Combofix Log - ComboFix 08-02.02.5 - Brian 2008-02-02 11:09:36.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1568 [GMT -8:00]
Running from: C:\Documents and Settings\Brian\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Brian\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE
C:\dcmqd.exe
C:\Documents and Settings\All Users\Application Data\gxyhersv.dll
C:\WINDOWS\exwluhcr.dll
C:\WINDOWS\kzaxcjgx.exe
C:\WINDOWS\pvkebtff
C:\WINDOWS\system32\fnhoje
C:\WINDOWS\system32\ijbijqbm.dll
C:\WINDOWS\system32\pmkji.dll
C:\WINDOWS\system32\rxjddnvj.exe
C:\WINDOWS\unwpatej.exe
E:\setup.exe
I:\LaunchU3.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\fnhoje
C:\WINDOWS\exwluhcr.dll
C:\WINDOWS\kzaxcjgx.exe
C:\WINDOWS\PerfInfo
C:\WINDOWS\PerfInfo\uK1OD0S2dHwp.exe
C:\WINDOWS\system32\fnhoje
C:\WINDOWS\system32\rxjddnvj.exe
C:\WINDOWS\unwpatej.exe
.
((((((((((((((((((((((((( Files Created from 2008-01-02 to 2008-02-02 )))))))))))))))))))))))))))))))
.
2008-02-02 00:16 . 2008-02-02 00:16 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-01 23:52 . 2008-02-01 23:52 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-01 23:52 . 2008-02-02 00:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-01 23:27 . 2008-02-01 23:27 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-01 23:27 . 2008-02-01 23:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-01 18:26 . 2008-02-02 11:10 7,911 --a------ C:\WINDOWS\system32\Config.MPF
2008-02-01 18:22 . 2007-07-21 09:08 201,288 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-02-01 18:22 . 2007-07-24 07:40 79,304 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-02-01 18:22 . 2007-07-21 09:08 40,488 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-02-01 18:22 . 2007-07-21 09:08 35,240 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-02-01 18:22 . 2007-07-24 12:02 33,800 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-02-01 18:21 . 2007-07-13 09:20 113,952 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-02-01 18:18 . 2008-02-01 18:19 <DIR> d-------- C:\Program Files\McAfee.com
2008-02-01 18:17 . 2008-02-02 09:51 <DIR> d-------- C:\Program Files\McAfee
2008-02-01 18:17 . 2008-02-01 18:21 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-02-01 18:11 . 2008-02-01 18:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-01 17:16 . 2008-02-01 17:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-01 17:14 . 2008-02-01 17:14 <DIR> d-------- C:\Program Files\ThreatFire
2008-02-01 17:14 . 2008-02-01 17:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-02-01 17:14 . 2007-12-20 11:24 52,032 --a------ C:\WINDOWS\system32\drivers\TfFsMon.sys
2008-02-01 17:14 . 2007-12-20 11:24 41,792 --a------ C:\WINDOWS\system32\drivers\TfSysMon.sys
2008-02-01 17:14 . 2007-12-20 11:13 33,600 --a------ C:\WINDOWS\system32\drivers\TfNetMon.sys
2008-02-01 17:14 . 2007-12-20 11:13 12,608 --a------ C:\WINDOWS\system32\drivers\TfKbMon.sys
2008-02-01 16:23 . 2008-02-01 16:23 <DIR> d-------- C:\WINDOWS\pvkebtff
2008-01-18 13:06 . 2008-01-18 13:37 <DIR> d-------- C:\Documents and Settings\Brian\Application Data\FileZilla
2008-01-18 13:05 . 2008-01-18 13:05 <DIR> d-------- C:\Program Files\FileZilla FTP Client
2008-01-18 12:48 . 2008-01-18 12:48 <DIR> d-------- C:\Program Files\FileZilla Server
2008-01-16 16:54 . 2008-01-25 15:46 <DIR> d-------- C:\Program Files\Xfire
2008-01-16 16:54 . 2008-02-02 11:09 <DIR> d-------- C:\Documents and Settings\Brian\Application Data\Xfire
2008-01-15 11:36 . 2008-02-01 17:05 4,958,588 --------- C:\WINDOWS\{00000002-00000000-00000009-00001102-00000004-10031102}.BAK
2008-01-15 11:36 . 2008-02-02 11:10 30,912 --a------ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000009-00001102-00000004-10031102}.rfx
2008-01-15 11:36 . 2008-02-02 11:10 30,912 --a------ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000009-00001102-00000004-10031102}.rfx
2008-01-15 11:36 . 2008-02-02 11:10 30,120 --a------ C:\WINDOWS\system32\BMXCtrlState-{00000002-00000000-00000009-00001102-00000004-10031102}.rfx
2008-01-15 11:36 . 2008-02-02 11:10 30,120 --a------ C:\WINDOWS\system32\BMXBkpCtrlState-{00000002-00000000-00000009-00001102-00000004-10031102}.rfx
2008-01-15 11:36 . 2008-02-02 11:10 11,564 --a------ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000009-00001102-00000004-10031102}.rfx
2008-01-15 11:36 . 2008-02-02 11:10 1,080 --a------ C:\WINDOWS\system32\settingsbkup.sfm
2008-01-15 11:36 . 2008-02-02 11:10 1,080 --a------ C:\WINDOWS\system32\settings.sfm
2008-01-15 11:20 . 2008-02-01 17:05 4,958,588 --a------ C:\WINDOWS\{00000002-00000000-00000009-00001102-00000004-10031102}.CDF
2008-01-15 11:19 . 2006-08-11 15:14 86,446 --a------ C:\WINDOWS\system32\instwdm.ini
2008-01-15 11:19 . 2006-08-11 14:55 10,240 --a------ C:\WINDOWS\CTDCRES.DLL
2008-01-15 10:05 . 2008-01-15 10:06 <DIR> d-------- C:\WINDOWS\NV31362052.TMP
2008-01-15 10:04 . 2008-01-15 10:04 <DIR> d-------- C:\NVIDIA
2008-01-15 08:21 . 2008-01-15 08:21 <DIR> d-------- C:\Program Files\Linksys Wireless-G Wireless Network Monitor
2008-01-15 08:21 . 2004-12-22 01:32 1,396,831 --a------ C:\WINDOWS\system32\AegisE5.dll
2008-01-15 08:21 . 2004-12-22 01:32 369,024 --a------ C:\WINDOWS\system32\drivers\BCMWL5.SYS
2008-01-15 08:21 . 2003-11-20 22:03 147,456 --a------ C:\WINDOWS\system32\ssleay32.dll
2008-01-15 08:21 . 2005-03-04 03:13 71,520 --a------ C:\WINDOWS\system32\drivers\WMP54GS.inf
2008-01-15 08:21 . 2008-01-15 08:21 17,801 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2008-01-15 08:21 . 2005-03-07 11:50 7,986 --a------ C:\WINDOWS\system32\drivers\WMP54GS.cat
2008-01-15 08:21 . 2008-01-15 08:21 4,200 --a------ C:\WINDOWS\system32\WLAN.INI
2008-01-14 15:02 . 2007-06-28 08:43 17,254 --a------ C:\WINDOWS\system32\nvwsapps.xml
2008-01-14 14:47 . 2005-02-01 18:18 17,992 --a------ C:\WINDOWS\system32\drivers\bcm42rly.sys
2008-01-14 14:47 . 2005-02-01 18:18 17,992 --a------ C:\WINDOWS\bcm42rly.sys
2008-01-14 14:29 . 2008-01-14 14:29 2,422 --a------ C:\WINDOWS\system32\wpa.bak
2008-01-14 13:52 . 2004-08-03 22:08 17,024 --a------ C:\WINDOWS\system32\drivers\usbohci.sys
2008-01-14 13:52 . 2004-08-03 22:08 17,024 --a--c--- C:\WINDOWS\system32\dllcache\usbohci.sys
2008-01-10 20:30 . 2008-01-10 20:30 <DIR> d-------- C:\Documents and Settings\Brian\Application Data\Logitech
2008-01-10 20:29 . 2008-01-10 20:29 <DIR> d-------- C:\Program Files\Common Files\LogiShared
2008-01-10 20:29 . 2008-01-10 20:29 <DIR> d-------- C:\Documents and Settings\Brian\Application Data\Leadertech
2008-01-10 20:28 . 2007-04-11 15:33 1,419,024 --a------ C:\WINDOWS\system32\WdfCoInstaller01005.dll
2008-01-10 20:28 . 2007-04-11 15:32 56,080 --a------ C:\WINDOWS\KHALMNPR.Exe
2008-01-10 20:28 . 2007-04-11 15:32 36,112 --a------ C:\WINDOWS\system32\drivers\LMouFilt.Sys
2008-01-10 20:28 . 2007-04-11 15:32 34,832 --a------ C:\WINDOWS\system32\drivers\LHidFilt.Sys
2008-01-10 20:28 . 2008-01-10 20:28 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-01-10 20:28 . 2008-01-10 20:28 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-01-10 20:27 . 2008-01-10 20:27 <DIR> d-------- C:\Program Files\Logitech
2008-01-10 20:27 . 2008-01-10 20:27 <DIR> d-------- C:\Program Files\Common Files\Logitech
2008-01-10 20:27 . 2008-01-10 20:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-01-10 20:27 . 2007-04-23 04:00 163,840 --a------ C:\WINDOWS\system32\kemutb.dll
2008-01-10 20:27 . 2007-04-23 04:00 135,168 --a------ C:\WINDOWS\system32\KemUtil.dll
2008-01-10 20:27 . 2007-04-23 04:00 110,592 --a------ C:\WINDOWS\system32\KemWnd.dll
2008-01-10 20:27 . 2007-04-23 04:00 69,632 --a------ C:\WINDOWS\system32\KemXML.dll
2008-01-10 20:26 . 2008-01-10 20:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
2008-01-10 16:30 . 2008-01-10 16:30 54,608 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-01-10 14:20 . 2008-02-01 13:43 23 --a------ C:\WINDOWS\popcinfot.dat
2008-01-09 15:14 . 2008-01-09 15:14 376 --a------ C:\WINDOWS\ODBC.INI
2008-01-09 15:13 . 2008-01-09 15:13 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-01-08 10:29 . 2008-01-08 10:29 <DIR> d-------- C:\Program Files\Rainlendar2
2008-01-08 10:29 . 2008-02-02 10:04 <DIR> d-------- C:\Documents and Settings\Brian\.rainlendar2
2008-01-04 14:26 . 2008-01-04 14:26 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Creative
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-02 07:26 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-02 00:33 --------- d-----w C:\Program Files\AIMTunes
2008-02-02 00:27 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-02 00:16 --------- d-----w C:\Program Files\Stardock
2008-02-02 00:16 --------- d-----w C:\Program Files\Common Files\Stardock
2008-02-01 22:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-01 21:42 --------- d-----w C:\Program Files\Steam
2008-01-31 04:15 --------- d-----w C:\Documents and Settings\Brian\Application Data\uTorrent
2008-01-29 01:09 --------- d-----w C:\Program Files\World of Warcraft
2008-01-18 19:47 --------- d-----w C:\Documents and Settings\Brian\Application Data\Apple Computer
2008-01-16 11:43 --------- d-----w C:\Program Files\Last.fm
2008-01-15 19:35 --------- d-----w C:\Program Files\Creative
2008-01-15 19:19 --------- d-----w C:\Documents and Settings\Brian\Application Data\Creative
2008-01-15 17:45 22,328 ----a-w C:\Documents and Settings\Brian\Application Data\PnkBstrK.sys
2008-01-15 15:46 --------- d-----w C:\Program Files\Trillian
2008-01-09 23:20 --------- d-----w C:\Documents and Settings\Brian\Application Data\Viewpoint
2008-01-09 23:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-09 23:19 --------- d-----w C:\Program Files\MAIET
2008-01-09 23:17 --------- d-----w C:\Program Files\Diablo II
2007-12-09 20:27 --------- d-----w C:\Program Files\Ventrilo
2007-12-05 09:41 7,435,392 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{49EE4829-CC17-4E3E-8483-F6BC614F3BE1}]
C:\WINDOWS\system32\pmkji.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}]
C:\Program Files\Helper\1201911954.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 07:20 50528]
"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 10:31 1372160]
"bpg6688"="C:\Program Files\ZASystems Inc\ZAShare\ZaShare.exe" [ ]
"Rainlendar2"="C:\Program Files\Rainlendar2\Rainlendar2.exe" [2007-12-30 02:23 1365504]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-03 23:56 158208]
"ThreatFire"="C:\Program Files\ThreatFire\TFTray.exe" [2007-12-20 11:13 1238336]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SetDefaultMIDI"="MIDIDEF.exe" [2006-08-11 14:42 25600 C:\WINDOWS\MIDIDEF.EXE]
C:\Documents and Settings\Brian\Start Menu\Programs\Startup\
Last.fm Helper.lnk - C:\Program Files\Last.fm\LastFMHelper.exe [2007-09-02 00:28:37 106496]
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2007-05-11 12:43:44 3450608]
Xfire.lnk - C:\Program Files\Xfire\xfire.exe [2008-01-10 16:30:34 2872144]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-01-10 20:27:39 692224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"uK1OD0S2dH"= rundll32.exe "C:\WINDOWS\exwluhcr.dll",DllCleanServer
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjiiig]
ljjiiig.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mxkufdsj]
mxkufdsj.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Brian^Start Menu^Programs^Startup^Last.fm Helper.lnk]
path=C:\Documents and Settings\Brian\Start Menu\Programs\Startup\Last.fm Helper.lnk
backup=C:\WINDOWS\pss\Last.fm Helper.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Brian^Start Menu^Programs^Startup^Product Registration.lnk]
path=C:\Documents and Settings\Brian\Start Menu\Programs\Startup\Product Registration.lnk
backup=C:\WINDOWS\pss\Product Registration.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\9cffd297]
C:\WINDOWS\system32\ijbijqbm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
--a------ 2005-09-23 21:30 483328 C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
--a------ 2006-08-11 14:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2007-04-03 14:29 165784 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-11-15 13:11 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
--a------ 2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Krait]
--a------ 2006-01-24 09:38 147456 C:\Program Files\Razer\Krait\razerhid.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 08:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-12-05 01:41 8523776 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-12-05 01:41 81920 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-11-14 23:43 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2007-12-01 08:54 1266936 C:\Program Files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-03-14 02:43 83608 C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tarantula]
--a------ 2007-05-07 09:52 159744 C:\Program Files\Razer\Tarantula\razerhid.exe
R1 crdpkt;Cirond NDIS Usermode I/O Protocol;C:\WINDOWS\system32\DRIVERS\crdpkt.sys [2004-12-03 15:34]
S1 fnhoje;fnhoje;C:\WINDOWS\system32\fnhoje []
S3 krait03;Razer krait USB Filter Driver;C:\WINDOWS\system32\Drivers\krait.sys [2005-12-07 16:27]
S3 TarFltr;Razer Tarantula USB Keyboard;C:\WINDOWS\system32\Drivers\UsbFltr.sys [2007-04-11 15:23]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d13162cb-b25e-11db-8e15-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-02-01 01:16:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-02 02:20:08 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-02-02 02:20:06 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-02 11:12:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\Program Files\Stardock\ObjectDock\DockShellHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Linksys Wireless-G Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G Wireless Network Monitor\WMP54GS.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-02-02 11:15:26 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-02 19:15:23
ComboFix2.txt 2008-02-02 18:06:13
.
2008-01-11 13:01:16 --- E O F ---
HJT - Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:19:16 AM, on 2/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Linksys Wireless-G Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G Wireless Network Monitor\WMP54GS.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Xfire\xfire.exe
C:\Program Files\AIM6\aolsoftware.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {49EE4829-CC17-4E3E-8483-F6BC614F3BE1} - C:\WINDOWS\system32\pmkji.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: e404 helper - {F10587E9-0E47-4CBE-ABCD-7DD20B8622FF} - C:\Program Files\Helper\1201911954.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA9960] command /c del "C:\Documents and Settings\Brian\Local Settings\Temp\~DFA13F.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8101] cmd /c del "C:\Documents and Settings\Brian\Local Settings\Temp\~DFA13F.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2027] command /c del "C:\WINDOWS\system32\mxkufdsj.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7250] cmd /c del "C:\WINDOWS\system32\mxkufdsj.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9049] command /c del "C:\WINDOWS\system32\mxkufdsj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2860] cmd /c del "C:\WINDOWS\system32\mxkufdsj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2488] command /c del "C:\WINDOWS\system32\pmkji.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6247] cmd /c del "C:\WINDOWS\system32\pmkji.dll_old"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [bpg6688] "C:\Program Files\ZASystems Inc\ZAShare\ZaShare.exe" bpg6688
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKLM\..\Policies\Explorer\Run: [uK1OD0S2dH] rundll32.exe "C:\WINDOWS\exwluhcr.dll",DllCleanServer
O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'Default user')
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://www.creative....031/CTSUEng.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1196234744766O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1196234734297O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative....15033/CTPID.cabO20 - Winlogon Notify: ljjiiig - ljjiiig.dll (file missing)
O20 - Winlogon Notify: mxkufdsj - mxkufdsj.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: WMP54GSSVC - GEMTEKS - C:\Program Files\Linksys Wireless-G Wireless Network Monitor\WLService.exe
--
End of file - 9686 bytes