EDIT: I noticed that my logs say Norton is disabled, however, it's giving me the impression that it's running.
EDIT2: Removed the code tags from my logs. Seems like they are unwanted around here.
Here are my logs:
GMER:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-07-29 21:03:52
Windows 6.1.7601 Service Pack 1
Running: 9tyx7rhu.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0026832d7cb1
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0026832d7cb1 (not active ControlSet)
---- EOF - GMER 1.0.15 ----
DDS:
.
DDS (Ver_2011-06-23.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Shawn at 10:21:04 on 2011-07-30
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8169.6386 [GMT -4:00]
.
AV: Norton Security Suite *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Security Suite *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Security Suite *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Windows\system32\IProsetMonitor.exe
C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\PS3 Media Server\win32\service\wrapper.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\SysWOW64\java.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Hewlett-Packard\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\UI0Detect.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\dllhost.exe
C:\Windows\System32\msdtc.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit=userinit.exe,
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\IPS\IPSBHO.DLL
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO: CIESpeechBHO Class: {8d10f6c4-0e01-4bd4-8601-11ac1fdf8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO: {cbc5b60a-aa4d-45f6-84c2-d086f320299a} - No File
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [Google Update] "C:\Users\Shawn\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [AdobeBridge]
mRun: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.4.26.0.cab
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{1CE16BC8-19D1-4C7B-B9E3-4BA2E1BE89ED} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{9715E4C9-ACA8-4FE7-8DB2-A1464A1DACE4} : DhcpNameServer = 192.168.2.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO-X64: HP Print Enhancer - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll
BHO-X64: Symantec NCO BHO - No File
BHO-X64: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\IPS\IPSBHO.DLL
BHO-X64: Symantec Intrusion Prevention - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO-X64: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
BHO-X64: IESpeakDoc - No File
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: {cbc5b60a-aa4d-45f6-84c2-d086f320299a} - No File
BHO-X64: BHO Project - No File
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
BHO-X64: HP Smart BHO Class - No File
TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll
EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
mRun-x64: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
mRun-x64: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun-x64: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun-x64: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [HP Software Update] C:\Program Files (x86)\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
mRun-x64: [(Default)]
mRun-x64: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Shawn\AppData\Roaming\Mozilla\Firefox\Profiles\ii0iyt5t.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: C:\Users\Shawn\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: C:\Users\Shawn\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Shawn\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;C:\Windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS --> C:\Windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [?]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS --> C:\Windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [?]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20110723.001\BHDrvx64.sys [2011-7-22 1151096]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20110729.030\IDSviA64.sys [2011-7-29 488056]
R1 SymIRON;Symantec Iron Driver;C:\Windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS --> C:\Windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [?]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\system32\Drivers\N360x64\0501000.01D\SYMNETS.SYS --> C:\Windows\system32\Drivers\N360x64\0501000.01D\SYMNETS.SYS [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2010-10-27 52896]
R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;C:\Windows\system32\IProsetMonitor.exe --> C:\Windows\system32\IProsetMonitor.exe [?]
R2 N360;Norton Security Suite;C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\ccsvchst.exe [2011-6-2 130008]
R2 PS3 Media Server;PS3 Media Server;C:\Program Files (x86)\PS3 Media Server\win32\service\wrapper.exe [2011-5-17 366872]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AthBTPort;Atheros Virtual Bluetooth Class;C:\Windows\system32\DRIVERS\btath_flt.sys --> C:\Windows\system32\DRIVERS\btath_flt.sys [?]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\system32\drivers\btath_a2dp.sys --> C:\Windows\system32\drivers\btath_a2dp.sys [?]
R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\system32\DRIVERS\btath_bus.sys --> C:\Windows\system32\DRIVERS\btath_bus.sys [?]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\system32\DRIVERS\btath_hcrp.sys --> C:\Windows\system32\DRIVERS\btath_hcrp.sys [?]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\system32\DRIVERS\btath_lwflt.sys --> C:\Windows\system32\DRIVERS\btath_lwflt.sys [?]
R3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\system32\DRIVERS\btath_rcp.sys --> C:\Windows\system32\DRIVERS\btath_rcp.sys [?]
R3 BtFilter;BtFilter;C:\Windows\system32\DRIVERS\btfilter.sys --> C:\Windows\system32\DRIVERS\btfilter.sys [?]
R3 e1cexpress;Intel® PRO/1000 PCI Express Network Connection Driver C;C:\Windows\system32\DRIVERS\e1c62x64.sys --> C:\Windows\system32\DRIVERS\e1c62x64.sys [?]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-7-29 136824]
R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 ATHDFU;Atheros Valkyrie USB BootROM;C:\Windows\system32\Drivers\AthDfu.sys --> C:\Windows\system32\Drivers\AthDfu.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\C:\Windows\system32\4135.tmp --> C:\Windows\system32\4135.tmp [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-12-27 31124344]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-07-30 01:57:28 -------- d-----w- C:\Users\Shawn\DoctorWeb
2011-07-30 01:44:32 18816 ------w- C:\Windows\SysWow64\SAVRKBootTasks.sys
2011-07-30 01:36:51 6144 ------w- C:\Windows\System32\4135.tmp
2011-07-30 01:36:32 6144 ------w- C:\Windows\System32\F7D5.tmp
2011-07-30 01:36:19 -------- d-----w- C:\Program Files (x86)\Sophos
2011-07-30 00:43:32 34560 ----a-w- C:\Windows\SysWow64\drivers\Normandy.sys
2011-07-30 00:39:59 35712 ----a-w- C:\Windows\SysWow64\drivers\BlackBox.sys
2011-07-30 00:16:33 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-07-29 22:21:56 737072 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll
2011-07-29 22:21:43 4283672 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2011-07-29 22:21:29 42776 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2011-07-29 22:21:26 539968 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-07-29 22:14:33 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-07-29 22:02:29 -------- d-----w- C:\Users\Shawn\AppData\Roaming\Malwarebytes
2011-07-29 22:01:49 -------- d-----w- C:\ProgramData\Malwarebytes
2011-07-29 22:01:46 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-07-29 21:47:56 200976 ----a-w- C:\Windows\SysWow64\drivers\tmcomm.sys
2011-07-29 21:37:14 2829 ----a-w- C:\Windows\War3Unin.pif
2011-07-29 21:37:14 139264 ----a-w- C:\Windows\War3Unin.exe
2011-07-26 23:08:30 -------- d-----w- C:\Users\Shawn\AppData\Roaming\OpenOffice.org
2011-07-26 22:29:57 -------- d-----w- C:\Users\Shawn\AppData\Roaming\XBMC
2011-07-26 22:28:28 -------- d-----w- C:\Program Files (x86)\XBMC
2011-07-26 21:29:52 -------- d-----w- C:\Program Files (x86)\OpenOffice.org 3
2011-07-26 01:48:00 0 --sha-w- C:\Windows\conta32.exe
2011-07-25 22:34:59 580096 ----a-w- C:\Windows\System32\ac3filter64.acm
2011-07-25 22:34:59 497664 ----a-w- C:\Windows\SysWow64\ac3filter.acm
2011-07-25 22:34:59 -------- d-----w- C:\Program Files (x86)\AC3Filter
2011-07-23 01:40:00 0 --sha-w- C:\Windows\conappssvc.exe
2011-07-23 01:36:01 0 --sha-w- C:\Windows\configser.exe
2011-07-22 21:36:03 453456 ----a-w- C:\Windows\SysWow64\d3dx10_42.dll
2011-07-21 07:00:30 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2011-07-20 01:44:00 0 --sha-w- C:\Windows\bgscan.exe
2011-07-20 01:36:20 64512 --sha-r- C:\Windows\SysWow64\ncobjapi9.dll
2011-07-19 21:03:50 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe
2011-07-19 21:01:26 -------- d-----w- C:\ProgramData\ALM
2011-07-19 18:03:30 -------- d-----w- C:\ProgramData\WEBREG
2011-07-19 18:03:11 -------- d-----w- C:\Users\Shawn\AppData\Local\HP
2011-07-19 18:02:30 253440 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\hpfpp02t.dll
2011-07-19 18:02:01 -------- d-----w- C:\Program Files (x86)\Microsoft
2011-07-19 18:01:49 -------- d-----w- C:\Windows\SysWow64\spool
2011-07-19 18:01:26 -------- d-----w- C:\Users\Shawn\AppData\Roaming\HpUpdate
2011-07-19 18:01:10 -------- d-----w- C:\Program Files (x86)\Common Files\HP
2011-07-19 18:01:00 138752 ----a-w- C:\Windows\System32\hpf3l02t.dll
2011-07-19 18:00:57 -------- d-----w- C:\Program Files (x86)\HP
2011-07-19 17:58:45 906240 ----a-w- C:\Windows\System32\hpwwiax5.dll
2011-07-19 17:58:45 644456 ----a-w- C:\Windows\System32\hpzids40.dll
2011-07-19 17:58:45 553472 ----a-w- C:\Windows\System32\hppldcoi.dll
2011-07-19 17:58:45 488960 ----a-w- C:\Windows\System32\hpovst11.dll
2011-07-19 17:58:45 1422848 ----a-w- C:\Windows\System32\hpwtiop4.dll
2011-07-19 00:14:30 -------- d-----w- C:\Windows\ehome
2011-07-18 23:59:10 -------- d-----w- C:\ProgramData\PMS
2011-07-18 23:59:06 -------- d-----w- C:\Program Files (x86)\PS3 Media Server
2011-07-18 23:52:49 737072 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2011-07-18 23:52:38 4283672 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-07-18 23:52:23 42776 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-07-18 23:52:20 539968 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-07-15 10:20:43 258048 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\hpfppw73.dll
2011-07-13 00:25:19 -------- d-----w- C:\Users\Shawn\AppData\Local\Microsoft Help
2011-07-10 15:35:22 -------- d-----w- C:\Users\Shawn\AppData\Local\ElevatedDiagnostics
2011-07-10 14:40:54 -------- d-----w- C:\Program Files (x86)\Common Files\Hewlett-Packard
2011-07-10 14:40:39 -------- d-----w- C:\Program Files (x86)\Common Files\MSSoap
2011-07-03 01:34:50 59839 --sh--w- C:\Windows\dtmn.exe
.
==================== Find3M ====================
.
2011-07-22 21:35:42 466456 ----a-w- C:\Windows\System32\wrap_oal.dll
2011-07-22 21:35:42 444952 ----a-w- C:\Windows\SysWow64\wrap_oal.dll
2011-07-22 21:35:42 122904 ----a-w- C:\Windows\System32\OpenAL32.dll
2011-07-22 21:35:42 109080 ----a-w- C:\Windows\SysWow64\OpenAL32.dll
2011-06-18 15:41:10 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-06-11 03:07:25 3137536 ----a-w- C:\Windows\System32\win32k.sys
2011-06-09 21:25:03 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-06-04 23:35:54 178800 ----a-w- C:\Windows\SysWow64\CmdLineExt_x64.dll
2011-06-03 06:57:45 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-06-03 06:57:45 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-06-03 06:57:45 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-06-03 06:57:44 214528 ----a-w- C:\Windows\System32\winsrv.dll
2011-06-03 06:57:38 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-06-03 06:56:38 421888 ----a-w- C:\Windows\System32\KernelBase.dll
2011-06-03 06:53:33 338944 ----a-w- C:\Windows\System32\conhost.exe
2011-06-03 06:00:53 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-06-03 05:57:52 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-06-03 05:57:33 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-06-03 05:56:12 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-06-03 05:56:11 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-06-03 03:53:31 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-06-03 03:53:31 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-06-03 03:48:32 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-06-03 03:48:31 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-06-03 03:48:31 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-06-03 03:48:31 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-06-02 23:42:04 189480 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2011-06-02 21:09:06 174200 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2011-06-02 18:04:08 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-06-02 18:04:08 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-06-02 17:11:20 0 ----a-w- C:\Windows\ativpsrm.bin
2011-05-25 04:26:56 9359872 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2011-05-25 03:53:28 23336960 ----a-w- C:\Windows\System32\atio6axx.dll
2011-05-25 03:44:30 61952 ----a-w- C:\Windows\System32\OVDecode64.dll
2011-05-25 03:44:26 59904 ----a-w- C:\Windows\SysWow64\OVDecode.dll
2011-05-25 03:44:04 16672768 ----a-w- C:\Windows\System32\amdocl64.dll
2011-05-25 03:43:50 12798976 ----a-w- C:\Windows\SysWow64\amdocl.dll
2011-05-25 03:31:38 17940992 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2011-05-25 03:07:58 151552 ----a-w- C:\Windows\System32\atiapfxx.exe
2011-05-25 03:07:48 688128 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2011-05-25 03:06:38 811008 ----a-w- C:\Windows\System32\aticfx64.dll
2011-05-25 03:04:16 462848 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2011-05-25 03:04:10 485376 ----a-w- C:\Windows\System32\atieclxx.exe
2011-05-25 03:03:38 204288 ----a-w- C:\Windows\System32\atiesrxx.exe
2011-05-25 03:02:30 120320 ----a-w- C:\Windows\System32\atitmm64.dll
2011-05-25 03:02:16 423424 ----a-w- C:\Windows\System32\atipdl64.dll
2011-05-25 03:02:10 356352 ----a-w- C:\Windows\SysWow64\atipdlxx.dll
2011-05-25 03:02:00 278528 ----a-w- C:\Windows\SysWow64\Oemdspif.dll
2011-05-25 03:01:54 16384 ----a-w- C:\Windows\System32\atimuixx.dll
2011-05-25 03:01:50 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2011-05-25 03:01:46 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2011-05-25 03:00:00 1113088 ----a-w- C:\Windows\System32\atiumd6v.dll
2011-05-25 02:59:38 1828864 ----a-w- C:\Windows\SysWow64\atiumdmv.dll
2011-05-25 02:59:26 3810816 ----a-w- C:\Windows\System32\atiumd6a.dll
2011-05-25 02:58:52 4219904 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2011-05-25 02:50:38 4017152 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2011-05-25 02:49:44 5008384 ----a-w- C:\Windows\System32\atidxx64.dll
2011-05-25 02:47:40 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
2011-05-25 02:47:38 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2011-05-25 02:47:30 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2011-05-25 02:47:28 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
2011-05-25 02:47:18 8489472 ----a-w- C:\Windows\System32\aticaldd64.dll
2011-05-25 02:43:52 6847488 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2011-05-25 02:39:16 4330496 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2011-05-25 02:38:18 53760 ----a-w- C:\Windows\System32\atimpc64.dll
2011-05-25 02:38:18 53760 ----a-w- C:\Windows\System32\amdpcom64.dll
2011-05-25 02:38:14 52736 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2011-05-25 02:38:14 52736 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2011-05-25 02:33:04 5486592 ----a-w- C:\Windows\System32\atiumd64.dll
2011-05-25 02:26:18 366592 ----a-w- C:\Windows\System32\atiadlxx.dll
2011-05-25 02:26:12 262144 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2011-05-25 02:26:04 14848 ----a-w- C:\Windows\System32\atig6pxx.dll
2011-05-25 02:26:00 12800 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
2011-05-25 02:26:00 12800 ----a-w- C:\Windows\System32\atiglpxx.dll
2011-05-25 02:25:58 39936 ----a-w- C:\Windows\System32\atig6txx.dll
2011-05-25 02:25:48 32768 ----a-w- C:\Windows\SysWow64\atigktxx.dll
2011-05-25 02:25:42 309760 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
2011-05-25 02:24:58 40960 ----a-w- C:\Windows\System32\atiuxp64.dll
2011-05-25 02:24:50 31744 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2011-05-25 02:24:44 38912 ----a-w- C:\Windows\System32\atiu9p64.dll
2011-05-25 02:24:36 29184 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2011-05-25 02:24:08 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2011-05-25 02:19:00 58880 ----a-w- C:\Windows\System32\coinst.dll
2011-05-24 23:14:10 270720 ------w- C:\Windows\System32\MpSigStub.exe
2011-05-24 11:42:55 404480 ----a-w- C:\Windows\System32\umpnpmgr.dll
2011-05-24 10:40:05 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
2011-05-24 10:40:05 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll
2011-05-24 10:39:38 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll
2011-05-24 10:37:54 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe
2011-05-05 05:27:58 51712 ----a-w- C:\Windows\SysWow64\OpenCL.dll
2011-05-04 05:25:03 2315776 ----a-w- C:\Windows\System32\tquery.dll
2011-05-04 05:22:25 778752 ----a-w- C:\Windows\System32\mssvp.dll
2011-05-04 05:22:25 2223616 ----a-w- C:\Windows\System32\mssrch.dll
2011-05-04 05:22:24 75264 ----a-w- C:\Windows\System32\msscntrs.dll
2011-05-04 05:22:24 491520 ----a-w- C:\Windows\System32\mssph.dll
2011-05-04 05:22:24 288256 ----a-w- C:\Windows\System32\mssphtb.dll
2011-05-04 05:19:28 591872 ----a-w- C:\Windows\System32\SearchIndexer.exe
2011-05-04 05:19:28 249856 ----a-w- C:\Windows\System32\SearchProtocolHost.exe
2011-05-04 05:19:28 113664 ----a-w- C:\Windows\System32\SearchFilterHost.exe
2011-05-04 04:34:43 1549312 ----a-w- C:\Windows\SysWow64\tquery.dll
.
============= FINISH: 10:21:16.96 ===============
I've attached my other DDS log as requested.
Thank you for any help, this is frustrating.. What kind of jerk off makes these things?
Attached File(s)
-
Attach.txt (5.74K)
Number of downloads: 0
This post has been edited by quomodo: 30 July 2011 - 09:59 AM

Help
This topic is locked

Back to top











