Here's te three reports:the Kaspersky, the DDS and the ComboFixer.
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, March 30, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, March 30, 2009 14:35:03
Records in database: 1986635
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
Scan statistics:
Files scanned: 74819
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 00:32:24
File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\gaopdxmejdnosecwsrsbwyksiquhxidctiqbow.dll.vir Infected: Packed.Win32.Tdss.f 1
The selected area was scanned.
DDS (Ver_09-03-16.01) - NTFSx86
Run by shintorg at 13:41:30.50 on Mon 03/30/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2046.1281 [GMT -4:00]
AV: Norton AntiVirus *On-access scanning disabled* (Updated)
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\shintorg\Desktop\dds.scr
============== Pseudo HJT Report ===============
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\16.5.0.134\IPSBHO.DLL
mRun: [P17Helper] Rundll32 P17.dll,P17Helper
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\shintorg\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\ssv.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\shintorg\applic~1\mozilla\firefox\profiles\d2zqdpon.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.expiation-guild.org/joomla/
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files\vlc\npvlc.dll
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1005000.086\SymEFA.sys [2009-3-24 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1005000.086\BHDrvx86.sys [2009-3-24 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1005000.086\cchpx86.sys [2009-3-24 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090318.001\IDSXpx86.sys [2009-3-24 276344]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\engine\16.5.0.134\ccSvcHst.exe [2009-3-24 115560]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090330.002\NAVENG.SYS [2009-3-30 89104]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090330.002\NAVEX15.SYS [2009-3-30 876144]
=============== Created Last 30 ================
2009-03-30 12:39 <DIR> --d----- C:\ComboFix
2009-03-29 16:35 <DIR> a-dshr-- C:\cmdcons
2009-03-29 16:34 161,792 a------- c:\windows\SWREG.exe
2009-03-29 16:34 98,816 a------- c:\windows\sed.exe
2009-03-28 13:54 53,248 a----r-- c:\windows\system32\P17CPI.dll
2009-03-28 13:54 1,389,056 a----r-- c:\windows\system32\drivers\P17.sys
2009-03-28 13:53 137,728 a----r-- c:\windows\system32\P17res.dll
2009-03-28 13:53 2,167,684 a----r-- c:\windows\system32\ct2mgm.sf2
2009-03-28 13:53 115,200 a----r-- c:\windows\system32\sfms32.dll
2009-03-28 13:53 20,992 a----r-- c:\windows\system32\sfman32.dll
2009-03-28 13:53 138,752 a----r-- c:\windows\system32\drivers\ctsfm2k.sys
2009-03-28 13:53 106,496 a----r-- c:\windows\system32\drivers\ctoss2k.sys
2009-03-25 16:02 64,512 a----r-- c:\windows\system32\P17.dll
2009-03-25 01:12 <DIR> --d----- c:\windows\system32\URTTemp
2009-03-25 00:52 <DIR> --d----- C:\Sid Meier's Civilization 4
2009-03-25 00:51 2,297,552 a------- c:\windows\system32\d3dx9_26.dll
2009-03-24 19:55 <DIR> --d--r-- c:\program files\Norton Support
2009-03-24 19:41 36,400 a----r-- c:\windows\system32\drivers\SymIM.sys
2009-03-24 19:41 124,464 a------- c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-24 19:41 60,808 a------- c:\windows\system32\S32EVNT1.DLL
2009-03-24 19:41 7,386 a------- c:\windows\system32\drivers\SYMEVENT.CAT
2009-03-24 19:41 805 a------- c:\windows\system32\drivers\SYMEVENT.INF
2009-03-24 19:41 <DIR> --d----- c:\program files\Symantec
2009-03-24 19:41 <DIR> --d----- c:\program files\common files\Symantec Shared
2009-03-24 19:40 <DIR> --d----- c:\windows\system32\drivers\NAV
2009-03-24 19:40 <DIR> --d----- c:\program files\Norton AntiVirus
2009-03-24 19:40 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Symantec
2009-03-24 19:40 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Norton
2009-03-24 19:38 <DIR> --d----- c:\program files\NortonInstaller
2009-03-24 19:38 <DIR> --d----- c:\docume~1\alluse~1\applic~1\NortonInstaller
2009-03-24 18:14 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-03-24 17:54 138,384 a------- c:\windows\system32\drivers\tmcomm.sys
2009-03-24 17:53 <DIR> --d----- c:\docume~1\shintorg\applic~1\HouseCall 6.6
2009-03-24 17:36 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-03-24 16:46 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Downloaded Installations
2009-03-24 16:46 <DIR> --d----- c:\program files\AVG
2009-03-24 16:46 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg8
2009-03-24 14:05 347 a------- c:\windows\CTWave32.INI
2009-03-24 14:05 29 a------- c:\windows\sfbm.INI
2009-03-16 08:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
2009-03-10 12:04 <DIR> --d----- c:\program files\common files\Blizzard Entertainment
2009-03-09 16:09 13,463,552 ac------ c:\windows\system32\dllcache\hwxjpn.dll
2009-03-09 03:00 <DIR> --d----- c:\program files\MSXML 4.0
2009-03-08 02:48 <DIR> --d----- c:\program files\Elements
2009-03-08 02:48 20,016 -------- c:\windows\system32\drivers\pxhelp20.sys
2009-03-08 02:48 82,432 a------- c:\windows\system32\msxml4r.dll
2009-03-05 04:00 221,184 a------- c:\windows\system32\wmpns.dll
2009-03-05 02:04 410,984 a------- c:\windows\system32\deploytk.dll
2009-03-05 02:04 73,728 a------- c:\windows\system32\javacpl.cpl
2009-03-03 12:53 <DIR> --d----- C:\World of Warcraft
2009-03-03 12:42 <DIR> --d----- c:\program files\Windows Media Connect 2
2009-03-03 12:39 <DIR> --d----- c:\windows\system32\LogFiles
2009-03-03 12:37 13,646 a------- c:\windows\system32\wpa.bak
2009-03-03 12:32 <DIR> --d----- C:\World of Warcraft Public Test
2009-03-03 11:52 <DIR> --d----- C:\fsaua.data
2009-03-03 11:25 <DIR> --d----- c:\docume~1\shintorg\applic~1\Malwarebytes
2009-03-03 11:25 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-03-03 11:16 <DIR> --d----- c:\windows\system32\CatRoot_bak
2009-03-03 11:16 272,128 -c------ c:\windows\system32\dllcache\bthport.sys
2009-03-03 11:16 272,128 -------- c:\windows\system32\drivers\bthport.sys
2009-03-03 11:16 2,136,064 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-03 11:16 2,180,352 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-03 11:16 2,057,728 -c------ c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-03 11:16 2,015,744 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-03 11:15 453,632 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2009-03-03 11:12 26,488 a------- c:\windows\system32\spupdsvc.exe
2009-03-03 11:12 <DIR> --d----- c:\windows\system32\PreInstall
2009-03-03 11:12 <DIR> --d-h--- c:\windows\$hf_mig$
2009-03-03 11:06 1,072 a------- c:\windows\system32\settingsbkup.sfm
2009-03-03 11:06 1,072 a------- c:\windows\system32\settings.sfm
2009-03-03 10:50 647,872 -------- c:\windows\system32\Mscomct2.ocx
2009-03-03 10:50 41,984 -------- c:\windows\Ctregrun.exe
2009-03-03 10:47 183 a------- c:\windows\setuplog
2009-03-03 10:43 <DIR> --d----- c:\windows\RegisteredPackages
2009-03-03 10:43 <DIR> --d----- c:\program files\Creative
2009-03-03 10:21 446,464 a------- c:\windows\system32\CapabilityTable.exe
2009-03-03 10:21 <DIR> --d----- c:\windows\system32\SoftwareDistribution
2009-03-03 10:21 1,570 -------- c:\windows\system32\nvide.nvu
2009-03-03 10:21 363,008 a----r-- c:\windows\system32\idecoiins.dll
2009-03-03 10:21 363,008 a----r-- c:\windows\system32\idecoi.dll
2009-03-03 10:21 105,344 a----r-- c:\windows\system32\drivers\nvata.sys
2009-03-03 10:21 35,840 a----r-- c:\windows\system32\NVCOI.DLL
2009-03-03 10:21 <DIR> --d----- c:\windows\system32\ReinstallBackups
2009-03-03 10:21 356,352 -------- c:\windows\system32\nvuide.exe
2009-03-03 10:21 202,240 a----r-- c:\windows\system32\fdco1ins.dll
2009-03-03 10:21 52,736 a----r-- c:\windows\system32\drivers\NVENETFD.sys
2009-03-03 10:21 202,240 a------- c:\windows\system32\fdco1.dll
2009-03-03 10:20 110,080 a----r-- c:\windows\system32\drivers\nvtcp.sys
2009-03-03 10:20 208,896 a------- c:\windows\system32\nvunrm.exe
2009-03-03 10:20 3,903 a------- c:\windows\system32\nvnrm.nvu
2009-03-03 10:20 261,120 a----r-- c:\windows\system32\drivers\nvsnpu.sys
2009-03-03 10:20 35,840 a----r-- c:\windows\system32\nvconrm.dll
2009-03-03 10:20 10,240 a----r-- c:\windows\system32\bdco1ins.dll
2009-03-03 10:20 10,240 a----r-- c:\windows\system32\bdco1.dll
2009-03-03 10:20 <DIR> --d----- c:\windows\NV18361868.TMP
2009-03-03 10:20 1,104,896 a----r-- c:\windows\system32\drivers\nvnrm.sys
2009-03-03 10:20 208,896 a----r-- c:\windows\system32\nvusmb.exe
2009-03-03 10:20 18,944 a----r-- c:\windows\system32\drivers\nvnetbus.sys
2009-03-03 10:20 1,864 a----r-- c:\windows\system32\nvsmb.nvu
2009-03-03 10:14 <DIR> --d----- c:\program files\VLC
2009-03-03 10:13 <DIR> --d----- c:\program files\Ventrilo
2009-03-03 10:13 262 a------- c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2009-03-03 10:13 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-03-03 10:13 <DIR> --d----- C:\Fraps
2009-03-03 10:11 94,610 a------- c:\windows\system32\nvapps.xml
2009-03-03 10:10 356,352 a------- c:\windows\system32\nvudisp.exe
2009-03-03 10:10 17,056 a------- c:\windows\system32\nvdisp.nvu
2009-03-03 10:10 <DIR> --d----- c:\windows\nview
2009-03-03 10:10 356,352 a------- c:\windows\system32\NVUNINST.EXE
2009-03-03 10:07 <DIR> --d----- c:\documents and settings\shintorg
2009-03-03 10:06 <DIR> --ds---- c:\windows\system32\Microsoft
2009-03-03 10:06 8,192 a------- c:\windows\REGLOCS.OLD
2009-03-03 10:04 92,416 ac------ c:\windows\system32\dllcache\mga.sys
2009-03-03 10:03 <DIR> --dsh--- c:\documents and settings\all users\DRM
2009-03-03 10:03 <DIR> --d--r-- c:\windows\Offline Web Pages
2009-03-03 10:03 488 a---hr-- c:\windows\system32\WindowsLogon.manifest
2009-03-03 10:03 488 a---hr-- c:\windows\system32\logonui.exe.manifest
2009-03-03 10:03 <DIR> --ds---- c:\windows\Downloaded Program Files
2009-03-03 10:03 749 a---hr-- c:\windows\WindowsShell.Manifest
2009-03-03 10:03 749 a---hr-- c:\windows\system32\wuaucpl.cpl.manifest
2009-03-03 10:03 749 a---hr-- c:\windows\system32\sapi.cpl.manifest
2009-03-03 10:03 749 a---hr-- c:\windows\system32\nwc.cpl.manifest
2009-03-03 10:03 749 a---hr-- c:\windows\system32\ncpa.cpl.manifest
2009-03-03 10:03 749 a---hr-- c:\windows\system32\cdplayer.exe.manifest
2009-03-03 10:03 <DIR> --d-h--- c:\program files\WindowsUpdate
2009-03-03 10:03 4,399,505 ac------ c:\windows\system32\dllcache\nls302en.lex
2009-03-03 10:03 <DIR> --d----- c:\windows\system32\DirectX
2009-03-03 10:02 <DIR> --d----- c:\program files\common files\MSSoap
2009-03-03 10:01 <DIR> --d----- c:\program files\Online Services
2009-03-03 10:01 <DIR> --d----- c:\program files\Messenger
2009-03-03 10:01 <DIR> --d----- c:\program files\MSN Gaming Zone
2009-03-03 10:01 <DIR> --d----- c:\program files\Windows NT
2009-03-03 00:35 <DIR> --d----- c:\program files\common files\ODBC
2009-03-03 00:35 <DIR> --d----- c:\program files\common files\SpeechEngines
2009-03-03 00:35 <DIR> --d--r-- c:\documents and settings\all users\Documents
==================== Find3M ====================
2009-03-25 01:46 163,644 a------- c:\windows\system32\drivers\secdrv.sys
2009-03-03 10:11 76,487 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-03-03 10:02 21,640 a------- c:\windows\system32\emptyregdb.dat
2009-02-26 12:46 74,760 a------- c:\windows\system32\drivers\UniversalDD.sys
2009-02-26 12:46 25,608 a------- c:\windows\system32\drivers\AVGIDSErHr.sys
2009-02-09 06:19 1,846,272 a------- c:\windows\system32\win32k.sys
2009-01-03 07:24 81,920 a------- c:\windows\system32\frapsvid.dll
============= FINISH: 13:41:40.45 ===============
ComboFix 09-03-29.04 - shintorg 2009-03-30 12:40:31.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2046.1683 [GMT -4:00]
Running from: c:\documents and settings\shintorg\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\shintorg\Desktop\CFScript.txt
AV: Norton AntiVirus *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\autorun.inf\lpt3.This folder was created by Flash_Disinfector
c:\documents and settings\shintorg\Application Data\uTorrent
c:\documents and settings\shintorg\Application Data\uTorrent\Battlestar Galactica S04E19 HDTV XviD-0TV.torrent
c:\documents and settings\shintorg\Application Data\uTorrent\Battlestar.Galactica.S04E18.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\shintorg\Application Data\uTorrent\Battlestar.Galactica.S04E19.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\shintorg\Application Data\uTorrent\Battlestar.Galactica.S04E19.HDTV.XviD-0TV.torrent
c:\documents and settings\shintorg\Application Data\uTorrent\dht.dat
c:\documents and settings\shintorg\Application Data\uTorrent\dht.dat.old
c:\documents and settings\shintorg\Application Data\uTorrent\resume.dat
c:\documents and settings\shintorg\Application Data\uTorrent\resume.dat.old
c:\documents and settings\shintorg\Application Data\uTorrent\rss.dat
c:\documents and settings\shintorg\Application Data\uTorrent\rss.dat.old
c:\documents and settings\shintorg\Application Data\uTorrent\settings.dat
c:\documents and settings\shintorg\Application Data\uTorrent\settings.dat.old
c:\documents and settings\shintorg\Application Data\uTorrent\Sopranos Season 4.1.torrent
c:\documents and settings\shintorg\Application Data\uTorrent\Sopranos Season 4.torrent
c:\documents and settings\shintorg\Application Data\uTorrent\Sopranos Season 5.1.torrent
c:\documents and settings\shintorg\Application Data\uTorrent\Sopranos Season 5.torrent
c:\documents and settings\shintorg\Application Data\uTorrent\Sopranos Season 6 Part 1.torrent
c:\documents and settings\shintorg\Application Data\uTorrent\Sopranos Season 6 Part 2.torrent
c:\documents and settings\shintorg\Application Data\uTorrent\utorrent.lng
.
((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-30 )))))))))))))))))))))))))))))))
.
2009-03-28 13:54 . 2005-07-06 20:14 1,389,056 -ra------ c:\windows\system32\drivers\P17.sys
2009-03-28 13:54 . 2003-10-01 22:48 53,248 -ra------ c:\windows\system32\P17CPI.dll
2009-03-28 13:53 . 1999-09-21 11:18 2,167,684 -ra------ c:\windows\system32\ct2mgm.sf2
2009-03-28 13:53 . 2005-01-09 22:15 138,752 -ra------ c:\windows\system32\drivers\ctsfm2k.sys
2009-03-28 13:53 . 2005-06-13 01:03 137,728 -ra------ c:\windows\system32\P17res.dll
2009-03-28 13:53 . 2005-01-09 22:15 115,200 -ra------ c:\windows\system32\sfms32.dll
2009-03-28 13:53 . 2005-01-09 22:15 106,496 -ra------ c:\windows\system32\drivers\ctoss2k.sys
2009-03-28 13:53 . 2005-01-09 22:15 20,992 -ra------ c:\windows\system32\sfman32.dll
2009-03-25 16:02 . 2005-05-02 23:38 64,512 -ra------ c:\windows\system32\P17.dll
2009-03-25 01:12 . 2009-03-25 01:12 <DIR> d-------- c:\windows\system32\URTTemp
2009-03-25 01:07 . 2009-03-25 01:07 <DIR> d-------- c:\documents and settings\shintorg\Application Data\InstallShield
2009-03-25 00:52 . 2009-03-25 01:13 <DIR> d-------- C:\Sid Meier's Civilization 4
2009-03-25 00:51 . 2005-05-26 15:34 2,297,552 --a------ c:\windows\system32\d3dx9_26.dll
2009-03-24 19:55 . 2009-03-24 19:55 <DIR> dr------- c:\program files\Norton Support
2009-03-24 19:41 . 2009-03-24 19:41 <DIR> d-------- c:\program files\Symantec
2009-03-24 19:41 . 2009-03-24 19:45 <DIR> d-------- c:\program files\Common Files\Symantec Shared
2009-03-24 19:41 . 2009-03-24 19:41 124,464 --a------ c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-24 19:41 . 2009-03-24 19:41 60,808 --a------ c:\windows\system32\S32EVNT1.DLL
2009-03-24 19:41 . 2009-03-24 19:41 36,400 -ra------ c:\windows\system32\drivers\SymIM.sys
2009-03-24 19:41 . 2009-03-24 19:41 7,386 --a------ c:\windows\system32\drivers\SYMEVENT.CAT
2009-03-24 19:41 . 2009-03-24 19:41 805 --a------ c:\windows\system32\drivers\SYMEVENT.INF
2009-03-24 19:40 . 2009-03-24 19:40 <DIR> d-------- c:\windows\system32\drivers\NAV
2009-03-24 19:40 . 2009-03-24 19:40 <DIR> d-------- c:\program files\Windows Sidebar
2009-03-24 19:40 . 2009-03-24 19:41 <DIR> d-------- c:\program files\Norton AntiVirus
2009-03-24 19:40 . 2009-03-25 13:51 <DIR> d-------- c:\documents and settings\All Users\Application Data\Symantec
2009-03-24 19:40 . 2009-03-24 19:41 <DIR> d-------- c:\documents and settings\All Users\Application Data\Norton
2009-03-24 19:38 . 2009-03-24 19:38 <DIR> d-------- c:\program files\NortonInstaller
2009-03-24 19:38 . 2009-03-24 19:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-03-24 18:14 . 2009-03-25 15:34 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-03-24 17:54 . 2007-12-24 17:37 138,384 --a------ c:\windows\system32\drivers\tmcomm.sys
2009-03-24 17:53 . 2009-03-24 18:21 <DIR> d-------- c:\documents and settings\shintorg\Application Data\HouseCall 6.6
2009-03-24 17:36 . 2009-03-25 15:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-24 16:46 . 2009-03-24 16:46 <DIR> d-------- c:\program files\AVG
2009-03-24 16:46 . 2009-03-24 16:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-03-24 16:46 . 2009-03-24 19:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-03-24 14:05 . 2009-03-25 15:33 347 --a------ c:\windows\CTWave32.INI
2009-03-24 14:05 . 2009-03-24 14:05 29 --a------ c:\windows\sfbm.INI
2009-03-17 12:19 . 2009-03-24 19:40 <DIR> d-------- c:\documents and settings\Administrator
2009-03-16 08:47 . 2009-03-24 13:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-03-16 08:41 . 2009-03-16 08:41 <DIR> d-------- c:\windows\Sun
2009-03-10 12:04 . 2009-03-10 12:04 <DIR> d-------- c:\program files\Common Files\Blizzard Entertainment
2009-03-09 16:09 . 2004-08-04 08:00 13,463,552 --a--c--- c:\windows\system32\dllcache\hwxjpn.dll
2009-03-09 03:00 . 2009-03-09 03:00 <DIR> d-------- c:\program files\MSXML 4.0
2009-03-08 02:48 . 2009-03-08 02:50 <DIR> d-------- c:\program files\Elements
2009-03-08 02:48 . 2009-03-08 02:50 <DIR> d-------- c:\program files\Common Files\Adobe
2009-03-08 02:48 . 2009-03-08 02:48 82,432 --a------ c:\windows\system32\msxml4r.dll
2009-03-08 02:48 . 2009-03-08 02:46 20,016 --------- c:\windows\system32\drivers\pxhelp20.sys
2009-03-05 04:00 . 2004-08-04 08:00 221,184 --a------ c:\windows\system32\wmpns.dll
2009-03-05 02:04 . 2009-03-28 13:58 <DIR> d-------- c:\program files\Java
2009-03-05 02:04 . 2009-03-09 05:19 410,984 --a------ c:\windows\system32\deploytk.dll
2009-03-05 02:04 . 2009-03-09 02:53 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-03-03 14:46 . 2009-03-29 01:24 <DIR> d-------- c:\documents and settings\shintorg\Application Data\dvdcss
2009-03-03 14:45 . 2009-03-17 15:26 <DIR> d-------- c:\documents and settings\shintorg\Application Data\vlc
2009-03-03 12:53 . 2009-03-14 02:39 <DIR> d-------- C:\World of Warcraft
2009-03-03 12:42 . 2009-03-03 12:43 <DIR> d-------- c:\program files\Windows Media Connect 2
2009-03-03 12:41 . 2009-03-03 15:44 <DIR> d-------- c:\documents and settings\shintorg\Application Data\Ventrilo
2009-03-03 12:39 . 2009-03-03 12:39 <DIR> d-------- c:\windows\system32\LogFiles
2009-03-03 12:39 . 2009-03-03 12:40 <DIR> d-------- c:\windows\system32\drivers\UMDF
2009-03-03 12:37 . 2009-03-03 12:37 13,646 --a------ c:\windows\system32\wpa.bak
2009-03-03 12:32 . 2009-03-24 01:20 <DIR> d-------- C:\World of Warcraft Public Test
2009-03-03 11:52 . 2009-03-03 11:52 <DIR> d-------- C:\fsaua.data
2009-03-03 11:25 . 2009-03-03 11:25 <DIR> d-------- c:\documents and settings\shintorg\Application Data\Malwarebytes
2009-03-03 11:25 . 2009-03-03 11:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-03 11:16 . 2009-03-11 02:07 <DIR> d-------- c:\windows\system32\CatRoot_bak
2009-03-03 11:16 . 2008-08-14 06:00 2,180,352 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-03 11:16 . 2008-08-14 05:58 2,136,064 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-03 11:16 . 2008-08-14 05:22 2,057,728 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-03 11:16 . 2008-08-14 05:22 2,015,744 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-03 11:16 . 2008-06-13 09:10 272,128 --------- c:\windows\system32\drivers\bthport.sys
2009-03-03 11:16 . 2008-06-13 09:10 272,128 -----c--- c:\windows\system32\dllcache\bthport.sys
2009-03-03 11:15 . 2008-10-24 07:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2009-03-03 11:12 . 2009-03-10 17:51 <DIR> d--h----- c:\windows\$hf_mig$
2009-03-03 11:12 . 2007-07-27 09:41 26,488 --a------ c:\windows\system32\spupdsvc.exe
2009-03-03 11:06 . 2009-03-03 11:06 <DIR> d-------- c:\documents and settings\shintorg\Application Data\Creative
2009-03-03 11:06 . 2009-03-28 13:48 1,072 --a------ c:\windows\system32\settingsbkup.sfm
2009-03-03 11:06 . 2009-03-28 13:48 1,072 --a------ c:\windows\system32\settings.sfm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-25 19:33 --------- d-----w c:\program files\Creative
2009-03-25 05:46 163,644 ----a-w c:\windows\system32\drivers\secdrv.sys
2009-03-25 05:13 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-20 04:48 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-03 14:45 --------- d-----w c:\program files\Common Files\InstallShield
2009-03-03 14:18 --------- d-----w c:\documents and settings\All Users\Application Data\NVIDIA
2009-03-03 14:15 --------- d-----w c:\program files\VLC
2009-03-03 14:13 --------- d-----w c:\program files\Ventrilo
2009-03-03 14:13 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-03-03 14:04 --------- d-----w c:\program files\microsoft frontpage
2009-02-26 16:46 74,760 ----a-w c:\windows\system32\drivers\UniversalDD.sys
2009-02-26 16:46 25,608 ----a-w c:\windows\system32\drivers\AVGIDSErHr.sys
2009-02-09 10:19 1,846,272 ----a-w c:\windows\system32\win32k.sys
2009-01-03 11:24 81,920 ----a-w c:\windows\system32\frapsvid.dll
2008-12-05 07:12 144,896 ----a-w c:\windows\system32\schannel.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-03-29_16.46.35.92 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-30 16:37:55 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_448.dat
+ 2009-03-30 16:38:03 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_464.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"P17Helper"="P17.dll" [2005-05-02 c:\windows\system32\P17.dll]
c:\documents and settings\shintorg\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"enablefirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\World of Warcraft Public Test\\Launcher.exe"=
"c:\\World of Warcraft\\BackgroundDownloader.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1005000.086\SymEFA.sys [2009-03-24 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1005000.086\BHDrvx86.sys [2009-03-24 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1005000.086\cchpx86.sys [2009-03-24 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090318.001\IDSXpx86.sys [2009-03-24 276344]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe [2009-03-24 115560]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\shintorg\Application Data\Mozilla\Firefox\Profiles\d2zqdpon.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.expiation-guild.org/joomla/
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\program files\VLC\npvlc.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-30 12:42:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.5.0.134\diMaster.dll\" /prefetch:1"
.
Completion time: 2009-03-30 12:42:53
ComboFix-quarantined-files.txt 2009-03-30 16:42:51
ComboFix2.txt 2009-03-29 20:47:03
Pre-Run: 143,638,069,248 bytes free
Post-Run: 144,034,312,192 bytes free
187 --- E O F --- 2009-03-11 06:07:32