ComboFix 09-04-19.01 - Divilov 04/18/2009 13:41.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1623 [GMT -4:00]
Running from: c:\documents and settings\Divilov\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Divilov\Desktop\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
FW: ESET Personal firewall *enabled*
* Created a new restore point
* Resident AV is active
FILE ::
c:\windows\system32\dofimete.dll.tmp
c:\windows\system32\gakikedo.dll.tmp
c:\windows\system32\gurawubo.dll.tmp
c:\windows\system32\hezubuti.dll.tmp
c:\windows\system32\hobokuzu.dll.tmp
c:\windows\system32\pozayeda.dll.tmp
c:\windows\system32\seduvumo.dll.tmp
c:\windows\system32\tobuvuzi.dll.tmp
c:\windows\system32\wewusigo.dll.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Divilov\Application Data\uTorrent
c:\documents and settings\Divilov\Application Data\uTorrent\2007 Best Remixes.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\Arcanum.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\Counter-Strike Source FULL [October 15 2007] DiGiTALZonE.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\Dark Sector CrackFix.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\DF.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\dht.dat
c:\documents and settings\Divilov\Application Data\uTorrent\dht.dat.old
c:\documents and settings\Divilov\Application Data\uTorrent\DnLInstall.exe.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\Eye Training [PC.CD][English][
www.zonatorrent.com].torrent
c:\documents and settings\Divilov\Application Data\uTorrent\Fallout 2.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\fraps2.9.8.EXE.1.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\fraps2.9.8.EXE.2.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\fraps2.9.8.EXE.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\Hacker.Evolution[2007][PCGame]-ZeeForge.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\Mercenaries.2.World.In.Flames.Crackfix-RELOADED.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\MIRC.v6.31.KeyMaker.and.AuthPatch.Only-DVT.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\Mirrors.Edge.Update.Crack.1.01-RELOADED.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\PCSX2-0.9.4.1.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\PCSX2-0.9.4.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\Perfect World International.zip.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\psx2_bios.rar.1.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\psx2_bios.rar.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\R3AP3R100HD2.rar.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\resume.dat
c:\documents and settings\Divilov\Application Data\uTorrent\resume.dat.old
c:\documents and settings\Divilov\Application Data\uTorrent\rss.dat
c:\documents and settings\Divilov\Application Data\uTorrent\rss.dat.old
c:\documents and settings\Divilov\Application Data\uTorrent\settings.dat
c:\documents and settings\Divilov\Application Data\uTorrent\settings.dat.old
c:\documents and settings\Divilov\Application Data\uTorrent\Space.Siege-RELOADED.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\Supreme.Ruler.2020-SKIDROW.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\The Rosetta Stone SFX.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\The.Fall.Last.Days.Of.Gaia.Extended.English.Mod.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\Tom Clancy Rainbow Six Vegas 2 Keygen Serial Only.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\utorrent.lng
c:\documents and settings\Divilov\Application Data\uTorrent\VA-The Best Of Techno Vol.1-2008-.
www.lokotorrents.com.torrent
c:\documents and settings\Divilov\Application Data\uTorrent\X9B2yjlC_runesofmagic_open_beta.rar.torrent
c:\program files\uTorrent
c:\program files\uTorrent\uTorrent.exe
c:\windows\system32\basesrv.dll
c:\windows\system32\dofimete.dll.tmp
c:\windows\system32\drivers\ovfsthdyirjxbqbruvooetoirfopxlbcyavyqm.sys
c:\windows\system32\gakikedo.dll.tmp
c:\windows\system32\gurawubo.dll.tmp
c:\windows\system32\hezubuti.dll.tmp
c:\windows\system32\hobokuzu.dll.tmp
c:\windows\system32\ovfsthomimpemcnatgjaqbeciqqolalhclmafp.dll
c:\windows\system32\ovfsthpatlvnuaaswefbomylnvulewrlgdlxas.dat
c:\windows\system32\ovfsthpwumalopkgvkdqhexxjxisktymoypyqf.dat
c:\windows\system32\ovfsthqlhslpdiutkrmyxvrodunwhopxgscjcw.dll
c:\windows\system32\ovfsthwhbewnkfimwcbqtuxunkrfwsujdqxrqh.dll
c:\windows\system32\pozayeda.dll.tmp
c:\windows\system32\seduvumo.dll.tmp
c:\windows\system32\tobuvuzi.dll.tmp
c:\windows\system32\wewusigo.dll.tmp
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_ovfsthjnvdokwpdwehwaivkipxbbuttesibgkv
((((((((((((((((((((((((( Files Created from 2009-03-18 to 2009-04-18 )))))))))))))))))))))))))))))))
.
2009-04-16 14:24 . 2009-04-16 15:24 20480 ----a-w c:\windows\system32\ak1.exe
2009-04-16 14:22 . 2009-04-16 14:22 118 ----a-w c:\windows\system32\MRT.INI
2009-04-16 14:03 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-16 14:03 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 14:03 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 14:03 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 14:03 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 14:03 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 14:03 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-16 14:03 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 14:03 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 14:02 . 2009-03-27 06:58 1203922 -c----w c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 14:02 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-16 14:02 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-15 15:55 . 2009-04-15 17:40 81920 ----a-w c:\windows\system32\ftp_non_crp.exe
2009-04-06 02:39 . 2008-04-14 00:12 218624 ----a-w c:\windows\system32\uxtheme.backup
2009-04-02 01:56 . 2009-04-02 01:56 -------- d-----w c:\documents and settings\Divilov\Application Data\Eltima Software
2009-03-22 18:12 . 2009-03-22 18:12 -------- d-----w c:\documents and settings\Divilov\Application Data\SPSSInc
2009-03-22 17:30 . 2009-03-22 17:30 -------- d-----w c:\documents and settings\Divilov\.spss
2009-03-22 17:28 . 2009-04-11 15:30 114 ----a-w c:\windows\system32\prsgrc.tgz
2009-03-22 17:28 . 2009-03-22 17:28 1024 ----a-w c:\windows\system32\grcauth2.dll
2009-03-22 17:28 . 2009-03-22 17:28 1024 ----a-w c:\windows\system32\grcauth1.dll
2009-03-22 17:28 . 2009-03-22 17:28 -------- d-----w c:\documents and settings\All Users\Application Data\SafeNet Sentinel
2009-03-22 17:28 . 2009-03-22 17:28 -------- d-----w c:\documents and settings\All Users\Application Data\SPSS
2009-03-22 17:27 . 2009-03-22 17:27 219 ----a-w c:\windows\system32\lsprst7.tgz
2009-03-22 17:27 . 2009-03-22 17:27 16 ---h--w c:\windows\system32\servdat.slm
2009-03-22 17:27 . 2009-03-22 17:27 1025 ----a-w c:\windows\system32\sysprs7.tgz
2009-03-22 17:27 . 2009-03-22 17:27 1025 ----a-w c:\windows\system32\sysprs7.dll
2009-03-21 14:06 . 2009-03-21 14:06 989696 -c----w c:\windows\system32\dllcache\kernel32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-18 17:45 . 2007-12-30 01:44 532 ----a-w C:\RTHDCPL_Dump.txt
2009-04-08 00:22 . 2009-04-08 00:21 -------- d-----w c:\program files\WinPcap
2009-04-08 00:19 . 2007-07-21 06:22 95408 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-08 00:19 . 2009-04-08 00:19 -------- d-----w c:\program files\LM Studio
2009-04-05 23:22 . 2008-05-24 05:15 -------- d-----w c:\program files\JDown
2009-04-05 04:47 . 2008-08-08 03:54 -------- d-----w c:\program files\Mozilla Thunderbird
2009-04-01 02:01 . 2009-04-01 02:01 -------- d-----w c:\program files\Alcohol Soft
2009-04-01 00:33 . 2008-01-02 19:39 717296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-03-30 16:45 . 2007-12-28 11:39 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-30 16:24 . 2008-05-26 20:57 -------- d-----w c:\program files\Fraps
2009-03-30 12:31 . 2007-07-21 02:36 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-22 17:28 . 2009-03-22 17:28 -------- d-----w c:\program files\Common Files\SPSS
2009-03-22 17:27 . 2009-03-22 17:27 -------- d-----w c:\program files\SPSSInc
2009-03-21 15:29 . 2009-03-21 15:29 -------- d-----w c:\program files\VALVe
2009-03-20 01:22 . 2009-03-20 01:22 -------- d-----w c:\program files\DAMN NFO Viewer
2009-03-19 01:15 . 2009-03-19 01:15 -------- d-----w c:\program files\Azure Gaming
2009-03-18 03:42 . 2009-03-18 03:42 -------- d-----w c:\documents and settings\All Users\Application Data\WotT
2009-03-16 03:58 . 2009-03-16 03:58 115936 ----a-w c:\windows\system32\drivers\prodrv03.sys
2009-03-11 00:20 . 2008-01-20 17:43 -------- d-----w c:\program files\PB
2009-03-10 23:25 . 2008-01-14 03:55 -------- d-----w c:\program files\DAEMON Tools Pro
2009-03-06 14:22 . 2008-08-31 11:56 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-04 19:31 . 2008-02-04 21:24 79268 ---ha-w c:\windows\system32\mlfcache.dat
2009-03-03 00:18 . 2007-02-20 09:52 826368 ----a-w c:\windows\system32\wininet.dll
2009-03-02 23:05 . 2009-03-02 23:05 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-03-02 16:53 . 2009-03-02 16:53 -------- d-----w c:\documents and settings\Divilov\Application Data\Foxit
2009-03-01 20:17 . 2009-03-01 20:10 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-01 20:17 . 2007-12-27 18:14 -------- d-----w c:\program files\Java
2009-02-24 19:36 . 2009-02-24 19:36 -------- d-----w c:\documents and settings\All Users\Application Data\NortonInstaller
2009-02-20 18:09 . 2008-08-31 11:57 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-20 03:46 . 2008-08-06 10:05 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-02-19 12:54 . 2009-02-19 12:54 -------- d-----w c:\documents and settings\Divilov\Application Data\Malwarebytes
2009-02-18 15:07 . 2009-02-18 15:07 -------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-02-12 15:07 . 2009-01-14 15:26 413696 ----a-w c:\windows\system32\wrap_oal.dll
2009-02-12 15:07 . 2009-01-14 15:26 110592 ----a-w c:\windows\system32\OpenAL32.dll
2009-02-09 12:10 . 2008-08-31 11:56 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2008-08-31 11:56 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2008-08-31 11:56 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2008-08-31 11:56 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 11:13 . 2008-08-31 11:56 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2008-08-31 11:56 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2008-08-31 11:56 2145280 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-04 05:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2008-08-31 11:56 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 19:59 . 2008-08-31 11:56 56832 ----a-w c:\windows\system32\secur32.dll
2009-01-28 14:57 . 2009-01-28 14:57 77060 ----a-w C:\svf_info.txt
2009-01-26 17:27 . 2008-03-17 22:59 202032 ----a-w c:\windows\system32\PnkBstrB.exe
2009-01-23 06:02 . 2008-01-19 02:01 22328 ----a-w c:\documents and settings\Divilov\Application Data\PnkBstrK.sys
2009-01-23 06:01 . 2008-03-17 22:59 66872 ----a-w c:\windows\system32\PnkBstrA.exe
2009-01-23 06:01 . 2008-04-12 22:35 2337865 ----a-w c:\windows\system32\pbsvc.exe
2009-01-23 01:17 . 2009-01-23 01:17 42320 ----a-w c:\windows\system32\xfcodec.dll
2007-12-27 18:09 . 2007-12-27 18:09 130 ----a-w c:\documents and settings\Divilov\Local Settings\Application Data\fusioncache.dat
2007-07-21 06:22 . 2007-12-27 18:08 68456 ----a-w c:\documents and settings\Divilov\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-08-31 16:04 . 2008-08-31 16:04 32768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008083120080901\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-04-18_13.57.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-18 17:45 . 2009-04-18 17:45 16384 c:\windows\temp\Perflib_Perfdata_6e8.dat
+ 2008-08-31 11:56 . 2008-04-14 00:11 52736 c:\windows\system32\dllcache\basesrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdminWorks Tray"="c:\acer\LANScope Agent\awtray.exe" [2007-05-22 1459992]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-18 13574144]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 86960]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-08-09 221184]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-01 1443072]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-18 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-01 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-12-20 16860672]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-09-18 1657376]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\SPSSInc\\Statistics17\\statistics.exe"=
"c:\\Program Files\\SPSSInc\\Statistics17\\SPSSWinWrapIDE.exe"=
"c:\\Program Files\\SPSSInc\\Statistics17\\statistics.com"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9999:UDP"= 9999:UDP:LANScope UDP Port
"2804:TCP"= 2804:TCP:LANScope TCP Port
"9420:TCP"= 9420:TCP:Red Swoosh
"5000:UDP"= 5000:UDP:Red Swoosh
R3 Acer ODDSpeedControl;Acer ODDSpeedControl;c:\acer\Empowering Technology\eAcoustics\ODDSpeedCtl\speedcontrol.exe [2005-02-15 81920]
R3 FStarForce;FStarForce;c:\windows\system32\DRIVERS\FStarForce.sys [2009-01-01 8192]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-02-17 2736890]
S1 OsaFsLoc;OsaFsLoc;c:\windows\system32\drivers\OsaFsLoc.sys [2007-08-27 26768]
S1 prodrv03;Star Force copy protection driver v3;c:\windows\system32\drivers\prodrv03.sys [2009-03-16 115936]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
S2 netlimiter;netlimiter;c:\windows\system32\drivers\netlimiter.sys [2006-10-03 18072]
S2 netlock;netlock;c:\windows\system32\drivers\netlock.sys [2007-05-30 14616]
S2 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2007-06-13 15640]
S2 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2006-11-09 10944]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-04-18 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-02-15 20:31]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://google.com/
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*
http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: vzTCPConfig - hxxp://www2.verizon.net/help/fios_settings_POTT20009/include/vzTCPConfig.CAB
FF - ProfilePath - c:\documents and settings\Divilov\Application Data\Mozilla\Firefox\Profiles\4wbj4hia.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - component: c:\documents and settings\Divilov\Application Data\Mozilla\Firefox\Profiles\4wbj4hia.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-18 13:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ovfsthjnvdokwpdwehwaivkipxbbuttesibgkv]
"imagepath"="\systemroot\system32\drivers\ovfsthdyirjxbqbruvooetoirfopxlbcyavyqm.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1269103037-3874296902-2670244853-1008\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:c2,2b,07,7a,e3,7d,53,ec,63,47,d5,a7,1f,c2,14,36,dc,c0,ac,d0,50,79,a9,
e1,e3,62,d0,53,33,cf,85,a8,90,95,32,4d,42,70,70,a3,66,59,ef,6b,ea,59,c5,54,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
[HKEY_USERS\S-1-5-21-1269103037-3874296902-2670244853-1008\Software\SecuROM\License information*]
"datasecu"=hex:df,e5,ea,76,71,90,73,86,f2,3b,64,e1,44,75,32,48,0e,0d,17,d9,a4,
7d,9d,b1,b2,f8,5f,13,8a,bd,a1,55,fd,d0,43,89,5a,c2,94,27,4f,b8,86,97,26,e7,\
"rkeysecu"=hex:65,18,48,8e,28,49,90,6b,b5,75,cc,af,3d,1e,4d,fa
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1116)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1332)
c:\windows\system32\mshtml.dll
.
------------------------ Other Running Processes ------------------------
.
c:\acer\Empowering Technology\ePerformance\MemCheck.exe
c:\acer\LANScope Agent\awServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\matlab\webserver\bin\win32\matlabserver.exe
c:\acer\LANScope Agent\lockkm.exe
c:\windows\system32\nvsvc32.exe
c:\matlab\bin\win32\MATLAB.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2009-04-18 13:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-18 17:49
ComboFix2.txt 2009-04-18 14:00
Pre-Run: 38,777,741,312 bytes free
Post-Run: 38,761,951,232 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
304 --- E O F --- 2009-04-18 13:58
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:51:40 PM, on 4/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Acer\LANScope Agent\awServ.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\MATLAB\webserver\bin\win32\matlabserver.exe
C:\Acer\LANScope Agent\LockKM.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Acer\LANScope Agent\awtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Divilov\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page =
http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [AdminWorks Tray] "C:\Acer\LANScope Agent\awtray.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: vzTCPConfig -
http://www2.verizon.net/help/fios_settings_POTT20009/include/vzTCPConfig.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1198781864515
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1209481842781
O23 - Service: Acer ODDSpeedControl - TODO: <????> - C:\Acer\Empowering Technology\eAcoustics\ODDSpeedCtl\speedcontrol.exe
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AdminWorks Agent X6 (AWService) - OSA Technologies Inc., An Avocent Company - C:\Acer\LANScope Agent\awServ.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB\webserver\bin\win32\matlabserver.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
--
End of file - 6457 bytes