ComboFix 11-08-16.05 - Chris 16/08/2011 23:19:29.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3060.1691 [GMT 1:00]
Running from: c:\users\Chris\Downloads\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_usnjsvc
.
.
((((((((((((((((((((((((( Files Created from 2011-07-16 to 2011-08-16 )))))))))))))))))))))))))))))))
.
.
2011-08-17 00:37 . 2011-08-17 00:37 -------- d-----w- c:\users\Chris\AppData\Roaming\CyberLink
2011-08-17 00:00 . 2011-08-17 00:00 -------- d-----w- c:\program files\Common Files\xing shared
2011-08-16 23:59 . 2011-08-17 00:00 -------- d-----w- c:\program files\real
2011-08-16 23:46 . 2011-08-17 00:17 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-16 23:42 . 2011-08-16 23:42 -------- d-----w- c:\users\Chris\AppData\Local\Secunia PSI
2011-08-16 23:42 . 2011-08-16 23:42 -------- d-----w- c:\program files\Secunia
2011-08-16 23:42 . 2011-08-16 23:42 -------- d-----w- c:\users\Chris\AppData\Roaming\Malwarebytes
2011-08-16 23:42 . 2011-07-06 18:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-16 23:42 . 2011-08-16 23:42 -------- d-----w- c:\programdata\Malwarebytes
2011-08-16 23:42 . 2011-08-16 23:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-16 23:42 . 2011-07-06 18:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-16 23:39 . 2011-08-16 23:39 -------- d-----w- c:\windows\Sun
2011-08-16 23:26 . 2011-03-12 21:55 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-08-16 23:24 . 2011-08-16 23:24 -------- d-----w- c:\program files\Common Files\Adobe
2011-08-16 23:24 . 2011-08-16 12:33 -------- d-----w- c:\users\Chris\AppData\Local\Adobe
2011-08-16 23:22 . 2011-08-16 23:22 -------- d-----w- c:\program files\Common Files\Java
2011-08-16 23:22 . 2011-08-16 23:22 544656 ----a-w- c:\windows\system32\deployJava1.dll
2011-08-16 23:19 . 2011-08-16 23:19 -------- d-----w- c:\users\Chris\AppData\Local\Mozilla
2011-08-16 23:18 . 2011-08-16 23:18 -------- d-----w- c:\program files\FileHippo.com
2011-08-16 22:22 . 2011-08-16 22:22 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-15 23:46 . 2011-03-03 15:40 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-08-15 23:45 . 2011-03-10 17:03 1162240 ----a-w- c:\windows\system32\mfc42u.dll
2011-08-15 23:45 . 2011-03-10 17:03 1136640 ----a-w- c:\windows\system32\mfc42.dll
2011-08-15 23:45 . 2011-07-06 15:31 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-15 23:45 . 2011-04-29 13:24 79872 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-08-15 23:45 . 2011-04-29 13:24 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-08-15 23:45 . 2011-04-21 13:58 273408 ----a-w- c:\windows\system32\drivers\afd.sys
2011-08-15 23:45 . 2010-12-17 15:45 2067968 ----a-w- c:\windows\system32\mstscax.dll
2011-08-15 23:45 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-08-15 23:45 . 2011-06-17 20:13 905104 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-15 23:45 . 2011-06-20 08:54 3602832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-08-15 23:45 . 2011-06-20 08:54 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-08-15 23:40 . 2011-04-29 15:59 276992 ----a-w- c:\windows\system32\schannel.dll
2011-08-15 23:36 . 2011-08-16 23:43 -------- d-----w- c:\program files\Common Files\Symantec Shared
2011-08-15 23:36 . 2011-08-16 23:18 126584 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-08-15 23:36 . 2011-08-16 23:18 -------- d-----w- c:\program files\Symantec
2011-08-15 23:36 . 2011-08-16 23:37 -------- d-----w- c:\windows\system32\drivers\NIS
2011-08-15 23:36 . 2011-08-15 23:36 -------- d-----w- c:\program files\Norton Internet Security
2011-08-15 23:36 . 2011-08-15 23:37 -------- d-----w- c:\programdata\Norton
2011-08-15 23:36 . 2011-08-15 23:36 -------- d-----w- c:\program files\NortonInstaller
2011-08-15 23:35 . 2011-08-15 23:35 -------- d-----w- c:\program files\Microsoft.NET
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-17 00:00 . 2008-10-23 12:05 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-08-17 00:00 . 2008-10-23 12:05 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-07-08 07:31 . 2011-08-16 23:19 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-10 2153472]
"FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2010-08-09 248832]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-25 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-25 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-25 141848]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"TkBellExe"="c:\program files\real\realplayer\Update\realsched.exe" [2011-08-17 273544]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2011-4-19 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]
R3 MOSUMAC;USB-Ethernet Driver;c:\windows\system32\DRIVERS\MOSUMAC.SYS [2009-12-10 43520]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1206000.01D\SYMDS.SYS [2011-01-27 340088]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1206000.01D\SYMEFA.SYS [2011-03-15 744568]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110812.001\BHDrvx86.sys [2011-07-22 815736]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20110815.030\IDSvix86.sys [2011-08-12 367736]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1206000.01D\Ironx86.SYS [2011-01-27 136312]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\NIS\1206000.01D\SYMTDIV.SYS [2011-03-22 331384]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe [2011-04-17 130008]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [2011-04-19 993848]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [2011-04-19 399416]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-08-16 105592]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 15544]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.visagecomputers.co.uk/
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\3jxbff1v.default\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre7\bin\jusched.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-08-16 23:24
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\18.6.0.29\diMaster.dll\" /prefetch:1"
.
------------------------ Other Running Processes ------------------------
.
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2011-08-16 23:26:29 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-16 22:26
.
Pre-Run: 273,366,630,400 bytes free
Post-Run: 273,264,934,912 bytes free
.
- - End Of File - - C241156BEE8D296E1B010743AFBAA63F