Here are the scan results
ComboFix 09-10-22.01 - John 10/23/2009 18:27.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1513 [GMT -7:00]
Running from: c:\documents and settings\John\Desktop\ComboFix.exe
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
((((((((((((((((((((((((( Files Created from 2009-09-24 to 2009-10-24 )))))))))))))))))))))))))))))))
.
2009-10-22 01:30 . 2009-06-01 20:51 27792 ----a-w- c:\windows\system32\drivers\point32.sys
2009-10-22 01:30 . 2009-10-22 01:30 -------- d-----w- c:\program files\Microsoft IntelliPoint
2009-10-20 22:43 . 2009-10-20 22:43 -------- d-----w- c:\program files\Trend Micro
2009-10-20 05:14 . 2009-10-20 05:14 -------- d-----w- c:\documents and settings\John\Application Data\Nitro PDF
2009-10-20 05:14 . 2009-10-20 05:14 -------- d-----w- c:\program files\Nitro PDF
2009-10-20 05:14 . 2009-10-20 05:14 -------- d-----w- c:\program files\Common Files\Nitro PDF
2009-10-20 05:14 . 2009-10-20 05:14 -------- d-----w- c:\program files\Common Files\BCL Technologies
2009-10-20 05:14 . 2009-10-20 05:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Nitro PDF
2009-10-20 05:13 . 2009-10-20 05:13 -------- d-----w- c:\windows\Downloaded Installations
2009-10-20 05:02 . 2009-10-20 05:02 -------- d-----w- c:\documents and settings\John\Application Data\InfraRecorder
2009-10-20 05:01 . 2009-10-20 05:01 -------- d-----w- c:\program files\InfraRecorder
2009-10-20 03:45 . 2001-08-18 05:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2009-10-20 03:45 . 2008-04-13 18:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2009-10-20 03:45 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-10-20 03:45 . 2008-04-14 00:12 159232 ----a-w- c:\windows\system32\ptpusd.dll
2009-10-17 22:41 . 2009-10-17 22:41 -------- d-----w- c:\documents and settings\John\Local Settings\Application Data\Identities
2009-10-17 17:32 . 2009-10-17 17:32 -------- d-----w- c:\windows\Sun
2009-10-17 17:31 . 2009-10-17 17:31 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-17 17:31 . 2009-10-17 17:31 -------- d-----w- c:\program files\Java
2009-10-16 04:29 . 2009-10-16 04:58 -------- d-----w- c:\documents and settings\John\Application Data\Apple Computer
2009-10-16 04:29 . 2009-05-18 21:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-10-16 04:29 . 2008-04-17 20:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-10-16 04:28 . 2009-10-16 04:28 -------- d-----w- c:\program files\iPod
2009-10-16 04:20 . 2009-10-20 03:45 -------- d-----w- c:\documents and settings\John\Local Settings\Application Data\Apple Computer
2009-10-16 01:15 . 2009-10-16 01:15 -------- d-----w- c:\windows\system32\LogFiles
2009-10-15 23:22 . 2009-10-15 23:23 -------- d-----w- c:\program files\My Mobile
2009-10-15 23:13 . 2009-10-15 23:13 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-10-14 00:18 . 2009-10-14 00:18 -------- d-----w- c:\documents and settings\John\Application Data\Malwarebytes
2009-10-14 00:17 . 2009-09-10 21:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-14 00:17 . 2009-10-14 00:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-14 00:17 . 2009-10-14 00:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-14 00:17 . 2009-09-10 21:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-14 00:05 . 2009-10-14 00:05 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-10-14 00:05 . 2009-10-14 00:05 -------- d-----w- c:\program files\uTorrent
2009-10-14 00:05 . 2009-10-14 00:13 -------- d-----w- c:\documents and settings\John\Application Data\uTorrent
2009-10-12 04:57 . 2009-10-13 04:08 -------- d-----w- c:\documents and settings\All Users\Application Data\xml_param
2009-10-12 04:45 . 2009-09-01 17:40 25704 ----a-w- c:\windows\system32\drivers\WsAudio_DeviceS(5).sys
2009-10-12 04:44 . 2009-09-01 17:40 25704 ----a-w- c:\windows\system32\drivers\WsAudio_DeviceS(4).sys
2009-10-12 04:44 . 2009-09-01 17:40 25704 ----a-w- c:\windows\system32\drivers\WsAudio_DeviceS(3).sys
2009-10-12 04:44 . 2009-09-01 17:40 25704 ----a-w- c:\windows\system32\drivers\WsAudio_DeviceS(2).sys
2009-10-12 04:44 . 2009-09-01 17:40 25704 ----a-w- c:\windows\system32\drivers\WsAudio_DeviceS(1).sys
2009-10-12 04:44 . 2009-10-12 04:44 -------- d-----w- c:\program files\Daniusoft
2009-10-11 21:17 . 2009-10-11 21:17 -------- d-----w- c:\program files\ImTOO
2009-10-10 21:43 . 2009-08-07 02:23 215920 ----a-w- c:\windows\system32\muweb.dll
2009-10-10 21:43 . 2009-08-07 02:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-10-10 14:50 . 2009-10-10 14:50 -------- d-----w- c:\documents and settings\John\Application Data\Foxit
2009-10-10 14:50 . 2009-10-20 01:00 -------- d-----w- c:\program files\Foxit Software
2009-10-10 04:27 . 2009-10-10 04:27 -------- d-sh--w- c:\documents and settings\John\IETldCache
2009-10-10 04:24 . 2009-10-10 04:24 -------- d-----w- c:\documents and settings\John\Local Settings\Application Data\Google
2009-10-10 04:24 . 2009-10-17 15:36 -------- d-----w- c:\program files\Google
2009-10-10 04:17 . 2009-10-10 04:27 -------- d-----w- c:\documents and settings\John\Tracing
2009-10-10 04:16 . 2009-10-10 04:16 -------- d-----w- c:\program files\Microsoft
2009-10-10 04:16 . 2009-10-10 04:16 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-10-10 04:15 . 2009-10-10 04:16 -------- d-----w- c:\program files\Windows Live
2009-10-10 04:13 . 2009-10-10 04:13 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-10 03:33 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-10-10 03:32 . 2009-10-10 03:33 -------- d-----w- c:\windows\ie8updates
2009-10-10 03:32 . 2009-08-29 08:08 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-10-10 03:32 . 2009-08-29 08:08 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-10-10 03:32 . 2009-08-29 08:08 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-10-10 03:32 . 2009-08-29 08:08 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-10-10 03:32 . 2009-08-29 08:08 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-10-10 03:32 . 2009-08-29 08:08 11069440 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-10-10 03:31 . 2009-10-10 03:32 -------- dc-h--w- c:\windows\ie8
2009-10-09 05:24 . 2009-10-09 05:26 -------- d-----w- c:\program files\The KMPlayer
2009-10-09 04:26 . 2009-10-09 04:27 -------- d-----w- c:\program files\DivX
2009-10-09 04:22 . 2009-10-09 04:22 -------- d-----w- c:\documents and settings\John\Local Settings\Application Data\WinAVI
2009-10-09 04:21 . 2009-10-09 04:21 -------- d-----w- c:\program files\WinAVI Video Converter
2009-10-09 00:51 . 2009-10-09 00:51 -------- d-----w- c:\program files\RealVNC
2009-10-09 00:24 . 2009-08-29 08:08 916480 -c----w- c:\windows\system32\dllcache\wininet.dll
2009-10-09 00:24 . 2009-08-29 08:08 1208832 -c----w- c:\windows\system32\dllcache\urlmon.dll
2009-10-09 00:23 . 2008-10-16 01:00 1499136 -c----w- c:\windows\system32\dllcache\shdocvw.dll
2009-10-09 00:23 . 2009-08-29 08:08 5940224 -c----w- c:\windows\system32\dllcache\mshtml.dll
2009-10-08 03:59 . 2009-10-08 03:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Digsby
2009-10-08 03:59 . 2009-10-23 02:10 14364 ---ha-w- c:\windows\system32\mlfcache.dat
2009-10-08 03:57 . 2009-10-08 03:59 -------- d-----w- c:\documents and settings\John\Application Data\Digsby
2009-10-08 03:57 . 2009-10-08 03:59 -------- d-----w- c:\documents and settings\John\Local Settings\Application Data\Digsby
2009-10-08 03:56 . 2009-10-08 03:58 -------- d-----w- c:\program files\Digsby
2009-10-08 03:54 . 2009-10-08 03:54 -------- d-----w- c:\documents and settings\John\Application Data\TeraCopy
2009-10-08 03:33 . 2009-10-08 03:33 0 ----a-w- c:\windows\nsreg.dat
2009-10-08 03:32 . 2009-10-08 03:32 -------- d-----w- c:\documents and settings\John\Local Settings\Application Data\Mozilla
2009-10-08 03:32 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-10-08 03:30 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2009-10-08 03:30 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-10-08 03:30 . 2008-05-01 14:33 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2009-10-08 03:30 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2009-10-08 03:30 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-10-08 03:30 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2009-10-08 03:29 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-10-08 03:29 . 2008-09-04 17:15 1106944 -c----w- c:\windows\system32\dllcache\msxml3.dll
2009-10-08 03:29 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-10-08 03:29 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-10-08 03:29 . 2009-06-22 06:44 726528 -c--a-w- c:\windows\system32\dllcache\jscript.dll
2009-10-08 03:23 . 2009-10-08 03:23 -------- d-----w- c:\program files\Defraggler
2009-10-08 03:23 . 2009-10-08 03:23 -------- d-----w- c:\program files\FreeFileSync
2009-10-08 03:20 . 2009-10-08 03:20 -------- d-----w- c:\program files\VS Revo Group
2009-10-08 03:20 . 2009-10-08 03:20 -------- d-----w- c:\program files\CCleaner
2009-10-08 03:15 . 2009-10-08 03:15 -------- d-----w- c:\program files\TeraCopy
2009-10-08 03:15 . 2008-04-13 18:45 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2009-10-08 03:08 . 2009-10-08 03:08 -------- d-----w- c:\windows\system32\scripting
2009-10-08 03:08 . 2009-10-08 03:08 -------- d-----w- c:\windows\system32\en
2009-10-08 03:08 . 2009-10-08 03:08 -------- d-----w- c:\windows\system32\bits
2009-10-08 03:08 . 2009-10-08 03:08 -------- d-----w- c:\windows\l2schemas
2009-10-08 03:08 . 2009-10-22 03:07 14080 ----a-w- c:\documents and settings\John\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-08 03:07 . 2009-10-08 03:07 -------- d-----w- c:\windows\ServicePackFiles
2009-10-08 03:03 . 2009-10-08 03:03 -------- d-----w- c:\windows\EHome
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-24 01:28 . 2009-10-07 19:18 -------- d-----w- c:\program files\Common Files
2009-10-22 23:23 . 2009-10-08 03:22 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-10-22 23:23 . 2009-10-08 03:22 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-22 23:23 . 2009-10-08 03:22 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2009-10-22 23:23 . 2009-10-08 03:22 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2009-10-22 23:23 . 2009-10-08 03:22 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-10-16 04:30 . 2009-10-16 04:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-10-16 04:30 . 2009-10-16 04:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-10-16 04:29 . 2009-10-16 04:28 -------- d-----w- c:\program files\iTunes
2009-10-16 04:29 . 2009-10-16 04:28 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-16 04:28 . 2009-10-16 04:21 -------- d-----w- c:\program files\Common Files\Apple
2009-10-16 04:28 . 2009-10-16 04:22 -------- d-----w- c:\program files\Bonjour
2009-10-16 04:22 . 2009-10-16 04:22 -------- d-----w- c:\program files\QuickTime
2009-08-26 08:00 . 2007-09-03 15:41 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-12 07:36 . 2009-08-12 07:36 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-08-12 07:36 . 2009-08-12 07:36 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-08-12 07:36 . 2009-08-12 07:36 1060864 ----a-w- c:\windows\system32\MFC71.dll
2009-08-07 02:24 . 2009-10-08 02:42 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-07 02:24 . 2009-10-08 02:42 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-07 02:24 . 2009-10-08 02:51 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-07 02:24 . 2009-10-08 02:42 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-07 02:24 . 2009-10-08 02:42 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-07 02:24 . 2007-09-03 15:40 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-07 02:23 . 2009-10-08 02:42 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-07 02:23 . 2009-10-08 02:42 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2007-09-03 15:41 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 15:13 . 2007-09-03 15:41 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-03 22:59 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-07-29 04:37 . 2007-09-03 15:41 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2007-09-03 15:40 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-26 23:44 . 2009-07-26 23:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-10-22 2010904]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-06-01 1468296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-10-08 03:22 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [10/7/2009 8:22 PM 161800]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/7/2009 8:22 PM 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/7/2009 8:22 PM 360584]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [10/7/2009 8:22 PM 285392]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [10/22/2009 4:23 PM 2321208]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [10/7/2009 8:22 PM 30104]
R3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_D eviceS(1).sys [10/11/2009 9:44 PM 25704]
R3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_D eviceS(2).sys [10/11/2009 9:44 PM 25704]
R3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_D eviceS(3).sys [10/11/2009 9:44 PM 25704]
R3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_D eviceS(4).sys [10/11/2009 9:44 PM 25704]
R3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_D eviceS(5).sys [10/11/2009 9:45 PM 25704]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [10/7/2009 8:22 PM 30104]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Nitro PDF Professional]
cscript //B "c:\program files\Nitro PDF\Professional\RemoveOldAddins.vbs"
.
Contents of the 'Scheduled Tasks' folder
2009-10-22 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2009-06-01 20:51]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\6j7cc6pq.default\
FF - component: c:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\6j7cc6pq.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - plugin: c:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\6j7cc6pq.default\extensions\ietab@ip.cn\plugi ns\npCoralIETab.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-23 18:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3916)
c:\windows\system32\WININET.dll
c:\program files\MediaMonkey\DeskPlayer.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2009-10-24 18:30
ComboFix-quarantined-files.txt 2009-10-24 01:30
Pre-Run: 116,464,672,768 bytes free
Post-Run: 116,487,667,712 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - A043C2F21A25C1FC85D44F35A1364DB2
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:31:36 PM, on 10/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe
C:\Program Files\My Mobile\MyMobiler\MyMobiler.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsu...?1254970250046
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
--
End of file - 4281 bytes