i know but who ever is doing the downloading of the code stuff i m fixing to put a Knot on his head ha ha any way i have the 2 logs here tComboFix 09-04-30.05 - Andy 04/30/2009 18:41.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1983.1418 [GMT -5:00]
Running from: c:\documents and settings\Andy\Desktop\ComboFix.exe1.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
.
((((((((((((((((((((((((( Files Created from 2009-03-28 to 2009-04-30 )))))))))))))))))))))))))))))))
.
2009-04-30 22:08 . 2009-04-30 22:08 -------- d-----w C:\_OTMoveIt
2009-04-30 21:19 . 2009-04-30 22:50 -------- d-----w C:\Lop SD
2009-04-30 20:49 . 2009-04-30 20:58 -------- d-----w c:\program files\Trend Micro
2009-04-30 20:04 . 2009-04-30 20:04 -------- d-----w c:\documents and settings\Andy\Application Data\Malwarebytes
2009-04-30 20:03 . 2009-04-06 20:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-30 20:03 . 2009-04-06 20:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-30 20:03 . 2009-04-30 20:03 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-30 20:03 . 2009-04-30 20:03 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-30 19:41 . 2009-04-30 22:19 -------- d-----w c:\program files\NoAdware
2009-04-30 17:28 . 2009-04-30 17:28 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-04-30 17:28 . 2009-04-30 17:28 -------- d-----w c:\program files\SUPERAntiSpyware
2009-04-30 17:28 . 2009-04-30 17:28 -------- d-----w c:\documents and settings\Andy\Application Data\SUPERAntiSpyware.com
2009-04-30 17:27 . 2009-04-30 17:27 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-04-30 15:31 . 2009-04-30 17:12 -------- d-----w c:\program files\EsetOnlineScanner
2009-04-30 14:19 . 2009-04-30 14:19 -------- d-----w c:\windows\system32\XPSViewer
2009-04-30 14:18 . 2009-04-30 14:18 -------- d-----w c:\program files\MSBuild
2009-04-30 14:18 . 2009-04-30 14:18 -------- d-----w c:\program files\Reference Assemblies
2009-04-30 14:18 . 2008-07-06 12:06 117760 ------w c:\windows\system32\prntvpt.dll
2009-04-30 14:18 . 2008-07-06 12:06 89088 -c----w c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-04-30 14:18 . 2008-07-06 10:50 597504 -c----w c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-04-30 14:18 . 2008-07-06 12:06 575488 -c----w c:\windows\system32\dllcache\xpsshhdr.dll
2009-04-30 14:18 . 2008-07-06 12:06 575488 ------w c:\windows\system32\xpsshhdr.dll
2009-04-30 14:18 . 2008-07-06 12:06 1676288 -c----w c:\windows\system32\dllcache\xpssvcs.dll
2009-04-30 14:18 . 2008-07-06 12:06 1676288 ------w c:\windows\system32\xpssvcs.dll
2009-04-30 14:18 . 2009-04-30 14:21 -------- d-----w c:\windows\SxsCaPendDel
2009-04-27 20:48 . 2009-04-27 20:48 -------- d-----w c:\documents and settings\Andy\Application Data\PlayFirst
2009-04-27 20:48 . 2009-04-27 20:48 -------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2009-04-27 20:47 . 2009-04-27 21:51 -------- d-----w C:\My Games
2009-04-27 20:47 . 2009-04-27 20:47 -------- d-----w c:\documents and settings\All Users\Application Data\RealArcade
2009-04-27 20:47 . 2009-04-27 20:47 -------- d-----w C:\users
2009-04-27 20:46 . 2009-04-27 21:51 -------- d-----w c:\program files\RealArcade
2009-04-27 17:32 . 2009-04-27 17:32 -------- d-----w c:\documents and settings\All Users\Application Data\FloodLightGames
2009-04-27 17:32 . 2009-04-27 17:32 -------- d-----w c:\documents and settings\Andy\Saved Games
2009-04-27 17:32 . 2009-04-27 17:32 -------- d-----w c:\documents and settings\Andy\Application Data\FloodLightGames
2009-04-21 04:48 . 2009-04-21 04:48 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-04-20 04:28 . 2009-04-20 04:28 -------- d-sh--w c:\documents and settings\Andy\IECompatCache
2009-04-20 04:22 . 2009-04-20 04:22 -------- d-sh--w c:\documents and settings\Andy\PrivacIE
2009-04-20 04:19 . 2009-04-20 04:19 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-04-20 04:19 . 2009-04-20 04:19 -------- d-sh--w c:\documents and settings\Andy\IETldCache
2009-04-20 04:18 . 2009-04-20 04:18 -------- d-----w c:\windows\ie8updates
2009-04-20 04:16 . 2009-04-20 04:16 -------- dc-h--w c:\windows\ie8
2009-04-20 04:14 . 2009-02-28 04:55 105984 -c----w c:\windows\system32\dllcache\iecompat.dll
2009-04-16 17:04 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-16 17:04 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 17:04 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-16 17:04 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 17:04 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 17:04 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 17:04 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 17:04 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 17:04 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 17:04 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-16 17:04 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-15 05:32 . 2009-04-15 05:32 -------- d-----w c:\documents and settings\Andy\Application Data\Joost
2009-04-15 05:32 . 2009-04-15 05:32 -------- d-----w c:\documents and settings\Andy\Local Settings\Application Data\Joost
2009-04-14 12:23 . 2009-03-09 19:06 15688 ----a-w c:\windows\system32\lsdelete.exe
2009-04-14 04:48 . 2009-04-28 04:48 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-04-14 04:43 . 2009-04-30 22:15 -------- d-----w C:\ProgramData
2009-04-14 04:43 . 2009-04-14 04:43 -------- d-----w c:\program files\Angle Interactive
2009-04-14 04:42 . 2009-04-14 04:42 -------- dc-h--w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-04-14 04:42 . 2009-04-14 04:42 -------- d-----w c:\program files\Lavasoft
2009-04-13 07:38 . 2009-04-13 07:38 -------- d-----w c:\windows\system32\help
2009-04-13 07:21 . 2008-12-05 02:42 815104 ----a-w c:\windows\system32\xvidcore.dll
2009-04-13 07:21 . 2008-12-05 02:46 180224 ----a-w c:\windows\system32\xvidvfw.dll
2009-04-13 07:21 . 2009-04-13 07:21 -------- d-----w c:\program files\Xvid
2009-04-13 07:07 . 2009-04-13 07:31 -------- d-----w c:\documents and settings\Andy\Application Data\vlc
2009-04-13 06:08 . 2009-04-13 06:10 -------- d-----w c:\program files\XtalViD-Codec
2009-04-13 05:45 . 2009-04-13 05:51 -------- d-----w c:\program files\Xvid Decoder
2009-04-12 21:47 . 2009-04-12 21:47 -------- d-----w c:\program files\Common Files\DivX Shared
2009-04-10 16:39 . 2009-04-28 23:14 -------- d-----w c:\program files\Oberon Media
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-30 22:48 . 2008-12-27 17:57 -------- d-----w c:\program files\Viewpoint
2009-04-30 22:22 . 2008-07-12 04:54 67848 ----a-w c:\documents and settings\Andy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-30 20:41 . 2008-07-12 04:20 -------- d-----w c:\program files\Java
2009-04-30 03:00 . 2009-02-15 14:52 -------- d-----w c:\program files\Norton Security Scan
2009-04-27 03:01 . 2009-02-15 14:52 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-21 20:47 . 2008-08-04 04:34 -------- d-----w c:\program files\Microsoft Silverlight
2009-04-12 21:48 . 2008-07-30 11:49 -------- d-----w c:\program files\DivX
2009-03-28 02:54 . 2009-03-28 02:54 -------- d-----w c:\program files\Unibrain
2009-03-28 02:52 . 2009-03-28 02:52 -------- d-----w c:\program files\Intel Desktop Board
2009-03-28 02:43 . 2009-03-27 03:16 -------- d-----w c:\program files\Common Files\Logitech
2009-03-27 03:17 . 2009-03-27 03:17 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-03-27 03:17 . 2009-03-27 03:17 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-03-27 03:16 . 2009-03-27 03:16 -------- d-----w c:\program files\Logitech
2009-03-27 03:16 . 2008-07-12 03:56 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-27 02:56 . 2009-03-27 02:56 -------- d-----w c:\program files\PC Drivers HeadQuarters
2009-03-14 06:48 . 2009-03-14 06:48 -------- d-----w c:\program files\Microsoft
2009-03-14 06:47 . 2009-01-18 03:28 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 09:34 . 2004-08-04 12:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 09:34 . 2004-08-04 12:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 09:33 . 2004-08-04 12:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 09:33 . 2004-08-04 12:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 09:32 . 2004-08-04 12:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 09:32 . 2004-08-04 12:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 09:31 . 2004-08-04 12:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 09:31 . 2004-08-04 12:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 09:31 . 2004-08-04 12:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 09:22 . 2004-08-04 12:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2004-08-04 12:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-02 05:51 . 2008-12-27 19:05 -------- d-----w c:\program files\Common Files\Autodesk Shared
2009-03-02 05:49 . 2008-12-27 19:05 -------- d-----w c:\program files\Autodesk
2009-03-02 05:47 . 2008-12-28 09:42 -------- d-----w c:\program files\AnswerWorks 4.0
2009-03-02 05:00 . 2008-12-28 09:41 -------- d-----w c:\program files\AutoCAD 2004
2009-03-02 05:00 . 2009-01-08 04:58 -------- d-----w c:\program files\Common Files\Macrovision Shared
2009-02-24 19:34 . 2009-02-24 19:34 90112 ----a-w c:\windows\system32\dpl100.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 ----a-w c:\windows\system32\divx_xx0c.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 ----a-w c:\windows\system32\divx_xx07.dll
2009-02-24 19:34 . 2009-02-24 19:34 815104 ----a-w c:\windows\system32\divx_xx0a.dll
2009-02-24 19:34 . 2009-02-24 19:34 802816 ----a-w c:\windows\system32\divx_xx11.dll
2009-02-24 19:34 . 2009-02-24 19:34 684032 ----a-w c:\windows\system32\DivX.dll
2009-02-17 04:17 . 2008-07-12 03:52 453152 ----a-w c:\windows\system32\NVUNINST.EXE
2009-02-09 12:10 . 2004-08-04 12:00 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-04 12:00 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-04 12:00 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-04 12:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2004-08-04 12:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2004-08-04 12:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2004-08-04 12:00 2145280 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-04 12:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2004-08-03 22:59 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 19:59 . 2004-08-04 12:00 56832 ----a-w c:\windows\system32\secur32.dll
2009-01-31 14:19 . 2009-01-18 17:38 10520 ----a-w c:\windows\system32\avgrsstx.dll
2009-01-31 14:19 . 2009-01-18 17:38 325128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-31 14:18 . 2009-01-18 17:38 107272 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-04-30_23.16.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-30 23:30 . 2009-04-30 23:30 16384 c:\windows\Temp\Perflib_Perfdata_148.dat
+ 2008-07-11 21:48 . 2009-04-30 23:30 259840 c:\windows\system32\FNTCACHE.DAT
- 2008-07-11 21:48 . 2009-04-30 14:21 259840 c:\windows\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-20 4363504]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-23 68856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-04-28 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-07-12 925696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-03 116040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-09 289064]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-08-10 221184]
"DMXLauncher"="c:\program files\Roxio\Media Experience\DMXLauncher.exe" [2006-08-14 102400]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-07-31 1116920]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2009-02-27 38768]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-02-27 640376]
"dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2008-11-18 827904]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-14 148888]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-04-28 516440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-18 1657376]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-3-27 692224]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 14:19 10520 ----a-w c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^The University of Oklahoma OU-VPN Client.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\The University of Oklahoma OU-VPN Client.lnk
backup=c:\windows\pss\The University of Oklahoma OU-VPN Client.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Joost\\xulrunner\\tvprunner.exe"=
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-04-28 953168]
R3 AWINDIS5;AWINDIS5 Protocol Driver;c:\windows\system32\AWINDIS5.SYS [2002-04-11 16194]
R3 EraserUtilDrv10910;EraserUtilDrv10910;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys [2009-04-27 101936]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-04-28 64160]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-01-31 325128]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-01-31 107272]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-04-28 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-04-28 72944]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-31 903960]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-31 298264]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S2 ubsbm;Unibrain 1394 SBM Driver;c:\windows\system32\DRIVERS\ubsbm.sys [2005-07-27 14080]
S2 ubumapi;Unibrain 1394 FireAPI Driver;c:\windows\system32\DRIVERS\ubumapi.sys [2005-07-27 36352]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-04 13592]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-04-28 7408]
S3 ubohci;Unibrain 1394 OHCI Driver;c:\windows\system32\DRIVERS\ubohci.sys [2005-07-27 77056]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b8c6579c-598d-11dd-8679-0016b6531647}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-04-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 04:48]
2009-04-30 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-23 23:00]
2009-04-30 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
2009-04-30 c:\windows\Tasks\Norton Security Scan for Andy.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 01:20]
.
.
------- Supplementary Scan -------
.
uLocal Page = \blank.htm
uStart Page = hxxp://www.cnn.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
FF - ProfilePath - c:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\2xnqv335.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q=
FF - prefs.js: browser.search.selectedEngine - FireSearch
FF - prefs.js: browser.startup.homepage - hxxp://www2.firesearch.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-30 18:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1040)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(3584)
c:\windows\system32\nview.dll
c:\program files\Common Files\Ahead\Lib\NeroSearchBar.dll
c:\program files\Common Files\Ahead\Lib\MFC71U.DLL
c:\program files\Common Files\Ahead\Lib\BCGCBPRO860un71.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-04-30 18:44
ComboFix-quarantined-files.txt 2009-04-30 23:44
ComboFix2.txt 2009-04-30 23:17
Pre-Run: 9,526,657,024 bytes free
Post-Run: 9,523,359,744 bytes free
296 --- E O F --- 2009-04-30 17:51
hey are ok bu the way the computer is running great at the moment no pop ups so far ComboFix 09-04-30.05 - Andy 04/30/2009 18:41.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1983.1418 [GMT -5:00]
Running from: c:\documents and settings\Andy\Desktop\ComboFix.exe1.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
.
((((((((((((((((((((((((( Files Created from 2009-03-28 to 2009-04-30 )))))))))))))))))))))))))))))))
.
2009-04-30 22:08 . 2009-04-30 22:08 -------- d-----w C:\_OTMoveIt
2009-04-30 21:19 . 2009-04-30 22:50 -------- d-----w C:\Lop SD
2009-04-30 20:49 . 2009-04-30 20:58 -------- d-----w c:\program files\Trend Micro
2009-04-30 20:04 . 2009-04-30 20:04 -------- d-----w c:\documents and settings\Andy\Application Data\Malwarebytes
2009-04-30 20:03 . 2009-04-06 20:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-30 20:03 . 2009-04-06 20:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-30 20:03 . 2009-04-30 20:03 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-30 20:03 . 2009-04-30 20:03 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-30 19:41 . 2009-04-30 22:19 -------- d-----w c:\program files\NoAdware
2009-04-30 17:28 . 2009-04-30 17:28 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-04-30 17:28 . 2009-04-30 17:28 -------- d-----w c:\program files\SUPERAntiSpyware
2009-04-30 17:28 . 2009-04-30 17:28 -------- d-----w c:\documents and settings\Andy\Application Data\SUPERAntiSpyware.com
2009-04-30 17:27 . 2009-04-30 17:27 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-04-30 15:31 . 2009-04-30 17:12 -------- d-----w c:\program files\EsetOnlineScanner
2009-04-30 14:19 . 2009-04-30 14:19 -------- d-----w c:\windows\system32\XPSViewer
2009-04-30 14:18 . 2009-04-30 14:18 -------- d-----w c:\program files\MSBuild
2009-04-30 14:18 . 2009-04-30 14:18 -------- d-----w c:\program files\Reference Assemblies
2009-04-30 14:18 . 2008-07-06 12:06 117760 ------w c:\windows\system32\prntvpt.dll
2009-04-30 14:18 . 2008-07-06 12:06 89088 -c----w c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-04-30 14:18 . 2008-07-06 10:50 597504 -c----w c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-04-30 14:18 . 2008-07-06 12:06 575488 -c----w c:\windows\system32\dllcache\xpsshhdr.dll
2009-04-30 14:18 . 2008-07-06 12:06 575488 ------w c:\windows\system32\xpsshhdr.dll
2009-04-30 14:18 . 2008-07-06 12:06 1676288 -c----w c:\windows\system32\dllcache\xpssvcs.dll
2009-04-30 14:18 . 2008-07-06 12:06 1676288 ------w c:\windows\system32\xpssvcs.dll
2009-04-30 14:18 . 2009-04-30 14:21 -------- d-----w c:\windows\SxsCaPendDel
2009-04-27 20:48 . 2009-04-27 20:48 -------- d-----w c:\documents and settings\Andy\Application Data\PlayFirst
2009-04-27 20:48 . 2009-04-27 20:48 -------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2009-04-27 20:47 . 2009-04-27 21:51 -------- d-----w C:\My Games
2009-04-27 20:47 . 2009-04-27 20:47 -------- d-----w c:\documents and settings\All Users\Application Data\RealArcade
2009-04-27 20:47 . 2009-04-27 20:47 -------- d-----w C:\users
2009-04-27 20:46 . 2009-04-27 21:51 -------- d-----w c:\program files\RealArcade
2009-04-27 17:32 . 2009-04-27 17:32 -------- d-----w c:\documents and settings\All Users\Application Data\FloodLightGames
2009-04-27 17:32 . 2009-04-27 17:32 -------- d-----w c:\documents and settings\Andy\Saved Games
2009-04-27 17:32 . 2009-04-27 17:32 -------- d-----w c:\documents and settings\Andy\Application Data\FloodLightGames
2009-04-21 04:48 . 2009-04-21 04:48 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-04-20 04:28 . 2009-04-20 04:28 -------- d-sh--w c:\documents and settings\Andy\IECompatCache
2009-04-20 04:22 . 2009-04-20 04:22 -------- d-sh--w c:\documents and settings\Andy\PrivacIE
2009-04-20 04:19 . 2009-04-20 04:19 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-04-20 04:19 . 2009-04-20 04:19 -------- d-sh--w c:\documents and settings\Andy\IETldCache
2009-04-20 04:18 . 2009-04-20 04:18 -------- d-----w c:\windows\ie8updates
2009-04-20 04:16 . 2009-04-20 04:16 -------- dc-h--w c:\windows\ie8
2009-04-20 04:14 . 2009-02-28 04:55 105984 -c----w c:\windows\system32\dllcache\iecompat.dll
2009-04-16 17:04 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-16 17:04 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 17:04 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-16 17:04 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 17:04 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 17:04 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 17:04 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 17:04 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 17:04 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 17:04 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-16 17:04 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-15 05:32 . 2009-04-15 05:32 -------- d-----w c:\documents and settings\Andy\Application Data\Joost
2009-04-15 05:32 . 2009-04-15 05:32 -------- d-----w c:\documents and settings\Andy\Local Settings\Application Data\Joost
2009-04-14 12:23 . 2009-03-09 19:06 15688 ----a-w c:\windows\system32\lsdelete.exe
2009-04-14 04:48 . 2009-04-28 04:48 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-04-14 04:43 . 2009-04-30 22:15 -------- d-----w C:\ProgramData
2009-04-14 04:43 . 2009-04-14 04:43 -------- d-----w c:\program files\Angle Interactive
2009-04-14 04:42 . 2009-04-14 04:42 -------- dc-h--w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-04-14 04:42 . 2009-04-14 04:42 -------- d-----w c:\program files\Lavasoft
2009-04-13 07:38 . 2009-04-13 07:38 -------- d-----w c:\windows\system32\help
2009-04-13 07:21 . 2008-12-05 02:42 815104 ----a-w c:\windows\system32\xvidcore.dll
2009-04-13 07:21 . 2008-12-05 02:46 180224 ----a-w c:\windows\system32\xvidvfw.dll
2009-04-13 07:21 . 2009-04-13 07:21 -------- d-----w c:\program files\Xvid
2009-04-13 07:07 . 2009-04-13 07:31 -------- d-----w c:\documents and settings\Andy\Application Data\vlc
2009-04-13 06:08 . 2009-04-13 06:10 -------- d-----w c:\program files\XtalViD-Codec
2009-04-13 05:45 . 2009-04-13 05:51 -------- d-----w c:\program files\Xvid Decoder
2009-04-12 21:47 . 2009-04-12 21:47 -------- d-----w c:\program files\Common Files\DivX Shared
2009-04-10 16:39 . 2009-04-28 23:14 -------- d-----w c:\program files\Oberon Media
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-30 22:48 . 2008-12-27 17:57 -------- d-----w c:\program files\Viewpoint
2009-04-30 22:22 . 2008-07-12 04:54 67848 ----a-w c:\documents and settings\Andy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-30 20:41 . 2008-07-12 04:20 -------- d-----w c:\program files\Java
2009-04-30 03:00 . 2009-02-15 14:52 -------- d-----w c:\program files\Norton Security Scan
2009-04-27 03:01 . 2009-02-15 14:52 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-21 20:47 . 2008-08-04 04:34 -------- d-----w c:\program files\Microsoft Silverlight
2009-04-12 21:48 . 2008-07-30 11:49 -------- d-----w c:\program files\DivX
2009-03-28 02:54 . 2009-03-28 02:54 -------- d-----w c:\program files\Unibrain
2009-03-28 02:52 . 2009-03-28 02:52 -------- d-----w c:\program files\Intel Desktop Board
2009-03-28 02:43 . 2009-03-27 03:16 -------- d-----w c:\program files\Common Files\Logitech
2009-03-27 03:17 . 2009-03-27 03:17 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-03-27 03:17 . 2009-03-27 03:17 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-03-27 03:16 . 2009-03-27 03:16 -------- d-----w c:\program files\Logitech
2009-03-27 03:16 . 2008-07-12 03:56 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-27 02:56 . 2009-03-27 02:56 -------- d-----w c:\program files\PC Drivers HeadQuarters
2009-03-14 06:48 . 2009-03-14 06:48 -------- d-----w c:\program files\Microsoft
2009-03-14 06:47 . 2009-01-18 03:28 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 09:34 . 2004-08-04 12:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 09:34 . 2004-08-04 12:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 09:33 . 2004-08-04 12:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 09:33 . 2004-08-04 12:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 09:32 . 2004-08-04 12:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 09:32 . 2004-08-04 12:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 09:31 . 2004-08-04 12:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 09:31 . 2004-08-04 12:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 09:31 . 2004-08-04 12:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 09:22 . 2004-08-04 12:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2004-08-04 12:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-02 05:51 . 2008-12-27 19:05 -------- d-----w c:\program files\Common Files\Autodesk Shared
2009-03-02 05:49 . 2008-12-27 19:05 -------- d-----w c:\program files\Autodesk
2009-03-02 05:47 . 2008-12-28 09:42 -------- d-----w c:\program files\AnswerWorks 4.0
2009-03-02 05:00 . 2008-12-28 09:41 -------- d-----w c:\program files\AutoCAD 2004
2009-03-02 05:00 . 2009-01-08 04:58 -------- d-----w c:\program files\Common Files\Macrovision Shared
2009-02-24 19:34 . 2009-02-24 19:34 90112 ----a-w c:\windows\system32\dpl100.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 ----a-w c:\windows\system32\divx_xx0c.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 ----a-w c:\windows\system32\divx_xx07.dll
2009-02-24 19:34 . 2009-02-24 19:34 815104 ----a-w c:\windows\system32\divx_xx0a.dll
2009-02-24 19:34 . 2009-02-24 19:34 802816 ----a-w c:\windows\system32\divx_xx11.dll
2009-02-24 19:34 . 2009-02-24 19:34 684032 ----a-w c:\windows\system32\DivX.dll
2009-02-17 04:17 . 2008-07-12 03:52 453152 ----a-w c:\windows\system32\NVUNINST.EXE
2009-02-09 12:10 . 2004-08-04 12:00 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-04 12:00 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-04 12:00 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-04 12:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2004-08-04 12:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2004-08-04 12:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2004-08-04 12:00 2145280 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-04 12:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2004-08-03 22:59 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 19:59 . 2004-08-04 12:00 56832 ----a-w c:\windows\system32\secur32.dll
2009-01-31 14:19 . 2009-01-18 17:38 10520 ----a-w c:\windows\system32\avgrsstx.dll
2009-01-31 14:19 . 2009-01-18 17:38 325128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-31 14:18 . 2009-01-18 17:38 107272 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-04-30_23.16.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-30 23:30 . 2009-04-30 23:30 16384 c:\windows\Temp\Perflib_Perfdata_148.dat
+ 2008-07-11 21:48 . 2009-04-30 23:30 259840 c:\windows\system32\FNTCACHE.DAT
- 2008-07-11 21:48 . 2009-04-30 14:21 259840 c:\windows\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-20 4363504]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-23 68856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-04-28 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-07-12 925696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-03 116040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-09 289064]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-08-10 221184]
"DMXLauncher"="c:\program files\Roxio\Media Experience\DMXLauncher.exe" [2006-08-14 102400]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-07-31 1116920]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2009-02-27 38768]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-02-27 640376]
"dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2008-11-18 827904]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-14 148888]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-04-28 516440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-18 1657376]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-3-27 692224]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 14:19 10520 ----a-w c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^The University of Oklahoma OU-VPN Client.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\The University of Oklahoma OU-VPN Client.lnk
backup=c:\windows\pss\The University of Oklahoma OU-VPN Client.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Joost\\xulrunner\\tvprunner.exe"=
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-04-28 953168]
R3 AWINDIS5;AWINDIS5 Protocol Driver;c:\windows\system32\AWINDIS5.SYS [2002-04-11 16194]
R3 EraserUtilDrv10910;EraserUtilDrv10910;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys [2009-04-27 101936]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-04-28 64160]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-01-31 325128]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-01-31 107272]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-04-28 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-04-28 72944]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-31 903960]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-31 298264]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S2 ubsbm;Unibrain 1394 SBM Driver;c:\windows\system32\DRIVERS\ubsbm.sys [2005-07-27 14080]
S2 ubumapi;Unibrain 1394 FireAPI Driver;c:\windows\system32\DRIVERS\ubumapi.sys [2005-07-27 36352]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-04 13592]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-04-28 7408]
S3 ubohci;Unibrain 1394 OHCI Driver;c:\windows\system32\DRIVERS\ubohci.sys [2005-07-27 77056]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b8c6579c-598d-11dd-8679-0016b6531647}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-04-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 04:48]
2009-04-30 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-23 23:00]
2009-04-30 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
2009-04-30 c:\windows\Tasks\Norton Security Scan for Andy.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 01:20]
.
.
------- Supplementary Scan -------
.
uLocal Page = \blank.htm
uStart Page = hxxp://www.cnn.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
FF - ProfilePath - c:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\2xnqv335.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q=
FF - prefs.js: browser.search.selectedEngine - FireSearch
FF - prefs.js: browser.startup.homepage - hxxp://www2.firesearch.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-30 18:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1040)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(3584)
c:\windows\system32\nview.dll
c:\program files\Common Files\Ahead\Lib\NeroSearchBar.dll
c:\program files\Common Files\Ahead\Lib\MFC71U.DLL
c:\program files\Common Files\Ahead\Lib\BCGCBPRO860un71.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-04-30 18:44
ComboFix-quarantined-files.txt 2009-04-30 23:44
ComboFix2.txt 2009-04-30 23:17
Pre-Run: 9,526,657,024 bytes free
Post-Run: 9,523,359,744 bytes free
296 --- E O F --- 2009-04-30 17:51
thank you so much for your time and effort