the log at the end of the scan:
ComboFix 09-06-01.03 - James 03/06/2009 16:07.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.1279.739 [GMT 1:00]
Running from: c:\users\James\Desktop\JA.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\users\James\AppData\Local\Temp\{04BB0FD9-4EED-4DA8-8684-F345CF576EB2}\_Setup.dll
c:\users\James\AppData\Local\Temp\{04BB0FD9-4EED-4DA8-8684-F345CF576EB2}\ISSetup.dll
c:\users\James\AppData\Local\Temp\{0AE49B1A-3FD9-4B62-833E-2995271B8984}\_Setup.dll
c:\users\James\AppData\Local\Temp\{0AE49B1A-3FD9-4B62-833E-2995271B8984}\ISSetup.dll
c:\users\James\AppData\Local\Temp\{70243D8D-3394-488C-A764-681D8E53E835}\_Setup.dll
c:\users\James\AppData\Local\Temp\{70243D8D-3394-488C-A764-681D8E53E835}\ISSetup.dll
c:\users\James\AppData\Local\Temp\{D576E671-6C60-409E-84D1-B5F3CD0BB288}\_Setup.dll
c:\users\James\AppData\Local\Temp\{D576E671-6C60-409E-84D1-B5F3CD0BB288}\ISSetup.dll
c:\users\James\AppData\Local\Temp\{D62F2F14-53D7-4353-BF9C-6A0C338FB6A5}\_Setup.dll
c:\users\James\AppData\Local\Temp\{D62F2F14-53D7-4353-BF9C-6A0C338FB6A5}\ISSetup.dll
c:\users\James\AppData\Local\Temp\{EBC5AF12-ED96-4760-9A48-DA1475250290}\_Setup.dll
c:\users\James\AppData\Local\Temp\{EBC5AF12-ED96-4760-9A48-DA1475250290}\ISSetup.dll
c:\users\James\AppData\Local\Temp\{FCBBAF9B-8F3A-46AE-B053-2C9D79CF3108}\{8FDC1610-3FB5-4EF2-A0D0-CEDC3A525A25}\S5Running.exe
c:\users\James\AppData\Local\Temp\{FE12DEBD-C1F3-479C-A37E-5F066B28E738}\_Setup.dll
c:\users\James\AppData\Local\Temp\{FE12DEBD-C1F3-479C-A37E-5F066B28E738}\ISSetup.dll
c:\windows\system32\drivers\gxvxcwnwiceioyvvpmpxtucfsmlopjrosrdqo.sys
c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
c:\windows\system32\gxvxceitpdtqpipopfqrrmgecygymgalbxnqt.dll
c:\windows\system32\gxvxcosntphfiwhxterbfiwewcsfsaxdsxrjx.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_GXVXCSERV.SYS
((((((((((((((((((((((((( Files Created from 2009-05-03 to 2009-06-03 )))))))))))))))))))))))))))))))
.
2009-06-03 15:26 . 2009-06-03 15:27 -------- d-----w- c:\users\James\AppData\Local\temp
2009-05-29 18:11 . 2009-05-29 18:11 -------- d-----w- c:\program files\ERUNT
2009-05-27 22:45 . 2009-01-18 21:35 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-05-27 22:45 . 2009-05-27 22:45 123396 ----a-w- c:\programdata\Lavasoft\Ad-Aware\ThreatWork\Submit\pncrt.dll
2009-05-27 22:45 . 2009-05-27 22:45 684036 ----a-w- c:\programdata\Lavasoft\Ad-Aware\ThreatWork\Submit\DivX.dll
2009-05-27 21:44 . 2009-01-18 21:30 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-05-27 21:44 . 2009-05-27 21:44 -------- dc-h--w- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-05-27 21:44 . 2009-01-18 21:43 2892112 -c--a-w- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
2009-05-27 21:44 . 2009-05-27 21:44 -------- d-----w- c:\programdata\Lavasoft
2009-05-27 21:44 . 2009-05-27 21:44 -------- d-----w- c:\program files\Lavasoft
2009-05-25 12:39 . 2009-05-25 12:39 -------- d-----w- c:\users\James\AppData\Local\WinZip
2009-05-25 12:39 . 2009-05-25 12:39 -------- d-----w- c:\programdata\WinZip
2009-05-24 14:05 . 2009-05-25 10:20 -------- d-----w- c:\programdata\Kontiki
2009-05-06 19:52 . 2009-05-06 19:52 -------- d-----w- c:\users\James\AppData\Roaming\Snapfish
2009-05-05 22:51 . 2009-05-05 22:52 -------- d-----w- c:\program files\AC3Filter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-29 18:12 . 2009-05-29 18:12 -------- d-----w- c:\program files\Trend Micro
2009-05-29 15:56 . 2009-01-24 13:05 -------- d-----w- c:\program files\DivX
2009-05-28 13:58 . 2009-01-24 13:06 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-05-28 00:22 . 2007-06-25 17:31 -------- d-----w- c:\program files\Google
2009-05-26 22:23 . 2007-06-25 17:34 -------- d-----w- c:\programdata\Symantec
2009-05-26 22:23 . 2007-06-25 17:34 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-05-26 22:22 . 2007-06-25 17:34 -------- d-----w- c:\program files\Symantec
2009-05-25 12:41 . 2009-01-27 19:13 -------- d-----w- c:\users\James\AppData\Roaming\uTorrent
2009-05-25 10:25 . 2008-04-12 18:33 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-05-25 10:21 . 2007-06-25 17:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-19 23:40 . 2008-05-13 22:36 -------- d-----w- c:\users\James\AppData\Roaming\LimeWire
2009-05-13 08:55 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-03 11:15 . 2009-05-03 10:17 745094707 ----a-w- c:\users\James\AppData\Roaming\uTorrent\officeblack1.5.exe
2009-05-03 09:56 . 2008-09-09 18:02 4612 ----a-w- c:\users\James\AppData\Roaming\wklnhst.dat
2009-05-02 22:23 . 2008-02-09 19:10 72472 ----a-w- c:\users\James\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-02 22:23 . 2009-05-02 22:23 -------- d-----w- c:\programdata\FLEXnet
2009-05-02 22:16 . 2008-06-01 22:23 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-02 22:06 . 2009-05-02 22:06 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-05-02 21:58 . 2009-05-02 21:47 5960944 ----a-w- c:\users\James\AppData\Roaming\uTorrent\Adobe Photoshop CS3 Extended + Crack\redist\WindowsServer2003-KB898715-ia64-enu.exe
2009-05-02 21:58 . 2009-05-02 21:43 4584688 ----a-w- c:\users\James\AppData\Roaming\uTorrent\Adobe Photoshop CS3 Extended + Crack\redist\WindowsServer2003-KB898715-x64-enu.exe
2009-05-02 21:58 . 2009-05-02 21:50 1536752 ----a-w- c:\users\James\AppData\Roaming\uTorrent\Adobe Photoshop CS3 Extended + Crack\redist\WindowsServer2003-KB898715-x86-enu.exe
2009-05-02 21:58 . 2009-05-02 21:42 4584688 ----a-w- c:\users\James\AppData\Roaming\uTorrent\Adobe Photoshop CS3 Extended + Crack\redist\WindowsXP-KB898715-x64-enu.exe
2009-05-02 21:58 . 2009-05-02 21:42 2585872 ----a-w- c:\users\James\AppData\Roaming\uTorrent\Adobe Photoshop CS3 Extended + Crack\redist\WindowsInstaller-KB893803-v2-x86.exe
2009-05-02 21:57 . 2009-05-02 21:49 2689208 ----a-w- c:\users\James\AppData\Roaming\uTorrent\Adobe Photoshop CS3 Extended + Crack\Setup.exe
2009-05-02 21:57 . 2009-05-02 21:42 44814336 ----a-w- c:\users\James\AppData\Roaming\uTorrent\Adobe Photoshop CS3 Extended + Crack\Crack\Photoshop.exe
2009-04-21 20:49 . 2007-06-25 17:40 -------- d-----w- c:\programdata\Microsoft Help
2009-04-17 15:32 . 2008-05-17 11:29 -------- d-----w- c:\users\James\AppData\Roaming\Apple Computer
2009-04-10 19:19 . 2009-04-10 19:19 223980 ----a-w- c:\windows\Racing Team Manager Uninstaller.exe
2009-04-10 19:19 . 2009-04-10 19:19 -------- d-----w- c:\program files\Kalypso Media
2009-03-17 03:38 . 2009-04-16 08:59 13824 ----a-w- c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-16 08:59 24064 ----a-w- c:\windows\system32\amxread.dll
2009-03-09 04:19 . 2009-03-08 22:11 410984 ----a-w- c:\windows\system32\deploytk.dll
2007-06-26 01:50 . 2007-06-26 02:00 65536 --sha-w- c:\windows\oem\mp\boot\bootstat.dat
2007-06-26 01:51 . 2007-06-26 01:51 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-09 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"toolbar_eula_launcher"="c:\program files\Packard Bell\GOOGLE_EULA\EULALauncher.exe" [2007-02-20 28672]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-01-18 506712]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-11-09 3784704]
c:\users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [27/05/2009 22:44 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18/01/2009 22:34 921936]
--- Other Services/Drivers In Memory ---
*Deregistered* - sptd
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {B9701D86-3D63-7F49-9948-27670574B4CC} /qb
.
Contents of the 'Scheduled Tasks' folder
2009-06-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 21:34]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} -
http://www.sky.com
FF - ProfilePath - c:\users\James\AppData\Roaming\Mozilla\Firefox\Profiles\ndlyvrkx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
www.google.co.uk
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\James\AppData\Roaming\Mozilla\Firefox\Profiles\ndlyvrkx.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-03 16:27
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1452309453-2183165736-2517102808-1002\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:67,36,75,05,e6,54,4b,01,e7,9b,d9,0e,7f,ce,cc,fe,9e,9c,f1,38,46,
30,25,0c,8a,d3,50,b2,3a,58,f8,5d,31,4b,f4,ad,0c,7c,0e,20,e3,19,e9,39,e7,62,\
"rkeysecu"=hex:de,b6,88,f1,4a,ef,9e,a7,7b,a7,e0,ef,c4,ac,6c,b4
.
Completion time: 2009-06-03 16:30
ComboFix-quarantined-files.txt 2009-06-03 15:30
Pre-Run: 69,710,110,720 bytes free
Post-Run: 69,736,599,552 bytes free
173 --- E O F --- 2009-05-21 18:03