| Sorry this took so long. Had a out of town emergency. Now back to putting out this fire!
Here is the Hijack log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:40:06, on 7/29/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal
Running processes: I:\WINDOWS\System32\smss.exe I:\WINDOWS\system32\winlogon.exe I:\WINDOWS\system32\services.exe I:\WINDOWS\system32\lsass.exe I:\WINDOWS\system32\svchost.exe I:\WINDOWS\System32\svchost.exe I:\WINDOWS\system32\LEXBCES.EXE I:\WINDOWS\system32\spoolsv.exe I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe I:\Program Files\CyberLink\Shared Files\RichVideo.exe I:\WINDOWS\System32\svchost.exe I:\WINDOWS\ALCXMNTR.EXE I:\WINDOWS\system32\VTTimer.exe I:\Program Files\CyberLink\PowerDVD\PDVDServ.exe I:\Program Files\Java\jre1.5.0_03\bin\jusched.exe I:\Program Files\QuickTime\qttask.exe I:\Program Files\iTunes\iTunesHelper.exe I:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe I:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe I:\WINDOWS\system32\ctfmon.exe I:\Program Files\MSN Messenger\msnmsgr.exe I:\Program Files\Java\jre1.5.0_03\bin\jucheck.exe I:\WINDOWS\system32\wscntfy.exe I:\Program Files\iPod\bin\iPodService.exe I:\WINDOWS\system32\wuauclt.exe I:\WINDOWS\system32\wuauclt.exe I:\WINDOWS\explorer.exe I:\Program Files\Internet Explorer\iexplore.exe I:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.liverpoolfc.tv/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - i:\program files\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - i:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [RemoteControl] "I:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [LanguageShortcut] "I:\Program Files\CyberLink\PowerDVD\Language\Language.exe" O4 - HKLM\..\Run: [NeroFilterCheck] I:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [PrinTray] I:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] I:\Program Files\Java\jre1.5.0_03\bin\jusched.exe O4 - HKLM\..\Run: [QuickTime Task] "I:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "I:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] I:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe O4 - HKLM\..\Run: [Lexmark X73 Button Manager] I:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe O4 - HKLM\..\Run: [789:;<=>?@ABCDEFGHIJexe] ,-./0123456789:;<=>?@ABCDEFGHIJexe O4 - HKLM\..\Run: [3456789:;<=>?@ABCDEFexe] ()*+,-./0123456789:;<=>?@ABCDEFexe O4 - HKLM\..\Run: [+,-./0123456789:;<exe] !"#$%&'()*+,-./0123456789:;<exe O4 - HKLM\..\Run: [3456789:;<=>?@ABCDEFGexe] ()*+,-./0123456789:;<=>?@ABCDEFGexe O4 - HKCU\..\Run: [ctfmon.exe] I:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "I:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [789:;<=>?@ABCDEFGHIJexe] ,-./0123456789:;<=>?@ABCDEFGHIJexe O4 - HKCU\..\Run: [3456789:;<=>?@ABCDEFexe] ()*+,-./0123456789:;<=>?@ABCDEFexe O4 - HKCU\..\Run: [+,-./0123456789:;<exe] !"#$%&'()*+,-./0123456789:;<exe O4 - HKCU\..\Run: [3456789:;<=>?@ABCDEFGexe] ()*+,-./0123456789:;<=>?@ABCDEFGexe O4 - Global Startup: Microsoft Office.lnk = I:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://I:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cabO16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1177343156734O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cabO16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cabO23 - Service: Apple Mobile Device - Apple, Inc. - I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Google Updater Service (gusvc) - Google - I:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - I:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - I:\WINDOWS\system32\LEXBCES.EXE O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - I:\Program Files\CyberLink\Shared Files\RichVideo.exe
-- End of file - 5893 bytes
Here is the ComboFix Log:
ComboFix 08-07-29.1 - User 2008-07-29 19:27:35.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.185 [GMT -4:00] Running from: I:\Documents and Settings\User\Desktop\ComboFix.exe * Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color] .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
I:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat I:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat I:\Documents and Settings\User\Application Data\macromedia\Flash Player\#SharedObjects\2CK77YJE\iforex.com I:\Documents and Settings\User\Application Data\macromedia\Flash Player\#SharedObjects\2CK77YJE\iforex.com\Emerp\Events\flash_object.swf\user_data.sol I:\Documents and Settings\User\Application Data\macromedia\Flash Player\#SharedObjects\2CK77YJE\interclick.com I:\Documents and Settings\User\Application Data\macromedia\Flash Player\#SharedObjects\2CK77YJE\interclick.com\pep3.sol I:\Documents and Settings\User\Application Data\macromedia\Flash Player\#SharedObjects\2CK77YJE\interclick.com\ud.sol I:\Documents and Settings\User\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com I:\Documents and Settings\User\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol I:\Documents and Settings\User\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com I:\Documents and Settings\User\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol I:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML I:\WINDOWS\system32\mcrh.tmp I:\WINDOWS\system32\mwmgbdbp.dll I:\WINDOWS\system32\nrvxxeni.ini I:\WINDOWS\system32\ppftrc.dll I:\WINDOWS\system32\ttbuauop.dll I:\WINDOWS\system32\unvkhfjy.ini I:\WINDOWS\system32\xgeusg.dll
----- BITS: Possible infected sites -----
-------\Legacy_CLBDRIVER
((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-29 ))))))))))))))))))))))))))))))) .
2100-02-23 14:35 . 2001-02-22 09:54 768 --a------ I:\WINDOWS\x73_lut.dat 2100-02-08 15:53 . 2008-04-21 08:54 1,438 --a------ I:\WINDOWS\GtX73.ini 2008-07-26 14:33 . 2008-07-26 14:33 <DIR> d-------- I:\Program Files\Malwarebytes' Anti-Malware 2008-07-26 14:33 . 2008-07-26 14:33 <DIR> d-------- I:\Documents and Settings\User\Application Data\Malwarebytes 2008-07-26 14:33 . 2008-07-26 14:33 <DIR> d-------- I:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-07-26 14:33 . 2008-07-23 20:09 38,472 --a------ I:\WINDOWS\system32\drivers\mbamswissarmy.sys 2008-07-26 14:33 . 2008-07-23 20:09 17,144 --a------ I:\WINDOWS\system32\drivers\mbam.sys 2008-07-25 21:15 . 2008-07-26 15:27 <DIR> d-------- I:\Program Files\SUPERAntiSpyware 2008-07-25 21:15 . 2008-07-26 15:27 <DIR> d-------- I:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com 2008-07-25 21:15 . 2008-07-25 21:15 <DIR> d-------- I:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2008-07-25 21:09 . 2008-07-25 21:09 <DIR> d-------- I:\Program Files\Trend Micro 2008-07-25 20:32 . 2008-07-25 20:32 <DIR> d-------- I:\VundoFix Backups 2008-07-25 18:38 . 2008-07-25 18:39 <DIR> d-------- I:\WINDOWS\ERUNT 2008-07-25 01:39 . 2008-07-25 01:48 <DIR> d-------- I:\Documents and Settings\User\Application Data\Symantec 2008-07-25 01:33 . 2008-07-26 14:30 <DIR> d-------- I:\Program Files\Norton 360 2008-07-25 01:24 . 2008-07-26 14:31 <DIR> d-------- I:\Program Files\Common Files\Symantec Shared 2008-07-24 23:20 . 2008-07-24 23:20 <DIR> d-------- I:\Documents and Settings\Administrator 2008-07-24 22:57 . 2003-03-31 15:00 4,224 --a------ I:\WINDOWS\system32\beep.sys 2008-07-24 22:45 . 2008-07-24 22:45 <DIR> d-------- I:\Documents and Settings\User\Application Data\Pegasys Inc 2008-07-24 21:26 . 2008-07-24 21:39 26 --a------ I:\WINDOWS\dvdSanta.INI 2008-07-24 21:23 . 2008-07-24 21:34 <DIR> d-------- I:\Program Files\dvdSanta 2008-07-24 21:23 . 2007-04-22 22:11 1,216,512 --a------ I:\WINDOWS\system32\xvidcore.dll 2008-07-24 21:23 . 2006-10-28 11:11 516,096 --a------ I:\WINDOWS\system32\ac3filter.ax 2008-07-24 21:23 . 2004-01-10 18:02 258,048 --a------ I:\WINDOWS\system32\GplMpgDec.ax 2008-07-24 21:23 . 2007-04-22 22:11 237,568 --a------ I:\WINDOWS\system32\xvidvfw.dll 2008-07-24 21:23 . 2004-03-26 16:32 116,224 --a------ I:\WINDOWS\system32\rmalt.ax 2008-07-24 21:23 . 2007-04-22 22:11 61,440 --a------ I:\WINDOWS\system32\xvid.ax 2008-07-24 21:23 . 2004-04-30 21:46 28,672 --a------ I:\WINDOWS\system32\qtalt.ax 2008-07-04 23:32 . 2008-07-04 23:32 <DIR> d-------- I:\Program Files\Adobe Media Player 2008-07-04 23:31 . 2008-07-04 23:31 <DIR> d-------- I:\Program Files\Common Files\Adobe AIR 2008-07-02 23:42 . 2008-07-02 23:41 145,504 --a------ I:\WINDOWS\system32\bgsvcgen.exe 2008-07-02 23:42 . 2008-07-02 23:41 59,488 --a------ I:\WINDOWS\system32\GenSvcInst.exe 2008-07-02 23:42 . 2008-07-02 23:41 33,408 --a------ I:\WINDOWS\system32\drivers\CDRBSDRV.SYS
. (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-28 12:11 --------- d--h--w I:\Program Files\InstallShield Installation Information 2008-07-28 12:11 --------- d-----w I:\Program Files\Common Files\Panda Software 2008-07-27 15:00 --------- d-----w I:\Program Files\Common Files\InstallShield 2008-07-27 14:47 --------- d-----w I:\Program Files\Winamp 2008-07-27 14:47 --------- d-----w I:\Program Files\QuickTime 2008-07-27 14:47 --------- d-----w I:\Program Files\MSN Messenger 2008-07-27 14:47 --------- d-----w I:\Program Files\iTunes 2008-07-27 14:47 --------- d-----w I:\Program Files\Google 2008-07-26 20:16 --------- d-----w I:\Program Files\LexmarkX73 2008-07-26 20:15 133,915 ----a-w I:\PAVVTS.DAT 2008-07-26 20:15 10,160 ----a-w I:\PAVPROT.BIN 2008-07-25 02:58 --------- d-----w I:\Documents and Settings\User\Application Data\LimeWire 2008-07-23 16:42 --------- d-----w I:\Program Files\PokerStars 2008-07-19 17:22 --------- d-----w I:\Documents and Settings\All Users\Application Data\DVD Shrink 2008-07-12 15:17 --------- d-----w I:\Documents and Settings\User\Application Data\Vso 2008-07-12 15:15 --------- d-----w I:\Documents and Settings\User\Application Data\DVD Flick 2008-07-06 15:47 --------- d-----w I:\Program Files\DVD Flick 2008-07-03 03:33 --------- d---a-w I:\Documents and Settings\All Users\Application Data\TEMP 2008-07-03 03:33 --------- d-----w I:\Documents and Settings\User\Application Data\VideoReDoPlus 2008-06-20 10:45 360,320 ----a-w I:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:44 138,368 ----a-w I:\WINDOWS\system32\drivers\afd.sys 2008-06-20 09:52 225,920 ----a-w I:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-13 13:10 272,128 ------w I:\WINDOWS\system32\drivers\bthport.sys 2008-06-11 14:15 --------- d-----w I:\Documents and Settings\User\Application Data\Hamachi 2008-06-11 02:48 --------- d-----w I:\Program Files\Solveig Multimedia 2008-06-11 02:48 --------- d-----w I:\Program Files\Common Files\Solveig Multimedia 2008-05-15 02:31 21,808 ----a-w I:\Documents and Settings\User\Application Data\GDIPFONTCACHEV1.DAT 2007-05-15 15:21 81,920 ----a-w I:\Documents and Settings\User\Application Data\ezpinst.exe 2007-05-15 15:21 47,360 ----a-w I:\Documents and Settings\User\Application Data\pcouffin.sys 2007-05-13 23:17 40 ----a-w I:\Documents and Settings\User\language.dat 2001-07-26 20:58 47 ----a-w I:\Program Files\ACMonitor_X73.ini 2001-07-05 16:46 8,116 ----a-w I:\Program Files\OSLO3071b2.USB 2001-05-11 15:39 53,248 ----a-w I:\Program Files\ACMonitor_X73.exe 2001-05-08 20:36 114,688 ----a-w I:\Program Files\lxarscan.dll 2001-04-23 18:22 1,437 ----a-w I:\Program Files\gtx73.ini 2001-02-22 13:54 768 ----a-w I:\Program Files\x73_lut.dat .
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "789:;<=>?@ABCDEFGHIJexe"="" [?] "3456789:;<=>?@ABCDEFexe"="()*+" [?] "3456789:;<=>?@ABCDEFGexe"="()*+" [?] "ctfmon.exe"="I:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360] "msnmsgr"="I:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "789:;<=>?@ABCDEFGHIJexe"="" [?] "3456789:;<=>?@ABCDEFexe"="()*+" [?] "3456789:;<=>?@ABCDEFGexe"="()*+" [?] "RemoteControl"="I:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 15:10 56928] "LanguageShortcut"="I:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 22:55 54832] "NeroFilterCheck"="I:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648] "PrinTray"="I:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2001-10-12 03:42 36864] "SunJavaUpdateSched"="I:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48 36975] "QuickTime Task"="I:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24 286720] "iTunesHelper"="I:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42 267064] "Lexmark X73 Button Monitor"="I:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe" [2001-10-08 16:21 53248] "Lexmark X73 Button Manager"="I:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe" [2001-07-11 12:08 53248] "AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 I:\WINDOWS\ALCXMNTR.EXE] "VTTimer"="VTTimer.exe" [2005-03-08 04:33 53248 I:\WINDOWS\system32\VTTimer.exe]
I:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Microsoft Office.lnk - I:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wineh46.sys] @="Driver"
[HKLM\~\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=I:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=I:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk] path=I:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk backup=I:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk] path=I:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk backup=I:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater] --a------ 2007-06-19 10:07 2321600 I:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager] --a------ 2007-08-27 16:19 4670704 I:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "I:\\Program Files\\Messenger\\msmsgs.exe"= "I:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "I:\\Program Files\\MSN Messenger\\livecall.exe"= "I:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"= "I:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "I:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "I:\\Program Files\\uTorrent\\uTorrent.exe"= "I:\\Program Files\\iTunes\\iTunes.exe"=
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;I:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-02-27 08:14] S0 Wineh46;Wineh46;I:\WINDOWS\system32\Drivers\Wineh46.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{292062a0-5a98-11dd-a924-000ea6a7bea5}] \Shell\AutoRun\command - K:\CDGO.exe . Contents of the 'Scheduled Tasks' folder
2008-07-28 I:\WINDOWS\Tasks\AppleSoftwareUpdate.job - I:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
2008-07-26 I:\WINDOWS\Tasks\Uniblue SpyEraser Nag.job - I:\Program Files\Uniblue\SpyEraser\SpyEraser.exe []
2008-07-25 I:\WINDOWS\Tasks\Uniblue SpyEraser.job - I:\Program Files\Uniblue\SpyEraser\SpyEraser.exe [] . . ------- Supplementary Scan ------- . R0 -: HKCU-Main,Start Page = hxxp://www.liverpoolfc.tv/ O8 -: E&xport to Microsoft Excel - I:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2008-07-29 19:31:58 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
************************************************************************** . ------------------------ Other Running Processes ------------------------ . I:\WINDOWS\system32\LEXBCES.EXE I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe I:\Program Files\CyberLink\Shared Files\RichVideo.exe I:\Program Files\Java\jre1.5.0_03\bin\jucheck.exe I:\WINDOWS\system32\wscntfy.exe I:\Program Files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2008-07-29 19:36:27 - machine was rebooted ComboFix-quarantined-files.txt 2008-07-29 23:36:24
Pre-Run: 7,659,851,776 bytes free Post-Run: 8,114,688,000 bytes free
211 --- E O F --- 2008-07-09 07:01:42
What do I do next sir?
|