Logs requested
Combofix log:
ComboFix 08-07-26.1 - Ej Davis 2008-07-27 10:01:45.7 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.358 [GMT -4:00]
Running from: C:\Users\Ej Davis\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\eqvwamkl.dll
C:\Windows\nfavxwdbqxv.dll
C:\Windows\system32\adjngnax.dll
C:\Windows\system32\aefszr.dll
C:\Windows\system32\ajeypdjy.dll
C:\Windows\system32\bbukdkib.dll
C:\Windows\system32\cewyxj.dll
C:\Windows\system32\eiobun.dll
C:\Windows\system32\epijwfqa.dll
C:\Windows\System32\fiblajcw.ini
C:\Windows\system32\frlhiwoo.dll
C:\Windows\system32\gbtcwd.dll
C:\Windows\system32\hdsxfnph.dll
C:\Windows\system32\iovhbtqs.dll
C:\Windows\system32\jffejvco.ini
C:\Windows\system32\kacyfxxu.dll
C:\Windows\system32\kptvqvkv.dll
C:\Windows\system32\kxxmqvhf.dll
C:\Windows\system32\ldrwut.dll
C:\Windows\system32\mcrh.tmp
C:\Windows\system32\occenyqm.dll
C:\Windows\system32\qwhpbyhf.dll
C:\Windows\system32\rnbtwjtg.dll
C:\Windows\system32\rtnftwia.dll
C:\Windows\system32\sAcdNXyb.ini
C:\Windows\System32\sAcdNXyb.ini2
C:\Windows\system32\svvnli.dll
C:\Windows\system32\syvocuik.dll
C:\Windows\system32\tapncfed.dll
C:\Windows\system32\tgvtbpmu.dll
C:\Windows\system32\tknkghug.dll
C:\Windows\System32\umpbtvgt.ini
C:\Windows\system32\ussgpfck.dll
C:\Windows\system32\vrrgkqtg.dll
C:\Windows\system32\wcjalbif.dll
C:\Windows\system32\wlbieokk.dll
C:\Windows\System32\xangnjda.ini
C:\Windows\system32\yudesrns.dll
.
((((((((((((((((((((((((( Files Created from 2008-06-27 to 2008-07-27 )))))))))))))))))))))))))))))))
.
2008-07-24 15:42 . 2008-07-24 15:45 <DIR> d-------- C:\Program Files\Instant Scenery
2008-07-24 15:20 . 2008-07-24 15:20 <DIR> d-------- C:\Program Files\AI Flight Creator
2008-07-24 09:03 . 2008-07-24 15:41 737,280 --a------ C:\Windows\iun6002.exe
2008-07-24 09:02 . 2008-07-24 15:46 <DIR> d-------- C:\Users\Ej Davis\AppData\Roaming\Flight1
2008-07-24 09:02 . 2008-07-24 09:07 <DIR> d-------- C:\Program Files\AFX
2008-07-23 17:10 . 2008-07-23 17:10 <DIR> d-------- C:\Program Files\FLIGHT1
2008-07-23 17:07 . 2008-07-23 17:19 834 ---hs---- C:\Windows\System32\inhiovqp.ini
2008-07-23 11:13 . 2008-03-29 14:32 50,768 --a------ C:\Windows\System32\drivers\aswMonFlt.sys
2008-07-23 06:57 . 2008-07-23 13:41 32,256 --a------ C:\Windows\SysC43A.exe
2008-07-23 06:57 . 2008-07-23 13:41 31,744 --a------ C:\Windows\SysC4A7.exe
2008-07-23 04:32 . 2008-07-22 15:00 30,720 --a------ C:\Windows\SysD90F.exe
2008-07-23 04:32 . 2008-07-22 15:00 30,208 --a------ C:\Windows\SysD806.exe
2008-07-22 22:20 . 2008-07-22 22:27 <DIR> d-------- C:\ComboFix(0)
2008-07-22 21:51 . 2008-07-22 21:51 <DIR> d-------- C:\Program Files\Alwil Software
2008-07-22 20:19 . 2008-07-22 15:00 30,720 --a------ C:\Windows\SysB837.exe
2008-07-22 20:19 . 2008-07-22 15:00 30,208 --a------ C:\Windows\SysAF22.exe
2008-07-22 19:03 . 2008-07-22 19:03 323,648 --a------ C:\Windows\System32\byXNdcAs.dll
2008-07-22 18:57 . 2008-07-22 13:48 86,016 --a------ C:\Windows\grswptdl.exe
2008-07-22 18:53 . 2008-07-18 19:54 32,256 --a------ C:\Windows\SysE612.exe
2008-07-22 18:53 . 2008-07-18 19:54 31,744 --a------ C:\Windows\SysE6AE.exe
2008-07-22 18:53 . 2008-07-18 19:54 30,720 --a------ C:\Windows\SysE805.exe
2008-07-22 18:53 . 2008-07-18 19:54 30,208 --a------ C:\Windows\SysE70B.exe
2008-07-22 18:23 . 2008-07-22 20:00 <DIR> d-------- C:\Users\All Users\PC Drivers HeadQuarters
2008-07-22 18:23 . 2008-07-22 20:00 <DIR> d-------- C:\ProgramData\PC Drivers HeadQuarters
2008-07-22 18:23 . 2008-07-22 18:23 <DIR> d-------- C:\Program Files\PC Drivers HeadQuarters
2008-07-17 20:41 . 2008-06-25 20:33 12,240,896 --a------ C:\Windows\System32\NlsLexicons0007.dll
2008-07-17 20:41 . 2008-06-25 20:33 2,644,480 --a------ C:\Windows\System32\NlsLexicons0009.dll
2008-07-17 20:39 . 2008-06-25 20:33 11,722,752 --a------ C:\Windows\System32\NlsLexicons0001.dll
2008-07-16 22:42 . 2008-07-16 22:42 <DIR> d-------- C:\Program Files\WinAVIVideoConverter
2008-07-16 22:35 . 2008-07-16 22:35 <DIR> d-------- C:\DVDVideoSoft
2008-07-16 22:34 . 2008-07-16 22:34 <DIR> d-------- C:\Program Files\DVDVideoSoft
2008-07-16 22:34 . 2008-07-16 22:34 <DIR> d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-07-16 22:10 . 2008-07-16 22:10 <DIR> d-------- C:\Program Files\Image Converter .EXE
2008-07-16 22:10 . 2008-07-16 22:10 <DIR> d-------- C:\Program Files\Common Files\SoftTech InterCorp
2008-07-16 22:10 . 2004-10-27 10:52 834,128 --a------ C:\Windows\System32\Actbar2.ocx
2008-07-16 22:10 . 2007-05-04 23:17 561,152 --a------ C:\Windows\System32\AltST.dll
2008-07-16 22:10 . 2000-07-31 14:47 491,520 --a------ C:\Windows\System32\imagx4.dll
2008-07-16 22:10 . 2000-06-29 16:38 421,888 --a------ C:\Windows\System32\imagr4.dll
2008-07-16 22:10 . 2002-09-21 16:08 372,736 --a------ C:\Windows\System32\ShellExtension.dll
2008-07-16 22:10 . 2000-07-31 18:16 250,736 --a------ C:\Windows\System32\ImagXpr4.dll
2008-07-16 22:10 . 2006-09-28 17:55 57,344 --a------ C:\Windows\System32\sticversion.exe
2008-07-16 22:10 . 2000-06-27 08:31 35,328 --a------ C:\Windows\System32\picn20.dll
2008-07-09 16:45 . 2008-07-09 16:45 <DIR> d-------- C:\Users\Ej Davis\AppData\Roaming\WinCare2008
2008-07-09 16:45 . 2008-07-09 16:53 <DIR> d-------- C:\Program Files\Spotmau WinCare 2008
2008-07-07 08:57 . 2008-07-07 08:57 <DIR> d-------- C:\Program Files\Data Doctor Recovery Removable Media (Demo)
2008-07-04 10:46 . 2008-07-04 10:46 <DIR> d-------- C:\Program Files\FS2004 Night Time
2008-07-02 18:43 . 2008-07-02 18:43 <DIR> d-------- C:\Windows\CONCORDE SSTSIM
2008-07-02 18:43 . 2005-04-27 05:36 2,048 --a------ C:\Windows\sstv10.lic
2008-07-02 18:35 . 2008-07-02 18:35 <DIR> d-------- C:\Windows\SSTSim
2008-07-02 16:49 . 2008-07-25 16:47 <DIR> d-------- C:\Program Files\FS Panel Studio
2008-06-30 17:24 . 2008-06-30 18:34 81,984 --a------ C:\Windows\System32\bdod.bin
2008-06-30 16:00 . 2008-06-30 16:00 121 --a------ C:\Windows\bdagent.INI
2008-06-30 15:41 . 2008-06-30 18:36 <DIR> d-------- C:\Program Files\BitDefender
2008-06-30 15:39 . 2008-06-30 17:10 <DIR> d-------- C:\Program Files\Common Files\BitDefender
2008-06-27 14:33 . 2008-06-27 14:33 <DIR> d-------- C:\Users\Ej Davis\AppData\Roaming\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-27 14:10 --------- d---a-w C:\ProgramData\TEMP
2008-07-27 14:08 --------- d-----w C:\Users\Ej Davis\AppData\Roaming\DNA
2008-07-26 20:18 --------- d-----w C:\Program Files\Mozilla Firefox 3 Beta 4
2008-07-25 21:04 --------- d-----w C:\Users\Ej Davis\AppData\Roaming\BitTorrent
2008-07-23 21:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-23 12:30 --------- d-----w C:\ProgramData\Ulead Systems
2008-07-23 12:30 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-07-21 09:07 1,328 ----a-w C:\FSUIPC_reg.bin
2008-07-20 23:35 --------- d-----w C:\Program Files\Microsoft Games
2008-07-18 19:13 --------- d-----w C:\Users\Ej Davis\AppData\Roaming\LimeWire
2008-07-17 14:10 --------- d-----w C:\Program Files\LimeWire
2008-07-10 13:07 --------- d-----w C:\Program Files\Windows Mail
2008-07-09 20:35 --------- d-----w C:\Program Files\Ulead Systems
2008-06-25 22:36 --------- d-----w C:\ProgramData\Hewlett-Packard
2008-06-25 21:21 --------- d-----w C:\ProgramData\HP
2008-06-25 20:37 --------- d-----w C:\Users\Ej Davis\AppData\Roaming\ESTsoft
2008-06-25 20:33 --------- d-----w C:\ProgramData\ESTsoft
2008-06-25 20:32 --------- d-----w C:\Program Files\ESTsoft
2008-06-05 19:54 --------- d-----w C:\Users\Ej Davis\AppData\Roaming\NewzToolz
2008-06-05 02:45 --------- d-----w C:\Users\Ej Davis\AppData\Roaming\Ulead Systems
2008-06-03 19:37 --------- d-----w C:\Program Files\GameSpy Arcade
2008-06-03 02:03 --------- d-----w C:\Program Files\Watchtower
2008-06-03 00:41 --------- d-----w C:\ProgramData\InterVideo
2008-06-03 00:41 --------- d-----w C:\Program Files\Common Files\InterVideo
2008-05-31 12:06 --------- d-----w C:\Program Files\VideoShow Expressions
2008-05-31 11:51 --------- d-----w C:\ProgramData\McAfee
2008-05-31 11:51 --------- d-----w C:\Program Files\McAfee
2008-05-31 00:11 --------- d-----w C:\Users\Ej Davis\AppData\Roaming\McAfee
2008-05-31 00:10 --------- d-----w C:\ProgramData\SiteAdvisor
2008-05-04 18:03 286,720 ----a-w C:\Windows\iun506.exe
2007-11-22 03:14 198 ----a-w C:\Users\Ej Davis\AppData\Roaming\wklnhst.dat
2007-10-07 01:39 174 --sha-w C:\Program Files\desktop.ini
2008-03-18 02:19 61 --sh--w C:\Windows\cnerolf.bin
2008-03-10 00:44 119 --sh--w C:\Windows\cnerolf.dat
2005-08-25 03:10 174,592 --sha-w C:\Windows\System32\ncfpsys.exe
2008-04-22 22:56 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat
2008-04-22 22:57 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008042220080423\index.dat
.
((((((((((((((((((((((((((((( snapshot@2008-07-23_ 4.52.13.97 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-23 08:47:13 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-07-27 14:10:44 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-07-27 14:10:44 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-07-23 08:47:13 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-07-27 14:10:44 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-07-27 14:10:44 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
+ 2008-03-29 18:45:49 1,146,232 ----a-w C:\Windows\System32\aswBoot.exe
+ 2008-03-29 18:23:22 95,608 ----a-w C:\Windows\System32\AvastSS.scr
+ 2008-07-24 19:44:32 34,308 ----a-w C:\Windows\System32\BASSMOD.dll
- 2008-07-23 01:41:55 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-07-27 14:10:26 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-07-23 01:41:55 147,456 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-07-27 14:10:26 147,456 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-07-23 01:41:55 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-07-27 14:10:26 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-07-23 12:30:29 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-07-27 14:01:32 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-03-29 18:35:49 20,560 ----a-w C:\Windows\System32\drivers\aswFsBlk.sys
+ 2008-03-29 18:29:08 23,152 ----a-w C:\Windows\System32\drivers\aswRdr.sys
+ 2008-03-29 18:31:34 75,856 ----a-w C:\Windows\System32\drivers\aswSP.sys
+ 2008-03-29 18:27:33 42,912 ----a-w C:\Windows\System32\drivers\aswTdi.sys
- 2008-07-23 08:48:41 20,570 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-443751153-3735565120-1847588147-1000_UserData.bin
+ 2008-07-27 13:41:20 21,402 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-443751153-3735565120-1847588147-1000_UserData.bin
- 2008-07-23 08:48:41 68,494 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-07-27 13:41:20 69,648 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-07-23 08:48:37 65,050 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-07-23 22:19:15 67,620 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-07-22 19:18:18 272,160 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2008-07-26 20:42:26 280,506 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2008-07-23 08:41:45 124,015,103 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2008-07-23 19:48:02 212,093,859 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E6EE385F-04CE-403D-9747-5A62F49270F2}]
2008-07-22 19:03 323648 --a------ C:\Windows\system32\byXNdcAs.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\FolderProtect0]
@="{D7BC78F3-3624-455C-8C4B-9C77C3BFEE4E}"
[HKEY_CLASSES_ROOT\CLSID\{D7BC78F3-3624-455C-8C4B-9C77C3BFEE4E}]
2007-12-02 17:05 348160 --a------ C:\Program Files\Spotmau WinCare 2008\sub\FSDRIVER\FolderProtectShellExtension.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\FolderProtect1]
@="{8A814C29-D3CD-4F9E-9770-DF8704503ACA}"
[HKEY_CLASSES_ROOT\CLSID\{8A814C29-D3CD-4F9E-9770-DF8704503ACA}]
2007-12-02 17:05 348160 --a------ C:\Program Files\Spotmau WinCare 2008\sub\FSDRIVER\FolderProtectShellExtension.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2006-11-10 17:22 417792]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-06 20:56 289088]
"Uniblue RegistryBooster 2"="c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe" [2008-05-05 13:01 99608]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 05:39 486856]
"Desktop Secretary"="C:\Program Files\Spotmau WinCare 2008\sub\Desktop_Secretary\Desktop_Secretary.exe" [2008-01-24 18:54 1265664]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 08:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-25 21:45 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"UVS11 Preload"="C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe" [2007-07-23 13:55 341232]
"f6bf4d3c"="C:\Windows\system32\ocvjeffj.dll" [BU]
"BMf58c7ea0"="C:\Windows\system32\hdsxfnph.dll" [BU]
C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 23:24:54 98632]
C:\Users\Ej Davis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"VIDC.ZDSV"= scrvid.dll
"msacm.MPEGacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
[HKLM\~\startupfolder\C:^Users^Ej Davis^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=C:\Users\Ej Davis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=C:\Windows\pss\OpenOffice.org 2.3.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Ej Davis^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Screenshot Utility.lnk]
backupExtension=.Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\au
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\
00TCrdMain]
--a------ 2006-12-15 18:59 530552 C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
--a------ 2008-05-06 20:56 289088 C:\Program Files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GeelixHUDDesktop]
--a------ 2008-03-18 17:18 2146304 C:\Program Files\Geelix.4.0.6.0\GeelixHUDDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2007-05-22 18:39 1862144 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2008-01-02 17:06 166424 C:\Windows\System32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HSON]
--a------ 2006-12-07 19:49 55416 C:\Program Files\Toshiba\TBS\HSON.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HWSetup]
--a------ 2006-11-01 11:06 413696 C:\Program Files\Toshiba\Utilities\HWSetup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2008-01-02 17:07 141848 C:\Windows\System32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
--a------ 2007-08-31 12:01 1037736 C:\Program Files\Microsoft IntelliPoint\ipoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeNotify]
--a------ 2006-11-06 20:14 34352 C:\Program Files\Toshiba\Utilities\KeNotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
--a------ 2005-12-16 05:41 188416 C:\Program Files\ltmoh\ltmoh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
--a------ 2008-01-02 17:07 133656 C:\Windows\System32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
--a------ 2007-10-23 17:18 443968 C:\Program Files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\prntscrn]
--a------ 2006-01-03 22:55 1257472 C:\Program Files\PrntScrn.NET\PrntScrn.NET.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Screen Recorder]
--a------ 2007-05-24 13:19 860160 C:\Program Files\ZD Soft\Screen Recorder\srecorder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
--a------ 2006-12-11 20:45 448632 C:\Program Files\Toshiba\SmoothView\SmoothView.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SVPWUTIL]
--a------ 2006-01-18 19:06 421888 C:\Program Files\Toshiba\Utilities\SVPWUTIL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-12-25 21:45 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPwrMain]
--a------ 2006-12-20 02:16 411768 C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2007-10-06 21:31 1006264 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 2006-11-09 13:57 3784704 C:\Windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A128CD60-A295-4083-AE9E-A518E58012BD}"= UDP:C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{01069126-3EC4-4B6A-83FA-65AF7223E68A}"= TCP:C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{AFC464D8-51FB-4D4C-BD78-3EB9F37E7554}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A5E1D63E-4ED9-4CA0-A6E5-D1DD9E835E41}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{383D3605-14AF-4742-9811-253368481467}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{F4839679-2742-451D-84DA-D6431B70B215}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{62569EA4-D9B0-43A0-964F-8DAF85E4CFE8}C:\\program files\\bitlord\\bitlord.exe"= UDP:C:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{37162428-355F-4493-BD59-150D9B5B431D}C:\\program files\\bitlord\\bitlord.exe"= TCP:C:\program files\bitlord\bitlord.exe:BitLord
"TCP Query User{45B8494F-7BC8-4CA3-A885-CE294C55029E}C:\\program files\\bitlord2\\bitlord.exe"= UDP:C:\program files\bitlord2\bitlord.exe:
"UDP Query User{DF76B48B-340B-4127-8AD8-52BB46911588}C:\\program files\\bitlord2\\bitlord.exe"= TCP:C:\program files\bitlord2\bitlord.exe:
"{B68AE2BF-CAC6-4F3A-81D4-9E908F14F384}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{3F752D21-D9FE-4D32-87CE-DB7F67D1B5EA}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{3B0269F1-1168-4A40-A5A8-196B320E1A34}C:\\program files\\bitlord2\\bitlord.exe"= UDP:C:\program files\bitlord2\bitlord.exe:
"UDP Query User{B37624B8-CF3C-484A-AB6C-C216B09C523A}C:\\program files\\bitlord2\\bitlord.exe"= TCP:C:\program files\bitlord2\bitlord.exe:
"TCP Query User{A24B4CB1-EA00-45DE-935C-444329E2CCAF}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{07A4700A-36AF-4C52-A9AB-9EB7DAC3C359}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"{7A6552FA-EFDC-4F47-890B-3321E8A5D714}"= UDP:C:\Program Files\DNA\btdna.exe

NA
"{CD8059C6-78D0-4B67-9D2F-649D12B81AF8}"= TCP:C:\Program Files\DNA\btdna.exe

NA
"{0125D812-FCF2-4D12-93BF-9AD87BB5A9F4}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{D4DF4749-D771-46F3-9D2D-25A21F60C1C1}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{8742A762-2A34-4EEE-B919-3B55B868860F}"= UDP:C:\Program Files\DNA\btdna.exe

NA
"{DF6912B5-D9A6-4C42-B281-FCAA41ACFEAB}"= TCP:C:\Program Files\DNA\btdna.exe

NA
"{7BB5575D-5A2E-416B-BFC1-460DBC2DE7A7}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{6BB1DDCB-B885-4EFC-AA6C-6DE6E8942794}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{C0B4C0F4-7D17-4CBB-8173-56BA1BA1832F}C:\\program files\\microsoft games\\halo trial\\halo.exe"= UDP:C:\program files\microsoft games\halo trial\halo.exe:Halo
"UDP Query User{B08DC92D-B0CB-4147-9A5D-AD44D68B03F3}C:\\program files\\microsoft games\\halo trial\\halo.exe"= TCP:C:\program files\microsoft games\halo trial\halo.exe:Halo
"TCP Query User{18FDA89F-E585-4F52-8C2B-38336977DB76}C:\\program files\\real\\realplayer\\realplay.exe"= UDP:C:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{BF73257E-EA44-4685-AA25-99B5CFF0968E}C:\\program files\\real\\realplayer\\realplay.exe"= TCP:C:\program files\real\realplayer\realplay.exe:RealPlayer
"TCP Query User{7A8F3A28-2D0D-4A2C-9166-F48285C29FA3}C:\\program files\\microsoft games\\flight simulator 9\\fs9.exe"= UDP:C:\program files\microsoft games\flight simulator 9\fs9.exe:Microsoft Flight Simulator
"UDP Query User{CF5F1730-6CDC-452D-9812-DF9E6DA77110}C:\\program files\\microsoft games\\flight simulator 9\\fs9.exe"= TCP:C:\program files\microsoft games\flight simulator 9\fs9.exe:Microsoft Flight Simulator
"TCP Query User{0845F57D-8502-4255-A0AD-6E317EAB047B}C:\\windows\\system32\\dpnsvr.exe"= UDP:C:\windows\system32\dpnsvr.exe:Microsoft DirectPlay8 Server
"UDP Query User{F79A2E70-6566-441A-B680-64CBDB665BBD}C:\\windows\\system32\\dpnsvr.exe"= TCP:C:\windows\system32\dpnsvr.exe:Microsoft DirectPlay8 Server
"{D37B31E2-447F-4DC0-B78D-36A8613A7D62}"= Disabled:UDP:C:\Users\Ej Davis\AppData\Roaming\U3\
00001853E472B205\
0DE4F643-C398-46ec-9339-2362F2311932\Exec\Skype.exe:Skype
"{0AE34C26-7595-4FF6-876F-13732AB82713}"= Disabled:TCP:C:\Users\Ej Davis\AppData\Roaming\U3\
00001853E472B205\
0DE4F643-C398-46ec-9339-2362F2311932\Exec\Skype.exe:Skype
"TCP Query User{0D40E195-4BA2-440F-85E3-BDCD54B0547A}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{8F49B554-1599-4687-AB54-475A319A6F0F}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"{82DC7C4B-2CF9-4882-ABB7-BF714158C0C3}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{14357B79-8EDC-4A5A-B81F-106C673BB01D}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{63E4D837-91FF-481E-B4D7-1527796750C0}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"TCP Query User{5B67FEF3-CA9E-4964-887D-BD17BE01F31F}C:\\program files\\microsoft games\\halo\\halo.exe"= UDP:C:\program files\microsoft games\halo\halo.exe:Halo
"UDP Query User{5F3816AF-6CFA-4844-8A5C-C01838E339A1}C:\\program files\\microsoft games\\halo\\halo.exe"= TCP:C:\program files\microsoft games\halo\halo.exe:Halo
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"= C:\TOSHIBA\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= C:\TOSHIBA\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-03-29 14:31]
R1 FolderProtectDriver;FolderProtectDriver;C:\Program Files\Spotmau WinCare 2008\sub\FSDRIVER\FolderProtectDriverVista.sys [2008-01-10 22:20]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-03-29 14:35]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-03-29 14:32]
R2 FolderProtectService;FolderProtectService;C:\Program Files\Spotmau WinCare 2008\sub\FSDRIVER\FolderProtectService.exe [2007-12-22 00:23]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 ssoftnt4;ssoftnt4;C:\Windows\system32\Drivers\ssoftnt4.sys [2007-07-13 19:05]
R3 scrcap;scrcap;C:\Windows\system32\DRIVERS\scrcap.sys [2006-12-27 10:47]
S3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys [2006-11-02 05:15]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{464d0f1e-e35a-11dc-9b7e-001b383e0102}]
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Password.txt
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4a41218a-42f1-11dd-915b-001b383e0102}]
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Password.txt
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{63e916d4-16f1-11dd-b4d0-001b383e0102}]
\shell\AutoRun\command - F:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c54aee68-2201-11dd-a4a9-001b383e0102}]
\shell\AutoRun\command - E:\setup.exe /autorun
\shell\directx\command - E:\DirectX\dxsetup.exe
\shell\setup\command - E:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef1ba05d-a4ef-11dc-ad5a-001b383e0102}]
\shell\AutoRun\command - E:\Autorun.exe /run
\shell\Shell00\Command - E:\Autorun.exe /run
\shell\Shell01\Command - E:\Autorun.exe /action
\shell\Shell02\Command - E:\Autorun.exe /uninstall
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f6d9ac79-d975-11dc-9f46-001b383e0102}]
\shell\AutoRun\command - G:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2008-05-08 C:\Windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job - s !8C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe/AUTOCHECK /AUTOFIX Ej Davis []
.
- - - - ORPHANS REMOVED - - - -
BHO-{3A1D80A5-75D4-4548-BD79-5BBEEB2D1267} - C:\Users\Ej Davis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4Y1U1TO6\3077ahntdksr[1].dll
SSODL-eqvwamkl-{6056154C-5A2B-482A-910A-16252D26D460} - C:\Windows\eqvwamkl.dll
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://airliners.net/
R0 -: HKCU-Main,Default_Search_URL = hxxp://www.google.com/ie
R1 -: HKCU-Internet Settings,ProxyOverride = local
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-27 10:10:51
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Fraps\fraps.exe
C:\Windows\System32\agrsmsvc.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\Windows\System32\cryptainersrv.exe
C:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Windows\System32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Spotmau WinCare 2008\sub\FSDRIVER\FolderProtect.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\VSSVC.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-07-27 10:18:05 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-27 14:17:51
ComboFix2.txt 2008-07-23 19:29:00
ComboFix3.txt 2008-07-23 16:34:33
ComboFix4.txt 2008-07-23 16:14:00
ComboFix5.txt 2008-07-27 13:58:36
Pre-Run: 35,238,617,088 bytes free
Post-Run: 35,024,359,424 bytes free
419 --- E O F --- 2008-07-23 19:51:27
__________________________________________________________________________________
__________________________________________________________________________________
HJT LOG:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:19:14 AM, on 7/27/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Fraps\fraps.exe
C:\Program Files\Spotmau WinCare 2008\sub\FSDRIVER\FolderProtect.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Spotmau WinCare 2008\sub\Desktop_Secretary\Desktop_Secretary.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://airliners.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {E6EE385F-04CE-403D-9747-5A62F49270F2} - C:\Windows\system32\byXNdcAs.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [UVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
O4 - HKLM\..\Run: [f6bf4d3c] rundll32.exe "C:\Windows\system32\ocvjeffj.dll",b
O4 - HKLM\..\Run: [BMf58c7ea0] Rundll32.exe "C:\Windows\system32\hdsxfnph.dll",s
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Desktop Secretary] "C:\Program Files\Spotmau WinCare 2008\sub\Desktop_Secretary\Desktop_Secretary.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: FolderProtectService - Unknown owner - C:\Program Files\Spotmau WinCare 2008\sub\FSDRIVER\FolderProtectService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: pinger - Unknown owner - C:\TOSHIBA\IVP\ISM\pinger.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Cryptainer service (ssoftservice) - Cypherix Software (India) Pvt. Ltd. - C:\Windows\SYSTEM32\cryptainersrv.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 7961 bytes
____________________________________________________________________________
____________________________________________________________________________
HJT UNINSTALL LOG:
A380 pour FS2004
Activation Assistant for the 2007 Microsoft Office suites
Active Camera 2004 2.1 for FS 2004 (updated to 9.1)
Ad-Aware 2007
Adobe Bridge 1.0
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 8.1.2
Adobe Shockwave Player
Adobe Stock Photos 1.0
AFX
AFX
AI Flight Creator 1.7.4
Airbus Fleet
Airport for Windows Upgrade to v2.60
ALZip
ARNZ ATR72-200 & 500
AS355 VH-NEH. North Eastern Helicopters.
AS355, N588BP operated by Texair.
Atheros Driver Installation Program
Audio Recorder for FREE v9.4
avast! Antivirus
Bat
Bejeweled 2 Deluxe
Blackhawk Striker 2
Blaine's Letterbox Effects
Blasterball 3
Bluetooth Stack for Windows by Toshiba
BusRunner
CCleaner (remove only)
CD/DVD Drive Acoustic Silencer
ClonyXXL
CONCORDE SSTSIM
Cryptainer LE
Dash 8Q-300 by fanda v1.004
Data Doctor Recovery Removable Media (Demo)
Desktop Activity Recorder 1.6
Desktop Dialer
Diner Dash - Flo on the Go
DUBAÏ 2004
DUBAÏ landclass
DUBAÏ mesh
DVD MovieFactory for TOSHIBA
EditVoicepack
Eurocopter AS355, G-JPAL
Eurocopter AS355, ZJ139, RAF Royal Flight.
Eurocopter AS355. C-FOPP. Ontario Provincial Police.
Express Burn
Expstudio Audio Editor FREE
FastStone Photo Resizer 1.4
FATE
FeelThere PIC ERJ-145LR 1.0
Flight Simulator 2004 BGLComp SDK
Fraps (remove only)
Free FLV Converter V 1.0
Free Video to Flash Converter version 4.1
FS Architect
FS Panel Studio for FSX Build 20207
FS Recorder 1.32 for FS2004
FS2004 Night Time
FSAddon - FSCargo
FSCamera
GameSpy Arcade
Google Desktop
Google Earth
Google SketchUp 6
Google SketchUp 6
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Ground Environment Professional
HijackThis 2.0.2
Image Converter .EXE 2.0.0.81
Image ReSizer 1.6
ImageSkill Magic Enhancer Lite (remove only)
Instant Scenery
Intel(R) Graphics Media Accelerator Driver
Internet Offers
InterVideo DeviceService
Islands of the West Indies
IsoBuster 2.2
Java(TM) 6 Update 5
Java(TM) SE Runtime Environment 6
LimeWire 4.16.7
Line Rider
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB929729)
Microsoft Flight Simulator 2004 A Century of Flight
Microsoft Halo
Microsoft MPEG-4 VKI Video Codec V1/V2/V3
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual J# 2.0 Redistributable Package - SE
Microsoft Works
Mozilla Firefox (2.0.0.14)
Mozilla Firefox (2.0.0.16)
Mozilla Firefox (3.0b5)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 Parser and SDK
Multi-Soundboard Player 1.5.0
MySQL Connector/ODBC 3.51
Napster
Napster Burn Engine
NewzToolz v2.0.2
oggcodecs 0.71.0946
OpenOffice.org 2.3
Opera 9.27
Password Protect USB 3.6.1
Penguins!
Picasa 2
Polar Bowler
Polar Golfer
PrntScrn.NET
Radar v2.0 for FS2004
RealPlayer
Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
Realtek High Definition Audio Driver
Remove UK2000 Gatwick FREE files
SoundTap
SpeedUp for MS FlightSimulator 9
SpongeBob Monopoly Free
Spotmau Wincare 2008
Spybot - Search & Destroy
Switch
TeamSpeak 2 RC2
Texas Instruments PCIxx21/x515/xx12 drivers.
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA Disc Creator
TOSHIBA Extended Tiles for Windows Mobility Center
TOSHIBA Flash Cards Support Utility
TOSHIBA Game Console
TOSHIBA Hardware Setup
TOSHIBA Media Center Game Console
TOSHIBA Music
Toshiba Registration
TOSHIBA SD Memory Utilities
TOSHIBA Software Modem
TOSHIBA Software Upgrades
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
Total Video Converter 3.10
Ulead VideoStudio 11
Uniblue RegistryBooster 2
Uninstall 1.0.0.1
Uninstall VAFS
Uninstall VCAS
Update for Office 2007 (KB934528)
Update for Office System 2007 Setup (KB929722)
VideoShow Expressions
VisioForge Video Edit SDK (Delphi) + MPEG
VRtainment CapturePad 0.1beta
WavePad Uninstall
WinAVIVideoConverter
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Player Firefox Plugin
Windows Movie Maker 2 Winter Fun Pack
Windows Movie Maker 2.6
WinDVD for TOSHIBA
Wisdom-soft AutoScreenRecorder 2.0 Free
Wisdom-soft AutoScreenRecorder 2.1 Pro
Wisdom-soft Toolbar
WM Converter 2.0
XviD MPEG-4 Video Codec
Yahoo! Install Manager
Yahoo! Music Jukebox
Yahoo! Toolbar
ZD Soft Screen Recorder
ZD Soft Screen Video Decoder
THANK YOU SO MUCH FOR THE HELP

By the way, when combofix was rebooting my computer, right before it shut down, a error message popped. i was reading it quick but i believe it said: Application Failed to Launch Properly. 0 * 000142
