ComboFix 10-03-15.06 - T 03/18/2010 20:29:50.2.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.247.98 [GMT -4:00] Running from: c:\downloads\ComboFix.exe Command switches used :: c:\downloads\CFScript.txt AV: Norton Security Suite *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton Security Suite *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_LMIINFO -------\Legacy_LMIRESCUE -------\Service_LMIInfo -------\Service_LMIRescue ((((((((((((((((((((((((( Files Created from 2010-02-19 to 2010-03-19 ))))))))))))))))))))))))))))))) . 2010-03-18 13:38 . 2010-03-18 13:38 -------- d-----w- c:\documents and settings\T\Application Data\ArcSoft Backup Application 2010-03-18 12:13 . 2010-02-04 14:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll 2010-03-18 12:13 . 2010-02-04 14:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll 2010-03-18 12:12 . 2010-02-04 14:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll 2010-03-18 12:11 . 2010-02-04 14:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll 2010-03-18 12:11 . 2009-09-04 21:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll 2010-03-18 12:10 . 2009-09-04 21:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll 2010-03-18 12:10 . 2009-09-04 21:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll 2010-03-18 12:10 . 2009-09-04 21:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll 2010-03-18 12:10 . 2009-09-04 21:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll 2010-03-18 12:10 . 2009-09-04 21:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll 2010-03-18 12:09 . 2009-09-04 21:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll 2010-03-18 12:09 . 2009-03-09 19:27 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll 2010-03-18 12:09 . 2009-03-09 19:27 453456 ----a-w- c:\windows\system32\d3dx10_41.dll 2010-03-18 12:09 . 2009-03-09 19:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll 2010-03-18 12:09 . 2009-09-04 21:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll 2010-03-18 12:09 . 2009-03-16 18:18 517448 ----a-w- c:\windows\system32\XAudio2_4.dll 2010-03-18 12:08 . 2009-03-16 18:18 235352 ----a-w- c:\windows\system32\xactengine3_4.dll 2010-03-18 12:08 . 2009-03-16 18:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll 2010-03-18 12:08 . 2008-10-10 08:52 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll 2010-03-18 12:08 . 2008-10-10 08:52 452440 ----a-w- c:\windows\system32\d3dx10_40.dll 2010-03-18 12:08 . 2008-10-10 08:52 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll 2010-03-18 12:08 . 2008-10-27 14:04 70992 ----a-w- c:\windows\system32\XAPOFX1_2.dll 2010-03-18 12:08 . 2008-10-27 14:04 514384 ----a-w- c:\windows\system32\XAudio2_3.dll 2010-03-18 12:07 . 2008-10-27 14:04 235856 ----a-w- c:\windows\system32\xactengine3_3.dll 2010-03-18 12:07 . 2008-10-27 14:04 23376 ----a-w- c:\windows\system32\X3DAudio1_5.dll 2010-03-18 12:07 . 2008-07-31 14:41 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll 2010-03-18 12:07 . 2008-07-31 14:40 509448 ----a-w- c:\windows\system32\XAudio2_2.dll 2010-03-18 12:07 . 2008-07-31 14:41 238088 ----a-w- c:\windows\system32\xactengine3_2.dll 2010-03-18 12:06 . 2008-07-10 15:00 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll 2010-03-18 12:06 . 2008-07-10 15:01 467984 ----a-w- c:\windows\system32\d3dx10_39.dll 2010-03-18 12:06 . 2008-07-10 15:00 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll 2010-03-18 12:06 . 2008-05-30 18:17 65032 ----a-w- c:\windows\system32\XAPOFX1_0.dll 2010-03-18 12:06 . 2008-05-30 18:19 507400 ----a-w- c:\windows\system32\XAudio2_1.dll 2010-03-18 12:06 . 2008-05-30 18:18 238088 ----a-w- c:\windows\system32\xactengine3_1.dll 2010-03-18 12:06 . 2008-05-30 18:17 25608 ----a-w- c:\windows\system32\X3DAudio1_4.dll 2010-03-18 12:06 . 2008-05-30 18:11 1491992 ----a-w- c:\windows\system32\D3DCompiler_38.dll 2010-03-18 12:06 . 2008-05-30 18:11 467984 ----a-w- c:\windows\system32\d3dx10_38.dll 2010-03-18 12:06 . 2008-05-30 18:11 3850760 ----a-w- c:\windows\system32\D3DX9_38.dll 2010-03-18 12:05 . 2008-03-05 20:03 479752 ----a-w- c:\windows\system32\XAudio2_0.dll 2010-03-18 12:05 . 2008-03-05 20:03 238088 ----a-w- c:\windows\system32\xactengine3_0.dll 2010-03-18 12:05 . 2008-03-05 20:00 25608 ----a-w- c:\windows\system32\X3DAudio1_3.dll 2010-03-18 12:05 . 2008-03-05 19:56 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll 2010-03-18 12:05 . 2008-02-06 03:07 462864 ----a-w- c:\windows\system32\d3dx10_37.dll 2010-03-18 12:05 . 2008-03-05 19:56 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll 2010-03-18 12:05 . 2007-10-22 07:39 267272 ----a-w- c:\windows\system32\xactengine2_10.dll 2010-03-18 12:05 . 2007-10-12 19:14 1374232 ----a-w- c:\windows\system32\D3DCompiler_36.dll 2010-03-18 12:05 . 2007-10-02 13:56 444776 ----a-w- c:\windows\system32\d3dx10_36.dll 2010-03-18 12:04 . 2007-10-12 19:14 3734536 ----a-w- c:\windows\system32\d3dx9_36.dll 2010-03-18 12:04 . 2007-07-20 04:57 267112 ----a-w- c:\windows\system32\xactengine2_9.dll 2010-03-18 12:04 . 2007-07-19 22:14 444776 ----a-w- c:\windows\system32\d3dx10_35.dll 2010-03-18 12:04 . 2007-07-19 22:14 1358192 ----a-w- c:\windows\system32\D3DCompiler_35.dll 2010-03-18 12:04 . 2007-07-19 22:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll 2010-03-18 12:04 . 2007-06-21 00:46 266088 ----a-w- c:\windows\system32\xactengine2_8.dll 2010-03-18 12:04 . 2007-10-22 07:37 17928 ----a-w- c:\windows\system32\X3DAudio1_2.dll 2010-03-18 12:04 . 2007-05-16 20:45 443752 ----a-w- c:\windows\system32\d3dx10_34.dll 2010-03-18 12:04 . 2007-05-16 20:45 1124720 ----a-w- c:\windows\system32\D3DCompiler_34.dll 2010-03-18 12:04 . 2007-05-16 20:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll 2010-03-18 12:02 . 2007-04-04 22:55 261480 ----a-w- c:\windows\system32\xactengine2_7.dll 2010-03-18 12:02 . 2007-03-15 20:57 443752 ----a-w- c:\windows\system32\d3dx10_33.dll 2010-03-18 12:02 . 2007-03-12 20:42 1123696 ----a-w- c:\windows\system32\D3DCompiler_33.dll 2010-03-18 12:00 . 2007-03-12 20:42 3495784 ----a-w- c:\windows\system32\d3dx9_33.dll 2010-03-18 11:59 . 2007-01-24 19:27 255848 ----a-w- c:\windows\system32\xactengine2_6.dll 2010-03-18 11:41 . 2010-03-18 11:51 -------- d--h--w- c:\windows\msdownld.tmp 2010-03-18 11:41 . 2010-03-18 11:41 -------- d-----w- c:\windows\Logs 2010-03-18 11:37 . 2010-03-18 17:14 -------- d-----w- c:\program files\Windows Live Safety Center 2010-03-17 18:43 . 2009-06-30 13:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys 2010-03-17 18:42 . 2010-03-17 18:42 -------- d-----w- c:\program files\Panda Security 2010-03-17 18:05 . 2010-03-17 18:05 -------- d-----w- c:\documents and settings\T\Local Settings\Application Data\Symantec 2010-03-15 17:25 . 2010-03-15 20:12 -------- d-----w- C:\Energy 2010-03-14 13:12 . 2010-03-14 13:12 -------- d-----w- c:\program files\trend micro 2010-03-14 13:11 . 2010-03-14 13:12 -------- d-----w- C:\rsit 2010-03-13 14:43 . 2010-03-13 14:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec 2010-03-13 12:39 . 2010-03-13 12:39 -------- d-----w- c:\documents and settings\T\Application Data\ArcSoft 2010-03-13 12:39 . 2010-03-13 12:39 -------- d-----w- c:\documents and settings\T\Application Data\HP SimpleSave Application 2010-03-12 16:38 . 2010-03-12 16:35 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys 2010-03-12 16:38 . 2010-03-12 16:35 107368 ----a-r- c:\windows\system32\GEARAspi.dll 2010-03-12 16:36 . 2010-03-12 16:35 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys 2010-03-12 16:36 . 2010-03-12 16:36 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL 2010-03-12 16:36 . 2010-03-12 16:36 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2010-03-12 16:36 . 2010-03-12 17:04 -------- d-----w- c:\program files\Common Files\Symantec Shared 2010-03-12 16:36 . 2010-03-12 16:36 -------- d-----w- c:\program files\Symantec 2010-03-12 16:34 . 2010-03-12 22:05 -------- d-----w- c:\windows\system32\drivers\N360 2010-03-12 16:34 . 2010-03-12 16:35 -------- d-----w- c:\program files\Norton Security Suite 2010-03-12 16:34 . 2010-03-12 16:34 -------- d-----w- c:\program files\Windows Sidebar 2010-03-12 16:34 . 2010-03-12 16:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton 2010-03-12 16:32 . 2010-03-12 16:32 -------- d-----w- c:\program files\NortonInstaller 2010-03-12 13:31 . 2010-03-12 13:31 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller 2010-03-12 12:17 . 2010-03-12 12:17 -------- d-----w- c:\documents and settings\T\Local Settings\Application Data\Sunbelt Software 2010-03-10 16:32 . 2010-03-10 16:32 -------- d-----w- c:\documents and settings\DVG\Local Settings\Application Data\Yahoo 2010-03-10 16:30 . 2010-03-10 16:30 -------- d-----w- c:\documents and settings\DVG\Application Data\Yahoo! 2010-03-10 16:12 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe 2010-03-10 01:10 . 2010-03-10 01:18 -------- d-----w- c:\documents and settings\T\Local Settings\Application Data\Yahoo 2010-03-10 00:46 . 2010-03-10 01:09 -------- d-----w- c:\documents and settings\T\Application Data\Yahoo! 2010-03-10 00:43 . 2010-03-11 22:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! 2010-03-09 21:26 . 2010-03-09 22:03 -------- d-----w- c:\documents and settings\DVG\Application Data\mIRC 2010-03-09 18:49 . 2010-03-09 18:49 -------- d-----w- c:\documents and settings\T\Application Data\mIRC 2010-03-09 18:46 . 2010-03-09 18:46 -------- d-----w- c:\program files\Dream Sudoku Trial 2010-03-06 19:07 . 2010-03-06 19:08 -------- d-----w- c:\documents and settings\DVG\Application Data\webex 2010-03-06 19:04 . 2010-03-06 19:08 -------- d-----w- c:\documents and settings\DVG\Local Settings\Application Data\WebEx 2010-03-03 21:04 . 2004-06-10 14:34 53693 ----a-r- c:\windows\UNDPX2A.sys 2010-03-03 21:04 . 2004-06-10 14:31 135168 ----a-r- c:\windows\UNDPX2A.exe 2010-03-03 21:04 . 2004-06-09 23:42 15429 ----a-r- c:\windows\system32\drivers\Sacm2A.sys 2010-02-23 18:28 . 2010-03-11 18:09 -------- d-----w- C:\GM591 2010-02-20 00:26 . 2010-03-17 18:21 -------- d-----w- c:\documents and settings\T\Application Data\Move Networks . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-18 15:59 . 2006-02-28 18:05 -------- d-----w- c:\program files\Java 2010-03-18 15:56 . 2010-01-06 14:11 152576 ----a-w- c:\documents and settings\T\Application Data\Sun\Java\jre1.6.0_17\lzma.dll 2010-03-18 13:37 . 2006-02-28 18:10 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-03-16 01:17 . 2009-09-14 22:56 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-03-15 14:20 . 2010-01-05 16:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2010-03-13 02:01 . 2010-01-05 14:06 -------- d-----w- c:\documents and settings\DVG\Application Data\MyScribe 2010-03-12 16:36 . 2010-03-12 16:36 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF 2010-03-12 16:36 . 2010-03-12 16:36 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT 2010-03-12 16:35 . 2010-03-12 16:35 1291104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll 2010-03-12 16:35 . 2010-03-12 16:35 136840 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll 2010-03-12 16:35 . 2010-03-12 16:35 776952 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll 2010-03-12 15:16 . 2009-09-15 21:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft 2010-03-12 12:26 . 2009-11-03 13:12 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys 2010-03-12 08:54 . 2010-03-18 22:25 1647984 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100318.016\NAVEX32A.DLL 2010-03-12 08:54 . 2010-03-18 22:25 1324720 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100318.016\NAVEX15.SYS 2010-03-12 08:54 . 2010-03-18 22:25 84912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100318.016\NAVENG.SYS 2010-03-12 08:54 . 2010-03-18 22:25 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100318.016\NAVENG32.DLL 2010-03-12 08:54 . 2010-03-18 22:25 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100318.016\EECTRL.SYS 2010-03-12 08:54 . 2010-03-18 22:25 2747440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100318.016\CCERASER.DLL 2010-03-12 08:54 . 2010-03-18 22:25 259440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100318.016\ECMSVR32.DLL 2010-03-12 08:54 . 2010-03-18 22:25 102448 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100318.016\ERASER.SYS 2010-03-12 00:23 . 2010-01-26 13:47 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2010-03-05 21:53 . 2009-09-13 20:55 -------- d-----w- c:\program files\CCleaner 2010-03-03 20:25 . 2009-06-17 01:20 -------- d-----w- c:\documents and settings\DVG\Application Data\U3 2010-02-28 20:51 . 2010-01-04 18:57 -------- d-----w- c:\documents and settings\T\Application Data\MyScribe 2010-02-28 16:22 . 2010-02-03 20:51 54 ----a-w- c:\windows\system32\rp_stats.dat 2010-02-28 16:22 . 2010-02-03 20:51 39 ----a-w- c:\windows\system32\rp_rules.dat 2010-02-12 22:41 . 2010-03-19 00:43 558448 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll 2010-02-07 20:12 . 2009-02-05 11:36 -------- d-----w- c:\program files\Google 2010-02-07 16:12 . 2010-01-23 20:09 -------- d-----w- c:\program files\LogMeIn 2010-02-01 11:07 . 2009-12-16 07:25 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat 2010-01-29 21:19 . 2010-01-29 21:19 388096 ----a-r- c:\documents and settings\T\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe 2010-01-29 21:19 . 2010-01-29 21:19 -------- d-----w- c:\program files\TrendMicro 2010-01-29 19:52 . 2009-10-25 23:23 -------- d-----w- c:\program files\Windows Live 2010-01-29 18:55 . 2009-03-01 20:04 -------- d-----w- c:\documents and settings\T\Application Data\StumbleUpon 2010-01-29 14:52 . 2009-02-05 11:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2010-01-29 03:22 . 2010-01-29 03:22 503808 ----a-w- c:\documents and settings\DVG\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2d6b94d7-n\msvcp71.dll 2010-01-29 03:22 . 2010-01-29 03:22 499712 ----a-w- c:\documents and settings\DVG\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2d6b94d7-n\jmc.dll 2010-01-29 03:22 . 2010-01-29 03:22 348160 ----a-w- c:\documents and settings\DVG\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2d6b94d7-n\msvcr71.dll 2010-01-29 03:22 . 2010-01-29 03:22 61440 ----a-w- c:\documents and settings\DVG\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1c4601b9-n\decora-sse.dll 2010-01-29 03:22 . 2010-01-29 03:22 12800 ----a-w- c:\documents and settings\DVG\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1c4601b9-n\decora-d3d.dll 2010-01-28 16:34 . 2006-02-28 18:05 -------- d-----w- c:\program files\Common Files\Java 2010-01-28 16:04 . 2010-01-28 16:04 503808 ----a-w- c:\documents and settings\T\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4d67b283-n\msvcp71.dll 2010-01-28 16:04 . 2010-01-28 16:04 348160 ----a-w- c:\documents and settings\T\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4d67b283-n\msvcr71.dll 2010-01-28 16:04 . 2010-01-28 16:04 499712 ----a-w- c:\documents and settings\T\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4d67b283-n\jmc.dll 2010-01-28 16:04 . 2010-01-28 16:04 61440 ----a-w- c:\documents and settings\T\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-35a4f4fd-n\decora-sse.dll 2010-01-28 16:04 . 2010-01-28 16:04 12800 ----a-w- c:\documents and settings\T\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-35a4f4fd-n\decora-d3d.dll 2010-01-24 00:45 . 2010-01-24 00:45 -------- d-----w- c:\program files\Belarc 2010-01-23 23:29 . 2010-01-23 23:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Grisoft 2010-01-20 21:27 . 2010-01-20 21:26 -------- d-----w- c:\program files\Common Files\Adobe 2010-01-20 20:56 . 2010-01-06 14:11 79488 ----a-w- c:\documents and settings\T\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2010-01-20 20:56 . 2006-02-28 18:18 -------- d-----w- c:\program files\Common Files\Real 2010-01-20 20:24 . 2010-01-20 20:16 -------- d-----w- c:\program files\QuickTime 2010-01-20 20:15 . 2010-01-20 20:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer 2010-01-20 00:07 . 2009-03-14 19:14 -------- d-----w- c:\program files\Microsoft Silverlight 2010-01-14 16:12 . 2009-10-16 23:14 181120 ------w- c:\windows\system32\MpSigStub.exe 2010-01-07 11:53 . 2009-03-20 00:17 80368 ----a-w- c:\documents and settings\T\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-01-06 19:22 . 2009-08-01 22:32 80368 ----a-w- c:\documents and settings\DVG\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-01-05 20:57 . 2010-01-25 01:20 103424 ----a-w- c:\documents and settings\DVG\Application Data\Mozilla\Firefox\Profiles\lbx0w7jx.default\extensions\[removed]\libs\pixomatic.dll 2010-01-05 20:57 . 2010-01-25 01:20 545280 ----a-w- c:\documents and settings\DVG\Application Data\Mozilla\Firefox\Profiles\lbx0w7jx.default\extensions\[removed]\libs\PicLensHelper.exe 2010-01-05 20:57 . 2010-01-25 01:20 153600 ----a-w- c:\documents and settings\DVG\Application Data\Mozilla\Firefox\Profiles\lbx0w7jx.default\extensions\[removed]\plugins\npcoolirisplugin.dll 2010-01-05 20:57 . 2010-01-25 01:20 344064 ----a-w- c:\documents and settings\DVG\Application Data\Mozilla\Firefox\Profiles\lbx0w7jx.default\extensions\[removed]\libs\LaunchCooliris.exe 2010-01-05 20:57 . 2010-01-25 01:20 4725760 ----a-w- c:\documents and settings\DVG\Application Data\Mozilla\Firefox\Profiles\lbx0w7jx.default\extensions\[removed]\libs\cooliris192.dll 2010-01-05 20:57 . 2010-01-25 01:20 57856 ----a-w- c:\documents and settings\DVG\Application Data\Mozilla\Firefox\Profiles\lbx0w7jx.default\extensions\[removed]\components\coolirisstub.dll 2009-12-31 16:50 . 2006-02-28 17:44 353792 ----a-w- c:\windows\system32\drivers\srv.sys 2009-12-21 19:14 . 2004-08-10 18:51 916480 ------w- c:\windows\system32\wininet.dll 2010-01-08 21:08 . 2010-01-08 21:08 28472 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll 2010-01-08 21:08 . 2010-01-08 21:08 185224 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll 2010-01-08 21:08 . 2010-01-08 21:08 99208 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll 2009-02-14 17:22 . 2009-02-14 17:22 56 --sh--r- c:\windows\system32\398F75844F.sys 2009-02-14 17:22 . 2009-02-14 17:22 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((( SnapShot@2010-03-16_18.22.21 ))))))))))))))))))))))))))))))))))))))))) . + 2010-03-19 00:22 . 2010-03-19 00:22 16384 c:\windows\Temp\Perflib_Perfdata_6b4.dat + 2010-03-19 00:43 . 2010-03-19 00:43 16384 c:\windows\Temp\Perflib_Perfdata_6a8.dat + 2010-03-19 00:42 . 2010-03-19 00:42 16384 c:\windows\Temp\Perflib_Perfdata_67c.dat + 2009-09-03 11:36 . 2007-04-04 22:53 81768 c:\windows\system32\xinput1_3.dll + 2009-09-03 11:36 . 2007-03-05 16:42 15128 c:\windows\system32\x3daudio1_1.dll - 2009-09-03 11:36 . 2006-11-15 15:38 15128 c:\windows\system32\x3daudio1_1.dll - 2010-01-28 16:02 . 2009-12-17 22:14 153376 c:\windows\system32\javaws.exe + 2010-03-18 16:01 . 2009-12-17 22:14 153376 c:\windows\system32\javaws.exe + 2010-03-18 16:01 . 2009-12-17 22:14 145184 c:\windows\system32\javaw.exe - 2010-01-28 16:02 . 2009-12-17 22:14 145184 c:\windows\system32\javaw.exe - 2010-01-28 16:02 . 2009-12-17 22:14 145184 c:\windows\system32\java.exe + 2010-03-18 16:01 . 2009-12-17 22:14 145184 c:\windows\system32\java.exe + 2010-02-06 00:52 . 2010-02-06 00:52 464272 c:\windows\Downloaded Program Files\wlscBase.dll + 2009-08-04 18:06 . 2009-08-04 18:06 132352 c:\windows\Downloaded Program Files\as2stubie.dll + 2010-03-18 15:59 . 2010-03-18 15:59 1757696 c:\windows\Installer\10b2b1b.msi - 2009-02-01 10:11 . 2010-03-02 05:30 31648712 c:\windows\system32\MRT.exe + 2009-02-01 10:11 . 2010-03-02 01:30 31648712 c:\windows\system32\MRT.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SigmatelSysTrayApp"="stsystra.exe" [2005-09-10 393216] "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-15 94208] "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-15 114688] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-15 77824] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ \0SsiEfr.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys] @="FSFilter Activity Monitor" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2009-12-11 20:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2009-12-22 06:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter] 2007-09-14 01:50 1603152 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu] 2007-10-26 01:10 652624 ----a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet] 2005-12-15 16:44 839680 ----a-w- c:\program files\Dell\QuickSet\quickset.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor] 2008-10-25 16:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] 2004-07-27 22:50 221184 ----a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] 2004-07-27 22:50 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2009-11-11 04:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2010-01-11 20:21 246504 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] 2005-11-29 10:56 761947 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] 2010-01-20 20:39 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "RDSessMgr"=3 (0x3) "RasMan"=3 (0x3) "RasAuto"=3 (0x3) "TapiSrv"=3 (0x3) "StumbleUponUpdateService"=3 (0x3) "mnmsrvc"=3 (0x3) "Microsoft Office Groove Audit Service"=3 (0x3) "gusvc"=2 (0x2) "gupdate1c987866e79faa8"=2 (0x2) "CiSvc"=3 (0x3) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [3/17/2010 2:43 PM 28552] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0308000.029\SymEFA.sys [3/12/2010 1:17 PM 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0308000.029\BHDrvx86.sys [3/12/2010 1:17 PM 259632] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0308000.029\cchpx86.sys [3/12/2010 1:17 PM 482432] R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100312.001\IDSXpx86.sys [3/14/2010 6:17 PM 329592] R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [11/3/2009 9:12 AM 95024] R2 N360;Norton Security Suite;c:\program files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe [3/12/2010 1:16 PM 117640] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/12/2010 4:54 AM 102448] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?] S3 getPlus(R) Installer;getPlus(R) Installer;c:\program files\NOS\bin\getPlus_HelperSvc.exe --> c:\program files\NOS\bin\getPlus_HelperSvc.exe [?] S3 pctNDIS;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [10/23/2009 6:06 PM 55208] S4 gupdate1c987866e79faa8;Google Update Service (gupdate1c987866e79faa8);c:\program files\Google\Update\GoogleUpdate.exe [2/5/2009 7:39 AM 133104] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] getPlusHelper REG_MULTI_SZ getPlusHelper . Contents of the 'Scheduled Tasks' folder 2010-03-17 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34] 2010-03-19 c:\windows\Tasks\User_Feed_Synchronization-{A1436AFE-2180-4C5F-A870-A156C3FC039E}.job - c:\windows\system32\msfeedssync.exe [2007-08-13 08:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://malwareremoval.com/forum/viewtopic.php?f=11&t=50086&p=511727&e=511727 uInternet Connection Wizard,ShellNext = iexplore DPF: {AD58C149-8AE2-4878-99DC-3A164E32F814} - hxxp://appsnet.bentley.com/myselectcd/SAXFileEE.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-03-18 20:44 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360] "ImagePath"="\"c:\program files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\3.8.0.41\diMaster.dll\" /prefetch:1" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(864) c:\windows\system32\COMRes.dll - - - - - - - > 'explorer.exe'(3936) c:\windows\system32\WININET.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll c:\windows\system32\LMIRfsClientNP.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\System32\WLTRYSVC.EXE c:\windows\System32\bcmwltry.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\system32\wscntfy.exe c:\windows\stsystra.exe c:\windows\system32\igfxsrvc.exe . ************************************************************************** . Completion time: 2010-03-18 20:52:56 - machine was rebooted ComboFix-quarantined-files.txt 2010-03-19 00:52 ComboFix2.txt 2010-03-16 18:33 Pre-Run: 14,268,334,080 bytes free Post-Run: 14,139,478,016 bytes free - - End Of File - - 7EAFEE6391863EB0F45A4A8099CDE3B4