Logfile of HijackThis v1.99.1
Scan saved at 2:27:12 AM, on 19/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Your log looks clean but there are few files that look suspicious
Lets check those out:
Do this.
Make your hidden files visible:
->On the Tools menu in Windows Explorer, click Folder Options.
->Click the View tab.
->Under Hidden files and folders, click Show hidden files and folders.
Go to http://www.virustotal.com -> Press Browse
-> Search this file D:\-->Setup.exe -> OK and Send
-> Post the results to here so we can see if it is dirty
Check this file too in the virustotal and post the results here:
C:\Program Files\PowerISO\-->PWRISOVM.EXE
The D:/setup.exe is weird. It was actually my girlfreinds mp3 cd in the dvd drive, however no such file is on the disc.
The other one appears to be clean :
This is a report processed by VirusTotal on 03/18/2006 at 20:25:53 (CET) after scanning the file "PWRISOVM.EXE" file.
Antivirus Version Update Result
AntiVir 6.34.0.53 03.18.2006 no virus found
Avast 4.6.695.0 03.17.2006 no virus found
AVG 718 03.17.2006 no virus found
Avira 6.34.0.53 03.18.2006 no virus found
BitDefender 7.2 03.18.2006 no virus found
CAT-QuickHeal 8.00 03.18.2006 no virus found
ClamAV devel-20060126 03.17.2006 no virus found
DrWeb 4.33 03.18.2006 no virus found
eTrust-InoculateIT 23.71.105 03.18.2006 no virus found
eTrust-Vet 12.4.2123 03.17.2006 no virus found
Ewido 3.5 03.18.2006 no virus found
Fortinet 2.71.0.0 03.18.2006 no virus found
F-Prot 3.16c 03.17.2006 no virus found
Ikarus 0.2.59.0 03.17.2006 no virus found
Kaspersky 4.0.2.24 03.18.2006 no virus found
McAfee 4721 03.17.2006 no virus found
NOD32v2 1.1450 03.18.2006 no virus found
Norman 5.70.10 03.17.2006 no virus found
Panda 9.0.0.4 03.18.2006 no virus found
Sophos 4.03.0 03.18.2006 no virus found
Symantec 8.0 03.18.2006 no virus found
TheHacker 5.9.5.115 03.17.2006 no virus found
UNA 1.83 03.16.2006 no virus found
VBA32 3.10.5 03.17.2006 no virus found
cheers.
p.s.
Spybot recognises ctfmon.exe as a coolwebsearch variant, however when I googled it, it identified it as being nothing to worry about.
Run HijackThis and fix this entry: (Do a system scan only, check entry, close all other windows, press Fix checked)
O4 - HKLM\..\Run: [zzzHPSETUP] D:\Setup.exe
Then do a new system scan with HijackThis and check that is the
O4 - HKLM\..\Run: [zzzHPSETUP] D:\Setup.exe entry gone
By the way, if you want to make your computer (especially the startup) faster, you can fix these entries with HijackThis:
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
The following can also be fixed if you don't need any Japanese translating/writing support:
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName