This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] packed.generic.200 virus

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I think I have the .exe file for SP3 in my laptop. Could it be "Win32 Cabinet Self-extractor, v.6.0.2448.0, 4.18 MB?

If so, will it work if I burn a CD with this file?

That's worth a try.
When I right click the SR.INF file and click install the window I mentioned before opens. Files needed: sr.sys (again about the SP3 CD). I just saw your response about burning the cd. So meanwhile, I will try to do it.
I burned the CD but I have the .exe file if I click on I get the agreement page to start the installation. So I suppose I cannot do it.
You could try copying the file from the working pc to the non-working one. Just be sure to put it where it belongs.
What file would that be? sr.inf or sr.sys? The laptop is also Windows XP SP3 but in spanish, the other one is in english. Are these files the same regardless of the language? Please confirm also if I can copy it where exactly I have to do it.
SR.INF

Do this first:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.

It should be located in: C:\windows

Look for the one you need to copy over.
I found the files in several places. The 'sr.inf' file is at: C:\Windows\INF C:\I386 The 'sr.sys' file is at: C:\386 C:\Windows\$NtServicePackUninstall$ C:\Windows\ServicePackFiles\i386 C:\Windows\System32\Drivers The 'sr.sys' file is the one the pc is requesting from the SP3 CD. And it says to search in C:\I386 (well, I don't know the exact path but I am sure about I386). I cannot look at it now because the infected computer froze so I will have to unplug it. The only thing is that I had the C:\Windows\INF file open and with all files showing, so I hope it doesn't get worse than already is. I have copied the file "sr.inf" located at C:\Windows\INF in a pen drive to pass it to the infected computer. This file already exists in the infected computer so if I copy it I suppose it will ask if I want to replace it. Do I replace it? Just to make sure. Because if I am not wrong this is the file you wanted me to copy, is it? I will do this tomorrow or better, later on today… it is already here 02:40 in the morning and I must get up early. But first I will wait for your confirmation before doing anything. Thank you.

Do I replace it? Just to make sure. Because if I am not wrong this is the file you wanted me to copy, is it?

Yes replace it.
Nothing we are trying to do works. I replaced the file "sr.inf" and then I click "install" and get the message asking me for the SP3 CD. I copied the "Service Pack files" in C:\Windows\ServicePackfiles into a CD and tried to get the file requested (sr.sys) from there but when I try to open the CD from the window requesting the file it freezes. If I go to my computer and can open it from there. I copied the file in the desktop but then it says it is in a different language and if I want to overwrite it, so I said no. Then I was given the chance to continue without that file and then it request another file and another, and another, I don't know exactly how many but conclusion… I cannot do it without the SP3 CD. I suppose there isn't much to do.
I cannot believe it yet, it worked this time!
I have the log from Combofix, but before the log was finished and when I was not supposed to run any programs, the internet connection started to work and all the programs were starting until I was able to disable the internet connection.

At the moment I have it disabled. I don't want to connect it yet until you tell me what to do. A window from Norton Internet Security keeps poping up as every time I started the computer on previous days, telling me about the files infected and not resolved. Should I connect and download the Norton updates?

Well, here is the log:

ComboFix 09-05-03.4 - Begona Franco 06/05/2009 23:07.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1012 [GMT 2:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.com.exe
AV: Norton Internet Security *On-access scanning enabled* (Updated)
FW: Norton Internet Security *enabled*

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Begona Franco\Start Menu\Programs\Download programs.url
c:\documents and settings\Begona Franco\Start Menu\Programs\Games.url
c:\documents and settings\Begona Franco\Start Menu\Programs\Translator.url
c:\documents and settings\Begona Franco\Start Menu\Programs\Videos.url
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\Fonts\ALGER(2).TTF
c:\windows\Fonts\ARLRDBD(2).TTF
c:\windows\Fonts\BASKVILL(2).TTF
c:\windows\Fonts\BAUHS93(2).TTF
c:\windows\Fonts\BELL(2).TTF
c:\windows\Fonts\BELLB(2).TTF
c:\windows\Fonts\BELLI(2).TTF
c:\windows\Fonts\BERNHC(2).TTF
c:\windows\Fonts\BRITANIC(2).TTF
c:\windows\Fonts\BRUSHSCI(2).TTF
c:\windows\Fonts\CALIST(2).TTF
c:\windows\Fonts\CALISTB(2).TTF
c:\windows\Fonts\CALISTBI(2).TTF
c:\windows\Fonts\CALISTI(2).TTF
c:\windows\Fonts\CASTELAR(2).TTF
c:\windows\Fonts\CENSCBK(2).TTF
c:\windows\Fonts\CENTAUR(2).TTF
c:\windows\Fonts\CHILLER(2).TTF
c:\windows\Fonts\COLONNA(2).TTF
c:\windows\Fonts\COOPBL(2).TTF
c:\windows\Fonts\ELEPHNT(2).TTF
c:\windows\Fonts\ELEPHNTI(2).TTF
c:\windows\Fonts\ERASBD(2).TTF
c:\windows\Fonts\ERASMD(2).TTF
c:\windows\Fonts\FRADMCN(2).TTF
c:\windows\Fonts\FRAHV(2).TTF
c:\windows\Fonts\FRAHVIT(2).TTF
c:\windows\Fonts\FRAMDCN(2).TTF
c:\windows\Fonts\FREESCPT(2).TTF
c:\windows\Fonts\FTLTLT(2).TTF
c:\windows\Fonts\GIGI(2).TTF
c:\windows\Fonts\GIL_____(2).TTF
c:\windows\Fonts\GILB____(2).TTF
c:\windows\Fonts\GILBI___(2).TTF
c:\windows\Fonts\GILC____(2).TTF
c:\windows\Fonts\GILI____(2).TTF
c:\windows\Fonts\GILLUBCD(2).TTF
c:\windows\Fonts\GILSANUB(2).TTF
c:\windows\Fonts\GLECB(2).TTF
c:\windows\Fonts\GLSNECB(2).TTF
c:\windows\Fonts\GOUDOS(2).TTF
c:\windows\Fonts\GOUDOSB(2).TTF
c:\windows\Fonts\GOUDOSI(2).TTF
c:\windows\Fonts\HARLOWSI(2).TTF
c:\windows\Fonts\HARNGTON(2).TTF
c:\windows\Fonts\HATTEN(2).TTF
c:\windows\Fonts\IMPRISHA(2).TTF
c:\windows\Fonts\INFROMAN(2).TTF
c:\windows\Fonts\JOKERMAN(2).TTF
c:\windows\Fonts\JUICE___(2).TTF
c:\windows\Fonts\KUNSTLER(2).TTF
c:\windows\Fonts\LATINWD(2).TTF
c:\windows\Fonts\LBRITE(2).TTF
c:\windows\Fonts\LBRITED(2).TTF
c:\windows\Fonts\LBRITEDI(2).TTF
c:\windows\Fonts\LBRITEI(2).TTF
c:\windows\Fonts\LCALLIG(2).TTF
c:\windows\Fonts\LFAX(2).TTF
c:\windows\Fonts\LFAXD(2).TTF
c:\windows\Fonts\LFAXDI(2).TTF
c:\windows\Fonts\LFAXI(2).TTF
c:\windows\Fonts\LHANDW(2).TTF
c:\windows\Fonts\LTYPE(2).TTF
c:\windows\Fonts\LTYPEB(2).TTF
c:\windows\Fonts\LTYPEBO(2).TTF
c:\windows\Fonts\LTYPEO(2).TTF
c:\windows\Fonts\MATURASC(2).TTF
c:\windows\Fonts\MOD20(2).TTF
c:\windows\Fonts\MTCORSVA(2).TTF
c:\windows\Fonts\OCRAEXT(2).TTF
c:\windows\Fonts\OLDENGL(2).TTF
c:\windows\Fonts\ONYX(2).TTF
c:\windows\Fonts\PALSCRI(2).TTF
c:\windows\Fonts\PARCHM(2).TTF
c:\windows\Fonts\PERTIBD(2).TTF
c:\windows\Fonts\PERTILI(2).TTF
c:\windows\Fonts\PLAYBILL(2).TTF
c:\windows\Fonts\POORICH(2).TTF
c:\windows\Fonts\PRISTINA(2).TTF
c:\windows\Fonts\RAGE(2).TTF
c:\windows\Fonts\ROCC____(2).TTF
c:\windows\Fonts\ROCCB___(2).TTF
c:\windows\Fonts\ROCK(2).TTF
c:\windows\Fonts\ROCKB(2).TTF
c:\windows\Fonts\ROCKBI(2).TTF
c:\windows\Fonts\ROCKI(2).TTF
c:\windows\Fonts\SCHLBKB(2).TTF
c:\windows\Fonts\SCHLBKBI(2).TTF
c:\windows\Fonts\SCHLBKI(2).TTF
c:\windows\Fonts\SCRIPTBL(2).TTF
c:\windows\Fonts\SNAP____(2).TTF
c:\windows\Fonts\STENCIL(2).TTF
c:\windows\Fonts\TCB_____(2).TTF
c:\windows\Fonts\TCBI____(2).TTF
c:\windows\Fonts\TCCB____(2).TTF
c:\windows\Fonts\TCCM____(2).TTF
c:\windows\Fonts\TCM_____(2).TTF
c:\windows\Fonts\TCMI____(2).TTF
c:\windows\Fonts\VINERITC(2).TTF
c:\windows\Fonts\VLADIMIR(2).TTF
c:\windows\IE4 Error Log.txt
c:\windows\ieocx.dll
c:\windows\patch.exe
c:\windows\system32\drivers\UACwlpavyqjdsmkoeh.sys
c:\windows\system32\FM20(2).DLL
c:\windows\system32\FM20(3).DLL
c:\windows\system32\FM20ESN(2).DLL
c:\windows\system32\FM20ESP(2).DLL
c:\windows\system32\msrecr40(2).dll
c:\windows\system32\MSSTDFMT(2).DLL
c:\windows\system32\OUTLWAB(2).DLL
c:\windows\system32\UACfsycwvtmgtllmrf.log
c:\windows\system32\UACgyltkewxmkdbcin.dll
c:\windows\system32\UAChivdiaqbokqoxlt.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACkbqagwkiiurubrr.dll
c:\windows\system32\UACkvrjbxdorjittjp.dll
c:\windows\system32\UACpoaqginlpenowpn.dat
c:\windows\system32\UACpwukfuimxhmwlro.log
c:\windows\system32\UACsfnsakodyhuqwtv.dll
c:\windows\system32\UACtrrjiyheoyirftx.log

—– BITS: Possible infected sites —–

hxxp://tubeontvgl.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys
——-\Legacy_HWCLOCK
——-\Legacy_NVCPLSCAN


((((((((((((((((((((((((( Files Created from 2009-04-06 to 2009-05-06 )))))))))))))))))))))))))))))))
.

2009-05-06 21:02 . 2009-05-06 21:20 161824 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-06 21:02 . 2009-05-06 21:20 5664 –sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-04 15:29 . 2005-07-27 19:11 360256 —-a-w c:\windows\system32\drivers\ar5523.sys
2009-05-04 15:29 . 2005-07-27 19:15 149392 —-a-w c:\windows\system32\drivers\ar5523.bin
2009-05-04 08:50 . 2009-04-06 13:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-04 08:50 . 2009-04-06 13:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-04 08:50 . 2009-05-04 08:50 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-04 08:50 . 2009-05-04 09:54 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-26 08:28 . 2009-04-26 08:28 ——– d—–w c:\documents and settings\All Users\Application Data\ParetoLogic Anti-Virus PLUS
2009-04-26 08:28 . 2009-04-26 08:28 ——– d—–w c:\program files\Common Files\ParetoLogic
2009-04-26 08:28 . 2009-04-26 08:28 ——– d—–w c:\program files\ParetoLogic
2009-04-26 08:28 . 2009-04-26 08:28 ——– d—–w c:\documents and settings\All Users\Application Data\ParetoLogic
2009-04-26 08:24 . 2009-04-26 08:24 ——– d—–w c:\documents and settings\Begona Franco\Local Settings\Application Data\Downloaded Installations
2009-04-25 18:02 . 2009-04-25 18:02 ——– d—–w c:\documents and settings\Emilio Zubiete\Application Data\Ahead
2009-04-25 17:56 . 2009-04-25 17:56 ——– d—–w c:\documents and settings\Emilio Zubiete\Local Settings\Application Data\Ahead
2009-04-25 17:55 . 2009-04-25 17:55 ——– d—–w c:\documents and settings\Emilio Zubiete\Local Settings\Application Data\Steam
2009-04-25 16:39 . 2009-04-25 16:39 ——– d—–w c:\documents and settings\Administrator\Application Data\Uniblue
2009-04-25 12:04 . 2009-04-25 12:04 ——– d—–w c:\documents and settings\Begona Franco\Local Settings\Application Data\Symantec
2009-04-22 14:37 . 2009-04-22 16:42 664 —-a-w c:\windows\system32\d3d9caps.dat
2009-04-17 16:43 . 2009-04-17 16:43 ——– d—–w c:\program files\TomTom International B.V
2009-04-16 18:00 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-04-16 18:00 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 18:00 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-04-16 18:00 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 18:00 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 18:00 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 18:00 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 18:00 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 18:00 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 17:57 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-16 17:57 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-04-09 18:57 . 2009-04-09 18:57 ——– d—–w c:\program files\iPod
2009-04-09 18:57 . 2009-04-09 18:58 ——– d—–w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-06 21:17 . 2005-04-22 10:31 6 —ha-w c:\windows\Tasks\SA.DAT
2009-05-06 21:16 . 2009-05-06 21:02 2804 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-06 21:16 . 2009-05-06 21:02 1460 –sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-06 21:16 . 2005-07-06 21:50 288 —-a-w c:\windows\system32\DVCStateBkp-{00000002-00000000-00000007-00001102-00000004-10031102}.dat
2009-05-06 21:16 . 2005-07-06 21:50 288 —-a-w c:\windows\system32\DVCState-{00000002-00000000-00000007-00001102-00000004-10031102}.dat
2009-05-04 22:33 . 2009-04-26 08:28 432 —-a-w c:\windows\Tasks\ParetoLogic Update Version2.job
2009-05-04 16:55 . 2005-04-22 11:48 ——– d–h–w c:\program files\InstallShield Installation Information
2009-05-04 07:35 . 2009-03-24 08:35 472 —-a-w c:\windows\Tasks\Ad-Aware Update (Weekly).job
2009-05-03 09:16 . 2007-09-01 10:15 ——– d—–w c:\program files\Steam
2009-04-27 16:04 . 2005-05-20 06:08 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-04-27 16:00 . 2009-04-26 08:28 458 —-a-w c:\windows\Tasks\ParetoLogic Anti-Virus PLUS_dbsummary.job
2009-04-26 08:28 . 2009-04-26 08:28 482 —-a-w c:\windows\Tasks\ParetoLogic Anti-Virus PLUS.job
2009-04-24 22:23 . 2009-04-24 22:23 43 —-a-w c:\documents and settings\Emilio Zubiete\Application Data\~ygw.tmp
2009-04-21 18:25 . 2008-08-20 08:26 284 —-a-w c:\windows\Tasks\AppleSoftwareUpdate.job
2009-04-21 13:44 . 2009-03-24 08:35 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-04-17 16:41 . 2009-02-10 15:12 ——– d—–w c:\program files\TomTom HOME 2
2009-04-09 18:58 . 2005-05-18 10:47 ——– d—–w c:\program files\iTunes
2009-04-09 18:57 . 2007-06-29 19:03 ——– d—–w c:\program files\Common Files\Apple
2009-03-24 08:32 . 2008-01-18 09:52 ——– d—–w c:\program files\Lavasoft
2009-03-24 08:32 . 2005-05-07 14:57 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-03-22 14:20 . 2009-03-22 14:20 291 —-a-w c:\windows\PowerReg.dat
2009-03-20 10:02 . 2006-04-06 08:43 ——– d—–w c:\program files\Symantec
2009-03-20 10:02 . 2008-12-04 12:15 805 —-a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-03-20 10:02 . 2008-12-04 12:15 7386 —-a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-03-20 10:02 . 2008-12-04 12:15 60808 —-a-w c:\windows\system32\S32EVNT1.DLL
2009-03-20 10:02 . 2008-12-04 12:15 124464 —-a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-19 17:05 . 2008-09-12 19:29 ——– d—–w c:\program files\QuickTime
2009-03-19 14:32 . 2008-01-29 10:01 23400 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-18 07:31 . 2005-04-27 19:25 ——– d—–r c:\program files\Skype
2009-03-13 18:20 . 2005-04-22 21:17 147136 —-a-w c:\documents and settings\Emilio Zubiete\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-13 13:43 . 2005-04-25 20:41 ——– d—–w c:\program files\Common Files\Adobe
2009-03-13 10:08 . 2005-04-22 18:20 147136 —-a-w c:\documents and settings\Begona Franco\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-13 07:57 . 2009-03-13 07:56 ——– d—–w c:\program files\EurocamSuite PRO 9
2009-03-12 09:03 . 2009-03-20 21:27 36400 —-a-r c:\windows\system32\drivers\SymIM.sys
2009-03-09 19:06 . 2009-03-30 07:30 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-03-08 13:16 . 2008-02-20 22:16 ——– d—–w c:\program files\Azureus
2009-03-06 14:22 . 2002-09-03 16:51 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2005-02-18 14:19 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-08-04 07:56 78336 —-a-w c:\windows\system32\ieencode.dll
2009-02-18 12:43 . 2009-02-18 12:43 243024 —-a-w c:\windows\system32\LSPInstall.dll
2009-02-18 12:43 . 2009-02-18 12:43 111960 —-a-w c:\windows\system32\INetHTTPFilter.dll
2009-02-15 15:30 . 2007-07-10 18:02 138584 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-02-15 15:30 . 2007-07-10 17:48 70968 —-a-w c:\windows\system32\PnkBstrA.exe
2009-02-15 15:30 . 2007-07-10 17:48 189672 —-a-w c:\windows\system32\PnkBstrB.exe
2009-02-09 12:10 . 2002-09-03 16:39 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2005-01-14 05:33 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2002-09-03 16:49 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2002-09-03 16:27 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2002-09-03 17:11 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-06 18:34 . 2009-02-06 18:34 308616 —-a-w c:\windows\WLXPGSS.SCR
2009-02-06 17:52 . 2009-02-06 17:52 49504 —-a-w c:\windows\system32\sirenacm.dll
2009-02-06 17:08 . 2009-02-21 21:35 55152 —-a-w c:\windows\system32\drivers\fssfltr_tdi.sys
2009-02-06 11:11 . 2002-09-03 16:59 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2002-09-03 16:50 2145280 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2002-09-03 16:58 35328 —-a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2002-08-29 01:04 2023936 —-a-w c:\windows\system32\ntkrnlpa.exe
2005-04-28 16:24 . 2005-04-28 12:42 9517 —-a-w c:\program files\hijackthis.log
2004-02-25 16:35 . 2005-10-12 09:35 90 —-a-w c:\program files\Sonic MyDVD Studio Deluxe 5 - serial #.txt
2002-09-03 17:07 . 2002-09-03 17:07 94784 –sha-w c:\windows\TWAIN.DLL
2008-04-14 00:12 . 2002-09-03 17:07 50688 –sha-w c:\windows\twain_32.dll
2008-04-14 00:12 . 2002-09-03 16:46 413696 –sha-w c:\windows\system32\msvcp60.dll
2008-04-14 00:12 . 2002-09-03 16:51 84992 –sha-w c:\windows\system32\olepro32.dll
2008-04-14 00:12 . 2002-09-03 16:56 11776 –sh–w c:\windows\system32\regsvr32.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-07-15 21:00 66912 —-a-w c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-11 68856]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-03-06 24095528]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"ISUSPM Startup"="c:\progra~1\common~1\instal~1\update~1\isuspm.exe" [2004-07-27 221184]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-04-21 516440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-24 132496]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-06-13 528384]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"RevolteMediaDetector"="c:\program files\Colormailer\Photo Manager\MediaDetector.exe" [2005-02-09 69632]
"NBKeyScan"="c:\program files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe" [2007-03-26 1185328]
"Motive SmartBridge"="c:\progra~1\CABLEC~1\SMARTB~1\DExec.exe" [2005-03-10 69632]
"LVCOMS"="c:\program files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2001-09-24 98304]
"hplampc"="c:\windows\system32\hplampc.exe" [2002-01-17 40448]
"HPHmon03"="c:\windows\system32\hphmon03.exe" [2001-10-25 311296]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-25 196608]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"EVENTLISTENER"="c:\program files\Common Files\FotoNation\EvLstnr.exe" [2000-06-20 53248]
"CXMon"="c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2001-09-19 45056]
"CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-09-11 53248]
"CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-29 45056]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2006-03-10 684032]
"ParetoLogic Anti-Virus PLUS"="c:\program files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.lnk" [2009-05-06 2355]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CtHelper.exe [2002-09-03 24576]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Begona Franco\Start Menu\Programs\Startup\
Recorte de pantalla e Inicio r pido de OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]

c:\documents and settings\Emilio Zubiete\Start Menu\Programs\Startup\
Microsoft Office Groove.lnk - c:\program files\Microsoft Office\Office12\GROOVE.EXE [2007-8-29 340856]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Búsqueda en el escritorio de Windows.lnk]
backup=c:\windows\pss\Búsqueda en el escritorio de Windows.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^cablecom assistant.lnk]
backup=c:\windows\pss\cablecom assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Gigaset WLAN Adapter Monitor.lnk]
backup=c:\windows\pss\Gigaset WLAN Adapter Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
backup=c:\windows\pss\Picture Package Menu.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Begona Franco^Start Menu^Programs^Startup^Picture Motion Browser Media Check Tool.lnk]
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Gorka Zubiete^Start Menu^Programs^Startup^Xfire.lnk]
backup=c:\windows\pss\Xfire.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\License Manager
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Valve\\Steam\\Steam.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Games\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Octoshape Streaming Services\\Begona Franco\\OctoshapeClient.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

R1 sonypvd3;Sony DVD Handycam;c:\windows\system32\DRIVERS\sonypvd3.sys [2004-12-07 64964]
R3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [2001-10-25 18864]
R3 fsssvc;Windows Live Protección Infantil;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2008-05-17 13352]
R3 hp4200c;%usbscan.SvcDesc%;c:\windows\system32\DRIVERS\hp4200c.sys [2001-02-18 9312]
R3 s125bus;Sony Ericsson Device 125 driver (WDM);c:\windows\system32\DRIVERS\s125bus.sys [2007-04-24 83336]
R3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s125mdfl.sys [2007-04-24 15112]
R3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s125mdm.sys [2007-04-24 108680]
R3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s125mgmt.sys [2007-04-24 100488]
R3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s125obex.sys [2007-04-24 98696]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-04-21 64160]
S0 sonypvl3;sonypvl3; [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SYMEFA.SYS [2009-03-12 310320]
S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\Drivers\NIS\1005000.087\BHDrvx86.sys [2009-03-12 258608]
S1 ccHP;Symantec Hash Provider;c:\windows\System32\Drivers\NIS\1005000.087\ccHPx86.sys [2009-03-20 482352]
S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090420.001\IDSxpx86.sys [2009-01-29 276344]
S1 sonypvf3;sonypvf3; [x]
S1 sonypvt3;sonypvt3; [x]
S2 fssfltr;fssfltr;c:\windows\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-04-21 953168]
S2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [2009-03-12 115560]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-04-08 92008]
S2 ZeppelinService;plasservice;c:\program files\Common Files\ParetoLogic\PLAS\plasservice.exe [2009-02-18 587216]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-25 101936]
S3 QCPro;Logitech QuickCam Pro USB(PID_D001);c:\windows\system32\DRIVERS\p35u.sys [2001-09-24 116448]


— Other Services/Drivers In Memory —

*Deregistered* - uphcleanhlp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2734bad4-1335-11da-8d86-0007e9dffe90}]
\Shell\AutoRun\command - G:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6853e4ff-f77f-11dd-973e-0007e9dffe90}]
\Shell\AutoRun\command - G:\InstallTomTomHOME.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b5fdc48d-c36e-11db-921a-0007e9dffe90}]
\Shell\AutoRun\command - G:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d18d2e8a-c29d-11db-9218-0007e9dffe90}]
\Shell\AutoRun\command - G:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder

2009-05-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 13:44]

2009-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 10:34]

2009-04-26 c:\windows\Tasks\ParetoLogic Anti-Virus PLUS.job
- c:\program files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.exe [2009-02-18 12:43]

2009-04-27 c:\windows\Tasks\ParetoLogic Anti-Virus PLUS_dbsummary.job
- c:\program files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.exe [2009-02-18 12:43]

2009-05-06 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2008-02-22 10:25]

2009-05-04 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2008-02-22 10:25]
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{E3EA4FD9-CADE-4AE5-84F7-086EEE888BE4} - (no file)
HKLM-RunServices-Windows Recylinder Check - cnzfpsjurw.exe
HKU-Default-Run-MSN7 Startup - msn7.exe
HKU-Default-Run-IExplorer7 Java Scripting - IExplore327.exe
HKU-Default-Run-Windows Compliant - eijyky.exe
HKU-Default-RunOnce-IETI - c:\program files\Skype\Phone\IEPlugin\unins000.exe


.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://uk.yahoo.com
uInternet Settings,ProxyOverride = *.local
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java
DPF: {B6F0855B-A06D-498B-A537-80AFF04A1B4E} - hxxps://www.telefonicaonline.com/o1/http/WSClient.cab
FF - ProfilePath - c:\documents and settings\Begona Franco\Application Data\Mozilla\Firefox\Profiles\o86dfyis.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\documents and settings\Begona Franco\Application Data\Mozilla\plugins\npoctoshape.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npsharedview.dll
FF - plugin: c:\program files\Octoshape Streaming Services\Begona Franco\octoprogram-L03-NMS0806260_SUA_000\npoctoshape.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-06 23:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-606747145-1547161642-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\:õwjY*]
"DisplayName"="\09"
"DeviceDesc"="\09"
"ProviderName"=""
"MFG"="?"
"ReinstallString"="2002, 6.13.10.6143"
"DeviceInstanceIds"=multi:"\00"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(688)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3424)
c:\progra~1\CABLEC~1\SMARTB~1\SBHook.dll
c:\windows\system32\ctagent.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\program files\Sony Ericsson\Mobile2\File Manager\FM.dll
c:\windows\system32\MSVCR71.dll
c:\program files\Common Files\Teleca Shared\tlib_log.dll
c:\program files\Common Files\Teleca Shared\boost_log-vc71-mt-1_33.dll
c:\program files\Common Files\Teleca Shared\TC Device Mgmt.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nikon\NkView\MLCamView.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTSVCCDA.EXE
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\UPHClean\uphclean.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\searchindexer.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Teleca Shared\Generic.exe
c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
c:\windows\system32\searchprotocolhost.exe
c:\progra~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Windows Desktop Search\WindowsSearch.exe
c:\progra~1\CABLEC~1\SMARTB~1\MotiveSB.exe
c:\windows\system32\searchfilterhost.exe
.
**************************************************************************
.
Completion time: 2009-05-06 23:36 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-06 21:35

Pre-Run: 44,661,542,912 bytes free
Post-Run: 45,184,446,464 bytes free

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
524 — E O F — 2009-04-17 16:45
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::

Regnull:: 
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\:õwjY*]

Folder::
c:\program files\AskSBar
c:\Program Files\Bonjour

Driver::


Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
The Combofix log went much faster than previous one. Then I was able to use the last version of HJT that before running Combofix was impossible. When trying to pass to the pen drive the first Combofix log "my computer" froze and I had to restart the computer, this time everything went smoother. The only problem was the program Spybot that is warning me about an important registry entry that has been changed and to allow or deny, but I don't want to do anything and the window stays there. When all this problem started I downloaded a few programs that are still there.

Another thing I forgot to mention is that in the infected computer there are three users, one of them with password.

Following are the logs for Combofix and HJT:

ComboFix 09-05-03.4 - Begona Franco 07/05/2009 0:47.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.686 [GMT 2:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.com.exe
Command switches used :: c:\documents and settings\Begona Franco\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Outdated)
FW: Norton Internet Security *disabled*

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\AskSBar
c:\program files\AskSBar\bar\1.bin\A2FFXTBR.JAR
c:\program files\AskSBar\bar\1.bin\A2FFXTBR.MANIFEST
c:\program files\AskSBar\bar\1.bin\A2HIGHIN.EXE
c:\program files\AskSBar\bar\1.bin\A2NTSTBR.JAR
c:\program files\AskSBar\bar\1.bin\A2NTSTBR.MANIFEST
c:\program files\AskSBar\bar\1.bin\A2PLUGIN.DLL
c:\program files\AskSBar\bar\1.bin\ASKSBAR.DLL
c:\program files\AskSBar\bar\1.bin\NPASKSBR.DLL
c:\program files\AskSBar\bar\1.bin\V2RSSMNU.DLL
c:\program files\AskSBar\bar\Cache\00D04EF7
c:\program files\AskSBar\bar\Cache\02C2D864.bin
c:\program files\AskSBar\bar\Cache\02C2E6DB.bin
c:\program files\AskSBar\bar\Cache\02C2E98B.bin
c:\program files\AskSBar\bar\Cache\02C2EC2B.bin
c:\program files\AskSBar\bar\Cache\02C2F013.bin
c:\program files\AskSBar\bar\Cache\02C2F2C2.bin
c:\program files\AskSBar\bar\Cache\files.ini
c:\program files\AskSBar\bar\History\search2
c:\program files\AskSBar\bar\Settings\prevcfg2.htm
c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
c:\program files\Bonjour
c:\program files\Bonjour\About Bonjour.rtf
c:\program files\Bonjour\mdnsNSP.dll
c:\program files\Bonjour\mDNSResponder.exe

.
((((((((((((((((((((((((( Files Created from 2009-04-06 to 2009-05-06 )))))))))))))))))))))))))))))))
.

2009-05-06 21:02 . 2009-05-06 22:51 296992 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-06 21:02 . 2009-05-06 22:51 13344 –sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-04 15:29 . 2005-07-27 19:11 360256 —-a-w c:\windows\system32\drivers\ar5523.sys
2009-05-04 15:29 . 2005-07-27 19:15 149392 —-a-w c:\windows\system32\drivers\ar5523.bin
2009-05-04 08:50 . 2009-04-06 13:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-04 08:50 . 2009-04-06 13:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-04 08:50 . 2009-05-04 08:50 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-04 08:50 . 2009-05-04 09:54 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-26 08:28 . 2009-04-26 08:28 ——– d—–w c:\documents and settings\All Users\Application Data\ParetoLogic Anti-Virus PLUS
2009-04-26 08:28 . 2009-04-26 08:28 ——– d—–w c:\program files\Common Files\ParetoLogic
2009-04-26 08:28 . 2009-04-26 08:28 ——– d—–w c:\program files\ParetoLogic
2009-04-26 08:28 . 2009-04-26 08:28 ——– d—–w c:\documents and settings\All Users\Application Data\ParetoLogic
2009-04-26 08:24 . 2009-04-26 08:24 ——– d—–w c:\documents and settings\Begona Franco\Local Settings\Application Data\Downloaded Installations
2009-04-25 18:02 . 2009-04-25 18:02 ——– d—–w c:\documents and settings\Emilio Zubiete\Application Data\Ahead
2009-04-25 17:56 . 2009-04-25 17:56 ——– d—–w c:\documents and settings\Emilio Zubiete\Local Settings\Application Data\Ahead
2009-04-25 17:55 . 2009-04-25 17:55 ——– d—–w c:\documents and settings\Emilio Zubiete\Local Settings\Application Data\Steam
2009-04-25 16:39 . 2009-04-25 16:39 ——– d—–w c:\documents and settings\Administrator\Application Data\Uniblue
2009-04-25 12:04 . 2009-04-25 12:04 ——– d—–w c:\documents and settings\Begona Franco\Local Settings\Application Data\Symantec
2009-04-22 14:37 . 2009-04-22 16:42 664 —-a-w c:\windows\system32\d3d9caps.dat
2009-04-17 16:43 . 2009-04-17 16:43 ——– d—–w c:\program files\TomTom International B.V
2009-04-16 18:00 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-04-16 18:00 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 18:00 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-04-16 18:00 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 18:00 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 18:00 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 18:00 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 18:00 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 18:00 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 17:57 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-16 17:57 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-04-09 18:57 . 2009-04-09 18:57 ——– d—–w c:\program files\iPod
2009-04-09 18:57 . 2009-04-09 18:58 ——– d—–w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-06 22:46 . 2005-04-22 10:31 6 —ha-w c:\windows\Tasks\SA.DAT
2009-05-06 22:33 . 2009-04-26 08:28 432 —-a-w c:\windows\Tasks\ParetoLogic Update Version2.job
2009-05-06 21:57 . 2009-05-06 21:02 3620 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-06 21:57 . 2009-05-06 21:02 1916 –sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-06 21:57 . 2005-07-06 21:50 288 —-a-w c:\windows\system32\DVCStateBkp-{00000002-00000000-00000007-00001102-00000004-10031102}.dat
2009-05-06 21:57 . 2005-07-06 21:50 288 —-a-w c:\windows\system32\DVCState-{00000002-00000000-00000007-00001102-00000004-10031102}.dat
2009-05-06 21:26 . 2009-05-06 21:26 458 —-a-w c:\windows\Tasks\ParetoLogic Registration.job
2009-05-04 16:55 . 2005-04-22 11:48 ——– d–h–w c:\program files\InstallShield Installation Information
2009-05-04 07:35 . 2009-03-24 08:35 472 —-a-w c:\windows\Tasks\Ad-Aware Update (Weekly).job
2009-05-03 09:16 . 2007-09-01 10:15 ——– d—–w c:\program files\Steam
2009-04-27 16:04 . 2005-05-20 06:08 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-04-27 16:00 . 2009-04-26 08:28 458 —-a-w c:\windows\Tasks\ParetoLogic Anti-Virus PLUS_dbsummary.job
2009-04-26 08:28 . 2009-04-26 08:28 482 —-a-w c:\windows\Tasks\ParetoLogic Anti-Virus PLUS.job
2009-04-24 22:23 . 2009-04-24 22:23 43 —-a-w c:\documents and settings\Emilio Zubiete\Application Data\~ygw.tmp
2009-04-21 18:25 . 2008-08-20 08:26 284 —-a-w c:\windows\Tasks\AppleSoftwareUpdate.job
2009-04-21 13:44 . 2009-03-24 08:35 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-04-17 16:41 . 2009-02-10 15:12 ——– d—–w c:\program files\TomTom HOME 2
2009-04-09 18:58 . 2005-05-18 10:47 ——– d—–w c:\program files\iTunes
2009-04-09 18:57 . 2007-06-29 19:03 ——– d—–w c:\program files\Common Files\Apple
2009-03-24 08:32 . 2008-01-18 09:52 ——– d—–w c:\program files\Lavasoft
2009-03-24 08:32 . 2005-05-07 14:57 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-03-22 14:20 . 2009-03-22 14:20 291 —-a-w c:\windows\PowerReg.dat
2009-03-20 10:02 . 2006-04-06 08:43 ——– d—–w c:\program files\Symantec
2009-03-20 10:02 . 2008-12-04 12:15 805 —-a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-03-20 10:02 . 2008-12-04 12:15 7386 —-a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-03-20 10:02 . 2008-12-04 12:15 60808 —-a-w c:\windows\system32\S32EVNT1.DLL
2009-03-20 10:02 . 2008-12-04 12:15 124464 —-a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-19 17:05 . 2008-09-12 19:29 ——– d—–w c:\program files\QuickTime
2009-03-19 14:32 . 2008-01-29 10:01 23400 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-18 07:31 . 2005-04-27 19:25 ——– d—–r c:\program files\Skype
2009-03-13 18:20 . 2005-04-22 21:17 147136 —-a-w c:\documents and settings\Emilio Zubiete\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-13 13:43 . 2005-04-25 20:41 ——– d—–w c:\program files\Common Files\Adobe
2009-03-13 10:08 . 2005-04-22 18:20 147136 —-a-w c:\documents and settings\Begona Franco\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-13 07:57 . 2009-03-13 07:56 ——– d—–w c:\program files\EurocamSuite PRO 9
2009-03-12 09:03 . 2009-03-20 21:27 36400 —-a-r c:\windows\system32\drivers\SymIM.sys
2009-03-09 19:06 . 2009-03-30 07:30 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-03-08 13:16 . 2008-02-20 22:16 ——– d—–w c:\program files\Azureus
2009-03-06 14:22 . 2002-09-03 16:51 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2005-02-18 14:19 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-08-04 07:56 78336 —-a-w c:\windows\system32\ieencode.dll
2009-02-18 12:43 . 2009-02-18 12:43 243024 —-a-w c:\windows\system32\LSPInstall.dll
2009-02-18 12:43 . 2009-02-18 12:43 111960 —-a-w c:\windows\system32\INetHTTPFilter.dll
2009-02-15 15:30 . 2007-07-10 18:02 138584 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-02-15 15:30 . 2007-07-10 17:48 70968 —-a-w c:\windows\system32\PnkBstrA.exe
2009-02-15 15:30 . 2007-07-10 17:48 189672 —-a-w c:\windows\system32\PnkBstrB.exe
2009-02-09 12:10 . 2002-09-03 16:39 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2005-01-14 05:33 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2002-09-03 16:49 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2002-09-03 16:27 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2002-09-03 17:11 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-06 18:34 . 2009-02-06 18:34 308616 —-a-w c:\windows\WLXPGSS.SCR
2009-02-06 17:52 . 2009-02-06 17:52 49504 —-a-w c:\windows\system32\sirenacm.dll
2009-02-06 17:08 . 2009-02-21 21:35 55152 —-a-w c:\windows\system32\drivers\fssfltr_tdi.sys
2009-02-06 11:11 . 2002-09-03 16:59 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2002-09-03 16:50 2145280 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2002-09-03 16:58 35328 —-a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2002-08-29 01:04 2023936 —-a-w c:\windows\system32\ntkrnlpa.exe
2005-04-28 16:24 . 2005-04-28 12:42 9517 —-a-w c:\program files\hijackthis.log
2004-02-25 16:35 . 2005-10-12 09:35 90 —-a-w c:\program files\Sonic MyDVD Studio Deluxe 5 - serial #.txt
2002-09-03 17:07 . 2002-09-03 17:07 94784 –sha-w c:\windows\TWAIN.DLL
2008-04-14 00:12 . 2002-09-03 17:07 50688 –sha-w c:\windows\twain_32.dll
2008-04-14 00:12 . 2002-09-03 16:46 413696 –sha-w c:\windows\system32\msvcp60.dll
2008-04-14 00:12 . 2002-09-03 16:51 84992 –sha-w c:\windows\system32\olepro32.dll
2008-04-14 00:12 . 2002-09-03 16:56 11776 –sh–w c:\windows\system32\regsvr32.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-05-06_21.19.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-06 22:01 . 2009-05-06 22:01 16384 c:\windows\Temp\Perflib_Perfdata_6e8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-11 68856]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-03-06 24095528]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"ISUSPM Startup"="c:\progra~1\common~1\instal~1\update~1\isuspm.exe" [2004-07-27 221184]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-04-21 516440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-24 132496]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-06-13 528384]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"RevolteMediaDetector"="c:\program files\Colormailer\Photo Manager\MediaDetector.exe" [2005-02-09 69632]
"NBKeyScan"="c:\program files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe" [2007-03-26 1185328]
"Motive SmartBridge"="c:\progra~1\CABLEC~1\SMARTB~1\DExec.exe" [2005-03-10 69632]
"LVCOMS"="c:\program files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2001-09-24 98304]
"hplampc"="c:\windows\system32\hplampc.exe" [2002-01-17 40448]
"HPHmon03"="c:\windows\system32\hphmon03.exe" [2001-10-25 311296]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-25 196608]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"EVENTLISTENER"="c:\program files\Common Files\FotoNation\EvLstnr.exe" [2000-06-20 53248]
"CXMon"="c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2001-09-19 45056]
"CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-09-11 53248]
"CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-29 45056]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2006-03-10 684032]
"ParetoLogic Anti-Virus PLUS"="c:\program files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.lnk" [2009-05-06 2355]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CtHelper.exe [2002-09-03 24576]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Begona Franco\Start Menu\Programs\Startup\
Recorte de pantalla e Inicio r pido de OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]

c:\documents and settings\Emilio Zubiete\Start Menu\Programs\Startup\
Microsoft Office Groove.lnk - c:\program files\Microsoft Office\Office12\GROOVE.EXE [2007-8-29 340856]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Búsqueda en el escritorio de Windows.lnk]
backup=c:\windows\pss\Búsqueda en el escritorio de Windows.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^cablecom assistant.lnk]
backup=c:\windows\pss\cablecom assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Gigaset WLAN Adapter Monitor.lnk]
backup=c:\windows\pss\Gigaset WLAN Adapter Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
backup=c:\windows\pss\Picture Package Menu.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Begona Franco^Start Menu^Programs^Startup^Picture Motion Browser Media Check Tool.lnk]
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Gorka Zubiete^Start Menu^Programs^Startup^Xfire.lnk]
backup=c:\windows\pss\Xfire.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Valve\\Steam\\Steam.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Games\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Octoshape Streaming Services\\Begona Franco\\OctoshapeClient.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

R1 sonypvd3;Sony DVD Handycam;c:\windows\system32\DRIVERS\sonypvd3.sys [2004-12-07 64964]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-04-21 953168]
R3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [2001-10-25 18864]
R3 fsssvc;Windows Live Protección Infantil;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2008-05-17 13352]
R3 hp4200c;%usbscan.SvcDesc%;c:\windows\system32\DRIVERS\hp4200c.sys [2001-02-18 9312]
R3 s125bus;Sony Ericsson Device 125 driver (WDM);c:\windows\system32\DRIVERS\s125bus.sys [2007-04-24 83336]
R3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s125mdfl.sys [2007-04-24 15112]
R3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s125mdm.sys [2007-04-24 108680]
R3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s125mgmt.sys [2007-04-24 100488]
R3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s125obex.sys [2007-04-24 98696]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-04-21 64160]
S0 sonypvl3;sonypvl3; [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SYMEFA.SYS [2009-03-12 310320]
S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\Drivers\NIS\1005000.087\BHDrvx86.sys [2009-03-12 258608]
S1 ccHP;Symantec Hash Provider;c:\windows\System32\Drivers\NIS\1005000.087\ccHPx86.sys [2009-03-20 482352]
S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090420.001\IDSxpx86.sys [2009-01-29 276344]
S1 sonypvf3;sonypvf3; [x]
S1 sonypvt3;sonypvt3; [x]
S2 fssfltr;fssfltr;c:\windows\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
S2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [2009-03-12 115560]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-04-08 92008]
S2 ZeppelinService;plasservice;c:\program files\Common Files\ParetoLogic\PLAS\plasservice.exe [2009-02-18 587216]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-25 101936]
S3 QCPro;Logitech QuickCam Pro USB(PID_D001);c:\windows\system32\DRIVERS\p35u.sys [2001-09-24 116448]


— Other Services/Drivers In Memory —

*Deregistered* - uphcleanhlp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2734bad4-1335-11da-8d86-0007e9dffe90}]
\Shell\AutoRun\command - G:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6853e4ff-f77f-11dd-973e-0007e9dffe90}]
\Shell\AutoRun\command - G:\InstallTomTomHOME.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b5fdc48d-c36e-11db-921a-0007e9dffe90}]
\Shell\AutoRun\command - G:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d18d2e8a-c29d-11db-9218-0007e9dffe90}]
\Shell\AutoRun\command - G:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder

2009-05-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 13:44]

2009-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 10:34]

2009-04-26 c:\windows\Tasks\ParetoLogic Anti-Virus PLUS.job
- c:\program files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.exe [2009-02-18 12:43]

2009-04-27 c:\windows\Tasks\ParetoLogic Anti-Virus PLUS_dbsummary.job
- c:\program files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.exe [2009-02-18 12:43]

2009-05-06 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2008-02-22 10:25]

2009-05-06 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2008-02-22 10:25]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://uk.yahoo.com
uInternet Settings,ProxyOverride = *.local
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java
DPF: {B6F0855B-A06D-498B-A537-80AFF04A1B4E} - hxxps://www.telefonicaonline.com/o1/http/WSClient.cab
FF - ProfilePath - c:\documents and settings\Begona Franco\Application Data\Mozilla\Firefox\Profiles\o86dfyis.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-07 00:51
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-606747145-1547161642-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\:õwjY*]
"DisplayName"="\09"
"DeviceDesc"="\09"
"ProviderName"=""
"MFG"="?"
"ReinstallString"="2002, 6.13.10.6143"
"DeviceInstanceIds"=multi:"\00"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(656)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-05-06 0:54
ComboFix-quarantined-files.txt 2009-05-06 22:54
ComboFix2.txt 2009-05-06 21:36

Pre-Run: 45,092,130,816 bytes free
Post-Run: 45,126,819,840 bytes free

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
351 — E O F — 2009-04-17 16:45


The HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:59:06, on 07/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Common Files\ParetoLogic\PLAS\plasservice.exe
C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Colormailer\Photo Manager\MediaDetector.exe
C:\Program Files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe
C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\FotoNation\EvLstnr.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\PROGRA~1\CABLEC~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Begona Franco\Desktop\HJTInstall.exe
C:\WINDOWS\system32\SearchProtocolHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://latam.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {06663B56-0D73-4f9f-BCC5-4AA941470AFD} - (no file)
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL (file missing)
N4 - Mozilla: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\BEGONA FRANCO\Application Data\Mozilla\Profiles\default\81f2bvtn.slt\prefs.js)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Aplicación auxiliar de inicio de sesión - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (file missing)
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (file missing)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [RevolteMediaDetector] C:\Program Files\Colormailer\Photo Manager\MediaDetector.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\CABLEC~1\SMARTB~1\DExec.exe 180000 C:\PROGRA~1\CABLEC~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [hplampc] C:\WINDOWS\system32\hplampc.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EVENTLISTENER] C:\Program Files\Common Files\FotoNation\EvLstnr.exe
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [ParetoLogic Anti-Virus PLUS] "C:\Program Files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.lnk" -NM -hidesplash
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Recorte de pantalla e Inicio rápido de OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Recorte de pantalla e Inicio rápido de OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: Recorte de pantalla e Inicio rápido de OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Agregar entrada - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Agregar entrada en Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (IPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/qtinstall.info.app…meInstaller.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://begoena.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/DE-CH/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1114180811671
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147277982296
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B6F0855B-A06D-498B-A537-80AFF04A1B4E} (WSClientCtl Class) - https://www.telefonicaonline.com/o1/http/WSClient.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca12.custhelp.com/7530-b327h/rnl/java/RntX.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/install/gtdownde.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by112fd.bay112.hotmail.msn.com/activex/HMAtchmt.ocx
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: plasservice (ZeppelinService) - ParetoLogic Inc. - C:\Program Files\Common Files\ParetoLogic\PLAS\plasservice.exe

–
End of file - 19679 bytes
No, only Symantec. I also have the free version of Lavasoft Ad-Aware Anniversary Edition that has Ad-wacht live. ParetoLogic\Anti-Virus PLUS is one of the programs I downloaded when this happened but was unable to run it because I needed internet connection. It started to connect after the first time running Combofix, when the internet connection started. I was waiting for the log to be prepared and I was supposed not to run any program so the only way I saw to stop it was disabling internet connection.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI