hi,
pc seems to hang a lot now..
and fingerprint software doesn't seem to work..
here are the logs :
Combofix:
ComboFix 08-09-27.06 - Abhishek 2008-10-02 9:23:09.4 - NTFSx86
Microsoft® Windows Vista™ Business 6.0.6001.1.1252.1.1033.18.271 [GMT 7:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Users\Abhishek\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Bonjour
C:\Program Files\Bonjour\About Bonjour.rtf
C:\Program Files\Bonjour\mdnsNSP.dll
C:\Program Files\Bonjour\mDNSResponder.exe
C:\VundoFix Backups
.
((((((((((((((((((((((((( Files Created from 2008-09-02 to 2008-10-02 )))))))))))))))))))))))))))))))
.
2008-09-29 18:48 . 2008-09-29 18:48 d——– C:\Program Files\RSA
2008-09-29 11:39 . 2008-09-29 11:39 d——– C:\Users\All Users\Avira
2008-09-29 11:39 . 2008-09-29 11:39 d——– C:\ProgramData\Avira
2008-09-29 11:39 . 2008-09-29 11:39 d——– C:\Program Files\Avira
2008-09-29 01:20 . 2008-09-29 01:20 d——– C:\Users\All Users\Malwarebytes
2008-09-29 01:20 . 2008-09-29 01:20 d——– C:\Users\Abhishek\AppData\Roaming\Malwarebytes
2008-09-29 01:20 . 2008-09-29 01:20 d——– C:\ProgramData\Malwarebytes
2008-09-29 01:20 . 2008-09-29 01:22 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-29 01:20 . 2008-09-10 00:04 38,528 –a—— C:\Windows\System32\drivers\mbamswissarmy.sys
2008-09-29 01:20 . 2008-09-10 00:03 17,200 –a—— C:\Windows\System32\drivers\mbam.sys
2008-09-28 18:02 . 2008-09-29 01:45 d——– C:\Users\All Users\Spybot - Search & Destroy
2008-09-28 18:02 . 2008-09-29 01:45 d——– C:\ProgramData\Spybot - Search & Destroy
2008-09-28 18:02 . 2008-09-29 01:45 d——– C:\Program Files\Spybot - Search & Destroy
2008-09-28 17:40 . 2008-09-28 17:40 d——– C:\Program Files\Zone Labs
2008-09-28 17:40 . 2008-03-03 15:05 1,086,952 –a—— C:\Windows\System32\zpeng24.dll
2008-09-28 17:39 . 2008-09-28 17:40 d——– C:\Windows\System32\ZoneLabs
2008-09-28 17:39 . 2008-09-28 17:39 d——– C:\Users\All Users\CheckPoint
2008-09-28 17:39 . 2008-09-28 17:39 d——– C:\ProgramData\CheckPoint
2008-09-28 17:39 . 2008-10-02 09:29 352,615 –ah—– C:\Windows\System32\drivers\vsconfig.xml
2008-09-28 17:39 . 2008-03-03 15:06 279,440 –a—— C:\Windows\System32\drivers\vsdatant.sys
2008-09-28 15:51 . 2008-09-28 15:51 d——– C:\Program Files\Trend Micro
2008-09-28 15:01 . 2008-10-02 09:31 d——– C:\Windows\Internet Logs
2008-09-28 10:36 . 2008-08-17 17:33 678,408 –a—— C:\Windows\System32\gpprefcl.dll
2008-09-28 10:35 . 2008-09-28 10:35 d——– C:\Program Files\MSXML 4.0
2008-09-28 09:36 . 2008-06-19 17:24 28,544 –a—— C:\Windows\System32\drivers\pavboot.sys
2008-09-28 09:35 . 2008-09-28 09:35 d——– C:\Program Files\Panda Security
2008-09-28 01:30 . 2008-09-28 01:30 d——– C:\Program Files\NetSend
2008-09-28 01:27 . 2008-09-28 01:29 1,296,872 –a—— C:\Users\Abhishek\netsend.exe
2008-09-27 22:30 . 2008-09-27 22:30 d——– C:\Program Files\Nero
2008-09-27 17:52 . 2008-06-24 13:45 1,414,440 –a—— C:\Windows\System32\ShellManager310E2D762.dll
2008-09-27 17:52 . 2008-06-23 17:36 773,120 –a—— C:\Windows\System32\NEROINSTAEC43759.DB
2008-09-27 17:43 . 2008-09-27 17:43 0 –a—— C:\Windows\Irremote.ini
2008-09-27 16:58 . 2008-09-27 16:58 d——– C:\Users\Abhishek\AppData\Roaming\Nero
2008-09-27 16:51 . 2008-09-27 22:30 d——– C:\Users\All Users\Nero
2008-09-27 16:51 . 2008-09-27 22:30 d——– C:\ProgramData\Nero
2008-09-27 16:51 . 2008-09-27 22:36 d——– C:\Program Files\Common Files\Nero
2008-09-25 12:13 . 2008-09-25 12:13 dr——- C:\Windows\System32\config\systemprofile\Music
2008-09-25 11:21 . 2008-09-25 11:21 d—-c— C:\Windows\System32\DRVSTORE
2008-09-25 11:21 . 2008-04-17 13:12 107,368 –a—— C:\Windows\System32\GEARAspi.dll
2008-09-25 11:21 . 2008-04-17 13:12 15,464 –a—— C:\Windows\System32\drivers\GEARAspiWDM.sys
2008-09-25 11:20 . 2008-09-25 11:21 d——– C:\Users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-25 11:20 . 2008-09-25 11:21 d——– C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-25 11:20 . 2008-09-25 11:21 d——– C:\Program Files\iTunes
2008-09-25 11:20 . 2008-09-25 11:20 d——– C:\Program Files\iPod
2008-09-25 11:16 . 2008-09-25 11:20 d——– C:\Users\All Users\Apple Computer
2008-09-25 11:16 . 2008-09-25 11:20 d——– C:\ProgramData\Apple Computer
2008-09-25 11:16 . 2008-09-25 11:17 d——– C:\Program Files\QuickTime
2008-09-25 11:15 . 2008-09-25 11:15 d——– C:\Program Files\Apple Software Update
2008-09-25 11:13 . 2008-09-25 11:17 d——– C:\Program Files\Common Files\Apple
2008-09-25 10:00 . 2008-09-25 10:00 d——– C:\Windows\Sun
2008-09-25 09:51 . 2008-09-25 11:22 d——– C:\Users\Abhishek\AppData\Roaming\Apple Computer
2008-09-25 09:48 . 2008-09-25 09:50 d——– C:\Program Files\Safari
2008-09-25 09:46 . 2008-09-25 09:46 d——– C:\Users\All Users\Apple
2008-09-25 09:46 . 2008-09-25 09:46 d——– C:\ProgramData\Apple
2008-09-23 20:12 . 2008-09-24 09:23 d——– C:\Users\All Users\TamoSoft
2008-09-23 20:12 . 2008-09-24 09:23 d——– C:\ProgramData\TamoSoft
2008-09-23 19:04 . 2008-09-23 19:04 d——– C:\Program Files\SuperScan
2008-09-19 12:50 . 2008-09-19 12:50 d——– C:\Users\All Users\Messenger Plus!
2008-09-19 12:50 . 2008-09-19 12:50 d——– C:\ProgramData\Messenger Plus!
2008-09-19 12:42 . 2008-09-19 12:42 d——– C:\Program Files\Messenger Plus! Live
2008-09-15 20:47 . 2008-09-15 20:47 8 –a—— C:\Users\Abhishek\AppData\Roaming\usb.dat.bin
2008-09-15 11:55 . 2008-09-15 11:55 410,976 –a—— C:\Windows\System32\deploytk.dll
2008-09-10 16:45 . 2008-09-10 16:45 32,000 –a—— C:\Windows\System32\drivers\usbaapl.sys
2008-09-10 12:36 . 2008-07-31 08:13 4,240,384 –a—— C:\Windows\System32\GameUXLegacyGDFs.dll
2008-09-10 12:36 . 2008-07-31 10:32 28,160 –a—— C:\Windows\System32\Apphlpdm.dll
2008-09-10 11:46 . 2008-06-26 10:29 303,616 –a—— C:\Windows\System32\wmpeffects.dll
2008-09-10 11:42 . 2008-08-02 08:01 625,152 –a—— C:\Windows\System32\drivers\dxgkrnl.sys
2008-09-10 11:42 . 2008-06-26 10:29 565,248 –a—— C:\Windows\System32\emdmgmt.dll
2008-09-10 11:42 . 2008-05-09 02:21 211,968 –a—— C:\Windows\System32\drivers\mrxsmb10.sys
2008-09-10 11:42 . 2008-05-20 09:07 148,480 –a—— C:\Windows\System32\drivers\nwifi.sys
2008-09-10 11:42 . 2008-06-26 10:29 45,056 –a—— C:\Windows\System32\dataclen.dll
2008-09-10 11:42 . 2008-08-02 10:26 36,864 –a—— C:\Windows\System32\cdd.dll
2008-09-06 15:09 . 2008-09-06 15:09 90,112 –a—— C:\Windows\System32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 –a—— C:\Windows\System32\QuickTime.qts
2008-09-04 16:45 . 2008-09-04 16:45 d——– C:\Users\Abhishek\AppData\Roaming\PeerNetworking
2008-09-03 09:48 . 2008-07-19 12:09 1,811,656 –a—— C:\Windows\System32\wuaueng.dll
2008-09-03 09:48 . 2008-07-19 10:44 1,524,736 –a—— C:\Windows\System32\wucltux.dll
2008-09-03 09:48 . 2008-07-19 12:09 563,912 –a—— C:\Windows\System32\wuapi.dll
2008-09-03 09:48 . 2008-07-19 10:44 83,456 –a—— C:\Windows\System32\wudriver.dll
2008-09-03 09:48 . 2008-07-19 12:10 53,448 –a—— C:\Windows\System32\wuauclt.exe
2008-09-03 09:48 . 2008-07-19 12:10 45,768 –a—— C:\Windows\System32\wups2.dll
2008-09-03 09:48 . 2008-07-19 12:10 36,552 –a—— C:\Windows\System32\wups.dll
2008-09-03 09:47 . 2008-07-18 22:08 163,904 –a—— C:\Windows\System32\wuwebv.dll
2008-09-03 09:47 . 2008-07-18 20:44 31,232 –a—— C:\Windows\System32\wuapp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-29 11:51 ——— d—–w C:\Program Files\Protector Suite QL
2008-09-29 11:47 ——— d—–w C:\ProgramData\UIB
2008-09-29 04:50 ——— d—–w C:\ProgramData\Symantec
2008-09-29 04:50 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-09-29 03:49 33,288,859 —-a-w C:\Windows\Internet Logs\vsmon_on_demand_2008_09_29_10_46_10_full.dmp.zip
2008-09-29 03:48 33,513,186 —-a-w C:\Windows\Internet Logs\vsmon_on_demand_2008_09_29_10_06_05_full.dmp.zip
2008-09-29 03:35 ——— d—–w C:\Users\Abhishek\AppData\Roaming\Skype
2008-09-29 03:33 ——— d—–w C:\Users\Abhishek\AppData\Roaming\skypePM
2008-09-29 02:48 33,494,839 —-a-w C:\Windows\Internet Logs\vsmon_on_demand_2008_09_29_09_21_56_full.dmp.zip
2008-09-25 02:22 ——— d—–w C:\Users\Abhishek\AppData\Roaming\CopyTransManager
2008-09-19 05:50 ——— d—–w C:\Users\Abhishek\AppData\Roaming\LimeWire
2008-09-18 05:02 ——— d—–w C:\Program Files\Free Download Manager
2008-09-15 04:54 ——— d—–w C:\Program Files\Java
2008-09-11 15:36 ——— d—–w C:\Program Files\TeamViewer3
2008-09-10 05:48 ——— d—–w C:\ProgramData\Microsoft Help
2008-08-29 03:18 87,336 —-a-w C:\Windows\System32\dns-sd.exe
2008-08-29 02:53 61,440 —-a-w C:\Windows\System32\dnssd.dll
2008-08-19 01:11 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-08-16 04:59 ——— d—–w C:\Program Files\DBPix20
2008-08-16 04:16 ——— d—–w C:\Program Files\Windows Mail
2008-08-09 04:26 ——— d—–w C:\Program Files\FxPro MetaTrader
2008-08-06 09:03 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-08-06 09:03 ——— d—–w C:\Program Files\Toshiba
2008-08-05 06:54 ——— d—–w C:\Users\Abhishek\AppData\Roaming\Gizmo5
2008-08-01 05:48 56 —ha-w C:\Users\All Users\ezsidmv.dat
2008-08-01 05:48 56 —ha-w C:\ProgramData\ezsidmv.dat
2008-07-31 03:32 460,288 —-a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-07-31 03:32 2,154,496 —-a-w C:\Windows\AppPatch\AcGenral.dll
2008-07-31 03:32 173,056 —-a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-07-29 07:38 34 —-a-w C:\Users\Abhishek\AppData\Roaming\pwcpsw.dat
2008-07-16 01:32 2,048 —-a-w C:\Windows\System32\tzres.dll
2008-06-04 08:43 174 –sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((( snapshot_2008-10-01_12.55.08.74 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-10-01 05:47:12 1,708,328 —-a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2008-10-02 02:28:42 1,708,328 —-a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2008-10-02 02:29:27 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-10-02 02:29:27 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-10-01 05:48:32 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-10-02 02:36:13 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-10-02 02:36:13 262,144 —ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-10-01 05:48:32 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-10-02 02:36:18 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-10-02 02:36:18 262,144 —ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-10-01 05:48:06 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-10-02 02:29:33 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-10-01 05:48:06 49,152 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-10-02 02:29:33 49,152 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-10-01 05:48:06 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-10-02 02:29:33 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-10-01 05:38:06 10,892 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2297491860-3654364137-680863739-1000_UserData.bin
+ 2008-10-02 01:58:30 10,932 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2297491860-3654364137-680863739-1000_UserData.bin
- 2008-10-01 05:38:06 64,378 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-10-02 01:58:29 64,678 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-10-01 01:46:35 49,382 —-a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-10-02 01:58:28 49,542 —-a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-09-29 02:18:37 264,712 —-a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2008-10-01 12:34:51 267,086 —-a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\NBHShellExt]
@="{8D2223A2-B3C6-4e32-B096-CDD11F628C60}"
[HKEY_CLASSES_ROOT\CLSID\{8D2223A2-B3C6-4e32-B096-CDD11F628C60}]
2007-12-13 22:02 96552 –a—— C:\Program Files\Nero\Nero8\InCD\NBHShx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-11-14 12:22 3186440 –a—— C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-11-14 12:22 3186440 –a—— C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2006-11-10 417792]
"googletalk"="C:\Users\Abhishek\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-02 3739648]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Google Update"="C:\Users\Abhishek\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 1688872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ThpSrv"="C:\Windows\system32\thpsrv" [X]
"TOSDCR"="C:\Program Files\TOSHIBA\PasswordUtility\TOSDCR.exe" [2007-08-28 169296]
"TPwrMain"="C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-10-11 431456]
"HSON"="C:\Program Files\TOSHIBA\TBS\HSON.exe" [2007-10-31 54608]
"SmoothView"="C:\Program Files\Toshiba\SmoothView\SmoothView.exe" [2007-06-15 448080]
"00TCrdMain"="C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-10-11 712704]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2006-09-11 180224]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2005-12-16 188416]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-11 133656]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-09-15 144792]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 2213160]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="C:\Program Files\Nero\Nero8\InCD\NBHGui.exe" [2007-12-13 2048808]
"InCD"="C:\Program Files\Nero\Nero8\InCD\InCD.exe" [2007-12-13 1082152]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 959976]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"PSQLLauncher"="C:\Program Files\Protector Suite QL\launcher.exe" [2007-11-14 49416]
"NDSTray.exe"="NDSTray.exe" [BU]
C:\Users\Abhishek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office Groove.lnk - C:\Program Files\Microsoft Office\Office12\GROOVE.EXE [2007-08-29 340856]
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-11-25 2134016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-11-14 12:07 96008 C:\Windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{92548292-E0D8-49BA-BB5A-FA859858DC94}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{16D6CCE3-C2DA-40D3-90BF-D928923077AE}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{383F0680-E0FF-418B-B312-E159E172B2B9}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{077C717D-2F86-4E35-A97C-BBB8D522D865}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{B6D06E33-C96D-461F-8466-49A167E27FC0}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{0B209EAF-1AE1-4A72-B416-9EFEDABE8296}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{FE0270C3-34F0-4E2C-A25B-C69F29665AF9}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{A8088C30-3116-4269-B2D8-D2340C2BE40E}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{2500AAC6-C40E-4AC7-A0AE-647A2034EA38}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{6131690C-F518-495A-8217-20603ED3323A}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{7632614B-7552-40A2-B615-B7B8C5FEC888}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C76FEC4D-EE24-47B5-A084-F0E2F5AAD0BC}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{F0CBFAD7-92DE-4813-9819-39ABBA8B5D6B}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
"{18B9D0FE-6308-4C5E-AEAD-559BC9627809}"= UDP:C:\Program Files\VoipCheapCom\VoipCheapCom.exe:VoipCheapCom
"{22A1135E-4190-4141-A30B-1D59E78A406D}"= TCP:C:\Program Files\VoipCheapCom\VoipCheapCom.exe:VoipCheapCom
"{5130BF34-05F7-44EC-B26E-64D11D08FFC5}"= UDP:C:\Program Files\Gizmo5\Gizmo5.exe:Gizmo5
"{E74D7A18-6B17-434B-9478-82EB7B8AC3C1}"= TCP:C:\Program Files\Gizmo5\Gizmo5.exe:Gizmo5
"{BCADA139-9861-4327-B806-DE250AA97437}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{CD80AF80-50B3-4FEA-BBC7-131827E9387A}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{CE79FE3B-FA0A-4C44-A83B-286254D3975B}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{40E619CC-FC74-4755-8BFD-AD66F02DDF12}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 pavboot;pavboot;C:\Windows\system32\drivers\pavboot.sys [2008-06-19 28544]
R0 Thpdrv;TOSHIBA HDD Protection Driver;C:\Windows\system32\DRIVERS\Thpdrv.sys [2007-02-08 16896]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;C:\Windows\system32\DRIVERS\Thpevm.SYS [2007-02-07 6528]
R2 NeroRegInCDSrv;Nero Registry InCD Service;C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe [2007-12-13 50984]
R2 TeamViewer;TeamViewer 3;C:\Program Files\TeamViewer3\TeamViewer_Host.exe [2008-05-15 181544]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
Contents of the 'Scheduled Tasks' folder
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-02 09:37:43
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\Windows\Explorer.exe
-> ?:\Windows\system32\ieframe.dll
-> ?:\Windows\system32\urlmon.dll
.
———————— Other Running Processes ————————
.
C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\audiodg.exe
C:\Program Files\Protector Suite QL\upeksvr.exe
C:\Windows\System32\ZoneLabs\vsmon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Windows\System32\agrsmsvc.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\System32\ThpSrv.exe
C:\Windows\System32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\System32\conime.exe
C:\Windows\System32\ThpSrv.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Windows\System32\igfxsrvc.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Apoint2K\ApntEx.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-10-02 9:43:23 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-02 02:43:11
ComboFix2.txt 2008-10-01 05:56:04
ComboFix3.txt 2008-09-29 02:53:17
ComboFix4.txt 2008-09-28 20:03:32
Pre-Run: 50,127,929,344 bytes free
Post-Run: 50,093,977,600 bytes free
332 — E O F — 2008-09-29 03:11:43
HijackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:47:31, on 02/10/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\conime.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Windows\System32\ThpSrv.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\ltmoh\ltmoh.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Nero\Nero8\InCD\NBHGui.exe
C:\Program Files\Nero\Nero8\InCD\InCD.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Abhishek\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Microsoft Office\Office12\GROOVE.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [TOSDCR] %ProgramFiles%\TOSHIBA\PasswordUtility\TOSDCR.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ThpSrv] C:\Windows\system32\thpsrv /logon
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero8\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero8\InCD\InCD.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [googletalk] C:\Users\Abhishek\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Abhishek\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Microsoft Office Groove.lnk = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) -
http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Host.exe
O23 - Service: TOSHIBA HDD Protection (Thpsrv) - TOSHIBA Corporation - C:\Windows\system32\ThpSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
–
End of file - 10300 bytes
greetz
xz0rd