ComboFix 09-05-22.07 - abdullah 05/23/2009 13:59.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1256.966.1033.18.3066.2356 [GMT 3:00]
Running from: c:\users\abdullah\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\bcmwlrmt.dll
.
((((((((((((((((((((((((( Files Created from 2009-04-23 to 2009-05-23 )))))))))))))))))))))))))))))))
.
2009-05-23 11:01 . 2009-05-23 11:02 -------- d-----w c:\users\abdullah\AppData\Local\temp
2009-05-23 05:51 . 2009-05-23 05:51 -------- d-----w C:\$WINDOWS.~LS
2009-05-23 05:49 . 2009-05-23 06:00 -------- d-----w C:\$UPGRADE.~OS
2009-05-23 05:49 . 2009-05-23 05:49 -------- d-----w C:\$WINDOWS.~BT
2009-05-22 15:09 . 2009-05-22 15:09 -------- d-----w c:\users\abdullah\AppData\Local\SupportSoft
2009-05-22 13:54 . 2009-05-22 13:54 -------- d-----w c:\users\abdullah\AppData\Roaming\Macrovision
2009-05-22 13:54 . 2009-05-22 13:54 -------- d-----w c:\users\abdullah\AppData\Roaming\ATI
2009-05-22 13:54 . 2009-05-22 13:54 -------- d-----w c:\users\abdullah\AppData\Local\ATI
2009-05-22 13:54 . 2009-05-22 13:54 -------- d-----w c:\users\abdullah\Bluetooth Software
2009-05-22 13:53 . 2009-05-22 13:53 -------- d-----w c:\users\abdullah\AppData\Local\MediaDirect
2009-05-22 13:53 . 2009-05-22 13:53 -------- d-----w c:\users\abdullah\AppData\Roaming\DigitalPersona
2009-05-22 13:53 . 2009-05-22 13:53 -------- d-----w c:\users\abdullah\AppData\Local\DigitalPersona
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-23 11:01 . 2008-10-30 20:31 12 ----a-w c:\windows\bthservsdp.dat
2009-05-22 15:49 . 2008-10-30 20:38 -------- d-----w c:\programdata\McAfee
2009-05-22 15:37 . 2009-05-22 15:37 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-05-22 14:09 . 2008-10-30 20:52 -------- d-----w c:\programdata\Dell
2009-05-22 13:50 . 2009-05-22 13:50 -------- d-----w c:\users\abdullah\AppData\Roaming\Dell
2009-05-22 13:50 . 2009-05-22 13:50 65800 ----a-w c:\users\abdullah\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-22 13:47 . 2009-05-22 13:47 -------- d-sh--w c:\programdata\Templates
2009-05-22 13:47 . 2009-05-22 13:47 -------- d-sh--w c:\programdata\Start Menu
2009-05-22 13:47 . 2009-05-22 13:47 -------- d-sh--w c:\programdata\Favorites
2009-05-22 13:47 . 2009-05-22 13:47 -------- d-sh--w c:\programdata\Documents
2009-05-22 13:47 . 2009-05-22 13:47 -------- d-sh--w c:\programdata\Desktop
2008-10-30 20:44 . 2008-10-30 20:44 74 --sha-r c:\windows\CT4CET.bin
2008-10-31 04:59 . 2008-10-31 04:58 8192 --sha-w c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-10-30 20:48 10536 ----a-w c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickSet.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk
backup=c:\windows\pss\QuickSet.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^abdullah^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk]
path=c:\users\abdullah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
backup=c:\windows\pss\Dell Dock.lnk.Startup
backupExtension=.Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D07D90B4-8992-44AF-A4CB-B4E2039A78FF}"= c:\program files\Dell\MediaDirect\MediaDirect.exe

ell MediaDirect
"{9E6AFF4E-3BC2-4254-AD02-298062AF9431}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{047FF7FE-E681-43EC-8E7A-585B8BB14D0A}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{2531089B-1F73-49C9-886B-99555D8C7510}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{E513760D-0CAF-482B-8064-78F5362370EA}"= UDP:c:\program files\Dell Video Chat\DellVideoChat.exe:SightSpeed
"{FC1ADB25-C89A-46F3-8D20-1741A943F5E0}"= TCP:c:\program files\Dell Video Chat\DellVideoChat.exe:SightSpeed
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f091b975\AEstSrv.exe [31/10/08 08:07 ص 73728]
R2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [05/05/08 07:46 م 1168632]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [02/05/08 04:09 م 161048]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\System32\drivers\ATSwpWDF.sys [31/10/08 08:08 ص 475136]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\System32\drivers\btwl2cap.sys [30/10/08 11:29 م 29736]
R3 itecir;ITECIR Infrared Receiver;c:\windows\System32\drivers\itecir.sys [31/10/08 08:08 ص 54784]
R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\k57nd60x.sys [31/10/08 08:08 ص 203264]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\System32\drivers\OA001Ufd.sys [31/10/08 08:08 ص 144672]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\System32\drivers\OA001Vid.sys [31/10/08 08:08 ص 277504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder
2009-05-22 c:\windows\Tasks\User_Feed_Synchronization-{B1618183-51CE-4C4F-B430-1816D4E402A5}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:34]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyServer = 192.168.150.3:8080
uInternet Settings,ProxyOverride = <local>
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-23 14:03
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(664)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(3512)
c:\windows\system32\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f091b975\stacsv.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\Ati2evxx.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\System32\conime.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\windows\System32\wermgr.exe
c:\windows\System32\msdtc.exe
c:\windows\System32\BCMWLTRY.EXE
c:\windows\System32\WerFault.exe
.
**************************************************************************
.
Completion time: 2009-05-23 14:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-23 11:05
Pre-Run: 117,011,689,472 bytes free
Post-Run: 116,689,367,040 bytes free
145