A few things:
Prevx, and I think pxscan, are from an online scanner I tried after Kaspersky online scanner failed to load. It quickly got on my nerves with constant pop-up reminders to buy, and is gone.
Although it says Sophos anti-virus is running, at this point the main Sophos .exe file was corrupt, so while it may have had some pieces running, it was not protecting anything, and I could not disable it for Combofix.
ComboFix 09-04-04.01 - OLIVASED 2009-04-09 10:09:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1601 [GMT -5:00]
Running from: c:\documents and settings\OLIVASED\Desktop\Combo-Fix.exe
AV: Sophos Anti-Virus *On-access scanning enabled* (Outdated)
FW: Sophos Client Firewall *enabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\OLIVASED\Application Data\drivers\downld
c:\documents and settings\OLIVASED\Application Data\drivers\downld\23473640.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\23475203.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\23475765.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\23711015.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\23715250.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\23717625.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\23765843.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\23932515.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\23935000.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\23935390.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\23978781.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\23981875.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\23983031.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24383265.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24385312.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24385546.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24390968.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24393578.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24394296.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24398906.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24400906.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24400953.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24418093.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24423187.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24424359.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24425703.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24482671.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24487000.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24489484.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24551281.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24555328.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24555750.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24564359.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24565859.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24566015.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24745437.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24752187.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24752984.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24829656.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24842046.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24850875.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24852796.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24859968.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24862078.exe
c:\documents and settings\OLIVASED\Application Data\drivers\downld\24862250.exe
c:\documents and settings\OLIVASED\Application Data\drivers\wfsintwq.sys
c:\documents and settings\OLIVASED\Application Data\drivers\winupgro.exe
c:\documents and settings\OLIVASED\Application Data\m
c:\documents and settings\OLIVASED\Application Data\m\flec006.exe
c:\documents and settings\OLIVASED\Application Data\m\list.oct
c:\documents and settings\OLIVASED\Application Data\m\shared\3D Ikebana Screensaver 4.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\3DCombine 3.4.1 Crack.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Activation.Symantec.Norton.Systeme.Works.2007.Avec.Crack.&.Super.News.2007.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Advanced Business Card Maker 4.0 (Key+Serial).zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Agenda Organizer Deluxe 2.8 (Serial).zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Agent Card Maker 1.20 Build 040722.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Agogo DVD To PSP Video Converter 6.91.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Agree Free Mobile 3GP MP4 MPEG4 Video Converter 4.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\AlacartE 4.62.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\AlarmClock Gadget 1.0.0.216.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Apexico VAT-Books 1.2.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Arc Menu 5.3a (KeyGen).zip
c:\documents and settings\OLIVASED\Application Data\m\shared\ArGoSoft Time Synchronizer 1.0.0.6.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Assistant Tech Admin Tool 1.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\ASTsearch Toolbar 1.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Auction Kung Fu 1.2.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Avex DVD to iPod Converter 4 build 05.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Avg.Anti-Virus.v7.1.394.757.Incl.Keygen-Ssg.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\AVS DVD Player 2.4.4.144.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Bible Max 1.3.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Bill Gates Eyes 1.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Bound Around 1.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\CanonWebcam 1.0.0.51.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\CD to iPod Solution 6.4.3.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Chaos Sync 2.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Character-Building Thought Power 1.0 [Serial].zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Christersson SendFile 2.0.6 for Sony Ericsson [KeyGen].zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Clip Color 1.0.5.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Collectorz.com MP3 Collector 2.2.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\CompuApps OnBelay 2.0 build 012.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\ConnectCode Barcode Font Pack 3.0 (Key+Serial).zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Convert XLS To Any 2.6 (Patch).zip
c:\documents and settings\OLIVASED\Application Data\m\shared\CRM Customer Portal 3.0.2.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\cryptlib 3.1.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\dataPro 1.5.6.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\DentSuite 1.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Desktop Christmas Tree 1.12.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\DigiCat 1.03h.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\DomainInspect 1.6.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Dragonfly Chart .Net 2.000.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Earthsim 1.9.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\EasyCollage (Home Edition) 1.6 [Key+Serial].zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Email Director 9.2.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\EmailMarketingAssistant Pro 1.1.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Embird Alphabet 17 1.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Excel Invoice Manager Platinum 2.8.1012 (With Crack).zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Flash Terminal 4.2.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\FlexCls Express 1.7.10.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Font Manager 3.53 [Serial].zip
c:\documents and settings\OLIVASED\Application Data\m\shared\FreeSecurity 1.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\FunkyBit 3GP Video Converter 1.2 (Patch).zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Gas Station Software 4.1 (Patch).zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Gather Items CMM 2.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Graph Plotter 2.5 Serial.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\HandyFind 2.0.6.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Hide Folders XP 2.9.8.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\HiFi WAV Cutter 1.00.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\HistoryKill Shot & PopUp Killer Pro 3.032.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\HumanityThunder 3.1.1028 (Key).zip
c:\documents and settings\OLIVASED\Application Data\m\shared\IB LogManager Viewer 2.6.0.2.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\iMacros Web Automation and Web Testing 6.12.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\ImTOO Video to Audio Converter 3.1.53.0321b.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Indiecom Services (001582676-A) 2.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\InfoRSS 1.1.4.2.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Insulated Concrete Forms 1.00.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Intrinsic Value Investing Training Wizard 3.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Invisible Secrets 4.6.1 [Serial].zip
c:\documents and settings\OLIVASED\Application Data\m\shared\iPlayAnywhere for iTunes 4.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\iWellsoft 3GP Video Converter 1.3.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Jet DVD Ripper 1.4 (Patch).zip
c:\documents and settings\OLIVASED\Application Data\m\shared\JPEGCompressor 1.0 [Key].zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Keyboard Layout Manager 2.90.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\LingvoSoft Suite 2008 German - Russian 2.1.28.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\LyricGrabber 0.8.4.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\MagicPDF 2.01.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\MDTeleText 0.62.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\MetaLAN 2 Beta [KeyGen].zip
c:\documents and settings\OLIVASED\Application Data\m\shared\MetaTags 2.3.5.2.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\MobileDJ Pro 1.03 (KeyGen).zip
c:\documents and settings\OLIVASED\Application Data\m\shared\MSDict Pocket Oxford Dictionary and Thesaurus (Pocket PC) 4.40.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\MSN Emoticons Plus 3.2.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\MSN Monitor Pro & MSN Sniffer 2.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\MySQLDirect .NET Data Provider 4.00 Key.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Need4 iPod Converter 5.6.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Net Logger Pro 2.06.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Nitro PDF Professional 4.91.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\NOD32.2.70.23.[Inglés][by.verdugofinal].zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Notepad GTI 1.904.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Pamela for Skype Standard Version 1.36 (Cracked).zip
c:\documents and settings\OLIVASED\Application Data\m\shared\PaxKel Christmas 2.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Pops 0.1.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Portable Key Launch 1.71.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Pragma Fortress SSH Server.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\PrinterJob 2.0.2.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Profit Percent Calculator 1.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\QRCode 2D Barcode ActiveX 3.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Quick Pallet Maker 4.1.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\RAUL 1.0.3.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\ReportMaker 4.15.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Ro-En Translator 1.1.0.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Rock Collector 1.0 (Crack).zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Rubber Ducky System Monitor 1.11.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Safelist Marketing eCourse 3.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Secura Backup Home Edition 2.13.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Serial.Prevx1.41.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Shutdown Monster 4.0.5.2.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Siteheart 0.2.1.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Slingo Casino Pak 1.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\SmartList To Go 3.0.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Softcode Analog Clock 1.3b.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\SOPHOS.ANTIVIRUS.V3.88.NTW2KXP.Multilanguage-FeDEX.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Space Exploration 3D Screensaver 1.0 [Crack].zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Spell Maestro 2.2.7 (Key+Serial).zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Spellway Hotkey Assistant 1.65.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Spider-Man 2 Trailer.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\StepVoice Recorder 1.4.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Symantec.Norton.Ghost.10.Spanish.part06.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\TAMP 1.04.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\The Big Bang Screensaver.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Timaeus 6.0.5 [Cracked].zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Universe Wars Extension 1.17.11.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Unreal Tournament 2004 Sniper Arena 2K4 mod.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Visual Paradigm for UML Enterprise Edition 5.2.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Web Printer 1.2 [Patch].zip
c:\documents and settings\OLIVASED\Application Data\m\shared\Weld Cost Calc XL 1.0.2.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\WiFi Signal 2.7.1.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\WinGraphic 2.1.1.zip
c:\documents and settings\OLIVASED\Application Data\m\shared\WinTiles 1.2.zip
c:\documents and settings\OLIVASED\Application Data\m\srvlist.oct
c:\windows\system32\ban_list.txt
c:\windows\system32\mdelk.exe
c:\windows\system32\mdm.exe
c:\windows\system32\wintems.exe
d:\users\OLIVASED\My Documents\iridium.exe
----- BITS: Possible infected sites -----
hxxp://wsus.ad.ge.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SROSA
-------\Legacy_SROSA
-------\Service_sK9Ou0s
((((((((((((((((((((((((( Files Created from 2009-03-09 to 2009-04-09 )))))))))))))))))))))))))))))))
.
2009-04-09 09:22 . 2009-04-09 10:03 <DIR> d-------- c:\windows\BDOSCAN8
2009-04-09 09:05 . 2009-04-09 09:05 <DIR> d-------- c:\program files\Prevx
2009-04-09 09:05 . 2009-04-09 10:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-04-09 09:05 . 2009-04-09 09:05 22,024 --a------ c:\windows\system32\drivers\pxscan.sys
2009-04-09 09:05 . 2009-04-09 09:05 39 --a------ c:\windows\wininit.ini
2009-04-09 07:38 . 2009-04-09 07:55 <DIR> d-------- c:\documents and settings\OLIVASED\Application Data\HouseCall 6.6
2009-04-09 06:16 . 2009-04-09 10:11 <DIR> d--h----- c:\documents and settings\OLIVASED\Application Data\drivers
2009-04-09 00:48 . 2009-04-09 00:48 <DIR> d-------- c:\program files\LEAD Technologies
2009-04-09 00:48 . 2008-05-20 20:05 1,855,488 --a------ c:\windows\system32\LFDJV14n.dll
2009-03-29 11:08 . 2008-04-04 21:00 147,456 --a------ c:\windows\system32\hpcpn5r1.dll
2009-03-29 11:05 . 2009-03-29 11:05 <DIR> d-------- C:\HP LJP3005 PCL6 Driver
2009-03-23 11:25 . 2009-03-23 11:25 <DIR> d-------- c:\windows\system32\Adobe
2009-03-09 13:24 . 2009-03-09 13:24 <DIR> d-------- c:\program files\ENDFORCE
2009-03-09 13:24 . 2009-03-09 13:24 <DIR> d-------- c:\program files\Common Files\PostureAgent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-09 14:59 --------- d-----w c:\program files\Symantec
2009-04-09 12:31 --------- d-----w c:\program files\Nortel Networks
2009-04-09 12:12 --------- d-----w c:\program files\eMule
2009-04-09 05:48 --------- d--h--w c:\program files\InstallShield Installation Information
2009-04-07 04:53 --------- d-----w c:\program files\SafeBoot
2009-03-23 16:37 --------- d-----w c:\program files\CIMPLICITY Machine Edition
2009-03-18 23:36 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-02-27 14:16 --------- d-----w c:\program files\Hewlett-Packard
2009-02-26 21:51 --------- d-----w c:\program files\Oracle
2009-02-12 18:46 --------- d-----w c:\program files\Java
2007-03-02 14:52 961,160 ----a-w c:\documents and settings\All Users\Application Data\NXPowerLite.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-16 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-16 155648]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-16 131072]
"PDVDDXSrv"="c:\progra~1\CYBERL~1\POWERD~1\PDVDDX~1.EXE" [2006-10-20 118784]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-09 2183168]
"SBMGRNT.EXE"="c:\progra~1\SafeBoot\SBMGRNT.EXE" [2008-05-16 49212]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-07-20 1228800]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SCFTrayStartUp"="c:\program files\Sophos\Sophos Client Firewall\SCFTray.exe" [2009-04-09 224296]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-12 148888]
"ENDFORCEAgent"="c:\program files\ENDFORCE\AgntTray.exe" [2007-12-21 1646592]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 c:\windows\STSYSTRA.EXE]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A81300000003}\IconAC76BA86.exe [2008-11-13 300032]
AutoUpdate Monitor.lnk - c:\program files\Sophos\AutoUpdate\ALMon.exe [2007-10-26 245760]
Workstation Status Monitor.lnk - c:\program files\GE Energy\WorkstationST Features\WorkstationStatusMonitor.exe [2008-07-22 65536]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLogonScripts"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceStartMenuLogOff"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\CAF]
2008-02-29 20:13 27400 c:\program files\Ca\DSM\bin\cfWlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-857407748-547254352-1705232-22426\Scripts\Logon\
0\
0]
"Script"=CAUnicenterR11CheckV3.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-857407748-547254352-1705232-22426\Scripts\Logon\1\
0]
"Script"=PSAMERLogonScript.vbs
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Woodward\\Control Assistant 3\\ctrlassist.exe"=
"c:\\Program Files\\Woodward\\Watch Window II\\WatchWindowII.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5556:TCP"= 5556:TCP:SafeBoot
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2009-04-09 22024]
R0 SafeBoot;SafeBoot;c:\windows\system32\drivers\safeboot.sys [2008-05-16 30267]
R0 SBAlg;SBAlg;c:\windows\system32\drivers\sbalg.sys [2008-05-16 44848]
R1 RsvLock;RsvLock;c:\windows\system32\drivers\rsvlock.sys [2008-05-16 4752]
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [2008-11-17 101120]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [2008-11-17 33408]
R1 SBFlop;SBFlop;c:\windows\system32\drivers\sbflop.sys [2008-05-16 6096]
R1 SbPrcCtl;SbPrcCtl;c:\windows\system32\drivers\sbprcctl.sys [2008-05-16 14864]
R2 caf;CA DSM r11 Common Application Framework.;c:\program files\Ca\DSM\bin\CAF.exe [2008-02-29 193800]
R2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [2009-04-09 4414520]
R2 DataHistorian;Data Historian;c:\progra~1\GECONT~1\DATAHI~1\DataHistorian.exe [2008-11-13 450645]
R2 DBServer;SDB Server;c:\progra~1\GECONT~1\SDB_SE~2\DBServer.exe [2008-11-13 274432]
R2 EgdCfg;GE EGD Configuration Server;c:\program files\GE Energy\EgdCfgServer\EgdCfgServer.exe [2008-07-22 32768]
R2 ENDFORCE Agent API;ENDFORCE Agent API;c:\program files\ENDFORCE\AgentAPI.exe [2007-12-19 2945024]
R2 FiberlinkMonitor;Fiberlink Monitor Service;c:\program files\Fiberlink\Extend360\WENGINE\wmonitor.exe [2005-05-06 65604]
R2 GeCssOpcAEServer;GeCssOpcAEServer;c:\program files\GE Energy\WorkstationST Features\GeCssOpcAEServer.exe [2008-07-22 77824]
R2 SafeBootConfigurationManager;SafeBoot Configuration Manager;c:\program files\SafeBoot\sbmgrnt.exe [2008-05-16 49212]
R2 WorkstationSTservice;Ge WorkstationSTservice;c:\program files\GE Energy\WorkstationST Features\WorkstationSTservice.exe [2008-07-22 81920]
R3 BW2NDIS5;BW2NDIS5;c:\windows\system32\drivers\BW2NDIS5.SYS [2004-11-01 17536]
R3 Eacfilt;Eacfilt Miniport;c:\windows\system32\drivers\eacfilt.sys [2008-05-14 9433]
S0 black;black;c:\windows\system32\drivers\BlackDrv.sys --> c:\windows\system32\drivers\BlackDrv.sys [?]
S1 scfdriver;SCF Kernel Driver;\??\c:\windows\system32\Drivers\scfdriver.sys --> c:\windows\system32\Drivers\scfdriver.sys [?]
S2 GeCssOpcServer;Ge Css Opc Server;c:\program files\GE Energy\GeCssOpcServer\GeCssOpcServer.exe [2008-07-22 45056]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [2008-05-14 115680]
S2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2008-11-17 69632]
S2 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [2008-11-17 98304]
S2 Sophos Client Firewall Manager;Sophos Client Firewall Manager;c:\program files\Sophos\Sophos Client Firewall\SCFManager.exe [2009-04-04 109608]
S2 Sophos Client Firewall;Sophos Client Firewall;c:\program files\Sophos\Sophos Client Firewall\SCFService.exe [2009-04-04 93224]
S3 CA_LIC_CLNT;CA-License Client;c:\windows\LIC98RMT.exe [2003-08-06 73728]
S3 CA_LIC_SRVR;CA-License Server;c:\windows\LIC98RMTD.exe [2003-08-06 73728]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys --> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [?]
S3 ExtranetAccess;Contivity VPN Service;c:\program files\Nortel Networks\Extranet_serv.exe [2008-05-14 630784]
S3 ICN Service;EGD Service Control System Solutions;c:\progra~1\GECONT~1\ICN_SE~1\ICNService.exe [2008-11-13 77824]
S3 LiveDataServer;LiveDataServer;c:\progra~1\GECONT~1\DATAHI~1\LiveDataServer.exe -SS --> c:\progra~1\GECONT~1\DATAHI~1\LiveDataServer.exe -SS [?]
S3 RapFile;RapFile;c:\windows\system32\drivers\RapFile.sys [2006-11-03 36676]
S3 RapNet;RapNet;c:\windows\system32\drivers\RapNet.sys [2006-11-03 24344]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{02d7e951-9f6e-11dd-946a-444553544200}]
\Shell\AutoRun\command - G:\DTVaultPrivacy.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0ca4a5e2-8ec9-11db-9d25-806d6172696f}]
\Shell\AutoRun\command - e:\programs\nu2menu\nu2menu.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3195f28-29e0-11dd-940b-444553544200}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa0210f2-1b8f-11de-94ed-444553544200}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Flash 9.0.159.0]
c:\windows\Options\Packages\Specapps\Adobe_Flash_9.0.159.0\Install.exe /V9 /S
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1D2908F4-2CC5-4F72-BAFF-9026CF04C227}]
%systemroot\system32\msiexec.exe /i %systemroot%\options\packages\coreapps\pcinfo\pcinfo.msi /qb!
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{257AC5ED-A013-4E10-B3C0-099F5E8D8FC2}]
%Sytemroot%\system32\msiexec.exe /i %Systemroot%\options\pacakges\coreapps\TSG Proxy\TSG Proxy Button.msi /qn
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{27B3FC9C-0096-4590-85B5-FF334D432C8D}]
c:\windows\system32\msiexec.exe /i c:\windows\options\packages\coreapps\MekkoGraphics3\MekkoGraphics3.msi Transforms="c:\windows\options\packages\coreapps\MekkoGraphics3\MekkoGraphics3.mst" /qn
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{621FCD24-4498-4324-A81E-07D331376EDF}]
c:\program files\PixiePack Codec Pack\InstallerHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{AB543DE7-1359-4C70-B0FC-D4BB3AB83D8B}]
c:\windows\system32\msiexec.exe /fomus c:\windows\options\packages\specapps\nxplite3\nxplite301.msi /qb!
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{AC76BA86-7AD7-1033-7B44-A81200000003}]
msiexec.exe /fu {AC76BA86-7AD7-1033-7B44-A81200000003} /qn
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}]
c:\windows\System32\msiexec.exe /fu {C8B0680B-CDAE-4809-9F91-387B6DE00F7C} /qn
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E72B0C-1F6A-4C67-84D8-3F7743B87E37}]
c:\windows\System32\msiexec.exe /i c:\windows\Options\Packages\CoreApps\GETemplates\GETemplatesGEE.msi /qb!
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D9C88940-0322-4E06-AB35-ADC6F01E9AD7}]
c:\windows\system32\msiexec.exe /i c:\windows\options\packages\coreapps\customsettings\geecustset1.msi /qb!
.
Contents of the 'Scheduled Tasks' folder
2009-04-07 c:\windows\Tasks\Workstation.job
- c:\program files\Sophos\Sophos Anti-Virus\BackgroundScanClient.exe [2008-11-17 07:47]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-IridiumTimeWizard - d:\users\OLIVASED\My Documents\iridium.exe
HKLM-Run-AuditMode - c:\sysprep\factory.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: {{7107766B-746A-4B6F-8356-8CF9EA743708} - c:\program files\TSG Proxy\Proxy.exe c:\program files\TSG Proxy\Proxy.exe
Trusted Zone: ge-registrar.com
Trusted Zone: ge.com
Trusted Zone: ge.com\*.supportcentral
Trusted Zone: ge.com\cincnt1.ssqc
Trusted Zone: ge.com\cincnt2.ssqc
Trusted Zone: ge.com\genet.ae
Trusted Zone: ge.com\inside
Trusted Zone: ge.com\libraries
Trusted Zone: ge.com\ssqc
Trusted Zone: ge.com\time.infra
TCP: {67618DDB-01D1-43C3-8CC4-72CD9F4D3412} = 195.219.14.20,66.110.61.66
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabDPF: {CAFECAFE-0013-0001-0029-ABCDEFABCDEF} - hxxp://gpserplb01.corporate.ge.com:8040/jinitiator/oajinit.exe
DPF: {CAFECAFE-0013-0001-0030-ABCDEFABCDEF} - hxxp://gpserplb01.corporate.ge.com:8040/jinitiator/oajinit.exe
.
.
------- File Associations -------
.
inifile=%SystemRoot%\System32\NOTEPAD.EXE %1"
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-09 10:17:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sophos Message Router]
"ImagePath"="\"c:\program files\Sophos\Remote Management System\RouterNT.exe\" -service -name Router -ORBListenEndpoints iiop://:8193/ssl_port=8194"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1652)
c:\windows\system32\BCMLogon.dll
c:\program files\CA\DSM\Bin\cfwlogon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\windows\system32\scardsvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Ca\SC\CAM\bin\cam.exe
c:\program files\GE Fanuc\GE Fanuc Licensing\CCFLIC0.exe
c:\windows\system32\Crypserv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\LckFldService.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\program files\Sophos\Remote Management System\ManagementAgentNT.exe
c:\program files\Sophos\Remote Management System\RouterNT.exe
c:\program files\SigmaTel\C-Major Audio\WDM\STACSV.EXE
c:\windows\system32\wdfmgr.exe
c:\program files\Ca\DSM\bin\cfsmsmd.exe
c:\program files\Ca\DSM\bin\ccnfAgent.exe
c:\program files\Ca\DSM\bin\cfnotsrvd.exe
c:\program files\Ca\DSM\bin\ccsmagtd.exe
c:\program files\Ca\DSM\bin\amswmagt.exe
c:\program files\Ca\DSM\PMAgent\capmuamagt.exe
c:\program files\Ca\DSM\bin\cfFTPlugin.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Apoint\hidfind.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-04-09 10:21:52 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-09 15:21:50
Pre-Run: 19,283,714,048 bytes free
Post-Run: 19,123,331,072 bytes free
447 --- E O F --- 2008-12-13 16:03:50