ComboFix 09-03-23.01 - Wayne 2009-03-25 12:14:27.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1489 [GMT 11:00]
Running from: c:\documents and settings\Wayne\Desktop\ComboFix.exe
AV: CA Anti-Virus *On-access scanning enabled* (Updated)
FW: CA Personal Firewall *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\test.txt
c:\windows\system32\hpomjfkp.ini
c:\windows\system32\IlnWyyay.ini
c:\windows\system32\IlnWyyay.ini2
.
((((((((((((((((((((((((( Files Created from 2009-02-25 to 2009-03-25 )))))))))))))))))))))))))))))))
.
2009-03-24 21:41 . 2009-03-24 21:41 <DIR> d-------- c:\documents and settings\All Users\Application Data\SITEguard
2009-03-24 21:40 . 2009-03-24 21:40 <DIR> d-------- c:\program files\Common Files\iS3
2009-03-24 18:03 . 2009-03-24 18:27 <DIR> d-------- C:\VideoOutput
2009-03-24 17:29 . 2009-03-24 18:30 <DIR> d-------- c:\documents and settings\Wayne\Application Data\uTorrent
2009-03-24 17:27 . 2009-03-24 17:29 <DIR> d-------- c:\documents and settings\Wayne\Application Data\uTorrent(2)
2009-03-24 09:40 . 2009-03-24 09:41 2 --a------ C:\-127167480
2009-03-21 20:26 . 2009-03-21 20:26 <DIR> d--hs---- c:\documents and settings\Wayne\IECompatCache
2009-03-21 20:24 . 2009-03-21 20:24 <DIR> d--hs---- c:\documents and settings\Wayne\PrivacIE
2009-03-21 20:22 . 2009-03-21 20:22 <DIR> d--hs---- c:\documents and settings\Wayne\IETldCache
2009-03-21 20:22 . 2009-03-21 20:22 <DIR> d--hs---- c:\documents and settings\NetworkService\IETldCache
2009-03-21 19:08 . 2009-03-21 19:09 <DIR> d--h-c--- c:\windows\ie8
2009-03-21 09:41 . 2009-03-21 09:41 <DIR> d-------- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-03-18 04:25 . 2009-03-18 04:25 <DIR> d-------- c:\temp\atmp8
2009-03-18 04:24 . 2009-03-18 04:25 17,634,976 --a------ c:\documents and settings\Wayne\nvRGKTFOAS.exe
2009-03-18 04:24 . 2009-03-18 04:24 28,672 --a------ c:\documents and settings\Wayne\nsvRlRJhiX.exe
2009-03-17 22:03 . 2009-03-17 22:03 <DIR> d-------- c:\documents and settings\Wayne\Application Data\Ahead
2009-03-17 14:19 . 2009-03-17 14:19 <DIR> d-------- c:\documents and settings\Wayne\Application Data\dvdcss
2009-03-17 14:15 . 2008-05-06 17:01 45,056 --a------ c:\windows\system32\WNASPI32.DLL
2009-03-17 14:15 . 2008-05-06 17:01 16,512 --a------ c:\windows\system32\drivers\ASPI32.SYS
2009-03-16 13:38 . 2009-03-16 13:38 <DIR> d-------- c:\documents and settings\Wayne\Application Data\Xilisoft Corporation
2009-03-16 13:37 . 2009-03-17 15:25 <DIR> d-------- c:\program files\Xilisoft
2009-03-11 20:39 . 2009-03-11 20:39 7,680 --ahs---- c:\windows\Thumbs.db
2009-03-10 20:37 . 2009-03-18 04:25 <DIR> d-------- C:\Temp
2009-03-10 11:37 . 2009-03-10 11:48 <DIR> d-------- C:\Need4Video files
2009-03-09 14:09 . 2009-03-09 14:19 <DIR> d-------- c:\program files\uTorrent
2009-03-09 02:13 . 2009-03-09 02:13 <DIR> d-------- c:\documents and settings\Wayne\Application Data\.ABC
2009-03-08 14:22 . 2009-03-08 14:22 49,152 --------- c:\windows\system32\msrating.dll.mui
2009-03-08 14:22 . 2009-03-08 14:22 2,560 --------- c:\windows\system32\mshta.exe.mui
2009-03-08 14:21 . 2009-03-08 14:21 4,096 --------- c:\windows\system32\ie4uinit.exe.mui
2009-03-08 14:20 . 2009-03-08 14:20 81,920 --------- c:\windows\system32\iedkcs32.dll.mui
2009-03-08 04:33 . 2009-03-08 04:33 18,944 -----c--- c:\windows\system32\dllcache\corpol.dll
2009-03-06 14:34 . 2009-03-06 14:35 <DIR> d-------- c:\program files\GetRight
2009-03-05 23:01 . 2009-03-05 23:01 <DIR> d-------- c:\program files\Hiro-Media
2009-03-05 23:01 . 2009-03-05 23:01 <DIR> d-------- c:\documents and settings\All Users\Application Data\Hiro-Media
2009-03-03 21:15 . 2009-03-14 15:30 <DIR> d-------- c:\documents and settings\Wayne\Application Data\HPAppData
2009-03-03 19:57 . 2009-03-03 19:57 <DIR> d-------- c:\documents and settings\All Users\Application Data\WEBREG
2009-03-03 19:57 . 2009-03-03 19:57 <DIR> d-------- c:\documents and settings\All Users\Application Data\HPSSUPPLY
2009-03-03 19:55 . 2009-03-03 19:55 <DIR> d-------- c:\documents and settings\Wayne\Application Data\HP
2009-03-03 19:49 . 2009-03-03 19:49 <DIR> d-------- c:\program files\Hewlett-Packard
2009-03-03 19:49 . 2009-03-03 19:49 <DIR> d-------- c:\program files\Common Files\Hewlett-Packard
2009-03-03 19:49 . 2009-03-03 19:49 <DIR> d-------- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-03-03 19:49 . 2009-03-03 19:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\HP
2009-03-03 19:48 . 2009-03-03 19:48 <DIR> d-------- c:\program files\Common Files\HP
2009-03-03 19:47 . 2009-03-03 19:47 <DIR> d-------- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-03-03 19:47 . 2007-11-09 01:52 271,704 -ra------ c:\windows\system32\hpzids01.dll
2009-03-03 19:47 . 2007-10-20 18:25 117,760 --a------ c:\windows\system32\hpzll5mu.dll
2009-03-03 19:47 . 2007-10-30 20:25 49,920 -ra------ c:\windows\system32\drivers\HPZid412.sys
2009-03-03 19:47 . 2007-10-30 20:25 16,496 -ra------ c:\windows\system32\drivers\HPZipr12.sys
2009-03-03 19:46 . 2007-10-30 20:11 729,088 -ra------ c:\windows\system32\hpowiax7.dll
2009-03-03 19:46 . 2007-10-30 20:11 581,632 -ra------ c:\windows\system32\hpotscl6.dll
2009-03-03 19:46 . 2007-10-30 20:25 372,736 -ra------ c:\windows\system32\hppldcoi.dll
2009-03-03 19:46 . 2007-10-30 20:25 309,760 -ra------ c:\windows\system32\difxapi.dll
2009-03-03 19:46 . 2007-10-30 20:11 303,104 -ra------ c:\windows\system32\hpovst15.dll
2009-03-03 19:46 . 2007-10-30 20:25 21,568 -ra------ c:\windows\system32\drivers\HPZius12.sys
2009-03-03 19:46 . 2008-04-14 04:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2009-03-03 19:46 . 2008-04-14 04:45 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2009-03-03 19:43 . 2009-03-03 19:55 <DIR> d-------- c:\program files\HP
2009-03-03 19:38 . 2009-03-03 19:55 157,454 --a------ c:\windows\hpoins27.dat
2009-03-03 19:38 . 2008-01-19 02:56 932 --------- c:\windows\hpomdl27.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-03-25 01:29 --------- d-----w c:\program files\BitComet
2009-03-25 01:24 64 ----a-w c:\windows\system32\drivers\kmxcfg.u2k7
2009-03-25 01:24 64 ----a-w c:\windows\system32\drivers\kmxcfg.u2k6
2009-03-25 01:24 64 ----a-w c:\windows\system32\drivers\kmxcfg.u2k5
2009-03-25 01:24 64 ----a-w c:\windows\system32\drivers\kmxcfg.u2k4
2009-03-25 01:24 64 ----a-w c:\windows\system32\drivers\kmxcfg.u2k3
2009-03-25 01:24 64 ----a-w c:\windows\system32\drivers\kmxcfg.u2k2
2009-03-25 01:24 64 ----a-w c:\windows\system32\drivers\kmxcfg.u2k1
2009-03-25 01:24 197,154 ----a-w c:\windows\system32\drivers\kmxcfg.u2k0
2009-03-24 13:34 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-24 13:33 --------- d-----w c:\program files\SpywareBlaster
2009-03-24 13:31 --------- d-----w c:\documents and settings\Wayne\Application Data\CallingID
2009-03-24 13:31 --------- d-----w c:\documents and settings\All Users\Application Data\STOPzilla!
2009-03-24 06:35 --------- d-----w c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-03-24 06:30 --------- d-----w c:\program files\Spyware Terminator
2009-03-24 05:37 --------- d-----w c:\documents and settings\Wayne\Application Data\Spyware Terminator
2009-03-22 08:23 --------- d-----w c:\program files\Common Files\Adobe
2009-03-19 03:56 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-11 07:43 --------- d-----w c:\documents and settings\Wayne\Application Data\GetRight
2009-03-11 06:41 --------- d-----w c:\documents and settings\Wayne\Application Data\Vso
2009-03-05 12:02 --------- d-----w c:\program files\XviD
2009-03-03 10:39 --------- d-----w c:\program files\Common Files\Adobe AIR
2009-03-03 07:54 --------- d-----w c:\program files\Common Files\EPSON
2009-03-01 12:00 --------- d-----w c:\documents and settings\Wayne\Application Data\Skype
2009-02-26 13:00 --------- d-----w c:\documents and settings\Wayne\Application Data\teamspeak2
2009-02-26 11:09 --------- d-----w c:\program files\SUPERAntiSpyware
2009-02-22 01:08 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-02-22 01:08 --------- d-----r c:\program files\Skype
2009-02-20 05:20 --------- d-----w c:\documents and settings\All Users\Application Data\NCH Software
2009-02-20 05:19 --------- d-----w c:\documents and settings\Wayne\Application Data\NCH Software
2009-02-18 03:44 6,308,224 ----a-w c:\windows\system32\drivers\nv4_mini.sys
2009-02-12 08:10 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-02-10 23:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-10 23:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-02-06 06:23 --------- d-----w c:\program files\Java
2009-02-06 01:08 --------- d-----w c:\program files\Common Files\Apple
2008-01-26 00:17 32 ------w c:\documents and settings\All Users\Application Data\ezsid.dat
2007-09-16 08:24 47,360 ------w c:\documents and settings\Wayne\Application Data\pcouffin.sys
2005-03-31 12:17 40,960 ------w c:\program files\Uninstall_CDS.exe
2008-08-17 12:52 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008081720080 818\index.dat
2008-08-28 10:47 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082820080 829\index.dat
.
------- Sigcheck -------
2006-04-20 23:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-31 03:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 21:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 22:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 22:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-06-20 21:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\$NtServicePackUninstall$\tcpip.sys
2006-02-28 23:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB917953$\tcpip.sys
2007-09-17 00:08 359808 ba57942c0029b0878afba052a3e33689 c:\windows\$NtUninstallKB941644$\tcpip.sys
2008-04-14 06:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\$NtUninstallKB951748$\tcpip.sys
2007-10-31 04:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748_0$\tcpip.sys
2008-04-14 06:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\ServicePackFiles\i386\tcpip.sys
2008-09-03 04:17 361600 eec9730f9cc03819111d90e6caa2dcc9 c:\windows\system32\dllcache\tcpip.sys
2008-09-03 04:17 361600 eec9730f9cc03819111d90e6caa2dcc9 c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"filehippo.com"="c:\program files\filehippo.com\UpdateChecker.exe" [2008-07-04 137216]
"BitComet"="c:\program files\BitComet\BitComet.exe" [2009-01-20 2523960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-01-24 181488]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-12-20 234736]
"cafw"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-12-20 771312]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-12-20 173296]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-12-20 259312]
"QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe" [2008-12-20 14088]
"SpywareTerminator"="c:\progra~1\SPYWAR~1\SpywareT erminatorShield.exe" [2009-02-18 2233856]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-05 148888]
"NvMediaCenter"="c:\windows\system32\NvMcTray. dll" [2009-02-18 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 c:\windows\system32\HdAShCut.exe]
"nwiz"="nwiz.exe" [2009-02-18 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1 \DW\dwtrig20.exe" [2007-08-24 437160]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-21 77824]
"{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"= "c:\program files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\CIDLinkAdvisor.dll" [2008-06-23 1373624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-01-04 17:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-05-18 14:30 79368 c:\windows\system32\UmxWNP.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Hiro-Media Client.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Hiro-Media Client.lnk
backup=c:\windows\pss\Hiro-Media Client.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VersionTrackerPro.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\VersionTrackerPro.lnk
backup=c:\windows\pss\VersionTrackerPro.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Wayne^Start Menu^Programs^Startup^BitDefender Total Security 2008.lnk]
backup=c:\windows\pss\BitDefender Total Security 2008.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Wayne^Start Menu^Programs^Startup^DesktopEarth AutoStart.lnk]
backup=c:\windows\pss\DesktopEarth AutoStart.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Wayne^Start Menu^Programs^Startup^Karen's Replicator.lnk]
path=c:\documents and settings\Wayne\Start Menu\Programs\Startup\Karen's Replicator.lnk
backup=c:\windows\pss\Karen's Replicator.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Wayne^Start Menu^Programs^Startup^MagicDisc.lnk]
backup=c:\windows\pss\MagicDisc.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Wayne^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Wayne\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMLABTECMOUSE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
--a------ 2008-07-29 16:54 2831360 c:\program files\Ares Ultra\Ares Ultra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares ultra]
--a------ 2008-07-29 16:54 2831360 c:\program files\Ares Ultra\Ares Ultra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
--a------ 2009-01-20 17:37 2523960 c:\program files\BitComet\BitComet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMOFFICE4DMOUSE]
--a------ 2008-06-03 18:34 958464 c:\program files\Labtec\Desktop\V5.1\MOffice.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-11-08 19:58 133104 c:\documents and settings\Wayne\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 08:00 33648 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2007-10-14 21:17 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--------- 2005-06-11 01:20 1397760 c:\program files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a------ 2005-06-08 15:44 196608 c:\program files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a------ 2005-06-08 16:24 458752 c:\program files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a------ 2005-06-08 16:14 217088 c:\program files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMS]
--------- 2002-12-10 18:54 127022 c:\program files\Common Files\Logitech\QCDriver3\LVComS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
--a------ 2009-02-11 10:19 399504 c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
--------- 2005-05-19 20:38 1957888 c:\program files\Ahead\Nero BackItUp\NBJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--------- 2001-07-09 12:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSLauncher]
--a------ 2006-11-28 02:12 2658304 c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OFFICEKB]
--a------ 2008-06-03 18:34 387584 c:\program files\Labtec\Desktop\V5.1\KBDAP32A.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerBar]
--------- 2004-04-21 11:26 86016 c:\program files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2009-01-29 14:01 23975720 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 2009-02-26 22:09 1830128 c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"23939:TCP"= 23939:TCP:BitComet 23939 TCP
"23939:UDP"= 23939:UDP:BitComet 23939 UDP
"60235:TCP"= 60235:TCP:BitComet 60235 TCP
"60235:UDP"= 60235:UDP:BitComet 60235 UDP
"7773:TCP"= 7773:TCP:BitComet 7773 TCP
"7773:UDP"= 7773:UDP:BitComet 7773 UDP
"16050:TCP"= 16050:TCP:BitComet 16050 TCP
"16050:UDP"= 16050:UDP:BitComet 16050 UDP
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxS tart.sys [2008-06-24 93712]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxA gent.sys [2008-06-24 63504]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFil e.sys [2008-06-24 45584]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [2008-06-24 115216]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2006-10-10 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2007-02-27 55024]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2008-07-30 142592]
R2 BT848;WinFast TV2000 XP WDM Video Capture;c:\windows\system32\drivers\wf2kvcap.sys [2005-06-01 76325]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [2008-06-24 134648]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.s ys [2008-06-24 66576]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2008-07-10 179856]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-07-23 206096]
R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [2008-06-24 1010192]
R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [2008-06-24 801296]
R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [2008-06-24 281104]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.s ys [2008-06-24 88816]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\dr ivers\mbam.sys [2008-07-10 15504]
R3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [2008-12-20 185584]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMo n.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSy sMon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
S2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service --> c:\program files\ThreatFire\TFService.exe service [?]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2008-04-30 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2008-04-30 8320]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2006-02-16 4096]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\ TfNetMon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSe tup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-02-18 c:\windows\Tasks\CAAntiSpywareScan_Daily as Wayne at 13 40.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2008-12-20 13:43]
2009-03-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-2025429265-839522115-1003.job
- c:\documents and settings\Wayne\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-08 19:58]
2009-03-24 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Wayne.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-02-11 10:19]
2009-03-24 c:\windows\Tasks\Malwarebytes' Scheduled Update for Wayne.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-02-11 10:19]
2009-03-24 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 17:04]
2009-03-25 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 17:04]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-PowerBar - (no file)
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-BDAgent - c:\program files\BitDefender\BitDefender 2008\bdagent.exe
MSConfigStartUp-BitDefender Antiphishing Helper - c:\program files\BitDefender\BitDefender 2008\IEShow.exe
MSConfigStartUp-DriverUpdaterPro - c:\program files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe
MSConfigStartUp-LDM - c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
MSConfigStartUp-LogitechGalleryRepair - c:\program files\Logitech\ImageStudio\ISStart.exe
MSConfigStartUp-LogitechImageStudioTray - c:\program files\Logitech\ImageStudio\LogiTray.exe
MSConfigStartUp-Windows Defender - c:\program files\Windows Defender\MSASCui.exe
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = localhost
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
LSP: c:\windows\system32\VetRedir.dll
TCP: {951B9C38-DC18-4D03-9A14-5BE1608A8FD5} = 61.9.133.193,61.9.134.49
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {96EEC7FF-106A-47F3-90D6-B4BB754AA40E} - hxxps://autxn.paywithpoli.com/ewcustomer/POLiPayOnline.cab
FF - ProfilePath - c:\documents and settings\Wayne\Application Data\Mozilla\Firefox\Profiles\8cpr16ar.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - component: c:\documents and settings\Wayne\Application Data\Mozilla\Firefox\Profiles\8cpr16ar.default\ext ensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\program files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\Firefox\components\CallingID LinkAdvisorGecko.dll
FF - component: c:\program files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\Firefox\components\CIDDomFx3.dll
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\Wayne\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
.
************************************************** ************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-25 12:29:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1512)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\documents and settings\Wayne\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\ UIREPAIR.DLL
c:\windows\system32\UmxWnp.Dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
- - - - - - - > 'lsass.exe'(1768)
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Ahead\InCD\InCDsrv.exe
c:\program files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe
c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe
c:\windows\system32\WgaTray.exe
c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
c:\windows\system32\rundll32.exe
c:\program files\CA\CA Internet Security Suite\ccprovsp.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\cappactiveprotection.exe
.
************************************************** ************************
.
Completion time: 2009-03-25 12:33:27 - machine was rebooted [Wayne]
ComboFix-quarantined-files.txt 2009-03-25 01:33:24
Pre-Run: 107,760,553,984 bytes free
Post-Run: 107,937,488,896 bytes free
Current=1 Default=1 Failed=3 LastKnownGood=4 Sets=1,2,3,4
409 --- E O F --- 2009-03-20 08:40:26
Here are the last scans from superantispyware and malwarebytes too Evil,thanks so much for your help.
SUPERAntiSpyware Scan Log
SUPERAntiSpyware.com - AntiAdware, AntiSpyware, AntiMalware!
Generated 03/25/2009 at 06:36 AM
Application Version : 4.25.1014
Core Rules Database Version : 3811
Trace Rules Database Version: 1765
Scan type : Complete Scan
Total Scan Time : 00:57:53
Memory items scanned : 542
Memory threats detected : 0
Registry items scanned : 7113
Registry threats detected : 0
File items scanned : 75397
File threats detected : 1
Rootkit.Agent/Gen-Rustock
C:\SYSTEM VOLUME INFORMATION\_RESTORE{2C03431D-8BE3-4BF8-9330-B1997CCBF2D1}\RP163\A0042457.SYS
Malwarebytes' Anti-Malware 1.34
Database version: 1891
Windows 5.1.2600 Service Pack 3
25/03/2009 05:35:45
mbam-log-2009-03-25 (05-35-45).txt
Scan type: Full Scan (C:\|)
Objects scanned: 151618
Time elapsed: 1 hour(s), 1 minute(s), 50 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)