ComboFix 11-07-19.04 - Chris 20/07/2011 3:02.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3060.1717 [GMT 1:00]
Running from: c:\users\Chris\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Chris\AppData\Roaming\inst.exe
c:\users\Chris\AppData\Roaming\pcouffin.sys
.
.
((((((((((((((((((((((((( Files Created from 2011-06-20 to 2011-07-20 )))))))))))))))))))))))))))))))
.
.
2011-07-20 02:05 . 2011-07-20 02:06 -------- d-----w- c:\users\Chris\AppData\Local\temp
2011-07-20 02:05 . 2011-07-20 02:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-20 01:52 . 2011-07-20 01:52 -------- d-----w- c:\program files\SIW
2011-07-19 01:06 . 2011-07-19 01:06 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2011-07-19 01:06 . 2011-07-19 01:23 -------- d-----w- c:\users\Chris\AppData\Roaming\Vso
2011-07-19 01:06 . 2009-09-02 20:58 626688 ----a-w- c:\windows\system32\vp7vfw.dll
2011-07-19 01:06 . 2009-09-02 20:58 65602 ----a-w- c:\windows\system32\cook3260.dll
2011-07-19 01:06 . 2009-09-02 20:58 217127 ----a-w- c:\windows\system32\drv43260.dll
2011-07-19 01:06 . 2009-09-02 20:58 208935 ----a-w- c:\windows\system32\drv33260.dll
2011-07-19 01:06 . 2009-09-02 20:58 176165 ----a-w- c:\windows\system32\drv23260.dll
2011-07-19 01:06 . 2009-09-02 20:58 102439 ----a-w- c:\windows\system32\sipr3260.dll
2011-07-19 01:06 . 2009-09-02 20:57 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll
2011-07-19 01:06 . 2011-07-19 01:06 -------- d-----w- c:\program files\VSO
2011-07-18 04:51 . 2011-04-25 15:29 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-07-18 04:51 . 2011-04-22 23:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-07-18 04:51 . 2011-04-22 23:35 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-07-17 17:32 . 2011-07-17 17:32 -------- d-----w- c:\users\Chris\Tracing
2011-07-17 17:18 . 2011-07-17 17:25 -------- d-----w- c:\users\Chris\AppData\Local\Windows Live
2011-07-17 17:18 . 2011-07-17 17:18 -------- d-----w- c:\program files\Common Files\Windows Live
2011-07-17 17:12 . 2011-07-17 17:12 -------- d-----w- c:\program files\FileHippo.com
2011-07-17 01:00 . 2011-07-17 01:00 -------- d-----w- c:\users\Chris\AppData\Roaming\CyberLink
2011-07-16 00:30 . 2011-07-17 17:24 -------- d-----w- C:\Casino
2011-07-14 01:51 . 2011-07-14 02:03 -------- d-----w- c:\program files\Common Files\Symantec Shared
2011-07-14 01:51 . 2011-07-14 01:59 -------- d-----w- c:\program files\Symantec
2011-07-14 01:51 . 2011-07-14 01:59 126584 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-07-14 01:51 . 2011-07-14 02:02 -------- d-----w- c:\windows\system32\drivers\NIS
2011-07-14 01:51 . 2011-07-14 01:51 -------- d-----w- c:\program files\Norton Internet Security
2011-07-14 01:51 . 2011-07-14 01:51 -------- d-----w- c:\program files\NortonInstaller
2011-07-14 00:41 . 2011-07-14 00:41 -------- d-----w- c:\program files\CCleaner
2011-07-14 00:35 . 2011-07-14 00:35 -------- d-----w- c:\users\Chris\AppData\Local\GoTrusted.com
2011-07-14 00:34 . 2011-07-14 00:34 -------- d-----w- c:\program files\GoTrusted.com
2011-07-13 19:02 . 2011-07-19 03:30 -------- d-----w- c:\users\Chris\AppData\Local\CrashDumps
2011-07-13 18:02 . 2011-07-18 04:27 -------- d-----w- c:\users\Chris\AppData\Local\NPE
2011-07-13 17:10 . 2011-07-13 17:10 -------- d-----w- c:\users\Chris\AppData\Roaming\vlc
2011-07-13 17:09 . 2011-07-13 17:09 -------- d-----w- c:\program files\VideoLAN
2011-07-13 15:54 . 2011-07-13 15:54 -------- d-----w- c:\windows\PRIndex
2011-07-13 15:54 . 2011-07-13 15:54 -------- d-----w- c:\users\Chris\AppData\Roaming\NewspaperDirect
2011-07-13 08:58 . 2011-07-20 01:58 -------- d-----w- c:\program files\PeerBlock
2011-07-13 08:56 . 2011-07-20 01:09 -------- d-----w- c:\program files\uTorrent
2011-07-13 08:56 . 2011-07-20 01:58 -------- d-----w- c:\users\Chris\AppData\Roaming\uTorrent
2011-07-13 08:56 . 2011-07-13 08:56 -------- d-----w- c:\users\Chris\AppData\Local\uTorrent
2011-07-13 08:44 . 2011-07-13 08:44 -------- d-----w- c:\program files\ESET
2011-07-12 23:51 . 2011-03-12 21:55 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-07-12 23:45 . 2011-07-12 23:45 -------- d-----w- c:\users\Chris\AppData\Local\Mozilla
2011-07-12 23:45 . 2011-07-12 23:45 -------- d-----w- c:\program files\Common Files\xing shared
2011-07-12 23:44 . 2011-07-12 23:44 -------- d-----w- c:\program files\real
2011-07-12 23:40 . 2011-07-12 23:40 -------- d-----w- c:\users\Chris\AppData\Roaming\Malwarebytes
2011-07-12 23:39 . 2011-07-12 23:39 -------- d-----w- c:\programdata\Malwarebytes
2011-07-12 23:39 . 2011-07-06 18:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-12 23:39 . 2011-07-17 17:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-12 23:39 . 2011-07-06 18:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-12 23:38 . 2011-07-12 23:38 -------- d-----w- c:\users\Chris\AppData\Local\Secunia PSI
2011-07-12 23:37 . 2011-07-12 23:37 -------- d-----w- c:\program files\Secunia
2011-07-12 23:36 . 2011-07-12 23:36 -------- d-----w- c:\program files\Common Files\Adobe
2011-07-12 23:34 . 2011-07-12 23:34 -------- d-----w- c:\program files\Common Files\Adobe AIR
2011-07-12 23:34 . 2011-07-12 23:35 -------- d-----w- c:\users\Chris\AppData\Local\Adobe
2011-07-12 23:32 . 2011-07-13 00:01 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-12 23:24 . 2011-07-12 23:24 -------- d-----w- c:\program files\Common Files\Java
2011-07-12 23:24 . 2011-05-04 03:52 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-07-12 23:01 . 2011-03-03 15:40 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-07-12 23:01 . 2011-03-03 13:35 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-07-12 22:59 . 2011-02-18 14:03 305152 ----a-w- c:\windows\system32\drivers\srv.sys
2011-07-12 22:58 . 2011-05-02 12:02 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-07-12 22:55 . 2011-04-29 13:24 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-07-12 22:55 . 2011-04-29 13:24 79872 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-07-12 22:55 . 2011-04-29 13:24 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-12 22:53 . 2010-12-17 15:45 2067968 ----a-w- c:\windows\system32\mstscax.dll
2011-07-12 22:53 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-07-12 22:53 . 2011-04-29 15:59 276992 ----a-w- c:\windows\system32\schannel.dll
2011-07-12 22:53 . 2011-05-02 17:16 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-07-12 22:53 . 2011-04-20 15:55 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-07-12 22:53 . 2011-04-20 15:50 49152 ----a-w- c:\windows\system32\csrsrv.dll
2011-07-12 22:43 . 2011-07-12 22:43 -------- d-----w- c:\programdata\Symantec
2011-07-12 22:43 . 2011-07-14 01:51 -------- d-----w- c:\programdata\Norton
2011-07-12 22:37 . 2011-07-12 22:37 -------- d-----w- c:\program files\Microsoft.NET
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-17 17:19 . 2011-03-28 17:36 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-07-12 23:44 . 2008-10-23 12:05 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-07-12 23:44 . 2008-10-23 12:05 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-05-13 15:03 . 2011-05-13 15:03 49016 ----a-w- c:\windows\system32\sirenacm.dll
2011-07-08 07:31 . 2011-07-12 23:44 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-10 2153472]
"GoTrusted"="c:\program files\GoTrusted.com\GoTrusted Secure Tunnel v2.3.0.5\GoTrusted Secure Tunnel.exe" [2011-04-12 188488]
"FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2010-08-09 248832]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-25 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-25 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-25 141848]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-07-12 273544]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2011-4-19 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 MOSUMAC;USB-Ethernet Driver;c:\windows\system32\DRIVERS\MOSUMAC.SYS [2009-12-10 43520]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1206000.01D\SYMDS.SYS [2011-01-27 340088]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1206000.01D\SYMEFA.SYS [2011-03-15 744568]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110701.001\BHDrvx86.sys [2011-06-30 810616]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20110716.031\IDSvix86.sys [2011-07-13 367736]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1206000.01D\Ironx86.SYS [2011-01-27 136312]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\NIS\1206000.01D\SYMTDIV.SYS [2011-03-22 331384]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-05 77824]
S2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe [2011-04-17 130008]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [2011-04-19 993848]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [2011-04-19 399416]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-07-14 105592]
S3 gttap1;GoTrusted TAP Adapter;c:\windows\system32\DRIVERS\gttap1.sys [2008-03-18 20480]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 15544]
S4 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-07-06 41272]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 87184967
*NewlyCreated* - MODEM
*Deregistered* - 87184967
*Deregistered* - pbfilter
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.visagecomputers.co.uk/
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\3co3mo8b.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-07-20 03:06
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\18.6.0.29\diMaster.dll\" /prefetch:1"
.
Completion time: 2011-07-20 03:07:27
ComboFix-quarantined-files.txt 2011-07-20 02:07
.
Pre-Run: 184,649,793,536 bytes free
Post-Run: 184,620,732,416 bytes free
.
- - End Of File - - C2C55E7AF98010694BD2811C3B3B4CBC