Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan.Alemod


  • This topic is locked This topic is locked
14 replies to this topic

#1 packman1234

packman1234

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:52 PM

Posted 20 February 2010 - 09:47 AM

Hi
I keep getting this notification in my Norton Virus Scans. Trojan.Alemod cannot be removed.
Here is the info.. My Firefox locks up frequently and this machine is getting very slow... Please Help!!

DDS (Ver_09-12-01.01) - NTFSx86
Run by Bob at 8:29:30.51 on Sat 02/20/2010
Internet Explorer: 8.0.6001.18882 BrowserJavaVersion: 1.6.0_18
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.2046.1246 [GMT -6:00]

SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FW: Norton AntiVirus *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\CTsvcCDA.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe
C:\Program Files\OO Software\Defrag\oodag.exe
C:\Windows\system32\IoctlSvc.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe -k imgsvc
D:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\OO Software\Defrag\oodtray.exe
D:\Program Files\MX Mouse\SetPoint\SetPoint.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\Bob\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Bob\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Users\Bob\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bob\Documents\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Bob\Documents\Downloads\dds.scr
C:\PROGRAM FILES\NORTON ANTIVIRUS\ENGINE\16.8.0.41\cltLMH.exe

============== Pseudo HJT Report ===============

uStart Page = about:blank
uInternet Settings,ProxyOverride = <local>;*.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - d:\program files\spybot - search & destroy\SDHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\16.8.0.41\IPSBHO.DLL
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: OToolbarHelper Class: {ead3a971-6a23-4246-8691-c9244e858967} - c:\program files\paypal\paypal plug-in\PayPalHelper.dll
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [<NO NAME>]
mRun: [OODefragTray] c:\program files\oo software\defrag\oodtray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - d:\program files\mx mouse\setpoint\SetPoint.exe
uPolicies-explorer: NoAddPrinter = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Download all by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/202
IE: &Download by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Download selected by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/203
IE: &Grab video by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/204
IE: Append to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - d:\program files\spybot - search & destroy\SDHelper.dll
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15111/CTPID.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - eBay
FF - prefs.js: browser.startup.homepage - hxxp://forecast.weather.gov/MapClick.php?CityName=Menomonee+Falls&state=WI&site=MKX&textField1=43.1472&textField2=-88.1259
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNfox000&fl=0&ptb=qpSaoYRNbM37Y4egFwlnRw&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=
FF - component: c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\extensions\{a6e4a4eb-d169-4e99-8988-250fcbafe767}\components\FFExternalAlert.dll
FF - component: c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\extensions\{a6e4a4eb-d169-4e99-8988-250fcbafe767}\components\RadioWMPCore.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npagent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\musicnotes\npmusicn.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
FF - plugin: c:\users\bob\appdata\local\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\extensions\devicedetection@logitech.com\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\users\bob\appdata\roaming\mozilla\plugins\npPxPlay.dll
FF - plugin: d:\program files\real\realplayer\netscape6\nppl3260.dll
FF - plugin: d:\program files\real\realplayer\netscape6\nprjplug.dll
FF - plugin: d:\program files\real\realplayer\netscape6\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
mailbox:// in capability.policy.localfilelinks.sites.c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1008000.029\SymEFA.sys [2010-1-27 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1008000.029\BHDrvx86.sys [2010-1-27 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1008000.029\cchpx86.sys [2010-1-27 482432]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100218.001\IDSvix86.sys [2010-2-19 343088]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\engine\16.8.0.41\ccSvcHst.exe [2010-1-27 117640]
R2 SBSDWSCService;SBSD Security Center Service;d:\program files\spybot - search & destroy\SDWinSec.exe [2008-3-9 1153368]
R2 StarWindServiceAE;StarWind AE Service;d:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-12-4 102448]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\nav\1008000.029\symndisv.sys [2010-1-27 48688]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\common files\creative labs shared\service\AL6Licensing.exe [2010-2-3 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2010-2-2 79360]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-4-10 21504]
S3 grmn0200;grmn0200.Sys Garmin USB DCP driver (install);c:\windows\system32\drivers\grmn0200.sys [2007-7-1 23208]
S3 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\wintv\HCWTVS~1.EXE [2008-2-6 815104]

============== File Associations ===============

regfile=regedit.exe "%1" %*

=============== Created Last 30 ================

2010-02-18 00:12:28 0 d-----w- c:\users\bob\DoctorWeb
2010-02-13 15:37:10 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-02-13 15:37:09 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2010-02-13 15:37:04 1314816 ----a-w- c:\windows\system32\quartz.dll
2010-02-13 15:37:03 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2010-02-13 15:37:03 31744 ----a-w- c:\windows\system32\msvidc32.dll
2010-02-13 15:37:03 22528 ----a-w- c:\windows\system32\msyuv.dll
2010-02-13 15:37:03 13312 ----a-w- c:\windows\system32\msrle32.dll
2010-02-13 15:37:03 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2010-02-13 15:37:02 91136 ----a-w- c:\windows\system32\avifil32.dll
2010-02-13 15:37:02 82944 ----a-w- c:\windows\system32\mciavi32.dll
2010-02-13 15:37:02 123904 ----a-w- c:\windows\system32\msvfw32.dll
2010-02-13 15:36:57 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-02-13 15:36:57 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-02-13 15:34:30 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-13 15:34:30 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-03 23:17:56 0 d-----w- c:\programdata\Creative Labs
2010-02-03 01:27:55 2873820 ------w- c:\windows\system32\Sens_oal.dll
2010-02-03 01:27:24 0 d-----w- c:\program files\common files\Creative Labs Shared
2010-02-03 01:13:43 87 ---ha-r- c:\windows\ctfile.rfc
2010-02-03 01:04:20 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-31 19:12:06 815104 ----a-w- c:\windows\system32\xvidcore.dll
2010-01-31 19:12:06 77824 ----a-w- c:\windows\system32\xvid.ax
2010-01-31 19:12:06 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2010-01-31 19:12:05 0 d-----w- c:\program files\Xvid
2010-01-31 19:00:15 0 d-----w- c:\users\bob\dwhelper
2010-01-31 18:56:57 0 d-----w- c:\program files\ConvertHelper
2010-01-30 11:26:46 0 d-----w- c:\programdata\NOS
2010-01-28 10:24:24 0 d-----w- c:\programdata\Sun
2010-01-27 01:32:08 547 ----a-w- c:\windows\system32\ff_vfw.dll.manifest
2010-01-27 01:32:05 7680 ----a-w- c:\windows\system32\ff_acm.acm
2010-01-27 01:32:05 6144 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-27 01:32:04 0 d-----w- c:\program files\ffdshow
2010-01-24 12:39:26 0 d-----w- c:\users\bob\appdata\roaming\AnvSoft

==================== Find3M ====================

2010-02-20 14:26:48 70801 ----a-w- c:\programdata\nvModes.dat
2010-02-18 10:58:25 86016 ----a-w- c:\windows\inf\infpub.dat
2010-02-18 10:58:25 143360 ----a-w- c:\windows\inf\infstor.dat
2010-02-18 10:58:24 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-02-03 01:28:19 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-02-03 01:28:19 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-01-12 18:03:34 9388648 ----a-w- c:\windows\system32\nvd3dum.dll
2010-01-12 18:03:34 68200 ----a-w- c:\windows\system32\OpenCL.dll
2010-01-12 18:03:34 4077672 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-01-12 18:03:34 4061800 ----a-w- c:\windows\system32\nvcuda.dll
2010-01-12 18:03:34 2243176 ----a-w- c:\windows\system32\nvcuvid.dll
2010-01-12 18:03:34 182888 ----a-w- c:\windows\system32\nvcod189.dll
2010-01-12 18:03:34 14924392 ----a-w- c:\windows\system32\nvoglv32.dll
2010-01-12 18:03:34 1280616 ----a-w- c:\windows\system32\nvapi.dll
2010-01-12 18:03:34 11639400 ----a-w- c:\windows\system32\nvcompiler.dll
2010-01-12 18:03:34 11586280 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2010-01-12 18:03:34 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2010-01-12 04:18:00 962664 ----a-w- c:\windows\system32\nvsvc.dll
2010-01-12 04:18:00 13679720 ----a-w- c:\windows\system32\nvcpl.dll
2010-01-12 04:18:00 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-01-12 04:18:00 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-01-07 22:07:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 06:38:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32:33 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32:33 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57:00 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-17 23:14:00 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-08 10:40:39 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-04-11 01:06:01 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:40:37 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:40:37 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:40:37 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:40:37 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2007-05-03 14:16:30 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\mshist012007050320070504\index.dat
2007-05-05 17:47:39 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\mshist012007050520070506\index.dat
2008-10-24 19:05:11 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2008-10-24 19:05:11 32768 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2008-10-24 19:05:11 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
2008-02-26 02:48:23 16384 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\feeds cache\index.dat
2008-03-04 23:09:35 49152 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008022520080303\index.dat
2008-03-10 10:54:42 49152 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008030320080310\index.dat
2008-03-17 09:45:06 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008031020080317\index.dat
2008-03-18 02:04:43 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008031720080318\index.dat
2008-03-13 23:18:20 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\internet explorer\userdata\index.dat
2009-11-13 00:26:14 245760 --sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
2008-06-12 00:56:16 113891360 --sha-w- c:\windows\system32\drivers\fidbox(49).dat

============= FINISH: 8:32:39.66 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:52 PM

Posted 20 February 2010 - 02:23 PM

Hi,

My name is Extremeboy (or EB for short), and I will be helping you with your log.

If you still require assistance we would like to see the current condition of your system so please post a new set of DDS Logs as well as a GMER log and a description of any remaining problems or symptoms you may still have please.

If for any reason you did not post a DDS log or GMER log please refer to this page and in step #6 and Step #7 and Step #8 for further instructions on downloading and running DDS & GMER. If you have any problems when running the tools or unable to produce a report for any reason, just let me know in your next reply.


For your next reply I would like to see:
-The DDS logs
---DDS.txt and Attach logs
-GMER log
-Description of any remaining problems you may still have.


With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#3 packman1234

packman1234
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:52 PM

Posted 20 February 2010 - 02:59 PM

Hi EB
Thank You for your time!!
The computer is still very slow and the GMER program cant seem to finish without rebooting and making me start the scans all over- I'll try to get that in the post if I can..


DDS (Ver_09-12-01.01) - NTFSx86
Run by Bob at 13:51:52.28 on Sat 02/20/2010
Internet Explorer: 8.0.6001.18882 BrowserJavaVersion: 1.6.0_18
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.2046.1159 [GMT -6:00]

SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FW: Norton AntiVirus *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\CTsvcCDA.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe
C:\Program Files\OO Software\Defrag\oodag.exe
C:\Windows\system32\IoctlSvc.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe -k imgsvc
D:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
D:\Program Files\MX Mouse\SetPoint\SetPoint.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Users\Bob\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bob\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bob\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bob\Documents\Downloads\dds (1).scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = about:blank
uInternet Settings,ProxyOverride = <local>;*.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - d:\program files\spybot - search & destroy\SDHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\16.8.0.41\IPSBHO.DLL
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: OToolbarHelper Class: {ead3a971-6a23-4246-8691-c9244e858967} - c:\program files\paypal\paypal plug-in\PayPalHelper.dll
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: PayPal Plug-In: {dc0f2f93-27fa-4f84-acaa-9416f90b9511} - c:\program files\paypal\paypal plug-in\OToolbar.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [<NO NAME>]
mRun: [OODefragTray] c:\program files\oo software\defrag\oodtray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - d:\program files\mx mouse\setpoint\SetPoint.exe
uPolicies-explorer: NoAddPrinter = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Download all by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/202
IE: &Download by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Download selected by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/203
IE: &Grab video by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/204
IE: Append to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - d:\program files\spybot - search & destroy\SDHelper.dll
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15111/CTPID.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - eBay
FF - prefs.js: browser.startup.homepage - hxxp://forecast.weather.gov/MapClick.php?CityName=Menomonee+Falls&state=WI&site=MKX&textField1=43.1472&textField2=-88.1259
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNfox000&fl=0&ptb=qpSaoYRNbM37Y4egFwlnRw&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=
FF - component: c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\extensions\{a6e4a4eb-d169-4e99-8988-250fcbafe767}\components\FFExternalAlert.dll
FF - component: c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\extensions\{a6e4a4eb-d169-4e99-8988-250fcbafe767}\components\RadioWMPCore.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npagent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\musicnotes\npmusicn.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
FF - plugin: c:\users\bob\appdata\local\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\extensions\devicedetection@logitech.com\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\users\bob\appdata\roaming\mozilla\plugins\npPxPlay.dll
FF - plugin: d:\program files\real\realplayer\netscape6\nppl3260.dll
FF - plugin: d:\program files\real\realplayer\netscape6\nprjplug.dll
FF - plugin: d:\program files\real\realplayer\netscape6\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
mailbox:// in capability.policy.localfilelinks.sites.c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1008000.029\SymEFA.sys [2010-1-27 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1008000.029\BHDrvx86.sys [2010-1-27 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1008000.029\cchpx86.sys [2010-1-27 482432]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100218.001\IDSvix86.sys [2010-2-19 343088]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\engine\16.8.0.41\ccSvcHst.exe [2010-1-27 117640]
R2 SBSDWSCService;SBSD Security Center Service;d:\program files\spybot - search & destroy\SDWinSec.exe [2008-3-9 1153368]
R2 StarWindServiceAE;StarWind AE Service;d:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-12-4 102448]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\nav\1008000.029\symndisv.sys [2010-1-27 48688]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\common files\creative labs shared\service\AL6Licensing.exe [2010-2-3 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2010-2-2 79360]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-4-10 21504]
S3 grmn0200;grmn0200.Sys Garmin USB DCP driver (install);c:\windows\system32\drivers\grmn0200.sys [2007-7-1 23208]
S3 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\wintv\HCWTVS~1.EXE [2008-2-6 815104]

============== File Associations ===============

regfile=regedit.exe "%1" %*

=============== Created Last 30 ================

2010-02-18 00:12:28 0 d-----w- c:\users\bob\DoctorWeb
2010-02-13 15:37:10 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-02-13 15:37:09 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2010-02-13 15:37:04 1314816 ----a-w- c:\windows\system32\quartz.dll
2010-02-13 15:37:03 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2010-02-13 15:37:03 31744 ----a-w- c:\windows\system32\msvidc32.dll
2010-02-13 15:37:03 22528 ----a-w- c:\windows\system32\msyuv.dll
2010-02-13 15:37:03 13312 ----a-w- c:\windows\system32\msrle32.dll
2010-02-13 15:37:03 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2010-02-13 15:37:02 91136 ----a-w- c:\windows\system32\avifil32.dll
2010-02-13 15:37:02 82944 ----a-w- c:\windows\system32\mciavi32.dll
2010-02-13 15:37:02 123904 ----a-w- c:\windows\system32\msvfw32.dll
2010-02-13 15:36:57 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-02-13 15:36:57 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-02-13 15:34:30 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-13 15:34:30 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-03 23:17:56 0 d-----w- c:\programdata\Creative Labs
2010-02-03 01:27:55 2873820 ------w- c:\windows\system32\Sens_oal.dll
2010-02-03 01:27:24 0 d-----w- c:\program files\common files\Creative Labs Shared
2010-02-03 01:13:43 87 ---ha-r- c:\windows\ctfile.rfc
2010-02-03 01:04:20 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-31 19:12:06 815104 ----a-w- c:\windows\system32\xvidcore.dll
2010-01-31 19:12:06 77824 ----a-w- c:\windows\system32\xvid.ax
2010-01-31 19:12:06 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2010-01-31 19:12:05 0 d-----w- c:\program files\Xvid
2010-01-31 19:00:15 0 d-----w- c:\users\bob\dwhelper
2010-01-31 18:56:57 0 d-----w- c:\program files\ConvertHelper
2010-01-30 11:26:46 0 d-----w- c:\programdata\NOS
2010-01-28 10:24:24 0 d-----w- c:\programdata\Sun
2010-01-27 01:32:08 547 ----a-w- c:\windows\system32\ff_vfw.dll.manifest
2010-01-27 01:32:05 7680 ----a-w- c:\windows\system32\ff_acm.acm
2010-01-27 01:32:05 6144 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-27 01:32:04 0 d-----w- c:\program files\ffdshow
2010-01-24 12:39:26 0 d-----w- c:\users\bob\appdata\roaming\AnvSoft

==================== Find3M ====================

2010-02-20 19:43:57 70801 ----a-w- c:\programdata\nvModes.dat
2010-02-18 10:58:25 86016 ----a-w- c:\windows\inf\infpub.dat
2010-02-18 10:58:25 143360 ----a-w- c:\windows\inf\infstor.dat
2010-02-18 10:58:24 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-02-03 01:28:19 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-02-03 01:28:19 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-01-12 18:03:34 9388648 ----a-w- c:\windows\system32\nvd3dum.dll
2010-01-12 18:03:34 68200 ----a-w- c:\windows\system32\OpenCL.dll
2010-01-12 18:03:34 4077672 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-01-12 18:03:34 4061800 ----a-w- c:\windows\system32\nvcuda.dll
2010-01-12 18:03:34 2243176 ----a-w- c:\windows\system32\nvcuvid.dll
2010-01-12 18:03:34 182888 ----a-w- c:\windows\system32\nvcod189.dll
2010-01-12 18:03:34 14924392 ----a-w- c:\windows\system32\nvoglv32.dll
2010-01-12 18:03:34 1280616 ----a-w- c:\windows\system32\nvapi.dll
2010-01-12 18:03:34 11639400 ----a-w- c:\windows\system32\nvcompiler.dll
2010-01-12 18:03:34 11586280 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2010-01-12 18:03:34 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2010-01-12 04:18:00 962664 ----a-w- c:\windows\system32\nvsvc.dll
2010-01-12 04:18:00 13679720 ----a-w- c:\windows\system32\nvcpl.dll
2010-01-12 04:18:00 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-01-12 04:18:00 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-01-07 22:07:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 06:38:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32:33 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32:33 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57:00 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-17 23:14:00 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-08 10:40:39 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-04-11 01:06:01 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:40:37 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:40:37 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:40:37 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:40:37 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2007-05-03 14:16:30 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\mshist012007050320070504\index.dat
2007-05-05 17:47:39 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\mshist012007050520070506\index.dat
2008-10-24 19:05:11 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2008-10-24 19:05:11 32768 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2008-10-24 19:05:11 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
2008-02-26 02:48:23 16384 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\feeds cache\index.dat
2008-03-04 23:09:35 49152 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008022520080303\index.dat
2008-03-10 10:54:42 49152 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008030320080310\index.dat
2008-03-17 09:45:06 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008031020080317\index.dat
2008-03-18 02:04:43 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008031720080318\index.dat
2008-03-13 23:18:20 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\internet explorer\userdata\index.dat
2009-11-13 00:26:14 245760 --sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
2008-06-12 00:56:16 113891360 --sha-w- c:\windows\system32\drivers\fidbox(49).dat

============= FINISH: 13:54:23.86 ===============

Attached Files



#4 packman1234

packman1234
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:52 PM

Posted 20 February 2010 - 03:40 PM

Try this for the GMER Scan...

Attached Files

  • Attached File  ark.txt   26.75KB   2 downloads


#5 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:52 PM

Posted 20 February 2010 - 04:26 PM

Thanks for those logs. We are going to start with Combofix. Read instructions below on running it.

Download and Run ComboFix

Note to readers of this post other than the starter of this thread:
ComboFix is a VERY POWERFUL tool which should NOT BE USED without guidance of an expert.

Download Combofix from any of the links below, and save it to your desktop.
Link 1
Link 2

Please refer to this page for full instructions on how to run ComboFix.
  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Double click ComboFix.exe to start the program. Agree to the prompts.
  • When ComboFix is finished, a log report (C:\ComboFix.txt) will open. Post back with it.
Leave your computer alone while ComboFix is running.

ComboFix will restart your computer if malware is found; allow it to do so.


Note: Please Do NOT mouseclick combofix's window while its running because it may call it to stall.

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#6 packman1234

packman1234
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:52 PM

Posted 20 February 2010 - 06:56 PM

I ran combofix..
Right at the end a box popped up and said....Cannot export RegRuns00. Error opening the file. There may be a disk or file system error. Then it proceeded to the log...

ComboFix 10-02-20.03 - Bob 02/20/2010 17:22:25.1.1 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.2046.1318 [GMT -6:00]
Running from: c:\users\Bob\Downloads\ComboFix.exe
FW: Norton AntiVirus *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-51003140-4199384537-3980697693-500
c:\windows\COUPON~1.OCX
c:\windows\CouponPrinter.ocx
c:\windows\system32\cJilmUvw.ini

.
((((((((((((((((((((((((( Files Created from 2010-01-20 to 2010-02-20 )))))))))))))))))))))))))))))))
.

2010-02-20 21:17 . 2010-02-20 21:17 -------- d-----w- c:\users\Administrator\AppData\Local\Mozilla
2010-02-18 00:12 . 2010-02-18 00:12 -------- d-----w- c:\users\Bob\DoctorWeb
2010-02-13 15:37 . 2009-12-08 20:01 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-02-13 15:37 . 2009-12-08 17:26 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2010-02-13 15:37 . 2009-12-04 18:29 1314816 ----a-w- c:\windows\system32\quartz.dll
2010-02-13 15:37 . 2009-12-04 18:30 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2010-02-13 15:37 . 2009-12-04 18:28 22528 ----a-w- c:\windows\system32\msyuv.dll
2010-02-13 15:37 . 2009-12-04 18:28 31744 ----a-w- c:\windows\system32\msvidc32.dll
2010-02-13 15:37 . 2009-12-04 18:28 13312 ----a-w- c:\windows\system32\msrle32.dll
2010-02-13 15:37 . 2009-12-04 18:28 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2010-02-13 15:37 . 2009-12-04 18:28 123904 ----a-w- c:\windows\system32\msvfw32.dll
2010-02-13 15:37 . 2009-12-04 18:28 82944 ----a-w- c:\windows\system32\mciavi32.dll
2010-02-13 15:37 . 2009-12-04 18:27 91136 ----a-w- c:\windows\system32\avifil32.dll
2010-02-13 15:36 . 2009-12-11 11:43 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-02-13 15:36 . 2009-12-11 11:43 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-02-13 15:34 . 2009-12-04 15:56 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-13 15:34 . 2009-12-04 15:56 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-03 23:24 . 2010-02-03 23:24 -------- d-----w- c:\users\Administrator\AppData\Local\Thunderbird
2010-02-03 23:24 . 2010-02-03 23:24 -------- d-----w- c:\users\Administrator\AppData\Roaming\Thunderbird
2010-02-03 23:17 . 2010-02-03 23:17 -------- d-----w- c:\programdata\Creative Labs
2010-02-03 23:06 . 2010-02-03 23:06 -------- d-----w- c:\users\Administrator\AppData\Roaming\Logitech
2010-02-03 01:27 . 2009-04-02 17:33 2873820 ------w- c:\windows\system32\Sens_oal.dll
2010-02-03 01:27 . 2010-02-03 01:27 -------- d-----w- c:\program files\Common Files\Creative Labs Shared
2010-02-03 01:04 . 2010-01-14 17:12 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-31 19:12 . 2008-12-05 03:46 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2010-01-31 19:12 . 2008-12-05 03:42 815104 ----a-w- c:\windows\system32\xvidcore.dll
2010-01-31 19:12 . 2010-01-31 19:12 -------- d-----w- c:\program files\Xvid
2010-01-31 19:00 . 2010-01-31 19:00 -------- d-----w- c:\users\Bob\dwhelper
2010-01-31 18:56 . 2010-01-31 18:57 -------- d-----w- c:\program files\ConvertHelper
2010-01-30 11:26 . 2010-01-30 15:25 -------- d-----w- c:\programdata\NOS
2010-01-30 10:12 . 2010-01-30 10:12 -------- d-----w- c:\users\Bob\AppData\Local\Enounce
2010-01-30 10:11 . 2010-01-30 10:11 -------- d-----w- c:\users\Bob\AppData\Local\Downloaded Installations
2010-01-28 10:24 . 2010-01-28 10:24 -------- d-----w- c:\program files\Common Files\Java
2010-01-27 01:32 . 2006-08-23 18:33 6144 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-27 01:32 . 2010-01-27 01:32 -------- d-----w- c:\program files\ffdshow
2010-01-24 12:39 . 2010-01-24 12:39 -------- d-----w- c:\users\Bob\AppData\Roaming\AnvSoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-20 22:43 . 2010-01-12 10:27 70801 ----a-w- c:\programdata\nvModes.dat
2010-02-19 17:48 . 2007-07-29 13:35 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-02-18 10:58 . 2007-03-13 01:32 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-18 10:51 . 2008-02-23 02:48 -------- d-----w- c:\program files\a-squared Free
2010-02-15 22:14 . 2008-10-21 01:04 680 ----a-w- c:\users\Gayle\AppData\Local\d3d9caps.dat
2010-02-14 17:27 . 2007-03-12 23:37 -------- d-----w- c:\users\Bob\AppData\Roaming\Azureus
2010-02-13 23:53 . 2007-03-15 00:38 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-13 15:49 . 2008-03-01 12:44 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-13 15:47 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-02-13 15:41 . 2007-03-13 08:45 -------- d-----w- c:\programdata\Microsoft Help
2010-02-05 00:46 . 2010-02-13 13:15 52224 ----a-w- c:\users\Bob\AppData\Roaming\Mozilla\Firefox\Profiles\gx283to3.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
2010-02-05 00:46 . 2010-02-13 13:15 101376 ----a-w- c:\users\Bob\AppData\Roaming\Mozilla\Firefox\Profiles\gx283to3.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
2010-02-03 23:17 . 2007-07-08 18:40 -------- d-----w- c:\programdata\Creative
2010-02-03 23:14 . 2007-07-08 17:56 -------- d-----w- c:\program files\Creative
2010-02-03 23:11 . 2010-02-03 23:11 12907880 ----a-w- c:\programdata\Creative\Software Update\cache\Creative WaveStudio 7.12.00__\WAVESTD_PCAPP_LB_7_12_00.exe
2010-02-03 23:11 . 2010-02-03 23:10 37634288 ----a-w- c:\programdata\Creative\Software Update\cache\Creative MediaSource 5 Player_Organizer 5.26.02__\CMS5_PCAPP_LB_5_26_02.exe
2010-02-03 23:10 . 2010-02-03 23:09 8512328 ----a-w- c:\programdata\Creative\Software Update\cache\Creative ALchemy 1.25.10__\ALMY_PCVTAPP_LB_1_25_10.exe
2010-02-03 23:09 . 2010-02-03 23:09 18323888 ----a-w- c:\programdata\Creative\Software Update\cache\Creative ALchemy 1.41.02__\ALMY_PCVTAPP_LB_1_41_02.exe
2010-02-03 09:00 . 2010-02-20 16:18 84912 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100220.006\NAVENG.SYS
2010-02-03 09:00 . 2010-02-20 16:18 1324720 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100220.006\NAVEX15.SYS
2010-02-03 01:28 . 2007-03-13 01:44 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-02-03 01:28 . 2007-03-13 01:44 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-02-03 01:12 . 2007-04-14 16:05 -------- d-----w- c:\programdata\NVIDIA
2010-02-03 01:10 . 2010-01-13 00:38 -------- d-----w- c:\program files\NVIDIA Corporation
2010-02-02 01:20 . 2010-02-20 23:18 165240 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2010-01-30 19:22 . 2008-03-09 14:48 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-01-28 10:23 . 2007-03-12 23:35 -------- d-----w- c:\program files\Java
2010-01-27 01:43 . 2010-01-18 21:43 -------- d-----w- c:\users\Bob\AppData\Roaming\DivX
2010-01-25 16:02 . 2010-01-30 11:26 29344 ----a-w- c:\users\Bob\AppData\Roaming\Mozilla\Firefox\Profiles\gx283to3.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2010-01-25 01:24 . 2008-12-23 00:52 1 ----a-w- c:\users\Bob\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-01-21 23:13 . 2010-01-26 23:39 52224 ----a-w- c:\users\Bob\AppData\Roaming\Mozilla\Firefox\Profiles\gx283to3.default\extensions\{a6e4a4eb-d169-4e99-8988-250fcbafe767}\components\FFExternalAlert.dll
2010-01-21 23:13 . 2010-01-26 23:39 101376 ----a-w- c:\users\Bob\AppData\Roaming\Mozilla\Firefox\Profiles\gx283to3.default\extensions\{a6e4a4eb-d169-4e99-8988-250fcbafe767}\components\RadioWMPCore.dll
2010-01-21 17:46 . 2010-02-06 10:51 441168 ----a-w- c:\users\Bob\AppData\Roaming\Mozilla\Firefox\Profiles\gx283to3.default\extensions\DeviceDetection@logitech.com\plugins\npLogitechDeviceDetection.dll
2010-01-17 20:46 . 2010-01-17 20:44 -------- d-----w- c:\users\Bob\AppData\Roaming\MtStudio
2010-01-17 20:44 . 2010-01-17 20:44 -------- d-----w- c:\program files\MtStudio
2010-01-14 23:18 . 2010-01-14 23:18 -------- d-----w- c:\programdata\McAfee
2010-01-13 10:43 . 2008-06-17 22:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-13 10:42 . 2008-06-28 16:07 5115824 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-13 02:15 . 2010-01-13 02:15 0 ----a-w- c:\users\Gayle\AppData\Roaming\Thunderbird\Profiles\wypr0lol.Gayle\Mail.sbd\wi.rr.com
2010-01-12 18:03 . 2010-01-12 18:03 68200 ----a-w- c:\windows\system32\OpenCL.dll
2010-01-12 18:03 . 2010-01-12 18:03 4077672 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-01-12 18:03 . 2010-01-12 18:03 4061800 ----a-w- c:\windows\system32\nvcuda.dll
2010-01-12 18:03 . 2010-01-12 18:03 2243176 ----a-w- c:\windows\system32\nvcuvid.dll
2010-01-12 18:03 . 2010-01-12 18:03 182888 ----a-w- c:\windows\system32\nvcod189.dll
2010-01-12 18:03 . 2010-01-12 18:03 14924392 ----a-w- c:\windows\system32\nvoglv32.dll
2010-01-12 18:03 . 2010-01-12 18:03 11639400 ----a-w- c:\windows\system32\nvcompiler.dll
2010-01-12 18:03 . 2010-01-12 18:03 11586280 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2010-01-12 18:03 . 2010-01-12 18:03 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2010-01-12 18:03 . 2007-07-06 18:15 9388648 ----a-w- c:\windows\system32\nvd3dum.dll
2010-01-12 18:03 . 2007-07-06 18:15 1280616 ----a-w- c:\windows\system32\nvapi.dll
2010-01-12 04:18 . 2010-01-12 04:18 962664 ----a-w- c:\windows\system32\nvsvc.dll
2010-01-12 04:18 . 2010-01-12 04:18 13679720 ----a-w- c:\windows\system32\nvcpl.dll
2010-01-12 04:18 . 2010-01-12 04:18 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-01-12 04:18 . 2010-01-12 04:18 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-01-10 18:40 . 2007-03-18 00:58 -------- d-----w- c:\program files\DivX
2010-01-10 18:39 . 2010-01-10 18:39 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-01-10 18:38 . 2010-01-10 18:38 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-01-10 17:00 . 2008-12-28 14:11 -------- d-----w- c:\program files\TurboTax
2010-01-10 10:39 . 2007-03-11 23:02 -------- d-----w- c:\users\Bob\AppData\Roaming\Thunderbird
2010-01-10 10:28 . 2010-01-10 10:28 0 ----a-w- c:\users\Gayle\AppData\Roaming\Thunderbird\Profiles\a17oh2bq.default\Mail.sbd\pop-server.wi.rr.com
2010-01-10 10:27 . 2008-10-21 02:15 -------- d-----w- c:\users\Gayle\AppData\Roaming\Thunderbird
2010-01-07 22:07 . 2008-07-22 22:57 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07 . 2008-06-17 22:36 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 00:03 . 2010-01-06 00:03 690952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-01-05 01:31 . 2008-10-20 21:35 133568 ----a-w- c:\users\Gayle\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-03 15:01 . 2007-03-11 20:11 133568 ----a-w- c:\users\Bob\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-03 15:00 . 2010-01-03 15:00 -------- d-----w- c:\users\Bob\AppData\Roaming\Sibelius Software
2010-01-03 14:55 . 2010-01-03 14:55 -------- d-----w- c:\program files\Sibelius Software
2010-01-02 18:19 . 2010-01-02 18:19 -------- d-----w- c:\programdata\Musicnotes
2010-01-02 06:38 . 2010-02-03 01:02 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-02-03 01:02 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 06:32 . 2010-02-03 01:02 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 04:57 . 2010-02-03 01:02 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-28 00:47 . 2009-12-28 00:46 -------- d-----w- c:\program files\Musicnotes
2009-12-25 20:21 . 2007-04-01 13:04 -------- d-----w- c:\users\Bob\AppData\Roaming\Apple Computer
2009-12-25 19:43 . 2009-12-25 19:42 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-25 19:43 . 2009-12-25 19:42 -------- d-----w- c:\program files\iTunes
2009-12-25 19:42 . 2009-01-11 04:48 -------- d-----w- c:\program files\iPod
2009-12-25 19:42 . 2007-08-17 01:53 -------- d-----w- c:\program files\Common Files\Apple
2009-12-25 19:31 . 2009-12-25 19:31 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-12-17 23:14 . 2009-01-11 04:43 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-09 09:00 . 2010-02-20 16:18 2747440 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100220.006\CCERASER.DLL
2009-12-08 10:40 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-09-04 00:37 . 2009-09-04 00:37 10437264 ----a-w- c:\program files\mozilla firefox\plugins\PDFNetC.dll
2009-09-04 00:58 . 2009-09-04 00:58 107760 ----a-w- c:\program files\mozilla firefox\plugins\ScorchPDFWrapper.dll
2008-06-12 00:56 . 2008-05-07 13:22 113891360 --sha-w- c:\windows\System32\drivers\fidbox(49).dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2009-09-12 2524416]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - d:\program files\MX Mouse\SetPoint\SetPoint.exe [2008-9-13 805392]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoAddPrinter"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^UltraMon.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\UltraMon.lnk
backup=c:\windows\pss\UltraMon.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Bob^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ERUNT AutoBackup.lnk]
path=c:\users\Bob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
backup=c:\windows\pss\ERUNT AutoBackup.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Gayle^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Gayle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2008-01-12 00:54 623992 ----a-w- d:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 21:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 07:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
2008-03-13 00:48 4608 ----a-w- d:\program files\Alcohol Soft\Alcohol 120\AxCmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTRegRun]
2006-10-06 20:17 53248 ------w- c:\windows\Ctregrun.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-19 04:33 125952 ----a-w- c:\windows\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-02-13 11:41 135664 ----atw- c:\users\Bob\AppData\Local\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2008-02-28 22:07 1828136 ----a-w- c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 22:33 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2008-02-29 08:12 76304 ----a-w- c:\windows\KHALMNPR.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LiveMonitor]
2008-03-14 16:41 498176 ----a-w- c:\program files\MSI\Live Update 3\LMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-01-07 22:07 1394000 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2008-02-18 21:29 2221352 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-01-12 04:18 110696 ----a-w- c:\windows\System32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OSSelectorReinstall]
2006-04-12 20:15 1261475 ----a-w- c:\program files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17RunE]
2008-03-28 13:57 14848 ----a-w- c:\windows\System32\P17RunE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 05:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
2009-04-11 11:31 160592 ----a-w- c:\program files\Siber Systems\AI RoboForm\robotaskbaricon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2007-03-09 21:28 598016 ----a-w- c:\windows\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-11 21:21 246504 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-19 04:33 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(cool.gif:44,71,f5,e9,72,36,ca,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2187811846-2828430337-354150576-1000]
"EnableNotificationsRef"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2187811846-2828430337-354150576-1004]
"EnableNotificationsRef"=dword:00000001

R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\NAV\1008000.029\SymEFA.sys [1/27/2010 6:11 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\NAV\1008000.029\BHDrvx86.sys [1/27/2010 6:11 PM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\NAV\1008000.029\cchpx86.sys [1/27/2010 6:10 PM 482432]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100218.001\IDSvix86.sys [2/19/2010 7:06 PM 343088]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe [1/27/2010 6:10 PM 117640]
R2 SBSDWSCService;SBSD Security Center Service;d:\program files\Spybot - Search & Destroy\SDWinSec.exe [3/9/2008 8:48 AM 1153368]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/20/2010 10:18 AM 102448]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\NAV\1008000.029\symndisv.sys [1/27/2010 6:11 PM 48688]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [4/3/2007 6:21 PM 716272]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2/3/2010 5:14 PM 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2/2/2010 7:27 PM 79360]
S3 grmn0200;grmn0200.Sys Garmin USB DCP driver (install);c:\windows\System32\drivers\grmn0200.sys [7/1/2007 10:50 AM 23208]
S3 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\WinTV\HCWTVS~1.EXE [2/6/2008 5:34 AM 815104]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-02-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2187811846-2828430337-354150576-1000Core.job
- c:\users\Bob\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-13 11:41]

2010-02-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2187811846-2828430337-354150576-1000UA.job
- c:\users\Bob\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-13 11:41]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = <local>;*.local
IE: &Download all by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/202
IE: &Download by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Download selected by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/203
IE: &Grab video by Orbit - d:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Append to existing PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
FF - ProfilePath - c:\users\Bob\AppData\Roaming\Mozilla\Firefox\Profiles\gx283to3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - eBay
FF - prefs.js: browser.startup.homepage - hxxp://forecast.weather.gov/MapClick.php?CityName=Menomonee+Falls&state=WI&site=MKX&textField1=43.1472&textField2=-88.1259
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNfox000&fl=0&ptb=qpSaoYRNbM37Y4egFwlnRw&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=
FF - component: c:\users\Bob\AppData\Roaming\Mozilla\Firefox\Profiles\gx283to3.default\extensions\{a6e4a4eb-d169-4e99-8988-250fcbafe767}\components\FFExternalAlert.dll
FF - component: c:\users\Bob\AppData\Roaming\Mozilla\Firefox\Profiles\gx283to3.default\extensions\{a6e4a4eb-d169-4e99-8988-250fcbafe767}\components\RadioWMPCore.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npagent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Musicnotes\npmusicn.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - plugin: c:\users\Bob\AppData\Local\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\users\Bob\AppData\Roaming\Mozilla\Firefox\Profiles\gx283to3.default\extensions\DeviceDetection@logitech.com\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\users\Bob\AppData\Roaming\Mozilla\plugins\npPxPlay.dll
FF - plugin: d:\program files\Real\RealPlayer\Netscape6\nppl3260.dll
FF - plugin: d:\program files\Real\RealPlayer\Netscape6\nprjplug.dll
FF - plugin: d:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
mailbox:// in capability.policy.localfilelinks.sites.c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-SpyHunter Security Suite - c:\program files\Enigma Software Group\SpyHunter\SHStartup.exe
MSConfigStartUp-THGuard - c:\program files\TrojanHunter 5.0\THGuard.exe
AddRemove-Magic ISO Maker v5.3 (build 0216) - h:\progra~1\MagicISO\UNWISE.EXE
AddRemove-Magic ISO Maker v5.4 (build 0251) - h:\progra~1\MagicISO\UNWISE.EXE
AddRemove-Visual Studio 6.0 Enterprise Edition - g:\program files\Microsoft Visual Studio\Common\Setup\1033\Setup.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-20 17:41
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"
.
Completion time: 2010-02-20 17:51:21
ComboFix-quarantined-files.txt 2010-02-20 23:51

Pre-Run: 8,052,187,136 bytes free
Post-Run: 8,172,978,176 bytes free

- - End Of File - - 786E1429365DAD846CF066097D3AC13C


#7 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:52 PM

Posted 20 February 2010 - 08:14 PM

Are the re-directs still there? Please continue with a scan with Malwarebytes.

Download and run MalwareBytes Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

For complete or visual instructions on installing and running Malwarebytes Anti-Malware please read this link

Take a new DDS run afterward and post back with both the DDS and Attach logs in your next reply. Also, let me know how your computer is running and if you have any more problems, issues or symptoms left.

Thanks.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#8 packman1234

packman1234
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:52 PM

Posted 20 February 2010 - 09:16 PM

Malwarebytes' Anti-Malware 1.44
Database version: 3768
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882

2/20/2010 8:14:08 PM
mbam-log-2010-02-20 (20-14-08).txt

Scan type: Quick Scan
Objects scanned: 135500
Time elapsed: 40 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


#9 packman1234

packman1234
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:52 PM

Posted 20 February 2010 - 09:23 PM

I run the Malwarebytes scan frequently with updates and never find any issues.. I don't have any redirects or popups...Just a slow machine booting and using windows..


DDS (Ver_09-12-01.01) - NTFSx86
Run by Bob at 20:17:45.06 on Sat 02/20/2010
Internet Explorer: 8.0.6001.18882 BrowserJavaVersion: 1.6.0_18
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.2046.932 [GMT -6:00]

SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FW: Norton AntiVirus *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\CTsvcCDA.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe
C:\Program Files\OO Software\Defrag\oodag.exe
C:\Windows\system32\IoctlSvc.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe -k imgsvc
D:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Windows\explorer.exe
D:\Program Files\MX Mouse\SetPoint\SetPoint.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Bob\Downloads\dds(2).scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = about:blank
uInternet Settings,ProxyOverride = <local>;*.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - d:\program files\spybot - search & destroy\SDHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\16.8.0.41\IPSBHO.DLL
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: OToolbarHelper Class: {ead3a971-6a23-4246-8691-c9244e858967} - c:\program files\paypal\paypal plug-in\PayPalHelper.dll
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: PayPal Plug-In: {dc0f2f93-27fa-4f84-acaa-9416f90b9511} - c:\program files\paypal\paypal plug-in\OToolbar.dll
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [OODefragTray] c:\program files\oo software\defrag\oodtray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - d:\program files\mx mouse\setpoint\SetPoint.exe
uPolicies-explorer: NoAddPrinter = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Download all by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/202
IE: &Download by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Download selected by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/203
IE: &Grab video by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/204
IE: Append to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - d:\program files\spybot - search & destroy\SDHelper.dll
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15111/CTPID.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - eBay
FF - prefs.js: browser.startup.homepage - hxxp://forecast.weather.gov/MapClick.php?CityName=Menomonee+Falls&state=WI&site=MKX&textField1=43.1472&textField2=-88.1259
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNfox000&fl=0&ptb=qpSaoYRNbM37Y4egFwlnRw&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=
FF - component: c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\extensions\{a6e4a4eb-d169-4e99-8988-250fcbafe767}\components\FFExternalAlert.dll
FF - component: c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\extensions\{a6e4a4eb-d169-4e99-8988-250fcbafe767}\components\RadioWMPCore.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npagent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\musicnotes\npmusicn.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
FF - plugin: c:\users\bob\appdata\local\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\extensions\devicedetection@logitech.com\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\users\bob\appdata\roaming\mozilla\plugins\npPxPlay.dll
FF - plugin: d:\program files\real\realplayer\netscape6\nppl3260.dll
FF - plugin: d:\program files\real\realplayer\netscape6\nprjplug.dll
FF - plugin: d:\program files\real\realplayer\netscape6\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
mailbox:// in capability.policy.localfilelinks.sites.c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1008000.029\SymEFA.sys [2010-1-27 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1008000.029\BHDrvx86.sys [2010-1-27 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1008000.029\cchpx86.sys [2010-1-27 482432]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100218.001\IDSvix86.sys [2010-2-19 343088]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\engine\16.8.0.41\ccSvcHst.exe [2010-1-27 117640]
R2 SBSDWSCService;SBSD Security Center Service;d:\program files\spybot - search & destroy\SDWinSec.exe [2008-3-9 1153368]
R2 StarWindServiceAE;StarWind AE Service;d:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-2-20 102448]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2008-7-22 38224]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\nav\1008000.029\symndisv.sys [2010-1-27 48688]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\common files\creative labs shared\service\AL6Licensing.exe [2010-2-3 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2010-2-2 79360]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-4-10 21504]
S3 grmn0200;grmn0200.Sys Garmin USB DCP driver (install);c:\windows\system32\drivers\grmn0200.sys [2007-7-1 23208]
S3 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\wintv\HCWTVS~1.EXE [2008-2-6 815104]

=============== Created Last 30 ================

2010-02-20 23:51:36 0 d-sh--w- C:\$RECYCLE.BIN
2010-02-20 23:20:35 98816 ----a-w- c:\windows\sed.exe
2010-02-20 23:20:35 77312 ----a-w- c:\windows\MBR.exe
2010-02-20 23:20:35 261632 ----a-w- c:\windows\PEV.exe
2010-02-20 23:20:35 161792 ----a-w- c:\windows\SWREG.exe
2010-02-18 00:12:28 0 d-----w- c:\users\bob\DoctorWeb
2010-02-13 15:37:10 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-02-13 15:37:09 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2010-02-13 15:37:04 1314816 ----a-w- c:\windows\system32\quartz.dll
2010-02-13 15:37:03 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2010-02-13 15:37:03 31744 ----a-w- c:\windows\system32\msvidc32.dll
2010-02-13 15:37:03 22528 ----a-w- c:\windows\system32\msyuv.dll
2010-02-13 15:37:03 13312 ----a-w- c:\windows\system32\msrle32.dll
2010-02-13 15:37:03 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2010-02-13 15:37:02 91136 ----a-w- c:\windows\system32\avifil32.dll
2010-02-13 15:37:02 82944 ----a-w- c:\windows\system32\mciavi32.dll
2010-02-13 15:37:02 123904 ----a-w- c:\windows\system32\msvfw32.dll
2010-02-13 15:36:57 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-02-13 15:36:57 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-02-13 15:34:30 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-13 15:34:30 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-03 23:17:56 0 d-----w- c:\programdata\Creative Labs
2010-02-03 01:27:55 2873820 ------w- c:\windows\system32\Sens_oal.dll
2010-02-03 01:27:24 0 d-----w- c:\program files\common files\Creative Labs Shared
2010-02-03 01:13:43 87 ---ha-r- c:\windows\ctfile.rfc
2010-02-03 01:04:20 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-31 19:12:06 815104 ----a-w- c:\windows\system32\xvidcore.dll
2010-01-31 19:12:06 77824 ----a-w- c:\windows\system32\xvid.ax
2010-01-31 19:12:06 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2010-01-31 19:12:05 0 d-----w- c:\program files\Xvid
2010-01-31 19:00:15 0 d-----w- c:\users\bob\dwhelper
2010-01-31 18:56:57 0 d-----w- c:\program files\ConvertHelper
2010-01-30 11:26:46 0 d-----w- c:\programdata\NOS
2010-01-28 10:24:24 0 d-----w- c:\programdata\Sun
2010-01-27 01:32:08 547 ----a-w- c:\windows\system32\ff_vfw.dll.manifest
2010-01-27 01:32:05 7680 ----a-w- c:\windows\system32\ff_acm.acm
2010-01-27 01:32:05 6144 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-27 01:32:04 0 d-----w- c:\program files\ffdshow
2010-01-24 12:39:26 0 d-----w- c:\users\bob\appdata\roaming\AnvSoft

==================== Find3M ====================

2010-02-20 23:51:47 70801 ----a-w- c:\programdata\nvModes.dat
2010-02-18 10:58:25 86016 ----a-w- c:\windows\inf\infpub.dat
2010-02-18 10:58:25 143360 ----a-w- c:\windows\inf\infstor.dat
2010-02-18 10:58:24 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-02-03 01:28:19 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-02-03 01:28:19 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-01-12 18:03:34 9388648 ----a-w- c:\windows\system32\nvd3dum.dll
2010-01-12 18:03:34 68200 ----a-w- c:\windows\system32\OpenCL.dll
2010-01-12 18:03:34 4077672 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-01-12 18:03:34 4061800 ----a-w- c:\windows\system32\nvcuda.dll
2010-01-12 18:03:34 2243176 ----a-w- c:\windows\system32\nvcuvid.dll
2010-01-12 18:03:34 182888 ----a-w- c:\windows\system32\nvcod189.dll
2010-01-12 18:03:34 14924392 ----a-w- c:\windows\system32\nvoglv32.dll
2010-01-12 18:03:34 1280616 ----a-w- c:\windows\system32\nvapi.dll
2010-01-12 18:03:34 11639400 ----a-w- c:\windows\system32\nvcompiler.dll
2010-01-12 18:03:34 11586280 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2010-01-12 18:03:34 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2010-01-12 04:18:00 962664 ----a-w- c:\windows\system32\nvsvc.dll
2010-01-12 04:18:00 13679720 ----a-w- c:\windows\system32\nvcpl.dll
2010-01-12 04:18:00 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-01-12 04:18:00 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-01-07 22:07:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 06:38:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32:33 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32:33 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57:00 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-17 23:14:00 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-08 10:40:39 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-04-11 01:06:01 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:40:37 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:40:37 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:40:37 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:40:37 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2007-05-03 14:16:30 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\mshist012007050320070504\index.dat
2007-05-05 17:47:39 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\mshist012007050520070506\index.dat
2008-10-24 19:05:11 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2008-10-24 19:05:11 32768 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2008-10-24 19:05:11 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
2008-02-26 02:48:23 16384 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\feeds cache\index.dat
2008-03-04 23:09:35 49152 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008022520080303\index.dat
2008-03-10 10:54:42 49152 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008030320080310\index.dat
2008-03-17 09:45:06 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008031020080317\index.dat
2008-03-18 02:04:43 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008031720080318\index.dat
2008-03-13 23:18:20 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\internet explorer\userdata\index.dat
2009-11-13 00:26:14 245760 --sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
2008-06-12 00:56:16 113891360 --sha-w- c:\windows\system32\drivers\fidbox(49).dat

============= FINISH: 20:20:05.37 ===============

Attached Files



#10 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:52 PM

Posted 20 February 2010 - 09:29 PM

P2P Programs: Azureus Vuze

Peer-to-Peer Programs Warning

Your log shows that you are using so called peer-to-peer or file-sharing programs. These programs allow to share files between users as the name(s) suggest. In today's world cyber crime has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.

It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care. Some further readings on this subject, along the included links, are as follows: File-Sharing, otherwise known as Peer To Peer and Risks of File-Sharing Technology.

It is also important to note that sharing entertainment files and proprietary software infringes the copyright laws in many countries over the world and you are putting yourself at risk of being indicted through organizations watching over the rights of the authors of such files (i.e. the RIAA for music files, or the MPAA for movie files in the USA) or the authors of the files themselves.

Naturally there are also legal ways to use these services, such as downloading Linux distributions or office suites such as "Open Office."

It is your decision whether or not you wish to keep your program(s) but I suggest you remove it via add/remove. However, please refrain from using them until your computer has been declared clean.

---
We'll see if we can do some cleanup later and fix your slowness issue.

Run ESET Online Scan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the icon on your desktop.
  4. Check
  5. Click the button.
  6. Accept any security warnings from your browser.
  7. Check
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
  11. Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the button.
  13. Push
You can refer to this animation by neomage if needed.

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#11 packman1234

packman1234
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:52 PM

Posted 21 February 2010 - 01:29 PM

I ran the Eset online scan and it found one problem after 6 hours and reaching 40%. I dont have the patience for a scanner that takes that long.
The bad file was Win32/adware.Virtumonde.NEO application and I believe it quarantined it..
Should I try to rerun this scanner at another time??

#12 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:52 PM

Posted 21 February 2010 - 02:45 PM

You can, otherwise just post a new DDS log so I can see. IT looks good, the online scan was for a second opinion.


Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#13 packman1234

packman1234
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:52 PM

Posted 21 February 2010 - 04:47 PM

Seems better...Maybe the C drive is getting too full or I need to uninstall some junk from years ago!!


DDS (Ver_09-12-01.01) - NTFSx86
Run by Bob at 15:42:10.34 on Sun 02/21/2010
Internet Explorer: 8.0.6001.18882 BrowserJavaVersion: 1.6.0_18
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.2046.1003 [GMT -6:00]

SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FW: Norton AntiVirus *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\CTsvcCDA.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe
C:\Program Files\OO Software\Defrag\oodag.exe
C:\Windows\system32\IoctlSvc.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe -k imgsvc
D:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\OO Software\Defrag\oodtray.exe
D:\Program Files\Replay Media Catcher\FLVSrvc.exe
D:\Program Files\MX Mouse\SetPoint\SetPoint.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Bob\Downloads\dds(3).scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = about:blank
uInternet Settings,ProxyOverride = <local>;*.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - d:\program files\spybot - search & destroy\SDHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\16.8.0.41\IPSBHO.DLL
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: OToolbarHelper Class: {ead3a971-6a23-4246-8691-c9244e858967} - c:\program files\paypal\paypal plug-in\PayPalHelper.dll
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: PayPal Plug-In: {dc0f2f93-27fa-4f84-acaa-9416f90b9511} - c:\program files\paypal\paypal plug-in\OToolbar.dll
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [OODefragTray] c:\program files\oo software\defrag\oodtray.exe
mRun: [Ask and Record FLV Service] "d:\program files\replay media catcher\FLVSrvc.exe" /run
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - d:\program files\mx mouse\setpoint\SetPoint.exe
uPolicies-explorer: NoAddPrinter = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Download all by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/202
IE: &Download by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Download selected by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/203
IE: &Grab video by Orbit - d:\program files\orbitdownloader\orbitmxt.dll/204
IE: Append to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - d:\program files\spybot - search & destroy\SDHelper.dll
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15111/CTPID.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - eBay
FF - prefs.js: browser.startup.homepage - hxxp://forecast.weather.gov/MapClick.php?CityName=Menomonee+Falls&state=WI&site=MKX&textField1=43.1472&textField2=-88.1259
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNfox000&fl=0&ptb=qpSaoYRNbM37Y4egFwlnRw&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=
FF - component: c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\extensions\{a6e4a4eb-d169-4e99-8988-250fcbafe767}\components\FFExternalAlert.dll
FF - component: c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\extensions\{a6e4a4eb-d169-4e99-8988-250fcbafe767}\components\RadioWMPCore.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npagent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\musicnotes\npmusicn.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
FF - plugin: c:\users\bob\appdata\local\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\users\bob\appdata\roaming\mozilla\firefox\profiles\gx283to3.default\extensions\devicedetection@logitech.com\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\users\bob\appdata\roaming\mozilla\plugins\npPxPlay.dll
FF - plugin: d:\program files\real\realplayer\netscape6\nppl3260.dll
FF - plugin: d:\program files\real\realplayer\netscape6\nprjplug.dll
FF - plugin: d:\program files\real\realplayer\netscape6\nprpjplug.dll
FF - plugin: d:\program files\videolan\vlc\npvlc.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
mailbox:// in capability.policy.localfilelinks.sites.c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1008000.029\SymEFA.sys [2010-1-27 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1008000.029\BHDrvx86.sys [2010-1-27 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1008000.029\cchpx86.sys [2010-1-27 482432]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100218.001\IDSvix86.sys [2010-2-19 343088]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\engine\16.8.0.41\ccSvcHst.exe [2010-1-27 117640]
R2 SBSDWSCService;SBSD Security Center Service;d:\program files\spybot - search & destroy\SDWinSec.exe [2008-3-9 1153368]
R2 StarWindServiceAE;StarWind AE Service;d:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-2-20 102448]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\nav\1008000.029\symndisv.sys [2010-1-27 48688]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\common files\creative labs shared\service\AL6Licensing.exe [2010-2-3 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2010-2-2 79360]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-4-10 21504]
S3 grmn0200;grmn0200.Sys Garmin USB DCP driver (install);c:\windows\system32\drivers\grmn0200.sys [2007-7-1 23208]
S3 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\wintv\HCWTVS~1.EXE [2008-2-6 815104]

=============== Created Last 30 ================

2010-02-21 12:57:24 0 d-----w- c:\windows\Applian FLV Player
2010-02-21 12:43:31 156672 ----a-w- c:\windows\system32\rmc_fixasf.exe
2010-02-21 12:43:30 237568 ----a-w- c:\windows\system32\rmc_rtspdl.dll
2010-02-21 12:41:37 0 d-----w- c:\windows\Applian Director
2010-02-21 12:41:37 0 d-----w- c:\program files\Applian Director
2010-02-21 12:40:56 0 d-----w- c:\windows\Replay Media Catcher
2010-02-20 23:51:36 0 d-sh--w- C:\$RECYCLE.BIN
2010-02-20 23:20:35 98816 ----a-w- c:\windows\sed.exe
2010-02-20 23:20:35 77312 ----a-w- c:\windows\MBR.exe
2010-02-20 23:20:35 261632 ----a-w- c:\windows\PEV.exe
2010-02-20 23:20:35 161792 ----a-w- c:\windows\SWREG.exe
2010-02-18 00:12:28 0 d-----w- c:\users\bob\DoctorWeb
2010-02-13 15:37:10 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-02-13 15:37:09 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2010-02-13 15:37:04 1314816 ----a-w- c:\windows\system32\quartz.dll
2010-02-13 15:37:03 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2010-02-13 15:37:03 31744 ----a-w- c:\windows\system32\msvidc32.dll
2010-02-13 15:37:03 22528 ----a-w- c:\windows\system32\msyuv.dll
2010-02-13 15:37:03 13312 ----a-w- c:\windows\system32\msrle32.dll
2010-02-13 15:37:03 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2010-02-13 15:37:02 91136 ----a-w- c:\windows\system32\avifil32.dll
2010-02-13 15:37:02 82944 ----a-w- c:\windows\system32\mciavi32.dll
2010-02-13 15:37:02 123904 ----a-w- c:\windows\system32\msvfw32.dll
2010-02-13 15:36:57 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-02-13 15:36:57 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-02-13 15:34:30 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-13 15:34:30 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-03 23:17:56 0 d-----w- c:\programdata\Creative Labs
2010-02-03 01:27:55 2873820 ------w- c:\windows\system32\Sens_oal.dll
2010-02-03 01:27:24 0 d-----w- c:\program files\common files\Creative Labs Shared
2010-02-03 01:13:43 87 ---ha-r- c:\windows\ctfile.rfc
2010-02-03 01:04:20 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-31 19:12:06 815104 ----a-w- c:\windows\system32\xvidcore.dll
2010-01-31 19:12:06 77824 ----a-w- c:\windows\system32\xvid.ax
2010-01-31 19:12:06 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2010-01-31 19:12:05 0 d-----w- c:\program files\Xvid
2010-01-31 19:00:15 0 d-----w- c:\users\bob\dwhelper
2010-01-31 18:56:57 0 d-----w- c:\program files\ConvertHelper
2010-01-30 11:26:46 0 d-----w- c:\programdata\NOS
2010-01-28 10:24:24 0 d-----w- c:\programdata\Sun
2010-01-27 01:32:08 547 ----a-w- c:\windows\system32\ff_vfw.dll.manifest
2010-01-27 01:32:05 7680 ----a-w- c:\windows\system32\ff_acm.acm
2010-01-27 01:32:05 6144 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-27 01:32:04 0 d-----w- c:\program files\ffdshow
2010-01-24 12:39:26 0 d-----w- c:\users\bob\appdata\roaming\AnvSoft

==================== Find3M ====================

2010-02-21 21:40:40 70801 ----a-w- c:\programdata\nvModes.dat
2010-02-18 10:58:25 86016 ----a-w- c:\windows\inf\infpub.dat
2010-02-18 10:58:25 143360 ----a-w- c:\windows\inf\infstor.dat
2010-02-18 10:58:24 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-02-03 01:28:19 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-02-03 01:28:19 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-01-12 18:03:34 9388648 ----a-w- c:\windows\system32\nvd3dum.dll
2010-01-12 18:03:34 68200 ----a-w- c:\windows\system32\OpenCL.dll
2010-01-12 18:03:34 4077672 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-01-12 18:03:34 4061800 ----a-w- c:\windows\system32\nvcuda.dll
2010-01-12 18:03:34 2243176 ----a-w- c:\windows\system32\nvcuvid.dll
2010-01-12 18:03:34 182888 ----a-w- c:\windows\system32\nvcod189.dll
2010-01-12 18:03:34 14924392 ----a-w- c:\windows\system32\nvoglv32.dll
2010-01-12 18:03:34 1280616 ----a-w- c:\windows\system32\nvapi.dll
2010-01-12 18:03:34 11639400 ----a-w- c:\windows\system32\nvcompiler.dll
2010-01-12 18:03:34 11586280 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2010-01-12 18:03:34 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2010-01-12 04:18:00 962664 ----a-w- c:\windows\system32\nvsvc.dll
2010-01-12 04:18:00 13679720 ----a-w- c:\windows\system32\nvcpl.dll
2010-01-12 04:18:00 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-01-12 04:18:00 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-01-07 22:07:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 06:38:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32:33 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32:33 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57:00 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-17 23:14:00 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-08 10:40:39 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-04-11 01:06:01 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:40:37 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:40:37 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:40:37 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:40:37 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2007-05-03 14:16:30 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\mshist012007050320070504\index.dat
2007-05-05 17:47:39 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\mshist012007050520070506\index.dat
2008-10-24 19:05:11 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2008-10-24 19:05:11 32768 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2008-10-24 19:05:11 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
2008-02-26 02:48:23 16384 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\feeds cache\index.dat
2008-03-04 23:09:35 49152 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008022520080303\index.dat
2008-03-10 10:54:42 49152 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008030320080310\index.dat
2008-03-17 09:45:06 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008031020080317\index.dat
2008-03-18 02:04:43 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008031720080318\index.dat
2008-03-13 23:18:20 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\internet explorer\userdata\index.dat
2009-11-13 00:26:14 245760 --sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
2008-06-12 00:56:16 113891360 --sha-w- c:\windows\system32\drivers\fidbox(49).dat

============= FINISH: 15:44:59.26 ===============

Attached Files



#14 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:52 PM

Posted 21 February 2010 - 06:38 PM

Hello.

Looks good. Let's wrap up. smile.gif Probably a good idea to do some maintenance. You might want to use windows cleanup manager (Disk Cleanup).

Please follow/read the steps below to remove the tools we used and for some more information. smile.gif


Uninstall ComboFix

Remove Combofix now that we're done with it.
  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")
  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
This will uninstall Combofix and anything assoicated with it.

Download and Run OTC

We will now remove the tools we used during this fix using OTC.
  • Download OTC by OldTimer and save it to your desktop.
  • Double click icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big button.
  • You will get a prompt saying "Being Cleanup Process". Please select Yes.
  • Restart your computer when prompted.

System A bit Slow? Try StartupLight

You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.

If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware.


Congratulations! You now appear clean! specool.gif

Now that you are clean, please follow and read some of the prevention tips below.

Preventing Infections in the Future


Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

Some of the main things you should consider to perform/read are:
  • Disabling Autorun/Play on Flash-Drive/Removable Drives
  • Avoid gaming sites, underground web pages, pirated software sites, and Peer to Peer Programs
  • Keep Windows Updated through going to Windows Updates
  • Updating Non-Microsoft Programs
  • Keeping Security softwares updated

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.

Update all programs regularly - Make sure you update all the programs you have installed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help and thank you for choosing Bleeping Computer as you malware removal source.
Don't forget to tell your friends about us and Good luck thumbup2.gif


If you have no more questions, comments or problems please tell us, so we can close off the topic.

Thanks smile.gif

With Regards,
Extremeboy



Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#15 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:52 PM

Posted 26 February 2010 - 09:53 PM

Hello.

Since the problem appears to be resolved, this topic is now Closed. Glad we could help smile.gif
If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.

This applies only to the original topic starter

Everyone else please start a new topic.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users