Everything ran correctly. Here is ComboFix.txt, hijackthis log will follow in the next post.
ComboFix 09-10-08.04 - bobbalouie 10/09/2009 13:22.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1110 [GMT -5:00]
Running from: c:\documents and settings\bobbalouie\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Trend Micro OfficeScan Antivirus *On-access scanning disabled* (Outdated) {BE118821-8C29-4952-9C0D-E9BE86BF23D1}
FW: Trend Micro OfficeScan Enterprise Client Firewall *disabled* {BE118821-8C29-4952-9C0D-E9BE86BF23D1}
FW: Trend Micro OfficeScan Enterprise Client Firewall *enabled* {E97937E6-2DD6-4F7D-9A3B-8C4D660B0CDF}
FW: Trend Micro Personal Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\bobbalouie\Local Settings\Temporary Internet Files\AllModuleInfo.txt
C:\install.exe
c:\recycler\S-1-5-21-583907252-2139871995-725345543-500
c:\windows\AUTOLNCH.REG
c:\windows\win32k.sys
----- BITS: Possible infected sites -----
hxxp://usslmcli001.net.plm.eds.com
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Legacy_R_SERVER
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Service_npf
-------\Service_r_server
((((((((((((((((((((((((( Files Created from 2009-09-09 to 2009-10-09 )))))))))))))))))))))))))))))))
.
2009-10-09 18:32 . 2009-10-09 18:32 -------- d-----w- c:\temp\WPDNSE
2009-10-09 18:31 . 2009-10-09 18:31 53248 ----a-w- c:\temp\catchme.dll
2009-10-09 18:31 . 2009-07-27 06:45 296224 ----a-w- c:\temp\IP9A72.EXE
2009-10-09 18:30 . 2009-10-09 18:30 16384 ----atw- c:\temp\Perflib_Perfdata_48c.dat
2009-10-09 14:18 . 2009-10-09 14:19 -------- d-----w- c:\temp\plugtmp-2
2009-10-09 00:08 . 2009-10-09 00:08 -------- d-----w- c:\temp\RarSFX8
2009-10-09 00:08 . 2009-10-09 00:08 -------- d-----w- c:\temp\RarSFX7
2009-10-09 00:08 . 2009-10-09 00:08 -------- d-----w- c:\temp\RarSFX6
2009-10-08 23:44 . 2009-10-08 23:44 -------- d-----w- c:\temp\RarSFX5
2009-10-08 22:36 . 2009-10-08 22:36 -------- d-----w- c:\program files\Sophos
2009-10-07 22:27 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-07 22:26 . 2009-10-07 22:29 -------- d-----w- c:\program files\Malwareremoval
2009-10-07 22:26 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-07 22:23 . 2009-10-07 22:23 -------- d-----w- c:\documents and settings\bobbalouie\Application Data\Malwarebytes
2009-10-07 22:23 . 2009-10-07 22:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-07 22:16 . 2009-10-09 18:26 -------- d-----w- c:\temp\RarSFX4
2009-10-07 22:15 . 2009-10-07 22:15 -------- d-----w- c:\temp\RarSFX3
2009-10-07 22:14 . 2009-10-09 18:26 -------- d-----w- c:\temp\RarSFX2
2009-10-07 22:14 . 2009-10-07 22:14 -------- d-----w- c:\temp\RarSFX1
2009-10-07 22:14 . 2009-10-07 22:14 -------- d-----w- c:\temp\RarSFX0
2009-10-07 21:51 . 2009-10-07 21:51 -------- d-----w- c:\program files\ERUNT
2009-10-07 21:42 . 2009-10-07 21:47 -------- d-----w- c:\program files\blaaaaa
2009-10-07 21:32 . 2009-10-07 21:38 -------- d-----w- c:\program files\blaaa
2009-10-07 21:18 . 2009-10-07 21:34 -------- d-----w- c:\program files\blaaaa
2009-10-06 16:26 . 2009-10-06 16:27 -------- d-----w- c:\temp\plugtmp-1
2009-10-06 15:47 . 2009-10-06 15:47 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-10-06 15:46 . 2009-10-06 15:46 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-10-06 15:46 . 2009-10-06 15:46 -------- d-----w- c:\documents and settings\bobbalouie\Application Data\SUPERAntiSpyware.com
2009-10-06 15:46 . 2009-10-06 15:46 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-06 13:49 . 2009-10-06 15:41 -------- d-----w- C:\$AVG8.VAULT$
2009-10-05 23:52 . 2009-10-06 15:23 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-10-05 23:52 . 2009-10-06 15:23 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-05 23:52 . 2009-10-05 23:52 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-10-05 23:52 . 2009-10-06 15:23 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-05 23:52 . 2009-10-09 13:55 -------- d-----w- c:\windows\system32\drivers\Avg
2009-10-05 23:52 . 2009-10-05 23:52 -------- d-----w- c:\program files\AVG
2009-10-05 23:52 . 2009-10-05 23:52 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-10-05 23:51 . 2009-10-05 23:53 -------- d-----w- c:\temp\7zS1.tmp
2009-10-05 19:17 . 2009-10-05 20:59 -------- d-----w- c:\program files\blaa
2009-10-05 18:38 . 2009-10-07 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-05 18:38 . 2009-10-05 19:03 -------- d-----w- c:\program files\bla
2009-10-04 17:38 . 2009-10-04 17:38 -------- d-----w- c:\documents and settings\bobbalouie\Application Data\Office Genuine Advantage
2009-10-02 17:26 . 2009-10-02 17:26 -------- d-----w- c:\program files\Pano2VR
2009-10-01 21:12 . 2009-10-01 23:16 -------- d-----w- c:\temp\C__DOCUME~1_bobbalouie_APPLIC~1_IDMComp_ULTRAE~1_QUARK_~1.TXT0
2009-09-29 19:38 . 2009-10-05 18:40 -------- d-----w- c:\temp\Nkn3D7.tmp
2009-09-29 19:36 . 2009-10-05 18:40 -------- d-----w- c:\temp\Nkn3D5.tmp
2009-09-29 19:35 . 2009-10-05 18:40 -------- d-----w- c:\temp\Nkn3D3.tmp
2009-09-28 22:50 . 2009-10-01 16:19 -------- d-----w- c:\temp\ipx420.IPIXIS
2009-09-28 22:49 . 2004-07-14 17:54 676864 ----a-w- c:\windows\system32\drivers\hardlock.sys
2009-09-28 22:49 . 2009-09-28 22:49 6656 ----a-w- c:\windows\system32\haspvdd.dll
2009-09-28 22:49 . 2009-09-28 22:49 47616 ----a-w- c:\windows\system32\drivers\Haspnt.sys
2009-09-28 22:49 . 2009-09-28 22:49 383 ----a-w- c:\windows\system32\haspdos.sys
2009-09-28 22:49 . 2009-09-28 22:49 -------- d-----w- c:\windows\occache
2009-09-28 22:49 . 2005-07-11 22:52 588288 ----a-w- c:\windows\system32\Ipx32d56.dll
2009-09-28 22:49 . 2009-09-28 22:50 -------- d-----w- c:\program files\Common Files\iPIX
2009-09-28 22:49 . 2005-07-11 22:52 729088 ----a-w- c:\windows\system32\Ipx32_56.dll
2009-09-28 22:49 . 2005-07-11 22:52 448000 ----a-w- c:\windows\system32\MM32DCMP.DLL
2009-09-28 22:49 . 2009-09-28 22:49 -------- d-----w- c:\program files\iPIX
2009-09-24 15:51 . 2009-09-24 15:53 -------- d-----w- c:\temp\ge4264
2009-09-24 03:31 . 2009-09-24 03:31 207640 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-09-23 16:57 . 2009-09-23 16:57 -------- d-----w- c:\documents and settings\bobbalouie\Application Data\ArGoSoft
2009-09-23 16:55 . 2009-09-23 16:55 -------- d-----w- c:\documents and settings\bobbalouie\Local Settings\Application Data\Apple_Inc
2009-09-23 16:31 . 2009-09-23 16:31 -------- d-----w- c:\program files\iPod
2009-09-23 16:31 . 2009-09-23 16:32 -------- d-----w- c:\program files\iTunes
2009-09-23 16:20 . 2009-09-23 16:20 -------- d-----w- c:\program files\iPhone Configuration Utility
2009-09-22 15:08 . 2009-09-22 15:08 -------- d-----w- c:\program files\Easypano
2009-09-17 19:30 . 2009-09-23 23:26 -------- d-----w- c:\documents and settings\bobbalouie\Application Data\SQLyog
2009-09-17 19:30 . 2009-09-17 19:30 -------- d-----w- c:\program files\SQLyog Community
2009-09-15 21:31 . 2009-09-15 21:32 -------- d-----w- c:\documents and settings\bobbalouie\Application Data\TrueCrypt
2009-09-15 21:30 . 2009-09-15 21:30 217664 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2009-09-15 21:30 . 2009-09-15 21:30 -------- d-----w- c:\program files\TrueCrypt
2009-09-09 22:47 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-09 20:05 . 2009-09-09 20:05 62632 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-09 18:33 . 2009-09-09 18:34 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-09 18:03 . 2005-11-30 15:33 -------- d-----w- c:\program files\Mobile Automation
2009-10-09 15:04 . 2006-09-08 14:52 -------- d-----w- c:\program files\stt
2009-10-08 15:29 . 2008-06-10 19:43 -------- d-----w- c:\documents and settings\bobbalouie\Application Data\FileZilla
2009-10-07 23:13 . 2006-05-23 12:12 -------- d-----w- c:\program files\Trend Micro
2009-10-05 21:42 . 2006-11-08 20:46 -------- d-----w- c:\program files\Opera
2009-10-05 21:41 . 2007-03-30 16:45 -------- d-----w- c:\program files\Neat Image
2009-10-02 21:56 . 2008-02-20 00:09 -------- d-----w- c:\documents and settings\bobbalouie\Application Data\MySQL
2009-10-02 17:27 . 2009-01-22 18:08 -------- d-----w- c:\documents and settings\bobbalouie\Application Data\GardenGnomeSoftware
2009-09-29 19:38 . 2006-09-18 20:39 20 -c-h--w- c:\documents and settings\All Users\Application Data\PKP_DLbz.DAT
2009-09-23 16:31 . 2007-07-12 22:35 -------- d-----w- c:\program files\Common Files\Apple
2009-09-09 23:00 . 2006-09-06 18:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-09 22:52 . 2009-08-03 18:57 -------- d-----w- c:\program files\Java
2009-09-09 18:46 . 2006-09-18 15:49 -------- d-----w- c:\documents and settings\bobbalouie\Application Data\Apple Computer
2009-08-31 18:21 . 2009-07-24 14:11 -------- d-----w- c:\program files\Free Video Converter
2009-08-29 00:42 . 2008-09-10 15:41 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-29 00:42 . 2007-11-13 17:12 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-24 19:54 . 2006-09-18 20:16 20 -c-h--w- c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2009-08-24 19:54 . 2007-01-29 16:16 20 -c-h--w- c:\documents and settings\All Users\Application Data\PKP_DLeh.DAT
2009-08-10 18:33 . 2006-09-18 14:11 81320 ----a-w- c:\documents and settings\bobbalouie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-07 00:24 . 2005-11-29 16:19 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-07 00:24 . 2005-11-29 16:19 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-07 00:24 . 2006-05-09 14:50 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-07 00:24 . 2005-11-29 16:19 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-07 00:24 . 2005-11-29 16:19 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-07 00:24 . 2004-08-04 04:56 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-07 00:23 . 2005-11-29 16:19 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-07 00:23 . 2008-01-22 21:01 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-07 00:23 . 2008-01-22 21:01 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-07 00:23 . 2005-11-29 16:19 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2004-08-04 04:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 20:07 . 2009-08-03 20:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
2009-08-03 20:07 . 2009-08-03 20:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 20:07 . 2009-08-03 20:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
2009-07-25 10:23 . 2009-08-03 18:58 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 2004-08-04 04:56 58880 ------w- c:\windows\system32\atl.dll
2009-07-14 04:43 . 2004-08-04 04:56 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2007-07-09 21:30 . 2007-07-09 21:30 57344 -c--a-w- c:\program files\internet explorer\plugins\PluginWrapper.dll
2005-07-11 22:52 . 2009-09-28 22:49 32768 ----a-w- c:\program files\mozilla firefox\plugins\appsub32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMMUNICATOR"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2007-07-23 5803368]
"wben"="c:\program files\Starfield\Desktop Notifier\wben.exe" [2009-06-25 338456]
"\\192.168.1.116\EPSON NX300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIEJA.EXE" [2008-01-21 188928]
"HijackThis startup scan"="d:\install\spybot\HijackThis.exe" [2009-10-07 401720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoxioEngineUtility"="c:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 65536]
"RoxioDragToDisc"="c:\apps\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2004-01-09 868352]
"OfficeScanNT Monitor"="c:\program files\Trend Micro\OfficeScan Client\pccntmon.exe" [2009-07-27 718120]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-03-20 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 86960]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DVDTray"="c:\program files\Ahead\ODD Toolkit\DVDTray.exe" [2004-09-03 65536]
"iRiver Updater"="\Updater.exe" [2004-07-01 212992]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-15 623992]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SIECACST"="c:\program files\Siemens\CardOS API\bin\siecacst.exe" [2007-08-02 81920]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2008-10-28 181544]
"QuickTime Task"="c:\apps\QuickTime\qttask.exe" [2009-09-05 417792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-06 2023704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-11-04 7204864]
"EPM Agent"="c:\progra~1\MOBILE~1\rstate.exe" [2006-05-26 94208]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-11-04 1519616]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2007-07-23 5803368]
"MSMSGS"="c:\progra~1\MESSEN~1\Msmsgs.exe" [2005-09-01 1658592]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Install Pending Files.LNK - c:\program files\PTPNDFLS\PTPNDFLS.EXE [2006-9-6 1695744]
Monitor Apache Servers.lnk - c:\program files\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe [2007-1-9 41041]
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2006-9-18 118784]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-2-5 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-10-06 15:23 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
2004-11-01 16:50 8704 ----a-w- c:\windows\system32\PCANotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\Msmsgs.exe"=
"c:\\Program Files\\Microsoft Office Communicator\\communicator.exe"=
"c:\\apps\\MSOffice\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/5/2009 6:52 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/5/2009 6:52 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/15/2009 11:42 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 74480]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/5/2009 6:52 PM 297752]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [10/28/2008 4:42 PM 156968]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 5:45 AM 13088]
R2 MobileAutmationAgentService;iPass Endpoint Policy Management Agent;c:\program files\Mobile Automation\rstate.exe [11/30/2005 10:33 AM 94208]
R2 TmFilter;Trend Micro Filter;c:\program files\Trend Micro\OfficeScan Client\tmxpflt.sys [11/9/2005 8:34 PM 225296]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\Trend Micro\OfficeScan Client\tmpreflt.sys [11/9/2005 8:34 PM 36368]
R2 wsnm;VMware VDM Client Service;c:\program files\VMware\VMware VDM\Client\bin\wsnm.exe [5/8/2008 6:51 PM 131072]
R3 cxbu0wdm;CardMan 3x21;c:\windows\system32\drivers\cxbu0wdm.sys [1/15/2008 1:39 PM 97792]
R3 Eacfilt;Eacfilt Miniport;c:\windows\system32\drivers\eacfilt.sys [9/6/2006 5:11 PM 11113]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [11/23/2007 4:15 PM 338960]
R3 TmPfw;OfficeScan NT Firewall;c:\program files\Trend Micro\OfficeScan Client\TmPfw.exe [3/31/2008 12:51 PM 488768]
R3 WSUSBDMAN;VMware VDM Virtual Client USB Manager;c:\windows\system32\drivers\WSUSBDMAN.sys [5/8/2008 6:45 PM 21504]
S2 gupdate1c98bcf40f039ca;Google Update Service (gupdate1c98bcf40f039ca);c:\program files\Google\Update\GoogleUpdate.exe [2/10/2009 5:31 PM 133104]
S2 SttService;Stt Services;c:\windows\SttService.exe [5/19/2009 1:20 PM 36923]
S3 ExtranetAccess;Contivity VPN Service;c:\program files\Nortel Networks\Extranet_serv.exe [9/6/2006 5:11 PM 782336]
S3 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [9/6/2006 5:11 PM 216459]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\4E9.tmp --> c:\windows\system32\4E9.tmp [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 7408]
S3 SIWIO;SIW low-level I/O driver;\??\c:\windows\TEMP\SiwIo.sys --> c:\windows\TEMP\SiwIo.sys [?]
S3 TmProxy;OfficeScan NT Proxy Service;c:\program files\Trend Micro\OfficeScan Client\TmProxy.exe [3/31/2008 12:51 PM 652552]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MDM
*NewlyCreated* - OSE
*Deregistered* - uphcleanhlp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2008-09-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-10 22:30]
2009-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-10 22:30]
2009-10-08 c:\windows\Tasks\stt_inv_report_24.job
- c:\program files\stt\stt_report_controller.bat [2006-09-08 13:52]
2009-10-09 c:\windows\Tasks\User_Feed_Synchronization-{1F129A1B-6685-4148-8FB7-5609AA0C6559}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://infoweb.ugs.com/
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\apps\MSOffice\Office12\EXCEL.EXE/3000
Trusted Zone: swserve
Trusted Zone: ugs.com
TCP: {BA8A4B2F-E44F-4BF5-B0ED-54F7D46E3501} = 134.244.252.169,146.122.6.16
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: Web-Based Email Tools - hxxp://email.secureserver.net/Download.CAB
DPF: {87BF5318-D5F0-41F4-9D14-47967FA8C12B} - hxxp://www.ipix.com/viewers/ipixx.cab
FF - ProfilePath - c:\documents and settings\bobbalouie\Application Data\Mozilla\Firefox\Profiles\279ww07z.default\
FF - prefs.js: browser.startup.homepage - hxxp://infoweb.ugs.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\apps\QuickTime\Plugins\npqtplugin.dll
FF - plugin: c:\apps\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: c:\apps\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: c:\apps\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: c:\apps\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: c:\apps\QuickTime\Plugins\npqtplugin6.dll
FF - plugin: c:\apps\QuickTime\Plugins\npqtplugin7.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npipx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPipxLicenseRetriever.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
AddRemove-Guitar Leads - d:\program files\Guitar-Leads.com\uninst.exe
AddRemove-WZCLINE - c:\apps\WinZip\winzip32
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-09 13:31
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\4E9.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"d:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"d:\program files\MySQL\MySQL Server 5.0\my.ini\" MySQL"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@DACL=(02 0011)
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@DACL=(02 0011)
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@DACL=(02 0011)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1324)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2804)
c:\windows\system32\WININET.dll
c:\windows\system32\nview.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\apps\Hummingbird\Hummingbird Neighborhood\heshell.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\scardsvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\Hummingbird\Connectivity\10.00\Inetd\inetd32.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Trend Micro\OfficeScan Client\NTRtScan.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\system32\tcpsvcs.exe
c:\program files\Trend Micro\OfficeScan Client\TmListen.exe
c:\program files\UPHClean\uphclean.exe
c:\windows\system32\MsPMSPSv.exe
c:\program files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
c:\temp\IP9A72.EXE
C:\Updater.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-10-09 13:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-09 18:41
Pre-Run: 512,024,576 bytes free
Post-Run: 1,278,980,096 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
382 --- E O F --- 2009-10-04 17:31