SDFix: Version 1.159
Run by Administrator on Thu 03/20/2008 at 01:40 AM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\ADMINI~1\Desktop\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\Program Files\Setup.exe - Deleted
C:\WINDOWS\rs.txt - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-20 01:43:18
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:31,2b,8f,21,77,ce,4d,e5,e8,4c,b6,80,20,a9,b2,d5,92,21,b4,4a,57,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,f6,71,30,db,1f,91,19,42,22,cd,05,34,a6,8a,4d,a5,f8,..
"khjeh"=hex:76,62,9b,72,d1,3f,d7,69,81,fd,68,8a,f0,48,b3,b8,9c,93,9c,5e,ab,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:9b,1b,df,5c,21,9f,75,0a,61,61,e7,ee,0f,09,dc,ac,e6,46,8a,ac,1a,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:31,2b,8f,21,77,ce,4d,e5,e8,4c,b6,80,20,a9,b2,d5,92,21,b4,4a,57,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,f6,71,30,db,1f,91,19,42,22,cd,05,34,a6,8a,4d,a5,f8,..
"khjeh"=hex:76,62,9b,72,d1,3f,d7,69,81,fd,68,8a,f0,48,b3,b8,9c,93,9c,5e,ab,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:9b,1b,df,5c,21,9f,75,0a,61,61,e7,ee,0f,09,dc,ac,e6,46,8a,ac,1a,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\\24\xe1\21]
"DisplayName"="\x3720\x21b\x3720\x21b\1"
"DeviceDesc"="\x3720\x21b\x3720\x21b\1"
"ProviderName"="\xfed4\21\xee18\x7c90\xff44\21\b"
"MFG"="\x620"
"ReinstallString"="C:\WINDOWS\System32\ReinstallBackups\\xe114\21\x80\xc010\DriverFiles\.INF"
"DeviceInstanceIds"=str(7):"d:\i386\apps\app16164\sbdrv\smbus\smbusati.inf"
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\FrostWire\\FrostWire.exe"="C:\\Program Files\\FrostWire\\FrostWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\BitTyrant\\Azureus.exe"="C:\\Program Files\\BitTyrant\\Azureus.exe:*:Enabled:Azureus"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
Remaining Files :
File Backups: - C:\DOCUME~1\ADMINI~1\Desktop\SDFix\backups\backups.zip
Files with Hidden Attributes :
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Fri 14 Mar 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Finished!
ComboFix 08-03-18.1 - Owner 2008-03-20 1:49:15.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.110 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\autorun.inf
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-02-20 to 2008-03-20 )))))))))))))))))))))))))))))))
.
2008-03-20 01:39 . 2008-03-20 01:39 <DIR> d-------- C:\WINDOWS\ERUNT
2008-03-19 02:03 . 2008-03-19 02:06 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-03-19 02:03 . 2008-03-19 02:10 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-19 00:16 . 2008-03-19 00:16 <DIR> d-------- C:\Program Files\Universal
2008-03-18 23:58 . 2008-03-19 00:19 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-03-18 23:58 . 2008-03-19 00:19 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-03-18 23:58 . 2008-03-19 00:19 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-03-18 23:45 . 2008-03-18 23:45 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-03-18 23:42 . 2005-03-23 22:22 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-03-18 23:42 . 2008-02-23 01:15 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2008-03-18 23:42 . 2008-02-23 01:15 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\McAfee
2008-03-18 23:37 . 2008-03-18 23:37 <DIR> d-------- C:\Program Files\Advanced Windows Cleaner
2008-03-18 11:29 . 2008-03-18 11:29 <DIR> d-------- C:\Deckard
2008-03-18 09:59 . 2008-03-19 00:00 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-03-18 09:28 . 2008-03-18 09:28 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-17 16:04 . 2008-03-20 01:23 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-17 16:04 . 2008-03-20 01:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-17 04:20 . 2008-03-16 23:18 204,800 --------- C:\WINDOWS\etlrlws.dll_old
2008-03-14 22:23 . 2008-03-14 22:23 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\vlc
2008-03-14 19:42 . 2008-03-18 23:38 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-03-14 19:35 . 2008-03-14 19:35 <DIR> d-------- C:\Program Files\VideoLAN
2008-03-14 19:21 . 2008-03-18 23:38 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-03-14 18:20 . 2008-03-14 18:20 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\CyberLink
2008-03-14 18:17 . 2008-03-14 18:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-03-09 17:05 . 2008-03-19 02:09 1,065 --a------ C:\WINDOWS\winamp.ini
2008-03-09 17:04 . 2008-03-09 17:07 <DIR> d-------- C:\Program Files\Winamp
2008-03-08 17:59 . 2008-03-08 17:59 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\AccurateRip
2008-03-08 17:59 . 2008-03-08 17:58 4,230,520 --a------ C:\WINDOWS\system32\SpoonUninstall.exe
2008-03-08 17:59 . 2008-03-08 17:58 33,846 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.bmp
2008-03-08 17:59 . 2008-03-08 17:59 12,896 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2008-03-08 17:58 . 2008-03-08 17:58 <DIR> d-------- C:\Program Files\Illustrate
2008-03-08 16:59 . 2006-11-30 20:50 638,976 --a------ C:\Program Files\coolplayer.exe
2008-03-08 06:24 . 2008-03-08 06:24 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Grisoft
2008-03-08 06:23 . 2008-03-18 23:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-08 06:23 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-08 06:22 . 2007-06-14 18:38 12,413,440 --a------ C:\Program Files\avgas-setup-7.5.1.43.exe
2008-03-05 03:44 . 2008-03-08 17:19 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\BitTyrant
2008-03-05 03:41 . 2008-03-08 17:19 <DIR> d-------- C:\Program Files\BitTyrant
2008-03-04 16:09 . 2008-03-04 16:09 <DIR> d-------- C:\Program Files\NCH Software
2008-03-01 23:47 . 2008-03-01 23:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-03-01 23:45 . 2008-03-08 16:42 <DIR> d-------- C:\Program Files\NCH Swift Sound
2008-03-01 23:45 . 2008-03-01 23:45 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\NCH Swift Sound
2008-03-01 22:40 . 2008-03-01 22:40 <DIR> d-------- C:\Program Files\Maxis
2008-03-01 22:31 . 2003-08-28 10:27 122,372,241 --a------ C:\Program Files\Sound.dat
2008-03-01 22:30 . 2003-08-28 10:27 115,072,687 --a------ C:\Program Files\SimCity_3.dat
2008-03-01 22:29 . 2008-03-01 22:29 <DIR> d-------- C:\Program Files\UKEnglsh
2008-03-01 22:29 . 2008-03-01 22:29 <DIR> d-------- C:\Program Files\Swedish
2008-03-01 22:29 . 2008-03-01 22:29 <DIR> d-------- C:\Program Files\Support
2008-03-01 22:29 . 2008-03-01 22:29 <DIR> d-------- C:\Program Files\Spanish
2008-03-01 22:29 . 2008-03-01 22:34 <DIR> d-------- C:\Program Files\Sku_Data
2008-03-01 22:29 . 2008-03-01 22:33 <DIR> d-------- C:\Program Files\Regions
2008-03-01 22:29 . 2008-03-01 22:29 <DIR> d-------- C:\Program Files\ReadMe
2008-03-01 22:29 . 2008-03-01 22:30 <DIR> d-------- C:\Program Files\Radio
2008-03-01 22:29 . 2008-03-01 22:29 <DIR> d-------- C:\Program Files\Portgese
2008-03-01 22:29 . 2008-03-01 22:29 <DIR> d-------- C:\Program Files\Polish
2008-03-01 22:29 . 2008-03-01 22:29 <DIR> d-------- C:\Program Files\Plugins
2008-03-01 22:29 . 2008-03-01 22:29 <DIR> d-------- C:\Program Files\Norwgian
2008-03-01 22:29 . 2008-03-01 22:29 <DIR> d-------- C:\Program Files\Italian
2008-03-01 22:29 . 2008-03-18 09:11 <DIR> d-------- C:\Program Files\autorun
2008-03-01 22:28 . 2008-03-01 22:28 <DIR> d-------- C:\Program Files\German
2008-03-01 22:28 . 2008-03-01 22:28 <DIR> d-------- C:\Program Files\French
2008-03-01 22:28 . 2008-03-01 22:28 <DIR> d-------- C:\Program Files\Fonts
2008-03-01 22:28 . 2008-03-01 22:28 <DIR> d-------- C:\Program Files\Finnish
2008-03-01 22:28 . 2008-03-01 22:28 <DIR> d-------- C:\Program Files\Dutch
2008-03-01 22:28 . 2008-03-01 22:28 <DIR> d-------- C:\Program Files\DirectX
2008-03-01 22:28 . 2008-03-01 22:28 <DIR> d-------- C:\Program Files\Danish
2008-03-01 22:28 . 2003-08-28 10:27 169,268,568 --a------ C:\Program Files\SimCity_2.dat
2008-03-01 22:27 . 2008-03-01 22:27 <DIR> d-------- C:\Program Files\Apps
2008-03-01 22:27 . 2003-08-28 11:02 286,720 --a------ C:\Program Files\eauninstall.exe
2008-03-01 22:26 . 2003-08-28 10:27 144,547,650 --a------ C:\Program Files\SimCity_1.dat
2008-03-01 22:26 . 2003-08-24 23:04 18,242,823 --a------ C:\Program Files\Intro.dat
2008-03-01 22:26 . 2003-08-28 11:02 147,456 --a------ C:\Program Files\RunGame.exe
2008-03-01 22:26 . 2003-08-28 10:16 12,400 --a------ C:\Program Files\SECDRV.SYS
2008-03-01 22:25 . 2003-08-28 10:27 104,090,983 --a------ C:\Program Files\SimCity_5.dat
2008-03-01 22:25 . 2003-08-28 10:27 61,030,094 --a------ C:\Program Files\EP1.dat
2008-03-01 22:25 . 2003-08-28 10:16 41,472 --a------ C:\Program Files\DRVMGT.DLL
2008-03-01 22:24 . 2003-08-28 10:27 125,574,688 --a------ C:\Program Files\SimCity_4.dat
2008-03-01 22:24 . 2003-08-28 10:38 1,736,704 --a------ C:\Program Files\AutoRunGUI.dll
2008-03-01 22:24 . 2003-08-28 10:37 700,416 --a------ C:\Program Files\SC4_uninst.exe
2008-03-01 22:24 . 2003-08-28 11:02 561,152 --a------ C:\Program Files\AutoRun.exe
2008-03-01 16:44 . 2008-03-01 22:40 531 --a------ C:\WINDOWS\eReg.dat
2008-03-01 15:41 . 2008-03-01 15:41 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-03-01 05:52 . 2008-03-01 05:52 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\DAEMON Tools
2008-03-01 05:52 . 2008-03-01 05:52 716,272 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-03-01 01:42 . 2008-03-01 01:43 <DIR> d-------- C:\Program Files\MagicDisc
2008-03-01 01:42 . 2008-02-18 18:29 96,256 --a------ C:\WINDOWS\system32\drivers\mcdbus.sys
2008-03-01 01:33 . 2004-09-22 02:02 <DIR> d-a------ C:\Program Files\CD 2
2008-03-01 01:31 . 2004-09-22 01:54 <DIR> d-a------ C:\Program Files\CD 1
2008-02-27 19:17 . 2008-02-27 19:18 <DIR> d-------- C:\Program Files\FLAC
2008-02-27 17:01 . 2008-03-19 02:13 49 --a------ C:\WINDOWS\NeroDigital.ini
2008-02-25 04:27 . 2008-02-25 04:27 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-02-24 19:12 . 2008-02-24 19:12 <DIR> d---s---- C:\Documents and Settings\Owner\UserData
2008-02-24 04:12 . 2004-08-04 14:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-02-24 04:06 . 2006-08-21 04:14 128,896 -----c--- C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-02-24 04:06 . 2006-08-21 04:14 23,040 -----c--- C:\WINDOWS\system32\dllcache\fltmc.exe
2008-02-24 04:06 . 2006-08-21 07:21 16,896 -----c--- C:\WINDOWS\system32\dllcache\fltlib.dll
2008-02-23 18:57 . 2008-03-20 01:51 <DIR> d-------- C:\Program Files\PeerGuardian2
2008-02-23 16:44 . 2008-02-23 16:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Azureus
2008-02-23 16:43 . 2008-03-20 01:26 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Azureus
2008-02-23 16:42 . 2008-03-19 16:58 <DIR> d-------- C:\Program Files\Azureus
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-08 22:10 1,259 ----a-w C:\Program Files\coolplayer.ini
2008-03-08 22:10 0 ----a-w C:\Program Files\default.m3u
2008-02-23 08:04 8,552 ----a-w C:\WINDOWS\system32\drivers\asctrm.sys
2007-12-14 15:07 48,130 ------w C:\Program Files\autoruns.chm
2006-07-28 13:32 7,005 ------w C:\Program Files\Eula.txt
2004-09-07 04:15 773,337,600 ----a-r C:\Program Files\SC4DELUXE1.mdf
2003-08-28 16:02 23,214 ----a-w C:\Program Files\sv_filelist.txt
2003-08-28 16:02 23,214 ----a-w C:\Program Files\pt-br_filelist.txt
2003-08-28 16:02 23,214 ----a-w C:\Program Files\pl_filelist.txt
2003-08-28 16:02 23,214 ----a-w C:\Program Files\no_filelist.txt
2003-08-28 16:02 23,214 ----a-w C:\Program Files\nl_filelist.txt
2003-08-28 16:02 23,214 ----a-w C:\Program Files\it_filelist.txt
2003-08-28 16:02 23,214 ----a-w C:\Program Files\fr-fr_filelist.txt
2003-08-28 16:02 23,214 ----a-w C:\Program Files\fi_filelist.txt
2003-08-28 16:02 23,214 ----a-w C:\Program Files\es_filelist.txt
2003-08-28 16:02 23,214 ----a-w C:\Program Files\en-uk_filelist.txt
2003-08-28 16:02 23,214 ----a-w C:\Program Files\de_filelist.txt
2003-08-28 16:02 23,214 ----a-w C:\Program Files\da_filelist.txt
2003-08-28 15:16 317,440 ----a-w C:\Program Files\
00000002.TMP
2003-08-28 15:16 308,280 ----a-w C:\Program Files\
00000000.256
2003-08-28 15:16 2,048 ----a-w C:\Program Files\
00000001.TMP
2003-08-28 15:16 153,718 ----a-w C:\Program Files\
00000000.016
2003-08-25 04:10 10,420 ----a-w C:\Program Files\Video Cards.sgr
2003-08-25 04:03 19,976 ----a-w C:\Program Files\Graphics Rules.sgr
2003-07-12 17:31 10,134 ----a-w C:\Program Files\SC4_ConnectToWebIcon.ico
2003-07-12 17:31 10,134 ----a-w C:\Program Files\SC4.ico
2003-07-12 17:31 10,134 ----a-w C:\Program Files\eauninstall.ico
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2008-02-23 02:14 267592 --a------ C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL" [2008-02-23 02:14 267592]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 19:40 1421824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-03-19 17:17 78960]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-11-15 18:04 135168]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 14:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-23 03:09 98304]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 23:24 32768]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 19:54 77824 C:\WINDOWS\SOUNDMAN.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-02-23 02:36 1502976]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-23 03:12 249896]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-25 04:26 185632]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\WINDOWS\system32\guard32.dll
"LoadAppInit_DLLs"=1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\FrostWire\\FrostWire.exe"=
"C:\\Program Files\\BitTyrant\\Azureus.exe"=
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-02-23 02:36]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-02-23 02:36]
*Newly Created Service* - PGFILTER
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-20 01:51:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\guard32.dll
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\guard32.dll
.
Completion time: 2008-03-20 1:53:06
ComboFix-quarantined-files.txt 2008-03-20 06:52:50
.
2008-03-12 08:05:14 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 1:56:02 AM, on 3/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\COMODO\Firewall\cfpupdat.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis_v2.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://youtorrent.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
--
End of file - 5842 bytes