Hi Neal,
Thanks for taking up the problem. The only way I could stop NOD32 running, was to rename all the exe files in the program folder! Combofix STILL showed NOD32 to be running after a restart, but I can't see how. Hope it hasn't messed up the results you require. If necessary, I'll totally uninstall NOD32 & re-run Combofix. Let me know
Roger
ComboFix 09-02-10.01 - Roger 2009-02-10 20:26:28.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2703 [GMT 0:00]
Running from: c:\documents and settings\Roger\Desktop\ComboFix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated)
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\gaopdxoyjkwoif.sys
c:\windows\system32\gaopdxirxtxbun.dll
c:\windows\system32\MSVCTSCP.DLL
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gaopdxserv.sys
((((((((((((((((((((((((( Files Created from 2009-01-10 to 2009-02-10 )))))))))))))))))))))))))))))))
.
2009-02-09 23:04 . 2009-02-09 23:04 0 --a------ c:\windows\oodcnt.INI
2009-02-09 23:02 . 2009-02-09 23:03 <DIR> d-------- c:\windows\system32\oodag
2009-02-09 20:04 . 2009-02-09 20:04 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-02-09 20:03 . 2009-02-09 20:03 <DIR> d-------- c:\documents and settings\Administrator
2009-02-08 19:42 . 2009-02-08 22:01 <DIR> d-------- C:\fixwareout
2009-02-08 10:29 . 2009-02-08 10:29 <DIR> d-------- c:\program files\Trend Micro
2009-02-08 09:26 . 2009-02-08 09:58 <DIR> d-------- C:\bfu
2009-02-07 21:47 . 2009-02-07 22:47 <DIR> d-------- c:\documents and settings\Roger\DoctorWeb
2009-02-07 18:54 . 2009-02-08 12:34 <DIR> d-------- c:\documents and settings\Roger\.housecall6.6
2009-02-07 18:43 . 2009-01-18 21:35 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-02-07 18:18 . 2009-01-18 21:30 64,160 --a------ c:\windows\system32\drivers\Lbd.sys
2009-02-07 18:17 . 2009-02-07 18:17 <DIR> d-------- c:\program files\Lavasoft
2009-02-07 18:17 . 2009-02-07 18:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-07 18:17 . 2009-02-07 18:17 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-06 23:07 . 2009-02-06 23:07 <DIR> d-------- c:\program files\Belkin
2009-02-06 23:07 . 2005-01-19 11:01 1,396,831 --a------ c:\windows\system32\AegisE5.dll
2009-02-06 23:07 . 2003-10-13 15:30 94,208 --a------ c:\windows\system32\GTW32N50.dll
2009-02-06 23:07 . 2004-04-30 15:12 40,960 --a------ c:\windows\system32\F5D7051.dll
2009-02-06 23:07 . 2003-09-25 23:28 31,930 --a------ c:\windows\system32\GTNDIS3.VXD
2009-02-06 23:07 . 2004-03-30 16:57 29,184 --a------ c:\windows\system32\drivers\RNDISMPK.sys
2009-02-06 23:07 . 2009-02-06 23:07 17,801 --a------ c:\windows\system32\drivers\AegisP.sys
2009-02-06 23:07 . 2003-09-25 22:15 15,872 --a------ c:\windows\system32\GTNDIS5.sys
2009-02-06 23:07 . 2004-03-30 16:57 13,824 --a------ c:\windows\system32\drivers\usb8023k.sys
2009-02-06 13:23 . 2009-02-06 13:23 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-06 13:23 . 2009-02-06 13:23 <DIR> d-------- c:\documents and settings\Roger\Application Data\Malwarebytes
2009-02-06 13:23 . 2009-02-06 13:23 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-06 13:23 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-06 13:23 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-06 13:09 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2009-02-06 13:09 . 2001-08-17 13:48 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2009-02-06 13:09 . 2008-04-13 19:45 10,368 --a------ c:\windows\system32\drivers\hidusb.sys
2009-02-06 13:09 . 2008-04-13 19:45 10,368 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2009-02-05 14:55 . 2009-02-05 15:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-01-24 16:20 . 2009-01-24 16:53 <DIR> d-------- c:\program files\Boilsoft MOV Converter
2009-01-21 18:12 . 2009-01-21 18:12 <DIR> d-------- c:\program files\Xilisoft
2009-01-19 23:43 . 2009-01-19 23:43 <DIR> d-------- c:\documents and settings\Roger\Application Data\AVS4YOU
2009-01-19 23:43 . 2009-01-19 23:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\AVS4YOU
2009-01-19 23:40 . 2009-01-20 20:04 <DIR> d-------- c:\program files\Common Files\AVSMedia
2009-01-19 23:40 . 2009-01-20 20:04 <DIR> d-------- c:\program files\AVS4YOU
2009-01-19 23:40 . 2008-08-13 10:22 1,700,352 --a------ c:\windows\system32\GdiPlus.dll
2009-01-19 23:40 . 2008-08-13 10:22 24,576 --a------ c:\windows\system32\msxml3a.dll
2009-01-18 22:38 . 2009-01-18 22:38 <DIR> d-------- c:\documents and settings\Roger\Application Data\Nero
2009-01-18 22:35 . 2009-01-18 22:37 <DIR> d-------- c:\program files\Common Files\Nero
2009-01-18 22:35 . 2009-01-18 22:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Nero
2009-01-18 22:01 . 2009-01-19 22:42 8 --ah----- c:\windows\system32\adb.dat
2009-01-18 20:12 . 2009-01-20 20:04 <DIR> d-------- c:\program files\AviSynth 2.5
2009-01-18 20:12 . 2009-01-18 20:12 <DIR> d-------- c:\program files\AC3Filter
2009-01-18 20:12 . 2007-08-18 07:54 380,928 --a------ c:\windows\system32\ac3filter.acm
2009-01-18 18:15 . 2009-01-18 18:15 <DIR> d-------- c:\documents and settings\Roger\Application Data\dvdcss
2009-01-18 16:49 . 2009-01-18 16:49 38 --a------ c:\windows\AviSplitter.INI
2009-01-18 16:48 . 2009-01-18 16:48 <DIR> d-------- c:\program files\XP Codec Pack
2009-01-18 16:48 . 2009-01-18 16:49 <DIR> d-------- c:\documents and settings\Roger\Application Data\Media Player Classic
2009-01-17 17:58 . 2008-12-31 06:55 45,056 --a------ c:\windows\system32\WNASPI32.DLL
2009-01-17 17:58 . 2008-12-31 06:55 16,512 --a------ c:\windows\system32\drivers\ASPI32.SYS
2009-01-15 17:49 . 2009-01-15 17:49 <DIR> d-------- c:\program files\Common Files\SWF Studio
2009-01-14 22:08 . 2009-01-14 22:21 <DIR> d-------- c:\program files\Nirvana
2009-01-14 22:00 . 2009-01-14 22:07 73,728 --a------ c:\documents and settings\Roger\SetupNI.dll
2009-01-11 12:13 . 2009-01-11 12:13 <DIR> d-------- c:\program files\Microsoft WSE
2009-01-11 12:08 . 2009-01-11 12:08 <DIR> d-------- c:\windows\system32\XPSViewer
2009-01-11 12:08 . 2009-01-11 12:08 <DIR> d-------- c:\program files\Reference Assemblies
2009-01-11 12:07 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-02-10 20:19 --------- d-----w c:\program files\ESET
2009-02-10 07:17 --------- d-----w c:\program files\LogMeIn
2009-02-05 12:14 --------- d-----w c:\program files\DYMO Label
2009-02-05 09:17 --------- d-----w c:\program files\MLDownloader
2009-01-25 16:55 --------- d-----w c:\program files\CloneDVD
2009-01-23 20:20 --------- d-----w c:\program files\TradeGuider
2009-01-19 20:21 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-18 22:35 --------- d-----w c:\program files\Nero
2009-01-18 22:14 --------- d-----w c:\documents and settings\Roger\Application Data\MailWasherPro
2009-01-17 17:40 --------- d-----w c:\program files\ElcomSoft
2009-01-14 22:11 --------- d-----w c:\documents and settings\All Users\Application Data\Nirvana Systems
2009-01-14 18:09 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-11 12:08 --------- d-----w c:\program files\MSBuild
2009-01-06 22:37 --------- d-----w c:\program files\EOD Downloader
2008-12-30 17:58 --------- d-----w c:\program files\TradingSolutions 4.0
2008-12-30 08:55 --------- d-----w c:\program files\CCleaner
2008-12-30 08:25 --------- d-----w c:\program files\Common Files\Business Objects
2008-12-23 09:27 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-12-23 09:27 --------- d-----w c:\program files\Java
2008-12-14 19:19 --------- d-----w c:\program files\TeamViewer
2008-12-14 19:15 --------- d-----w c:\documents and settings\Roger\Application Data\TeamViewer
2008-12-14 12:40 --------- d-----w c:\program files\Common Files\Adobe
2008-12-13 15:48 --------- d-----w c:\program files\Adobe Media Player
2008-12-13 15:44 --------- d-----w c:\program files\Common Files\Adobe AIR
2008-12-13 15:33 --------- d-----w c:\program files\Common Files\Macrovision Shared
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-10 09:16 --------- d-----w c:\program files\Topaz Labs
2008-12-02 11:38 1,150,976 ----a-w c:\windows\system32\tlisimplify04_dll.dll
2008-11-30 17:20 3,520,000 ----a-w c:\windows\system32\tlisimplify04.dll
2008-11-19 09:28 1,839,104 ----a-w c:\windows\system32\tlisimplifyreg.exe
2008-03-01 16:47 7,775 ----a-w c:\program files\hijackthis.log
2008-03-01 16:46 401,720 ----a-w c:\program files\HiJackThis.exe
2008-10-08 20:26 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008100820081 009\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"SetDefPrt"="c:\program files\Brother\Brmfl04a\BrStDvPt.exe" [2004-05-25 49152]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 851968]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.ex e" [2008-08-14 611712]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 2213160]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-01-18 506712]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 c:\windows\soundman.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-01-31 789008]
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2008-01-31 819200]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-01-09 12:30 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-16 20:35 87352 c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"vidc.ffds"= ffdshow.ax
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
--a------ 2008-06-11 22:43 640376 c:\program files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
--a------ 2008-06-12 02:25 37232 c:\program files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-09-03 19:12 111936 c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2006-09-28 19:21 57344 c:\program files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-14 00:12 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-09-26 22:16 133104 c:\documents and settings\Roger\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 18:57 289576 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 14:57 153136 c:\program files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-12-23 09:27 136600 c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
--a------ 2007-11-29 02:17 55824 c:\windows\KHALMNPR.Exe
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Roger\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager .exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-07 64160]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod3 2drv.sys [2008-07-23 15424]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 921936]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [2008-07-24 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sy s [2008-12-14 47640]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\i:\ntglm7x.sys --> i:\NTGLM7X.sys [?]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - GTNDIS5
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{05b76e9e-eacd-11dc-8a0e-0019dbc6b51e}]
\Shell\AutoRun\command - L:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder
2009-02-09 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 21:34]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-nod32kui - c:\program files\Eset\nod32kui.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bbc.co.uk/news
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
FF - ProfilePath - c:\documents and settings\Roger\Application Data\Mozilla\Firefox\Profiles\s4w35dk4.default\
FF - prefs.
js: browser.startup.homepage - hxxp://news.bbc.co.uk/
FF - plugin: c:\documents and settings\Roger\Application Data\Mozilla\plugins\npPxPlay.dll
FF - plugin: c:\documents and settings\Roger\Local Settings\Application Data\Google\Update\1.2.133.33\npGoogleOneClick7.dl l
---- FIREFOX POLICIES ----
FF - user.
js: yahoo.homepage.dontask - true.
************************************************** ************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-10 20:30:56
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\Curr entVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="61FAEEA589C33258 70338C8AE1ED38DC461C5C2B5C42630E0CE0E4BB06A0F0A641 F4F56987F0144DB03C1507B6DA53FE32484C348488340C342D B4293283381FA35A6384DA162A59988A972ECBC4387FD84442 4AAE52E2AF26E65ABDFC583AAE5FC581BBD06C6643735E786F F3D7069D1C11DFA5CF5C5ED2F6ED5418230D51EADE1B4DBA08 B1AF761E3AD09D534151BC6FEE7CE2B3E585F151675640B211 4B07207D740F7827E0018D64EDF064B422E35B67218279FEBC 9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E 127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC49 80AC7933A6A0AC4980AC7933A6171C11EC38DE3DC038D530D6 EB3452F844E2A4EA7BCDF1004F00B02FBB10B286CDF2016054 F4539781E25242A083FD113533B65847AE9C64956C61A5FD0C C1D3DDBB2C7E2098E0505877FD628E87D7DFA2C07AED67A446 0C552500560BC938F065E0FAFA6E5D1BD168A58603C06B883B 9F745A0AE1C0E0C04E0B0CDFA21F2CBA705DA3D65C855EA6AF 9C752554F95304B0D7D5CE7174B0D135221CA4BD4A0A9100CB EE56BFB45AE098B3670F99E14B9A531B7FA28298D0913190D5 CC86EA0FD8896FB9019E74139407658FC81534DAE3750F80AE 36E83057DE24F6C2D984CE77752C76A335335FDAD04E359EFD 683CCAFA2D916263830E7DCE4B4F364C81AF5A210929CCF2C2 ECCF3FB1B1A4C259833CB90F04EF126C01E1049B439923ACEC 6F5E36EBD2FAD6399411F4F3AC8343922B7D733A4C020B7468 76CACA255A3715ABEF03EA4C250B994E77207CD2934BA38A85 BD2BB122AAA376933773541F350A07126469967DD9B5A49A64 E2F07C7542560374E3A0997A22F73A5F5B64D39F83FBEE73BA 51C2A708C39191D1AB7BAE518C20C201D8418E565B3E67B8D9 0FD28C0A296C496068B862DE6C1E8766FE4383ADF4F6B760A6 5D7712E817D17B9C8D83B5553212EB17B4E627ACA3D5492D65 E33E9205CE828C439593F3D906D4F9F59A87FBC6266029AB0E D8C8602243DDAD4D4A7A0422CCE600905A92C0423459935A09 1B54ABEC2E0E242E2A36E7851F15EF5EA4AC1F916035A0E5E5 FE0E2DA2D31B4BA3285A08E9B0C6E72EAA36042FF9530CFB5F 4AE7D4EBCDB7086CFE186F068D617A3480E754CDEC4BA7E7AC F8839E4DE8DFA0BBA8D78EF5578305410E0E5F3463F68A7F88 9882DBA15D3C8460C42A8D8E22149D722E6D4ACED8E897EE81 F7656DE8E64CAB17CFB0368899867CCF26929B0B07AF27503A D2ACFC5C54DE804B4B9D0FA47054621B5ADAD6949052B40232 3155E7C56D6D0F6705D646614474BB6519A04488CA41AF9D63 6BE7952AB81093732F48452F6565366C42B3B8C97D8C8686C4 EB469B30B712A8DAF29B91D205368E3DE0AA9ACF1DC17E1153 6CDF6DE5D51219646F165FC6A18730B5"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(712)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\windows\system32\LMIinit.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\system32\LMIRfsClientNP.dll
- - - - - - - > 'lsass.exe'(768)
c:\windows\system32\imon.dll
.
Completion time: 2009-02-10 20:32:14
ComboFix-quarantined-files.txt 2009-02-10 20:32:12
Pre-Run: 177,497,059,328 bytes free
Post-Run: 177,574,064,128 bytes free
261 --- E O F --- 2009-01-14 18:09:38
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:52:05, on 10/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Belkin\F5D7051\WLService.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Belkin\F5D7051\WLanCfgG.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
BBC NEWS | News Front Page
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
MSN.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.ex e" -launchedbylogin
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://appldnld.apple.com.edgesuite....x/qtplugin.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://dl8-cdn-01.sun.com/s/ESD5/JSC...ws-i586-jc.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) -
http://www.photodex.com/pxplay.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Belkin High-Speed Mode Wireless G USB Driver (Belkin High-Speed Mode Wireless G USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\F5D7051\WLService.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
--
End of file - 9755 bytes