ComboFix 09-05-21.01 - » Jay « 05/22/2009 0:15.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1024.706 [GMT -4:00]
Running from: c:\documents and settings\» Jay «\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\» Jay «\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\All Users.WINDOWS.0\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users.WINDOWS.0\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows.0\search_res.txt
c:\windows.0\system32\drivers\gxvxciqvxxlvmoedfejailccyhtlxftdqwgsw.sys
c:\windows.0\system32\drivers\gxvxcoyuwqvpktprqdhmknselkbuyrexecpje.sys
c:\windows.0\system32\drivers\gxvxcserv.sys
c:\windows.0\system32\dumphive.exe
c:\windows.0\system32\gxvxccounter
c:\windows.0\system32\gxvxceyavtlspusqtjxbomexwnofckdyivydl.dll
c:\windows.0\system32\Process.exe
c:\windows.0\system32\SrchSTS.exe
c:\windows.0\system32\tmp.reg
c:\windows.0\system32\VCCLSID.exe
c:\windows.0\system32\WS2Fix.exe
c:\windows.0\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
D:\Autorun.inf
----- BITS: Possible infected sites -----
hxxp://thenetworkcom.com
hxxp://onsafepro.com
hxxp://www.thenetworkcom.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gxvxcserv.sys
((((((((((((((((((((((((( Files Created from 2009-04-22 to 2009-05-22 )))))))))))))))))))))))))))))))
.
2009-05-20 17:33 . 2009-05-20 17:33 -------- dc----w c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-05-20 17:19 . 2009-05-20 17:19 -------- dc----w c:\documents and settings\LocalService\Application Data\Yahoo!
2009-05-20 17:19 . 2009-05-20 17:33 -------- dc----w c:\documents and settings\LocalService\Application Data\MEGAUPLOADTOOLBAR
2009-05-20 17:18 . 2009-05-20 17:18 -------- d-----w c:\program files\SeekingAlpha
2009-05-20 16:39 . 2009-05-20 16:39 -------- d-----w c:\program files\LunaPlayer
2009-05-20 02:08 . 2009-05-22 04:13 -------- dc----w c:\documents and settings\» Jay «\Application Data\DNA
2009-05-20 02:08 . 2009-05-21 18:49 -------- d-----w c:\program files\DNA
2009-05-20 02:08 . 2009-05-20 02:08 -------- d-----w c:\program files\AskBarDis
2009-05-17 16:04 . 2009-05-17 16:04 -------- dc----w C:\_OTMoveIt
2009-05-16 19:48 . 2009-05-16 19:49 -------- dc----w C:\rsit
2009-05-16 16:54 . 2009-05-16 16:54 -------- dc----w c:\documents and settings\» Jay «\Application Data\Malwarebytes
2009-05-16 16:52 . 2009-05-16 16:54 -------- d-----w c:\program files\ABC
2009-05-16 16:34 . 2009-04-06 19:32 15504 ----a-w c:\windows.0\system32\drivers\mbam.sys
2009-05-16 16:34 . 2009-04-06 19:32 38496 ----a-w c:\windows.0\system32\drivers\mbamswissarmy.sys
2009-05-16 16:34 . 2009-05-16 16:34 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-16 16:34 . 2009-05-16 16:34 -------- dc----w c:\documents and settings\All Users.WINDOWS.0\Application Data\Malwarebytes
2009-05-14 19:06 . 2009-03-30 14:33 96104 ----a-w c:\windows.0\system32\drivers\avipbb.sys
2009-05-14 19:06 . 2009-03-24 20:08 55640 ----a-w c:\windows.0\system32\drivers\avgntflt.sys
2009-05-14 19:06 . 2009-02-13 16:29 22360 ----a-w c:\windows.0\system32\drivers\avgntmgr.sys
2009-05-14 19:06 . 2009-02-13 16:17 45416 ----a-w c:\windows.0\system32\drivers\avgntdd.sys
2009-05-14 19:06 . 2009-05-14 19:06 -------- dc----w c:\documents and settings\All Users.WINDOWS.0\Application Data\Avira
2009-05-14 19:06 . 2009-05-14 19:06 -------- d-----w c:\program files\Avira
2009-05-14 01:21 . 2009-05-14 01:21 -------- d-----w c:\program files\ERUNT
2009-05-13 02:13 . 2009-05-14 01:34 -------- dc----w c:\documents and settings\» Jay «\Application Data\GetRightToGo
2009-05-12 19:16 . 2009-05-14 01:03 -------- dc----w c:\documents and settings\All Users.WINDOWS.0\Application Data\Lavasoft
2009-05-12 18:59 . 2009-05-14 01:04 -------- d-----w c:\program files\Panda Security
2009-05-11 17:08 . 2009-05-14 01:04 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-30 14:44 . 2009-04-30 14:44 -------- d-----w c:\program files\FXLabs
2009-04-29 21:07 . 2009-04-29 21:07 -------- dc----w c:\documents and settings\ Jay
2009-04-29 18:24 . 2009-04-29 18:24 -------- d-----w c:\windows.0\Logs
2009-04-29 17:36 . 2009-04-29 17:36 -------- dc----w c:\documents and settings\? Jay ?
2009-04-29 17:35 . 2009-04-29 17:35 4096 ----a-w c:\windows.0\d3dx.dat
2009-04-29 15:47 . 2009-04-29 15:47 -------- d-----w c:\program files\YouTube Downloader
2009-04-29 14:18 . 2009-04-29 14:18 -------- dc----w c:\documents and settings\» Jay «\Application Data\Red Kawa
2009-04-29 14:14 . 2009-04-29 14:14 -------- d-----w c:\program files\Regensoft
2009-04-29 14:14 . 2009-04-29 14:14 -------- d-----w c:\program files\AviSynth 2.5
2009-04-29 14:14 . 2009-04-29 14:14 -------- d-----w c:\program files\Red Kawa
2009-04-29 13:18 . 2009-04-29 13:18 -------- dc----w c:\documents and settings\» Jay «\Local Settings\Application Data\DNA
2009-04-28 00:37 . 2009-04-28 00:37 -------- d-----w c:\program files\iPod
2009-04-28 00:37 . 2009-04-28 00:38 -------- dc----w c:\documents and settings\All Users.WINDOWS.0\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-28 00:37 . 2009-04-28 00:38 -------- d-----w c:\program files\iTunes
2009-04-28 00:36 . 2009-04-28 00:36 -------- d-----w c:\program files\Bonjour
2009-04-28 00:34 . 2009-04-28 00:34 -------- d-----w c:\program files\Apple Software Update
2009-04-28 00:32 . 2009-03-26 19:23 36864 ----a-w c:\windows.0\system32\drivers\usbaapl.sys
2009-04-28 00:32 . 2009-03-26 19:23 1900544 ----a-w c:\windows.0\system32\usbaaplrc.dll
2009-04-28 00:22 . 2009-05-08 16:47 -------- d-----w c:\program files\Counter-Strike 1.6
2009-04-27 17:20 . 2009-04-27 17:20 -------- d-----w c:\program files\Google
2009-04-25 05:10 . 2009-04-25 05:10 -------- dc----w c:\documents and settings\» Jay «\Local Settings\Application Data\Yahoo
2009-04-25 05:09 . 2009-04-25 14:27 -------- dc----w c:\documents and settings\All Users.WINDOWS.0\Application Data\Yahoo! Companion
2009-04-25 05:09 . 2009-04-25 05:09 -------- dc----w c:\documents and settings\» Jay «\Application Data\Yahoo!
2009-04-25 05:08 . 2009-03-18 21:55 607472 -c--a-w c:\documents and settings\All Users.WINDOWS.0\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-04-25 05:08 . 2009-04-25 05:10 -------- dc----w c:\documents and settings\All Users.WINDOWS.0\Application Data\Yahoo!
2009-04-25 05:08 . 2009-04-25 05:09 -------- d-----w c:\program files\Yahoo!
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-20 16:28 . 2007-11-17 19:02 -------- dc----w c:\documents and settings\» Jay «\Application Data\MegauploadToolbar
2009-05-18 20:21 . 2007-10-29 22:35 -------- dc--a-w c:\documents and settings\All Users.WINDOWS.0\Application Data\TEMP
2009-05-15 02:21 . 2007-09-13 02:22 -------- d-----w c:\program files\Steam
2009-05-14 01:07 . 2009-01-25 18:12 -------- d-----w c:\program files\MediaRing
2009-05-14 01:06 . 2009-01-25 18:33 -------- dc----w c:\documents and settings\All Users.WINDOWS.0\Application Data\Skype
2009-05-14 01:01 . 2008-09-15 23:46 335872 -c--a-w c:\documents and settings\All Users.WINDOWS.0\Application Data\NexonUS\NGM\NGMResource.dll
2009-05-14 00:58 . 2008-03-16 15:19 -------- d-----w c:\program files\Sonic the Hedgehog Adventure 3
2009-04-30 14:44 . 2006-12-02 23:01 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-29 18:26 . 2009-04-29 18:25 -------- d-----w c:\program files\AGEIA Technologies
2009-04-29 13:08 . 2008-05-13 01:54 -------- dc----w c:\documents and settings\» Jay «\Application Data\Apple Computer
2009-04-28 00:37 . 2008-05-13 01:52 -------- d-----w c:\program files\Common Files\Apple
2009-04-28 00:36 . 2007-11-12 22:43 -------- d-----w c:\program files\QuickTime Alternative
2009-04-26 20:38 . 2009-01-25 18:36 -------- dc----w c:\documents and settings\» Jay «\Application Data\skypePM
2009-04-25 20:38 . 2007-09-26 19:05 -------- d-----w c:\program files\Counter-Strike Source
2009-04-04 17:50 . 2009-04-04 17:50 585728 -c--a-w c:\documents and settings\» Jay «\Application Data\Octoshape\Octoshape Streaming Services\pmv302a-0902180-0-libOctoshapeClient.dll
2009-04-04 17:50 . 2009-04-04 17:50 120088 -c--a-w c:\documents and settings\» Jay «\Application Data\Mozilla\Plugins\npoctoshape.dll
2009-04-04 17:50 . 2009-04-04 17:50 -------- dc----w c:\documents and settings\» Jay «\Application Data\Octoshape
2009-04-02 20:29 . 2009-04-02 20:29 75048 -c--a-w c:\documents and settings\All Users.WINDOWS.0\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-03-30 15:57 . 2009-04-04 17:50 409088 -c--a-w c:\documents and settings\» Jay «\Application Data\Octoshape\Octoshape Streaming Services\sua-0903300-0-libOctoshapeClient.dll
2009-03-30 15:57 . 2009-04-04 17:50 120088 -c--a-w c:\documents and settings\» Jay «\Application Data\Octoshape\Octoshape Streaming Services\sua-0903300-0-npoctoshape.dll
2009-03-30 15:57 . 2009-04-04 17:50 132376 -c--a-w c:\documents and settings\» Jay «\Application Data\Octoshape\Octoshape Streaming Services\sua-0903300-0-apoctoshape.dll
2009-03-27 17:36 . 2009-03-27 17:36 57344 -c--a-w c:\documents and settings\» Jay «\Application Data\Sun\Java\Deployment\cache\6.0\50\5b902232-37886cad-n\Decora-SSE.dll
2009-03-27 17:36 . 2009-03-27 17:36 24064 -c--a-w c:\documents and settings\» Jay «\Application Data\Sun\Java\Deployment\cache\6.0\15\4e09eacf-3a40350d-n\Decora-D3D.dll
2009-03-27 17:36 . 2009-03-27 17:36 315392 -c--a-w c:\documents and settings\» Jay «\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-6939ab23-n\jogl.dll
2009-03-27 17:36 . 2009-03-27 17:36 20480 -c--a-w c:\documents and settings\» Jay «\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-6939ab23-n\jogl_awt.dll
2009-03-27 17:36 . 2009-03-27 17:36 20480 -c--a-w c:\documents and settings\» Jay «\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-49f39cec-n\gluegen-rt.dll
2009-03-27 17:36 . 2009-03-27 17:36 114688 -c--a-w c:\documents and settings\» Jay «\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-6939ab23-n\jogl_cg.dll
2009-03-27 17:36 . 2009-03-27 17:36 499712 -c--a-w c:\documents and settings\» Jay «\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-12a76870-n\msvcp71.dll
2009-03-27 17:36 . 2009-03-27 17:36 499712 -c--a-w c:\documents and settings\» Jay «\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-12a76870-n\jmc.dll
2009-03-27 17:36 . 2009-03-27 17:36 348160 -c--a-w c:\documents and settings\» Jay «\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-12a76870-n\msvcr71.dll
2009-03-27 17:35 . 2007-03-31 18:10 -------- d-----w c:\program files\Java
2009-03-27 17:35 . 2009-03-27 17:35 152576 -c--a-w c:\documents and settings\» Jay «\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-19 20:32 . 2009-03-19 20:32 23400 -c--a-w c:\documents and settings\All Users.WINDOWS.0\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 20:32 . 2008-01-29 16:01 23400 ----a-w c:\windows.0\system32\drivers\GEARAspiWDM.sys
2009-03-09 09:19 . 2009-01-02 06:01 410984 ----a-w c:\windows.0\system32\deploytk.dll
2007-09-18 02:40 . 2007-09-18 02:40 4564112 ----a-w c:\program files\dxnt.cab
2007-09-13 00:57 . 2007-09-13 00:57 1904 ----a-w c:\program files\Daily Planner Plus 5.0.lnk
2004-07-20 02:58 . 2004-07-20 02:58 1156363 ----a-w c:\program files\BDANT.cab
2004-07-20 02:53 . 2004-07-20 02:53 976020 ----a-w c:\program files\BDAXP.cab
2004-07-09 13:13 . 2004-07-09 13:13 703080 ----a-w c:\program files\BDA.cab
2004-07-09 08:08 . 2004-07-09 08:08 2242560 ----a-w c:\program files\dsetup32.dll
2004-07-09 07:03 . 2004-07-09 07:03 62976 ----a-w c:\program files\DSETUP.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-29 21:24 325000 ----a-w c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows.0\system32\ctfmon.exe" [2004-08-04 15360]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"Google Update"="c:\documents and settings\» Jay «\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-28 133104]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-05-20 321344]
"SetDefaultMIDI"="MIDIDef.exe" - c:\windows.0\MIDIDEF.EXE [2005-04-22 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-02-07 185632]
"SansaDispatch"="c:\program files\SanDisk\Sansa Updater\SansaDispatch.exe" [2007-10-22 75584]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"QuickTime Task"="c:\program files\QuickTime Alternative\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"P17RunE"="P17RunE.dll" - c:\windows.0\system32\P17RunE.dll [2007-04-09 14848]
"P17Helper"="SPIRun.dll" - c:\windows.0\system32\SPIRun.dll [2006-07-03 10752]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 01000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="%windir%\Resources\LogonUI\zune\logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"odserv"=3 (0x3)
"idsvc"=3 (0x3)
"SCardSvr"=3 (0x3)
"ehSched"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Counter-Strike Source\\hl2.exe"=
"d:\\Halo\\halo.exe"=
"c:\\Program Files\\Steam\\steamapps\\renegade_jp\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\supreme_nigger\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Documents and Settings\\All Users.WINDOWS.0\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Documents and Settings\\» Jay «\\Application Data\\Octoshape\\Octoshape Streaming Services\\OctoshapeClient.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\cstrike.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"47062:TCP"= 47062:TCP:limewire
R1 raddrvv3;raddrvv3;c:\windows.0\system32\rserver30\raddrvv3.sys [4/24/2008 8:49 AM 45848]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/14/2009 3:06 PM 108289]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/7/2007 11:07 PM 24652]
R3 mirrorv3;mirrorv3;c:\windows.0\system32\drivers\rminiv3.sys [11/1/2006 6:01 AM 3328]
S3 RServer3;Radmin Server V3;"c:\windows.0\system32\rserver30\RServer3.exe" /service --> c:\windows.0\system32\rserver30\RServer3.exe [?]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows.0\system32\drivers\ScreamingBAudio.sys --> c:\windows.0\system32\drivers\ScreamingBAudio.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-05-19 c:\windows.0\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Taskbar Hide - c:\progra~1\TASKBA~1\TaskBar.exe
HKCU-Run-DriverUpdaterPro - c:\program files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe
HKLM-Run-WinBlueSoft - c:\program files\WinBlueSoft Software\WinBlueSoft\WinBlueSoft.exe
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT1269415
mLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
uInternet Settings,ProxyOverride = <local>;*.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows.0\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows.0\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\» Jay «\Application Data\Mozilla\Firefox\Profiles\clp1skg0.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Searchme
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - plugin: c:\documents and settings\All Users.WINDOWS.0\Application Data\NexonUS\NGM\npNxGameUS.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-22 00:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(576)
c:\windows.0\system32\Ati2evxx.dll
.
Completion time: 2009-05-22 0:25
ComboFix-quarantined-files.txt 2009-05-22 04:25
ComboFix2.txt 2007-11-14 21:35
Pre-Run: 34,946,936,832 bytes free
Post-Run: 36,249,452,544 bytes free
245 --- E O F --- 2007-11-13 20:17
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:27:37 AM, on 5/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS.0\System32\tcpsvcs.exe
C:\WINDOWS.0\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS.0\system32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS.0\system32\notepad.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS.0\system32\wuauclt.exe
C:\Documents and Settings\» Jay «\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://search.conduit.com?SearchSource=10&ctid=CT1269415
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [P17Helper] Rundll32 SPIRun.dll,RunDLLEntry
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SansaDispatch] C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS.0\system32\ctfmon.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\» Jay «\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) -
https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://www.creative.com/su/ocx/15030/CTSUEng.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1188362464718
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1188376184828
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/su/ocx/15030/CTPID.cab
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Radmin Server V3 (RServer3) - Unknown owner - C:\WINDOWS.0\system32\rserver30\RServer3.exe (file missing)
O23 - Service: Messenger Sharing Folders USN Journal Reader service (usnjsvc) - Unknown owner - C:\Program Files\MSN Messenger\usnsvc.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O24 - Desktop Component 0: My Current Home Page - (no file)
--
End of file - 8364 bytes