Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:18:58 PM, on 4/27/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\wltray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Macrium\Reflect\ReflectService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Broadcom Wireless Manager] C:\WINDOWS\system32\wltray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://asia.msi.com.tw
O15 - Trusted Zone:
http://global.msi.com.tw
O15 - Trusted Zone:
http://www.msi.com.tw
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) -
http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} -
http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Fences - {EC654325-1273-C2A9-2B7C-45A29BCE2FBD} - C:\Program Files\Stardock\Fences\DesktopDock.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Macrium Reflect Image Mounting Service (ReflectService) - Unknown owner - C:\Program Files\Macrium\Reflect\ReflectService.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O23 - Service: XAMPP Service (XAMPP) - Unknown owner - E:\xampp\service.exe (file missing)
--
End of file - 6599 bytes
----------------------------------------------------------------
ComboFix 09-04-27.02 - Ryan 04/27/2009 17:15.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2812 [GMT -7:00]
Running from: c:\documents and settings\Ryan\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090319-0] *On-access scanning enabled* (Outdated)
.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-28 )))))))))))))))))))))))))))))))
.
2009-04-24 06:14 . 2009-04-24 06:14 -------- d-----w c:\program files\Trend Micro
2009-04-24 06:12 . 2009-04-24 06:13 -------- d-----w c:\program files\ERUNT
2009-04-22 04:55 . 2009-04-22 04:55 -------- d-----w c:\program files\Audacity
2009-04-21 21:49 . 2009-04-21 21:49 17 ----a-w c:\windows\popcinfo.dat
2009-04-21 06:56 . 2009-04-21 06:56 -------- d-----w c:\documents and settings\Ryan\Application Data\InstallShield
2009-04-21 06:10 . 2009-03-09 19:06 15688 ----a-w c:\windows\system32\lsdelete.exe
2009-04-21 06:06 . 2009-04-21 13:43 113575 ----a-w C:\MGlogs.zip
2009-04-21 06:06 . 2009-04-21 13:43 -------- d-----w C:\MGtools
2009-04-21 06:04 . 2009-04-06 22:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-21 06:04 . 2009-04-06 22:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-21 06:04 . 2009-04-21 06:04 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-21 06:00 . 2009-04-21 06:00 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2009-04-21 05:59 . 2009-04-21 05:59 -------- d-----w c:\program files\SUPERAntiSpyware
2009-04-21 05:58 . 2009-04-21 05:58 1340797 ----a-w C:\MGtools.exe
2009-04-21 05:07 . 2009-03-09 19:06 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-04-21 05:05 . 2009-04-21 05:05 -------- dc-h--w c:\documents and settings\All Users.WINDOWS\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-04-20 06:27 . 2009-04-20 06:29 -------- d-----w c:\program files\ACW
2009-04-20 03:52 . 2008-08-25 23:48 40496 ----a-w c:\windows\system32\drivers\hotcore3.sys
2009-04-20 03:51 . 2009-04-20 03:51 -------- d-----w c:\program files\Paragon Software
2009-04-19 19:34 . 2009-04-19 19:34 -------- d-----w c:\documents and settings\Ryan\Application Data\Auslogics
2009-04-19 19:34 . 2009-04-19 19:34 -------- d-----w c:\program files\Auslogics
2009-04-19 19:26 . 2009-04-19 19:26 -------- d-----w c:\program files\Zards software
2009-04-18 20:01 . 2009-04-19 19:45 -------- d-----w c:\documents and settings\Ryan\.sockso
2009-04-18 04:08 . 2009-04-18 04:08 -------- d-----w c:\documents and settings\Ryan\Local Settings\Application Data\Gas Powered Games
2009-04-18 03:03 . 2009-04-18 03:03 -------- d--h--w c:\windows\PIF
2009-04-18 01:45 . 2009-04-18 01:45 -------- d-----w c:\documents and settings\Ryan\Application Data\Slam Dunk Studios, LLC
2009-04-18 01:43 . 2009-04-18 01:43 4096 ----a-w c:\windows\d3dx.dat
2009-04-16 21:42 . 2009-04-16 21:42 -------- d-----w c:\documents and settings\Ryan\Shaders
2009-04-16 19:21 . 2009-02-03 19:59 56832 -c----w c:\windows\system32\dllcache\secur32.dll
2009-04-16 19:21 . 2009-03-21 14:06 989696 -c----w c:\windows\system32\dllcache\kernel32.dll
2009-04-16 19:21 . 2008-06-12 14:23 91648 -c----w c:\windows\system32\dllcache\mtxoci.dll
2009-04-16 19:21 . 2008-06-12 14:23 161792 -c----w c:\windows\system32\dllcache\msdtcuiu.dll
2009-04-16 19:21 . 2008-06-12 14:23 66560 -c----w c:\windows\system32\dllcache\mtxclu.dll
2009-04-16 19:21 . 2008-06-12 14:23 58880 -c----w c:\windows\system32\dllcache\msdtclog.dll
2009-04-16 19:21 . 2008-06-12 14:23 956928 -c----w c:\windows\system32\dllcache\msdtctm.dll
2009-04-16 19:21 . 2008-12-16 12:30 354304 -c----w c:\windows\system32\dllcache\winhttp.dll
2009-04-16 19:21 . 2009-02-20 08:10 81920 -c----w c:\windows\system32\dllcache\ieencode.dll
2009-04-16 19:20 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-16 19:20 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 19:20 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-16 19:20 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 19:20 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 19:20 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 19:20 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 19:20 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 19:20 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 19:20 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-16 19:20 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-15 02:25 . 2009-04-15 02:25 -------- d-s---w c:\documents and settings\Ryan\UserData
2009-04-14 00:41 . 2008-04-13 23:11 21504 -c--a-w c:\windows\system32\dllcache\hidserv.dll
2009-04-14 00:41 . 2008-04-13 23:11 21504 ----a-w c:\windows\system32\hidserv.dll
2009-04-13 23:03 . 2009-04-13 23:03 -------- d-----w c:\program files\Pcsx2
2009-04-11 16:39 . 2009-04-11 16:39 -------- d-----w c:\documents and settings\Ryan\Application Data\Braid
2009-04-10 15:51 . 2008-08-07 11:14 111360 ----a-r c:\windows\system32\drivers\Rtenicxp.sys
2009-04-10 15:51 . 2008-08-07 03:38 9728 ----a-r c:\windows\system32\RtNicProp32.dll
2009-04-10 15:51 . 2009-04-10 15:51 -------- d-----w c:\windows\OPTIONS
2009-04-10 15:48 . 2009-04-10 15:48 -------- d-----w c:\windows\system32\RTCOM
2009-04-10 15:48 . 2007-11-20 10:15 1826816 ------r c:\windows\SkyTel.exe
2009-04-10 15:48 . 2008-07-15 05:47 1196032 ------r c:\windows\RtlUpd.exe
2009-04-10 15:48 . 2008-06-19 08:27 9715200 ------r c:\windows\RTLCPL.exe
2009-04-10 15:48 . 2008-07-24 10:02 4749824 ------r c:\windows\system32\drivers\RtkHDAud.sys
2009-04-10 15:48 . 2008-07-23 08:51 16804864 ------r c:\windows\RTHDCPL.exe
2009-04-10 15:48 . 2007-06-28 08:44 2165760 ------r c:\windows\MicCal.exe
2009-04-10 15:48 . 2008-06-19 08:20 57344 ------r c:\windows\Alcmtr.exe
2009-04-10 15:48 . 2008-06-19 08:42 2808832 ------r c:\windows\alcwzrd.exe
2009-04-10 15:48 . 2009-04-19 19:43 -------- d-----w c:\program files\Realtek
2009-04-10 15:48 . 2009-04-10 15:48 319488 ----a-w c:\windows\HideWin.exe
2009-04-10 15:48 . 2008-07-15 05:58 524288 ------r c:\windows\RtlExUpd.dll
2009-04-10 15:43 . 2008-08-19 02:56 53248 ----a-r c:\windows\system32\CSVer.dll
2009-04-10 15:43 . 2009-04-10 15:43 -------- d-----w c:\program files\Intel
2009-04-10 15:42 . 2009-04-10 15:42 -------- d-----w C:\Intel
2009-04-10 15:42 . 2008-05-02 22:08 146528 ----a-w c:\windows\system32\dvmurl.dll
2009-04-10 15:42 . 2009-04-10 15:42 -------- d-----w c:\program files\Browser Configuration Utility
2009-04-10 15:41 . 2009-04-10 02:02 -------- d-----w c:\program files\GIGABYTE
2009-04-10 15:40 . 2009-04-28 00:13 16608 ----a-w c:\windows\gdrv.sys
2009-04-10 14:42 . 2008-04-13 17:45 20608 -c--a-w c:\windows\system32\dllcache\usbuhci.sys
2009-04-10 14:42 . 2008-04-13 17:45 20608 ----a-w c:\windows\system32\drivers\usbuhci.sys
2009-04-10 14:21 . 2009-04-10 14:21 -------- d-----w c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Google
2009-04-10 02:02 . 2009-04-20 06:25 24944 ----a-w c:\windows\system32\drivers\GVTDrv.sys
2009-04-07 01:37 . 2009-04-07 01:37 -------- d-----w C:\ubuntu-backup
2009-04-07 01:02 . 2009-04-07 01:02 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Macrium
2009-04-07 00:53 . 2009-04-07 00:53 -------- d-----w c:\program files\Macrium
2009-04-07 00:47 . 2009-04-07 01:25 -------- d-----w c:\program files\nLite
2009-04-06 05:08 . 2009-04-06 05:08 -------- d-----w c:\documents and settings\Ryan\Application Data\PyScripter
2009-04-06 02:51 . 2009-04-06 02:51 -------- d-----w c:\program files\Texter
2009-04-02 03:25 . 2007-07-24 14:24 25600 ----a-w c:\windows\system32\GTCCRMON.DLL
2009-04-02 00:17 . 2009-04-02 00:17 -------- d-----w c:\documents and settings\Ryan\Application Data\Move Networks
2009-03-30 23:57 . 2009-03-09 22:27 1846632 ----a-w c:\windows\system32\D3DCompiler_41.dll
2009-03-30 23:57 . 2009-03-09 22:27 453456 ----a-w c:\windows\system32\d3dx10_41.dll
2009-03-30 23:57 . 2009-03-09 22:27 4178264 ----a-w c:\windows\system32\D3DX9_41.dll
2009-03-30 23:57 . 2009-03-16 21:18 69448 ----a-w c:\windows\system32\XAPOFX1_3.dll
2009-03-30 23:57 . 2009-03-16 21:18 517448 ----a-w c:\windows\system32\XAudio2_4.dll
2009-03-30 23:57 . 2009-03-16 21:18 235352 ----a-w c:\windows\system32\xactengine3_4.dll
2009-03-30 23:57 . 2009-03-16 21:18 22360 ----a-w c:\windows\system32\X3DAudio1_6.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-27 04:12 . 2008-11-04 06:47 189472 ----a-w c:\windows\system32\PnkBstrB.exe
2009-04-27 02:51 . 2008-11-04 06:48 138168 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-04-27 02:51 . 2008-11-04 06:47 75064 ----a-w c:\windows\system32\PnkBstrA.exe
2009-04-21 06:57 . 2009-04-21 06:57 -------- d-----w c:\program files\Dynex G Desktop Card Adapter
2009-04-21 05:59 . 2008-08-22 00:15 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-04-21 05:04 . 2008-10-14 05:43 -------- d-----w c:\program files\Lavasoft
2009-04-21 01:37 . 2008-12-19 22:38 -------- d-----w c:\program files\GOG.com
2009-04-20 22:14 . 2008-07-29 19:59 -------- d-----w c:\program files\Common Files\Adobe AIR
2009-04-20 03:54 . 2008-10-18 20:20 -------- d-----w c:\program files\Google
2009-04-19 19:43 . 2008-07-29 00:07 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-15 02:14 . 2009-02-04 03:05 -------- d-----w c:\program files\The Rosetta Stone
2009-04-14 00:40 . 2008-08-30 23:44 -------- d-----w c:\program files\Ventrilo
2009-04-07 00:59 . 2008-12-20 23:17 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-06 02:53 . 2008-11-02 01:10 -------- d-----w c:\program files\CCleaner
2009-04-02 21:44 . 2009-01-02 19:31 68734 ----a-w c:\windows\War3Unin.dat
2009-04-02 21:41 . 2008-10-05 21:22 -------- d-----w c:\program files\ROBO Master
2009-04-02 03:25 . 2008-10-05 21:23 -------- d-----w c:\program files\Craft ROBO Controller
2009-04-01 21:53 . 2008-12-09 23:08 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-28 23:47 . 2008-10-03 03:53 -------- d-----w c:\program files\iTunes
2009-03-28 23:47 . 2008-10-03 03:53 -------- d-----w c:\program files\iPod
2009-03-28 23:46 . 2008-09-10 04:15 -------- d-----w c:\program files\Bonjour
2009-03-24 01:00 . 2009-03-24 01:00 -------- d-----w c:\program files\Panasonic
2009-03-24 01:00 . 2008-07-29 00:05 -------- d-----w c:\program files\Common Files\InstallShield
2009-03-20 21:43 . 2008-11-08 23:34 -------- d-----w c:\program files\Common Files\Blizzard Entertainment
2009-03-19 13:54 . 2008-09-21 22:04 -------- d-----w c:\program files\Microsoft Silverlight
2009-03-18 00:40 . 2008-11-05 05:40 23784 ----a-w c:\documents and settings\Ryan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-12 04:54 . 2008-08-07 02:25 -------- d-----w c:\program files\Notepad++
2009-03-12 00:29 . 2008-11-04 06:48 22328 ----a-w c:\documents and settings\Ryan\Application Data\PnkBstrK.sys
2009-03-12 00:29 . 2008-11-04 06:47 2246144 ----a-w c:\windows\system32\pbsvc.exe
2009-03-10 05:07 . 2009-03-10 05:07 132096 --sh--w c:\windows\system32\d3d7.dll
2009-03-06 14:22 . 2004-08-04 07:56 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-06 06:59 . 2009-03-28 23:45 1900544 ----a-w c:\windows\system32\usbaaplrc.dll
2009-03-06 06:59 . 2008-11-04 06:16 36864 ----a-w c:\windows\system32\drivers\usbaapl.sys
2009-03-06 05:35 . 2008-12-14 02:37 413696 ----a-w c:\windows\system32\wrap_oal.dll
2009-03-06 05:35 . 2008-12-14 02:37 110592 ----a-w c:\windows\system32\OpenAL32.dll
2009-03-06 04:35 . 2009-01-23 23:16 -------- d-----w c:\program files\Stardock
2009-02-26 23:41 . 2009-02-26 23:41 98304 ----a-w c:\windows\system32CmdLineExt.dll
2009-02-20 08:10 . 2007-06-11 22:06 666112 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:10 . 2004-08-04 07:56 81920 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2007-06-11 22:03 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2007-06-11 22:05 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2004-08-04 07:56 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-04 07:56 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 11:13 . 2007-06-11 22:06 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2004-08-04 07:56 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2007-06-11 22:05 2145280 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2001-08-23 12:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2006-12-19 09:12 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-04 01:36 . 2009-02-04 01:36 56 ---ha-w c:\windows\system32\ezsidmv.dat
2009-02-03 19:59 . 2004-08-04 07:56 56832 ----a-w c:\windows\system32\secur32.dll
.
((((((((((((((((((((((((((((( SnapShot_2009-04-28_00.09.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-28 00:13 . 2009-04-28 00:13 16384 c:\windows\Temp\Perflib_Perfdata_764.dat
+ 2009-04-28 00:13 . 2009-04-28 00:13 16384 c:\windows\Temp\Perflib_Perfdata_610.dat
+ 2009-04-28 00:14 . 2009-04-28 00:14 16384 c:\windows\Temp\Perflib_Perfdata_520.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"Broadcom Wireless Manager"="c:\windows\system32\wltray.exe" [2007-03-02 1282048]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC654325-1273-C2A9-2B7C-45A29BCE2FBD}"= "c:\program files\Stardock\Fences\DesktopDock.dll" [2009-02-25 517480]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Craft ROBO Status Supervisor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Craft ROBO Status Supervisor.lnk
backup=c:\windows\pss\Craft ROBO Status Supervisor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Dynex Wireless Networking Utility.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Dynex Wireless Networking Utility.lnk
backup=c:\windows\pss\Dynex Wireless Networking Utility.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Ryan^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Ryan\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Ryan^Start Menu^Programs^Startup^WinMySQLadmin.lnk]
path=c:\documents and settings\Ryan\Start Menu\Programs\Startup\WinMySQLadmin.lnk
backup=c:\windows\pss\WinMySQLadmin.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SymSnapService"=3 (0x3)
"Norton Ghost"=2 (0x2)
"LiveUpdate"=3 (0x3)
"aawservice"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Games\\Steam\\steam.exe"=
"c:\\Games\\Steam\\steamapps\\sgtpeppers920\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\InstantRails-2.0-win\\apache\\Apache.exe"=
"c:\\InstantRails-2.0-win\\ruby\\bin\\ruby.exe"=
"c:\\Games\\Steam\\steamapps\\common\\titan quest immortal throne\\Tqit.exe"=
"c:\\Games\\Steam\\steamapps\\sgtpeppers920\\half-life\\hl.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Games\\Warcraft III\\Warcraft III.exe"=
"c:\\Games\\id Software\\Enemy Territory - QUAKE Wars\\etqw.exe"=
"c:\\Games\\id Software\\Enemy Territory - QUAKE Wars\\etqwded.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Games\\Steam\\steamapps\\sgtpeppers920\\day of defeat source\\hl2.exe"=
"c:\\Games\\Steam\\steamapps\\common\\gravitron2\\Gravitron2.exe"=
"c:\\Games\\Steam\\steamapps\\common\\eets\\Eets.exe"=
"c:\\Games\\Steam\\steamapps\\common\\trials 2 second edition\\launcher.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Games\\Steam\\steamapps\\common\\multiwinia\\multiwinia.exe"=
"c:\\Games\\Steam\\steamapps\\sgtpeppers920\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Games\\Steam\\steamapps\\common\\i-fluid\\I-Fluid.exe"=
"c:\\Games\\Steam\\steamapps\\sgtpeppers920\\garrysmod\\hl2.exe"=
"c:\\Games\\Steam\\steamapps\\sgtpeppers920\\synergy\\hl2.exe"=
"c:\\Games\\Steam\\steamapps\\common\\il 2 sturmovik 1946\\il2fb.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Games\\Steam\\steamapps\\sgtpeppers920\\counter-strike source\\hl2.exe"=
"c:\\Games\\Steam\\steamapps\\common\\rainbow six vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"c:\\Games\\Steam\\steamapps\\common\\company of heroes\\RelicDownloader\\RelicDownloader.exe"=
"c:\\Games\\Steam\\steamapps\\common\\company of heroes\\help.htm"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Program Files\\GOG.com\\Stronghold Crusader\\Stronghold Crusader.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Games\\Steam\\steamapps\\common\\ghost recon advanced warfighter\\graw.exe"=
"c:\\Games\\Steam\\steamapps\\common\\company of heroes\\RelicCOH.exe"=
"c:\\Games\\Steam\\steamapps\\common\\farcry\\Bin32\\FarCry.exe"=
"c:\\Games\\Steam\\steamapps\\common\\farcry\\Bin32\\FarCryConfigurator.exe"=
"c:\\Games\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Games\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\GOG.com\\Unreal Tournament 2004\\System\\UT2004.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R2 CoLinuxDriver;CoLinuxDriver; [x]
R2 XAMPP;XAMPP Service; [x]
R3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-10-06 33752]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408]
S0 hotcore3;Hotcore helper;c:\windows\system32\DRIVERS\hotcore3.sys [2008-08-25 40496]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-03-09 64160]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-06-20 28544]
S0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\DRIVERS\pssnap.sys [2008-05-20 15328]
S1 aswSP;avast! Self Protection; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-03-23 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-03-23 72944]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
S2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [2008-09-25 68136]
S2 LasMan;Local Connection Manager;c:\windows\System32\svchost.exe [2008-04-14 14336]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
S2 ReflectService;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [2008-08-06 216032]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ASWUPDSV
*NewlyCreated* - AVAST!_MAIL_SCANNER
*NewlyCreated* - AVAST!_WEB_SCANNER
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
LasMan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Installer.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be36bd3f-f49f-11dd-bc61-001cdf4f7a8e}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-04-21 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]
2009-04-25 c:\windows\Tasks\My Backup xml.job
- c:\program files\Macrium\Reflect\reflect.exe [2009-03-23 18:24]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
Trusted Zone: com.tw\
www.msi
DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
FF - ProfilePath - c:\documents and settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hidig8xh.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig#
FF - plugin: c:\documents and settings\All Users.WINDOWS\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\documents and settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hidig8xh.default\extensions\LogMeInClient@logmein.com\plugins\npRACtrl.dll
FF - plugin: c:\documents and settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hidig8xh.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-27 17:17
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1275210071-1647877149-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ac,c1,be,ec,ec,46,93,5e,19,14,c0,3a,90,d8,5a,b2,76,f2,e6,eb,e5,64,f7,
83,5c,ab,18,29,03,1e,b5,12,ac,2a,8d,87,b4,6f,7d,27,de,b5,83,85,27,8a,1d,e4,\
"??"=hex:31,99,68,58,1e,f9,15,26,79,de,c3,49,c8,0a,37,44
[HKEY_USERS\S-1-5-21-1275210071-1647877149-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:51,5d,de,74,a2,f7,ce,fb,1f,19,27,1b,d7,40,d8,f8,10,9d,c7,3b,12,
6e,62,9e,98,ff,17,3c,df,40,72,f0,b3,f9,a8,53,ac,d1,03,e7,80,19,d8,e5,70,97,\
"rkeysecu"=hex:39,cc,8a,da,7f,44,84,09,da,b7,e2,0c,b8,a9,a5,33
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"Licence0"="04F0D21-79D8-7A25-D702-433F"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(792)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(3400)
c:\program files\Stardock\Fences\DesktopDock.dll
c:\program files\SUPERAntiSpyware\SASSEH.DLL
c:\windows\system32\xpsp3res.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2009-04-28 17:18
ComboFix-quarantined-files.txt 2009-04-28 00:18
ComboFix2.txt 2009-04-28 00:10
ComboFix3.txt 2009-04-22 04:29
Pre-Run: 18,360,954,880 bytes free
Post-Run: 18,353,291,264 bytes free
339 --- E O F --- 2009-04-17 02:45