ComboFix 09-03-02.01 - Michael Setter 2009-03-03 10:52:11.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3061.2419 [GMT 11:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe AV: Norton 360 *On-access scanning enabled* (Updated) FW: Norton 360 *enabled* * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2009-02-02 to 2009-03-02 ))))))))))))))))))))))))))))))) . 2009-03-02 10:04 . 2009-03-02 10:04 250 --a------ c:\windows\gmer.ini 2009-02-28 14:06 . 2009-02-28 14:41 d-------- c:\program files\Syncrosoft 2009-02-28 14:06 . 2005-10-17 09:35 704,512 --a------ c:\windows\system32\SYNSOACC.dll 2009-02-28 14:06 . 2004-05-10 15:58 147,456 --a------ c:\windows\system32\SynsoLChk.dll 2009-02-28 14:06 . 2003-07-31 20:28 147,425 --a------ c:\windows\system32\SYNSOACC-Aide.chm 2009-02-28 14:06 . 2003-05-26 15:29 120,468 --a------ c:\windows\system32\SYNSOACC-Hilfe.chm 2009-02-28 14:06 . 2003-05-26 15:29 114,279 --a------ c:\windows\system32\SYNSOACC-Help.chm 2009-02-28 14:06 . 2002-11-25 08:36 45,056 --a------ c:\windows\system32\Synsopos.exe 2009-02-19 12:03 . 2009-02-19 12:03 579,464 --a------ c:\windows\system32\SymNeti.dll 2009-02-19 12:03 . 2009-02-19 12:03 207,240 --a------ c:\windows\system32\SymRedir.dll 2009-02-19 11:31 . 2009-02-19 11:31 184,496 --a------ c:\windows\system32\drivers\symtdi.sys 2009-02-19 11:31 . 2009-02-19 11:31 96,560 --a------ c:\windows\system32\drivers\symfw.sys 2009-02-19 11:31 . 2009-02-19 11:31 41,008 --a------ c:\windows\system32\drivers\symndisv.sys 2009-02-19 11:31 . 2009-02-19 11:31 38,576 --a------ c:\windows\system32\drivers\symids.sys 2009-02-19 11:31 . 2009-02-19 11:31 37,424 --a------ c:\windows\system32\drivers\symndis.sys 2009-02-19 11:31 . 2009-02-19 11:31 22,320 --a------ c:\windows\system32\drivers\symredrv.sys 2009-02-19 11:31 . 2009-02-19 11:31 13,616 --a------ c:\windows\system32\drivers\symdns.sys 2009-02-19 11:31 . 2009-02-19 11:31 9,844 --a------ c:\windows\system32\drivers\SymRedir.cat 2009-02-19 11:31 . 2009-02-19 11:31 1,611 --a------ c:\windows\system32\drivers\SymRedir.inf 2009-02-18 07:55 . 2009-02-18 07:55 d-------- c:\program files\Windows Sidebar 2009-02-18 07:54 . 2009-02-18 14:30 d-------- c:\program files\Norton 360 2009-02-18 07:53 . 2009-02-18 19:46 124,464 --a------ c:\windows\system32\drivers\SYMEVENT.SYS 2009-02-18 07:53 . 2009-02-18 19:46 60,808 --a------ c:\windows\system32\S32EVNT1.DLL 2009-02-18 07:53 . 2009-02-18 19:46 10,635 --a------ c:\windows\system32\drivers\SYMEVENT.CAT 2009-02-18 07:53 . 2009-02-18 19:46 806 --a------ c:\windows\system32\drivers\SYMEVENT.INF 2009-02-18 00:06 . 2009-02-18 00:06 d-------- c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP 2009-02-18 00:06 . 2009-02-18 00:06 d-------- c:\program files\CCleaner 2009-02-18 00:06 . 2009-02-18 16:59 d-------- c:\documents and settings\Michael Setter\Application Data\Desktopicon 2009-02-18 00:05 . 2009-02-18 00:05 d-a------ c:\documents and settings\All Users\Application Data\TEMP 2009-02-17 23:39 . 2009-02-17 23:39 d-------- c:\documents and settings\Guest\Application Data\Symantec 2009-02-17 23:38 . 2009-02-17 23:59 d-------- c:\documents and settings\Guest 2009-02-17 16:00 . 2009-02-18 00:05 d-------- c:\documents and settings\Administrator 2009-02-17 07:36 . 2009-02-18 00:05 d-------- c:\program files\ArtsAcoustic Reverb 2009-02-17 07:36 . 2009-02-17 07:36 d-------- c:\documents and settings\All Users\Application Data\ArtsAcoustic 2009-02-16 19:35 . 2008-04-14 14:42 221,184 --a------ c:\windows\system32\wmpns.dll 2009-02-15 13:18 . 2009-02-15 13:18 d-------- c:\program files\Trend Micro 2009-02-14 08:57 . 2009-02-14 08:57 d-------- C:\PerfLogs 2009-02-09 17:39 . 2001-05-11 13:18 420,240 --a------ c:\windows\system32\mpg4c32.dll 2009-02-09 17:39 . 2001-05-16 17:54 309,616 --a------ c:\windows\system32\wmv8dmod.dll 2009-02-09 17:39 . 2001-03-26 04:41 245,760 --a------ c:\windows\system32\mp4sds32.ax 2009-02-09 17:39 . 2003-04-18 16:29 44,544 --a------ c:\windows\system32\msxml4a.dll 2009-02-09 17:37 . 2006-03-22 16:20 491,520 --a------ c:\windows\system32\mgxoschk.dll 2009-02-09 17:37 . 2006-02-06 13:07 2,770 --a------ c:\windows\mgxoschk.ini 2009-02-09 13:21 . 2009-02-09 13:21 d-------- c:\windows\system32\N360_BACKUP 2009-02-09 11:41 . 2009-02-18 19:46 d-------- c:\program files\Symantec 2009-02-09 11:41 . 2009-02-18 16:38 d-------- c:\documents and settings\All Users\Application Data\Symantec 2009-02-09 11:31 . 2009-02-09 13:21 d-------- c:\documents and settings\Michael Setter\Application Data\Symantec 2009-02-08 14:23 . 2009-02-08 14:23 d-------- c:\program files\YAMAHA 2009-02-07 21:45 . 2009-02-07 21:45 d-------- c:\program files\Propellerhead 2009-02-06 14:34 . 2009-02-07 09:04 1,233,979 --a------ C:\Delirium mix new gatirs.cpr 2009-02-04 22:34 . 2009-02-06 14:20 1,345,755 --a------ C:\Delirium mix.cpr 2009-02-04 17:46 . 2009-02-04 17:53 1,183,808 --a------ C:\Deliriumin bfd seq.cpr 2009-02-03 14:25 . 2009-02-04 12:33 1,229,158 --a------ C:\Delirium.cpr . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-03-02 23:53 --------- d-----w c:\program files\Common Files\Symantec Shared 2009-02-28 04:49 --------- d-----w c:\program files\Steinberg 2009-02-27 07:00 --------- d-----w c:\program files\Norton Security Scan 2009-02-21 08:56 --------- d-----w c:\program files\Windows Live Toolbar 2009-02-20 04:50 --------- d-----w c:\documents and settings\Michael Setter\Application Data\uTorrent 2009-02-20 04:44 --------- d-----w c:\program files\uTorrent 2009-02-19 00:31 31,280 ----a-w c:\windows\system32\drivers\SymIM.sys 2009-02-17 13:06 --------- d-----w c:\documents and settings\All Users\Application Data\avg8 2009-02-17 13:05 --------- d-----w c:\program files\waves 2009-02-17 13:02 --------- d-----w c:\program files\Google 2009-02-17 13:01 --------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-02-16 20:35 --------- d-----w c:\documents and settings\Michael Setter\Application Data\LimeWire 2009-02-11 11:03 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help 2009-02-11 04:30 --------- d-----w c:\program files\microsoft frontpage 2009-02-10 23:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-10 23:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys 2009-02-08 02:49 --------- d--h--w c:\program files\InstallShield Installation Information 2009-01-29 21:56 410,984 ----a-w c:\windows\system32\deploytk.dll 2009-01-29 21:55 --------- d-----w c:\program files\Java 2009-01-05 03:02 --------- d-----w c:\program files\Common Files\Nero 2009-01-03 05:47 --------- d-----w c:\program files\Nero 2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll . ((((((((((((((((((((((((((((( SnapShot@2009-02-09_ 9.49.26.73 ))))))))))))))))))))))))))))))))))))))))) . + 2009-02-17 12:54:31 22,016 ----a-w c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP\WiseCustomCall.dll + 2009-03-01 23:04:28 884,736 ----a-w c:\windows\gmer.dll + 2008-04-17 10:13:02 811,008 ----a-w c:\windows\gmer.exe + 2008-10-16 20:38:34 124,928 -c----w c:\windows\ie7updates\KB961260-IE7\advpack.dll + 2008-10-16 20:38:34 347,136 -c----w c:\windows\ie7updates\KB961260-IE7\dxtmsft.dll + 2008-10-16 20:38:34 214,528 -c----w c:\windows\ie7updates\KB961260-IE7\dxtrans.dll + 2008-10-16 20:38:35 133,120 -c----w c:\windows\ie7updates\KB961260-IE7\extmgr.dll + 2008-10-16 20:38:35 63,488 -c----w c:\windows\ie7updates\KB961260-IE7\icardie.dll + 2008-10-16 13:11:09 70,656 -c----w c:\windows\ie7updates\KB961260-IE7\ie4uinit.exe + 2008-10-16 20:38:35 153,088 -c----w c:\windows\ie7updates\KB961260-IE7\ieakeng.dll + 2008-10-16 20:38:35 230,400 -c----w c:\windows\ie7updates\KB961260-IE7\ieaksie.dll + 2008-10-15 07:04:53 161,792 -c----w c:\windows\ie7updates\KB961260-IE7\ieakui.dll + 2008-10-16 20:38:35 383,488 -c----w c:\windows\ie7updates\KB961260-IE7\ieapfltr.dll + 2008-10-16 20:38:35 384,512 -c----w c:\windows\ie7updates\KB961260-IE7\iedkcs32.dll + 2008-10-16 20:38:37 6,066,176 -c----w c:\windows\ie7updates\KB961260-IE7\ieframe.dll + 2008-10-16 20:38:37 44,544 -c----w c:\windows\ie7updates\KB961260-IE7\iernonce.dll + 2008-10-16 20:38:37 267,776 -c----w c:\windows\ie7updates\KB961260-IE7\iertutil.dll + 2008-10-16 13:11:09 13,824 -c----w c:\windows\ie7updates\KB961260-IE7\ieudinit.exe + 2008-10-15 07:06:26 633,632 -c----w c:\windows\ie7updates\KB961260-IE7\iexplore.exe + 2008-10-16 20:38:37 27,648 -c----w c:\windows\ie7updates\KB961260-IE7\jsproxy.dll + 2008-10-16 20:38:37 459,264 -c----w c:\windows\ie7updates\KB961260-IE7\msfeeds.dll + 2008-10-16 20:38:37 52,224 -c----w c:\windows\ie7updates\KB961260-IE7\msfeedsbs.dll + 2008-12-13 06:40:02 3,593,216 -c----w c:\windows\ie7updates\KB961260-IE7\mshtml.dll + 2008-10-16 20:38:38 477,696 -c----w c:\windows\ie7updates\KB961260-IE7\mshtmled.dll + 2008-10-16 20:38:38 193,024 -c----w c:\windows\ie7updates\KB961260-IE7\msrating.dll + 2008-10-16 20:38:39 671,232 -c----w c:\windows\ie7updates\KB961260-IE7\mstime.dll + 2008-10-16 20:38:39 102,912 -c----w c:\windows\ie7updates\KB961260-IE7\occache.dll + 2008-10-16 20:38:39 44,544 -c----w c:\windows\ie7updates\KB961260-IE7\pngfilt.dll + 2007-03-06 01:22:41 213,216 -c----w c:\windows\ie7updates\KB961260-IE7\spuninst\spuninst.exe + 2007-03-06 01:23:51 371,424 -c----w c:\windows\ie7updates\KB961260-IE7\spuninst\updspapi.dll + 2008-10-16 20:38:39 105,984 -c----w c:\windows\ie7updates\KB961260-IE7\url.dll + 2008-10-16 20:38:39 1,160,192 -c----w c:\windows\ie7updates\KB961260-IE7\urlmon.dll + 2008-10-16 20:38:39 233,472 -c----w c:\windows\ie7updates\KB961260-IE7\webcheck.dll + 2008-10-16 20:38:40 826,368 -c----w c:\windows\ie7updates\KB961260-IE7\wininet.dll + 2008-02-21 22:02:38 873,848 ----a-r c:\windows\Installer\$PatchCache$\Managed\FF26F08EC3D591A4489079122F292860\3.4.1\LUALL.EXE + 2008-02-21 22:02:44 3,220,856 ----a-r c:\windows\Installer\$PatchCache$\Managed\FF26F08EC3D591A4489079122F292860\3.4.1\LuComServer.EXE - 2009-01-17 10:27:28 1,165,584 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe + 2009-02-11 11:03:07 1,165,584 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe - 2009-01-17 10:27:28 20,240 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe + 2009-02-11 11:03:08 20,240 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe - 2009-01-17 10:27:28 159,504 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe + 2009-02-11 11:03:08 159,504 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe - 2009-01-17 10:27:28 184,080 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe + 2009-02-11 11:03:08 184,080 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe - 2009-01-17 10:27:28 217,864 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe + 2009-02-11 11:03:08 217,864 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe - 2009-01-17 10:27:28 18,704 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe + 2009-02-11 11:03:08 18,704 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe - 2009-01-17 10:27:29 35,088 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe + 2009-02-11 11:03:09 35,088 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe - 2009-01-17 10:27:28 845,584 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe + 2009-02-11 11:03:08 845,584 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe - 2009-01-17 10:27:28 922,384 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe + 2009-02-11 11:03:08 922,384 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe - 2009-01-17 10:27:28 272,648 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe + 2009-02-11 11:03:08 272,648 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe - 2009-01-17 10:27:28 888,080 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe + 2009-02-11 11:03:08 888,080 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe - 2009-01-17 10:27:28 1,172,240 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe + 2009-02-11 11:03:08 1,172,240 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe - 2008-11-13 05:14:51 15,086 ----a-r c:\windows\Installer\{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}\ARPPRODUCTICON.exe + 2009-02-17 12:39:13 15,086 ----a-r c:\windows\Installer\{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}\ARPPRODUCTICON.exe - 2008-11-13 05:14:51 15,086 ----a-r c:\windows\Installer\{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}\DesktopShortcut_10110FE91EE84A3DADFD1294F86BE5FC.exe + 2009-02-17 12:39:13 15,086 ----a-r c:\windows\Installer\{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}\DesktopShortcut_10110FE91EE84A3DADFD1294F86BE5FC.exe - 2008-11-13 05:14:52 53,248 ----a-r c:\windows\Installer\{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}\ProgramGroupShortcut_EFA2BBEBCF93493B904B1B970B8DFAB6.exe + 2009-02-17 12:39:13 53,248 ----a-r c:\windows\Installer\{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}\ProgramGroupShortcut_EFA2BBEBCF93493B904B1B970B8DFAB6.exe + 2009-02-09 00:41:07 7,406 ----a-r c:\windows\Installer\{E80F62FF-5D3C-4A19-8409-9721F2928206}\IconE80F62FF.exe - 1998-10-29 06:45:06 306,688 ----a-w c:\windows\IsUninst.exe + 1998-10-29 05:45:06 306,688 ----a-w c:\windows\IsUninst.exe - 2008-10-16 20:38:34 124,928 ----a-w c:\windows\system32\advpack.dll + 2008-12-20 23:15:11 124,928 ----a-w c:\windows\system32\advpack.dll - 2000-04-27 02:31:18 19,456 ------w c:\windows\system32\asapi.dll + 2000-04-27 01:31:18 19,456 ----a-w c:\windows\system32\asapi.dll + 2009-02-11 08:28:03 36,608 ----a-w c:\windows\system32\bassmod.dll - 2007-10-21 07:38:06 516,832 ----a-w c:\windows\system32\capicom.dll + 2007-04-11 19:11:20 511,328 ----a-w c:\windows\system32\capicom.dll + 2005-04-09 11:17:44 401,408 ----a-w c:\windows\system32\DLLAV32.dll - 2008-10-16 20:38:34 124,928 -c----w c:\windows\system32\dllcache\advpack.dll + 2008-12-20 23:15:11 124,928 -c----w c:\windows\system32\dllcache\advpack.dll - 2008-10-16 20:38:34 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll + 2008-12-20 23:15:12 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll - 2008-10-16 20:38:34 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll + 2008-12-20 23:15:13 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll - 2008-10-16 20:38:35 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll + 2008-12-20 23:15:13 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll - 2008-10-16 20:38:35 63,488 -c----w c:\windows\system32\dllcache\icardie.dll + 2008-12-20 23:15:13 63,488 -c----w c:\windows\system32\dllcache\icardie.dll - 2008-10-16 13:11:09 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe + 2008-12-19 09:10:15 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe - 2008-10-16 20:38:35 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll + 2008-12-20 23:15:14 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll - 2008-10-16 20:38:35 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll + 2008-12-20 23:15:14 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll - 2008-10-15 07:04:53 161,792 -c----w c:\windows\system32\dllcache\ieakui.dll + 2008-12-19 05:23:56 161,792 -c----w c:\windows\system32\dllcache\ieakui.dll - 2008-10-16 20:38:35 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll + 2008-12-20 23:15:15 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll - 2008-10-16 20:38:35 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll + 2008-12-20 23:15:16 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll - 2008-10-16 20:38:37 6,066,176 -c----w c:\windows\system32\dllcache\ieframe.dll + 2008-12-20 23:15:21 6,066,688 -c----w c:\windows\system32\dllcache\ieframe.dll - 2008-10-16 20:38:37 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll + 2008-12-20 23:15:21 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll - 2008-10-16 20:38:37 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll + 2008-12-20 23:15:22 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll - 2008-10-16 13:11:09 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe + 2008-12-19 09:10:15 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe - 2008-10-15 07:06:26 633,632 -c----w c:\windows\system32\dllcache\iexplore.exe + 2008-12-19 05:25:25 634,024 -c----w c:\windows\system32\dllcache\iexplore.exe - 2008-10-16 20:38:37 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll + 2008-12-20 23:15:23 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll - 2008-10-16 20:38:37 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll + 2008-12-20 23:15:23 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll - 2008-10-16 20:38:37 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll + 2008-12-20 23:15:24 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll - 2008-12-13 06:40:02 3,593,216 -c----w c:\windows\system32\dllcache\mshtml.dll + 2009-01-16 10:35:14 3,594,752 -c----w c:\windows\system32\dllcache\mshtml.dll - 2008-10-16 20:38:38 477,696 -c----w c:\windows\system32\dllcache\mshtmled.dll + 2008-12-20 23:15:30 477,696 -c----w c:\windows\system32\dllcache\mshtmled.dll - 2008-10-16 20:38:38 193,024 -c----w c:\windows\system32\dllcache\msrating.dll + 2008-12-20 23:15:31 193,024 -c----w c:\windows\system32\dllcache\msrating.dll - 2008-10-16 20:38:39 671,232 -c----w c:\windows\system32\dllcache\mstime.dll + 2008-12-20 23:15:32 671,232 -c----w c:\windows\system32\dllcache\mstime.dll - 2008-10-16 20:38:39 102,912 -c----w c:\windows\system32\dllcache\occache.dll + 2008-12-20 23:15:38 102,912 -c----w c:\windows\system32\dllcache\occache.dll - 2008-10-16 20:38:39 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll + 2008-12-20 23:15:38 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll - 2008-04-14 03:42:06 8,461,312 -c----w c:\windows\system32\dllcache\shell32.dll + 2008-06-17 19:02:19 8,461,312 -c----w c:\windows\system32\dllcache\shell32.dll - 2008-10-16 20:38:39 105,984 -c----w c:\windows\system32\dllcache\url.dll + 2008-12-20 23:15:39 105,984 -c----w c:\windows\system32\dllcache\url.dll - 2008-10-16 20:38:39 1,160,192 -c----w c:\windows\system32\dllcache\urlmon.dll + 2008-12-20 23:15:40 1,160,192 -c----w c:\windows\system32\dllcache\urlmon.dll - 2008-10-16 20:38:39 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll + 2008-12-20 23:15:40 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll - 2008-10-16 20:38:40 826,368 -c----w c:\windows\system32\dllcache\wininet.dll + 2008-12-20 23:15:41 826,368 -c----w c:\windows\system32\dllcache\wininet.dll + 2003-03-13 23:33:12 114,688 ----a-w c:\windows\system32\DLLCDA32.dll + 2003-03-13 23:33:00 61,440 ----a-w c:\windows\system32\DLLCDF32.dll + 2003-03-13 23:32:48 81,920 ----a-w c:\windows\system32\DLLCPY32.dll + 2005-04-09 11:17:28 155,648 ----a-w c:\windows\system32\DLLDEV32.dll + 2003-03-13 23:32:44 32,768 ----a-w c:\windows\system32\DLLDIR32.dll + 2005-04-09 11:17:24 143,360 ----a-w c:\windows\system32\DLLDRV32.dll + 2003-03-13 23:33:02 45,056 ----a-w c:\windows\system32\DLLIMG32.dll + 2005-04-09 11:17:30 49,152 ----a-w c:\windows\system32\DLLIO32.dll + 2003-03-13 23:32:46 32,768 ----a-w c:\windows\system32\DLLISO32.dll + 2003-03-13 23:32:40 24,576 ----a-w c:\windows\system32\DLLIX.dll + 2003-03-13 23:32:42 32,768 ----a-w c:\windows\system32\DLLMSC32.dll + 2005-04-09 11:17:34 36,864 ----a-w c:\windows\system32\DLLPNT32.dll + 2003-03-13 23:32:44 49,152 ----a-w c:\windows\system32\DLLPRF32.dll + 2003-03-13 23:33:04 53,248 ----a-w c:\windows\system32\DLLPRJ32.dll + 2003-03-13 23:32:50 65,536 ----a-w c:\windows\system32\DLLPTL32.dll + 2003-03-13 23:35:00 40,960 ----a-w c:\windows\system32\DLLRD32.dll + 2005-04-09 11:17:20 188,416 ----a-w c:\windows\system32\DLLRES32.dll + 2003-03-13 23:32:54 57,344 ----a-w c:\windows\system32\DLLTPO32.dll - 2005-05-09 10:08:40 33,792 ------w c:\windows\system32\drivers\cledx.sys + 2005-05-09 09:08:40 33,792 ----a-w c:\windows\system32\drivers\cledx.sys + 2007-08-09 00:39:56 36,056 ----a-w c:\windows\system32\drivers\CO_Mon.sys + 2008-07-30 06:42:12 23,888 ----a-w c:\windows\system32\drivers\COH_Mon.sys + 2009-03-01 23:04:28 85,969 ----a-w c:\windows\system32\drivers\gmer.sys + 2008-02-01 01:51:16 279,088 ----a-w c:\windows\system32\drivers\srtsp.sys + 2008-02-01 01:51:16 317,616 ----a-w c:\windows\system32\drivers\srtspl.sys + 2008-02-01 01:51:16 43,696 ----a-w c:\windows\system32\drivers\srtspx.sys - 2002-11-24 19:46:16 16,896 ------w c:\windows\system32\drivers\synasUSB.sys + 2002-11-24 18:46:16 16,896 ----a-w c:\windows\system32\drivers\synasUSB.sys - 2008-10-16 20:38:34 347,136 ------w c:\windows\system32\dxtmsft.dll + 2008-12-20 23:15:12 347,136 ------w c:\windows\system32\dxtmsft.dll - 2008-10-16 20:38:34 214,528 ------w c:\windows\system32\dxtrans.dll + 2008-12-20 23:15:13 214,528 ------w c:\windows\system32\dxtrans.dll - 2008-10-16 20:38:35 133,120 ------w c:\windows\system32\extmgr.dll + 2008-12-20 23:15:13 133,120 ------w c:\windows\system32\extmgr.dll - 2008-04-17 02:12:54 107,368 ----a-w c:\windows\system32\GEARAspi.dll + 2008-01-29 01:02:30 107,368 ----a-w c:\windows\system32\GEARAspi.dll + 1998-10-15 06:28:16 85,504 ----a-w c:\windows\system32\HtmlWH.dll - 2008-10-16 20:38:35 63,488 ----a-w c:\windows\system32\icardie.dll + 2008-12-20 23:15:13 63,488 ----a-w c:\windows\system32\icardie.dll - 2008-10-16 13:11:09 70,656 ------w c:\windows\system32\ie4uinit.exe + 2008-12-19 09:10:15 70,656 ------w c:\windows\system32\ie4uinit.exe - 2008-10-16 20:38:35 153,088 ------w c:\windows\system32\ieakeng.dll + 2008-12-20 23:15:14 153,088 ------w c:\windows\system32\ieakeng.dll - 2008-10-16 20:38:35 230,400 ------w c:\windows\system32\ieaksie.dll + 2008-12-20 23:15:14 230,400 ------w c:\windows\system32\ieaksie.dll - 2008-10-15 07:04:53 161,792 ------w c:\windows\system32\ieakui.dll + 2008-12-19 05:23:56 161,792 ------w c:\windows\system32\ieakui.dll - 2008-10-16 20:38:35 383,488 ----a-w c:\windows\system32\ieapfltr.dll + 2008-12-20 23:15:15 383,488 ----a-w c:\windows\system32\ieapfltr.dll - 2008-10-16 20:38:35 384,512 ------w c:\windows\system32\iedkcs32.dll + 2008-12-20 23:15:16 384,512 ------w c:\windows\system32\iedkcs32.dll - 2008-10-16 20:38:37 6,066,176 ----a-w c:\windows\system32\ieframe.dll + 2008-12-20 23:15:21 6,066,688 ----a-w c:\windows\system32\ieframe.dll - 2008-10-16 20:38:37 44,544 ------w c:\windows\system32\iernonce.dll + 2008-12-20 23:15:21 44,544 ------w c:\windows\system32\iernonce.dll - 2008-10-16 20:38:37 267,776 ----a-w c:\windows\system32\iertutil.dll + 2008-12-20 23:15:22 267,776 ----a-w c:\windows\system32\iertutil.dll - 2008-10-16 13:11:09 13,824 ------w c:\windows\system32\ieudinit.exe + 2008-12-19 09:10:15 13,824 ------w c:\windows\system32\ieudinit.exe + 1999-01-28 03:44:20 49,152 ----a-w c:\windows\system32\INETWH32.dll - 2002-09-26 07:34:26 153,088 ------w c:\windows\system32\IWUninstall.exe + 2002-09-26 06:34:26 153,088 ----a-w c:\windows\system32\IWUninstall.exe - 2008-10-16 20:38:37 27,648 ------w c:\windows\system32\jsproxy.dll + 2008-12-20 23:15:23 27,648 ------w c:\windows\system32\jsproxy.dll - 2009-01-10 01:35:28 20,853,704 ----a-w c:\windows\system32\MRT.exe + 2009-02-03 23:21:12 21,244,864 ----a-w c:\windows\system32\MRT.exe - 2008-10-16 20:38:37 459,264 ----a-w c:\windows\system32\msfeeds.dll + 2008-12-20 23:15:23 459,264 ----a-w c:\windows\system32\msfeeds.dll - 2008-10-16 20:38:37 52,224 ----a-w c:\windows\system32\msfeedsbs.dll + 2008-12-20 23:15:24 52,224 ----a-w c:\windows\system32\msfeedsbs.dll - 2008-12-13 06:40:02 3,593,216 ----a-w c:\windows\system32\mshtml.dll + 2009-01-16 10:35:14 3,594,752 ----a-w c:\windows\system32\mshtml.dll - 2008-10-16 20:38:38 477,696 ------w c:\windows\system32\mshtmled.dll + 2008-12-20 23:15:30 477,696 ------w c:\windows\system32\mshtmled.dll - 2008-10-16 20:38:38 193,024 ------w c:\windows\system32\msrating.dll + 2008-12-20 23:15:31 193,024 ------w c:\windows\system32\msrating.dll - 2008-10-16 20:38:39 671,232 ------w c:\windows\system32\mstime.dll + 2008-12-20 23:15:32 671,232 ------w c:\windows\system32\mstime.dll - 2003-03-18 20:14:52 499,712 ------w c:\windows\system32\msvcp71.dll + 2004-07-11 15:10:00 499,712 ----a-w c:\windows\system32\msvcp71.dll - 2003-04-18 06:29:26 82,432 ------w c:\windows\system32\msxml4r.dll + 2003-04-18 05:29:26 82,432 ----a-w c:\windows\system32\msxml4r.dll - 2008-10-16 20:38:39 102,912 ------w c:\windows\system32\occache.dll + 2008-12-20 23:15:38 102,912 ------w c:\windows\system32\occache.dll - 2008-10-16 20:38:39 44,544 ------w c:\windows\system32\pngfilt.dll + 2008-12-20 23:15:38 44,544 ------w c:\windows\system32\pngfilt.dll - 2009-02-08 03:24:52 4,612,100 ----a-w c:\windows\system32\Restore\rstrlog.dat + 2009-02-17 13:07:03 22,371,984 ----a-w c:\windows\system32\Restore\rstrlog.dat + 2002-09-20 13:33:28 1,089,536 ----a-w c:\windows\system32\ROBOEX32.DLL - 2008-04-14 03:42:06 8,461,312 ------w c:\windows\system32\shell32.dll + 2008-06-17 19:02:19 8,461,312 ----a-w c:\windows\system32\shell32.dll - 2007-11-30 12:39:22 17,272 ------w c:\windows\system32\spmsg.dll + 2008-07-09 07:38:24 17,272 ------w c:\windows\system32\spmsg.dll + 1996-01-12 07:00:00 24,576 ----a-w c:\windows\system32\STKIT432.DLL + 2005-04-09 11:17:20 32,768 ----a-w c:\windows\system32\STRING32.dll + 2003-03-13 23:32:54 24,576 ----a-w c:\windows\system32\TTI32.dll + 2003-03-13 23:32:54 24,576 ----a-w c:\windows\system32\TTIC32.dll - 2008-10-16 20:38:39 105,984 ----a-w c:\windows\system32\url.dll + 2008-12-20 23:15:39 105,984 ----a-w c:\windows\system32\url.dll - 2008-10-16 20:38:39 1,160,192 ----a-w c:\windows\system32\urlmon.dll + 2008-12-20 23:15:40 1,160,192 ----a-w c:\windows\system32\urlmon.dll - 2008-10-16 20:38:39 233,472 ------w c:\windows\system32\webcheck.dll + 2008-12-20 23:15:40 233,472 ------w c:\windows\system32\webcheck.dll + 2009-03-02 21:46:05 16,384 ----atw c:\windows\temp\Perflib_Perfdata_738.dat + 2009-03-02 21:46:17 16,384 ----atw c:\windows\temp\Perflib_Perfdata_c80.dat . -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded] @="{4433A54A-1AC8-432F-90FC-85F045CF383C}" [HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}] 2008-10-31 12:24 576352 --a------ c:\program files\Common Files\Symantec Shared\Backup\buShell.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending] @="{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}" [HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}] 2008-10-31 12:24 576352 --a------ c:\program files\Common Files\Symantec Shared\Backup\buShell.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected] @="{476D0EA3-80F9-48B5-B70B-05E677C9C148}" [HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}] 2008-10-31 12:24 576352 --a------ c:\program files\Common Files\Symantec Shared\Backup\buShell.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-01-15 147456] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-14 68856] "Google Update"="c:\documents and settings\Michael Setter\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-04 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-07 8523776] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-07 81920] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648] "Acrobat Assistant 7.0"="c:\program files\Adobe\Distillr\Acrotray.exe" [2008-04-23 483328] "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-12-06 69216] "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-30 136600] "LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984] "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048] "osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-27 988512] "H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-10-23 385024] "SigmatelSysTrayApp"="sttray.exe" [2008-02-01 c:\windows\sttray.exe] "nwiz"="nwiz.exe" [2007-11-07 c:\windows\system32\nwiz.exe] "FirefaceTray"="fireface.exe" [2006-06-29 c:\windows\system32\fireface.exe] "FirefaceMixTray"="firefacemix.exe" [2006-07-06 c:\windows\system32\firefacemix.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\Michael Setter\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2008-06-10 25214] Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-06-12 113664] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "wave1"= fireface_mme.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\WINDOWS\\system32\\usmt\\migwiz.exe"= "c:\\Program Files\\eMule\\eMule.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\WINDOWS\\system32\\mmc.exe"= R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [2008-06-12 11264] R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};c:\program files\CyberLink\PowerDVD\[u]0[/u]00.fcl [2008-06-10 14:55:26 13560] R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2008-02-19 149352] R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2008-06-12 33792] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-26 101936] R3 fireface;Service for Fireface (WDM);c:\windows\system32\drivers\fireface.sys [2008-06-12 79232] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-01-13 23888] --- Other Services/Drivers In Memory --- *NewlyCreated* - COMHOST . Contents of the 'Scheduled Tasks' folder 2009-02-17 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34] 2009-03-02 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20] 2009-03-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-1326574676-1801674531-1003.job - c:\documents and settings\Michael Setter\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 14:09] 2009-02-27 c:\windows\Tasks\Norton Security Scan for Michael Setter.job - c:\program files\Norton Security Scan\Nss.exe [2008-09-19 04:18] . - - - - ORPHANS REMOVED - - - - HKLM-Run-UnlockerAssistant - c:\program files\Unlocker\UnlockerAssistant.exe . ------- Supplementary Scan ------- . uDefault_Search_URL = hxxp://www.google.com/ie uStart Page = hxxp://www.google.com.au/ uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert to existing PDF - c:\program files\Adobe\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-03 10:53:06 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}] "ImagePath"="\??\c:\program files\CyberLink\PowerDVD\[u]0[/u]00.fcl" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(988) c:\windows\system32\fireface_mme.dll . Completion time: 2009-03-03 10:53:57 ComboFix-quarantined-files.txt 2009-03-02 23:53:55 ComboFix2.txt 2009-02-08 22:50:09 Pre-Run: 316,316,766,208 bytes free Post-Run: 316,354,973,696 bytes free 472 --- E O F --- 2009-02-24 21:40:29