New Combofix:
ComboFix 09-10-17.01 - Owner 10/18/2009 14:56.9.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.447.146 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: BitDefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
* Resident AV is active
FILE ::
"c:\windows\system32\drivers\PavProc.sys"
"c:\windows\system32\duhaluno.dll"
"c:\windows\system32\hitodute.dll"
"c:\windows\system32\kotimiso.dll"
"c:\windows\system32\pozayomu.dll"
"c:\windows\system32\yesodeme.dll"
.
((((((((((((((((((((((((( Files Created from 2009-09-18 to 2009-10-18 )))))))))))))))))))))))))))))))
.
2009-10-17 17:56 . 2009-10-17 17:56 -------- d-----w- c:\documents and settings\Owner\Application Data\BitDefender
2009-10-17 17:54 . 2009-10-17 19:11 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender
2009-10-17 09:38 . 2009-10-17 09:33 38208 ----a-w- c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\
http://www.macromedia.com\bin\airapp...pinstaller.exe
2009-10-17 09:34 . 2009-10-17 09:34 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-10-17 09:31 . 2009-10-17 17:58 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-10-17 09:21 . 2009-10-17 09:21 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-16 00:36 . 2009-10-17 19:44 81984 ----a-w- c:\windows\system32\bdod.bin
2009-10-15 23:55 . 2009-10-17 17:55 -------- d-----w- c:\program files\BitDefender
2009-10-15 23:50 . 2009-10-17 17:55 -------- d-----w- c:\program files\Common Files\BitDefender
2009-10-12 04:15 . 2009-10-12 04:15 -------- d-----w- c:\documents and settings\Administrator.HOME\Local Settings\Application Data\Opera
2009-10-12 02:39 . 2009-10-12 02:39 -------- d-----w- c:\documents and settings\Administrator.HOME\Application Data\Lavasoft
2009-10-11 19:07 . 2009-10-13 23:28 -------- d-----w- c:\program files\iPod
2009-10-10 16:27 . 2009-10-10 16:27 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-10 00:03 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-10 00:03 . 2009-10-11 18:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-10 00:03 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-08 21:39 . 2009-10-08 21:39 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-10-06 04:40 . 2009-10-06 04:40 -------- d-----w- c:\windows\system32\wbem\Repository
2009-10-06 04:14 . 2009-10-06 04:14 -------- d-----w- c:\documents and settings\Administrator.HOME\PrivacIE
2009-10-04 16:39 . 2009-10-04 16:39 -------- d-----w- c:\program files\Trend Micro
2009-09-26 01:07 . 2009-10-11 19:07 -------- d-----w- c:\program files\iPod(2)
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-18 20:20 . 2008-10-14 04:42 -------- d-----w- c:\program files\Common Files\Akamai
2009-10-17 19:41 . 2009-02-12 21:52 104456 ----a-w- c:\windows\system32\drivers\bdfndisf.sys
2009-10-17 09:38 . 2004-04-19 23:19 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-17 09:32 . 2007-02-26 06:23 -------- d-----w- c:\program files\Google
2009-10-17 09:20 . 2004-01-21 01:53 -------- d-----w- c:\program files\Java
2009-10-17 09:07 . 2004-01-21 09:48 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-10-17 08:43 . 2004-01-21 09:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-10-14 10:53 . 2008-10-28 01:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-13 03:41 . 2004-05-15 01:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-13 03:41 . 2004-05-15 01:16 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-11 19:07 . 2008-01-11 22:02 -------- d-----w- c:\program files\iTunes
2009-10-11 19:07 . 2008-10-10 00:34 -------- d-----w- c:\program files\Common Files\Apple
2009-10-11 19:05 . 2004-11-28 03:54 -------- d-----w- c:\documents and settings\Owner\Application Data\Apple Computer
2009-10-11 18:24 . 2008-01-11 21:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-10-03 09:39 . 2008-08-05 22:08 64000 -c-ha-w- c:\windows\system32\mlfcache.dat
2009-10-02 04:36 . 2008-08-03 14:55 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-09-28 00:10 . 2009-08-29 09:06 314944 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-09-19 20:27 . 2005-08-19 17:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-09-15 22:22 . 2008-06-09 22:30 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-12 13:01 . 2009-09-12 13:01 -------- d-----w- c:\program files\iPhone Configuration Utility
2009-09-12 12:59 . 2009-09-12 12:58 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-12 12:54 . 2009-09-12 12:52 -------- d-----w- c:\program files\QuickTime
2009-09-11 14:33 . 2004-02-16 19:14 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 00:14 . 2008-08-04 00:54 -------- d-----w- c:\program files\Ares
2009-09-08 02:34 . 2007-03-10 22:38 -------- d-----w- c:\program files\Opera
2009-09-07 18:14 . 2009-08-19 23:37 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-07 18:00 . 2009-09-07 17:50 -------- d-----w- c:\program files\Perfect Uninstaller
2009-09-05 23:52 . 2009-08-03 01:56 -------- d-----w- c:\program files\Opera 10 Beta
2009-09-05 23:44 . 2009-09-05 23:44 81144 ----a-w- c:\documents and settings\Administrator.HOME\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-04 20:45 . 2004-02-16 19:14 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-02-06 23:05 916480 ------w- c:\windows\system32\wininet.dll
2009-08-29 00:42 . 2009-03-21 08:55 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-29 00:42 . 2009-03-21 08:55 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-27 05:44 . 2009-08-27 05:44 -------- d-----w- c:\program files\WBFS
2009-08-27 03:09 . 2009-08-27 03:09 -------- d-----w- c:\program files\Western Digital Corporation
2009-08-27 02:56 . 2009-08-27 02:56 1078 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{DB09C3D8-5ED0-42A3-8EC8-3B9F665971EF}\_A337FA7F14B1AA85BFA8A6.exe
2009-08-27 02:56 . 2009-08-27 02:56 1078 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{DB09C3D8-5ED0-42A3-8EC8-3B9F665971EF}\_7CFBC8C69E44C18F04FF2E.exe
2009-08-27 02:56 . 2009-08-27 02:56 10134 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{DB09C3D8-5ED0-42A3-8EC8-3B9F665971EF}\_3B0267A284AF1E1AD9D67E.exe
2009-08-27 02:54 . 2009-08-27 02:54 -------- d-----w- c:\program files\Western Digital Corp
2009-08-26 08:16 . 2004-02-16 18:47 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-22 14:32 . 2004-04-14 17:10 81144 -c--a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-22 04:55 . 2008-11-19 01:13 -------- d-----w- c:\program files\MSBuild
2009-08-22 04:55 . 2009-08-22 04:55 -------- d-----w- c:\program files\Reference Assemblies
2009-08-21 02:56 . 2009-08-21 02:56 -------- d-----w- c:\program files\Atomic Alarm Clock
2009-08-20 22:04 . 2007-02-28 03:53 -------- d-----w- c:\program files\Desktop Tray Clock
2009-08-20 10:36 . 2009-08-20 10:36 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-08-20 10:36 . 2009-08-20 10:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-19 23:37 . 2009-08-19 23:37 -------- d-----w- c:\program files\AVG
2009-08-19 23:31 . 2009-08-19 23:31 -------- d-----w- c:\documents and settings\Owner\Application Data\AVG8
2009-08-19 22:56 . 2009-07-23 05:25 -------- d-----w- c:\program files\FlashGet
2009-08-05 09:11 . 2002-12-12 15:14 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 14:00 . 2004-01-21 00:04 2180352 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 13:13 . 2002-08-29 08:04 2057728 ------w- c:\windows\system32\ntkrnlpa.exe
2009-07-29 04:53 . 2004-02-16 19:13 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-07-29 04:53 . 2004-02-16 18:48 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-03-05 23:08 . 2009-10-16 00:05 49664 ----a-w- c:\program files\mozilla firefox\components\FFComm.dll
.
((((((((((((((((((((((((((((( SnapShot_2009-10-18_12.10.30 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-18 16:32 . 2009-10-18 16:32 16384 c:\windows\temp\Perflib_Perfdata_550.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"SkinClock"="c:\program files\Atomic Alarm Clock\AtomicAlarmClock.exe" [2009-04-27 1742848]
"ares"="c:\program files\Ares\Ares.exe" [2009-02-03 1004544]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-17 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-10-17 782336]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2009-02-23 69632]
c:\documents and settings\Administrator.HOME\Start Menu\Programs\Startup\
AutoTBar.exe [2003-9-30 57344]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 08:42 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2003-02-21 01:50 40960 ----a-w- c:\program files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoa dGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^BitTorrent.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\BitTorrent.lnk
backup=c:\windows\pss\BitTorrent.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^eFax 4.4.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\eFax 4.4.lnk
backup=c:\windows\pss\eFax 4.4.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Gmote Server.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Gmote Server.lnk
backup=c:\windows\pss\Gmote Server.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^MLB.TV NexDef Plug-in.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\MLB.TV NexDef Plug-in.lnk
backup=c:\windows\pss\MLB.TV NexDef Plug-in.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Stardock ObjectDock.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
backup=c:\windows\pss\Stardock ObjectDock.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"STOPzilla Local Service"=2 (0x2)
"avg8wd"=2 (0x2)
"StyleXPService"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\137903\\Program\\BackWeb-137903.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\kdx\\khost.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"9420:TCP"= 9420:TCP:*Disabled:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:*Disabled:Akamai NetSession Interface
"3139:TCP"= 3139:TCP:*Disabled:Akamai NetSession Interface
"2755:TCP"= 2755:TCP:*Disabled:Akamai NetSession Interface
"2860:TCP"= 2860:TCP:*Disabled:Akamai NetSession Interface
"2892:TCP"= 2892:TCP:*Disabled:Akamai NetSession Interface
"2928:TCP"= 2928:TCP:*Disabled:Akamai NetSession Interface
"1576:TCP"= 1576:TCP:*Disabled:Akamai NetSession Interface
"1634:TCP"= 1634:TCP:*Disabled:Akamai NetSession Interface
"1649:TCP"= 1649:TCP:*Disabled:Akamai NetSession Interface
"1774:TCP"= 1774:TCP:*Disabled:Akamai NetSession Interface
"3327:TCP"= 3327:TCP:*Disabled:Akamai NetSession Interface
"3397:TCP"= 3397:TCP:*Disabled:Akamai NetSession Interface
"1218:TCP"= 1218:TCP:*Disabled:Akamai NetSession Interface
"4705:TCP"= 4705:TCP:*Disabled:Akamai NetSession Interface
"4945:TCP"= 4945:TCP:*Disabled:Akamai NetSession Interface
"3657:TCP"= 3657:TCP:*Disabled:Akamai NetSession Interface
"3696:TCP"= 3696:TCP:*Disabled:Akamai NetSession Interface
"1069:TCP"= 1069:TCP:*Disabled:Akamai NetSession Interface
"3451:TCP"= 3451:TCP:*Disabled:Akamai NetSession Interface
"2332:TCP"= 2332:TCP:*Disabled:Akamai NetSession Interface
"4668:TCP"= 4668:TCP:*Disabled:Akamai NetSession Interface
"4716:TCP"= 4716:TCP:*Disabled:Akamai NetSession Interface
"1208:TCP"= 1208:TCP:*Disabled:Akamai NetSession Interface
"2531:TCP"= 2531:TCP:*Disabled:Akamai NetSession Interface
"2593:TCP"= 2593:TCP:*Disabled:Akamai NetSession Interface
"4549:TCP"= 4549:TCP:*Disabled:Akamai NetSession Interface
"4036:TCP"= 4036:TCP:*Disabled:Akamai NetSession Interface
"4512:TCP"= 4512:TCP:*Disabled:Akamai NetSession Interface
"3993:TCP"= 3993:TCP:*Disabled:Akamai NetSession Interface
"4012:TCP"= 4012:TCP:*Disabled:Akamai NetSession Interface
"4125:TCP"= 4125:TCP:*Disabled:Akamai NetSession Interface
"2441:TCP"= 2441:TCP:*Disabled:Akamai NetSession Interface
"1180:TCP"= 1180:TCP:*Disabled:Akamai NetSession Interface
"3717:TCP"= 3717:TCP:*Disabled:Akamai NetSession Interface
"1721:TCP"= 1721:TCP:*Disabled:Akamai NetSession Interface
"3260:TCP"= 3260:TCP:*Disabled:Akamai NetSession Interface
"4435:TCP"= 4435:TCP:*Disabled:Akamai NetSession Interface
"4759:TCP"= 4759:TCP:*Disabled:Akamai NetSession Interface
"1252:TCP"= 1252:TCP:*Disabled:Akamai NetSession Interface
"2274:TCP"= 2274:TCP:*Disabled:Akamai NetSession Interface
"3636:TCP"= 3636:TCP:*Disabled:Akamai NetSession Interface
"2616:TCP"= 2616:TCP:*Disabled:Akamai NetSession Interface
"2829:TCP"= 2829:TCP:*Disabled:Akamai NetSession Interface
"2098:TCP"= 2098:TCP:*Disabled:Akamai NetSession Interface
"3553:TCP"= 3553:TCP:*Disabled:Akamai NetSession Interface
"3801:TCP"= 3801:TCP:*Disabled:Akamai NetSession Interface
"4767:TCP"= 4767:TCP:*Disabled:Akamai NetSession Interface
"4782:TCP"= 4782:TCP:*Disabled:Akamai NetSession Interface
"4821:TCP"= 4821:TCP:*Disabled:Akamai NetSession Interface
"1348:TCP"= 1348:TCP:*Disabled:Akamai NetSession Interface
"3309:TCP"= 3309:TCP:*Disabled:Akamai NetSession Interface
"4523:TCP"= 4523:TCP:*Disabled:Akamai NetSession Interface
"3648:TCP"= 3648:TCP:*Disabled:Akamai NetSession Interface
"4634:TCP"= 4634:TCP:*Disabled:Akamai NetSession Interface
R2 Akamai;Akamai;c:\windows\System32\svchost.exe -k Akamai [2/16/2004 1:47 PM 14336]
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [10/6/2008 6:16 PM 82696]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [9/18/2008 12:09 PM 111112]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2/12/2009 4:52 PM 104456]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [1/20/2009 7:16 PM 172032]
S3 P1370Aud;Creative WebCam Audio Control;c:\windows\system32\drivers\P1370Aud.sys [2/15/2009 12:51 AM 93056]
S3 P1370Aul;PD1370 Lower Filter Driver;c:\windows\system32\drivers\P1370Aul.sys [2/15/2009 12:51 AM 4992]
S3 P1370Vfx;P1370Vfx;c:\windows\system32\drivers\P1370Vfx.sys [2/15/2009 12:51 AM 6272]
S3 P1370VID;Live! Cam Voice;c:\windows\system32\drivers\P1370Vid.sys [2/15/2009 12:51 AM 297792]
S3 SCR3xx USB Smart Card Reader;SCR3xx USB Smart Card Reader;c:\windows\system32\drivers\SCR3XX2K.sys [6/2/2008 12:02 PM 47488]
S3 usbvm328;HP Camera;c:\windows\system32\drivers\usbvm326.sys [8/31/2007 9:00 PM 219648]
S3 vmfilter323;VC0326 filter service for Serome;c:\windows\system32\drivers\vmfilter323.sys [8/31/2007 9:15 PM 475264]
S4 Nuliecnt;Nuliecnt; [x]
S4 STOPzilla Local Service;STOPzilla Local Service;c:\program files\STOPzilla!\szntsvc.exe /service "STOPzilla Local Service" --> c:\program files\STOPzilla!\szntsvc.exe [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - GUSVC
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
bdx REG_MULTI_SZ scan
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder
2009-10-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2008-12-27 c:\windows\Tasks\Microsoft_Hardware_Launch_IType_exe.job
- c:\program files\Microsoft IntelliType Pro\itype.exe [2008-06-10 19:56]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com
uDefault_Search_URL = hxxp://srch-us10.hpwis.com/
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://www.yahoo.com/search/ie.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &AIM Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: turbotax.com
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: RaptisoftGameLoader - hxxp://www.miniclip.com/hamsterball/raptisoftgameloader.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\e4wuvfee.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1641676&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?q=&ctid=CT1641676&SearchSource=2
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-18 15:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(972)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\Softex\OmniPass\opxpgina.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
- - - - - - - > 'explorer.exe'(9532)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-10-18 15:30
ComboFix-quarantined-files.txt 2009-10-18 20:29
ComboFix2.txt 2009-10-18 19:22
ComboFix3.txt 2009-10-18 12:21
ComboFix4.txt 2009-10-16 22:57
ComboFix5.txt 2009-10-18 19:52
Pre-Run: 43,032,440,832 bytes free
Post-Run: 43,015,917,568 bytes free
337 --- E O F --- 2009-10-18 10:07