Note: I installed Adobe Reader today.
Also, I did install Recovery Console, although ComboFix log says I did´t.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:56:46, on 8.1.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
F:\Programi\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GEST] m‘|\ü
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 3674 bytes
ComboFix 09-01-06.02 - Administrator 2009-01-08 15:44:48.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.3326.2959 [GMT 1:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
FW: ZoneAlarm Firewall *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\pthreadGC2.dll
.
((((((((((((((((((((((((( Files Created from 2008-12-08 to 2009-01-08 )))))))))))))))))))))))))))))))
.
2009-01-08 12:20 . 2009-01-08 12:20 <DIR> d-------- c:\documents and settings\Administrator\Application Data\AdobeUM
2009-01-08 12:16 . 2009-01-08 12:16 <DIR> d-------- c:\program files\Common Files\Adobe
2009-01-03 16:34 . 2009-01-03 16:34 <DIR> d-------- c:\program files\SpywareBlaster
2009-01-03 16:34 . 2009-01-03 16:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\TEMP
2008-12-31 13:05 . 2001-08-17 13:57 16,128 --a------ c:\windows\system32\drivers\MODEMCSA.sys
2008-12-31 13:05 . 2001-08-17 13:57 16,128 --a--c--- c:\windows\system32\dllcache\modemcsa.sys
2008-12-31 13:04 . 2001-08-17 13:28 794,399 --a------ c:\windows\system32\drivers\USR1806V.SYS
2008-12-31 13:04 . 2001-08-17 13:28 794,399 --a--c--- c:\windows\system32\dllcache\usr1806v.sys
2008-12-31 09:33 . 2008-12-31 09:33 <DIR> d-------- c:\windows\Samsung
2008-12-31 09:33 . 2006-03-23 17:18 454,656 --a------ c:\windows\ssndii.exe
2008-12-31 09:33 . 2005-01-24 03:15 65,536 --a------ c:\windows\system32\ssdevm.dll
2008-12-31 09:33 . 2004-02-04 06:24 49,152 --a------ c:\windows\system32\ssusbpn.dll
2008-12-31 09:33 . 2003-04-18 08:29 44,544 --a------ c:\windows\system32\msxml4a.dll
2008-12-31 09:33 . 2000-08-03 17:52 21,776 --a------ c:\windows\system32\msxml2a.dll
2008-12-31 09:32 . 2005-12-12 07:56 151,552 --a------ c:\windows\system32\SM2570CI.exe
2008-12-31 09:32 . 2005-12-12 07:57 57,344 --a------ c:\windows\system32\SM2570CI.dll
2008-12-31 09:32 . 2006-01-02 07:42 22,663 --a------ c:\windows\system32\ml2570lk.DLL
2008-12-31 09:32 . 2005-12-13 08:00 555 --a------ c:\windows\system32\ml2570lk.SMT
2008-12-31 09:31 . 2005-03-03 05:32 151,552 --a------ c:\windows\system32\SSCoInst.exe
2008-12-31 09:31 . 2005-12-12 07:56 151,552 --a------ c:\windows\system32\ml2570ci.exe
2008-12-31 09:31 . 2005-03-03 11:09 57,344 --a------ c:\windows\system32\SSCoInst.dll
2008-12-31 09:31 . 2005-12-12 07:57 57,344 --a------ c:\windows\system32\ml2570ci.dll
2008-12-31 09:31 . 2006-01-02 07:42 22,663 --a------ c:\windows\system32\sugo2LMK.DLL
2008-12-31 09:31 . 2005-07-08 21:54 11,502 --------- c:\windows\Dr. Printer Icon.ico
2008-12-31 09:31 . 2005-12-13 08:00 555 --a------ c:\windows\system32\sugo2lmk.smt
2008-12-31 09:30 . 2008-12-31 09:30 <DIR> d-------- c:\windows\system32\drivers\Samsung
2008-12-31 09:30 . 2008-12-31 09:30 <DIR> d-------- c:\program files\Samsung
2008-12-31 09:30 . 2004-08-11 07:39 41,984 --------- c:\windows\system32\drivers\DGIVECP.SYS
2008-12-31 09:24 . 2004-08-03 23:01 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2008-12-31 09:24 . 2004-08-03 23:01 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys
2008-12-27 15:05 . 2008-12-27 15:05 <DIR> d-------- c:\documents and settings\All Users\Application Data\nView_Profiles
2008-12-27 14:45 . 2009-01-08 15:47 6,027,296 --ahs---- c:\windows\system32\drivers\fidbox.dat
2008-12-27 14:45 . 2009-01-08 15:46 73,748 --ahs---- c:\windows\system32\drivers\fidbox.idx
2008-12-27 14:41 . 2008-12-27 14:41 <DIR> d-------- c:\documents and settings\All Users\Application Data\MailFrontier
2008-12-27 14:41 . 2008-07-09 09:05 1,086,952 --a------ c:\windows\system32\zpeng24.dll
2008-12-27 14:41 . 2008-07-09 09:05 75,248 --a------ c:\windows\zllsputility.exe
2008-12-27 14:41 . 2004-04-27 04:40 11,264 --a------ c:\windows\system32\SpOrder.dll
2008-12-27 14:41 . 2008-12-27 14:43 4,212 --ah----- c:\windows\system32\zllictbl.dat
2008-12-27 14:40 . 2008-12-27 14:41 <DIR> d-------- c:\windows\system32\ZoneLabs
2008-12-27 14:40 . 2009-01-08 15:41 <DIR> d-------- c:\windows\Internet Logs
2008-12-27 14:40 . 2008-12-27 14:40 <DIR> d-------- c:\program files\Zone Labs
2008-12-27 14:40 . 2009-01-08 15:39 352,918 --a------ c:\windows\system32\vsconfig.xml
2008-12-27 14:31 . 2004-08-03 22:41 1,041,536 --a------ c:\windows\system32\drivers\HSFDPSP2.sys
2008-12-27 14:31 . 2004-08-03 22:41 1,041,536 --a--c--- c:\windows\system32\dllcache\hsfdpsp2.sys
2008-12-27 14:31 . 2004-08-03 22:41 685,056 --a------ c:\windows\system32\drivers\HSFCXTS2.sys
2008-12-27 14:31 . 2004-08-03 22:41 685,056 --a--c--- c:\windows\system32\dllcache\hsfcxts2.sys
2008-12-27 14:31 . 2004-08-03 22:41 220,032 --a------ c:\windows\system32\drivers\HSFBS2S2.sys
2008-12-27 14:31 . 2004-08-03 22:41 220,032 --a--c--- c:\windows\system32\dllcache\hsfbs2s2.sys
2008-12-27 14:31 . 2004-07-17 22:55 129,045 --a------ c:\windows\system32\drivers\cxthsfS2.cty
2008-12-27 14:31 . 2004-08-04 00:56 86,016 --a------ c:\windows\system32\mdmxsdk.dll
2008-12-27 14:31 . 2004-08-04 00:56 32,285 --a------ c:\windows\system32\HSFCISP2.dll
2008-12-27 14:31 . 2004-08-04 00:56 32,285 --a--c--- c:\windows\system32\dllcache\hsfcisp2.dll
2008-12-27 14:31 . 2004-08-03 22:41 11,868 --a------ c:\windows\system32\drivers\mdmxsdk.sys
2008-12-25 14:31 . 1996-11-11 08:00 51,472 -ra--c--- c:\windows\system32\dllcache\IMAGECFG.EXE
2008-12-25 14:26 . 1996-11-11 08:00 51,472 -ra------ c:\windows\system32\IMAGECFG.EXE
2008-12-25 14:26 . 2008-12-25 13:38 24,643 --a------ c:\windows\system32\imagecfg.zip
2008-12-24 22:42 . 2008-12-24 22:42 <DIR> d--h----- c:\windows\PIF
2008-12-24 22:38 . 2009-01-01 20:51 <DIR> d--h----- C:\$AVG8.VAULT$
2008-12-24 22:37 . 2008-12-24 22:37 <DIR> d-------- c:\program files\AnswerWorks 4.0
2008-12-24 22:33 . 2009-01-02 13:59 <DIR> d-------- c:\program files\AutoCAD 2006
2008-12-24 22:33 . 2008-12-24 22:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\Autodesk
2008-12-24 22:33 . 2008-12-30 09:40 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Autodesk
2008-12-24 22:30 . 2008-12-24 22:37 <DIR> d-------- c:\program files\Common Files\Autodesk Shared
2008-12-24 22:30 . 2008-12-24 22:30 <DIR> d-------- c:\program files\Autodesk
2008-12-24 22:27 . 2008-12-24 22:27 <DIR> d-------- c:\program files\Novolit
2008-12-24 22:20 . 2008-12-30 15:04 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-12-24 22:20 . 2008-12-30 15:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-24 22:19 . 2008-12-24 22:19 0 --a------ c:\windows\nsreg.dat
2008-12-24 21:50 . 1998-05-07 10:57 143,872 --a------ c:\windows\system32\iacenc.dll
2008-12-24 19:36 . 1998-10-29 15:45 306,688 --a------ c:\windows\IsUninst.exe
2008-12-24 18:15 . 2004-08-03 23:08 26,496 --a--c--- c:\windows\system32\dllcache\usbstor.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-08 14:47 16,608 ----a-w c:\windows\gdrv.sys
2008-12-31 08:33 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-31 08:33 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-29 12:38 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys
2008-12-24 21:17 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-12-22 23:40 --------- d-----w c:\program files\MSBuild
2008-12-22 23:38 --------- d-----w c:\program files\Reference Assemblies
2008-12-22 23:34 10,520 ----a-w c:\windows\system32\avgrsstx.dll
2008-12-22 23:34 --------- d-----w c:\program files\AVG
2008-12-22 23:30 --------- d-----w c:\documents and settings\Administrator\Application Data\Winamp
2008-12-22 23:28 --------- d-----w c:\program files\Winamp
2008-12-22 23:27 --------- d-----w c:\program files\ffdshow
2008-12-22 23:21 --------- d-----w c:\program files\Microsoft Works
2008-12-22 23:21 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-22 23:06 --------- d-----w c:\program files\Realtek
2008-12-22 23:06 --------- d-----w c:\documents and settings\Administrator\Application Data\InstallShield
2008-12-22 23:04 315,392 ----a-w c:\windows\HideWin.exe
2008-12-22 23:01 --------- d-----w c:\program files\Intel
2008-12-22 23:00 --------- d-----w c:\program files\GIGABYTE
2008-12-22 22:45 --------- d-----w c:\program files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="m‘|\ü" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-29 1261336]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\ssmmgr.exe" [2006-02-14 507904]
"nwiz"="nwiz.exe" [2008-05-16 c:\windows\system32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart16.exe [2005-03-05 10872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv31"= c:\windows\system32\ir32_32.dll
"vidc.iv32"= c:\windows\system32\ir32_32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RTHDCPL"=RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-23 97928]
R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-23 231704]
R4 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [2008-12-23 80392]
.
- - - - ORPHANS REMOVED - - - -
BHO-{2E99D908-AFF6-46F6-A913-4D666A244C85} - c:\windows\system32\qoMgDSMD.dll
BHO-{B3478B65-15CA-4647-A408-04B0A12D09CA} - (no file)
Notify-cbXQGvUM - cbXQGvUM.dll
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\gslxk129.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-08 15:47:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-08 15:48:15 - machine was rebooted [Administrator]
ComboFix-quarantined-files.txt 2009-01-08 14:48:12
Pre-Run: 46.668.021.760 bytes free
Post-Run: 46,607,527,936 bytes free
184