I dont know how this works, but if anyone can help me I will be extremely grateful!
It started with a lot of popups asking me to install different anti virus programs. When I restarted the screen first turned in to the Windows 'green field' wallpaper, after that it said 'starting windows' as normal. But nothing was normal... Icons gone or changed, explorer starting and stopping all the time, task manager 'disabled by administrator' etc. And the file structure was messed up. I have managed to fix some things, but far from all. I have run HiJackThis and ComboFix and give you the logs here.
Can anyone help me? I have a lot of my research on this computer, and some things are not backed up so I curse myself ......
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:46: VIRUS ALERT!, on 2008-07-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program\Intel\Wireless\Bin\S24EvMon.exe
C:\Program\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program\AVG\AVG8\avgwdsvc.exe
C:\Program\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program\Dell\QuickSet\QuickSet.exe
C:\Program\Apoint\Apoint.exe
C:\Program\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\Notepad++\notepad++.exe
C:\Program\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Windows Live\Messenger\MsnMsgr.Exe
C:\Program\I8kfanGUI\I8kfanGUI.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\AVG\AVG8\avgrsx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarerefer...=...6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O3 - Toolbar: sqvgnrpx - {DB62CC01-ECD2-492E-BCE6-57B0AD8A8D59} - C:\WINDOWS\sqvgnrpx.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program\AVG\AVG8\avgtoolbar.dll
O4 - HKLM\..\Run: [IntelWireless] C:\Program\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [Apoint] C:\Program\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program\Delade filer\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program\Delade filer\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISTray] "C:\Program\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\Program\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [i8kfangui] C:\Program\I8kfanGUI\I8kfanGUI.exe /startup
O4 - HKCU\..\Run: [WinSpywareProtect] "C:\Documents and Settings\All Users.WINDOWS\Application Data\ADSL Software Ltd\WinSpywareProtect\winspywareprotect.exe" /autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe (file missing)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.euro....iler/SysPro.CAB
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....031/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail....es/MSNPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.co.../sysreqlab2.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius....tiveXPlugin.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.on...e/en/crlocx.ocx
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative....15034/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\DELADE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O21 - SSODL: fsrpknov - {B4292AB3-0B2A-4EA6-8F9C-A2EF4E757828} - C:\WINDOWS\fsrpknov.dll
O21 - SSODL: fdxbameg - {724BBE22-BB2B-49AF-9C9A-AC52821E44AE} - C:\WINDOWS\fdxbameg.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\Program\AVG\AVG8\avgwdsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program\Spyware Doctor\pctsSvc.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
--
End of file - 8653 bytes
----------------------------------------------------------------
ComboFix 08-07-09.5 - Patrik 2008-07-11 8:24:51.2 - NTFSx86
Running from: C:\Documents and Settings\Patrik\Skrivbord\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\Patrik\Favoriter\Error Cleaner.url
C:\Documents and Settings\Patrik\Favoriter\Privacy Protector.url
C:\Documents and Settings\Patrik\Favoriter\Spyware&Malware Protection.url
C:\Documents and Settings\Patrik\Skrivbord\Error Cleaner.url
C:\Documents and Settings\Patrik\Skrivbord\Privacy Protector.url
C:\Documents and Settings\Patrik\Skrivbord\Spyware&Malware Protection.url
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\enxw.exe
C:\WINDOWS\fdxbameg.dll
C:\WINDOWS\fsrpknov.dll
C:\WINDOWS\gpefaowr.exe
C:\WINDOWS\system32\bund1
C:\WINDOWS\system32\hRBHjkkj.ini
C:\WINDOWS\system32\hRBHjkkj.ini2
.
((((((((((((((((((((((((( Files Created from 2008-06-11 to 2008-07-11 )))))))))))))))))))))))))))))))
.
2008-07-09 23:36 . 2008-07-11 08:13 <KAT> d--h----- C:\$AVG8.VAULT$
2008-07-09 23:14 . 2008-07-09 23:14 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-09 23:14 . 2008-07-09 23:14 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-09 23:13 . 2008-07-09 23:18 <KAT> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-09 23:13 . 2008-07-09 23:13 <KAT> d-------- C:\Program\AVG
2008-07-09 23:13 . 2008-07-09 23:13 <KAT> d-------- C:\Documents and Settings\Patrik\Application Data\AVGTOOLBAR
2008-07-09 22:50 . 2008-07-09 22:52 <KAT> d-------- C:\Documents and Settings\Patrik\.housecall6.6
2008-07-09 21:09 . 2008-07-09 21:09 <KAT> d-------- C:\Documents and Settings\LocalService.NT INSTANS\Application Data\TmpRecentIcons
2008-07-09 21:09 . 2008-07-09 21:09 <KAT> d-------- C:\Documents and Settings\LocalService.NT INSTANS\Application Data\Intel
2008-07-09 21:08 . 2008-07-09 21:08 <KAT> d-------- C:\Documents and Settings\LocalService.NT INSTANS\Start-meny
2008-07-09 21:08 . 2008-07-09 21:08 <KAT> d-------- C:\Documents and Settings\LocalService.NT INSTANS\Skrivbord
2008-07-09 21:08 . 2008-07-09 21:08 <KAT> dr------- C:\Documents and Settings\LocalService.NT INSTANS\Mina dokument
2008-07-09 21:08 . 2008-07-09 22:14 <KAT> dr------- C:\Documents and Settings\LocalService.NT INSTANS\Favoriter
2008-07-09 20:57 . 2008-07-09 20:57 318,208 --------- C:\WINDOWS\system32\jkkjHBRh.dll
2008-07-09 20:51 . 2008-07-09 20:51 29,568 --a------ C:\WINDOWS\system32\khfCttQk.dll
2008-07-09 20:51 . 2008-07-09 20:51 29,568 --a------ C:\WINDOWS\system32\geBtutuT.dll
2008-07-09 20:50 . 2008-07-09 20:50 <KAT> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\ADSL Software Ltd
2008-07-09 20:50 . 2008-07-09 14:09 352,256 --a------ C:\WINDOWS\wbxdpgfedxa.dll
2008-07-09 14:11 . 2008-07-09 14:11 <KAT> d-------- C:\Documents and Settings\Patrik\Application Data\iShell
2008-07-09 11:26 . 2003-07-12 02:21 274,432 --a------ C:\WINDOWS\GSpot.exe
2008-07-09 11:26 . 2003-07-12 02:19 64,777 --a------ C:\WINDOWS\GSpot221.dat
2008-07-09 11:26 . 2001-10-30 08:10 11,264 --a------ C:\WINDOWS\msdmo.dll
2008-07-08 14:09 . 2008-07-08 14:09 <KAT> d-------- C:\WINDOWS\Microsoft.VC80.ATL
2008-07-08 14:09 . 2008-02-04 10:54 94,208 --a------ C:\WINDOWS\FunambolAddin.dll
2008-07-07 13:32 . 2008-07-09 13:31 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-07 13:32 . 2008-07-07 13:32 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-07 13:28 . 2008-07-10 22:35 63,783 --a------ C:\WINDOWS\system32\nvwsapps.xml
2008-07-07 13:27 . 2006-03-23 01:30 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-07-06 17:34 . 2008-07-06 17:36 <KAT> d-------- C:\Program\HyCam2
2008-07-05 21:42 . 2008-06-15 12:24 31,232 --a------ C:\WINDOWS\system\vdremote.dll
2008-07-05 21:42 . 2008-06-15 12:23 25,088 --a------ C:\WINDOWS\system\vdsvrlnk.dll
2008-07-05 18:10 . 2008-07-05 18:10 <KAT> d-------- C:\Documents and Settings\Patrik\Application Data\Agency9
2008-06-28 09:34 . 2008-07-09 23:13 <KAT> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avg8
2008-06-21 20:21 . 2008-06-21 20:21 <KAT> d-------- C:\Documents and Settings\Patrik\Application Data\PCF-VLC
2008-06-21 20:15 . 2008-06-21 20:15 <KAT> d-------- C:\Documents and Settings\Patrik\Application Data\Participatory Culture Foundation
2008-06-21 20:13 . 2008-06-21 20:13 <KAT> d-------- C:\Program\Participatory Culture Foundation
2008-06-19 22:18 . 2008-06-19 22:20 <KAT> d-------- C:\Foto
2008-06-19 15:23 . 2008-06-19 15:23 <KAT> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Tools
2008-06-19 15:23 . 2008-06-16 00:11 159,880 --a------ C:\WINDOWS\system32\drivers\pctfw2.sys
2008-06-13 01:19 . 2007-04-09 13:23 28,040 --a------ C:\WINDOWS\system32\mdimon.dll
2008-06-12 22:29 . 2008-06-12 22:29 <KAT> d-------- C:\Documents and Settings\Patrik\Application Data\Sibelius Software
2008-06-12 22:28 . 2008-06-12 22:28 <KAT> d-------- C:\Program\Sibelius Software
2008-06-11 12:08 . 2008-06-11 12:08 <KAT> d-------- C:\Program\Neurobehavioral Systems
2008-06-11 12:08 . 2008-06-11 12:08 33,820 --a------ C:\WINDOWS\system32\drivers\OldUsbkey.sys
2008-06-11 12:07 . 2008-06-11 12:07 <KAT> d-------- C:\Program\Delade filer\Wise Installation Wizard
2008-06-11 09:56 . 2008-06-14 20:01 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 09:56 . 2008-06-14 20:01 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-10 21:31 --------- d---a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-07-10 21:30 --------- d-----w C:\Program\Spyware Doctor
2008-07-10 19:02 --------- d-----w C:\Documents and Settings\Patrik\Application Data\EndNote
2008-07-09 18:48 --------- d-----w C:\Documents and Settings\Patrik\Application Data\uTorrent
2008-07-09 08:49 --------- d-----w C:\Documents and Settings\Patrik\Application Data\dvdcss
2008-07-07 12:54 --------- d-----w C:\Documents and Settings\Patrik\Application Data\gtk-2.0
2008-07-06 13:59 --------- d-----w C:\Documents and Settings\Patrik\Application Data\DivX
2008-07-06 13:54 1,080 ----a-w C:\Program\up_down(360).txt
2008-07-05 19:36 --------- d--h--w C:\Program\InstallShield Installation Information
2008-06-28 09:57 --------- d-----w C:\Documents and Settings\Patrik\Application Data\Skype
2008-06-28 09:56 --------- d-----w C:\Documents and Settings\Patrik\Application Data\skypePM
2008-06-19 20:39 --------- d-----w C:\Documents and Settings\Patrik\Application Data\WinEdt
2008-06-19 13:23 --------- d-----w C:\Program\Delade filer\PC Tools
2008-06-13 09:28 --------- d-----w C:\Program\Delade filer\Risxtd
2008-06-11 12:37 --------- d-----w C:\Program\DivX
2008-06-11 10:08 86,016 ----a-w C:\WINDOWS\system32\KL2DLL32.DLL
2008-06-11 10:08 8,968 ----a-w C:\WINDOWS\system32\KL2DLL.DLL
2008-06-11 10:08 7,440 ----a-w C:\WINDOWS\system32\ppmon.dll
2008-06-11 10:08 24,136 ----a-w C:\WINDOWS\system32\ppmon.exe
2008-06-11 10:08 126,976 ----a-w C:\WINDOWS\system32\NWKL2_32.DLL
2008-06-11 10:08 12,480 ----a-w C:\WINDOWS\system32\KL2N.DLL
2008-05-30 23:22 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-05-30 23:22 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-05-30 23:22 815,104 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-05-30 23:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\DivX.dll
2008-05-30 23:22 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-05-30 23:22 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-05-30 23:22 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-05-30 23:22 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-05-30 23:22 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-05-30 23:22 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-05-22 22:22 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-05-22 22:22 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-05-22 22:22 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-05-22 22:22 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-05-22 22:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:22 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-05-22 22:22 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2008-05-22 22:22 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2008-05-22 22:20 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-05-22 22:20 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-05-22 22:19 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-05-22 22:19 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-05-22 22:19 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-22 22:18 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-17 02:54 15,045 ----a-w C:\WINDOWS\E220AutoRunLog.tmp
2008-05-13 11:39 --------- d-----w C:\Documents and Settings\Patrik\Application Data\IObit
2008-05-13 11:33 --------- d-----w C:\Program\IObit
2008-05-07 22:49 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-05-07 22:49 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-05-07 05:16 1,289,728 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-26 01:14 3,118,860 ----a-w C:\Program\01 - Scuttle Buttin' [#].mp3
2008-04-23 04:22 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-22 13:01 32 ----a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\ezsid.dat
2004-12-13 20:19 13,312 ----a-w C:\Program\toclip.exe
2008-04-25 12:32 5,817,064 ----a-w C:\Program\mozilla firefox\plugins\ScorchPDFWrapper.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{684BFE7F-F5B2-4AB3-A95E-EB5036A2D286}]
2008-07-09 20:51 29568 --a------ C:\WINDOWS\system32\khfCttQk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{73DAB7FA-86EB-4E15-824C-6186FE450F72}]
2008-07-09 20:57 318208 --------- C:\WINDOWS\system32\jkkjHBRh.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{874EA085-3B7B-412B-91AE-7291A94978D0}]
2008-07-09 14:09 352256 --a------ C:\WINDOWS\wbxdpgfedxa.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{DB62CC01-ECD2-492E-BCE6-57B0AD8A8D59}"= "C:\WINDOWS\sqvgnrpx.dll" [BU]
[HKEY_CLASSES_ROOT\clsid\{db62cc01-ecd2-492e-bce6-57b0ad8a8d59}]
[HKEY_CLASSES_ROOT\sqvgnrpx.1]
[HKEY_CLASSES_ROOT\TypeLib\{ABBAFC19-C497-4EC0-9A4D-E19C6C5CF8A3}]
[HKEY_CLASSES_ROOT\sqvgnrpx]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"MsnMsgr"="C:\Program\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 12:35 5724184]
"i8kfangui"="C:\Program\I8kfanGUI\I8kfanGUI.exe" [2007-02-16 18:58 856064]
"WinSpywareProtect"="C:\Documents and Settings\All Users.WINDOWS\Application Data\ADSL Software Ltd\WinSpywareProtect\winspywareprotect.exe" [2008-07-09 20:51 1241600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [X]
"IntelWireless"="C:\Program\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 14:59 385024]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-22 23:32 7561216]
"Dell QuickSet"="C:\Program\Dell\QuickSet\QuickSet.exe" [2006-06-29 13:13 1032192]
"Apoint"="C:\Program\Apoint\Apoint.exe" [2004-09-13 11:33 155648]
"SunJavaUpdateSched"="C:\Program\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"ISUSPM Startup"="C:\Program\Delade filer\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 16:30 249856]
"ISUSScheduler"="C:\Program\Delade filer\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920]
"QuickTime Task"="C:\Program\QuickTime\qttask.exe" [2007-06-29 06:24 286720]
"AVG8_TRAY"="C:\Program\AVG\AVG8\avgtray.exe" [2008-07-09 23:13 1232152]
"nwiz"="nwiz.exe" [2006-03-22 23:32 1519616 C:\WINDOWS\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2006-03-22 23:32 73728 C:\WINDOWS\system32\nvhotkey.dll]
"NvMediaCenter"="NvMCTray.dll" [2006-03-22 23:32 86016 C:\WINDOWS\system32\nvmctray.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispCPL"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{684BFE7F-F5B2-4AB3-A95E-EB5036A2D286}"= "C:\WINDOWS\system32\khfCttQk.dll" [2008-07-09 20:51 29568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"fsrpknov"= {B4292AB3-0B2A-4EA6-8F9C-A2EF4E757828} - C:\WINDOWS\fsrpknov.dll [BU]
"fdxbameg"= {724BBE22-BB2B-49AF-9C9A-AC52821E44AE} - C:\WINDOWS\fdxbameg.dll [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 16:08 110592 C:\Program\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khfCttQk]
2008-07-09 20:51 29568 C:\WINDOWS\system32\khfCttQk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"Midi1"= sfvmr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
--a------ 2008-07-09 23:13 1232152 C:\Program\AVG\AVG8\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX3800 Series]
--a------ 2005-02-08 06:00 98304 C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIACE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program\Delade filer\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 06:24 286720 C:\Program\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"NMIndexingService"=3 (0x3)
"NBService"=3 (0x3)
"sdCoreService"=3 (0x3)
"sdAuxService"=2 (0x2)
"avg8wd"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program\\uTorrent\\utorrent.exe"=
"C:\\Program\\Mozilla Firefox\\firefox.exe"=
"C:\\Program\\VideoLAN\\VLC\\vlc.exe"=
"C:\\Program\\Internet Explorer\\iexplore.exe"=
"C:\\Program\\Bonjour\\mDNSResponder.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program\\MATLAB\\R2007b\\bin\\win32\\MATLAB.exe"=
"C:\\Program\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Project\\Cpp\\Sound Feedback\\UDP\\server\\Debug\\server.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program\\Participatory Culture Foundation\\Miro\\xulrunner\\python\\Miro_Downloader.exe"=
"C:\\Program\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"46672:TCP"= 46672:TCP:uTorrent
"46678:TCP"= 46678:TCP:utorrent
"27015:UDP"= 27015:UDP:eget program
"1024:UDP"= 1024:UDP:eget program 2
"33515:TCP"= 33515:TCP:Windows Update Service Helper
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-09 23:14]
R1 fanio;FanIO driver;C:\WINDOWS\system32\drivers\fanio.sys [2007-02-16 11:05]
R1 pctfw2;pctfw2;C:\WINDOWS\system32\drivers\pctfw2.sys [2008-06-16 00:11]
R1 sfvmr;sfvmr;C:\WINDOWS\system32\drivers\sfvmr.SYS [1998-06-30 14:28]
R2 avg8wd;AVG Free8 WatchDog;C:\Program\AVG\AVG8\avgwdsvc.exe [2008-07-09 23:13]
R2 NBSPortDriver;NBSPortDriver;C:\WINDOWS\system32\DRIVERS\NBSPortDriver.sys [2007-05-21 10:48]
R2 P1090CDI;Camera Driver Interface Service;C:\WINDOWS\system32\DRIVERS\P1090Cdi.sys [2002-09-16 02:00]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2006-04-06 16:49]
S3 BCMTPM;BCMTPM;C:\WINDOWS\system32\DRIVERS\btpmw32.sys [2004-08-13 13:52]
S3 N;N;C:\Program\NewTech Infosystems\NTI Ripper\DJ\ []
S3 P1090VID;Creative WebCam Mobile;C:\WINDOWS\system32\DRIVERS\P1090Vid.sys [2002-10-10 02:00]
S4 msvsmon90;Visual Studio 2008 Remote Debugger;C:\Program\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2007-11-07 09:58]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5455f274-1fb9-11dd-b39d-0012f0a1e4ff}]
\Shell\AutoRun\command - E:\AutoRun.exe
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-CloneCDTray - C:\Program\SlySoft\CloneCD\CloneCDTray.exe
MSConfigStartUp-HUAWEI E620 Data Card - C:\Program\Kanguru\Kanguru.exe
MSConfigStartUp-SDTray - C:\Program\Spyware Doctor\SDTrayApp.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-11 09:02:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\N]
"ImagePath"="\??\C:\Program\NewTech Infosystems\NTI Ripper\DJ\"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\khfCttQk.dll
.
Completion time: 2008-07-11 9:12:47
ComboFix-quarantined-files.txt 2008-07-11 07:09:30
Pre-Run: 11,529,027,584 byte ledigt
Post-Run: 11,517,079,552 byte ledigt
270 --- E O F --- 2008-06-22 11:02:39
Thanks!!!!!!!!!
Patrik