Thanks for the quick replies Gecko!
---------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:22, on 2008-06-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
C:\WINDOWS\TEMP\OX9913.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\LANMessage.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\X3watch\x3watch.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\Client Server Security Agent\pccntupd.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\cdigiovanna\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://internetsearchservice.comR1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
http://internetsearchservice.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://internetsearchservice.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://internetsearchservice.com/ie6.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
O2 - BHO: (no name) - {68D2DE65-4ECD-4213-A439-953A544350B3} - C:\WINDOWS\system32\dbgen.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: {d06a37b1-862a-146b-ad24-3367c1a460eb} - {be064a1c-7633-42da-b641-a2681b73a60d} - C:\WINDOWS\system32\defrpqqj.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LANMessage] "C:\LANMessage.exe" Silent
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [x3watch] C:\Program Files\X3watch\x3watch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [d8ea0be2] rundll32.exe "C:\WINDOWS\system32\eueblfyi.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcStd7_0_9 -reboot 1
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Startup: HotSync Manager.LNK = C:\Program Files\palmOne\Hotsync.exe
O4 - Startup: palmOne Registration.lnk = C:\Program Files\palmOne\register.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://www.tdameritrade.comO16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) -
http://www.installshield.com/client/iftwclix.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupda ... 8698301234O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) -
http://h20270.www2.hp.com/ediags/gmn2/i ... ection.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftup ... 8698329576O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) -
http://javadl-esd.sun.com/update/1.5.0/ ... 586-jc.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = CT.local
O17 - HKLM\Software\..\Telephony: DomainName = CT.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = CT.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = CT.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = CT.local
O20 - Winlogon Notify: byXNdefg - C:\WINDOWS\
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
--
End of file - 11311 bytes
-----------------------------------------------------------------------------
ComboFix 08-06-16.5 - cdigiovanna 2008-06-20 21:00:42.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.210 [GMT -7:00]
Running from: C:\Documents and Settings\cdigiovanna\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\cdigiovanna\Desktop\cfscript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINDOWS\system32\dbgen.dll
C:\WINDOWS\system32\drivers\wwlqaabc.dat
C:\WINDOWS\system32\iifDWPfF.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\{EE953C0A-67F8-42A6-998A-1D35B1EA6CB9}
C:\Documents and Settings\All Users\Application Data\{EE953C0A-67F8-42A6-998A-1D35B1EA6CB9}\BulkSMSFromPC2007Setup.dat
C:\Documents and Settings\All Users\Application Data\{EE953C0A-67F8-42A6-998A-1D35B1EA6CB9}\BulkSMSFromPC2007Setup.exe
C:\Documents and Settings\All Users\Application Data\{EE953C0A-67F8-42A6-998A-1D35B1EA6CB9}\BulkSMSFromPC2007Setup.msi
C:\Documents and Settings\All Users\Application Data\{EE953C0A-67F8-42A6-998A-1D35B1EA6CB9}\BulkSMSFromPC2007Setup.par
C:\Documents and Settings\All Users\Application Data\{EE953C0A-67F8-42A6-998A-1D35B1EA6CB9}\BulkSMSFromPC2007Setup.res
C:\Documents and Settings\All Users\Application Data\{EE953C0A-67F8-42A6-998A-1D35B1EA6CB9}\instance.dat
C:\Documents and Settings\All Users\Application Data\{EE953C0A-67F8-42A6-998A-1D35B1EA6CB9}\mia.dll
C:\Documents and Settings\All Users\Application Data\{EE953C0A-67F8-42A6-998A-1D35B1EA6CB9}\setup.bmp
C:\WINDOWS\BMdbd9387e.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\FfPWDfii.ini
C:\WINDOWS\system32\FfPWDfii.ini2
C:\WINDOWS\system32\iifDWPfF.dll
C:\WINDOWS\system32\iyflbeue.ini
C:\WINDOWS\system32\okmijutw.dll
C:\WINDOWS\system32\osndtxpa.dll
C:\WINDOWS\system32\spbqnhep.ini
C:\WINDOWS\system32\xrfanpyf.dll
C:\WINDOWS\system32\drivers\wwlqaabc.dat . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_nxjseqsl
-------\Service_nxjseqsl
((((((((((((((((((((((((( Files Created from 2008-05-21 to 2008-06-21 )))))))))))))))))))))))))))))))
.
2008-06-20 19:43 . 2008-06-20 19:43 86,016 --a------ C:\WINDOWS\system32\eueblfyi.dll
2008-06-20 19:40 . 2008-06-20 19:40 101,888 --a------ C:\WINDOWS\system32\defrpqqj.dll
2008-06-18 17:21 . 2008-06-18 17:21 <DIR> d-------- C:\Program Files\iTunes
2008-06-18 17:21 . 2008-06-18 17:21 <DIR> d-------- C:\Program Files\iPod
2008-06-18 17:14 . 2008-06-18 17:14 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-06-11 10:34 . 2008-06-11 10:34 <DIR> d-------- C:\Documents and Settings\cdigiovanna\Application Data\Uniblue
2008-06-09 21:37 . 2008-06-09 21:37 <DIR> d-------- C:\Program Files\MAPILab Ltd
2008-06-09 21:37 . 2008-06-09 21:37 <DIR> d-------- C:\Program Files\Common Files\Outlook Security Manager
2008-06-09 21:37 . 2008-06-09 21:37 <DIR> d-------- C:\Program Files\Common Files\MAPILab Ltd
2008-06-09 21:37 . 2008-06-09 21:37 <DIR> d-------- C:\Documents and Settings\cdigiovanna\Application Data\MAPILab Ltd
2008-06-08 18:23 . 2008-06-08 18:23 <DIR> d-------- C:\Documents and Settings\cdigiovanna\Application Data\Management-Ware Solutions Inc
2008-06-08 18:23 . 2008-06-08 18:23 <DIR> d-------- C:\Documents and Settings\cdigiovanna\Application Data\Management-Ware
2008-06-08 18:22 . 2008-06-08 18:22 <DIR> d-------- C:\Program Files\Management-Ware
2008-05-29 13:35 . 2008-05-29 13:35 <DIR> d-------- C:\Documents and Settings\Administrator
2008-05-27 21:04 . 2008-06-04 07:39 10,752 --a------ C:\WINDOWS\DCEBoot.exe
2008-05-27 14:51 . 2008-05-27 14:51 <DIR> d-------- C:\Program Files\SmartDraw 7
2008-05-27 13:48 . 2008-05-27 17:14 <DIR> d-------- C:\Program Files\SmartDraw 2007
2008-05-27 10:50 . 2008-05-27 10:50 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-05-27 10:50 . 2008-05-27 10:50 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-05-26 21:55 . 2008-05-28 14:59 <DIR> d-------- C:\WINDOWS\system32\824223
2008-05-26 13:52 . 2008-05-27 17:15 <DIR> d-------- C:\Documents and Settings\cdigiovanna\System
2008-05-26 13:52 . 2008-05-30 16:47 <DIR> d-------- C:\Documents and Settings\cdigiovanna\Application Data\SmartDraw
2008-05-26 13:44 . 2008-06-04 12:12 <DIR> d-------- C:\Program Files\SmartDraw 2008
2008-05-25 20:59 . 2008-06-01 16:49 488 --a------ C:\hpfr5550.xml
2008-05-21 09:07 . 2008-05-21 09:07 <DIR> d-------- C:\Program Files\Citrix
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-19 00:18 --------- d-----w C:\Program Files\QuickTime
2008-06-18 04:25 --------- d-----w C:\Program Files\Apple Software Update
2008-06-13 17:04 --------- d-----w C:\Program Files\Trend Micro
2008-05-28 20:49 --------- d-----w C:\Documents and Settings\cdigiovanna\Application Data\LimeWire
2008-05-27 05:16 --------- d-----r C:\Program Files\My Music
2008-05-17 22:43 --------- d-----w C:\Documents and Settings\cdigiovanna\Application Data\Snapfish
2008-05-13 00:03 --------- d-----w C:\Documents and Settings\cdigiovanna\Application Data\AdobeUM
2008-04-24 19:58 --------- d-----w C:\Program Files\MSECache
2007-04-24 17:41 1,133 ----a-w C:\Program Files\INSTALL.LOG
2001-09-29 01:00 164,864 ----a-w C:\Program Files\UNWISE.EXE
.
((((((((((((((((((((((((((((( snapshot@2008-06-18_14.41.55.96 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-18 21:26:35 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-21 04:05:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-19 00:22:18 102,400 ----a-r C:\WINDOWS\Installer\{9F70BF98-003C-491D-81FC-FF9792206AF0}\iTunesIco.exe
+ 2008-06-18 22:08:08 1,812 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{F55B47DA-365F-473C-80E2-29CB78FCC848}.bin
- 2008-06-18 18:44:48 7,905 ---h--w C:\WINDOWS\system\data.dat
+ 2008-06-21 02:37:48 8,994 ---h--w C:\WINDOWS\system\data.dat
- 2006-09-19 23:44:04 15,664 ----a-w C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
+ 2008-01-29 19:01:28 16,168 ----a-w C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
+ 2008-02-18 18:16:24 30,464 -c--a-w C:\WINDOWS\system32\DRVSTORE\usbaapl_4351B7DAFF62FD33510D77DFAE3CF8CC82517571\usbaapl.sys
- 2006-10-04 02:47:52 109,360 ----a-w C:\WINDOWS\system32\GEARAspi.dll
+ 2008-01-29 19:02:30 107,368 ----a-w C:\WINDOWS\system32\GEARAspi.dll
+ 2007-03-29 16:10:02 214,712 ----a-w C:\WINDOWS\TEMP\OX9913.EXE
+ 2006-12-02 05:54:32 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-02 05:54:34 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-02 05:54:32 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{68D2DE65-4ECD-4213-A439-953A544350B3}]
C:\WINDOWS\system32\dbgen.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{be064a1c-7633-42da-b641-a2681b73a60d}]
2008-06-20 19:40 101888 --a------ C:\WINDOWS\system32\defrpqqj.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Offline Files]
@={750fdf0e-2a26-11d1-a3ea-080036587f03}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
{47833539-D0C5-4125-9FA8-0819E2EAAC93}
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"Free Download Manager"="C:\Program Files\Free Download Manager\fdm.exe" [ ]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-25 01:40 7569408]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-31 16:01 761946]
"LANMessage"="C:\LANMessage.exe" [2001-05-10 12:34 110592]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-23 11:38 131072]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-18 11:29 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"x3watch"="C:\Program Files\X3watch\x3watch.exe" [2005-08-13 08:27 376832]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" [2006-10-12 04:10 49263]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 20:52 483328]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" [2007-10-29 12:17 398784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-16 14:25 185784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-06-02 11:13 267048]
"d8ea0be2"="C:\WINDOWS\system32\eueblfyi.dll" [2008-06-20 19:43 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 20:29 39264]
C:\Documents and Settings\cdigiovanna\Start Menu\Programs\Startup\
DING!.lnk - C:\Program Files\Southwest Airlines\Ding\Ding.exe [2006-06-22 15:15:48 462848]
HotSync Manager.LNK - C:\Program Files\palmOne\Hotsync.exe [2004-06-09 14:27:34 471040]
palmOne Registration.lnk - C:\Program Files\palmOne\register.exe [2005-09-19 13:20:36 2367488]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-BA7E-100000000002}\SC_Acrobat.exe [2007-01-24 11:34:16 25214]
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-09-24 13:14:56 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
HOTSYNCSHORTCUTNAME.lnk - C:\Program Files\palmOne\Hotsync.exe [2004-06-09 14:27:34 471040]
hp psc 2000 Series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2003-04-09 17:41:38 323646]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-09 18:11:12 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byXNdefg]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 nxjseqsl;nxjseqsl;C:\WINDOWS\system32\drivers\wwlqaabc.dat []
R1 oreans32;oreans32;C:\WINDOWS\system32\drivers\oreans32.sys [2006-10-09 00:30]
S3 Ntpifdc;Ntpifdc;C:\WINDOWS\system32\drivers\ipfltdrv.sys [2001-08-23 05:00]
S3 pnetmdm;PdaNet Modem;C:\WINDOWS\system32\DRIVERS\pnetmdm.sys [2004-12-27 01:35]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e963019-f798-11db-99b9-0016d30913dc}]
\Shell\AutoRun\command - E:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{28ddffe6-9506-11db-9987-0016d30913dc}]
\Shell\AutoRun\command - D:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd001536-e9cb-11db-99b2-0016d30913dc}]
\Shell\AutoRun\command - ie.exe
\Shell\explore\Command - ie.exe
\Shell\open\Command - ie.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{db63a7d2-c84f-11dc-ac16-0016d30913dc}]
\Shell\AutoRun\command - D:\Installer.exe
*Newly Created Service* - NXJSEQSL
.
Contents of the 'Scheduled Tasks' folder
"2008-06-19 00:02:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-19 21:00:06 C:\WINDOWS\Tasks\cdigiovannaBU.job"
- C:\Backup Script\cdigiovannaBU.bat
"2008-06-05 23:01:14 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2200 series#1207263625.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
"2008-06-21 04:08:32 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-20 21:07:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\iyflbeue.ini 294 bytes
scan completed successfully
hidden files: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\nxjseqsl]
"ImagePath"="system32\drivers\wwlqaabc.dat"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\Client Server Security Agent\NTRtScan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\Client Server Security Agent\TmListen.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
C:\WINDOWS\TEMP\OX9913.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\Client Server Security Agent\PccNTUpd.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2008-06-20 21:20:04 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-21 04:19:58
ComboFix2.txt 2008-06-19 20:39:28
ComboFix3.txt 2008-06-18 21:59:33
ComboFix4.txt 2008-06-18 21:42:21
Pre-Run: 25,659,228,160 bytes free
Post-Run: 25,650,257,920 bytes free
234 --- E O F --- 2007-12-07 06:45:35