juibre
Topic Starter
Hi guys can somebody please have a look at my logs.My laptop keeps freezing all pages from firefox to wordpad,etc every couple of minutes.Ive downloaded nothing new recently and have had clear reports from norton,etc.
Thanks
ComboFix 10-02-05.02 - Brian 05/02/2010 23:50:06.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.502.193 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton 360 *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\restore
c:\windows\AegisP.inf
.
((((((((((((((((((((((((( Files Created from 2010-01-05 to 2010-02-05 )))))))))))))))))))))))))))))))
.
2010-02-05 22:34 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\Scxpx86.dll
2010-02-05 22:34 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSvix86.sys
2010-02-05 22:34 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSXpx86.sys
2010-02-05 22:34 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSxpx86.dll
2010-02-05 22:34 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSviA64.sys
2010-02-05 18:37 . 2009-12-29 20:50 165240 —-a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2010-02-05 18:04 . 2010-02-05 18:04 ——– d—–w- c:\program files\iPod
2010-02-05 18:03 . 2010-02-05 18:05 ——– d—–w- c:\program files\iTunes
2010-02-05 17:41 . 2010-02-05 17:41 72488 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-05 16:50 . 2010-02-03 09:00 1324720 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\NAVEX15.SYS
2010-02-05 16:50 . 2009-12-29 06:58 177520 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\NAVENG32.DLL
2010-02-05 16:50 . 2009-12-29 06:58 1647984 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\NAVEX32A.DLL
2010-02-05 16:50 . 2010-02-03 09:00 84912 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\NAVENG.SYS
2010-02-05 16:50 . 2009-12-29 06:58 371248 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\EECTRL.SYS
2010-02-05 16:50 . 2009-12-29 06:58 2747440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\CCERASER.DLL
2010-02-05 16:50 . 2009-12-29 06:58 259440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\ECMSVR32.DLL
2010-02-05 16:50 . 2009-12-29 06:58 102448 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\ERASER.SYS
2010-01-30 05:37 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSXpx86.sys
2010-01-30 05:37 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\Scxpx86.dll
2010-01-30 05:37 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSxpx86.dll
2010-01-30 05:37 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSvix86.sys
2010-01-30 05:37 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSviA64.sys
2010-01-27 19:47 . 2010-01-27 19:47 ——– d—–w- c:\program files\Common Files\Java
2010-01-27 19:47 . 2010-01-27 19:47 503808 —-a-w- c:\documents and settings\Brian\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-325ae5ae-n\msvcp71.dll
2010-01-27 19:47 . 2010-01-27 19:47 499712 —-a-w- c:\documents and settings\Brian\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-325ae5ae-n\jmc.dll
2010-01-27 19:47 . 2010-01-27 19:47 348160 —-a-w- c:\documents and settings\Brian\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-325ae5ae-n\msvcr71.dll
2010-01-27 19:47 . 2010-01-27 19:47 61440 —-a-w- c:\documents and settings\Brian\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-75dff2b4-n\decora-sse.dll
2010-01-27 19:47 . 2010-01-27 19:47 12800 —-a-w- c:\documents and settings\Brian\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-75dff2b4-n\decora-d3d.dll
2010-01-07 14:57 . 2010-01-07 15:32 ——– d—–w- c:\documents and settings\Brian\Application Data\TS3Client
2010-01-07 14:53 . 2010-01-07 14:53 ——– d—–w- c:\program files\TeamSpeak 3 Client
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 21:06 . 2009-02-28 16:06 ——– d—–w- c:\documents and settings\Brian\Application Data\teamspeak2
2010-02-05 18:04 . 2008-07-29 18:49 ——– d—–w- c:\program files\Common Files\Apple
2010-02-05 17:55 . 2009-09-18 16:54 ——– d—–w- c:\program files\QuickTime
2010-02-05 16:39 . 2009-02-15 17:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-02-02 17:26 . 2009-10-30 17:34 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-02 17:24 . 2009-12-05 12:58 5115824 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-02-02 17:21 . 2008-07-29 18:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-30 21:31 . 2009-02-15 17:47 ——– d—–w- c:\program files\Google
2010-01-27 19:46 . 2009-02-16 20:00 ——– d—–w- c:\program files\Java
2010-01-07 16:07 . 2009-10-30 17:35 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 16:07 . 2009-10-30 17:35 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-30 19:21 . 2009-12-30 19:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-12-29 21:32 . 2009-12-29 20:50 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-12-29 20:50 . 2009-12-29 20:50 ——– d—–w- c:\program files\Symantec
2009-12-29 20:50 . 2009-12-29 20:50 7456 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-12-29 20:50 . 2009-12-29 20:50 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2009-12-29 20:50 . 2009-12-29 20:50 806 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-12-29 20:50 . 2009-12-29 20:50 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-12-29 20:50 . 2009-12-29 20:50 36400 —-a-r- c:\windows\system32\drivers\SymIM.sys
2009-12-29 20:50 . 2008-01-29 11:01 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-12-29 20:50 . 2009-12-29 20:50 1291104 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-12-29 20:50 . 2009-12-29 20:50 136840 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2009-12-29 20:50 . 2008-01-29 11:02 107368 —-a-r- c:\windows\system32\GEARAspi.dll
2009-12-29 20:49 . 2009-12-29 20:51 554352 —-a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
2009-12-29 20:49 . 2009-12-29 20:49 771440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-12-29 20:49 . 2009-12-29 20:49 ——– d—–w- c:\program files\Norton 360
2009-12-29 20:49 . 2009-12-29 20:49 ——– d—–w- c:\program files\Windows Sidebar
2009-12-29 20:49 . 2009-12-29 20:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-12-29 20:48 . 2009-12-29 20:46 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-12-29 20:46 . 2009-12-29 20:46 ——– d—–w- c:\program files\NortonInstaller
2009-12-27 02:41 . 2008-07-29 18:05 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-21 19:14 . 2002-08-29 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-17 17:14 . 2009-02-16 20:01 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-07 20:18 . 2009-12-07 20:18 152576 —-a-w- c:\documents and settings\Brian\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-07 20:17 . 2009-12-07 20:17 79488 —-a-w- c:\documents and settings\Brian\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-21 15:51 . 2002-08-29 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-07-14 00:16 . 2009-07-14 00:16 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-07-14 00:16 . 2009-07-14 00:16 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 995328]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 1101824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0308000.029\SymEFA.sys [02/02/2010 08:32 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0308000.029\BHDrvx86.sys [02/02/2010 08:31 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0308000.029\cchpx86.sys [02/02/2010 08:31 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSXpx86.sys [05/02/2010 22:34 329592]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe [02/02/2010 08:31 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [29/12/2009 06:58 102448]
S2 gupdate1c98f95aa54a886;Google Update Service (gupdate1c98f95aa54a886);c:\program files\Google\Update\GoogleUpdate.exe [15/02/2009 17:48 133104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-02-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-02-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-15 16:13]
2010-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 17:48]
2010-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 17:48]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Brian\Application Data\Mozilla\Firefox\Profiles\djm6tmvi.default\
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\documents and settings\Brian\Application Data\Mozilla\Firefox\Profiles\djm6tmvi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-CTFMON - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-05 23:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.8.0.41\diMaster.dll\" /prefetch:1"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1280)
c:\windows\system32\netprovcredman.dll
.
Completion time: 2010-02-05 23:58:59
ComboFix-quarantined-files.txt 2010-02-05 23:58
Pre-Run: 8,708,423,680 bytes free
Post-Run: 8,893,964,288 bytes free
- - End Of File - - 55076AE507A16A869487BFEE534DC700
Thanks
ComboFix 10-02-05.02 - Brian 05/02/2010 23:50:06.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.502.193 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton 360 *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\restore
c:\windows\AegisP.inf
.
((((((((((((((((((((((((( Files Created from 2010-01-05 to 2010-02-05 )))))))))))))))))))))))))))))))
.
2010-02-05 22:34 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\Scxpx86.dll
2010-02-05 22:34 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSvix86.sys
2010-02-05 22:34 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSXpx86.sys
2010-02-05 22:34 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSxpx86.dll
2010-02-05 22:34 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSviA64.sys
2010-02-05 18:37 . 2009-12-29 20:50 165240 —-a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2010-02-05 18:04 . 2010-02-05 18:04 ——– d—–w- c:\program files\iPod
2010-02-05 18:03 . 2010-02-05 18:05 ——– d—–w- c:\program files\iTunes
2010-02-05 17:41 . 2010-02-05 17:41 72488 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-05 16:50 . 2010-02-03 09:00 1324720 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\NAVEX15.SYS
2010-02-05 16:50 . 2009-12-29 06:58 177520 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\NAVENG32.DLL
2010-02-05 16:50 . 2009-12-29 06:58 1647984 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\NAVEX32A.DLL
2010-02-05 16:50 . 2010-02-03 09:00 84912 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\NAVENG.SYS
2010-02-05 16:50 . 2009-12-29 06:58 371248 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\EECTRL.SYS
2010-02-05 16:50 . 2009-12-29 06:58 2747440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\CCERASER.DLL
2010-02-05 16:50 . 2009-12-29 06:58 259440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\ECMSVR32.DLL
2010-02-05 16:50 . 2009-12-29 06:58 102448 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100205.002\ERASER.SYS
2010-01-30 05:37 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSXpx86.sys
2010-01-30 05:37 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\Scxpx86.dll
2010-01-30 05:37 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSxpx86.dll
2010-01-30 05:37 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSvix86.sys
2010-01-30 05:37 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSviA64.sys
2010-01-27 19:47 . 2010-01-27 19:47 ——– d—–w- c:\program files\Common Files\Java
2010-01-27 19:47 . 2010-01-27 19:47 503808 —-a-w- c:\documents and settings\Brian\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-325ae5ae-n\msvcp71.dll
2010-01-27 19:47 . 2010-01-27 19:47 499712 —-a-w- c:\documents and settings\Brian\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-325ae5ae-n\jmc.dll
2010-01-27 19:47 . 2010-01-27 19:47 348160 —-a-w- c:\documents and settings\Brian\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-325ae5ae-n\msvcr71.dll
2010-01-27 19:47 . 2010-01-27 19:47 61440 —-a-w- c:\documents and settings\Brian\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-75dff2b4-n\decora-sse.dll
2010-01-27 19:47 . 2010-01-27 19:47 12800 —-a-w- c:\documents and settings\Brian\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-75dff2b4-n\decora-d3d.dll
2010-01-07 14:57 . 2010-01-07 15:32 ——– d—–w- c:\documents and settings\Brian\Application Data\TS3Client
2010-01-07 14:53 . 2010-01-07 14:53 ——– d—–w- c:\program files\TeamSpeak 3 Client
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 21:06 . 2009-02-28 16:06 ——– d—–w- c:\documents and settings\Brian\Application Data\teamspeak2
2010-02-05 18:04 . 2008-07-29 18:49 ——– d—–w- c:\program files\Common Files\Apple
2010-02-05 17:55 . 2009-09-18 16:54 ——– d—–w- c:\program files\QuickTime
2010-02-05 16:39 . 2009-02-15 17:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-02-02 17:26 . 2009-10-30 17:34 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-02 17:24 . 2009-12-05 12:58 5115824 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-02-02 17:21 . 2008-07-29 18:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-30 21:31 . 2009-02-15 17:47 ——– d—–w- c:\program files\Google
2010-01-27 19:46 . 2009-02-16 20:00 ——– d—–w- c:\program files\Java
2010-01-07 16:07 . 2009-10-30 17:35 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 16:07 . 2009-10-30 17:35 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-30 19:21 . 2009-12-30 19:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-12-29 21:32 . 2009-12-29 20:50 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-12-29 20:50 . 2009-12-29 20:50 ——– d—–w- c:\program files\Symantec
2009-12-29 20:50 . 2009-12-29 20:50 7456 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-12-29 20:50 . 2009-12-29 20:50 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2009-12-29 20:50 . 2009-12-29 20:50 806 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-12-29 20:50 . 2009-12-29 20:50 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-12-29 20:50 . 2009-12-29 20:50 36400 —-a-r- c:\windows\system32\drivers\SymIM.sys
2009-12-29 20:50 . 2008-01-29 11:01 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-12-29 20:50 . 2009-12-29 20:50 1291104 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-12-29 20:50 . 2009-12-29 20:50 136840 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2009-12-29 20:50 . 2008-01-29 11:02 107368 —-a-r- c:\windows\system32\GEARAspi.dll
2009-12-29 20:49 . 2009-12-29 20:51 554352 —-a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
2009-12-29 20:49 . 2009-12-29 20:49 771440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-12-29 20:49 . 2009-12-29 20:49 ——– d—–w- c:\program files\Norton 360
2009-12-29 20:49 . 2009-12-29 20:49 ——– d—–w- c:\program files\Windows Sidebar
2009-12-29 20:49 . 2009-12-29 20:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-12-29 20:48 . 2009-12-29 20:46 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-12-29 20:46 . 2009-12-29 20:46 ——– d—–w- c:\program files\NortonInstaller
2009-12-27 02:41 . 2008-07-29 18:05 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-21 19:14 . 2002-08-29 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-17 17:14 . 2009-02-16 20:01 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-07 20:18 . 2009-12-07 20:18 152576 —-a-w- c:\documents and settings\Brian\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-07 20:17 . 2009-12-07 20:17 79488 —-a-w- c:\documents and settings\Brian\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-21 15:51 . 2002-08-29 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-07-14 00:16 . 2009-07-14 00:16 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-07-14 00:16 . 2009-07-14 00:16 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 995328]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 1101824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0308000.029\SymEFA.sys [02/02/2010 08:32 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0308000.029\BHDrvx86.sys [02/02/2010 08:31 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0308000.029\cchpx86.sys [02/02/2010 08:31 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSXpx86.sys [05/02/2010 22:34 329592]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe [02/02/2010 08:31 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [29/12/2009 06:58 102448]
S2 gupdate1c98f95aa54a886;Google Update Service (gupdate1c98f95aa54a886);c:\program files\Google\Update\GoogleUpdate.exe [15/02/2009 17:48 133104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-02-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-02-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-15 16:13]
2010-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 17:48]
2010-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 17:48]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Brian\Application Data\Mozilla\Firefox\Profiles\djm6tmvi.default\
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\documents and settings\Brian\Application Data\Mozilla\Firefox\Profiles\djm6tmvi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-CTFMON - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-05 23:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.8.0.41\diMaster.dll\" /prefetch:1"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1280)
c:\windows\system32\netprovcredman.dll
.
Completion time: 2010-02-05 23:58:59
ComboFix-quarantined-files.txt 2010-02-05 23:58
Pre-Run: 8,708,423,680 bytes free
Post-Run: 8,893,964,288 bytes free
- - End Of File - - 55076AE507A16A869487BFEE534DC700