ComboFix 09-02-28.01 - User` 2009-02-28 14:17:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3327.2904 [GMT -5:00]
Running from: c:\documents and settings\User`\Desktop\ComboFix.exe
FW: Norton AntiVirus *enabled*
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\ios.dat
c:\windows\system32\c.ico
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\drivers\senekabvxxxipr.sys
c:\windows\system32\drivers\senekackpkhaii.sys
c:\windows\system32\drivers\senekadurtgtlo.sys
c:\windows\system32\drivers\senekafqqheekc.sys
c:\windows\system32\drivers\senekahbebxtex.sys
c:\windows\system32\drivers\senekailrrewip.sys
c:\windows\system32\drivers\senekaisrquehf.sys
c:\windows\system32\drivers\senekajuaypkjb.sys
c:\windows\system32\drivers\senekakfcvkahy.sys
c:\windows\system32\drivers\senekanhejsyrn.sys
c:\windows\system32\drivers\senekaopepoufg.sys
c:\windows\system32\drivers\senekaplbfgdpn.sys
c:\windows\system32\drivers\senekaqpcmgusl.sys
c:\windows\system32\drivers\senekaqvnnbmit.sys
c:\windows\system32\drivers\senekardylquoo.sys
c:\windows\system32\drivers\senekatejndcdv.sys
c:\windows\system32\drivers\senekavckppdsa.sys
c:\windows\system32\fejokt.dll
c:\windows\system32\m.ico
c:\windows\system32\M277CDp2.exe.a_a
c:\windows\system32\m3.ico
c:\windows\system32\p.ico
c:\windows\system32\s.ico
c:\windows\system32\senekabgkvxepa.dll
c:\windows\system32\senekacdybbpjx.dat
c:\windows\system32\senekacylpswtu.dll
c:\windows\system32\senekadibcmcjp.dll
c:\windows\system32\senekaesevpfdx.dll
c:\windows\system32\senekahwmcepmb.dll
c:\windows\system32\senekaijpyfqrw.dll
c:\windows\system32\senekaivpdipou.dll
c:\windows\system32\senekajcxeyrul.dll
c:\windows\system32\senekakalmprmh.dat
c:\windows\system32\senekakrodlsqw.dll
c:\windows\system32\senekamoybaphe.dat
c:\windows\system32\senekaowyqoxms.dat
c:\windows\system32\senekapsatrecp.dll
c:\windows\system32\senekaqqorjuyu.dat
c:\windows\system32\senekarchxnssi.dat
c:\windows\system32\senekarhnxfakj.dll
c:\windows\system32\senekaspbyqxtf.dll
c:\windows\system32\senekatferlujp.dat
c:\windows\system32\senekativfwbde.dll
c:\windows\system32\senekaucrnsetu.dat
c:\windows\system32\senekauicvpeoj.dll
c:\windows\system32\senekauwswqvmp.dll
c:\windows\system32\senekaxnxomtsw.dll
c:\windows\system32\senekaxyfqaita.dll
c:\windows\system32\senekaxynvxtqb.dat
c:\windows\system32\sf.ico
c:\windows\system32\SVxF6H2J.exe.a_a
c:\windows\system32\uvDdKkkj.ini
c:\windows\system32\uvDdKkkj.ini2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SENEKA
((((((((((((((((((((((((( Files Created from 2009-01-28 to 2009-02-28 )))))))))))))))))))))))))))))))
.
2009-02-28 14:33 . 2009-02-28 14:33 53,248 --a------ c:\temp\catchme.dll
2009-02-28 14:30 . 2009-02-28 14:30 <DIR> d-------- c:\temp\WPDNSE
2009-02-28 13:38 . 2009-02-28 13:38 <DIR> d-------- c:\program files\Trend Micro
2009-02-28 11:05 . 2009-02-28 14:33 <DIR> d-------- c:\temp\WERc544.dir00
2009-02-24 23:02 . 2009-02-28 14:33 <DIR> d-------- c:\temp\WER41d2.dir00
2009-02-16 17:31 . 2009-02-16 17:37 4 --a------ c:\windows\oykamldx
2009-02-15 12:26 . 2009-02-15 12:26 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Webroot
2009-02-14 17:49 . 2009-02-14 17:53 <DIR> d-------- c:\temp\7zS5A.tmp
2009-02-14 17:30 . 2009-02-14 17:30 <DIR> d-------- c:\windows\system32\drivers\NAV
2009-02-14 17:30 . 2009-02-14 17:30 <DIR> d-------- c:\program files\Windows Sidebar
2009-02-14 17:02 . 2009-02-14 17:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\PCSettings
2009-02-14 17:01 . 2009-02-14 17:01 <DIR> d-------- c:\program files\NortonInstaller
2009-02-14 17:01 . 2009-02-14 17:01 <DIR> d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-02-14 17:01 . 2009-02-14 17:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Norton
2009-02-14 14:26 . 2009-02-28 14:33 <DIR> d-------- c:\temp\WERa01b.dir00
2009-02-11 18:32 . 2009-02-11 18:32 <DIR> d--h----- c:\windows\system32\GroupPolicy
2009-02-11 18:22 . 2009-02-11 18:22 <DIR> d--hs---- c:\temp\Temporary Internet Files
2009-02-11 18:22 . 2009-02-11 18:22 <DIR> d--hs---- c:\temp\History
2009-02-11 18:22 . 2009-02-28 14:32 <DIR> d--hs---- c:\temp\Cookies
2009-02-11 16:55 . 2009-02-11 16:55 132,608 --a------ c:\windows\ucuqaviv.dll
2009-02-10 12:14 . 2009-02-28 14:33 <DIR> d-------- c:\temp\WER4de3.dir00
2009-02-09 22:04 . 2009-02-28 14:32 <DIR> d-------- c:\temp\sTMP3
2009-02-09 21:55 . 2009-02-28 14:27 2,816 --a------ c:\windows\yxexyruw
2009-02-03 10:09 . 2009-02-03 10:09 54,156 --ah----- c:\windows\QTFont.qfn
2009-02-03 10:09 . 2009-02-03 10:09 1,409 --a------ c:\windows\QTFont.for
2009-01-30 00:30 . 2006-10-04 09:06 1,197,294 -----c--- c:\windows\system32\dllcache\sysmain.sdb
2009-01-30 00:30 . 2006-10-04 09:06 764,868 -----c--- c:\windows\system32\dllcache\apph_sp.sdb
2009-01-30 00:30 . 2006-10-04 09:06 217,118 -----c--- c:\windows\system32\dllcache\apphelp.sdb
2009-01-30 00:29 . 2009-01-30 00:30 <DIR> d-------- c:\windows\system32\drivers\UMDF
2009-01-30 00:27 . 2009-02-28 14:33 <DIR> d-------- c:\temp\{12B17FE5-25A1-48A5-B0E0-171D14A09DE9}
2009-01-30 00:18 . 2007-06-18 14:18 23,680 --a------ c:\windows\system32\drivers\motport.sys
2009-01-29 23:44 . 2009-01-29 23:44 <DIR> d-------- c:\program files\Venturi2
2009-01-29 23:44 . 2002-05-10 09:28 57,344 --a------ c:\windows\system32\vlsp.dll
2009-01-29 23:30 . 2009-01-29 23:30 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
2009-01-29 23:30 . 2009-01-29 23:30 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
2009-01-29 23:27 . 2007-06-18 14:18 23,680 --a------ c:\windows\system32\drivers\motmodem.sys
2009-01-29 23:27 . 2007-11-02 14:36 18,176 --a------ c:\windows\system32\drivers\motccgp.sys
2009-01-29 23:27 . 2007-01-23 19:03 7,680 --a------ c:\windows\system32\drivers\motccgpfl.sys
2009-01-29 23:27 . 2007-11-02 14:51 6,400 --a------ c:\windows\system32\drivers\motswch.sys
2009-01-29 23:22 . 2009-01-29 23:23 <DIR> d-------- c:\program files\Avanquest update
2009-01-29 23:21 . 2009-01-29 23:21 <DIR> d-------- c:\temp\CDM
2009-01-29 23:21 . 2009-01-30 00:31 <DIR> d-------- c:\program files\Motorola Phone Tools
2009-01-29 23:21 . 2009-01-29 23:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\BVRP Software
2009-01-29 23:21 . 2009-01-29 23:21 92,064 --a------ c:\documents and settings\User`\mqdmmdm.sys
2009-01-29 23:21 . 2009-01-29 23:21 79,328 --a------ c:\documents and settings\User`\mqdmserd.sys
2009-01-29 23:21 . 2009-01-29 23:21 66,656 --a------ c:\documents and settings\User`\mqdmbus.sys
2009-01-29 23:21 . 2004-08-03 23:08 25,600 --a------ c:\windows\system32\drivers\usbser.sys
2009-01-29 23:21 . 2004-08-03 23:08 25,600 --a--c--- c:\windows\system32\dllcache\usbser.sys
2009-01-29 23:21 . 2009-01-29 23:21 25,600 --a------ c:\documents and settings\User`\usbsermptxp.sys
2009-01-29 23:21 . 2009-01-29 23:21 22,768 --a------ c:\documents and settings\User`\usbsermpt.sys
2009-01-29 23:21 . 2009-01-29 23:21 9,232 --a------ c:\documents and settings\User`\mqdmmdfl.sys
2009-01-29 23:21 . 2009-01-29 23:21 6,208 --a------ c:\documents and settings\User`\mqdmcmnt.sys
2009-01-29 23:21 . 2009-01-29 23:21 5,936 --a------ c:\documents and settings\User`\mqdmwhnt.sys
2009-01-29 23:21 . 2009-01-29 23:21 4,048 --a------ c:\documents and settings\User`\mqdmcr.sys
2009-01-29 23:18 . 2009-01-29 23:18 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-01-29 23:18 . 2009-01-29 23:18 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_motport_01005.Wdf
2009-01-29 23:18 . 2009-01-29 23:18 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-01-29 23:17 . 2006-11-13 20:45 1,419,232 --a------ c:\windows\system32\wdfcoinstaller01005.dll
2009-01-29 23:16 . 2009-01-29 23:16 <DIR> d-------- c:\program files\Common Files\Motorola Shared
2009-01-29 23:13 . 2009-01-29 23:13 <DIR> d-------- C:\Motorola
2009-01-29 20:30 . 2009-01-29 20:30 <DIR> d-------- c:\documents and settings\User`\Application Data\Free Sound Recorder
2009-01-29 20:29 . 2009-01-29 20:30 <DIR> d-------- c:\program files\Free Sound Recorder
2009-01-29 20:29 . 2005-05-17 12:37 1,986,560 --a------ c:\windows\system32\NCTAudioFile2.dll
2009-01-29 20:29 . 2005-05-18 11:52 1,212,416 --a------ c:\windows\system32\NCTAudioInformation2.dll
2009-01-29 20:29 . 2005-04-15 12:08 880,640 --a------ c:\windows\system32\NCTAudioEditor2.dll
2009-01-29 20:29 . 2004-11-04 13:31 835,584 --a------ c:\windows\system32\NCTAudioCDGrabber2.dll
2009-01-29 20:29 . 2005-04-04 17:21 602,112 --a------ c:\windows\system32\NCTAudioTransform2.dll
2009-01-29 20:29 . 2005-03-28 15:54 479,232 --a------ c:\windows\system32\NCTAudioVisualization2.dll
2009-01-29 20:29 . 2005-04-25 13:01 458,752 --a------ c:\windows\system32\NCTAudioRecord2.dll
2009-01-29 20:29 . 2005-04-25 13:01 458,752 --a------ c:\windows\system32\NCTAudioPlayer2.dll
2009-01-29 20:29 . 2005-03-28 15:52 417,792 --a------ c:\windows\system32\NCTTextToAudio2.dll
2009-01-29 20:29 . 2005-02-24 11:51 348,160 --a------ c:\windows\system32\NCTWMAFile2.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-14 22:31 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-02-14 22:31 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-02-14 22:31 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-02-14 22:31 --------- d-----w c:\program files\Symantec
2009-02-14 22:30 --------- d-----w c:\program files\Norton AntiVirus
2009-02-14 22:27 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-02-14 22:18 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-01-30 05:27 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-18 21:30 --------- d-----w c:\program files\Lavalys
2007-12-20 17:32 0 --sha-w c:\documents and settings\User`\Application Data\6720255eba5078d909a32c540ba1e2bc.dat
2005-10-12 20:04 131,072 ----a-w c:\program files\internet explorer\plugins\LV80ActiveXControl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-15 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"00THotkey"="c:\windows\system32\
00THotkey.exe" [2005-03-01 03:43 245760]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-23 7340032]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-08 761947]
"TouchED"="c:\program files\TOSHIBA\TouchED\TouchED.Exe" [2005-06-28 126976]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"Kraidman"="c:\program files\TOSHIBA\TOSHIBA RAID\Console\Kraidman.exe" [2005-09-30 1126484]
"TosHKCW.exe"="c:\program files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" [2005-05-17 49152]
"PSQLLauncher"="c:\program files\Protector Suite QL\launcher.exe" [2005-12-22 30208]
"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2005-12-06 1077322]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-26 122880]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-10-06 122940]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 151552]
"IVPServiceMgr"="c:\toshiba\ivp\ism\ivpsvmgr.exe" [2003-10-20 475136]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
"osCheck"="c:\program files\Norton AntiVirus\osCheck.exe" [2006-09-05 26248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-09-06 169264]
"Oliqowilojihu"="c:\windows\ucuqaviv.dll" [2009-02-11 132608]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-12-10 5367608]
"000StTHK"="000StTHK.exe" [2001-06-23 07:28 24576 c:\windows\system32\
000StTHK.exe]
"TPSMain"="TPSMain.exe" [2005-12-06 c:\windows\system32\TPSMain.exe]
"TPSODDCtl"="TPSODDCtl.exe" [2005-12-06 c:\windows\system32\TPSODDCtl.exe]
"TFNF5"="TFNF5.exe" [2005-12-09 c:\windows\system32\TFNF5.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
"TFncKy"="TFncKy.exe" [BU]
"CFSServ.exe"="CFSServ.exe" [BU]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
MFWAKeys.lnk - c:\program files\MOTU\FireWire Audio\MFWAKeys.exe [2006-06-16 106496]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-01-13 155648]
Venturi 2.lnk - c:\program files\Venturi2\Configurator\ventcfg.exe [2009-01-29 1478656]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2005-12-22 00:42 40448 c:\windows\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^User`^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=c:\documents and settings\User`\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=c:\windows\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-07-31 17:44 271672 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 11:24 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell]
--a------ 2006-11-08 19:03 323216 c:\program files\Napster\napster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
--a------ 2007-12-10 20:08 5367608 c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-06-15 12:17 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\wEmail Removedexe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1137179788\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Call of Duty\\CoDMP.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
R0 KR10N2K;KR10N2K;c:\windows\system32\drivers\KR10N2K.sys [2006-01-13 207360]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1002000.007\SymEFA.sys [2009-02-14 309296]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1002000.007\BHDrvx86.sys [2009-02-14 255536]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1002000.007\cchpx86.sys [2009-02-14 362544]
R2 FdRedir;FdRedir;c:\program files\Common Files\Protector Suite QL\Drivers\FdRedir.sys [2005-12-22 13568]
R2 FileDisk2;FileDisk Protector Kernel Driver;c:\program files\Common Files\Protector Suite QL\Drivers\filedisk.sys [2005-12-22 33024]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe [2009-02-14 115560]
R2 smihlp;SMI helper driver;c:\program files\Protector Suite QL\smihlp.sys [2005-12-22 3456]
R2 thdudf;TOSHIBA UDF2.5 Reader File System Driver;c:\windows\system32\drivers\thdudf.sys [2006-01-13 66816]
R2 TOS_SPS;TOSHIBA SPS Driver;c:\program files\Toshiba\TMP2VDec\tos_sps.sys [2005-12-21 169216]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-25 101936]
R3 motubus;MOTU Audio MIDI Extension;c:\windows\system32\drivers\motubus.sys [2006-06-16 15488]
R3 ttv300x;TOSHIBA PCI TV Tuner;c:\windows\system32\drivers\ttv300x.sys [2006-01-17 136960]
S0 yxexyruw;yxexyruw;c:\windows\system32\drivers\tnebehbi.sys []
S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090225.002\IDSxpx86.sys [2009-02-28 276344]
S3 MFWAMIDI;MOTU FireWire Audio MIDI;c:\windows\system32\drivers\MFWAMIDI.sys [2006-06-16 18816]
S3 MFWAWAVE;MOTU FireWire Audio Wave;c:\windows\system32\drivers\MFWAWave.sys [2006-06-16 24320]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2009-01-29 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2009-01-29 7680]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2009-01-30 23680]
S3 MotuFWA;MotuFWA;c:\windows\system32\drivers\MotuFWA.sys [2006-06-16 120576]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - .\Encryption Tool\MaxtorEncryption.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1dcabfbe-a94a-11dd-8fd9-00038a000015}]
\Shell\AutoRun\command - .\Encryption Tool\MaxtorEncryption.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ff55c60-a2cb-11dc-8f18-00038a000015}]
\Shell\AutoRun\command - EXPLORER.EXE
\Shell\explore\Command - EXPLORER.EXE
\Shell\open\Command - EXPLORER.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{34e718a4-094a-11dc-8e5c-00038a000015}]
\Shell\AutoRun\command - EXPLORER.EXE
\Shell\explore\Command - EXPLORER.EXE
\Shell\open\Command - EXPLORER.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6645125e-9c46-11dc-8f16-94de8168b46b}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68fe6482-d809-11dc-8f51-00038a000015}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2008-01-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 12:15]
2008-10-13 c:\windows\Tasks\wrSpySweeperTrialSweep.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2007-12-10 20:08]
2008-10-13 c:\windows\Tasks\wrSpySweeperTrialSweep.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2007-12-10 20:08]
2008-10-13 c:\windows\Tasks\wrSpySweeperTrialSweep.job
- C:\ [2009-02-28 14:24]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Brotaba - c:\windows\Clakeyifeg.dll
HKLM-Run-SigmatelSysTrayApp - stsystra.exe
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: vlsp.dll
Trusted Zone: turbotax.com
FF - ProfilePath - c:\documents and settings\User`\Application Data\Mozilla\Firefox\Profiles\h3h9impk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJPI150_04.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPOJI610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-28 14:33:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\system32\drivers\tnebehbi.sys 25088 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.2.0.7\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(980)
c:\windows\system32\psqlpwd.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\windows\system32\biologon.dll
c:\program files\Protector Suite QL\homepass.dll
c:\program files\Protector Suite QL\bio.dll
c:\program files\Protector Suite QL\remote.dll
c:\windows\system32\WRLogonNTF.dll
c:\program files\Protector Suite QL\crypto.dll
c:\program files\Protector Suite QL\mysafe.dll
- - - - - - - > 'lsass.exe'(1044)
c:\windows\system32\psqlpwd.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\windows\system32\vlsp.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Common Files\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Toshiba\TOSHIBA RAID\Service\kraidsvc.exe
c:\windows\system32\lkcitdl.exe
c:\windows\system32\lkads.exe
c:\windows\system32\lktsrv.exe
c:\program files\Maxtor\Sync\SyncServices.exe
c:\program files\Synaptics\SynTP\Toshiba.exe
c:\windows\system32\TPSBattM.exe
c:\program files\National Instruments\Shared\Security\nidmsrv.exe
c:\windows\system32\nisvcloc.exe
c:\program files\Toshiba\ConfigFree\NDSTray.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Protector Suite QL\psqltray.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\SigmaTel\C-Major Audio\WDM\stacsv.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\Venturi2\Client\VentC.exe
c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\windows\ehome\ehmsas.exe
c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
c:\program files\Symantec\LiveUpdate\AUPDATE.EXE
.
**************************************************************************
.
Completion time: 2009-02-28 14:39:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-28 19:38:56
Pre-Run: 38,184,873,984 bytes free
Post-Run: 39,890,067,456 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect /forceresetreg
402 --- E O F --- 2009-01-31 14:53:27