ComboFix log file...
ComboFix 09-09-25.01 - crawford 09/27/2009 17:50.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3069.2026 [GMT -7:00]
Running from: c:\users\crawford\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RI1UOY4\IMG_0615.JPG
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RI1UOY4\Picasa.ini
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$ROALP6W.picasaoriginals\.picasa.ini
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$ROALP6W.picasaoriginals\IMG_0994.JPG
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$ROQNWYU\_Setup.dll
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$ROQNWYU\ISSetup.dll
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RUJYZKI\.picasaoriginals\IMG_1087.JPG
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RXLYZOW\manifest.xml
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RXLYZOW\Racecars\05HospitalShootout_short.mp3
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RXLYZOW\Racecars\08Sweetnin_short.mp3
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RXLYZOW\Racecars\42Glamdring_short.mp3
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RXLYZOW\Racecars\edit1.jpg
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RXLYZOW\Racecars\edit2.jpg
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RXLYZOW\Racecars\projectIcon.jpg
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RXLYZOW\Racecars\SB_11293302.jpg
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RXLYZOW\Racecars\snappyIcon.jpg
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RXLYZOW\Racecars\template.swf
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RXLYZOW\Racecars\templateContent.xml
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RXLYZOW\Racecars\templateDescription.xml
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-1000\$RXLYZOW\Racecars\templateIcon.jpg
c:\$recycle.bin\S-1-5-21-2255522232-2540408132-457849326-500
c:\$recycle.bin\S-1-5-21-2289998049-2954938465-3815309393-500
c:\program files\TS\tsc.exe
c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
c:\programdata\ntuser.dat{84e998b7-07db-11dd-9f44-001eec03d37a}.TMContainer00000000000000000001.regtrans-ms
c:\users\crawford\AppData\Roaming\wiaserva.log
c:\users\crawford\Desktop\Total Security.lnk
c:\windows\Installer\WMEncoder.msi
c:\windows\system32\1251214205.exe
c:\windows\system32\1620298512.dat
c:\windows\system32\AutoRun.inf
----- BITS: Possible infected sites -----
hxxp://msgr.dlservice.microsoft.com
.
((((((((((((((((((((((((( Files Created from 2009-08-28 to 2009-09-28 )))))))))))))))))))))))))))))))
.
2009-09-28 01:35 . 2009-09-28 01:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-26 23:42 . 2009-03-08 11:32 72704 ----a-w- c:\windows\system32\admparse.dll
2009-09-20 00:54 . 2009-09-20 00:55 -------- d-----w- c:\users\carleen\AppData\Local\Microsoft Games
2009-09-18 00:37 . 2009-09-18 00:37 -------- d-----w- c:\program files\Common Files\TSUninstall
2009-09-18 00:37 . 2009-09-28 01:30 -------- d-----w- c:\program files\TS
2009-09-09 16:24 . 2009-09-09 16:24 3195 ----a-w- c:\users\senna\AppData\Local\olegasutiyayi.dll
2009-09-05 02:17 . 2009-09-05 02:17 3187 ----a-w- c:\users\senna\AppData\Local\ibezeleqayi.dll
2009-09-04 15:37 . 2009-09-04 15:37 3195 ----a-w- c:\users\senna\AppData\Local\uliyogom.dll
2009-09-03 21:52 . 2009-09-03 21:52 3211 ----a-w- c:\users\senna\AppData\Local\ekugubel.dll
2009-09-03 21:25 . 2009-09-03 21:25 -------- d-----w- c:\users\alec\AppData\Local\Adobe
2009-09-03 16:51 . 2009-09-09 00:36 3211 ----a-w- c:\users\senna\AppData\Local\eqexupetozuxaho.dll
2009-09-03 16:47 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-03 16:47 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-02 00:21 . 2009-09-02 00:21 3219 ----a-w- c:\users\senna\AppData\Local\axosabam.dll
2009-09-01 16:50 . 2009-09-01 16:50 3187 ----a-w- c:\users\senna\AppData\Local\unayiruburu.dll
2009-08-31 20:01 . 2009-08-31 20:01 3091 ----a-w- c:\users\senna\AppData\Local\ecehazuyosegefim.dll
2009-08-30 18:00 . 2009-08-30 18:00 -------- d-----w- c:\users\alec\AppData\Local\Unity
2009-08-29 23:45 . 2009-08-29 23:45 3195 ----a-w- c:\users\senna\AppData\Local\ejiyakiw.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-27 00:15 . 2009-03-14 01:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-26 23:54 . 2009-03-14 01:22 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-26 23:49 . 2008-08-13 01:10 -------- d-----w- c:\programdata\avg8
2009-09-26 23:45 . 2008-10-23 01:22 -------- d-----w- c:\users\crawford\AppData\Roaming\LimeWire
2009-09-26 21:44 . 2009-08-17 21:06 120 ----a-w- c:\users\senna\AppData\Local\Ykuxamujoyexam.dat
2009-09-23 00:11 . 2009-03-14 03:07 -------- d-----w- c:\users\senna\AppData\Roaming\LimeWire
2009-09-10 21:54 . 2009-03-14 01:20 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 21:53 . 2009-03-14 01:20 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-09 16:56 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-09 16:56 . 2007-11-21 05:15 -------- d-----w- c:\programdata\Microsoft Help
2009-08-21 18:53 . 2009-08-21 18:53 3227 ----a-w- c:\users\senna\AppData\Local\okilohawurovi.dll
2009-08-20 21:53 . 2009-08-20 21:53 3203 ----a-w- c:\users\senna\AppData\Local\arikinas.dll
2009-08-20 17:12 . 2009-03-14 04:18 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-20 17:12 . 2008-08-13 01:10 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-20 17:12 . 2008-04-13 00:02 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-14 17:07 . 2009-09-09 16:21 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 16:29 . 2009-09-09 16:21 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:29 . 2009-09-09 16:21 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:16 . 2009-09-09 16:21 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:16 . 2009-09-09 16:21 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:16 . 2009-09-09 16:21 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:16 . 2009-09-09 16:21 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:16 . 2009-09-09 16:21 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:16 . 2009-09-09 16:21 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:16 . 2009-09-09 16:21 10240 ----a-w- c:\windows\system32\finger.exe
2009-07-21 21:52 . 2009-09-26 23:43 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-09-26 23:43 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-09-26 23:43 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-09-26 23:43 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 20:08 . 2009-03-17 00:44 112408 ----a-w- c:\users\alec\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-17 14:35 . 2009-08-12 21:53 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-14 13:00 . 2009-08-12 21:53 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 12:59 . 2009-08-12 21:53 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-14 12:58 . 2009-08-12 21:53 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-14 10:59 . 2009-08-12 21:53 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-11 19:32 . 2009-09-09 16:21 513024 ----a-w- c:\windows\system32\wlansvc.dll
2009-07-11 19:32 . 2009-09-09 16:21 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-07-11 19:32 . 2009-09-09 16:21 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-07-11 19:29 . 2009-09-09 16:21 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-02-21 21:00 . 2009-02-21 21:00 37888 --sh--r- c:\windows\System32\apdsx.exe
2008-03-29 22:11 . 2008-03-29 22:11 4 --sh--r- c:\windows\System32\drivers\taishop.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2007-01-22 417792]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-07-27 204800]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-23 438272]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-08 55416]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-04-11 413696]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-09-11 180224]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-23 538744]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-20 2007832]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-02-19 267048]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-06-13 4489216]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-4-1 692224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuMyGames"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2255522232-2540408132-457849326-1000]
"EnableNotificationsRef"=dword:00000002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{346D3BA6-BEB2-464B-A6CF-F96476EC76B1}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{4F3F0893-6C72-4772-B321-2068238560FE}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{61DC09EE-6ED9-41F8-92D2-DB7D5A5C94B0}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{38C539B3-063F-4B7F-9F1A-38B5DECDE0B5}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{59BFE721-AF80-47B0-909D-79D234E513AA}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{C6F4CC72-1B77-483A-A0A6-DFEA0E2A2777}"= Disabled:UDP:d:\setup\HPZnui01.exe:hpznui01.exe
"{D02F16D0-3CB4-4527-8333-62AED97D56F2}"= Disabled:TCP:d:\setup\HPZnui01.exe:hpznui01.exe
"{F80A646E-FD4E-4F76-977F-F4C6BED54107}"= Disabled:UDP:d:\setup\HPZNUI01.EXE:hpznui01.exe
"{DE350171-5001-40D8-90EB-FBA8D26FFA91}"= Disabled:TCP:d:\setup\HPZNUI01.EXE:hpznui01.exe
"{EEA9EB90-DC9B-44AC-9731-9F5300028AEC}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{DE6BD288-EEE5-46C0-B9B1-2F7779FB720F}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{1E19496F-2346-4F33-8930-B9715AB53F84}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{EFC158BC-4ED7-4115-A134-BAB1F273186B}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{DFF055F9-CA74-425F-9D67-126185F3200A}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
"{90E7FDA4-99B2-40A6-ADA3-73823D8554C0}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
"{448342A1-9D40-4B37-B1A6-1F2A91C076D3}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
"{7AC38BD4-D00D-4A53-B788-FF9B34069C41}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
"{F597B22B-45A3-458E-9BB7-DFBEA8211544}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{CA55D2BC-5827-41E5-BEEB-3FDBBCEC67A8}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{469FBDE6-C4E7-4AE4-A61D-BE0D0C94F9BF}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe
"{DD531A9F-6E77-4A17-9ACC-CAE52A2CC636}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe
"{BD0B9E51-ED4D-4775-ABEB-D0A1B363D8BC}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{05DB087A-6E3D-45DC-AC2F-88E27FD73247}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{6B92AB37-AE7F-47F3-80F0-15889A0C6F9F}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{8C46B414-2BED-46A2-8C77-C8FC38444D3A}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{7128E0BB-6BEA-4EE1-85D6-5DE6C73A350B}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
"{3E4F247A-A31E-419F-8AC4-33673F32C232}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
"{06A19AC7-D37E-4EEB-A1CF-BC3FBFAE7B91}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe:hpqnrs08.exe
"{537A9610-54A5-4F26-9E71-26D53F9C14E5}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe:hpqnrs08.exe
"TCP Query User{7D9B14F7-437B-4B3E-901D-E1008C8DDA54}d:\\setup.exe"= UDP

:\setup.exe:Setup
"UDP Query User{CD7A8C80-27B1-4C0A-BF5A-7742F0291FD7}d:\\setup.exe"= TCP

:\setup.exe:Setup
"{D2416700-6204-4047-A334-268D581E8258}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{4077C923-9004-4325-AD09-1B75DB7F9794}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{76F9E9B6-BDAC-42F0-A571-AAB878FA8069}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{B2A96120-9C9D-489C-8949-D72AF75DD1DC}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{D6967C98-A5C7-4337-92FD-BAD2D4A20B6E}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{3912272F-681D-4001-B573-73C0E8F856AA}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{63FC3874-DF51-4CB1-A563-A95DFE433CA6}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{2563508C-142D-4F10-8DF2-44377A00A6E4}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{9CFF4BBF-35A3-44DB-9BE5-ADE5F1E7A560}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"= c:\toshiba\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\toshiba\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [8/12/2008 6:10 PM 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/13/2009 9:18 PM 297752]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [3/13/2009 6:22 PM 809296]
S2 SDRSVCidsvc;Windows Backup SDRSVCidsvc;c:\windows\system32\apdsx.exe srv --> c:\windows\system32\apdsx.exe srv [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2255522232-2540408132-457849326-1001Core.job
- c:\users\carleen\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-06 21:04]
2009-09-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2255522232-2540408132-457849326-1001UA.job
- c:\users\carleen\AppData\Local\Google\Update\GoogleUpdate.exe [2009-08-06 21:04]
2009-09-28 c:\windows\Tasks\User_Feed_Synchronization-{62097DF1-7580-4894-9F3D-8DF4A841945C}.job
- c:\windows\system32\msfeedssync.exe [2009-09-26 20:13]
2009-09-28 c:\windows\Tasks\User_Feed_Synchronization-{F18E36A0-DF8A-4213-8627-26D6771BDCB8}.job
- c:\windows\system32\msfeedssync.exe [2009-09-26 20:13]
2009-09-28 c:\windows\Tasks\User_Feed_Synchronization-{F61C58D8-CCC9-44CD-9333-3BFD7E7E10B6}.job
- c:\windows\system32\msfeedssync.exe [2009-09-26 20:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\wpclsp.dll
DPF: {26B2A5DA-BFD6-422F-A89A-28A54C74B12B} - hxxp://www.costcophotocenter.com/upload/activex/v3_0_0_4/PhotoCenter_ActiveX_Control.cab
DPF: {DEA6994F-3ED5-40BC-B5E3-0FD02411B1B4} - hxxp://www.costcophotocenter.com/upload/activex/v3_0_0_1/PhotoCenter_ActiveX_Control.cab?
DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} - hxxp://www.costcophotocenter.com/upload/activex/v3_0_0_2/PhotoCenter_ActiveX_Control.cab?
FF - ProfilePath - c:\users\crawford\AppData\Roaming\Mozilla\Firefox\Profiles\2ga920c5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-eeekp.sys
AddRemove-TS - c:\program files\TS\tsc.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-27 19:58
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(3456)
c:\program files\Logitech\SetPoint\lgscroll.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\toshiba\IVP\ISM\pinger.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\System32\TODDSrv.exe
c:\program files\Toshiba\Power Saver\TosCoSrv.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\System32\rundll32.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\AVG\AVG8\avgtray.exe
c:\program files\Synaptics\SynTP\SynToshiba.exe
c:\program files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\System32\wbem\WMIADAP.exe
.
**************************************************************************
.
Completion time: 2009-09-28 20:03 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-28 03:03
Pre-Run: 126,827,278,336 bytes free
Post-Run: 131,275,624,448 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
308