Combofix Log
ComboFix 08-08-03.05 - SpEEdy 2008-08-04 15:10:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1033.18.1505 [GMT 3:00]
Running from: C:\Documents and Settings\SpEEdy\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\SpEEdy\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMe38e274c.txt
C:\WINDOWS\BMe38e274c.xml
C:\WINDOWS\system32\CeKUvyay.ini
C:\WINDOWS\system32\CeKUvyay.ini2
C:\WINDOWS\system32\cnkvvbnn.dll
C:\WINDOWS\system32\efcCvTnm.dll
C:\WINDOWS\system32\fjjqksnp.ini
C:\WINDOWS\system32\fqbwumfi.ini
C:\WINDOWS\system32\lphxhabx.dll
C:\WINDOWS\system32\lweogwyl.ini
C:\WINDOWS\system32\lywgoewl.dll
C:\WINDOWS\system32\oamwirrw.dll
C:\WINDOWS\system32\pnskqjjf.dll
C:\WINDOWS\system32\tmp25.tmp
C:\WINDOWS\system32\tmp26.tmp
C:\WINDOWS\system32\wrriwmao.ini
C:\WINDOWS\system32\xbahxhpl.ini
C:\WINDOWS\system32\yayvUKeC.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-04 to 2008-08-04 )))))))))))))))))))))))))))))))
.
2008-08-04 15:18 . 2008-08-04 15:18 <DIR> d-------- C:\Documents and Settings\SpEEdy\Application Data\FaxCtr
2008-08-04 15:05 . 2008-08-04 15:05 <DIR> d-------- C:\Program Files\Lexmark_P910 Series
2008-08-04 15:04 . 2004-11-22 13:27 32,768 --a------ C:\WINDOWS\system32\LXPRMON.DLL
2008-08-04 15:04 . 2004-11-22 13:26 20,480 --a------ C:\WINDOWS\system32\LXPMONUI.DLL
2008-08-04 15:03 . 2008-08-04 15:03 <DIR> d-------- C:\Program Files\Lexmark Fax Solutions
2008-08-04 15:03 . 2008-08-04 15:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FaxCtr
2008-08-04 15:03 . 2003-03-11 18:26 339,968 -ra------ C:\WINDOWS\system32\IMGMAN32.DLL
2008-08-04 15:03 . 2003-03-11 18:26 98,345 -ra------ C:\WINDOWS\system32\IMHOST32.DLL
2008-08-04 15:03 . 2003-03-11 18:26 98,304 -ra------ C:\WINDOWS\system32\IM31XPNG.DEL
2008-08-04 15:03 . 2003-03-11 18:26 69,632 -ra------ C:\WINDOWS\system32\IM31XTIF.DEL
2008-08-04 15:03 . 2003-03-11 18:26 49,152 -ra------ C:\WINDOWS\system32\IM31IMG.DIL
2008-08-04 15:03 . 2004-11-22 13:30 12,288 --a------ C:\WINDOWS\system32\LXPMONRC.DLL
2008-08-04 15:01 . 2008-08-04 15:05 11,349 --a------ C:\WINDOWS\system32\LexFiles.ulf
2008-08-04 15:00 . 2008-08-04 15:07 <DIR> d-------- C:\Program Files\Lx_cats
2008-08-04 14:59 . 2004-11-09 17:29 65,536 -ra------ C:\WINDOWS\system32\lxbycfg.dll
2008-08-04 14:59 . 2005-01-20 20:43 1,385 -ra------ C:\WINDOWS\system32\lxby.loc
2008-08-04 14:58 . 2008-08-04 15:17 <DIR> d-------- C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
2008-08-04 14:58 . 2008-08-04 15:05 <DIR> d-------- C:\Program Files\Lexmark P910 Series
2008-08-04 14:56 . 2008-04-14 00:15 32,128 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-08-04 14:56 . 2008-04-14 00:15 32,128 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-08-04 14:56 . 2008-04-14 00:15 26,368 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-08-04 14:56 . 2008-04-14 00:17 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-08-04 14:56 . 2008-04-14 00:17 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-07-31 18:48 . 2008-07-31 18:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-07-31 18:43 . 2008-07-31 18:43 <DIR> d-------- C:\Program Files\Yahoo!
2008-07-31 12:25 . 2008-07-31 12:25 144,384 --a------ C:\WINDOWS\system32\miccyhook.dll
2008-07-31 12:22 . 2008-07-31 12:22 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-07-31 00:17 . 2008-07-31 00:17 <DIR> d-------- C:\Program Files\MSECache
2008-07-31 00:13 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-07-30 23:57 . 2008-07-30 23:57 <DIR> d-------- C:\Program Files\Microsoft Works
2008-07-30 23:56 . 2008-07-30 23:56 <DIR> d-------- C:\Program Files\MSBuild
2008-07-30 23:46 . 2008-07-30 23:55 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-07-30 23:45 . 2008-07-31 00:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-30 23:43 . 2008-07-30 23:43 <DIR> dr-h----- C:\MSOCache
2008-07-30 18:41 . 2008-07-30 18:41 <DIR> d-------- C:\models
2008-07-30 18:41 . 2008-07-30 18:41 <DIR> d-------- C:\maps
2008-07-30 16:56 . 2008-07-30 16:56 <DIR> d-------- C:\Program Files\Crystal Player
2008-07-30 16:56 . 2008-07-30 17:04 <DIR> d-------- C:\Documents and Settings\SpEEdy\Application Data\Crystal Player
2008-07-30 13:17 . 2008-07-30 13:17 <DIR> d-------- C:\Documents and Settings\SpEEdy\Application Data\Media Player Classic
2008-07-30 12:58 . 2008-08-03 13:45 <DIR> d-------- C:\Documents and Settings\SpEEdy\Application Data\SporeCreatureCreator
2008-07-30 11:42 . 2008-08-03 12:12 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-07-30 11:42 . 2008-07-30 21:20 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-07-30 11:42 . 2008-08-03 12:12 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-30 11:24 . 2008-07-30 11:24 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-30 11:05 . 2008-07-30 11:05 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-07-29 23:52 . 2008-07-29 23:52 278,984 --a------ C:\WINDOWS\system32\drivers\atksgt.sys
2008-07-29 23:52 . 2008-07-29 23:52 25,416 --a------ C:\WINDOWS\system32\drivers\lirsgt.sys
2008-07-29 23:50 . 2008-01-29 13:53 782,336 -ra------ C:\WINDOWS\system32\tmp123.tmp
2008-07-29 23:50 . 2008-01-29 13:53 782,336 -ra------ C:\WINDOWS\system32\tmp122.tmp
2008-07-29 23:49 . 2008-07-29 23:49 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2008-07-29 23:49 . 2008-07-29 23:49 <DIR> d-------- C:\Program Files\AGEIA Technologies
2008-07-29 23:48 . 2008-07-29 23:48 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-29 23:47 . 2008-07-29 23:47 <DIR> d-------- C:\Program Files\OpenAL
2008-07-29 23:47 . 2008-07-29 23:50 413,696 --a------ C:\WINDOWS\system32\wrap_oal.dll
2008-07-29 23:47 . 2008-07-29 23:50 110,592 --a------ C:\WINDOWS\system32\OpenAL32.dll
2008-07-29 23:44 . 2008-07-29 23:44 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-07-29 22:53 . 2008-07-29 22:53 <DIR> d-------- C:\Documents and Settings\SpEEdy\Application Data\temp
2008-07-29 22:46 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2008-07-29 22:37 . 2008-07-29 22:37 <DIR> d-------- C:\Documents and Settings\SpEEdy\Application Data\DAEMON Tools
2008-07-29 22:37 . 2008-07-29 22:37 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-07-29 21:41 . 2008-08-02 13:02 1,309 --a------ C:\WINDOWS\wininit.ini
2008-07-29 21:26 . 2008-07-29 21:27 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-29 21:26 . 2008-07-30 15:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-29 19:30 . 2008-07-29 19:30 6,144 --a------ C:\WINDOWS\system32\BReWErS.dll
2008-07-29 19:21 . 2008-07-29 19:25 <DIR> d-------- C:\Program Files\Winamp
2008-07-29 19:21 . 2008-07-29 19:25 <DIR> d-------- C:\Documents and Settings\SpEEdy\Application Data\Winamp
2008-07-29 19:04 . 2008-03-03 14:25 5,702 --ah----- C:\WINDOWS\nod32restoretemdono.reg
2008-07-29 19:04 . 2008-03-03 18:21 568 --ah----- C:\WINDOWS\nod32fixtemdono.reg
2008-07-29 19:03 . 2008-07-29 19:03 <DIR> d-------- C:\Program Files\ESET
2008-07-29 19:03 . 2008-07-29 19:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-07-29 17:38 . 2008-07-29 17:38 <DIR> d-------- C:\Program Files\GIGABYTE
2008-07-29 17:14 . 2008-07-29 17:14 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-29 17:05 . 2008-07-29 17:05 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-07-29 17:04 . 2008-07-29 17:04 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-07-29 17:04 . 2008-07-29 17:05 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-07-29 17:01 . 2008-04-14 00:15 6,272 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-07-29 17:01 . 2008-04-14 00:15 6,272 --a--c--- C:\WINDOWS\system32\dllcache\splitter.sys
2008-07-29 17:00 . 2008-04-14 00:47 83,072 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-07-29 17:00 . 2008-04-14 00:47 83,072 --a--c--- C:\WINDOWS\system32\dllcache\wdmaud.sys
2008-07-29 17:00 . 2008-04-14 00:15 56,576 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2008-07-29 17:00 . 2008-04-14 00:15 56,576 --a--c--- C:\WINDOWS\system32\dllcache\swmidi.sys
2008-07-29 17:00 . 2008-04-14 00:15 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2008-07-29 17:00 . 2008-04-14 00:15 52,864 --a--c--- C:\WINDOWS\system32\dllcache\dmusic.sys
2008-07-29 17:00 . 2006-08-01 10:02 49,152 -ra------ C:\WINDOWS\system32\ChCfg.exe
2008-07-29 16:58 . 2008-07-29 17:00 <DIR> d-------- C:\WINDOWS\system32\RTCOM
2008-07-29 16:58 . 2008-04-14 00:09 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2008-07-29 16:58 . 2008-04-14 00:09 5,376 --a--c--- C:\WINDOWS\system32\dllcache\mspclock.sys
2008-07-29 16:57 . 2008-04-14 00:49 146,048 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2008-07-29 16:57 . 2008-04-14 00:49 146,048 --a--c--- C:\WINDOWS\system32\dllcache\portcls.sys
2008-07-29 16:57 . 2008-04-14 00:15 60,160 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2008-07-29 16:57 . 2008-04-14 00:15 60,160 --a--c--- C:\WINDOWS\system32\dllcache\drmk.sys
2008-07-29 16:57 . 2008-04-14 05:41 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2008-07-29 16:57 . 2008-04-14 05:41 4,096 --a--c--- C:\WINDOWS\system32\dllcache\ksuser.dll
2008-07-29 16:56 . 2007-06-15 11:45 1,826,816 -r------- C:\WINDOWS\SkyTel.exe
2008-07-29 16:56 . 2008-04-14 05:42 129,536 --a------ C:\WINDOWS\system32\ksproxy.ax
2008-07-29 16:56 . 2008-04-14 05:42 129,536 --a--c--- C:\WINDOWS\system32\dllcache\ksproxy.ax
2008-07-29 16:56 . 2006-07-21 11:14 86,016 -r------- C:\WINDOWS\SoundMan.exe
2008-07-29 16:55 . 2007-03-23 14:19 9,715,200 -r------- C:\WINDOWS\RTLCPL.exe
2008-07-29 16:55 . 2007-07-18 14:26 4,547,584 -r------- C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-07-29 16:55 . 2007-01-16 05:39 1,191,936 -r------- C:\WINDOWS\RtlUpd.exe
2008-07-29 16:55 . 2006-08-18 01:58 282,624 -ra------ C:\WINDOWS\system32\RTSndMgr.cpl
2008-07-29 16:54 . 2007-07-05 11:08 16,380,416 -r------- C:\WINDOWS\RTHDCPL.exe
2008-07-29 16:54 . 2007-06-28 11:44 2,165,760 -r------- C:\WINDOWS\MicCal.exe
2008-07-29 16:53 . 2008-07-29 16:53 <DIR> d-------- C:\Program Files\Realtek
2008-07-29 16:53 . 2008-08-04 15:05 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-07-29 16:53 . 2006-05-04 11:26 2,808,832 -r------- C:\WINDOWS\alcwzrd.exe
2008-07-29 16:53 . 2005-09-21 05:25 299,008 -ra------ C:\WINDOWS\system32\ALSndMgr.cpl
2008-07-29 16:53 . 2005-05-03 13:43 69,632 -r------- C:\WINDOWS\Alcmtr.exe
2008-07-29 16:52 . 2007-01-12 11:54 520,192 -r------- C:\WINDOWS\RtlExUpd.dll
2008-07-29 16:52 . 2008-07-29 16:53 315,392 --a------ C:\WINDOWS\HideWin.exe
2008-07-29 16:07 . 2008-07-29 23:49 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-07-29 16:07 . 2008-07-29 16:07 <DIR> d-------- C:\Program Files\DIFX
2008-07-29 16:07 . 2008-07-29 16:07 <DIR> d-------- C:\
068d88b4b8fcb7d04444d80fd1a6b6
2008-07-29 16:07 . 2006-06-18 23:37 36,864 --a------ C:\WINDOWS\system32\drivers\AmdK8.sys
2008-07-29 16:05 . 2008-08-04 15:18 174,630 --a------ C:\WINDOWS\system32\nvapps.xml
2008-07-29 16:01 . 2008-07-29 18:11 <DIR> d-------- C:\WINDOWS\nview
2008-07-29 16:01 . 2008-05-02 22:46 442,368 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-07-29 16:01 . 2008-05-02 22:46 18,070 --a------ C:\WINDOWS\system32\nvdisp.nvu
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-04 12:02 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-04 11:49 --------- d-----w C:\Documents and Settings\SpEEdy\Application Data\BitTorrent
2008-08-04 10:48 --------- d-----w C:\Program Files\DNA
2008-07-29 15:43 --------- d-----w C:\Program Files\BitTorrent
2008-07-29 15:14 15,600 ----a-w C:\WINDOWS\gdrv.sys
2008-07-29 12:50 --------- d-----w C:\Documents and Settings\SpEEdy\Application Data\InstallShield
2008-07-29 12:41 --------- d-----w C:\Program Files\Foxit Software
2008-07-29 12:38 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-07-29 12:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-29 12:27 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 05:42 15360]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 12:39 486856]
"Messenger (Yahoo!)"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2008-05-27 21:58 4269296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 11:06 1443072]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 21:49 36352]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"LXBYCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBYtime.dll" [2004-11-02 18:13 69632]
"lxbymon.exe"="C:\Program Files\Lexmark P910 Series\lxbymon.exe" [2005-01-18 12:50 196608]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2004-11-22 13:29 299008]
"EzPrint"="C:\Program Files\Lexmark P910 Series\ezprint.exe" [2004-09-17 16:24 61440]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 11:08 16380416 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 05:42 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-02-20 11:11]
S2 NOD32FiXTemDono;Eset Nod32 Boot;C:\WINDOWS\system32\regedt32.exe [2004-08-04 15:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3d208358-5d6c-11dd-982e-806d6172696f}]
\Shell\AutoRun\command - F:\Run.exe
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-e0bd14d0 - C:\WINDOWS\system32\lphxhabx.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\SpEEdy\Application Data\Mozilla\Firefox\Profiles\dllhmgli.default\
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-04 15:18:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\SoftwareDistribution
C:\WINDOWS\system32\wuapi.dll.mui 25944 bytes executable
C:\WINDOWS\system32\wuauclt.exe.wusetup.227703.bak 111104 bytes executable
C:\WINDOWS\system32\wups2.dll 43352 bytes executable
scan completed successfully
hidden files: 4
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\lxbycoms.exe
C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2008-08-04 15:21:58 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-04 12:21:55
Pre-Run: 29,611,843,584 bytes free
Post-Run: 29,519,917,056 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
247
HijackThis Log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:25:38, on 04.08.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Lexmark P910 Series\lxbymon.exe
C:\Program Files\Lexmark P910 Series\ezprint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\lxbycoms.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\SpEEdyRoBy.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [LXBYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBYtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxbymon.exe] "C:\Program Files\Lexmark P910 Series\lxbymon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark P910 Series\ezprint.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Mbit.lnk = ?
O4 - Startup: SPD.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{00520848-C558-4644-909D-F63D1248313F}: NameServer = 89.39.208.11 89.39.208.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{00520848-C558-4644-909D-F63D1248313F}: NameServer = 89.39.208.11 89.39.208.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{00520848-C558-4644-909D-F63D1248313F}: NameServer = 89.39.208.11 89.39.208.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: lxby_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbycoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 5616 bytes