ComboFix 10-03-10.08 - jon 03/11/2010 14:18:40.1.2 - x86 Microsoft� Windows Vista� Home Premium 6.0.6002.2.1252.1.1033.18.2046.1149 [GMT 0:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500 c:\windows\system32\is38881.dll . ((((((((((((((((((((((((( Files Created from 2010-02-11 to 2010-03-11 ))))))))))))))))))))))))))))))) . 2010-03-11 14:23 . 2010-03-11 14:23 -------- d-----w- c:\users\jon\AppData\Local\temp 2010-03-11 14:23 . 2010-03-11 14:23 -------- d-----w- c:\users\Default\AppData\Local\temp 2010-03-11 14:15 . 2010-03-11 14:15 -------- d-----w- C:\32788R22FWJFW 2010-03-11 13:58 . 2010-02-12 17:41 558448 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll 2010-03-10 14:41 . 2009-10-28 22:37 343088 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100305.002\IDSvix86.sys 2010-03-10 14:41 . 2009-10-28 22:37 329592 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100305.002\IDSXpx86.sys 2010-03-10 14:41 . 2009-10-28 22:37 811896 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100305.002\Scxpx86.dll 2010-03-10 14:41 . 2009-10-28 22:37 488312 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100305.002\IDSxpx86.dll 2010-03-10 14:41 . 2009-10-28 22:37 466992 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100305.002\IDSviA64.sys 2010-03-01 19:14 . 2010-03-01 19:14 -------- d-----w- c:\program files\Trend Micro 2010-02-24 09:48 . 2010-01-23 09:26 2048 ----a-w- c:\windows\system32\tzres.dll 2010-02-24 09:47 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc_isv.dll 2010-02-24 09:47 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc.dll 2010-02-24 09:47 . 2010-01-25 08:21 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe 2010-02-24 09:47 . 2010-01-25 08:21 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe 2010-02-24 09:47 . 2010-01-25 08:21 518144 ----a-w- c:\windows\system32\RMActivate.exe 2010-02-24 09:47 . 2010-01-25 08:21 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe 2010-02-24 09:47 . 2010-01-25 12:00 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll 2010-02-24 09:47 . 2010-01-25 12:00 152064 ----a-w- c:\windows\system32\secproc_ssp.dll 2010-02-24 09:47 . 2010-01-25 11:58 332288 ----a-w- c:\windows\system32\msdrm.dll 2010-02-24 09:47 . 2010-01-06 15:39 1696256 ----a-w- c:\windows\system32\gameux.dll 2010-02-24 09:47 . 2010-01-06 15:38 28672 ----a-w- c:\windows\system32\Apphlpdm.dll 2010-02-24 09:47 . 2010-01-06 13:30 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2010-02-22 12:32 . 2010-02-22 12:32 -------- d-----w- c:\programdata\50059827 2010-02-12 18:23 . 2010-02-12 18:23 -------- d--h--w- c:\windows\msdownld.tmp 2010-02-12 17:05 . 2010-02-12 17:14 -------- d-----w- c:\program files\Mass Effect 2 2010-02-10 06:32 . 2009-12-11 11:43 302080 ----a-w- c:\windows\system32\drivers\srv.sys 2010-02-10 06:32 . 2009-12-11 11:43 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys 2010-02-10 06:32 . 2009-12-08 20:01 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe 2010-02-10 06:32 . 2009-12-08 20:01 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe 2010-02-10 06:32 . 2009-12-08 20:01 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys 2010-02-10 06:32 . 2009-12-08 17:26 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys 2010-02-10 06:32 . 2009-12-04 18:29 1314816 ----a-w- c:\windows\system32\quartz.dll 2010-02-10 06:31 . 2009-12-04 18:30 12288 ----a-w- c:\windows\system32\tsbyuv.dll 2010-02-10 06:31 . 2009-12-04 18:28 22528 ----a-w- c:\windows\system32\msyuv.dll 2010-02-10 06:31 . 2009-12-04 18:28 31744 ----a-w- c:\windows\system32\msvidc32.dll 2010-02-10 06:31 . 2009-12-04 18:28 13312 ----a-w- c:\windows\system32\msrle32.dll 2010-02-10 06:31 . 2009-12-04 18:28 50176 ----a-w- c:\windows\system32\iyuv_32.dll 2010-02-10 06:31 . 2009-12-04 18:28 123904 ----a-w- c:\windows\system32\msvfw32.dll 2010-02-10 06:31 . 2009-12-04 18:28 82944 ----a-w- c:\windows\system32\mciavi32.dll 2010-02-10 06:31 . 2009-12-04 18:27 91136 ----a-w- c:\windows\system32\avifil32.dll 2010-02-10 06:31 . 2009-12-04 15:56 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2010-02-10 06:31 . 2009-12-04 15:56 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-11 13:58 . 2009-02-20 19:44 -------- d-----w- c:\program files\Steam 2010-03-11 13:58 . 2009-01-14 19:19 -------- d-----w- c:\programdata\NVIDIA 2010-03-05 19:53 . 2009-02-20 19:44 -------- d-----w- c:\program files\Common Files\Steam 2010-02-25 08:32 . 2009-01-14 18:13 49224 ----a-w- c:\users\jon\AppData\Local\GDIPFONTCACHEV1.DAT 2010-02-12 17:43 . 2009-01-14 18:17 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-02-12 17:33 . 2009-11-14 18:34 -------- d-----w- c:\program files\Common Files\BioWare 2010-02-12 17:31 . 2009-01-16 17:13 -------- d-----w- c:\program files\Electronic Arts 2010-02-12 17:22 . 2009-02-08 13:16 -------- d-----w- c:\programdata\Media Center Programs 2010-02-12 17:17 . 2009-01-24 11:49 -------- d-----w- c:\program files\Activision 2010-02-10 17:31 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2010-02-05 16:47 . 2010-02-05 16:47 -------- d-----w- c:\program files\iTunes 2010-02-05 16:47 . 2010-02-05 16:47 -------- d-----w- c:\program files\iPod 2010-02-05 16:47 . 2009-01-15 20:08 -------- d-----w- c:\program files\Common Files\Apple 2010-02-05 16:43 . 2010-02-05 16:43 72488 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe 2010-02-04 17:18 . 2010-02-04 17:18 -------- d-----w- c:\users\jon\AppData\Roaming\PureEdge 2010-02-04 17:18 . 2010-02-04 17:17 -------- d-----w- c:\programdata\PureEdge 2010-02-04 17:17 . 2010-02-04 17:17 -------- d-----w- c:\program files\IBM 2010-02-04 10:01 . 2010-02-12 18:24 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll 2010-02-04 10:01 . 2010-02-12 18:24 528216 ----a-w- c:\windows\system32\XAudio2_6.dll 2010-02-04 10:01 . 2010-02-12 18:24 238936 ----a-w- c:\windows\system32\xactengine3_6.dll 2010-02-04 10:01 . 2010-02-12 18:24 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll 2010-02-03 09:00 . 2010-03-11 14:09 84912 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100310.037\NAVENG.SYS 2010-02-03 09:00 . 2010-03-11 14:09 1324720 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100310.037\NAVEX15.SYS 2010-02-03 06:07 . 2010-02-03 06:07 -------- d-----w- c:\program files\SystemRequirementsLab 2010-01-31 18:54 . 2010-01-31 18:54 -------- d-----w- c:\users\jon\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2010-01-27 01:34 . 2010-01-10 17:46 -------- d-----w- c:\users\jon\AppData\Roaming\DivX 2010-01-23 00:43 . 2009-01-16 17:35 -------- d-----w- c:\programdata\Electronic Arts 2010-01-23 00:33 . 2009-06-23 11:17 -------- d-----w- c:\program files\Common Files\Adobe AIR 2010-01-23 00:33 . 2010-01-23 00:34 38784 ----a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe 2010-01-23 00:33 . 2009-06-23 11:17 38784 ----a-w- c:\users\jon\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe 2010-01-21 02:33 . 2009-10-25 01:57 -------- d-----w- c:\program files\Microsoft Silverlight 2010-01-14 02:04 . 2009-06-23 11:18 -------- d-----w- c:\program files\Common Files\Adobe 2010-01-10 17:12 . 2010-01-10 17:08 -------- d-----w- c:\program files\Google 2010-01-10 17:10 . 2010-01-10 17:08 -------- d-----w- c:\program files\DivX 2010-01-10 17:09 . 2010-01-10 17:09 -------- d-----w- c:\program files\Common Files\PX Storage Engine 2010-01-10 17:09 . 2010-01-10 17:08 -------- d-----w- c:\program files\Common Files\DivX Shared 2010-01-06 15:38 . 2010-02-24 09:47 173056 ----a-w- c:\windows\AppPatch\AcXtrnal.dll 2010-01-06 15:38 . 2010-02-24 09:47 542720 ----a-w- c:\windows\AppPatch\AcLayers.dll 2010-01-06 15:38 . 2010-02-24 09:47 458752 ----a-w- c:\windows\AppPatch\AcSpecfc.dll 2010-01-06 15:38 . 2010-02-24 09:47 2159616 ----a-w- c:\windows\AppPatch\AcGenral.dll 2010-01-02 06:38 . 2010-01-22 02:03 916480 ----a-w- c:\windows\system32\wininet.dll 2010-01-02 06:32 . 2010-01-22 02:03 109056 ----a-w- c:\windows\system32\iesysprep.dll 2010-01-02 06:32 . 2010-01-22 02:03 71680 ----a-w- c:\windows\system32\iesetup.dll 2010-01-02 04:57 . 2010-01-22 02:03 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2009-12-28 02:48 . 2009-12-28 02:48 690952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2009-12-23 01:13 . 2009-12-23 01:16 24576 ----a-w- c:\windows\system32\AsIO.dll 2009-12-23 01:13 . 2009-12-23 01:16 12400 ----a-w- c:\windows\system32\drivers\AsIO.sys 2009-12-16 21:05 . 2009-12-16 21:05 652296 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsTemplate\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2009-12-16 21:04 . 2009-12-16 21:04 416128 ----a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "Steam"="c:\program files\Steam\Steam.exe" [2010-02-20 1217872] "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-13 4351216] "TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-11-13 247144] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-18 76304] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352] "NvSvc"="c:\windows\system32\nvsvc.dll" [2007-11-06 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-06 8530464] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-06 81920] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-7-1 809488] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys] @="FSFilter Activity Monitor" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000001 "VistaSp2"=hex(b):24,1c,ad,a7,12,46,ca,01 R2 gupdate1ca9217a1d16aa1;Google Update Service (gupdate1ca9217a1d16aa1);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-10 133104] R3 netr28u;Linksys USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [2007-08-15 552448] R3 Razerlow;Razerlow USB Filter Driver;c:\windows\system32\Drivers\Razerlow.sys [2005-04-24 13225] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0308000.029\SYMEFA.SYS [2009-08-22 310320] S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys [2009-08-22 259632] S1 ccHP;Symantec Hash Provider;c:\windows\System32\Drivers\N360\0308000.029\ccHPx86.sys [2009-08-22 482432] S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100310.001\IDSvix86.sys [2009-10-28 343088] S2 N360;Norton 360;c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe [2009-08-22 117640] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-09-27 240232] S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-09-16 102448] S3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS [2009-08-22 48688] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder 2010-03-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-10 17:08] 2010-03-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-10 17:08] . . ------- Supplementary Scan ------- . uStart Page = hxxp://uk.yahoo.com/ mStart Page = hxxp://uk.yahoo.com uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://uk.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://uk.search.yahoo.com DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab . - - - - ORPHANS REMOVED - - - - BHO-{97D0764D-2EEF-38CD-ACCB-C7E6F78F687C} - c:\windows\system32\is38881.dll HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-03-11 14:23 Windows 6.0.6002 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360] "ImagePath"="\"c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.8.0.41\diMaster.dll\" /prefetch:1" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-809746976-2780265997-1167772207-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:eb,ac,0f,31,c8,60,ca,9f,ea,a4,c4,89,62,c5,e8,dc,d3,27,3b,a2,fa,84,e7, 82,0d,3b,25,89,01,68,15,1f,71,4d,ba,7f,7d,dd,0e,45,b0,38,77,7b,c0,9c,93,07,\ "??"=hex:a1,5e,47,db,25,65,bb,27,8b,92,55,34,10,3f,d9,49 [HKEY_USERS\S-1-5-21-809746976-2780265997-1167772207-1000\Software\SecuROM\License information*] "datasecu"=hex:a5,ed,64,35,ef,48,0a,15,1d,73,e1,09,69,af,7c,c5,e3,4c,4f,88,1d, e1,e8,56,c5,8b,47,d5,4e,0d,df,ec,34,d6,45,17,53,74,bf,5c,b8,59,51,f4,70,9a,\ "rkeysecu"=hex:ee,ce,58,6c,84,f0,7d,93,8b,a8,34,13,62,64,82,e9 . Completion time: 2010-03-11 14:25:31 ComboFix-quarantined-files.txt 2010-03-11 14:25 Pre-Run: 154,811,416,576 bytes free Post-Run: 155,052,879,872 bytes free - - End Of File - - 014732FB76DDD46A02EB710E9046365A