Ok, like so many others here, I've just suffered a virtumonde.dll attack. Running Windows XP Pro Service Pack 3. 99.9% positive that it came from downloading and installing a Nero 8 Trial version from dodgy source that packed the trojan in with it. Windows security centre is fouled up, auto updates appears to be off even though I've set it to 'on' and I can't find and use the Microsoft Malicious Software Removal Tool either. Neither IE7 nor Firefox 3 are allowing me to browse at all. Avast warns me that something external is trying to connect with the trojan and allows me to break that connection, but it won't find and kill the problem. Spybot found the issue, but as with everyone else, it returns on reboot and with teatime causing so many issues, I've uninstalled it for the time being. Now using a separate computer to transfer info between the infected machine and the internet. Both ComboFix and HijackThis have been run with the log files copied below. Please let me know what else I need to do.
ComboFix 08-05-15.3 - Administrator 2008-05-18 15:57:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2496 [GMT 1:00]
Running from: G:\Utilities\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aIRsttwa.ini
C:\WINDOWS\system32\aIRsttwa.ini2
C:\WINDOWS\system32\dwxxdpnb.ini
C:\WINDOWS\system32\FLmTAcfe.ini
C:\WINDOWS\system32\FLmTAcfe.ini2
C:\WINDOWS\system32\jkdxhmel.ini
C:\WINDOWS\system32\ljrvcxjn.ini
C:\WINDOWS\system32\nnvccsps.ini
C:\WINDOWS\system32\uEeOqBeg.ini
C:\WINDOWS\system32\uEeOqBeg.ini2
.
((((((((((((((((((((((((( Files Created from 2008-04-18 to 2008-05-18 )))))))))))))))))))))))))))))))
.
2008-05-18 16:06 . 2008-05-18 16:06 417 --ahs---- C:\WINDOWS\system32\aIRsttwa.ini
2008-05-18 16:03 . 2008-05-18 16:03 <DIR> d-------- C:\WINDOWS\system32\xircom
2008-05-18 16:03 . 2008-05-18 16:03 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-05-18 13:54 . 2008-05-18 13:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-18 13:52 . 2008-05-18 13:52 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-18 13:36 . 2008-05-18 13:36 117,248 --a------ C:\WINDOWS\system32\spsccvnn.dll
2008-05-18 13:30 . 2008-05-18 13:30 133,120 --a------ C:\WINDOWS\system32\lakcthev.dll
2008-05-18 13:19 . 2008-05-18 13:19 124,928 --a------ C:\WINDOWS\system32\exjguhim.dll
2008-05-18 13:18 . 2008-05-18 13:18 371,200 --a------ C:\WINDOWS\system32\awttsRIa.dll
2008-05-18 12:42 . 2008-05-18 12:42 133,120 --a------ C:\WINDOWS\system32\swflcrmv.dll
2008-05-18 12:24 . 2008-05-18 12:24 124,928 --a------ C:\WINDOWS\system32\ftwydiix.dll
2008-05-18 12:21 . 2008-05-18 12:21 9,439 --a------ C:\WINDOWS\system32\qirgmqfv.dll
2008-05-18 11:30 . 2008-05-18 11:30 371,200 --a------ C:\WINDOWS\system32\efcATmLF.dll_old
2008-05-18 10:41 . 2008-05-18 12:19 211 --a------ C:\WINDOWS\wininit.ini
2008-05-18 09:11 . 2008-05-18 13:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-17 23:10 . 2008-05-17 23:10 134,144 --a------ C:\WINDOWS\system32\musmrwqf.dll
2008-05-17 23:04 . 2008-05-17 23:04 125,952 --a------ C:\WINDOWS\system32\dxiltrbx.dll
2008-05-17 23:04 . 2008-05-18 16:05 109,807 --a------ C:\WINDOWS\BM67ef7406.xml
2008-05-17 10:54 . 2008-05-17 10:54 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Nero
2008-05-17 10:53 . 2008-05-17 10:53 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\X10 Commander
2008-05-17 10:52 . 2008-05-17 10:52 59,392 --a------ C:\WINDOWS\system32\urqPFUlj.dll
2008-05-17 10:47 . 2008-05-17 22:31 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-05-17 10:47 . 2008-05-17 22:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-05-16 01:32 . 2008-05-16 01:32 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-04-29 18:10 . 2003-10-17 17:14 315,436 --a------ C:\WINDOWS\_detmp.2
2008-04-29 18:10 . 2008-04-13 12:03 4,105 --a------ C:\WINDOWS\_detmp.1
2008-04-26 12:44 . 2008-05-17 19:37 38 --a------ C:\WINDOWS\avisplitter.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-18 15:07 7,387,168 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-18 15:06 --------- d-----w C:\Documents and Settings\Administrator\Application Data\OpenOffice.org2
2008-05-18 15:01 103,184 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-29 17:17 --------- d-----w C:\Program Files\USB Super Link
2008-04-13 21:27 --------- d-----w C:\Program Files\Unlocker
2008-04-13 19:02 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Winamp
2008-04-13 11:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-13 10:06 --------- d-----w C:\Documents and Settings\Administrator\Application Data\J River
2008-04-12 20:34 --------- d-----w C:\Program Files\Java
2008-04-12 20:04 28,276 ----a-w C:\WINDOWS\system32\drivers\MxlW2k.sys
2008-04-12 19:48 --------- d-----w C:\Program Files\MUSICMATCH
2008-04-12 18:55 --------- d-----w C:\Documents and Settings\Administrator\Application Data\vlc
2008-04-12 18:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-12 17:54 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Creative
2008-04-12 17:43 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Talkback
2008-04-12 16:35 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Talkback
2008-04-12 14:18 --------- d-----w C:\Program Files\ZoneAlarmSB
2008-04-12 14:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-04-12 13:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Creative
2008-04-12 13:52 --------- d-----w C:\Program Files\Creative
2008-04-12 13:48 81,920 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-04-12 13:48 233,472 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-04-12 13:40 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-12 13:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\ATI MMC
2008-04-12 13:25 --------- d-----w C:\Program Files\Common Files\ATI
2008-04-12 13:25 --------- d-----w C:\Program Files\ATI Multimedia
2008-04-12 13:23 --------- d-----w C:\Program Files\msaccrt
2008-04-12 13:22 --------- d-----w C:\Program Files\Windows Media Components
2008-04-12 13:22 --------- d-----w C:\Program Files\Common Files\CyberLink
2008-04-12 13:21 --------- d-----w C:\Program Files\ATI Technologies
2008-04-12 13:11 --------- d-----w C:\Program Files\Chaintech
2008-04-12 13:08 --------- d-----w C:\Program Files\Generic
2008-04-12 13:07 724,992 ----a-w C:\WINDOWS\iun6002.exe
2008-04-12 11:39 --------- d-----w C:\Program Files\VistaExperience.org
2008-04-12 11:39 --------- d-----w C:\Program Files\Styler
2008-04-12 11:39 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Styler
2008-04-12 11:34 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-12 11:33 --------- d-----w C:\Program Files\Windows Sidebar
2008-04-12 11:32 --------- d-----w C:\Program Files\Sysinternals
2008-04-12 11:32 --------- d-----w C:\Program Files\Stardock
2008-04-12 11:32 --------- d-----w C:\Program Files\Kristanix
2008-04-12 11:32 --------- d-----w C:\Program Files\Common Files\Stardock
2008-04-12 11:32 --------- d-----w C:\Program Files\Alky for Applications
2008-04-12 11:31 --------- d-----w C:\Program Files\Common Files\Java
2008-04-12 11:31 --------- d-----w C:\Program Files\CCleaner
2008-04-12 11:29 89 ----a-w C:\WINDOWS\system32\config\systemprofile\Del213D.bat
2008-04-12 11:29 89 ----a-w C:\Documents and Settings\Default User\Del213D.bat
2008-04-12 11:29 89 ----a-w C:\Documents and Settings\Administrator\Del213D.bat
2008-04-12 11:28 --------- d-----w C:\Program Files\Reference Assemblies
2008-04-12 11:28 --------- d-----w C:\Program Files\MSBuild
2008-04-12 11:18 --------- d-----w C:\Program Files\Utilities
2008-04-12 11:18 --------- d-----w C:\Program Files\LClock
2008-04-12 11:18 --------- d-----w C:\Program Files\Desktop
2008-04-12 11:17 --------- d-----w C:\Program Files\TaskSwitchXP
2008-04-12 11:17 --------- d-----w C:\Program Files\JkDefragGUI
2008-04-12 11:17 --------- d-----w C:\Program Files\Attribute Changer
2008-03-27 19:22 3,038 ----a-w C:\WINDOWS\system32\presetup.cmd
2008-03-27 19:22 28,672 ----a-w C:\WINDOWS\system32\setupold.exe
2008-03-27 19:22 159,744 ----a-w C:\WINDOWS\system32\drivers\fst376xp.sys
2008-03-27 19:15 86,073 ----a-w C:\WINDOWS\system32\usrfaxa.dll
2008-03-27 19:12 990,208 ----a-w C:\WINDOWS\system32\syssetup.dll
2008-03-27 19:12 61,952 ----a-w C:\WINDOWS\system32\hdaudpropshortcut.exe
2008-03-27 19:12 5,120 ----a-w C:\WINDOWS\system32\hdaudpropres.dll
2008-03-27 19:12 361,344 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-03-27 19:12 24,064 ----a-w C:\WINDOWS\system32\hdaudprop.dll
2008-03-27 19:12 2,350,208 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-03-27 19:12 140,288 ----a-w C:\WINDOWS\system32\sfc_os.dll
2008-03-27 19:12 113,664 ----a-w C:\WINDOWS\inf\hdaudio.sys
2008-03-27 19:10 98,304 ----a-w C:\WINDOWS\system32\makecab.exe
2008-03-27 19:09 3,734,536 ----a-w C:\WINDOWS\system32\d3dx9_36.dll
2008-03-27 19:09 3,727,720 ----a-w C:\WINDOWS\system32\d3dx9_35.dll
2008-03-27 19:09 3,497,832 ----a-w C:\WINDOWS\system32\d3dx9_34.dll
2008-03-27 19:09 3,495,784 ----a-w C:\WINDOWS\system32\d3dx9_33.dll
2008-03-27 19:09 3,426,072 ----a-w C:\WINDOWS\system32\d3dx9_32.dll
2008-03-27 19:09 2,414,360 ----a-w C:\WINDOWS\system32\d3dx9_31.dll
2008-03-27 19:09 2,297,552 ----a-w C:\WINDOWS\system32\d3dx9_26.dll
2008-03-23 20:48 11,217,408 ----a-w C:\WINDOWS\system32\logonui.exe
2008-03-22 17:30 2,085,376 ----a-w C:\WINDOWS\system32\x264vfw.dll
2008-03-21 07:32 1,295,938 ----a-r C:\WINDOWS\SET3.tmp
2008-03-21 07:25 1,088,979 ----a-r C:\WINDOWS\SET4.tmp
2008-03-21 07:24 16,674 ----a-r C:\WINDOWS\SET8.tmp
2008-03-21 06:36 74,752 ----a-w C:\WINDOWS\system32\storprop.dll
2008-03-21 06:36 74,240 ----a-w C:\WINDOWS\system32\usbui.dll
2008-03-21 06:36 29,184 ----a-w C:\WINDOWS\system32\sdhcinst.dll
2008-03-21 06:35 30,208 ----a-w C:\WINDOWS\system32\bthserv.dll
2008-03-21 06:35 20,992 ----a-w C:\WINDOWS\system32\bthci.dll
2008-03-21 05:49 1,804 ----a-w C:\WINDOWS\system32\Dcache.bin
2008-03-21 05:40 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-03-21 05:37 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-03-21 05:37 9,216 ----a-w C:\WINDOWS\system32\scrnsave.scr
2008-03-21 05:37 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-03-21 05:37 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys
2008-03-21 05:37 299,520 ----a-w C:\WINDOWS\system32\drmclien.dll
2008-03-21 05:37 21,896 ----a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2008-03-21 05:37 146,432 ----a-w C:\WINDOWS\system32\winspool.drv
2008-03-21 05:37 139,656 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2008-03-21 05:37 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-03-21 05:37 12,040 ----a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2008-03-21 05:35 98,304 ----a-w C:\WINDOWS\system32\actxprxy.dll
2008-03-21 05:34 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
.
------- Sigcheck -------
2008-03-27 20:12 361344 a3c3d568108ad955870b288769f9c97d C:\WINDOWS\system32\drivers\tcpip.sys
2008-03-27 20:16 2227072 d81c9e73280e3843c1ffb3f9fbca3ac0 C:\WINDOWS\system32\ntkrnlpa.exe
2008-03-27 20:12 2350208 56313f4d281f6770783a918474539594 C:\WINDOWS\system32\ntoskrnl.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{12137C43-7BE4-4014-9EBB-542CD7EAB82D}]
C:\WINDOWS\system32\geBqOeEu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{324a17bf-46ed-4d07-bbe4-159418d17fa5}]
2008-05-18 13:30 133120 --a------ C:\WINDOWS\system32\lakcthev.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{36D9CB8D-B8CA-4A85-A879-06A71109F11E}]
2008-05-17 10:52 59392 --a------ C:\WINDOWS\system32\urqPFUlj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AF575173-2BB7-48EF-A66F-EAEE28AE524E}]
C:\WINDOWS\system32\efcATmLF.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B1D0A1B5-4079-4181-83BC-44F79D5AFDAC}]
2008-05-18 13:18 371200 --a------ C:\WINDOWS\system32\awttsRIa.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL" [2008-04-12 15:18 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-04-12 15:18 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-03-21 06:36 15360]
"TaskSwitchXP"="C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 14:59 62976]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-03-22 22:18 1271808]
"ATI Remote Control"="C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe" [2004-03-23 05:39 196608]
"Creative Detector"="G:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23 102400]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ptipbmf"="ptipbmf.dll" [2006-02-26 16:21 118784 C:\WINDOWS\system32\ptipbmf.dll]
"LClock"="C:\Program Files\LClock\LClock.exe" [2004-09-19 12:27 65536]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-02-27 09:33 15872]
"VisualTooltip"="C:\Program Files\Utilities\VisualTooltip\VisualToolTip.exe" [2007-04-25 09:45 956928]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Disk Monitor"="C:\Program Files\Generic\6-in-1 USB Card Reader Driver v1.8b\Disk_Monitor.exe" [2002-10-04 03:35 438784]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-23 21:10 335872]
"ATI DeviceDetect"="C:\Program Files\ATI Multimedia\\Program Files\ATI Multimedia\main\ATIDtct.EXE" [ ]
"CTDVDDET"="C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 01:00 45056]
"RCSystem"="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 18:25 49152]
"AudioDrvEmulator"="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 18:25 49152]
"CTHelper"="CTHELPER.EXE" [2005-08-07 23:10 16384 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2005-08-07 23:10 18944 C:\WINDOWS\system32\CTXFIHLP.EXE]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00 90112]
"ashMaiSv"="G:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe" [2008-05-16 00:19 247160]
"ZoneAlarm Client"="G:\Program Files\ZoneAlarm\zlclient.exe" [2008-03-13 23:11 919016]
"WinampAgent"="G:\Program Files\Winamp\winampa.exe" [2008-04-01 19:49 36352]
"NBKeyScan"="G:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"64dc479a"="C:\WINDOWS\system32\spsccvnn.dll" [2008-05-18 13:36 117248]
"BM67ef7406"="C:\WINDOWS\system32\exjguhim.dll" [2008-05-18 13:19 124928]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-03-21 06:36 15360]
"TaskSwitchXP"="C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 14:59 62976]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2008-03-01 14:03 124928 C:\WINDOWS\system32\advpack.dll]
"ShowDeskFix"="regsvr32 /s /n /i:u shell32" []
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - G:\Program Files\Open Office\program\quickstart.exe [1/21/2008 3:41:28 PM 393216]
Styler.lnk - C:\Documents and Settings\Administrator\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [4/12/2008 12:38:22 PM 15086]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{36D9CB8D-B8CA-4A85-A879-06A71109F11E}"= C:\WINDOWS\system32\urqPFUlj.dll [2008-05-17 10:52 59392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqPFUlj]
urqPFUlj.dll 2008-05-17 10:52 59392 C:\WINDOWS\system32\urqPFUlj.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.X264"= x264vfw.dll
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\awttsRIa
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R0 fst376xp;fst376xp;C:\WINDOWS\system32\drivers\fst376xp.sys [2008-03-27 20:22]
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;C:\WINDOWS\system32\DRIVERS\nvcchflt.sys [2006-02-26 16:21]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 00:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 00:16]
R2 MEMACC;MemAccess Library Driver;C:\WINDOWS\system32\memacc.sys [2001-03-01 08:00]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2005-08-07 22:54]
S3 Usblink;Usblink Driver;C:\WINDOWS\system32\Drivers\ulink.sys [2003-08-08 10:07]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
RUNDLL32 advpack.dll,LaunchINFSection Sidebar.inf,Register
.
Contents of the 'Scheduled Tasks' folder
"2008-05-18 11:25:19 C:\WINDOWS\Tasks\User_Feed_Synchronization-{3B52C62C-7EDB-4270-BAF0-7AD2D2C262EA}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-18 16:06:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\aIRsttwa.ini 345 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\urqPFUlj.dll
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Unlocker\UnlockerHook.dll
-> C:\WINDOWS\system32\spsccvnn.dll
-> C:\WINDOWS\system32\exjguhim.dll
-> C:\WINDOWS\system32\awttsRIa.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
G:\Program Files\Lavasoft\Ad Aware\aawservice.exe
G:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
G:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\CTXFISPI.EXE
G:\Program Files\Alwil Software\Avast4\Setup\avast.setup
C:\Program Files\Styler\Styler.exe
C:\WINDOWS\system32\rundll32.exe
G:\Program Files\Open Office\program\soffice.exe
G:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
G:\Program Files\Open Office\program\soffice.bin
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
.
**************************************************************************
.
Completion time: 2008-05-18 16:09:34 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-18 15:07:59
Pre-Run: 3,195,199,488 bytes free
Post-Run: 4,077,355,008 bytes free
294 --- E O F --- 2008-05-16 10:41:23
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:15:07, on 18/05/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20772)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
G:\Program Files\Lavasoft\Ad Aware\aawservice.exe
G:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
G:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Utilities\VisualTooltip\VisualToolTip.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Generic\6-in-1 USB Card Reader Driver v1.8b\Disk_Monitor.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
G:\Program Files\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
G:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
G:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Styler\Styler.exe
C:\WINDOWS\system32\rundll32.exe
G:\Program Files\Open Office\program\soffice.exe
G:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
G:\Program Files\Open Office\program\soffice.BIN
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\WINDOWS\explorer.exe
G:\Program Files\Hijack This\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sirius.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:12080
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [VisualTooltip] C:\Program Files\Utilities\VisualTooltip\VisualToolTip.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Disk Monitor] C:\Program Files\Generic\6-in-1 USB Card Reader Driver v1.8b\Disk_Monitor.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ashMaiSv] G:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "G:\Program Files\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [WinampAgent] "G:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [NBKeyScan] "G:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [64dc479a] rundll32.exe "C:\WINDOWS\system32\spsccvnn.dll",b
O4 - HKLM\..\Run: [BM67ef7406] Rundll32.exe "C:\WINDOWS\system32\exjguhim.dll",s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [Creative Detector] "G:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = G:\Program Files\Open Office\program\quickstart.exe
O4 - Startup: Styler.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - G:\Program Files\Lavasoft\Ad Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - G:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - G:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - G:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - G:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
--
End of file - 8062 bytes
ComboFix 08-05-15.3 - Administrator 2008-05-18 15:57:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2496 [GMT 1:00]
Running from: G:\Utilities\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aIRsttwa.ini
C:\WINDOWS\system32\aIRsttwa.ini2
C:\WINDOWS\system32\dwxxdpnb.ini
C:\WINDOWS\system32\FLmTAcfe.ini
C:\WINDOWS\system32\FLmTAcfe.ini2
C:\WINDOWS\system32\jkdxhmel.ini
C:\WINDOWS\system32\ljrvcxjn.ini
C:\WINDOWS\system32\nnvccsps.ini
C:\WINDOWS\system32\uEeOqBeg.ini
C:\WINDOWS\system32\uEeOqBeg.ini2
.
((((((((((((((((((((((((( Files Created from 2008-04-18 to 2008-05-18 )))))))))))))))))))))))))))))))
.
2008-05-18 16:06 . 2008-05-18 16:06 417 --ahs---- C:\WINDOWS\system32\aIRsttwa.ini
2008-05-18 16:03 . 2008-05-18 16:03 <DIR> d-------- C:\WINDOWS\system32\xircom
2008-05-18 16:03 . 2008-05-18 16:03 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-05-18 13:54 . 2008-05-18 13:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-18 13:52 . 2008-05-18 13:52 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-18 13:36 . 2008-05-18 13:36 117,248 --a------ C:\WINDOWS\system32\spsccvnn.dll
2008-05-18 13:30 . 2008-05-18 13:30 133,120 --a------ C:\WINDOWS\system32\lakcthev.dll
2008-05-18 13:19 . 2008-05-18 13:19 124,928 --a------ C:\WINDOWS\system32\exjguhim.dll
2008-05-18 13:18 . 2008-05-18 13:18 371,200 --a------ C:\WINDOWS\system32\awttsRIa.dll
2008-05-18 12:42 . 2008-05-18 12:42 133,120 --a------ C:\WINDOWS\system32\swflcrmv.dll
2008-05-18 12:24 . 2008-05-18 12:24 124,928 --a------ C:\WINDOWS\system32\ftwydiix.dll
2008-05-18 12:21 . 2008-05-18 12:21 9,439 --a------ C:\WINDOWS\system32\qirgmqfv.dll
2008-05-18 11:30 . 2008-05-18 11:30 371,200 --a------ C:\WINDOWS\system32\efcATmLF.dll_old
2008-05-18 10:41 . 2008-05-18 12:19 211 --a------ C:\WINDOWS\wininit.ini
2008-05-18 09:11 . 2008-05-18 13:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-17 23:10 . 2008-05-17 23:10 134,144 --a------ C:\WINDOWS\system32\musmrwqf.dll
2008-05-17 23:04 . 2008-05-17 23:04 125,952 --a------ C:\WINDOWS\system32\dxiltrbx.dll
2008-05-17 23:04 . 2008-05-18 16:05 109,807 --a------ C:\WINDOWS\BM67ef7406.xml
2008-05-17 10:54 . 2008-05-17 10:54 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Nero
2008-05-17 10:53 . 2008-05-17 10:53 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\X10 Commander
2008-05-17 10:52 . 2008-05-17 10:52 59,392 --a------ C:\WINDOWS\system32\urqPFUlj.dll
2008-05-17 10:47 . 2008-05-17 22:31 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-05-17 10:47 . 2008-05-17 22:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-05-16 01:32 . 2008-05-16 01:32 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-04-29 18:10 . 2003-10-17 17:14 315,436 --a------ C:\WINDOWS\_detmp.2
2008-04-29 18:10 . 2008-04-13 12:03 4,105 --a------ C:\WINDOWS\_detmp.1
2008-04-26 12:44 . 2008-05-17 19:37 38 --a------ C:\WINDOWS\avisplitter.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-18 15:07 7,387,168 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-18 15:06 --------- d-----w C:\Documents and Settings\Administrator\Application Data\OpenOffice.org2
2008-05-18 15:01 103,184 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-29 17:17 --------- d-----w C:\Program Files\USB Super Link
2008-04-13 21:27 --------- d-----w C:\Program Files\Unlocker
2008-04-13 19:02 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Winamp
2008-04-13 11:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-13 10:06 --------- d-----w C:\Documents and Settings\Administrator\Application Data\J River
2008-04-12 20:34 --------- d-----w C:\Program Files\Java
2008-04-12 20:04 28,276 ----a-w C:\WINDOWS\system32\drivers\MxlW2k.sys
2008-04-12 19:48 --------- d-----w C:\Program Files\MUSICMATCH
2008-04-12 18:55 --------- d-----w C:\Documents and Settings\Administrator\Application Data\vlc
2008-04-12 18:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-12 17:54 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Creative
2008-04-12 17:43 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Talkback
2008-04-12 16:35 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Talkback
2008-04-12 14:18 --------- d-----w C:\Program Files\ZoneAlarmSB
2008-04-12 14:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-04-12 13:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Creative
2008-04-12 13:52 --------- d-----w C:\Program Files\Creative
2008-04-12 13:48 81,920 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-04-12 13:48 233,472 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-04-12 13:40 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-12 13:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\ATI MMC
2008-04-12 13:25 --------- d-----w C:\Program Files\Common Files\ATI
2008-04-12 13:25 --------- d-----w C:\Program Files\ATI Multimedia
2008-04-12 13:23 --------- d-----w C:\Program Files\msaccrt
2008-04-12 13:22 --------- d-----w C:\Program Files\Windows Media Components
2008-04-12 13:22 --------- d-----w C:\Program Files\Common Files\CyberLink
2008-04-12 13:21 --------- d-----w C:\Program Files\ATI Technologies
2008-04-12 13:11 --------- d-----w C:\Program Files\Chaintech
2008-04-12 13:08 --------- d-----w C:\Program Files\Generic
2008-04-12 13:07 724,992 ----a-w C:\WINDOWS\iun6002.exe
2008-04-12 11:39 --------- d-----w C:\Program Files\VistaExperience.org
2008-04-12 11:39 --------- d-----w C:\Program Files\Styler
2008-04-12 11:39 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Styler
2008-04-12 11:34 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-12 11:33 --------- d-----w C:\Program Files\Windows Sidebar
2008-04-12 11:32 --------- d-----w C:\Program Files\Sysinternals
2008-04-12 11:32 --------- d-----w C:\Program Files\Stardock
2008-04-12 11:32 --------- d-----w C:\Program Files\Kristanix
2008-04-12 11:32 --------- d-----w C:\Program Files\Common Files\Stardock
2008-04-12 11:32 --------- d-----w C:\Program Files\Alky for Applications
2008-04-12 11:31 --------- d-----w C:\Program Files\Common Files\Java
2008-04-12 11:31 --------- d-----w C:\Program Files\CCleaner
2008-04-12 11:29 89 ----a-w C:\WINDOWS\system32\config\systemprofile\Del213D.bat
2008-04-12 11:29 89 ----a-w C:\Documents and Settings\Default User\Del213D.bat
2008-04-12 11:29 89 ----a-w C:\Documents and Settings\Administrator\Del213D.bat
2008-04-12 11:28 --------- d-----w C:\Program Files\Reference Assemblies
2008-04-12 11:28 --------- d-----w C:\Program Files\MSBuild
2008-04-12 11:18 --------- d-----w C:\Program Files\Utilities
2008-04-12 11:18 --------- d-----w C:\Program Files\LClock
2008-04-12 11:18 --------- d-----w C:\Program Files\Desktop
2008-04-12 11:17 --------- d-----w C:\Program Files\TaskSwitchXP
2008-04-12 11:17 --------- d-----w C:\Program Files\JkDefragGUI
2008-04-12 11:17 --------- d-----w C:\Program Files\Attribute Changer
2008-03-27 19:22 3,038 ----a-w C:\WINDOWS\system32\presetup.cmd
2008-03-27 19:22 28,672 ----a-w C:\WINDOWS\system32\setupold.exe
2008-03-27 19:22 159,744 ----a-w C:\WINDOWS\system32\drivers\fst376xp.sys
2008-03-27 19:15 86,073 ----a-w C:\WINDOWS\system32\usrfaxa.dll
2008-03-27 19:12 990,208 ----a-w C:\WINDOWS\system32\syssetup.dll
2008-03-27 19:12 61,952 ----a-w C:\WINDOWS\system32\hdaudpropshortcut.exe
2008-03-27 19:12 5,120 ----a-w C:\WINDOWS\system32\hdaudpropres.dll
2008-03-27 19:12 361,344 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-03-27 19:12 24,064 ----a-w C:\WINDOWS\system32\hdaudprop.dll
2008-03-27 19:12 2,350,208 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-03-27 19:12 140,288 ----a-w C:\WINDOWS\system32\sfc_os.dll
2008-03-27 19:12 113,664 ----a-w C:\WINDOWS\inf\hdaudio.sys
2008-03-27 19:10 98,304 ----a-w C:\WINDOWS\system32\makecab.exe
2008-03-27 19:09 3,734,536 ----a-w C:\WINDOWS\system32\d3dx9_36.dll
2008-03-27 19:09 3,727,720 ----a-w C:\WINDOWS\system32\d3dx9_35.dll
2008-03-27 19:09 3,497,832 ----a-w C:\WINDOWS\system32\d3dx9_34.dll
2008-03-27 19:09 3,495,784 ----a-w C:\WINDOWS\system32\d3dx9_33.dll
2008-03-27 19:09 3,426,072 ----a-w C:\WINDOWS\system32\d3dx9_32.dll
2008-03-27 19:09 2,414,360 ----a-w C:\WINDOWS\system32\d3dx9_31.dll
2008-03-27 19:09 2,297,552 ----a-w C:\WINDOWS\system32\d3dx9_26.dll
2008-03-23 20:48 11,217,408 ----a-w C:\WINDOWS\system32\logonui.exe
2008-03-22 17:30 2,085,376 ----a-w C:\WINDOWS\system32\x264vfw.dll
2008-03-21 07:32 1,295,938 ----a-r C:\WINDOWS\SET3.tmp
2008-03-21 07:25 1,088,979 ----a-r C:\WINDOWS\SET4.tmp
2008-03-21 07:24 16,674 ----a-r C:\WINDOWS\SET8.tmp
2008-03-21 06:36 74,752 ----a-w C:\WINDOWS\system32\storprop.dll
2008-03-21 06:36 74,240 ----a-w C:\WINDOWS\system32\usbui.dll
2008-03-21 06:36 29,184 ----a-w C:\WINDOWS\system32\sdhcinst.dll
2008-03-21 06:35 30,208 ----a-w C:\WINDOWS\system32\bthserv.dll
2008-03-21 06:35 20,992 ----a-w C:\WINDOWS\system32\bthci.dll
2008-03-21 05:49 1,804 ----a-w C:\WINDOWS\system32\Dcache.bin
2008-03-21 05:40 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-03-21 05:37 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-03-21 05:37 9,216 ----a-w C:\WINDOWS\system32\scrnsave.scr
2008-03-21 05:37 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-03-21 05:37 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys
2008-03-21 05:37 299,520 ----a-w C:\WINDOWS\system32\drmclien.dll
2008-03-21 05:37 21,896 ----a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2008-03-21 05:37 146,432 ----a-w C:\WINDOWS\system32\winspool.drv
2008-03-21 05:37 139,656 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2008-03-21 05:37 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-03-21 05:37 12,040 ----a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2008-03-21 05:35 98,304 ----a-w C:\WINDOWS\system32\actxprxy.dll
2008-03-21 05:34 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
.
------- Sigcheck -------
2008-03-27 20:12 361344 a3c3d568108ad955870b288769f9c97d C:\WINDOWS\system32\drivers\tcpip.sys
2008-03-27 20:16 2227072 d81c9e73280e3843c1ffb3f9fbca3ac0 C:\WINDOWS\system32\ntkrnlpa.exe
2008-03-27 20:12 2350208 56313f4d281f6770783a918474539594 C:\WINDOWS\system32\ntoskrnl.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{12137C43-7BE4-4014-9EBB-542CD7EAB82D}]
C:\WINDOWS\system32\geBqOeEu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{324a17bf-46ed-4d07-bbe4-159418d17fa5}]
2008-05-18 13:30 133120 --a------ C:\WINDOWS\system32\lakcthev.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{36D9CB8D-B8CA-4A85-A879-06A71109F11E}]
2008-05-17 10:52 59392 --a------ C:\WINDOWS\system32\urqPFUlj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AF575173-2BB7-48EF-A66F-EAEE28AE524E}]
C:\WINDOWS\system32\efcATmLF.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B1D0A1B5-4079-4181-83BC-44F79D5AFDAC}]
2008-05-18 13:18 371200 --a------ C:\WINDOWS\system32\awttsRIa.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL" [2008-04-12 15:18 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-04-12 15:18 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-03-21 06:36 15360]
"TaskSwitchXP"="C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 14:59 62976]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-03-22 22:18 1271808]
"ATI Remote Control"="C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe" [2004-03-23 05:39 196608]
"Creative Detector"="G:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23 102400]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ptipbmf"="ptipbmf.dll" [2006-02-26 16:21 118784 C:\WINDOWS\system32\ptipbmf.dll]
"LClock"="C:\Program Files\LClock\LClock.exe" [2004-09-19 12:27 65536]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-02-27 09:33 15872]
"VisualTooltip"="C:\Program Files\Utilities\VisualTooltip\VisualToolTip.exe" [2007-04-25 09:45 956928]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Disk Monitor"="C:\Program Files\Generic\6-in-1 USB Card Reader Driver v1.8b\Disk_Monitor.exe" [2002-10-04 03:35 438784]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-23 21:10 335872]
"ATI DeviceDetect"="C:\Program Files\ATI Multimedia\\Program Files\ATI Multimedia\main\ATIDtct.EXE" [ ]
"CTDVDDET"="C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 01:00 45056]
"RCSystem"="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 18:25 49152]
"AudioDrvEmulator"="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 18:25 49152]
"CTHelper"="CTHELPER.EXE" [2005-08-07 23:10 16384 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2005-08-07 23:10 18944 C:\WINDOWS\system32\CTXFIHLP.EXE]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00 90112]
"ashMaiSv"="G:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe" [2008-05-16 00:19 247160]
"ZoneAlarm Client"="G:\Program Files\ZoneAlarm\zlclient.exe" [2008-03-13 23:11 919016]
"WinampAgent"="G:\Program Files\Winamp\winampa.exe" [2008-04-01 19:49 36352]
"NBKeyScan"="G:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"64dc479a"="C:\WINDOWS\system32\spsccvnn.dll" [2008-05-18 13:36 117248]
"BM67ef7406"="C:\WINDOWS\system32\exjguhim.dll" [2008-05-18 13:19 124928]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-03-21 06:36 15360]
"TaskSwitchXP"="C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 14:59 62976]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2008-03-01 14:03 124928 C:\WINDOWS\system32\advpack.dll]
"ShowDeskFix"="regsvr32 /s /n /i:u shell32" []
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - G:\Program Files\Open Office\program\quickstart.exe [1/21/2008 3:41:28 PM 393216]
Styler.lnk - C:\Documents and Settings\Administrator\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [4/12/2008 12:38:22 PM 15086]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{36D9CB8D-B8CA-4A85-A879-06A71109F11E}"= C:\WINDOWS\system32\urqPFUlj.dll [2008-05-17 10:52 59392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqPFUlj]
urqPFUlj.dll 2008-05-17 10:52 59392 C:\WINDOWS\system32\urqPFUlj.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.X264"= x264vfw.dll
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\awttsRIa
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R0 fst376xp;fst376xp;C:\WINDOWS\system32\drivers\fst376xp.sys [2008-03-27 20:22]
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;C:\WINDOWS\system32\DRIVERS\nvcchflt.sys [2006-02-26 16:21]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 00:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 00:16]
R2 MEMACC;MemAccess Library Driver;C:\WINDOWS\system32\memacc.sys [2001-03-01 08:00]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2005-08-07 22:54]
S3 Usblink;Usblink Driver;C:\WINDOWS\system32\Drivers\ulink.sys [2003-08-08 10:07]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
RUNDLL32 advpack.dll,LaunchINFSection Sidebar.inf,Register
.
Contents of the 'Scheduled Tasks' folder
"2008-05-18 11:25:19 C:\WINDOWS\Tasks\User_Feed_Synchronization-{3B52C62C-7EDB-4270-BAF0-7AD2D2C262EA}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-18 16:06:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\aIRsttwa.ini 345 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\urqPFUlj.dll
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Unlocker\UnlockerHook.dll
-> C:\WINDOWS\system32\spsccvnn.dll
-> C:\WINDOWS\system32\exjguhim.dll
-> C:\WINDOWS\system32\awttsRIa.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
G:\Program Files\Lavasoft\Ad Aware\aawservice.exe
G:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
G:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\CTXFISPI.EXE
G:\Program Files\Alwil Software\Avast4\Setup\avast.setup
C:\Program Files\Styler\Styler.exe
C:\WINDOWS\system32\rundll32.exe
G:\Program Files\Open Office\program\soffice.exe
G:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
G:\Program Files\Open Office\program\soffice.bin
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
.
**************************************************************************
.
Completion time: 2008-05-18 16:09:34 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-18 15:07:59
Pre-Run: 3,195,199,488 bytes free
Post-Run: 4,077,355,008 bytes free
294 --- E O F --- 2008-05-16 10:41:23
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:15:07, on 18/05/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20772)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
G:\Program Files\Lavasoft\Ad Aware\aawservice.exe
G:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
G:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Utilities\VisualTooltip\VisualToolTip.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Generic\6-in-1 USB Card Reader Driver v1.8b\Disk_Monitor.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
G:\Program Files\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
G:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
G:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Styler\Styler.exe
C:\WINDOWS\system32\rundll32.exe
G:\Program Files\Open Office\program\soffice.exe
G:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
G:\Program Files\Open Office\program\soffice.BIN
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\WINDOWS\explorer.exe
G:\Program Files\Hijack This\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sirius.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:12080
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [VisualTooltip] C:\Program Files\Utilities\VisualTooltip\VisualToolTip.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Disk Monitor] C:\Program Files\Generic\6-in-1 USB Card Reader Driver v1.8b\Disk_Monitor.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ashMaiSv] G:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "G:\Program Files\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [WinampAgent] "G:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [NBKeyScan] "G:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [64dc479a] rundll32.exe "C:\WINDOWS\system32\spsccvnn.dll",b
O4 - HKLM\..\Run: [BM67ef7406] Rundll32.exe "C:\WINDOWS\system32\exjguhim.dll",s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [Creative Detector] "G:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = G:\Program Files\Open Office\program\quickstart.exe
O4 - Startup: Styler.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - G:\Program Files\Lavasoft\Ad Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - G:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - G:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - G:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - G:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
--
End of file - 8062 bytes