ComboFix 08-06-16.5 - Bao P 2008-06-19 9:54:36.1 - NTFSx86
Running from: C:\Users\Bao P\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\NetProject
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Possible infected sites -----
hxxp://origin.dogfood.windowsonecare.com
.
((((((((((((((((((((((((( Files Created from 2008-05-19 to 2008-06-19 )))))))))))))))))))))))))))))))
.
2008-06-17 12:40 . 2008-06-17 12:40 <DIR> d-------- C:\_OTMoveIt
2008-06-16 10:45 . 2008-06-16 10:45 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-14 16:08 . 2008-04-22 21:42 428,544 --a------ C:\Windows\System32\EncDec.dll
2008-06-14 16:08 . 2008-04-22 21:42 293,376 --a------ C:\Windows\System32\psisdecd.dll
2008-06-14 16:08 . 2008-04-22 21:41 218,624 --a------ C:\Windows\System32\psisrndr.ax
2008-06-14 16:08 . 2008-04-22 21:41 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
2008-06-14 14:08 . 1998-10-29 16:45 306,688 --a------ C:\Windows\IsUninst.exe
2008-06-10 14:51 . 2008-04-26 01:08 1,314,816 --a------ C:\Windows\System32\quartz.dll
2008-06-10 14:51 . 2008-05-09 20:35 885,248 --a------ C:\Windows\System32\RacEngn.dll
2008-06-10 14:51 . 2008-04-28 18:42 220,160 --a------ C:\Windows\System32\drivers\bthport.sys
2008-06-10 14:51 . 2008-04-28 20:54 181,760 --a------ C:\Windows\System32\fsquirt.exe
2008-06-10 14:51 . 2008-05-09 18:33 113,664 --a------ C:\Windows\System32\drivers\rmcast.sys
2008-06-10 14:51 . 2008-04-28 18:42 29,184 --a------ C:\Windows\System32\drivers\BTHUSB.SYS
2008-06-10 14:51 . 2008-05-09 15:22 9,127 --a------ C:\Windows\System32\RacUR.xml
2008-06-10 14:51 . 2008-05-09 15:22 153 --a------ C:\Windows\System32\RacUREx.xml
2008-06-10 14:50 . 2008-04-24 21:35 826,880 --a------ C:\Windows\System32\wininet.dll
2008-06-10 14:49 . 2008-04-24 19:12 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-06-07 22:32 . 2008-06-07 23:53 <DIR> d-------- C:\Program Files\Total Video Converter
2008-06-07 22:32 . 2000-05-22 22:58 608,448 --a------ C:\Windows\System32\comctl32.ocx
2008-06-07 14:26 . 2008-06-07 14:26 <DIR> d-------- C:\Windows\System32\Analogy dir
2008-06-07 14:26 . 2008-06-07 14:26 201,728 --a------ C:\Windows\System32\Analogy.scr
2008-06-05 19:52 . 2008-06-05 19:52 <DIR> d-------- C:\Users\All Users\Musicnotes
2008-06-05 19:52 . 2008-06-05 19:52 <DIR> d-------- C:\ProgramData\Musicnotes
2008-06-05 19:45 . 2008-06-05 19:45 284,248 --a------ C:\Program Files\npmusicn.dll
2008-05-27 11:23 . 2008-03-07 19:08 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-27 11:23 . 2008-03-07 21:21 1,695,744 --a------ C:\Windows\System32\gameux.dll
2008-05-24 10:26 . 2007-11-27 22:45 91,200 --a------ C:\Windows\System32\drivers\msfwdrv.sys
2008-05-24 10:26 . 2007-11-27 22:44 37,440 --a------ C:\Windows\System32\drivers\msfwhlpr.sys
2008-05-24 10:23 . 2008-05-24 10:23 <DIR> d-------- C:\Program Files\Common Files\PX Storage Engine
2008-05-24 10:22 . 2007-07-06 15:09 70,928 --a------ C:\Windows\System32\drivers\MpFilter.sys
2008-05-24 10:08 . 2008-06-18 23:40 <DIR> d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-05-24 10:05 . 2008-05-24 10:05 <DIR> d-------- C:\Users\Bao P\Program Files
2008-05-24 09:39 . 2008-06-19 10:07 <DIR> d-------- C:\Users\Bao P\AppData\Roaming\DNA
2008-05-24 09:39 . 2008-06-15 01:02 <DIR> d-------- C:\Users\Bao P\AppData\Roaming\BitTorrent
2008-05-24 09:39 . 2008-05-24 09:39 <DIR> d-------- C:\Program Files\DNA
2008-05-24 09:39 . 2008-05-24 09:39 <DIR> d-------- C:\Program Files\BitTorrent
2008-05-21 03:15 . 2008-05-24 09:27 <DIR> d-------- C:\Users\All Users\WeFi
2008-05-21 03:15 . 2008-05-24 09:27 <DIR> d-------- C:\ProgramData\WeFi
2008-05-21 02:12 . 2008-05-21 02:12 <DIR> d-------- C:\Users\Bao P\AppData\Roaming\Camfrog
2008-05-21 02:12 . 2008-05-21 02:12 <DIR> d-------- C:\Program Files\The Weather Channel FW
2008-05-20 05:31 . 2008-05-20 05:31 <DIR> d-------- C:\Program Files\Apple Software Update
2008-05-19 20:36 . 2008-05-19 20:36 <DIR> d-------- C:\Users\Bao P\AppData\Roaming\Worksimaging
2008-05-19 19:51 . 2008-05-19 19:51 <DIR> d-------- C:\Program Files\Common Files\muvee Technologies
2008-05-19 19:50 . 2007-02-08 12:30 626,688 -ra------ C:\Windows\System32\msvcr80.dll
2008-05-19 19:50 . 2007-02-08 12:30 548,864 -ra------ C:\Windows\System32\msvcp80.dll
2008-05-19 19:50 . 2007-02-08 12:30 95,744 -ra------ C:\Windows\System32\atl80.dll
2008-05-19 19:48 . 2008-05-19 19:48 <DIR> d-------- C:\Program Files\OLYMPUS
2008-05-19 19:46 . 2008-05-19 19:46 <DIR> d-------- C:\Program Files\MSXML 4.0
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-14 21:32 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-12 18:23 --------- d-----w C:\Program Files\Windows Mail
2008-06-07 14:14 --------- d-----w C:\ProgramData\Skype
2008-06-06 17:59 --------- d-----w C:\Users\Bao P\AppData\Roaming\OpenOffice.org2
2008-05-24 16:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-20 02:49 --------- d-----w C:\ProgramData\Apple Computer
2008-05-20 02:05 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-10 16:33 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-09 05:35 --------- d-----w C:\Program Files\RegistryPatrol3.0
2008-04-27 04:28 --------- d-----w C:\Program Files\TOSHIBA
2008-04-21 23:06 130,208 ------r C:\Windows\bwUnin-8.1.1.87-8876480SL.exe
2008-04-06 19:41 174 --sha-w C:\Program Files\desktop.ini
2008-02-07 16:50 32 ----a-w C:\Users\All Users\ezsid.dat
2008-02-07 16:50 32 ----a-w C:\ProgramData\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@={F2F31467-B1AC-4df0-AE79-FD5FA085E22B}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@={A3E208F7-0E3A-4182-A7A6-B169D5D691AA}
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-11-14 13:22 3186440 --a------ C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-11-14 13:22 3186440 --a------ C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 00:33 1233920]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 00:33 125952]
"VistaBatterySaver"="C:\Program Files\SharpSoft\Vista Battery Saver\VistaBatterySaver.exe" [2007-07-24 19:49 401408]
"OM2_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-09-04 14:52 95536]
"BitTorrent DNA"="C:\Users\Bao P\Program Files\DNA\btdna.exe" [2008-05-24 10:05 289088]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 00:33 202240]
"Speech Recognition"="C:\Windows\Speech\Common\sapisvr.exe" [2008-01-19 00:33 49664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSDCR"="C:\Program Files\TOSHIBA\PasswordUtility\TOSDCR.exe" [2006-12-01 18:45 171696]
"TPwrMain"="C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE" [2006-12-02 13:14 409264]
"HSON"="C:\Program Files\TOSHIBA\TBS\HSON.exe" [2006-11-28 13:19 52912]
"SmoothView"="C:\Program Files\Toshiba\SmoothView\SmoothView.exe" [2006-11-20 13:15 446128]
"00TCrdMain"="C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" [2006-11-29 15:03 523952]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2006-09-11 00:21 180224]
"ThpSrv"="C:\Windows\system32\thpsrv /logon" [ ]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-05 18:02 98304]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-05 18:05 106496]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-05 18:02 81920]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2005-12-15 11:41 188416]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 17:02 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 17:06 2027792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"PSQLLauncher"="C:\Program Files\Protector Suite QL\launcher.exe" [2007-11-14 12:38 49416]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-02-29 22:10 15872]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-17 17:41 185896]
"OM2_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" [2007-09-04 14:52 54576]
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [2008-05-14 15:37 67112]
C:\Users\Bao P\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
1-Click Answers.lnk - C:\Program Files\1-Click Answers\answers.exe [2008-02-05 19:43:28 798720]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-06-14 14:32:53 113664]
Bluetooth Monitor.lnk - C:\Program Files\TOSHIBA\Bluetooth Monitor\BtMon2.exe [2008-04-26 21:28:14 69632]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-04-21 16:06:39 91440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
C:\Windows\system32\psqlpwd.dll 2007-11-14 13:07 96008 C:\Windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\vio\dvacm.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{BC5BEAD8-8493-4150-9FAB-830AF72E7222}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{74F4A3AF-5ED1-430F-A043-C39E54C0572C}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{500F1D46-14F0-4732-9369-AA066D3D4DBD}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{865192DC-8101-402B-8F17-5103E186D67E}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{F3E17541-E4F6-48E4-B013-38CCB6421D99}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{AB7F7335-106C-4F1B-8E99-456C1472E41F}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{DA9164BF-B526-44A9-9299-B6CA877FCD7B}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{0DC319A4-A8A4-44FC-B181-F239A5A68540}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{B778C23C-4519-4A83-BFD0-15EB65E757FD}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{08A49FED-04BA-48C2-AECF-AEDD36CDCEC6}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{2CC4DF79-9F7B-4FB0-9851-F40830D7772F}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{41DAC1B7-8D8D-4B97-A195-27F8ABC53E7C}"= UDP:6331:Windows Live OneCare
"{E772FD40-D6CC-4E78-A8B2-5F4172BA6F2C}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{79C147DF-3F3E-4496-BFA5-68E1F2FFA2EA}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{FC09A855-A4D0-48A3-BB80-609C28E720D7}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{E84ABAB1-6D39-41F7-840B-63810D44D8DD}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{B3991199-3856-446B-8424-95267DF02C14}"= UDP:C:\Program Files\DNA\btdna.exe

NA
"{A33DBA09-2608-4D11-B061-8481AF93DB27}"= TCP:C:\Program Files\DNA\btdna.exe

NA
"{91E91E95-2F9C-48AF-8364-DD03F6963B8B}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{CB0FCA58-607D-4647-B1BC-12BB88D0454C}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{AEC77D67-B75B-44C6-9256-4DF02066EAFD}C:\\users\\bao p\\program files\\dna\\btdna.exe"= UDP:C:\users\bao p\program files\dna\btdna.exe:btdna.exe
"UDP Query User{673A63BC-0B36-4966-8C68-613D762B270E}C:\\users\\bao p\\program files\\dna\\btdna.exe"= TCP:C:\users\bao p\program files\dna\btdna.exe:btdna.exe
"{D02B228E-18D6-4AFB-9E2D-111EB58D53F5}"= UDP:63331:Windows Live OneCare
"{143CE8F1-AE2B-4861-83D9-22C786D3A8CD}"= UDP:63331:Windows Live OneCare
"{D1C484A1-8F15-461D-A7D9-B64F640D9F36}"= UDP:63331:Windows Live OneCare
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 Thpdrv;TOSHIBA HDD Protection Driver;C:\Windows\system32\DRIVERS\thpdrv.sys [2007-02-08 13:46]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;C:\Windows\system32\DRIVERS\Thpevm.SYS [2007-02-07 17:29]
R2 OcHealthMon;Windows Live OneCare Health Monitor;"C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe" [2008-05-14 15:33]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-05 19:29]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-19 10:11:06
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\Windows\Explorer.exe
-> C:\Program Files\Unlocker\UnlockerHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\System32\audiodg.exe
C:\Program Files\Protector Suite QL\upeksvr.exe
C:\Windows\System32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\System32\ThpSrv.exe
C:\Windows\System32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\System32\ThpSrv.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
.
**************************************************************************
.
Completion time: 2008-06-19 10:18:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-19 17:18:24
Pre-Run: 78,050,643,968 bytes free
Post-Run: 78,032,379,904 bytes free
226 --- E O F --- 2008-06-15 08:04:18