ComboFix 09-02-06.01 - Traci 2009-02-06 17:42:02.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1013.331 [GMT -5:00]
Running from: c:\users\Traci\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\gaopdxcounter
.
((((((((((((((((((((((((( Files Created from 2009-01-06 to 2009-02-06 )))))))))))))))))))))))))))))))
.
2009-02-05 20:29 . 2009-02-05 20:29 <DIR> d-------- c:\users\Traci\AppData\Roaming\Malwarebytes
2009-02-05 20:29 . 2009-02-05 20:29 <DIR> d-------- c:\users\All Users\Malwarebytes
2009-02-05 20:29 . 2009-02-05 20:29 <DIR> d-------- c:\programdata\Malwarebytes
2009-02-05 20:29 . 2009-02-05 20:29 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-05 20:29 . 2009-01-14 16:11 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-05 20:29 . 2009-01-14 16:11 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-02-05 13:08 . 2009-02-05 13:08 <DIR> d-------- C:\rsit
2009-02-02 18:21 . 2008-04-26 03:26 891,448 --a------ c:\windows\System32\drivers\tcpip.sys
2009-02-01 20:19 . 2009-02-01 20:19 <DIR> d-------- c:\windows\Sun
2009-02-01 18:56 . 2009-02-01 18:56 <DIR> d-------- C:\PerfLogs
2009-02-01 17:49 . 2009-02-01 17:49 <DIR> d-------- c:\program files\Trend Micro
2009-01-31 17:05 . 2009-01-31 17:08 <DIR> d-------- c:\users\All Users\Lavasoft
2009-01-31 17:05 . 2009-01-31 17:08 <DIR> d-------- c:\programdata\Lavasoft
2009-01-31 17:05 . 2009-01-31 17:05 <DIR> d-------- c:\program files\Lavasoft
2009-01-31 17:04 . 2009-01-31 17:04 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-01-24 20:22 . 2009-01-24 20:23 <DIR> d-------- c:\users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-24 20:22 . 2009-01-24 20:23 <DIR> d-------- c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-24 20:22 . 2009-01-24 20:23 <DIR> d-------- c:\program files\iTunes
2009-01-24 20:22 . 2009-01-24 20:22 <DIR> d-------- c:\program files\iPod
2009-01-22 09:00 . 2009-01-22 11:18 <DIR> d-------- c:\users\Traci\AppData\Roaming\Elluminate
2009-01-14 07:04 . 2008-12-15 21:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
2009-01-11 06:21 . 2009-01-11 06:21 <DIR> d-------- c:\users\All Users\TVU Networks
2009-01-11 06:21 . 2009-01-11 06:21 <DIR> d-------- c:\programdata\TVU Networks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-06 22:34 --------- d-----w c:\users\Traci\AppData\Roaming\OpenOffice.org2
2009-02-02 00:09 174 --sha-w c:\program files\desktop.ini
2009-02-01 23:58 --------- d-----w c:\program files\Windows Sidebar
2009-02-01 23:58 --------- d-----w c:\program files\Windows Photo Gallery
2009-02-01 23:58 --------- d-----w c:\program files\Windows Mail
2009-02-01 23:58 --------- d-----w c:\program files\Windows Journal
2009-02-01 23:58 --------- d-----w c:\program files\Windows Defender
2009-02-01 23:58 --------- d-----w c:\program files\Windows Collaboration
2009-02-01 23:58 --------- d-----w c:\program files\Windows Calendar
2009-02-01 23:38 82,432 ----a-w c:\windows\System32\axaltocm.dll
2009-02-01 23:38 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2009-02-01 22:05 --------- d-----w c:\program files\Google
2009-02-01 22:02 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-25 01:22 --------- d-----w c:\program files\Common Files\Apple
2009-01-25 01:20 --------- d-----w c:\program files\QuickTime
2009-01-24 14:48 20 ---h--w c:\users\All Users\PKP_DLec.DAT
2009-01-24 14:48 20 ---h--w c:\users\All Users\PKP_DLds.DAT
2009-01-24 14:48 20 ---h--w c:\programdata\PKP_DLec.DAT
2009-01-24 14:48 20 ---h--w c:\programdata\PKP_DLds.DAT
2009-01-18 00:50 --------- d-----w c:\users\Traci\AppData\Roaming\dvdcss
2008-12-09 23:52 --------- d-----w c:\programdata\Pure Digital Technologies
2008-12-09 23:52 --------- d-----w c:\program files\Pure Digital Technologies
2008-12-09 23:52 --------- d-----w c:\program files\3ivx
2008-12-06 20:30 --------- d-----w c:\program files\muvee Technologies
2007-02-28 20:39 262,144 ----a-w c:\programdata\ntuser.dat
2008-10-25 22:54 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-10-25 22:54 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-10-25 22:54 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2006-11-10 417792]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-31 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-31 151552]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-31 126976]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-02 835584]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2006-12-20 411768]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-01-19 448632]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-01-17 534648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-01-08 185896]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-10-02 67488]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-08-18 1447168]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-06 c:\windows\RtHDVCpl.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
c:\users\Traci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 393216]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-02-16 118784]
StupAssist.lnk - c:\program files\Common Files\Nikon\Utilities\StupAssist.exe [2008-02-16 31744]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"vidc.3IV2"= 3ivxVfWCodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{85C4F6F4-FBAD-4811-A2FC-0B886590C511}"= UDP:c:\program files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{F1926EDE-ADD4-4898-8C28-4A6D81A6D4E6}"= TCP:c:\program files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"TCP Query User{CEF27E43-49B6-438A-9434-E01D7E6D210B}c:\\program files\\videolan\\vlc\\vlc.exe"= UDP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"UDP Query User{83A09ADF-3257-44E5-9CB2-959F28C24DF1}c:\\program files\\videolan\\vlc\\vlc.exe"= TCP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"TCP Query User{D834C343-6DAC-44EF-B78A-E4536C2A76C0}c:\\program files\\real\\realplayer\\realplay.exe"= UDP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{E19BE0E8-2635-4FC6-9419-4EF2C7E69EFF}c:\\program files\\real\\realplayer\\realplay.exe"= TCP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"{40425DD8-0183-421C-AA67-B673533E4F40}"= UDP:c:\windows\System32\dlbkcoms.exe:AIO Printer A920 Server
"{18AA58DA-D92A-42AB-B8FD-147BE7EC651F}"= TCP:c:\windows\System32\dlbkcoms.exe:AIO Printer A920 Server
"TCP Query User{CAA513D3-92FB-4975-B089-2BD59FD06CD9}c:\\program files\\quicktime\\quicktimeplayer.exe"= UDP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player
"UDP Query User{6C0DF230-ECA7-40D7-B286-0DC9341DC273}c:\\program files\\quicktime\\quicktimeplayer.exe"= TCP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player
"{B0AC4416-2113-4E11-A3F6-C3A696679903}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{6D50B350-E1A9-4612-9D31-5457912E38A6}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{9B0A3D35-D45B-4346-AD34-80DABFF44266}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{5009BCB6-B87D-4991-B546-677EC9AC372A}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{53511D64-9853-4459-B702-094574EE38FC}c:\\program files\\videolan\\vlc\\vlc.exe"= UDP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"UDP Query User{F247F7F3-F21D-41AA-A942-274ED606B1F7}c:\\program files\\videolan\\vlc\\vlc.exe"= TCP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"TCP Query User{580FBBEF-E36E-44F2-940B-BE890A4B8DCD}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{05B27F73-BF0D-448F-A90E-6CB67355BB99}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{450ADB3E-1BC7-4145-8B54-5F4D41CC611E}c:\\program files\\java\\jre1.6.0\\bin\\javaw.exe"= UDP:c:\program files\java\jre1.6.0\bin\javaw.exe:Java(TM) Platform SE binary
"UDP Query User{4D9F3CED-7E02-48AC-86EF-1DC6E256C9EF}c:\\program files\\java\\jre1.6.0\\bin\\javaw.exe"= TCP:c:\program files\java\jre1.6.0\bin\javaw.exe:Java(TM) Platform SE binary
"{36F30F2A-8BBA-470C-B305-EF8DC724F309}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{A9D819BE-AF1F-42F1-A619-FB8505C31CB2}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"= c:\toshiba\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\toshiba\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger
R1 epfwtdir;epfwtdir;c:\windows\System32\drivers\epfwtdir.sys [2008-08-18 34312]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-10-02 124832]
R2 dlbk_device;dlbk_device;c:\windows\system32\dlbkcoms.exe -service --> c:\windows\system32\dlbkcoms.exe -service [?]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-08-18 468224]
R2 FlipShare Service;FlipShare Service;c:\program files\Pure Digital Technologies\FlipShare\FlipShareService.exe [2008-11-13 439616]
R3 FwLnk;FwLnk Driver;c:\windows\System32\drivers\FwLnk.sys [2007-02-28 7168]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{acef92e2-c2fa-11dd-bb80-00a0d16f7a44}]
\shell\AutoRun\command - e:\system\viewer\FlipVideoforPC.exe
\shell\Flip Video for PC\command - e:\system\viewer\FlipVideoforPC.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{acef92f0-c2fa-11dd-bb80-00a0d16f7a44}]
\shell\AutoRun\command - E:\Setup_FlipShare.exe
\shell\Setup FlipShare\command - E:\Setup_FlipShare.exe
.
Contents of the 'Scheduled Tasks' folder
2009-02-06 c:\windows\Tasks\User_Feed_Synchronization-{D2174069-5A9F-49D6-9730-39498F9ADBB6}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 02:33]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Dell AIO Printer A920 - c:\program files\Dell AIO Printer A920\dlbkbmgr.exe
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.toshibadirect.com/dpdstartIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {0C92900E-4D5A-4F04-ACC9-729E1767BBAE} -
hxxp://www.ritzpix.com/net/Uploader/LPUploader45.cabFF - ProfilePath - c:\users\Traci\AppData\Roaming\Mozilla\Firefox\Profiles\c7wcrjrz.default\
1 file(s) moved.
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\Traci\AppData\Roaming\Mozilla\Firefox\Profiles\c7wcrjrz.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-06 17:46:34
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD = c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/i????????q????????8???p?????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-02-06 17:49:13
ComboFix-quarantined-files.txt 2009-02-06 22:49:07
Pre-Run: 86,359,433,216 bytes free
Post-Run: 86,705,016,832 bytes free
185 --- E O F --- 2009-02-05 22:55:59