hey...
combofix.txt
ComboFix 08-04-10.9 - G 2008-04-11 19:57:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.549 [GMT 5.5:30]
Running from: C:\Documents and Settings\G\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMb7d027cd.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\asobkkmh.dll
C:\WINDOWS\system32\beirpdql.dll
C:\WINDOWS\system32\blnfoexp.dll
C:\WINDOWS\system32\cfjhixjk.dll
C:\WINDOWS\system32\dnbmyavx.dll
C:\WINDOWS\system32\dseeiosv.dll
C:\WINDOWS\system32\glbxqxmi.dll
C:\WINDOWS\system32\gugpsmln.dll
C:\WINDOWS\system32\gygylcao.ini
C:\WINDOWS\system32\hmkkbosa.ini
C:\WINDOWS\system32\jaxtwswb.ini
C:\WINDOWS\system32\jloeacvc.ini
C:\WINDOWS\system32\ktbbynpa.ini
C:\WINDOWS\system32\kyaoupcb.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\orhhmsmo.dll
C:\WINDOWS\system32\pmnNfdaY.dll
C:\WINDOWS\system32\pxeofnlb.ini
C:\WINDOWS\system32\vebtbhoq.dll
C:\WINDOWS\system32\vsoieesd.ini
C:\WINDOWS\system32\x64
C:\WINDOWS\system32\xvaymbnd.ini
C:\WINDOWS\system32\YadfNnmp.ini
C:\WINDOWS\system32\YadfNnmp.ini2
.
((((((((((((((((((((((((( Files Created from 2008-03-11 to 2008-04-11 )))))))))))))))))))))))))))))))
.
2008-04-11 13:28 . 2008-04-11 13:28 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-11 13:26 . 2008-04-11 13:26 <DIR> d-------- C:\Deckard
2008-04-09 14:42 . 2008-04-11 16:46 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-04-08 10:47 . 2008-04-04 23:10 269,312 --a------ C:\WINDOWS\system32\pmnNfdaY.dll_old
2008-04-08 10:47 . 2008-04-06 12:54 85,056 --a------ C:\WINDOWS\system32\bwswtxaj.dll_old
2008-04-06 14:55 . 2008-04-06 19:25 733 --a------ C:\WINDOWS\wininit.ini
2008-04-06 13:11 . 2008-04-08 13:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-05 15:36 . 2008-04-05 15:36 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-04-05 15:36 . 2008-04-05 15:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Macrovision
2008-04-05 10:10 . 2008-04-05 10:10 <DIR> d-------- C:\Program Files\Microsoft Photoeditor
2008-04-05 10:06 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-04-04 23:49 . 2008-04-04 23:49 <DIR> d-------- C:\Program Files\VideoLAN
2008-04-04 23:42 . 2008-04-07 10:45 <DIR> d-------- C:\Program Files\eMule
2008-04-04 17:37 . 2008-04-04 17:37 35,840 --a------ C:\WINDOWS\system32\geBqQHYs.dll
2008-04-04 17:32 . 2008-04-04 17:32 <DIR> d-------- C:\Program Files\NeroInstall.bak
2008-04-04 17:28 . 2008-04-04 17:28 <DIR> d-------- C:\Documents and Settings\G\Application Data\Nero
2008-04-04 17:26 . 2008-04-04 17:26 <DIR> d-------- C:\Program Files\Nero
2008-04-04 17:26 . 2008-04-04 17:27 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-04-04 17:26 . 2008-04-04 17:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-04-04 14:50 . 2008-04-04 14:50 <DIR> d-------- C:\Program Files\Desktop Guitarist 2
2008-04-04 14:50 . 2008-04-04 14:50 <DIR> d-------- C:\Documents and Settings\G\WINDOWS
2008-04-04 14:50 . 1999-03-23 09:12 299,520 --a------ C:\WINDOWS\uninst.exe
2008-04-04 14:28 . 2008-04-04 14:28 <DIR> d-------- C:\Program Files\GPLGS
2008-04-04 14:24 . 2008-04-04 14:24 <DIR> d-------- C:\Program Files\Acro Software
2008-04-04 14:24 . 2007-07-12 22:33 87,552 --a------ C:\WINDOWS\system32\cpwmon2k.dll
2008-04-04 14:21 . 2008-04-04 14:21 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-04-04 14:21 . 2008-04-04 14:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-04-04 14:14 . 2008-04-05 15:34 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-04-04 14:03 . 2008-04-04 14:16 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-04 14:02 . 2008-04-04 14:03 <DIR> d-------- C:\Program Files\Windows Live
2008-04-04 14:02 . 2008-04-04 14:02 <DIR> d-------- C:\Program Files\MagicISO
2008-04-04 14:02 . 2008-04-04 14:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-04 00:59 . 2008-04-04 00:59 <DIR> d-------- C:\Program Files\iTunes
2008-04-04 00:59 . 2008-04-04 00:59 <DIR> d-------- C:\Program Files\iPod
2008-04-04 00:59 . 2008-04-04 00:59 <DIR> d-------- C:\Program Files\Bonjour
2008-04-04 00:59 . 2008-04-04 00:59 <DIR> d-------- C:\Documents and Settings\G\Application Data\Apple Computer
2008-04-04 00:59 . 2008-04-04 10:52 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-04 00:59 . 2008-04-04 01:00 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-04 00:58 . 2008-04-04 00:59 <DIR> d-------- C:\Program Files\QuickTime
2008-04-04 00:58 . 2008-04-04 00:58 <DIR> d-------- C:\Program Files\Apple Software Update
2008-04-04 00:58 . 2008-04-04 00:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-04 00:58 . 2008-02-18 11:16 30,464 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
2008-04-04 00:57 . 2008-04-04 00:57 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-04-04 00:57 . 2008-04-04 00:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-04-03 23:03 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-02 19:56 . 2008-04-02 19:56 376 --a------ C:\WINDOWS\ODBC.INI
2008-04-02 19:55 . 2008-04-02 19:55 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-04-02 19:54 . 2008-04-02 19:55 <DIR> d-------- C:\WINDOWS\ShellNew
2008-04-02 18:33 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-04-02 18:33 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-04-02 18:33 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-04-02 18:33 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-04-02 01:31 . 2008-04-03 23:18 <DIR> d-------- C:\Program Files\BitLord
2008-04-02 01:22 . 2008-04-11 16:02 <DIR> d-------- C:\shared
2008-04-02 01:22 . 2008-04-11 16:02 <DIR> d-------- C:\Incomplete
2008-04-02 01:22 . 2008-04-02 01:22 <DIR> d-------- C:\Documents and Settings\G\Incomplete
2008-04-02 01:17 . 2008-04-04 13:45 <DIR> d-------- C:\Documents and Settings\G\Application Data\LimeWire
2008-04-02 01:14 . 2008-04-03 23:03 <DIR> d-------- C:\Program Files\Java
2008-04-02 01:03 . 2008-04-08 21:45 <DIR> d-------- C:\Program Files\LimeWire
2008-04-02 01:03 . 2008-04-02 01:03 <DIR> d-------- C:\Program Files\Common Files\Java
2008-04-02 00:25 . 2008-04-02 00:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-04-02 00:24 . 2008-04-02 00:24 <DIR> d-------- C:\Program Files\Yahoo!
2008-04-02 00:02 . 2008-04-02 00:02 <DIR> d-------- C:\Documents and Settings\G\Contacts
2008-04-01 23:34 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-04-01 23:34 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-04-01 23:34 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-04-01 23:34 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-04-01 23:34 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-04-01 18:01 . 2004-08-04 00:56 74,240 --a------ C:\WINDOWS\system32\usbui.dll
2008-04-01 18:01 . 2004-08-04 00:56 74,240 --a--c--- C:\WINDOWS\system32\dllcache\usbui.dll
2008-04-01 18:01 . 2004-08-04 04:29 57,472 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-04-01 18:01 . 2004-08-03 22:58 23,040 --a------ C:\WINDOWS\system32\drivers\mouclass.sys
2008-04-01 18:01 . 2004-08-03 22:58 23,040 --a--c--- C:\WINDOWS\system32\dllcache\mouclass.sys
2008-04-01 18:01 . 2004-08-04 04:01 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys
2008-04-01 18:01 . 2004-08-04 04:37 8,832 --a------ C:\WINDOWS\system32\drivers\wmiacpi.sys
2008-04-01 18:00 . 2008-04-04 17:33 <DIR> d--hs---- C:\WINDOWS\Installer
2008-04-01 18:00 . 2008-04-11 19:44 356,120 --a------ C:\WINDOWS\system32\PerfStringBackup.INI
2008-04-01 18:00 . 2004-08-04 04:37 14,080 --a------ C:\WINDOWS\system32\drivers\CmBatt.sys
2008-04-01 18:00 . 2001-08-17 19:27 14,080 --a------ C:\WINDOWS\system32\drivers\battc.sys
2008-04-01 18:00 . 2001-08-17 19:28 9,344 --a------ C:\WINDOWS\system32\drivers\compbatt.sys
2008-04-01 18:00 . 2008-04-01 16:00 1,355 --a------ C:\WINDOWS\imsins.BAK
2008-04-01 16:20 . 2008-04-01 16:20 <DIR> d-------- C:\Documents and Settings\G\Application Data\DivX
2008-04-01 16:07 . 2008-04-01 16:06 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-04-01 16:07 . 2008-04-01 16:06 298,104 --a------ C:\WINDOWS\system32\imon.dll
2008-04-01 16:07 . 2008-04-01 16:06 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2008-04-01 16:06 . 2008-04-08 13:38 <DIR> d-------- C:\Program Files\ESET
2008-04-01 16:00 . 2008-04-02 14:27 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-04-01 15:43 . 2008-04-01 15:45 <DIR> d-------- C:\Program Files\InterActual
2008-04-01 15:41 . 2008-04-04 18:08 <DIR> d-------- C:\Program Files\DivX
2008-04-01 15:39 . 2008-04-01 15:39 <DIR> d-------- C:\Documents and Settings\G\Application Data\InterVideo
2008-04-01 15:38 . 2008-04-01 15:38 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-01 15:38 . 2008-04-04 10:52 <DIR> d-------- C:\Program Files\Google
2008-04-01 15:37 . 2008-04-01 15:42 <DIR> d-------- C:\Program Files\InterVideo
2008-04-01 15:37 . 2008-04-01 15:37 <DIR> d-------- C:\Program Files\Creative
2008-04-01 15:37 . 2008-04-01 15:43 <DIR> d-------- C:\Program Files\Common Files\InterVideo
2008-04-01 15:37 . 2003-01-27 16:32 831,600 --a------ C:\WINDOWS\system32\Ctaa1.dat
2008-04-01 15:37 . 2003-11-11 10:44 333,600 --a------ C:\WINDOWS\system32\drivers\ctdvda2k.sys
2008-04-01 15:37 . 2002-11-21 10:57 204,800 --a------ C:\WINDOWS\system32\IVIresizeW7.dll
2008-04-01 15:37 . 2002-11-21 10:57 200,704 --a------ C:\WINDOWS\system32\IVIresizeA6.dll
2008-04-01 15:37 . 2002-11-21 10:57 192,512 --a------ C:\WINDOWS\system32\IVIresizeP6.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-01 10:30 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-04-01 10:30 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
2008-04-01 08:38 --------- d-----w C:\Program Files\Intel
2008-04-01 07:11 --------- d-----w C:\Program Files\microsoft frontpage
2008-02-28 12:08 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2008-02-26 10:44 972,072 ----a-w C:\WINDOWS\UNRecode.exe
2008-02-21 02:05 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-02-21 02:05 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-02-21 02:04 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-02-21 02:04 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-02-21 02:04 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-02-21 02:04 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-02-21 02:04 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-02-21 02:04 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-02-21 02:04 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-02-21 02:04 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-02-21 02:03 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-02-21 02:03 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-02-18 10:51 132,904 ----a-w C:\WINDOWS\system32\drivers\imagesrv.sys
2008-02-18 10:51 11,304 ----a-w C:\WINDOWS\system32\drivers\imagedrv.sys
2008-02-18 10:34 95,600 ----a-w C:\WINDOWS\system32\NeroCo.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7CE67716-5803-4FB7-B344-0C7A17F93B5D}]
2008-04-04 17:37 35840 --a------ C:\WINDOWS\system32\geBqQHYs.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:26 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2006-10-24 16:10 4662776]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-10 14:18 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-22 22:07 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-08-24 11:01 135168]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-08-24 11:01 159744]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-08-24 11:00 131072]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-02 02:52 3739648]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-12-06 14:13 202032]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-04-01 16:06 949376]
"nod32upd"="C:\Program Files\Eset\fc_upd.dll" [2008-04-01 16:12 3584]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-04-05 15:34:39 113664]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{7CE67716-5803-4FB7-B344-0C7A17F93B5D}"= C:\WINDOWS\system32\geBqQHYs.dll [2008-04-04 17:37 35840]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geBqQHYs]
geBqQHYs.dll 2008-04-04 17:37 35840 C:\WINDOWS\system32\geBqQHYs.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
--a------ 2007-05-10 22:46 624248 C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
--a------ 2005-02-08 16:38 159744 C:\Program Files\Apoint2K\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2008-02-28 17:07 1828136 C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-02-19 13:10 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2008-02-18 16:29 2221352 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2008-02-28 09:59 570664 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-31 23:13 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\BitLord\\BitLord.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
R2 XAudio;XAudio;C:\WINDOWS\system32\DRIVERS\xaudio.sys [2007-07-10 22:27]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-11 07:16:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-11 20:05:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\geBqQHYs.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\ESET\nod32krn.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-04-11 20:07:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-11 14:37:21
Pre-Run: 31,574,102,016 bytes free
Post-Run: 31,658,704,896 bytes free
hijack this log file...
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:13:30 PM, on 4/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7CE67716-5803-4FB7-B344-0C7A17F93B5D} - C:\WINDOWS\system32\geBqQHYs.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [nod32upd] rundll32 "C:\Program Files\Eset\fc_upd.dll",NOD32Ioctl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1207072857281O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO20 - Winlogon Notify: geBqQHYs - C:\WINDOWS\SYSTEM32\geBqQHYs.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\WINDOWS\system32\DRIVERS\xaudio.exe
--
End of file - 8301 bytes