Unfortunatly now I can't connect to the internet either by lan or wireless even in safe mode (with networking) on that computer; diagnostics thinks that there is a problem with the drivers or devices. So use the restore point? Has combofix been known to do that? I tried with several reboots. The first time I got an error stating something to the effect that there was an illegal call to a registry marked for deletion. After a reboot I didn't get that error.
Also Combofix warned me that Mcafee was enabled yet I had uninstalled it & ran that cleaner.
Combofix:
ComboFix 09-09-01.04 - Linda 09/01/2009 16:31.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1917.1055 [GMT -5:00]
Running from: c:\users\Linda\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
SP: AntiVir Desktop *disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
SP: McAfee VirusScan *enabled* (Updated) {C78B3C70-4777-4742-BB91-9D615CC575E6}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-356769637-270181211-1932191970-500
c:\windows\Installer\508e6.msi
c:\windows\Installer\WMEncoder.msi
c:\windows\system32\drivers\ndisrd.sys
c:\windows\system32\drivers\snetcfg.exe
c:\windows\system32\ndisapi.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_Ndisrd
-------\Service_NdisrdMP
((((((((((((((((((((((((( Files Created from 2009-08-01 to 2009-09-01 )))))))))))))))))))))))))))))))
.
2009-09-01 03:50 . 2009-09-01 03:58 117760 ----a-w- c:\users\Linda\AppData\Roaming\SUPERAntiSpyware.co m\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-09-01 03:49 . 2009-09-01 03:49 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2009-09-01 03:49 . 2009-09-01 03:49 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-01 03:49 . 2009-09-01 03:49 -------- d-----w- c:\users\Linda\AppData\Roaming\SUPERAntiSpyware.co m
2009-09-01 00:43 . 2009-09-01 00:43 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-31 23:55 . 2009-08-31 23:55 680 ----a-w- c:\users\Linda\AppData\Local\d3d9caps.dat
2009-08-31 23:31 . 2009-07-28 21:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-31 23:31 . 2009-03-30 15:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-08-31 23:30 . 2009-08-31 23:30 -------- d-----w- c:\programdata\Avira
2009-08-31 23:30 . 2009-08-31 23:30 -------- d-----w- c:\program files\Avira
2009-08-31 23:19 . 2009-08-31 23:21 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-08-31 23:19 . 2009-08-31 23:21 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-31 23:18 . 2009-08-31 23:18 -------- d-----w- c:\users\Linda\AppData\Roaming\Malwarebytes
2009-08-31 23:18 . 2009-08-03 18:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-31 23:18 . 2009-08-31 23:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-31 23:18 . 2009-08-31 23:18 -------- d-----w- c:\programdata\Malwarebytes
2009-08-31 23:18 . 2009-08-03 18:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-31 23:02 . 2009-08-31 23:02 -------- d-----w- c:\program files\Trend Micro
2009-08-31 00:58 . 2009-09-01 00:11 -------- d-----w- c:\program files\Common Files\Uninstall
2009-08-28 22:46 . 2009-06-22 08:44 2048 ----a-w- c:\windows\system32\tzres.dll
2009-08-27 01:46 . 2009-06-05 12:30 1686016 ----a-w- c:\windows\system32\gameux.dll
2009-08-27 01:46 . 2009-06-05 12:28 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-27 01:46 . 2009-06-05 08:44 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-26 17:44 . 2009-06-15 15:29 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-08-26 17:44 . 2009-06-15 15:25 216576 ----a-w- c:\windows\system32\msv1_0.dll
2009-08-26 17:44 . 2009-06-15 15:23 494592 ----a-w- c:\windows\system32\kerberos.dll
2009-08-26 17:44 . 2009-06-15 15:28 272384 ----a-w- c:\windows\system32\schannel.dll
2009-08-26 17:44 . 2009-06-15 15:23 1233920 ----a-w- c:\windows\system32\lsasrv.dll
2009-08-26 17:44 . 2009-06-15 18:12 408136 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-08-26 17:44 . 2009-06-15 15:28 72704 ----a-w- c:\windows\system32\secur32.dll
2009-08-26 17:44 . 2009-06-15 13:10 7680 ----a-w- c:\windows\system32\lsass.exe
2009-08-12 21:17 . 2009-07-17 14:52 71680 ----a-w- c:\windows\system32\atl.dll
2009-08-12 21:17 . 2009-06-10 12:16 156160 ----a-w- c:\windows\system32\wkssvc.dll
2009-08-12 21:17 . 2009-06-04 12:43 1871872 ----a-w- c:\windows\system32\mstscax.dll
2009-08-12 21:17 . 2009-06-04 12:36 116736 ----a-w- c:\windows\system32\aaclient.dll
2009-08-12 21:17 . 2009-06-04 12:47 36352 ----a-w- c:\windows\system32\tsgqec.dll
2009-08-12 21:17 . 2009-06-10 12:04 88576 ----a-w- c:\windows\system32\avifil32.dll
2009-08-12 21:16 . 2009-06-10 12:04 65024 ----a-w- c:\windows\system32\avicap32.dll
2009-08-12 21:16 . 2009-06-10 12:10 31232 ----a-w- c:\windows\system32\msvidc32.dll
2009-08-12 21:16 . 2009-06-10 12:10 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-08-12 21:16 . 2009-06-10 12:09 12800 ----a-w- c:\windows\system32\msrle32.dll
2009-08-12 21:16 . 2009-06-10 12:07 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-08-12 21:16 . 2009-07-14 13:02 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-08-12 21:16 . 2009-07-14 13:00 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-08-12 21:16 . 2009-07-14 13:01 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-08-12 21:16 . 2009-07-14 11:11 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2009-08-10 00:15 . 2008-06-20 01:17 97800 ----a-w- c:\windows\system32\infocardapi.dll
2009-08-10 00:14 . 2008-06-20 01:18 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNativ e_v0300.dll
2009-08-10 00:14 . 2008-06-20 01:17 622080 ----a-w- c:\windows\system32\icardagt.exe
2009-08-10 00:14 . 2008-06-20 01:17 11264 ----a-w- c:\windows\system32\icardres.dll
2009-08-10 00:14 . 2008-06-20 01:18 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2009-08-10 00:14 . 2008-06-20 01:18 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-08-10 00:14 . 2008-06-20 01:18 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2009-08-09 23:54 . 2008-07-27 18:00 96760 ----a-w- c:\windows\system32\dfshim.dll
2009-08-09 23:54 . 2008-07-27 18:00 282112 ----a-w- c:\windows\system32\mscoree.dll
2009-08-09 23:54 . 2008-07-27 18:00 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-08-09 23:52 . 2008-07-27 18:00 158720 ----a-w- c:\windows\system32\mscorier.dll
2009-08-09 23:52 . 2008-07-27 18:00 83968 ----a-w- c:\windows\system32\mscories.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-08-31 22:05 . 2008-05-18 15:26 -------- d-----w- c:\programdata\Google Updater
2009-08-19 00:19 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-08-09 23:49 . 2009-08-08 19:37 -------- d-----w- c:\programdata\Logishrd
2009-08-09 03:11 . 2008-10-16 13:57 14412776 ----a-w- c:\programdata\WildTangent\TOSHIBA Game Console\Downloads\en-us\Installers\SetupGamesClient.exe
2009-08-09 02:04 . 2009-08-08 19:37 -------- d-----w- c:\program files\Logitech
2009-08-08 19:43 . 2009-08-08 19:37 -------- d-----w- c:\program files\Common Files\LogiShrd
2009-08-08 19:42 . 2009-08-08 19:42 127034 ------r- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
2009-08-08 19:42 . 2007-08-22 19:39 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-08 19:42 . 2009-08-08 19:42 -------- d-----w- c:\users\Linda\AppData\Roaming\Leadertech
2009-08-08 19:37 . 2009-08-08 19:37 -------- d-----w- c:\programdata\Logitech
2009-07-25 01:28 . 2008-09-15 18:51 -------- d-----w- c:\programdata\Lx_cats
2009-07-18 12:17 . 2009-08-01 13:49 827392 ----a-w- c:\windows\system32\wininet.dll
2009-07-18 12:10 . 2009-08-01 13:49 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-07-18 12:10 . 2009-08-01 13:49 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-07-18 12:07 . 2009-08-01 13:49 72704 ----a-w- c:\windows\system32\admparse.dll
2009-07-18 10:00 . 2009-08-01 13:49 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-18 08:34 . 2009-08-01 13:49 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-07-07 22:26 . 2009-07-07 22:26 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_0 1005.Wdf
2009-06-17 13:44 . 2009-06-17 13:44 456304 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb1611.tmp.exe
2009-06-15 15:29 . 2009-07-18 11:24 156160 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 15:23 . 2009-07-18 11:24 24064 ----a-w- c:\windows\system32\lpk.dll
2009-06-15 15:22 . 2009-07-18 11:24 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 15:21 . 2009-07-18 11:24 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-06-15 15:20 . 2009-07-18 11:24 34304 ----a-w- c:\windows\system32\atmlib.dll
2009-06-15 13:03 . 2009-07-18 11:24 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-06-14 13:04 . 2009-06-14 13:04 456304 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb92F0.tmp.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2007-05-18 430080]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2008-05-18 68856]
"Logitech Vid"="c:\program files\Logitech\Logitech Vid\vid.exe" [2009-07-16 5458704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2007-08-22 1006264]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-08-15 102400]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-22 1862144]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2007-07-16 311984]
"lxdimon.exe"="c:\program files\Lexmark 3500-4500 Series\lxdimon.exe" [2007-07-16 434864]
"lxdiamon"="c:\program files\Lexmark 3500-4500 Series\lxdiamon.exe" [2007-07-16 25264]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-08-10 4702208]
"NDSTray.exe"="NDSTray.exe" [BU]
c:\users\Linda\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe [2009-8-8 66864]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleD esktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-356769637-270181211-1932191970-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\FirewallRules]
"{0785CEB4-1D06-45CA-A60D-A0FC19B7E410}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{629351EB-E461-4ADC-AB51-DFF1C9221FF9}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{DF6E9C05-499C-4CC0-BB64-8431FF2C8748}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxd itime.exe:Lexmark Connect Time Executable
"{3F988F68-3A54-458B-935E-617A4DD5BACD}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxd itime.exe:Lexmark Connect Time Executable
"{E248C62C-4248-4666-BF2F-1199F93816EA}"= UDP:c:\program files\Lexmark 3500-4500 Series\lxdimon.exe

evice Monitor
"{755F9885-CDF7-4913-A324-E6B36F2DF369}"= TCP:c:\program files\Lexmark 3500-4500 Series\lxdimon.exe

evice Monitor
"{2C6B5707-4290-448C-95BF-A42BB62BB041}"= UDP:c:\users\Linda\AppData\Local\Temp\lxdi\wireles s\ENGLISH\lxdiwpss.exe:
"{3DA01AC0-40C6-4E5A-AA7E-81218B3F48EA}"= TCP:c:\users\Linda\AppData\Local\Temp\lxdi\wireles s\ENGLISH\lxdiwpss.exe:
"{F1A9E2DC-BFA3-4A5B-A714-E1FE584F5BAF}"= UDP:c:\windows\System32\lxdicfg.exe:Printer Communication System
"{88462605-99D4-4BAA-B79A-5472F41564FE}"= TCP:c:\windows\System32\lxdicfg.exe:Printer Communication System
"{DDF9885E-FD0A-4A55-9C83-760912E3E9A8}"= UDP:c:\windows\System32\lxdicoms.exe:Lexmark Communications System
"{12210602-A915-4148-9F6B-BE069915A89E}"= TCP:c:\windows\System32\lxdicoms.exe:Lexmark Communications System
"{8B406501-C33A-4742-97F8-2487A3C6C6CF}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxd ipswx.exe:Printer Status Window
"{09135044-5799-442A-BF9D-90CEF89AC541}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxd ipswx.exe:Printer Status Window
"{37C5DD69-B922-41B0-9E4F-3B6C01E882B4}"= UDP:c:\program files\Lexmark 3500-4500 Series\lxdiamon.exe:Lexmark Device Monitor
"{FBE9E020-ECD6-4789-A245-DFA720E18E85}"= TCP:c:\program files\Lexmark 3500-4500 Series\lxdiamon.exe:Lexmark Device Monitor
"{C6ED13C4-104A-4830-A8D3-F4D297220B98}"= UDP:c:\program files\Lexmark 3500-4500 Series\App4R.exe:Lexmark Imaging Studio
"{B18D1F9E-E376-4A0E-83A0-1A1B4D221A5C}"= TCP:c:\program files\Lexmark 3500-4500 Series\App4R.exe:Lexmark Imaging Studio
"{1FB421C4-D6DB-4D8A-9A61-AB073114D47D}"= UDP:c:\program files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader
"{6D1E958E-50FA-471C-B184-FCF1E9530DBF}"= TCP:c:\program files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader
"{E3A1E886-7E03-4BBB-90E5-72A7A31DA4A1}"= UDP:c:\program files\Lexmark Fax Solutions\FaxCtr.exe:Fax software
"{9CE4488E-48D2-43FD-A974-AF4C3FFF8FDF}"= TCP:c:\program files\Lexmark Fax Solutions\FaxCtr.exe:Fax software
"{9B65ADCF-1AF0-44F0-AAD0-8D9C80DC3526}"= UDP:c:\program files\Lexmark 3500-4500 Series\Wireless\lxdiwpss.exe:
"{3AA91455-602E-4D93-B80F-D5A7D4FCDC0B}"= TCP:c:\program files\Lexmark 3500-4500 Series\Wireless\lxdiwpss.exe:
"{9C840A8D-B698-4CA2-BDCC-012767C4F12D}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxd itime.exe:Lexmark Connect Time Executable
"{B0C7E942-4D71-4F3C-9F9F-C6B5939040A0}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxd itime.exe:Lexmark Connect Time Executable
"{62C98D29-C3D2-4E3F-AE66-95B0BC1ABB96}"= UDP:c:\windows\System32\lxdicoms.exe:Lexmark Communications System
"{00764E52-B84C-4CDB-9DC4-C71C0C484B90}"= TCP:c:\windows\System32\lxdicoms.exe:Lexmark Communications System
"{F7406EBC-FA38-4F6D-A6FF-1CDC7C65CAD3}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxd ipswx.exe:Printer Status Window
"{9A9556D6-E1B8-45DC-9143-34A10AEFC51E}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxd ipswx.exe:Printer Status Window
"{0C443A61-EE53-4F99-9AB6-F67CC83C988D}"= UDP:c:\program files\Lexmark 3500-4500 Series\lxdiamon.exe:Lexmark Device Monitor
"{30043BAA-9E51-43E2-9560-189C916CC467}"= TCP:c:\program files\Lexmark 3500-4500 Series\lxdiamon.exe:Lexmark Device Monitor
"{D04620FA-80B7-4E80-A31D-5B5340041B81}"= UDP:c:\program files\Lexmark 3500-4500 Series\App4R.exe:Lexmark Imaging Studio
"{B40FFEE9-8B59-497A-99AF-EC59E6ECD7E9}"= TCP:c:\program files\Lexmark 3500-4500 Series\App4R.exe:Lexmark Imaging Studio
"{1FDC802E-6A8F-4A38-816A-544349A135EE}"= UDP:c:\program files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader
"{B3E9BE29-2F4D-4E56-900A-37C3C65C423C}"= TCP:c:\program files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader
"{931F3860-04F0-4BDA-BACB-18CA4E381A69}"= UDP:c:\program files\Lexmark Fax Solutions\FaxCtr.exe:Fax software
"{EF5A9B99-8DDF-42E9-B0E0-436BF2912F79}"= TCP:c:\program files\Lexmark Fax Solutions\FaxCtr.exe:Fax software
"{E18F021E-76AE-46E7-820F-1D610F06BAB3}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{FE8BDB5C-015E-49FC-8F0D-B2D1E2A90E2E}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1A58EDC4-B555-4469-A3A9-6627E87043A5}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{8F5A1F75-C55D-4936-B5B2-81DECE519531}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{5A8E3942-4998-419D-B76C-703739A25891}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe:Logitech Desktop Messenger
"{7451A326-D266-4A02-B73E-5069903DFEFF}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe:Logitech Desktop Messenger
"{FD45D389-59B2-4816-8355-03DA9EED5F8E}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe:Logitech Desktop Messenger
"{B5D11434-4ADC-4B47-9A81-9068C24E3C02}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe:Logitech Desktop Messenger
"{D97119C6-CF13-4832-A5CC-2DE0482F82EE}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe:Logitech Desktop Messenger
"{DDFF9374-6746-45B6-94B6-C67A32DF87AF}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe:Logitech Desktop Messenger
"{A4FDFA94-70D0-4C94-9230-3EFF69B88886}"= UDP:c:\program files\Logitech\Logitech Vid\Vid.exe:Logitech Vid
"{DDCEC42E-AE38-4897-92FF-F09E5018BCEC}"= TCP:c:\program files\Logitech\Logitech Vid\Vid.exe:Logitech Vid
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|S vc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\StandardProfile\AuthorizedApplications\List]
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"= c:\toshiba\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\toshiba\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [8/5/2009 4:06 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/5/2009 4:06 PM 74480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [8/31/2009 6:30 PM 108289]
R2 lxdi_device;lxdi_device;c:\windows\system32\lxdico ms.exe -service --> c:\windows\system32\lxdicoms.exe -service [?]
R2 lxdiCATSCustConnectService;lxdiCATSCustConnectServ ice;c:\windows\System32\spool\drivers\w32x86\3\lxd iserv.exe [6/11/2007 9:14 AM 99248]
R3 FwLnk;FwLnk Driver;c:\windows\System32\drivers\FwLnk.sys [8/22/2007 2:53 PM 7168]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\System32\drivers\rtl8187B.sys [11/13/2007 8:13 AM 252416]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/5/2009 4:06 PM 7408]
S3 winbondcir;Winbond IR Transceiver;c:\windows\System32\drivers\winbondcir .sys [3/28/2007 9:51 AM 43008]
.
Contents of the 'Scheduled Tasks' folder
2009-09-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-08-22 12:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.toshibadirect.com/dpdstart
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
.
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2009-09-01 16:45
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
------------------------ Other Running Processes ------------------------
.
c:\windows\Microsoft.NET\Framework\v3.0\WPF\Presen tationFontCache.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\System32\lxdicoms.exe
c:\toshiba\IVP\ISM\pinger.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\System32\TODDSrv.exe
c:\program files\Toshiba\Power Saver\TosCoSrv.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\System32\wbem\WMIADAP.exe
.
************************************************** ************************
.
Completion time: 2009-09-01 16:51 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-01 21:51
Pre-Run: 129,057,734,656 bytes free
Post-Run: 128,912,777,216 bytes free
286 --- E O F --- 2009-09-01 15:19
HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:02:24 PM, on 9/1/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16890)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
C:\Program Files\Logitech\Logitech Vid\Vid.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
Personalized Start Page
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
MSN.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\s wg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3. dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdise rv.exe
O23 - Service: lxdi_device - - C:\Windows\system32\lxdicoms.exe
O23 - Service: pinger - Unknown owner - C:\Toshiba\IVP\ISM\pinger.exe
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 9559 bytes