Hi SpySentinel
I downloaded
COMBO FIX and followed the onscreen prompts until a log file report was generated which l copied and pasted below:
ComboFix 09-04-04.01 - Toshiba 2009-04-10 14:44:54.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1014.149 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: PCguard Anti-Virus *On-access scanning disabled* (Updated)
FW: PCguard Firewall *enabled*
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-03-10 to 2009-04-10 )))))))))))))))))))))))))))))))
.
2009-04-10 14:26 . 2006-03-03 00:42 73,728 –a—— C:\pv.exe
2009-04-09 13:21 . 2009-04-09 13:21 d——– c:\users\All Users\SiteAdvisor
2009-04-09 13:21 . 2009-04-09 13:21 d——– c:\programdata\SiteAdvisor
2009-04-09 13:17 . 2009-04-09 13:17 d——– c:\program files\Common Files\McAfee
2009-04-09 13:16 . 2009-04-09 13:16 d——– c:\users\All Users\Yahoo! Companion
2009-04-09 13:16 . 2009-04-09 13:17 d——– c:\users\All Users\McAfee
2009-04-09 13:16 . 2009-04-09 13:16 d——– c:\programdata\Yahoo! Companion
2009-04-09 13:16 . 2009-04-09 13:17 d——– c:\programdata\McAfee
2009-04-09 13:16 . 2009-04-09 14:14 d——– c:\program files\McAfee
2009-04-09 13:13 . 2009-04-09 13:16 d——– c:\program files\SpywareGuard
2009-04-09 13:09 . 2009-04-09 13:09 d——– c:\program files\SpywareBlaster
2009-04-09 09:30 . 2008-06-20 02:14 781,344 –a—— c:\windows\System32\PresentationNative_v0300.dll
2009-04-09 09:30 . 2008-06-20 02:14 622,080 –a—— c:\windows\System32\icardagt.exe
2009-04-09 09:30 . 2008-06-20 02:14 326,160 –a—— c:\windows\System32\PresentationHost.exe
2009-04-09 09:30 . 2008-06-20 02:14 105,016 –a—— c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-04-09 09:30 . 2008-06-20 02:14 97,800 –a—— c:\windows\System32\infocardapi.dll
2009-04-09 09:30 . 2008-06-20 02:14 43,544 –a—— c:\windows\System32\PresentationHostProxy.dll
2009-04-09 09:30 . 2008-06-20 02:14 37,384 –a—— c:\windows\System32\infocardcpl.cpl
2009-04-09 09:30 . 2008-06-20 02:14 11,264 –a—— c:\windows\System32\icardres.dll
2009-04-09 09:20 . 2008-07-27 19:03 96,760 –a—— c:\windows\System32\dfshim.dll
2009-04-09 09:19 . 2008-07-27 19:03 282,112 –a—— c:\windows\System32\mscoree.dll
2009-04-09 09:19 . 2008-07-27 19:03 158,720 –a—— c:\windows\System32\mscorier.dll
2009-04-09 09:19 . 2008-07-27 19:03 83,968 –a—— c:\windows\System32\mscories.dll
2009-04-09 09:19 . 2008-07-27 19:03 41,984 –a—— c:\windows\System32\netfxperf.dll
2009-04-08 15:59 . 2009-04-08 15:59 d——– C:\_OTMoveIt
2009-04-05 19:21 . 2009-04-09 13:23 d——– c:\program files\watch-football.net
2009-03-27 15:28 . 2009-03-27 15:28 607,640 –a—— c:\users\Toshiba\jre-6u13-windows-i586-p-iftw.exe
2009-03-27 14:58 . 2009-03-27 15:28 d——– c:\users\Toshiba\.SunDownloadManager
2009-03-26 20:01 . 2009-03-26 20:01 d——– c:\users\Toshiba\AppData\Roaming\Nero
2009-03-26 15:36 . 2009-03-26 15:36 d——– c:\users\All Users\SUPERAntiSpyware.com
2009-03-26 15:36 . 2009-03-26 15:36 d——– c:\programdata\SUPERAntiSpyware.com
2009-03-26 15:35 . 2009-03-26 15:35 d——– c:\users\Toshiba\AppData\Roaming\SUPERAntiSpyware.com
2009-03-26 15:35 . 2009-03-27 16:25 d——– c:\program files\SUPERAntiSpyware
2009-03-26 15:33 . 2009-03-26 15:33 d——– c:\program files\Common Files\Wise Installation Wizard
2009-03-26 13:42 . 2009-03-27 08:58 156,629,198 –a—— c:\windows\MEMORY.DMP
2009-03-25 09:51 . 2009-03-25 09:51 d——– C:\OutputFolder
2009-03-25 09:48 . 2009-03-25 09:49 d——– c:\users\Toshiba\AppData\Roaming\GetRightToGo
2009-03-23 18:21 . 2009-03-23 18:58 d——– C:\VideoToDVD
2009-03-23 08:26 . 2002-05-19 02:57 944,797 –a—— c:\program files\wrar300.exe
2009-03-23 01:39 . 2009-03-23 01:40 d——– c:\program files\Ares
2009-03-20 19:11 . 2009-03-20 19:11 d——– c:\program files\ToggleEN
2009-03-20 19:11 . 2009-03-20 19:11 d——– c:\program files\Conduit
2009-03-20 18:32 . 2009-03-20 18:55 d-ahs—- c:\users\Public\DRM
2009-03-18 21:07 . 2009-03-18 21:07 d——– C:\_OTListIt
2009-03-18 20:13 . 2009-03-25 18:30 1,423 –a—— c:\windows\System32\SHORTCUT.INI
2009-03-18 19:42 . 2009-03-25 19:40 132 –a—— c:\windows\System32\REMOTEDEVICE.INI
2009-03-18 19:36 . 2009-04-10 14:33 5,982 –a—— c:\windows\System32\LOCALSERVICE.INI
2009-03-18 19:36 . 2009-03-25 19:33 99 –a—— c:\windows\System32\LOCALDEVICE.INI
2009-03-18 19:32 . 2009-03-18 19:32 0 –a—— c:\windows\System32\BSPRINT.INI
2009-03-18 17:02 . 2001-07-06 14:41 569,344 -ra—— c:\windows\System32\imagr5.dll
2009-03-18 17:02 . 2001-07-06 12:44 544,768 -ra—— c:\windows\System32\imagx5.dll
2009-03-18 17:02 . 2001-07-06 18:24 283,920 -ra—— c:\windows\System32\ImagXpr5.dll
2009-03-18 17:02 . 2000-06-26 11:45 106,496 -ra—— c:\windows\System32\TwnLib20.dll
2009-03-18 17:02 . 2001-06-26 08:15 38,912 -ra—— c:\windows\System32\picn20.dll
2009-03-17 17:50 . 2009-03-17 17:50 125,425 –a—— c:\users\Toshiba\WindowsXP-KB835935-SP2-ENU.exe
2009-03-17 15:11 . 2009-02-15 01:17 331,776 –a—— C:\Interop.WMPLib.dll
2009-03-17 15:11 . 2009-02-15 01:17 61,440 –a—— C:\AxInterop.WMPLib.dll
2009-03-12 23:07 . 2009-03-12 23:07 d——– c:\users\All Users\InterVideo
2009-03-12 23:07 . 2009-03-12 23:07 d——– c:\programdata\InterVideo
2009-03-12 09:44 . 2009-03-12 09:44 0 –a—— C:\OrbPVR.db
2009-03-11 09:02 . 2008-12-16 04:29 8,147,456 –a—— c:\windows\System32\wmploc.DLL
2009-03-11 09:02 . 2009-02-09 04:10 2,033,152 –a—— c:\windows\System32\win32k.sys
2009-03-11 09:02 . 2008-11-27 05:43 268,288 –a—— c:\windows\System32\schannel.dll
2009-03-11 09:02 . 2008-12-16 06:31 7,680 –a—— c:\windows\System32\spwmp.dll
2009-03-11 09:02 . 2008-12-16 06:31 4,096 –a—— c:\windows\System32\msdxm.ocx
2009-03-11 09:02 . 2008-12-16 06:31 4,096 –a—— c:\windows\System32\dxmasf.dll
2009-03-10 14:24 . 2009-03-10 14:26 d——– c:\users\All Users\WinZip
2009-03-10 14:24 . 2009-03-10 14:26 d——– c:\programdata\WinZip
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-10 13:51 ——— d—–w c:\programdata\Kontiki
2009-04-10 13:34 ——— d—–w c:\program files\Winamp Remote
2009-04-10 09:56 ——— d—–w c:\programdata\Google Updater
2009-04-09 12:16 ——— d—–w c:\program files\Yahoo!
2009-03-27 14:34 ——— d—–w c:\program files\Java
2009-03-27 09:27 ——— d—–w c:\programdata\NOS
2009-03-27 09:22 ——— d—–w c:\program files\NOS
2009-03-26 16:56 ——— d—–w c:\users\Toshiba\AppData\Roaming\Winamp
2009-03-26 16:56 ——— d—–w c:\programdata\Ulead Systems
2009-03-25 17:23 ——— d—–w c:\users\Toshiba\AppData\Roaming\Skype
2009-03-25 16:11 ——— d—–w c:\users\Toshiba\AppData\Roaming\skypePM
2009-03-25 07:51 ——— d—a-w c:\programdata\TEMP
2009-03-23 18:10 ——— d—–w c:\program files\Kontiki
2009-03-18 16:55 ——— d—–w c:\programdata\Bluetooth
2009-03-18 15:52 ——— d—–w c:\programdata\Nero
2009-03-18 08:46 ——— d—–w c:\users\Toshiba\AppData\Roaming\LimeWire
2009-03-12 08:04 ——— d—–w c:\program files\Windows Mail
2009-03-12 07:59 ——— d—–w c:\programdata\Microsoft Help
2009-03-11 19:46 ——— d—–w c:\users\Toshiba\AppData\Roaming\Ulead Systems
2009-03-09 05:19 410,984 —-a-w c:\windows\System32\deploytk.dll
2009-02-27 16:45 9,728 —-a-w c:\windows\System32\BsMonUI.dll
2009-02-27 16:45 57,430 —-a-w c:\windows\System32\btfunc.dll
2009-02-27 16:45 405,589 —-a-w c:\windows\System32\BsUI.dll
2009-02-27 16:45 18,432 —-a-w c:\windows\System32\BsMonSvr.dll
2009-02-27 16:44 622,693 —-a-w c:\windows\System32\BSShell.dll
2009-02-27 16:44 53,248 —-a-w c:\windows\System32\HtmPrintHelper.dll
2009-02-27 16:44 278,647 —-a-w c:\windows\System32\outlookAddin.dll
2009-02-27 16:44 114,774 —-a-w c:\windows\System32\versit.dll
2009-02-27 16:43 94,314 —-a-w c:\windows\System32\BsHelpCSps.dll
2009-02-27 16:43 557,142 —-a-w c:\windows\System32\Bscdlg.dll
2009-02-27 16:43 553,075 —-a-w c:\windows\System32\BlueSoleilCSps.dll
2009-02-27 16:43 151,642 —-a-w c:\windows\System32\BsCommon.dll
2009-02-27 16:43 114,788 —-a-w c:\windows\System32\BsProfileFunc.dll
2009-02-27 16:41 98,403 —-a-w c:\windows\System32\Bs2Res.dll
2009-02-27 16:41 28,766 —-a-w c:\windows\System32\PlayerCtrl.dll
2009-02-27 16:41 241,748 —-a-w c:\windows\System32\BsSDK.dll
2009-02-27 16:41 122,976 —-a-w c:\windows\System32\BsMobileSDK.dll
2009-02-27 16:40 28,760 —-a-w c:\windows\System32\BsTrace.dll
2009-02-27 16:40 28,672 —-a-w c:\windows\System32\BsMobileCSps.dll
2009-02-24 08:20 ——— d—–w c:\program files\Veetle
2009-02-17 20:37 ——— d—–w c:\program files\Google
2009-02-14 23:20 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-02-11 10:19 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 10:19 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-02-10 17:43 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-10 16:56 ——— d—–w c:\program files\Microsoft Games
2009-02-10 16:43 ——— d—–w c:\program files\Common Files\SWF Studio
2009-01-15 06:11 827,392 —-a-w c:\windows\System32\wininet.dll
2008-08-08 13:56 174 –sha-w c:\program files\desktop.ini
2002-05-19 02:48 102 —-a-w c:\program files\Readme.txt
2002-05-15 00:37 473 —-a-w c:\program files\rarreg.key
2008-06-30 12:44 324,976 —-a-w c:\program files\mozilla firefox\components\coFFPlgn.dll
2008-08-13 23:01 122,880 —-a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-04-07 07:41 67,696 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-04-07 07:41 54,376 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-04-07 07:41 34,952 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-04-07 07:41 46,720 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-04-07 07:41 172,144 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-04-02 09:29 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-04-02 09:29 32,768 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-04-02 09:29 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-05-11 20:17 16,384 –sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-05-11 20:17 32,768 –sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-05-11 20:17 16,384 –sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2008-07-16 1266992]
"{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTogg.dll" [2009-02-16 1882136]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
2009-02-16 16:44 1882136 –a—— c:\program files\ToggleEN\tbTogg.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTogg.dll" [2009-02-16 1882136]
"{829db392-4699-433f-b952-5ae235e3259d}"= "c:\program files\watch-football.net\tbwatc.dll" [2006-09-13 1117208]
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
[HKEY_CLASSES_ROOT\clsid\{829db392-4699-433f-b952-5ae235e3259d}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{038CB5C7-48EA-4AF9-94E0-A1646542E62B}"= "c:\program files\ToggleEN\tbTogg.dll" [2009-02-16 1882136]
"{829DB392-4699-433F-B952-5AE235E3259D}"= "c:\program files\watch-football.net\tbwatc.dll" [2006-09-13 1117208]
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
[HKEY_CLASSES_ROOT\clsid\{829db392-4699-433f-b952-5ae235e3259d}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"kdx"="c:\program files\Kontiki\KHost.exe" [2009-01-02 1041960]
"ares"="c:\program files\Ares\Ares.exe" [2009-02-03 1004544]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-03-27 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-22 894248]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Ulead AutoDetector"="c:\program files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe" [2003-11-18 45056]
"Ulead Photo Express Calendar Checker"="c:\program files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe" [2004-01-12 69632]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-08-14 29744]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"4oD"="c:\program files\Kontiki\KHost.exe" [2009-01-02 1041960]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"Broadbandadvisor.exe"="c:\program files\Virgin Broadband\advisor\Broadbandadvisor.exe" [2007-08-07 2061552]
"PCguard"="c:\program files\Virgin Broadband\PCguard\Rps.exe" [2007-09-05 310000]
"-FreedomNeedsReboot"="c:\program files\Virgin Broadband\PCguard\ZkRunOnceR.exe" [2007-09-05 13552]
"Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 585728]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"BtTray"="c:\program files\IVT Corporation\BlueSoleil\BtTray.exe" [2009-02-27 278016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 c:\windows\RtHDVCpl.exe]
"Skytel"="Skytel.exe" [2007-06-15 c:\windows\SkyTel.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
c:\users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-05-14 113664]
RAMASST.lnk - c:\windows\System32\RAMASST.exe [2008-05-14 155648]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-01-14 525664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 12:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\
0autocheck autochk *
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{657E2790-7A68-44EB-B717-9C7D89E33040}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{A962E0D5-562C-4EAC-AAFE-0E98951BA33B}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{CEFB1A4C-4196-4ED5-91C3-5C51C40DE9B4}c:\\program files\\bitdownload\\bitdownload.exe"= UDP:c:\program files\bitdownload\bitdownload.exe:BitDownload
"UDP Query User{1CC5647E-7BDA-4D2A-AB89-F56532495045}c:\\program files\\bitdownload\\bitdownload.exe"= TCP:c:\program files\bitdownload\bitdownload.exe:BitDownload
"TCP Query User{D504B23E-0E79-4B5C-AFCF-4641A3D69675}c:\\program files\\bitdownload\\bitdownload.exe"= UDP:c:\program files\bitdownload\bitdownload.exe:BitDownload
"UDP Query User{C3130EC2-65C1-43C6-9FBC-F468FBAE2615}c:\\program files\\bitdownload\\bitdownload.exe"= TCP:c:\program files\bitdownload\bitdownload.exe:BitDownload
"TCP Query User{A7917DA3-A0B0-4C21-90C8-E97714F157DE}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{3F8F07C5-BDA2-412B-8797-536CE8806ACB}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"{3302937E-EB92-434D-95B7-1F9BD18757A3}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{A0F47E87-3668-4BC3-94AA-4E2C9B97F7DF}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{21BAEA41-560D-4D76-8850-D53ADFEA00D9}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{49EBA0A9-AE2D-4AD4-993D-6FA3DBDB7614}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{1500C895-2326-446F-B23A-F1FC1C4121C2}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EAA97DAB-8AA3-40AC-8B4B-D9685020FD1F}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{3B505F01-FA9C-4F03-B2E8-9FC2863D93F8}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{16057D6C-BF53-4B22-84D3-645A320C0600}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{62292CD1-4D2F-4367-9564-8521D8B80926}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{0AF14551-7353-4166-8898-99D989DE9993}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{8A84FF83-3AEE-47A4-A398-3FC562E7937E}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{35498E36-7575-493B-A961-D4DCF78CB456}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{33801AA8-3FF6-43EE-88AB-2F495AAC7CD3}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{B5845C2E-1AD1-45F2-AE7A-B7F5246752E3}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{0420E385-645D-41E1-A1EC-33F9B7E8F205}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{ECD2DBEB-DF81-4DFF-B6C7-0F6C9C87621C}"= UDP:c:\program files\McAfee\Common Framework\FrameworkService.exe:McAfee Framework Service
"{A6698BAD-28C3-4629-9B83-053A8B56FEB1}"= TCP:c:\program files\McAfee\Common Framework\FrameworkService.exe:McAfee Framework Service
"{0BC1ACC5-2F22-4C15-8A52-3DC35DFA08E5}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{61568BDD-5D2D-481D-AC5A-5BCF5BB34FE4}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil_.exe:BlueSoleil
"{3448B3C0-6CAB-448F-AAC6-7788071EF9A6}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil_.exe:BlueSoleil
"{C0BDE073-1A9F-43FD-AE21-7D3C9F06F284}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{8AEE36D9-5F73-42B3-8F1E-4E64D6BFEA80}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{6EC89285-C9FB-4655-A203-461C21F05B3E}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{396E548D-C287-4325-B138-F83E16969CF1}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{CCF289AB-27EA-4114-9A5E-A0FFAEF3ED70}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{C50C5BAD-1289-4BC6-B15B-BF917681CA4C}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"{CF46C3AB-633C-4F5C-BF6B-9D2E6A3B0482}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"{63988533-9DCB-4ECE-9B45-49DB5D5D7889}"= Disabled:UDP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{FA0559D9-B3AB-4A88-B272-0B2C1F3CE9A8}"= Disabled:TCP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{13AD6692-36FF-4789-BED0-168807376B51}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil_.exe:BlueSoleil
"{BA8047FC-9E9C-407E-A6DC-66B012E6DEC9}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil_.exe:BlueSoleil
"{91B58C53-162A-49EF-9B25-468AC87FDF74}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{0262F07B-B541-4E5F-B634-C3B150B0575A}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{684B9D67-DE81-4995-BC52-5B13CE1EFC86}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{88FD7088-EE74-4F50-A8F5-A3FD8A01DDF1}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"UDP Query User{31DB0BAB-4476-42DE-A513-1680A5ACCC2A}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"TCP Query User{D92E2C82-9699-42CA-AD78-94DAA118103A}c:\\users\\toshiba\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= UDP:c:\users\toshiba\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"UDP Query User{48EEA5F2-41E0-4DC4-AE75-D8DB8F2F90AF}c:\\users\\toshiba\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= TCP:c:\users\toshiba\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"{2C390D6A-CECB-4C3D-AB36-3751ECBFB915}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{9151333D-0FC9-41C4-B8B1-FEBC2C73B2C9}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"TCP Query User{68BF232E-B7C0-468C-8F44-8675C91DEB1E}c:\\program files\\kontiki\\khost.exe"= UDP:c:\program files\kontiki\khost.exe:Delivery Manager
"UDP Query User{B1B62B52-665E-4945-A5CF-D80988D6188B}c:\\program files\\kontiki\\khost.exe"= TCP:c:\program files\kontiki\khost.exe:Delivery Manager
"{385D04FD-A628-4000-84A3-CA059562196C}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{105EDC7E-9F7E-44DF-80EB-89C432E2F968}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"TCP Query User{D7CE99D2-2697-4811-9001-B6721FE16EA8}c:\\program files\\webmediaplayer\\webmediaplayer.exe"= UDP:c:\program files\webmediaplayer\webmediaplayer.exe:WebMediaPlayer
"UDP Query User{BA24DC06-2CDC-40B4-A009-4EC768664BDD}c:\\program files\\webmediaplayer\\webmediaplayer.exe"= TCP:c:\program files\webmediaplayer\webmediaplayer.exe:WebMediaPlayer
"{D85F615F-9C05-41A4-B0B6-5E6C6B371F84}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{99EAC962-86A6-4245-B053-45432C0E6EA1}c:\\program files\\tvuplayer\\tvuplayer.exe"= UDP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"UDP Query User{2A4773D4-61F7-426D-95F7-001EEB626995}c:\\program files\\tvuplayer\\tvuplayer.exe"= TCP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"{E97C5382-0215-4F61-AC12-4C4596BB66FC}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D5DA6B19-6CF5-41C3-B191-62D5BD2CF5A3}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C3D7987C-5625-4CEA-A234-CD77493C0A30}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{9B202BBF-E1FC-4FC8-BDB1-616E2F3FE4C0}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{3C960676-35A5-463A-B79A-FD6DAAA9A0DB}c:\\users\\toshiba\\appdata\\local\\octoshape\\octoshape streaming services\\octoshapeclient.exe"= UDP:c:\users\toshiba\appdata\local\octoshape\octoshape streaming services\octoshapeclient.exe:octoshapeclient.exe
"UDP Query User{C361EC20-DA38-4BC0-9DA6-C97A99F6BD55}c:\\users\\toshiba\\appdata\\local\\octoshape\\octoshape streaming services\\octoshapeclient.exe"= TCP:c:\users\toshiba\appdata\local\octoshape\octoshape streaming services\octoshapeclient.exe:octoshapeclient.exe
"{4AB6ED73-3206-493E-A141-543F6DD8057C}"= UDP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"{82ED0535-46FB-4036-9255-B16031FAF02C}"= TCP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"{D04923DC-1088-42AB-8C56-864FB88B912E}"= UDP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"{00E84E16-6DC3-4411-B503-65254394FF1E}"= TCP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"{479C9AF8-907B-4976-81F6-2A1E0F1909F8}"= UDP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"{84CCFC95-731D-403C-8493-9E496EC7E9FB}"= TCP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"TCP Query User{69BB1901-52FB-49DE-9BDB-FB3D4105587C}c:\\program files\\tvuplayer\\tvuplayer.exe"= UDP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"UDP Query User{C6F91E58-A4AD-4996-8F87-3A25ADED90D0}c:\\program files\\tvuplayer\\tvuplayer.exe"= TCP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"{E67A5491-1BD7-42B6-B5C6-7584817ED5F0}"= UDP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{360883DE-FA6F-4C12-A09D-A4D56630657E}"= TCP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{E9ECFC1D-5062-4BBD-8CF4-FF1FDCD66CB7}"= UDP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{5274B3E7-BAAA-4461-BC2B-6C2CD17A88BD}"= TCP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{4B16DD7B-B423-488B-B679-B848BE8806D5}"= UDP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{3B861E98-1843-45B1-A534-9AA1720B76B9}"= TCP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{A56ADD76-0293-45AE-B683-5021261EC50B}"= UDP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{2A83CE77-4517-4C3F-8E40-E6A63FD93EC3}"= TCP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{79F6EB85-8791-49FF-A114-E34DA4FC5B1F}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{3225AA82-1FF7-4B83-94F9-5B8C4E15F69F}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{18DA592B-E9BC-4A77-A4C7-914601121A40}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{EFF7B652-70AE-495E-8A34-8DF20BF66051}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"TCP Query User{6EF6BD60-74A9-4C99-AA32-29142052AF9D}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{107D3784-ACC0-415D-90A9-9A5386B33865}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\System32\drivers\BtHidBus.sys [2009-01-08 20744]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-02-17 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-02-17 55024]
R2 BsMobileCS;BsMobileCS;c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [2009-02-27 143467]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-04-09 210216]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\System32\drivers\btnetBus.sys [2008-12-07 30088]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\System32\drivers\IvtBtBus.sys [2008-07-02 26248]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\System32\drivers\RTL8187B.sys [2008-08-12 339456]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-03-27 33176]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-08-05 29744]
S3 Radialpoint Security Services;Virgin Broadband PCguard;c:\windows\System32\dllhost.exe [2006-11-02 7168]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder
2008-08-17 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
2009-04-10 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 08:47]
2009-04-10 c:\windows\Tasks\User_Feed_Synchronization-{3F837391-37B4-4652-8F63-A24909EEA1FE}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 08:33]
2009-04-10 c:\windows\Tasks\User_Feed_Synchronization-{99FB82D8-7D7F-4B02-B9E1-3BB97C159D41}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 08:33]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p;=%s
IE: &Search;
IE: &Winamp; Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Windows; Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send by Bluetooth - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm
IE: Send via &Message;… - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/710-44557-9400-3/4
IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} -
http://www.amazon.co.uk/exec/obidos/redire…1&site;=home
FF - ProfilePath -
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.hideGoButton", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver;={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features;=TrustRank&client;={moz:client}&appver;={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-10 14:50:26
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'Explorer.exe'(5100)
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\windows\system32\BsMobileSDK.dll
c:\windows\system32\BsLangInDepRes.dll
c:\windows\system32\Bs2Res.dll
.
Completion time: 2009-04-10 14:54:37
ComboFix-quarantined-files.txt 2009-04-10 13:54:30
ComboFix2.txt 2008-11-23 19:59:11
ComboFix3.txt 2008-09-13 19:24:19
Pre-Run: 20,191,776,768 bytes free
Post-Run: 20,063,526,912 bytes free
397 — E O F — 2009-04-09 08:38:30
Will be waiting to hear from your next response
Thanks for your cooperation
Ldee247