Combofix and HJT logs respectively
ComboFix 08-06-09.7 - Jeremy 2008-06-10 17:41:57.1 - NTFSx86
Running from: C:\Documents and Settings\Jeremy\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\dypwfcqj.ini
C:\WINDOWS\system32\eeogoyhx.dll
C:\WINDOWS\system32\fccdcYsq.dll
C:\WINDOWS\system32\fccyyVNE.dll
C:\WINDOWS\system32\JPXHkUvw.ini
C:\WINDOWS\system32\JPXHkUvw.ini2
C:\WINDOWS\system32\jqcfwpyd.dll
C:\WINDOWS\system32\ljJBrRll.dll
C:\WINDOWS\system32\qsYcdccf.ini
C:\WINDOWS\system32\qsYcdccf.ini2
C:\WINDOWS\system32\xhyogoee.ini
.
((((((((((((((((((((((((( Files Created from 2008-05-10 to 2008-06-10 )))))))))))))))))))))))))))))))
.
2008-06-10 15:24 . 2008-06-10 15:24 <DIR> d-------- C:\Program Files\Avira
2008-06-10 15:24 . 2008-06-10 15:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-06-09 15:45 . 2008-06-09 15:45 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-08 12:54 . 2008-06-08 12:54 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-06-08 12:54 . 2008-06-08 12:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-08 01:41 . 2008-06-08 12:19 151 --a------ C:\WINDOWS\wininit.ini
2008-06-08 00:41 . 2008-06-08 00:41 <DIR> d-------- C:\Program Files\PowerISO
2008-06-06 08:50 . 2008-06-06 08:50 <DIR> d-------- C:\Program Files\Karen's Power Tools
2008-06-06 08:50 . 2008-06-06 08:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Karen's Power Tools
2008-06-04 22:01 . 2008-06-04 22:01 <DIR> d-------- C:\Program Files\Touchpad Pro
2008-06-04 20:47 . 2008-06-04 20:47 <DIR> d-------- C:\Documents and Settings\Jeremy\donkeycache
2008-06-04 20:46 . 2008-06-04 21:17 <DIR> d-------- C:\Program Files\XMLSpear
2008-06-04 20:24 . 2008-06-04 20:24 <DIR> d-------- C:\Program Files\TightVNC
2008-06-03 18:41 . 2008-06-03 18:41 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\Alloysoft
2008-06-03 18:39 . 2008-06-03 18:39 <DIR> d-------- C:\Program Files\Signal
2008-06-02 16:08 . 2008-06-02 16:13 <DIR> d-------- C:\Program Files\PTGui
2008-06-02 16:08 . 2008-06-02 16:08 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\PTGui Pro
2008-06-02 12:36 . 2008-06-02 12:36 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\WTablet
2008-05-23 19:30 . 2008-05-23 19:30 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\WTablet
2008-05-23 19:30 . 2007-09-07 11:31 3,499,304 --a------ C:\WINDOWS\system32\WacomTablet.cpl
2008-05-23 19:30 . 2007-09-05 14:30 1,910,035 --a------ C:\WINDOWS\system32\WacomTablet.znc
2008-05-23 19:30 . 2004-08-04 17:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-05-23 19:30 . 2004-08-04 17:56 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-05-23 19:30 . 2004-08-04 15:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-05-23 19:30 . 2004-08-04 15:58 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-05-23 19:29 . 2008-05-23 19:29 <DIR> d-------- C:\WINDOWS\system32\WTablet
2008-05-23 19:29 . 2008-05-23 19:29 <DIR> d-------- C:\Program Files\Tablet
2008-05-23 19:29 . 2007-09-07 11:40 1,373,480 --a------ C:\WINDOWS\system32\Wacom_Tablet.exe
2008-05-23 19:29 . 2007-09-07 11:20 181,544 --a------ C:\WINDOWS\system32\Wintab32.dll
2008-05-23 19:29 . 2007-09-07 11:33 128,296 --a------ C:\WINDOWS\system32\Wacom_Tablet.dll
2008-05-23 19:29 . 2007-02-16 10:30 12,848 --a------ C:\WINDOWS\system32\drivers\wacomvhid.sys
2008-05-23 19:29 . 2007-02-15 16:11 11,440 --a------ C:\WINDOWS\system32\drivers\WacomVKHid.sys
2008-05-23 19:29 . 2007-02-16 11:12 11,312 --a------ C:\WINDOWS\system32\drivers\wacommousefilter.sys
2008-05-23 19:25 . 2008-05-23 19:25 <DIR> d-------- C:\Program Files\REAL SKY PRO EDITION
2008-05-23 19:15 . 2008-05-23 19:22 <DIR> d-------- C:\Program Files\Pocket Tanks Deluxe 1.3
2008-05-23 18:36 . 2008-05-23 18:36 <DIR> d-------- C:\Program Files\Easy Barcode Creator
2008-05-23 18:34 . 2008-05-23 18:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-23 18:33 . 2008-05-23 18:34 <DIR> d-------- C:\Program Files\Barcode Maker 5
2008-05-23 17:01 . 2008-06-08 16:27 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-05-23 16:58 . 2008-05-23 16:58 <DIR> d-------- C:\Program Files\Shockwave 3D Lights Redux for FS9
2008-05-22 13:28 . 2008-05-22 13:28 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\Nero
2008-05-22 13:25 . 2008-05-22 13:25 <DIR> d-------- C:\Program Files\Nero
2008-05-22 13:25 . 2008-05-22 13:27 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-05-22 13:25 . 2008-05-22 13:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-05-22 12:29 . 2008-05-22 12:29 <DIR> d-------- C:\Program Files\Red Kawa
2008-05-22 12:29 . 2008-05-22 12:29 <DIR> d-------- C:\Program Files\AviSynth 2.5
2008-05-21 23:06 . 2008-05-21 23:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-05-21 23:02 . 2008-06-04 22:21 156 --a------ C:\WINDOWS\Twunk001.MTX
2008-05-21 23:02 . 2008-06-04 22:21 3 --a------ C:\WINDOWS\Twain001.Mtx
2008-05-21 23:02 . 2008-05-21 23:02 0 --a------ C:\WINDOWS\Twunk002.MTX
2008-05-21 22:23 . 2008-05-21 22:23 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-05-21 12:23 . 2008-05-21 12:23 <DIR> d-------- C:\WINDOWS\Sun
2008-05-18 23:49 . 2008-05-18 23:49 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-18 23:49 . 2008-05-19 00:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-17 04:52 . 2008-05-17 04:52 <DIR> d-------- C:\Program Files\CleanCache 3.0
2008-05-17 02:37 . 2008-05-17 02:37 51,600 --a------ C:\WINDOWS\system32\RadLightMPCUninstall.exe
2008-05-16 22:52 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-05-16 22:51 . 2008-05-16 22:52 <DIR> d-------- C:\Program Files\Java
2008-05-16 22:48 . 2008-05-16 22:48 <DIR> d-------- C:\Program Files\Common Files\Java
2008-05-14 16:15 . 2008-06-02 16:57 <DIR> d-------- C:\Program Files\WinSCP
2008-05-14 15:01 . 2008-05-14 15:03 <DIR> d-------- C:\Program Files\FreeTrack
2008-05-14 14:39 . 2008-05-14 14:39 61 ---hs---- C:\WINDOWS\cnerolf.dat
2008-05-14 14:04 . 2008-05-14 14:04 <DIR> d-------- C:\Program Files\DIFX
2008-05-14 14:04 . 2008-05-14 14:04 <DIR> d-------- C:\Program Files\Cachya Software
2008-05-14 13:57 . 2008-05-14 13:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\EPSON
2008-05-14 13:57 . 2006-12-08 02:04 76,800 --a------ C:\WINDOWS\system32\E_FLB9LE.DLL
2008-05-14 13:57 . 2006-04-19 02:00 62,976 --a------ C:\WINDOWS\system32\E_FD4B9LE.DLL
2008-05-14 13:57 . 2004-09-10 20:12 49,152 --a------ C:\WINDOWS\system32\E_DCINST.DLL
2008-05-14 13:55 . 2008-05-14 13:55 <DIR> d-------- C:\Program Files\EPSON
2008-05-14 13:55 . 2008-05-14 13:55 <DIR> d-------- C:\EPSON SPR1800
2008-05-14 13:50 . 2004-08-04 16:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-05-14 13:50 . 2004-08-04 16:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-05-14 10:59 . 2008-05-14 10:59 <DIR> d-------- C:\Program Files\Nikon
2008-05-14 10:58 . 2008-05-14 10:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ultima_T15
2008-05-14 10:58 . 2008-05-14 10:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\EnterNHelp
2008-05-14 10:58 . 2008-05-14 10:58 0 --a------ C:\Documents and Settings\All Users\Application Data\PKP_DLdy.DAT
2008-05-10 16:52 . 2008-05-10 16:52 <DIR> d-------- C:\Program Files\MSXML 4.0
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-07 15:23 --------- d-----w C:\Documents and Settings\Jeremy\Application Data\uTorrent
2008-05-21 12:39 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-20 18:56 --------- d-----w C:\Program Files\uTorrent
2008-05-20 10:55 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-14 01:00 --------- d-----w C:\Program Files\Common Files\Nikon
2008-05-07 05:42 --------- d-----w C:\Program Files\Microsoft Games
2008-05-06 07:24 --------- d-----w C:\Documents and Settings\Jeremy\Application Data\iPhoneRingToneMaker
2008-05-06 04:52 --------- d-----w C:\Documents and Settings\Jeremy\Application Data\Apple Computer
2008-05-06 01:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-06 01:27 --------- d-----w C:\Program Files\iPhoneRingToneMaker
2008-04-30 06:39 --------- d-----w C:\Program Files\MSXML 6.0
2008-04-29 18:26 --------- d-----w C:\Documents and Settings\Jeremy\Application Data\vlc
2008-04-29 17:49 --------- d-----w C:\Program Files\Apoint2K
2008-04-29 16:31 --------- d-----w C:\Program Files\Apple Software Update
2008-04-29 16:13 --------- d-----w C:\Program Files\MSBuild
2008-04-29 16:06 --------- d-----w C:\Program Files\Reference Assemblies
2008-04-29 15:10 --------- d-----w C:\Program Files\iTunes
2008-04-29 15:09 --------- d-----w C:\Program Files\iPod
2008-04-29 15:09 --------- d-----w C:\Program Files\Bonjour
2008-04-29 15:08 --------- d-----w C:\Program Files\QuickTime
2008-04-29 15:06 --------- d-----w C:\Program Files\Common Files\Apple
2008-04-29 15:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-04-29 14:55 --------- d-----w C:\Program Files\Windows Live
2008-04-29 14:50 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-29 14:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-29 14:41 --------- d-----w C:\Program Files\Pro Imaging Powertoys
2008-04-29 12:25 --------- d-----w C:\Program Files\AC3Filter
2008-04-29 12:05 --------- d-----w C:\Program Files\Raxco
2008-04-29 12:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Raxco
2008-04-29 12:00 --------- d-----w C:\Program Files\VideoLAN
2008-04-29 11:59 --------- d-----w C:\Program Files\Fujitsu
2008-04-29 09:19 --------- d-----w C:\Program Files\Microsoft.NET
2008-04-29 09:19 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-04-29 09:19 --------- d-----w C:\Program Files\Common Files\L&H
2008-04-29 09:18 --------- d-----w C:\Program Files\Microsoft Works
2008-04-29 08:51 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-29 08:47 --------- d-----w C:\Program Files\Intel
2008-04-29 08:37 --------- d-----w C:\Program Files\DiskInternals
2008-04-29 08:37 --------- d-----w C:\Program Files\7-Zip
2008-04-29 08:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-29 08:20 --------- d-----w C:\Program Files\ltmoh
2008-04-29 08:18 --------- d-----w C:\Program Files\usb_spk
2008-04-29 08:18 --------- d-----w C:\Program Files\SigmaTel
2008-04-29 08:10 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-29 08:09 558,142 ----a-w C:\WINDOWS\java\Packages\WBFP793H.ZIP
2008-04-29 08:09 155,995 ----a-w C:\WINDOWS\java\Packages\YRNV1VNH.ZIP
2008-04-16 03:00 230,664 ----a-w C:\WINDOWS\system32\PDBoot.exe
2008-04-10 02:08 71,184 ----a-r C:\WINDOWS\system32\drivers\DefragFS.sys
2008-04-01 03:23 129,784 ----a-w C:\WINDOWS\system32\pxafs.dll
2008-04-01 03:23 118,520 ----a-w C:\WINDOWS\system32\pxinsi64.exe
2008-04-01 03:23 118,056 ----a-w C:\WINDOWS\system32\pxcpyi64.exe
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 08:29 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-03-19 08:26 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-03-12 03:10 633,344 ----a-w C:\WINDOWS\system32\gpprefcl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4D7C0BED-D841-499C-B67E-816DE6FE3689}]
C:\WINDOWS\system32\wvUkHXPJ.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 17:56 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"EPSON Stylus Photo R1800"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.exe" [2007-01-12 05:00 177664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-04-09 19:42 118784]
"IndicatorUtility"="C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2002-08-28 09:20 81920]
"AGRSMMSG"="AGRSMMSG.exe" [2003-04-09 19:42 87751 C:\WINDOWS\AGRSMMSG.exe]
"LoadBtnHnd"="C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe" [2002-08-27 11:01 61440]
"LoadFujitsuQuickTouch"="C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe" [2002-08-28 09:59 242688]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-04-09 19:42 114688]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2002-12-18 14:20 86016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-08-31 12:25 249896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 17:56 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
C:\WINDOWS\System32\LgNotify.dll 2003-01-12 17:17 110592 C:\WINDOWS\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
-ra------ 2008-04-01 13:21 61440 C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-12-13 19:10 1688872 C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2007-12-03 14:21 2213160 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 14:57 153136 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\WinSCP\\WinSCP.exe"=
"C:\\Program Files\\Signal\\Signal.exe"=
"C:\\Program Files\\TightVNC\\WinVNC.exe"=
"C:\\Program Files\\Touchpad Pro\\Touchpad Media Server Trial\\TouchpadMediaServer.exe"=
"C:\\Program Files\\Touchpad Pro\\Touchpad Media Server Trial\\TouchpadMediaServer.Patched.exe"=
R2 PD91Agent;PD91Agent;"C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe" [2008-04-16 13:00]
R2 TabletServiceWacom;TabletServiceWacom;C:\WINDOWS\system32\Wacom_Tablet.exe [2007-09-07 11:40]
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 11:12]
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2007-02-16 10:30]
R3 WacomVKHid;Virtual Keyboard Driver;C:\WINDOWS\system32\DRIVERS\WacomVKHid.sys [2007-02-15 16:11]
S3 PD91Engine;PD91Engine;"C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe" [2008-04-16 13:00]
S3 vhidmini;Cachya Virtual Joystick;C:\WINDOWS\system32\DRIVERS\vhidmini.sys []
*Newly Created Service* - SSMDRV
.
Contents of the 'Scheduled Tasks' folder
"2008-05-16 21:23:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-10 18:03:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\S24EvMon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
C:\Program Files\Apoint2K\ApntEx.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-06-10 18:13:09 - machine was rebooted [Jeremy]
ComboFix-quarantined-files.txt 2008-06-10 08:12:45
Pre-Run: 8,454,881,280 bytes free
Post-Run: 8,360,423,424 bytes free
258 --- E O F --- 2008-06-06 12:52:48
--------------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:16:23 PM, on 10/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/ig
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4D7C0BED-D841-499C-B67E-816DE6FE3689} - C:\WINDOWS\system32\wvUkHXPJ.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [EPSON Stylus Photo R1800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE /FU "C:\WINDOWS\TEMP\E_S42B.tmp" /EF "HKCU"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/wuweb_site.cab?1209472357675
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1209472347170
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\WINDOWS\system32\Wacom_Tablet.exe
--
End of file - 7937 bytes