there you go.
ComboFix 09-02-27.02 - Administrator 2009-02-27 22:42:30.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.636 [GMT -5:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated)
FW: BitDefender Firewall *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\vlc-0.9.4-win32.exe
c:\documents and settings\All Users\Application Data\vlc-0.9.6-win32.exe
c:\windows\system32\winio.dll
.
((((((((((((((((((((((((( Files Created from 2009-01-28 to 2009-02-28 )))))))))))))))))))))))))))))))
.
2009-02-27 22:41 . 2009-02-27 22:41 731 --a--c--- c:\windows\system32\BDUpdateV1.xml
2009-02-27 21:54 . 2009-02-27 21:54 <DIR> d----c--- c:\program files\Malwarebytes' Anti-Malware
2009-02-27 21:54 . 2009-02-27 21:54 <DIR> d----c--- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-27 21:54 . 2009-02-27 21:54 <DIR> d----c--- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-02-27 21:54 . 2009-02-11 10:19 38,496 --a--c--- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-27 21:54 . 2009-02-11 10:19 15,504 --a--c--- c:\windows\system32\drivers\mbam.sys
2009-02-25 09:53 . 2009-02-25 09:53 <DIR> d----c--- c:\program files\Trend Micro
2009-02-24 23:57 . 2009-02-24 23:57 <DIR> d----c--- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-02-19 09:58 . 2009-02-19 10:01 <DIR> d----c--- c:\program files\RegCure
2009-02-19 09:39 . 2009-02-22 19:02 <DIR> d----c--- c:\program files\Security Task Manager
2009-02-19 09:39 . 2009-02-19 09:49 <DIR> d----c--- c:\documents and settings\All Users\Application Data\SecTaskMan
2009-02-16 00:14 . 2009-02-16 00:17 <DIR> d----c--- c:\documents and settings\Administrator\Application Data\ErrorFix
2009-02-16 00:06 . 2009-02-16 00:06 23,392 --a--c--- c:\windows\system32\nscompat.tlb
2009-02-16 00:06 . 2009-02-16 00:06 16,832 --a--c--- c:\windows\system32\amcompat.tlb
2009-02-14 19:16 . 2009-02-14 19:16 <DIR> d----c--- c:\documents and settings\Administrator\Application Data\Xilisoft Corporation
2009-02-14 19:15 . 2009-02-14 19:15 <DIR> d----c--- c:\program files\Xilisoft
2009-02-14 17:52 . 2009-02-14 17:52 <DIR> d----c--- c:\documents and settings\Guest\Application Data\Windows Desktop Search
2009-02-14 17:52 . 2009-02-14 17:52 <DIR> d----c--- c:\documents and settings\Guest\Application Data\BitDefender
2009-02-12 13:50 . 2006-10-26 19:56 32,592 --a--c--- c:\windows\system32\msonpmon.dll
2009-02-12 13:47 . 2009-02-12 13:47 <DIR> d----c--- c:\program files\Microsoft Works
2009-02-12 13:46 . 2009-02-12 13:46 <DIR> d----c--- c:\program files\MSBuild
2009-02-12 13:43 . 2009-02-12 13:43 <DIR> d----c--- c:\program files\Microsoft.NET
2009-02-12 13:40 . 2009-02-12 13:40 <DIR> d----c--- c:\program files\Microsoft Visual Studio 8
2009-02-12 13:39 . 2009-02-12 13:45 <DIR> d----c--- c:\windows\SHELLNEW
2009-02-12 13:38 . 2009-02-12 13:51 <DIR> d----c--- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-12 13:37 . 2009-02-12 13:37 <DIR> dr-h-c--- C:\MSOCache
2009-02-12 13:25 . 2009-02-12 13:25 <DIR> d----c--- C:\ConverterOutput
2009-02-12 13:24 . 2009-02-12 13:24 <DIR> d----c--- c:\program files\Cucusoft
2009-02-12 13:24 . 2007-03-25 00:51 3,049,984 --a--c--- c:\windows\system32\libavcodec.dll
2009-02-12 13:24 . 2007-03-25 21:40 2,174,976 --a--c--- c:\windows\system32\ffdshow.ax
2009-02-12 13:24 . 2007-03-25 00:51 404,480 --a--c--- c:\windows\system32\libmplayer.dll
2009-02-12 13:24 . 2007-01-01 05:30 200,704 --a--c--- c:\windows\system32\TomsMoComp_ff.dll
2009-02-12 13:24 . 2006-07-08 04:07 114,688 --a--c--- c:\windows\system32\PropListCtrl.ocx
2009-02-12 13:24 . 2007-03-25 00:51 114,688 --a--c--- c:\windows\system32\libmpeg2_ff.dll
2009-02-12 13:24 . 2004-09-10 13:50 34,820 --a--c--- c:\windows\system32\ffdshow.reg
2009-02-12 09:43 . 2009-02-24 15:19 <DIR> d----c--- c:\program files\PeerGuardian2
2009-02-11 16:38 . 2009-02-27 22:42 121 --a--c--- c:\windows\bdagent.INI
2009-02-11 16:37 . 2009-02-11 16:37 <DIR> d----c--- c:\documents and settings\Administrator\Application Data\Windows Search
2009-02-11 16:34 . 2009-02-11 16:34 <DIR> d----c--- c:\windows\system32\GroupPolicy
2009-02-11 16:34 . 2009-02-11 16:34 <DIR> d----c--- c:\program files\Windows Desktop Search
2009-02-11 16:34 . 2009-02-11 16:34 <DIR> d----c--- c:\documents and settings\Administrator\Application Data\Windows Desktop Search
2009-02-11 16:32 . 2009-02-16 00:04 <DIR> d----c--- c:\program files\Windows Media Connect 2
2009-02-11 16:30 . 2009-02-11 16:31 <DIR> d----c--- c:\windows\system32\drivers\UMDF
2009-02-11 16:15 . 2009-02-11 16:15 850 --a--c--- c:\windows\system32\ProductTweaks.xml
2009-02-11 16:15 . 2009-02-11 16:15 385 --a--c--- c:\windows\system32\user_gensett.xml
2009-02-11 16:04 . 2009-02-27 22:41 81,984 --a--c--- c:\windows\system32\bdod.bin
2009-02-11 15:59 . 2009-02-11 15:59 <DIR> d----c--- c:\windows\system32\logs
2009-02-11 15:59 . 2009-02-11 15:59 <DIR> d----c--- c:\program files\BitDefender
2009-02-11 15:59 . 2009-02-11 16:02 <DIR> d----c--- c:\documents and settings\All Users\Application Data\BitDefender
2009-02-11 15:59 . 2009-02-11 15:59 <DIR> d----c--- c:\documents and settings\Administrator\Application Data\BitDefender
2009-02-11 15:59 . 2009-02-11 15:59 <DIR> d----c--- C:\Binaries
2009-02-11 15:57 . 2009-02-11 15:57 <DIR> d----c--- c:\windows\system32\URTTemp
2009-02-11 15:50 . 2009-02-11 15:59 <DIR> d----c--- c:\program files\Common Files\BitDefender
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-28 02:40 --------- dc----w c:\program files\lg_fwupdate
2009-02-27 19:28 --------- dc----w c:\documents and settings\Administrator\Application Data\uTorrent
2009-02-25 05:11 --------- dc----w c:\program files\LimeWire
2009-02-14 23:52 --------- dc----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-13 04:10 --------- dc----w c:\program files\7-Zip
2009-02-12 14:33 --------- dc----w c:\documents and settings\All Users\Application Data\WinZip
2009-02-11 21:04 104,328 -c--a-w c:\windows\system32\drivers\bdfndisf.sys
2009-01-25 20:56 --------- dc----w c:\documents and settings\Administrator\Application Data\Apple Computer
2009-01-23 21:30 --------- dc----w c:\program files\Apple Software Update
2009-01-23 21:30 --------- dc----w c:\documents and settings\All Users\Application Data\Apple
2009-01-20 16:13 --------- dc----w c:\program files\DivX
2009-01-14 19:42 --------- dc----w c:\program files\CDisplay
2009-01-07 19:48 --------- dc----w c:\documents and settings\All Users\Application Data\ATI MMC
2009-01-07 06:44 --------- dc----w c:\documents and settings\Administrator\Application Data\vlc
2008-12-20 23:15 826,368 -c--a-w c:\windows\system32\wininet.dll
2008-12-18 16:48 410,984 -c--a-w c:\windows\system32\deploytk.dll
2008-12-11 00:33 86,016 -c--a-w c:\windows\system32\dpl100.dll
2008-12-11 00:33 200,704 -c--a-w c:\windows\system32\dtu100.dll
2008-12-09 02:28 593,920 -c--a-w c:\windows\system32\dpuGUI11.dll
2008-12-09 02:28 57,344 -c--a-w c:\windows\system32\dpv11.dll
2008-12-09 02:28 344,064 -c--a-w c:\windows\system32\dpus11.dll
2008-12-09 02:28 294,912 -c--a-w c:\windows\system32\dpu11.dll
2008-10-05 19:53 22,328 -c--a-w c:\documents and settings\Administrator\Application Data\PnkBstrK.sys
2004-10-01 19:00 40,960 -c--a-w c:\program files\Uninstall_CDS.exe
2002-05-28 12:19 61,440 -c--a-w c:\windows\inf\i386\onetUSD.dll
2002-05-20 12:22 36,864 -c--a-w c:\windows\inf\i386\Vizmicro.dll
2002-05-20 12:20 172,032 -c--a-w c:\windows\inf\i386\viceo.dll
2002-05-20 12:02 225,280 -c--a-w c:\windows\inf\i386\rtscan.dll
2001-08-03 22:29 13,824 -c--a-w c:\windows\inf\i386\Usbscan.sys
2008-12-16 22:52 61,440 -c--a-w c:\program files\mozilla firefox\components\FFComm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATI Launchpad"="c:\program files\ATI Multimedia\main\launchpd.exe" [2004-06-15 106571]
"ATI Remote Control"="c:\program files\ATI Multimedia\RemCtrl\ATIRW.exe" [2004-04-16 196608]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2007-12-01 15360]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-04 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-10 339968]
"ATI DeviceDetect"="c:\program files\ATI Multimedia\main\ATIDtct.EXE" [2004-06-15 69705]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-18 136600]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-07-08 1397760]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2008-12-29 548864]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-07-28 185896]
"OneTouch Monitor"="c:\program files\Visioneer OneTouch\OneTouchMon.exe" [2002-05-28 86016]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-01-09 741376]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2008-10-17 69632]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 c:\windows\SOUNDMAN.EXE]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Supero Doctor III Client.lnk - c:\program files\SUPERMICRO\SDIII\SuperoDoctor.exe [2008-07-23 397312]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, credssp.dll, msnsspc.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroad
cast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R1 ISAIONT;ISAIONT;c:\windows\system32\drivers\IsaIoNt.sys [2008-07-23 3853]
R1 MemMapNt;MemMapNt;c:\windows\system32\drivers\memmapnt.sys [2008-07-23 3908]
R1 SMBus;SMBus;c:\windows\system32\drivers\smbus.sys [2008-07-23 10112]
R1 superbmc;superbmc;c:\windows\system32\drivers\SUPERBMC.SYS [2008-07-23 14169]
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [2008-10-06 82696]
R2 SuperMicro Health Assistant;SuperMicro Health Assistant;c:\program files\SUPERMICRO\SDIII\NTService.exe [2008-07-23 131072]
R2 Supero SD3Service Daemon;Supero SD3Service Daemon;c:\windows\system32\SD3Service.exe [2008-07-23 40960]
R2 Xitami;Xitami Web Server;c:\program files\SUPERMICRO\SDIII\xitami\xiwinnt.exe [2008-07-23 552960]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008-09-18 111112]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2008-10-17 104328]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-09-18 33752]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
Contents of the 'Scheduled Tasks' folder
2009-01-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-02-27 c:\windows\Tasks\ErrorFix Scan.job
- c:\program files\ErrorFix\ErrorFix.exe []
2009-02-27 c:\windows\Tasks\ErrorFix Scan.job
- c:\program files\ErrorFix []
2009-02-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-606747145-790525478-1417001333-500.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-04 00:32]
2009-02-28 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2009-02-13 23:20]
2009-02-26 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2009-02-13 23:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ig28otl2.default\
FF - prefs.js: browser.startup.homepage - ww.google.com
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-27 22:44:53
Windows 5.1.2600 Service Pack 3, v.5657 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\Administrator\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:8e,2e,5c,88,69,c3,a3,16,8f,2c,e2,70,9e,01,5e,ac,72,c1,33,82,c8,53,62,
df,5f,bc,e7,90,01,a3,5c,79,9e,f3,19,4a,c6,b7,2e,18,4b,6d,fd,df,a4,3c,c4,2c,\
"??"=hex:0f,48,1a,76,ce,fe,3d,eb,b8,9e,e1,3e,48,7b,fe,fd
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1008)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-02-27 22:46:56
ComboFix-quarantined-files.txt 2009-02-28 03:46:42
Pre-Run: 105,960,312,832 bytes free
Post-Run: 106,018,836,480 bytes free
220 --- E O F --- 2009-02-27 05:01:06