Combofix log
ComboFix 10-02-20.01 - Tool 01/01/2003 0:42.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.831 [GMT -7:00]
Running from: c:\documents and settings\Tool\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\Mozilla Firefox\searchplugins\search.xml
c:\recycler\NPROTECT
c:\recycler\NPROTECT\00000000.DAT
c:\recycler\NPROTECT\00000001.DAT
c:\recycler\NPROTECT\00000002
c:\recycler\NPROTECT\00000003
c:\recycler\NPROTECT\00000004
c:\recycler\NPROTECT\00000005
c:\recycler\NPROTECT\00000007
c:\recycler\NPROTECT\00000009
c:\recycler\NPROTECT\00000010
c:\recycler\NPROTECT\00000013.0
c:\recycler\NPROTECT\00000014
c:\recycler\NPROTECT\00000015
c:\recycler\NPROTECT\00000016.DAT
c:\recycler\NPROTECT\00000017
c:\recycler\NPROTECT\00000018
c:\recycler\NPROTECT\00000019
c:\recycler\NPROTECT\00000020
c:\recycler\NPROTECT\00000023
c:\recycler\NPROTECT\00000024.DAT
c:\recycler\NPROTECT\00000025
c:\recycler\NPROTECT\00000026
c:\recycler\NPROTECT\00000027.DAT
c:\recycler\NPROTECT\00000028
c:\recycler\NPROTECT\00000029
c:\recycler\NPROTECT\00000030
c:\recycler\NPROTECT\00000031
c:\recycler\NPROTECT\00000032
c:\recycler\NPROTECT\00000033
c:\recycler\NPROTECT\00000034
c:\recycler\NPROTECT\00000035
c:\recycler\NPROTECT\00000036
c:\recycler\NPROTECT\00000037
c:\recycler\NPROTECT\00000038
c:\recycler\NPROTECT\00000039
c:\recycler\NPROTECT\00000040
c:\recycler\NPROTECT\00000041.dat
c:\recycler\NPROTECT\00000042
c:\recycler\NPROTECT\00000043
c:\recycler\NPROTECT\00000046
c:\recycler\NPROTECT\00000047
c:\recycler\NPROTECT\00000048
c:\recycler\NPROTECT\00000049
c:\recycler\NPROTECT\00000050
c:\recycler\NPROTECT\00000051
c:\recycler\NPROTECT\00000052
c:\recycler\NPROTECT\00000053
c:\recycler\NPROTECT\00000054
c:\recycler\NPROTECT\00000056
c:\recycler\NPROTECT\00000058
c:\recycler\NPROTECT\00000059
c:\recycler\NPROTECT\00000060
c:\recycler\NPROTECT\00000061
c:\recycler\NPROTECT\00000062
c:\recycler\NPROTECT\00000063
c:\recycler\NPROTECT\00000064
c:\recycler\NPROTECT\00000065
c:\recycler\NPROTECT\00000066
c:\recycler\NPROTECT\00000067
c:\recycler\NPROTECT\00000068
c:\recycler\NPROTECT\00000069
c:\recycler\NPROTECT\00000070
c:\recycler\NPROTECT\00000071
c:\recycler\NPROTECT\00000072
c:\recycler\NPROTECT\00000073
c:\recycler\NPROTECT\00000074
c:\recycler\NPROTECT\00000075
c:\recycler\NPROTECT\00000076
c:\recycler\NPROTECT\00000078
c:\recycler\NPROTECT\00000079
c:\recycler\NPROTECT\00000080
c:\recycler\NPROTECT\00000082
c:\recycler\NPROTECT\00000083
c:\recycler\NPROTECT\00000084
c:\recycler\NPROTECT\00000085
c:\recycler\NPROTECT\00000087
c:\recycler\NPROTECT\00000089
c:\recycler\NPROTECT\00000090
c:\recycler\NPROTECT\00000092
c:\recycler\NPROTECT\00000093
c:\recycler\NPROTECT\00000094
c:\recycler\NPROTECT\00000095
c:\recycler\NPROTECT\00000096
c:\recycler\NPROTECT\00000098
c:\recycler\NPROTECT\00000099
c:\recycler\NPROTECT\00000100
c:\recycler\NPROTECT\00000101
c:\recycler\NPROTECT\00000103
c:\recycler\NPROTECT\00000104
c:\recycler\NPROTECT\00000105
c:\recycler\NPROTECT\00000107
c:\recycler\NPROTECT\00000108
c:\recycler\NPROTECT\00000109
c:\recycler\NPROTECT\00000111
c:\recycler\NPROTECT\00000112
c:\recycler\NPROTECT\00000113
c:\recycler\NPROTECT\00000114
c:\recycler\NPROTECT\00000115
c:\recycler\NPROTECT\00000116
c:\recycler\NPROTECT\00000117
c:\recycler\NPROTECT\00000118
c:\recycler\NPROTECT\00000119
c:\recycler\NPROTECT\00000120
c:\recycler\NPROTECT\00000121
c:\recycler\NPROTECT\00000122
c:\recycler\NPROTECT\00000123
c:\recycler\NPROTECT\00000125
c:\recycler\NPROTECT\00000126
c:\recycler\NPROTECT\00000127
c:\recycler\NPROTECT\00000128
c:\recycler\NPROTECT\00000130
c:\recycler\NPROTECT\00000131
c:\recycler\NPROTECT\00000132
c:\recycler\NPROTECT\00000133
c:\recycler\NPROTECT\00000134
c:\recycler\NPROTECT\00000135
c:\recycler\NPROTECT\00000136
c:\recycler\NPROTECT\00000137
c:\recycler\NPROTECT\00000138
c:\recycler\NPROTECT\00000140
c:\recycler\NPROTECT\00000141
c:\recycler\NPROTECT\00000143
c:\recycler\NPROTECT\00000144
c:\recycler\NPROTECT\00000146
c:\recycler\NPROTECT\00000147
c:\recycler\NPROTECT\00000148
c:\recycler\NPROTECT\00000149
c:\recycler\NPROTECT\00000150
c:\recycler\NPROTECT\00000152
c:\recycler\NPROTECT\00000153
c:\recycler\NPROTECT\00000154
c:\recycler\NPROTECT\00000156
c:\recycler\NPROTECT\00000157
c:\recycler\NPROTECT\00000159
c:\recycler\NPROTECT\00000160
c:\recycler\NPROTECT\00000162
c:\recycler\NPROTECT\00000163
c:\recycler\NPROTECT\00000164
c:\recycler\NPROTECT\00000165
c:\recycler\NPROTECT\00000166
c:\recycler\NPROTECT\00000167
c:\recycler\NPROTECT\00000168
c:\recycler\NPROTECT\00000169.DB-
c:\recycler\NPROTECT\00000170
c:\recycler\NPROTECT\00000171
c:\recycler\NPROTECT\00000172
c:\recycler\NPROTECT\00000173
c:\recycler\NPROTECT\00000174
c:\recycler\NPROTECT\00000175
c:\recycler\NPROTECT\00000176
c:\recycler\NPROTECT\00000177
c:\recycler\NPROTECT\00000178
c:\recycler\NPROTECT\00000180
c:\recycler\NPROTECT\00000182
c:\recycler\NPROTECT\00000183
c:\recycler\NPROTECT\00000184
c:\recycler\NPROTECT\00000185
c:\recycler\NPROTECT\00000187
c:\recycler\NPROTECT\00000188
c:\recycler\NPROTECT\00000189
c:\recycler\NPROTECT\00000191
c:\recycler\NPROTECT\00000192
c:\recycler\NPROTECT\00000194
c:\recycler\NPROTECT\00000195
c:\recycler\NPROTECT\00000196
c:\recycler\NPROTECT\00000197
c:\recycler\NPROTECT\00000198
c:\recycler\NPROTECT\00000200
c:\recycler\NPROTECT\00000201
c:\recycler\NPROTECT\00000202
c:\recycler\NPROTECT\00000203
c:\recycler\NPROTECT\00000204
c:\recycler\NPROTECT\00000205
c:\recycler\NPROTECT\00000206
c:\recycler\NPROTECT\00000208
c:\recycler\NPROTECT\00000210
c:\recycler\NPROTECT\00000211
c:\recycler\NPROTECT\00000212
c:\recycler\NPROTECT\00000213
c:\recycler\NPROTECT\00000214
c:\recycler\NPROTECT\00000215
c:\recycler\NPROTECT\00000216
c:\recycler\NPROTECT\00000217
c:\recycler\NPROTECT\00000218
c:\recycler\NPROTECT\00000220
c:\recycler\NPROTECT\00000222
c:\recycler\NPROTECT\00000223
c:\recycler\NPROTECT\00000224
c:\recycler\NPROTECT\00000225
c:\recycler\NPROTECT\00000226
c:\recycler\NPROTECT\00000228
c:\recycler\NPROTECT\00000229
c:\recycler\NPROTECT\00000231
c:\recycler\NPROTECT\00000232
c:\recycler\NPROTECT\00000233
c:\recycler\NPROTECT\00000234
c:\recycler\NPROTECT\00000236
c:\recycler\NPROTECT\00000237
c:\recycler\NPROTECT\00000240
c:\recycler\NPROTECT\00000241
c:\recycler\NPROTECT\00000242
c:\recycler\NPROTECT\00000244
c:\recycler\NPROTECT\00000246
c:\recycler\NPROTECT\00000247
c:\recycler\NPROTECT\00000248
c:\recycler\NPROTECT\00000249
c:\recycler\NPROTECT\00000250
c:\recycler\NPROTECT\00000251
c:\recycler\NPROTECT\00000252
c:\recycler\NPROTECT\00000253
c:\recycler\NPROTECT\00000254
c:\recycler\NPROTECT\00000255
c:\recycler\NPROTECT\00000256
c:\recycler\NPROTECT\00000257
c:\recycler\NPROTECT\00000259
c:\recycler\NPROTECT\00000260
c:\recycler\NPROTECT\00000262
c:\recycler\NPROTECT\00000263
c:\recycler\NPROTECT\00000264
c:\recycler\NPROTECT\00000266
c:\recycler\NPROTECT\00000267
c:\recycler\NPROTECT\00000268
c:\recycler\NPROTECT\00000269
c:\recycler\NPROTECT\00000270
c:\recycler\NPROTECT\00000272
c:\recycler\NPROTECT\00000273
c:\recycler\NPROTECT\00000274
c:\recycler\NPROTECT\00000275
c:\recycler\NPROTECT\00000277
c:\recycler\NPROTECT\00000278
c:\recycler\NPROTECT\00000279
c:\recycler\NPROTECT\00000280
c:\recycler\NPROTECT\00000281
c:\recycler\NPROTECT\00000282
c:\recycler\NPROTECT\00000283
c:\recycler\NPROTECT\00000284
c:\recycler\NPROTECT\00000285
c:\recycler\NPROTECT\00000286
c:\recycler\NPROTECT\00000290
c:\recycler\NPROTECT\00000291.dat
c:\recycler\NPROTECT\00000292.dat
c:\recycler\NPROTECT\00000293
c:\recycler\NPROTECT\00000294
c:\recycler\NPROTECT\00000295
c:\recycler\NPROTECT\00000296
c:\recycler\NPROTECT\00000297
c:\recycler\NPROTECT\00000298
c:\recycler\NPROTECT\00000299
c:\recycler\NPROTECT\00000301
c:\recycler\NPROTECT\00000303.dat
c:\recycler\NPROTECT\00000307
c:\recycler\NPROTECT\00000308.bat
c:\recycler\NPROTECT\00000309
c:\recycler\NPROTECT\00000310
c:\recycler\NPROTECT\00000312
c:\recycler\NPROTECT\00000314
c:\recycler\NPROTECT\00000315
c:\recycler\NPROTECT\00000316
c:\recycler\NPROTECT\00000319
c:\recycler\NPROTECT\00000320
c:\recycler\NPROTECT\00000321
c:\recycler\NPROTECT\00000322
c:\recycler\NPROTECT\00000324
c:\recycler\NPROTECT\00000325
c:\recycler\NPROTECT\00000326
c:\recycler\NPROTECT\00000327
c:\recycler\NPROTECT\00000328
c:\recycler\NPROTECT\00000329
c:\recycler\NPROTECT\00000330
c:\recycler\NPROTECT\00000331
c:\recycler\NPROTECT\00000332
c:\recycler\NPROTECT\00000333
c:\recycler\NPROTECT\00000334
c:\recycler\NPROTECT\00000335
c:\recycler\NPROTECT\00000336
c:\recycler\NPROTECT\00000337
c:\recycler\NPROTECT\00000338
c:\recycler\NPROTECT\00000340
c:\recycler\NPROTECT\00000341
c:\recycler\NPROTECT\00000344
c:\recycler\NPROTECT\00000347.SYS
c:\recycler\NPROTECT\00000348
c:\recycler\NPROTECT\00000349
c:\recycler\NPROTECT\00000350
c:\recycler\NPROTECT\00000351
c:\recycler\NPROTECT\00000352
c:\recycler\NPROTECT\00000353
c:\recycler\NPROTECT\00000354
c:\recycler\NPROTECT\00000355
c:\recycler\NPROTECT\00000356.dat
c:\recycler\NPROTECT\00000357
c:\recycler\NPROTECT\00000358
c:\recycler\NPROTECT\00000359.bad
c:\recycler\NPROTECT\00000360
c:\recycler\NPROTECT\00000361
c:\recycler\NPROTECT\00000362
c:\recycler\NPROTECT\00000363
c:\recycler\NPROTECT\00000364
c:\recycler\NPROTECT\00000370
c:\recycler\NPROTECT\00000372
c:\recycler\NPROTECT\00000374.md5
c:\recycler\NPROTECT\00000381
c:\recycler\NPROTECT\00000383
c:\recycler\NPROTECT\00000384
c:\recycler\NPROTECT\NPROTECT.LOG
c:\windows\$NtServicePackUninstall$\6to4svc.dll
----- BITS: Possible infected sites -----
hxxp://definitions.symantec.com
Infected copy of c:\windows\system32\msgsvc.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\msgsvc.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS
((((((((((((((((((((((((( Files Created from 2002-12-01 to 2003-01-01 )))))))))))))))))))))))))))))))
.
2010-02-20 19:16 . 2010-02-10 08:00 84912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100220.006\NAVENG.SYS
2010-02-20 19:16 . 2010-02-10 08:00 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100220.006\EECTRL.SYS
2010-02-20 19:16 . 2010-02-10 08:00 2747440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100220.006\CCERASER.DLL
2010-02-20 19:16 . 2010-02-10 08:00 259440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100220.006\ECMSVR32.DLL
2010-02-20 19:16 . 2010-02-10 08:00 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100220.006\NAVENG32.DLL
2010-02-20 19:16 . 2010-02-10 08:00 1647984 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100220.006\NAVEX32A.DLL
2010-02-20 19:16 . 2010-02-10 08:00 1324720 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100220.006\NAVEX15.SYS
2010-02-20 19:16 . 2010-02-10 08:00 102448 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100220.006\ERASER.SYS
2010-02-20 03:19 . 2009-11-17 00:51 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100218.001\Scxpx86.dll
2010-02-20 03:19 . 2009-11-17 00:51 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100218.001\IDSxpx86.dll
2010-02-20 03:19 . 2009-11-17 00:51 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100218.001\IDSviA64.sys
2010-02-20 03:19 . 2009-11-17 00:51 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100218.001\IDSvix86.sys
2010-02-20 03:19 . 2009-11-17 00:51 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100218.001\IDSXpx86.sys
2010-02-15 17:31 . 2010-02-15 17:31 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-02-14 21:40 . 2009-11-17 00:51 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100210.001\Scxpx86.dll
2010-02-14 21:40 . 2009-11-17 00:51 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100210.001\IDSxpx86.dll
2010-02-14 21:40 . 2009-11-17 00:51 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100210.001\IDSviA64.sys
2010-02-14 21:40 . 2009-11-17 00:51 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100210.001\IDSvix86.sys
2010-02-14 21:40 . 2009-11-17 00:51 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100210.001\IDSXpx86.sys
2010-02-14 04:33 . 2010-02-14 04:35 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-14 04:33 . 2003-01-01 07:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-13 18:24 . 2010-02-13 18:24 -------- dc----w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2010-02-13 14:48 . 2009-12-10 03:16 784752 ----a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\coFFPlgn\components\coFFPlgn.dll
2010-02-13 14:48 . 2009-11-17 00:51 164216 ----a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\IPSFFPlgn\components\IPSFFPl.dll
2010-02-13 14:46 . 2009-11-17 00:51 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\BinHub\IDSvia64.sys
2010-02-13 14:46 . 2009-11-17 00:51 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\BinHub\IDSvix86.sys
2010-02-13 14:46 . 2009-11-17 00:51 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\BinHub\IDSxpx86.sys
2010-02-13 14:46 . 2009-11-17 00:51 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\BinHub\scxpx86.dll
2010-02-13 14:46 . 2009-12-08 02:20 965488 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\OCS\hsplayer.dll
2010-02-13 14:46 . 2009-11-17 00:51 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\BinHub\idsxpx86.dll
2010-02-13 14:46 . 2009-12-17 06:31 893296 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\CLT\cltLMSx.dll
2010-02-13 14:46 . 2010-02-13 14:46 -------- d-----w- c:\windows\system32\drivers\NIS
2010-02-13 14:46 . 2010-02-13 14:46 -------- d-----w- c:\program files\Norton Internet Security
2010-02-13 14:46 . 2010-02-13 14:46 -------- d-----w- c:\program files\Windows Sidebar
2010-02-13 14:12 . 2010-02-13 14:12 -------- d-----w- c:\documents and settings\All Users\Application Data\PCSettings
2010-02-11 18:44 . 2010-02-11 18:44 201616 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20100211.001\BHRules.dll
2010-02-11 18:44 . 2010-02-11 18:44 1406352 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20100211.001\BHEngine.dll
2010-02-11 18:44 . 2010-02-11 18:44 676912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20100211.001\BHDrvx64.sys
2010-02-11 18:44 . 2010-02-11 18:44 536112 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20100211.001\BHDrvx86.sys
2010-02-11 18:44 . 2010-02-11 18:44 611216 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20100211.001\bbRGen.dll
2010-02-05 21:57 . 2010-02-13 13:38 -------- d-----w- c:\documents and settings\Tool\Local Settings\Application Data\fpidyb
2010-02-03 00:38 . 2010-02-03 00:38 -------- d-----w- c:\documents and settings\Tool\Application Data\Malwarebytes
2010-02-03 00:38 . 2010-01-07 23:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-03 00:38 . 2010-02-03 00:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-03 00:38 . 2010-02-03 00:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-03 00:38 . 2010-01-07 23:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-02 03:42 . 2010-02-02 03:42 -------- d-sh--w- c:\documents and settings\All Users\Application Data\LPOZLHTCG
2010-02-02 03:42 . 2009-06-25 17:02 435704 ----a-w- c:\documents and settings\All Users\Application Data\cdba3ff\sqlite3.dll
2010-02-02 03:42 . 2009-06-25 17:02 710136 ----a-w- c:\documents and settings\All Users\Application Data\cdba3ff\mozcrt19.dll
2010-02-02 03:42 . 2010-02-02 03:43 -------- d-sh--w- c:\documents and settings\All Users\Application Data\cdba3ff
2010-01-13 07:13 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2009-12-24 15:55 . 2009-12-24 15:55 -------- d--h--w- c:\documents and settings\All Users\Application Data\CanonIJScan
2009-12-24 15:55 . 2009-12-24 15:55 -------- d-----w- c:\documents and settings\Tool\Application Data\Canon
2009-12-16 18:43 . 2009-12-16 18:43 343040 -c----w- c:\windows\system32\dllcache\mspaint.exe
2009-12-14 07:08 . 2009-12-14 07:08 33280 -c----w- c:\windows\system32\dllcache\csrsrv.dll
2009-12-08 09:23 . 2009-12-08 09:23 474112 -c----w- c:\windows\system32\dllcache\shlwapi.dll
2009-11-27 17:11 . 2009-11-27 17:11 17920 -c----w- c:\windows\system32\dllcache\msyuv.dll
2009-11-27 16:07 . 2009-11-27 16:07 8704 -c----w- c:\windows\system32\dllcache\tsbyuv.dll
2009-11-27 16:07 . 2009-11-27 16:07 48128 -c----w- c:\windows\system32\dllcache\iyuv_32.dll
2009-11-27 16:07 . 2009-11-27 16:07 11264 -c----w- c:\windows\system32\dllcache\msrle32.dll
2009-11-11 10:26 . 2010-02-05 14:23 79488 ----a-w- c:\documents and settings\Tool\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-10-21 05:38 . 2009-10-21 05:38 75776 -c----w- c:\windows\system32\dllcache\strmfilt.dll
2009-10-21 05:38 . 2009-10-21 05:38 25088 -c----w- c:\windows\system32\dllcache\httpapi.dll
2009-10-20 16:20 . 2009-10-20 16:20 265728 -c----w- c:\windows\system32\dllcache\http.sys
2009-10-13 10:30 . 2009-10-13 10:30 270336 -c----w- c:\windows\system32\dllcache\oakley.dll
2009-10-12 13:38 . 2009-10-12 13:38 149504 -c----w- c:\windows\system32\dllcache\rastls.dll
2009-10-12 13:38 . 2009-10-12 13:38 79872 -c----w- c:\windows\system32\dllcache\raschap.dll
2009-10-02 22:42 . 2009-10-02 22:42 -------- d-----w- c:\program files\EA Games
2009-10-02 03:50 . 2009-09-15 00:58 1291640 ----a-w- c:\documents and settings\Tool\Application Data\Mozilla\Firefox\Profiles\xltalngg.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\BFHUpdater.exe
2009-10-02 03:50 . 2009-09-15 00:58 729088 ----a-w- c:\documents and settings\Tool\Application Data\Mozilla\Firefox\Profiles\xltalngg.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll
2009-09-26 17:51 . 2009-09-26 17:51 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-20 21:56 . 2009-09-20 21:56 -------- d-----w- c:\program files\Disney
2009-09-09 10:44 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-04 21:03 . 2009-09-04 21:03 58880 -c----w- c:\windows\system32\dllcache\msasn1.dll
2009-08-21 10:10 . 2009-08-21 10:10 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-21 10:10 . 2009-08-21 10:10 -------- d-----w- c:\program files\MSBuild
2009-08-21 10:10 . 2009-08-21 10:10 -------- d-----w- c:\program files\Reference Assemblies
2009-08-21 10:09 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2009-08-21 10:08 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-21 10:08 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-21 10:08 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-21 10:08 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2009-08-21 10:08 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-21 10:08 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-21 10:08 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-21 10:08 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-12 10:27 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-31 16:23 . 2009-07-31 16:23 -------- d-----w- c:\program files\Microsoft Games
2009-07-21 07:05 . 2009-07-21 07:05 1348432 ----a-w- c:\windows\system32\msxml4.dll
2009-07-17 22:55 . 2010-02-14 00:00 -------- d-----w- c:\documents and settings\Tool\Local Settings\Application Data\Temp
2009-07-17 19:01 . 2009-07-17 19:01 58880 -c----w- c:\windows\system32\dllcache\atl.dll
2009-07-17 16:22 . 2009-07-17 16:22 1435648 -c----w- c:\windows\system32\dllcache\query.dll
2009-07-12 17:17 . 2009-07-12 17:17 -------- d-----w- c:\program files\PopCap Games
2009-06-25 08:25 . 2009-09-11 14:18 136192 -c----w- c:\windows\system32\dllcache\msv1_0.dll
2009-06-25 08:25 . 2009-06-25 08:25 54272 -c----w- c:\windows\system32\dllcache\wdigest.dll
2009-06-25 08:25 . 2009-06-25 08:25 301568 -c----w- c:\windows\system32\dllcache\kerberos.dll
2009-06-24 11:18 . 2009-06-24 11:18 92928 -c----w- c:\windows\system32\dllcache\ksecdd.sys
2009-06-16 14:36 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2009-06-16 14:36 . 2009-10-15 16:28 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2009-06-12 12:31 . 2009-06-12 12:31 76288 -c----w- c:\windows\system32\dllcache\telnet.exe
2009-06-10 14:13 . 2009-11-27 16:07 84992 -c----w- c:\windows\system32\dllcache\avifil32.dll
2009-06-10 06:14 . 2009-06-10 06:14 132096 -c----w- c:\windows\system32\dllcache\wkssvc.dll
2009-06-04 19:05 . 2009-06-04 19:05 -------- d--h--w- c:\windows\PIF
2009-05-07 15:32 . 2009-05-07 15:32 345600 -c----w- c:\windows\system32\dllcache\localspl.dll
2009-04-16 01:32 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-04-16 01:31 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-04-16 01:31 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-04-16 01:31 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-04-16 01:31 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2009-04-16 01:31 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-04-16 01:31 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 01:31 . 2009-06-25 08:25 730112 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 01:31 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2009-04-16 01:31 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 01:31 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-04-15 14:51 . 2009-04-15 14:51 585216 -c----w- c:\windows\system32\dllcache\rpcrt4.dll
2009-03-30 23:34 . 2001-08-18 05:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2009-03-30 23:34 . 2008-04-14 00:12 159232 ----a-w- c:\windows\system32\ptpusd.dll
2009-03-21 15:45 . 2009-03-21 15:45 -------- d--h--w- c:\documents and settings\All Users\Application Data\CanonIJEGV
2009-03-21 14:06 . 2009-03-21 14:06 989696 -c----w- c:\windows\system32\dllcache\kernel32.dll
2009-02-27 20:31 . 2009-02-27 20:37 -------- d-----w- c:\documents and settings\Tool\Application Data\SBTT
2009-02-27 20:26 . 2009-02-27 20:27 -------- d-----w- c:\program files\Nick Arcade
2009-02-27 14:10 . 2009-02-27 14:10 -------- d-----w- c:\program files\Common Files\CANON
2009-02-27 14:08 . 2009-02-27 14:08 -------- d--h--w- c:\documents and settings\All Users\Application Data\CanonBJ
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-13 14:55 . 2004-10-21 01:58 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-02-13 14:46 . 2009-01-14 19:31 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-02-13 14:46 . 2009-01-14 19:31 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-02-13 03:41 . 2010-02-13 03:41 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-12-31 16:50 . 2004-08-04 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:21 . 2004-08-04 12:00 667136 ----a-w- c:\windows\system32\wininet.dll
2009-12-22 05:20 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-16 18:43 . 2004-10-21 01:12 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-08-04 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-04 18:22 . 2004-08-04 12:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:11 . 2004-08-04 12:00 1291776 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:11 . 2004-08-04 00:56 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:07 . 2004-08-04 12:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-17 22:36 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2004-08-04 12:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2004-08-04 12:00 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2004-08-04 00:56 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-21 15:51 . 2004-08-04 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-10-21 05:38 . 2004-08-04 12:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 12:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 12:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-15 16:28 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-10-15 16:28 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-10-13 10:30 . 2004-08-04 12:00 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-04 12:00 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-04 12:00 79872 ----a-w- c:\windows\system32\raschap.dll
2009-09-11 14:18 . 2004-08-04 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-26 08:00 . 2004-08-04 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-25 09:17 . 2004-08-04 12:00 354816 ----a-w- c:\windows\system32\winhttp.dll
2009-08-14 13:21 . 2004-08-04 12:00 1850624 ----a-w- c:\windows\system32\win32k.sys
2009-08-07 02:24 . 2004-10-21 01:14 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-07 02:24 . 2004-10-21 01:14 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-07 02:24 . 2004-10-21 01:14 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-07 02:24 . 2004-08-04 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-07 02:23 . 2004-10-21 01:14 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-07 02:23 . 2004-10-21 01:14 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 03:44 . 2004-08-04 12:00 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-03 22:59 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-07-31 17:05 . 2008-09-04 03:41 1372672 ------w- c:\windows\system32\msxml6.dll
2009-07-31 04:35 . 2004-08-04 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2009-07-17 19:01 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-17 16:22 . 2004-08-04 12:00 1435648 ----a-w- c:\windows\system32\query.dll
2009-07-14 06:43 . 2004-08-04 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-25 08:25 . 2004-08-04 12:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-04 12:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-04 12:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-04 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-04 12:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-24 11:18 . 2004-08-04 12:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-12 12:31 . 2004-08-04 12:00 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 16:19 . 2004-10-21 01:12 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2004-08-04 12:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-15 14:51 . 2004-08-04 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-02 06:02 . 2004-08-04 12:00 604160 ----a-w- c:\windows\system32\wmspdmod.dll
2009-03-06 14:22 . 2004-08-04 12:00 284160 ----a-w- c:\windows\system32\pdh.dll
2009-02-09 12:10 . 2004-10-21 01:12 453120 ----a-w- c:\windows\system32\wbem\wmiprvsd.dll
2009-02-09 12:10 . 2004-10-21 01:12 473600 ----a-w- c:\windows\system32\wbem\fastprox.dll
2009-02-09 12:10 . 2004-08-04 12:00 714752 ----a-w- c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-04 12:00 617472 ----a-w- c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-04 12:00 401408 ----a-w- c:\windows\system32\rpcss.dll
2009-02-06 11:11 . 2004-08-04 12:00 110592 ----a-w- c:\windows\system32\services.exe
2009-02-06 10:39 . 2004-08-04 12:00 35328 ----a-w- c:\windows\system32\sc.exe
2009-02-06 10:10 . 2004-10-21 01:12 227840 ----a-w- c:\windows\system32\wbem\wmiprvse.exe
2009-01-29 23:05 . 2009-01-29 23:05 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-01-29 23:05 . 2009-01-29 23:05 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-01-15 01:10 . 2003-01-01 07:07 -------- d-----w- c:\program files\Common Files\Adobe
2009-01-14 20:25 . 2004-10-21 01:58 -------- d-----w- c:\documents and settings\Tool\Application Data\Symantec
2009-01-14 20:25 . 2004-10-21 01:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2008-10-23 12:36 . 2004-08-04 12:00 286720 ----a-w- c:\windows\system32\gdi32.dll
2008-09-15 11:21 . 2009-06-04 19:05 142794 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Personal_32_1033.dat
2008-09-15 11:20 . 2004-10-21 01:16 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2008-08-14 10:04 . 2004-08-04 12:00 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2008-07-07 20:26 . 2004-08-04 12:00 253952 ----a-w- c:\windows\system32\es.dll
2008-06-25 01:12 . 2006-10-19 04:47 295936 ----a-w- c:\windows\system32\wmpeffects.dll
2008-06-24 16:43 . 2004-08-04 12:00 74240 ----a-w- c:\windows\system32\mscms.dll
2008-06-20 17:46 . 2004-08-04 12:00 245248 ----a-w- c:\windows\system32\mswsock.dll
2008-06-20 11:51 . 2004-08-04 12:00 361600 ----a-w- c:\windows\system32\drivers\tcpip.sys
2008-06-20 11:08 . 2004-08-04 12:00 225856 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2008-06-18 12:03 . 2004-08-04 12:00 938496 ----a-w- c:\windows\system32\WMNetmgr.dll
2008-06-18 08:09 . 2004-08-04 12:00 100864 ----a-w- c:\windows\system32\logagent.exe
2008-06-12 14:23 . 2004-10-21 01:12 91648 ----a-w- c:\windows\system32\mtxoci.dll
2008-06-12 14:23 . 2004-10-21 01:12 161792 ----a-w- c:\windows\system32\msdtcuiu.dll
2008-06-12 14:23 . 2004-10-21 01:12 956928 ----a-w- c:\windows\system32\msdtctm.dll
2008-06-12 14:23 . 2004-10-21 01:12 58880 ----a-w- c:\windows\system32\msdtclog.dll
2008-06-12 14:23 . 2004-10-21 01:12 428032 ----a-w- c:\windows\system32\msdtcprx.dll
2008-06-12 14:23 . 2004-08-04 12:00 66560 ----a-w- c:\windows\system32\mtxclu.dll
2008-06-03 06:20 . 2004-10-20 18:07 3100160 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2008-06-03 03:21 . 2004-10-20 18:07 306688 ----a-w- c:\windows\system32\ati2dvag.dll
2008-06-03 02:59 . 2004-10-20 18:07 3500352 ----a-w- c:\windows\system32\ati3duag.dll
2008-06-03 02:48 . 2004-10-20 18:07 2120832 ----a-w- c:\windows\system32\ativvaxx.dll
2008-06-03 02:21 . 2004-10-20 18:07 557056 ----a-w- c:\windows\system32\ati2cqag.dll
2008-05-30 21:19 . 2008-07-15 17:06 507400 ----a-w- c:\windows\system32\XAudio2_1.dll
2008-05-30 21:18 . 2008-07-15 17:06 238088 ----a-w- c:\windows\system32\xactengine3_1.dll
2008-05-30 21:17 . 2008-07-15 17:06 65032 ----a-w- c:\windows\system32\XAPOFX1_0.dll
2008-05-30 21:17 . 2008-07-15 17:06 25608 ----a-w- c:\windows\system32\X3DAudio1_4.dll
2008-05-30 21:11 . 2008-07-15 17:06 467984 ----a-w- c:\windows\system32\d3dx10_38.dll
2008-05-30 21:11 . 2008-07-15 17:06 1491992 ----a-w- c:\windows\system32\D3DCompiler_38.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Bandwidth Monitor Pro"="c:\program files\Bandwidth Monitor Pro\Bandwidth Monitor Pro.exe" [2003-12-03 182272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NapsterShell"="c:\program files\Napster\napster.exe" [2008-05-09 323216]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NSWosCheck"="c:\program files\Norton SystemWorks\osCheck.exe" [2008-09-25 160112]
"NswUiTray"="c:\program files\Norton SystemWorks\NswUiTray.exe" [2008-09-25 85360]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-04 1848648]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\InterVideo\\WinDVD4PR\\WinDVD.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Microsoft Games\\Dungeon Siege 2\\DungeonSiege2.exe"=
"c:\\Program Files\\Napster\\napster.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9990:TCP"= 9990:TCP:a
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [11/12/2008 4:02 PM 29808]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1105000.07F\SymDS.sys [2/13/2010 7:46 AM 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1105000.07F\SymEFA.sys [2/13/2010 7:46 AM 172592]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20100211.001\BHDrvx86.sys [2/11/2010 11:44 AM 536112]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1105000.07F\cchpx86.sys [2/13/2010 7:46 AM 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1105000.07F\Ironx86.sys [2/13/2010 7:46 AM 116272]
R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\17.5.0.127\ccSvcHst.exe [2/13/2010 7:46 AM 126392]
R2 NProtectService;Norton UnErase Protection;c:\progra~1\NORTON~3\NORTON~1\NPROTECT.EXE [9/25/2008 2:53 PM 95600]
R2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [1/14/2009 2:54 PM 1086840]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/14/2010 1:19 AM 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100218.001\IDSXpx86.sys [2/19/2010 8:19 PM 329592]
S2 gupdate1c9664954f7bd1c;Google Update Service (gupdate1c9664954f7bd1c);c:\program files\Google\Update\GoogleUpdate.exe [12/24/2008 9:29 PM 133104]
S3 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2003-01-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-25 06:10]
2010-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-25 06:10]
2010-02-15 c:\windows\Tasks\Norton SystemWorks One Button Checkup.job
- c:\program files\Norton SystemWorks\OBC.exe [2008-09-25 21:52]
.
.
------- Supplementary Scan -------
.
IE: &NeoTrace It! - c:\progra~1\NEOTRA~1\NTXcontext.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Tool\Application Data\Mozilla\Firefox\Profiles\xltalngg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://www.google.com/
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\documents and settings\Tool\Application Data\Mozilla\Firefox\Profiles\xltalngg.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npstrlnk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Cmaudio - cmicnfg.cpl
MSConfigStartUp-SVCHOST - c:\windows\system32\drivers\svchost.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2003-01-01 00:54
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\17.5.0.127\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\17.5.0.127\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(640)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\msv1_0.dll
- - - - - - - > 'explorer.exe'(548)
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\progra~1\NORTON~3\NORTON~1\SPEEDD~1\NOPDB.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2003-01-01 00:58:28 - machine was rebooted
ComboFix-quarantined-files.txt 2003-01-01 07:58
Pre-Run: 9,902,997,504 bytes free
Post-Run: 10,112,544,768 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 4E8351BC03E586D6AF4C4C346F1B33DE