((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-05-18 12:05 1232896]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 20:34 2159104 C:\Windows\System32\oobefldr.dll]
"TOSCDSPD"="TOSCDSPD.EXE" []
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 16:21 1449984]
"HuaWeiEVDO.exe"="C:\Program Files\Huawei technologies\Mobile Connect\Mobile Connect.exe" [2007-10-09 11:58 925696]
"ares"="C:\Program Files\Ares\Ares.exe" [ ]
"RemoveIT Pro XT"="C:\Program Files\InCode Solutions\RemoveIT Pro v4-Trial\removeit.exe" [2008-05-27 23:05 580096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-14 15:50 4399104 C:\Windows\RtHDVCpl.exe]
"NDSTray.exe"="NDSTray.exe" []
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-09-20 11:07 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-09-20 11:07 154136]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-09-20 11:07 129560]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-02 13:36 835584]
"TPwrMain"="C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE" [2006-12-19 23:16 411768]
"HSON"="C:\Program Files\TOSHIBA\TBS\HSON.exe" [2006-12-07 16:49 55416]
"SmoothView"="C:\Program Files\Toshiba\SmoothView\SmoothView.exe" [2007-03-22 11:46 448632]
"00TCrdMain"="C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-03-23 14:41 538744]
"Camera Assistant Software"="C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" [2007-03-21 17:23 413696]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-05-16 11:51 949376]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 12:36 229376]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-05-31 10:32 262401]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 14:05 959976]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
C:\Users\TOSHIBA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-04-19 03:21:09 147456]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C902BB4C-47D3-4F0C-8D16-C4F19F126686}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{57714F56-E0CC-4A60-B926-00DE69F5F56F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{488B65FD-EEEF-48F7-9633-FD68B5ADCD5C}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{8C8B1178-3CD6-446E-B31D-51C9F9BB6A6B}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"{6A420FCC-F3A3-47B1-858E-4702BD3B087E}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{4DB7550B-1C9F-40FA-A163-24BF84A7B229}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{18B1B8B1-4E35-4A12-B1CA-944B00BAF1FD}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{171F1DD0-1514-4347-A37A-B7655367A0E4}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{BFCDE734-DAC6-4B3F-B1DD-1177934F7EA4}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{80F1A701-BF14-4F4B-B139-4D831F5390C3}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{9F69B517-F7E3-4F8F-8AF9-034AF0FC63CF}C:\\program files\\ares\\ares.exe"= UDP:C:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{231FD8B2-47D6-4D5B-8619-A8A05C7FF3C7}C:\\program files\\ares\\ares.exe"= TCP:C:\program files\ares\ares.exe:Ares p2p for windows
"TCP Query User{1A4FD322-25F3-4A2A-9032-E2D5D2FA6900}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{11BB9531-E527-41C3-9C4F-171D12424A73}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{7A3F7380-DD18-4275-BE1F-E8CB7BAF553A}C:\\program files\\incode solutions\\removeit pro v4-trial\\removeit.exe"= UDP:C:\program files\incode solutions\removeit pro v4-trial\removeit.exe:removeit
"UDP Query User{69ED6CA7-E059-4D23-997F-E2AADA5694E8}C:\\program files\\incode solutions\\removeit pro v4-trial\\removeit.exe"= TCP:C:\program files\incode solutions\removeit pro v4-trial\removeit.exe:removeit
"{003E26EA-F7D4-492D-9872-397E9C586BCF}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{203DC79D-B8C4-4445-BB88-5B4E035153CB}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 tos_sps32;TOSHIBA tos_sps32 Service;C:\Windows\system32\DRIVERS\tos_sps32.sys [2007-09-19 10:59]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 TNaviSrv;TOSHIBA Navi Support Service;C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe [2007-09-19 11:01]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-26 12:55]
R3 FwLnk;FwLnk Driver;C:\Windows\system32\DRIVERS\FwLnk.sys [2006-11-20 13:11]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-09-13 15:23]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver;C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-19 02:50]
R3 UVCFTR;UVCFTR;C:\Windows\system32\DRIVERS\UVCFTR_S.SYS [2007-03-12 21:47]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-01-10 01:00]
S3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2006-11-02 15:30]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\shell\AutoRun\command - E:\wd_windows_tools\WDEULA.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{60f6bbee-27c7-11dd-9af7-001cbfcdd3e3}]
\shell\AutoRun\command - E:\wd_windows_tools\WDEULA.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6ebe81b2-2ae8-11dd-bcd6-001cbfcdd3e3}]
\shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{74c7f661-2b14-11dd-b374-001cbfcdd3e3}]
\shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{74c7f66e-2b14-11dd-b374-001cbfcdd3e3}]
\shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7c58070d-2a17-11dd-bbf6-001e3331441a}]
\shell\AutoPlay\command - wscript.exe \saifulfaizan.js
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe \saifulfaizan.js
\shell\Explore\command - wscript.exe \saifulfaizan.js -Clicked
\shell\Open\command - wscript.exe \saifulfaizan.js
\shell\Scan for Viruses\command - wscript.exe \saifulfaizan.js
\shell\Scan with AVG\command - wscript.exe \saifulfaizan.js
\shell\Scan with Norton AntiVirus\command - wscript.exe \saifulfaizan.js
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7d50ed21-29ab-11dd-a1c0-001cbfcdd3e3}]
\shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7d50ed4c-29ab-11dd-a1c0-001e3331441a}]
\shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{db2532ca-272a-11dd-ba7a-001cbfcdd3e3}]
\shell\AutoPlay\command - wscript.exe \saifulfaizan.js
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe \saifulfaizan.js
\shell\Explore\command - wscript.exe \saifulfaizan.js -Clicked
\shell\Open\command - wscript.exe \saifulfaizan.js
\shell\Scan for Viruses\command - wscript.exe \saifulfaizan.js
\shell\Scan with AVG\command - wscript.exe \saifulfaizan.js
\shell\Scan with Norton AntiVirus\command - wscript.exe \saifulfaizan.js
.
Contents of the 'Scheduled Tasks' folder
"2008-05-17 02:20:35 C:\Windows\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-30 12:20:35 C:\Windows\Tasks\User_Feed_Synchronization-{11EA8DFC-B6F5-4624-B338-034E421E2214}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-31 18:57:52
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\Users\TOSHIBA\AppData\Local\Microsoft\Messenger\
[email protected]\SharingMetadata\Working\database_9EE4_636C_E463_461D\$db_clean$ 0 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
Completion time: 2008-05-31 18:59:09
ComboFix-quarantined-files.txt 2008-05-31 10:58:38
ComboFix2.txt 2008-05-26 06:14:08
ComboFix3.txt 2008-05-25 15:17:42
Pre-Run: 91,136,757,760 bytes free
Post-Run: 91,445,297,152 bytes free
437 --- E O F --- 2008-05-31 08:09:20