((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@={F2F31467-B1AC-4df0-AE79-FD5FA085E22B}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@={A3E208F7-0E3A-4182-A7A6-B169D5D691AA}
[HKEY_CLASSES_ROOT\CLSID{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-01-05 15:41 2857984 --a------ C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_CLASSES_ROOT\CLSID{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-01-05 15:41 2857984 --a------ C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“WindowsWelcomeCenter”=“rundll32.exe” [2006-11-02 04:45 44544 C:\Windows\System32\rundll32.exe]
“ehTray.exe”=“C:\Windows\ehome\ehTray.exe” [2006-11-02 07:35 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Windows Defender”=“C:\Program Files\Windows Defender\MSASCui.exe” [2007-05-03 13:24 1006264]
“RtHDVCpl”=“RtHDVCpl.exe” [2007-04-06 13:18 4423680 C:\Windows\RtHDVCpl.exe]
“IgfxTray”=“C:\Windows\system32\igfxtray.exe” [2007-03-23 22:06 138008]
“HotKeysCmds”=“C:\Windows\system32\hkcmd.exe” [2007-03-23 22:05 154392]
“Persistence”=“C:\Windows\system32\igfxpers.exe” [2007-03-23 22:06 133912]
“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2007-03-07 21:38 835584]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 01:11 132496]
“ISBMgr.exe”=“C:\Program Files\Sony\ISB Utility\ISBMgr.exe” [2007-04-16 21:06 321656]
“NapsterShell”=“C:\Program Files\Napster\napster.exe”
“VAIOCameraUtility”=“C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe” [2007-04-02 18:49 411768]
“VAIO Center Access Bar”=“c:\program files\sony\VAIO Center Access Bar\VCAB.exe” [2007-03-06 17:22 36864]
“VAIOSecurity”=“C:\Program Files\Sony\VAIO Security Center\VSC.exe” [2007-03-13 19:13 2322432]
“QuickBooks Simple Start”=“C:\Program Files\Intuit\SimpleStartEntice\entice.exe” [2007-01-30 23:59 371712]
“Acrobat Assistant 8.0”=“C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe” [2008-01-11 19:54 623992]
“PSQLLauncher”=“C:\Program Files\Protector Suite QL\launcher.exe” [2007-01-05 15:07 49168]
“Corel Photo Downloader”=“C:\Program Files\Corel\Corel Snapfire\Corel PhotoDownloader.exe”
“VAIOSurvey”=“C:\Program Files\Sony\VAIO Survey\Vista VAIO Survey.exe” [2006-12-06 19:08 577536]
“TkBellExe”=“C:\Program Files\Common Files\Real\Update_OB\realsched.exe” [2007-10-09 01:50 185632]
“avast!”=“C:\PROGRA~1\Avast\ashDisp.exe” [2007-09-06 05:06 79224]
“Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2008-01-11 22:16 39792]
“GrooveMonitor”=“C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe” [2007-08-24 07:00 33648]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2006-11-29 13:09:20 968224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“DisableCAD”= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
“{93994DE8-8239-4655-B1D1-5F4E91300429}”= C:\Program Files\DVD Region+CSS Free\DVDShell.dll [2004-10-09 15:18 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
C:\Windows\system32\psqlpwd.dll 2007-01-05 15:28 90112 C:\Windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2007-04-23 19:19 98304 C:\Windows\System32\VESWinlogon.dll
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-09-06 05:02]
R2 MSSQL$VAIO_VEDB;SQL Server (VAIO_VEDB);“C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe” [2007-02-10 05:29]
R2 regi;regi;C:\Windows\system32\drivers\regi.sys [2007-01-03 13:19]
R2 SQLWriter;SQL Server VSS Writer;“C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe” [2007-02-10 05:29]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-02-27 07:18]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-03-23 22:05]
R3 NETw4v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-09-26 13:12]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;C:\Windows\system32\Drivers\R5U870FLx86.sys [2007-04-04 09:13]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;C:\Windows\system32\Drivers\R5U870FUx86.sys [2007-04-04 09:13]
R3 RTL8169;Realtek 8169 NT Driver;C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-12-28 11:21]
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\Windows\system32\DRIVERS\SonyImgF.sys [2007-04-05 08:06]
R3 TcUsb;TC USB Kernel Driver;C:\Windows\system32\Drivers\tcusb.sys [2006-12-01 07:07]
R3 ti21sony;ti21sony;C:\Windows\system32\drivers\ti21sony.sys [2007-04-23 12:29]
S3 ICScsiSV;Image Converter SCSI Service;C:\Program Files\Sony\Image Converter 3\ICScsiSV.exe [2007-01-26 13:41]
S3 IcVzMonLauncher;IcVzMonLauncher;“C:\Program Files\Sony\Image Converter 3\IcVzMonLauncher.exe” [2007-01-26 13:41]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Program Files\Sony\Image Converter 3\IcVzMon.exe [2007-01-26 13:41]
S3 NPF;NetGroup Packet Filter Driver;C:\Windows\system32\drivers\npf.sys [2007-06-21 15:55]
.
Contents of the ‘Scheduled Tasks’ folder
“2008-02-15 22:06:34 C:\Windows\Tasks\User_Feed_Synchronization-{DFD2146F-409B-412F-9A8D-08E7DA58CA32}.job”
- C:\Windows\system32\msfeedssync.exe
.
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-16 03:04:31
Windows 6.0.6000 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Protector Suite QL\upeksvr.exe
C:\Program Files\Avast\aswUpdSv.exe
C:\Program Files\Avast\ashServ.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Avast\ashMaiSv.exe
C:\Program Files\Avast\ashWebSv.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Windows\system32\conime.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\Program Files\Avast\ashDisp.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\DllHost.exe
C:\?\C:\Windows\system32\wbem\WMIADAP.EXE
.
.
Completion time: 2008-02-16 3:08:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-16 08:07:55
.
2008-02-15 09:10:32 — E O F —