I followed your instructions, and ComboFix notifies me that I have a rootkit. It tells me to take notes of the 2 following files in bold as it may be useful to the future:
C:\Windows\System32\Drivers\
goapdxydebxne.sysC:\Windows\System32\
goapdxyidoesuh.dllAfter finding Rootkit in Wikipedia, it says that: "Often, they are Trojans as well, thus fooling users into believing they are safe to run on their systems. Techniques used to accomplish this can include concealing running processes from monitoring programs, or hiding files or system data from the operating system. Rootkits may also install a 'backdoor' in a system by replacing the login mechanism (such as /bin/login) with an executable that accepts a secret login combination which in turn allows an attacker to access the system regardless of changes to the actual accounts on the system."
This really scares me. How can I be positive that my pc is no longer vulnerable?
"Removal
Many hold this to be forbiddingly impractical. Even if the nature and composition of a rootkit is known, the time and effort of a system administrator with the necessary skills or experience would be better spent re-installing the operating system from scratch. Since drive imaging software makes the task of restoring a “clean” OS installation almost trivial, there is no good reason to try to dig a rootkit out directly."
What do you recommend? Also, I don't want to waste too much of your time, so should I just reimage my laptop?
Here is the ComboFix Log:
ComboFix 09-02-04.04 - Owner 2009-02-05 7:45:55.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.291 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
FW: ESET Personal firewall *enabled*
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\program files\Mozilla Firefox\components\iamfamous.dll
c:\windows\system32\drivers\gaopdxydebxnxe.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\gaopdxyidoesuh.dll
c:\windows\system32\packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\tmp.reg
c:\windows\system32\wpcap.dll
D:\Autorun.inf
D:\install.exe
d:\recycler\S-4-4-37-100031774-100012292-100001058-2517.com
d:\recycler\S-5-5-35-100000964-100007501-100028479-2612.com
d:\recycler\S-7-1-57-100027044-100026302-100005975-1601.com
d:\recycler\S-7-6-50-100015339-100009933-100013886-5443.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gaopdxserv.sys
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2009-01-05 to 2009-02-05 )))))))))))))))))))))))))))))))
.
2009-02-05 07:50 . 2009-02-05 07:50 <DIR> d--hs---- C:\FOUND.000
2009-02-04 22:29 . 2008-04-13 13:47 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2009-02-04 22:29 . 2008-04-13 13:47 25,856 --a------ c:\windows\system32\dllcache\usbprint.sys
2009-02-03 20:27 . 2009-02-03 20:27 <DIR> d-------- c:\program files\Trend Micro
2009-02-03 20:20 . 2006-10-26 19:58 30,512 --a------ c:\windows\system32\mdimon.dll
2009-02-03 20:19 . 2009-02-03 20:19 <DIR> d-------- c:\program files\Microsoft Works
2009-02-03 20:18 . 2009-02-03 20:18 <DIR> d-------- c:\program files\Microsoft.NET
2009-02-03 20:16 . 2009-02-05 07:45 4 --a------ c:\windows\system32\gaopdxcounter
2009-02-03 20:15 . 2009-02-03 20:15 <DIR> d-------- c:\windows\SHELLNEW
2009-02-03 20:14 . 2009-02-03 20:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-03 20:13 . 2009-02-03 20:13 <DIR> dr-h----- C:\MSOCache
2009-02-03 20:08 . 2009-02-03 20:08 <DIR> d-------- c:\program files\Alcohol Soft
2009-02-03 20:01 . 2009-02-03 20:01 717,296 --a------ c:\windows\system32\drivers\sptd.sys
2009-02-03 17:25 . 2009-02-03 17:25 <DIR> d-------- c:\windows\Sun
2009-02-03 17:25 . 2009-02-03 17:25 <DIR> d-------- c:\program files\SystemRequirementsLab
2009-02-03 17:25 . 2009-02-03 17:25 <DIR> d-------- c:\documents and settings\Owner\Application Data\SystemRequirementsLab
2009-02-03 15:48 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-02-03 15:48 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-02-03 15:48 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-02-02 22:09 . 2009-02-02 22:09 <DIR> d-------- c:\documents and settings\Owner\Application Data\AdobeUM
2009-02-02 20:13 . 2009-02-02 20:14 <DIR> d-------- c:\documents and settings\Owner\Tracing
2009-02-02 20:12 . 2009-02-02 20:12 <DIR> d-------- c:\program files\Microsoft
2009-02-02 20:11 . 2009-02-02 20:12 <DIR> d-------- c:\program files\Windows Live SkyDrive
2009-02-02 20:11 . 2009-02-02 20:11 <DIR> d-------- c:\program files\Windows Live
2009-02-02 19:14 . 2009-02-02 19:14 <DIR> d-------- c:\program files\Common Files\Windows Live
2009-02-02 16:51 . 2003-07-19 10:17 5,174 --a------ c:\windows\system32\nppt9x.vxd
2009-02-02 16:51 . 2005-01-03 01:43 4,682 --a------ c:\windows\system32\npptNT2.sys
2009-02-02 16:50 . 2009-02-02 16:50 <DIR> d-------- c:\program files\Common Files\INCA Shared
2009-02-02 15:57 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2009-02-02 15:57 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\dllcache\mouhid.sys
2009-02-02 15:56 . 2004-08-04 05:00 9,600 --a------ c:\windows\system32\drivers\hidusb.sys
2009-02-01 20:27 . 2009-02-01 20:27 <DIR> d-------- c:\program files\NCSoft
2009-02-01 20:26 . 2009-02-01 20:27 <DIR> d-------- c:\documents and settings\Owner\Application Data\InstallShield
2009-02-01 20:26 . 2009-02-01 20:26 <DIR> d-------- c:\documents and settings\Owner\Application Data\GetRightToGo
2009-02-01 20:20 . 2009-02-01 20:20 <DIR> d-------- c:\program files\Softnyx
2009-02-01 20:07 . 2009-02-01 20:07 <DIR> d-------- c:\windows\system32\XPSViewer
2009-02-01 20:07 . 2009-02-01 20:07 <DIR> d-------- c:\program files\Reference Assemblies
2009-02-01 20:07 . 2009-02-01 20:07 <DIR> d-------- c:\program files\MSBuild
2009-02-01 20:07 . 2008-07-06 07:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-02-01 20:07 . 2008-07-06 07:06 1,676,288 --------- c:\windows\system32\dllcache\xpssvcs.dll
2009-02-01 20:07 . 2008-07-06 05:50 597,504 --------- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-02-01 20:07 . 2008-07-06 07:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-02-01 20:07 . 2008-07-06 07:06 575,488 --------- c:\windows\system32\dllcache\xpsshhdr.dll
2009-02-01 20:07 . 2008-07-06 07:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-02-01 20:07 . 2008-07-06 07:06 89,088 --------- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-02-01 20:00 . 2009-02-01 20:00 <DIR> d-------- c:\program files\Windows Media Connect 2
2009-02-01 19:58 . 2009-02-01 19:58 <DIR> d-------- c:\windows\system32\drivers\UMDF
2009-02-01 19:55 . 2009-02-01 19:55 <DIR> d-------- c:\windows\system32\URTTemp
2009-02-01 19:20 . 2007-04-17 04:32 2,455,488 --------- c:\windows\system32\dllcache\ieapfltr.dat
2009-02-01 19:20 . 2007-03-08 00:10 991,232 --------- c:\windows\system32\dllcache\ieframe.dll.mui
2009-02-01 19:20 . 2008-10-16 15:38 459,264 --------- c:\windows\system32\dllcache\msfeeds.dll
2009-02-01 19:20 . 2008-10-16 15:38 383,488 --------- c:\windows\system32\dllcache\ieapfltr.dll
2009-02-01 19:20 . 2008-10-16 15:38 267,776 --------- c:\windows\system32\dllcache\iertutil.dll
2009-02-01 19:20 . 2008-10-16 15:38 63,488 --------- c:\windows\system32\dllcache\icardie.dll
2009-02-01 19:20 . 2008-10-16 15:38 52,224 --------- c:\windows\system32\dllcache\msfeedsbs.dll
2009-02-01 19:20 . 2008-10-16 08:11 13,824 --------- c:\windows\system32\dllcache\ieudinit.exe
2009-02-01 19:19 . 2008-10-16 15:38 6,066,176 --------- c:\windows\system32\dllcache\ieframe.dll
2009-02-01 19:10 . 2009-02-01 19:10 <DIR> d-------- c:\program files\MSXML 4.0
2009-02-01 19:05 . 2008-08-14 05:11 2,189,184 --------- c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-01 19:05 . 2008-08-14 05:09 2,145,280 --------- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-01 19:05 . 2008-08-14 04:33 2,023,936 --------- c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-01 19:05 . 2008-09-15 07:12 1,846,400 --------- c:\windows\system32\dllcache\win32k.sys
2009-02-01 19:05 . 2008-10-15 20:00 1,499,136 --------- c:\windows\system32\dllcache\shdocvw.dll
2009-02-01 19:05 . 2008-10-16 15:38 1,160,192 --------- c:\windows\system32\dllcache\urlmon.dll
2009-02-01 19:05 . 2008-10-16 15:38 826,368 --------- c:\windows\system32\dllcache\wininet.dll
2009-02-01 19:05 . 2008-06-13 06:05 272,128 --------- c:\windows\system32\dllcache\bthport.sys
2009-02-01 19:04 . 2008-12-13 01:40 3,593,216 --------- c:\windows\system32\dllcache\mshtml.dll
2009-02-01 19:04 . 2008-08-14 04:33 2,066,048 --------- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-01 19:04 . 2008-09-04 12:15 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
2009-02-01 19:04 . 2008-04-11 14:04 691,712 --------- c:\windows\system32\dllcache\inetcomm.dll
2009-02-01 19:04 . 2008-10-24 06:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
2009-02-01 19:04 . 2008-10-15 11:34 337,408 --------- c:\windows\system32\dllcache\netapi32.dll
2009-02-01 19:04 . 2008-12-11 05:57 333,952 --------- c:\windows\system32\dllcache\srv.sys
2009-02-01 19:04 . 2008-05-01 09:33 331,776 --------- c:\windows\system32\dllcache\msadce.dll
2009-02-01 19:04 . 2008-05-08 09:02 203,136 --------- c:\windows\system32\dllcache\rmcast.sys
2009-02-01 18:59 . 2008-04-13 19:12 221,184 --a------ c:\windows\system32\wmpns.dll
2009-02-01 18:50 . 2009-02-01 18:50 <DIR> d-------- c:\windows\system32\scripting
2009-02-01 18:50 . 2009-02-01 18:50 <DIR> d-------- c:\windows\system32\en
2009-02-01 18:50 . 2009-02-01 18:50 <DIR> d-------- c:\windows\system32\bits
2009-02-01 18:50 . 2009-02-01 18:50 <DIR> d-------- c:\windows\l2schemas
2009-02-01 18:47 . 2009-02-01 18:47 <DIR> d-------- c:\windows\ServicePackFiles
2009-02-01 18:39 . 2009-02-01 18:39 <DIR> d-------- c:\windows\EHome
2009-02-01 18:27 . 2004-08-03 22:41 1,309,184 --------- c:\windows\system32\drivers\mtlstrm.sys
2009-02-01 18:26 . 2004-08-03 22:29 1,897,408 --------- c:\windows\system32\drivers\nv4_mini.sys
2009-02-01 18:14 . 2009-02-01 18:14 <DIR> d--h----- c:\windows\$hf_mig$
2009-02-01 18:08 . 2009-02-01 18:08 <DIR> d--hs---- c:\documents and settings\Owner\UserData
2009-02-01 17:40 . 2009-02-01 17:40 <DIR> d-------- c:\documents and settings\Owner\Application Data\ESET
2009-02-01 17:40 . 2008-01-07 14:29 352 --ah----- c:\windows\nod32fixtemdono.reg
2009-02-01 17:37 . 2009-02-01 17:38 <DIR> d-------- c:\program files\ESET
2009-02-01 17:37 . 2009-02-01 17:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2009-02-01 17:33 . 2009-02-01 17:33 <DIR> d-------- c:\program files\Internet Download Manager
2009-02-01 17:33 . 2009-02-01 17:33 <DIR> d-------- c:\documents and settings\Owner\Application Data\IDM
2009-02-01 17:33 . 2009-02-01 17:33 <DIR> d-------- c:\documents and settings\Owner\Application Data\DMCache
2009-02-01 17:21 . 2009-02-01 17:21 <DIR> d-------- c:\program files\Java
2009-02-01 17:21 . 2009-02-01 17:21 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-01 17:21 . 2009-02-01 17:21 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-02-01 09:47 . 2009-02-01 09:47 <DIR> d-------- c:\windows\system32\LogFiles
2009-02-01 08:09 . 2009-02-01 08:09 <DIR> d-------- c:\documents and settings\Owner\Application Data\Webroot
2009-02-01 07:58 . 2009-02-01 07:58 0 --a------ c:\windows\nsreg.dat
2009-01-31 23:39 . 2009-02-05 07:35 0 --------- c:\windows\system32\eRLog.ini
2009-01-31 23:37 . 2009-01-31 23:37 <DIR> d-------- c:\windows\Downloaded Installations
2009-01-31 23:37 . 2005-06-30 16:58 7,296 --a------ c:\windows\system32\drivers\osaio.sys
2009-01-31 23:37 . 2005-01-14 15:57 4,010 --a------ c:\windows\system32\drivers\osanbm.sys
2009-01-31 23:35 . 2005-06-20 10:52 253,952 --a------ c:\windows\system32\Uninstall_eRecovery.exe
2009-01-31 23:35 . 2009-01-31 23:35 92 --a------ c:\windows\GridV.UNI
2009-01-31 23:35 . 2009-01-31 23:35 0 --a------ c:\windows\NT.INI
2009-01-31 23:34 . 2009-01-31 23:34 <DIR> d-------- c:\program files\Launch Manager
2009-01-31 23:34 . 2004-12-10 11:49 147,456 --a------ c:\windows\UNINST32.EXE
2009-01-31 23:34 . 2002-12-19 15:58 49,152 --a------ c:\windows\system32\QtBtLib.dll
2009-01-31 23:34 . 2004-12-08 14:10 16,896 --a------ c:\windows\system32\drivers\DKbFltr.SYS
2009-01-31 23:34 . 2004-12-09 12:04 5,120 --a------ c:\windows\system32\FILTRCOI.DLL
2009-01-31 23:34 . 2009-01-31 23:34 83 --a------ c:\windows\QtZgAcer.UNI
2009-01-31 23:33 . 2004-10-29 18:48 3,222,784 --a------ c:\windows\system32\drivers\w29n51.sys
2009-01-31 23:33 . 2004-10-15 10:20 458,752 --a------ c:\windows\system32\w29NCPA.dll
2009-01-31 23:33 . 2004-11-10 11:06 13 --a------ c:\windows\system32\drivers\verfile.tic
2009-01-31 23:32 . 2009-01-31 23:33 17,119 --a------ c:\windows\system32\drivers\AegisP.sys
2009-01-31 23:31 . 2009-01-31 23:31 <DIR> d-------- c:\program files\WinPCap
2009-01-31 23:31 . 2009-01-31 23:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\Intel
2009-01-31 23:30 . 2009-01-31 23:30 <DIR> d-------- C:\Acer
2009-01-31 23:30 . 2004-09-01 23:57 221,258 --a------ c:\windows\system32\Epm-Po.dll
2009-01-31 23:30 . 2005-04-07 18:08 78,208 --a------ c:\windows\system32\drivers\epm-shd.sys
2009-01-31 23:30 . 2004-07-19 13:10 4,096 --a------ c:\windows\system32\drivers\epm-psd.sys
2009-01-31 23:29 . 2004-06-14 11:48 3,318,626 --a------ c:\windows\as_1280x800.swf
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-03 03:37 49,480 ----a-w c:\windows\system32\sirenacm.dll
2008-11-27 16:47 10,240 ----a-w c:\windows\system32\RtNicProp32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-07 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-07 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-06-07 114688]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 53248]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 688218]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PCMService"="c:\program files\Acer\Acer Arcade\PCMService.exe" [2005-08-11 143360]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-08-11 200704]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-03-15 2893824]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2005-08-19 462848]
"eRecoveryService"="c:\program files\Acer\eRecovery\Monitor.exe" [2005-08-18 352256]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-01 136600]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-12-21 1443072]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 c:\windows\system32\HdAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-08-09 c:\windows\RTHDCPL.EXE]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.mkdmp3enc"= c:\progra~1\Acer\ACERAR~1\Kernel\Burner\MKDMP3Enc.ACM
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R2 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [2009-01-31 4096]
R2 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [2009-01-31 78208]
R2 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2009-01-31 7296]
R2 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2009-01-31 4010]
S4 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - INT15.SYS
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext =
hxxp://global.acer.com/IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\yfsx1h5i.default\
FF - component: c:\documents and settings\Owner\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-05 07:51:19
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gaopdxserv.sys]
"imagepath"="\systemroot\system32\drivers\gaopdxyubndjba.sys"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gaopdxserv.sys]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\gaopdxyubndjba.sys"
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\acer\eManager\anbmServ.exe
c:\program files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
c:\program files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
c:\program files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-02-05 7:53:03 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2009-02-05 12:53:02
Pre-Run: 18,598,428,672 bytes free
Post-Run: 18,611,142,656 bytes free
265 --- E O F --- 2009-02-02 21:01:07
Here is the HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:12:01, on 2/5/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Acer Arcade\PCMService.exe
C:\acer\epm\epm-dm.exe
C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://global.acer.com/O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
--
End of file - 7248 bytes