Hi,
Here are the logs:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:22:02, on 2008-3-28
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Prime95\Prime95.exe
C:\Program Files\NetMeeting\mstinit.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Alcohol.exe Autorun] C:\Program Files\Alcohol Soft\Alcohol 120\Alcohol.exe /startup
O4 - HKLM\..\Run: [LexPPS.exe] C:\WINNT\system32\lexpps.exe
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKUS\S-1-5-21-57989841-920026266-1202660629-500\..\Run: [internat.exe] internat.exe (User '?')
O4 - HKUS\S-1-5-21-57989841-920026266-1202660629-500\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork (User '?')
O4 - HKUS\S-1-5-21-57989841-920026266-1202660629-500\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount (User '?')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINNT\system32\Macromed\Flash\FlashUtil9d.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java æŽ§åˆ¶å° - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINNT\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINNT\bdoscandel.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} -
http://www.worldwinner.com/games/v46/scrab...rabblecubes.cabO16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
http://downloads.ewido.net/ewidoOnlineScan.cabO16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} -
http://www.worldwinner.com/games/v47/share...GamesLoader.cabO16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} -
http://www.worldwinner.com/games/v50/pool/pool.cabO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) -
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cabO16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} -
http://www.worldwinner.com/games/v57/bjattack/bja.cabO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scan8/oscan8.cabO16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} -
http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cabO16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} -
http://www.worldwinner.com/games/v41/freecell/freecell.cabO16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
http://ca.com/us/securityadvisor/virusinfo/webscan.cabO16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} -
http://www.worldwinner.com/games/shared/wwlaunch.cabO16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} -
http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cabO16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} -
http://www.worldwinner.com/games/v46/sol/sol.cabO16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} -
http://www.worldwinner.com/games/v41/hangman/hangman.cabO16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} -
http://a532.g.akamai.net/f/532/6712/5m/vir...l/installer.exeO16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} -
http://www.worldwinner.com/games/v47/wwspades/wwspades.cabO16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) -
http://driveragent.com/files/driveragent.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINNT\System32\svchost.exe (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: COM+ Event System (EventSystem) - Unknown owner - C:\WINNT\System32\svchost.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: Network Connections (Netman) - Unknown owner - C:\WINNT\System32\svchost.exe (file missing)
O23 - Service: Removable Storage (NtmsSvc) - Unknown owner - C:\WINNT\system32\svchost.exe (file missing)
O23 - Service: Prime95 Service - Unknown owner - C:\Program Files\Prime95\Prime95.exe
O23 - Service: Remote Access Auto Connection Manager (RasAuto) - Unknown owner - C:\WINNT\systom32\svchost.exe (file missing)
O23 - Service: Remote Access Connection Manager (RasMan) - Unknown owner - C:\WINNT\System32\svchost.exe (file missing)
O23 - Service: Remote Procedure Call (RPC) (RpcSs) - Unknown owner - C:\WINNT\system32\svchost.exe (file missing)
O23 - Service: Remote Procedure Call (TPM) (RPCT) - Remote ABC - C:\Program Files\NetMeeting\mstinit.exe
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINNT\System32\svchost.exe (file missing)
O23 - Service: System Event Notification (SENS) - Unknown owner - C:\WINNT\system32\svchost.exe (file missing)
O23 - Service: Internet Connection Sharing (SharedAccess) - Unknown owner - C:\WINNT\System32\svchost.exe (file missing)
O23 - Service: Telephony (TapiSrv) - Unknown owner - C:\WINNT\System32\svchost.exe (file missing)
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINNT\system32\svchost.exe (file missing)
O23 - Service: Wireless Configuration (WZCSVC) - Unknown owner - C:\WINNT\System32\svchost.exe (file missing)
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ADMINI~1.GU-/LOCALS~1/Temp/msoclip1/02/clip_image002.jpg
O24 - Desktop Component 1: (no name) - C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\My Documents\My Pictures\let it snow.bmp
--
End of file - 7587 bytes
-------------------------------------------------------------------------------------------------------------------------------------
ComboFix 08-03-27.1 - Administrator 2008-03-28 16:05:32.1 - [color=\"red\"]
FAT32[/color]x86
Running from: C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\桌é¢\ComboFix.exe
[color=\"red\"]
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINNT\system32\drivers\npf.sys
C:\WINNT\system32\eadeafbdbafed_z.dll
C:\WINNT\system32\grecorder.dll
C:\WINNT\system32\nbjs.dll
C:\WINNT\system32\Packet.dll
C:\WINNT\system32\pthreadVC.dll
C:\WINNT\system32\WanPacket.dll
C:\WINNT\system32\wpcap.dll
C:\WINNT\systom32
C:\WINNT\systom32\svchost.exe
C:\WINNT\Web\default.htt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-28 )))))))))))))))))))))))))))))))
.
2008-03-27 21:42 . 08-03-28 10:07 923,740 ---h----- C:\WINNT\ShellIconCache
2008-03-26 17:50 . 08-03-26 17:50 <DIR> d-------- C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\DoctorWeb
2008-03-25 16:57 . 08-03-25 17:06 250 --a------ C:\WINNT\gmer.ini
2008-03-25 16:12 . 08-03-25 16:12 36,433 --a------ C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\catchme.zip
2008-03-25 16:09 . 08-03-25 16:09 <DIR> d-------- C:\WINNT\ERUNT
2008-03-25 16:07 . 08-03-25 06:29 <DIR> d-------- C:\SDFix
2008-03-24 19:47 . 03-06-19 15:05 12,592 --a------ C:\WINNT\system32\drivers\usbscan.sys
2008-03-24 19:47 . 03-06-19 15:05 12,592 --a------ C:\WINNT\system32\dllcache\usbscan.sys
2008-03-24 19:43 . 08-03-24 19:43 <DIR> d-------- C:\Lexmark X74-X75
2008-03-24 11:55 . 08-03-24 11:55 <DIR> d-------- C:\Documents and Settings\All Users.WINNT\Application Data\Kaspersky Lab Setup Files
2008-03-24 10:32 . 08-03-24 13:29 187 --a------ C:\JANUS.ERR
2008-03-24 10:22 . 08-03-24 10:23 1,435 --a------ C:\WINNT\imsins.BAK
2008-03-23 11:36 . 08-03-23 11:36 <DIR> d-------- C:\kav
2008-03-23 11:08 . 08-03-23 11:08 217,088 --a------ C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\sysclean.exe
2008-03-22 09:53 . 08-03-22 09:53 <DIR> d-------- C:\Program Files\jv16 PowerTools 2008
2008-03-22 09:53 . 08-03-22 09:53 23 --a------ C:\WINNT\system32\dfaa6_z.ocx
2008-03-19 15:58 . 08-03-19 15:58 <DIR> d-------- C:\Program Files\RADVideo
2008-03-15 10:04 . 08-03-15 10:04 <DIR> d-------- C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\Moyea
2008-03-15 10:03 . 08-03-15 10:03 <DIR> d-------- C:\Program Files\Moyea
2008-03-14 12:33 . 08-03-16 13:14 8,192 --a------ C:\WINNT\system32\1.hiv
2008-03-14 09:37 . 08-03-14 09:37 <DIR> d-------- C:\Program Files\Deskshare
2008-03-12 09:54 . 08-03-12 09:54 <DIR> d-------- C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\DemoCreator
2008-03-12 09:53 . 08-03-12 09:53 <DIR> d-------- C:\Program Files\Wondershare
2008-03-12 09:49 . 08-03-12 09:49 <DIR> d-------- C:\Program Files\Wisdom-soft AutoScreenRecorder
2008-03-11 17:24 . 02-12-11 18:50 301,712 --a------ C:\WINNT\system32\drmclien.dll
2008-03-11 17:24 . 02-12-11 18:50 301,712 --a------ C:\WINNT\system32\dllcache\drmclien.dll
2008-03-11 17:24 . 02-12-11 17:34 82,432 --a------ C:\WINNT\system32\drmstor.dll
2008-03-11 17:24 . 02-12-11 17:34 82,432 --a------ C:\WINNT\system32\dllcache\drmstor.dll
2008-03-11 17:24 . 02-12-11 17:34 9,728 --a------ C:\WINNT\system32\dllcache\npwmsdrm.dll
2008-03-11 12:18 . 08-03-11 12:18 <DIR> d-------- C:\Program Files\PTAutoRun
2008-03-11 12:17 . 08-03-11 12:18 249,856 --------- C:\WINNT\Setup1.exe
2008-03-11 12:17 . 08-03-11 12:17 73,216 --a------ C:\WINNT\temp.000
2008-03-11 12:01 . 08-03-11 12:01 <DIR> d-------- C:\Program Files\free-downloads.net
2008-03-11 12:01 . 08-03-11 12:01 <DIR> d-------- C:\Program Files\Conduit
2008-03-11 11:49 . 08-03-11 11:49 <DIR> d-------- C:\Program Files\PhotoActions
2008-03-10 19:31 . 08-03-10 19:31 <DIR> d-------- C:\INF-Tool
2008-03-10 19:21 . 08-03-10 19:21 <DIR> d-------- C:\Program Files\Screen Recorder Gold
2008-03-10 18:42 . 08-03-10 18:42 <DIR> d-------- C:\Fraps
2008-03-10 18:27 . 08-03-10 18:27 <DIR> d-------- C:\Program Files\7-Zip
2008-03-10 18:14 . 08-03-10 18:14 <DIR> d-------- C:\install
2008-03-10 14:00 . 08-03-10 14:00 <DIR> d-------- C:\IV
2008-03-10 13:59 . 08-03-10 18:43 6,881 --a------ C:\IVWINST.RPT
2008-03-09 09:49 . 08-03-09 09:49 <DIR> d-------- C:\Program Files\TechSmith
2008-03-09 09:49 . 08-03-09 09:49 <DIR> d-------- C:\Documents and Settings\All Users.WINNT\Application Data\TechSmith
2008-03-06 19:09 . 08-03-06 19:09 <DIR> d-------- C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\AdobeUM
2008-03-05 19:38 . 08-03-05 19:38 <DIR> d-------- C:\WINNT\Cache
2008-03-05 16:13 . 08-03-05 16:13 <DIR> d-------- C:\Program Files\CamStudio
2008-03-02 15:48 . 08-03-02 15:48 <DIR> d-------- C:\Program Files\Hypercam2
2008-03-02 15:47 . 07-10-22 15:09 106,496 --a------ C:\Program Files\CamRes2.dll
2008-03-02 10:34 . 08-03-02 10:34 <DIR> d-------- C:\Program Files\ZD Soft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-18 16:25 --------- d-----w C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\ABBYY
2008-02-18 15:57 --------- d-----w C:\Program Files\NJStar Chinese WP
2008-02-18 15:55 --------- d-----w C:\Program Files\Google
2008-02-18 03:28 --------- d-----w C:\Program Files\SoftwareForLitSupport
2008-02-18 00:26 --------- d-----w C:\Program Files\Common Files\Download Manager
2008-02-18 00:22 72,192 ----a-w C:\WINNT\cadkasdeinst01e.exe
2008-02-18 00:22 --------- d-----w C:\Program Files\OCR-TextScan 2 Word 1
2008-02-17 23:40 --------- d-----w C:\Program Files\Cuneiform 6.0
2008-02-17 22:45 --------- d-----w C:\Program Files\MagicDisc
2008-02-17 22:35 716,272 ----a-w C:\WINNT\system32\drivers\sptd.sys
2008-02-17 22:35 --------- d-----w C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\DAEMON Tools
2008-02-17 19:58 --------- d-----w C:\Program Files\Microsoft Office 2003 Developer Resources
2008-02-17 18:58 --------- d-----w C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\NJStar
2008-02-12 06:36 92,544 ----a-w C:\WINNT\system32\drivers\mcdbus.sys
2008-02-10 05:37 --------- d-----w C:\Documents and Settings\All Users.WINNT\Application Data\SUPERAntiSpyware.com
2008-02-05 23:04 --------- d-----w C:\Program Files\Trend Micro
2008-02-03 19:04 --------- d-----w C:\Program Files\Fortinet
2008-02-03 18:52 --------- d-----w C:\Program Files\Pocket Tanks
2008-02-03 18:51 --------- d-----w C:\Program Files\Pocket Tanks Deluxe
2008-02-03 17:34 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-03 06:50 --------- d-----w C:\Program Files\ImmenseTech
2008-02-02 17:40 --------- d-----w C:\Program Files\IObit
2008-01-30 01:37 --------- d-----w C:\Program Files\Prime95
2008-01-28 23:20 --------- d-----w C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Application Data\ImgBurn
2008-01-20 00:48 25,992 ----a-w C:\WINNT\system32\pgdfgsvc.exe
2008-01-16 23:25 52,736 ----a-w C:\WINNT\ipuninst.exe
2008-01-14 12:52 81,920 ----a-w C:\WINNT\system32\frapsvid.dll
2008-01-09 03:42 28,418 ----a-w C:\Program Files\lcdfont.zip
2008-01-09 03:42 13,234 ----a-w C:\Program Files\backfont.zip
2008-01-07 23:23 6,625,744 ----a-w C:\Program Files\FontCreatorSetup.exe
2007-12-28 22:43 139,264 ----a-w C:\WINNT\War3Unin.exe
2007-11-30 04:56 63 ----a-w C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\B50LOAD.DAT
2007-10-31 17:52 1,044,173 ----a-w C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\testmh240.exe
2007-08-29 15:55 37,475 ----a-w C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\Driver_Magician_3.22.zip
2007-07-20 18:03 20 ---h--w C:\Documents and Settings\All Users.WINNT\Application Data\PKP_DLec.DAT
2007-06-18 19:45 942,891 ----a-w C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\error-repair.exe
2006-12-14 17:18 3,274 ----a-w C:\Program Files\agreement.txt
2005-07-03 22:45 271 ---h--w C:\Program Files\desktop.ini
2005-07-03 22:45 21,931 ---h--w C:\Program Files\folder.htt
2003-09-30 15:46 5,120 ----a-w C:\Program Files\ACDSee.sip
2003-09-30 13:20 1,741 ----a-w C:\Program Files\ACDSee60Tips.tip
2000-01-10 19:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
1999-06-24 18:49 587 ----a-w C:\Program Files\8-44100d.wav
1999-06-24 18:49 421 ----a-w C:\Program Files\8-44100u.wav
1999-06-24 18:47 317 ----a-w C:\Program Files\8-22050d.wav
1999-06-24 18:47 225 ----a-w C:\Program Files\8-22050u.wav
1999-06-24 18:46 183 ----a-w C:\Program Files\8-11025d.wav
1999-06-24 18:46 135 ----a-w C:\Program Files\8-11025u.wav
1999-06-24 18:44 127 ----a-w C:\Program Files\8-8000u.wav
1999-06-24 18:43 151 ----a-w C:\Program Files\8-8000d.wav
1999-06-24 18:41 220 ----a-w C:\Program Files\16-8000u.wav
1999-06-24 18:40 260 ----a-w C:\Program Files\16-8000d.wav
1999-06-24 18:38 956 ----a-w C:\Program Files\16-44100u.wav
1999-06-24 18:37 1,186 ----a-w C:\Program Files\16-44100d.wav
1999-06-24 18:34 652 ----a-w C:\Program Files\16-22050d.wav
1999-06-24 18:34 442 ----a-w C:\Program Files\16-22050u.wav
1999-06-24 17:54 340 ----a-w C:\Program Files\16-11025d.wav
1999-06-24 17:50 326 ----a-w C:\Program Files\16-11025u.wav
1996-12-19 21:26 25 ----a-w C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\TSGUIDE.BAT
1996-12-19 21:24 22 ----a-w C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\README.BAT
1996-12-19 00:34 487,850 ----a-w C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\L2DOSFIX.EXE
1996-12-19 00:34 347,178 ----a-w C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\L2WINFIX.EXE
1996-10-15 17:40 291,600 ----a-w C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\WININET.DLL
1996-07-29 19:11 733,296 ----a-w C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\OPENGL32.DLL
1996-07-29 19:09 139,712 ----a-w C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\GLU32.DLL
1995-10-13 03:42 423,424 ----a-r C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\SU27.EXE
1995-10-09 03:54 25 ----a-r C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\LOAD.BAT
1995-06-05 10:10 64,880 ----a-r C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\B50LOAD.EXE
1993-07-16 18:53 35,614 ----a-r C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\DOWNLOAD.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [00-01-10 12:00 21264 C:\WINNT\system32\internat.exe]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [07-03-05 14:57 1103480]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [08-02-22 04:30 217544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 15:05 111376 C:\WINNT\system32\mobsync.exe]
"LexPPS.exe"="C:\WINNT\system32\lexpps.exe" [02-10-14 14:00 174592]
"Lexmark X74-X75"="C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe" [02-10-14 14:09 57344]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="C:\WINNT\system32\Macromed\Flash\FlashUtil9d.exe" [07-06-11 13:04 190696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= C:\Documents and Settings\Administrator.GU-3R3LEUQBGPNO\My Documents\My Pictures\let it snow.bmp
FriendlyName=
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [06-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 07-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Avi Player]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotSexy_ca]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Playboy_ca]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"NoteBurner"=C:\Program Files\NoteBurner\VTBurnerGUI.exe /silence
"FortiClient"="C:\Program Files\Fortinet\FortiClient\FortiClient.exe" /minimize
*Newly Created Service* - SHAREDACCESS
.
Contents of the 'Scheduled Tasks' folder
"2007-09-28 19:31:56 C:\WINNT\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-03-18 00:25:22 C:\WINNT\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-28 16:16:13
Windows 5.0.2195 Service Pack 4 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINNT\system32\winlogon.exe
-> C:\WINNT\system32\tsd32.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Prime95\Prime95.exe
C:\Program Files\NetMeeting\mstinit.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\conime.exe
.
**************************************************************************
.
Completion time: 2008-03-28 16:18:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-28 23:18:22
Pre-Run: 300,048,384 bytes free
Post-Run: 251,138,048 bytes free
.
2008-03-12 18:03:18 --- E O F ---
Thanks Again!
Waterburn