ComboFix 09-09-01.04 - dell 09/01/2009 19:52.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1023.657 [GMT -4:00]
Running from: c:\documents and settings\dell\Desktop\abc.com.exe
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\1b2885.msp
c:\windows\Installer\1b2886.msp
c:\windows\Installer\1b2887.msp
c:\windows\Installer\1b2888.msp
c:\windows\Installer\1b2889.msp
c:\windows\Installer\1b288a.msp
c:\windows\Installer\1b288b.msp
c:\windows\Installer\1b288c.msp
c:\windows\Installer\1b288d.msp
c:\windows\Installer\1e049d.msp
c:\windows\Installer\1e049e.msp
c:\windows\Installer\1e049f.msp
c:\windows\Installer\1e04a0.msp
c:\windows\Installer\1e04a1.msp
c:\windows\Installer\1e04a2.msp
c:\windows\Installer\1e04a3.msp
c:\windows\Installer\1e04a4.msp
c:\windows\Installer\1e04a5.msp
c:\windows\Installer\1e04a6.msp
c:\windows\Installer\2223a.msi
c:\windows\Installer\22240.msi
c:\windows\Installer\22246.msi
c:\windows\Installer\277ece.msi
c:\windows\Installer\277ed4.msi
c:\windows\Installer\277eda.msi
c:\windows\Installer\317e88.msi
c:\windows\Installer\3a560ef.msi
c:\windows\Installer\3a560f5.msi
c:\windows\Installer\3a560fb.msi
c:\windows\Installer\3a89a.msi
c:\windows\Installer\3bdb3.msi
c:\windows\Installer\427a9d.msi
c:\windows\Installer\57607.msi
c:\windows\Installer\9238d.msi
c:\windows\Installer\92392.msi
c:\windows\Installer\92397.msi
c:\windows\Installer\a62c20.msi
c:\windows\Installer\a924a9.msp
c:\windows\Installer\a924aa.msp
c:\windows\Installer\a924ab.msp
c:\windows\Installer\a924ac.msp
c:\windows\Installer\a924ad.msp
c:\windows\Installer\a924ae.msp
c:\windows\Installer\a924af.msp
c:\windows\Installer\a924b0.msp
c:\windows\Installer\a924b1.msp
c:\windows\Installer\a924b2.msp
c:\windows\Installer\e3039.msp
c:\windows\Installer\e303a.msp
c:\windows\Installer\e303b.msp
c:\windows\Installer\e303c.msp
c:\windows\Installer\e303d.msp
c:\windows\Installer\e303e.msp
c:\windows\Installer\e303f.msp
c:\windows\Installer\e3040.msp
c:\windows\Installer\e3041.msp
c:\windows\system32\Data
c:\windows\system32\lp3codec32win.dll
Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\eventlog(3).dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2009-08-02 to 2009-09-02 )))))))))))))))))))))))))))))))
.
2009-09-01 20:48 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-01 20:48 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-01 20:48 . 2009-09-01 20:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-01 20:28 . 2009-09-01 20:28 -------- d-----w- c:\documents and settings\dell\DoctorWeb
2009-09-01 19:19 . 2009-09-01 19:19 -------- d-----w- c:\documents and settings\LocalService\Application Data\Spyware Terminator
2009-09-01 18:22 . 2009-09-01 18:26 -------- d-----w- c:\program files\WinClamAVShield
2009-08-31 22:16 . 2006-06-19 17:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2009-08-31 22:16 . 2006-05-25 19:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2009-08-31 22:16 . 2005-08-26 05:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2009-08-31 22:16 . 2003-02-03 00:06 153088 ----a-w- c:\windows\system32\unrar3.dll
2009-08-31 22:16 . 2002-03-06 05:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2009-08-31 22:01 . 2009-08-31 23:13 -------- dc----w- C:\MGtools
2009-08-31 18:13 . 2009-08-31 18:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Bitdefender
2009-08-31 18:11 . 2009-08-31 20:57 81984 ----a-w- c:\windows\system32\bdod.bin
2009-08-31 18:10 . 2009-08-31 18:10 -------- d-----w- c:\documents and settings\dell\Application Data\Bitdefender
2009-08-31 18:09 . 2009-08-31 18:09 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender
2009-08-31 18:09 . 2009-08-31 18:09 -------- d-----w- c:\program files\Softwin
2009-08-31 18:08 . 2009-09-01 23:44 -------- d-----w- c:\program files\Common Files\Softwin
2009-08-31 05:22 . 2009-08-31 05:22 -------- d-----w- c:\program files\Bam
2009-08-30 17:19 . 2009-08-31 17:53 -------- d-----w- c:\program files\trend micro
2009-08-30 15:33 . 2009-08-30 23:30 -------- d-----w- c:\program files\Unlocker
2009-08-30 14:22 . 2009-08-30 14:22 -------- dc----w- C:\rsit
2009-08-30 05:43 . 2009-08-30 05:43 -------- d-----w- c:\program files\Crawler
2009-08-30 05:43 . 2009-09-01 20:55 -------- d-----w- c:\documents and settings\dell\Application Data\Spyware Terminator
2009-08-30 05:43 . 2009-08-30 05:43 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2009-08-30 05:43 . 2009-08-30 05:43 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2009-08-30 05:43 . 2009-08-30 05:43 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2009-08-30 05:43 . 2009-09-01 20:55 -------- d-----w- c:\program files\Spyware Terminator
2009-08-30 05:43 . 2009-09-01 19:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-08-29 22:30 . 2009-08-30 01:23 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-08-29 22:30 . 2009-08-29 22:30 -------- d-----w- c:\documents and settings\dell\Application Data\SUPERAntiSpyware.com
2009-08-29 06:37 . 2009-08-29 06:37 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-08-26 19:32 . 2009-08-26 19:32 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-08-21 19:47 . 2009-09-01 05:29 -------- d-----w- c:\documents and settings\dell\Application Data\foobar2000
2009-08-21 19:47 . 2009-08-25 14:53 -------- d-----w- c:\program files\foobar2000
2009-08-17 07:04 . 2009-08-17 07:04 2173472 ----a-w- c:\windows\system32\nvcplui.exe
2009-08-17 07:04 . 2009-08-17 07:04 81920 ----a-w- c:\windows\system32\nvwddi.dll
2009-08-17 07:03 . 2009-08-17 07:03 3170304 ----a-w- c:\windows\system32\nvwss.dll
2009-08-17 07:03 . 2009-08-17 07:03 4026368 ----a-w- c:\windows\system32\nvvitvs.dll
2009-08-17 07:03 . 2009-08-17 07:03 188416 ----a-w- c:\windows\system32\nvmccss.dll
2009-08-17 07:03 . 2009-08-17 07:03 1286144 ----a-w- c:\windows\system32\nvmobls.dll
2009-08-17 07:03 . 2009-08-17 07:03 3547136 ----a-w- c:\windows\system32\nvgames.dll
2009-08-17 07:03 . 2009-08-17 07:03 4923392 ----a-w- c:\windows\system32\nvdisps.dll
2009-08-17 07:03 . 2009-08-17 07:03 86016 ----a-w- c:\windows\system32\nvmctray.dll
2009-08-17 07:03 . 2009-08-17 07:03 168004 ----a-w- c:\windows\system32\nvsvc32.exe
2009-08-17 07:03 . 2009-08-17 07:03 143360 ----a-w- c:\windows\system32\nvcolor.exe
2009-08-17 07:03 . 2009-08-17 07:03 13877248 ----a-w- c:\windows\system32\nvcpl.dll
2009-08-17 07:02 . 2009-08-17 07:02 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-08-17 04:57 . 2009-08-17 04:57 2189856 ----a-w- c:\windows\system32\nvcuvid.dll
2009-08-17 04:57 . 2009-08-17 04:57 1706528 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-08-17 04:57 . 2009-08-17 04:57 1597690 ----a-w- c:\windows\system32\nvdata.bin
2009-08-11 01:37 . 2009-08-11 01:37 -------- d-----w- c:\program files\MP3 Rocket
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-01 23:52 . 2004-08-04 10:00 55808 -c--a-w- c:\windows\system32\eventlog.dll
2009-09-01 21:00 . 2009-04-22 05:07 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-01 21:00 . 2008-02-01 18:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-01 18:45 . 2009-02-19 14:42 -------- d-----w- c:\program files\Windows Sidebar
2009-09-01 17:18 . 2009-02-11 23:49 -------- d-----w- c:\documents and settings\dell\Application Data\Vista Start Menu
2009-09-01 16:59 . 2009-06-09 01:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-30 23:31 . 2009-03-03 19:26 -------- d-----w- c:\documents and settings\dell\Application Data\Move Networks
2009-08-30 05:19 . 2009-02-26 06:06 -------- d-----w- c:\program files\Wise Disk Cleaner
2009-08-26 19:32 . 2008-04-25 17:16 -------- d-----w- c:\program files\NVIDIA Corporation
2009-08-26 19:16 . 2009-04-26 06:06 -------- d-----w- c:\program files\WinFlip
2009-08-26 15:16 . 2009-02-19 07:03 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-08-24 01:26 . 2008-02-01 04:37 -------- d-----w- c:\documents and settings\dell\Application Data\MP3Rocket
2009-08-17 04:57 . 2009-04-23 06:34 485920 ----a-w- c:\windows\system32\nvudisp.exe
2009-08-17 04:57 . 2008-01-21 14:54 868352 ----a-w- c:\windows\system32\nvapi.dll
2009-08-17 04:57 . 2008-01-21 14:54 155648 ----a-w- c:\windows\system32\nvcodins.dll
2009-08-17 04:57 . 2008-01-21 14:54 155648 ----a-w- c:\windows\system32\nvcod.dll
2009-08-17 04:57 . 2008-01-21 14:54 10457088 ----a-w- c:\windows\system32\nvoglnt.dll
2009-08-17 04:57 . 2008-01-21 14:54 2002944 ----a-w- c:\windows\system32\nvcuda.dll
2009-08-17 04:57 . 2008-01-08 12:04 7729568 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-08-17 04:57 . 2008-01-08 12:04 5845760 ----a-w- c:\windows\system32\nv4_disp.dll
2009-08-11 16:35 . 2009-04-23 06:34 485920 ----a-w- c:\windows\system32\nvuninst.exe
2009-07-28 20:33 . 2009-06-25 03:51 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-07-28 12:01 . 2009-07-28 03:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Autorun Eater
2009-07-22 21:12 . 2008-02-08 03:36 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-26 01:21 . 2009-06-26 01:21 488960 ----a-w- c:\documents and settings\dell\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv302-0811070-0-main.dll
2009-06-26 01:21 . 2009-06-26 01:21 319488 ----a-w- c:\documents and settings\dell\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe
2009-06-16 06:35 . 2009-06-16 06:35 97144 ----a-w- c:\documents and settings\dell\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
.
------- Sigcheck -------
[-] 2008-10-16 19:09 78360 0FB0036ACEA470CC670C4919FE53007F c:\windows\7SP_Files\wuauclt.exe
[-] 2008-10-16 19:09 78360 0FB0036ACEA470CC670C4919FE53007F c:\windows\7SP_Files\backup\wuauclt.exe
[-] 2008-10-16 19:09 78360 0FB0036ACEA470CC670C4919FE53007F c:\windows\system32\wuauclt.exe
[-] 2008-10-16 19:09 78360 0FB0036ACEA470CC670C4919FE53007F c:\windows\VSP_Files\wuauclt.exe
[-] 2008-10-16 19:09 78360 0FB0036ACEA470CC670C4919FE53007F c:\windows\VSP_Files\backup\wuauclt.exe
[-] 2004-08-04 10:00 1390080 D1D58275780F3DD626EC17904E2E734D c:\windows\7SP_Files\comres.dll
[7] 2004-08-04 10:00 792064 6728270CB7DBB776ED086F5AC4C82310 c:\windows\7SP_Files\backup\comres.dll
[-] 2004-08-04 10:00 948736 8C23B380C5292E3A9EF88C458341C30E c:\windows\system32\comres.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaStartMenu"="c:\program files\Vista Start Menu\VistaStartMenu.exe" [2008-09-24 2143744]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"TransBar"="c:\documents and settings\dell\Local Settings\Application Data\AKSoftware\TransBar\TransBar.exe" [2005-08-05 66048]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2007-08-29 1232384]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2009-08-30 3055616]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2005-03-15 196608]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-12-12 157312]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"IRReceive"="c:\program files\IRReceive\IRReceive.exe" [2007-06-26 675913]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-08-13 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-08-17 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-17 13877248]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-12-19 76304]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-12-19 76304]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-04 110592]
c:\documents and settings\dell\Start Menu\Programs\Startup\
TrueTransparency.lnk - c:\program files\TrueTransparency\TrueTransparency.exe [2009-4-26 263680]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-1-26 67128]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-3-28 809488]
TMMonitor.lnk - c:\program files\ArcSoft\TotalMedia 3.5\TMMonitor.exe [2009-6-25 258048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-19 04:30 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^dell^Start Menu^Programs^Startup^Refresh Icon Cache.lnk]
backup=c:\windows\pss\Refresh Icon Cache.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^dell^Start Menu^Programs^Startup^ViSplore.lnk]
backup=c:\windows\pss\ViSplore.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^dell^Start Menu^Programs^Startup^YzShadow.lnk]
backup=c:\windows\pss\YzShadow.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"diagent"="c:\program files\Creative\SBLive\Diagnostics\diagent.exe" startup
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"TV Card Remote Control Device Monitor"=c:\windows\713xRMTMon.exe
"REGSHAVE"=c:\program files\REGSHAVE\REGSHAVE.EXE /AUTORUN
"ArcSoft Connection Service"=c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
"BDMCon"="c:\program files\Softwin\BitDefender10\bdmcon.exe" /reg
"BDAgent"="c:\program files\Softwin\BitDefender10\bdagent.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\javaw.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\dell\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\ArcSoft\\TotalMedia 3.5\\TotalMedia.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
R0 BootScreen;BootScreen;\SystemRoot\\SystemRoot\System32\drivers\vidstub.sys --> \SystemRoot\\SystemRoot\System32\drivers\vidstub.sys [?]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [8/30/2009 1:43 AM 142592]
R3 AV88BASE;Cx2388x Base Driver;c:\windows\system32\drivers\av88base.sys [9/5/2008 7:33 PM 570112]
R3 viafilter;VIA USB Filter;c:\windows\system32\drivers\viausb1.sys [1/26/2009 2:08 AM 9728]
S1 SASDIFSV;SASDIFSV;\??\c:\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS --> C:c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S2 713xTVCard;SAA7130 TV Card;c:\windows\system32\drivers\SAA713x.sys [4/10/2008 8:21 PM 279552]
S2 HidCom;USB-HID -> COM Driver Service;c:\windows\system32\drivers\HidCom.sys [8/24/2001 9:06 AM 69575]
S2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [4/10/2008 8:24 PM 25984]
S3 audiobridge;Virtual Audio Bridge;c:\windows\system32\drivers\aubridge.sys [7/23/2007 3:04 PM 22528]
S3 CamdAudio;CamdAudio;c:\windows\system32\drivers\CamdAudio.sys [1/26/2009 2:13 PM 23096]
S3 CamdVideo;CamdVideo;c:\windows\system32\drivers\CamdVideo.sys [1/26/2009 2:13 PM 3768]
S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS --> c:\program files\SUPERAntiSpyware\SASENUM.SYS [?]
S3 SndTAudio;SndTAudio;c:\windows\system32\drivers\SndTAudio.sys [1/26/2009 11:54 AM 23096]
S3 SndTVideo;SndTVideo;c:\windows\system32\drivers\SndTVideo.sys [1/26/2009 11:54 AM 3768]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{34A19196-274E-4D75-9D30-D7A45A0A4178}]
"%ProgramFiles%\Windows Sidebar\.\regsvr32.exe" /s wlsrvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{65FFB6E3-03E8-48C4-9376-D649003738E9}]
HIDEC /W "%VAIOTOOLS%\REGTLIB" "%ProgramFiles%\Common Files\Ahead\Lib\NeroGadgetCMServer.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6B9228DA-9C15-419e-856C-19E768A13BDC}]
"%ProgramFiles%\Windows Sidebar\.\regsvr32.exe" /s sbdrop.dll
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
HIDEC /W "%VAIOTOOLS%\REGTLIB" "%ProgramFiles%\Windows Sidebar\sidebar.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-09-02 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-02-02 22:02]
2009-09-01 c:\windows\Tasks\User_Feed_Synchronization-{09F9BF91-3135-4F96-9BD3-0AA342EF2B6B}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
2009-03-01 c:\windows\Tasks\Wise Disk Cleaner 4.job
- c:\program files\Wise Disk Cleaner\WiseDiskCleaner.exe [2009-02-26 00:06]
2009-02-22 c:\windows\Tasks\Wise Registry Cleaner 4.job
- c:\program files\Wise Registry Cleaner 4\WiseRegistryCleaner.exe [2009-02-22 18:07]
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
SafeBoot-Winfl40.sys
.
------- Supplementary Scan -------
.
IE: Crawler Search - tbr:iemenu
TCP: {676EF022-6ED2-476D-ACC3-554386970D9C} = 208.67.222.222,208.67.220.220
TCP: {A85D69C8-F01C-4630-B4D8-6EF16A906F26} = 208.67.222.222,208.67.220.220
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\dell\Application Data\Mozilla\Firefox\Profiles\191kpxr4.default\
FF - prefs.js: browser.search.selectedEngine - Crawler Search
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xcomm.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xshared.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xsupport.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xwsg.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-01 20:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(636)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\windows\system32\MPR.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'explorer.exe'(3740)
c:\program files\RocketDock\RocketDock.dll
c:\program files\NVIDIA Corporation\nView\nview.dll
c:\program files\TrueTransparency\TrueTransparencyHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\windows\system32\nvwddi.dll
c:\program files\Vista Start Menu\VistaStartMenu.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\program files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
c:\windows\system32\ZuneBusEnum.exe
c:\program files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
.
**************************************************************************
.
Completion time: 2009-09-02 20:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-02 00:05
Pre-Run: 51,374,362,624 bytes free
Post-Run: 54,587,867,136 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
353 --- E O F --- 2009-01-16 08:01