Cubbybulin
asked on
Windows Task Manager or Ad-Aware will not open
Had some malware, and now now task manager or lavasoft adaware wont open. Its not disabled, just wont open. I downloaded procexp.exe and i can see taskmanager there running, but it wont open. I had Norton up to date and did not find any viruses, and spy bot got rid of the malware so PC seems clean now. Any ideas? Thanks!
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
I ran combofix (I had to rename it) and now task manager comes up and ad-aware is running! YEAY!
Here is the log:
ComboFix 09-12-21.04 - Administrator 12/22/2009 8:18.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18. 2046.1429 [GMT -5:00]
Running from: c:\documents and settings\Administrator\Des ktop\ab.ex e
.
(((((((((((((((((((((((((( (((((((((( ((( Other Deletions )))))))))))))))))))))))))) )))))))))) )))))))))) )))
.
c:\progra~1\COMMON~1\BLACK B~1\System \NTSVc.ocx
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\EventSystem.log
c:\windows\system32\regsvr .exe
.
(((((((((((((((((((((((((( (((((((((( ((( Drivers/Services )))))))))))))))))))))))))) )))))))))) )))))))))) )))
.
-------\Legacy_BHDRVX86
-------\Service_BHDrvx86
((((((((((((((((((((((((( Files Created from 2009-11-22 to 2009-12-22 )))))))))))))))))))))))))) )))))
.
2009-12-22 13:03 . 2009-12-02 13:19 64288 ----a-w- c:\windows\system32\driver s\Lbd.sys
2009-12-22 13:02 . 2009-12-22 13:02 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8 C9B-55C9A3 9A7CA9}
2009-12-22 13:01 . 2009-12-22 13:01 -------- d-----w- c:\program files\Lavasoft
2009-12-21 19:23 . 2004-08-04 10:00 4677 ----a-w- c:\windows\system32\dllcac he\zeeverm .dll
2009-12-21 19:23 . 2004-08-04 10:00 29760 ----a-w- c:\windows\system32\dllcac he\znetm.d ll
2009-12-21 19:23 . 2004-08-04 10:00 13894 ----a-w- c:\windows\system32\dllcac he\zonelib m.dll
2009-12-21 19:23 . 2004-08-04 10:00 113222 ----a-w- c:\windows\system32\dllcac he\zonecli m.dll
2009-12-21 19:23 . 2004-08-04 10:00 41029 ----a-w- c:\windows\system32\dllcac he\zcorem. dll
2009-12-21 19:23 . 2004-08-04 10:00 36937 ----a-w- c:\windows\system32\dllcac he\zclient m.exe
2009-12-21 19:23 . 2008-04-14 01:12 116224 ----a-w- c:\windows\system32\dllcac he\xrxwiad r.dll
2009-12-21 19:23 . 2001-08-18 03:36 23040 ----a-w- c:\windows\system32\dllcac he\xrxwbtm p.dll
2009-12-21 19:23 . 2008-04-14 01:12 18944 ----a-w- c:\windows\system32\dllcac he\xrxscnu i.dll
2009-12-21 19:23 . 2001-08-18 03:37 27648 ----a-w- c:\windows\system32\dllcac he\xrxftpl t.exe
2009-12-21 19:23 . 2001-08-18 03:37 4608 ----a-w- c:\windows\system32\dllcac he\xrxflnc h.exe
2009-12-21 19:22 . 2001-08-18 03:37 99865 ----a-w- c:\windows\system32\dllcac he\xlog.ex e
2009-12-21 19:22 . 2001-08-17 17:11 16970 ----a-w- c:\windows\system32\dllcac he\xem336n 5.sys
2009-12-21 19:22 . 2004-08-04 03:29 19455 ----a-w- c:\windows\system32\dllcac he\wvchntx x.sys
2009-12-21 19:22 . 2008-04-13 19:46 19200 ----a-w- c:\windows\system32\dllcac he\wstcode c.sys
2009-12-21 19:22 . 2004-08-04 03:29 12063 ----a-w- c:\windows\system32\dllcac he\wsiintx x.sys
2009-12-21 19:22 . 2008-04-14 01:12 8192 ----a-w- c:\windows\system32\dllcac he\wshirda .dll
2009-12-21 19:22 . 2008-04-13 19:36 8832 ----a-w- c:\windows\system32\dllcac he\wmiacpi .sys
2009-12-21 19:22 . 2004-08-04 03:31 154624 ----a-w- c:\windows\system32\dllcac he\wlluc48 .sys
2009-12-21 19:22 . 2001-08-17 17:12 34890 ----a-w- c:\windows\system32\dllcac he\wlandrv 2.sys
2009-12-21 19:22 . 2001-08-17 18:28 771581 ----a-w- c:\windows\system32\dllcac he\winacis a.sys
2009-12-21 19:22 . 2001-08-18 03:36 53760 ----a-w- c:\windows\system32\dllcac he\wiamsmu d.dll
2009-12-21 19:20 . 2001-08-17 18:49 24576 ----a-w- c:\windows\system32\dllcac he\viairda .sys
2009-12-21 19:19 . 2001-08-18 03:36 26624 ----a-w- c:\windows\system32\dllcac he\umaxu22 .dll
2009-12-21 19:18 . 2001-08-17 17:12 34375 ----a-w- c:\windows\system32\dllcac he\tpro4.s ys
2009-12-21 19:17 . 2001-08-17 17:50 36640 ----a-w- c:\windows\system32\dllcac he\t2r4min i.sys
2009-12-21 19:16 . 2004-08-04 10:00 101376 ----a-w- c:\windows\system32\dllcac he\srusbus d.dll
2009-12-21 19:15 . 2001-08-17 17:10 35913 ----a-w- c:\windows\system32\dllcac he\smcirda .sys
2009-12-21 19:14 . 2001-08-17 17:50 68608 ----a-w- c:\windows\system32\dllcac he\sis6306 p.sys
2009-12-21 19:13 . 2001-08-17 18:51 23936 ----a-w- c:\windows\system32\dllcac he\sccmusb m.sys
2009-12-21 19:12 . 2004-08-04 10:00 753236 ----a-w- c:\windows\system32\dllcac he\rvseres .dll
2009-12-21 19:11 . 2008-04-13 19:40 6016 ----a-w- c:\windows\system32\dllcac he\qic157. sys
2009-12-21 19:10 . 2001-08-18 03:36 16384 ----a-w- c:\windows\system32\dllcac he\philcam 1.dll
2009-12-21 19:09 . 2001-08-17 19:05 28032 ----a-w- c:\windows\system32\dllcac he\ovcd.sy s
2009-12-21 19:08 . 2001-08-17 17:20 126080 ----a-w- c:\windows\system32\dllcac he\nm5a2wd m.sys
2009-12-21 19:07 . 2001-08-18 03:36 19968 ----a-w- c:\windows\system32\dllcac he\mxicfg. dll
2009-12-21 19:07 . 2001-08-17 18:50 21888 ----a-w- c:\windows\system32\dllcac he\mxcard. sys
2009-12-21 19:07 . 2004-08-04 10:00 229439 ----a-w- c:\windows\system32\dllcac he\multibo x.dll
2009-12-21 19:07 . 2001-08-17 17:50 103296 ----a-w- c:\windows\system32\dllcac he\mtxvide o.sys
2009-12-21 19:07 . 2008-04-13 19:39 5504 ----a-w- c:\windows\system32\dllcac he\mstee.s ys
2009-12-21 19:07 . 2008-04-13 19:46 49024 ----a-w- c:\windows\system32\dllcac he\mstape. sys
2009-12-21 19:07 . 2001-08-17 18:48 12416 ----a-w- c:\windows\system32\dllcac he\msriffw v.sys
2009-12-21 19:07 . 2001-08-17 19:00 2944 ----a-w- c:\windows\system32\dllcac he\msmpu40 1.sys
2009-12-21 19:07 . 2008-04-13 19:54 22016 ----a-w- c:\windows\system32\dllcac he\msircom m.sys
2009-12-21 19:07 . 2004-08-04 10:00 98304 ----a-w- c:\windows\system32\dllcac he\msir3jp .dll
2009-12-21 19:07 . 2001-08-17 19:02 35200 ----a-w- c:\windows\system32\dllcac he\msgame. sys
2009-12-21 19:07 . 2001-08-17 18:48 6016 ----a-w- c:\windows\system32\dllcac he\msfsio. sys
2009-12-21 19:07 . 2008-04-13 19:46 51200 ----a-w- c:\windows\system32\dllcac he\msdv.sy s
2009-12-21 19:05 . 2001-08-17 18:28 727786 ----a-w- c:\windows\system32\dllcac he\ltck000 c.sys
2009-12-21 19:04 . 2001-08-17 19:55 5632 ----a-w- c:\windows\system32\dllcac he\kbd103. dll
2009-12-21 19:03 . 2001-08-17 19:06 100992 ----a-w- c:\windows\system32\dllcac he\icam5us b.sys
2009-12-21 19:02 . 2001-08-17 18:28 57471 ----a-w- c:\windows\system32\dllcac he\hsf_sam p.sys
2009-12-21 19:01 . 2001-08-18 03:36 119296 ----a-w- c:\windows\system32\dllcac he\hpdigwi a.dll
2009-12-21 19:00 . 2001-08-18 03:36 71680 ----a-w- c:\windows\system32\dllcac he\fnfilte r.dll
2009-12-21 18:59 . 2001-08-17 17:17 629952 ----a-w- c:\windows\system32\dllcac he\eqn.sys
2009-12-21 18:58 . 2001-08-17 17:11 29696 ----a-w- c:\windows\system32\dllcac he\dm9pci5 .sys
2009-12-21 18:57 . 2001-08-17 17:12 117760 ----a-w- c:\windows\system32\dllcac he\d100ib5 .sys
2009-12-21 18:56 . 2001-08-17 17:13 49182 ----a-w- c:\windows\system32\dllcac he\cem56n5 .sys
2009-12-21 18:55 . 2001-08-18 03:36 12800 ----a-w- c:\windows\system32\dllcac he\brevif. dll
2009-12-21 18:54 . 2001-08-17 17:19 747392 ----a-w- c:\windows\system32\dllcac he\adm8830 .sys
2009-12-21 18:53 . 2004-08-04 10:00 7680 ----a-w- c:\windows\system32\dllcac he\inetmgr .exe
2009-12-21 18:53 . 2004-08-04 10:00 19968 ----a-w- c:\windows\system32\dllcac he\inetslo c.dll
2009-12-21 18:53 . 2004-08-04 10:00 169984 ----a-w- c:\windows\system32\dllcac he\iisui.d ll
2009-12-21 18:53 . 2004-08-04 10:00 5632 ----a-w- c:\windows\system32\dllcac he\iisrsta p.dll
2009-12-21 18:53 . 2004-08-04 10:00 14336 ----a-w- c:\windows\system32\dllcac he\iisrese t.exe
2009-12-21 18:53 . 2004-08-04 10:00 6144 ----a-w- c:\windows\system32\dllcac he\ftpsapi 2.dll
2009-12-21 18:02 . 2009-12-22 13:13 -------- d-----w- c:\documents and settings\Administrator\App lication Data\U3
2009-12-21 17:15 . 2009-12-21 17:15 88000 ----a-w- c:\documents and settings\Administrator\Loc al Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-21 16:07 . 2009-12-21 16:07 -------- d-----w- C:\_OTM
2009-12-21 16:01 . 2009-12-21 16:01 -------- d-----w- c:\documents and settings\Administrator\Loc al Settings\Application Data\Identities
2009-12-21 16:01 . 2009-12-21 16:01 -------- d-----w- c:\documents and settings\Administrator\App lication Data\Windows Desktop Search
2009-12-21 16:01 . 2009-12-21 16:01 -------- d-----w- c:\documents and settings\Administrator\Loc al Settings\Application Data\LogMeIn
2009-12-21 15:51 . 2009-12-21 15:51 -------- d-sh--w- c:\documents and settings\Administrator\Pri vacIE
2009-12-21 15:49 . 2009-12-21 15:49 -------- d-----w- c:\documents and settings\Administrator\App lication Data\Windows Search
2009-12-21 15:08 . 2009-12-21 15:51 -------- d-----w- c:\documents and settings\Administrator
2009-12-09 08:01 . 2009-12-11 12:54 -------- d-----w- c:\windows\ie8updates
2009-12-08 23:16 . 2009-10-29 07:45 594432 ------w- c:\windows\system32\dllcac he\msfeeds .dll
2009-12-08 23:16 . 2009-10-29 07:45 12800 ------w- c:\windows\system32\dllcac he\xpshims .dll
2009-12-08 23:16 . 2009-10-29 07:45 55296 ------w- c:\windows\system32\dllcac he\msfeeds bs.dll
2009-12-08 23:16 . 2009-10-29 07:45 1985536 ------w- c:\windows\system32\dllcac he\iertuti l.dll
2009-12-08 23:16 . 2009-10-29 07:45 246272 ------w- c:\windows\system32\dllcac he\ieproxy .dll
2009-12-08 23:16 . 2009-10-29 07:45 11069952 ------w- c:\windows\system32\dllcac he\ieframe .dll
2009-12-08 19:23 . 2009-12-09 17:11 -------- d-----w- c:\documents and settings\LocalService\Loca l Settings\Application Data\Adobe
2009-12-08 19:19 . 2009-12-08 19:19 -------- d-----w- c:\documents and settings\dtrick\Local Settings\Application Data\Identities
2009-12-08 19:19 . 2009-12-08 19:19 -------- d-----w- c:\documents and settings\dtrick\Applicatio n Data\Windows Desktop Search
2009-12-08 19:19 . 2009-12-11 12:53 -------- d-----w- c:\program files\Windows Desktop Search
2009-12-08 19:19 . 2009-12-08 19:19 -------- d-----w- c:\windows\system32\GroupP olicy
2009-12-08 19:00 . 2009-12-22 13:03 -------- dc----w- c:\windows\system32\DRVSTO RE
2009-12-08 18:56 . 2009-12-08 18:56 -------- d-sh--w- c:\documents and settings\LocalService\IETl dCache
2009-12-08 18:55 . 2009-12-08 18:55 -------- d-----w- c:\documents and settings\dtrick\Local Settings\Application Data\LogMeIn
2009-12-08 18:55 . 2009-12-08 18:55 -------- d-----w- c:\documents and settings\All Users\Application Data\LogMeIn
2009-12-08 18:55 . 2009-12-08 18:55 -------- d-----w- c:\documents and settings\LocalService\Loca l Settings\Application Data\ICS
2009-12-08 18:55 . 2009-09-29 00:34 47416 ----a-w- c:\windows\system32\Spool\ prtprocs\w 32x86\LMIp roc.dll
2009-12-08 18:55 . 2009-09-29 00:34 83288 ----a-w- c:\windows\system32\LMIRfs ClientNP.d ll
2009-12-08 18:55 . 2009-09-29 00:34 28984 ----a-w- c:\windows\system32\LMIpor t.dll
2009-12-08 18:55 . 2008-08-11 17:41 47640 ----a-w- c:\windows\system32\driver s\LMIRfsDr iver.sys
2009-12-08 18:55 . 2009-09-29 00:34 87352 ----a-w- c:\windows\system32\LMIini t.dll
2009-12-08 18:54 . 2009-12-22 13:05 -------- d-----w- c:\program files\LogMeIn
2009-12-08 18:52 . 2009-12-22 13:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-12-08 17:52 . 2009-12-08 17:52 -------- d-----w- C:\a58cacb4d45445f6ef82d1b 1a360
2009-12-08 17:51 . 2009-12-08 17:52 -------- d-----w- C:\ae465e7bd8dcd50a7abf704 b000cd7
2009-12-08 17:34 . 2009-12-17 13:39 -------- d-----w- c:\program files\Microsoft Works
2009-12-08 17:33 . 2009-12-08 17:33 -------- d-----w- c:\program files\MSBuild
2009-12-08 17:31 . 2009-12-08 17:31 -------- d-----w- c:\program files\Microsoft.NET
2009-12-08 17:11 . 2009-12-08 17:11 -------- d-----w- c:\documents and settings\dtrick\Local Settings\Application Data\Microsoft Help
2009-12-08 17:10 . 2009-12-22 13:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-08 16:58 . 2009-12-08 16:58 -------- d-----r- C:\MSOCache
2009-12-08 16:48 . 2009-12-08 16:48 -------- d-sh--w- c:\documents and settings\dtrick\IECompatCa che
2009-12-08 16:47 . 2009-12-08 16:48 -------- d-sh--w- c:\documents and settings\dtrick\PrivacIE
2009-12-08 16:29 . 2009-12-08 16:29 -------- d-sh--w- c:\documents and settings\dtrick\IETldCache
2009-12-08 16:25 . 2009-12-08 16:33 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-08 16:25 . 2009-12-08 16:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-08 16:23 . 2009-12-08 16:24 -------- dc-h--w- c:\windows\ie8
2009-12-08 16:21 . 2009-12-08 16:26 -------- d-----w- C:\d38c2c431ddb372f9209dd5 1
.
(((((((((((((((((((((((((( (((((((((( (((( Find3M Report )))))))))))))))))))))))))) )))))))))) )))))))))) ))))))
.
2009-12-17 13:48 . 2008-11-17 15:15 88000 ----a-w- c:\documents and settings\dtrick\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-10 09:00 . 2009-12-22 13:17 2747440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D -4F28-AAA2 -85EF59112 6E7}\Norto n\Definiti ons\VirusD efs\200912 21.050\CCE RASER.DLL
2009-12-08 14:55 . 2005-08-15 20:42 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-12-07 14:10 . 2009-12-22 13:02 2953352 -c--a-w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8 C9B-55C9A3 9A7CA9}\Ad -AwareInst allation.e xe
2009-11-04 15:07 . 2009-10-05 14:02 -------- d-----w- c:\documents and settings\dtrick\Applicatio n Data\HpUpdate
2009-10-29 07:45 . 2004-08-11 22:00 916480 ----a-w- c:\windows\system32\winine t.dll
2009-10-21 05:38 . 2004-08-11 22:00 75776 ----a-w- c:\windows\system32\strmfi lt.dll
2009-10-21 05:38 . 2004-08-11 22:00 25088 ----a-w- c:\windows\system32\httpap i.dll
2009-10-20 16:20 . 2004-08-04 04:00 265728 ----a-w- c:\windows\system32\driver s\http.sys
2009-10-13 10:30 . 2004-08-11 22:00 270336 ----a-w- c:\windows\system32\oakley .dll
2009-10-12 13:38 . 2004-08-11 22:00 149504 ----a-w- c:\windows\system32\rastls .dll
2009-10-12 13:38 . 2004-08-11 22:00 79872 ----a-w- c:\windows\system32\rascha p.dll
2009-09-27 08:00 . 2009-12-22 13:17 259440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D -4F28-AAA2 -85EF59112 6E7}\Norto n\Definiti ons\VirusD efs\200912 21.050\ECM SVR32.DLL
.
(((((((((((((((((((((((((( (((((((((( ( Reg Loading Points )))))))))))))))))))))))))) )))))))))) )))))))))) ))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWA RE\Microso ft\Windows \CurrentVe rsion\Run]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\D VDLauncher .exe" [2004-04-26 53248]
"Synchronization Manager"="c:\windows\syste m32\mobsyn c.exe" [2008-04-14 143360]
"igfxtray"="c:\windows\sys tem32\igfx tray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\sy stem32\hkc md.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\sys tem32\igfx pers.exe" [2005-09-20 114688]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe " [2006-08-22 282624]
"D-Link RangeBooster G WDA-2320"="c:\program files\D-Link\RangeBooster G WDA-2320\AirPlusCFG.exe" [2005-12-15 2490368]
"ANIWZCS2Service"="c:\prog ram files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2005-11-30 49152]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2002-09-11 368706]
"Motive SmartBridge"="c:\progra~1\ SBCSEL~1\S MARTB~1\Mo tiveSB.exe " [2005-08-24 442455]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2 .0\OpwareS E2.exe" [2003-05-08 49152]
"SunJavaUpdateSched"="c:\p rogram files\Java\jre6\bin\jusche d.exe" [2009-07-25 149280]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInS ystray.exe " [2008-08-11 63048]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\softwa re\microso ft\windows \currentve rsion\expl orer\Shell ExecuteHoo ks]
"{56F9679E-7826-4C84-81F3- 532071A8BC C5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dl l" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows nt\currentversion\winlogon \notify\LM Iinit]
2009-09-29 00:34 87352 ----a-w- c:\windows\system32\LMIini t.dll
[HKEY_LOCAL_MACHINE\SYSTEM \CurrentCo ntrolSet\C ontrol\Saf eBoot\Mini mal\Lavaso ft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM \CurrentCo ntrolSet\C ontrol\Saf eBoot\Mini mal\SymEFA .sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ Adobe Photo Downloader]
2007-03-09 15:09 63712 ----a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy. exe
[HKLM\~\services\sharedacc ess\parame ters\firew allpolicy\ standardpr ofile\Auth orizedAppl ications\L ist]
"%windir%\\system32\\sessm gr.exe"=
"c:\\Program Files\\Cisco Systems\\VPN Client\\cvpnd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe" =
"c:\\Program Files\\Lavasoft\\Ad-Aware\ \Ad-Aware. exe"=
R0 Lbd;Lbd;c:\windows\system3 2\drivers\ Lbd.sys [12/22/2009 8:03 AM 64288]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\syst em32\drive rs\NAV\100 7020.00B\S ymEFA.sys [9/9/2009 6:29 AM 310320]
R1 ccHP;Symantec Hash Provider;c:\windows\system 32\drivers \NAV\10070 20.00B\cch px86.sys [9/9/2009 6:27 AM 482432]
R1 IDSxpx86;IDSxpx86;c:\docum ents and settings\All Users\Application Data\Norton\{0C55C096-0F1D -4F28-AAA2 -85EF59112 6E7}\Norto n\Definiti ons\IPSDef s\20091217 .002\IDSXp x86.sys [12/21/2009 3:01 PM 329592]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AA WService.e xe [12/2/2009 8:19 AM 1184912]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.s ys [8/11/2008 12:41 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32 \drivers\L MIRfsDrive r.sys [12/8/2009 1:55 PM 47640]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.7.2.11 \ccSvcHst. exe [9/9/2009 6:28 AM 117640]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\s ystem32\dr ivers\A3AB .sys [8/25/2005 2:00 PM 466880]
R3 EraserUtilRebootDrv;Eraser UtilReboot Drv;c:\pro gram files\Common Files\Symantec Shared\EENGINE\EraserUtilR ebootDrv.s ys [12/18/2009 12:39 PM 102448]
S4 LMIRfsClientNP;LMIRfsClien tNP; [x]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.dell.com
mSearch Bar = hxxp://us.rd.yahoo.com/cus tomize/ie/ defaults/s b/msgr8/*http://www.yahoo.com/ext/search/search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFIC E11\EXCEL. EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\cla sses\xmlds o.cab
.
- - - - ORPHANS REMOVED - - - -
Notify-NavLogon - (no file)
************************** ********** ********** ********** ********** ********
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-22 08:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************** ********** ********** ********** ********** ********
[HKEY_LOCAL_MACHINE\System \ControlSe t001\Servi ces\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.7.2.11 \ccSvcHst. exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.7.2.11 \diMaster. dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-19139 89440-3093 678438-277 4681625-50 0\Software \Microsoft \Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A80 5A34F98AFF 34F5977"=h ex:01,00,0 0,00,d0,8c ,9d,df,01, 15,
d1,11,8c,7a,00,c0,4f,c2,97 ,eb,01,00, 00,00,95,0 3,39,5a,96 ,df,e4,4d, 8d,fe,98,\
"2D53CFFC5C1A3DD2E97B7979A C2A92BD59B C839E81"=h ex:01,00,0 0,00,d0,8c ,9d,df,01, 15,
d1,11,8c,7a,00,c0,4f,c2,97 ,eb,01,00, 00,00,95,0 3,39,5a,96 ,df,e4,4d, 8d,fe,98,\
[HKEY_LOCAL_MACHINE\softwa re\Determi nisticNetw orks\DNE\P arameters]
"SymbolicLinkValue"=hex(6) :5c,00,52, 00,65,00,6 7,00,69,00 ,73,00,74, 00,72,00,7 9,
00,5c,00,4d,00,61,00,63,00 ,68,00,69, 00,6e,00,6 5,00,5c,00 ,53,00,79, 00,73,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1544)
c:\windows\system32\CSGina .dll
c:\windows\system32\LMIini t.dll
- - - - - - - > 'explorer.exe'(3092)
c:\windows\system32\WININE T.dll
c:\progra~1\SBCSEL~1\SMART B~1\SBHook .dll
c:\program files\ScanSoft\OmniPageSE2 .0\ophookS E2.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dl l.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\iefram e.dll
c:\windows\system32\webche ck.dll
c:\windows\system32\WPDShS erviceObj. dll
c:\windows\system32\Portab leDeviceTy pes.dll
c:\windows\system32\Portab leDeviceAp i.dll
c:\windows\WinSxS\x86_Micr osoft.VC80 .CRT_1fc8b 3b9a1e18e3 b_8.0.5072 7.762_x-ww _6b128700\ MSVCR80.dl l
c:\program files\Lavasoft\Ad-Aware\Sh ellExt.dll
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dl l
c:\program files\Common Files\Adobe\Acrobat\Active X\AcroIEHe lper.dll
c:\progra~1\SPYBOT~1\SDHel per.dll
c:\program files\Common Files\Adobe\Acrobat\Active X\PDFShell .dll
c:\windows\system32\LMIRfs ClientNP.d ll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Java\jre6\bin\jqs.ex e
c:\program files\LogMeIn\x86\RaMaint. exe
c:\program files\LogMeIn\x86\LogMeIn. exe
c:\program files\LogMeIn\x86\LMIGuard ian.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\ Binn\sqlse rvr.exe
c:\windows\system32\Search Indexer.ex e
c:\windows\system32\wbem\u nsecapp.ex e
c:\program files\LogMeIn\x86\LMIGuard ian.exe
c:\program files\Lavasoft\Ad-Aware\AA WTray.exe
.
************************** ********** ********** ********** ********** ********
.
Completion time: 2009-12-22 08:34:41 - machine was rebooted
ComboFix-quarantined-files .txt 2009-12-22 13:34
Pre-Run: 16,570,699,776 bytes free
Post-Run: 16,544,915,456 bytes free
WindowsXP-KB310994-SP2-Pro -BootDisk- ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdi sk(0)parti tion(2)\WI NDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="M icrosoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)par tition(2)\ WINDOWS="M icrosoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 3061EC5342547EAD9F4531F426 B42251
Here is the log:
ComboFix 09-12-21.04 - Administrator 12/22/2009 8:18.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.
Running from: c:\documents and settings\Administrator\Des
.
((((((((((((((((((((((((((
.
c:\progra~1\COMMON~1\BLACK
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\EventSystem.log
c:\windows\system32\regsvr
.
((((((((((((((((((((((((((
.
-------\Legacy_BHDRVX86
-------\Service_BHDrvx86
((((((((((((((((((((((((( Files Created from 2009-11-22 to 2009-12-22 ))))))))))))))))))))))))))
.
2009-12-22 13:03 . 2009-12-02 13:19 64288 ----a-w- c:\windows\system32\driver
2009-12-22 13:02 . 2009-12-22 13:02 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8
2009-12-22 13:01 . 2009-12-22 13:01 -------- d-----w- c:\program files\Lavasoft
2009-12-21 19:23 . 2004-08-04 10:00 4677 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:23 . 2004-08-04 10:00 29760 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:23 . 2004-08-04 10:00 13894 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:23 . 2004-08-04 10:00 113222 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:23 . 2004-08-04 10:00 41029 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:23 . 2004-08-04 10:00 36937 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:23 . 2008-04-14 01:12 116224 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:23 . 2001-08-18 03:36 23040 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:23 . 2008-04-14 01:12 18944 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:23 . 2001-08-18 03:37 27648 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:23 . 2001-08-18 03:37 4608 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:22 . 2001-08-18 03:37 99865 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:22 . 2001-08-17 17:11 16970 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:22 . 2004-08-04 03:29 19455 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:22 . 2008-04-13 19:46 19200 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:22 . 2004-08-04 03:29 12063 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:22 . 2008-04-14 01:12 8192 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:22 . 2008-04-13 19:36 8832 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:22 . 2004-08-04 03:31 154624 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:22 . 2001-08-17 17:12 34890 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:22 . 2001-08-17 18:28 771581 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:22 . 2001-08-18 03:36 53760 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:20 . 2001-08-17 18:49 24576 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:19 . 2001-08-18 03:36 26624 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:18 . 2001-08-17 17:12 34375 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:17 . 2001-08-17 17:50 36640 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:16 . 2004-08-04 10:00 101376 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:15 . 2001-08-17 17:10 35913 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:14 . 2001-08-17 17:50 68608 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:13 . 2001-08-17 18:51 23936 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:12 . 2004-08-04 10:00 753236 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:11 . 2008-04-13 19:40 6016 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:10 . 2001-08-18 03:36 16384 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:09 . 2001-08-17 19:05 28032 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:08 . 2001-08-17 17:20 126080 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:07 . 2001-08-18 03:36 19968 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:07 . 2001-08-17 18:50 21888 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:07 . 2004-08-04 10:00 229439 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:07 . 2001-08-17 17:50 103296 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:07 . 2008-04-13 19:39 5504 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:07 . 2008-04-13 19:46 49024 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:07 . 2001-08-17 18:48 12416 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:07 . 2001-08-17 19:00 2944 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:07 . 2008-04-13 19:54 22016 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:07 . 2004-08-04 10:00 98304 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:07 . 2001-08-17 19:02 35200 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:07 . 2001-08-17 18:48 6016 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:07 . 2008-04-13 19:46 51200 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:05 . 2001-08-17 18:28 727786 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:04 . 2001-08-17 19:55 5632 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:03 . 2001-08-17 19:06 100992 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:02 . 2001-08-17 18:28 57471 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:01 . 2001-08-18 03:36 119296 ----a-w- c:\windows\system32\dllcac
2009-12-21 19:00 . 2001-08-18 03:36 71680 ----a-w- c:\windows\system32\dllcac
2009-12-21 18:59 . 2001-08-17 17:17 629952 ----a-w- c:\windows\system32\dllcac
2009-12-21 18:58 . 2001-08-17 17:11 29696 ----a-w- c:\windows\system32\dllcac
2009-12-21 18:57 . 2001-08-17 17:12 117760 ----a-w- c:\windows\system32\dllcac
2009-12-21 18:56 . 2001-08-17 17:13 49182 ----a-w- c:\windows\system32\dllcac
2009-12-21 18:55 . 2001-08-18 03:36 12800 ----a-w- c:\windows\system32\dllcac
2009-12-21 18:54 . 2001-08-17 17:19 747392 ----a-w- c:\windows\system32\dllcac
2009-12-21 18:53 . 2004-08-04 10:00 7680 ----a-w- c:\windows\system32\dllcac
2009-12-21 18:53 . 2004-08-04 10:00 19968 ----a-w- c:\windows\system32\dllcac
2009-12-21 18:53 . 2004-08-04 10:00 169984 ----a-w- c:\windows\system32\dllcac
2009-12-21 18:53 . 2004-08-04 10:00 5632 ----a-w- c:\windows\system32\dllcac
2009-12-21 18:53 . 2004-08-04 10:00 14336 ----a-w- c:\windows\system32\dllcac
2009-12-21 18:53 . 2004-08-04 10:00 6144 ----a-w- c:\windows\system32\dllcac
2009-12-21 18:02 . 2009-12-22 13:13 -------- d-----w- c:\documents and settings\Administrator\App
2009-12-21 17:15 . 2009-12-21 17:15 88000 ----a-w- c:\documents and settings\Administrator\Loc
2009-12-21 16:07 . 2009-12-21 16:07 -------- d-----w- C:\_OTM
2009-12-21 16:01 . 2009-12-21 16:01 -------- d-----w- c:\documents and settings\Administrator\Loc
2009-12-21 16:01 . 2009-12-21 16:01 -------- d-----w- c:\documents and settings\Administrator\App
2009-12-21 16:01 . 2009-12-21 16:01 -------- d-----w- c:\documents and settings\Administrator\Loc
2009-12-21 15:51 . 2009-12-21 15:51 -------- d-sh--w- c:\documents and settings\Administrator\Pri
2009-12-21 15:49 . 2009-12-21 15:49 -------- d-----w- c:\documents and settings\Administrator\App
2009-12-21 15:08 . 2009-12-21 15:51 -------- d-----w- c:\documents and settings\Administrator
2009-12-09 08:01 . 2009-12-11 12:54 -------- d-----w- c:\windows\ie8updates
2009-12-08 23:16 . 2009-10-29 07:45 594432 ------w- c:\windows\system32\dllcac
2009-12-08 23:16 . 2009-10-29 07:45 12800 ------w- c:\windows\system32\dllcac
2009-12-08 23:16 . 2009-10-29 07:45 55296 ------w- c:\windows\system32\dllcac
2009-12-08 23:16 . 2009-10-29 07:45 1985536 ------w- c:\windows\system32\dllcac
2009-12-08 23:16 . 2009-10-29 07:45 246272 ------w- c:\windows\system32\dllcac
2009-12-08 23:16 . 2009-10-29 07:45 11069952 ------w- c:\windows\system32\dllcac
2009-12-08 19:23 . 2009-12-09 17:11 -------- d-----w- c:\documents and settings\LocalService\Loca
2009-12-08 19:19 . 2009-12-08 19:19 -------- d-----w- c:\documents and settings\dtrick\Local Settings\Application Data\Identities
2009-12-08 19:19 . 2009-12-08 19:19 -------- d-----w- c:\documents and settings\dtrick\Applicatio
2009-12-08 19:19 . 2009-12-11 12:53 -------- d-----w- c:\program files\Windows Desktop Search
2009-12-08 19:19 . 2009-12-08 19:19 -------- d-----w- c:\windows\system32\GroupP
2009-12-08 19:00 . 2009-12-22 13:03 -------- dc----w- c:\windows\system32\DRVSTO
2009-12-08 18:56 . 2009-12-08 18:56 -------- d-sh--w- c:\documents and settings\LocalService\IETl
2009-12-08 18:55 . 2009-12-08 18:55 -------- d-----w- c:\documents and settings\dtrick\Local Settings\Application Data\LogMeIn
2009-12-08 18:55 . 2009-12-08 18:55 -------- d-----w- c:\documents and settings\All Users\Application Data\LogMeIn
2009-12-08 18:55 . 2009-12-08 18:55 -------- d-----w- c:\documents and settings\LocalService\Loca
2009-12-08 18:55 . 2009-09-29 00:34 47416 ----a-w- c:\windows\system32\Spool\
2009-12-08 18:55 . 2009-09-29 00:34 83288 ----a-w- c:\windows\system32\LMIRfs
2009-12-08 18:55 . 2009-09-29 00:34 28984 ----a-w- c:\windows\system32\LMIpor
2009-12-08 18:55 . 2008-08-11 17:41 47640 ----a-w- c:\windows\system32\driver
2009-12-08 18:55 . 2009-09-29 00:34 87352 ----a-w- c:\windows\system32\LMIini
2009-12-08 18:54 . 2009-12-22 13:05 -------- d-----w- c:\program files\LogMeIn
2009-12-08 18:52 . 2009-12-22 13:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-12-08 17:52 . 2009-12-08 17:52 -------- d-----w- C:\a58cacb4d45445f6ef82d1b
2009-12-08 17:51 . 2009-12-08 17:52 -------- d-----w- C:\ae465e7bd8dcd50a7abf704
2009-12-08 17:34 . 2009-12-17 13:39 -------- d-----w- c:\program files\Microsoft Works
2009-12-08 17:33 . 2009-12-08 17:33 -------- d-----w- c:\program files\MSBuild
2009-12-08 17:31 . 2009-12-08 17:31 -------- d-----w- c:\program files\Microsoft.NET
2009-12-08 17:11 . 2009-12-08 17:11 -------- d-----w- c:\documents and settings\dtrick\Local Settings\Application Data\Microsoft Help
2009-12-08 17:10 . 2009-12-22 13:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-08 16:58 . 2009-12-08 16:58 -------- d-----r- C:\MSOCache
2009-12-08 16:48 . 2009-12-08 16:48 -------- d-sh--w- c:\documents and settings\dtrick\IECompatCa
2009-12-08 16:47 . 2009-12-08 16:48 -------- d-sh--w- c:\documents and settings\dtrick\PrivacIE
2009-12-08 16:29 . 2009-12-08 16:29 -------- d-sh--w- c:\documents and settings\dtrick\IETldCache
2009-12-08 16:25 . 2009-12-08 16:33 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-08 16:25 . 2009-12-08 16:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-08 16:23 . 2009-12-08 16:24 -------- dc-h--w- c:\windows\ie8
2009-12-08 16:21 . 2009-12-08 16:26 -------- d-----w- C:\d38c2c431ddb372f9209dd5
.
((((((((((((((((((((((((((
.
2009-12-17 13:48 . 2008-11-17 15:15 88000 ----a-w- c:\documents and settings\dtrick\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-10 09:00 . 2009-12-22 13:17 2747440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D
2009-12-08 14:55 . 2005-08-15 20:42 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-12-07 14:10 . 2009-12-22 13:02 2953352 -c--a-w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8
2009-11-04 15:07 . 2009-10-05 14:02 -------- d-----w- c:\documents and settings\dtrick\Applicatio
2009-10-29 07:45 . 2004-08-11 22:00 916480 ----a-w- c:\windows\system32\winine
2009-10-21 05:38 . 2004-08-11 22:00 75776 ----a-w- c:\windows\system32\strmfi
2009-10-21 05:38 . 2004-08-11 22:00 25088 ----a-w- c:\windows\system32\httpap
2009-10-20 16:20 . 2004-08-04 04:00 265728 ----a-w- c:\windows\system32\driver
2009-10-13 10:30 . 2004-08-11 22:00 270336 ----a-w- c:\windows\system32\oakley
2009-10-12 13:38 . 2004-08-11 22:00 149504 ----a-w- c:\windows\system32\rastls
2009-10-12 13:38 . 2004-08-11 22:00 79872 ----a-w- c:\windows\system32\rascha
2009-09-27 08:00 . 2009-12-22 13:17 259440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D
.
((((((((((((((((((((((((((
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWA
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\D
"Synchronization Manager"="c:\windows\syste
"igfxtray"="c:\windows\sys
"igfxhkcmd"="c:\windows\sy
"igfxpers"="c:\windows\sys
"QuickTime Task"="c:\program files\QuickTime\qttask.exe
"D-Link RangeBooster G WDA-2320"="c:\program files\D-Link\RangeBooster G WDA-2320\AirPlusCFG.exe" [2005-12-15 2490368]
"ANIWZCS2Service"="c:\prog
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2002-09-11 368706]
"Motive SmartBridge"="c:\progra~1\
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2
"SunJavaUpdateSched"="c:\p
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInS
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\softwa
"{56F9679E-7826-4C84-81F3-
[HKEY_LOCAL_MACHINE\softwa
2009-09-29 00:34 87352 ----a-w- c:\windows\system32\LMIini
[HKEY_LOCAL_MACHINE\SYSTEM
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\softwa
2007-03-09 15:09 63712 ----a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.
[HKLM\~\services\sharedacc
"%windir%\\system32\\sessm
"c:\\Program Files\\Cisco Systems\\VPN Client\\cvpnd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"
"c:\\Program Files\\Lavasoft\\Ad-Aware\
R0 Lbd;Lbd;c:\windows\system3
R0 SymEFA;Symantec Extended File Attributes;c:\windows\syst
R1 ccHP;Symantec Hash Provider;c:\windows\system
R1 IDSxpx86;IDSxpx86;c:\docum
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AA
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.s
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.7.2.11
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\s
R3 EraserUtilRebootDrv;Eraser
S4 LMIRfsClientNP;LMIRfsClien
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.dell.com
mSearch Bar = hxxp://us.rd.yahoo.com/cus
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFIC
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\cla
.
- - - - ORPHANS REMOVED - - - -
Notify-NavLogon - (no file)
**************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-22 08:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.7.2.11
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-19139
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A80
d1,11,8c,7a,00,c0,4f,c2,97
"2D53CFFC5C1A3DD2E97B7979A
d1,11,8c,7a,00,c0,4f,c2,97
[HKEY_LOCAL_MACHINE\softwa
"SymbolicLinkValue"=hex(6)
00,5c,00,4d,00,61,00,63,00
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1544)
c:\windows\system32\CSGina
c:\windows\system32\LMIini
- - - - - - - > 'explorer.exe'(3092)
c:\windows\system32\WININE
c:\progra~1\SBCSEL~1\SMART
c:\program files\ScanSoft\OmniPageSE2
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dl
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\iefram
c:\windows\system32\webche
c:\windows\system32\WPDShS
c:\windows\system32\Portab
c:\windows\system32\Portab
c:\windows\WinSxS\x86_Micr
c:\program files\Lavasoft\Ad-Aware\Sh
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dl
c:\program files\Common Files\Adobe\Acrobat\Active
c:\progra~1\SPYBOT~1\SDHel
c:\program files\Common Files\Adobe\Acrobat\Active
c:\windows\system32\LMIRfs
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Java\jre6\bin\jqs.ex
c:\program files\LogMeIn\x86\RaMaint.
c:\program files\LogMeIn\x86\LogMeIn.
c:\program files\LogMeIn\x86\LMIGuard
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\
c:\windows\system32\Search
c:\windows\system32\wbem\u
c:\program files\LogMeIn\x86\LMIGuard
c:\program files\Lavasoft\Ad-Aware\AA
.
**************************
.
Completion time: 2009-12-22 08:34:41 - machine was rebooted
ComboFix-quarantined-files
Pre-Run: 16,570,699,776 bytes free
Post-Run: 16,544,915,456 bytes free
WindowsXP-KB310994-SP2-Pro
[boot loader]
timeout=2
default=multi(0)disk(0)rdi
[operating systems]
c:\cmdcons\BOOTSECT.DAT="M
multi(0)disk(0)rdisk(0)par
- - End Of File - - 3061EC5342547EAD9F4531F426
ASKER
Thanks for all your help!
No Problem at all.
I scanned you log file, and it looks as if your clean again. I would stronlgy suggest that you reinstall your copy of Norton. I have seen numerous cases where this type of infection has caused problems for the installed AV. It also looke as if one of the Norton Directories was blank. This could be an indication of suck problems/
I scanned you log file, and it looks as if your clean again. I would stronlgy suggest that you reinstall your copy of Norton. I have seen numerous cases where this type of infection has caused problems for the installed AV. It also looke as if one of the Norton Directories was blank. This could be an indication of suck problems/
A few things to try:
System Restore to a date when it was working properly.
From command line: chkdsk /f.
From run box with XP cd handy: sfc /scannow
Slave the drive to another machine and do a thorough malware scan of the drive.
Window Repair Install.
Nuke & Pave.