combofix log:
ComboFix 09-06-14.02 - Smartys 06/14/2009 18:01.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1033.18.446.103 [GMT -5:00]
Running from: c:\users\Smartys\Desktop\ComboFix.exe
Command switches used :: c:\users\Smartys\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090614-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! antivirus 4.8.1335 [VPS 090614-0] *disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Smartys\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\SUPERAntiSpyware Free Edition.lnk
.
((((((((((((((((((((((((( Files Created from 2009-05-14 to 2009-06-14 )))))))))))))))))))))))))))))))
.
2009-06-13 00:05 . 2009-05-26 18:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-13 00:05 . 2009-05-26 18:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-12 02:45 . 2009-04-23 12:56 696832 ----a-w- c:\windows\system32\localspl.dll
2009-06-12 02:40 . 2009-04-21 12:04 2028032 ----a-w- c:\windows\system32\win32k.sys
2009-06-12 02:24 . 2009-06-12 02:24 -------- d-----w- c:\users\Smartys\AppData\Local\WindowsUpdate
2009-06-12 02:08 . 2009-06-12 02:08 -------- d-----w- c:\users\Smartys\AppData\Local\MigWiz
2009-06-11 16:00 . 2009-06-14 22:48 117760 ----a-w- c:\users\Smartys\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-11 15:56 . 2009-06-11 15:56 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-11 15:27 . 2009-04-23 13:01 788992 ----a-w- c:\windows\system32\rpcrt4.dll
2009-06-11 15:27 . 2009-04-24 16:22 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-11 05:30 . 2009-06-11 05:30 -------- d-----w- c:\users\Smartys\AppData\Roaming\Malwarebytes
2009-06-11 05:30 . 2009-06-11 05:30 -------- d-----w- c:\programdata\Malwarebytes
2009-06-11 05:30 . 2009-06-13 00:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-11 05:01 . 2009-06-11 05:01 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2009-06-11 04:59 . 2009-06-11 15:58 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-06-11 04:59 . 2009-06-11 04:59 -------- d-----w- c:\users\Smartys\AppData\Roaming\SUPERAntiSpyware.com
2009-06-11 04:34 . 2009-02-05 20:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-06-11 04:34 . 2009-02-05 20:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-06-11 04:34 . 2009-02-05 20:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-06-11 04:34 . 2009-02-05 20:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-06-11 04:34 . 2009-02-05 20:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-06-11 04:33 . 2009-02-05 20:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
2009-06-11 04:33 . 2009-02-05 20:06 51792 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-06-11 04:33 . 2003-03-18 20:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2009-06-11 04:33 . 2009-06-11 04:33 -------- d-----w- c:\program files\Alwil Software
2009-06-10 05:04 . 2009-06-10 05:04 -------- d-----w- c:\program files\Panda Security
2009-06-10 02:46 . 2009-06-10 02:46 -------- d-----w- c:\program files\Trend Micro
2009-06-03 08:20 . 2009-06-03 08:20 -------- d-----w- C:\5dba22dae257e13d3112b3df165d
2009-05-22 01:25 . 2009-05-22 01:25 -------- d-----w- c:\users\Smartys\AppData\Roaming\MySpace
2009-05-22 01:25 . 2009-05-22 01:25 -------- d-----w- c:\program files\MySpace
2009-05-21 14:42 . 2009-05-21 14:42 -------- d-----w- c:\users\Smartys\AppData\Roaming\AdobeUM
2009-05-20 23:31 . 2009-05-20 23:31 -------- d-----w- c:\users\Smartys\AppData\Local\Yahoo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-12 23:31 . 2006-12-01 04:58 -------- d-----w- c:\programdata\Microsoft Help
2009-06-11 15:10 . 2006-12-03 23:14 -------- d-----w- c:\programdata\McAfee
2009-06-11 15:01 . 2006-12-01 04:56 -------- d-----w- c:\program files\Microsoft Works
2009-06-10 16:54 . 2006-12-01 04:19 -------- d-----w- c:\program files\Google
2009-05-16 21:40 . 2009-05-06 23:29 1376256 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\libXmlDocument.dll
2009-05-16 21:40 . 2009-05-06 23:29 13742760 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\WizardGraphicalClient.exe
2009-05-16 21:39 . 2009-05-06 23:28 49152 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\MG_Shockalock.dll
2009-05-16 21:39 . 2009-05-06 23:28 36864 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\MG_PotionMotion.dll
2009-05-16 21:39 . 2009-05-06 23:28 53248 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\MG_HotShots.dll
2009-05-16 21:39 . 2009-05-06 23:28 94208 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\MG_Dueling_Diego.dll
2009-05-16 21:39 . 2009-05-06 23:28 36864 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\MG_Concentration.dll
2009-05-16 21:39 . 2009-05-06 23:28 49152 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\MG_ChooChooZoo.dll
2009-05-16 21:39 . 2009-05-06 23:23 127656 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\BugReporter.exe
2009-05-16 21:38 . 2009-05-06 23:26 770728 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankB\WizardLauncher.exe
2009-05-16 21:38 . 2009-05-06 23:23 770728 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankA\WizardLauncher.exe
2009-05-16 21:38 . 2009-05-06 23:26 73728 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankB\PatchClientUIRsrc.dll
2009-05-16 21:38 . 2009-05-06 23:23 73728 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankA\PatchClientUIRsrc.dll
2009-05-16 21:38 . 2009-05-06 23:26 111272 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankB\Configurator.exe
2009-05-16 21:38 . 2009-05-06 23:23 111272 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankA\Configurator.exe
2009-05-15 20:30 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-09 18:16 . 2009-05-09 18:15 -------- d-----w- c:\programdata\PopCap Games
2009-05-09 18:16 . 2009-05-09 18:15 -------- d-----w- c:\program files\PopCap Games
2009-05-06 23:35 . 2009-05-06 23:35 449536 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Data\GameData\ZoneData\_Shared\WorldData\Sound\Miles72a\mss32.dll
2009-05-06 23:35 . 2009-05-06 23:35 389120 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Data\GameData\ZoneData\_Shared\WorldData\Sound\Miles\mss32.dll
2009-05-06 23:29 . 2009-05-06 23:29 59904 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\zlib1.dll
2009-05-06 23:29 . 2009-05-06 23:29 626688 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\msvcr80.dll
2009-05-06 23:29 . 2009-05-06 23:29 548864 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\msvcp80.dll
2009-05-06 23:29 . 2009-05-06 23:29 389120 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\mss32.dll
2009-05-06 23:29 . 2009-05-06 23:29 1101824 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\mfc80.dll
2009-05-06 23:29 . 2009-05-06 23:29 1645320 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\gdiplus.dll
2009-05-06 23:29 . 2009-05-06 23:29 1045128 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\dbghelp.dll
2009-05-06 23:29 . 2009-05-06 23:29 2414360 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\d3dx9_31.dll
2009-05-06 23:28 . 2009-05-06 23:28 2 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\PropertyClassSystem.dll
2009-05-06 23:28 . 2009-05-06 23:28 2 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\KIPlatformWebService.dll
2009-05-06 23:28 . 2009-05-06 23:28 2 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\KIPlatformDb.dll
2009-05-06 23:28 . 2009-05-06 23:28 2 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\KIHousingServer.dll
2009-05-06 23:28 . 2009-05-06 23:28 2 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Bin\ICSharpCode.SharpZipLib.dll
2009-05-06 23:27 . 2009-05-06 23:28 13107200 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankA\WizardGraphicalClient.exe
2009-05-06 23:27 . 2009-05-06 23:27 13107200 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankB\WizardGraphicalClient.exe
2009-05-06 23:23 . 2009-05-06 23:23 -------- d-----w- c:\programdata\KingsIsle Entertainment
2009-05-06 23:23 . 2006-12-01 03:21 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-06 22:23 . 2009-05-02 22:26 -------- d-----w- c:\program files\PokerStars
2009-05-05 23:05 . 2009-05-06 23:26 59904 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankB\zlib1.dll
2009-05-05 23:05 . 2009-05-06 23:26 495616 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankB\SkinCrafterDll.dll
2009-05-05 23:05 . 2009-05-06 23:26 207872 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankB\patchw32.dll
2009-05-05 23:05 . 2009-05-06 23:26 1645320 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankB\gdiplus.dll
2009-05-05 23:05 . 2009-05-06 23:23 37032 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\Wizard101.exe
2009-05-05 23:05 . 2009-05-06 23:23 59904 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankA\zlib1.dll
2009-05-05 23:05 . 2009-05-06 23:23 495616 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankA\SkinCrafterDll.dll
2009-05-05 23:05 . 2009-05-06 23:23 207872 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankA\patchw32.dll
2009-05-05 23:05 . 2009-05-06 23:23 1645320 ----a-w- c:\programdata\KingsIsle Entertainment\Wizard101\PatchClient\BankA\gdiplus.dll
2009-05-02 19:25 . 2006-12-01 04:18 -------- d-----w- c:\programdata\WildTangent
2009-05-02 16:05 . 2009-05-02 16:05 -------- d-----w- c:\users\Smartys\AppData\Roaming\WildTangent
2009-05-02 10:11 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2009-05-02 10:11 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-05-01 01:37 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2009-04-26 19:49 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2009-04-26 19:23 . 2009-04-26 19:23 4093440 ----a-w- c:\windows\system32\NlsLexicons004c.dll
2009-04-26 19:17 . 2009-04-26 19:17 1585664 ----a-w- c:\windows\system32\setupapi.dll
2009-04-26 19:14 . 2009-04-26 19:14 549888 ----a-w- c:\windows\system32\rpcss.dll
2009-04-26 19:14 . 2009-04-26 19:14 3503584 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-04-26 19:14 . 2009-04-26 19:14 3469280 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-04-26 19:14 . 2009-04-26 19:14 24576 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-04-26 19:14 . 2009-04-26 19:14 654336 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-04-26 19:14 . 2009-04-26 19:14 501760 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2009-04-26 19:14 . 2009-04-26 19:14 247296 ----a-w- c:\windows\system32\wbem\WmiPrvSE.exe
2009-04-26 19:14 . 2009-04-26 19:14 130560 ----a-w- c:\windows\system32\wbem\WmiDcPrv.dll
2009-04-26 19:14 . 2009-04-26 19:14 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
2009-04-26 19:14 . 2009-04-26 19:14 97280 ----a-w- c:\windows\system32\iasrecst.dll
2009-04-26 19:14 . 2009-04-26 19:14 53248 ----a-w- c:\windows\system32\iasads.dll
2009-04-26 19:14 . 2009-04-26 19:14 37888 ----a-w- c:\windows\system32\iasdatastore.dll
2009-04-26 19:14 . 2009-04-26 19:14 158720 ----a-w- c:\windows\system32\sdohlp.dll
2009-04-26 19:12 . 2009-04-26 19:12 9728 ----a-w- c:\windows\system32\LAPRXY.DLL
2009-04-26 19:12 . 2009-04-26 19:12 223232 ----a-w- c:\windows\system32\WMASF.DLL
2009-04-26 19:12 . 2009-04-26 19:12 2048 ----a-w- c:\windows\system32\asferror.dll
2009-04-26 19:11 . 2009-04-26 19:11 7680 ----a-w- c:\windows\system32\lsass.exe
2009-04-26 19:11 . 2009-04-26 19:11 72704 ----a-w- c:\windows\system32\secur32.dll
2009-04-26 19:11 . 2009-04-26 19:11 1233408 ----a-w- c:\windows\system32\lsasrv.dll
2009-04-26 19:11 . 2009-04-26 19:11 25600 ----a-w- c:\windows\system32\amxread.dll
2009-04-26 19:11 . 2009-04-26 19:11 14848 ----a-w- c:\windows\system32\apilogen.dll
2009-04-26 19:10 . 2009-04-26 19:10 33280 ----a-w- c:\windows\system32\slwmi.dll
2009-04-26 19:10 . 2009-04-26 19:10 268288 ----a-w- c:\windows\system32\mcbuilder.exe
2009-04-26 19:10 . 2009-04-26 19:10 223232 ----a-w- c:\windows\system32\SLC.dll
2009-04-26 19:10 . 2009-04-26 19:10 566784 ----a-w- c:\windows\system32\SLCommDlg.dll
2009-04-26 19:10 . 2009-04-26 19:10 57856 ----a-w- c:\windows\system32\SLUINotify.dll
2009-04-26 19:10 . 2009-04-26 19:10 351232 ----a-w- c:\windows\system32\SLUI.exe
2009-04-26 19:10 . 2009-04-26 19:10 186368 ----a-w- c:\windows\system32\SLLUA.exe
2009-04-26 19:10 . 2009-04-26 19:10 39936 ----a-w- c:\windows\system32\slcinst.dll
2009-04-26 19:10 . 2009-04-26 19:10 2605568 ----a-w- c:\windows\system32\SLsvc.exe
2009-04-26 19:09 . 2009-04-26 19:09 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-04-26 19:08 . 2009-04-26 19:08 712192 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-04-26 19:08 . 2009-04-26 19:08 347136 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-04-26 19:07 . 2009-04-26 19:07 37376 ----a-w- c:\windows\system32\printcom.dll
2009-04-26 19:07 . 2009-04-26 19:07 441856 ----a-w- c:\windows\system32\win32spl.dll
2009-04-26 19:06 . 2009-04-26 19:06 14848 ----a-w- c:\windows\system32\wshrm.dll
2009-04-26 19:06 . 2009-04-26 19:06 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2009-04-26 19:03 . 2009-04-26 19:03 11776 ----a-w- c:\windows\system32\sbunattend.exe
2009-04-26 18:59 . 2009-04-26 18:59 290304 ----a-w- c:\windows\system32\drivers\srv.sys
2009-04-25 18:14 . 2009-04-25 18:14 376832 ----a-w- c:\windows\system32\winhttp.dll
2009-04-25 15:32 . 2009-04-25 15:32 83968 ----a-w- c:\windows\system32\dnsrslvr.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-12 90112]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-27 815104]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2005-12-16 188416]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2006-11-01 413696]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-01-19 421888]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-12-01 240640]
"PINGER"="c:\toshiba\IVP\ISM\pinger.exe" [2006-07-20 151552]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2006-11-23 409264]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-11-28 52912]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2006-11-20 446128]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2006-11-29 523952]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-11-09 3784704]
"NDSTray.exe"="NDSTray.exe" [BU]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{9B84C7CB-938F-42A9-BC65-D496E5230231}"= UDP:c:\program files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{A6779502-346E-41E2-A06F-7A4A3699E167}"= TCP:c:\program files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{EB486A2C-BD47-41B8-9258-1BFD07655CFB}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{812F24F6-5A02-45BF-8FC7-ACBB0F1AF7A4}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{03EDD2C1-E2DC-42F4-B94E-B029C80C3994}"= UDP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"= c:\toshiba\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\toshiba\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [6/10/2009 11:34 PM 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 10:05 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 10:05 AM 72944]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [6/10/2009 11:34 PM 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [6/10/2009 11:33 PM 51792]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 10:05 AM 7408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-TOSCDSPD - TOSCDSPD.EXE
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-14 18:11
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\windows\System32\TODDSrv.exe
c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\System32\CF22572.exe
c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe
c:\program files\Synaptics\SynTP\SynToshiba.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
c:\program files\TOSHIBA\ConfigFree\CFSwMgr.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\windows\System32\wsqmcons.exe
c:\windows\System32\schtasks.exe
.
**************************************************************************
.
Completion time: 2009-06-14 18:20 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-14 23:20
Pre-Run: 49,822,482,432 bytes free
Post-Run: 50,904,535,040 bytes free
267 --- E O F --- 2009-06-12 23:37