((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
Infected copy of c:\windows\system32\drivers\pci.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_iWinGamesInstaller
((((((((((((((((((((((((( Files Created from 2010-05-15 to 2010-06-15 )))))))))))))))))))))))))))))))
.
2010-06-13 20:32 . 2010-06-13 21:39 87 ----a-w- c:\users\Daniel\jagex_runescape_preferences2.dat
2010-06-13 20:32 . 2010-06-13 20:32 0 ----a-w- c:\users\Daniel\jagex__preferences3.dat
2010-06-13 20:32 . 2010-06-13 20:33 45 ----a-w- c:\users\Daniel\jagex_runescape_preferences.dat
2010-06-09 10:40 . 2010-06-09 10:40 -------- d-----w- c:\users\David\AppData\Local\Symantec
2010-06-09 05:03 . 2010-06-09 05:03 -------- d-----w- c:\users\David\AppData\Roaming\SUPERAntiSpyware.com
2010-06-09 05:03 . 2010-06-09 05:03 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-06-09 05:03 . 2010-06-09 05:03 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-06-09 05:01 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-09 05:01 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-09 05:01 . 2010-06-09 05:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-08 19:04 . 2010-06-08 19:04 -------- d-----w- c:\programdata\Alwil Software
2010-06-08 19:04 . 2010-06-08 19:04 -------- d-----w- c:\program files\Alwil Software
2010-06-08 02:14 . 2010-06-08 02:26 -------- d-----w- c:\users\David\AppData\Local\NPE
2010-06-07 23:29 . 2010-06-07 23:29 -------- d-----w- c:\users\David\AppData\Roaming\Malwarebytes
2010-06-07 23:29 . 2010-06-07 23:29 -------- d-----w- c:\programdata\Malwarebytes
2010-06-07 01:34 . 2010-06-07 03:33 -------- d-----w- c:\program files\BYOND
2010-05-25 00:56 . 2010-05-25 00:56 -------- d-----w- c:\users\David\AppData\Roaming\LolClient
2010-05-24 19:48 . 2008-07-31 14:41 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll
2010-05-24 19:48 . 2008-07-31 14:40 509448 ----a-w- c:\windows\system32\XAudio2_2.dll
2010-05-24 19:48 . 2008-07-12 12:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-05-24 19:48 . 2008-07-12 12:18 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-05-24 19:48 . 2008-07-12 12:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-05-24 19:37 . 2010-06-13 22:32 -------- d-----w- C:\Riot Games
2010-05-24 19:19 . 2010-05-25 10:01 -------- d-----w- c:\users\David\AppData\Local\PMB Files
2010-05-24 19:18 . 2010-05-24 19:19 -------- d-----w- c:\programdata\PMB Files
2010-05-24 19:18 . 2010-05-24 19:18 -------- d-----w- c:\program files\Pando Networks
2010-05-17 23:58 . 2010-05-17 23:58 -------- d-----w- c:\windows\system32\syncdb
2010-05-17 23:40 . 2010-05-17 23:40 -------- d-----w- c:\programdata\FLEXnet
2010-05-17 23:37 . 2010-05-17 23:37 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-05-17 23:03 . 2010-05-17 23:33 -------- d-----w- c:\users\David\AppData\Roaming\Download Manager
2010-05-17 22:59 . 2010-05-17 22:59 -------- d-----w- c:\users\Public\Roaming
2010-05-17 19:57 . 2010-05-17 19:57 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
2010-05-17 19:52 . 2010-05-17 19:52 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-05-17 19:17 . 2010-06-09 21:35 -------- d-----w- c:\users\David\AppData\Roaming\uTorrent
2010-05-17 19:13 . 2010-05-18 00:05 -------- d-----w- c:\program files\Common Files\Akamai
2010-05-16 16:03 . 2010-05-16 16:03 -------- d-----w- c:\program files\JitBit
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-15 14:26 . 2010-03-25 23:28 50 ----a-w- c:\users\David\jagex__preferences3.dat
2010-06-15 14:15 . 2010-02-22 16:27 45 ----a-w- c:\users\David\jagex_runescape_preferences.dat
2010-06-15 09:49 . 2010-02-22 16:28 87 ----a-w- c:\users\David\jagex_runescape_preferences2.dat
2010-06-13 22:32 . 2008-08-04 18:21 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-13 20:29 . 2008-10-07 03:42 75432 ----a-w- c:\users\Daniel\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-09 21:35 . 2008-10-07 03:05 -------- d-----w- c:\program files\Microsoft Works
2010-06-09 21:35 . 2008-10-17 21:38 -------- d-----w- c:\program files\iWin Games
2010-06-09 05:04 . 2010-06-09 05:04 63488 ----a-w- c:\users\David\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-06-09 05:04 . 2010-06-09 05:04 52224 ----a-w- c:\users\David\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-06-09 05:04 . 2010-06-09 05:04 117760 ----a-w- c:\users\David\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-06-08 02:14 . 2010-02-14 16:26 -------- d-----w- c:\programdata\Norton
2010-06-01 10:59 . 2010-03-07 16:53 1864 ----a-w- c:\users\David\AppData\Roaming\wklnhst.dat
2010-05-30 16:46 . 2010-03-29 23:16 -------- d-----w- c:\program files\dl_Cats
2010-05-25 04:33 . 2010-02-22 16:22 75432 ----a-w- c:\users\David\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-17 23:58 . 2008-10-07 03:02 -------- d-----w- c:\program files\Common Files\Adobe
2010-05-17 19:52 . 2010-05-24 19:47 38784 ----a-w- c:\users\David\AppData\Roaming\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-05-17 19:52 . 2010-05-17 19:52 38784 ----a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-05-16 16:03 . 2010-05-16 16:03 3638 ----a-r- c:\users\David\AppData\Roaming\Microsoft\Installer\{2D57FB4E-6277-4A6D-8739-304C38051B89}\_FE8D9346612A3FA1CA6C54.exe
2010-05-16 16:03 . 2010-05-16 16:03 3638 ----a-r- c:\users\David\AppData\Roaming\Microsoft\Installer\{2D57FB4E-6277-4A6D-8739-304C38051B89}\_8558C8A0BCDE26BB5381A1.exe
2010-05-16 16:03 . 2010-05-16 16:03 3638 ----a-r- c:\users\David\AppData\Roaming\Microsoft\Installer\{2D57FB4E-6277-4A6D-8739-304C38051B89}\_6FEFF9B68218417F98F549.exe
2010-05-16 16:03 . 2010-05-16 16:03 3638 ----a-r- c:\users\David\AppData\Roaming\Microsoft\Installer\{2D57FB4E-6277-4A6D-8739-304C38051B89}\_375698F2AAFD2C1E7FA1BC.exe
2010-05-16 16:03 . 2010-05-16 16:03 1406 ----a-r- c:\users\David\AppData\Roaming\Microsoft\Installer\{2D57FB4E-6277-4A6D-8739-304C38051B89}\_CE61F9F35DBEC87A3354B8.exe
2010-04-24 11:24 . 2010-04-24 11:24 658184 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-03-31 01:07 . 2010-03-31 01:07 0 ----a-w- c:\windows\nsreg.dat
2008-08-04 19:04 . 2008-08-04 19:04 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"HPADVISOR"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-01-12 972344]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-05-18 2397424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-02-14 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-15 141608]
"DLCCCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2006-02-24 73728]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
c:\users\Jonathan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
iWin Desktop Alerts.lnk - c:\programdata\iWin Games\DesktopAlerts\DesktopAlerts.exe [2008-10-17 108032]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
PictureMover.lnk - c:\program files\PictureMover\Bin\PictureMover.exe [2008-6-3 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1446613826-128392484-1828478373-1000]
"EnableNotificationsRef"=dword:00000001
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0308000.029\SYMEFA.SYS [2010-02-14 310320]
S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys [2010-02-14 259632]
S1 ccHP;Symantec Hash Provider;c:\windows\System32\Drivers\N360\0308000.029\ccHPx86.sys [2010-02-14 482432]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100604.004\IDSvix86.sys [2010-05-28 344112]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 N360;Norton Security Suite;c:\program files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe [2010-02-14 117640]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-05-26 102448]
S3 HSXHWBS3;HSXHWBS3;c:\windows\system32\DRIVERS\HSXHWBS3.sys [2008-02-12 207360]
S3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS [2010-02-14 48688]
.
Contents of the 'Scheduled Tasks' folder
2010-06-14 c:\windows\Tasks\Norton Security Scan for David.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-04-02 04:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Presario&pf=cndt
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Presario&pf=cndt
FF - ProfilePath - c:\users\David\AppData\Roaming\Mozilla\Firefox\Profiles\a7kcl9bo.default\
FF - prefs.js: browser.startup.homepage - hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Presario&pf=cndt
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-AdobeBridge - c:\program files\Adobe\Adobe Bridge CS5\Bridge.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-06-15 11:01
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\3.8.0.41\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1446613826-128392484-1828478373-1002\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{AE5814EF-E753-A2EC-CCBE-0F530B9CA729}*]
"majngfmjojgjhpegjdkbhdhdjp"=hex:6a,61,6b,66,68,6f,62,64,6c,6d,66,6b,62,68,6a,
6f,61,6d,6d,67,00,e7
"nadoakkbpcndcckadfahgjkhbjin"=hex:6a,61,6b,66,68,6f,62,64,6c,6d,66,6b,62,68,
6a,6f,61,6d,6d,67,00,6d
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(3324)
c:\windows\system32\ieframe.dll
c:\windows\System32\SyncCenter.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dlcccoms.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\DllHost.exe
c:\windows\System32\rundll32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\windows\system32\iashost.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2010-06-15 11:07:53 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-15 15:07
Pre-Run: 221,944,852,480 bytes free
Post-Run: 222,148,575,232 bytes free
- - End Of File - - 9BCCA209211DF501B434B3FA1ACA39A2