After running combofix.txt, the problem appears to be fixed. I can change the desktop wallpaper normally. Thank you. I will wait for your all clear log and uninstalling combofix.
Here is my combofix.txt log.
ComboFix 10-04-13.02 - CFPP 04/14/2010 3:38.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1461 [GMT 3:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\OfficeSAS.lnk
C:\restore
.
((((((((((((((((((((((((( Files Created from 2010-03-14 to 2010-04-14 )))))))))))))))))))))))))))))))
.
2010-04-14 00:29 . 2010-04-14 00:29 0 —-a-w- c:\windows\system32\cd.dat
2010-04-13 19:53 . 2010-04-13 19:53 ——– d—–w- c:\program files\Common Files\Skype
2010-04-12 11:02 . 2010-04-12 11:21 ——– d—–w- c:\documents and settings\CFPP\Application Data\Auslogics
2010-04-12 11:02 . 2010-04-12 11:20 ——– d—–w- c:\program files\Auslogics
2010-04-11 11:48 . 2010-04-11 11:48 ——– d—–w- c:\documents and settings\CFPP\Application Data\Malwarebytes
2010-04-11 11:47 . 2010-03-29 21:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-11 11:47 . 2010-04-11 11:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-11 11:47 . 2010-03-29 21:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-11 11:47 . 2010-04-11 11:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-11 11:46 . 2010-04-11 11:46 ——– d—–w- c:\program files\ERUNT
2010-04-11 08:39 . 2010-04-11 08:39 208896 —-a-w- c:\documents and settings\CFPP\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\AutoMaintenance\Images.dll
2010-04-11 08:39 . 2010-04-11 08:39 698511 —-a-w- c:\documents and settings\CFPP\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\AutoMaintenance\AutoMaintenance.dll
2010-04-11 08:39 . 2010-04-11 08:39 750223 —-a-w- c:\documents and settings\All Users\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch2\HTML\AutoMaintenance\AutoMaintenance.dll
2010-04-11 08:39 . 2010-04-11 08:39 208896 —-a-w- c:\documents and settings\All Users\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch2\HTML\AutoMaintenance\Images.dll
2010-04-11 08:39 . 2010-04-11 08:39 698511 —-a-w- c:\documents and settings\All Users\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch1\HTML\AutoMaintenance\AutoMaintenance.dll
2010-04-11 08:39 . 2010-04-11 08:39 208896 —-a-w- c:\documents and settings\All Users\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch1\HTML\AutoMaintenance\Images.dll
2010-04-11 08:39 . 2010-04-11 08:39 ——– d–h–w- c:\documents and settings\CFPP\Application Data\GTek
2010-04-11 08:38 . 2010-04-11 08:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Gtek
2010-04-11 08:38 . 2010-04-11 08:38 ——– d—–w- c:\program files\DellAutomatedPCTuneUp
2010-04-11 08:35 . 2010-04-11 08:35 ——– d—–w- c:\documents and settings\CFPP\Local Settings\Application Data\BVRP Software
2010-04-11 08:35 . 2010-04-11 08:36 ——– d—–w- c:\program files\NetWaiting
2010-04-11 08:34 . 2010-04-11 08:35 ——– d—–w- c:\program files\Digital Line Detect
2010-04-11 07:30 . 2010-04-11 07:30 ——– d—–w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-11 07:30 . 2010-04-11 07:33 ——– d—–w- c:\program files\SpywareBlaster
2010-04-11 07:24 . 2010-04-11 07:24 ——– d—–w- c:\program files\Trend Micro
2010-04-09 22:54 . 2010-04-10 10:46 ——– d—–w- c:\documents and settings\CFPP\Local Settings\Application Data\Deployment
2010-04-08 19:42 . 2010-04-08 19:42 ——– d—–w- c:\program files\CCleaner
2010-04-08 10:39 . 2010-04-08 10:39 ——– d—–w- c:\documents and settings\CFPP\Application Data\JAM Software
2010-04-08 10:39 . 2010-04-08 10:39 ——– d—–w- c:\program files\JAM Software
2010-04-06 22:18 . 2010-04-06 22:18 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-04-06 08:04 . 2010-04-13 23:54 ——– d—–w- c:\documents and settings\CFPP\Application Data\vlc
2010-04-05 21:48 . 2010-04-05 21:48 ——– d—–w- c:\documents and settings\CFPP\Application Data\dvdcss
2010-04-05 21:46 . 2010-04-05 21:46 ——– d—–w- c:\documents and settings\All Users\Application Data\CyberLink
2010-03-31 09:34 . 2010-03-31 09:34 ——– d—–w- c:\program files\Common Files\Java
2010-03-31 09:08 . 2010-03-31 09:08 503808 —-a-w- c:\documents and settings\CFPP\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6652cc86-n\msvcp71.dll
2010-03-31 09:08 . 2010-03-31 09:08 499712 —-a-w- c:\documents and settings\CFPP\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6652cc86-n\jmc.dll
2010-03-31 09:08 . 2010-03-31 09:08 348160 —-a-w- c:\documents and settings\CFPP\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6652cc86-n\msvcr71.dll
2010-03-31 09:08 . 2010-03-31 09:08 61440 —-a-w- c:\documents and settings\CFPP\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6b45d82e-n\decora-sse.dll
2010-03-31 09:08 . 2010-03-31 09:08 12800 —-a-w- c:\documents and settings\CFPP\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6b45d82e-n\decora-d3d.dll
2010-03-30 15:33 . 2010-03-30 16:10 ——– d—–w- c:\program files\Red Alert 2 Yuri's Revenge
2010-03-30 15:25 . 2010-03-30 15:25 ——– d-sh–w- c:\documents and settings\CFPP\Phone Browser
2010-03-30 13:41 . 2010-03-30 13:41 ——– d—–w- c:\documents and settings\CFPP\Local Settings\Application Data\WMTools Downloaded Files
2010-03-18 10:58 . 2010-03-18 10:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-03-18 10:58 . 2010-03-18 10:58 ——– d—–w- c:\documents and settings\CFPP\Application Data\Office Genuine Advantage
2010-03-15 05:29 . 2010-03-15 05:29 ——– d—–r- C:\assembly
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-14 00:41 . 2009-10-18 16:55 ——– d—–w- c:\program files\Symantec AntiVirus
2010-04-13 21:44 . 2009-11-02 06:15 ——– d—–w- c:\documents and settings\CFPP\Application Data\Skype
2010-04-13 19:53 . 2009-11-02 06:13 ——– d—–r- c:\program files\Skype
2010-04-13 19:43 . 2009-11-02 06:16 ——– d—–w- c:\documents and settings\CFPP\Application Data\skypePM
2010-04-13 11:41 . 2009-10-17 02:14 ——– d—–w- c:\documents and settings\CFPP\Application Data\uTorrent
2010-04-11 08:43 . 2009-10-18 19:23 ——– d—–w- c:\documents and settings\CFPP\Application Data\Yahoo!
2010-04-11 08:35 . 2009-03-04 16:04 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-09 23:12 . 2009-03-04 16:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Dell
2010-04-09 23:09 . 2009-03-24 13:53 ——– d—–w- c:\documents and settings\CFPP\Application Data\Dell
2010-04-07 11:51 . 2009-10-15 06:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-06 06:24 . 2009-03-24 13:52 90032 —-a-w- c:\documents and settings\CFPP\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-31 09:06 . 2009-03-04 16:03 ——– d—–w- c:\program files\Java
2010-03-22 05:53 . 2009-11-02 05:56 ——– d—–w- c:\documents and settings\All Users\Application Data\WinZip
2010-03-14 13:17 . 2010-03-14 13:17 118784 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-03-14 13:17 . 2010-03-14 13:17 118784 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-03-14 13:17 . 2010-03-14 13:17 118784 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-03-14 13:17 . 2010-03-14 13:17 118784 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-03-14 13:17 . 2010-03-14 13:17 118784 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-03-14 13:17 . 2010-03-14 13:17 300616 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-03-14 13:17 . 2010-03-14 13:17 329312 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-03-14 13:17 . 2010-03-14 13:17 118784 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-03-14 13:17 . 2009-11-16 19:17 ——– d—–w- c:\program files\Common Files\Real
2010-03-14 13:16 . 2009-11-16 19:17 ——– d—–w- c:\program files\Real
2010-03-14 13:15 . 2010-03-14 13:15 ——– d—–w- c:\program files\Common Files\xing shared
2010-03-14 13:14 . 2006-07-11 23:35 348160 —-a-w- c:\windows\system32\msvcr71.dll
2010-03-14 13:03 . 2009-10-17 02:15 ——– d—–w- c:\program files\uTorrent
2010-03-14 04:25 . 2010-01-06 07:35 ——– d—–w- c:\documents and settings\CFPP\Application Data\Download Manager
2010-03-09 01:28 . 2009-03-04 16:03 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-26 03:09 . 2010-02-26 03:09 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Yahoo!
2010-02-25 06:24 . 2008-04-25 16:16 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 20:49 . 2010-02-24 20:49 ——– d—–w- c:\documents and settings\CFPP\Application Data\SWiSH miniMax3
2010-02-24 20:35 . 2010-02-24 20:35 ——– d—–w- c:\program files\SWiSH miniMax3
2010-02-24 20:35 . 2010-02-24 20:35 ——– d—–w- c:\program files\LameACM
2010-02-24 20:35 . 2010-02-24 20:35 ——– d—–w- c:\program files\Common Files\SWiSHzone.com
2010-02-24 14:37 . 2009-12-22 04:12 ——– d—–w- c:\program files\Common Files\Nokia
2010-02-24 14:34 . 2010-02-24 14:34 ——– d—–w- c:\program files\PC Connectivity Solution
2010-01-15 23:39 . 2009-03-04 16:06 75096 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
2009-11-04 02:12 556432 —-a-w- c:\progra~1\MI1933~1\Office14\URLREDIR.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-06-04 23:04 1144712 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2010-01-03 20:12 218160 —-a-w- c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-04 1144712]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2007-05-10 26144]
"DellAutomatedPCTuneUp"="c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 465136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-02-21 159744]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-21 16855552]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-09-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-09-21 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-09-21 137752]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-12-18 2289664]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2008-02-22 1245184]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-05-29 52840]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2007-10-08 125368]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2009-09-27 83312]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-14 202256]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2010-4-11 50688]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-27 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG111v2 Smart Wizard.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk
backup=c:\windows\pss\NETGEAR WG111v2 Smart Wizard.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WDDMStatus.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WDDMStatus.lnk
backup=c:\windows\pss\WDDMStatus.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WDSmartWare.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WDSmartWare.lnk
backup=c:\windows\pss\WDSmartWare.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^CFPP^Start Menu^Programs^Startup^Microsoft SharePoint Workspace.lnk]
path=c:\documents and settings\CFPP\Start Menu\Programs\Startup\Microsoft SharePoint Workspace.lnk
backup=c:\windows\pss\Microsoft SharePoint Workspace.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 06:57 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 12:58 611712 —-a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2006-11-12 10:48 157592 —-a-w- c:\program files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
2008-08-13 21:04 206064 —-a-w- c:\program files\Dell Support Center\bin\sprtcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-11-10 20:39 5244216 —-a-w- c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
2009-11-06 21:00 2090272 —-a-w- c:\program files\Nokia\Ovi Player\NokiaOviPlayer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2010-02-05 18:45 385856 —-a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeSyncProcess]
2009-11-04 03:06 649072 —-a-w- c:\program files\Microsoft Office\Office14\MSOSYNC.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe [1/9/2010 2:42 AM 285744]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [11/5/2009 4:44 PM 110592]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [6/16/2009 4:58 PM 20480]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [10/18/2009 8:43 PM 102448]
R3 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [3/4/2009 8:51 PM 51288]
R3 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [3/4/2009 8:51 PM 43608]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10/15/2009 9:16 AM 646392]
S3 EraserUtilDrvI3;EraserUtilDrvI3;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI3.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI3.sys [?]
S3 EraserUtilDrvI9;EraserUtilDrvI9;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys [?]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys –> c:\windows\system32\DRIVERS\ivusb.sys [?]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9/26/2009 12:28 PM 4639136]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [10/8/2007 3:48 AM 116664]
S3 USA19H;USA19H;c:\windows\system32\drivers\USA19H2k.sys [3/24/2009 4:57 PM 704000]
S3 USA19H2KP;Keyspan USB Serial Port Driver;c:\windows\system32\drivers\USA19H2kp.sys [3/24/2009 4:57 PM 24192]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [1/14/2010 10:17 AM 11520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vvdsvc REG_MULTI_SZ vvdsvc
.
Contents of the 'Scheduled Tasks' folder
2010-04-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-04-14 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 12:07]
2010-04-14 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1864842960-2535441436-2726737383-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
2010-04-11 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1864842960-2535441436-2726737383-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
2010-04-14 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-06-04 23:04]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = local 127.0.0.1
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - /105
IE: {{898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Nokia FastStart - c:\program files\Nokia\Nokia Music\NokiaMusic.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-14 03:44
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1080)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\System32\BCMLogon.dll
.
Completion time: 2010-04-14 03:47:49
ComboFix-quarantined-files.txt 2010-04-14 00:47
Pre-Run: 88,312,995,840 bytes free
Post-Run: 88,268,320,768 bytes free
- - End Of File - - D42AFD6417F3BBAE0B677ACB9856F05F