Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » gbtray.exe taking up CPU

[Fixed] Hijackthis! Logs - gbtray.exe taking up CPU posted in the Security & Safety forums; I have recently seen my laptop grind to a halt and it looks like it is down to a process called gbtray.exe that is the culprit. When I stop the ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 02-23-2008
Bronze Member
 
Join Date: Feb 2008
Posts: 23
PC Experience: Some Experience
jackd70 - See this Members User comments on their Profile page
Default gbtray.exe taking up CPU

I have recently seen my laptop grind to a halt and it looks like it is down to a process called gbtray.exe that is the culprit.

When I stop the process the computer is fine however I think it is part of my Norton GoBack software. By stopping it am I still fully protected with the Norton GoBack software?

I did try leaving it running to see if it would eventually stop but after about an hour it was still using up my cpu therefore stopping me from doing anything else.

Any ideas/help much appreciated.

Here's my log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:06:54, on 23/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Comodo\common\CAVASpy\cavasm.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Comodo\Comodo AntiVirus\cavse.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Comodo\Comodo AntiVirus\cavse.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\1135854072\ee\AOLSoftware.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Comodo\Comodo AntiVirus\CMain.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Comodo\Comodo AntiVirus\Cavaud.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\program files\common files\aol\1135854072\ee\services\antiSpywareApp\ve r2_0_12\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Google
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: del.icio.us - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [TOSHIBA Accessibility] C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1135854072\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [cnfgCav] "C:\Program Files\Comodo\Comodo AntiVirus\CMain.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [5c41522d] rundll32.exe "C:\WINDOWS\system32\xthqvlns.dll",b
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton GoBack\GBTray.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://fishingchamp.gamescampus.com/...amesCampus.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10...I.cab55579.cab
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {2DA3C4AB-E6B6-47A6-B0F3-1BD81524B51B} (ActiveWorldsDownload Control) - http://www.activeworlds.com/products...dsDownload.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10...y.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10...t.cab55579.cab
O16 - DPF: {759FD3DE-F0EF-4A76-909C-88CF840D4173} (DmDragDrop Class) - http://uri.open.ac.uk/content/wdk/na...kPluginCab.CAB
O16 - DPF: {809A6301-7B40-4436-A02C-87B8D3D7D9E3} (ZPA_DMNO Object) - http://zone.msn.com/bingame/zpagames...o.cab42341.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames...l.cab55579.cab
O16 - DPF: {A9FD89D6-C839-11D3-B0FE-0050044B8FE9} (OBInstallRunner Control) - http://www.opinionbar.com/download/r...allCabinet.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramewor...o.cab56649.cab
O16 - DPF: {BFA1F11D-3121-AFE1-4112-983219421AEF} (GameDesire 1Player Word Games) - http://67.15.101.3/g_bin/eng/wordssingle_2_0_0_43.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://webgames.d.tmsrv.com/c=a291d0...amesplayer.cab
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) - http://zone.msn.com/bingame/zpagames...l.cab42858.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/.../installer.exe
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10...y.cab55579.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/bej...loader_v10.cab
O16 - DPF: {E03EEB49-B0CB-46A3-A84B-BA758243A7B0} (Orbital Launcher) - http://www.shockwave.com/content/thw...cher-2.0.3.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: BOCore - Unknown owner - C:\Program Files\Comodo\CBOClean\BOCORE.exe (file missing)
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Comodo Anti-Virus and Anti-Spyware Service - Comodo Inc. - C:\Program Files\Comodo\common\CAVASpy\cavasm.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 14135 bytes



Last edited by jackd70; 02-23-2008 at 02:39 PM.
  #2  
Old 02-23-2008
Jelly Bean's Avatar
Moderation Team Leader
My PC
 
Join Date: Feb 2008
Location: Swansea
Posts: 6,064
PC Experience: I Try My Best.
Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page Jelly Bean - See this Members User comments on their Profile page
Send a message via MSN to Jelly Bean Send a message via Yahoo to Jelly Bean Send a message via Skype™ to Jelly Bean
Default Re: gbtray.exe taking up CPU

Possible
Windows errors related to gbtray.exe ?



gbtray.exe is a process associated with the Roxio GoBack program. This process, installed at the startup of Windows usually creates a shortcut on the system tray for convenient access to this program. This program is a non-essential system process, and is installed for ease of use.

Moving you to HJTL.


__________________
It is all in the hardware..........................................
Sources:
Microsoft Home Page /Seagate Home Page /Petri Home Page

PCHF Rules / Home Page / Prework /Windows Vista Home Page / XBOX360 / Test your Internet Speed
  #3  
Old 02-28-2008
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 545
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: gbtray.exe taking up CPU

I am not certain if you are still protected with GoBack by not allowing gbtray to run (I will have to research that more)

BUT I do see other infections on your system.

We will run ComboFix.

You need to disable your Antivirus and Spybot Teatimer before running ComboFix, as they will prevent it from running.


You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert. It is intended by its creator to be used under the guidance and supervision of an expert, not for private use. Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again.

Please visit this webpage for instructions for downloading and running ComboFix:
A guide and tutorial on using ComboFix

Be sure to install the Windows XP Recovery Console in case you have not installed it yet. <== IMPORTANT

We need Recovery Console because malware damages a lot and causes an instable system - and because of that, it may happen that your computer won't be able to boot anymore. With the Recovery Console installed, there are extra options present to repair whatever malware damaged.
Also, even though you're not infected, the presence of the Recovery Console is a useful feature in case a computer won't boot anymore because of several other reasons. Read here what you can do with the Recovery Console.

Extra note: After you have installed the Recovery Console - if you reboot your computer, right after reboot, you'll see the option for the Recovery Console now as well.
Don't select to run the Recovery Console as we don't need it.
By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows.


Post the ComboFix log.


__________________
Steve
  #4  
Old 03-08-2008
Bronze Member
 
Join Date: Feb 2008
Posts: 23
PC Experience: Some Experience
jackd70 - See this Members User comments on their Profile page
Default Re: gbtray.exe taking up CPU

Here is my Combo Foxlog

ComboFix 08-03-07.4 - David Turpie 2008-03-08 10:31:13.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.150 [GMT 0:00]Running from: C:\Documents and Settings\David Turpie\My Documents\Downloads\To check\ComboFix2.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\David Turpie\iexplorer.exe
C:\WINDOWS\Fonts\'
C:\WINDOWS\system32\abjkwprc.dll
C:\WINDOWS\system32\bcbeg.ini
C:\WINDOWS\system32\bcbeg.ini2
C:\WINDOWS\system32\dcbotxdv.dll
C:\WINDOWS\system32\dpdjxuwx.dll
C:\WINDOWS\system32\eadebjap.dll
C:\WINDOWS\system32\gebcb.dll
C:\WINDOWS\system32\gofxgpkd.dll
C:\WINDOWS\system32\jjjlm.ini
C:\WINDOWS\system32\jjjlm.ini2
C:\WINDOWS\system32\phwgbysa.dll
C:\WINDOWS\system32\rightonadz-uninst.exe
C:\WINDOWS\system32\sjhrawvs.dll
C:\WINDOWS\system32\snlvqhtx.ini
C:\WINDOWS\system32\toryogyn.dll
C:\WINDOWS\system32\vfypgxcw.dll
C:\WINDOWS\system32\xthqvlns.dll
C:\x.dat
C:\z.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\LEGACY_SFSYNC02
-------\sfsync02


((((((((((((((((((((((((( Files Created from 2008-02-08 to 2008-03-08 )))))))))))))))))))))))))))))))
.

2008-03-08 10:21 . 2008-03-08 10:22 <DIR> d-------- C:\ComboFix
2008-03-04 20:31 . 2008-03-04 20:32 <DIR> d-------- C:\Program Files\Elf Bowling The Last Insult
2008-03-02 16:37 . 2008-03-02 16:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MumboJumbo
2008-03-02 15:48 . 1995-02-28 11:14 164,928 --a------ C:\WINDOWS\system\BWCC.DLL
2008-03-02 15:48 . 1995-02-28 11:16 97,072 --a------ C:\WINDOWS\system\BWCC0007.DLL
2008-03-02 15:48 . 1995-02-28 11:16 96,928 --a------ C:\WINDOWS\system\BWCC000C.DLL
2008-03-02 15:48 . 1995-02-28 11:17 96,912 --a------ C:\WINDOWS\system\BWCC0009.DLL
2008-03-02 15:47 . 1998-02-06 22:23 248,064 --a------ C:\WINDOWS\UNINST16.EXE
2008-03-02 15:47 . 1995-07-13 19:43 26,768 --a------ C:\WINDOWS\system\CTL3D.DLL
2008-03-02 15:29 . 2008-03-02 15:35 <DIR> d-------- C:\Program Files\STARWARS_TheBattleOfEndor_v21
2008-03-01 17:31 . 2008-03-01 17:31 <DIR> d-------- C:\Program Files\mackoy
2008-03-01 16:45 . 2008-03-01 16:46 <DIR> d-------- C:\Program Files\BVE
2008-03-01 16:12 . 2008-03-01 16:44 <DIR> d-------- C:\BMW M3 Challenge
2008-03-01 16:00 . 2008-03-01 16:00 <DIR> d-------- C:\Program Files\Rorschach Software
2008-03-01 15:55 . 2008-03-01 15:55 <DIR> d-------- C:\TCPoker
2008-03-01 14:32 . 2008-03-01 14:32 <DIR> d-------- C:\Documents and Settings\David Turpie\freecol
2008-03-01 14:31 . 2008-03-01 14:39 <DIR> d-------- C:\Program Files\freecol
2008-03-01 12:46 . 2004-08-16 20:00 116,736 --a------ C:\WINDOWS\system32\CNMLM6s.DLL
2008-03-01 12:46 . 2004-08-16 20:00 7,680 --a------ C:\WINDOWS\system32\CNMVS6s.DLL
2008-03-01 12:45 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-03-01 12:45 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-03-01 12:42 . 1995-08-01 04:44 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
2008-03-01 12:40 . 2008-03-01 12:40 <DIR> d--h----- C:\CanonMP
2008-03-01 12:40 . 2004-10-26 05:03 557,056 --a------ C:\WINDOWS\system32\CNCC130.DLL
2008-03-01 12:40 . 2002-05-24 03:04 389,180 --a------ C:\WINDOWS\system32\UCS32P.DLL
2008-03-01 12:40 . 2004-09-07 14:53 94,208 --a------ C:\WINDOWS\system32\CNCL130.DLL
2008-03-01 12:40 . 2004-10-26 05:03 90,112 --a------ C:\WINDOWS\system32\CNCI130.DLL
2008-03-01 12:40 . 2004-10-26 05:15 49,152 --a------ C:\WINDOWS\system32\cncisco.dll
2008-03-01 12:39 . 2008-03-01 12:51 <DIR> d-------- C:\Program Files\Canon
2008-03-01 12:36 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-03-01 12:36 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-03-01 12:36 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-03-01 12:36 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-02-23 13:05 . 2008-02-23 13:05 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-17 20:59 . 2008-02-17 20:59 1,794 ---hs---- C:\WINDOWS\system32\qxdjcdpb.tmp
2008-02-17 12:26 . 2008-02-17 20:59 1,734 ---hs---- C:\WINDOWS\system32\qxdjcdpb.ini
2008-02-15 19:45 . 2008-02-17 12:24 1,554 ---hs---- C:\WINDOWS\system32\lrsvcpno.ini
2008-02-13 21:16 . 2008-02-15 19:43 1,374 ---hs---- C:\WINDOWS\system32\hdhsgfxs.ini
2008-02-13 20:19 . 2008-02-13 20:19 1,254 ---hs---- C:\WINDOWS\system32\hnajnftk.ini
2008-02-12 20:14 . 2008-02-13 20:14 1,194 ---hs---- C:\WINDOWS\system32\yqlapats.ini
2008-02-10 19:15 . 2008-02-10 19:15 0 --a------ C:\WINDOWS\TPTray.INI
2008-02-10 12:26 . 2008-02-10 12:27 145 --a------ C:\WINDOWS\Eudcedit.ini
2008-02-10 11:33 . 2008-02-12 20:11 954 ---hs---- C:\WINDOWS\system32\ibanbsok.ini
2008-02-09 12:18 . 2008-02-23 12:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-02-09 11:46 . 2008-02-09 11:46 294 ---hs---- C:\WINDOWS\system32\oulbvmyq.tmp
2008-02-09 11:46 . 2008-02-09 11:46 233 ---hs---- C:\WINDOWS\system32\oulbvmyq.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-03-06 20:54 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-01 15:55 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-03-01 15:55 286,720 ------w C:\WINDOWS\Setup1.exe
2008-03-01 12:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-23 13:22 --------- d-----w C:\Program Files\NovaTech Network
2008-02-23 12:47 --------- d-----w C:\Program Files\AOL 9.0
2008-02-12 21:07 --------- d-----w C:\Program Files\PartyGaming
2008-02-10 09:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-02-06 21:00 --------- d-----w C:\Documents and Settings\Wendy Proctor\Application Data\Comodo
2008-02-01 15:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-01-27 10:12 --------- d-----w C:\Program Files\Comodo
2008-01-26 16:44 102,400 ----a-w C:\WINDOWS\system32\drivers\cavasm.sys
2008-01-26 16:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Comodo
2008-01-26 15:59 --------- d-----w C:\Documents and Settings\David Turpie\Application Data\Comodo
2008-01-26 15:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-01-26 14:49 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-20 17:06 --------- d-----w C:\Program Files\Symantec
2008-01-20 17:06 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-20 16:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-20 12:50 --------- d-----w C:\Program Files\Crawler
2008-01-20 12:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-19 15:41 --------- d-----w C:\Program Files\XoftSpySE
2008-01-19 15:28 --------- d-----w C:\Program Files\Unlocker
2008-01-19 14:17 --------- d-----w C:\Program Files\jZip
2008-01-19 12:02 --------- d-----w C:\Program Files\Windows Installer Clean Up
2008-01-19 12:02 --------- d-----w C:\Program Files\MSECACHE
2008-01-19 08:50 --------- d-----w C:\Documents and Settings\David Turpie\Application Data\LimeWire
2008-01-17 21:19 --------- d-----w C:\Program Files\Kontiki
2008-01-15 21:21 --------- d-----w C:\Program Files\Common Files\AOL
2008-01-15 20:14 --------- d-----w C:\Program Files\Viewpoint
2007-11-25 07:59 40,960 ----a-w C:\Documents and Settings\David Turpie\f.exe
2007-11-25 07:59 0 -c--a-w C:\Documents and Settings\David Turpie\z.dat
2007-11-25 07:59 0 -c--a-w C:\Documents and Settings\David Turpie\x.dat
2007-10-28 14:47 28,677 ----a-w C:\Documents and Settings\David Turpie\update.exe
2006-10-20 20:34 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2006-09-10 11:22 2,594 ----a-w C:\Documents and Settings\David Turpie\Application Data\wklnhst.dat
2005-12-30 13:14 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\Pr ocs]
@={51D8EAB2-A055-487F-BBE0-DFB79DD0E76D}

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 10:26 65536]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2007-05-27 09:01 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2004-03-24 05:40 196608]
"Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [2005-04-05 15:25 73728]
"AGRSMMSG"="AGRSMMSG.exe" [2004-12-22 08:10 88358 C:\WINDOWS\agrsmmsg.exe]
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2005-05-10 13:13 675840]
"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2004-11-29 20:06 53248]
"TOSHIBA Accessibility"="C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe" [2004-04-30 22:02 24576]
"HWSetup"="C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-04-30 22:02 28672]
"SVPWUTIL"="C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2005-02-25 14:59 65536]
"Zooming"="ZoomingHook.exe" [2004-07-14 15:07 24576 C:\WINDOWS\system32\ZoomingHook.exe]
"TCtryIOHook"="TCtrlIOHook.exe" [2005-03-30 17:01 28672 C:\WINDOWS\system32\TCtrlIOHook.exe]
"TPSMain"="TPSMain.exe" [2005-01-21 07:53 266240 C:\WINDOWS\system32\TPSMain.exe]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-11 09:12 118784]
"NDSTray.exe"="NDSTray.exe" []
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-11-17 09:56 1077327]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-01-14 00:05 122939]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-08-14 13:39 98304]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2006-08-14 13:41 114688]
"Persistence"="C:\WINDOWS\system32\igfxpers.ex e" [2006-08-14 13:38 94208]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-01 23:38 802816]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-01 23:32 696320]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-03-17 08:10 185896]
"HostManager"="C:\Program Files\Common Files\AOL\1135854072\ee\AOLSoftware.exe" [2006-11-17 13:21 50736]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2008-01-26 15:56 1115728]
"cnfgCav"="C:\Program Files\Comodo\Comodo AntiVirus\CMain.exe" [2008-01-26 16:44 110592]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 12:00 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Norton GoBack.lnk - C:\Program Files\Norton GoBack\GBTray.exe [2004-08-13 10:26:46 803976]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-10-01 16:40:42 155648]

[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"= shdocvw.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccawxu]
fccawxu.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\monln]
monln.dll 2008-01-26 16:44 216576 C:\WINDOWS\system32\monln.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnolll]
opnolll.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyxxxv]
xxyxxxv.dll

[HKLM\~\startupfolder\C:^Documents and Settings^David Turpie^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
backup=C:\WINDOWS\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-10-10 19:51 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2007-12-07 15:30 71008 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 12:00 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Host Process]
C:\WINDOWS\Fonts\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-11-17 13:21 50736 C:\Program Files\Common Files\AOL\1135854072\ee\AOLSoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-12-11 12:10 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\postSetupCheck]
C:\WINDOWS\system32\gzmrt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 10:56 286720 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 03:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-05-27 09:01 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-03-17 08:10 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOL ACS"=2 (0x2)
"GBPoll"=2 (0x2)
"aawservice"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AOL 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Common Files\\AOL\\1135854072\\ee\\aolsoftware.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\\Program Files\\Kontiki\\KHost.exe"=

S3 SaiH5F0D;SaiH5F0D;C:\WINDOWS\system32\DRIVERS\SaiH 5F0D.sys [2005-11-14 06:19]
S3 SaiU5F0D;SaiU5F0D;C:\WINDOWS\system32\DRIVERS\SaiU 5F0D.sys [2005-11-14 06:19]
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2005-03-24 15:36]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-19 13:56:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-07 20:56:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-01 15:01:18 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2005-10-01 16:16:27 C:\WINDOWS\Tasks\Registration reminder 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2008-01-21 19:55:34 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
- C:\Program Files\RegistrySmart\RegistrySmart.ex
- C:\Program Files\RegistrySmart
"2008-03-08 10:48:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
"2007-11-25 08:39:28 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-11-25 08:39:27 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
************************************************** ************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-08 10:44:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Comodo\common\CAVASpy\cavasm.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Comodo\Comodo AntiVirus\cavse.exe
C:\Program Files\Comodo\Comodo AntiVirus\cavse.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Comodo\Comodo AntiVirus\Cavaud.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\common files\aol\1135854072\ee\services\antiSpywareApp\ve r2_0_12\AOLSP Scheduler.exe
C:\Program Files\iPod\bin\iPodService.exe
.
************************************************** ************************
.
Completion time: 2008-03-08 10:49:04 - machine was rebooted [David Turpie]
ComboFix-quarantined-files.txt 2008-03-08 10:48:58
.
2008-02-17 12:30:07 --- E O F ---


  #5  
Old 03-09-2008
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 545
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: gbtray.exe taking up CPU

Click Start, then Run and type Notepad and click OK.
Open notepad - don't use any other text editor than notepad or the script will fail.
Copy/paste the text in the code box below into notepad:

Code:
Files::

C:\WINDOWS\system32\qxdjcdpb.tmp
C:\WINDOWS\system32\qxdjcdpb.ini
C:\WINDOWS\system32\lrsvcpno.ini
C:\WINDOWS\system32\hdhsgfxs.ini
C:\WINDOWS\system32\hnajnftk.ini
C:\WINDOWS\system32\yqlapats.ini
C:\WINDOWS\system32\oulbvmyq.tmp
C:\WINDOWS\system32\oulbvmyq.ini
Name the Notepad file CFScript.txt and Save it to your desktop.

IMPORTANT: The above script was written specifically for this infection on this person's computer. It is NOT to be used on another computer, as it may cause damage that could result in a format!

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.





This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.


__________________
Steve
  #6  
Old 03-09-2008
Bronze Member
 
Join Date: Feb 2008
Posts: 23
PC Experience: Some Experience
jackd70 - See this Members User comments on their Profile page
Default Re: gbtray.exe taking up CPU

Hi

I ran combofix again with the text files as requested

Please find below my latest combofix report and hijack log

I have to say even before running the latest combofix with the text file my laptop is running a lot better. What was the latest run for out of interest?

I am guessing you are still seeing some things are not quite right.

Thanks

David

COMBOFIX LOG

ComboFix 08-03-07.4 - David Turpie 2008-03-09 14:33:08.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.170 [GMT 0:00]
Running from: C:\Documents and Settings\David Turpie\My Documents\Downloads\To check\ComboFix2.exe
Command switches used :: C:\Documents and Settings\David Turpie\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-02-09 to 2008-03-09 )))))))))))))))))))))))))))))))
.

2008-03-08 10:21 . 2008-03-08 10:22 <DIR> d-------- C:\ComboFix
2008-03-04 20:31 . 2008-03-04 20:32 <DIR> d-------- C:\Program Files\Elf Bowling The Last Insult
2008-03-02 16:37 . 2008-03-02 16:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MumboJumbo
2008-03-02 15:48 . 1995-02-28 11:14 164,928 --a------ C:\WINDOWS\system\BWCC.DLL
2008-03-02 15:48 . 1995-02-28 11:16 97,072 --a------ C:\WINDOWS\system\BWCC0007.DLL
2008-03-02 15:48 . 1995-02-28 11:16 96,928 --a------ C:\WINDOWS\system\BWCC000C.DLL
2008-03-02 15:48 . 1995-02-28 11:17 96,912 --a------ C:\WINDOWS\system\BWCC0009.DLL
2008-03-02 15:47 . 1998-02-06 22:23 248,064 --a------ C:\WINDOWS\UNINST16.EXE
2008-03-02 15:47 . 1995-07-13 19:43 26,768 --a------ C:\WINDOWS\system\CTL3D.DLL
2008-03-02 15:29 . 2008-03-02 15:35 <DIR> d-------- C:\Program Files\STARWARS_TheBattleOfEndor_v21
2008-03-01 17:31 . 2008-03-01 17:31 <DIR> d-------- C:\Program Files\mackoy
2008-03-01 16:45 . 2008-03-01 16:46 <DIR> d-------- C:\Program Files\BVE
2008-03-01 16:12 . 2008-03-01 16:44 <DIR> d-------- C:\BMW M3 Challenge
2008-03-01 16:00 . 2008-03-01 16:00 <DIR> d-------- C:\Program Files\Rorschach Software
2008-03-01 15:55 . 2008-03-01 15:55 <DIR> d-------- C:\TCPoker
2008-03-01 14:32 . 2008-03-01 14:32 <DIR> d-------- C:\Documents and Settings\David Turpie\freecol
2008-03-01 14:31 . 2008-03-01 14:39 <DIR> d-------- C:\Program Files\freecol
2008-03-01 12:46 . 2004-08-16 20:00 116,736 --a------ C:\WINDOWS\system32\CNMLM6s.DLL
2008-03-01 12:46 . 2004-08-16 20:00 7,680 --a------ C:\WINDOWS\system32\CNMVS6s.DLL
2008-03-01 12:45 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-03-01 12:45 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-03-01 12:42 . 1995-08-01 04:44 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
2008-03-01 12:40 . 2008-03-01 12:40 <DIR> d--h----- C:\CanonMP
2008-03-01 12:40 . 2004-10-26 05:03 557,056 --a------ C:\WINDOWS\system32\CNCC130.DLL
2008-03-01 12:40 . 2002-05-24 03:04 389,180 --a------ C:\WINDOWS\system32\UCS32P.DLL
2008-03-01 12:40 . 2004-09-07 14:53 94,208 --a------ C:\WINDOWS\system32\CNCL130.DLL
2008-03-01 12:40 . 2004-10-26 05:03 90,112 --a------ C:\WINDOWS\system32\CNCI130.DLL
2008-03-01 12:40 . 2004-10-26 05:15 49,152 --a------ C:\WINDOWS\system32\cncisco.dll
2008-03-01 12:39 . 2008-03-01 12:51 <DIR> d-------- C:\Program Files\Canon
2008-03-01 12:36 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-03-01 12:36 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-03-01 12:36 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-03-01 12:36 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-02-23 13:05 . 2008-02-23 13:05 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-17 20:59 . 2008-02-17 20:59 1,794 ---hs---- C:\WINDOWS\system32\qxdjcdpb.tmp
2008-02-17 12:26 . 2008-02-17 20:59 1,734 ---hs---- C:\WINDOWS\system32\qxdjcdpb.ini
2008-02-15 19:45 . 2008-02-17 12:24 1,554 ---hs---- C:\WINDOWS\system32\lrsvcpno.ini
2008-02-13 21:16 . 2008-02-15 19:43 1,374 ---hs---- C:\WINDOWS\system32\hdhsgfxs.ini
2008-02-13 20:19 . 2008-02-13 20:19 1,254 ---hs---- C:\WINDOWS\system32\hnajnftk.ini
2008-02-12 20:14 . 2008-02-13 20:14 1,194 ---hs---- C:\WINDOWS\system32\yqlapats.ini
2008-02-10 19:15 . 2008-02-10 19:15 0 --a------ C:\WINDOWS\TPTray.INI
2008-02-10 12:26 . 2008-02-10 12:27 145 --a------ C:\WINDOWS\Eudcedit.ini
2008-02-10 11:33 . 2008-02-12 20:11 954 ---hs---- C:\WINDOWS\system32\ibanbsok.ini
2008-02-09 12:18 . 2008-02-23 12:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-02-09 11:46 . 2008-02-09 11:46 294 ---hs---- C:\WINDOWS\system32\oulbvmyq.tmp
2008-02-09 11:46 . 2008-02-09 11:46 233 ---hs---- C:\WINDOWS\system32\oulbvmyq.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-03-06 20:54 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-01 15:55 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-03-01 15:55 286,720 ------w C:\WINDOWS\Setup1.exe
2008-03-01 12:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-23 13:22 --------- d-----w C:\Program Files\NovaTech Network
2008-02-23 12:47 --------- d-----w C:\Program Files\AOL 9.0
2008-02-12 21:07 --------- d-----w C:\Program Files\PartyGaming
2008-02-10 09:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-02-06 21:00 --------- d-----w C:\Documents and Settings\Wendy Proctor\Application Data\Comodo
2008-02-06 18:51 92,224 ----a-w C:\WINDOWS\system32\tkvssnjw.dll
2008-02-04 22:00 93,248 ----a-w C:\WINDOWS\system32\afyovcnn.dll
2008-02-01 15:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-01-27 10:12 --------- d-----w C:\Program Files\Comodo
2008-01-26 16:44 73,728 ----a-w C:\WINDOWS\system32\CavEmLSP.dll
2008-01-26 16:44 499,712 ----a-w C:\WINDOWS\system32\MSVCP71.DLL
2008-01-26 16:44 434,252 ----a-w C:\WINDOWS\system32\MSVCRTD.DLL
2008-01-26 16:44 348,160 ----a-w C:\WINDOWS\system32\MSVCR71.DLL
2008-01-26 16:44 216,576 ----a-w C:\WINDOWS\system32\monln.dll
2008-01-26 16:44 102,400 ----a-w C:\WINDOWS\system32\drivers\cavasm.sys
2008-01-26 16:44 1,060,864 ----a-w C:\WINDOWS\system32\mfc71.dll
2008-01-26 16:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Comodo
2008-01-26 15:59 --------- d-----w C:\Documents and Settings\David Turpie\Application Data\Comodo
2008-01-26 15:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-01-26 14:49 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-20 17:06 --------- d-----w C:\Program Files\Symantec
2008-01-20 17:06 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-20 16:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-20 12:50 --------- d-----w C:\Program Files\Crawler
2008-01-20 12:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-20 12:17 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-01-19 15:41 --------- d-----w C:\Program Files\XoftSpySE
2008-01-19 15:28 --------- d-----w C:\Program Files\Unlocker
2008-01-19 14:17 --------- d-----w C:\Program Files\jZip
2008-01-19 12:02 --------- d-----w C:\Program Files\Windows Installer Clean Up
2008-01-19 12:02 --------- d-----w C:\Program Files\MSECACHE
2008-01-19 08:50 --------- d-----w C:\Documents and Settings\David Turpie\Application Data\LimeWire
2008-01-17 21:19 --------- d-----w C:\Program Files\Kontiki
2008-01-15 21:21 --------- d-----w C:\Program Files\Common Files\AOL
2008-01-15 20:14 --------- d-----w C:\Program Files\Viewpoint
2008-01-06 10:21 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2007-11-25 07:59 40,960 ----a-w C:\Documents and Settings\David Turpie\f.exe
2007-11-25 07:59 0 -c--a-w C:\Documents and Settings\David Turpie\z.dat
2007-11-25 07:59 0 -c--a-w C:\Documents and Settings\David Turpie\x.dat
2007-10-28 14:47 28,677 ----a-w C:\Documents and Settings\David Turpie\update.exe
2006-10-20 20:34 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2006-09-10 11:22 2,594 ----a-w C:\Documents and Settings\David Turpie\Application Data\wklnhst.dat
2005-12-30 13:14 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\Pr ocs]
@={51D8EAB2-A055-487F-BBE0-DFB79DD0E76D}

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 10:26 65536]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2007-05-27 09:01 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2004-03-24 05:40 196608]
"Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [2005-04-05 15:25 73728]
"AGRSMMSG"="AGRSMMSG.exe" [2004-12-22 08:10 88358 C:\WINDOWS\agrsmmsg.exe]
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2005-05-10 13:13 675840]
"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2004-11-29 20:06 53248]
"TOSHIBA Accessibility"="C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe" [2004-04-30 22:02 24576]
"HWSetup"="C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-04-30 22:02 28672]
"SVPWUTIL"="C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2005-02-25 14:59 65536]
"Zooming"="ZoomingHook.exe" [2004-07-14 15:07 24576 C:\WINDOWS\system32\ZoomingHook.exe]
"TCtryIOHook"="TCtrlIOHook.exe" [2005-03-30 17:01 28672 C:\WINDOWS\system32\TCtrlIOHook.exe]
"TPSMain"="TPSMain.exe" [2005-01-21 07:53 266240 C:\WINDOWS\system32\TPSMain.exe]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-11 09:12 118784]
"NDSTray.exe"="NDSTray.exe" []
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-11-17 09:56 1077327]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-01-14 00:05 122939]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-08-14 13:39 98304]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2006-08-14 13:41 114688]
"Persistence"="C:\WINDOWS\system32\igfxpers.ex e" [2006-08-14 13:38 94208]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-01 23:38 802816]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-01 23:32 696320]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-03-17 08:10 185896]
"HostManager"="C:\Program Files\Common Files\AOL\1135854072\ee\AOLSoftware.exe" [2006-11-17 13:21 50736]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2008-01-26 15:56 1115728]
"cnfgCav"="C:\Program Files\Comodo\Comodo AntiVirus\CMain.exe" [2008-01-26 16:44 110592]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 12:00 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Norton GoBack.lnk - C:\Program Files\Norton GoBack\GBTray.exe [2004-08-13 10:26:46 803976]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-10-01 16:40:42 155648]

[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"= shdocvw.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccawxu]
fccawxu.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\monln]
monln.dll 2008-01-26 16:44 216576 C:\WINDOWS\system32\monln.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnolll]
opnolll.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyxxxv]
xxyxxxv.dll

[HKLM\~\startupfolder\C:^Documents and Settings^David Turpie^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
backup=C:\WINDOWS\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-10-10 19:51 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2007-12-07 15:30 71008 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 12:00 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Host Process]
C:\WINDOWS\Fonts\svchost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-11-17 13:21 50736 C:\Program Files\Common Files\AOL\1135854072\ee\AOLSoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-12-11 12:10 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\postSetupCheck]
C:\WINDOWS\system32\gzmrt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 10:56 286720 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 03:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-05-27 09:01 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-03-17 08:10 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOL ACS"=2 (0x2)
"GBPoll"=2 (0x2)
"aawservice"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AOL 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Common Files\\AOL\\1135854072\\ee\\aolsoftware.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\\Program Files\\Kontiki\\KHost.exe"=

S3 SaiH5F0D;SaiH5F0D;C:\WINDOWS\system32\DRIVERS\SaiH 5F0D.sys [2005-11-14 06:19]
S3 SaiU5F0D;SaiU5F0D;C:\WINDOWS\system32\DRIVERS\SaiU 5F0D.sys [2005-11-14 06:19]
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2005-03-24 15:36]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-19 13:56:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-09 13:57:33 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-01 15:01:18 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2005-10-01 16:16:27 C:\WINDOWS\Tasks\Registration reminder 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2008-01-21 19:55:34 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
- C:\Program Files\RegistrySmart\RegistrySmart.ex
- C:\Program Files\RegistrySmart
"2008-03-09 14:33:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
"2007-11-25 08:39:28 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-11-25 08:39:27 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
************************************************** ************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-09 14:36:23
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

************************************************** ************************
.
Completion time: 2008-03-09 14:37:16
ComboFix-quarantined-files.txt 2008-03-09 14:37:12
ComboFix2.txt 2008-03-08 10:49:05
.
2008-02-17 12:30:07 --- E O F ---


HIJACKTHIS LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:38:30, on 09/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Comodo\common\CAVASpy\cavasm.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\1135854072\ee\AOLSoftware.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Comodo\Comodo AntiVirus\CMain.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Comodo\Comodo AntiVirus\Cavaud.exe
C:\Program Files\Norton GoBack\GBTray.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\common files\aol\1135854072\ee\services\antiSpywareApp\ve r2_0_12\AOLSP Scheduler.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live Toolbar\msn_sl.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Google
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: del.icio.us Toolbar Helper - {7AA07AE6-01EF-44EC-93CA-9D7CD41CCDB6} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\sw g.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 -