ComboFix 13-05-16.02 - Main 05/17/2013 23:03:51.1.2 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.2010.1056 [GMT -4:00]
Running from: c:\users\User\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\programdata\Roaming
c:\programdata\Roaming\Intel\Wireless\Settings\Settings.ini
c:\users\Public\ntoskrnl.exe
c:\users\User\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk
c:\users\User\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\rasphone.pbk
c:\users\User\EndProcess.exe
c:\users\User\Net_Session.dll
c:\users\User\P2PEnv.dll
c:\users\User\watchupdate.dll
c:\users\User\xobglu32.dll
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\pt
c:\windows\system32\pt\toscdspd.cpl.mui
c:\windows\system32\Thumbs.db
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Files Created from 2013-04-18 to 2013-05-18 )))))))))))))))))))))))))))))))
.
.
2013-05-18 03:13 . 2013-05-18 03:13--------d-----w-c:\users\Default\AppData\Local\temp
2013-05-16 14:14 . 2013-05-16 14:14--------d-----w-c:\programdata\Malwarebytes
2013-05-16 14:14 . 2013-04-04 18:5022856----a-w-c:\windows\system32\drivers\mbam.sys
2013-05-16 14:14 . 2013-05-16 14:15--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2013-05-08 03:52 . 2013-05-08 03:52--------d-----w-c:\users\Main
2013-04-25 14:47 . 2013-04-25 14:47--------d-----w-c:\program files\DomaIQ Uninstaller
2013-04-25 14:40 . 2013-04-25 14:40--------d-----w-c:\users\User\AppData\Local\Updater19962
2013-04-25 14:40 . 2013-04-25 14:40--------d-----w-c:\users\User\AppData\Local\Supreme Savings
2013-04-25 14:40 . 2013-04-25 14:40--------d-----w-c:\program files\Supreme Savings
2013-04-25 14:04 . 2013-03-03 19:071082232----a-w-c:\windows\system32\drivers\ntfs.sys
2013-04-22 01:22 . 2013-04-04 09:3594112----a-w-c:\windows\system32\WindowsAccessBridge.dll
2013-04-18 03:58 . 2013-04-18 04:00--------d-----w-c:\users\User\AppData\Roaming\Oberon Media
2013-04-18 03:56 . 2013-04-18 03:5641----a-w-C:\user.js
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-15 12:45 . 2013-02-13 06:2971048----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-15 12:45 . 2013-02-13 06:29692104----a-w-c:\windows\system32\FlashPlayerApp.exe
2013-04-02 14:09 . 2013-04-02 14:094550656----a-w-c:\windows\system32\GPhotos.scr
2013-03-27 16:30 . 2013-03-27 16:30161792----a-w-c:\windows\system32\msls31.dll
2013-03-27 16:30 . 2013-03-27 16:3076800----a-w-c:\windows\system32\SetIEInstalledDate.exe
2013-03-27 16:30 . 2013-03-27 16:3074752----a-w-c:\windows\system32\RegisterIEPKEYs.exe
2013-03-27 16:30 . 2013-03-27 16:3048640----a-w-c:\windows\system32\mshtmler.dll
2013-03-27 16:30 . 2013-03-27 16:3086528----a-w-c:\windows\system32\iesysprep.dll
2013-03-27 16:30 . 2013-03-27 16:3074752----a-w-c:\windows\system32\iesetup.dll
2013-03-27 16:30 . 2013-03-27 16:3063488----a-w-c:\windows\system32\tdc.ocx
2013-03-27 16:30 . 2013-03-27 16:30367104----a-w-c:\windows\system32\html.iec
2013-03-27 16:30 . 2013-03-27 16:3023552----a-w-c:\windows\system32\licmgr10.dll
2013-03-27 16:30 . 2013-03-27 16:30152064----a-w-c:\windows\system32\wextract.exe
2013-03-27 16:30 . 2013-03-27 16:30150528----a-w-c:\windows\system32\iexpress.exe
2013-03-27 16:30 . 2013-03-27 16:3011776----a-w-c:\windows\system32\mshta.exe
2013-03-27 16:30 . 2013-03-27 16:30101888----a-w-c:\windows\system32\admparse.dll
2013-03-27 16:30 . 2013-03-27 16:3035840----a-w-c:\windows\system32\imgutil.dll
2013-03-27 16:30 . 2013-03-27 16:30110592----a-w-c:\windows\system32\IEAdvpack.dll
2013-03-11 13:25 . 2013-04-16 00:443603816----a-w-c:\windows\system32\ntkrnlpa.exe
2013-03-11 13:25 . 2013-04-16 00:443551080----a-w-c:\windows\system32\ntoskrnl.exe
2013-03-09 03:45 . 2013-04-16 00:4449152----a-w-c:\windows\system32\csrsrv.dll
2013-03-09 01:28 . 2013-04-16 00:4464000----a-w-c:\windows\system32\smss.exe
2013-03-08 03:53 . 2013-04-16 00:44376320----a-w-c:\windows\system32\winsrv.dll
2013-03-08 03:52 . 2013-04-16 00:442067968----a-w-c:\windows\system32\mstscax.dll
2013-03-06 22:33 . 2013-03-14 12:43164736----a-w-c:\windows\system32\drivers\aswVmm.sys
2013-03-06 22:33 . 2013-03-14 12:4349248----a-w-c:\windows\system32\drivers\aswRvrt.sys
2013-03-06 22:33 . 2012-02-17 00:40765736----a-w-c:\windows\system32\drivers\aswSnx.sys
2013-03-06 22:33 . 2012-02-17 00:4062376----a-w-c:\windows\system32\drivers\aswTdi.sys
2013-03-06 22:33 . 2012-02-17 00:4049760----a-w-c:\windows\system32\drivers\aswRdr.sys
2013-03-06 22:33 . 2012-02-17 00:40368176----a-w-c:\windows\system32\drivers\aswSP.sys
2013-03-06 22:33 . 2012-02-17 00:4066336----a-w-c:\windows\system32\drivers\aswMonFlt.sys
2013-03-06 22:33 . 2012-02-17 00:4029816----a-w-c:\windows\system32\drivers\aswFsBlk.sys
2013-03-06 22:32 . 2012-02-17 00:3941664----a-w-c:\windows\avastSS.scr
2013-03-06 22:32 . 2012-02-17 00:39228600----a-w-c:\windows\system32\aswBoot.exe
2013-03-06 05:33 . 2012-12-29 04:45861088----a-w-c:\windows\system32\npDeployJava1.dll
2013-03-06 05:33 . 2012-12-29 04:45782240----a-w-c:\windows\system32\deployJava1.dll
2013-03-05 01:40 . 2013-04-16 00:442049024----a-w-c:\windows\system32\win32k.sys
2013-02-22 03:46 . 2013-04-16 00:471800704----a-w-c:\windows\system32\jscript9.dll
2013-02-22 03:38 . 2013-04-16 00:471129472----a-w-c:\windows\system32\wininet.dll
2013-02-22 03:37 . 2013-04-16 00:471427968----a-w-c:\windows\system32\inetcpl.cpl
2013-02-22 03:34 . 2013-04-16 00:47142848----a-w-c:\windows\system32\ieUnatt.exe
2013-02-22 03:34 . 2013-04-16 00:47420864----a-w-c:\windows\system32\vbscript.dll
2013-02-22 03:31 . 2013-04-16 00:472382848----a-w-c:\windows\system32\mshtml.tlb
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-03-06 22:32121968----a-w-c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\Sidebar.exe" [2009-04-11 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2008-04-24 430080]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ThpSrv"="c:\windows\system32\thpsrv" [X]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-12-15 184320]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-13 6139904]
"TOSDCR"="c:\program files\TOSHIBA\PasswordUtility\TOSDCR.exe" [2007-08-28 169296]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-02-06 431456]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-11-01 54608]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2008-06-02 505720]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-05-09 716800]
"NDSTray.exe"="NDSTray.exe" [BU]
"TosAutLk"="c:\program files\TOSHIBA\WirelessKeyLogon\TosAutLk.exe" [2008-04-02 116040]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2011-05-05 30192]
"TPCHWMsg"="c:\program files\TOSHIBA\TPHM\TPCHWMsg.exe" [2008-08-29 480616]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-03-06 4767304]
"MsmqIntCert"="mqrt.dll" [2009-04-11 150528]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-22 13552160]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-08-22 92704]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2013-04-04 532040]
"Z1"="c:\users\User\Downloads\mbar-1.05.0.1001\mbar\mbar.exe" [2013-05-17 1398856]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ITSecMng]
2007-09-28 23:0375136----a-w-c:\program files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-08-22 17:1492704----a-w-c:\windows\System32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\picon]
2008-04-29 22:45367128----a-w-c:\program files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToshibaServiceStation]
2008-08-04 19:461242424----a-w-c:\program files\Toshiba\TOSHIBA Service Station\TSS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - TRUESIGHT
*Deregistered* - TrueSight
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetworkREG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonationREG_MULTI_SZ FontCache
LPDServiceREG_MULTI_SZ LPDSVC
rsmsvcsREG_MULTI_SZ ntmssvc
HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-10 09:131642448----a-w-c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-13 12:45]
.
2013-05-17 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2765216513-3551065896-2920961464-1000Core.job
- c:\users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-07 23:00]
.
2013-05-18 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2765216513-3551065896-2920961464-1000UA.job
- c:\users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-07 23:00]
.
2013-05-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-06 14:49]
.
2013-05-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-06 14:49]
.
.
------- Supplementary Scan -------
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 75.75.76.76 75.75.75.75
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-cfFncEnabler.exe - cfFncEnabler.exe
HKLM-Run-NWEReboot - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-UsbMonitor - c:\program files\TrueSuite Access Manager\usbnotify.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2013-05-17 23:14
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD = c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/I??????C8?????h?????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-05-17 23:17:03
ComboFix-quarantined-files.txt 2013-05-18 03:17
.
Pre-Run: 83,585,830,912 bytes free
Post-Run: 89,544,593,408 bytes free
.
- - End Of File - - 275E5A4864DA33BB266CE9A47C8F5CCB