Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:16:33 PM, on 6/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\PROGRA~1\MICROS~4\wcescomm.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijack This\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {B1A64443-6FCA-41CE-8D51-5F8991257555} - C:\WINDOWS\system32\vtUlKCvw.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~4\wcescomm.exe"
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (file missing)
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace....ploader1006.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace...ronGameHost.cab
O20 - Winlogon Notify: vtUlKCvw - C:\WINDOWS\SYSTEM32\vtUlKCvw.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
ComboFix 08-05-29.1 - Administrator 2008-05-30 19:39:33.2 - NTFSx86
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\inst.exe
C:\WINDOWS\x.exe
C:\WINDOWS\y.exe
.
---- Previous Run -------
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Program Files\AntiSpywareExpert
C:\Program Files\AntiSpywareExpert\ase.exe
C:\Program Files\webhancer
C:\Program Files\webhancer\Programs\license.txt
C:\Program Files\webhancer\Programs\readme.txt
C:\Program Files\webhancer\Programs\sporder.dll
C:\Program Files\webhancer\Programs\webhdll.dll
C:\Program Files\webhancer\Programs\whagent.exe
C:\Program Files\webhancer\Programs\whagent.ini
C:\Program Files\webhancer\Programs\whinstaller.exe
C:\setup.exe
C:\WINDOWS\BM3bdc1717.xml
C:\WINDOWS\default.htm
C:\WINDOWS\explore.exe
C:\WINDOWS\iexplorer.exe
C:\WINDOWS\lfn.exe
C:\WINDOWS\mainms.vpi
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\fledvbqf.dll
C:\WINDOWS\system32\kfroviqp.ini
C:\WINDOWS\system32\mpoerxcp.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\pqivorfk_old.dll
C:\WINDOWS\system32\qrpulpyu.dll
C:\WINDOWS\system32\tebjnpdo.dll
C:\WINDOWS\system32\xEgMnnmp.ini
C:\WINDOWS\system32\xEgMnnmp.ini2
C:\WINDOWS\system32\yvldkgit.ini
.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-30 )))))))))))))))))))))))))))))))
.
2008-05-29 19:23 . 2008-05-29 19:23 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-29 19:23 . 2008-05-29 19:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-29 19:23 . 2008-05-29 19:23 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-05-29 19:23 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-29 19:23 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-29 19:10 . 2008-05-29 19:10 17,664 --a------ C:\WINDOWS\funny.exe
2008-05-28 20:37 . 2008-05-28 20:37 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-28 20:33 . 2008-05-29 07:15 <DIR> d-------- C:\SDFix
2008-05-28 20:31 . 2008-05-28 20:31 <DIR> d-------- C:\Deckard
2008-05-27 20:33 . 2008-05-27 20:33 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-27 20:33 . 2008-05-27 20:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-27 20:31 . 2008-05-27 20:31 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-27 18:14 . 2008-05-30 19:30 <DIR> d-------- C:\Program Files\Hijack This
2008-05-24 17:29 . 2008-05-24 17:29 315,120 --a------ C:\WINDOWS\system32\pmnnMgEx_old.dll
2008-05-24 17:25 . 2008-05-29 05:09 <DIR> d-------- C:\Temp
2008-05-24 17:24 . 2008-05-24 17:24 26,384 --a------ C:\WINDOWS\system32\vtUlKCvw.dll
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\WINDOWS\system32\lsdelete.exe
2008-04-29 11:20 . 2008-04-29 11:20 15,648 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 11:19 . 2008-04-29 11:19 15,648 --a------ C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 11:19 . 2008-04-29 11:19 12,960 --a------ C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-27 14:51 . 2008-04-27 14:51 <DIR> d-------- C:\Program Files\iPod
2008-04-27 14:50 . 2008-04-27 14:51 <DIR> d-------- C:\Program Files\iTunes
2008-04-27 14:47 . 2008-04-27 14:48 <DIR> d-------- C:\Program Files\QuickTime
2008-04-20 09:23 . 2008-04-21 08:22 <DIR> d-------- C:\WINDOWS\system32\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-30 23:57 --------- d-----w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-05-30 23:12 1,311,232 ----a-w C:\WINDOWS\Internet Logs\rDB13.tmp
2008-05-30 07:20 1,317,888 ----a-w C:\WINDOWS\Internet Logs\rDB3.tmp
2008-05-28 20:18 1,309,696 ----a-w C:\WINDOWS\Internet Logs\rDB1F.tmp
2008-05-18 08:11 --------- d-----w C:\Program Files\Norton SystemWorks
2008-05-10 01:31 --------- d-----w C:\Program Files\3GP Player
2008-05-05 07:15 1,207,296 ----a-w C:\WINDOWS\Internet Logs\rDB1E.tmp
2008-04-27 22:17 --------- d-----w C:\Program Files\Java
2008-04-27 19:03 --------- d-----w C:\Program Files\Apple Software Update
2008-04-20 15:28 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Vso
2008-04-14 07:16 --------- d-----w C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-03-22 09:14 1,078,784 ----a-w C:\WINDOWS\Internet Logs\rDB1D.tmp
2008-03-15 03:32 1,071,104 ----a-w C:\WINDOWS\Internet Logs\rDB1C.tmp
2008-02-23 03:24 1,062,912 ----a-w C:\WINDOWS\Internet Logs\rDB1B.tmp
2008-02-09 15:45 1,065,472 ----a-w C:\WINDOWS\Internet Logs\rDB1A.tmp
2008-01-14 16:58 47,360 ----a-w C:\Documents and Settings\Administrator\Application Data\pcouffin.sys
2008-01-14 16:55 87,608 ----a-w C:\Documents and Settings\Administrator\Application Data\ezpinst.exe
2008-01-05 11:12 7,237,952 ----a-w C:\Documents and Settings\torrents\vsoConvertXtoDVD2_setup.exe
2007-10-22 22:08 79,856 ----a-w C:\Documents and Settings\torrents\MySpaceIM_Setup.exe
2007-09-17 16:01 612,152 ----a-w C:\Documents and Settings\torrents\DivoCodec-1.3.0.0-setup-0708.exe
2007-09-10 19:17 6,211,190 ----a-w C:\Documents and Settings\torrents\Combined-Community-Codec-Pack-2007-07-22.exe
2007-07-25 01:07 9,372,240 ----a-w C:\Program Files\DivXCreate.exe
2007-07-06 00:47 4,377,640 ----a-w C:\Documents and Settings\setup\LimeWireWin.exe
2007-02-03 16:37 6,576,504 ----a-w C:\Program Files\vsoConvertXtoDVD2_setup.exe
2007-02-03 16:35 7,744 ----a-w C:\Program Files\te.nfo
2007-02-03 16:35 413 ----a-w C:\Program Files\file_id.diz
2006-09-10 22:34 5,917,258 ----a-w C:\Program Files\powertab.zip
2006-02-11 13:35 13,312 ----a-w C:\Documents and Settings\Crack\ConvertXtoDVD2x_GOLDCrack.exe
2005-06-16 00:31 9,372,240 ----a-w C:\Program Files\DivXCreate.exe.BAK
2005-06-15 23:36 9,681 ----a-w C:\Program Files\ARTeam.nfo
2005-06-15 23:36 162 ----a-w C:\Program Files\ARTeam.sfv
2005-06-15 23:35 95,232 ----a-w C:\Program Files\DivX.Pro.v6.0.and.Converter.v1.0.patch.exe
2004-08-28 23:52 113 ----a-w C:\Documents and Settings\Downloaded\registration.reg
2004-08-28 23:48 544,768 ----a-w C:\Documents and Settings\Downloaded\Mp3Mate.exe
2007-12-16 01:44 32 --sha-w C:\WINDOWS\{0FC147B1-546D-4484-AEDD-0F73AECD56A3}.dat
2007-12-16 01:49 32 --sha-w C:\WINDOWS\{4EBAEA51-FB54-415A-AD03-4C9A669992B9}.dat
2007-12-16 01:46 32 --sha-w C:\WINDOWS\{5EF8D301-4AC0-48DD-B4EC-A363CD65563D}.dat
2007-12-16 01:48 32 --sha-w C:\WINDOWS\{6BE9F5BA-9041-44A0-962F-915B93D08C8F}.dat
2007-12-16 01:48 32 --sha-w C:\WINDOWS\{75F45582-67BC-41E1-8888-C125AE961041}.dat
2007-12-16 01:46 32 --sha-w C:\WINDOWS\{7D615075-59A4-4BE4-9CD0-3682664E3C39}.dat
2007-12-16 01:46 32 --sha-w C:\WINDOWS\{D6416FA0-D047-428B-B6DC-635F113FD320}.dat
2007-12-16 01:46 32 --sha-w C:\WINDOWS\system32\{1222392D-1E1B-4023-A322-40C0C03F45E7}.dat
2007-12-16 01:44 32 --sha-w C:\WINDOWS\system32\{4C6632E1-AF6C-41E6-8056-17FDAA01ECFF}.dat
2007-12-16 01:48 32 --sha-w C:\WINDOWS\system32\{6E9ED633-9F77-442F-98E6-50107A9115D4}.dat
2007-12-16 01:46 32 --sha-w C:\WINDOWS\system32\{BDFC48EB-D892-4154-B8FB-9EF3123D0A6C}.dat
2007-12-16 01:49 32 --sha-w C:\WINDOWS\system32\{C8EAE0FE-BFD2-4C1E-B3BF-1D08D17749E3}.dat
2007-12-16 01:48 32 --sha-w C:\WINDOWS\system32\{F69BC3B5-0F31-4484-A21C-64A89BE7C1E6}.dat
2007-12-16 01:46 32 --sha-w C:\WINDOWS\system32\{FBBBDEF1-6BA4-4255-98F0-4FDEC7A07D1F}.dat
.
((((((((((((((((((((((((((((( snapshot@2008-05-30_ 8.07.56.66 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-30 12:00:03 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-30 23:21:30 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B1A64443-6FCA-41CE-8D51-5F8991257555}]
2008-05-24 17:24 26384 --a------ C:\WINDOWS\system32\vtUlKCvw.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-07-24 21:45 171448]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-08 11:06 94208]
"H/PC Connection Agent"="C:\PROGRA~1\MICROS~4\wcescomm.exe" [2006-06-20 22:36 1207080]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-18 21:47 8720384]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 17:17 50736]
"Microsoft Windows Installer"="C:\Documents and Settings\Administrator\Application Data\Microsoft\dtsc\18852.exe" [2008-05-24 17:24 129024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-09-10 20:38 45056]
"ccRegVfy"="C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [2007-09-20 00:59 28672]
"GhostStartTrayApp"="C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe" [2008-05-27 20:23 94208]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 02:12 483328]
"CloneCDElbyCDFL"="C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" [2002-11-02 02:33 45056]
"CloneCDTray"="C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe" [2002-12-02 10:17 73728]
"NWEReboot"="" []
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2007-12-21 18:38 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"webHancer Agent"="C:\Program Files\webHancer\Programs\whagent.exe" [ ]
"combofix"="C:\WINDOWS\system32\CF25734.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-18 21:47 8720384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{B1A64443-6FCA-41CE-8D51-5F8991257555}"= C:\WINDOWS\system32\vtUlKCvw.dll [2008-05-24 17:24 26384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUlKCvw]
vtUlKCvw.dll 2008-05-24 17:24 26384 C:\WINDOWS\system32\vtUlKCvw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 ElbyVCD;ElbyVCD;C:\WINDOWS\system32\DRIVERS\ElbyVCD.sys [2002-11-28 06:43]
R0 pueqhkby;pueqhkby;C:\WINDOWS\system32\drivers\hgyxkfaw.dat []
R1 GhPciScan;GhostPciScanner;C:\Program Files\Norton SystemWorks\Norton Ghost\ghpciscan.sys [2002-08-14 16:11]
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2004-08-03 22:31]
R3 ess;ESS Audio Driver (WDM);C:\WINDOWS\system32\drivers\ess.sys [2001-08-17 12:19]
S3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\system32\DRIVERS\NtApm.sys [2001-08-17 09:47]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-20 13:49:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-30 04:00:01 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 13:00:06 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 14:05:20 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 15:00:07 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 16:00:05 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 17:00:18 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 18:00:23 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 19:00:10 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 20:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 21:00:02 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 22:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 05:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 23:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-31 00:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-31 01:00:01 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 02:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 03:00:01 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 06:00:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 07:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 08:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 09:00:01 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 10:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-30 11:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-29 12:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\0j6K3yvh.exe
"2008-05-31 00:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\NAVW32.exeG/task:C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\NORTON~1\Tasks\mycomp.sca
"2008-05-30 21:30:01 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
- C:\Program Files\Norton SystemWorks\OBC.exe
"2008-05-31 01:49:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-30 19:56:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\pueqhkby]
"ImagePath"="system32\drivers\hgyxkfaw.dat"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\vtUlKCvw.dll
.
Completion time: 2008-05-30 21:56:36
ComboFix-quarantined-files.txt 2008-05-31 01:53:07
Pre-Run: 28,967,522,304 bytes free
Post-Run: 28,935,499,776 bytes free
270