ComboFix 09-03-15.01 - Dwayne 2009-03-18 16:18:21.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1447 [GMT -4:00]
Running from: c:\documents and settings\Dwayne\Desktop\ComboFix.exe
AV: CA Anti-Virus *On-access scanning disabled* (Outdated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Dwayne\Application Data\Adobe\crc.dat
c:\documents and settings\Dwayne\Application Data\inst.exe
c:\documents and settings\LocalService.NT AUTHORITY\Application Data\twain_32
c:\documents and settings\LocalService.NT AUTHORITY\Application Data\twain_32\user.ds
C:\install.exe
c:\program files\INSTALL.LOG
c:\windows1\sysguard.exe
c:\windows1\system32\_000001_.tmp.dll
c:\windows1\system32\_000019_.tmp.dll
c:\windows1\system32\_000020_.tmp.dll
c:\windows1\system32\_000021_.tmp.dll
c:\windows1\system32\_000022_.tmp.dll
c:\windows1\system32\_000023_.tmp.dll
c:\windows1\system32\_000024_.tmp.dll
c:\windows1\system32\_000025_.tmp.dll
c:\windows1\system32\_000026_.tmp.dll
c:\windows1\system32\_000027_.tmp.dll
c:\windows1\system32\_000028_.tmp.dll
c:\windows1\system32\_000029_.tmp.dll
c:\windows1\system32\_000030_.tmp.dll
c:\windows1\system32\_000031_.tmp.dll
c:\windows1\system32\_000032_.tmp.dll
c:\windows1\system32\_000033_.tmp.dll
c:\windows1\system32\_000034_.tmp.dll
c:\windows1\system32\_000035_.tmp.dll
c:\windows1\system32\_000036_.tmp.dll
c:\windows1\system32\_000037_.tmp.dll
c:\windows1\system32\_000038_.tmp.dll
c:\windows1\system32\_000039_.tmp.dll
c:\windows1\system32\_000040_.tmp.dll
c:\windows1\system32\_000041_.tmp.dll
c:\windows1\system32\_000042_.tmp.dll
c:\windows1\system32\_000043_.tmp.dll
c:\windows1\system32\_000044_.tmp.dll
c:\windows1\system32\_000045_.tmp.dll
c:\windows1\system32\_000046_.tmp.dll
c:\windows1\system32\_000047_.tmp.dll
c:\windows1\system32\_000048_.tmp.dll
c:\windows1\system32\_000049_.tmp.dll
c:\windows1\system32\_000050_.tmp.dll
c:\windows1\system32\_000051_.tmp.dll
c:\windows1\system32\_000052_.tmp.dll
c:\windows1\system32\_000053_.tmp.dll
c:\windows1\system32\_000054_.tmp.dll
c:\windows1\system32\_000055_.tmp.dll
c:\windows1\system32\_000056_.tmp.dll
c:\windows1\system32\_000057_.tmp.dll
c:\windows1\system32\_000058_.tmp.dll
c:\windows1\system32\_000059_.tmp.dll
c:\windows1\system32\_000060_.tmp.dll
c:\windows1\system32\_000061_.tmp.dll
c:\windows1\system32\_000062_.tmp.dll
c:\windows1\system32\_000063_.tmp.dll
c:\windows1\system32\_000064_.tmp.dll
c:\windows1\system32\_000065_.tmp.dll
c:\windows1\system32\_000066_.tmp.dll
c:\windows1\system32\_000067_.tmp.dll
c:\windows1\system32\_000068_.tmp.dll
c:\windows1\system32\_000069_.tmp.dll
c:\windows1\system32\_000070_.tmp.dll
c:\windows1\system32\_000071_.tmp.dll
c:\windows1\system32\_000072_.tmp.dll
c:\windows1\system32\_000073_.tmp.dll
c:\windows1\system32\_000074_.tmp.dll
c:\windows1\system32\_000075_.tmp.dll
c:\windows1\system32\_000076_.tmp.dll
c:\windows1\system32\_000077_.tmp.dll
c:\windows1\system32\_000078_.tmp.dll
c:\windows1\system32\_000079_.tmp.dll
c:\windows1\system32\_000080_.tmp.dll
c:\windows1\system32\_000081_.tmp.dll
c:\windows1\system32\_000239_.tmp.dll
c:\windows1\system32\_000240_.tmp.dll
c:\windows1\system32\_000241_.tmp.dll
c:\windows1\system32\_000242_.tmp.dll
c:\windows1\system32\_000243_.tmp.dll
c:\windows1\system32\config\systemprofile\Application Data\Macromedia\Common
c:\windows1\system32\config\systemprofile\Application Data\Macromedia\Common\711500761.dll
c:\windows1\system32\EhRBaJlm.ini
c:\windows1\system32\EhRBaJlm.ini2
c:\windows1\system32\iehelper.dll
c:\windows1\system32\sCKTBcfe.ini
c:\windows1\system32\sCKTBcfe.ini2
c:\windows1\system32\uacinit.dll
c:\windows1\system32\UAClpivjedh.log
c:\windows1\system32\UAClpltpujc.dat
c:\windows1\system32\UACyoteosso.dll
c:\windows1\system32\uxfvbsby.ini
.
((((((((((((((((((((((((( Files Created from 2009-02-18 to 2009-03-18 )))))))))))))))))))))))))))))))
.
2009-03-14 16:20 . 2009-03-14 16:20 <DIR> d-------- c:\program files\Rockstar Games
2009-03-12 20:55 . 2009-03-12 20:55 <DIR> d-------- c:\windows1\Build a lot 3 Passport to Europe
2009-03-12 20:55 . 2009-03-12 20:55 <DIR> d-------- c:\program files\Build a lot 3 Passport to Europe
2009-03-12 20:55 . 2009-03-12 20:55 <DIR> d-------- c:\documents and settings\All Users.WINDOWS1\Application Data\HipSoft
2009-03-12 18:38 . 2009-03-12 18:38 <DIR> d-------- c:\windows1\Nick Chase A Detective Story Strategy Guide
2009-03-12 15:45 . 2009-03-12 15:46 <DIR> d-------- c:\documents and settings\All Users.WINDOWS1\Application Data\Nick Chase A Detective Story
2009-03-12 15:41 . 2009-03-12 15:41 <DIR> d-------- c:\windows1\Nick Chase A Detective Story
2009-03-09 18:37 . 2009-03-09 18:37 <DIR> d-------- c:\documents and settings\Dwayne\Application Data\SerpentOfIsis
2009-03-09 18:20 . 2009-03-09 18:20 <DIR> d-------- c:\windows1\The Serpent of Isis
2009-03-05 19:40 . 2009-03-05 19:40 <DIR> d-------- c:\documents and settings\Dwayne\Application Data\BrandX Games
2009-03-05 19:37 . 2009-03-05 19:37 <DIR> d-------- c:\windows1\Mae Q West and the Sign of the Stars
2009-03-04 20:13 . 2009-03-04 22:16 123,108 --a------ c:\windows1\HPHins12.dat
2009-03-04 20:13 . 2006-07-17 15:39 14,916 --------- c:\windows1\hphmdl12.dat
2009-03-04 14:25 . 2009-03-04 14:25 <DIR> d-------- c:\documents and settings\Dwayne\Application Data\Red Alert 3
2009-03-02 18:48 . 2009-03-02 18:48 <DIR> d-------- c:\program files\Trend Micro
2009-02-28 22:51 . 2009-02-28 22:51 <DIR> d-------- c:\program files\Common Files\Scanner
2009-02-28 22:49 . 2008-06-04 06:46 880,560 --a------ c:\windows1\system32\drivers\vetefile.sys
2009-02-28 22:49 . 2008-06-04 06:46 108,368 --a------ c:\windows1\system32\drivers\veteboot.sys
2009-02-28 22:47 . 2009-02-28 22:51 <DIR> d-------- c:\program files\CA
2009-02-28 22:47 . 2009-02-28 22:54 <DIR> d-------- c:\documents and settings\All Users.WINDOWS1\Application Data\CA
2009-02-28 22:47 . 2007-04-23 11:36 99,904 --a------ c:\windows1\system32\isafeif.dll
2009-02-28 22:47 . 2007-04-23 11:36 79,424 --a------ c:\windows1\system32\vetredir.dll
2009-02-28 22:47 . 2007-05-25 10:46 75,280 --a------ c:\windows1\system32\isafprod.dll
2009-02-28 22:47 . 2007-05-25 10:46 32,528 --a------ c:\windows1\system32\drivers\vetmonnt.sys
2009-02-28 22:47 . 2007-05-25 10:46 26,640 --a------ c:\windows1\system32\drivers\vet-filt.sys
2009-02-28 22:47 . 2007-05-25 10:46 21,648 --a------ c:\windows1\system32\drivers\vetfddnt.sys
2009-02-28 22:47 . 2007-05-25 10:46 21,392 --a------ c:\windows1\system32\drivers\vet-rec.sys
2009-02-28 10:25 . 2009-01-24 00:11 <DIR> d-------- c:\documents and settings\Guest\Application Data\Logitech
2009-02-28 10:25 . 2009-02-28 10:25 <DIR> d-------- c:\documents and settings\Guest
2009-02-23 13:48 . 2009-02-23 13:48 <DIR> d-------- c:\program files\QuickTiming
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-18 20:21 --------- d-----w c:\program files\lg_fwupdate
2009-03-18 19:40 --------- d---a-w c:\documents and settings\All Users.WINDOWS1\Application Data\TEMP
2009-03-14 20:18 --------- d-----w c:\program files\Microsoft Games
2009-03-13 00:54 --------- d-----w c:\documents and settings\Dwayne\Application Data\uTorrent
2009-03-05 00:47 --------- d-----w c:\program files\HP
2009-02-19 16:45 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-02-17 17:41 --------- d-----w c:\program files\Reflexive
2009-02-17 17:41 --------- d-----w c:\documents and settings\Dwayne\Application Data\Pogo Games
2009-02-16 16:32 --------- d-----w c:\documents and settings\All Users.WINDOWS1\Application Data\PCPitstop
2009-02-11 15:19 38,496 ----a-w c:\windows1\system32\drivers\mbamswissarmy.sys
2009-02-11 15:19 15,504 ----a-w c:\windows1\system32\drivers\mbam.sys
2009-01-30 02:18 --------- d-----w c:\documents and settings\All Users.WINDOWS1\Application Data\Pure Networks
2009-01-30 01:34 --------- d-----w c:\documents and settings\Dwayne\Application Data\dvdcss
2009-01-30 01:31 --------- d-----w c:\documents and settings\Dwayne\Application Data\GetRightToGo
2009-01-30 01:30 --------- d-----w c:\program files\Microsoft Works
2009-01-30 01:30 --------- d-----w c:\program files\DVDFab 5
2009-01-24 20:29 --------- d-----w c:\program files\PCPitstop
2009-01-24 20:25 --------- d-----w c:\program files\Electronic Arts
2009-01-24 04:11 --------- d-----w c:\documents and settings\Default User.WINDOWS1\Application Data\Logitech
2008-08-07 14:33 47,360 ----a-w c:\documents and settings\Dwayne\Application Data\pcouffin.sys
2004-10-01 19:00 40,960 ----a-w c:\program files\Uninstall_CDS.exe
.
------- Sigcheck -------
2008-06-23 12:12 667136 611ace3f4201e9610af8452f7c268995 c:\windows1\$hf_mig$\KB953838\SP2QFE\wininet.dll
2008-06-23 11:09 666112 f12fbb673de9cc802c5dc518fe99aa2f c:\windows1\$hf_mig$\KB953838\SP3GDR\wininet.dll
2008-06-23 10:54 666624 972299b7241ec325d8c7e5638c884925 c:\windows1\$hf_mig$\KB953838\SP3QFE\wininet.dll
2004-08-04 01:56 656384 c0823fc5469663ba63e7db88f9919d70 c:\windows1\ie7\wininet.dll
2008-04-13 20:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows1\ServicePackFiles\i386\wininet.dll
2008-04-13 20:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows1\SoftwareDistribution\Download\
0d3b5d19cc06db007bbe6584808bfa9e\wininet.dll
2008-06-23 11:38 659456 9eea04bc4c3fa521d256d89940fab4db c:\windows1\SoftwareDistribution\Download\7266a4d025877b3f91e09ddc873eafd6\sp2gdr\wininet.dll
2008-06-23 12:12 667136 611ace3f4201e9610af8452f7c268995 c:\windows1\SoftwareDistribution\Download\7266a4d025877b3f91e09ddc873eafd6\sp2qfe\wininet.dll
2008-06-23 11:09 666112 f12fbb673de9cc802c5dc518fe99aa2f c:\windows1\SoftwareDistribution\Download\7266a4d025877b3f91e09ddc873eafd6\sp3gdr\wininet.dll
2008-06-23 10:54 666624 972299b7241ec325d8c7e5638c884925 c:\windows1\SoftwareDistribution\Download\7266a4d025877b3f91e09ddc873eafd6\sp3qfe\wininet.dll
2008-10-16 06:37 659456 6f1e4bfd78c4e0d05ff3725d59b72925 c:\windows1\SoftwareDistribution\Download\7bc58354ca50aa200544caaef7677c8a\SP2GDR\wininet.dll
2008-10-16 06:20 667648 93c9d0a216498ee14eb9b26119bb95ee c:\windows1\SoftwareDistribution\Download\7bc58354ca50aa200544caaef7677c8a\SP2QFE\wininet.dll
2008-10-15 21:00 666112 1576318bf08d28cc61d1278114ad8d5b c:\windows1\SoftwareDistribution\Download\7bc58354ca50aa200544caaef7677c8a\SP3GDR\wininet.dll
2008-10-15 21:04 667136 e8fce58a470999350f64c591557f9e42 c:\windows1\SoftwareDistribution\Download\7bc58354ca50aa200544caaef7677c8a\SP3QFE\wininet.dll
2008-04-13 20:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows1\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\wininet.dll
2008-10-15 21:00 666112 1576318bf08d28cc61d1278114ad8d5b c:\windows1\system32\wininet.dll
2008-10-15 21:00 666112 1576318bf08d28cc61d1278114ad8d5b c:\windows1\system32\dllcache\wininet.dll
2008-06-20 06:44 360960 744e57c99232201ae98c49168b918f48 c:\windows1\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 07:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows1\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 07:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows1\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-04-13 15:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows1\ServicePackFiles\i386\tcpip.sys
2008-04-13 15:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows1\SoftwareDistribution\Download\
0d3b5d19cc06db007bbe6584808bfa9e\tcpip.sys
2008-06-20 07:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows1\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp3gdr\tcpip.sys
2004-08-04 00:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows1\SoftwareDistribution\Download\ca6c24ab62fe8433c5d63bb11a2e5a2c\backup\sp2gdr\tcpip.sys
2004-08-04 00:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows1\SoftwareDistribution\Download\ca6c24ab62fe8433c5d63bb11a2e5a2c\backup\sp2qfe\tcpip.sys
2008-04-13 15:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows1\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\tcpip.sys
2008-06-20 07:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows1\system32\dllcache\tcpip.sys
2004-08-04 01:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows1\system32\drivers\tcpip.sys
2008-04-13 15:20 182656 1df7f42665c94b825322fae71721130d c:\windows1\ServicePackFiles\i386\ndis.sys
2008-04-13 15:20 182656 1df7f42665c94b825322fae71721130d c:\windows1\SoftwareDistribution\Download\
0d3b5d19cc06db007bbe6584808bfa9e\ndis.sys
2008-04-13 15:20 182656 1df7f42665c94b825322fae71721130d c:\windows1\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ndis.sys
2004-08-04 01:14 182912 558635d3af1c7546d26067d5d9b6959e c:\windows1\system32\dllcache\ndis.sys
2004-08-04 01:14 182912 558635d3af1c7546d26067d5d9b6959e c:\windows1\system32\drivers\ndis.sys
2008-04-13 14:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows1\ServicePackFiles\i386\ip6fw.sys
2008-04-13 14:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows1\SoftwareDistribution\Download\
0d3b5d19cc06db007bbe6584808bfa9e\ip6fw.sys
2008-04-13 14:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows1\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ip6fw.sys
2004-08-04 01:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows1\system32\dllcache\ip6fw.sys
2004-08-04 01:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows1\system32\drivers\ip6fw.sys
2008-04-13 20:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows1\ServicePackFiles\i386\services.exe
2008-04-13 20:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows1\SoftwareDistribution\Download\
0d3b5d19cc06db007bbe6584808bfa9e\services.exe
2008-04-13 20:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows1\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\services.exe
2004-08-04 02:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows1\system32\services.exe
2004-08-04 02:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows1\system32\dllcache\services.exe
2008-04-13 20:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 c:\windows1\ServicePackFiles\i386\userinit.exe
2008-04-13 20:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 c:\windows1\SoftwareDistribution\Download\
0d3b5d19cc06db007bbe6584808bfa9e\userinit.exe
2008-04-13 20:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 c:\windows1\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\userinit.exe
2004-08-04 02:56 24576 39b1ffb03c2296323832acbae50d2aff c:\windows1\system32\userinit.exe
2004-08-04 02:56 24576 39b1ffb03c2296323832acbae50d2aff c:\windows1\system32\dllcache\userinit.exe
2008-04-13 20:11 989696 c24b983d211c34da8fcc1ac38477971d c:\windows1\ServicePackFiles\i386\kernel32.dll
2008-04-13 20:11 989696 c24b983d211c34da8fcc1ac38477971d c:\windows1\SoftwareDistribution\Download\
0d3b5d19cc06db007bbe6584808bfa9e\kernel32.dll
2008-04-13 20:11 989696 c24b983d211c34da8fcc1ac38477971d c:\windows1\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\kernel32.dll
2004-08-04 01:56 983552 888190e31455fad793312f8d087146eb c:\windows1\SoftwareDistribution\Download\fc75a45b73372bd0c2a61e3a51d766ff\backup\sp2gdr\kernel32.dll
2004-08-04 01:56 983552 888190e31455fad793312f8d087146eb c:\windows1\SoftwareDistribution\Download\fc75a45b73372bd0c2a61e3a51d766ff\backup\sp2qfe\kernel32.dll
2004-08-04 02:56 983552 888190e31455fad793312f8d087146eb c:\windows1\system32\kernel32.dll
2004-08-04 02:56 983552 888190e31455fad793312f8d087146eb c:\windows1\system32\dllcache\kernel32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PowerBar"="c:\program files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" [2004-04-21 86016]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-03-17 2289664]
"ctfmon.exe"="c:\windows1\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"NvMediaCenter"="c:\windows1\system32\NvMcTray.dll" [2007-12-05 81920]
"NvCplDaemon"="c:\windows1\system32\NvCpl.dll" [2007-12-05 8523776]
"NeroFilterCheck"="c:\windows1\system32\NeroCheck.exe" [2001-07-09 155648]
"LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2008-05-22 249856]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2006-03-16 1397760]
"Easy Synchronization"="c:\program files\Logitech\Easy Synchronization\LogitechEasySync.exe" [2005-10-05 53248]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2008-05-22 177416]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-05-25 230928]
"nwiz"="nwiz.exe" [2007-12-05 c:\windows1\system32\nwiz.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows1\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows1\KHALMNPR.Exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 c:\windows1\system32\bthprops.cpl]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Easy Synchronization"="c:\program files\Logitech\Easy Synchronization\LogitechEasySync.exe" [2005-10-05 53248]
c:\documents and settings\All Users.WINDOWS1\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-08-04 805392]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{FE24CD78-7C63-465D-8787-4EDF7FC79895}"= "c:\program files\Logitech\Easy Synchronization\shellexecutehook.dll" [2005-10-05 69632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 02:42 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=idrdjg.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS1^Start Menu^Programs^Startup^AT&T Self Support Tool.lnk]
backup=c:\windows1\pss\AT&T Self Support Tool.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Dwayne^Start Menu^Programs^Startup^GameSpot Download Manager.lnk]
backup=c:\windows1\pss\GameSpot Download Manager.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\SetPoint\\LBTWiz.exe"=
"c:\\Program Files\\DVDFab 5\\DVDFab.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS1\\system32\\winver.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [2007-08-16 189704]
S1 511688f1;511688f1;c:\windows1\system32\drivers\511688f1.sys --> c:\windows1\system32\drivers\511688f1.sys [?]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-11-17 33752]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{16247ac4-cd07-11dd-9159-0007e964ea6d}]
\Shell\AutoRun\command - g:\wd_windows_tools\WDSetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57135e49-b7d9-11dd-914a-0007e964ea6d}]
\Shell\AutoRun\command - G:\start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57135e4b-b7d9-11dd-914a-0007e964ea6d}]
\Shell\AutoRun\command - G:\start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c54d4e2d-27e4-11dd-b334-0007e964ea6d}]
\Shell\AutoRun\command - F:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c54d4e2e-27e4-11dd-b334-0007e964ea6d}]
\Shell\AutoRun\command - G:\setup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-03-01 c:\windows1\Tasks\CAAntiSpywareScan_Daily as Dwayne at 9 51 PM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-08-16 22:10]
.
- - - - ORPHANS REMOVED - - - -
BHO-{D536A62A-CBE2-4CB2-9FCA-CA84CC7B0947} - (no file)
Notify-awtrQIYR - awtrQIYR.dll
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows1\system32\VetRedir.dll
DPF: Microsoft XML Parser for Java - file://c:\windows1\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Dwayne\Application Data\Mozilla\Firefox\Profiles\h80bg4l3.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-18 16:21:50
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1004336348-1364589140-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:66,05,a8,e9,38,bc,cc,d9,db,16,2d,8c,3d,a2,3e,5d,bf,8c,b0,0b,46,46,53,
14,c1,09,46,dd,3f,7a,95,3b,10,7d,df,fb,a7,88,c8,48,ea,83,3b,75,87,56,97,10,\
"??"=hex:2f,b6,6f,45,ee,e2,ec,0a,29,d5,69,d3,55,fd,2c,18
[HKEY_USERS\S-1-5-21-1004336348-1364589140-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:f8,20,f6,14,bf,77,72,a6,b1,d4,cd,6a,64,6c,6b,d9,dc,f5,1d,f7,46,
8a,2d,59,27,18,3d,ed,51,ee,09,4b,76,87,ea,5b,ae,98,79,dc,02,c7,55,b9,b7,c8,\
"rkeysecu"=hex:91,d9,2b,a9,04,e3,26,ab,5f,ec,f9,a8,47,d7,89,3e
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(756)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
- - - - - - - > 'lsass.exe'(812)
c:\windows1\system32\VetRedir.dll
c:\windows1\system32\ISafeIf.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Ahead\InCD\incdsrv.exe
c:\program files\Common Files\Logishrd\Bluetooth\LBTServ.exe
c:\windows1\system32\rundll32.exe
c:\windows1\system32\rundll32.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe
c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Logitech\Easy Synchronization\servicestub.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows1\system32\nvsvc32.exe
c:\windows1\system32\HPZipm12.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\CA\CA Internet Security Suite\ccprovsp.exe
c:\windows1\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-03-18 16:24:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-18 20:24:15
Pre-Run: 99,456,385,024 bytes free
Post-Run: 99,794,374,656 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS1
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS1="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
365 --- E O F --- 2009-01-30 01:49:20