This is ComboFix log 2
ComboFix 09-07-08.04 - Administrator 07/09/2009 21:40.2 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.383.241 [GMT -7:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: f:\scanlogs\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
"c:\winnt\system32\drivers\f609df78.sys"
"c:\winnt\Tasks\ParetoLogic Registration.job"
"c:\winnt\Tasks\ParetoLogic Update Version2.job"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\ParetoLogic
c:\documents and settings\All Users\Application Data\ParetoLogic\UUS2\DriverCure\Master.xml
c:\documents and settings\All Users\Application Data\ParetoLogic\UUS2\DriverCure\Patch.xml
c:\documents and settings\All Users\Application Data\ParetoLogic\UUS2\DriverCure\Temp\Update.exe
c:\documents and settings\All Users\Application Data\ParetoLogic\UUS2\DriverCure\Update.xml
c:\documents and settings\All Users\Application Data\ParetoLogic\UUS2\Master.xml
c:\documents and settings\All Users\Application Data\ParetoLogic\UUS2\Patch.xml
c:\documents and settings\All Users\Application Data\ParetoLogic\UUS2\Update.xml
c:\program files\Common Files\ParetoLogic
c:\program files\Common Files\ParetoLogic\UUS2\Images\Logo.png
c:\program files\Common Files\ParetoLogic\UUS2\LiteUnzip.dll
c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe
c:\program files\Common Files\ParetoLogic\UUS2\ParetoLogicUpdate.chm
c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll
c:\program files\Viewpoint
c:\program files\Viewpoint\Common\ViewpointService.exe
c:\program files\Viewpoint\Common\VistaBoot.sdll
c:\program files\Viewpoint\Viewpoint Manager\CPtask.xml
c:\program files\Viewpoint\Viewpoint Manager\VETScriptInterpreter.dll
c:\program files\Viewpoint\Viewpoint Manager\ViewCP.cpl
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\s.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_av.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_cp.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_up.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bg.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bottom.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab_bg.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_off.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_on.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_off.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_on.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vwpt_logo.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\options.ini
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\viewpoint.ico
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\vmctrl.html
c:\program files\Viewpoint\Viewpoint Manager\ViewCPexe.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgrCore.dll
c:\program files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream_.dll
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream_0305000D.dll
c:\program files\Viewpoint\Viewpoint Media Player\ClassIDs.ini
c:\program files\Viewpoint\Viewpoint Media Player\ComponentMgr_0305001C.dll
c:\program files\Viewpoint\Viewpoint Media Player\ComponentRegistry.ini
c:\program files\Viewpoint\Viewpoint Media Player\Components\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\Cursors.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\DataTracking.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\JpegReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\MTS3Reader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SceneComponent.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SreeDMMX.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SWFView.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMgr.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPSpeech.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPVideo.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPVideo2.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\WaveletReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\DownLoadHist.ini
c:\program files\Viewpoint\Viewpoint Media Player\HostRegistry.ini
c:\program files\Viewpoint\Viewpoint Media Player\MetaStreamConfig.ini
c:\program files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
c:\program files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
c:\program files\Viewpoint\Viewpoint Media Player\MTSDownloadSites.txt
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\Cursors.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\JpegReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\MTS3Reader.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\SreeDMMX.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\SWFView.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\VMPVideo2.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\WaveletReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_01\-1159435808.mtx
c:\program files\Viewpoint\Viewpoint Media Player\Resources\UpdateVersionList_v2.mtx
c:\program files\Viewpoint\Viewpoint Toolbar\3.9.0\eula.txt
c:\program files\Viewpoint\Viewpoint Toolbar\3.9.0\Uninstaller.exe
c:\program files\Viewpoint\Viewpoint Toolbar\3.9.0\ViewBarBHO.dll
c:\program files\Viewpoint\Viewpoint Toolbar\3.9.0\ViewBarSystemInfo.dll
c:\program files\Viewpoint\Viewpoint Toolbar\delB5.tmp\delB6.tmp
c:\program files\Viewpoint\Viewpoint Toolbar\delB5.tmp\delB7.tmp
c:\winnt\system32\drivers\f609df78.sys
c:\winnt\Tasks\ParetoLogic Registration.job
c:\winnt\Tasks\ParetoLogic Update Version2.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_fc98e6536a9f048e41a65f73efc2525e
-------\Legacy_VIEWPOINT_MANAGER_SERVICE
-------\Service_26d261c5
-------\Service_c1fd68c2
-------\Service_f609df78
-------\Service_fc98e6536a9f048e41a65f73efc2525e
-------\Service_Viewpoint Manager Service
((((((((((((((((((((((((( Files Created from 2009-06-10 to 2009-07-10 )))))))))))))))))))))))))))))))
.
2009-07-09 19:35 . 2009-07-09 19:35 -------- d-----w- c:\documents and settings\Administrator\Application Data\Sprint
2009-07-09 19:15 . 2009-07-09 19:15 -------- d-----w- c:\documents and settings\Bill\Application Data\Sprint
2009-07-09 19:04 . 2008-10-15 18:58 27072 ----a-w- c:\winnt\system32\drivers\PCASp50.sys
2009-07-09 19:03 . 2005-03-15 18:11 17920 ----a-w- c:\winnt\system32\apintfnt.dll
2009-07-09 19:03 . 2008-04-13 17:45 17152 ----a-w- c:\winnt\system32\drivers\usbohci.sys
2009-07-09 19:03 . 2008-04-13 17:45 17152 ----a-w- c:\winnt\system32\dllcache\usbohci.sys
2009-07-09 19:01 . 2007-01-18 17:24 26496 ----a-r- c:\winnt\system32\drivers\RimSerial.sys
2009-07-09 18:55 . 2009-07-09 18:55 -------- d-----w- c:\program files\Common Files\Research in Motion
2009-07-09 18:55 . 2009-07-09 19:03 -------- d-----w- c:\program files\Sierra Wireless
2009-07-09 18:54 . 2009-07-09 19:02 -------- d-----w- c:\program files\Common Files\Motorola Shared
2009-07-09 18:54 . 2009-07-09 18:54 -------- d-----w- c:\program files\Novatel Wireless
2009-07-09 18:54 . 2009-07-09 18:54 -------- d-----w- c:\program files\Sprint
2009-07-09 18:54 . 2009-07-09 18:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Sprint
2009-07-09 18:45 . 2009-07-09 18:45 -------- d-----w- c:\documents and settings\Bill\Application Data\Sierra Wireless
2009-07-09 17:43 . 2009-07-09 17:48 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory
2009-07-09 17:35 . 2009-07-09 17:35 -------- d-----w- c:\program files\Sierra Wireless Inc
2009-07-09 17:35 . 2009-07-09 17:35 -------- d-----w- c:\documents and settings\Administrator\Application Data\Sierra Wireless
2009-07-08 19:56 . 2009-07-08 19:56 -------- d-----w- c:\documents and settings\Administrator\Application Data\DriverCure
2009-07-08 19:55 . 2009-07-10 01:06 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-08 19:53 . 2009-07-08 19:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-07-08 18:45 . 2009-07-09 19:23 117760 ----a-w- c:\documents and settings\Bill\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-08 18:42 . 2009-07-08 18:42 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-07-08 18:41 . 2009-07-08 22:30 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-07-08 18:41 . 2009-07-08 18:41 -------- d-----w- c:\documents and settings\Bill\Application Data\SUPERAntiSpyware.com
2009-07-08 07:38 . 2009-07-08 07:38 -------- d-----w- c:\documents and settings\Administrator\Application Data\Safer Networking
2009-07-08 07:37 . 2009-07-08 07:37 -------- d-----w- c:\program files\Safer Networking
2009-07-08 07:37 . 2009-07-08 07:37 -------- d-----w- C:\!KillBox
2009-07-08 07:34 . 2009-07-08 07:34 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-07-07 23:04 . 2009-07-07 23:04 94104 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-07 21:39 . 2009-07-07 21:39 -------- d-----w- c:\program files\SDHelper (Spybot - Search & Destroy)
2009-07-07 21:39 . 2009-07-07 21:39 -------- d-----w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-07-07 21:39 . 2009-07-07 21:39 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-07-07 21:39 . 2009-07-07 21:39 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-07-07 21:33 . 2009-07-07 22:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-07 21:33 . 2009-07-07 21:48 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-20 04:07 . 2009-06-20 04:07 -------- d-s---w- c:\winnt\system32\%USERPROFILE%
2009-06-17 05:12 . 2009-06-17 05:12 -------- d-----w- c:\winnt\system32\Mozilla Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-09 23:59 . 2009-06-08 23:32 95436 ----a-w- c:\winnt\system32\drivers\26d261c5.sys
2009-07-08 19:57 . 2009-01-30 19:53 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverCure
2009-07-08 19:31 . 2009-07-08 19:31 312847 ------w- c:\winnt\system32\647abd38a58580908918e8a3395fb887.TMP
2009-07-08 19:02 . 2009-07-08 19:02 312847 ------w- c:\winnt\system32\f1864ab73dbdccf734bbec48fddfe5cf.TMP
2009-07-07 21:24 . 2009-07-07 21:24 312847 ------w- c:\winnt\system32\8aab370f9a360b00da9c3c7d5e63494e.TMP
2009-07-07 21:05 . 2008-12-27 02:46 -------- d-----w- c:\program files\CleanUp!
2009-06-24 01:52 . 2004-08-30 21:40 -------- d-----w- c:\documents and settings\Pat\Application Data\WeatherBug
2009-06-18 02:17 . 2007-11-03 23:20 -------- d-----w- c:\program files\Windows Live Toolbar
2009-06-09 13:54 . 2009-06-08 20:13 0 ----a-w- c:\winnt\system32\drivers\c1fd68c2.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-07-10_00.02.19 )))))))))))))))))))))))))))))))))))))))))
.
- 1980-01-01 06:00 . 2009-07-09 19:02 58012 c:\winnt\system32\perfc009.dat
+ 1980-01-01 06:00 . 2009-07-10 05:11 58012 c:\winnt\system32\perfc009.dat
+ 1980-01-01 06:00 . 2009-07-10 05:11 391894 c:\winnt\system32\perfh009.dat
- 1980-01-01 06:00 . 2009-07-09 19:02 391894 c:\winnt\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-06-23 1830128]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sprint SmartView"="c:\program files\Sprint\Sprint SmartView\SprintSV.exe" [2008-10-15 17664]
[HKLM\~\startupfolder\C:^DOCUME~1^ALLUSE~1^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\docume~1\ALLUSE~1\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\winnt\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MSIServer"=3 (0x3)
"wuauserv"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"Viewpoint Manager Service"=2 (0x2)
"usnjsvc"=3 (0x3)
"SQLAgent$ALAMODE"=3 (0x3)
"sopidkc"=2 (0x2)
"ose"=3 (0x3)
"MSSQLServerADHelper"=3 (0x3)
"MSSQL$ALAMODE"=2 (0x2)
"dhcpsrv"=2 (0x2)
"dfgdjhse5rjfmkfsderhkldtd576ogd80"=2 (0x2)
"cvjser5usjfyigsfhjhswybn4wgss80"=2 (0x2)
"BITS"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Sprint\\Sprint SmartView\\SwiApiMux.exe"=
S1 sasdifsv;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
S1 saskutil;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
S3 ati2mpaa;ati2mpaa;c:\winnt\system32\drivers\ati2mpaa.sys [10/3/2001 8:23 AM 281856]
S3 PCDRDRV;Pcdr Helper Driver;\??\c:\atf\Qctest\PCDoc\PCDRDRV.sys --> c:\atf\Qctest\PCDoc\PCDRDRV.sys [?]
S3 sasenum;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]
S4 MSSQL$ALAMODE;MSSQL$ALAMODE;c:\program files\Microsoft SQL Server\MSSQL$ALAMODE\Binn\sqlservr.exe [5/4/2005 1:04 AM 9158656]
S4 SQLAgent$ALAMODE;SQLAgent$ALAMODE;c:\program files\Microsoft SQL Server\MSSQL$ALAMODE\Binn\sqlagent.EXE [5/3/2005 10:42 PM 323584]
.
Contents of the 'Scheduled Tasks' folder
2009-07-09 c:\winnt\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 19:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://msn.com
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-09 22:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-07-10 22:17 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-10 05:17
ComboFix2.txt 2009-07-10 00:12
Pre-Run: 7,628,197,888 bytes free
Post-Run: 7,593,283,584 bytes free
237 --- E O F --- 2009-05-17 15:02