Are you having any problems in particular? The log looks clean.
Main Topics
Browse All TopicsComboFix 09-08-04.04 - PavieJ 10/08/2009 11:54.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.33.1033.18
Running from: c:\program files\ComboFix.exe
AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E
FW: Symantec Endpoint Protection *disabled* {BE898FE3-CD0B-4014-85A9-0
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((
.
c:\windows\system32\lsprst
c:\windows\system32\ssprs.
.
((((((((((((((((((((((((( Files Created from 2009-07-10 to 2009-08-10 ))))))))))))))))))))))))))
.
2009-08-10 10:02 . 2009-08-10 10:03 53248 ----a-w- c:\temp\catchme.dll
2009-08-10 09:54 . 2009-08-10 09:54 -------- d-----w- c:\temp\WPDNSE
2009-08-10 07:34 . 2009-08-10 07:34 16384 ----atw- c:\temp\Perflib_Perfdata_3
2009-08-06 11:10 . 2009-08-06 11:10 3154932 ----a-r- c:\program files\ComboFix.exe
.
((((((((((((((((((((((((((
.
2009-08-10 08:18 . 2009-04-17 10:41 -------- d-----w- c:\documents and settings\PavieJ\Applicatio
2009-08-08 19:47 . 2008-04-14 10:59 12 ----a-w- c:\windows\bthservsdp.dat
2009-08-03 19:52 . 2008-12-10 17:18 -------- d-----w- c:\program files\Symantec AntiVirus
2009-07-21 12:41 . 2008-04-17 12:20 -------- d-----w- c:\documents and settings\PavieJ\Applicatio
2009-07-16 06:53 . 2009-02-06 20:24 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverCure
2009-06-29 05:29 . 2008-04-18 13:37 77552 ----a-w- c:\documents and settings\PavieJ\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-26 14:06 . 2009-06-26 14:06 156968 ----a-w- c:\documents and settings\LocalService\Loca
2009-06-26 14:04 . 2009-06-26 14:04 -------- d-----w- c:\program files\MSBuild
2009-06-26 14:04 . 2009-06-26 14:04 -------- d-----w- c:\program files\Reference Assemblies
2009-06-26 13:56 . 2009-06-26 13:56 -------- d-----w- c:\program files\MSXML 6.0
2009-06-26 12:57 . 2009-06-26 12:57 289080 ----a-w- c:\program files\AutodeskDesignRevSet
2009-06-22 22:36 . 2009-06-22 22:36 -------- d-----w- c:\program files\ParetoLogic
2009-06-22 22:36 . 2009-05-17 22:33 2988592 ----a-w- c:\documents and settings\All Users\Application Data\ParetoLogic\UUS2\Driv
2009-05-25 12:07 . 2009-05-25 11:38 124416 ----a-w- c:\windows\hpqins00.dat
2009-05-18 22:58 . 2009-05-29 08:35 1693316 ----a-w- c:\windows\system32\esetup
2009-05-01 19:15 . 2009-05-01 19:15 2488008 ----a-w- c:\program files\mediacenter.exe
2009-04-21 12:00 . 2009-04-21 11:59 1880648 ----a-w- c:\program files\TeamViewer_Setup.exe
2009-03-11 14:15 . 2009-03-11 14:14 34175700 ----a-w- c:\program files\Citadon setup.exe
2009-02-09 09:21 . 2009-02-09 09:21 6561169 ----a-w- c:\program files\SecureClient_Cluster
2009-02-06 22:51 . 2009-02-06 22:51 11562257 ----a-w- c:\program files\The-KMPlayer-FR-2412
2009-02-06 20:33 . 2009-02-06 20:32 52307672 ----a-w- c:\program files\AVSVideoConverter.ex
2008-09-22 09:38 . 2008-09-22 09:38 27199528 ----a-w- c:\program files\eDrawingsFullEnglish
2008-06-02 14:35 . 2008-06-02 14:35 1271557 ----a-w- c:\program files\wrar371fr.exe
2008-04-18 13:04 . 2008-04-18 13:03 213316736 ----a-w- c:\program files\SetupDWGTrueView2009
2008-04-14 14:35 . 2008-04-14 14:35 97694 ----a-w- c:\program files\install_Windows Media Player_.exe
2008-04-14 11:46 . 2008-04-14 11:46 16500592 ----a-w- c:\program files\DivXInstaller.exe
.
((((((((((((((((((((((((((
.
- 2004-08-04 12:00 . 2009-08-05 19:17 72238 c:\windows\system32\perfc0
+ 2004-08-04 12:00 . 2009-08-10 07:39 72238 c:\windows\system32\perfc0
- 2006-08-08 10:50 . 2009-08-01 13:52 32768 c:\windows\system32\config
+ 2006-08-08 10:50 . 2009-08-07 11:03 32768 c:\windows\system32\config
- 2006-08-08 10:50 . 2009-08-01 13:52 32768 c:\windows\system32\config
+ 2006-08-08 10:50 . 2009-08-07 11:03 32768 c:\windows\system32\config
+ 2006-08-08 10:50 . 2009-08-07 11:03 32768 c:\windows\system32\config
- 2006-08-08 10:50 . 2009-08-01 13:52 32768 c:\windows\system32\config
- 2004-08-04 12:00 . 2009-08-05 19:17 444362 c:\windows\system32\perfh0
+ 2004-08-04 12:00 . 2009-08-10 07:39 444362 c:\windows\system32\perfh0
+ 2006-08-08 11:29 . 2009-08-10 07:34 296480 c:\windows\system32\FNTCAC
- 2006-08-08 11:29 . 2009-07-18 11:12 296480 c:\windows\system32\FNTCAC
.
((((((((((((((((((((((((((
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"DriverCure"="c:\program files\ParetoLogic\DriverCu
[HKEY_LOCAL_MACHINE\SOFTWA
"igfxtray"="c:\windows\sys
"igfxhkcmd"="c:\windows\sy
"igfxpers"="c:\windows\sys
"SunJavaUpdateSched"="c:\p
"dla"="c:\windows\system32
"UpdateManager"="c:\progra
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"Discovery User Input"="c:\discovery\User Input\userin32.exe" [2009-01-09 233472]
"Broadcom Wireless Manager UI"="c:\windows\system32\W
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"bginfo"="c:\documents and settings\all users\application data\ech\bginfo.exe" [2008-02-06 963624]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-04-17 115560]
"SigmatelSysTrayApp"="stsy
"BluetoothAuthenticationAg
[HKEY_USERS\.DEFAULT\Softw
"CTFMON.EXE"="c:\windows\s
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
Powerproject Startup.lnk - c:\program files\Asta\Asta Powerproject\Teamplan.exe [2007-2-13 3485785]
[HKEY_LOCAL_MACHINE\softwa
"MaxGPOScriptWait"= 5 (0x5)
[HKEY_LOCAL_MACHINE\softwa
2008-01-29 14:14 24669 ----a-w- c:\windows\system32\ckpNot
[HKEY_LOCAL_MACHINE\softwa
"Script"=CachedMode.vbs
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\ECHARRIS.LOCAL\
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\ECHARRIS.LOCAL\
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\ECHARRIS.LOCAL\
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\ECHARRIS.LOCAL\
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\ECHARRIS.LOCAL\
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\ECHARRIS.LOCAL\
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\ECHARRIS.LOCAL\
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\ECHARRIS.LOCAL\
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\ECHARRIS.LOCAL\
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\ECHARRIS.LOCAL\
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\ECHARRIS.LOCAL\
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\ECHARRIS.LOCAL\
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\ECHARRIS.LOCAL\
[HKEY_LOCAL_MACHINE\SYSTEM
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM
@="Service"
[HKEY_LOCAL_MACHINE\softwa
"DisableMonitoring"=dword:
[HKLM\~\services\sharedacc
"%windir%\\system32\\sessm
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:16
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169
[HKLM\~\services\sharedacc
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22
"26675:TCP"= 26675:TCP:169.254.2.0/255.
R1 dwvkbd;DameWare Virtual Keyboard 32 bit Driver;c:\windows\system32
R1 FW1;SecuRemote Miniport;c:\windows\system
R2 CP_OMDRV;Check Point Office Mode Module;c:\windows\system32
R2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\
R2 VNASC;Check Point Virtual Network Adapter - SecureClient;c:\windows\sy
R2 VPN-1;VPN-1 Module;c:\windows\system32
R3 DwMirror;DwMirror;c:\windo
R3 EraserUtilRebootDrv;Eraser
S3 COH_Mon;COH_Mon;c:\windows
S3 G3GRUMDM;G3G R USB Modem;c:\windows\system32\
S3 G3GRUSER;G3G R USB Serial;c:\windows\system32
--- Other Services/Drivers In Memory ---
*Deregistered* - uphcleanhlp
[HKEY_LOCAL_MACHINE\softwa
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder
2009-02-06 c:\windows\Tasks\DriverCur
- c:\program files\ParetoLogic\DriverCu
2009-08-05 c:\windows\Tasks\ParetoLog
- c:\program files\Common Files\ParetoLogic\UUS2\UUS
2009-06-26 c:\windows\Tasks\ParetoLog
- c:\program files\Common Files\ParetoLogic\UUS2\Par
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://myportal.echarris.c
uInternet Connection Wizard,ShellNext = hxxp://echonew/live
uInternet Settings,ProxyServer = internetuk.echarris.local:
uInternet Settings,ProxyOverride = *.echarris.com;*.local;10.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFIC
Trusted Zone: citadon.com
Trusted Zone: echarris.com
Trusted Zone: echarris.local
Trusted Zone: uk1immstsweb1vm
Trusted Zone: uk1immtstweb1vm
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\cla
DPF: {5D86DDB5-BDF9-441B-9E9E-D
DPF: {6BD88D94-03D2-4ABF-99A3-7
FF - ProfilePath - c:\documents and settings\paviej\Applicatio
FF - prefs.js: browser.startup.homepage - hxxp://myportal.echarris.c
FF - prefs.js: network.proxy.ftp - internetuk.echarris.local
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - internetuk.echarris.local
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - internetuk.echarris.local
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - internetuk.echarris.local
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - internetuk.echarris.local
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 1
.
**************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-10 12:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1952)
c:\windows\system32\igfxde
.
Completion time: 2009-08-10 12:06
ComboFix-quarantined-files
ComboFix2.txt 2009-08-06 11:30
Pre-Run: 2,822,086,656 bytes free
Post-Run: 2,796,343,296 bytes free
217
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Business Accounts
Answer for Membership
by: ComputerTechiePosted on 2009-08-10 at 10:14:26ID: 25061829
uninstall bitdefender.