Ok.
I have been getting a Rundll error when I turn my computer on:
"Error loading c:\windows\system32\dibiyowa.dll" should I click ok...?
also recieved popup to buy Avira and notification that the program was updated...? Just ignore?
Here's the cobofix report...
ComboFix 09-09-23.02 - Cubby 09/24/2009 17:28.5.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.567 [GMT -4:00]
Running from: c:\documents and settings\cubby.MACDONALDWOOD\Desktop\Combo-Fix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DDNSFILTER
((((((((((((((((((((((((( Files Created from 2009-08-24 to 2009-09-24 )))))))))))))))))))))))))))))))
.
2009-09-23 01:45 . 2009-07-28 20:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-09-23 01:45 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-09-23 01:45 . 2009-02-13 16:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-09-23 01:45 . 2009-02-13 16:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-09-23 01:45 . 2009-09-23 01:45 -------- d-----w- c:\program files\Avira
2009-09-23 01:45 . 2009-09-23 01:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-09-18 22:45 . 2004-08-04 10:00 55808 -c--a-w- c:\windows\system32\dllcache\eventlog.dll
2009-09-18 22:45 . 2004-08-04 10:00 55808 ------w- c:\windows\system32\eventlog.dll
2009-09-18 22:45 . 2004-08-04 10:00 4224 -c--a-w- c:\windows\system32\dllcache\beep.sys
2009-09-18 22:45 . 2004-08-04 10:00 4224 ------w- c:\windows\system32\drivers\beep.sys
2009-09-16 23:57 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-16 17:14 . 2009-09-16 17:14 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-09-13 00:07 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-13 00:07 . 2009-09-16 17:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-13 00:07 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-01 18:37 . 2009-09-01 18:37 -------- d-----w- C:\_OTM
2009-09-01 15:53 . 2009-09-01 18:48 -------- d-----w- c:\program files\M1N1
2009-09-01 14:35 . 2009-09-01 14:35 -------- d-----w- c:\documents and settings\cubby.MACDONALDWOOD\Application Data\Malwarebytes
2009-09-01 14:35 . 2009-09-01 14:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-01 10:10 . 2009-09-01 10:10 -------- d-sh--w- c:\documents and settings\Cubby\PrivacIE
2009-09-01 10:01 . 2009-09-01 10:01 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-09-01 10:00 . 2009-09-01 10:00 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-08-31 20:54 . 2009-08-31 20:54 -------- d-sh--w- c:\documents and settings\Cubby\IETldCache
2009-08-31 20:28 . 2009-08-31 20:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-26 11:20 . 2009-08-26 11:20 -------- d-----w- c:\program files\Media5 Software
2009-08-26 11:17 . 2002-12-03 07:11 143872 ----a-w- c:\windows\system32\NCTWMAFile.dll
2009-08-26 11:17 . 2002-12-03 07:07 168448 ----a-w- c:\windows\system32\NCTAudioPlayer.dll
2009-08-26 11:17 . 2002-12-03 07:02 491520 ----a-w- c:\windows\system32\NCTAudioFile.dll
2009-08-26 11:13 . 2009-08-26 11:13 -------- d-----w- c:\program files\WMA WAV MP3 to Audio CD Maker
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-24 00:28 . 2007-09-13 16:05 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-09-24 00:17 . 2007-09-13 16:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-09-23 11:47 . 2006-08-22 06:06 35001 ----a-w- c:\windows\system32\nvModes.dat
2009-09-18 01:23 . 2009-03-28 23:35 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-17 01:25 . 2007-04-13 00:07 -------- d-----w- c:\program files\dl_Cats
2009-09-01 10:13 . 2006-08-22 06:33 -------- d-----w- c:\program files\Google
2009-09-01 00:58 . 2006-12-28 01:31 -------- d-----w- c:\documents and settings\cubby.MACDONALDWOOD\Application Data\Azureus
2009-08-31 20:04 . 2007-11-15 02:48 -------- d-----w- c:\documents and settings\cubby.MACDONALDWOOD\Application Data\Wave Systems Corp
2009-08-25 15:19 . 2009-08-21 00:40 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-25 01:46 . 2008-01-08 19:03 -------- d-----w- c:\program files\MediaCoder
2009-08-25 01:27 . 2009-08-25 01:27 -------- d-----w- c:\documents and settings\cubby.MACDONALDWOOD\Application Data\AVS4YOU
2009-08-25 01:27 . 2009-08-25 01:27 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
2009-08-25 01:27 . 2009-08-25 01:26 -------- d-----w- c:\program files\AVS4YOU
2009-08-25 01:27 . 2009-08-25 01:26 -------- d-----w- c:\program files\Common Files\AVSMedia
2009-08-24 23:56 . 2009-08-24 23:56 -------- d-----w- c:\documents and settings\cubby.MACDONALDWOOD\Application Data\iMeshMediabarTb
2009-08-24 23:56 . 2009-08-24 23:56 -------- d-----w- c:\program files\iMeshMediabarTb
2009-08-24 23:56 . 2009-08-24 23:56 -------- d-----w- c:\program files\iMesh Applications
2009-08-24 18:58 . 2009-08-24 18:58 -------- d-----w- c:\documents and settings\All Users\Application Data\2BAB
2009-08-22 14:03 . 2009-08-22 13:55 -------- d-----w- c:\documents and settings\cubby.MACDONALDWOOD\Application Data\CVS
2009-08-22 13:39 . 2009-08-22 13:39 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-08-22 13:38 . 2007-10-17 16:18 -------- d-----w- c:\program files\MSECache
2009-08-21 00:39 . 2009-08-21 00:39 -------- d-----w- c:\program files\LitexMedia
2009-08-07 13:39 . 2006-09-13 17:27 93472 ----a-w- c:\documents and settings\cubby.MACDONALDWOOD\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-06 07:07 . 2009-08-06 07:07 -------- d-----w- c:\program files\MSBuild
2009-08-06 07:07 . 2009-08-06 07:07 -------- d-----w- c:\program files\Reference Assemblies
2009-08-05 09:01 . 2004-08-04 10:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-31 19:27 . 2006-09-13 15:35 -------- d-----w- c:\documents and settings\cubby.MACDONALDWOOD\Application Data\AdobeUM
2009-07-17 19:01 . 2004-08-04 10:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-04 10:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2006-03-04 03:33 915456 ------w- c:\windows\system32\wininet.dll
2006-12-17 21:20 . 2006-12-17 21:20 36206039 -c--a-w- c:\program files\Top Producer Outlook Connector.EXE
2006-12-13 03:12 . 2007-02-08 21:35 66648 -c--a-w- c:\program files\mozilla firefox\components\jar50.dll
2006-12-13 03:12 . 2007-02-08 21:35 54352 -c--a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2006-12-13 03:12 . 2007-02-08 21:35 34928 -c--a-w- c:\program files\mozilla firefox\components\myspell.dll
2006-12-13 03:12 . 2007-02-08 21:35 46696 -c--a-w- c:\program files\mozilla firefox\components\spellchk.dll
2006-12-13 03:12 . 2007-02-08 21:35 172120 -c--a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2007-03-15 21:30 . 2007-03-15 21:30 80 -csha-r- c:\windows\system32\67F454E4E8.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-09-17_00.01.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-24 21:37 . 2009-09-24 21:37 16384 c:\windows\Temp\Perflib_Perfdata_4f0.dat
+ 2009-09-23 01:45 . 2009-05-11 14:12 28520 c:\windows\system32\drivers\ssmdrv.sys
- 2006-09-13 16:48 . 2009-08-27 12:57 23040 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2006-09-13 16:48 . 2009-09-18 01:07 23040 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2006-09-13 16:48 . 2009-08-27 12:57 61440 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2006-09-13 16:48 . 2009-09-18 01:07 61440 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2006-09-13 16:48 . 2009-08-27 12:57 27136 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2006-09-13 16:48 . 2009-09-18 01:07 27136 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2006-09-13 16:48 . 2009-08-27 12:57 11264 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2006-09-13 16:48 . 2009-09-18 01:07 11264 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2006-09-13 16:48 . 2009-08-27 12:57 12288 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2006-09-13 16:48 . 2009-09-18 01:07 12288 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2006-09-13 16:48 . 2009-08-27 12:57 4096 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2006-09-13 16:48 . 2009-09-18 01:07 4096 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2004-08-04 10:00 . 2009-03-08 08:33 726528 c:\windows\system32\jscript.dll
+ 2004-08-04 10:00 . 2009-06-22 06:44 726528 c:\windows\system32\jscript.dll
+ 2008-05-09 10:53 . 2009-06-22 06:44 726528 c:\windows\system32\dllcache\jscript.dll
- 2008-05-09 10:53 . 2009-03-08 08:33 726528 c:\windows\system32\dllcache\jscript.dll
+ 2006-09-13 16:48 . 2009-09-18 01:07 409600 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2006-09-13 16:48 . 2009-08-27 12:57 409600 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2006-09-13 16:48 . 2009-09-18 01:07 286720 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2006-09-13 16:48 . 2009-08-27 12:57 286720 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2006-09-13 16:48 . 2009-09-18 01:07 249856 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2006-09-13 16:48 . 2009-08-27 12:57 249856 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2006-09-13 16:48 . 2009-09-18 01:07 794624 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2006-09-13 16:48 . 2009-08-27 12:57 794624 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2006-09-13 16:48 . 2009-08-27 12:57 135168 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2006-09-13 16:48 . 2009-09-18 01:07 135168 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-09-18 01:05 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971961-IE8\spuninst\updspapi.dll
+ 2009-09-18 01:05 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971961-IE8\spuninst\spuninst.exe
+ 2009-09-18 01:05 . 2009-03-08 08:33 726528 c:\windows\ie8updates\KB971961-IE8\jscript.dll
+ 2004-08-04 10:00 . 2009-05-20 08:56 2458112 c:\windows\system32\WMVCore.dll
- 2004-08-04 10:00 . 2008-06-18 10:03 2458112 c:\windows\system32\WMVCore.dll
- 2004-08-04 10:00 . 2008-06-18 10:03 2458112 c:\windows\system32\dllcache\WMVCore.dll
+ 2004-08-04 10:00 . 2009-05-20 08:56 2458112 c:\windows\system32\dllcache\WMVCore.dll
+ 2009-08-25 18:57 . 2009-08-25 18:57 5518336 c:\windows\Installer\567e188.msp
+ 2009-09-18 01:07 . 2009-08-28 18:38 24689600 c:\windows\system32\MRT.exe
+ 2009-09-18 01:06 . 2009-09-18 01:06 15709696 c:\windows\Installer\567e176.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F}"= "c:\program files\iMeshMediabarTb\iMeshMediaBarDx.dll" [2009-07-31 91568]
[HKEY_CLASSES_ROOT\clsid\{abb49b3b-ab7d-4ed0-9135-93fd5aa4f69f}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-14 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-24 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLBTCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2007-02-12 73728]
"domezudim"="c:\windows\system32\dibiyowa.dll" [BU]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
c:\documents and settings\Cubby\Start Menu\Programs\Startup\
VZAccess Manager.lnk - c:\program files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe [2007-5-17 1220608]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{a292acc6-cf08-4d50-83ab-cb5c6eef5773}"= "c:\windows\system32\dibiyowa.dll" [BU]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-04-24 282624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"sagujesur"= {a292acc6-cf08-4d50-83ab-cb5c6eef5773} - c:\windows\system32\dibiyowa.dll [BU]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EMBASSY Trust Suite Secure Update.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\EMBASSY Trust Suite Secure Update.lnk
backup=c:\windows\pss\EMBASSY Trust Suite Secure Update.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^cubby.MACDONALDWOOD^Start Menu^Programs^Startup^Anapod Manager.lnk]
path=c:\documents and settings\cubby.MACDONALDWOOD\Start Menu\Programs\Startup\Anapod Manager.lnk
backup=c:\windows\pss\Anapod Manager.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^cubby.MACDONALDWOOD^Start Menu^Programs^Startup^RCA Detective.lnk]
path=c:\documents and settings\cubby.MACDONALDWOOD\Start Menu\Programs\Startup\RCA Detective.lnk
backup=c:\windows\pss\RCA Detective.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\WINDOWS\\system32\\dlbtcoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dlbtpswx.exe"=
"c:\\Program Files\\Red Chair Software\\Anapod Explorer\\anamgr.exe"=
"c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\umi.exe"=
"c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\VideoSpin.exe"=
"c:\\WebC_ActiveX4.22\\ptermX.exe"=
"c:\\Program Files\\Ericom Software\\PowerTerm WebConnect 5.6\\151.203.99.51\\ptermX.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [9/22/2009 9:45 PM 108289]
R2 WILPAR;Wordcraft Parallel Driver;c:\windows\system32\drivers\WILPAR.SYS [9/1/2006 11:40 AM 22976]
S3 cur_bus;Curitel USB Composite Device driver (WDM);c:\windows\system32\drivers\cur_bus.sys [9/5/2006 10:41 AM 50176]
S3 cur_mdfl;Curitel Packet Service Filter;c:\windows\system32\drivers\cur_mdfl.sys [9/5/2006 10:41 AM 6096]
S3 cur_mdm;Curitel Packet Service Drivers;c:\windows\system32\drivers\cur_mdm.sys [9/5/2006 10:41 AM 81056]
S3 pwi_bus;Curitel PC Card Composite Device driver (WDM);c:\windows\system32\drivers\pwi_bus.sys [5/17/2007 2:28 PM 55344]
S3 pwi_mdfl;Curitel PC Card Filter;c:\windows\system32\drivers\pwi_mdfl.sys [5/17/2007 2:28 PM 9200]
S3 pwi_mdm;Curitel PC Card Drivers;c:\windows\system32\drivers\pwi_mdm.sys [5/17/2007 2:28 PM 89936]
S3 pwi_oflt;Curitel PC Card OHCI Filter;c:\windows\system32\drivers\pwi_oflt.sys [5/17/2007 2:28 PM 9472]
S3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);c:\windows\system32\drivers\pwi_serd.sys [5/17/2007 2:28 PM 69632]
S3 SMC2208;SMC Compact USB to Ethernet converter;c:\windows\system32\drivers\SMC2208.SYS [2/16/2008 12:40 PM 26525]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34]
2009-09-24 c:\windows\Tasks\User_Feed_Synchronization-{522C9FDF-90D3-4175-A7FB-7B976A9CAC8A}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
2009-09-24 c:\windows\Tasks\{CB904F16-01AA-4E35-81DF-0F9BCF531682}_MACDONALDWOOD_Cubby.job
- c:\windows\system32\mobsync.exe [2004-08-04 00:12]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.commStart Page =
hxxp://www.google.comuInternet Settings,ProxyOverride = *.local
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Lookup on Merriam Webster -
file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia -
file://c:\program files\ieSpell\wikipedia.HTM
LSP: vlsp.dll
Trusted Zone: stumbleupon.com
DPF: Microsoft XML Parser for Java -
file:///C:/WINDOWS/Java/classes/xmldso.cabDPF: PUFLITE -
hxxp://cubbyfitts.point2agent.com/Office/ColpaControls/Photo/Control/PUFLITE.CABDPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} -
hxxps://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cabDPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} -
hxxp://www.facebook.com/controls/contactx.dllDPF: {7EC816D4-6FC3-4C58-A7DA-A770EE461602} -
hxxp://151.203.99.51/Ericom/WebConnect%205.6/web/windows/ptdownloader.cabFF - ProfilePath - c:\documents and settings\cubby.MACDONALDWOOD\Application Data\Mozilla\Firefox\Profiles\xf0e1ri2.default\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
AddRemove-NSS - c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.3.0.44\InstStub.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-24 18:04
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLBTCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,97,65,98,77,df,
c4,d9,d5,e2,63,26,f1,3f,c8,ff,68,26,da,4a,51,2c,18,5c,9b,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:46,47,15,b0,92,4b,c7,ef,c0,d8,10,c6,fc,
d8,85,02,6a,9c,d6,61,af,45,84,18,63,98,aa,41,9d,27,22,f8,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,77,6b,0f,1c,e2,
18,6e,17,ff,7c,85,e0,43,d4,0e,fe,42,e8,9f,e8,ec,72,c5,99,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,93,ca,7f,74,98,
a9,19,16,86,8c,21,01,be,91,eb,e7,18,97,a8,58,fe,a9,4e,79,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,3c,0e,eb,90,42,
fa,06,cb,f5,1d,4d,73,a8,13,5c,05,6b,83,dc,d8,36,37,17,f7,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,50,cf,42,b4,96,
4a,7b,52,df,20,58,62,78,6b,cf,c8,df,e7,7e,bd,d5,e9,01,09,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,cb,53,db,0d,94,
5e,6e,68,fb,a7,78,e6,12,2f,9a,ea,6f,2a,ed,60,b2,d1,47,83,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,ff,57,35,74,eb,
c0,05,20,01,3a,48,fc,e8,04,4a,f1,f1,75,68,bb,bf,e2,2e,a4,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,a9,be,9e,98,8b,
17,38,7b,f6,0f,4e,58,98,5b,89,c9,42,b2,98,75,e4,2f,3b,36,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,c2,82,54,f6,10,
e3,07,8e,3d,ce,ea,26,2d,45,aa,78,ee,29,88,ea,c4,c6,75,12,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,2d,db,c2,de,4b,
e1,3d,b4,2a,b7,cc,b5,b9,7f,41,e7,68,33,58,56,d5,cb,db,4d,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,62,be,74,45,21,
51,65,c7,6c,43,2d,1e,aa,22,2f,9c,08,b7,02,b6,70,38,f2,30,6c,43,2d,1e,aa,22,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(764)
c:\windows\system32\wvauth.dll
c:\windows\system32\biolsp.dll
c:\windows\system32\vlsp.dll
- - - - - - - > 'explorer.exe'(3104)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\vlsp.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\lexbces.exE
c:\windows\system32\scardsvr.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Wave Systems Corp\common\DataServer.exe
c:\windows\system32\dlbtcoms.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\spool\drivers\w32x86\3\HPZIPM12.EXE
c:\program files\Verizon Wireless\venturi\Client\VentC.exe
c:\windows\system32\BCMWLTRY.EXE
c:\windows\system32\fxssvc.exe
.
**************************************************************************
.
Completion time: 2009-09-24 18:08 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-24 22:08
ComboFix2.txt 2009-09-18 22:52
ComboFix3.txt 2009-09-18 12:38
ComboFix4.txt 2009-09-18 01:29
ComboFix5.txt 2009-09-24 21:27
Pre-Run: 36,201,574,400 bytes free
Post-Run: 36,150,185,984 bytes free
393 --- E O F --- 2009-09-18 01:09