milesinfront
New member
ComboFix 09-12-21.08 - Rick 23/12/2009 8:28.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1325 [GMT 10:00]
Running from: c:\documents and settings\Rick\My Documents\Downloads\ComboFix.exe
AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
c:\windows\EventSystem.log
.
((((((((((((((((((((((((( Files Created from 2009-11-22 to 2009-12-22 )))))))))))))))))))))))))))))))
.
2009-12-22 04:05 . 2009-12-22 04:05 -------- d-----w- c:\documents and settings\Rick\Local Settings\Application Data\Nero
2009-12-21 22:53 . 2009-12-22 04:37 -------- d-----w- c:\documents and settings\Rick\Application Data\vlc
2009-12-21 22:47 . 2009-12-21 22:47 -------- d-----w- c:\program files\VideoLAN
2009-12-20 22:41 . 2009-12-20 22:41 -------- d-----w- C:\_OTM
2009-12-17 05:28 . 2009-12-17 05:28 117760 ----a-w- c:\documents and settings\Rick\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-17 05:27 . 2009-12-17 05:27 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-12-17 05:26 . 2009-12-17 21:20 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-12-17 05:26 . 2009-12-17 05:26 -------- d-----w- c:\documents and settings\Rick\Application Data\SUPERAntiSpyware.com
2009-12-17 05:26 . 2009-12-17 05:26 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-13 22:17 . 2009-12-13 22:18 -------- d-----w- c:\documents and settings\Rick\Application Data\Nero
2009-12-13 21:57 . 2009-12-13 22:10 -------- d-----w- c:\program files\Nero
2009-12-13 21:56 . 2009-12-13 22:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-12-13 21:56 . 2009-12-13 22:11 -------- d-----w- c:\program files\Common Files\Nero
2009-12-11 22:45 . 2009-12-11 22:45 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2009-12-06 23:28 . 2009-12-06 23:28 -------- d-----w- c:\program files\ESET
2009-12-05 09:05 . 2009-12-05 09:05 -------- d-----w- c:\documents and settings\Rick\Application Data\Malwarebytes
2009-12-05 09:05 . 2009-12-03 06:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-05 09:05 . 2009-12-05 09:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-05 09:05 . 2009-12-05 09:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-05 09:05 . 2009-12-03 06:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-02 01:20 . 2009-12-02 01:20 10134 ----a-r- c:\documents and settings\Rick\Application Data\Microsoft\Installer\{95BE40AA-D511-42B5-B060-704B5C0A945D}\ARPPRODUCTICON.exe
2009-12-02 01:15 . 2009-12-02 01:15 -------- d-----w- c:\program files\Common Files\Business Objects
2009-12-02 01:15 . 2009-12-02 01:15 -------- d-----w- c:\program files\Business Objects
2009-12-02 00:16 . 2009-12-02 00:16 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\TeamViewer
2009-12-02 00:16 . 2009-12-02 00:16 -------- d-----w- c:\documents and settings\Rick\Application Data\TeamViewer
2009-12-01 02:14 . 2009-11-19 01:48 43008 ----a-w- c:\documents and settings\Rick\Application Data\Mozilla\Firefox\Profiles\3ir9oqfa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-01 02:14 . 2009-11-19 01:48 340480 ----a-w- c:\documents and settings\Rick\Application Data\Mozilla\Firefox\Profiles\3ir9oqfa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-01 02:14 . 2009-11-19 01:48 346624 ----a-w- c:\documents and settings\Rick\Application Data\Mozilla\Firefox\Profiles\3ir9oqfa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-12-01 02:14 . 2009-11-19 01:48 872960 ----a-w- c:\documents and settings\Rick\Application Data\Mozilla\Firefox\Profiles\3ir9oqfa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-11-30 22:55 . 2009-11-30 22:55 -------- d-----w- c:\program files\Trend Micro
2009-11-25 22:56 . 2009-11-25 22:56 -------- d-----w- c:\program files\ULSDb
2009-11-25 06:55 . 2009-11-25 06:55 -------- d-----w- c:\program files\Common Files\PCSuite
2009-11-25 06:43 . 2008-08-25 23:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-11-25 06:42 . 2009-11-25 06:42 -------- d-----w- c:\program files\PC Connectivity Solution
2009-11-25 06:37 . 2009-11-25 06:36 34429264 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_eng.exe
2009-11-25 06:37 . 2009-11-25 06:37 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\pcswpcsi.exe
2009-11-25 06:37 . 2009-11-25 06:37 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstCCD.exe
2009-11-25 06:37 . 2009-11-25 06:37 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-11-25 06:37 . 2009-11-25 06:37 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCS.exe
2009-11-25 05:14 . 2009-11-25 06:11 -------- d-----w- c:\documents and settings\All Users\Application Data\ULSVL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-22 22:26 . 2006-08-29 23:05 -------- d-----w- c:\documents and settings\Rick\Application Data\U3
2009-12-22 22:15 . 2009-04-14 21:56 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-12-18 01:14 . 2009-04-06 07:19 -------- d-----w- c:\documents and settings\All Users\Application Data\ULSMVX
2009-12-15 02:26 . 2008-12-19 00:59 1 ----a-w- c:\documents and settings\Rick\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-11 22:46 . 2009-08-26 01:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-09 21:23 . 2006-06-13 06:40 -------- d-----w- c:\program files\Virtual Mechanics
2009-12-02 23:26 . 2006-06-13 17:01 130280 ----a-w- c:\documents and settings\Rick\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-01 21:39 . 2007-06-18 03:32 -------- d-----w- c:\documents and settings\Rick\Application Data\Internode
2009-12-01 21:38 . 2007-06-18 03:32 -------- d-----w- c:\program files\Internode
2009-11-26 21:26 . 2009-04-16 21:56 111856 ----a-w- c:\windows\system32\isafprod.dll
2009-11-25 22:56 . 2008-06-03 06:16 -------- d-----w- c:\program files\ULS
2009-11-25 06:54 . 2009-10-09 07:16 -------- d-----w- c:\program files\Common Files\Nokia
2009-11-25 06:54 . 2009-10-09 07:15 -------- d-----w- c:\program files\Nokia
2009-11-25 06:36 . 2009-10-09 07:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-11-24 23:30 . 2006-06-13 05:21 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-24 21:54 . 2009-11-09 21:52 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-11-24 07:00 . 2006-06-07 02:15 -------- d-----w- c:\program files\ThinkPad
2009-11-15 22:49 . 2006-06-13 06:39 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-10 22:02 . 2007-10-22 22:00 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-09 21:53 . 2009-11-09 21:53 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-11-01 22:07 . 2009-11-01 22:07 -------- d-----w- c:\documents and settings\Rick\Application Data\Sonic
2009-11-01 22:06 . 2009-11-01 22:06 -------- d-----w- c:\documents and settings\Rick\Application Data\vnulneas
2009-11-01 22:06 . 2009-11-01 22:06 -------- d-----w- c:\documents and settings\Rick\Application Data\Leadertech
2009-11-01 22:06 . 2009-11-01 22:06 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-30 04:57 . 2009-10-30 04:57 -------- d-----w- c:\documents and settings\NetworkService\Application Data\vnulneas
2009-10-29 23:20 . 2006-06-07 02:15 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-29 23:19 . 2009-10-29 23:19 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2009-10-29 23:13 . 2009-10-29 23:13 -------- d-----w- c:\program files\Dr.METAZA2
2009-10-29 23:13 . 2006-06-13 05:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Roland DG Corporation
2009-10-29 20:52 . 2009-04-16 21:56 739696 ----a-w- c:\windows\system32\drivers\vetefile.sys
2009-10-29 20:52 . 2009-04-16 21:56 26352 ----a-w- c:\windows\system32\drivers\vet-filt.sys
2009-10-29 20:52 . 2009-04-16 21:56 21488 ----a-w- c:\windows\system32\drivers\vetfddnt.sys
2009-10-29 20:52 . 2009-04-16 21:56 21104 ----a-w- c:\windows\system32\drivers\vet-rec.sys
2009-10-29 20:52 . 2009-04-16 21:56 161008 ----a-w- c:\windows\system32\drivers\vetmonnt.sys
2009-10-29 20:52 . 2009-04-16 21:56 133520 ----a-w- c:\windows\system32\drivers\veteboot.sys
2009-10-29 07:45 . 1980-01-01 07:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 1980-01-01 07:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 1980-01-01 07:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 21:53 . 2008-06-15 20:50 1541416 ----a-w- c:\documents and settings\All Users\Application Data\CA\Consumer\AV\tmp\vete_tmp.dll
2009-10-13 10:30 . 1980-01-01 07:00 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 1980-01-01 07:00 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 1980-01-01 07:00 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-11 22:15 . 2009-10-11 22:15 152576 ----a-w- c:\documents and settings\Rick\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-10-09 07:23 . 2009-10-09 07:23 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\Installer\CommonCustomActions\msxml6Exec.exe
2009-10-09 07:23 . 2009-10-09 07:23 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\Installer\CommonCustomActions\Sleep.exe
2009-10-09 07:23 . 2009-10-09 07:23 3181612 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\Installer\CommonCustomActions\vcredistExec.exe
2009-10-09 07:22 . 2009-10-09 07:23 24501456 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\NokiaSoftwareUpdaterSetup_en[1].exe
2009-10-09 07:14 . 2009-10-09 07:14 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-10-09 07:14 . 2009-10-09 07:14 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-10-09 07:14 . 2009-10-09 07:14 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-10-09 07:14 . 2009-10-09 07:14 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-10-09 07:13 . 2009-10-09 07:14 33773208 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_eng_web.exe
2009-10-08 04:57 . 2007-10-09 03:03 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2009-10-08 04:57 . 1980-01-01 07:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 04:56 . 1980-01-01 07:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2009-10-06 01:52 . 2009-10-09 07:15 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2003-10-31 00:31 . 2003-10-31 00:31 0 ----a-w- c:\program files\error.dat
2008-08-15 00:06 . 2008-06-04 02:36 952 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"InternodeUsage"="c:\progra~1\INTERN~3\mum.exe" [2009-12-01 1361408]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-13 68856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-17 2002160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2005-08-29 94208]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-19 127037]
"CAVRID"="c:\program files\CA\eTrust Vet Antivirus\CAVRID.exe" [2009-11-26 271600]
"cctray"="c:\program files\CA\CA Internet Security Suite\casc.exe" [2009-11-11 374000]
"Norton Ghost 14.0"="c:\program files\Norton Ghost\Agent\VProTray.exe" [2008-12-11 2245992]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-03 1323008]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Enable Wireless Keyboard Driver.lnk - c:\program files\Wireless Device\Wireless Keyboard\Magickey.exe [2004-11-22 172032]
Enable Wireless Optical Mouse Driver.lnk - c:\program files\Wireless Device\Wireless Mouse\MouseAp.exe [2004-11-22 217088]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-12 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 04:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-06-06 05:46 79368 ----a-w- c:\windows\system32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-06 06:45 28672 ----a-w- c:\windows\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-06-17 05:23 24576 ----a-w- c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ERSvc"=2 (0x2)
"Messenger"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Laplink\\PCmover\\PCmover.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Internet Camera\\util\\util.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Keys Server\\sntlkeyssrvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Internet Camera\\admin\\admin.exe"=
"c:\\Program Files\\UltraVNC\\winvnc.exe"=
"c:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
"c:\\Program Files\\Virtual Mechanics\\SiteSpinner Pro V2\\bin\\SiteSpinnerProV2.exe"=
"c:\\Program Files\\UltraVNC\\vncviewer.exe"=
"c:\\Program Files\\UltraVNC\\vncviewer_tab.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Shareaza\\Shareaza.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
"53049:TCP"= 53049:TCP
xpsp2res.dll,-22009
"37955:TCP"= 37955:TCP
xpsp2res.dll,-22009
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [5/01/2009 11:36 AM 107512]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [18/11/2008 12:14 PM 72696]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23/11/2009 8:43 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23/11/2009 8:43 AM 74480]
R2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\CA\CA Internet Security Suite\ccschedulersvc.exe [17/04/2009 7:56 AM 128240]
R2 SentinelKeysServer;Sentinel Keys Server;c:\program files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [1/08/2006 1:00 AM 316992]
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [1/01/1980 5:00 PM 5120]
R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [12/12/2008 12:37 PM 1153528]
R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [10/12/2008 12:58 PM 797176]
R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [19/12/2008 1:59 PM 297464]
R2 uvnc_service;uvnc_service;c:\program files\UltraVNC\winvnc.exe [23/04/2009 12:39 PM 1693128]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [12/12/2008 12:37 PM 205304]
R3 mv2;mv2;c:\windows\system32\drivers\mv2.sys [11/04/2009 7:11 PM 10688]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [23/11/2009 8:43 AM 7408]
R3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [20/12/2007 5:13 PM 1558000]
S2 COSIDS_TB;COSIDS_TB;c:\progra~1\COSIDS\BIN\TbMux32.exe [22/05/2007 8:20 AM 165376]
S2 PLSLT;ULS PLSLT Series Laser Engraver Firmware Loader;c:\windows\system32\drivers\PLSLTBL.sys [25/01/2008 8:24 AM 7808]
S2 VERSA2;ULS VersaLaser Series Laser Engraver Firmware Loader;c:\windows\system32\drivers\VERSA2BL.sys [9/03/2007 7:56 AM 7808]
S2 VERSALdr;ULS VersaLaser Engraver Firmware LoaderUSB\VID_10C3&PID_012C.DeviceDesc=ULS VersaLaser Air Compressor Firmware Loader;c:\windows\system32\drivers\VERSABL.sys [25/06/2003 6:49 AM 10112]
S3 DTV-DVBM9205;DTV-DVB USB Hybrid Analog/Capture;c:\windows\system32\drivers\M9205.sys [23/01/2006 9:13 PM 70272]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [6/10/2009 9:21 AM 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [6/10/2009 9:21 AM 3072]
S3 M9207;DTV-DVB M9207 USB DVB-T / TV BOX;c:\windows\system32\drivers\M9207BDA.sys [23/01/2006 9:13 PM 37760]
S3 oxser;OX16C95x Serial port driver;c:\windows\system32\drivers\oxser.sys [9/08/2006 4:46 PM 49792]
S3 QSerBus;Quatech PCI/PCMCIA/ISA Multiport Serial Device Enumerator;c:\windows\system32\drivers\qserbus.sys [3/07/2006 7:32 AM 26624]
S3 QTSerial;Quatech Multiport Serial Driver;c:\windows\system32\drivers\qtserial.sys [3/07/2006 7:32 AM 91648]
S3 SWI32;SWI32;\??\c:\program files\ThinkVantage\SystemUpdate\session\79wc17ww\SWI32.sys --> c:\program files\ThinkVantage\SystemUpdate\session\79wc17ww\SWI32.sys [?]
S3 ULSPrint;ULS Print Service;c:\windows\system32\drivers\ULSPRINT.sys [10/07/2007 9:41 AM 17024]
S3 ZteitSerMux;ZteitSerMux;c:\windows\system32\drivers\ZteitSermux.sys [16/12/2006 8:31 AM 37888]
S3 zteitserprt;zteitserprt;c:\windows\system32\drivers\ZteitSerPrt.sys [16/12/2006 8:37 AM 19200]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.amiles.com.au/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
LSP: c:\windows\System32\VetRedir.dll
Trusted Zone: amiles.com.au\www
TCP: {71407124-ED89-4796-8404-5222CC3D2CBA} = 192.231.203.132,192.231.203.3
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {3FED5791-B952-4958-A556-05892FE80AEC} - hxxp://192.168.10.12/webrtp.cab
DPF: {E62D1A95-8299-4B94-85D0-731DC125A60D} - hxxp://192.168.1.52:5052/ocx/IMMP4Control.ocx
FF - ProfilePath - c:\documents and settings\Rick\Application Data\Mozilla\Firefox\Profiles\3ir9oqfa.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.amiles.com.au/
FF - component: c:\documents and settings\Rick\Application Data\Mozilla\Firefox\Profiles\3ir9oqfa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
AddRemove-DUMMy - c:\docume~1\Rick\LOCALS~1\Temp\_ISTMP2.DIR\_ISTMP0.DIR\dummy.log
AddRemove-SignLab61DeInstKey - c:\engravelab6\Uninst.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-23 08:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1513153548-3119829742-721034989-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{900CD2A7-7DA5-989B-035D-BEE1872F8C3F}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iampoahdcflmlfaljf"=hex:69,65,65,67,67,63,69,6a,6f,62,6a,6a,65,62,65,6f,6d,6a,
67,69,67,6c,6a,63,69,68,67,69,66,63,6c,65,69,62,63,69,6d,63,61,6c,69,69,6c,\
"hampoahdcfglmhkk"=hex:6d,61,6c,62,64,66,64,6b,68,6f,69,6c,6e,6a,65,61,67,62,
66,6f,6f,68,68,64,68,66,00,00
"gampoahdcfcnpc"=hex:61,69,62,6c,6d,62,70,6d,70,6e,6f,67,65,6e,69,6b,6b,6c,61,
6b,67,6f,62,6a,6c,68,66,70,6a,6e,63,69,67,6a,6c,62,6c,65,6a,64,6e,6e,65,6d,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73A803C7-4F74-C091-1EFB-121D42A78ED2}]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8BDF16A2-6D31-0350-366C-B753DCC9573B}]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Messaging Subsystem\Applications]
@DACL=(02 0000)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1952)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\UmxWnp.Dll
c:\windows\system32\tphklock.dll
.
Completion time: 2009-12-23 08:38:43
ComboFix-quarantined-files.txt 2009-12-22 22:38
ComboFix2.txt 2009-12-03 02:16
Pre-Run: 16,911,937,536 bytes free
Post-Run: 18,843,594,752 bytes free
- - End Of File - - A265B1576272CE8252E8AD02C2C049AD
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1325 [GMT 10:00]
Running from: c:\documents and settings\Rick\My Documents\Downloads\ComboFix.exe
AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
c:\windows\EventSystem.log
.
((((((((((((((((((((((((( Files Created from 2009-11-22 to 2009-12-22 )))))))))))))))))))))))))))))))
.
2009-12-22 04:05 . 2009-12-22 04:05 -------- d-----w- c:\documents and settings\Rick\Local Settings\Application Data\Nero
2009-12-21 22:53 . 2009-12-22 04:37 -------- d-----w- c:\documents and settings\Rick\Application Data\vlc
2009-12-21 22:47 . 2009-12-21 22:47 -------- d-----w- c:\program files\VideoLAN
2009-12-20 22:41 . 2009-12-20 22:41 -------- d-----w- C:\_OTM
2009-12-17 05:28 . 2009-12-17 05:28 117760 ----a-w- c:\documents and settings\Rick\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-17 05:27 . 2009-12-17 05:27 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-12-17 05:26 . 2009-12-17 21:20 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-12-17 05:26 . 2009-12-17 05:26 -------- d-----w- c:\documents and settings\Rick\Application Data\SUPERAntiSpyware.com
2009-12-17 05:26 . 2009-12-17 05:26 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-13 22:17 . 2009-12-13 22:18 -------- d-----w- c:\documents and settings\Rick\Application Data\Nero
2009-12-13 21:57 . 2009-12-13 22:10 -------- d-----w- c:\program files\Nero
2009-12-13 21:56 . 2009-12-13 22:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-12-13 21:56 . 2009-12-13 22:11 -------- d-----w- c:\program files\Common Files\Nero
2009-12-11 22:45 . 2009-12-11 22:45 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2009-12-06 23:28 . 2009-12-06 23:28 -------- d-----w- c:\program files\ESET
2009-12-05 09:05 . 2009-12-05 09:05 -------- d-----w- c:\documents and settings\Rick\Application Data\Malwarebytes
2009-12-05 09:05 . 2009-12-03 06:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-05 09:05 . 2009-12-05 09:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-05 09:05 . 2009-12-05 09:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-05 09:05 . 2009-12-03 06:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-02 01:20 . 2009-12-02 01:20 10134 ----a-r- c:\documents and settings\Rick\Application Data\Microsoft\Installer\{95BE40AA-D511-42B5-B060-704B5C0A945D}\ARPPRODUCTICON.exe
2009-12-02 01:15 . 2009-12-02 01:15 -------- d-----w- c:\program files\Common Files\Business Objects
2009-12-02 01:15 . 2009-12-02 01:15 -------- d-----w- c:\program files\Business Objects
2009-12-02 00:16 . 2009-12-02 00:16 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\TeamViewer
2009-12-02 00:16 . 2009-12-02 00:16 -------- d-----w- c:\documents and settings\Rick\Application Data\TeamViewer
2009-12-01 02:14 . 2009-11-19 01:48 43008 ----a-w- c:\documents and settings\Rick\Application Data\Mozilla\Firefox\Profiles\3ir9oqfa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-01 02:14 . 2009-11-19 01:48 340480 ----a-w- c:\documents and settings\Rick\Application Data\Mozilla\Firefox\Profiles\3ir9oqfa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-01 02:14 . 2009-11-19 01:48 346624 ----a-w- c:\documents and settings\Rick\Application Data\Mozilla\Firefox\Profiles\3ir9oqfa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-12-01 02:14 . 2009-11-19 01:48 872960 ----a-w- c:\documents and settings\Rick\Application Data\Mozilla\Firefox\Profiles\3ir9oqfa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-11-30 22:55 . 2009-11-30 22:55 -------- d-----w- c:\program files\Trend Micro
2009-11-25 22:56 . 2009-11-25 22:56 -------- d-----w- c:\program files\ULSDb
2009-11-25 06:55 . 2009-11-25 06:55 -------- d-----w- c:\program files\Common Files\PCSuite
2009-11-25 06:43 . 2008-08-25 23:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-11-25 06:42 . 2009-11-25 06:42 -------- d-----w- c:\program files\PC Connectivity Solution
2009-11-25 06:37 . 2009-11-25 06:36 34429264 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_eng.exe
2009-11-25 06:37 . 2009-11-25 06:37 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\pcswpcsi.exe
2009-11-25 06:37 . 2009-11-25 06:37 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstCCD.exe
2009-11-25 06:37 . 2009-11-25 06:37 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-11-25 06:37 . 2009-11-25 06:37 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCS.exe
2009-11-25 05:14 . 2009-11-25 06:11 -------- d-----w- c:\documents and settings\All Users\Application Data\ULSVL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-22 22:26 . 2006-08-29 23:05 -------- d-----w- c:\documents and settings\Rick\Application Data\U3
2009-12-22 22:15 . 2009-04-14 21:56 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-12-18 01:14 . 2009-04-06 07:19 -------- d-----w- c:\documents and settings\All Users\Application Data\ULSMVX
2009-12-15 02:26 . 2008-12-19 00:59 1 ----a-w- c:\documents and settings\Rick\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-11 22:46 . 2009-08-26 01:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-09 21:23 . 2006-06-13 06:40 -------- d-----w- c:\program files\Virtual Mechanics
2009-12-02 23:26 . 2006-06-13 17:01 130280 ----a-w- c:\documents and settings\Rick\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-01 21:39 . 2007-06-18 03:32 -------- d-----w- c:\documents and settings\Rick\Application Data\Internode
2009-12-01 21:38 . 2007-06-18 03:32 -------- d-----w- c:\program files\Internode
2009-11-26 21:26 . 2009-04-16 21:56 111856 ----a-w- c:\windows\system32\isafprod.dll
2009-11-25 22:56 . 2008-06-03 06:16 -------- d-----w- c:\program files\ULS
2009-11-25 06:54 . 2009-10-09 07:16 -------- d-----w- c:\program files\Common Files\Nokia
2009-11-25 06:54 . 2009-10-09 07:15 -------- d-----w- c:\program files\Nokia
2009-11-25 06:36 . 2009-10-09 07:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-11-24 23:30 . 2006-06-13 05:21 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-24 21:54 . 2009-11-09 21:52 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-11-24 07:00 . 2006-06-07 02:15 -------- d-----w- c:\program files\ThinkPad
2009-11-15 22:49 . 2006-06-13 06:39 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-10 22:02 . 2007-10-22 22:00 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-09 21:53 . 2009-11-09 21:53 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-11-01 22:07 . 2009-11-01 22:07 -------- d-----w- c:\documents and settings\Rick\Application Data\Sonic
2009-11-01 22:06 . 2009-11-01 22:06 -------- d-----w- c:\documents and settings\Rick\Application Data\vnulneas
2009-11-01 22:06 . 2009-11-01 22:06 -------- d-----w- c:\documents and settings\Rick\Application Data\Leadertech
2009-11-01 22:06 . 2009-11-01 22:06 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-30 04:57 . 2009-10-30 04:57 -------- d-----w- c:\documents and settings\NetworkService\Application Data\vnulneas
2009-10-29 23:20 . 2006-06-07 02:15 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-29 23:19 . 2009-10-29 23:19 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2009-10-29 23:13 . 2009-10-29 23:13 -------- d-----w- c:\program files\Dr.METAZA2
2009-10-29 23:13 . 2006-06-13 05:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Roland DG Corporation
2009-10-29 20:52 . 2009-04-16 21:56 739696 ----a-w- c:\windows\system32\drivers\vetefile.sys
2009-10-29 20:52 . 2009-04-16 21:56 26352 ----a-w- c:\windows\system32\drivers\vet-filt.sys
2009-10-29 20:52 . 2009-04-16 21:56 21488 ----a-w- c:\windows\system32\drivers\vetfddnt.sys
2009-10-29 20:52 . 2009-04-16 21:56 21104 ----a-w- c:\windows\system32\drivers\vet-rec.sys
2009-10-29 20:52 . 2009-04-16 21:56 161008 ----a-w- c:\windows\system32\drivers\vetmonnt.sys
2009-10-29 20:52 . 2009-04-16 21:56 133520 ----a-w- c:\windows\system32\drivers\veteboot.sys
2009-10-29 07:45 . 1980-01-01 07:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 1980-01-01 07:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 1980-01-01 07:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 21:53 . 2008-06-15 20:50 1541416 ----a-w- c:\documents and settings\All Users\Application Data\CA\Consumer\AV\tmp\vete_tmp.dll
2009-10-13 10:30 . 1980-01-01 07:00 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 1980-01-01 07:00 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 1980-01-01 07:00 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-11 22:15 . 2009-10-11 22:15 152576 ----a-w- c:\documents and settings\Rick\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-10-09 07:23 . 2009-10-09 07:23 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\Installer\CommonCustomActions\msxml6Exec.exe
2009-10-09 07:23 . 2009-10-09 07:23 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\Installer\CommonCustomActions\Sleep.exe
2009-10-09 07:23 . 2009-10-09 07:23 3181612 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\Installer\CommonCustomActions\vcredistExec.exe
2009-10-09 07:22 . 2009-10-09 07:23 24501456 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\NokiaSoftwareUpdaterSetup_en[1].exe
2009-10-09 07:14 . 2009-10-09 07:14 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-10-09 07:14 . 2009-10-09 07:14 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-10-09 07:14 . 2009-10-09 07:14 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-10-09 07:14 . 2009-10-09 07:14 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-10-09 07:13 . 2009-10-09 07:14 33773208 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_eng_web.exe
2009-10-08 04:57 . 2007-10-09 03:03 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2009-10-08 04:57 . 1980-01-01 07:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 04:56 . 1980-01-01 07:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2009-10-06 01:52 . 2009-10-09 07:15 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2003-10-31 00:31 . 2003-10-31 00:31 0 ----a-w- c:\program files\error.dat
2008-08-15 00:06 . 2008-06-04 02:36 952 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"InternodeUsage"="c:\progra~1\INTERN~3\mum.exe" [2009-12-01 1361408]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-13 68856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-17 2002160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2005-08-29 94208]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-19 127037]
"CAVRID"="c:\program files\CA\eTrust Vet Antivirus\CAVRID.exe" [2009-11-26 271600]
"cctray"="c:\program files\CA\CA Internet Security Suite\casc.exe" [2009-11-11 374000]
"Norton Ghost 14.0"="c:\program files\Norton Ghost\Agent\VProTray.exe" [2008-12-11 2245992]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-03 1323008]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Enable Wireless Keyboard Driver.lnk - c:\program files\Wireless Device\Wireless Keyboard\Magickey.exe [2004-11-22 172032]
Enable Wireless Optical Mouse Driver.lnk - c:\program files\Wireless Device\Wireless Mouse\MouseAp.exe [2004-11-22 217088]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-12 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 04:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-06-06 05:46 79368 ----a-w- c:\windows\system32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-06 06:45 28672 ----a-w- c:\windows\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-06-17 05:23 24576 ----a-w- c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ERSvc"=2 (0x2)
"Messenger"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Laplink\\PCmover\\PCmover.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Internet Camera\\util\\util.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Keys Server\\sntlkeyssrvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Internet Camera\\admin\\admin.exe"=
"c:\\Program Files\\UltraVNC\\winvnc.exe"=
"c:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
"c:\\Program Files\\Virtual Mechanics\\SiteSpinner Pro V2\\bin\\SiteSpinnerProV2.exe"=
"c:\\Program Files\\UltraVNC\\vncviewer.exe"=
"c:\\Program Files\\UltraVNC\\vncviewer_tab.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Shareaza\\Shareaza.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
"53049:TCP"= 53049:TCP

"37955:TCP"= 37955:TCP

R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [5/01/2009 11:36 AM 107512]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [18/11/2008 12:14 PM 72696]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23/11/2009 8:43 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23/11/2009 8:43 AM 74480]
R2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\CA\CA Internet Security Suite\ccschedulersvc.exe [17/04/2009 7:56 AM 128240]
R2 SentinelKeysServer;Sentinel Keys Server;c:\program files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [1/08/2006 1:00 AM 316992]
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [1/01/1980 5:00 PM 5120]
R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [12/12/2008 12:37 PM 1153528]
R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [10/12/2008 12:58 PM 797176]
R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [19/12/2008 1:59 PM 297464]
R2 uvnc_service;uvnc_service;c:\program files\UltraVNC\winvnc.exe [23/04/2009 12:39 PM 1693128]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [12/12/2008 12:37 PM 205304]
R3 mv2;mv2;c:\windows\system32\drivers\mv2.sys [11/04/2009 7:11 PM 10688]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [23/11/2009 8:43 AM 7408]
R3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [20/12/2007 5:13 PM 1558000]
S2 COSIDS_TB;COSIDS_TB;c:\progra~1\COSIDS\BIN\TbMux32.exe [22/05/2007 8:20 AM 165376]
S2 PLSLT;ULS PLSLT Series Laser Engraver Firmware Loader;c:\windows\system32\drivers\PLSLTBL.sys [25/01/2008 8:24 AM 7808]
S2 VERSA2;ULS VersaLaser Series Laser Engraver Firmware Loader;c:\windows\system32\drivers\VERSA2BL.sys [9/03/2007 7:56 AM 7808]
S2 VERSALdr;ULS VersaLaser Engraver Firmware LoaderUSB\VID_10C3&PID_012C.DeviceDesc=ULS VersaLaser Air Compressor Firmware Loader;c:\windows\system32\drivers\VERSABL.sys [25/06/2003 6:49 AM 10112]
S3 DTV-DVBM9205;DTV-DVB USB Hybrid Analog/Capture;c:\windows\system32\drivers\M9205.sys [23/01/2006 9:13 PM 70272]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [6/10/2009 9:21 AM 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [6/10/2009 9:21 AM 3072]
S3 M9207;DTV-DVB M9207 USB DVB-T / TV BOX;c:\windows\system32\drivers\M9207BDA.sys [23/01/2006 9:13 PM 37760]
S3 oxser;OX16C95x Serial port driver;c:\windows\system32\drivers\oxser.sys [9/08/2006 4:46 PM 49792]
S3 QSerBus;Quatech PCI/PCMCIA/ISA Multiport Serial Device Enumerator;c:\windows\system32\drivers\qserbus.sys [3/07/2006 7:32 AM 26624]
S3 QTSerial;Quatech Multiport Serial Driver;c:\windows\system32\drivers\qtserial.sys [3/07/2006 7:32 AM 91648]
S3 SWI32;SWI32;\??\c:\program files\ThinkVantage\SystemUpdate\session\79wc17ww\SWI32.sys --> c:\program files\ThinkVantage\SystemUpdate\session\79wc17ww\SWI32.sys [?]
S3 ULSPrint;ULS Print Service;c:\windows\system32\drivers\ULSPRINT.sys [10/07/2007 9:41 AM 17024]
S3 ZteitSerMux;ZteitSerMux;c:\windows\system32\drivers\ZteitSermux.sys [16/12/2006 8:31 AM 37888]
S3 zteitserprt;zteitserprt;c:\windows\system32\drivers\ZteitSerPrt.sys [16/12/2006 8:37 AM 19200]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.amiles.com.au/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
LSP: c:\windows\System32\VetRedir.dll
Trusted Zone: amiles.com.au\www
TCP: {71407124-ED89-4796-8404-5222CC3D2CBA} = 192.231.203.132,192.231.203.3
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {3FED5791-B952-4958-A556-05892FE80AEC} - hxxp://192.168.10.12/webrtp.cab
DPF: {E62D1A95-8299-4B94-85D0-731DC125A60D} - hxxp://192.168.1.52:5052/ocx/IMMP4Control.ocx
FF - ProfilePath - c:\documents and settings\Rick\Application Data\Mozilla\Firefox\Profiles\3ir9oqfa.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.amiles.com.au/
FF - component: c:\documents and settings\Rick\Application Data\Mozilla\Firefox\Profiles\3ir9oqfa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
AddRemove-DUMMy - c:\docume~1\Rick\LOCALS~1\Temp\_ISTMP2.DIR\_ISTMP0.DIR\dummy.log
AddRemove-SignLab61DeInstKey - c:\engravelab6\Uninst.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-23 08:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1513153548-3119829742-721034989-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{900CD2A7-7DA5-989B-035D-BEE1872F8C3F}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iampoahdcflmlfaljf"=hex:69,65,65,67,67,63,69,6a,6f,62,6a,6a,65,62,65,6f,6d,6a,
67,69,67,6c,6a,63,69,68,67,69,66,63,6c,65,69,62,63,69,6d,63,61,6c,69,69,6c,\
"hampoahdcfglmhkk"=hex:6d,61,6c,62,64,66,64,6b,68,6f,69,6c,6e,6a,65,61,67,62,
66,6f,6f,68,68,64,68,66,00,00
"gampoahdcfcnpc"=hex:61,69,62,6c,6d,62,70,6d,70,6e,6f,67,65,6e,69,6b,6b,6c,61,
6b,67,6f,62,6a,6c,68,66,70,6a,6e,63,69,67,6a,6c,62,6c,65,6a,64,6e,6e,65,6d,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73A803C7-4F74-C091-1EFB-121D42A78ED2}]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8BDF16A2-6D31-0350-366C-B753DCC9573B}]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Messaging Subsystem\Applications]
@DACL=(02 0000)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1952)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\UmxWnp.Dll
c:\windows\system32\tphklock.dll
.
Completion time: 2009-12-23 08:38:43
ComboFix-quarantined-files.txt 2009-12-22 22:38
ComboFix2.txt 2009-12-03 02:16
Pre-Run: 16,911,937,536 bytes free
Post-Run: 18,843,594,752 bytes free
- - End Of File - - A265B1576272CE8252E8AD02C2C049AD