Thx a bunch. the online scanner found some old stuff in avasts virus chest . i deleted them. hope it wont throw anything off.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:13:50 AM, on 1/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Symantec\Ghost\ngserver.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\PnkBstrA.exe
C:\Program Files\Symantec\Ghost\bin\dbserv.exe
C:\Program Files\Symantec\Ghost\bin\rteng9.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Symantec\Ghost\ngtray.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINNT\explorer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINNT\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\somethingelsentirely.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NGTray] "C:\Program Files\Symantec\Ghost\ngtray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://javadl.sun.com/webapps/download/AutoDL?BundleId=26688
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Ghost Database Service Wrapper (NGDBSERV) - Symantec Corporation - C:\Program Files\Symantec\Ghost\bin\dbserv.exe
O23 - Service: Symantec Ghost Configuration Server (NGSERVER) - Symantec Corporation - C:\Program Files\Symantec\Ghost\ngserver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINNT\system32\PnkBstrA.exe
--
End of file - 6136 bytes
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Friday, January 23, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, January 23, 2009 17:01:56
Records in database: 1675780
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
Scan statistics:
Files scanned: 64316
Threat name: 6
Infected objects: 6
Suspicious objects: 0
Duration of the scan: 01:29:30
File name / Threat name / Threats count
C:\Documents and Settings\CFSY VAIO\Desktop\Keepers\Downloads\Old Dnlds\kf151.zip Infected: not-a-virus

SWTool.Win32.RAS.g 1
C:\Documents and Settings\CFSY VAIO\Desktop\Keepers\Downloads\Old Dnlds\kf151.zip Infected: not-a-virus

SWTool.Win32.RAS.a 1
C:\Qoobox\Quarantine\C\WINNT\system32\fhbgiajs.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.gfy 1
C:\Qoobox\Quarantine\C\WINNT\system32\fiylotpp.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.gdc 1
C:\Qoobox\Quarantine\C\WINNT\system32\pgnrtjvh.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.gcf 1
C:\Qoobox\Quarantine\C\WINNT\system32\rwlfksom.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.gbs 1
The selected area was scanned.
ComboFix 09-01-21.04 - CFSY VAIO 2009-01-23 12:20:46.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.1102 [GMT -8:00]
Running from: c:\documents and settings\CFSY VAIO\Desktop\security\ComboFix.exe
Command switches used :: c:\documents and settings\CFSY VAIO\Desktop\security\CFScript.txt
AV: avast! antivirus 4.8.1296 [VPS 090123-0] *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\CFSY VAIO\Application Data\uTorrent
c:\documents and settings\CFSY VAIO\Application Data\uTorrent\yam-win.zip.torrent
.
((((((((((((((((((((((((( Files Created from 2008-12-23 to 2009-01-23 )))))))))))))))))))))))))))))))
.
2009-01-23 10:19 . 2009-01-23 10:19 <DIR> d-------- c:\winnt\LastGood
2009-01-23 08:48 . 2009-01-23 08:48 <DIR> d-------- c:\program files\AskBarDis
2009-01-23 08:48 . 2009-01-23 08:48 <DIR> d-------- c:\documents and settings\CFSY VAIO\Application Data\Foxit
2009-01-23 08:47 . 2009-01-23 08:47 <DIR> d-------- c:\program files\Foxit Software
2009-01-23 08:35 . 2008-04-14 05:42 221,184 --a------ c:\winnt\system32\wmpns.dll
2009-01-22 15:40 . 2009-01-22 15:40 <DIR> d-------- c:\winnt\LastGood.Tmp
2009-01-22 15:35 . 2009-01-22 15:35 <DIR> d-------- c:\winnt\system32\scripting
2009-01-22 15:33 . 2009-01-22 15:36 <DIR> d-------- c:\winnt\ServicePackFiles
2009-01-22 15:32 . 2008-04-14 05:42 294,912 -----c--- c:\winnt\system32\dllcache\dlimport.exe
2009-01-22 15:28 . 2006-12-29 00:31 19,569 --a------ c:\winnt\
003085_.tmp
2009-01-22 14:42 . 2008-10-16 12:38 6,066,176 -----c--- c:\winnt\system32\dllcache\ieframe.dll
2009-01-22 14:42 . 2007-04-17 01:32 2,455,488 -----c--- c:\winnt\system32\dllcache\ieapfltr.dat
2009-01-22 14:42 . 2007-03-07 21:10 991,232 -----c--- c:\winnt\system32\dllcache\ieframe.dll.mui
2009-01-22 14:42 . 2008-10-16 12:38 459,264 -----c--- c:\winnt\system32\dllcache\msfeeds.dll
2009-01-22 14:42 . 2008-10-16 12:38 383,488 -----c--- c:\winnt\system32\dllcache\ieapfltr.dll
2009-01-22 14:42 . 2008-10-16 12:38 267,776 -----c--- c:\winnt\system32\dllcache\iertutil.dll
2009-01-22 14:42 . 2008-10-16 12:38 63,488 -----c--- c:\winnt\system32\dllcache\icardie.dll
2009-01-22 14:42 . 2008-10-16 12:38 52,224 -----c--- c:\winnt\system32\dllcache\msfeedsbs.dll
2009-01-22 14:42 . 2008-10-16 05:11 13,824 -----c--- c:\winnt\system32\dllcache\ieudinit.exe
2009-01-22 14:10 . 2008-08-14 02:11 2,189,184 -----c--- c:\winnt\system32\dllcache\ntoskrnl.exe
2009-01-22 14:10 . 2008-08-14 02:09 2,145,280 -----c--- c:\winnt\system32\dllcache\ntkrnlmp.exe
2009-01-22 14:10 . 2008-08-14 01:33 2,066,048 -----c--- c:\winnt\system32\dllcache\ntkrnlpa.exe
2009-01-22 14:10 . 2008-08-14 01:33 2,023,936 -----c--- c:\winnt\system32\dllcache\ntkrpamp.exe
2009-01-22 14:10 . 2008-09-15 04:12 1,846,400 -----c--- c:\winnt\system32\dllcache\win32k.sys
2009-01-22 14:10 . 2008-04-11 11:04 691,712 -----c--- c:\winnt\system32\dllcache\inetcomm.dll
2009-01-22 14:10 . 2008-12-11 02:57 333,952 -----c--- c:\winnt\system32\dllcache\srv.sys
2009-01-22 14:10 . 2008-06-13 03:05 272,128 -----c--- c:\winnt\system32\dllcache\bthport.sys
2009-01-22 14:00 . 2007-09-07 02:04 524,317 -----c--- c:\winnt\system32\dllcache\kodakimg.exe
2009-01-22 14:00 . 2007-09-07 09:57 448,029 -----c--- c:\winnt\system32\dllcache\oieng400.dll
2009-01-22 14:00 . 2007-09-07 02:04 73,245 -----c--- c:\winnt\system32\dllcache\kodakprv.exe
2009-01-22 14:00 . 2007-09-07 09:57 38,941 -----c--- c:\winnt\system32\dllcache\jpeg2x32.dll
2009-01-22 14:00 . 2007-09-07 09:57 33,307 -----c--- c:\winnt\system32\dllcache\tifflt.dll
2009-01-22 13:59 . 2008-10-24 03:21 455,296 -----c--- c:\winnt\system32\dllcache\mrxsmb.sys
2009-01-22 13:59 . 2008-05-08 06:02 203,136 -----c--- c:\winnt\system32\dllcache\rmcast.sys
2009-01-21 10:43 . 2009-01-21 10:43 <DIR> d-------- c:\program files\Microsoft Games
2009-01-14 10:13 . 2009-01-14 10:13 <DIR> d-------- c:\program files\Trend Micro
2009-01-12 11:58 . 2009-01-12 11:58 <DIR> d-------- C:\VundoFix Backups
2009-01-12 11:56 . 2009-01-12 11:56 <DIR> d-------- c:\program files\Java
2009-01-12 11:56 . 2009-01-12 11:56 73,728 --a------ c:\winnt\system32\javacpl.cpl
2009-01-12 10:00 . 2009-01-12 10:00 93 --a------ c:\winnt\wininit.ini
2009-01-09 15:34 . 2008-10-15 08:34 337,408 -----c--- c:\winnt\system32\dllcache\netapi32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-23 16:59 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-23 16:37 --------- d-----w c:\program files\MSN Messenger
2009-01-21 18:42 --------- d-----w c:\documents and settings\CFSY VAIO\Application Data\U3
2009-01-16 23:50 --------- d-----w c:\program files\Blackout Ragnarok Online
2009-01-15 22:19 --------- d-----w c:\documents and settings\All Users\Application Data\2DBoy
2009-01-12 19:56 410,984 ----a-w c:\winnt\system32\deploytk.dll
2009-01-12 17:29 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-01-09 21:35 --------- d-----w c:\documents and settings\CFSY VAIO\Application Data\Hamachi
2008-12-11 22:34 --------- d-----w c:\program files\Steam
2008-12-11 22:32 --------- d-----w c:\program files\Left 4 Dead
2008-12-11 21:55 25,280 ----a-w c:\winnt\system32\drivers\hamachi.sys
2008-12-11 17:59 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-11 10:57 333,952 ----a-w c:\winnt\system32\drivers\srv.sys
2008-12-09 20:55 --------- d-----w c:\documents and settings\All Users\Application Data\SimCity Societies
2008-12-08 19:19 --------- d-----w c:\program files\Maxis
2008-12-03 20:56 --------- d-----w c:\program files\Ubisoft
2008-12-01 20:19 --------- d-----w c:\program files\Rockstar Games
2008-12-01 19:55 --------- d-----w c:\program files\DAEMON Tools Lite
2008-12-01 19:45 717,296 ----a-w c:\winnt\system32\drivers\sptd.sys
2008-12-01 19:45 --------- d-----w c:\documents and settings\CFSY VAIO\Application Data\DAEMON Tools
2008-11-27 17:52 --------- d-----w c:\program files\LEGO Company
2008-10-27 18:04 70,992 ----a-w c:\winnt\system32\XAPOFX1_2.dll
2008-10-27 18:04 514,384 ----a-w c:\winnt\system32\XAudio2_3.dll
2008-10-27 18:04 235,856 ----a-w c:\winnt\system32\xactengine3_3.dll
2008-10-27 18:04 23,376 ----a-w c:\winnt\system32\X3DAudio1_5.dll
2008-10-23 12:36 286,720 ----a-w c:\winnt\system32\gdi32.dll
2007-06-04 15:55 271 --sh--w c:\program files\desktop.ini
2007-06-04 15:55 21,952 ---ha-w c:\program files\folder.htt
.
((((((((((((((((((((((((((((( snapshot_2009-01-23_ 8.58.14.09 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-11-18 12:58 333192 --a------ c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"NGTray"="c:\program files\Symantec\Ghost\ngtray.exe" [2006-12-04 222856]
"NvCplDaemon"="c:\winnt\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\winnt\system32\NvMcTray.dll" [2007-06-28 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-12 136600]
"nwiz"="nwiz.exe" [2007-06-28 c:\winnt\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2008-04-14 214528]
"tscuninstall"="c:\winnt\system32\tscupgrd.exe" [2006-02-28 44544]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\winnt\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-14 05:42 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 11:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 c:\winnt\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-06-28 23:43 8466432 c:\winnt\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-06-28 23:43 81920 c:\winnt\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-07-07 09:42 2156368 c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a------ 2008-04-14 05:42 110592 c:\winnt\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-06-28 23:43 1626112 c:\winnt\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Synchronization Manager]
--a------ 2008-04-14 05:42 143360 c:\winnt\system32\mobsync.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"iPod Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Symantec\\Ghost\\ngserver.exe"=
"c:\\Program Files\\Symantec\\Ghost\\GhostSrv.exe"=
"c:\\Program Files\\Left 4 Dead\\left4dead.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R1 aswSP;avast! Self Protection;c:\winnt\system32\drivers\aswSP.sys [2008-04-08 111184]
R4 aswFsBlk;aswFsBlk;c:\winnt\system32\drivers\aswFsBlk.sys [2008-04-08 20560]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - USNJSVC
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\P]
\Shell\AutoRun\command - P:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06e5d26e-c44f-11dc-b7f2-0011d82a3c4c}]
\Shell\AutoRun\command - L:\ONSPCLCK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3071dfcc-9862-11dc-b7c9-0011d82a3c4c}]
\Shell\AutoRun\command - N:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3071dfce-9862-11dc-b7c9-0011d82a3c4c}]
\Shell\AutoRun\command - L:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3071dfd0-9862-11dc-b7c9-0011d82a3c4c}]
\Shell\AutoRun\command - P:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3b43bdb5-4cd5-11dc-b76f-0011d82a3c4c}]
\Shell\AutoRun\command - L:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4ab1c178-ae74-11dc-b7e1-0011d82a3c4c}]
\Shell\AutoRun\command - L:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f6d9bd2-aaa3-11dd-b8bd-0011d82a3c4c}]
\Shell\AutoRun\command - L:\ONSPCLCK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce5b1125-b264-11dd-b8c4-0011d82a3c4c}]
\Shell\AutoRun\command - L:\ONSPCLCK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d2d130a4-3d60-11dd-b870-0011d82a3c4c}]
\Shell\AutoRun\command - L:\ONSPCLCK.exe
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\CFSY VAIO\Application Data\Mozilla\Firefox\Profiles\q3kh05gv.default\
FF - plugin: c:\program files\Microsoft Silverlight\npctrl.1.0.21115.0.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-23 12:23:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-789336058-2077806209-839522115-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:84,b3,94,5f,a9,ed,00,08,66,a3,40,44,f9,0c,87,19,e5,1a,9d,37,aa,b0,c4,
9e,f3,92,38,48,07,09,ce,ea,b7,38,e6,19,2f,9d,d2,9a,dc,0a,ec,5e,f2,2f,52,27,\
"??"=hex:3d,31,5d,6e,6d,09,dd,1b,1f,09,dd,5e,d1,c6,6d,95
.
Completion time: 2009-01-23 12:25:08
ComboFix-quarantined-files.txt 2009-01-23 20:25:06
ComboFix2.txt 2009-01-23 16:59:30
ComboFix3.txt 2009-01-22 22:03:04
Pre-Run: 42,450,087,936 bytes free
Post-Run: 42,488,225,792 bytes free
209 --- E O F --- 2009-01-22 22:52:17