andrewaadobe
2008-05-29, 15:49
please help, I have been running spybot several times and it does not remove virtumonde and this means I cannot search using google or any other search engine:
Logs from Combofix and Hijack below
**********
Hijack
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:15:46, on 29/05/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Sony\VAIO Service Utility\VAIO-SUTOOL.exe
C:\Windows\system32\conime.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Sony\VAIO Center Access Bar\VCAB.exe
C:\Program Files\itunes\iTunesHelper.exe
C:\Program Files\Apoint\Apntex.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\WinZip E-Mail Companion\loadwzco.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Trillian\trillian.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Sony\SmartWi Connection Utility\CCP.exe
C:\Program Files\Sony\SmartWi Connection Utility\SmartWiToggletProxy.exe
C:\Program Files\Sony\SmartWi Connection Utility\SmartWiTogglet.exe
C:\Program Files\Sony\SmartWi Connection Utility\ActivationManager.exe
C:\Program Files\Sony\SmartWi Connection Utility\PowerManager.exe
C:\Program Files\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
C:\Program Files\Sony\SmartWi Connection Utility\SWGadgetServer.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Windows\System32\mobsync.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Andrew\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IEToolbarBHO Class - {1A1DAC8C-074D-440F-8707-7009A672D7D1} - C:\Program Files\LinkedIn\IE Toolbar\3.0.3.1100\LinkedinIEToolbar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {514A5C49-0C7D-42c3-A71B-38864A269B7A} - C:\Windows\system32\itlebmlm.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: LinkedIn Toolbar - {BB670D0B-5C46-40C7-B38B-40DD26987723} - C:\Program Files\LinkedIn\IE Toolbar\3.0.3.1100\LinkedinIEToolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [DRCU] "C:\Program Files\Sony\DRCU\DRCU.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [VAIO Center Access Bar] "c:\program files\sony\VAIO Center Access Bar\VCAB.exe"
O4 - HKLM\..\Run: [SmartWiHelper] C:\Program Files\Sony\SmartWi Connection Utility\SmartWiHelper.exe /WindowsStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinZip E-Mail Companion OEAPI] "C:\Program Files\WinZip E-Mail Companion\loadwzco.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [LaCie Backup] C:\Program Files\LaCie\Backup Software\\LaCieBackup.exe /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MobileConnect.EXE] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.EXE
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Linked&In Search - res://C:\Program Files\LinkedIn\IE Toolbar\3.0.3.1100\LinkedinIEToolbar.dll/ContextMenu.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: C:\Program Files\eGrabber\AddressGrabber Standard 2008\AddressGrabber - {90A81828-92DB-400e-AECD-78C540F5EB49} - C:\Program Files\eGrabber\AddressGrabber Standard 2008\InternetAddress.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {C61F6B9D-C575-4205-82D9-BBE611B28348} (OLOEImp.OLOEImporter) - http://www.spock.com/outlook_import/OLOEImp.CAB
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\stacsv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 12227 bytes
******
Combofix
ComboFix 08-05-28.4 - Andrew 2008-05-29 12:31:27.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.916 [GMT 1:00]
Running from: C:\Users\Andrew\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\Andrew\g2mdlhlpx.exe
C:\Windows\System32\BcLSvCdd.ini
C:\Windows\System32\BcLSvCdd.ini2
C:\Windows\system32\chymycnm.ini
C:\Windows\system32\ffooyyxv.dll
C:\Windows\system32\fppbtldt.dll
C:\Windows\system32\jdrenfuc.dll
C:\Windows\system32\jKAQgFxv.dll
C:\Windows\system32\mncymyhc.dll
C:\Windows\System32\pWwGNqru.ini
C:\Windows\System32\pWwGNqru.ini2
C:\Windows\system32\tdltbppf.ini
C:\Windows\System32\vxFgQAKj.ini
.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-29 )))))))))))))))))))))))))))))))
.
2008-05-29 08:48 . 2008-03-08 03:08 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-29 08:48 . 2008-03-08 05:21 1,695,744 --a------ C:\Windows\System32\gameux.dll
2008-05-29 00:04 . 2008-05-29 12:09 415 --a------ C:\Windows\wininit.ini
2008-05-28 23:45 . 2008-05-28 23:45 <DIR> d-------- C:\Program Files\CCleaner
2008-05-28 23:23 . 2008-05-29 00:04 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-05-28 23:23 . 2008-05-29 00:04 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-05-28 23:23 . 2008-05-28 23:23 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-28 23:15 . 2008-05-28 23:17 <DIR> d-------- C:\Users\All Users\Lavasoft
2008-05-28 23:15 . 2008-05-28 23:17 <DIR> d-------- C:\ProgramData\Lavasoft
2008-05-28 23:15 . 2008-05-28 23:15 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-26 18:26 . 2008-05-28 22:20 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-26 18:13 . 2008-05-28 22:32 <DIR> d-------- C:\Windows\System32\drivers\Avg
2008-05-26 18:13 . 2008-05-26 18:13 96,520 --a------ C:\Windows\System32\drivers\avgldx86.sys
2008-05-26 18:13 . 2008-05-26 18:13 67,080 --a------ C:\Windows\System32\drivers\avgwfpx.sys
2008-05-26 18:13 . 2008-05-26 18:13 12,424 --a------ C:\Windows\System32\drivers\avgrkx86.sys
2008-05-26 18:13 . 2008-05-26 18:13 10,520 --a------ C:\Windows\System32\avgrsstx.dll
2008-05-26 18:12 . 2008-05-26 18:12 <DIR> d-------- C:\Users\All Users\avg8
2008-05-26 18:12 . 2008-05-26 18:12 <DIR> d-------- C:\ProgramData\avg8
2008-05-26 18:12 . 2008-05-26 18:12 <DIR> d-------- C:\Program Files\AVG
2008-05-24 21:20 . 2007-03-23 04:05 29,272 --a------ C:\Windows\System32\AdobePDF.dll
2008-05-24 12:36 . 2008-05-24 12:36 <DIR> d--h----- C:\Windows\PIF
2008-05-24 12:02 . 2008-05-24 16:04 <DIR> d-------- C:\Users\Andrew\AppData\Roaming\Azureus
2008-05-24 12:02 . 2008-05-24 12:02 <DIR> d-------- C:\Users\All Users\Azureus
2008-05-24 12:02 . 2008-05-24 12:02 <DIR> d-------- C:\ProgramData\Azureus
2008-05-24 12:00 . 2008-05-24 16:04 <DIR> d-------- C:\Program Files\Azureus
2008-05-24 11:12 . 2008-05-27 09:36 <DIR> d-------- C:\Users\Andrew\AppData\Roaming\DNA
2008-05-24 11:12 . 2008-05-24 11:12 <DIR> d-------- C:\Program Files\DNA
2008-05-23 21:58 . 2008-05-23 21:58 <DIR> d-------- C:\Windows\CD95F661A5C444F5A6AAECDD91C240B5.TMP
2008-05-23 21:57 . 2008-05-23 21:58 <DIR> d-------- C:\Windows\CD95F661A5C444F5A6AAECDD91C240B6.TMP
2008-05-23 21:56 . 2008-05-23 21:56 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-05-23 16:39 . 2008-05-23 16:39 <DIR> d-------- C:\Users\All Users\SSScanAppDataDir
2008-05-23 16:39 . 2008-05-23 16:39 <DIR> d-------- C:\ProgramData\SSScanAppDataDir
2008-05-22 13:50 . 2008-05-22 13:50 8,442 --a------ C:\Great Artists Series 1 Disc 1.mds
2008-05-22 13:20 . 2008-05-22 13:50 7,487,127,552 --a------ C:\Great Artists Series 1 Disc 1.iso
2008-05-21 11:00 . 2008-05-21 11:00 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-05-18 20:21 . 2008-05-18 20:39 4,164,812,800 --a------ C:\Fritz11.iso
2008-05-16 15:15 . 2008-05-16 15:15 <DIR> d-------- C:\Program Files\Vodafone
2008-05-16 15:15 . 2008-05-28 23:13 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\Windows\System32\lsdelete.exe
2008-05-15 22:06 . 2008-05-15 22:06 <DIR> d--h----- C:\Users\All Users\CanonBJ
2008-05-15 22:06 . 2008-05-15 22:06 <DIR> d--h----- C:\ProgramData\CanonBJ
2008-05-15 18:24 . 2008-05-18 20:39 <DIR> d-------- C:\Users\Andrew\AppData\Roaming\ImgBurn
2008-05-15 18:23 . 2008-05-15 18:24 <DIR> d-------- C:\Program Files\ImgBurn
2008-05-15 18:09 . 2008-05-15 18:11 <DIR> d-------- C:\Click to DVD 2
2008-05-08 22:06 . 2008-05-12 21:26 <DIR> d-------- C:\Users\Andrew\AppData\Roaming\LinkedIn
2008-05-08 22:05 . 2008-05-12 21:26 <DIR> d-------- C:\Program Files\LinkedIn
2008-05-07 09:32 . 2008-05-07 09:32 56 --ah----- C:\Windows\System32\ezsidmv.dat
2008-05-07 09:27 . 2008-05-07 09:27 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-04-29 11:20 . 2008-04-29 11:20 15,648 --a------ C:\Windows\System32\drivers\NSDriver.sys
2008-04-29 11:19 . 2008-04-29 11:19 15,648 --a------ C:\Windows\System32\drivers\Awrtrd.sys
2008-04-29 11:19 . 2008-04-29 11:19 12,960 --a------ C:\Windows\System32\drivers\Awrtpd.sys
2008-04-29 07:20 . 2008-04-29 07:28 <DIR> d-------- C:\Program Files\Common Files\UpdateTemp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-29 11:39 --------- d-----w C:\Program Files\Trillian
2008-05-29 11:26 --------- d-----w C:\Users\Andrew\AppData\Roaming\Skype
2008-05-29 08:56 --------- d-----w C:\Users\Andrew\AppData\Roaming\skypePM
2008-05-24 20:21 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-24 15:29 --------- d-----w C:\ProgramData\WinZip
2008-05-18 09:26 218,831 ----a-w C:\Windows\E220AutoRunLog.tmp
2008-05-18 09:26 --------- d-----w C:\Program Files\Sony
2008-05-16 16:12 --------- d-----w C:\Users\admin\AppData\Roaming\Skype
2008-05-15 19:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-15 19:50 --------- d-----w C:\Users\Andrew\AppData\Roaming\ChessBase
2008-05-15 19:50 --------- d-----w C:\Program Files\ChessBase
2008-05-15 19:45 --------- d-----w C:\ProgramData\Vodafone
2008-05-14 20:46 --------- d-----w C:\Program Files\Windows Mail
2008-05-14 20:45 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-08 06:15 --------- d-----w C:\Users\Andrew\AppData\Roaming\Sony Corporation
2008-04-30 14:19 --------- d-----w C:\ProgramData\AddressGrabber Standard 2008
2008-04-28 21:00 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-04-26 13:26 --------- d-----w C:\Program Files\Microsoft
2008-04-21 21:53 --------- d-----w C:\Program Files\Safari
2008-04-21 21:49 --------- d-----w C:\Program Files\Apple Software Update
2008-04-21 07:43 --------- d-----w C:\ProgramData\WindowsSearch
2008-04-20 20:53 --------- d-----w C:\Program Files\Microsoft Small Business
2008-04-20 20:48 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-04-18 18:58 --------- d-----w C:\Program Files\OCA Marker
2008-04-18 18:49 32 ----a-w C:\Users\All Users\ezsid.dat
2008-04-18 18:49 32 ----a-w C:\ProgramData\ezsid.dat
2008-04-16 17:08 82,158 ----a-w C:\Users\Andrew\AppData\Roaming\nvModes.dat
2008-04-16 17:04 --------- d-----w C:\Users\Theodore\AppData\Roaming\Skype
2008-04-16 17:03 --------- d-----w C:\Users\Theodore\AppData\Roaming\Sony Corporation
2008-04-13 19:28 --------- d-----w C:\Program Files\KONICA MINOLTA
2008-04-12 20:59 --------- d-----w C:\Users\Andrew\AppData\Roaming\Apple Computer
2008-04-12 20:19 --------- d-----w C:\ProgramData\MSScanAppDataDir
2008-04-11 16:23 38,400 ----a-w C:\Windows\System32\SoundSchemes.exe
2008-04-10 19:50 --------- d-----w C:\Program Files\eGrabber
2008-04-03 18:50 --------- d-----w C:\Program Files\VAIO Startup
2008-04-03 15:07 --------- d-----w C:\ProgramData\NVIDIA
2008-04-03 13:40 174 --sha-w C:\Program Files\desktop.ini
2008-04-03 13:29 --------- d-----w C:\Program Files\Windows Sidebar
2008-04-03 13:29 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-04-03 13:29 --------- d-----w C:\Program Files\Windows Defender
2008-04-03 13:29 --------- d-----w C:\Program Files\Windows Collaboration
2008-04-03 13:29 --------- d-----w C:\Program Files\Windows Calendar
2008-04-03 13:05 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-04-03 13:05 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-04-03 12:32 47,560 ----a-w C:\Windows\System32\SPReview.exe
2008-04-03 12:32 152,576 ----a-w C:\Windows\System32\SPWizUI.dll
2008-04-03 11:55 --------- d-----w C:\Program Files\itunes
2008-04-03 11:54 --------- d-----w C:\ProgramData\Apple Computer
2008-04-03 11:54 --------- d-----w C:\Program Files\iPod
2008-04-03 11:53 --------- d-----w C:\Program Files\QuickTime
2008-04-03 11:43 --------- d-----w C:\Program Files\Java
2008-04-03 11:39 --------- d-----w C:\Users\Andrew\AppData\Roaming\PeerNetworking
2008-03-20 03:29 27,839 ----a-w C:\Users\Guest\AppData\Roaming\nvModes.dat
2008-03-12 20:21 678,408 ----a-w C:\Windows\System32\gpprefcl.dll
2008-03-08 04:19 540,672 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-03-08 04:19 458,752 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-03-08 04:19 2,153,984 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-03-08 04:19 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-03-08 01:58 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-02-29 07:14 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 07:11 988,216 ----a-w C:\Windows\System32\winload.exe
2008-02-29 07:11 927,288 ----a-w C:\Windows\System32\winresume.exe
2008-02-29 06:53 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll
2008-02-29 06:53 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:53 378,368 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 04:21 2,032,128 ----a-w C:\Windows\System32\win32k.sys
2008-02-29 04:12 318,464 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 04:12 14,848 ----a-w C:\Windows\System32\srdelayed.exe
2007-12-27 09:31 42,095 ----a-w C:\Users\admin\AppData\Roaming\nvModes.dat
2008-02-12 09:35 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-11-03 23:05 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012007110320071104\index.dat
2008-02-12 09:35 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-02-12 09:35 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-01-18 18:59 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-01-18 18:59 32,768 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-01-18 18:59 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2007-12-11 19:50 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat
2007-12-11 19:50 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012007121120071212\index.dat
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{514A5C49-0C7D-42c3-A71B-38864A269B7A}]
C:\Windows\system32\itlebmlm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-26 18:12 2051328 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-26 18:12 2051328]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-05-26 18:12 2051328]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@={F2F31467-B1AC-4df0-AE79-FD5FA085E22B}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@={A3E208F7-0E3A-4182-A7A6-B169D5D691AA}
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-01-05 21:41 2857984 --a------ C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-01-05 21:41 2857984 --a------ C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-18 23:33 1233920]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-04-23 17:45 22058792]
"LaCie Backup"="C:\Program Files\LaCie\Backup Software\\LaCieBackup.exe" [2006-07-06 11:30 2596864]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-18 23:33 125952]
"MobileConnect.EXE"="C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.EXE" [ ]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 23:33 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2006-11-09 13:01 118784]
"DRCU"="C:\Program Files\Sony\DRCU\DRCU.exe" [2007-06-18 15:05 73728]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 08:00 33648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2007-05-15 00:54 321656]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-06-18 19:54 138008]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-06-18 19:54 154392]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-06-18 19:54 133912]
"VAIOCameraUtility"="C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" [2007-02-07 20:43 411768]
"VAIO Center Access Bar"="c:\program files\sony\VAIO Center Access Bar\VCAB.exe" [2007-03-06 23:22 36864]
"SmartWiHelper"="C:\Program Files\Sony\SmartWi Connection Utility\SmartWiHelper.exe" [2007-01-05 14:10 57344]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-11-07 03:35 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-11-07 03:35 8534560]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-11-07 03:35 81920]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-26 18:12 1177368]
"WinZip E-Mail Companion OEAPI"="C:\Program Files\WinZip E-Mail Companion\loadwzco.exe" [2007-09-20 02:00 75136]
C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Trillian.lnk - C:\Program Files\Trillian\trillian.exe [12/11/2007 1:00:00 AM 1873280]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [9/16/2007 11:53:08 AM 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"DisableCAD"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
C:\Windows\system32\psqlpwd.dll 2007-01-05 21:28 90112 C:\Windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2007-04-24 01:19 98304 C:\Windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1798923751-2920748137-3304420446-1007]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{B967058B-4292-450D-9570-7C66051DA3AC}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{2E4885BE-BA14-49CD-AD88-8A81A6E28CE7}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{474BECA6-6FA5-40FE-9B7B-131AA8C74033}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{A08BFCC3-D239-4E8B-9471-51B834906A31}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{E4F9377E-43A8-4B42-B2F7-59A245B7BFBF}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{04BF05C6-4D2C-4699-B651-5F67408BA0F3}"= UDP:C:\Program Files\itunes\iTunes.exe:iTunes
"{56A323A5-A962-4480-8A4A-9F74279D250C}"= TCP:C:\Program Files\itunes\iTunes.exe:iTunes
"{FC511F1B-3164-40ED-BEDD-A5E250DD7B04}"= UDP:C:\Program Files\ChessBase\CBase9\CBase9.exe:ChessBase 9
"{80427CD5-B7AC-4767-A17A-A5FE4D76A925}"= TCP:C:\Program Files\ChessBase\CBase9\CBase9.exe:ChessBase 9
"{5446FA0B-A126-468B-8F06-9F3E6CA18C95}"= UDP:C:\Program Files\Internet Explorer\iexplore.exe:Internet Explorer
"{13B4C173-BCFD-480A-9F8B-33F91FEE3E3C}"= TCP:C:\Program Files\Internet Explorer\iexplore.exe:Internet Explorer
"{FAC55167-39F3-4894-8265-C077FA3E98EF}"= UDP:C:\Program Files\Mozilla Firefox\firefox.exe:Mozilla Firefox
"{C09EC8C8-8CDE-4E60-8123-CA1CD09B4E2D}"= TCP:C:\Program Files\Mozilla Firefox\firefox.exe:Mozilla Firefox
"{E16CF75F-D244-46FD-9F10-2D48241333F8}"= UDP:C:\Windows\System32\wercon.exe:Problem Reports and Solutions
"{FB9D8CB5-A906-4247-B220-013CEB4ABA8D}"= TCP:C:\Windows\System32\wercon.exe:Problem Reports and Solutions
"{3374495F-6D1C-454B-9605-7F2964256F7B}"= UDP:C:\Program Files\Sony\Download Taxi\SonyDownloadTaxi.exe:Sony Download Taxi
"{57A8DA46-0FC1-45D0-B41D-94EC6C4901F4}"= TCP:C:\Program Files\Sony\Download Taxi\SonyDownloadTaxi.exe:Sony Download Taxi
"{0C6C14AC-F403-475F-AA64-3E14EBD0AA5C}"= UDP:C:\Program Files\Internet Explorer\iexplore.exe:Internet Explorer
"{1C7BF6CB-ACE3-472C-8F02-E1A0D977400F}"= TCP:C:\Program Files\Internet Explorer\iexplore.exe:Internet Explorer
"{C9A41D6C-24AC-401D-B7C3-2CC2B0EF2C4A}"= UDP:C:\Program Files\Mozilla Firefox\firefox.exe:Mozilla Firefox
"{D56E6A5C-9E7B-4D32-9524-8F241DE79C58}"= TCP:C:\Program Files\Mozilla Firefox\firefox.exe:Mozilla Firefox
"{C55AEAE4-7E20-43B0-B198-12CB51FD1C8B}"= UDP:C:\Program Files\Trillian\trillian.exe:Trillian
"{087E078D-0406-42FB-BF36-16009D57BDD4}"= TCP:C:\Program Files\Trillian\trillian.exe:Trillian
"{6F5B287B-5F06-437A-8E7A-8D470BC710E2}"= UDP:C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:OUTLOOK.EXE
"{1D7AE9F1-7B8D-425F-9894-49E53D7DA0FD}"= TCP:C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:OUTLOOK.EXE
"TCP Query User{A411135D-433E-4C96-A95A-40E4AB8F9BAE}C:\\users\\andrew\\appdata\\local\\foldershare\\foldershare.exe"= UDP:C:\users\andrew\appdata\local\foldershare\foldershare.exe:foldershare.exe
"UDP Query User{CC8949EA-655A-4370-AA12-F116839F41E9}C:\\users\\andrew\\appdata\\local\\foldershare\\foldershare.exe"= TCP:C:\users\andrew\appdata\local\foldershare\foldershare.exe:foldershare.exe
"{B9602D58-C409-4869-B7C5-BC2AA408E386}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{E0953054-06AD-4484-AF4C-25C732616A49}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{892D7736-BA86-4AFE-B17A-407E82B0B116}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{52F5B0B1-7C71-479E-820E-5C78B483C580}"= TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{D84F97A0-457D-4654-895A-DEB2357BA511}"= Disabled:UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{884E21E5-CCDC-40E9-9015-8E61E6270ABF}"= Disabled:TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{C7DC1B92-B056-44ED-8E16-E782B5B8969D}"= Disabled:UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{3A9685E4-3B58-4A55-89C0-679534D57B33}"= Disabled:TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{FACAFA69-9716-4705-8B06-9C7E67F01F8A}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
"{D07A6097-1497-409A-806C-4B696A0F2CB9}"= C:\Program Files\AVG\AVG8\avgnsx.exe:avgnsx.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 AvgRkx86;avgrkx86.sys;C:\Windows\system32\Drivers\avgrkx86.sys [2008-05-26 18:13]
R0 shpf;Sony HDD Protection Filter Driver;C:\Windows\system32\DRIVERS\shpf.sys [2007-08-07 13:51]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-05-26 18:13]
R2 regi;regi;C:\Windows\system32\drivers\regi.sys [2007-04-18 04:09]
R3 AvgWfpX;AVG8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-05-26 18:13]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;C:\Windows\system32\Drivers\R5U870FLx86.sys [2007-04-23 14:33]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;C:\Windows\system32\Drivers\R5U870FUx86.sys [2007-04-23 14:33]
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\Windows\system32\DRIVERS\SonyImgF.sys [2007-08-07 11:43]
R3 SPI;Sony Programmable I/O Control Device;C:\Windows\system32\DRIVERS\SonyPI.sys [2006-10-25 18:42]
S3 IFXTPM;IFXTPM;C:\Windows\system32\DRIVERS\IFXTPM.SYS [2007-08-07 10:02]
S3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-06-18 19:54]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LPDService REG_MULTI_SZ
rsmsvcs REG_MULTI_SZ ntmssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
GPSvcGroup REG_MULTI_SZ GPSvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0bdd8f45-d949-11dc-b4c5-0013a9fe5320}]
\shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{12cbc89e-b3e4-11dc-8b2f-0013a9fe5320}]
\shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{239e1033-d882-11dc-b2f6-0013a9fe5320}]
\shell\AutoRun\command - E:\switch.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5146b618-2349-11dd-bb66-001a805c0825}]
\shell\AutoRun\command - E:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5146b62c-2349-11dd-bb66-001a805c0825}]
\shell\AutoRun\command - E:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52c7495f-03ad-11dd-9b0a-001a805c0825}]
\shell\AutoRun\command - E:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52c74961-03ad-11dd-9b0a-001a805c0825}]
\shell\AutoRun\command - E:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6800ed99-c76e-11dc-a5b8-0013a9fe5320}]
\shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b28e7437-24ba-11dd-8449-001a805c0825}]
\shell\AutoRun\command - E:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b28e7439-24ba-11dd-8449-001a805c0825}]
\shell\AutoRun\command - E:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c5003922-dc61-11dc-a1d8-0013a9fe5320}]
\shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb18fab2-c4dc-11dc-82d3-0013a9fe5320}]
\shell\AutoRun\command - F:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d71b5d8b-c801-11dc-a371-0013a9fe5320}]
\shell\AutoRun\command - E:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8584300-b3eb-11dc-b397-0013a9fe5320}]
\shell\AutoRun\command - E:\VMC_PBStarter.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-29 12:51:16
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Protector Suite QL\upeksvr.exe
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Windows\System32\dllhost.exe
C:\Windows\ehome\ehrecvr.exe
C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
C:\Windows\System32\Locator.exe
C:\Windows\System32\TCPSVCS.EXE
C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\System32\stacsv.exe
C:\Windows\System32\UI0Detect.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Windows\System32\vds.exe
C:\Windows\System32\VSSVC.exe
C:\Windows\System32\wbem\WmiApSrv.exe
C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
C:\Windows\System32\drivers\XAudio.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\System32\WUDFHost.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Windows\System32\msdtc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Service Utility\VAIO-SUTOOL.exe
C:\Windows\System32\conime.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\ApntEx.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Sony\SmartWi Connection Utility\CCP.exe
C:\Program Files\Sony\SmartWi Connection Utility\SmartWiToggletProxy.exe
C:\Program Files\Sony\SmartWi Connection Utility\SmartWiTogglet.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Sony\SmartWi Connection Utility\ActivationManager.exe
C:\Program Files\Sony\SmartWi Connection Utility\PowerManager.exe
C:\Program Files\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
C:\Program Files\Sony\SmartWi Connection Utility\SWGadgetServer.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-05-29 12:59:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-29 11:59:43
Pre-Run: 76,621,905,920 bytes free
Post-Run: 76,287,152,128 bytes free
404 --- E O F --- 2008-05-29 07:50:58
Logs from Combofix and Hijack below
**********
Hijack
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:15:46, on 29/05/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Sony\VAIO Service Utility\VAIO-SUTOOL.exe
C:\Windows\system32\conime.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Sony\VAIO Center Access Bar\VCAB.exe
C:\Program Files\itunes\iTunesHelper.exe
C:\Program Files\Apoint\Apntex.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\WinZip E-Mail Companion\loadwzco.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Trillian\trillian.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Sony\SmartWi Connection Utility\CCP.exe
C:\Program Files\Sony\SmartWi Connection Utility\SmartWiToggletProxy.exe
C:\Program Files\Sony\SmartWi Connection Utility\SmartWiTogglet.exe
C:\Program Files\Sony\SmartWi Connection Utility\ActivationManager.exe
C:\Program Files\Sony\SmartWi Connection Utility\PowerManager.exe
C:\Program Files\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
C:\Program Files\Sony\SmartWi Connection Utility\SWGadgetServer.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Windows\System32\mobsync.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Andrew\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IEToolbarBHO Class - {1A1DAC8C-074D-440F-8707-7009A672D7D1} - C:\Program Files\LinkedIn\IE Toolbar\3.0.3.1100\LinkedinIEToolbar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {514A5C49-0C7D-42c3-A71B-38864A269B7A} - C:\Windows\system32\itlebmlm.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: LinkedIn Toolbar - {BB670D0B-5C46-40C7-B38B-40DD26987723} - C:\Program Files\LinkedIn\IE Toolbar\3.0.3.1100\LinkedinIEToolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [DRCU] "C:\Program Files\Sony\DRCU\DRCU.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [VAIO Center Access Bar] "c:\program files\sony\VAIO Center Access Bar\VCAB.exe"
O4 - HKLM\..\Run: [SmartWiHelper] C:\Program Files\Sony\SmartWi Connection Utility\SmartWiHelper.exe /WindowsStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinZip E-Mail Companion OEAPI] "C:\Program Files\WinZip E-Mail Companion\loadwzco.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [LaCie Backup] C:\Program Files\LaCie\Backup Software\\LaCieBackup.exe /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MobileConnect.EXE] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.EXE
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Linked&In Search - res://C:\Program Files\LinkedIn\IE Toolbar\3.0.3.1100\LinkedinIEToolbar.dll/ContextMenu.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: C:\Program Files\eGrabber\AddressGrabber Standard 2008\AddressGrabber - {90A81828-92DB-400e-AECD-78C540F5EB49} - C:\Program Files\eGrabber\AddressGrabber Standard 2008\InternetAddress.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {C61F6B9D-C575-4205-82D9-BBE611B28348} (OLOEImp.OLOEImporter) - http://www.spock.com/outlook_import/OLOEImp.CAB
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\stacsv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 12227 bytes
******
Combofix
ComboFix 08-05-28.4 - Andrew 2008-05-29 12:31:27.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.916 [GMT 1:00]
Running from: C:\Users\Andrew\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\Andrew\g2mdlhlpx.exe
C:\Windows\System32\BcLSvCdd.ini
C:\Windows\System32\BcLSvCdd.ini2
C:\Windows\system32\chymycnm.ini
C:\Windows\system32\ffooyyxv.dll
C:\Windows\system32\fppbtldt.dll
C:\Windows\system32\jdrenfuc.dll
C:\Windows\system32\jKAQgFxv.dll
C:\Windows\system32\mncymyhc.dll
C:\Windows\System32\pWwGNqru.ini
C:\Windows\System32\pWwGNqru.ini2
C:\Windows\system32\tdltbppf.ini
C:\Windows\System32\vxFgQAKj.ini
.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-29 )))))))))))))))))))))))))))))))
.
2008-05-29 08:48 . 2008-03-08 03:08 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-29 08:48 . 2008-03-08 05:21 1,695,744 --a------ C:\Windows\System32\gameux.dll
2008-05-29 00:04 . 2008-05-29 12:09 415 --a------ C:\Windows\wininit.ini
2008-05-28 23:45 . 2008-05-28 23:45 <DIR> d-------- C:\Program Files\CCleaner
2008-05-28 23:23 . 2008-05-29 00:04 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-05-28 23:23 . 2008-05-29 00:04 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-05-28 23:23 . 2008-05-28 23:23 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-28 23:15 . 2008-05-28 23:17 <DIR> d-------- C:\Users\All Users\Lavasoft
2008-05-28 23:15 . 2008-05-28 23:17 <DIR> d-------- C:\ProgramData\Lavasoft
2008-05-28 23:15 . 2008-05-28 23:15 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-26 18:26 . 2008-05-28 22:20 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-26 18:13 . 2008-05-28 22:32 <DIR> d-------- C:\Windows\System32\drivers\Avg
2008-05-26 18:13 . 2008-05-26 18:13 96,520 --a------ C:\Windows\System32\drivers\avgldx86.sys
2008-05-26 18:13 . 2008-05-26 18:13 67,080 --a------ C:\Windows\System32\drivers\avgwfpx.sys
2008-05-26 18:13 . 2008-05-26 18:13 12,424 --a------ C:\Windows\System32\drivers\avgrkx86.sys
2008-05-26 18:13 . 2008-05-26 18:13 10,520 --a------ C:\Windows\System32\avgrsstx.dll
2008-05-26 18:12 . 2008-05-26 18:12 <DIR> d-------- C:\Users\All Users\avg8
2008-05-26 18:12 . 2008-05-26 18:12 <DIR> d-------- C:\ProgramData\avg8
2008-05-26 18:12 . 2008-05-26 18:12 <DIR> d-------- C:\Program Files\AVG
2008-05-24 21:20 . 2007-03-23 04:05 29,272 --a------ C:\Windows\System32\AdobePDF.dll
2008-05-24 12:36 . 2008-05-24 12:36 <DIR> d--h----- C:\Windows\PIF
2008-05-24 12:02 . 2008-05-24 16:04 <DIR> d-------- C:\Users\Andrew\AppData\Roaming\Azureus
2008-05-24 12:02 . 2008-05-24 12:02 <DIR> d-------- C:\Users\All Users\Azureus
2008-05-24 12:02 . 2008-05-24 12:02 <DIR> d-------- C:\ProgramData\Azureus
2008-05-24 12:00 . 2008-05-24 16:04 <DIR> d-------- C:\Program Files\Azureus
2008-05-24 11:12 . 2008-05-27 09:36 <DIR> d-------- C:\Users\Andrew\AppData\Roaming\DNA
2008-05-24 11:12 . 2008-05-24 11:12 <DIR> d-------- C:\Program Files\DNA
2008-05-23 21:58 . 2008-05-23 21:58 <DIR> d-------- C:\Windows\CD95F661A5C444F5A6AAECDD91C240B5.TMP
2008-05-23 21:57 . 2008-05-23 21:58 <DIR> d-------- C:\Windows\CD95F661A5C444F5A6AAECDD91C240B6.TMP
2008-05-23 21:56 . 2008-05-23 21:56 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-05-23 16:39 . 2008-05-23 16:39 <DIR> d-------- C:\Users\All Users\SSScanAppDataDir
2008-05-23 16:39 . 2008-05-23 16:39 <DIR> d-------- C:\ProgramData\SSScanAppDataDir
2008-05-22 13:50 . 2008-05-22 13:50 8,442 --a------ C:\Great Artists Series 1 Disc 1.mds
2008-05-22 13:20 . 2008-05-22 13:50 7,487,127,552 --a------ C:\Great Artists Series 1 Disc 1.iso
2008-05-21 11:00 . 2008-05-21 11:00 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-05-18 20:21 . 2008-05-18 20:39 4,164,812,800 --a------ C:\Fritz11.iso
2008-05-16 15:15 . 2008-05-16 15:15 <DIR> d-------- C:\Program Files\Vodafone
2008-05-16 15:15 . 2008-05-28 23:13 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\Windows\System32\lsdelete.exe
2008-05-15 22:06 . 2008-05-15 22:06 <DIR> d--h----- C:\Users\All Users\CanonBJ
2008-05-15 22:06 . 2008-05-15 22:06 <DIR> d--h----- C:\ProgramData\CanonBJ
2008-05-15 18:24 . 2008-05-18 20:39 <DIR> d-------- C:\Users\Andrew\AppData\Roaming\ImgBurn
2008-05-15 18:23 . 2008-05-15 18:24 <DIR> d-------- C:\Program Files\ImgBurn
2008-05-15 18:09 . 2008-05-15 18:11 <DIR> d-------- C:\Click to DVD 2
2008-05-08 22:06 . 2008-05-12 21:26 <DIR> d-------- C:\Users\Andrew\AppData\Roaming\LinkedIn
2008-05-08 22:05 . 2008-05-12 21:26 <DIR> d-------- C:\Program Files\LinkedIn
2008-05-07 09:32 . 2008-05-07 09:32 56 --ah----- C:\Windows\System32\ezsidmv.dat
2008-05-07 09:27 . 2008-05-07 09:27 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-04-29 11:20 . 2008-04-29 11:20 15,648 --a------ C:\Windows\System32\drivers\NSDriver.sys
2008-04-29 11:19 . 2008-04-29 11:19 15,648 --a------ C:\Windows\System32\drivers\Awrtrd.sys
2008-04-29 11:19 . 2008-04-29 11:19 12,960 --a------ C:\Windows\System32\drivers\Awrtpd.sys
2008-04-29 07:20 . 2008-04-29 07:28 <DIR> d-------- C:\Program Files\Common Files\UpdateTemp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-29 11:39 --------- d-----w C:\Program Files\Trillian
2008-05-29 11:26 --------- d-----w C:\Users\Andrew\AppData\Roaming\Skype
2008-05-29 08:56 --------- d-----w C:\Users\Andrew\AppData\Roaming\skypePM
2008-05-24 20:21 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-24 15:29 --------- d-----w C:\ProgramData\WinZip
2008-05-18 09:26 218,831 ----a-w C:\Windows\E220AutoRunLog.tmp
2008-05-18 09:26 --------- d-----w C:\Program Files\Sony
2008-05-16 16:12 --------- d-----w C:\Users\admin\AppData\Roaming\Skype
2008-05-15 19:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-15 19:50 --------- d-----w C:\Users\Andrew\AppData\Roaming\ChessBase
2008-05-15 19:50 --------- d-----w C:\Program Files\ChessBase
2008-05-15 19:45 --------- d-----w C:\ProgramData\Vodafone
2008-05-14 20:46 --------- d-----w C:\Program Files\Windows Mail
2008-05-14 20:45 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-08 06:15 --------- d-----w C:\Users\Andrew\AppData\Roaming\Sony Corporation
2008-04-30 14:19 --------- d-----w C:\ProgramData\AddressGrabber Standard 2008
2008-04-28 21:00 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-04-26 13:26 --------- d-----w C:\Program Files\Microsoft
2008-04-21 21:53 --------- d-----w C:\Program Files\Safari
2008-04-21 21:49 --------- d-----w C:\Program Files\Apple Software Update
2008-04-21 07:43 --------- d-----w C:\ProgramData\WindowsSearch
2008-04-20 20:53 --------- d-----w C:\Program Files\Microsoft Small Business
2008-04-20 20:48 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-04-18 18:58 --------- d-----w C:\Program Files\OCA Marker
2008-04-18 18:49 32 ----a-w C:\Users\All Users\ezsid.dat
2008-04-18 18:49 32 ----a-w C:\ProgramData\ezsid.dat
2008-04-16 17:08 82,158 ----a-w C:\Users\Andrew\AppData\Roaming\nvModes.dat
2008-04-16 17:04 --------- d-----w C:\Users\Theodore\AppData\Roaming\Skype
2008-04-16 17:03 --------- d-----w C:\Users\Theodore\AppData\Roaming\Sony Corporation
2008-04-13 19:28 --------- d-----w C:\Program Files\KONICA MINOLTA
2008-04-12 20:59 --------- d-----w C:\Users\Andrew\AppData\Roaming\Apple Computer
2008-04-12 20:19 --------- d-----w C:\ProgramData\MSScanAppDataDir
2008-04-11 16:23 38,400 ----a-w C:\Windows\System32\SoundSchemes.exe
2008-04-10 19:50 --------- d-----w C:\Program Files\eGrabber
2008-04-03 18:50 --------- d-----w C:\Program Files\VAIO Startup
2008-04-03 15:07 --------- d-----w C:\ProgramData\NVIDIA
2008-04-03 13:40 174 --sha-w C:\Program Files\desktop.ini
2008-04-03 13:29 --------- d-----w C:\Program Files\Windows Sidebar
2008-04-03 13:29 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-04-03 13:29 --------- d-----w C:\Program Files\Windows Defender
2008-04-03 13:29 --------- d-----w C:\Program Files\Windows Collaboration
2008-04-03 13:29 --------- d-----w C:\Program Files\Windows Calendar
2008-04-03 13:05 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-04-03 13:05 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-04-03 12:32 47,560 ----a-w C:\Windows\System32\SPReview.exe
2008-04-03 12:32 152,576 ----a-w C:\Windows\System32\SPWizUI.dll
2008-04-03 11:55 --------- d-----w C:\Program Files\itunes
2008-04-03 11:54 --------- d-----w C:\ProgramData\Apple Computer
2008-04-03 11:54 --------- d-----w C:\Program Files\iPod
2008-04-03 11:53 --------- d-----w C:\Program Files\QuickTime
2008-04-03 11:43 --------- d-----w C:\Program Files\Java
2008-04-03 11:39 --------- d-----w C:\Users\Andrew\AppData\Roaming\PeerNetworking
2008-03-20 03:29 27,839 ----a-w C:\Users\Guest\AppData\Roaming\nvModes.dat
2008-03-12 20:21 678,408 ----a-w C:\Windows\System32\gpprefcl.dll
2008-03-08 04:19 540,672 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-03-08 04:19 458,752 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-03-08 04:19 2,153,984 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-03-08 04:19 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-03-08 01:58 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-02-29 07:14 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 07:11 988,216 ----a-w C:\Windows\System32\winload.exe
2008-02-29 07:11 927,288 ----a-w C:\Windows\System32\winresume.exe
2008-02-29 06:53 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll
2008-02-29 06:53 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:53 378,368 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 04:21 2,032,128 ----a-w C:\Windows\System32\win32k.sys
2008-02-29 04:12 318,464 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 04:12 14,848 ----a-w C:\Windows\System32\srdelayed.exe
2007-12-27 09:31 42,095 ----a-w C:\Users\admin\AppData\Roaming\nvModes.dat
2008-02-12 09:35 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-11-03 23:05 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012007110320071104\index.dat
2008-02-12 09:35 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-02-12 09:35 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-01-18 18:59 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-01-18 18:59 32,768 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-01-18 18:59 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2007-12-11 19:50 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat
2007-12-11 19:50 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012007121120071212\index.dat
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{514A5C49-0C7D-42c3-A71B-38864A269B7A}]
C:\Windows\system32\itlebmlm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-26 18:12 2051328 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-26 18:12 2051328]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-05-26 18:12 2051328]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@={F2F31467-B1AC-4df0-AE79-FD5FA085E22B}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@={A3E208F7-0E3A-4182-A7A6-B169D5D691AA}
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-01-05 21:41 2857984 --a------ C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-01-05 21:41 2857984 --a------ C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-18 23:33 1233920]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-04-23 17:45 22058792]
"LaCie Backup"="C:\Program Files\LaCie\Backup Software\\LaCieBackup.exe" [2006-07-06 11:30 2596864]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-18 23:33 125952]
"MobileConnect.EXE"="C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.EXE" [ ]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 23:33 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2006-11-09 13:01 118784]
"DRCU"="C:\Program Files\Sony\DRCU\DRCU.exe" [2007-06-18 15:05 73728]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 08:00 33648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2007-05-15 00:54 321656]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-06-18 19:54 138008]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-06-18 19:54 154392]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-06-18 19:54 133912]
"VAIOCameraUtility"="C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" [2007-02-07 20:43 411768]
"VAIO Center Access Bar"="c:\program files\sony\VAIO Center Access Bar\VCAB.exe" [2007-03-06 23:22 36864]
"SmartWiHelper"="C:\Program Files\Sony\SmartWi Connection Utility\SmartWiHelper.exe" [2007-01-05 14:10 57344]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-11-07 03:35 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-11-07 03:35 8534560]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-11-07 03:35 81920]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-26 18:12 1177368]
"WinZip E-Mail Companion OEAPI"="C:\Program Files\WinZip E-Mail Companion\loadwzco.exe" [2007-09-20 02:00 75136]
C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Trillian.lnk - C:\Program Files\Trillian\trillian.exe [12/11/2007 1:00:00 AM 1873280]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [9/16/2007 11:53:08 AM 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"DisableCAD"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
C:\Windows\system32\psqlpwd.dll 2007-01-05 21:28 90112 C:\Windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2007-04-24 01:19 98304 C:\Windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1798923751-2920748137-3304420446-1007]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{B967058B-4292-450D-9570-7C66051DA3AC}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{2E4885BE-BA14-49CD-AD88-8A81A6E28CE7}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{474BECA6-6FA5-40FE-9B7B-131AA8C74033}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{A08BFCC3-D239-4E8B-9471-51B834906A31}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{E4F9377E-43A8-4B42-B2F7-59A245B7BFBF}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{04BF05C6-4D2C-4699-B651-5F67408BA0F3}"= UDP:C:\Program Files\itunes\iTunes.exe:iTunes
"{56A323A5-A962-4480-8A4A-9F74279D250C}"= TCP:C:\Program Files\itunes\iTunes.exe:iTunes
"{FC511F1B-3164-40ED-BEDD-A5E250DD7B04}"= UDP:C:\Program Files\ChessBase\CBase9\CBase9.exe:ChessBase 9
"{80427CD5-B7AC-4767-A17A-A5FE4D76A925}"= TCP:C:\Program Files\ChessBase\CBase9\CBase9.exe:ChessBase 9
"{5446FA0B-A126-468B-8F06-9F3E6CA18C95}"= UDP:C:\Program Files\Internet Explorer\iexplore.exe:Internet Explorer
"{13B4C173-BCFD-480A-9F8B-33F91FEE3E3C}"= TCP:C:\Program Files\Internet Explorer\iexplore.exe:Internet Explorer
"{FAC55167-39F3-4894-8265-C077FA3E98EF}"= UDP:C:\Program Files\Mozilla Firefox\firefox.exe:Mozilla Firefox
"{C09EC8C8-8CDE-4E60-8123-CA1CD09B4E2D}"= TCP:C:\Program Files\Mozilla Firefox\firefox.exe:Mozilla Firefox
"{E16CF75F-D244-46FD-9F10-2D48241333F8}"= UDP:C:\Windows\System32\wercon.exe:Problem Reports and Solutions
"{FB9D8CB5-A906-4247-B220-013CEB4ABA8D}"= TCP:C:\Windows\System32\wercon.exe:Problem Reports and Solutions
"{3374495F-6D1C-454B-9605-7F2964256F7B}"= UDP:C:\Program Files\Sony\Download Taxi\SonyDownloadTaxi.exe:Sony Download Taxi
"{57A8DA46-0FC1-45D0-B41D-94EC6C4901F4}"= TCP:C:\Program Files\Sony\Download Taxi\SonyDownloadTaxi.exe:Sony Download Taxi
"{0C6C14AC-F403-475F-AA64-3E14EBD0AA5C}"= UDP:C:\Program Files\Internet Explorer\iexplore.exe:Internet Explorer
"{1C7BF6CB-ACE3-472C-8F02-E1A0D977400F}"= TCP:C:\Program Files\Internet Explorer\iexplore.exe:Internet Explorer
"{C9A41D6C-24AC-401D-B7C3-2CC2B0EF2C4A}"= UDP:C:\Program Files\Mozilla Firefox\firefox.exe:Mozilla Firefox
"{D56E6A5C-9E7B-4D32-9524-8F241DE79C58}"= TCP:C:\Program Files\Mozilla Firefox\firefox.exe:Mozilla Firefox
"{C55AEAE4-7E20-43B0-B198-12CB51FD1C8B}"= UDP:C:\Program Files\Trillian\trillian.exe:Trillian
"{087E078D-0406-42FB-BF36-16009D57BDD4}"= TCP:C:\Program Files\Trillian\trillian.exe:Trillian
"{6F5B287B-5F06-437A-8E7A-8D470BC710E2}"= UDP:C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:OUTLOOK.EXE
"{1D7AE9F1-7B8D-425F-9894-49E53D7DA0FD}"= TCP:C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:OUTLOOK.EXE
"TCP Query User{A411135D-433E-4C96-A95A-40E4AB8F9BAE}C:\\users\\andrew\\appdata\\local\\foldershare\\foldershare.exe"= UDP:C:\users\andrew\appdata\local\foldershare\foldershare.exe:foldershare.exe
"UDP Query User{CC8949EA-655A-4370-AA12-F116839F41E9}C:\\users\\andrew\\appdata\\local\\foldershare\\foldershare.exe"= TCP:C:\users\andrew\appdata\local\foldershare\foldershare.exe:foldershare.exe
"{B9602D58-C409-4869-B7C5-BC2AA408E386}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{E0953054-06AD-4484-AF4C-25C732616A49}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{892D7736-BA86-4AFE-B17A-407E82B0B116}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{52F5B0B1-7C71-479E-820E-5C78B483C580}"= TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{D84F97A0-457D-4654-895A-DEB2357BA511}"= Disabled:UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{884E21E5-CCDC-40E9-9015-8E61E6270ABF}"= Disabled:TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{C7DC1B92-B056-44ED-8E16-E782B5B8969D}"= Disabled:UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{3A9685E4-3B58-4A55-89C0-679534D57B33}"= Disabled:TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{FACAFA69-9716-4705-8B06-9C7E67F01F8A}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
"{D07A6097-1497-409A-806C-4B696A0F2CB9}"= C:\Program Files\AVG\AVG8\avgnsx.exe:avgnsx.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 AvgRkx86;avgrkx86.sys;C:\Windows\system32\Drivers\avgrkx86.sys [2008-05-26 18:13]
R0 shpf;Sony HDD Protection Filter Driver;C:\Windows\system32\DRIVERS\shpf.sys [2007-08-07 13:51]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-05-26 18:13]
R2 regi;regi;C:\Windows\system32\drivers\regi.sys [2007-04-18 04:09]
R3 AvgWfpX;AVG8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-05-26 18:13]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;C:\Windows\system32\Drivers\R5U870FLx86.sys [2007-04-23 14:33]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;C:\Windows\system32\Drivers\R5U870FUx86.sys [2007-04-23 14:33]
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\Windows\system32\DRIVERS\SonyImgF.sys [2007-08-07 11:43]
R3 SPI;Sony Programmable I/O Control Device;C:\Windows\system32\DRIVERS\SonyPI.sys [2006-10-25 18:42]
S3 IFXTPM;IFXTPM;C:\Windows\system32\DRIVERS\IFXTPM.SYS [2007-08-07 10:02]
S3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-06-18 19:54]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LPDService REG_MULTI_SZ
rsmsvcs REG_MULTI_SZ ntmssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
GPSvcGroup REG_MULTI_SZ GPSvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0bdd8f45-d949-11dc-b4c5-0013a9fe5320}]
\shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{12cbc89e-b3e4-11dc-8b2f-0013a9fe5320}]
\shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{239e1033-d882-11dc-b2f6-0013a9fe5320}]
\shell\AutoRun\command - E:\switch.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5146b618-2349-11dd-bb66-001a805c0825}]
\shell\AutoRun\command - E:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5146b62c-2349-11dd-bb66-001a805c0825}]
\shell\AutoRun\command - E:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52c7495f-03ad-11dd-9b0a-001a805c0825}]
\shell\AutoRun\command - E:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52c74961-03ad-11dd-9b0a-001a805c0825}]
\shell\AutoRun\command - E:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6800ed99-c76e-11dc-a5b8-0013a9fe5320}]
\shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b28e7437-24ba-11dd-8449-001a805c0825}]
\shell\AutoRun\command - E:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b28e7439-24ba-11dd-8449-001a805c0825}]
\shell\AutoRun\command - E:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c5003922-dc61-11dc-a1d8-0013a9fe5320}]
\shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb18fab2-c4dc-11dc-82d3-0013a9fe5320}]
\shell\AutoRun\command - F:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d71b5d8b-c801-11dc-a371-0013a9fe5320}]
\shell\AutoRun\command - E:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8584300-b3eb-11dc-b397-0013a9fe5320}]
\shell\AutoRun\command - E:\VMC_PBStarter.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-29 12:51:16
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Protector Suite QL\upeksvr.exe
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Windows\System32\dllhost.exe
C:\Windows\ehome\ehrecvr.exe
C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
C:\Windows\System32\Locator.exe
C:\Windows\System32\TCPSVCS.EXE
C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\System32\stacsv.exe
C:\Windows\System32\UI0Detect.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Windows\System32\vds.exe
C:\Windows\System32\VSSVC.exe
C:\Windows\System32\wbem\WmiApSrv.exe
C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
C:\Windows\System32\drivers\XAudio.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\System32\WUDFHost.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Windows\System32\msdtc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Service Utility\VAIO-SUTOOL.exe
C:\Windows\System32\conime.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\ApntEx.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Sony\SmartWi Connection Utility\CCP.exe
C:\Program Files\Sony\SmartWi Connection Utility\SmartWiToggletProxy.exe
C:\Program Files\Sony\SmartWi Connection Utility\SmartWiTogglet.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Sony\SmartWi Connection Utility\ActivationManager.exe
C:\Program Files\Sony\SmartWi Connection Utility\PowerManager.exe
C:\Program Files\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
C:\Program Files\Sony\SmartWi Connection Utility\SWGadgetServer.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-05-29 12:59:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-29 11:59:43
Pre-Run: 76,621,905,920 bytes free
Post-Run: 76,287,152,128 bytes free
404 --- E O F --- 2008-05-29 07:50:58