THANKS ALOT FOR YOU HELP.
FOLLOWING THE REPORTS
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:16:40, on 18/09/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16711)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\notepad.exe
C:\Windows\Explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [smartchkwin] C:\Windows\system32\lcpmvono.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SDService - Max Secure Software - C:\Program Files\SpywareDetector\SDService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
--
End of file - 6219 bytes
-----------------------------------------------------
ComboFix 08-09-16.05 - DJ BoNnEt 2008-09-18 2:04:56.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.244 [GMT 1:00]
Running from: C:\Users\DJ BoNnEt\Desktop\ComboFix.exe
Command switches used :: C:\Users\DJ BoNnEt\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\System32\pavejqry.exe
C:\Windows\System32\pghidqhk.exe
.
((((((((((((((((((((((((( Files Created from 2008-08-18 to 2008-09-18 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-17 23:12 6,736 ----a-w C:\Windows\system32\drivers\PROCEXP90.SYS
2008-09-17 11:56 --------- d-----w C:\Program Files\Pool Station
2008-09-17 01:00 --------- d-----w C:\Program Files\SAV
2008-09-16 23:01 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-09-16 23:00 --------- d-----w C:\Users\DJ BoNnEt\AppData\Roaming\Malwarebytes
2008-09-16 23:00 --------- d-----w C:\ProgramData\Malwarebytes
2008-09-16 22:59 --------- d-----w C:\ProgramData\Zylom
2008-09-16 21:57 --------- d-----w C:\Program Files\Sun
2008-09-16 21:56 --------- d-----w C:\Program Files\Java
2008-09-16 21:53 --------- d-----w C:\Program Files\Common Files\Java
2008-09-16 02:03 --------- d-----w C:\Program Files\Norton 360
2008-09-15 19:37 --------- d-----w C:\Program Files\WMR11
2008-09-15 19:30 --------- d-----w C:\Program Files\Sytexis Software
2008-09-15 19:26 --------- d-----w C:\Users\DJ BoNnEt\AppData\Roaming\Sytexis
2008-09-15 19:21 --------- d-----w C:\Program Files\FLVCodec
2008-09-15 16:57 --------- d-----w C:\Program Files\Trend Micro
2008-09-15 16:47 98,304 ----a-w C:\Windows\System32\cpofilwr.exe
2008-09-15 09:43 --------- d-----w C:\Program Files\SpywareDetector
2008-09-15 07:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-14 15:44 --------- d-----w C:\ProgramData\Symantec
2008-09-14 15:43 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2008-09-14 15:43 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2008-09-14 15:43 10,671 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2008-09-14 15:43 --------- d-----w C:\Program Files\Symantec
2008-09-14 15:40 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-14 04:44 --------- d-----w C:\Users\DJ BoNnEt\AppData\Roaming\Symantec
2008-09-14 01:02 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-09-13 23:40 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-11 17:56 --------- d-----w C:\Program Files\MegaSpoof
2008-09-11 03:06 --------- d-----w C:\Users\DJ BoNnEt\AppData\Roaming\TVU Networks
2008-09-11 03:06 --------- d-----w C:\ProgramData\TVU Networks
2008-09-11 03:00 --------- d-----w C:\Users\DJ BoNnEt\AppData\Roaming\PPStream
2008-09-11 02:55 --------- d-----w C:\Program Files\Google
2008-09-10 02:06 --------- d-----w C:\ProgramData\Microsoft Help
2008-09-09 23:04 38,528 ----a-w C:\Windows\system32\drivers\mbamswissarmy.sys
2008-09-09 23:03 17,200 ----a-w C:\Windows\system32\drivers\mbam.sys
2008-09-08 07:03 --------- d-----w C:\Program Files\XAimer
2008-09-05 01:56 --------- d-----w C:\ProgramData\Skype
2008-09-02 21:19 20,481 ----a-w C:\Windows\System32\SystemsHook.dll
2008-09-02 17:35 --------- d-----w C:\Program Files\LightningWare
2008-09-02 04:12 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-09-02 04:06 --------- d-----w C:\Program Files\DivX
2008-09-02 03:41 --------- d-----w C:\Users\DJ BoNnEt\AppData\Roaming\Media Player Classic
2008-09-02 03:07 --------- d-----w C:\Program Files\TVersity
2008-08-31 16:19 --------- d---a-w C:\ProgramData\TEMP
2008-08-31 00:55 --------- d-----w C:\Program Files\HiChatter Messenger
2008-08-27 14:35 12,752 ----a-w C:\Windows\System32\SDEarlyDelete.exe
2008-08-27 11:30 917,504 ----a-w C:\Windows\System32\CheckDll.dll
2008-08-25 17:11 --------- d-----w C:\ProgramData\eSellerate
2008-08-25 17:11 --------- d-----w C:\Program Files\Common Files\eSellerate
2008-08-25 11:52 --------- d-----w C:\Users\DJ BoNnEt\AppData\Roaming\Microgaming
2008-08-23 23:18 --------- d-----w C:\Program Files\BitLord
2008-08-22 11:26 --------- d-----w C:\Users\DJ BoNnEt\AppData\Roaming\yahoo!
2008-08-22 11:26 --------- d-----w C:\ProgramData\Yahoo!
2008-08-22 11:26 --------- d-----w C:\Program Files\Yahoo!
2008-08-22 11:26 --------- d-----w C:\Program Files\Packard Bell
2008-08-22 11:23 --------- d-----w C:\Users\DJ BoNnEt\AppData\Roaming\skypePM
2008-08-22 02:12 --------- d-----w C:\Program Files\Windows Mail
2008-08-05 20:46 174 --sha-w C:\Program Files\desktop.ini
2008-08-04 14:33 --------- d-----w C:\Program Files\Bytescribe
2008-07-31 03:34 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-07-31 03:34 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-07-31 03:34 28,160 ----a-w C:\Windows\System32\Apphlpdm.dll
2008-07-31 03:34 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-07-31 03:34 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-07-31 03:34 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-07-30 23:47 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-07-30 23:32 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-07-30 16:42 23,888 ----a-w C:\Windows\system32\drivers\COH_Mon.sys
2008-07-30 16:28 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf
2008-07-30 16:28 10,537 ----a-w C:\Windows\system32\drivers\coh_mon.cat
2008-07-25 08:34 81,920 ----a-w C:\Windows\System32\dpl100.dll
2008-07-25 08:34 593,920 ----a-w C:\Windows\System32\dpuGUI11.dll
2008-07-25 08:34 57,344 ----a-w C:\Windows\System32\dpv11.dll
2008-07-25 08:34 53,248 ----a-w C:\Windows\System32\dpuGUI10.dll
2008-07-25 08:34 344,064 ----a-w C:\Windows\System32\dpus11.dll
2008-07-25 08:34 294,912 ----a-w C:\Windows\System32\dpu11.dll
2008-07-25 08:34 294,912 ----a-w C:\Windows\System32\dpu10.dll
2008-07-25 08:34 196,608 ----a-w C:\Windows\System32\dtu100.dll
2008-07-25 08:34 161,096 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-07-23 16:50 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-07-23 16:48 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-07-23 16:48 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-07-19 05:10 53,448 ----a-w C:\Windows\System32\wuauclt.exe
2008-07-19 05:10 45,768 ----a-w C:\Windows\System32\wups2.dll
2008-07-19 05:10 36,552 ----a-w C:\Windows\System32\wups.dll
2008-07-19 05:09 563,912 ----a-w C:\Windows\System32\wuapi.dll
2008-07-19 05:09 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
2008-07-19 03:44 83,456 ----a-w C:\Windows\System32\wudriver.dll
2008-07-19 03:44 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
2008-07-18 21:08 163,904 ----a-w C:\Windows\System32\wuwebv.dll
2008-07-18 19:44 31,232 ----a-w C:\Windows\System32\wuapp.exe
2008-07-15 23:48 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-06-27 03:54 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-06-27 03:54 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-06-27 03:54 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-06-27 03:54 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-06-26 00:34 7,964,672 ----a-w C:\Windows\System32\NlsLexicons0024.dll
2008-06-26 00:33 9,892,864 ----a-w C:\Windows\System32\NlsLexicons000a.dll
2008-06-19 03:25 61,440 ----a-w C:\Windows\System32\winipsec.dll
2008-02-06 21:58 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-02-06 21:58 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-02-06 21:58 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-02-16 19:10 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-02-16 19:10 32,768 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-01-14 13:30 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008010720080114\index.dat
2008-01-21 15:00 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008011420080121\index.dat
2008-01-29 13:30 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008012120080128\index.dat
2008-01-29 20:30 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008012920080130\index.dat
.
((((((((((((((((((((((((((((( snapshot@2008-09-16_21.33.38.17 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-16 15:13:52 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-09-17 23:07:18 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-09-16 15:13:52 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-09-17 23:07:18 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-09-16 20:26:55 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-09-17 23:10:05 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-09-17 23:10:05 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-09-16 20:29:27 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-09-18 01:10:48 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
- 2008-09-16 20:06:35 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-09-18 00:19:16 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-09-16 20:06:35 49,152 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-18 00:19:16 49,152 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-16 20:06:35 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-09-18 00:19:16 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-09-16 20:20:49 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-09-18 01:04:39 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-09-18 01:04:39 262,144 ---ha-w C:\Windows\System32\config\systemprofile\ntuser.dat.LOG1
- 2007-09-24 22:30:28 135,168 ----a-w C:\Windows\System32\java.exe
+ 2008-06-10 00:21:01 135,168 ----a-w C:\Windows\System32\java.exe
- 2007-09-24 22:30:30 135,168 ----a-w C:\Windows\System32\javaw.exe
+ 2008-06-10 00:21:04 135,168 ----a-w C:\Windows\System32\javaw.exe
- 2007-09-24 23:31:42 139,264 ----a-w C:\Windows\System32\javaws.exe
+ 2008-06-10 01:32:34 139,264 ----a-w C:\Windows\System32\javaws.exe
- 2008-09-16 15:16:46 11,516 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3335814581-3972811892-259792903-1002_UserData.bin
+ 2008-09-17 23:10:12 11,572 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3335814581-3972811892-259792903-1002_UserData.bin
- 2008-09-16 15:16:46 67,950 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-09-17 23:10:12 68,546 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-09-15 08:10:34 3,034 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
+ 2008-09-16 22:01:15 3,034 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
- 2008-09-16 15:16:41 51,750 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-09-17 23:10:06 52,126 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@="{4433A54A-1AC8-432F-90FC-85F045CF383C}"
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-02-26 09:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@="{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}"
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-02-26 09:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@="{476D0EA3-80F9-48B5-B70B-05E677C9C148}"
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-02-26 09:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"smartchkwin"="C:\Windows\system32\lcpmvono.exe" [BU]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-18 51048]
"osCheck"="C:\Program Files\Norton 360\osCheck.exe" [2008-02-26 988512]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SDNotify]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PalTalk.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PalTalk.lnk
backup=C:\Windows\pss\PalTalk.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
--a------ 2004-12-09 13:14 1068032 C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
--a------ 2006-11-02 13:35 125440 C:\Windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HiChatter]
--a------ 2008-08-24 18:55 3148288 C:\Program Files\HiChatter Messenger\HiChater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
--a------ 2007-01-13 02:48 275800 C:\Program Files\Microsoft LifeCam\LifeExp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-10-18 12:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 2004-11-25 13:59 143360 C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
--a------ 2004-11-24 13:29 880640 C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
--a------ 2007-01-11 11:40 232184 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
--a------ 2008-01-09 13:35 1232896 C:\Program Files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSTray]
--------- 2007-09-17 21:09 552960 C:\Program Files\SiS VGA Utilities\SiSTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
--a------ 2008-01-29 18:38 583048 C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2007-03-01 14:24 857648 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-12-16 03:00 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\toolbar_eula_launcher]
--a------ 2007-02-20 17:20 28672 C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX1000]
--a------ 2006-12-06 00:38 707360 C:\Windows\vVX1000.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2007-09-26 20:22 1006264 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2006-11-02 13:36 201728 C:\Program Files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 2007-09-03 11:39 4702208 C:\Windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
--a------ 2007-08-03 06:22 1826816 C:\Windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{EC6EA23B-9A35-4811-82D6-8E7AD6110811}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{7004C0FA-1B46-492C-81BF-92778791E96D}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{C21AB4A0-E097-4E12-AFB4-152116E536F2}C:\\program files\\paltalk messenger\\paltalk.exe"= UDP:C:\program files\paltalk messenger\paltalk.exe

altalkScene
"UDP Query User{BA7CDBA4-AA03-4C2E-B3CF-3F1CCA0C4A5C}C:\\program files\\paltalk messenger\\paltalk.exe"= TCP:C:\program files\paltalk messenger\paltalk.exe

altalkScene
"TCP Query User{3B7F71C8-ECF1-45C5-AD02-26F45EE806D8}C:\\program files\\paltalk messenger\\paltalk.exe"= UDP:C:\program files\paltalk messenger\paltalk.exe

altalkScene
"UDP Query User{A8B3E5F8-DBC6-411D-AA03-3AF9ABDDCA91}C:\\program files\\paltalk messenger\\paltalk.exe"= TCP:C:\program files\paltalk messenger\paltalk.exe

altalkScene
"{0DB9E773-E1DC-4514-AE98-E07E5A2E73DD}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{AA8F40BF-EAA4-4596-A10F-5509A9263360}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{DCC171FE-8C5A-4E2B-A5E8-96A7970E204E}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{3180D18E-32C4-4C96-88FA-7B303D38DEC6}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{CDA5062E-8639-4474-BBEC-6887B7A18557}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{F3EA9694-1236-4DA9-ABF8-526B8E8C3AA8}"= UDP:C:\Program Files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{411D83E8-EB2D-499B-9A56-EBE551AE409D}"= TCP:C:\Program Files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{E3A90BF0-1CC3-41CF-B1ED-421D3FB77845}"= UDP:C:\Program Files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{F95C1DDA-D688-4BF7-A7F9-E3FF3B99890B}"= TCP:C:\Program Files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{2ACE9084-7234-4017-963F-15B3ADA0A278}"= UDP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{C4A27154-AF46-462B-A02D-546C12F07B7D}"= TCP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{03E26DF2-95CE-4313-A388-3939D706742C}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{0875B147-D003-4A6A-A443-B827A966A436}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{9571F356-0017-41B2-835F-1A89FAB20758}"= UDP:C:\Program Files\Voipwise.com\Voipwise\Voipwise.exe:Voipwise
"{666EFB6F-CA08-4388-9BDF-554C7CAD1655}"= TCP:C:\Program Files\Voipwise.com\Voipwise\Voipwise.exe:Voipwise
"{77624406-AA48-443B-A2FB-D701D1242117}"= UDP:C:\Program Files\Voipwise.com\Voipwise\Voipwise.exe:Voipwise
"{7FFDB68D-98F0-4E6A-8014-BFBE1402ADE2}"= TCP:C:\Program Files\Voipwise.com\Voipwise\Voipwise.exe:Voipwise
"{A0CFB4EB-D5B9-4886-87D2-4EABD1C30666}"= UDP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{541AB76C-8374-49DE-A8AA-81EFB8EB7257}"= TCP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"TCP Query User{7D31529A-94FC-4F55-B346-D2CCD6C2C5AB}C:\\users\\dj bonnet\\appdata\\local\\yahoo!\\messenger for vista\\yahoo.messenger.ymapp.exe"= UDP:C:\users\dj bonnet\appdata\local\yahoo!\messenger for vista\yahoo.messenger.ymapp.exe:yahoo.messenger.ymapp.exe
"UDP Query User{7B337831-D04A-49B9-85D0-2080EBDA9205}C:\\users\\dj bonnet\\appdata\\local\\yahoo!\\messenger for vista\\yahoo.messenger.ymapp.exe"= TCP:C:\users\dj bonnet\appdata\local\yahoo!\messenger for vista\yahoo.messenger.ymapp.exe:yahoo.messenger.ymapp.exe
"{22AC8DC4-24E0-4801-BAA6-063B8BE180F9}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C2AE7D55-253F-47D7-AE7F-4C5FC60FDD7D}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{D51F3C21-292E-465E-8E34-6ECEEDF5887B}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{9DDB4E36-3D46-4AFD-A634-770F8D5E6DB7}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{47CC6B76-073D-47A0-813A-C2684CEB979F}C:\\program files\\bitlord\\bitlord.exe"= UDP:C:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{4E2903A8-8694-4F8D-BB9B-2E6E61E326E1}C:\\program files\\bitlord\\bitlord.exe"= TCP:C:\program files\bitlord\bitlord.exe:BitLord
"TCP Query User{B145B8DB-CBEB-4F8E-8A18-5E5A26F2DA3D}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{A4B905B5-3384-4D3D-BDAA-EF793FBF0F86}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{23E93E8F-FEFA-49D5-A166-E3D38CBDEF79}C:\\program files\\bitlord\\bitlord.exe"= UDP:C:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{27E8EE9B-C5C8-4B90-8BCA-C1AE7AFF1434}C:\\program files\\bitlord\\bitlord.exe"= TCP:C:\program files\bitlord\bitlord.exe:BitLord
"TCP Query User{2687C437-FDAF-4356-9D20-86C4A4344382}C:\\program files\\wh gbp casino\\casino.exe"= Disabled:UDP:C:\program files\wh gbp casino\casino.exe:Casino
"UDP Query User{A75FD8B7-F1B5-4C40-9B75-0D909682DE60}C:\\program files\\wh gbp casino\\casino.exe"= Disabled:TCP:C:\program files\wh gbp casino\casino.exe:Casino
"TCP Query User{F3D7BD7C-68E1-434F-9EC9-B7E3A8BFB1EA}C:\\program files\\wh gbp casino\\casinoua.exe"= Disabled:UDP:C:\program files\wh gbp casino\casinoua.exe:CasinoUA
"UDP Query User{4C06FE68-22BA-4C8B-9D60-220F4C050643}C:\\program files\\wh gbp casino\\casinoua.exe"= Disabled:TCP:C:\program files\wh gbp casino\casinoua.exe:CasinoUA
"TCP Query User{3EE8E4EE-C35C-425B-9D9B-6E6DCA47DD13}C:\\program files\\ppstream\\ppstream.exe"= UDP:C:\program files\ppstream\ppstream.exe

PS????
"UDP Query User{4C373856-1606-4848-AB65-D5520DB2D09E}C:\\program files\\ppstream\\ppstream.exe"= TCP:C:\program files\ppstream\ppstream.exe

PS????
"TCP Query User{03B8035D-2ABF-4B76-95BF-381F262E46AA}C:\\program files\\tvuplayer\\tvuplayer.exe"= UDP:C:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"UDP Query User{FF0526E5-8BA6-4CC7-BAF3-D1B1008E7E41}C:\\program files\\tvuplayer\\tvuplayer.exe"= TCP:C:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"TCP Query User{A006C09C-9A3D-4382-8844-0871E1421A8E}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{1C7F0726-562A-4C9B-91C0-1E7B46347789}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\PPStream\\PPStream.exe"= C:\Program Files\PPStream\PPStream.exe:*:Enabled

PSÍøÂçµçÊÓ
"C:\\Program Files\\PPStream\\PPSAP.exe"= C:\Program Files\PPStream\PPSAP.exe:*:Enabled

PS ÍøÂç¼ÓËÙÆ÷
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080913.004\IDSvix86.sys [2008-08-08 261680]
R2 LiveUpdate Notice;LiveUpdate Notice;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-02-18 149352]
R2 MSCamSvc;MSCamSvc;C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2007-01-04 240408]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-07-07 809296]
R3 SiS6350;SiS6350;C:\Windows\system32\DRIVERS\SISGRKMD.sys [2008-02-21 456192]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\system32\DRIVERS\SiSGB6.sys [2007-06-20 47616]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-06-13 41008]
S3 COH_Mon;COH_Mon;C:\Windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
S3 UMPass;Microsoft UMPass Driver;C:\Windows\system32\DRIVERS\umpass.sys [2006-11-02 7168]
S3 VX1000;VX-1000;C:\Windows\system32\DRIVERS\VX1000.sys [2006-12-06 1963680]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\shell\AutoRun\command - E:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52b473b1-b887-11dc-9a65-d8d01b36dcf1}]
\shell\AutoRun\command - E:\autorun.exe
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-uish - C:\Windows\system32\pavejqry.exe
MSConfigStartUp-AplCfg - C:\Windows\system32\pghidqhk.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-18 02:11:14
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-09-18 2:14:58
ComboFix-quarantined-files.txt 2008-09-18 01:13:53
ComboFix2.txt 2008-09-16 22:35:22
ComboFix3.txt 2008-09-16 20:36:00
Pre-Run: The system cannot find message text for message number 0x2379 in the message file for Application.
Post-Run: 4,163,993,600 bytes free
343 --- E O F --- 2008-09-16 22:46:55