ComboFix 10-01-24.05 - Maureen 01/25/2010 11:39:09.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.618 [GMT -5:00]
Running from: c:\documents and settings\Maureen\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
((((((((((((((((((((((((( Files Created from 2009-12-25 to 2010-01-25 )))))))))))))))))))))))))))))))
.
2010-01-25 00:56 . 2010-01-25 00:56 -------- d-----w- c:\program files\Common Files\Java
2010-01-25 00:55 . 2010-01-25 00:55 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-23 22:05 . 2010-01-23 22:05 -------- d-----w- c:\program files\Trend Micro
2010-01-20 17:08 . 2010-01-20 17:08 -------- d-sh--w- c:\documents and settings\Carolyn\PrivacIE
2010-01-20 17:04 . 2010-01-20 17:04 -------- d-sh--w- c:\documents and settings\Carolyn\IETldCache
2010-01-17 21:22 . 2010-01-17 21:29 -------- d-----w- c:\program files\Garmin
2010-01-17 21:22 . 2010-01-17 21:22 -------- d-----w- c:\documents and settings\All Users\Application Data\GARMIN
2010-01-17 21:22 . 2010-01-17 21:22 -------- d-----w- C:\Garmin
2010-01-17 19:49 . 2010-01-17 20:25 -------- d-----w- c:\documents and settings\Maureen\Application Data\Download Manager
2010-01-17 19:39 . 2010-01-17 20:53 -------- d-----w- c:\documents and settings\Maureen\Application Data\GARMIN
2010-01-17 01:54 . 2010-01-17 01:54 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-01-17 01:47 . 2010-01-17 01:47 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-01-16 19:55 . 2010-01-16 19:55 -------- d-----w- c:\documents and settings\Maureen\Application Data\Malwarebytes
2010-01-16 19:55 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-16 19:55 . 2010-01-16 19:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-16 19:55 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-16 19:55 . 2010-01-17 01:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-30 03:16 . 2009-12-30 03:16 -------- d-sh--w- c:\documents and settings\Bob\PrivacIE
2009-12-30 03:14 . 2009-12-30 03:14 -------- d-sh--w- c:\documents and settings\Bob\IETldCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-25 16:54 . 2009-08-23 20:04 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-01-25 16:54 . 2009-08-23 20:02 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2010-01-25 15:36 . 2007-07-04 12:37 -------- d-----w- c:\program files\iTunes
2010-01-25 15:36 . 2007-07-04 12:34 -------- d-----w- c:\program files\QuickTime
2010-01-25 15:36 . 2007-04-08 18:25 -------- d-----w- c:\program files\DellSupport
2010-01-25 00:55 . 2004-04-13 06:25 -------- d-----w- c:\program files\Java
2010-01-24 03:49 . 2005-04-03 16:04 -------- d-----w- c:\documents and settings\Carolyn\Application Data\Viewpoint
2010-01-24 03:49 . 2005-04-03 01:34 -------- d-----w- c:\documents and settings\Gregory Arnold\Application Data\Viewpoint
2010-01-24 03:49 . 2004-04-13 06:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2010-01-23 02:54 . 2008-10-24 23:22 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-10 15:49 . 2004-04-20 23:23 41224 ----a-w- c:\documents and settings\Maureen\Application Data\wklnhst.dat
2010-01-10 12:39 . 2004-11-08 01:35 12086 -c--a-w- c:\documents and settings\Gregory Arnold\Application Data\wklnhst.dat
2009-12-21 19:14 . 2004-02-06 22:05 916480 ------w- c:\windows\system32\wininet.dll
2009-12-21 09:31 . 2005-09-10 18:28 -------- d-----w- c:\program files\Google
2009-12-05 18:50 . 2009-08-23 20:10 -------- d-----w- c:\documents and settings\Maureen\Application Data\Skype
2009-12-05 13:05 . 2009-08-23 20:14 -------- d-----w- c:\documents and settings\Maureen\Application Data\skypePM
2009-12-02 03:14 . 2009-12-02 02:51 -------- d-----w- c:\documents and settings\Gregory Arnold\Application Data\Skype
2009-11-21 15:51 . 2002-08-29 10:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2008-07-31 11:32 . 2008-07-31 11:32 27024112 -c--a-w- c:\program files\PowerPointViewer.exe
2008-03-10 18:35 . 2008-03-10 18:35 0 -c--a-w- c:\program files\temp01
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-09-26 2356088]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-31 468408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-08-13 8466432]
"nwiz"="nwiz.exe" [2007-08-13 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-08-13 81920]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-05-08 2780432]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
c:\documents and settings\Bob\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2004-7-8 225280]
c:\documents and settings\Carolyn\Start Menu\Programs\Startup\
wkcalrem.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2003-12-5 24651]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
SMCWUSB-G 802.11g Wireless USB Utility.lnk - c:\program files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe [2006-6-26 610304]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
2004-08-25 15:27 65536 -c--a-w- c:\windows\SYSTEM32\Ati2mdxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDet]
2002-09-30 06:00 45056 -c--a-w- c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDET.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2002-10-29 14:18 49152 -c--a-w- c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920]
2003-06-02 18:25 270336 ----a-w- c:\program files\Dell AIO Printer A920\dlbkbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2003-08-06 06:04 114741 -c--a-w- c:\windows\SYSTEM32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
2003-09-04 01:12 221184 -c--a-w- c:\program files\Intel\Modem Event Monitor\IntelMEM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-09 02:09 305440 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
2003-10-06 15:05 53248 -c--a-w- c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnappau]
2004-08-13 21:41 86016 -c--a-w- c:\program files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2003-08-27 00:47 204800 -c----w- c:\program files\Dell\Media Experience\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 06:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
2003-08-19 05:01 110592 -c--a-w- c:\program files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 06:00 90112 -c----w- c:\windows\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"c:\\Program Files\\CyberLink\\PCM4Everio\\PCM4Everio.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R3 ZD1211BU(Atheros);Atheros ZD1211B IEEE 802.11 Wireless LAN Driver (USB)(Atheros);c:\windows\SYSTEM32\DRIVERS\ZD1211BU.sys [4/11/2008 8:52 PM 722432]
S2 gupdate1c9aff7d14c6f00;Google Update Service (gupdate1c9aff7d14c6f00);c:\program files\Google\Update\GoogleUpdate.exe [3/28/2009 5:52 PM 133104]
S2 MtxVideo;Matrox WDM capture/crossbar driver;c:\windows\SYSTEM32\DRIVERS\mtxvideo.sys [5/4/2008 11:22 AM 103296]
S3 SysInfo;SysInfo;c:\program files\PlayOnline\SquareEnix\PlayOnlineViewer\polcfg\sysinfo.sys [8/29/2003 2:40 PM 6912]
.
Contents of the 'Scheduled Tasks' folder
2010-01-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34]
2010-01-25 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\SYSTEM32\cleanmgr.exe [2002-08-29 00:12]
2010-01-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-28 22:51]
2010-01-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-28 22:51]
2010-01-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-08-16 17:22]
2010-01-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-08-16 17:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/home.html
uInternet Settings,ProxyOverride = *.local
Trusted Zone: dslreports.com\www
Trusted Zone: mcafee.com
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.1.0/GarminAxControl.CAB
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} - hxxp://www.gamehouse.com/games/gamehouse/ghplayer.cab
DPF: {775879E2-7309-4619-BB02-AADE41F4B690} - hxxp://webgames.d.tmsrv.com/c=fdb86f236d4106103ae39aef993e7860/aff=t_03cm_wg/p/release/playfirst/wg_dreamchronicles/dreamchronicles/dreamweb.1.0.0.9.cab
DPF: {E41BA393-9078-424E-9554-9DB5126F5F4C} - hxxp://www.shockwave.com/content/dreamchronicles2/sis/dream2web.1.0.0.13.cab
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Sonic RecordNow! - (no file)
HKU-Default-Run-ALUAlert - c:\program files\Symantec\LiveUpdate\ALUNotify.exe
MSConfigStartUp-AsioReg - CTASIO.DLL
MSConfigStartUp-ATIPTA - c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
MSConfigStartUp-CTHelper - CTHELPER.EXE
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\j2re1.4.2_05\bin\jusched.exe
MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
MSConfigStartUp-ViewMgr - c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-25 11:56
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(5732)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\progra~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\CTsvcCDA.exe
c:\program files\Creative\Shared Files\CTDevSrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\wanmpsvc.exe
c:\windows\System32\MsPMSPSv.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
.
**************************************************************************
.
Completion time: 2010-01-25 12:11:43 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-25 17:11
ComboFix2.txt 2010-01-23 21:48
Pre-Run: 30,423,629,824 bytes free
Post-Run: 30,417,563,648 bytes free
- - End Of File - - 3712C78E3B94289795482FE583CADB47
ok...just fyi - I will be away from my computer for a few hours but will be back to do the next task...thank you!