Hi Broni,
Ok, so I uninstalled the Zynga Toolbar and it directed me to reboot, which i did.
I ran MBR and ComoboFix and the logs are below. Keeping my fingers crossed.
Thanks again
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: Quanta
BIOS Manufacturer: Hewlett-Packard
System Manufacturer: Hewlett-Packard
System Product Name: HP Pavilion dv9500 Notebook PC
Logical Drives Mask: 0x0000007c
Kernel Drivers (total 177):
0x81C05000 \SystemRoot\system32\ntkrnlpa.exe
0x81FBE000 \SystemRoot\system32\hal.dll
0x80409000 \SystemRoot\system32\kdcom.dll
0x80410000 \SystemRoot\system32\PSHED.dll
0x80421000 \SystemRoot\system32\BOOTVID.dll
0x80429000 \SystemRoot\system32\CLFS.SYS
0x8046A000 \SystemRoot\system32\CI.dll
0x8054A000 \SystemRoot\system32\drivers\Wdf01000.sys
0x805C6000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8060C000 \SystemRoot\system32\drivers\acpi.sys
0x80652000 \SystemRoot\system32\drivers\WMILIB.SYS
0x8065B000 \SystemRoot\system32\drivers\msisadrv.sys
0x80663000 \SystemRoot\system32\drivers\pci.sys
0x8068A000 \SystemRoot\System32\drivers\partmgr.sys
0x80699000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x8069C000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x806A6000 \SystemRoot\system32\drivers\volmgr.sys
0x806B5000 \SystemRoot\System32\drivers\volmgrx.sys
0x806FF000 \SystemRoot\system32\drivers\pciide.sys
0x80706000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x80714000 \SystemRoot\System32\drivers\mountmgr.sys
0x80724000 \SystemRoot\system32\drivers\atapi.sys
0x8072C000 \SystemRoot\system32\drivers\ataport.SYS
0x8074A000 \SystemRoot\system32\drivers\fltmgr.sys
0x8077C000 \SystemRoot\system32\drivers\fileinfo.sys
0x8078C000 \SystemRoot\system32\drivers\N360\0308000.029\SYMEFA.SYS
0x807DB000 \SystemRoot\System32\Drivers\PxHelp20.sys
0x82208000 \SystemRoot\System32\Drivers\ksecdd.sys
0x82279000 \SystemRoot\system32\drivers\ndis.sys
0x82384000 \SystemRoot\system32\drivers\msrpc.sys
0x823AF000 \SystemRoot\system32\drivers\NETIO.SYS
0x87600000 \SystemRoot\System32\drivers\tcpip.sys
0x876EA000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8780F000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8791F000 \SystemRoot\system32\drivers\volsnap.sys
0x87958000 \SystemRoot\System32\Drivers\spldr.sys
0x87960000 \SystemRoot\System32\Drivers\mup.sys
0x8796F000 \SystemRoot\System32\drivers\ecache.sys
0x87996000 \SystemRoot\system32\drivers\disk.sys
0x879A7000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x879C8000 \SystemRoot\system32\drivers\crcdisk.sys
0x879F1000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x87800000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x87705000 \SystemRoot\system32\DRIVERS\amdk8.sys
0x87809000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x879FC000 \SystemRoot\system32\DRIVERS\cpqbttn.sys
0x87715000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x87725000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8772C000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x87735000 \SystemRoot\system32\DRIVERS\nvsmu.sys
0x87738000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x87742000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x87780000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8778F000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x877A7000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
0x8BA08000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8BA95000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x8BAA5000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x8BAB3000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x8BACD000 \SystemRoot\system32\DRIVERS\rimmptsk.sys
0x8BADC000 \SystemRoot\system32\DRIVERS\rimsptsk.sys
0x8BAF0000 \SystemRoot\system32\DRIVERS\rixdptsk.sys
0x8BC0B000 \SystemRoot\system32\DRIVERS\nvmfdx32.sys
0x8BD0C000 \SystemRoot\system32\DRIVERS\bcmwl6.sys
0x8C004000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8C746000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8C7E7000 \SystemRoot\System32\drivers\watchdog.sys
0x8BD92000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8C7F3000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8BDA5000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8C7FE000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8BDD0000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8BB41000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8BB70000 \SystemRoot\system32\DRIVERS\storport.sys
0x8BDDB000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8BDE6000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8BC00000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8BBB1000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8BBD4000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8BBE3000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x877AD000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x877C2000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8C000000 \SystemRoot\system32\DRIVERS\swenum.sys
0x877D2000 \SystemRoot\system32\DRIVERS\ks.sys
0x823EA000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x807E4000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8BBF7000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x8D203000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8D238000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8D249000 \SystemRoot\system32\drivers\CHDART.sys
0x8D275000 \SystemRoot\system32\drivers\portcls.sys
0x8D2A2000 \SystemRoot\system32\drivers\drmk.sys
0x8D2C7000 \SystemRoot\system32\DRIVERS\HSXHWAZL.sys
0x8D601000 \SystemRoot\system32\DRIVERS\HSX_DPV.sys
0x8D704000 \SystemRoot\system32\DRIVERS\HSX_CNXT.sys
0x8D7B8000 \SystemRoot\system32\drivers\modem.sys
0x8D7C5000 \SystemRoot\System32\Drivers\x10uif.sys
0x8D7C8000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x8D7D1000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8D7E8000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x8D7F0000 \SystemRoot\system32\DRIVERS\usbscan.sys
0x8D304000 \SystemRoot\system32\DRIVERS\usbprint.sys
0x8D30E000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x8D323000 \SystemRoot\System32\Drivers\usbvideo.sys
0x8D344000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8D34D000 \SystemRoot\System32\Drivers\Null.SYS
0x8D354000 \SystemRoot\System32\Drivers\Beep.SYS
0x8D35B000 \SystemRoot\System32\drivers\vga.sys
0x8D367000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8D388000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8D390000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8D398000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8D3A3000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8D3B1000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8D3BA000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8DA03000 \SystemRoot\System32\Drivers\N360\0308000.029\SYMTDI.SYS
0x8DA37000 \??\C:\Windows\system32\Drivers\SYMEVENT.SYS
0x8DA5C000 \SystemRoot\System32\Drivers\N360\0308000.029\SYMNDISV.SYS
0x8DA6A000 \SystemRoot\System32\Drivers\N360\0308000.029\SYMFW.SYS
0x8DA7F000 \SystemRoot\system32\DRIVERS\smb.sys
0x8DA93000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8DAC5000 \SystemRoot\system32\drivers\afd.sys
0x8DB0D000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8DB23000 \SystemRoot\system32\DRIVERS\SymIMv.sys
0x8DB2C000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8DB3A000 \SystemRoot\system32\DRIVERS\eabfiltr.sys
0x8DB3C000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8DB4F000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0x8DB55000 \SystemRoot\system32\drivers\N360\0308000.029\SRTSPX.SYS
0x8DB5F000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8DB9B000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8DBA5000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20110107.002\IDSvix86.sys
0x8E208000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
0x8E266000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
0x8E283000 \SystemRoot\System32\Drivers\dfsc.sys
0x8E29A000 \SystemRoot\System32\Drivers\N360\0308000.029\ccHPx86.sys
0x8E315000 \SystemRoot\System32\Drivers\N360\0308000.029\BHDrvx86.sys
0x8E357000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x8E361000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8E36E000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x8E379000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x97640000 \SystemRoot\System32\win32k.sys
0x8E381000 \SystemRoot\System32\drivers\Dxapi.sys
0x8E38B000 \SystemRoot\system32\DRIVERS\monitor.sys
0x97860000 \SystemRoot\System32\TSDDD.dll
0x97880000 \SystemRoot\System32\cdd.dll
0x97890000 \SystemRoot\System32\ATMFD.DLL
0x8E39A000 \SystemRoot\system32\drivers\luafv.sys
0x9C20E000 \SystemRoot\system32\drivers\spsys.sys
0x9C2BE000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x9C2CE000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x9C2F8000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x9C302000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9C315000 \SystemRoot\system32\drivers\HTTP.sys
0x9C382000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9C39F000 \SystemRoot\system32\DRIVERS\bowser.sys
0x9C3B8000 \SystemRoot\System32\drivers\mpsdrv.sys
0x9C3CD000 \SystemRoot\system32\drivers\mrxdav.sys
0x8E3BD000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x9E401000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x9E43A000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x9E452000 \SystemRoot\System32\DRIVERS\srv2.sys
0x9E47A000 \SystemRoot\System32\DRIVERS\srv.sys
0x9E4E0000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0x9E4E4000 \SystemRoot\system32\drivers\peauth.sys
0x9E5C2000 \SystemRoot\System32\Drivers\secdrv.SYS
0x9E5CC000 \SystemRoot\System32\drivers\tcpipreg.sys
0x9E5D8000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0x9E5ED000 \SystemRoot\system32\DRIVERS\WUDFPf.sys
0x9E4C8000 \SystemRoot\system32\DRIVERS\xaudio.sys
0x8E3DC000 \SystemRoot\system32\DRIVERS\cdfs.sys
0xAA407000 \SystemRoot\System32\Drivers\N360\0308000.029\SRTSP.SYS
0xAA45C000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20110110.004\NAVEX15.SYS
0xAA5A7000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20110110.004\NAVENG.SYS
0xAA5BB000 \??\C:\Users\Char\AppData\Local\Temp\catchme.sys
0xAA5C3000 \??\C:\Windows\system32\Drivers\PROCEXP113.SYS
0x774A0000 \WINDOWS\System32\ntdll.dll
Processes (total 72):
0 System Idle Process
4 System
432 C:\WINDOWS\System32\smss.exe
508 csrss.exe
560 C:\WINDOWS\System32\wininit.exe
568 csrss.exe
604 C:\WINDOWS\System32\services.exe
616 C:\WINDOWS\System32\lsass.exe
628 C:\WINDOWS\System32\lsm.exe
704 C:\WINDOWS\System32\winlogon.exe
800 C:\WINDOWS\System32\svchost.exe
852 C:\WINDOWS\System32\nvvsvc.exe
880 C:\WINDOWS\System32\svchost.exe
944 C:\WINDOWS\System32\svchost.exe
1016 C:\WINDOWS\System32\svchost.exe
1076 C:\WINDOWS\System32\svchost.exe
1148 C:\WINDOWS\System32\audiodg.exe
1172 C:\WINDOWS\System32\svchost.exe
1192 C:\WINDOWS\System32\SLsvc.exe
1268 C:\WINDOWS\System32\svchost.exe
1472 C:\WINDOWS\System32\svchost.exe
1760 C:\WINDOWS\System32\spoolsv.exe
1768 C:\WINDOWS\System32\taskeng.exe
1792 C:\WINDOWS\System32\svchost.exe
1880 C:\WINDOWS\System32\taskeng.exe
320 C:\WINDOWS\System32\dwm.exe
1616 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
788 C:\Program Files\HP\QuickPlay\QPService.exe
1608 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
2020 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
1932 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
672 C:\Program Files\Lexmark 5400 Series\lxctmon.exe
2204 C:\Program Files\SnapStream Media\Firefly\Firefly.exe
2212 C:\Program Files\HP\HP Software Update\hpwuschd2.exe
2232 C:\Program Files\Common Files\Java\Java Update\jusched.exe
2280 C:\Program Files\iTunes\iTunesHelper.exe
2292 C:\Program Files\DivX\DivX Update\DivXUpdate.exe
2300 C:\Program Files\winsim\ConnectionManager\Simply.SystemTrayIcon.exe
2316 C:\Program Files\Windows Sidebar\sidebar.exe
2336 C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
2464 C:\Program Files\Skype\Phone\Skype.exe
2504 C:\Program Files\Windows Media Player\wmpnscfg.exe
2648 C:\Program Files\Windows Sidebar\sidebar.exe
2708 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
2792 C:\Program Files\Bonjour\mDNSResponder.exe
2812 C:\WINDOWS\System32\svchost.exe
2844 C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
3096 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
3120 C:\WINDOWS\System32\lxctcoms.exe
3192 C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
3308 C:\WINDOWS\System32\svchost.exe
3848 dllhost.exe
3924 C:\Program Files\Skype\Plugin Manager\skypePM.exe
2428 C:\WINDOWS\System32\svchost.exe
452 C:\WINDOWS\System32\svchost.exe
3004 C:\WINDOWS\System32\SearchIndexer.exe
3516 C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
3920 WUDFHost.exe
5080 C:\PROGRA~1\COMMON~1\SNAPST~1\Common\X10nets.exe
5128 C:\WINDOWS\System32\mobsync.exe
5200 WmiPrvSE.exe
5476 C:\Program Files\Windows Media Player\wmpnetwk.exe
5928 C:\Program Files\iPod\bin\iPodService.exe
6000 C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
6016 C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
4428 C:\WINDOWS\System32\wbem\WmiApSrv.exe
5224 C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
5400 C:\WINDOWS\System32\conime.exe
1944 C:\WINDOWS\System32\SearchProtocolHost.exe
4328 C:\WINDOWS\System32\SearchFilterHost.exe
5600 C:\WINDOWS\explorer.exe
2672 C:\Users\Char\Desktop\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)
\\.\E: --> \\.\PhysicalDrive0 at offset 0x0000001a`1accfe00 (NTFS)
PhysicalDrive0 Model Number: ST9120822AS, Rev: 3.BHE
PhysicalDrive1 Model Number: WDCWD800BEVS-60RST0, Rev: 04.01G04
Size Device Name MBR Status
--------------------------------------------
111 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: D94F393960D1CD66C2071F2D7260A5196DF105AC
74 GB \\.\PhysicalDrive1 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Done!
ComboFix 11-01-10.04 - Char 10/01/2011 17:48:27.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.1982.1063 [GMT -8:00]
Running from: c:\users\Char\Desktop\ComboFix.exe
AV: Norton 360 *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
FW: Norton 360 *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
SP: Norton 360 *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2010-12-11 to 2011-01-11 )))))))))))))))))))))))))))))))
.
2011-01-11 02:00 . 2011-01-11 02:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-08 03:05 . 2007-03-22 17:36 43584 ------w- c:\windows\system32\drivers\avipbb.sys
2011-01-08 03:05 . 2011-01-08 03:05 -------- d-----w- c:\program files\Avira GmbH
2011-01-08 03:04 . 2003-02-28 00:12 696320 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll
2011-01-08 03:04 . 2002-12-05 22:10 155648 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll
2011-01-08 03:04 . 2002-12-02 23:22 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
2011-01-08 03:04 . 2002-12-02 21:33 57344 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll
2011-01-08 03:04 . 2002-12-02 21:33 237568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll
2011-01-08 03:04 . 2011-01-08 03:04 282756 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll
2011-01-08 03:04 . 2011-01-08 03:04 163972 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll
2011-01-07 07:20 . 2011-01-07 07:20 -------- d-----w- c:\program files\Conduit
2011-01-07 04:39 . 2011-01-07 06:48 -------- d-----w- c:\program files\Gamers Unite! Snag Bar
2011-01-07 04:14 . 2011-01-07 04:14 -------- d-----w- c:\users\Char\AppData\Local\ElevatedDiagnostics
2011-01-07 04:06 . 2011-01-07 04:10 -------- d-----w- c:\program files\Microsoft ATS
2011-01-06 11:23 . 2011-01-06 11:23 -------- d-----w- c:\users\Char\AppData\Local\Symantec
2011-01-06 01:46 . 2011-01-06 01:46 -------- d-----w- c:\users\Char\AppData\Roaming\CleanMyPC Software
2011-01-05 01:32 . 2011-01-05 01:32 49152 --sha-r- c:\windows\system32\sbeioi.dll
2011-01-04 23:04 . 2011-01-04 23:04 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2011-01-04 23:04 . 2011-01-05 00:53 -------- d-----w- c:\programdata\Rosetta Stone
2011-01-04 23:04 . 2011-01-04 23:04 -------- d-----w- c:\program files\Rosetta Stone
2011-01-04 20:07 . 2011-01-04 20:07 -------- d-----w- c:\windows\Crystal
2011-01-04 20:07 . 2011-01-04 20:07 -------- d-----w- c:\program files\Seagate Software
2011-01-04 20:07 . 2011-01-04 20:07 -------- d-----w- c:\program files\Common Files\AnswerWorks 5.0
2011-01-04 20:04 . 2011-01-04 20:07 -------- d-----w- c:\program files\Simply Accounting Enterprise 2010
2011-01-04 10:05 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C2AE2FC8-6BB3-47C1-B0B5-9B38FCA48491}\mpengine.dll
2010-12-17 02:08 . 2010-12-17 02:08 -------- d-----w- c:\users\Char\AppData\Roaming\Malwarebytes
2010-12-17 02:08 . 2010-12-21 02:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-17 02:08 . 2010-12-21 02:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-17 02:08 . 2010-12-17 02:08 -------- d-----w- c:\programdata\Malwarebytes
2010-12-17 02:08 . 2011-01-04 06:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-15 00:11 . 2010-10-28 13:20 2048 ----a-w- c:\windows\system32\tzres.dll
2010-12-15 00:11 . 2010-11-03 10:51 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2010-12-13 23:02 . 2010-12-13 23:02 -------- d-----w- c:\users\Char\AppData\Local\Sage Software
2010-12-13 22:35 . 2011-01-07 07:33 -------- d-----w- c:\users\Char\AppData\Local\Simply Accounting
2010-12-13 22:30 . 2011-01-04 20:10 -------- d-----w- c:\program files\winsim
2010-12-12 18:26 . 2010-12-12 18:38 -------- d-----w- c:\programdata\WinZip
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-11 00:55 . 2010-03-09 03:43 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2010-11-13 02:53 . 2010-04-16 06:05 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-10-19 18:41 . 2010-01-16 06:38 222080 ------w- c:\windows\system32\MpSigStub.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{b843a48a-b70f-45cd-a15a-6c2b30c2c11e}"= "c:\program files\Gamers Unite! Snag Bar\Helper.dll" [2011-01-07 356864]
[HKEY_CLASSES_ROOT\clsid\{b843a48a-b70f-45cd-a15a-6c2b30c2c11e}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{E2A57EE8-6A26-499F-95F8-A96E5C3BE17E}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{26A7CA19-7D58-411D-B2DA-F1B0324CBFFC}]
2011-01-07 06:48 1536000 ----a-w- c:\program files\Gamers Unite! Snag Bar\Toolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{25515A79-C1C7-4B97-97F8-31A711694487}"= "c:\program files\Gamers Unite! Snag Bar\Toolbar.dll" [2011-01-07 1536000]
[HKEY_CLASSES_ROOT\clsid\{25515a79-c1c7-4b97-97f8-31a711694487}]
[HKEY_CLASSES_ROOT\FCTB000062781.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{017D1380-106D-43D5-97DC-81E8A527FD73}]
[HKEY_CLASSES_ROOT\FCTB000062781.IEToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{25515A79-C1C7-4B97-97F8-31A711694487}"= "c:\program files\Gamers Unite! Snag Bar\Toolbar.dll" [2011-01-07 1536000]
[HKEY_CLASSES_ROOT\clsid\{25515a79-c1c7-4b97-97f8-31a711694487}]
[HKEY_CLASSES_ROOT\FCTB000062781.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{017D1380-106D-43D5-97DC-81E8A527FD73}]
[HKEY_CLASSES_ROOT\FCTB000062781.IEToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 484904]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-20 26192680]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-29 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 827392]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-04-24 176128]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-04 13556256]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-04 92704]
"lxctmon.exe"="c:\program files\Lexmark 5400 Series\lxctmon.exe" [2007-03-19 291760]
"Lexmark 5400 Series Fax Server"="c:\program files\Lexmark 5400 Series\fm3032.exe" [2007-03-19 304048]
"EzPrint"="c:\program files\Lexmark 5400 Series\ezprint.exe" [2007-03-19 82864]
"LXCTCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll" [2006-11-21 106496]
"CorelDRAW Graphics Suite 11b"="c:\program files\Corel\Corel Graphics 12\Languages\EN\Programs\registration.exe" [2003-11-25 729088]
"Firefly"="c:\program files\SnapStream Media\Firefly\Firefly.exe" [2006-06-06 180224]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-11-11 421160]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
"ConnectionManager"="c:\program files\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe" [2009-08-23 91432]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-21 963976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
R2 Simply Accounting Database Connection Manager;Simply Accounting Database Connection Manager;c:\program files\Winsim\ConnectionManager\SimplyConnectionManager.exe [2009-08-23 29992]
R3 Simply Accounting Transaction Manager 2010 - CDN;Simply Accounting Transaction Manager 2010 - CDN;c:\program files\Winsim\TransactionManager2010 - CDN\Sage_SA.TransactionManager.exe [2009-08-23 42280]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0308000.029\SYMEFA.SYS [2010-01-15 310320]
S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys [2010-01-15 259632]
S1 ccHP;Symantec Hash Provider;c:\windows\System32\Drivers\N360\0308000.029\ccHPx86.sys [2010-01-15 482432]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20110107.002\IDSvix86.sys [2010-11-09 353912]
S2 N360;Norton 360;c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe [2010-01-15 117640]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-05-26 102448]
S3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS [2010-01-15 48688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-04-19 20:23 452136 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2011-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 12:10]
2011-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 12:10]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-01-10 18:00
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCTCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.8.0.41\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-01-10 18:03:12
ComboFix-quarantined-files.txt 2011-01-11 02:03
ComboFix2.txt 2011-01-11 01:31
Pre-Run: 47,252,733,952 bytes free
Post-Run: 47,228,243,968 bytes free
- - End Of File - - 93B4F3BB23979822018DA53204787C34