Thanks for the help so far…
ComboFix log……………….
================================================================================
==================================ComboFix 09-02-01.01 - David P 2009-02-02 23:49:02.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.3325.2502 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus *On-access scanning enabled* (Updated)
* Created a new restore point
.
ADS - Windows: deleted 24 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\windows\system32\drivers\gaopdxcipvxqrc.sys
c:\windows\system32\gaopdxpousuexg.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_gaopdxserv.sys
((((((((((((((((((((((((( Files Created from 2009-01-03 to 2009-02-03 )))))))))))))))))))))))))))))))
.
2009-02-02 23:47 . 2009-02-02 23:47 46,640 –a—— c:\windows\System32\msln.exe
2009-01-22 23:25 . 2009-02-02 16:09 d——– c:\users\David P\AppData\Roaming\skypePM
2009-01-22 23:25 . 2009-01-22 23:25 56 –ah—– c:\users\All Users\ezsidmv.dat
2009-01-22 23:25 . 2009-01-22 23:25 56 –ah—– c:\programdata\ezsidmv.dat
2009-01-22 23:24 . 2009-02-02 23:44 d——– c:\users\David P\AppData\Roaming\Skype
2009-01-22 23:24 . 2009-01-22 23:24 d——– c:\users\All Users\Skype
2009-01-22 23:24 . 2009-01-22 23:24 d——– c:\programdata\Skype
2009-01-22 23:24 . 2009-01-22 23:24 d——– c:\program files\Skype
2009-01-22 23:24 . 2009-01-22 23:24 d——– c:\program files\Common Files\Skype
2009-01-19 18:33 . 2009-01-19 18:33 d——– c:\windows\Sun
2009-01-19 18:32 . 2009-01-19 18:31 410,984 –a—— c:\windows\System32\deploytk.dll
2009-01-19 18:28 . 2009-01-19 18:29 d——– c:\users\David P\Programs
2009-01-18 14:18 . 2009-01-23 15:51 d——– c:\users\David P\AppData\Roaming\mIRC
2009-01-18 14:18 . 2009-01-23 15:50 d——– c:\program files\mIRC
2009-01-15 08:00 . 2009-01-15 08:00 d——– c:\users\David P\AppData\Roaming\webex
2009-01-15 07:59 . 2009-01-15 07:59 d——– c:\users\All Users\WebEx
2009-01-15 07:59 . 2009-01-15 07:59 d——– c:\programdata\WebEx
2009-01-14 22:29 . 2009-01-14 22:29 d——– c:\program files\AnkhSvn 2.0
2009-01-13 20:48 . 2008-12-15 21:42 288,768 –a—— c:\windows\System32\drivers\srv.sys
2009-01-06 18:24 . 2009-01-06 18:24 d——– C:\inetpub
2009-01-06 17:22 . 2009-01-06 17:23 d——– C:\Data
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-03 04:46 ——— d—–w c:\programdata\VMware
2009-01-19 23:31 ——— d—–w c:\program files\Java
2009-01-18 21:44 ——— d—–w c:\programdata\Roxio
2009-01-15 08:01 ——— d—–w c:\programdata\Microsoft Help
2009-01-14 08:03 ——— d—–w c:\program files\Windows Mail
2009-01-08 04:37 ——— d—–w c:\program files\Roxio
2009-01-05 19:36 ——— d—–w c:\program files\Mozilla Thunderbird
2008-12-30 20:52 ——— d—–w c:\program files\Eclipse
2008-12-30 20:33 ——— d—–w c:\users\David P\AppData\Roaming\TortoiseSVN
2008-12-29 22:51 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-29 01:32 0 —ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-12-29 01:29 ——— d—–w c:\users\David P\AppData\Roaming\TomTom
2008-12-29 01:28 ——— d—–w c:\program files\TomTom
2008-12-29 01:26 ——— d—–w c:\programdata\TomTom
2008-12-25 14:38 ——— d—–w c:\users\David P\AppData\Roaming\VMware
2008-12-24 23:44 ——— d—–w c:\program files\Bonjour
2008-12-16 23:49 ——— d—–w c:\programdata\WindowsSearch
2008-12-12 16:18 87,336 —-a-w c:\windows\System32\dns-sd.exe
2008-12-12 16:11 61,440 —-a-w c:\windows\System32\dnssd.dll
2008-12-11 01:49 ——— d—–w c:\users\David P\AppData\Roaming\Roxio
2008-12-09 03:58 ——— d—–w c:\program files\Google
2008-12-08 20:13 ——— d—–w c:\program files\ReNamer
2008-12-08 17:03 ——— d—–w c:\program files\MusicBrainz Picard
2008-12-08 03:54 ——— d—–w c:\program files\MusicBrainz Tagger
2008-12-04 23:15 ——— d—–w c:\program files\VMware
2008-12-04 06:43 ——— d—–w c:\program files\Microsoft Visual Studio 8
2008-12-04 06:43 ——— d—–w c:\program files\Common Files\Merge Modules
2008-12-04 05:40 ——— d—–w c:\program files\Microsoft Device Emulator
2008-12-04 05:39 ——— d—–w c:\program files\Microsoft SQL Server 2005 Mobile Edition
2008-12-04 05:30 ——— d—–w c:\program files\Common Files\Business Objects
2008-12-04 05:29 ——— d—–w c:\programdata\PreEmptive Solutions
2008-12-04 05:29 ——— d—–w c:\program files\CE Remote Tools
2008-12-04 03:48 ——— d—–w c:\program files\PrimoPDF
2008-12-03 05:58 ——— d—–w c:\users\David P\AppData\Roaming\Apple Computer
2008-12-03 05:57 0 —ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-11-17 20:04 2,306,113 —-a-w c:\windows\System32\GPhotos.scr
2008-01-21 02:41 174 –sha-w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 –a—— c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 –a—— c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 –a—— c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 –a—— c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 –a—— c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 –a—— c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 –a—— c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 –a—— c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 –a—— c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-20 1233920]
"googletalk"="c:\users\David P\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Google Update"="c:\users\David P\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-11-23 133104]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2008-03-07 1694656]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-20 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-18 21633320]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-20 c:\windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"VirtualCloneDrive"="c:\program files\VirtualCloneDrive\VCDDaemon.exe" [2008-06-29 52168]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-02-01 115560]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2008-10-23 136080]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatchTray11.exe" [2008-08-14 240112]
"CPMonitor"="c:\program files\Roxio Creator 2009 Ultimate\5.0\CPMonitor.exe" [2008-08-10 80368]
"VMware hqtray"="c:\program files\VMware\VMware Player\hqtray.exe" [2008-10-28 64048]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-19 136600]
c:\users\David P\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-11-24 113664]
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2008-10-02 546288]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck msln\
0autocheck autochk *
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
–a—— 2008-12-09 05:12 234856 c:\program files\TomTom\HOME 2\HOMERunner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{EC5BDD3C-9525-496E-AE7E-9CE6B6C3570A}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{4FA96522-200B-4D16-8FDA-7929DC8BBAEB}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D24F1583-29BA-4259-B819-1D259552A3A2}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{838C0854-7E67-4253-983D-956D097C33FF}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{ED48AB14-A614-4C11-8955-2E9F7871FD17}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{DB94AF0E-E343-4484-B5DB-7310492A3843}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{2DBBE33C-3963-4043-882D-B2EF95442469}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{8FE0E8E4-D5DE-4A30-A672-3EB024495EA3}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{1C46ECF6-06E2-4199-BDA9-131D5EEC435C}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{59528DD8-2337-4E99-80E0-2D7AA895D9E5}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{951CEBCE-FC0D-4639-8F64-C1E212B2738B}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{6DF45EA2-E806-48AB-B3A1-D8981DD83C40}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{22E7C627-7E6C-433F-86C7-5A65E0ADBDCF}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{07582552-B34D-4B5C-BC90-A8AD3F3944A2}"= UDP:c:\program files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus
"{1451336A-7B91-4B37-ADC4-B59107E94362}"= TCP:c:\program files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus
"{DC1D043E-484D-402E-9991-1CC8AC074246}"= UDP:c:\program files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
"{A3611C6E-A92E-44DC-8561-C1D363132001}"= TCP:c:\program files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
"{6A9C0E42-5823-489B-AC96-9A285C358686}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{E2ED690F-3464-4606-B34A-6C84AED37E8C}c:\\program files\\macromedia\\dreamweaver mx 2004\\dreamweaver.exe"= UDP:c:\program files\macromedia\dreamweaver mx 2004\dreamweaver.exe:Dreamweaver MX 2004
"UDP Query User{3905F6DD-6253-44DB-8512-6C234F3C30FD}c:\\program files\\macromedia\\dreamweaver mx 2004\\dreamweaver.exe"= TCP:c:\program files\macromedia\dreamweaver mx 2004\dreamweaver.exe:Dreamweaver MX 2004
"{0BCF3AC1-B606-4B07-9652-0452C43E2553}"= UDP:c:\program files\VMware\VMware Player\vmware-authd.exe:VMware Authd
"{F9915F42-4F60-4CD8-B2AC-EB89AE4DB217}"= TCP:c:\program files\VMware\VMware Player\vmware-authd.exe:VMware Authd
"TCP Query User{19FB91FB-9410-48E8-902C-869704B0E53C}c:\\program files\\itunes\\itunes.exe"= UDP:c:\program files\itunes\itunes.exe:iTunes
"UDP Query User{4DB0B9C5-CB68-4437-B737-40BBEDCA556A}c:\\program files\\itunes\\itunes.exe"= TCP:c:\program files\itunes\itunes.exe:iTunes
"TCP Query User{DD825895-629D-458D-9F55-1A3833FE276D}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{02E6D324-001A-4807-9192-05DCCA0FB7ED}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{1C6AB00A-0814-4482-9F6A-C0908CA7CF02}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{16884123-F9C5-44B9-B309-D15F6327A790}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{5FC9F8DF-0407-4FBD-B4C1-D0F2DEB1905E}c:\\program files\\musicbrainz picard\\picard.exe"= UDP:c:\program files\musicbrainz picard\picard.exe:The next generation MusicBrainz tagger
"UDP Query User{6C0DA835-2A6A-44D6-B1CD-2F8155B4F230}c:\\program files\\musicbrainz picard\\picard.exe"= TCP:c:\program files\musicbrainz picard\picard.exe:The next generation MusicBrainz tagger
"{7DC92AC2-B881-4316-A0B8-E080DB36A0E6}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{4EE8356B-120E-421A-8AEF-5398786C326A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{25F9B651-D772-43F5-BADE-0A58B9A712B2}c:\\program files\\musicbrainz picard\\picard.exe"= UDP:c:\program files\musicbrainz picard\picard.exe:The next generation MusicBrainz tagger
"UDP Query User{7A9EEFED-F8A3-4BFE-B0A6-D94A37687806}c:\\program files\\musicbrainz picard\\picard.exe"= TCP:c:\program files\musicbrainz picard\picard.exe:The next generation MusicBrainz tagger
"TCP Query User{233B0928-2A10-4B39-8EDD-C8C52D1C3DC6}c:\\users\\david P\\appdata\\roaming\\macromedia\\flash player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"= UDP:c:\users\david P\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe:octoshape.exe
"UDP Query User{6C6F2CD5-12B0-4869-8CE1-423D4022D623}c:\\users\\david P\\appdata\\roaming\\macromedia\\flash player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"= TCP:c:\users\david P\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe:octoshape.exe
"{175F971B-6366-4435-9CA8-41442CFBC7B9}"= c:\program files\Skype\Phone\Skype.exe:Skype
R0 SahdIa32;HDD Filter Driver;c:\windows\System32\drivers\SahdIa32.sys [2008-11-26 20464]
R0 SaibIa32;Volume Filter Driver;c:\windows\System32\drivers\SaibIa32.sys [2008-11-26 15856]
R1 SaibVd32;Virtual Disk Driver;c:\windows\System32\drivers\SaibVd32.sys [2008-11-26 25584]
R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe [2008-08-01 125424]
R2 vmci;VMware vmci;c:\windows\System32\drivers\vmci.sys [2008-10-28 54960]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-11-24 99376]
S2 EraserSvc10824;Symantec Eraser Service;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [2008-02-01 108392]
S2 gupdate1c94d9236b2ec51;Google Update Service (gupdate1c94d9236b2ec51);c:\program files\Google\Update\GoogleUpdate.exe [2008-11-23 133104]
S2 Roxio Upnp Server 11;Roxio Upnp Server 11;c:\program files\Roxio Creator 2009 Ultimate\Digital Home 11\RoxioUpnpService11.exe [2008-08-14 367088]
S2 RoxLiveShare11;LiveShare P2P Server 11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxLiveShare11.exe [2008-08-14 309744]
S2 RoxWatch11;Roxio Hard Drive Watcher 11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatch11.exe [2008-08-14 170480]
S3 Roxio UPnP Renderer 11;Roxio UPnP Renderer 11;c:\program files\Roxio Creator 2009 Ultimate\Digital Home 11\RoxioUPnPRenderer11.exe [2008-08-14 313840]
S3 RoxMediaDB11;RoxMediaDB11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxMediaDB11.exe [2008-08-14 1124848]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2008-10-23 121744]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2007-02-22 2808664]
.
Contents of the 'Scheduled Tasks' folder
2009-02-03 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-11-23 12:37]
2009-02-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2527318067-1796310006-3798171769-1000.job
- c:\users\David P\AppData\Local\Google\Update\GoogleUpdate.exe [2008-11-23 12:38]
2009-02-02 c:\windows\Tasks\User_Feed_Synchronization-{856F2C3D-FF25-4EB2-A082-36B8D6D5F9B8}.job
- c:\windows\system32\msfeedssync.exe [2008-01-20 21:23]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\program files\VMware\VMware Player\vsocklib.dll
FF - ProfilePath - c:\users\David P\AppData\Roaming\Mozilla\Firefox\Profiles\gc8q8ljz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - component: c:\program files\Google\Google Gears\Firefox\components\gears.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\users\David P\AppData\Roaming\Mozilla\Firefox\Profiles\gc8q8ljz.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
FF - component: c:\users\David P\AppData\Roaming\Mozilla\Firefox\Profiles\gc8q8ljz.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npsharedview.dll
FF - plugin: c:\users\David P\AppData\Local\Google\Update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\users\David P\AppData\Roaming\Mozilla\plugins\npatgpc.dll
FF - plugin: c:\users\David P\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-02 23:51:39
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-02-02 23:53:50
ComboFix-quarantined-files.txt 2009-02-03 04:53:48
Pre-Run: 83,584,188,416 bytes free
Post-Run: 83,760,304,128 bytes free
260 — E O F — 2009-01-15 08:01:11
ComboFix 09-02-01.01
HiJackThis log……………….
================================================================================
==================================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:24:20 AM, on 2/3/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Roxio Creator 2009 Ultimate\5.0\CPMonitor.exe
C:\Program Files\VMware\VMware Player\hqtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\David P\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Users\David P\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\rdpclip.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O1 - Hosts: 208.112.31.219 jfrob-vps
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatchTray11.exe"
O4 - HKLM\..\Run: [CPMonitor] "C:\Program Files\Roxio Creator 2009 Ultimate\5.0\CPMonitor.exe"
O4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files\VMware\VMware Player\hqtray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [googletalk] C:\Users\David P\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [Google Update] "C:\Users\David P\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Google Calendar Sync.lnk = C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra 'Tools' menuitem: &Gears; Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware player\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware player\vsocklib.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CE0A1836-1875-45AC-A4AA-974CA6AA8A09}: NameServer = 192.168.1.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Roxio SAIB Service (9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269) - Unknown owner - C:\Program Files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Update Service (gupdate1c94d9236b2ec51) (gupdate1c94d9236b2ec51) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Roxio UPnP Renderer 11 - Sonic Solutions - C:\Program Files\Roxio Creator 2009 Ultimate\Digital Home 11\RoxioUPnPRenderer11.exe
O23 - Service: Roxio Upnp Server 11 - Sonic Solutions - C:\Program Files\Roxio Creator 2009 Ultimate\Digital Home 11\RoxioUpnpService11.exe
O23 - Service: LiveShare P2P Server 11 (RoxLiveShare11) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxLiveShare11.exe
O23 - Service: RoxMediaDB11 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxMediaDB11.exe
O23 - Service: Roxio Hard Drive Watcher 11 (RoxWatch11) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatch11.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-ufad.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
–
End of file - 9817 bytes