Heh my USB got infected while trying to transfer the files. Good thing USBs are easy to format.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:32:39 AM, on 9/14/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20861)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\Razer\Copperhead\razerhid.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Razer\Copperhead\razertra.exe
C:\Program Files\Razer\Copperhead\razerofa.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Maxthon2\Maxthon.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\bak\isuspm.exe" -startup
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.doginhispen.com
O15 - Trusted Zone: *.whataboutadog.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://photo.walgreens.com/WalgreensActivia.cabO16 - DPF: {7606693A-C18D-4567-AF85-6194FF70761E} (GomWeb Control) -
http://app.ipop.co.kr/gom/GomWeb.cabO23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 7291 bytes
ComboFix 08-09-13.05 - Stanley Chui 2008-09-14 11:18:56.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1587 [GMT -5:00]
Running from: C:\Documents and Settings\Stanley Chui\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\Temp\abW9
C:\Temp\fse
C:\WINDOWS\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
C:\WINDOWS\config\svchost.exe
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\jestertb.dll
C:\WINDOWS\system.exe
C:\WINDOWS\system32\aegxugnj.ini
C:\WINDOWS\system32\blphcpt3j0e38t.scr
C:\WINDOWS\system32\bwsggnsd.ini
C:\WINDOWS\system32\cffwirod.ini
C:\WINDOWS\system32\cqjrugew.ini
C:\WINDOWS\system32\cwkittua.ini
C:\WINDOWS\system32\diyfbngd.ini
C:\WINDOWS\system32\drivers\svchost.exe
C:\WINDOWS\system32\dvrbgpey.ini
C:\WINDOWS\system32\f10WtR
C:\WINDOWS\system32\fgkitbhm.ini
C:\WINDOWS\system32\fucnqmvy.ini
C:\WINDOWS\system32\fxnbsupa.ini
C:\WINDOWS\system32\gdtawoiu.ini
C:\WINDOWS\system32\gpdrunja.ini
C:\WINDOWS\system32\hptvtjwe.ini
C:\WINDOWS\system32\ijgnlysu.ini
C:\WINDOWS\system32\iraoohqi.ini
C:\WINDOWS\system32\jltiqxjf.ini
C:\WINDOWS\system32\liltedlq.ini
C:\WINDOWS\system32\lmsmpcug.ini
C:\WINDOWS\system32\lpbqrsim.ini
C:\WINDOWS\system32\lphcpt3j0e38t.exe
C:\WINDOWS\system32\lqchldan.ini
C:\WINDOWS\system32\lyljovwj.ini
C:\WINDOWS\system32\mbovxifu.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mvbkvnnn.ini
C:\WINDOWS\system32\mwfrjljm.ini
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\phcpt3j0e38t.bmp
C:\WINDOWS\system32\prmhxjii.ini
C:\WINDOWS\system32\qjrwablt.ini
C:\WINDOWS\system32\qlbuuvtf.ini
C:\WINDOWS\system32\qpfumdmj.ini
C:\WINDOWS\system32\rbmmmdid.ini
C:\WINDOWS\system32\rMa01yy
C:\WINDOWS\system32\rsknfthn.ini
C:\WINDOWS\system32\sqgtmygl.ini
C:\WINDOWS\system32\tdssadw.dll
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssl.dll
C:\WINDOWS\system32\tdsslog.dll
C:\WINDOWS\system32\tdssmain.dll
C:\WINDOWS\system32\tdsspopup.dll
C:\WINDOWS\system32\tdsspopup1.url
C:\WINDOWS\system32\tdsspopup2.url
C:\WINDOWS\system32\tdsspopup3.url
C:\WINDOWS\system32\tdssservers.dat
C:\WINDOWS\system32\tjppntay.ini
C:\WINDOWS\system32\ttitqeue.ini
C:\WINDOWS\system32\ujpssfvg.ini
C:\WINDOWS\system32\ujyppmon.ini
C:\WINDOWS\system32\utempxfd.ini
C:\WINDOWS\system32\vgqdyabr.tmp
C:\WINDOWS\system32\vgqdyabr.tmp2
C:\WINDOWS\system32\vihorvyr.ini
C:\WINDOWS\system32\vqtxxbht.ini
C:\WINDOWS\system32\vrgrgwic.ini
C:\WINDOWS\system32\wbpeskoc.ini
C:\WINDOWS\system32\wmjvapal.ini
C:\WINDOWS\system32\wpmmohcp.ini
C:\WINDOWS\system32\wyvjfcnr.ini
C:\WINDOWS\system32\xksowulp.ini
C:\WINDOWS\system32\xqegdiuy.ini
K:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DNSCACHEREADER
-------\Legacy_SYSREST.SYS
-------\Service_DNSCacheReader
-------\Service_sysrest.sys
((((((((((((((((((((((((( Files Created from 2008-08-14 to 2008-09-14 )))))))))))))))))))))))))))))))
.
2008-09-14 11:18 . 2008-04-13 19:12 146,432 --a------ C:\WINDOWS\system32\dllcache\regedit.exe
2008-09-14 11:18 . 2008-04-13 19:12 146,432 --a------ C:\WINDOWS\regedit.exe
2008-09-14 11:13 . 2008-09-14 11:13 160 --a------ C:\Documents and Settings\Stanley Chui\xrt_log.dat
2008-09-12 21:57 . 2008-09-14 11:25 <DIR> d-------- C:\Program Files\Steam
2008-09-11 23:06 . 2008-09-11 23:06 23,552 --a------ C:\WINDOWS\system32\sysrest32.exe
2008-09-11 23:06 . 2008-09-14 11:26 15,328 --a------ C:\WINDOWS\system32\sysrest.sys
2008-09-11 16:37 . 2008-09-11 16:37 <DIR> d-------- C:\Program Files\Lavasoft
2008-09-11 16:31 . 2008-09-11 16:31 2,608 --a------ C:\Autorun.PNF
2008-09-11 00:40 . 2008-09-11 00:40 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-11 00:10 . 2008-09-11 00:10 88,878 --a------ C:\WINDOWS\system32\casino3.ico
2008-09-11 00:10 . 2008-09-11 00:10 88,878 --a------ C:\WINDOWS\system32\casino2.ico
2008-09-11 00:09 . 2008-09-11 00:10 88,878 --a------ C:\WINDOWS\system32\casino1.ico
2008-09-10 23:49 . 2008-09-10 23:49 39,424 --a------ C:\Documents and Settings\Stanley Chui\xrt_wgjr.exe
2008-09-10 07:54 . 2008-09-10 07:54 <DIR> d--hs---- C:\Recycled
2008-09-09 17:09 . 2008-09-09 17:09 <DIR> d-------- C:\Program Files\Koei
2008-09-07 11:06 . 2008-09-11 16:34 <DIR> d-------- C:\Program Files\PeerGuardian2
2008-08-27 19:47 . 2008-09-11 00:32 <DIR> d-------- C:\Program Files\RivaTuner v2.09
2008-08-27 19:11 . 2008-08-15 23:22 453,152 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-08-27 19:11 . 2008-08-15 23:22 18,335 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-08-27 19:10 . 2008-08-27 19:10 <DIR> d-------- C:\NVIDIA
2008-08-27 18:20 . 2008-08-27 18:20 <DIR> d-------- C:\ETQW Tools
2008-08-27 16:03 . 2008-08-27 16:03 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-08-22 22:48 . 2008-08-22 22:48 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-22 22:48 . 2008-08-22 22:48 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-22 22:48 . 2008-08-22 22:48 <DIR> d-------- C:\WINDOWS\system32\bits
2008-08-22 22:48 . 2008-08-22 22:48 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-22 22:46 . 2008-08-22 22:46 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-22 22:36 . 2008-04-13 19:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-08-17 13:45 . 2008-08-23 15:12 <DIR> d-------- C:\cdcgames
2008-08-14 06:00 . 2008-04-11 14:04 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-14 16:12 --------- d-----w C:\Documents and Settings\Stanley Chui\Application Data\Xfire
2008-09-14 06:38 --------- d-----w C:\Program Files\Zoom Player
2008-09-14 05:37 --------- d-----w C:\Documents and Settings\Stanley Chui\Application Data\MxBoost
2008-09-13 15:48 138,784 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-09-13 03:16 --------- d-----w C:\Documents and Settings\Stanley Chui\Application Data\Azureus
2008-09-13 03:15 --------- d-----w C:\Program Files\Azureus
2008-09-11 21:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-11 21:37 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-11 21:36 --------- d-----w C:\Program Files\InstallShield Installation Information
2008-09-11 21:35 --------- d-----w C:\Documents and Settings\Stanley Chui\Application Data\SSH
2008-09-11 21:33 --------- d-----w C:\Program Files\Java
2008-09-11 21:31 --------- d-----w C:\Program Files\ATITool
2008-09-11 05:10 --------- d-----w C:\Program Files\Maxthon2
2008-09-10 22:14 --------- d-----w C:\Program Files\Xfire
2008-09-09 15:02 --------- d-----w C:\Program Files\Winamp
2008-09-09 15:02 --------- d-----w C:\Program Files\SuperMarisaWorld
2008-09-09 15:02 --------- d-----w C:\Program Files\mIRC
2008-09-09 15:01 --------- d-----w C:\Program Files\Maxthon
2008-09-09 15:01 --------- d-----w C:\Program Files\id Software
2008-09-09 15:01 --------- d-----w C:\Program Files\Google
2008-09-09 15:01 --------- d-----w C:\Program Files\DivX
2008-09-09 15:01 --------- d-----w C:\Program Files\Dell
2008-09-09 15:01 --------- d-----w C:\Program Files\DAP
2008-09-09 15:01 --------- d-----w C:\Program Files\Common Files\aolshare
2008-09-09 15:01 --------- d-----w C:\Program Files\Ahead
2008-08-16 04:22 6,121,504 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-07-30 16:04 --------- d-----w C:\Program Files\DAEMON Tools Pro
2008-07-28 01:02 --------- d-----w C:\Program Files\SEGA
2008-05-22 18:04 22,328 ----a-w C:\Documents and Settings\Stanley Chui\Application Data\PnkBstrK.sys
2008-02-22 08:14 49,504 ----a-w C:\Documents and Settings\Stanley Chui\Application Data\GDIPFONTCACHEV1.DAT
2006-08-10 16:37 1 ----a-w C:\Documents and Settings\Stanley Chui\SI.bin
2006-05-25 22:39 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.
------- Sigcheck -------
2004-08-10 06:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2008-04-13 19:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-09-10 23:49 507904 3969440ba384d35317dbbdeeaae641ce C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 50528]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Steam"="C:\Program Files\Steam\Steam.exe" [2008-09-12 1271032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\bak\isuspm.exe" [2005-06-10 249856]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2008-01-22 81920]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-10-11 62760]
"BDRegion"="C:\Program Files\Cyberlink\Shared Files\brs.exe" [2008-05-20 91432]
"razer"="C:\Program Files\Razer\Copperhead\razerhid.exe" [2005-10-08 155648]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-08-15 13570048]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-08-15 86016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 C:\WINDOWS\stsystra.exe]
"nwiz"="nwiz.exe" [2008-08-15 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 15360]
C:\Documents and Settings\Stanley Chui\Start Menu\Programs\Startup\
Xfire.lnk - C:\Program Files\Xfire\xfire.exe [2008-08-27 3068752]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\ff_vfw.dll
"vidc.wmv3"= C:\PROGRA~1\COMBIN~1\Filters\wmv9vcm.dll
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\
000.fcl [2008-01-30 12:28 41456]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 24592]
R3 Razerlow;Razer Copperhead Driver;C:\WINDOWS\system32\Drivers\Razerlow.sys [2005-08-12 19020]
R3 sysrest.sys;sysrest.sys;C:\WINDOWS\system32\sysrest.sys [2008-09-14 15328]
S3 jfdcd;jfdcd;C:\DOCUME~1\STANLE~1\LOCALS~1\Temp\jfdcd.sys [ ]
S3 XDva011;XDva011;C:\WINDOWS\system32\XDva011.sys [ ]
S3 XDva037;XDva037;C:\WINDOWS\system32\XDva037.sys [ ]
S3 XDva119;XDva119;C:\WINDOWS\system32\XDva119.sys [ ]
S3 XDva121;XDva121;C:\WINDOWS\system32\XDva121.sys [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{59491970-c43f-11dc-a5db-00123f7e2962}]
\Shell\AutoRun\command - wd_windows_tools\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e7d0e526-eab2-11da-a3da-00123f7e2962}]
\Shell\AutoRun\command - H:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e8135166-7afa-11da-a341-00123f7e2962}]
\Shell\AutoRun\command - G:\AutoPlay.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ee6b8207-38b5-11dc-a596-00123f7e2962}]
\Shell\AutoRun\command - wd_windows_tools\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8df5c6a-749a-11dd-9602-00123f7e2962}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
*Newly Created Service* - SYSREST.SYS
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-MsnMsgr - C:\Program Files\MSN Messenger\MsnMsgr.Exe
HKCU-Run-Uniblue RegistryBooster 2 - C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
HKLM-Run-QuickTime Task - C:\Program Files\QuickTime\bak\qttask.exe
HKLM-Run-RivaTunerStartupDaemon - C:\Program Files\RivaTuner v2.09\RivaTuner.exe
HKLM-Run-lphcpt3j0e38t - C:\WINDOWS\system32\lphcpt3j0e38t.exe
HKLM-Run-inrhctt3j0e38t - C:\Documents and Settings\Stanley Chui\Local Settings\Temp\.ttCE.tmp.exe
HKLM-Run-sysrest32.exe - C:\WINDOWS\system32\sysrest32.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Stanley Chui\Application Data\Mozilla\Firefox\Profiles\b95007o1.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - about:blank
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npracplug.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npunagi2.dll
FF -: plugin - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-14 11:26:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\
000.fcl"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Razer\Copperhead\razertra.exe
C:\Program Files\Razer\Copperhead\razerofa.exe
C:\WINDOWS\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-09-14 11:31:57 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-14 16:31:52
Pre-Run: 16,862,334,976 bytes free
Post-Run: 20,236,263,424 bytes free
291 --- E O F --- 2008-09-10 06:36:19