Thank you for the help!
ComboFix 10-01-16.02 - Dexter_De Size 01/17/2010 0:01.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.442 [GMT -5:00]
Running from: c:\documents and settings\De Size\Desktop\ComboFix.exe
AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
AV: Sophos Anti-Virus *On-access scanning disabled* (Outdated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
FW: CA Personal Firewall *disabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\De Size\Application Data\0200000019e4ec51660C.manifest
c:\documents and settings\De Size\Application Data\0200000019e4ec51660O.manifest
c:\documents and settings\De Size\Application Data\0200000019e4ec51660P.manifest
c:\documents and settings\De Size\Application Data\0200000019e4ec51660S.manifest
c:\documents and settings\De Size\Application Data\0200000019e4ec51724C.manifest
c:\documents and settings\De Size\Application Data\0200000019e4ec51724O.manifest
c:\documents and settings\De Size\Application Data\0200000019e4ec51724P.manifest
c:\documents and settings\De Size\Application Data\0200000019e4ec51724S.manifest
c:\documents and settings\De Size\Application Data\Mozilla\Firefox\Profiles\je11r1gi.default\extensions\{b74240e2-9974-44da-b327-24aab6bdd94b}
c:\documents and settings\De Size\Application Data\Mozilla\Firefox\Profiles\je11r1gi.default\extensions\{b74240e2-9974-44da-b327-24aab6bdd94b}\chrome.manifest
c:\documents and settings\De Size\Application Data\Mozilla\Firefox\Profiles\je11r1gi.default\extensions\{b74240e2-9974-44da-b327-24aab6bdd94b}\chrome\xulcache.jar
c:\documents and settings\De Size\Application Data\Mozilla\Firefox\Profiles\je11r1gi.default\extensions\{b74240e2-9974-44da-b327-24aab6bdd94b}\defaults\preferences\xulcache.js
c:\documents and settings\De Size\Application Data\Mozilla\Firefox\Profiles\je11r1gi.default\extensions\{b74240e2-9974-44da-b327-24aab6bdd94b}\install.rdf
c:\documents and settings\De Size\Application Data\SystemProc
c:\documents and settings\De Size\Application Data\SystemProc\lsass.exe
c:\documents and settings\LocalService\Application Data\Mozilla\Firefox\Profiles\qqbs34k1.default\extensions\{b74240e2-9974-44da-b327-24aab6bdd94b}
c:\documents and settings\LocalService\Application Data\Mozilla\Firefox\Profiles\qqbs34k1.default\extensions\{b74240e2-9974-44da-b327-24aab6bdd94b}\chrome.manifest
c:\documents and settings\LocalService\Application Data\Mozilla\Firefox\Profiles\qqbs34k1.default\extensions\{b74240e2-9974-44da-b327-24aab6bdd94b}\chrome\xulcache.jar
c:\documents and settings\LocalService\Application Data\Mozilla\Firefox\Profiles\qqbs34k1.default\extensions\{b74240e2-9974-44da-b327-24aab6bdd94b}\defaults\preferences\xulcache.js
c:\documents and settings\LocalService\Application Data\Mozilla\Firefox\Profiles\qqbs34k1.default\extensions\{b74240e2-9974-44da-b327-24aab6bdd94b}\install.rdf
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf
c:\recycler\NPROTECT
c:\windows\system32\11478.exe
c:\windows\system32\11538.exe
c:\windows\system32\11840.exe
c:\windows\system32\11942.exe
c:\windows\system32\12316.exe
c:\windows\system32\12382.exe
c:\windows\system32\12623.exe
c:\windows\system32\12859.exe
c:\windows\system32\13931.exe
c:\windows\system32\14604.exe
c:\windows\system32\14771.exe
c:\windows\system32\15006.exe
c:\windows\system32\15141.exe
c:\windows\system32\153.exe
c:\windows\system32\15350.exe
c:\windows\system32\15724.exe
c:\windows\system32\15890.exe
c:\windows\system32\16827.exe
c:\windows\system32\17035.exe
c:\windows\system32\17421.exe
c:\windows\system32\17673.exe
c:\windows\system32\1842.exe
c:\windows\system32\18467.exe
c:\windows\system32\1869.exe
c:\windows\system32\18716.exe
c:\windows\system32\18756.exe
c:\windows\system32\19169.exe
c:\windows\system32\19264.exe
c:\windows\system32\19629.exe
c:\windows\system32\19718.exe
c:\windows\system32\19895.exe
c:\windows\system32\19912.exe
c:\windows\system32\19954.exe
c:\windows\system32\20037.exe
c:\windows\system32\21726.exe
c:\windows\system32\22190.exe
c:\windows\system32\22648.exe
c:\windows\system32\23281.exe
c:\windows\system32\23805.exe
c:\windows\system32\23811.exe
c:\windows\system32\24084.exe
c:\windows\system32\24370.exe
c:\windows\system32\24393.exe
c:\windows\system32\24464.exe
c:\windows\system32\25547.exe
c:\windows\system32\25667.exe
c:\windows\system32\26299.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\27446.exe
c:\windows\system32\27529.exe
c:\windows\system32\27644.exe
c:\windows\system32\28145.exe
c:\windows\system32\28253.exe
c:\windows\system32\28703.exe
c:\windows\system32\288.exe
c:\windows\system32\292.exe
c:\windows\system32\29358.exe
c:\windows\system32\2995.exe
c:\windows\system32\30106.exe
c:\windows\system32\30333.exe
c:\windows\system32\3035.exe
c:\windows\system32\31101.exe
c:\windows\system32\31322.exe
c:\windows\system32\32391.exe
c:\windows\system32\32662.exe
c:\windows\system32\32757.exe
c:\windows\system32\3548.exe
c:\windows\system32\3902.exe
c:\windows\system32\41.exe
c:\windows\system32\4664.exe
c:\windows\system32\4827.exe
c:\windows\system32\491.exe
c:\windows\system32\4966.exe
c:\windows\system32\5436.exe
c:\windows\system32\5447.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\6729.exe
c:\windows\system32\6868.exe
c:\windows\system32\7376.exe
c:\windows\system32\7711.exe
c:\windows\system32\778.exe
c:\windows\system32\8723.exe
c:\windows\system32\8942.exe
c:\windows\system32\9040.exe
c:\windows\system32\9741.exe
c:\windows\system32\9894.exe
c:\windows\system32\9961.exe
c:\windows\system32\helper32.dll
c:\windows\system32\IS15.exe
c:\windows\system32\ntSVc.ocx
c:\windows\system32\smss32.exe
c:\windows\system32\warning.html
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\userinit.exe
.
((((((((((((((((((((((((( Files Created from 2009-12-17 to 2010-01-17 )))))))))))))))))))))))))))))))
.
2010-01-14 02:57 . 2010-01-14 02:57 -------- d-----w- c:\program files\Trend Micro
2010-01-13 02:37 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-10 20:32 . 2008-12-10 08:21 130088 ----a-w- c:\windows\system32\sdccoinstaller.dll
2010-01-10 20:28 . 2010-01-10 20:28 -------- d-----w- c:\program files\Common Files\Cisco Systems
2010-01-10 20:13 . 2008-12-09 16:10 23552 ----a-w- c:\windows\system32\SophosBootTasks.exe
2010-01-10 20:13 . 2010-01-10 20:35 -------- d-----w- c:\program files\Sophos
2010-01-10 20:13 . 2010-01-10 20:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Sophos
2010-01-10 20:12 . 2008-05-23 13:38 14976 ----a-w- c:\windows\system32\drivers\SophosBootDriver.sys
2010-01-10 20:12 . 2008-07-18 16:49 104704 ----a-w- c:\windows\system32\drivers\savonaccesscontrol.sys
2010-01-10 20:12 . 2008-07-18 16:49 35584 ----a-w- c:\windows\system32\drivers\savonaccessfilter.sys
2010-01-10 20:12 . 2010-01-10 20:12 -------- d-----w- C:\stdtsa
2010-01-03 00:21 . 2010-01-03 00:21 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-12-30 12:29 . 2009-12-30 12:29 309 ----a-w- C:\confin.sys
2009-12-25 00:12 . 2009-12-25 00:12 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-12-25 00:11 . 2010-01-06 23:16 -------- d-----w- c:\documents and settings\De Size\Local Settings\Application Data\Temp
2009-12-18 12:23 . 2009-12-18 12:23 -------- d-----w- c:\program files\iPod
2009-12-18 12:23 . 2009-12-18 12:24 -------- d-----w- c:\program files\iTunes
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-17 05:27 . 2006-09-01 01:58 -------- d-----w- c:\program files\Blue Coat K9 Web Protection
2010-01-17 05:26 . 2008-11-21 01:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-01-17 05:24 . 2009-01-30 01:22 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k7
2010-01-17 05:24 . 2009-01-30 01:22 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k6
2010-01-17 05:24 . 2009-01-30 01:22 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k5
2010-01-17 05:24 . 2009-01-30 01:22 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k4
2010-01-17 05:24 . 2009-01-30 01:22 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k3
2010-01-17 05:24 . 2009-01-30 01:22 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k2
2010-01-17 05:24 . 2009-01-30 01:22 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k1
2010-01-17 05:24 . 2009-01-30 01:22 204466 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k0
2010-01-16 13:45 . 2009-04-30 18:00 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-13 18:03 . 2008-10-19 12:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-11 02:25 . 2007-12-02 13:10 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-06 23:19 . 2008-06-26 04:29 -------- d-----w- c:\program files\Google
2010-01-03 00:20 . 2009-06-11 23:59 -------- d-----w- c:\program files\QuickTime
2010-01-03 00:19 . 2008-11-16 03:12 -------- d-----w- c:\documents and settings\De Size\Application Data\LimeWire
2009-12-31 14:58 . 2008-11-16 03:12 -------- d-----w- c:\program files\LimeWire
2009-12-18 12:23 . 2008-07-31 19:05 -------- d-----w- c:\program files\Common Files\Apple
2009-12-11 01:57 . 2009-12-11 01:56 -------- d-----w- c:\program files\PC Inspector File Recovery
2009-12-11 01:56 . 2006-04-10 21:39 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-10 12:32 . 2006-04-10 21:14 75776 ----a-w- c:\documents and settings\De Size\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-06 04:56 . 2009-10-13 17:11 739696 ----a-w- c:\windows\system32\drivers\vetefile.sys
2009-12-06 04:56 . 2009-10-13 17:11 133520 ----a-w- c:\windows\system32\drivers\veteboot.sys
2009-12-06 04:56 . 2009-01-26 21:43 32240 ----a-w- c:\windows\system32\drivers\vetmonnt.sys
2009-12-06 04:56 . 2009-01-26 21:43 26352 ----a-w- c:\windows\system32\drivers\vet-filt.sys
2009-12-06 04:56 . 2009-01-26 21:43 21488 ----a-w- c:\windows\system32\drivers\vetfddnt.sys
2009-12-06 04:56 . 2009-01-26 21:43 21104 ----a-w- c:\windows\system32\drivers\vet-rec.sys
2009-11-26 10:49 . 2008-10-19 12:36 -------- d-----w- c:\program files\Microsoft Works
2009-10-29 07:45 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 12:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 12:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 12:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-08-19 15:29 . 2009-08-19 15:29 356352 ----a-w- c:\program files\mozilla firefox\components\qebhbcaenavt.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2005-08-12 126464]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"nwiz"="nwiz.exe" [2006-03-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-02-18 185896]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-08-10 177392]
"QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" [2009-01-26 14088]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2009-12-06 230664]
"cafwc"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2009-01-26 1193200]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2009-01-26 173296]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2009-01-26 259312]
"lxdnmon.exe"="c:\program files\Lexmark 2600 Series\lxdnmon.exe" [2008-03-27 660136]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Local Service"="c:\documents and settings\De Size\Application Data\Microsoft\smss.exe" [2010-01-05 66560]
c:\documents and settings\De Size\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - c:\program files\Sophos\AutoUpdate\ALMon.exe [2007-6-21 245760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
2003-10-31 15:01 8704 ------w- c:\windows\system32\PCANotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-05-18 18:30 79368 ----a-w- c:\windows\system32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^De Size^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\De Size\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^De Size^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\De Size\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 11:58 611712 ----a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
2005-03-17 00:16 970752 ----a-w- c:\program files\Common Files\Adobe\Updater\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BHR]
2006-10-25 02:14 9375744 ----a-w- c:\program files\Zamaan's Software\Browser Hijack Retaliator 4.5\BHR.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
2004-10-27 19:21 61952 ------w- c:\windows\system32\HdAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 21:33 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdnamon]
2008-03-27 15:13 16040 ----a-w- c:\program files\Lexmark 2600 Series\lxdnamon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Codec Update Service]
2007-04-08 16:44 303104 ----a-w- c:\program files\Essentials Codec Pack\update.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2008-11-06 02:59 4347120 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 04:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2005-05-20 14:11 925696 ----a-r- c:\program files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-02-22 08:25 144784 ----a-w- c:\program files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-11-21 01:56 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
2009-05-26 22:31 85160 ----a-w- c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Sony\\Media Manager for WALKMAN\\MediaManager.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\lxdncoms.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnamon.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\frun.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnmon.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdnpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdntime.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdnjswx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdnwbgw.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnlscn.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [6/24/2008 7:08 PM 93712]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [8/24/2009 7:51 PM 64160]
R1 bckd;bckd;c:\windows\system32\drivers\bckd.sys [1/13/2009 6:39 PM 72992]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [6/24/2008 7:08 PM 63504]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [6/24/2008 7:08 PM 45584]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [6/24/2008 7:08 PM 115216]
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [1/10/2010 3:12 PM 104704]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [1/10/2010 3:12 PM 35584]
R2 bckwfs;Blue Coat K9 Web Protection;c:\program files\Blue Coat K9 Web Protection\k9filter.exe [3/28/2006 10:29 AM 1078560]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [6/24/2008 7:08 PM 134648]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [6/24/2008 7:08 PM 66576]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1028432]
R2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service --> c:\windows\system32\lxdncoms.exe -service [?]
R2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdnserv.exe [3/15/2009 4:45 PM 98984]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [12/9/2008 4:46 PM 69632]
R2 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [12/9/2008 4:44 PM 98304]
R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [10/18/2007 10:24 AM 1010192]
R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [10/18/2007 10:24 AM 801296]
R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [6/24/2008 7:10 PM 281104]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [6/24/2008 7:08 PM 88816]
R3 P1120VID;Creative WebCam NX Ultra;c:\windows\system32\drivers\P1120Vid.sys [4/29/2006 2:25 PM 759050]
R3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [8/16/2007 9:10 PM 189704]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/24/2009 7:11 PM 135664]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [1/10/2010 3:12 PM 14976]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 08:32 128512 ----a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
2010-01-12 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 00:50]
2010-01-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-12-22 c:\windows\Tasks\CAAntiSpywareScan_Daily as Dexter_De Size at 4 42 PM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-08-17 02:10]
2010-01-17 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-06-26 07:43]
2010-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-25 00:10]
2010-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-25 00:10]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\VetRedir.dll
FF - ProfilePath - c:\documents and settings\De Size\Application Data\Mozilla\Firefox\Profiles\je11r1gi.default\
FF - prefs.js: browser.startup.homepage -
www.yahoo.comFF - component: c:\program files\Mozilla Firefox\components\qebhbcaenavt.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-Run-ALUAlert - c:\program files\Symantec\LiveUpdate\ALUNotify.exe
HKLM-Explorer_Run-RTHDBPL - c:\documents and settings\De Size\Application Data\SystemProc\lsass.exe
MSConfigStartUp-Lexmark X74-X75 - c:\program files\Lexmark X74-X75\lxbbbmgr.exe
MSConfigStartUp-Yapta Tracker - c:\program files\Yapta\YaptaClient.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-17 00:28
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
RTHDBPL = c:\documents and settings\De Size\Application Data\SystemProc\lsass.exe?


















??
Local Service = c:\documents and settings\De Size\Application Data\Microsoft\smss.exe?#?0?

















??
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-790525478-1326574676-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*d%é*_*]
@Class="Shell"
[HKEY_USERS\S-1-5-21-790525478-1326574676-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*d%é*_*\OpenWithList]
@Class="Shell"
[HKEY_LOCAL_MACHINE\software\Classes\ë*_%d*_*a*u*t*o*_*f*i*l*e*\shell\Edit with Fireworks\Command]
@="\"c:\\Program Files\\Macromedia\\Fireworks MX\\Fireworks.exe\" %1"
[HKEY_LOCAL_MACHINE\software\Classes\ë*_%d*_*a*u*t*o*_*f*i*l*e*\shell\open]
"MuiVerb"="@shimgvw.dll,-550"
[HKEY_LOCAL_MACHINE\software\Classes\ë*_%d*_*a*u*t*o*_*f*i*l*e*\shell\open\Command]
@="\"c:\\Program Files\\Macromedia\\Fireworks MX\\Fireworks.exe\" %1"
[HKEY_LOCAL_MACHINE\software\Classes\ë*_%d*_*a*u*t*o*_*f*i*l*e*\shell\open\DropTarget]
"Clsid"="{E84FDA7C-1D6A-45F6-B725-CB260C236066}"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(820)
c:\windows\system32\UmxWnp.Dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'lsass.exe'(876)
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll
- - - - - - - > 'explorer.exe'(2280)
c:\windows\system32\WININET.dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
c:\windows\system32\lxdncoms.exe
c:\program files\Sophos\AutoUpdate\ALsvc.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
c:\program files\CA\CA Internet Security Suite\ccprovsp.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2010-01-17 00:42:00 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-17 05:41
Pre-Run: 19,051,347,968 bytes free
Post-Run: 19,847,729,152 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 1794BC6DCA74B2BD4D9D73C9F5142A98