b2e94} - C:\Documents and Settings\All Users.WINDOWS1\Application Data\gbczotcp.dll [2008-06-21 17:01 114688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\\WINDOWS1\\system32\\userinit.exe,C:\\WINDOWS1\\system32\\iftuyszv.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qomllmn]
qomllmn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=boteziwa.dll,C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIVX"= svmp4.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\PC Tools AntiVirus\\PCTAV.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS1\\System32\\lexpps.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.1.0-enUS-downloader.exe"=
"C:\\WINDOWS1\\System32\\dpvsetup.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Documents and Settings\\Alyssia\\Application Data\\MySpace\\IM\\bin\\MySpaceIM.exe"=
"C:\\Program Files\\Client\\ClientMain.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS1\system32\Drivers\avgldx86.sys [2008-06-22 16:36]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-06-22 16:35]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-22 16:35]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS1\system32\Drivers\avgtdix.sys [2008-06-22 16:36]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
S3 ATIPCXXX;ATI Parental control device;C:\WINDOWS1\system32\DRIVERS\atipcxxx.sys [2001-08-17 12:49]
S3 ATIVRVXX;ATI Rage Theatre Video (ATIRTCAP);C:\WINDOWS1\system32\DRIVERS\atirtcap.sys [2001-08-17 12:49]
S3 ATIVXSXX;ATI Audio Crossbar (ATIVXBAR);C:\WINDOWS1\system32\DRIVERS\ativxbar.sys [2001-08-17 12:49]
S3 mqdmbus;Motorola DM Composite Driver (WDM);C:\WINDOWS1\system32\DRIVERS\mqdmbus.sys [2007-02-25 12:46]
S3 mqdmmdfl;Motorola USB Modem (Filter);C:\WINDOWS1\system32\DRIVERS\mqdmmdfl.sys [2007-02-25 12:46]
S3 mqdmmdm;Motorola USB Modem;C:\WINDOWS1\system32\DRIVERS\mqdmmdm.sys [2007-02-25 12:46]
S3 mqdmserd;Motorola USB Diag;C:\WINDOWS1\system32\DRIVERS\mqdmserd.sys [2007-02-25 12:46]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{385b7390-1574-11dd-99bb-00e04c89103a}]
\Shell\AutoRun\command - C:\WINDOWS1\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL http://www.mgae.com/keylauncher/?code=3654263318491817
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c9442a8a-dee9-11dc-99ae-00e04c89103a}]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-25 14:11:39
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\C:\WINDOWS1\TEMP\mc21.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS1\explorer.exe
-> C:\Program Files\SiteAdvisor\6253\saHook.dll
-> C:\Documents and Settings\All Users.WINDOWS1\Application Data\gbczotcp.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS1\SYSTEM32\LEXBCES.EXE
C:\WINDOWS1\SYSTEM32\LEXPPS.EXE
C:\PROGRAM FILES\AVG\AVG8\AVGWDSVC.EXE
C:\PROGRAM FILES\PC TOOLS ANTIVIRUS\PCTAVSVC.EXE
C:\PROGRAM FILES\CYBERPOWER POWERPANEL PERSONAL EDITION\PPPED.EXE
C:\PROGRAM FILES\SPYWARE DOCTOR\SDHELP.EXE
C:\PROGRAM FILES\ALCOHOL SOFT\ALCOHOL 120\STARWIND\STARWINDSERVICEAE.EXE
C:\PROGRAM FILES\LEXMARK X74-X75\LXBBBMON.EXE
C:\PROGRAM FILES\AVG\AVG8\AVGTRAY.EXE
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRAM FILES\AVG\AVG8\AVGRSX.EXE
C:\PROGRAM FILES\AVG\AVG8\AVGRSX.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
.
**************************************************************************
.
Completion time: 2008-06-25 14:18:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-25 18:17:30
Pre-Run: 1,961,132,032 bytes free
Post-Run: 6,386,057,216 bytes free
329 --- E O F --- 2008-06-20 07:00:35
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:23:34, on 6/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS1\System32\smss.exe
C:\WINDOWS1\system32\csrss.exe
C:\WINDOWS1\system32\winlogon.exe
C:\WINDOWS1\system32\services.exe
C:\WINDOWS1\system32\lsass.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\system32\LEXBCES.EXE
C:\WINDOWS1\system32\LEXPPS.EXE
C:\WINDOWS1\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS1\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
C:\WINDOWS1\System32\alg.exe
C:\Program Files\Registry Mechanic\regmech.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\WINDOWS1\system32\carpserv.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS1\system32\ctfmon.exe
C:\Program Files\CyberPower PowerPanel Personal Edition\pppeuser.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\mjc\mjc.exe
C:\Program Files\GetPack\GetPack19.exe
C:\Program Files\GetModule\GetModule19.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS1\explorer.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS1\System32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fptb-mdp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS1\system32\userinit.exe,C:\WINDOWS1\system32\iftuyszv.exe,
O2 - BHO: (no name) - `C B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: Helper Class - {3670A914-63C2-4E67-8C9B-370AE1922143} - C:\Program Files\BChanger\bchanger.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8C13E23C-7B8A-0658-FF34-71A2E4E84892} - C:\WINDOWS1\system32\gdsxuef.dll (file missing)
O2 - BHO: (no name) - {8D524C93-D2F3-4F75-A1DA-1C3E66F8B77A} - C:\WINDOWS1\system32\jkhfe.dll (file missing)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {A90BD234-2A69-4EBA-A8FE-BAC927C212CD} - C:\WINDOWS1\system32\geeba.dll (file missing)
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: {84450c33-74b2-cb68-a8a4-69a142aa378e} - {e873aa24-1a96-4a8a-86bc-2b4733c05448} - C:\WINDOWS1\system32\fpgtdlcg.dll (file missing)
O2 - BHO: (no name) - C 497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: (no name) - ¨ ¨ D-6927-48C8-A975-17DF180C71AC} - (no file)
O2 - BHO: (no name) - āC 8ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [SansaDispatch] C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\regmech.exe /H
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [a8d728d6] rundll32.exe "C:\WINDOWS1\system32\dxrrylmi.dll",b
O4 - HKLM\..\Run: [BMabe41b4a] Rundll32.exe "C:\WINDOWS1\system32\qnrwrpnt.dll",s
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [{0caabaf0-1a92-6e16-27c8-58c705def711}] C:\WINDOWS1\System32\Rundll32.exe "C:\WINDOWS1\system32\scbzzwhzdpv.dll" DllStart
O4 - HKLM\..\RunOnce: [SpybotDeletingA9986] command /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5258] command /c del "C:\Program Files\ASPMonitor\logs\computer.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3620] cmd /c del "C:\Program Files\ASPMonitor\logs\computer.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7011] command /c del "C:\Program Files\ASPMonitor\logs\filedir.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8501] cmd /c del "C:\Program Files\ASPMonitor\logs\filedir.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8329] command /c del "C:\Program Files\ASPMonitor\logs\inetcon.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9191] cmd /c del "C:\Program Files\ASPMonitor\logs\inetcon.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2114] command /c del "C:\Program Files\ASPMonitor\logs\prnt.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9089] command /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1771] cmd /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS1\system32\ctfmon.exe
O4 - HKCU\..\Run: [PowerPanel Personal Edition User Interaction] "C:\Program Files\CyberPower PowerPanel Personal Edition\pppeuser.exe"
O4 - HKCU\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [mjc] C:\Program Files\mjc\mjc.exe
O4 - HKCU\..\Run: [GetPack19] "C:\Program Files\GetPack\GetPack19.exe"
O4 - HKCU\..\Run: [Crao] "C:\PROGRA~1\COMMON~1\FNTS~1\dvdplay.exe" -vt yazb
O4 - HKCU\..\Run: [Ylhxiz] "C:\Program Files\Common Files\s?curity\r?gsvr32.exe"
O4 - HKCU\..\Run: [GetModule19] "C:\Program Files\GetModule\GetModule19.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpeedRunner] C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\SpeedRunner\SpeedRunner.exe
O4 - HKCU\..\Run: [SfKg6wIP] C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\Microsoft\Windows\obnaw.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB9652] command /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7735] cmd /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155688179437
O16 - DPF: {A609CB6E-FEB5-47C3-966C-1B916842BD01} (Nlopflash Class) - http://poker.milbestlight.com/poker/PokerCreations.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CCS\Services\Tcpip\..\{0B767B2F-DA23-41FE-8D13-742906F589EE}: NameServer = 69.51.159.21,69.51.159.22
O17 - HKLM\System\CS1\Services\Tcpip\..\{0B767B2F-DA23-41FE-8D13-742906F589EE}: NameServer = 69.51.159.21,69.51.159.22
O17 - HKLM\System\CS3\Services\Tcpip\..\{0B767B2F-DA23-41FE-8D13-742906F589EE}: NameServer = 69.51.159.21,69.51.159.22
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: boteziwa.dll,C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll
O20 - Winlogon Notify: qomllmn - qomllmn.dll (file missing)
O21 - SSODL: gbczotcp - {dca236f8-fbdd-4c06-84f2-9202b29b2e94} - C:\Documents and Settings\All Users.WINDOWS1\Application Data\gbczotcp.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS1\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS1\system32\LEXBCES.EXE
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - Unknown owner - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: PowerPanel Personal Edition Service (ppped) - Unknown owner - C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 13706 bytes
StartupList report, 6/25/2008, 2:32:31 PM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16674)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================
Running processes:
C:\WINDOWS1\System32\smss.exe
C:\WINDOWS1\system32\csrss.exe
C:\WINDOWS1\system32\winlogon.exe
C:\WINDOWS1\system32\services.exe
C:\WINDOWS1\system32\lsass.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\system32\LEXBCES.EXE
C:\WINDOWS1\system32\LEXPPS.EXE
C:\WINDOWS1\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS1\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
C:\WINDOWS1\System32\alg.exe
C:\Program Files\Registry Mechanic\regmech.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\WINDOWS1\system32\carpserv.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS1\system32\ctfmon.exe
C:\Program Files\CyberPower PowerPanel Personal Edition\pppeuser.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\mjc\mjc.exe
C:\Program Files\GetPack\GetPack19.exe
C:\Program Files\GetModule\GetModule19.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS1\explorer.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS1\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Start Menu\Programs\Startup]
OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
Shell folders AltStartup:
*Folder not found*
User shell folders Startup:
*Folder not found*
User shell folders AltStartup:
*Folder not found*
Shell folders Common Startup:
[C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup]
*No files*
Shell folders Common AltStartup:
*Folder not found*
User shell folders Common Startup:
*Folder not found*
User shell folders Alternate Common Startup:
*Folder not found*
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS1\system32\userinit.exe,C:\WINDOWS1\system32\iftuyszv.exe,
[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*
[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SunJavaUpdateSched = "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
SiteAdvisor = C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
SansaDispatch = C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
RegistryMechanic = C:\Program Files\Registry Mechanic\regmech.exe /H
Lexmark X74-X75 = "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
Google Desktop Search = "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
CARPService = carpserv.exe
Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
a8d728d6 = rundll32.exe "C:\WINDOWS1\system32\dxrrylmi.dll",b
BMabe41b4a = Rundll32.exe "C:\WINDOWS1\system32\qnrwrpnt.dll",s
AVG8_TRAY = C:\PROGRA~1\AVG\AVG8\avgtray.exe
{0caabaf0-1a92-6e16-27c8-58c705def711} = C:\WINDOWS1\System32\Rundll32.exe "C:\WINDOWS1\system32\scbzzwhzdpv.dll" DllStart
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
SpybotDeletingA9986 = command /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
SpybotDeletingA5258 = command /c del "C:\Program Files\ASPMonitor\logs\computer.dat"
SpybotDeletingC3620 = cmd /c del "C:\Program Files\ASPMonitor\logs\computer.dat"
SpybotDeletingA7011 = command /c del "C:\Program Files\ASPMonitor\logs\filedir.dat"
SpybotDeletingC8501 = cmd /c del "C:\Program Files\ASPMonitor\logs\filedir.dat"
SpybotDeletingA8329 = command /c del "C:\Program Files\ASPMonitor\logs\inetcon.dat"
SpybotDeletingC9191 = cmd /c del "C:\Program Files\ASPMonitor\logs\inetcon.dat"
SpybotDeletingA2114 = command /c del "C:\Program Files\ASPMonitor\logs\prnt.dat"
SpybotDeletingA9089 = command /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
SpybotDeletingC1771 = cmd /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS1\system32\ctfmon.exe
PowerPanel Personal Edition User Interaction = "C:\Program Files\CyberPower PowerPanel Personal Edition\pppeuser.exe"
PCTAVApp = "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
igndlm.exe = C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
Aim6 = "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
AlcoholAutomount = "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
mjc = C:\Program Files\mjc\mjc.exe
GetPack19 = "C:\Program Files\GetPack\GetPack19.exe"
Crao = "C:\PROGRA~1\COMMON~1\FNTS~1\dvdplay.exe" -vt yazb
Ylhxiz = "C:\Program Files\Common Files\s?curity\r?gsvr32.exe"
GetModule19 = "C:\Program Files\GetModule\GetModule19.exe"
SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background
SpeedRunner = C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\SpeedRunner\SpeedRunner.exe
SfKg6wIP = C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\Microsoft\Windows\obnaw.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
SpybotDeletingB9652 = command /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
SpybotDeletingD7735 = cmd /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[OptionalComponents]
=
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command
(Default) = "%1" /S
--------------------------------------------------
File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command
(Default) = C:\WINDOWS1\system32\mshta.exe "%1" %*
--------------------------------------------------
File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1
--------------------------------------------------
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)
[<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}] *
StubPath = C:\WINDOWS1\system32\ieudinit.exe
[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS1\inf\unregmp2.exe /ShowWMP
[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = C:\WINDOWS1\system32\ie4uinit.exe -UserIconConfig
[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS1\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS1\INF\msmsgs.inf,BLC.QuietInstall.PerUser
[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS1\INF\wmp11.inf,PerUserStub
[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll
[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = C:\WINDOWS1\system32\ie4uinit.exe -BaseSettings
--------------------------------------------------
Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps
*Registry key not found*
--------------------------------------------------
Load/Run keys from C:\WINDOWS1\WIN.INI:
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=boteziwa.dll,C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS1\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS1\System32\ssmarque.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Checking for EXPLORER.EXE instances:
C:\WINDOWS1\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
C:\WINDOWS1\Explorer\Explorer.exe: not present
C:\WINDOWS1\System\Explorer.exe: not present
C:\WINDOWS1\System32\Explorer.exe: not present
C:\WINDOWS1\Command\Explorer.exe: not present
C:\WINDOWS1\Fonts\Explorer.exe: not present
--------------------------------------------------
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden
--------------------------------------------------
Verifying REGEDIT.EXE integrity:
- Regedit.exe found in C:\WINDOWS1
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'
Registry check passed
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - (no file) - `C B2A36-3DB1-42A4-A3CB-D426709BBFEB}
(no name) - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll - {02478D38-C3F9-4EFB-9B51-7695ECA05670}
(no name) - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll - {089FD14D-132B-48FC-8861-0048AE113215}
(no name) - C:\Program Files\BChanger\bchanger.dll - {3670A914-63C2-4E67-8C9B-370AE1922143}
WormRadar.com IESiteBlocker.NavFilter - C:\Program Files\AVG\AVG8\avgssie.dll - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}
(no name) - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - C:\WINDOWS1\system32\gdsxuef.dll (file missing) - {8C13E23C-7B8A-0658-FF34-71A2E4E84892}
(no name) - C:\WINDOWS1\system32\jkhfe.dll (file missing) - {8D524C93-D2F3-4F75-A1DA-1C3E66F8B77A}
(no name) - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL - {A057A204-BACC-4D26-9990-79A187E2698E}
(no name) - C:\WINDOWS1\system32\geeba.dll (file missing) - {A90BD234-2A69-4EBA-A8FE-BAC927C212CD}
(no name) - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll - {B56A7D7D-6927-48C8-A975-17DF180C71AC}
{84450c33-74b2-cb68-a8a4-69a142aa378e} - C:\WINDOWS1\system32\fpgtdlcg.dll (file missing) - {e873aa24-1a96-4a8a-86bc-2b4733c05448}
(no name) - (no file) - C 497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - (no file) - ¨ ¨ D-6927-48C8-A975-17DF180C71AC}
(no name) - (no file) - āC 8ED58-01DD-4d91-8333-CF10577473F7}
--------------------------------------------------
Enumerating Task Scheduler jobs:
*No jobs found*
--------------------------------------------------
Enumerating Download Program Files:
[YInstStarter Class]
InProcServer32 = C:\WINDOWS1\Downloaded Program Files\yinsthelper.dll
CODEBASE = http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
[CDownloadCtrl Object]
InProcServer32 = C:\Program Files\Download Manager\DLMControl.dll
CODEBASE = http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
[MUWebControl Class]
InProcServer32 = C:\WINDOWS1\system32\muweb.dll
CODEBASE = http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155688179437
[Java Plug-in 1.6.0_05]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
[{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
CODEBASE = http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
[Nlopflash Class]
InProcServer32 = C:\WINDOWS1\Downloaded Program Files\nlop.dll
CODEBASE = http://poker.milbestlight.com/poker/PokerCreations.cab
[Crucial cpcScan]
InProcServer32 = C:\WINDOWS1\Downloaded Program Files\cpcScan.dll
CODEBASE = http://www.crucial.com/controls/cpcScanner.cab
[Java Plug-in 1.5.0_09]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
[Java Plug-in 1.5.0_10]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
[Java Plug-in 1.5.0_11]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
[Java Plug-in 1.6.0_01]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
[Java Plug-in 1.6.0_02]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
[Java Plug-in 1.6.0_03]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
[Java Plug-in 1.6.0_05]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS1\system32\Macromed\Flash\Flash9f.ocx
CODEBASE = http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
[Quantum Streaming IE Player Class]
InProcServer32 = "C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\Move Networks\ie_bin\qsp2ie07074039.dll"
CODEBASE = http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
[Performance Viewer Activex Control]
InProcServer32 = C:\WINDOWS1\Downloaded Program Files\RACtrl.dll
CODEBASE = https://secure.logmein.com/activex/ractrl.cab?lmi=100
--------------------------------------------------
Enumerating Winsock LSP files:
NameSpace #1: C:\WINDOWS1\System32\mswsock.dll
NameSpace #2: C:\WINDOWS1\System32\winrnr.dll
NameSpace #3: C:\WINDOWS1\System32\mswsock.dll
Protocol #1: C:\WINDOWS1\system32\mswsock.dll
Protocol #2: C:\WINDOWS1\system32\mswsock.dll
Protocol #3: C:\WINDOWS1\system32\mswsock.dll
Protocol #4: C:\WINDOWS1\system32\rsvpsp.dll
Protocol #5: C:\WINDOWS1\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS1\system32\mswsock.dll
Protocol #7: C:\WINDOWS1\system32\mswsock.dll
Protocol #8: C:\WINDOWS1\system32\mswsock.dll
Protocol #9: C:\WINDOWS1\system32\mswsock.dll
Protocol #10: C:\WINDOWS1\system32\mswsock.dll
Protocol #11: C:\WINDOWS1\system32\mswsock.dll
Protocol #12: C:\WINDOWS1\system32\mswsock.dll
Protocol #13: C:\WINDOWS1\system32\mswsock.dll
--------------------------------------------------
Enumerating Windows NT/2000/XP services
Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD Networking Support Environment: \SystemRoot\System32\drivers\afd.sys (system)
Alerter: %SystemRoot%\System32\svchost.exe -k LocalService (disabled)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
AMD K7 Processor Driver: System32\DRIVERS\amdk7.sys (system)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: System32\DRIVERS\atapi.sys (system)
Ati HotKey Poller: %SystemRoot%\system32\Ati2evxx.exe (autostart)
ati2mtag: System32\DRIVERS\ati2mtag.sys (manual start)
atimtag: System32\DRIVERS\atimtag.sys (manual start)
ATI WDM Rage Theater Video (Microsoft Corporation): System32\DRIVERS\atinrvxx.sys (manual start)
ATI Parental control device: System32\DRIVERS\atipcxxx.sys (manual start)
ATI WDM TV Tuner (Microsoft Corporation): System32\DRIVERS\atintuxx.sys (manual start)
ATI WDM Rage Theater Audio (Microsoft Corporation): System32\DRIVERS\atinraxx.sys (manual start)
ATI Rage Theatre Video (ATIRTCAP): System32\DRIVERS\atirtcap.sys (manual start)
ATI Audio Crossbar (ATIVXBAR): System32\DRIVERS\ativxbar.sys (manual start)
ATI WDM TV Audio (Microsoft Corporation) Crossbar (Microsoft Corporation): System32\DRIVERS\atinxsxx.sys (manual start)
ATM ARP Client Protocol: System32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
AVG8 E-mail Scanner: C:\PROGRA~1\AVG\AVG8\avgemc.exe (autostart)
AVG8 WatchDog: C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (autostart)
AVG AVI Loader Driver x86: \SystemRoot\System32\Drivers\avgldx86.sys (system)
AVG On-access Scanner Minifilter Driver x86: \SystemRoot\System32\Drivers\avgmfx86.sys (system)
AVG8 Network Redirector: \SystemRoot\System32\Drivers\avgtdix.sys (autostart)
basic2
here are my logs
jhazel3@put yahoo here
ComboFix 08-06-20.4 - jim 2008-06-25 14:02:13.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.242 [GMT -4:00]
Running from: C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\SpeedRunner
C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\SpeedRunner\config.cfg
C:\Program Files\Common Files\fnts~1
C:\Program Files\Common Files\fnts~1\F?nts\
C:\Program Files\Common Files\scurit~1
C:\Program Files\Spcron
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS1\444.470
C:\WINDOWS1\444.471
C:\WINDOWS1\BMabe41b4a.xml
C:\WINDOWS1\cookies.ini
C:\WINDOWS1\ctfmon32.exe
C:\WINDOWS1\ctrlpan.dll
C:\WINDOWS1\directx32.exe
C:\WINDOWS1\dnsrelay.dll
C:\WINDOWS1\editpad.exe
C:\WINDOWS1\explore.exe
C:\WINDOWS1\explorer32.exe
C:\WINDOWS1\funniest.exe
C:\WINDOWS1\funny.exe
C:\WINDOWS1\gfmnaaa.dll
C:\WINDOWS1\helpcvs.exe
C:\WINDOWS1\inetinf.exe
C:\WINDOWS1\internet.exe
C:\WINDOWS1\mainms.vpi
C:\WINDOWS1\megavid.cdt
C:\WINDOWS1\msconfd.dll
C:\WINDOWS1\msspi.dll
C:\WINDOWS1\mswsc10.dll
C:\WINDOWS1\mswsc20.dll
C:\WINDOWS1\muotr.so
C:\WINDOWS1\pskt.ini
C:\WINDOWS1\qttasks.exe
C:\WINDOWS1\quicken.exe
C:\WINDOWS1\rundll16.exe
C:\WINDOWS1\rundll32.vbe
C:\WINDOWS1\searchword.dll
C:\WINDOWS1\sistem.exe
C:\WINDOWS1\svchost32.exe
C:\WINDOWS1\svcinit.exe
C:\WINDOWS1\system32\drivers\compbattt.sys
C:\WINDOWS1\system32\efhkj.ini
C:\WINDOWS1\system32\efhkj.ini2
C:\WINDOWS1\system32\hjsikxxc.ini
C:\WINDOWS1\system32\imlyrrxd.ini
C:\WINDOWS1\system32\mcrh.tmp
C:\WINDOWS1\system32\MSINET.oca
C:\WINDOWS1\system32\scbzzwhzdpv.dll
C:\WINDOWS1\system32\winpfz33.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_COMPBATTT
-------\Service_compbattt
((((((((((((((((((((((((( Files Created from 2008-05-25 to 2008-06-25 )))))))))))))))))))))))))))))))
.
2008-06-25 06:18 . 2008-06-25 06:18 64,179 --a------ C:\WINDOWS1\system32\mwialkiggbwxcuakv.exe
2008-06-24 18:16 . 2008-06-24 18:16 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-24 18:16 . 2008-06-24 18:16 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS1\Application Data\Spybot - Search & Destroy
2008-06-24 07:51 . 2008-06-24 07:51 <DIR> d-------- C:\Program Files\BChanger
2008-06-22 17:32 . 2008-06-22 17:32 <DIR> d-------- C:\Program Files\GetModule
2008-06-22 17:02 . 2008-06-22 17:02 <DIR> d--h----- C:\$AVG8.VAULT$
2008-06-22 16:59 . 2008-06-22 16:59 <DIR> d--hs---- C:\FOUND.000
2008-06-22 16:36 . 2008-06-22 16:36 <DIR> d-------- C:\WINDOWS1\system32\drivers\Avg
2008-06-22 16:36 . 2008-06-22 16:36 <DIR> d-------- C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\AVGTOOLBAR
2008-06-22 16:36 . 2008-06-22 16:36 96,520 --a------ C:\WINDOWS1\system32\drivers\avgldx86.sys
2008-06-22 16:36 . 2008-06-22 16:36 75,272 --a------ C:\WINDOWS1\system32\drivers\avgtdix.sys
2008-06-22 16:36 . 2008-06-22 16:36 10,520 --a------ C:\WINDOWS1\system32\avgrsstx.dll
2008-06-22 16:35 . 2008-06-22 16:35 <DIR> d-------- C:\Program Files\AVG
2008-06-22 16:35 . 2008-06-22 16:35 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS1\Application Data\avg8
2008-06-22 13:39 . 2008-06-23 00:50 3,078 --a------ C:\WINDOWS1\system32\tmp.reg
2008-06-22 13:38 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS1\system32\VCCLSID.exe
2008-06-22 13:38 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS1\system32\SrchSTS.exe
2008-06-22 13:38 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS1\system32\VACFix.exe
2008-06-22 13:38 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS1\system32\IEDFix.exe
2008-06-22 13:38 . 2008-06-15 15:28 81,920 --a------ C:\WINDOWS1\system32\IEDFix.C.exe
2008-06-22 13:38 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS1\system32\404Fix.exe
2008-06-22 13:38 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS1\system32\Process.exe
2008-06-22 13:38 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS1\system32\dumphive.exe
2008-06-22 13:38 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS1\system32\WS2Fix.exe
2008-06-21 20:58 . 2008-06-21 20:58 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-06-21 20:58 . 2008-06-21 20:58 <DIR> d-------- C:\Documents and Settings\Administrator
2008-06-21 17:46 . 2008-06-21 17:46 9,662 --a------ C:\WINDOWS1\system32\ZoneAlarmIconUS.ico
2008-06-21 17:20 . 2008-06-21 17:20 <DIR> d-------- C:\WINDOWS1\rzzi
2008-06-21 17:20 . 2008-06-21 17:20 <DIR> d-------- C:\Program Files\Common Files\rzzi
2008-06-21 17:14 . 2008-06-21 17:14 <DIR> d-------- C:\Program Files\iCheck
2008-06-21 17:14 . 2008-06-21 17:14 <DIR> d-------- C:\Program Files\GetPack
2008-06-21 17:08 . 2008-06-21 17:08 <DIR> d-------- C:\Program Files\Sacor
2008-06-21 17:03 . 2008-06-21 17:03 <DIR> d-------- C:\Program Files\mjc
2008-06-21 17:02 . 2008-06-21 17:02 <DIR> d--hs---- C:\WINDOWS1\TmFuY3kg
2008-06-21 17:01 . 2008-06-21 17:01 <DIR> d-------- C:\WINDOWS1\system32\netrax06
2008-06-21 17:01 . 2008-06-21 17:01 <DIR> d-------- C:\WINDOWS1\system32\eb10
2008-06-21 17:01 . 2008-06-21 17:01 <DIR> d-------- C:\WINDOWS1\system32\bgi
2008-06-21 17:01 . 2008-06-21 17:01 <DIR> d-------- C:\WINDOWS1\system32\axc
2008-06-21 17:01 . 2008-06-21 17:01 <DIR> d-------- C:\WINDOWS1\system32\1049a
2008-06-21 17:01 . 2008-06-21 17:01 <DIR> d-------- C:\Temp\itmp4
2008-06-21 17:01 . 2008-06-21 17:01 114,688 --a------ C:\Documents and Settings\All Users.WINDOWS1\Application Data\gbczotcp.dll
2008-06-21 17:00 . 2008-06-21 17:00 <DIR> d-------- C:\Program Files\Common Files\AutoEnginuity
2008-06-21 17:00 . 2008-06-21 17:00 <DIR> d-------- C:\Program Files\AutoEnginuity
2008-06-20 20:28 . 2008-06-20 20:28 <DIR> d-------- C:\Program Files\uTorrent
2008-06-20 20:27 . 2008-06-20 20:27 <DIR> d-------- C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\uTorrent
2008-06-20 19:25 . 2008-06-20 19:25 <DIR> d-------- C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Downloads
2008-06-20 19:25 . 2008-06-20 19:25 <DIR> d-------- C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\NewsLeecher
2008-06-18 22:12 . 2008-06-18 22:12 <DIR> d-------- C:\Program Files\NewsBinGN
2008-06-18 22:12 . 2008-06-18 22:12 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS1\Application Data\NewsBin
2008-06-18 21:53 . 2008-06-18 21:53 <DIR> d-------- C:\Program Files\NewsLeecher
2008-06-18 19:56 . 2008-06-18 19:57 <DIR> d-------- C:\Program Files\Binary Boy
2008-06-18 19:18 . 2004-07-14 12:54 676,864 --a------ C:\WINDOWS1\system32\drivers\hardlock.sys
2008-06-18 19:18 . 2008-06-18 19:18 47,616 --a------ C:\WINDOWS1\system32\drivers\Haspnt.sys
2008-06-18 19:18 . 2008-06-18 19:18 6,656 --a------ C:\WINDOWS1\system32\haspvdd.dll
2008-06-18 19:18 . 2006-08-09 23:46 2,577 --a------ C:\WINDOWS1\system32\config.hsp
2008-06-18 19:18 . 2008-06-18 19:18 383 --a------ C:\WINDOWS1\system32\haspdos.sys
2008-06-18 19:17 . 2008-06-18 19:17 <DIR> d-------- C:\Program Files\Common Files\ALLDATA Shared
2008-06-18 19:17 . 2008-06-18 19:17 <DIR> d-------- C:\ALLDATAW
2008-06-18 19:17 . 2006-01-26 14:12 327,680 --------- C:\WINDOWS1\system32\haspms32.dll
2008-06-18 19:17 . 2003-04-18 15:29 44,544 --------- C:\WINDOWS1\system32\msxml4a.dll
2008-06-18 18:30 . 2008-06-18 18:30 <DIR> d-------- C:\Program Files\7-Zip
2008-06-17 22:44 . 2008-06-17 22:44 <DIR> d-------- C:\Program Files\Alcohol Soft
2008-06-17 22:39 . 2008-06-17 22:39 716,272 --a------ C:\WINDOWS1\system32\drivers\sptd.sys
2008-06-17 21:54 . 2008-06-17 21:54 <DIR> d-------- C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\Forte
2008-06-17 21:53 . 2008-06-17 21:53 <DIR> d-------- C:\Program Files\Agent
2008-06-14 22:51 . 2008-06-14 22:51 <DIR> d-------- C:\Program Files\Client
2008-06-11 03:27 . 2008-06-13 09:10 272,128 --------- C:\WINDOWS1\system32\dllcache\bthport.sys
2008-06-07 21:23 . 2004-08-17 23:14 442,368 -ra------ C:\WINDOWS1\system32\vp6vfw.dll
2008-06-07 18:25 . 2008-06-07 18:25 <DIR> d-------- C:\Netsetup
2008-05-29 18:47 . 2008-05-29 18:47 <DIR> d-------- C:\Documents and Settings\Alyssia\Application Data\acccore
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-13 13:10 272,128 ------w C:\WINDOWS1\system32\drivers\bthport.sys
2008-05-22 01:02 --------- d-----w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\acccore
2008-05-22 01:01 --------- d-----w C:\Program Files\AIMTunes
2008-05-22 01:00 --------- d-----w C:\Documents and Settings\All Users.WINDOWS1\Application Data\AOL Downloads
2008-05-22 00:59 --------- d-----w C:\Documents and Settings\All Users.WINDOWS1\Application Data\Viewpoint
2008-05-22 00:59 --------- d-----w C:\Documents and Settings\All Users.WINDOWS1\Application Data\AOL OCP
2008-05-22 00:59 --------- d-----w C:\Documents and Settings\All Users.WINDOWS1\Application Data\AOL
2008-05-17 18:21 --------- d-----w C:\Program Files\Western Digital Technologies
2008-05-11 00:21 --------- d-----w C:\Program Files\AIM6
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS1\system32\drivers\RMCast.sys
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS1\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS1\system32\quartz.dll
2008-05-07 05:18 1,287,680 ------w C:\WINDOWS1\system32\dllcache\quartz.dll
2008-04-24 02:16 3,591,680 ----a-w C:\WINDOWS1\system32\dllcache\mshtml.dll
2008-04-22 07:40 625,664 ------w C:\WINDOWS1\system32\dllcache\iexplore.exe
2008-04-22 07:39 70,656 ------w C:\WINDOWS1\system32\dllcache\ie4uinit.exe
2008-04-22 07:39 13,824 ------w C:\WINDOWS1\system32\dllcache\ieudinit.exe
2008-04-20 05:07 161,792 ----a-w C:\WINDOWS1\system32\dllcache\ieakui.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS1\system32\msjint40.dll
2008-03-27 08:12 151,583 ------w C:\WINDOWS1\system32\dllcache\msjint40.dll
2007-05-21 23:26 633,856 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\EscapeToNorrath.exe
2007-05-21 23:25 633,856 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\_scapeToNorrath.exe
2007-02-25 16:46 92,064 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\mqdmmdm.sys
2007-02-25 16:46 9,232 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\mqdmmdfl.sys
2007-02-25 16:46 79,328 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\mqdmserd.sys
2007-02-25 16:46 66,656 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\mqdmbus.sys
2007-02-25 16:46 6,208 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\mqdmcmnt.sys
2007-02-25 16:46 5,936 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\mqdmwhnt.sys
2007-02-25 16:46 4,048 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\mqdmcr.sys
2007-02-25 16:46 25,600 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\usbsermptxp.sys
2007-02-25 16:46 22,768 ----a-w C:\Documents and Settings\jim.HEAD-WUFEOHT14M\usbsermpt.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3670A914-63C2-4E67-8C9B-370AE1922143}]
2008-06-19 10:21 36864 --a------ C:\Program Files\BChanger\bchanger.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8C13E23C-7B8A-0658-FF34-71A2E4E84892}]
C:\WINDOWS1\system32\gdsxuef.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8D524C93-D2F3-4F75-A1DA-1C3E66F8B77A}]
C:\WINDOWS1\system32\jkhfe.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{98dbbf16-ca43-4c33-be80-99e6694468a4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A90BD234-2A69-4EBA-A8FE-BAC927C212CD}]
C:\WINDOWS1\system32\geeba.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bc97b254-b2b9-4d40-971d-78e0978f5f26}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e873aa24-1a96-4a8a-86bc-2b4733c05448}]
C:\WINDOWS1\system32\fpgtdlcg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E9383002-FC55-4330-B9C9-67E03BC5C840}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fec3c4df-4545-2fe3-ea4e-24f1067fffa1}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS1\system32\ctfmon.exe" [2004-08-04 03:56 15360]
"PowerPanel Personal Edition User Interaction"="C:\Program Files\CyberPower PowerPanel Personal Edition\pppeuser.exe" [2005-10-24 10:26 262144]
"PCTAVApp"="C:\Program Files\PC Tools AntiVirus\PCTAV.exe" [2006-08-15 21:59 1110016]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 17:57 1103480]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-03-25 16:21 50528]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-03-20 12:49 217544]
"mjc"="C:\Program Files\mjc\mjc.exe" [2008-06-21 17:03 145408]
"GetPack19"="C:\Program Files\GetPack\GetPack19.exe" [2008-06-17 05:56 350208]
"Crao"="C:\PROGRA~1\COMMON~1\FNTS~1\dvdplay.exe" [ ]
"Ylhxiz"="C:\Program Files\Common Files\s?curity\r?gsvr32.exe" [ ]
"GetModule19"="C:\Program Files\GetModule\GetModule19.exe" [2008-06-17 05:58 351744]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"SpeedRunner"="C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\SpeedRunner\SpeedRunner.exe" [ ]
"SfKg6wIP"="C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\Microsoft\Windows\obnaw.exe" [ ]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingB9652"="command" []
"SpybotDeletingD7735"="del" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2007-03-01 14:34 35928]
"SansaDispatch"="C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe" [2007-10-22 12:52 75584]
"RegistryMechanic"="C:\Program Files\Registry Mechanic\regmech.exe" [2006-04-05 09:56 2177256]
"Lexmark X74-X75"="C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 15:09 57344]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-10 13:46 1838592]
"CARPService"="carpserv.exe" [2001-12-23 20:02 4608 C:\WINDOWS1\system32\carpserv.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"a8d728d6"="C:\WINDOWS1\system32\dxrrylmi.dll" [ ]
"BMabe41b4a"="C:\WINDOWS1\system32\qnrwrpnt.dll" [ ]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-22 16:35 1177368]
"{0caabaf0-1a92-6e16-27c8-58c705def711}"="C:\WINDOWS1\system32\scbzzwhzdpv.dll" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA9986"="command" []
"SpybotDeletingA5258"="command" []
"SpybotDeletingC3620"="del" []
"SpybotDeletingA7011"="command" []
"SpybotDeletingC8501"="del" []
"SpybotDeletingA8329"="command" []
"SpybotDeletingC9191"="del" []
"SpybotDeletingA2114"="command" []
"SpybotDeletingA9089"="command" []
"SpybotDeletingC1771"="del" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [2007-01-12 14:06 2115728]
C:\Documents and Settings\Guest.WINDOWS1\Start Menu\Programs\Startup\
OpenOffice.org 2.1.lnk - C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe [2006-11-27 16:45:48 393216]
C:\Documents and Settings\Nancy\Start Menu\Programs\Startup\
Event Reminder.lnk - C:\pmw\PMREMIND.EXE [1998-05-18 12:41:00 255408]
C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Start Menu\Programs\Startup\
OpenOffice.org 2.1.lnk - C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe [2006-11-27 16:45:48 393216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"gbczotcp"= {dca236f8-fbdd-4c06-84f2-9202b29b2e94} - C:\Documents and Settings\All Users.WINDOWS1\Application Data\gbczotcp.dll [2008-06-21 17:01 114688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\\WINDOWS1\\system32\\userinit.exe,C:\\WINDOWS1\\system32\\iftuyszv.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qomllmn]
qomllmn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=boteziwa.dll,C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIVX"= svmp4.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\PC Tools AntiVirus\\PCTAV.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS1\\System32\\lexpps.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.1.0-enUS-downloader.exe"=
"C:\\WINDOWS1\\System32\\dpvsetup.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Documents and Settings\\Alyssia\\Application Data\\MySpace\\IM\\bin\\MySpaceIM.exe"=
"C:\\Program Files\\Client\\ClientMain.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS1\system32\Drivers\avgldx86.sys [2008-06-22 16:36]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-06-22 16:35]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-22 16:35]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS1\system32\Drivers\avgtdix.sys [2008-06-22 16:36]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
S3 ATIPCXXX;ATI Parental control device;C:\WINDOWS1\system32\DRIVERS\atipcxxx.sys [2001-08-17 12:49]
S3 ATIVRVXX;ATI Rage Theatre Video (ATIRTCAP);C:\WINDOWS1\system32\DRIVERS\atirtcap.sys [2001-08-17 12:49]
S3 ATIVXSXX;ATI Audio Crossbar (ATIVXBAR);C:\WINDOWS1\system32\DRIVERS\ativxbar.sys [2001-08-17 12:49]
S3 mqdmbus;Motorola DM Composite Driver (WDM);C:\WINDOWS1\system32\DRIVERS\mqdmbus.sys [2007-02-25 12:46]
S3 mqdmmdfl;Motorola USB Modem (Filter);C:\WINDOWS1\system32\DRIVERS\mqdmmdfl.sys [2007-02-25 12:46]
S3 mqdmmdm;Motorola USB Modem;C:\WINDOWS1\system32\DRIVERS\mqdmmdm.sys [2007-02-25 12:46]
S3 mqdmserd;Motorola USB Diag;C:\WINDOWS1\system32\DRIVERS\mqdmserd.sys [2007-02-25 12:46]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{385b7390-1574-11dd-99bb-00e04c89103a}]
\Shell\AutoRun\command - C:\WINDOWS1\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL http://www.mgae.com/keylauncher/?code=3654263318491817
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c9442a8a-dee9-11dc-99ae-00e04c89103a}]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-25 14:11:39
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\C:\WINDOWS1\TEMP\mc21.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS1\explorer.exe
-> C:\Program Files\SiteAdvisor\6253\saHook.dll
-> C:\Documents and Settings\All Users.WINDOWS1\Application Data\gbczotcp.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS1\SYSTEM32\LEXBCES.EXE
C:\WINDOWS1\SYSTEM32\LEXPPS.EXE
C:\PROGRAM FILES\AVG\AVG8\AVGWDSVC.EXE
C:\PROGRAM FILES\PC TOOLS ANTIVIRUS\PCTAVSVC.EXE
C:\PROGRAM FILES\CYBERPOWER POWERPANEL PERSONAL EDITION\PPPED.EXE
C:\PROGRAM FILES\SPYWARE DOCTOR\SDHELP.EXE
C:\PROGRAM FILES\ALCOHOL SOFT\ALCOHOL 120\STARWIND\STARWINDSERVICEAE.EXE
C:\PROGRAM FILES\LEXMARK X74-X75\LXBBBMON.EXE
C:\PROGRAM FILES\AVG\AVG8\AVGTRAY.EXE
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRAM FILES\AVG\AVG8\AVGRSX.EXE
C:\PROGRAM FILES\AVG\AVG8\AVGRSX.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
.
**************************************************************************
.
Completion time: 2008-06-25 14:18:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-25 18:17:30
Pre-Run: 1,961,132,032 bytes free
Post-Run: 6,386,057,216 bytes free
329 --- E O F --- 2008-06-20 07:00:35
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:23:34, on 6/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS1\System32\smss.exe
C:\WINDOWS1\system32\csrss.exe
C:\WINDOWS1\system32\winlogon.exe
C:\WINDOWS1\system32\services.exe
C:\WINDOWS1\system32\lsass.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\system32\LEXBCES.EXE
C:\WINDOWS1\system32\LEXPPS.EXE
C:\WINDOWS1\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS1\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
C:\WINDOWS1\System32\alg.exe
C:\Program Files\Registry Mechanic\regmech.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\WINDOWS1\system32\carpserv.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS1\system32\ctfmon.exe
C:\Program Files\CyberPower PowerPanel Personal Edition\pppeuser.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\mjc\mjc.exe
C:\Program Files\GetPack\GetPack19.exe
C:\Program Files\GetModule\GetModule19.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS1\explorer.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS1\System32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fptb-mdp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS1\system32\userinit.exe,C:\WINDOWS1\system32\iftuyszv.exe,
O2 - BHO: (no name) - `C B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: Helper Class - {3670A914-63C2-4E67-8C9B-370AE1922143} - C:\Program Files\BChanger\bchanger.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8C13E23C-7B8A-0658-FF34-71A2E4E84892} - C:\WINDOWS1\system32\gdsxuef.dll (file missing)
O2 - BHO: (no name) - {8D524C93-D2F3-4F75-A1DA-1C3E66F8B77A} - C:\WINDOWS1\system32\jkhfe.dll (file missing)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {A90BD234-2A69-4EBA-A8FE-BAC927C212CD} - C:\WINDOWS1\system32\geeba.dll (file missing)
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: {84450c33-74b2-cb68-a8a4-69a142aa378e} - {e873aa24-1a96-4a8a-86bc-2b4733c05448} - C:\WINDOWS1\system32\fpgtdlcg.dll (file missing)
O2 - BHO: (no name) - C 497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: (no name) - ¨ ¨ D-6927-48C8-A975-17DF180C71AC} - (no file)
O2 - BHO: (no name) - āC 8ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [SansaDispatch] C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\regmech.exe /H
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [a8d728d6] rundll32.exe "C:\WINDOWS1\system32\dxrrylmi.dll",b
O4 - HKLM\..\Run: [BMabe41b4a] Rundll32.exe "C:\WINDOWS1\system32\qnrwrpnt.dll",s
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [{0caabaf0-1a92-6e16-27c8-58c705def711}] C:\WINDOWS1\System32\Rundll32.exe "C:\WINDOWS1\system32\scbzzwhzdpv.dll" DllStart
O4 - HKLM\..\RunOnce: [SpybotDeletingA9986] command /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5258] command /c del "C:\Program Files\ASPMonitor\logs\computer.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3620] cmd /c del "C:\Program Files\ASPMonitor\logs\computer.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7011] command /c del "C:\Program Files\ASPMonitor\logs\filedir.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8501] cmd /c del "C:\Program Files\ASPMonitor\logs\filedir.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8329] command /c del "C:\Program Files\ASPMonitor\logs\inetcon.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9191] cmd /c del "C:\Program Files\ASPMonitor\logs\inetcon.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2114] command /c del "C:\Program Files\ASPMonitor\logs\prnt.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9089] command /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1771] cmd /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS1\system32\ctfmon.exe
O4 - HKCU\..\Run: [PowerPanel Personal Edition User Interaction] "C:\Program Files\CyberPower PowerPanel Personal Edition\pppeuser.exe"
O4 - HKCU\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [mjc] C:\Program Files\mjc\mjc.exe
O4 - HKCU\..\Run: [GetPack19] "C:\Program Files\GetPack\GetPack19.exe"
O4 - HKCU\..\Run: [Crao] "C:\PROGRA~1\COMMON~1\FNTS~1\dvdplay.exe" -vt yazb
O4 - HKCU\..\Run: [Ylhxiz] "C:\Program Files\Common Files\s?curity\r?gsvr32.exe"
O4 - HKCU\..\Run: [GetModule19] "C:\Program Files\GetModule\GetModule19.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpeedRunner] C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\SpeedRunner\SpeedRunner.exe
O4 - HKCU\..\Run: [SfKg6wIP] C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\Microsoft\Windows\obnaw.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB9652] command /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7735] cmd /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155688179437
O16 - DPF: {A609CB6E-FEB5-47C3-966C-1B916842BD01} (Nlopflash Class) - http://poker.milbestlight.com/poker/PokerCreations.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CCS\Services\Tcpip\..\{0B767B2F-DA23-41FE-8D13-742906F589EE}: NameServer = 69.51.159.21,69.51.159.22
O17 - HKLM\System\CS1\Services\Tcpip\..\{0B767B2F-DA23-41FE-8D13-742906F589EE}: NameServer = 69.51.159.21,69.51.159.22
O17 - HKLM\System\CS3\Services\Tcpip\..\{0B767B2F-DA23-41FE-8D13-742906F589EE}: NameServer = 69.51.159.21,69.51.159.22
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: boteziwa.dll,C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll
O20 - Winlogon Notify: qomllmn - qomllmn.dll (file missing)
O21 - SSODL: gbczotcp - {dca236f8-fbdd-4c06-84f2-9202b29b2e94} - C:\Documents and Settings\All Users.WINDOWS1\Application Data\gbczotcp.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS1\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS1\system32\LEXBCES.EXE
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - Unknown owner - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: PowerPanel Personal Edition Service (ppped) - Unknown owner - C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 13706 bytes
StartupList report, 6/25/2008, 2:32:31 PM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16674)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================
Running processes:
C:\WINDOWS1\System32\smss.exe
C:\WINDOWS1\system32\csrss.exe
C:\WINDOWS1\system32\winlogon.exe
C:\WINDOWS1\system32\services.exe
C:\WINDOWS1\system32\lsass.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\system32\LEXBCES.EXE
C:\WINDOWS1\system32\LEXPPS.EXE
C:\WINDOWS1\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Program Files\CyberPower PowerPanel Personal Edition\ppped.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS1\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
C:\WINDOWS1\System32\alg.exe
C:\Program Files\Registry Mechanic\regmech.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\WINDOWS1\system32\carpserv.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS1\system32\ctfmon.exe
C:\Program Files\CyberPower PowerPanel Personal Edition\pppeuser.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\mjc\mjc.exe
C:\Program Files\GetPack\GetPack19.exe
C:\Program Files\GetModule\GetModule19.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS1\explorer.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS1\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Start Menu\Programs\Startup]
OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
Shell folders AltStartup:
*Folder not found*
User shell folders Startup:
*Folder not found*
User shell folders AltStartup:
*Folder not found*
Shell folders Common Startup:
[C:\Documents and Settings\All Users.WINDOWS1\Start Menu\Programs\Startup]
*No files*
Shell folders Common AltStartup:
*Folder not found*
User shell folders Common Startup:
*Folder not found*
User shell folders Alternate Common Startup:
*Folder not found*
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS1\system32\userinit.exe,C:\WINDOWS1\system32\iftuyszv.exe,
[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*
[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SunJavaUpdateSched = "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
SiteAdvisor = C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
SansaDispatch = C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
RegistryMechanic = C:\Program Files\Registry Mechanic\regmech.exe /H
Lexmark X74-X75 = "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
Google Desktop Search = "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
CARPService = carpserv.exe
Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
a8d728d6 = rundll32.exe "C:\WINDOWS1\system32\dxrrylmi.dll",b
BMabe41b4a = Rundll32.exe "C:\WINDOWS1\system32\qnrwrpnt.dll",s
AVG8_TRAY = C:\PROGRA~1\AVG\AVG8\avgtray.exe
{0caabaf0-1a92-6e16-27c8-58c705def711} = C:\WINDOWS1\System32\Rundll32.exe "C:\WINDOWS1\system32\scbzzwhzdpv.dll" DllStart
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
SpybotDeletingA9986 = command /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
SpybotDeletingA5258 = command /c del "C:\Program Files\ASPMonitor\logs\computer.dat"
SpybotDeletingC3620 = cmd /c del "C:\Program Files\ASPMonitor\logs\computer.dat"
SpybotDeletingA7011 = command /c del "C:\Program Files\ASPMonitor\logs\filedir.dat"
SpybotDeletingC8501 = cmd /c del "C:\Program Files\ASPMonitor\logs\filedir.dat"
SpybotDeletingA8329 = command /c del "C:\Program Files\ASPMonitor\logs\inetcon.dat"
SpybotDeletingC9191 = cmd /c del "C:\Program Files\ASPMonitor\logs\inetcon.dat"
SpybotDeletingA2114 = command /c del "C:\Program Files\ASPMonitor\logs\prnt.dat"
SpybotDeletingA9089 = command /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
SpybotDeletingC1771 = cmd /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS1\system32\ctfmon.exe
PowerPanel Personal Edition User Interaction = "C:\Program Files\CyberPower PowerPanel Personal Edition\pppeuser.exe"
PCTAVApp = "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
igndlm.exe = C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
Aim6 = "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
AlcoholAutomount = "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
mjc = C:\Program Files\mjc\mjc.exe
GetPack19 = "C:\Program Files\GetPack\GetPack19.exe"
Crao = "C:\PROGRA~1\COMMON~1\FNTS~1\dvdplay.exe" -vt yazb
Ylhxiz = "C:\Program Files\Common Files\s?curity\r?gsvr32.exe"
GetModule19 = "C:\Program Files\GetModule\GetModule19.exe"
SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background
SpeedRunner = C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\SpeedRunner\SpeedRunner.exe
SfKg6wIP = C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\Microsoft\Windows\obnaw.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
SpybotDeletingB9652 = command /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
SpybotDeletingD7735 = cmd /c del "C:\WINDOWS1\system32\drivers\core.cache.dsk"
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[OptionalComponents]
=
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command
(Default) = "%1" /S
--------------------------------------------------
File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command
(Default) = C:\WINDOWS1\system32\mshta.exe "%1" %*
--------------------------------------------------
File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1
--------------------------------------------------
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)
[<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}] *
StubPath = C:\WINDOWS1\system32\ieudinit.exe
[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS1\inf\unregmp2.exe /ShowWMP
[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = C:\WINDOWS1\system32\ie4uinit.exe -UserIconConfig
[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS1\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS1\INF\msmsgs.inf,BLC.QuietInstall.PerUser
[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS1\INF\wmp11.inf,PerUserStub
[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll
[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = C:\WINDOWS1\system32\ie4uinit.exe -BaseSettings
--------------------------------------------------
Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps
*Registry key not found*
--------------------------------------------------
Load/Run keys from C:\WINDOWS1\WIN.INI:
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=boteziwa.dll,C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS1\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS1\System32\ssmarque.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Checking for EXPLORER.EXE instances:
C:\WINDOWS1\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
C:\WINDOWS1\Explorer\Explorer.exe: not present
C:\WINDOWS1\System\Explorer.exe: not present
C:\WINDOWS1\System32\Explorer.exe: not present
C:\WINDOWS1\Command\Explorer.exe: not present
C:\WINDOWS1\Fonts\Explorer.exe: not present
--------------------------------------------------
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden
--------------------------------------------------
Verifying REGEDIT.EXE integrity:
- Regedit.exe found in C:\WINDOWS1
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'
Registry check passed
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - (no file) - `C B2A36-3DB1-42A4-A3CB-D426709BBFEB}
(no name) - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll - {02478D38-C3F9-4EFB-9B51-7695ECA05670}
(no name) - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll - {089FD14D-132B-48FC-8861-0048AE113215}
(no name) - C:\Program Files\BChanger\bchanger.dll - {3670A914-63C2-4E67-8C9B-370AE1922143}
WormRadar.com IESiteBlocker.NavFilter - C:\Program Files\AVG\AVG8\avgssie.dll - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}
(no name) - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - C:\WINDOWS1\system32\gdsxuef.dll (file missing) - {8C13E23C-7B8A-0658-FF34-71A2E4E84892}
(no name) - C:\WINDOWS1\system32\jkhfe.dll (file missing) - {8D524C93-D2F3-4F75-A1DA-1C3E66F8B77A}
(no name) - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL - {A057A204-BACC-4D26-9990-79A187E2698E}
(no name) - C:\WINDOWS1\system32\geeba.dll (file missing) - {A90BD234-2A69-4EBA-A8FE-BAC927C212CD}
(no name) - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll - {B56A7D7D-6927-48C8-A975-17DF180C71AC}
{84450c33-74b2-cb68-a8a4-69a142aa378e} - C:\WINDOWS1\system32\fpgtdlcg.dll (file missing) - {e873aa24-1a96-4a8a-86bc-2b4733c05448}
(no name) - (no file) - C 497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - (no file) - ¨ ¨ D-6927-48C8-A975-17DF180C71AC}
(no name) - (no file) - āC 8ED58-01DD-4d91-8333-CF10577473F7}
--------------------------------------------------
Enumerating Task Scheduler jobs:
*No jobs found*
--------------------------------------------------
Enumerating Download Program Files:
[YInstStarter Class]
InProcServer32 = C:\WINDOWS1\Downloaded Program Files\yinsthelper.dll
CODEBASE = http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
[CDownloadCtrl Object]
InProcServer32 = C:\Program Files\Download Manager\DLMControl.dll
CODEBASE = http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
[MUWebControl Class]
InProcServer32 = C:\WINDOWS1\system32\muweb.dll
CODEBASE = http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155688179437
[Java Plug-in 1.6.0_05]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
[{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
CODEBASE = http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
[Nlopflash Class]
InProcServer32 = C:\WINDOWS1\Downloaded Program Files\nlop.dll
CODEBASE = http://poker.milbestlight.com/poker/PokerCreations.cab
[Crucial cpcScan]
InProcServer32 = C:\WINDOWS1\Downloaded Program Files\cpcScan.dll
CODEBASE = http://www.crucial.com/controls/cpcScanner.cab
[Java Plug-in 1.5.0_09]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
[Java Plug-in 1.5.0_10]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
[Java Plug-in 1.5.0_11]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
[Java Plug-in 1.6.0_01]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
[Java Plug-in 1.6.0_02]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
[Java Plug-in 1.6.0_03]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
[Java Plug-in 1.6.0_05]
InProcServer32 = C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS1\system32\Macromed\Flash\Flash9f.ocx
CODEBASE = http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
[Quantum Streaming IE Player Class]
InProcServer32 = "C:\Documents and Settings\jim.HEAD-WUFEOHT14M\Application Data\Move Networks\ie_bin\qsp2ie07074039.dll"
CODEBASE = http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
[Performance Viewer Activex Control]
InProcServer32 = C:\WINDOWS1\Downloaded Program Files\RACtrl.dll
CODEBASE = https://secure.logmein.com/activex/ractrl.cab?lmi=100
--------------------------------------------------
Enumerating Winsock LSP files:
NameSpace #1: C:\WINDOWS1\System32\mswsock.dll
NameSpace #2: C:\WINDOWS1\System32\winrnr.dll
NameSpace #3: C:\WINDOWS1\System32\mswsock.dll
Protocol #1: C:\WINDOWS1\system32\mswsock.dll
Protocol #2: C:\WINDOWS1\system32\mswsock.dll
Protocol #3: C:\WINDOWS1\system32\mswsock.dll
Protocol #4: C:\WINDOWS1\system32\rsvpsp.dll
Protocol #5: C:\WINDOWS1\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS1\system32\mswsock.dll
Protocol #7: C:\WINDOWS1\system32\mswsock.dll
Protocol #8: C:\WINDOWS1\system32\mswsock.dll
Protocol #9: C:\WINDOWS1\system32\mswsock.dll
Protocol #10: C:\WINDOWS1\system32\mswsock.dll
Protocol #11: C:\WINDOWS1\system32\mswsock.dll
Protocol #12: C:\WINDOWS1\system32\mswsock.dll
Protocol #13: C:\WINDOWS1\system32\mswsock.dll
--------------------------------------------------
Enumerating Windows NT/2000/XP services
Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD Networking Support Environment: \SystemRoot\System32\drivers\afd.sys (system)
Alerter: %SystemRoot%\System32\svchost.exe -k LocalService (disabled)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
AMD K7 Processor Driver: System32\DRIVERS\amdk7.sys (system)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: System32\DRIVERS\atapi.sys (system)
Ati HotKey Poller: %SystemRoot%\system32\Ati2evxx.exe (autostart)
ati2mtag: System32\DRIVERS\ati2mtag.sys (manual start)
atimtag: System32\DRIVERS\atimtag.sys (manual start)
ATI WDM Rage Theater Video (Microsoft Corporation): System32\DRIVERS\atinrvxx.sys (manual start)
ATI Parental control device: System32\DRIVERS\atipcxxx.sys (manual start)
ATI WDM TV Tuner (Microsoft Corporation): System32\DRIVERS\atintuxx.sys (manual start)
ATI WDM Rage Theater Audio (Microsoft Corporation): System32\DRIVERS\atinraxx.sys (manual start)
ATI Rage Theatre Video (ATIRTCAP): System32\DRIVERS\atirtcap.sys (manual start)
ATI Audio Crossbar (ATIVXBAR): System32\DRIVERS\ativxbar.sys (manual start)
ATI WDM TV Audio (Microsoft Corporation) Crossbar (Microsoft Corporation): System32\DRIVERS\atinxsxx.sys (manual start)
ATM ARP Client Protocol: System32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
AVG8 E-mail Scanner: C:\PROGRA~1\AVG\AVG8\avgemc.exe (autostart)
AVG8 WatchDog: C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (autostart)
AVG AVI Loader Driver x86: \SystemRoot\System32\Drivers\avgldx86.sys (system)
AVG On-access Scanner Minifilter Driver x86: \SystemRoot\System32\Drivers\avgmfx86.sys (system)
AVG8 Network Redirector: \SystemRoot\System32\Drivers\avgtdix.sys (autostart)
basic2