ComboFix 08-08-24.02 - Administrator 2008-08-25 14:51:54.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.643 [GMT -7:00]
Running from: C:\Users\Administrator\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-07-25 to 2008-08-25 )))))))))))))))))))))))))))))))
.
2008-08-25 01:34 . 2008-08-25 01:34 <DIR> d-------- C:\Users\All Users\Adobe
2008-08-25 01:34 . 2008-08-25 01:34 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-08-25 01:34 . 2008-08-25 01:34 <DIR> d-------- C:\Program Files\Adobe Media Player
2008-08-24 11:24 . 2008-08-24 11:24 <DIR> d-------- C:\Program Files\MSN Messenger
2008-08-24 11:24 . 2008-08-25 14:36 <DIR> d-------- C:\Program Files\MessengerDiscovery
2008-08-24 11:24 . 2004-03-09 00:00 609,824 --a------ C:\Windows\System32\COMCTL32.ocx
2008-08-24 11:24 . 2004-03-09 00:00 212,240 --a------ C:\Windows\System32\richtx32.OCX
2008-08-24 11:24 . 2004-03-08 22:00 152,848 --a------ C:\Windows\System32\comdlg32.OCX
2008-08-24 11:24 . 2004-03-09 00:00 124,688 --a------ C:\Windows\System32\MSWINSCK.ocx
2008-08-24 00:56 . 2008-08-24 00:56 <DIR> d-------- C:\Program Files\Hotspot Shield
2008-08-24 00:04 . 2008-08-24 00:04 <DIR> d-------- C:\Program Files\Logitech
2008-08-24 00:04 . 2008-08-24 00:04 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-08-24 00:03 . 2008-08-24 00:04 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-08-23 23:30 . 2008-08-23 23:30 <DIR> d-------- C:\Users\All Users\Microsoft Corporation
2008-08-23 23:30 . 2008-08-23 23:30 <DIR> d-------- C:\PROGRA~2\Microsoft Corporation
2008-08-22 11:13 . 2008-08-23 02:10 <DIR> d-------- C:\Users\All Users\Messenger Plus!
2008-08-22 11:13 . 2008-08-23 02:10 <DIR> d-------- C:\PROGRA~2\Messenger Plus!
2008-08-22 10:53 . 2008-08-22 10:53 <DIR> d-------- C:\Windows\Sun
2008-08-22 04:54 . 2008-08-22 04:54 <DIR> d-------- C:\Users\All Users\Stardock
2008-08-22 04:54 . 2008-08-22 04:54 <DIR> d-------- C:\PROGRA~2\Stardock
2008-08-22 02:29 . 2008-08-22 02:29 <DIR> d-------- C:\Users\All Users\Google
2008-08-22 02:28 . 2008-08-22 02:29 <DIR> d-------- C:\Program Files\Google
2008-08-22 02:05 . 2008-08-22 02:05 <DIR> d-------- C:\Program Files\Messenger Plus! Live
2008-08-22 02:05 . 2008-08-22 02:05 <DIR> d-------- C:\Program Files\Circle Developement
2008-08-22 01:43 . 2008-08-22 01:57 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-22 01:42 . 2008-08-22 01:42 <DIR> d-------- C:\Users\All Users\WLInstaller
2008-08-22 01:42 . 2008-08-22 01:57 <DIR> d-------- C:\Program Files\Windows Live
2008-08-22 01:42 . 2008-08-22 01:42 <DIR> d-------- C:\PROGRA~2\WLInstaller
2008-08-22 01:33 . 2008-08-24 23:19 438,260 --a------ C:\Windows\System32\perfh001.dat
2008-08-22 01:33 . 2008-08-22 01:13 285,290 --a------ C:\Windows\System32\perfi001.dat
2008-08-22 01:33 . 2008-08-24 23:19 77,914 --a------ C:\Windows\System32\perfc001.dat
2008-08-22 01:33 . 2008-08-22 01:13 41,018 --a------ C:\Windows\System32\perfd001.dat
2008-08-22 01:29 . 2008-08-22 01:29 <DIR> d-------- C:\Windows\System32\fr
2008-08-22 01:29 . 2008-08-22 01:29 <DIR> d-------- C:\Windows\System32\drivers\fr-FR
2008-08-22 01:29 . 2008-08-22 01:29 <DIR> d-------- C:\Windows\System32\drivers\ar-SA
2008-08-22 01:29 . 2008-08-22 01:29 <DIR> d-------- C:\Windows\System32\ar
2008-08-22 01:29 . 2008-08-22 01:29 <DIR> d-------- C:\Windows\System32\
040C
2008-08-22 01:29 . 2008-08-22 01:29 <DIR> d-------- C:\Windows\fr-FR
2008-08-22 01:29 . 2008-08-22 01:29 <DIR> d-------- C:\Windows\ar-SA
2008-08-22 01:27 . 2008-06-18 20:31 361,984 --a------ C:\Windows\System32\IPSECSVC.DLL
2008-08-22 01:26 . 2008-04-26 01:25 3,600,952 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-08-22 01:26 . 2008-04-26 01:25 3,549,240 --a------ C:\Windows\System32\ntoskrnl.exe
2008-08-22 01:26 . 2008-04-26 01:26 891,448 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-08-22 01:26 . 2008-04-11 20:32 784,896 --a------ C:\Windows\System32\rpcrt4.dll
2008-08-22 01:26 . 2008-05-09 20:35 564,736 --a------ C:\Windows\System32\emdmgmt.dll
2008-08-22 01:26 . 2008-04-04 18:21 72,192 --a------ C:\Windows\System32\drivers\pacer.sys
2008-08-22 01:26 . 2008-04-04 20:34 15,360 --a------ C:\Windows\System32\pacerprf.dll
2008-08-22 01:23 . 2008-07-15 18:32 2,048 --a------ C:\Windows\System32\tzres.dll
2008-08-22 01:22 . 2008-04-17 22:48 269,312 --a------ C:\Windows\System32\es.dll
2008-08-22 01:18 . 2008-06-25 20:29 801,280 --a------ C:\Windows\System32\NaturalLanguage6.dll
2008-08-22 01:17 . 2008-06-25 18:45 12,240,896 --a------ C:\Windows\System32\NlsLexicons0007.dll
2008-08-22 01:17 . 2008-06-25 18:45 2,644,480 --a------ C:\Windows\System32\NlsLexicons0009.dll
2008-08-22 01:16 . 2008-06-26 18:55 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-08-22 01:16 . 2008-06-26 21:15 827,392 --a------ C:\Windows\System32\wininet.dll
2008-08-22 00:58 . 2008-04-26 01:08 1,314,816 --a------ C:\Windows\System32\quartz.dll
2008-08-22 00:58 . 2008-04-09 22:12 738,304 --a------ C:\Windows\System32\inetcomm.dll
2008-08-22 00:58 . 2008-04-22 21:42 428,544 --a------ C:\Windows\System32\EncDec.dll
2008-08-22 00:58 . 2008-04-22 21:42 293,376 --a------ C:\Windows\System32\psisdecd.dll
2008-08-22 00:58 . 2008-04-22 21:41 218,624 --a------ C:\Windows\System32\psisrndr.ax
2008-08-22 00:58 . 2008-04-22 21:41 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
2008-08-22 00:57 . 2008-08-22 00:57 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-08-21 23:57 . 2008-08-21 23:57 <DIR> dr------- C:\Windows\System32\config\systemprofile\Music
2008-08-21 23:31 . 2008-08-23 00:20 69 --a------ C:\Windows\NeroDigital.ini
2008-08-21 23:06 . 2008-08-21 23:06 <DIR> d-------- C:\Users\Administrator\AppData\Roaming\ACD Systems
2008-08-21 23:06 . 2008-08-21 23:06 <DIR> d-------- C:\Users\ADMINI~1\AppData\Roaming\ACD Systems
2008-08-21 23:06 . 2008-08-21 23:06 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-08-21 15:47 . 2008-08-21 15:47 <DIR> d-------- C:\Program Files\Software Remove Master
2008-08-21 15:39 . 2008-08-21 15:39 <DIR> d-------- C:\Program Files\NeroInstall.bak
2008-08-21 15:38 . 2008-08-21 15:38 <DIR> d-------- C:\Users\Administrator\AppData\Roaming\Nero
2008-08-21 15:38 . 2008-08-21 15:38 <DIR> d-------- C:\Users\ADMINI~1\AppData\Roaming\Nero
2008-08-21 15:36 . 2008-08-21 15:36 <DIR> d-------- C:\Users\All Users\Nero
2008-08-21 15:36 . 2008-08-21 15:36 <DIR> d-------- C:\Program Files\Nero
2008-08-21 15:36 . 2008-08-21 15:37 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-08-21 15:36 . 2008-08-21 15:36 <DIR> d-------- C:\PROGRA~2\Nero
2008-08-21 15:30 . 2008-08-21 15:30 25 --a------ C:\Windows\cdplayer.ini
2008-08-21 15:25 . 2008-08-21 15:25 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-08-21 15:25 . 2003-03-18 20:14 499,712 --a------ C:\Windows\System32\msvcp71.dll
2008-08-21 15:25 . 2003-02-21 04:42 348,160 --a------ C:\Windows\System32\msvcr71.dll
2008-08-21 15:16 . 2008-08-21 15:16 <DIR> d-------- C:\Users\All Users\ACD Systems
2008-08-21 15:16 . 2008-08-21 15:16 <DIR> d-------- C:\Program Files\Common Files\ACD Systems
2008-08-21 15:16 . 2008-08-21 15:16 <DIR> d-------- C:\Program Files\ACD Systems
2008-08-21 15:16 . 2008-08-21 15:16 <DIR> d-------- C:\PROGRA~2\ACD Systems
2008-08-21 15:03 . 2008-08-21 15:03 <DIR> d-------- C:\Program Files\Real
2008-08-21 15:03 . 2008-08-21 15:25 <DIR> d-------- C:\Program Files\Common Files\Real
2008-08-21 14:55 . 2008-08-21 14:55 <DIR> d-------- C:\Program Files\Java
2008-08-21 14:55 . 2008-08-21 14:55 <DIR> d-------- C:\Program Files\Common Files\Java
2008-08-21 14:53 . 2008-08-25 01:22 <DIR> d-------- C:\Windows\System32\Macromed
2008-08-21 01:59 . 2008-08-21 01:59 <DIR> d-------- C:\Users\Administrator\AppData\Roaming\Avira
2008-08-21 01:59 . 2008-08-21 01:59 <DIR> d-------- C:\Users\ADMINI~1\AppData\Roaming\Avira
2008-08-21 01:46 . 2008-08-20 18:04 <DIR> d-------- C:\Users\All Users\Avira
2008-08-21 01:46 . 2008-08-21 03:36 <DIR> d-------- C:\Users\Administrator\{2f3532e7-ce3c-46e3-a60c-34b86da1829e}
2008-08-21 01:46 . 2008-08-21 01:46 <DIR> d-------- C:\Program Files\Avira
2008-08-21 01:46 . 2008-08-20 18:04 <DIR> d-------- C:\PROGRA~2\Avira
2008-08-21 01:46 . 2008-08-20 18:25 71,592 --a------ C:\Windows\System32\drivers\avfwot.sys
2008-08-21 01:46 . 2008-08-20 18:25 71,464 --a------ C:\Windows\System32\drivers\avfwim.sys
2008-08-21 01:22 . 2008-08-21 01:22 <DIR> d-------- C:\Users\All Users\TuneUp Software
2008-08-21 01:22 . 2008-08-21 01:22 <DIR> d-------- C:\Users\Administrator\AppData\Roaming\TuneUp Software
2008-08-21 01:22 . 2008-08-21 01:22 <DIR> d-------- C:\Users\ADMINI~1\AppData\Roaming\TuneUp Software
2008-08-21 01:22 . 2008-08-21 01:22 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008
2008-08-21 01:22 . 2008-08-21 01:22 <DIR> d-------- C:\PROGRA~2\TuneUp Software
2008-08-21 01:22 . 2008-08-21 01:22 354,560 --a------ C:\Windows\System32\TuneUpDefragService.exe
2008-08-21 01:22 . 2008-04-04 14:51 28,416 --a------ C:\Windows\System32\uxtuneup.dll
2008-08-21 01:22 . 2008-04-04 14:51 16,640 --a------ C:\Windows\System32\authuitu.dll
2008-08-21 01:09 . 2006-10-26 19:56 32,592 --a------ C:\Windows\System32\msonpmon.dll
2008-08-21 01:07 . 2008-08-21 01:07 <DIR> d-------- C:\Windows\PCHEALTH
2008-08-21 01:07 . 2008-08-21 01:07 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-08-21 01:07 . 2008-08-21 01:07 <DIR> d-------- C:\Program Files\Microsoft Works
2008-08-21 01:06 . 2008-08-21 00:11 <DIR> d-------- C:\Windows\Panther
2008-08-21 01:06 . 2008-08-21 01:06 <DIR> d--hs---- C:\Boot
2008-08-21 01:06 . 2008-01-20 19:22 333,203 -rahs---- C:\bootmgr
2008-08-21 01:06 . 2008-08-21 01:06 8,192 -ra-s---- C:\BOOTSECT.BAK
2008-08-21 01:05 . 2008-08-21 01:05 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-08-21 01:04 . 2008-08-21 01:09 <DIR> d-------- C:\Users\All Users\Microsoft Help
2008-08-21 01:04 . 2008-08-21 01:09 <DIR> d-------- C:\PROGRA~2\Microsoft Help
2008-08-21 01:04 . 2008-08-21 01:04 <DIR> dr-h----- C:\MSOCache
2008-08-21 00:58 . 2008-08-21 00:58 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2008-08-21 00:57 . 2008-08-25 01:38 <DIR> d--hs---- C:\Windows\Installer
2008-08-21 00:15 . 2008-08-21 23:07 <DIR> dr------- C:\Users\Administrator\Videos
2008-08-21 00:15 . 2008-08-21 00:15 <DIR> dr------- C:\Users\Administrator\Searches
2008-08-21 00:15 . 2008-08-21 00:15 <DIR> dr------- C:\Users\Administrator\Saved Games
2008-08-21 00:15 . 2008-08-25 07:52 <DIR> dr------- C:\Users\Administrator\Pictures
2008-08-21 00:15 . 2008-08-21 15:05 <DIR> dr------- C:\Users\Administrator\Music
2008-08-21 00:15 . 2008-08-21 00:15 <DIR> dr------- C:\Users\Administrator\Links
2008-08-21 00:15 . 2008-08-25 11:43 <DIR> dr------- C:\Users\Administrator\Downloads
2008-08-21 00:15 . 2008-08-23 23:30 <DIR> dr------- C:\Users\Administrator\Documents
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-22 08:29 --------- d-----w C:\Program Files\Windows Sidebar
2008-08-22 08:29 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-08-22 08:29 --------- d-----w C:\Program Files\Windows Mail
2008-08-22 08:29 --------- d-----w C:\Program Files\Windows Journal
2008-08-22 08:29 --------- d-----w C:\Program Files\Windows Defender
2008-08-22 08:29 --------- d-----w C:\Program Files\Windows Collaboration
2008-08-22 08:29 --------- d-----w C:\Program Files\Windows Calendar
2008-08-21 08:07 --------- d-----w C:\Program Files\MSBuild
2008-06-12 05:28 541,696 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-05-27 05:21 1,582,592 ----a-w C:\Windows\System32\tquery.dll
2008-05-27 05:21 1,418,240 ----a-w C:\Windows\System32\mssrch.dll
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\SearchFilterHost.exe
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\mssitlb.dll
2008-05-27 05:17 754,176 ----a-w C:\Windows\System32\propsys.dll
2008-05-27 05:17 60,416 ----a-w C:\Windows\System32\msscntrs.dll
2008-05-27 05:17 6,103,040 ----a-w C:\Windows\System32\chtbrkr.dll
2008-05-27 05:17 34,816 ----a-w C:\Windows\System32\msscb.dll
2008-05-27 05:17 32,768 ----a-w C:\Windows\System32\mssprxy.dll
2008-05-27 05:17 313,344 ----a-w C:\Windows\System32\thawbrkr.dll
2008-05-27 05:17 301,568 ----a-w C:\Windows\System32\srchadmin.dll
2008-05-27 05:17 194,560 ----a-w C:\Windows\System32\offfilt.dll
2008-05-27 05:17 143,872 ----a-w C:\Windows\System32\korwbrkr.dll
2008-05-27 05:17 11,776 ----a-w C:\Windows\System32\msshooks.dll
2008-05-27 05:17 1,671,680 ----a-w C:\Windows\System32\chsbrkr.dll
2008-05-27 04:59 18,904 ----a-w C:\Windows\System32\StructuredQuerySchemaTrivial.bin
2008-05-27 04:59 106,605 ----a-w C:\Windows\System32\StructuredQuerySchema.bin
2008-01-21 02:41 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-20 19:21 1233920]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 17:07 1828136]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-08-22 02:29 171448]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-20 19:23 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"avgnt"="C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" [2008-08-20 18:25 266497]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"MsgCenterExe"="C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" [2008-08-21 15:25 69632]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-08-21 15:25 185896]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 16:29 2221352]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-01-19 11:45 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-01-19 11:39 217088]
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Media Player.lnk - C:\Program Files\Adobe Media Player\Adobe Media Player.exe [2008-08-25 01:34:39 260096]
C:\Users\ADMINI~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\
Adobe Media Player.lnk - C:\Program Files\Adobe Media Player\Adobe Media Player.exe [2008-08-25 01:34:39 260096]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1272675348-428297823-745401570-500]
"EnableNotificationsRef"=dword:00000003
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{97FB02E1-1765-4C15-A6E2-FA904A328D30}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{DA7455C5-98D9-4E3A-9BAD-7EE0A942B786}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{856ABC95-5285-47B2-96B8-96E3B33B10AB}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{A77AA9C8-0484-41C2-9CED-1A7FCEF5A21F}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4360C5BB-125A-46C7-8655-5B3A845AF6C3}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{90C14FA4-4B7B-4FC0-8542-D71A50D243F9}C:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:C:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"UDP Query User{74FDE944-C077-41F4-9A88-75C4618CB34F}C:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:C:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"{5CCD68A6-67E9-44FB-A9F0-B9D87B7077F7}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
R2 AntiVirMailService;Avira Premium Security Suite MailGuard;C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe [2008-08-20 18:25]
R2 antivirwebservice;Avira Premium Security Suite WebGuard;C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE [2008-08-20 18:25]
R2 AVEService;Avira Premium Security Suite MailGuard helper service;C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe [2008-08-20 18:25]
R2 UxTuneUp;TuneUp Theme Extension;C:\Windows\System32\svchost.exe [2008-01-20 19:21]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2008-01-20 19:21]
R3 tapvpn;TAP VPN Adapter;C:\Windows\system32\DRIVERS\tapvpn.sys [2007-06-07 23:52]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\Windows\System32\TuneUpDefragService.exe [2008-08-21 01:22]
S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-20 19:21]
S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-01-20 19:21]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d49bf7dc-6f4f-11dd-922e-806e6f6e6963}]
\shell\AutoRun\command - E:\setup.exe
\shell\LVIPCAP\command - E:\techsupt\CaptureTest\LVidCap.exe
\shell\PCITEST\command - E:\techsupt\SysTools\Listpci.exe
\shell\USBREADY\command - E:\techsupt\Systools\USBReady.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Device Detector - DevDetect.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
O8 -: ?&???? ??? Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-25 14:54:55
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\Windows\Explorer.exe
-> ?:\Windows\system32\ieframe.dll
.
Completion time: 2008-08-25 14:56:30
ComboFix-quarantined-files.txt 2008-08-25 21:56:25
Pre-Run: 11,587,108,864 bytes free
Post-Run: 11,260,444,672 bytes free
252 --- E O F --- 2008-08-22 08:28:27
وهذا للهايجك ،،
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:00:38 PM, on 8/25/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehmsas.exe
C:\PROGRA~2\Stardock\XGF\XGFRuntimeServer.exe
C:\Program Files\MessengerDiscovery\MessengerDiscovery Live.exe
C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\MessengerDiscovery\MessengerDiscovery Live.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\system32\conime.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Administrator\Desktop\Zyzoom_HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: ????? ??? OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: ??&??? ??? OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash ) -
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Avira Premium Security Suite MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe
O23 - Service: Avira Premium Security Suite Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
O23 - Service: Avira Premium Security Suite Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe
O23 - Service: Avira Premium Security Suite WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE
O23 - Service: Avira Premium Security Suite MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
--
End of file - 7159 bytes
انتظر تعليقك