martinezboada
New member
Hi,
Photoshop isn't working, but all other programs seem to be working fine. Do you recommend to disable Norton while fixing the virus issue?
Here's the combofix log:
ComboFix 08-04-18.3 - Adrian 2008-04-20 19:47:39.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1197 [GMT 1:00]
Running from: C:\Users\Adrian\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.exe
C:\Program Files\Inet Delivery
C:\Program Files\Inet Delivery\inetdl.exe
C:\Program Files\Inet Delivery\intdel.exe
C:\Windows\a.bat
C:\Windows\apoxqwfv.exe
C:\Windows\base64.tmp
C:\Windows\bdn.com
C:\Windows\FVProtect.exe
C:\Windows\iTunesMusic.exe
C:\Windows\mslagent
C:\Windows\mslagent\2_mslagent.dll
C:\Windows\mslagent\mslagent.exe
C:\Windows\mslagent\uninstall.exe
C:\Windows\mssecu.exe
C:\Windows\system32akttzn.exe
C:\Windows\system32anticipator.dll
C:\Windows\system32awtoolb.dll
C:\Windows\system32bdn.com
C:\Windows\system32bsva-egihsg52.exe
C:\Windows\system32dpcproxy.exe
C:\Windows\system32emesx.dll
C:\Windows\system32h@tkeysh@@k.dll
C:\Windows\system32hoproxy.dll
C:\Windows\system32hxiwlgpm.dat
C:\Windows\system32hxiwlgpm.exe
C:\Windows\system32medup012.dll
C:\Windows\system32medup020.dll
C:\Windows\system32msgp.exe
C:\Windows\system32msnbho.dll
C:\Windows\system32mssecu.exe
C:\Windows\system32msvchost.exe
C:\Windows\system32mtr2.exe
C:\Windows\system32mwin32.exe
C:\Windows\system32netode.exe
C:\Windows\system32newsd32.exe
C:\Windows\system32ps1.exe
C:\Windows\system32psof1.exe
C:\Windows\system32psoft1.exe
C:\Windows\system32regc64.dll
C:\Windows\system32regm64.dll
C:\Windows\system32Rundl1.exe
C:\Windows\system32smp
C:\Windows\system32smp\msrc.exe
C:\Windows\system32sncntr.exe
C:\Windows\system32ssurf022.dll
C:\Windows\system32ssvchost.com
C:\Windows\system32ssvchost.exe
C:\Windows\system32sysreq.exe
C:\Windows\system32taack.dat
C:\Windows\system32taack.exe
C:\Windows\system32temp#01.exe
C:\Windows\system32thun.dll
C:\Windows\system32thun32.dll
C:\Windows\system32VBIEWER.OCX
C:\Windows\system32vbsys2.dll
C:\Windows\system32vcatchpi.dll
C:\Windows\system32winlogonpc.exe
C:\Windows\system32winsystem.exe
C:\Windows\system32WINWGPX.EXE
C:\Windows\userconfig9x.dll
C:\Windows\vnbptxlf.dll
C:\Windows\Web\def.htm
C:\Windows\winsystem.exe
C:\Windows\zip1.tmp
C:\Windows\zip2.tmp
C:\Windows\zip3.tmp
C:\Windows\zipped.tmp
.
((((((((((((((((((((((((( Files Created from 2008-03-20 to 2008-04-20 )))))))))))))))))))))))))))))))
.
2008-04-19 23:57 . 2008-04-20 19:43 <DIR> d-------- C:\Users\Adrian\AppData\Roaming\Free Download Manager
2008-04-19 01:40 . 2008-04-19 01:40 355 --a------ C:\Windows\System32\MRT.INI
2008-04-19 01:25 . 2008-02-29 05:21 2,032,128 --a------ C:\Windows\System32\win32k.sys
2008-04-19 01:25 . 2008-02-22 03:50 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-04-19 01:25 . 2008-02-22 06:01 826,880 --a------ C:\Windows\System32\wininet.dll
2008-04-19 01:25 . 2008-02-22 05:57 295,936 --a------ C:\Windows\System32\gdi32.dll
2008-04-15 22:59 . 2008-04-15 22:59 <DIR> d-------- C:\Program Files\iTunes(342)
2008-04-15 22:59 . 2008-04-15 22:59 <DIR> d-------- C:\Program Files\iPod(341)
2008-04-15 09:50 . 2008-04-15 09:50 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-04-10 00:22 . 2008-04-10 00:22 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-07 22:34 . 2008-04-09 09:15 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-07 22:34 . 2008-04-09 09:21 <DIR> d-------- C:\PROGRA~2\Spybot - Search & Destroy
2008-04-07 16:46 . 2008-04-07 16:46 <DIR> d-------- C:\PROGRA~2\Avg7
2008-04-07 11:11 . 2008-04-07 11:11 <DIR> d-------- C:\Users\Adrian\AppData\Roaming\Download Manager
2008-04-07 02:41 . 2008-04-07 10:16 <DIR> d-a------ C:\PROGRA~2\TEMP
2008-04-06 23:31 . 2008-04-19 01:08 <DIR> d-------- C:\PROGRA~2\wzgfybah
2008-04-05 16:56 . 2008-04-19 01:07 <DIR> d-------- C:\Program Files\Norton 360
2008-04-05 16:53 . 2008-04-05 16:58 123,952 --a------ C:\Windows\System32\drivers\SYMEVENT.SYS
2008-04-05 16:53 . 2008-04-05 16:58 10,563 --a------ C:\Windows\System32\drivers\SYMEVENT.CAT
2008-04-05 16:53 . 2008-04-05 16:58 805 --a------ C:\Windows\System32\drivers\SYMEVENT.INF
2008-04-05 16:52 . 2008-04-05 16:58 <DIR> d-------- C:\Program Files\Symantec
2008-04-05 16:41 . 2008-04-20 11:00 <DIR> d-------- C:\PROGRA~2\Symantec
2008-04-05 16:20 . 2008-04-05 16:20 <DIR> dr------- C:\Windows\System32\config\systemprofile\Music
2008-04-05 16:17 . 2008-04-05 16:17 <DIR> d-------- C:\PROGRA~2\Symantec Temporary Files
2008-04-05 11:37 . 2008-04-05 11:37 <DIR> d--hs---- C:\Windows\ftpcache
2008-04-05 11:30 . 2008-04-05 11:30 54,156 --ah----- C:\Windows\QTFont.qfn
2008-04-05 11:30 . 2008-04-05 11:30 1,409 --a------ C:\Windows\QTFont.for
2008-04-05 11:29 . 2008-04-19 01:33 <DIR> d-------- C:\Program Files\iTunes
2008-04-05 11:29 . 2008-04-19 01:33 <DIR> d-------- C:\Program Files\iPod
2008-04-05 11:26 . 2008-04-05 11:27 <DIR> d-------- C:\Program Files\QuickTime
2008-04-04 12:46 . 2008-04-19 19:59 <DIR> d-------- C:\Users\Adrian\.netbeans-derby
2008-04-04 12:45 . 2008-04-04 12:45 <DIR> d-------- C:\Users\Adrian\.netbeans
2008-04-04 12:13 . 2008-04-04 12:13 <DIR> d-------- C:\Users\Adrian\.netbeans-registration
2008-04-04 12:13 . 2008-04-04 12:13 <DIR> d-------- C:\Program Files\Apache Software Foundation
2008-04-04 12:11 . 2008-04-04 12:16 <DIR> d-------- C:\Program Files\glassfish-v2ur1
2008-04-04 12:08 . 2008-04-04 12:11 <DIR> d-------- C:\Program Files\NetBeans 6.0.1
2008-04-04 12:07 . 2008-04-04 12:16 <DIR> d-------- C:\Users\Adrian\.nbi
2008-04-03 23:06 . 2008-04-03 23:06 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-04-02 13:32 . 2008-04-02 13:32 <DIR> d-------- C:\PerfLogs
2008-04-02 13:08 . 2008-04-02 12:45 152,576 --a------ C:\Windows\System32\SPWizUI.dll
2008-04-02 13:08 . 2008-04-02 12:45 47,560 --a------ C:\Windows\System32\SPReview.exe
2008-04-02 12:52 . 2008-01-18 23:33 599,552 --a------ C:\Windows\System32\vsp1cln.exe
2008-04-02 12:52 . 2008-01-18 23:33 193,024 --a------ C:\Windows\System32\recdisc.exe
2008-04-02 12:52 . 2008-01-18 23:36 142,336 --a------ C:\Windows\System32\spp.dll
2008-04-02 12:52 . 2008-01-18 23:36 28,160 --a------ C:\Windows\System32\sxproxy.dll
2008-04-02 12:52 . 2008-01-18 23:36 6,656 --a------ C:\Windows\System32\sdspres.dll
2008-04-02 12:47 . 2008-01-18 23:33 44,032 --a------ C:\Windows\System32\cbsra.exe
2008-04-02 12:45 . 2008-04-07 11:24 327,680 --a------ C:\Windows\SPInstall.etl
2008-04-02 11:23 . 2008-04-02 11:23 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\Windows\System32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\Windows\System32\QuickTime.qts
2008-03-27 14:34 . 2008-03-27 14:34 <DIR> d-------- C:\Program Files\Sun
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-20 16:35 --------- d-----w C:\PROGRA~2\WinZip
2008-04-20 15:11 --------- d-----w C:\Program Files\Free Download Manager
2008-04-20 10:30 424 ----a-w C:\Users\Adrian\AppData\Roaming\wklnhst.dat
2008-04-20 10:00 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-20 00:01 --------- d-----w C:\Program Files\Picasa2
2008-04-20 00:01 --------- d-----w C:\Program Files\Microsoft Works
2008-04-20 00:01 --------- d-----w C:\Program Files\Google
2008-04-20 00:01 --------- d-----w C:\Program Files\Common Files\Skype
2008-04-20 00:01 --------- d-----w C:\Program Files\Apoint
2008-04-20 00:01 --------- d-----w C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2008-04-20 00:00 --------- d-----w C:\Program Files\Windows Mail
2008-04-20 00:00 --------- d-----w C:\PROGRA~2\Microsoft Help
2008-04-19 23:37 --------- d-----w C:\Users\Adrian\AppData\Roaming\Skype
2008-04-19 00:08 --------- d-----w C:\PROGRA~2\FreeDownloadManager.ORG
2008-04-15 21:59 --------- d-----w C:\PROGRA~2\Apple Computer
2008-04-15 08:45 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-07 12:38 225,142 ----a-w C:\Users\Adrian\AppData\Roaming\nvModes.dat
2008-04-07 00:37 --------- d-----w C:\PROGRA~2\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2008-04-05 15:59 --------- d-----w C:\Users\Adrian\AppData\Roaming\Symantec
2008-04-05 10:32 --------- d-----w C:\PROGRA~2\Sony Corporation
2008-04-02 12:43 174 --sha-w C:\Program Files\desktop.ini
2008-04-02 12:33 --------- d-----w C:\Program Files\Windows Sidebar
2008-04-02 12:33 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-04-02 12:33 --------- d-----w C:\Program Files\Windows Journal
2008-04-02 12:33 --------- d-----w C:\Program Files\Windows Defender
2008-04-02 12:33 --------- d-----w C:\Program Files\Windows Collaboration
2008-04-02 12:33 --------- d-----w C:\Program Files\Windows Calendar
2008-04-02 12:16 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-04-02 12:16 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-03-27 20:17 --------- d-----w C:\PROGRA~2\Roxio
2008-03-27 13:34 --------- d-----w C:\Program Files\Java
2008-03-06 20:32 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf
2008-03-06 20:32 23,904 ----a-w C:\Windows\system32\drivers\COH_Mon.sys
2008-03-06 20:32 10,537 ----a-w C:\Windows\system32\drivers\coh_mon.cat
2008-02-20 01:06 24,112 ----a-w C:\Windows\system32\drivers\SymIMV.sys
2008-02-13 19:15 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-01-29 11:02 107,368 ----a-w C:\Windows\System32\GEARAspi.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2008-02-24 03:08 349552 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-04-05 16:57 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll" [2008-02-24 03:08 349552]
"{2A800B4E-351C-4230-B792-D73A5EA9CB31}"= "C:\Windows\vnbptxlf.dll" [ ]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CLASSES_ROOT\clsid\{2a800b4e-351c-4230-b792-d73a5ea9cb31}]
[HKEY_CLASSES_ROOT\vnbptxlf.1]
[HKEY_CLASSES_ROOT\TypeLib\{2114456D-6A21-4CB0-8796-FC773DB60436}]
[HKEY_CLASSES_ROOT\vnbptxlf]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll [2008-02-24 03:08 349552]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@={4433A54A-1AC8-432F-90FC-85F045CF383C}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@={F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@={476D0EA3-80F9-48B5-B70B-05E677C9C148}
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-02-26 09:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-02-26 09:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-02-26 09:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-18 23:33 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-18 23:38 1008184]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2007-06-10 01:12 118784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2007-06-12 02:27 317560]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-07-23 19:53 1831424]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Free-1"="C:\Program Files\IPEVO\Free-1 USB Phone\Free-1 USB Phone.exe" [2007-09-14 13:50 446464]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-22 02:08 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-22 02:09 842584]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-06-28 01:04 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-06-28 01:03 8429568]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-06-28 01:03 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-18 20:37 51048]
"osCheck"="C:\Program Files\Norton 360\osCheck.exe" [2008-02-26 15:50 988512]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 22:18 443968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2007-07-12 16:33 98304 C:\Windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{1C0EA9C8-F40A-4316-AE8B-074DB7442A97}"= UDP:C:\Program Files\Google\Google Talk\googletalk.exe:Google Talk
"{F4F15440-9D6E-4164-B884-DBE0D51F4153}"= TCP:C:\Program Files\Google\Google Talk\googletalk.exe:Google Talk
"{4ECD853C-BA10-45EE-91BA-738BEDD0BA2D}"= Disabled:UDP:C:\Program Files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{1BCB5D8B-B0FD-4385-8827-8E5228092650}"= Disabled:TCP:C:\Program Files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{9AF3AC34-F0E4-434D-85E8-0DB8765DCA23}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{8E69AF12-722D-4617-8E40-045241E3C2E6}"= UDP:C:\Program Files\VoipCheapCom\VoipCheapCom.exe:VoipCheapCom
"{4A75F96A-8180-42A7-91F0-A5B3D54B7C3D}"= TCP:C:\Program Files\VoipCheapCom\VoipCheapCom.exe:VoipCheapCom
"{14B08AE8-57F3-4D10-A26F-11D2CE5DE68E}"= UDP:C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe:[VAIO Media] Integrated Server
"{F8874D15-E01F-41F5-9548-404B667B2C96}"= TCP:C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe:[VAIO Media] Integrated Server
"{92859DBD-0632-46ED-974C-078880C59E75}"= UDP:C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe:[VAIO Media] HTTP Server
"{C9100289-8876-47BC-8AEF-72370B6944D3}"= TCP:C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe:[VAIO Media] HTTP Server
"{B0DAF243-DB5A-4EA5-8EB3-6B331A0CDBBD}"= UDP:C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe:[VAIO Media] Content Collection
"{6896C04D-E254-4B29-8FAA-B669734B7116}"= TCP:C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe:[VAIO Media] Content Collection
"{F335AE44-FB54-4C05-B209-059EFAE04BBA}"= UDP:C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe:[VAIO Media] UPnP Server
"{AF02CBFF-9A09-4461-8A37-305A14FB6B64}"= TCP:C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe:[VAIO Media] UPnP Server
"{D1B4BBB9-2BC5-41FB-9289-9272C9AF1D13}"= UDP:C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmServerSettings.exe:[VAIO Media] SNAC Server
"{32788583-EF6F-4642-A00C-93D0F60EDA6D}"= TCP:C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmServerSettings.exe:[VAIO Media] SNAC Server
"{844D362D-5B74-40A6-9352-D5B583A39163}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{150961B8-161A-4ECA-8A29-1908E76D1840}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{4621AD37-3F78-4A66-8FD6-023699F7F624}"= UDP:C:\Program Files\Norton 360\MAINSTUB.EXE:Norton 360
"{0EBF0EEC-810F-48DA-AE4B-55E36D878325}"= TCP:C:\Program Files\Norton 360\MAINSTUB.EXE:Norton 360
"TCP Query User{08D4BA4A-A31E-4908-969F-E78D948F6501}C:\\program files\\java\\jdk1.6.0_05\\jre\\bin\\java.exe"= UDP:C:\program files\java\jdk1.6.0_05\jre\bin\java.exe:Java(TM) Platform SE binary
"UDP Query User{0A6781A2-11B9-4F12-808F-3B28133F8B23}C:\\program files\\java\\jdk1.6.0_05\\jre\\bin\\java.exe"= TCP:C:\program files\java\jdk1.6.0_05\jre\bin\java.exe:Java(TM) Platform SE binary
"{529F0978-7600-4B3F-A368-DB8FBD46A5FC}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{CAADD9CF-AF7F-4C3D-9C5F-187D5816A749}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{2BF7C802-9E08-4626-9097-C13986F97880}"= Disabled:UDP:C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{D25F4354-AD43-4EFC-AD14-80648F64182C}"= Disabled:TCP:C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080415.001\IDSvix86.sys [2008-04-04 00:24]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R2 regi;regi;C:\Windows\system32\drivers\regi.sys [2007-04-18 04:09]
R2 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe [2007-01-11 00:51]
R2 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);"C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-UCLS-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\UCLS\HTTP" []
R2 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-06-20 23:34]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-06-05 04:20]
R3 btwaudio;Bluetooth Audio Device Service;C:\Windows\system32\drivers\btwaudio.sys [2007-07-03 02:17]
R3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2007-07-03 02:17]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys [2007-07-03 02:16]
R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-07-03 02:17]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;C:\Windows\system32\Drivers\R5U870FLx86.sys [2007-06-28 01:01]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;C:\Windows\system32\Drivers\R5U870FUx86.sys [2007-06-28 01:01]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-02-05 20:34]
R3 ti21sony;ti21sony;C:\Windows\system32\drivers\ti21sony.sys [2007-06-06 01:00]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-05-19 01:02]
S3 COH_Mon;COH_Mon;C:\Windows\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;"C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe" [2007-07-06 03:12]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;"C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe" [2007-07-06 01:43]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - G:\Autorun\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - H:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01f0c9e7-d24b-11dc-9d97-001bfb8b127a}]
\shell\AutoRun\command - H:\LaunchU3.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-20 19:55:20
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 15
**************************************************************************
.
Completion time: 2008-04-20 19:57:06
ComboFix-quarantined-files.txt 2008-04-20 18:56:38
ComboFix2.txt 2008-04-13 16:01:14
ComboFix3.txt 2008-04-13 15:31:19
ComboFix4.txt 2008-04-12 18:27:58
ComboFix5.txt 2008-04-12 17:17:32
Pre-Run: 85,892,034,560 bytes free
Post-Run: 86,613,069,824 bytes free
327 --- E O F --- 2008-04-19 00:41:45
Photoshop isn't working, but all other programs seem to be working fine. Do you recommend to disable Norton while fixing the virus issue?
Here's the combofix log:
ComboFix 08-04-18.3 - Adrian 2008-04-20 19:47:39.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1197 [GMT 1:00]
Running from: C:\Users\Adrian\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.exe
C:\Program Files\Inet Delivery
C:\Program Files\Inet Delivery\inetdl.exe
C:\Program Files\Inet Delivery\intdel.exe
C:\Windows\a.bat
C:\Windows\apoxqwfv.exe
C:\Windows\base64.tmp
C:\Windows\bdn.com
C:\Windows\FVProtect.exe
C:\Windows\iTunesMusic.exe
C:\Windows\mslagent
C:\Windows\mslagent\2_mslagent.dll
C:\Windows\mslagent\mslagent.exe
C:\Windows\mslagent\uninstall.exe
C:\Windows\mssecu.exe
C:\Windows\system32akttzn.exe
C:\Windows\system32anticipator.dll
C:\Windows\system32awtoolb.dll
C:\Windows\system32bdn.com
C:\Windows\system32bsva-egihsg52.exe
C:\Windows\system32dpcproxy.exe
C:\Windows\system32emesx.dll
C:\Windows\system32h@tkeysh@@k.dll
C:\Windows\system32hoproxy.dll
C:\Windows\system32hxiwlgpm.dat
C:\Windows\system32hxiwlgpm.exe
C:\Windows\system32medup012.dll
C:\Windows\system32medup020.dll
C:\Windows\system32msgp.exe
C:\Windows\system32msnbho.dll
C:\Windows\system32mssecu.exe
C:\Windows\system32msvchost.exe
C:\Windows\system32mtr2.exe
C:\Windows\system32mwin32.exe
C:\Windows\system32netode.exe
C:\Windows\system32newsd32.exe
C:\Windows\system32ps1.exe
C:\Windows\system32psof1.exe
C:\Windows\system32psoft1.exe
C:\Windows\system32regc64.dll
C:\Windows\system32regm64.dll
C:\Windows\system32Rundl1.exe
C:\Windows\system32smp
C:\Windows\system32smp\msrc.exe
C:\Windows\system32sncntr.exe
C:\Windows\system32ssurf022.dll
C:\Windows\system32ssvchost.com
C:\Windows\system32ssvchost.exe
C:\Windows\system32sysreq.exe
C:\Windows\system32taack.dat
C:\Windows\system32taack.exe
C:\Windows\system32temp#01.exe
C:\Windows\system32thun.dll
C:\Windows\system32thun32.dll
C:\Windows\system32VBIEWER.OCX
C:\Windows\system32vbsys2.dll
C:\Windows\system32vcatchpi.dll
C:\Windows\system32winlogonpc.exe
C:\Windows\system32winsystem.exe
C:\Windows\system32WINWGPX.EXE
C:\Windows\userconfig9x.dll
C:\Windows\vnbptxlf.dll
C:\Windows\Web\def.htm
C:\Windows\winsystem.exe
C:\Windows\zip1.tmp
C:\Windows\zip2.tmp
C:\Windows\zip3.tmp
C:\Windows\zipped.tmp
.
((((((((((((((((((((((((( Files Created from 2008-03-20 to 2008-04-20 )))))))))))))))))))))))))))))))
.
2008-04-19 23:57 . 2008-04-20 19:43 <DIR> d-------- C:\Users\Adrian\AppData\Roaming\Free Download Manager
2008-04-19 01:40 . 2008-04-19 01:40 355 --a------ C:\Windows\System32\MRT.INI
2008-04-19 01:25 . 2008-02-29 05:21 2,032,128 --a------ C:\Windows\System32\win32k.sys
2008-04-19 01:25 . 2008-02-22 03:50 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-04-19 01:25 . 2008-02-22 06:01 826,880 --a------ C:\Windows\System32\wininet.dll
2008-04-19 01:25 . 2008-02-22 05:57 295,936 --a------ C:\Windows\System32\gdi32.dll
2008-04-15 22:59 . 2008-04-15 22:59 <DIR> d-------- C:\Program Files\iTunes(342)
2008-04-15 22:59 . 2008-04-15 22:59 <DIR> d-------- C:\Program Files\iPod(341)
2008-04-15 09:50 . 2008-04-15 09:50 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-04-10 00:22 . 2008-04-10 00:22 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-07 22:34 . 2008-04-09 09:15 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-07 22:34 . 2008-04-09 09:21 <DIR> d-------- C:\PROGRA~2\Spybot - Search & Destroy
2008-04-07 16:46 . 2008-04-07 16:46 <DIR> d-------- C:\PROGRA~2\Avg7
2008-04-07 11:11 . 2008-04-07 11:11 <DIR> d-------- C:\Users\Adrian\AppData\Roaming\Download Manager
2008-04-07 02:41 . 2008-04-07 10:16 <DIR> d-a------ C:\PROGRA~2\TEMP
2008-04-06 23:31 . 2008-04-19 01:08 <DIR> d-------- C:\PROGRA~2\wzgfybah
2008-04-05 16:56 . 2008-04-19 01:07 <DIR> d-------- C:\Program Files\Norton 360
2008-04-05 16:53 . 2008-04-05 16:58 123,952 --a------ C:\Windows\System32\drivers\SYMEVENT.SYS
2008-04-05 16:53 . 2008-04-05 16:58 10,563 --a------ C:\Windows\System32\drivers\SYMEVENT.CAT
2008-04-05 16:53 . 2008-04-05 16:58 805 --a------ C:\Windows\System32\drivers\SYMEVENT.INF
2008-04-05 16:52 . 2008-04-05 16:58 <DIR> d-------- C:\Program Files\Symantec
2008-04-05 16:41 . 2008-04-20 11:00 <DIR> d-------- C:\PROGRA~2\Symantec
2008-04-05 16:20 . 2008-04-05 16:20 <DIR> dr------- C:\Windows\System32\config\systemprofile\Music
2008-04-05 16:17 . 2008-04-05 16:17 <DIR> d-------- C:\PROGRA~2\Symantec Temporary Files
2008-04-05 11:37 . 2008-04-05 11:37 <DIR> d--hs---- C:\Windows\ftpcache
2008-04-05 11:30 . 2008-04-05 11:30 54,156 --ah----- C:\Windows\QTFont.qfn
2008-04-05 11:30 . 2008-04-05 11:30 1,409 --a------ C:\Windows\QTFont.for
2008-04-05 11:29 . 2008-04-19 01:33 <DIR> d-------- C:\Program Files\iTunes
2008-04-05 11:29 . 2008-04-19 01:33 <DIR> d-------- C:\Program Files\iPod
2008-04-05 11:26 . 2008-04-05 11:27 <DIR> d-------- C:\Program Files\QuickTime
2008-04-04 12:46 . 2008-04-19 19:59 <DIR> d-------- C:\Users\Adrian\.netbeans-derby
2008-04-04 12:45 . 2008-04-04 12:45 <DIR> d-------- C:\Users\Adrian\.netbeans
2008-04-04 12:13 . 2008-04-04 12:13 <DIR> d-------- C:\Users\Adrian\.netbeans-registration
2008-04-04 12:13 . 2008-04-04 12:13 <DIR> d-------- C:\Program Files\Apache Software Foundation
2008-04-04 12:11 . 2008-04-04 12:16 <DIR> d-------- C:\Program Files\glassfish-v2ur1
2008-04-04 12:08 . 2008-04-04 12:11 <DIR> d-------- C:\Program Files\NetBeans 6.0.1
2008-04-04 12:07 . 2008-04-04 12:16 <DIR> d-------- C:\Users\Adrian\.nbi
2008-04-03 23:06 . 2008-04-03 23:06 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-04-02 13:32 . 2008-04-02 13:32 <DIR> d-------- C:\PerfLogs
2008-04-02 13:08 . 2008-04-02 12:45 152,576 --a------ C:\Windows\System32\SPWizUI.dll
2008-04-02 13:08 . 2008-04-02 12:45 47,560 --a------ C:\Windows\System32\SPReview.exe
2008-04-02 12:52 . 2008-01-18 23:33 599,552 --a------ C:\Windows\System32\vsp1cln.exe
2008-04-02 12:52 . 2008-01-18 23:33 193,024 --a------ C:\Windows\System32\recdisc.exe
2008-04-02 12:52 . 2008-01-18 23:36 142,336 --a------ C:\Windows\System32\spp.dll
2008-04-02 12:52 . 2008-01-18 23:36 28,160 --a------ C:\Windows\System32\sxproxy.dll
2008-04-02 12:52 . 2008-01-18 23:36 6,656 --a------ C:\Windows\System32\sdspres.dll
2008-04-02 12:47 . 2008-01-18 23:33 44,032 --a------ C:\Windows\System32\cbsra.exe
2008-04-02 12:45 . 2008-04-07 11:24 327,680 --a------ C:\Windows\SPInstall.etl
2008-04-02 11:23 . 2008-04-02 11:23 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\Windows\System32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\Windows\System32\QuickTime.qts
2008-03-27 14:34 . 2008-03-27 14:34 <DIR> d-------- C:\Program Files\Sun
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-20 16:35 --------- d-----w C:\PROGRA~2\WinZip
2008-04-20 15:11 --------- d-----w C:\Program Files\Free Download Manager
2008-04-20 10:30 424 ----a-w C:\Users\Adrian\AppData\Roaming\wklnhst.dat
2008-04-20 10:00 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-20 00:01 --------- d-----w C:\Program Files\Picasa2
2008-04-20 00:01 --------- d-----w C:\Program Files\Microsoft Works
2008-04-20 00:01 --------- d-----w C:\Program Files\Google
2008-04-20 00:01 --------- d-----w C:\Program Files\Common Files\Skype
2008-04-20 00:01 --------- d-----w C:\Program Files\Apoint
2008-04-20 00:01 --------- d-----w C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2008-04-20 00:00 --------- d-----w C:\Program Files\Windows Mail
2008-04-20 00:00 --------- d-----w C:\PROGRA~2\Microsoft Help
2008-04-19 23:37 --------- d-----w C:\Users\Adrian\AppData\Roaming\Skype
2008-04-19 00:08 --------- d-----w C:\PROGRA~2\FreeDownloadManager.ORG
2008-04-15 21:59 --------- d-----w C:\PROGRA~2\Apple Computer
2008-04-15 08:45 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-07 12:38 225,142 ----a-w C:\Users\Adrian\AppData\Roaming\nvModes.dat
2008-04-07 00:37 --------- d-----w C:\PROGRA~2\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2008-04-05 15:59 --------- d-----w C:\Users\Adrian\AppData\Roaming\Symantec
2008-04-05 10:32 --------- d-----w C:\PROGRA~2\Sony Corporation
2008-04-02 12:43 174 --sha-w C:\Program Files\desktop.ini
2008-04-02 12:33 --------- d-----w C:\Program Files\Windows Sidebar
2008-04-02 12:33 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-04-02 12:33 --------- d-----w C:\Program Files\Windows Journal
2008-04-02 12:33 --------- d-----w C:\Program Files\Windows Defender
2008-04-02 12:33 --------- d-----w C:\Program Files\Windows Collaboration
2008-04-02 12:33 --------- d-----w C:\Program Files\Windows Calendar
2008-04-02 12:16 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-04-02 12:16 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-03-27 20:17 --------- d-----w C:\PROGRA~2\Roxio
2008-03-27 13:34 --------- d-----w C:\Program Files\Java
2008-03-06 20:32 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf
2008-03-06 20:32 23,904 ----a-w C:\Windows\system32\drivers\COH_Mon.sys
2008-03-06 20:32 10,537 ----a-w C:\Windows\system32\drivers\coh_mon.cat
2008-02-20 01:06 24,112 ----a-w C:\Windows\system32\drivers\SymIMV.sys
2008-02-13 19:15 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-01-29 11:02 107,368 ----a-w C:\Windows\System32\GEARAspi.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2008-02-24 03:08 349552 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-04-05 16:57 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll" [2008-02-24 03:08 349552]
"{2A800B4E-351C-4230-B792-D73A5EA9CB31}"= "C:\Windows\vnbptxlf.dll" [ ]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CLASSES_ROOT\clsid\{2a800b4e-351c-4230-b792-d73a5ea9cb31}]
[HKEY_CLASSES_ROOT\vnbptxlf.1]
[HKEY_CLASSES_ROOT\TypeLib\{2114456D-6A21-4CB0-8796-FC773DB60436}]
[HKEY_CLASSES_ROOT\vnbptxlf]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll [2008-02-24 03:08 349552]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@={4433A54A-1AC8-432F-90FC-85F045CF383C}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@={F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@={476D0EA3-80F9-48B5-B70B-05E677C9C148}
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-02-26 09:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-02-26 09:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-02-26 09:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-18 23:33 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-18 23:38 1008184]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2007-06-10 01:12 118784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2007-06-12 02:27 317560]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-07-23 19:53 1831424]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Free-1"="C:\Program Files\IPEVO\Free-1 USB Phone\Free-1 USB Phone.exe" [2007-09-14 13:50 446464]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-22 02:08 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-22 02:09 842584]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-06-28 01:04 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-06-28 01:03 8429568]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-06-28 01:03 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-18 20:37 51048]
"osCheck"="C:\Program Files\Norton 360\osCheck.exe" [2008-02-26 15:50 988512]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 22:18 443968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2007-07-12 16:33 98304 C:\Windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{1C0EA9C8-F40A-4316-AE8B-074DB7442A97}"= UDP:C:\Program Files\Google\Google Talk\googletalk.exe:Google Talk
"{F4F15440-9D6E-4164-B884-DBE0D51F4153}"= TCP:C:\Program Files\Google\Google Talk\googletalk.exe:Google Talk
"{4ECD853C-BA10-45EE-91BA-738BEDD0BA2D}"= Disabled:UDP:C:\Program Files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{1BCB5D8B-B0FD-4385-8827-8E5228092650}"= Disabled:TCP:C:\Program Files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{9AF3AC34-F0E4-434D-85E8-0DB8765DCA23}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{8E69AF12-722D-4617-8E40-045241E3C2E6}"= UDP:C:\Program Files\VoipCheapCom\VoipCheapCom.exe:VoipCheapCom
"{4A75F96A-8180-42A7-91F0-A5B3D54B7C3D}"= TCP:C:\Program Files\VoipCheapCom\VoipCheapCom.exe:VoipCheapCom
"{14B08AE8-57F3-4D10-A26F-11D2CE5DE68E}"= UDP:C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe:[VAIO Media] Integrated Server
"{F8874D15-E01F-41F5-9548-404B667B2C96}"= TCP:C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe:[VAIO Media] Integrated Server
"{92859DBD-0632-46ED-974C-078880C59E75}"= UDP:C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe:[VAIO Media] HTTP Server
"{C9100289-8876-47BC-8AEF-72370B6944D3}"= TCP:C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe:[VAIO Media] HTTP Server
"{B0DAF243-DB5A-4EA5-8EB3-6B331A0CDBBD}"= UDP:C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe:[VAIO Media] Content Collection
"{6896C04D-E254-4B29-8FAA-B669734B7116}"= TCP:C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe:[VAIO Media] Content Collection
"{F335AE44-FB54-4C05-B209-059EFAE04BBA}"= UDP:C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe:[VAIO Media] UPnP Server
"{AF02CBFF-9A09-4461-8A37-305A14FB6B64}"= TCP:C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe:[VAIO Media] UPnP Server
"{D1B4BBB9-2BC5-41FB-9289-9272C9AF1D13}"= UDP:C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmServerSettings.exe:[VAIO Media] SNAC Server
"{32788583-EF6F-4642-A00C-93D0F60EDA6D}"= TCP:C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmServerSettings.exe:[VAIO Media] SNAC Server
"{844D362D-5B74-40A6-9352-D5B583A39163}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{150961B8-161A-4ECA-8A29-1908E76D1840}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{4621AD37-3F78-4A66-8FD6-023699F7F624}"= UDP:C:\Program Files\Norton 360\MAINSTUB.EXE:Norton 360
"{0EBF0EEC-810F-48DA-AE4B-55E36D878325}"= TCP:C:\Program Files\Norton 360\MAINSTUB.EXE:Norton 360
"TCP Query User{08D4BA4A-A31E-4908-969F-E78D948F6501}C:\\program files\\java\\jdk1.6.0_05\\jre\\bin\\java.exe"= UDP:C:\program files\java\jdk1.6.0_05\jre\bin\java.exe:Java(TM) Platform SE binary
"UDP Query User{0A6781A2-11B9-4F12-808F-3B28133F8B23}C:\\program files\\java\\jdk1.6.0_05\\jre\\bin\\java.exe"= TCP:C:\program files\java\jdk1.6.0_05\jre\bin\java.exe:Java(TM) Platform SE binary
"{529F0978-7600-4B3F-A368-DB8FBD46A5FC}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{CAADD9CF-AF7F-4C3D-9C5F-187D5816A749}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{2BF7C802-9E08-4626-9097-C13986F97880}"= Disabled:UDP:C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{D25F4354-AD43-4EFC-AD14-80648F64182C}"= Disabled:TCP:C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080415.001\IDSvix86.sys [2008-04-04 00:24]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R2 regi;regi;C:\Windows\system32\drivers\regi.sys [2007-04-18 04:09]
R2 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe [2007-01-11 00:51]
R2 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);"C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-UCLS-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\UCLS\HTTP" []
R2 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-06-20 23:34]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-06-05 04:20]
R3 btwaudio;Bluetooth Audio Device Service;C:\Windows\system32\drivers\btwaudio.sys [2007-07-03 02:17]
R3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2007-07-03 02:17]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys [2007-07-03 02:16]
R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-07-03 02:17]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;C:\Windows\system32\Drivers\R5U870FLx86.sys [2007-06-28 01:01]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;C:\Windows\system32\Drivers\R5U870FUx86.sys [2007-06-28 01:01]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-02-05 20:34]
R3 ti21sony;ti21sony;C:\Windows\system32\drivers\ti21sony.sys [2007-06-06 01:00]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-05-19 01:02]
S3 COH_Mon;COH_Mon;C:\Windows\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;"C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe" [2007-07-06 03:12]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;"C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe" [2007-07-06 01:43]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - G:\Autorun\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - H:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01f0c9e7-d24b-11dc-9d97-001bfb8b127a}]
\shell\AutoRun\command - H:\LaunchU3.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-20 19:55:20
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 15
**************************************************************************
.
Completion time: 2008-04-20 19:57:06
ComboFix-quarantined-files.txt 2008-04-20 18:56:38
ComboFix2.txt 2008-04-13 16:01:14
ComboFix3.txt 2008-04-13 15:31:19
ComboFix4.txt 2008-04-12 18:27:58
ComboFix5.txt 2008-04-12 17:17:32
Pre-Run: 85,892,034,560 bytes free
Post-Run: 86,613,069,824 bytes free
327 --- E O F --- 2008-04-19 00:41:45