2nd page of ComboFix log…
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“TOSCDSPD”=“C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe” [2007-12-28 15:05 65536]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 06:00 15360]
“LDM”=“C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe” [2007-12-28 15:05 36864]
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-10-13 10:24 1694208]
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2007-12-28 15:05 68856]
“SUPERAntiSpyware”=“C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe” [2007-06-21 14:06 1318912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Tvs”=“C:\Program Files\Toshiba\Tvs\TvsTray.exe” [2007-12-28 15:05 73728]
“THotkey”=“C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe” [2005-08-10 12:23 356352]
“IgfxTray”=“C:\WINDOWS\system32\igfxtray.exe” [2007-12-28 15:05 94208]
“HotKeysCmds”=“C:\WINDOWS\system32\hkcmd.exe” [2007-12-28 15:05 77824]
“Persistence”=“C:\WINDOWS\system32\igfxpers.exe” [2007-12-28 15:05 114688]
“LtMoh”=“C:\Program Files\ltmoh\Ltmoh.exe” [2007-12-28 15:05 184320]
“AGRSMMSG”=“AGRSMMSG.exe” [2005-04-12 17:17 88358 C:\WINDOWS\agrsmmsg.exe]
“SynTPLpr”=“C:\Program Files\Synaptics\SynTP\SynTPLpr.exe” [2007-12-28 15:05 98394]
“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2007-12-28 15:05 688218]
“TFncKy”=“TFncKy.exe”
“TPSMain”=“TPSMain.exe” [2005-05-31 22:00 282624 C:\WINDOWS\system32\TPSMain.exe]
“NDSTray.exe”=“NDSTray.exe”
“PadTouch”=“C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe” [2007-12-28 15:05 1077301]
“SmoothView”=“C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe” [2007-12-28 15:05 122880]
“Pinger”=“c:\toshiba\ivp\ism\pinger.exe” [2007-12-28 15:05 151552]
“dla”=“C:\WINDOWS\system32\dla\tfswctrl.exe” [2007-12-28 15:05 122941]
“IntelWireless”=“C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe” [2007-12-28 15:05 385024]
“Logitech Utility”=“Logi_MwX.Exe” [2003-12-17 03:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
“HP Software Update”=“C:\Program Files\HP\HP Software Update\HPWuSchd2.exe” [2007-12-28 15:05 49152]
“Notebook Maximizer”=“C:\Program Files\Notebook Maximizer\maximizer_startup.exe” [2004-05-25 15:35 28672]
“MimBoot”=“C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe” [2006-11-07 15:41 8192]
“CFSServ.exe”=“CFSServ.exe”
“ReminderApp”=“C:\Program Files\Nova Development\Greeting Card Factory Photo Card Maker\ReminderApp.exe” [2007-12-28 15:05 156160]
“QuickTime Task”=“C:\Program Files\QuickTime\QTTask.exe” [2007-11-14 23:43 286720]
“Windows Defender”=“C:\Program Files\Windows Defender\MSASCui.exe” [2006-11-03 19:20 866584]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 07:00 79224]
C:\Documents and Settings\Jon Faulkner\Start Menu\Programs\Startup
TrueAssistant.lnk - C:\Program Files\TrueAssistant\TrueAssistant.exe [2006-11-17 03:45:00]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 20:40:10]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-08-08 01:38:41]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-07-28 14:56:17]
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Engine\ymetray.exe [2007-07-24 15:58:00]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
“{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}”= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-10-15 13:27 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
R0 KR10N;KR10N;C:\WINDOWS\system32\drivers\KR10N.sys [2005-01-11 11:05]
S3 PCTINDIS5;PCTINDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\PCTINDIS5.SYS
S3 SEMWModem;Sony Ericsson SEMWModem;C:\WINDOWS\system32\DRIVERS\GCXX.sys [2005-01-03 01:32]
S3 SEMWWNIC;Sony Ericsson SEMWWNIC;C:\WINDOWS\system32\DRIVERS\GCXXNet.sys [2005-01-03 01:32]
S3 STVqx3;Intel Play QX3 Microscope;C:\WINDOWS\system32\drivers\STVqx3.sys [2001-04-12 13:04]
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2005-05-30 19:28]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the ‘Scheduled Tasks’ folder
“2008-01-01 02:33:51 C:\WINDOWS\Tasks\MP Scheduled Scan.job”
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-31 20:31:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
.
Completion time: 2007-12-31 20:35:52 - machine was rebooted
C:\qoobox\ComboFix-quarantined-files.txt 2008-01-01 02:35:48
.
2007-12-23 07:06:39 — E O F —