Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

grin Welcome to What the Tech! ( Log In | Register ) What tech support ought to be... Fast, friendly and free! Once registered - you'll have the ability to post your question in the appropriate forum below. Additionally, if you can assist another member by sharing your tech knowledge, please post a reply! Best of all - Registration and all assistance is FREE! Once you've completed registration, simply choose the appropriate forum below, click on the "new topic" button, and post your question! What are you waiting for? Register today! *Registered users see NO ADVERTISING.

   
3 Pages V   1 2 3 >  
Closed TopicStart new topic
> [Resolved] Spyware, Trojans, Vundo, Etc., Slow boot, slow web page load, odd results
royb
post Jun 29 2009, 03:03 PM
Post #1


New Member
*

Group: Authentic Member
Posts: 18
Joined: 29-June 09
Member No.: 86,469
Operating System: XP SP3



Slow boot,slow or no loading of web page, strange search results, odd behavior and if I try to delete a user account it crashes. I have Norton running, run MalWarebytes Anti Malware and others often.

Need help. Intermediate user.

Thanks
Go to the top of the page
 
+Quote Post
jpshortstuff
post Jul 1 2009, 03:36 AM
Post #2


SuperHelper
Group Icon

Group: Classroom Teacher
Posts: 5,027
Joined: 28-April 07
From: UK
Member No.: 69,799
Operating System: Windows XP (Professional), Windows Vista (Home Business), Windows 7 (Ultimate), Ubuntu Linux



Hi,

Does MalwareBytes' find anything? If so, please post a log.


Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
    1. DDS.txt
    2. Attach.txt
  • Save both reports to your desktop.
---------------------------------------------------
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.


Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Right-click gmer.exe and select Run As Administrator. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<--- ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
Go to the top of the page
 
+Quote Post
royb
post Jul 1 2009, 12:28 PM
Post #3


New Member
*

Group: Authentic Member
Posts: 18
Joined: 29-June 09
Member No.: 86,469
Operating System: XP SP3



Thanks for the help. I will gladly donate as soon as look at the exchange rate (I only have uUSD $8.00 in my PayPal account).

MalWarebytes finds Vundo. I have run VundoFix from Atribune.org and it removes it? Norton dosen't find Vundo and it returns.

I think I have complied with your requests, if not please let me know.

Malwarebytes' Anti-Malware 1.38
Database version: 2358
Windows 5.1.2600 Service Pack 3

7/1/2009 2:12:27 PM
mbam-log-2009-07-01 (14-12-02).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 20420
Time elapsed: 1 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{161b3614-fe54-4d30-8019-0d1e95dd4db1} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\kvedspul (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{161b3614-fe54-4d30-8019-0d1e95dd4db1} (Trojan.Vundo.H) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\ixqavxo.dll (Trojan.Vundo.H) -> No action taken.


DDS (Ver_09-06-26.01) - NTFSx86
Run by Roy Bristow at 11:22:18.20 on Wed 07/01/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.178 [GMT -4:00]

AV: Norton Internet Security *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Documents and Settings\Roy Bristow\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Roy Bristow\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://comcast.net/
uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us-smb
uDefault_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=0080514
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us-smb
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us-smb
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: : {161b3614-fe54-4d30-8019-0d1e95dd4db1} - c:\windows\system32\ixqavxo.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\16.5.0.135\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\16.5.0.135\IPSBHO.DLL
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - No File
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\16.5.0.135\coIEPlg.dll
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [Google Update] "c:\documents and settings\roy bristow\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~2.lnk - c:\program files\microsoft office\office\FINDFAST.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\office~1.lnk - c:\program files\microsoft office\office\OSA.EXE
IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F}
LSP: c:\windows\system32\lsp.dll
Trusted Zone: download.com
Trusted Zone: intuit.com
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/OAS/ActiveX/MSDcode.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} - hxxp://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab
DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {94B82441-A413-4E43-8422-D49930E69764} - hxxps://chat2.j2.com/Media/VisitorchatEnu/TLIEFlash.CAB
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton internet security\engine\16.5.0.135\CoIEPlg.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
Notify: kvedspul - ixqavxo.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
AppInit_DLLs: frgehi.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-2-25 64160]
R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [2009-1-28 17264]
R0 nielprt;Nielsen Patch Service;c:\windows\system32\drivers\nielprt.sys [2009-5-12 21888]
R0 qrgfbrnh;qrgfbrnh;c:\windows\system32\drivers\qrgfbrnh.sys [2004-8-10 23424]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1005000.087\SymEFA.sys [2009-3-23 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nis\1005000.087\BHDrvx86.sys [2009-3-23 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nis\1005000.087\cchpx86.sys [2009-3-23 482352]
R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [2008-12-7 14336]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-4-28 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-4-28 72944]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [2008-11-13 13360]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-11 30312]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 953168]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-1-4 195856]
R2 Norton Internet Security;Norton Internet Security;c:\program files\norton internet security\engine\16.5.0.135\ccSvcHst.exe [2009-3-23 115560]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2008-11-13 69168]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-2-25 101936]
R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [2008-12-7 8832]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2008-9-26 19096]
R3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2008-11-24 29263712]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090630.055\NAVENG.SYS [2009-7-1 89104]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090630.055\NAVEX15.SYS [2009-7-1 876144]
S1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090625.003\IDSXpx86.sys [2009-6-30 276344]
S2 gupdate1c9a2515ee9ac6;Google Update Service (gupdate1c9a2515ee9ac6);c:\program files\google\update\GoogleUpdate.exe [2009-3-11 133104]
S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys [2009-5-12 9088]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-4-28 7408]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2008-10-23 92464]

=============== Created Last 30 ================

2009-06-29 17:34 <DIR> --d----- c:\program files\Flip Words
2009-06-29 15:17 <DIR> --d----- c:\docume~1\roybri~1\applic~1\ZoomBrowser EX
2009-06-29 15:09 <DIR> --d----- c:\docume~1\roybri~1\applic~1\CameraWindowDC
2009-06-29 15:09 <DIR> --d----- c:\docume~1\roybri~1\applic~1\CANON INC
2009-06-22 14:17 <DIR> -cd-h--- c:\windows\ie8
2009-06-22 14:04 255,848 a------- c:\windows\system32\xactengine2_6.dll
2009-06-22 14:03 <DIR> --d-h--- c:\windows\msdownld.tmp
2009-06-22 14:02 <DIR> --d----- c:\windows\Logs
2009-06-21 19:27 16 a------- c:\documents and settings\roy bristow\FlipWords.dat
2009-06-21 14:14 293 a------- c:\windows\FlipWords.ini
2009-06-18 19:07 <DIR> --d----- c:\docume~1\alluse~1\applic~1\ZoomBrowser
2009-06-18 19:07 <DIR> --d----- c:\program files\Canon
2009-06-18 19:04 <DIR> --d----- c:\program files\common files\Canon
2009-06-11 20:00 183,296 a------- c:\windows\system32\lsp.dll
2009-06-10 16:03 118 a------- c:\windows\system32\MRT.INI
2009-06-10 04:52 246,272 -------- c:\windows\system32\dllcache\ieproxy.dll
2009-06-10 04:52 12,800 -------- c:\windows\system32\dllcache\xpshims.dll
2009-06-09 15:37 <DIR> --dsh--- c:\documents and settings\roy bristow\IECompatCache
2009-06-03 23:24 <DIR> --dsh--- c:\documents and settings\roy bristow\PrivacIE
2009-06-03 23:21 <DIR> --dsh--- c:\documents and settings\roy bristow\IETldCache
2009-06-03 23:18 <DIR> --d----- c:\windows\ie8updates
2009-06-03 23:18 102,912 -------- c:\windows\system32\dllcache\iecompat.dll

==================== Find3M ====================

2009-06-21 14:13 1,682 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-06-17 11:27 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 11:27 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-06-06 23:44 481,743 a------- c:\windows\system32\kungsfuvbrsvpj.dat
2009-05-21 11:33 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-13 01:15 915,456 a------- c:\windows\system32\wininet.dll
2009-05-13 01:15 5,936,128 -------- c:\windows\system32\dllcache\mshtml.dll
2009-05-13 01:15 915,456 -------- c:\windows\system32\dllcache\wininet.dll
2009-05-12 06:56 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_nielprt_01007.Wdf
2009-05-12 06:55 0 a---h--- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-05-07 11:32 345,600 a------- c:\windows\system32\localspl.dll
2009-05-07 11:32 345,600 -------- c:\windows\system32\dllcache\localspl.dll
2009-04-30 17:22 1,985,024 -------- c:\windows\system32\dllcache\iertutil.dll
2009-04-30 17:22 11,064,832 -------- c:\windows\system32\dllcache\ieframe.dll
2009-04-30 17:22 1,207,808 -------- c:\windows\system32\dllcache\urlmon.dll
2009-04-30 17:22 25,600 -------- c:\windows\system32\dllcache\jsproxy.dll
2009-04-30 17:22 385,536 -------- c:\windows\system32\dllcache\iedkcs32.dll
2009-04-30 07:21 173,056 -------- c:\windows\system32\dllcache\ie4uinit.exe
2009-04-22 20:09 15,688 a------- c:\windows\system32\lsdelete.exe
2009-04-17 08:26 1,847,168 a------- c:\windows\system32\win32k.sys
2009-04-17 08:26 1,847,168 -------- c:\windows\system32\dllcache\win32k.sys
2009-04-15 10:51 585,216 a------- c:\windows\system32\rpcrt4.dll
2009-04-15 10:51 585,216 -------- c:\windows\system32\dllcache\rpcrt4.dll
2009-02-10 15:38 60,744 a------- c:\documents and settings\roy bristow\g2mdlhlpx.exe
2009-01-26 12:00 2,516 a--sh--- c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys
2009-01-26 12:00 88 ---shr-- c:\docume~1\alluse~1\applic~1\020AC935B7.sys
2008-07-07 09:56 81,920 a------- c:\docume~1\roybri~1\applic~1\ezpinst.exe
2008-07-07 09:56 47,360 a------- c:\docume~1\roybri~1\applic~1\pcouffin.sys
2008-12-07 21:55 56 ---shr-- c:\windows\system32\B735C90A02.sys
2008-09-23 20:59 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092320080924\index.dat

============= FINISH: 11:23:26.17 ===============



GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-01 12:44:33
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.15 ----

SSDT 86BC4270 ZwAlertResumeThread
SSDT 865556B0 ZwAlertThread
SSDT 86432A90 ZwAllocateVirtualMemory
SSDT 86540050 ZwAssignProcessToJobObject
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xA9D8B040]
SSDT 86432288 ZwCreateMutant
SSDT 86431CD0 ZwCreateSymbolicLinkObject
SSDT 864B0720 ZwCreateThread
SSDT 86541050 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA9D8B2C0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA9D8B820]
SSDT 86432BE8 ZwDuplicateObject
SSDT spok.sys ZwEnumerateKey [0xF7411CA2]
SSDT spok.sys ZwEnumerateValueKey [0xF7412030]
SSDT 864328F0 ZwFreeVirtualMemory
SSDT 86D5C068 ZwImpersonateAnonymousToken
SSDT 86C3F268 ZwImpersonateThread
SSDT 86543050 ZwLoadDriver
SSDT 864A8878 ZwMapViewOfSection
SSDT 8654D050 ZwOpenEvent
SSDT spok.sys ZwOpenKey [0xF73F30C0]
SSDT 86432D88 ZwOpenProcess
SSDT 86BDF0B8 ZwOpenProcessToken
SSDT 86544050 ZwOpenSection
SSDT 86432CB8 ZwOpenThread
SSDT 86431DA0 ZwProtectVirtualMemory
SSDT spok.sys ZwQueryKey [0xF7412108]
SSDT spok.sys ZwQueryValueKey [0xF7411F88]
SSDT 86EF6850 ZwResumeThread
SSDT 86EF0C08 ZwSetContextThread
SSDT 86432710 ZwSetInformationProcess
SSDT 86542050 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA9D8BA70]
SSDT 8654C050 ZwSuspendProcess
SSDT 86C3C158 ZwSuspendThread
SSDT 86BD80B8 ZwTerminateProcess
SSDT 86C67E50 ZwTerminateThread
SSDT 86CDD378 ZwUnmapViewOfSection
SSDT 864329C0 ZwWriteVirtualMemory

INT 0x63 ? 86CB0F00
INT 0x73 ? 86FD6BF8
INT 0x73 ? 86FD6BF8
INT 0x73 ? 86FD6BF8
INT 0x73 ? 86FD6BF8
INT 0x73 ? 86CB0F00
INT 0x73 ? 86CB0F00
INT 0x73 ? 86FD6BF8
INT 0x94 ? 86CB0F00
INT 0xA4 ? 86CB0F00

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!ZwCallbackReturn + 2CD4 80504570 4 Bytes CALL 14D688A0
PAGE ntkrnlpa.exe!ObReferenceObjectByHandle + 44F 805BB8ED 7 Bytes JMP 86F63B40
? spok.sys The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F600E8AC 5 Bytes JMP 86CB04E0

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F73F4040] spok.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F73F413C] spok.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F73F40BE] spok.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F73F47FC] spok.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F73F46D2] spok.sys

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 86F661F8

AttachedDevice \FileSystem\Ntfs \Ntfs MPRIFL.SYS (My Private Folder driver/FSPro Labs)

Device \Driver\usbehci \Device\USBPDO-0 86CD1500
Device \Driver\usbuhci \Device\USBPDO-1 86D4F1F8
Device \Driver\usbuhci \Device\USBPDO-2 86D4F1F8
Device \Driver\usbuhci \Device\USBPDO-3 86D4F1F8
Device \Driver\usbuhci \Device\USBPDO-4 86D4F1F8

AttachedDevice \Driver\Tcpip \Device\Tcp nnrnstdi.SYS (NNRNSTDI helper driver/The Nielsen Company)

Device \Driver\usbuhci \Device\USBPDO-5 86D4F1F8
Device \Driver\usbuhci \Device\USBPDO-6 86D4F1F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 86F681F8
Device \Driver\usbehci \Device\USBPDO-7 86CD1500
Device \Driver\Ftdisk \Device\HarddiskVolume2 86F681F8
Device \Driver\Cdrom \Device\CdRom0 86C08500
Device \Driver\NetBT \Device\NetBT_Tcpip_{28C8854A-4440-4535-9B10-CE5FEF99D1FE} 8655E500
Device \Driver\NetBT \Device\NetBt_Wins_Export 8655E500
Device \Driver\NetBT \Device\NetbiosSmb 8655E500

AttachedDevice \Driver\Tcpip \Device\RawIp nnrnstdi.SYS (NNRNSTDI helper driver/The Nielsen Company)

Device \Driver\usbuhci \Device\USBFDO-0 86D4F1F8
Device \Driver\usbuhci \Device\USBFDO-1 86D4F1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 865531F8
Device \Driver\usbuhci \Device\USBFDO-2 86D4F1F8
Device 865531F8
Device \Driver\usbehci \Device\USBFDO-3 86CD1500
Device \Driver\usbuhci \Device\USBFDO-4 86D4F1F8
Device \Driver\Ftdisk \Device\FtControl 86F681F8
Device \Driver\usbuhci \Device\USBFDO-5 86D4F1F8
Device \Driver\usbuhci \Device\USBFDO-6 86D4F1F8
Device \Driver\usbehci \Device\USBFDO-7 86CD1500
Device 863E61F8
Device A7EEF297

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs 86401500
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)

---- Services - GMER 1.0.15 ----

Service system32\drivers\kungsfkvrndpsk.sys (*** hidden *** ) [SYSTEM] kungsfxjbqlxwn <-- ROOTKIT !!!
Service system32\drivers\SKYNETxviwqjgq.sys (*** hidden *** ) [SYSTEM] SKYNETbdwptntr <-- ROOTKIT !!!

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn@imagepath \systemroot\system32\drivers\kungsfkvrndpsk.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main@aid 10096
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main@cmddelay 7200
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main\injector@* kungsfwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\modules@kungsfrk.sys \systemroot\system32\drivers\kungsfkvrndpsk.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\modules@kungsfcmd.dll \systemroot\system32\kungsfarmpydlv.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\modules@kungsflog.dat \systemroot\system32\kungsfuvbrsvpj.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\modules@kungsfwsp.dll \systemroot\system32\kungsfnbmqhhlj.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\modules@kungsf.dat \systemroot\system32\kungsfwrtlnkou.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr@imagepath \systemroot\system32\drivers\SKYNETxviwqjgq.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETxviwqjgq.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr\modules@SKYNETcmd.dll \systemroot\system32\SKYNETxtiouodx.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn@imagepath \systemroot\system32\drivers\kungsfkvrndpsk.sys
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main@aid 10096
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main@sid 0
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main@cmddelay 7200
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main\delete
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main\injector
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main\injector@* kungsfwsp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main\tasks
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\modules
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\modules@kungsfrk.sys \systemroot\system32\drivers\kungsfkvrndpsk.sys
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\modules@kungsfcmd.dll \systemroot\system32\kungsfarmpydlv.dll
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\modules@kungsflog.dat \systemroot\system32\kungsfuvbrsvpj.dat
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\modules@kungsfwsp.dll \systemroot\system32\kungsfnbmqhhlj.dll
Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\modules@kungsf.dat \systemroot\system32\kungsfwrtlnkou.dat
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr@imagepath \systemroot\system32\drivers\SKYNETxviwqjgq.sys
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr\main
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr\main\injector
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr\modules
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETxviwqjgq.sys
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr\modules@SKYNETcmd.dll \systemroot\system32\SKYNETxtiouodx.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{161B3614-FE54-4D30-8019-0D1E95DD4DB1}\ProgID@ Akzydiqq
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506}@naiojgmabnolokncbdkabjolfgno 0x6A 0x61 0x62 0x6C ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506}@macpdhjbficnaokdjnleaadhcf 0x6A 0x61 0x62 0x6C ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506}@abedlckcohpbmiinnnoaocjeefpokfiloe 0x61 0x62 0x6C 0x6F ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506}@mahdadeebgllhgadjcapkcnlnf 0x64 0x62 0x63 0x70 ...

---- Files - GMER 1.0.15 ----

File C:\Documents and Settings\Roy Bristow\My Documents\My Lockbox 0 bytes
File C:\Documents and Settings\Roy Bristow\My Documents\My Lockbox\New Folder 0 bytes

---- EOF - GMER 1.0.15 ----





Attached File(s)
Attached File  Attach.txt ( 12.54K ) Number of downloads: 163
 
Go to the top of the page
 
+Quote Post
jpshortstuff
post Jul 1 2009, 12:36 PM
Post #4


SuperHelper
Group Icon

Group: Classroom Teacher
Posts: 5,027
Joined: 28-April 07
From: UK
Member No.: 69,799
Operating System: Windows XP (Professional), Windows Vista (Home Business), Windows 7 (Ultimate), Ubuntu Linux



Looks like you've got a nasty Rootkit (or two) on board. Let's see if we can drag it out.

Please delete any existing copies of ComboFix that you might have.

Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3





IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on Combo-Fix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



  • Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

This post has been edited by jpshortstuff: Jul 1 2009, 12:39 PM
Go to the top of the page
 
+Quote Post
royb
post Jul 1 2009, 01:33 PM
Post #5


New Member
*

Group: Authentic Member
Posts: 18
Joined: 29-June 09
Member No.: 86,469
Operating System: XP SP3



FYI - I received several warnings that the ComboFix site was a scam and it gave me the "real" sites. I was also advised that if I purchased ComboFix from other than the "real" sites I should ask my bank to stop the transaction.


ComboFix 09-07-01.01 - Roy Bristow 07/01/2009 15:11.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.475 [GMT -4:00]
Running from: c:\documents and settings\Roy Bristow\Desktop\Combo-Fix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\Downloaded Program Files\ODCTOOLS
c:\windows\system32\afexzso.dll
c:\windows\system32\api.dat
c:\windows\system32\dkiorkdm.ini
c:\windows\system32\drivers\lafsmdxk.sys
c:\windows\system32\drivers\qrgfbrnh.sys
c:\windows\system32\gloltirm.ini
c:\windows\system32\ixqavxo.dll
c:\windows\system32\ixvokqiu.ini
c:\windows\system32\kungsfuvbrsvpj.dat
c:\windows\system32\lsp.dll
c:\windows\system32\opfqebys.ini
c:\windows\system32\pcgcnbjm.ini
c:\windows\system32\pkffjqjf.dll
c:\windows\Tasks\At1.job

----- BITS: Possible infected sites -----

hxxp://www.spiralfrog.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_QRGFBRNH
-------\Service_kungsfxjbqlxwn
-------\Service_qrgfbrnh
-------\Service_SKYNETbdwptntr


((((((((((((((((((((((((( Files Created from 2009-06-01 to 2009-07-01 )))))))))))))))))))))))))))))))
.

2009-07-01 15:44 . 2009-02-19 09:00 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVENG.SYS
2009-07-01 15:44 . 2009-02-19 09:00 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVEX15.SYS
2009-07-01 15:44 . 2009-02-19 09:00 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVENG32.DLL
2009-07-01 15:44 . 2009-02-19 09:00 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVEX32A.DLL
2009-07-01 15:44 . 2009-02-25 09:00 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\EECTRL.SYS
2009-07-01 15:44 . 2009-02-25 09:00 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\CCERASER.DLL
2009-07-01 15:44 . 2009-02-25 09:00 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\ERASER.SYS
2009-07-01 15:44 . 2009-01-18 07:18 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\ECMSVR32.DLL
2009-06-30 21:57 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\Scxpx86.dll
2009-06-30 21:57 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys
2009-06-30 21:57 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSvix86.sys
2009-06-30 21:57 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSxpx86.dll
2009-06-30 21:57 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSviA64.sys
2009-06-29 21:34 . 2009-06-29 21:34 -------- d-----w- c:\program files\Flip Words
2009-06-29 19:17 . 2009-06-29 19:18 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\ZoomBrowser EX
2009-06-29 19:09 . 2009-06-29 19:17 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\CameraWindowDC
2009-06-29 19:09 . 2009-06-29 19:09 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\CANON INC
2009-06-24 01:35 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\Scxpx86.dll
2009-06-24 01:35 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSXpx86.sys
2009-06-24 01:35 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSvix86.sys
2009-06-24 01:35 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSxpx86.dll
2009-06-24 01:35 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSviA64.sys
2009-06-23 21:28 . 2009-06-23 21:28 152576 ----a-w- c:\documents and settings\Roy Bristow\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-22 18:17 . 2009-06-22 18:20 -------- dc-h--w- c:\windows\ie8
2009-06-22 18:04 . 2007-01-24 19:27 255848 ----a-w- c:\windows\system32\xactengine2_6.dll
2009-06-22 18:03 . 2009-06-23 21:35 -------- d--h--w- c:\windows\msdownld.tmp
2009-06-22 18:02 . 2009-06-22 18:02 -------- d-----w- c:\windows\Logs
2009-06-21 23:27 . 2009-06-28 17:28 16 ----a-w- c:\documents and settings\Roy Bristow\FlipWords.dat
2009-06-21 18:55 . 2009-06-21 18:55 16 ----a-w- c:\documents and settings\Owen\FlipWords.dat
2009-06-20 20:46 . 2009-06-20 20:46 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-06-18 23:07 . 2009-06-18 23:07 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-06-18 23:07 . 2009-06-18 23:08 -------- d-----w- c:\program files\Canon
2009-06-18 23:04 . 2009-06-18 23:04 -------- d-----w- c:\program files\Common Files\Canon
2009-06-10 08:52 . 2009-04-30 21:22 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-06-10 08:52 . 2009-04-30 21:22 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-09 19:37 . 2009-06-09 19:37 -------- d-sh--w- c:\documents and settings\Roy Bristow\IECompatCache
2009-06-09 13:16 . 2009-06-09 13:16 -------- d-sh--w- c:\documents and settings\Margaret\PrivacIE
2009-06-08 22:22 . 2009-06-08 22:22 -------- d-sh--w- c:\documents and settings\Owen\PrivacIE
2009-06-08 21:06 . 2009-06-08 21:06 -------- d-----w- c:\documents and settings\Eden\Application Data\CyberLink
2009-06-08 11:49 . 2009-06-08 11:49 -------- d-----w- c:\documents and settings\Margaret\Local Settings\Application Data\Symantec
2009-06-07 15:18 . 2009-06-07 15:18 -------- d-sh--w- c:\documents and settings\Eden\PrivacIE
2009-06-07 15:08 . 2009-06-07 15:08 -------- d-----w- c:\documents and settings\Margaret\Application Data\Logitech
2009-06-04 03:24 . 2009-06-04 03:24 -------- d-sh--w- c:\documents and settings\Roy Bristow\PrivacIE
2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-06-04 03:21 . 2009-06-04 03:21 -------- d-sh--w- c:\documents and settings\Roy Bristow\IETldCache
2009-06-04 03:18 . 2009-06-22 18:09 -------- d-----w- c:\windows\ie8updates
2009-06-04 03:18 . 2009-05-12 05:11 102912 ------w- c:\windows\system32\dllcache\iecompat.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-30 19:38 . 2009-03-11 13:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-28 17:29 . 2009-05-08 22:58 117760 ----a-w- c:\documents and settings\Roy Bristow\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-28 17:29 . 2009-05-08 21:10 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-06-28 17:14 . 2008-11-20 15:47 188501 ----a-w- c:\documents and settings\Roy Bristow\Application Data\ContentGuard\CGGuard2.dll
2009-06-23 21:31 . 2008-05-14 14:57 -------- d-----w- c:\program files\Java
2009-06-21 18:13 . 2008-12-07 19:08 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-19 12:12 . 2008-11-20 15:47 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\ContentGuard
2009-06-19 01:23 . 2009-01-04 15:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-19 01:21 . 2009-01-05 03:07 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-17 15:27 . 2008-09-26 23:11 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 15:27 . 2008-09-26 23:11 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-15 01:48 . 2008-05-16 01:27 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\LimeWire
2009-06-14 20:01 . 2008-07-30 18:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-12 00:15 . 2008-06-05 01:14 -------- d-----w- c:\program files\SpiralFrog
2009-06-08 22:21 . 2009-06-08 22:21 -------- d-----w- c:\documents and settings\Owen\Application Data\Logitech
2009-06-08 22:21 . 2009-06-08 22:21 -------- d-----w- c:\documents and settings\Owen\Application Data\Sunbelt
2009-06-07 15:16 . 2009-06-07 15:16 -------- d-----w- c:\documents and settings\Eden\Application Data\Logitech
2009-06-07 15:16 . 2009-06-07 15:16 -------- d-----w- c:\documents and settings\Eden\Application Data\Sunbelt
2009-06-07 15:08 . 2009-06-07 15:07 73872 ----a-w- c:\documents and settings\Margaret\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-07 15:08 . 2009-06-07 15:08 -------- d-----w- c:\documents and settings\Margaret\Application Data\Sunbelt
2009-05-21 15:33 . 2009-01-25 21:52 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-21 08:34 . 2008-05-14 15:01 -------- d-----w- c:\program files\Google
2009-05-13 05:15 . 2004-08-10 17:51 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-12 12:16 . 2009-05-09 16:58 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-05-12 10:56 . 2009-05-12 10:56 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_nielprt_01007.Wdf
2009-05-12 10:55 . 2009-05-12 10:55 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-05-09 16:58 . 2009-05-09 16:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-05-09 15:08 . 2009-05-09 15:08 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq
2009-05-08 21:10 . 2009-05-08 21:10 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-08 21:10 . 2009-05-08 21:10 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\SUPERAntiSpyware.com
2009-05-08 21:10 . 2008-05-22 00:29 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-08 17:12 . 2008-05-14 15:05 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-08 13:25 . 2009-05-08 13:25 -------- d-----w- c:\documents and settings\NetworkService\Application Data\gsdljreq
2009-05-07 15:32 . 2004-08-10 17:51 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-28 00:08 . 2009-04-28 00:08 299352 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-04-23 00:09 . 2009-05-08 10:43 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-04-23 00:09 . 2009-04-23 00:09 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-04-23 00:09 . 2009-04-23 00:09 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-04-23 00:09 . 2009-04-23 00:09 165728 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-04-23 00:09 . 2009-04-23 00:09 343888 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-04-23 00:09 . 2009-04-23 00:09 289632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-04-23 00:09 . 2009-04-23 00:09 82784 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-04-23 00:08 . 2009-04-23 00:08 1629024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-04-23 00:08 . 2009-04-23 00:08 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-04-23 00:08 . 2009-04-23 00:08 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-04-23 00:08 . 2009-04-23 00:08 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-04-23 00:08 . 2009-02-26 01:08 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-04-23 00:08 . 2009-04-23 00:08 632680 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-04-23 00:08 . 2009-04-23 00:08 539512 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-04-23 00:08 . 2009-04-23 00:08 552808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-04-23 00:08 . 2009-04-23 00:08 2324808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-04-23 00:08 . 2009-04-23 00:08 626000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-04-23 00:08 . 2009-04-23 00:08 516440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-04-23 00:08 . 2009-04-23 00:08 953168 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-04-17 12:26 . 2004-08-10 17:51 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-10 17:51 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2008-12-08 01:55 . 2008-12-07 19:08 56 --sh--r- c:\windows\system32\B735C90A02.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"Google Update"="c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-06 133104]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-05-22 160592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-06-17 414992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-9-23 805392]
Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1997-7-11 111376]
Office Startup.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1997-7-11 51984]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 06:42 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/25/2009 9:08 PM 64160]
R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [1/28/2009 1:58 PM 17264]
R0 nielprt;Nielsen Patch Service;c:\windows\system32\drivers\nielprt.sys [5/12/2009 6:55 AM 21888]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SymEFA.sys [3/23/2009 11:39 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1005000.087\BHDrvx86.sys [3/23/2009 11:39 AM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1005000.087\cchpx86.sys [3/23/2009 11:39 AM 482352]
R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [12/7/2008 2:41 PM 14336]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [4/28/2009 11:33 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [4/28/2009 11:33 AM 72944]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [11/13/2008 7:20 PM 13360]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [1/11/2008 6:50 PM 30312]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 6:45 AM 13088]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 5:34 PM 953168]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/4/2009 11:20 AM 195856]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [3/23/2009 11:39 AM 115560]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [11/13/2008 7:20 PM 69168]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/25/2009 5:00 AM 101936]
R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [12/7/2008 2:41 PM 8832]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/26/2008 7:11 PM 19096]
R3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [11/24/2008 10:31 PM 29263712]
S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys [6/30/2009 5:57 PM 276344]
S2 gupdate1c9a2515ee9ac6;Google Update Service (gupdate1c9a2515ee9ac6);c:\program files\Google\Update\GoogleUpdate.exe [3/11/2009 9:55 AM 133104]
S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys [5/12/2009 6:55 AM 9088]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/6/2007 4:22 PM 34064]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [4/28/2009 11:33 AM 7408]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [10/23/2008 5:09 AM 92464]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - QRGFBRNH
*Deregistered* - qrgfbrnh

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
yogtgxzm

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-30 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 00:08]

2008-05-22 c:\windows\Tasks\Ad-Aware.job
- c:\progra~1\Lavasoft\Ad-Aware\Ad-Aware.exe [2009-01-18 00:08]

2009-07-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57]

2009-07-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-11 16:29]

2009-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-11 13:55]

2009-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-11 13:55]

2009-07-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1362977303-1881232705-3471229379-1006Core.job
- c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 06:35]

2009-07-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1362977303-1881232705-3471229379-1006UA.job
- c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 06:35]

2009-05-30 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-01-04 05:07]

2009-07-01 c:\windows\Tasks\User_Feed_Synchronization-{F028BE97-6493-45D6-98BA-3C4460D4AD4D}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-SBAMSvc


.
------- Supplementary Scan -------
.
uStart Page = hxxp://comcast.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Trusted Zone: download.com
Trusted Zone: intuit.com
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-01 15:20
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRT]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNDSrvc]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMTDI]
"ImagePath"="-"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"naiojgmabnolokncbdkabjolfgno"=hex:6a,61,62,6c,67,64,63,6e,6f,64,63,68,6c,65,
6f,61,63,67,6e,6d,00,00
"macpdhjbficnaokdjnleaadhcf"=hex:6a,61,62,6c,67,64,63,6e,6f,64,63,68,6c,65,6f,
61,63,67,6e,6d,00,56
"abedlckcohpbmiinnnoaocjeefpokfiloe"=hex:61,62,6c,6f,6d,66,6a,6b,61,6c,70,69,
6d,6d,6b,6f,62,67,6f,6b,6c,6e,68,67,65,6d,67,6d,68,68,6c,64,65,63,00,7e
"mahdadeebgllhgadjcapkcnlnf"=hex:64,62,63,70,66,6b,6a,6a,62,6a,64,70,70,69,6f,
70,68,6a,61,70,68,6b,68,6b,62,64,62,6f,69,64,63,66,62,6a,63,62,68,61,6e,6e,\

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000003
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000002
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{161B3614-FE54-4D30-8019-0D1E95DD4DB1}\ProgID]
@DACL=(02 0000)
@="Akzydiqq"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1152)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(2156)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\windows\system32\CDRTC.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Dell Network Assistant\hnm_svc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2009-07-01 15:25 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-01 19:25

Pre-Run: 132,412,030,976 bytes free
Post-Run: 138,492,420,096 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

372 --- E O F --- 2009-06-14 20:01
Go to the top of the page
 
+Quote Post
jpshortstuff
post Jul 1 2009, 02:09 PM
Post #6


SuperHelper
Group Icon

Group: Classroom Teacher
Posts: 5,027
Joined: 28-April 07
From: UK
Member No.: 69,799
Operating System: Windows XP (Professional), Windows Vista (Home Business), Windows 7 (Ultimate), Ubuntu Linux



Hi,

Please click Start >> Control Panel >> Add/Remove Programs, and then find and Remove these old versions of Java:
J2SE Runtime Environment 5.0 Update 6
Java™ 6 Update 5
Java™ 6 Update 7

(Leave update 14 as it is the latest)

While you are there, I recommend you consider removing Limewire - its a great way to get yourself infected.


Please disable Spybot TeaTimer via its System Tray icon. For more info, check here.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

CODE
FileLook::
c:\windows\system32\B735C90A02.sys
c:\windows\system32\drivers\nnrnstdi.sys

DirLook::
c:\documents and settings\Roy Bristow\Application Data\gsdljreq
c:\documents and settings\NetworkService\Application Data\gsdljreq

NetSvcs::
yogtgxzm

RegNull::
[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506}*]

RegLockDel::
[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506}*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{161B3614-FE54-4D30-8019-0D1E95DD4DB1}]

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.



5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt.


Next, let's check for any leftovers. Please go to Kaspersky website and perform an online antivirus scan.
  1. Read through the requirements and privacy statement and click on Accept button.
  2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  3. When the downloads have finished, click on Settings.
  4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  5. Click on My Computer under Scan.
  6. Once the scan is complete, it will display the results. Click on View Scan Report.
  7. You will see a list of infected items there. Click on Save Report As....
  8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  9. Please post this log in your next reply.
Let me know how things are running after all this.
Go to the top of the page
 
+Quote Post
royb
post Jul 1 2009, 02:47 PM
Post #7


New Member
*

Group: Authentic Member
Posts: 18
Joined: 29-June 09
Member No.: 86,469
Operating System: XP SP3



Before I go further - I removed J2SE, Java 6 Update 5, Java 6 update 7 and Limewire. I do not have Spybot listed in Add/Remove. Found a Spybot folder in C:\ but cannot delete it.

Please advise.

Thanks
Go to the top of the page
 
+Quote Post
jpshortstuff
post Jul 1 2009, 02:51 PM
Post #8


SuperHelper
Group Icon

Group: Classroom Teacher
Posts: 5,027
Joined: 28-April 07
From: UK
Member No.: 69,799
Operating System: Windows XP (Professional), Windows Vista (Home Business), Windows 7 (Ultimate), Ubuntu Linux



Hi,

You don't need to delete Spybot, just disable it.
  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Uncheck the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done.
  • (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]
Go to the top of the page
 
+Quote Post
royb
post Jul 1 2009, 02:56 PM
Post #9


New Member
*

Group: Authentic Member
Posts: 18
Joined: 29-June 09
Member No.: 86,469
Operating System: XP SP3



I wasn't clear. Spybot is no longer a program on my computer. Left over is a folder with TeaTimer.exe in it but you cannot launch it or delete it.

Thanks
Go to the top of the page
 
+Quote Post
royb
post Jul 1 2009, 02:57 PM
Post #10


New Member
*

Group: Authentic Member
Posts: 18
Joined: 29-June 09
Member No.: 86,469
Operating System: XP SP3



I wasn't clear. Spybot is no longer a program on my computer. Left over is a folder with TeaTimer.exe in it but you cannot launch it or delete it.

Thanks
Go to the top of the page
 
+Quote Post
jpshortstuff
post Jul 1 2009, 02:59 PM
Post #11


SuperHelper
Group Icon

Group: Classroom Teacher
Posts: 5,027
Joined: 28-April 07
From: UK
Member No.: 69,799
Operating System: Windows XP (Professional), Windows Vista (Home Business), Windows 7 (Ultimate), Ubuntu Linux



Ah, I understand. In which case, you don't have to worry about it, we will remove it later if you still can't delete it.
Go to the top of the page
 
+Quote Post
royb
post Jul 1 2009, 06:21 PM
Post #12


New Member
*

Group: Authentic Member
Posts: 18
Joined: 29-June 09
Member No.: 86,469
Operating System: XP SP3



I must go for the evening. My machine still works so if you need to help others please do.

Thanks so far.


ComboFix 09-07-01.01 - Roy Bristow 07/01/2009 17:05.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.497 [GMT -4:00]
Running from: c:\documents and settings\Roy Bristow\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Roy Bristow\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((( Files Created from 2009-06-01 to 2009-07-01 )))))))))))))))))))))))))))))))
.

2009-07-01 15:44 . 2009-02-19 09:00 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVENG.SYS
2009-07-01 15:44 . 2009-02-19 09:00 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVEX15.SYS
2009-07-01 15:44 . 2009-02-19 09:00 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVENG32.DLL
2009-07-01 15:44 . 2009-02-19 09:00 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVEX32A.DLL
2009-07-01 15:44 . 2009-02-25 09:00 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\EECTRL.SYS
2009-07-01 15:44 . 2009-02-25 09:00 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\CCERASER.DLL
2009-07-01 15:44 . 2009-02-25 09:00 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\ERASER.SYS
2009-07-01 15:44 . 2009-01-18 07:18 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\ECMSVR32.DLL
2009-06-30 21:57 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\Scxpx86.dll
2009-06-30 21:57 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys
2009-06-30 21:57 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSvix86.sys
2009-06-30 21:57 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSxpx86.dll
2009-06-30 21:57 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSviA64.sys
2009-06-29 21:34 . 2009-06-29 21:34 -------- d-----w- c:\program files\Flip Words
2009-06-29 19:17 . 2009-06-29 19:18 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\ZoomBrowser EX
2009-06-29 19:09 . 2009-06-29 19:17 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\CameraWindowDC
2009-06-29 19:09 . 2009-06-29 19:09 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\CANON INC
2009-06-24 01:35 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\Scxpx86.dll
2009-06-24 01:35 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSXpx86.sys
2009-06-24 01:35 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSvix86.sys
2009-06-24 01:35 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSxpx86.dll
2009-06-24 01:35 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSviA64.sys
2009-06-23 21:28 . 2009-06-23 21:28 152576 ----a-w- c:\documents and settings\Roy Bristow\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-22 18:17 . 2009-06-22 18:20 -------- dc-h--w- c:\windows\ie8
2009-06-22 18:04 . 2007-01-24 19:27 255848 ----a-w- c:\windows\system32\xactengine2_6.dll
2009-06-22 18:03 . 2009-06-23 21:35 -------- d--h--w- c:\windows\msdownld.tmp
2009-06-22 18:02 . 2009-06-22 18:02 -------- d-----w- c:\windows\Logs
2009-06-21 23:27 . 2009-06-28 17:28 16 ----a-w- c:\documents and settings\Roy Bristow\FlipWords.dat
2009-06-21 18:55 . 2009-06-21 18:55 16 ----a-w- c:\documents and settings\Owen\FlipWords.dat
2009-06-20 20:46 . 2009-06-20 20:46 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-06-18 23:07 . 2009-06-18 23:07 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-06-18 23:07 . 2009-06-18 23:08 -------- d-----w- c:\program files\Canon
2009-06-18 23:04 . 2009-06-18 23:04 -------- d-----w- c:\program files\Common Files\Canon
2009-06-10 08:52 . 2009-04-30 21:22 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-06-10 08:52 . 2009-04-30 21:22 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-09 19:37 . 2009-06-09 19:37 -------- d-sh--w- c:\documents and settings\Roy Bristow\IECompatCache
2009-06-09 13:16 . 2009-06-09 13:16 -------- d-sh--w- c:\documents and settings\Margaret\PrivacIE
2009-06-08 22:22 . 2009-06-08 22:22 -------- d-sh--w- c:\documents and settings\Owen\PrivacIE
2009-06-08 21:06 . 2009-06-08 21:06 -------- d-----w- c:\documents and settings\Eden\Application Data\CyberLink
2009-06-08 11:49 . 2009-06-08 11:49 -------- d-----w- c:\documents and settings\Margaret\Local Settings\Application Data\Symantec
2009-06-07 15:18 . 2009-06-07 15:18 -------- d-sh--w- c:\documents and settings\Eden\PrivacIE
2009-06-07 15:08 . 2009-06-07 15:08 -------- d-----w- c:\documents and settings\Margaret\Application Data\Logitech
2009-06-04 03:24 . 2009-06-04 03:24 -------- d-sh--w- c:\documents and settings\Roy Bristow\PrivacIE
2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-06-04 03:21 . 2009-06-04 03:21 -------- d-sh--w- c:\documents and settings\Roy Bristow\IETldCache
2009-06-04 03:18 . 2009-06-22 18:09 -------- d-----w- c:\windows\ie8updates
2009-06-04 03:18 . 2009-05-12 05:11 102912 ------w- c:\windows\system32\dllcache\iecompat.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-01 20:39 . 2009-03-11 13:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-01 20:31 . 2008-05-16 01:27 -------- d-----w- c:\program files\LimeWire
2009-07-01 20:31 . 2008-05-14 14:57 -------- d-----w- c:\program files\Java
2009-06-28 17:29 . 2009-05-08 22:58 117760 ----a-w- c:\documents and settings\Roy Bristow\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-28 17:29 . 2009-05-08 21:10 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-06-28 17:14 . 2008-11-20 15:47 188501 ----a-w- c:\documents and settings\Roy Bristow\Application Data\ContentGuard\CGGuard2.dll
2009-06-21 18:13 . 2008-12-07 19:08 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-19 12:12 . 2008-11-20 15:47 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\ContentGuard
2009-06-19 01:23 . 2009-01-04 15:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-19 01:21 . 2009-01-05 03:07 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-17 15:27 . 2008-09-26 23:11 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 15:27 . 2008-09-26 23:11 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-15 01:48 . 2008-05-16 01:27 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\LimeWire
2009-06-14 20:01 . 2008-07-30 18:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-12 00:15 . 2008-06-05 01:14 -------- d-----w- c:\program files\SpiralFrog
2009-06-08 22:21 . 2009-06-08 22:21 -------- d-----w- c:\documents and settings\Owen\Application Data\Logitech
2009-06-08 22:21 . 2009-06-08 22:21 -------- d-----w- c:\documents and settings\Owen\Application Data\Sunbelt
2009-06-07 15:16 . 2009-06-07 15:16 -------- d-----w- c:\documents and settings\Eden\Application Data\Logitech
2009-06-07 15:16 . 2009-06-07 15:16 -------- d-----w- c:\documents and settings\Eden\Application Data\Sunbelt
2009-06-07 15:08 . 2009-06-07 15:07 73872 ----a-w- c:\documents and settings\Margaret\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-07 15:08 . 2009-06-07 15:08 -------- d-----w- c:\documents and settings\Margaret\Application Data\Sunbelt
2009-05-21 15:33 . 2009-01-25 21:52 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-21 08:34 . 2008-05-14 15:01 -------- d-----w- c:\program files\Google
2009-05-13 05:15 . 2004-08-10 17:51 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-12 12:16 . 2009-05-09 16:58 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-05-12 10:56 . 2009-05-12 10:56 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_nielprt_01007.Wdf
2009-05-12 10:55 . 2009-05-12 10:55 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-05-09 16:58 . 2009-05-09 16:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-05-09 15:08 . 2009-05-09 15:08 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq
2009-05-08 21:10 . 2009-05-08 21:10 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-08 21:10 . 2009-05-08 21:10 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\SUPERAntiSpyware.com
2009-05-08 21:10 . 2008-05-22 00:29 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-08 17:12 . 2008-05-14 15:05 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-08 13:25 . 2009-05-08 13:25 -------- d-----w- c:\documents and settings\NetworkService\Application Data\gsdljreq
2009-05-07 15:32 . 2004-08-10 17:51 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-28 00:08 . 2009-04-28 00:08 299352 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-04-23 00:09 . 2009-05-08 10:43 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-04-23 00:09 . 2009-04-23 00:09 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-04-23 00:09 . 2009-04-23 00:09 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-04-23 00:09 . 2009-04-23 00:09 165728 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-04-23 00:09 . 2009-04-23 00:09 343888 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-04-23 00:09 . 2009-04-23 00:09 289632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-04-23 00:09 . 2009-04-23 00:09 82784 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-04-23 00:08 . 2009-04-23 00:08 1629024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-04-23 00:08 . 2009-04-23 00:08 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-04-23 00:08 . 2009-04-23 00:08 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-04-23 00:08 . 2009-04-23 00:08 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-04-23 00:08 . 2009-02-26 01:08 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-04-23 00:08 . 2009-04-23 00:08 632680 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-04-23 00:08 . 2009-04-23 00:08 539512 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-04-23 00:08 . 2009-04-23 00:08 552808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-04-23 00:08 . 2009-04-23 00:08 2324808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-04-23 00:08 . 2009-04-23 00:08 626000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-04-23 00:08 . 2009-04-23 00:08 516440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-04-23 00:08 . 2009-04-23 00:08 953168 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-04-17 12:26 . 2004-08-10 17:51 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-10 17:51 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2008-12-08 01:55 . 2008-12-07 19:08 56 --sh--r- c:\windows\system32\B735C90A02.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

--- c:\windows\system32\B735C90A02.sys ---
Company: ------
File Description: ------
File Version: ------
Product Name: ------
Copyright: ------
Original Filename: ------
File size: 56
Created time: 2008-12-07 19:08
Modified time: 2008-12-08 01:55
MD5: AC554BEF1249849DD1567F07B13B947C
SHA1: 4A8B2537D53957B4F1D60446B3E500D23FC76B8E


--- c:\windows\system32\drivers\nnrnstdi.sys ---
Company: The Nielsen Company
File Description: NNRNSTDI helper driver
File Version: 5.1.3.15r
Product Name: NielsenOnline
Copyright: Copyright © 1997-2007 The Nielsen Company
Original Filename: nnrnstdi.sys
File size: 14336
Created time: 2008-12-07 18:41
Modified time: 2008-08-22 19:37
MD5: BA285D9D8F9C650BB1C8713E5A6D94DC
SHA1: 2BB5A832522AB0F034E9C484DBBCFBB3E0D00BC6

---- Directory of c:\documents and settings\NetworkService\Application Data\gsdljreq ----

2009-05-08 13:25 . 2009-05-08 13:25 569 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\localstore.rdf
2009-05-08 13:25 . 2009-05-08 13:25 8598 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\pluginreg.dat
2009-05-08 13:25 . 2009-05-08 13:25 2048 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\webappsstore.sqlite
2009-05-08 13:25 . 2009-05-08 13:25 4096 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\formhistory.sqlite
2009-05-08 13:25 . 2009-05-08 13:25 131072 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\places.sqlite
2009-05-08 13:25 . 2009-05-08 13:26 0 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\places.sqlite-journal
2009-05-08 13:25 . 2009-05-08 13:25 16384 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\key3.db
2009-05-08 13:25 . 2009-05-08 13:25 65536 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\cert8.db
2009-05-08 13:25 . 2009-05-08 13:25 16384 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\secmod.db
2009-05-08 13:25 . 2009-05-08 13:27 2048 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\cookies.sqlite
2009-05-08 13:25 . 2009-05-08 13:25 2048 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\permissions.sqlite
2009-05-08 13:25 . 2009-05-08 13:25 367 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\prefs.js
2009-05-08 13:25 . 2009-05-08 13:25 127820 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\compreg.dat
2009-05-08 13:25 . 2009-05-08 13:25 96173 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\xpti.dat
2009-05-08 13:25 . 2009-05-08 13:25 207 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\compatibility.ini
2009-05-08 13:25 . 2009-05-08 13:25 111 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\profiles.ini

---- Directory of c:\documents and settings\Roy Bristow\Application Data\gsdljreq ----

2009-05-09 15:09 . 2009-05-09 15:09 569 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\localstore.rdf
2009-05-09 15:09 . 2009-05-09 15:09 8598 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\pluginreg.dat
2009-05-09 15:09 . 2009-05-09 15:09 2048 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\webappsstore.sqlite
2009-05-09 15:09 . 2009-05-09 15:09 4096 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\formhistory.sqlite
2009-05-09 15:09 . 2009-05-09 15:09 131072 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\places.sqlite
2009-05-09 15:09 . 2009-05-09 15:09 0 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\places.sqlite-journal
2009-05-09 15:09 . 2009-05-09 15:09 16384 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\key3.db
2009-05-09 15:09 . 2009-05-09 15:20 65536 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\cert8.db
2009-05-09 15:09 . 2009-05-09 15:09 16384 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\secmod.db
2009-05-09 15:09 . 2009-05-09 15:20 2048 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\cookies.sqlite
2009-05-09 15:09 . 2009-05-09 15:09 2048 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\permissions.sqlite
2009-05-09 15:09 . 2009-05-09 15:09 367 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\prefs.js
2009-05-09 15:09 . 2009-05-09 15:09 127820 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\compreg.dat
2009-05-09 15:09 . 2009-05-09 15:09 96173 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\xpti.dat
2009-05-09 15:08 . 2009-05-09 15:08 207 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\compatibility.ini
2009-05-09 15:08 . 2009-05-09 15:08 111 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\profiles.ini


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"Google Update"="c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-06 133104]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-05-22 160592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-06-17 414992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-9-23 805392]
Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1997-7-11 111376]
Office Startup.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1997-7-11 51984]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 06:42 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/25/2009 9:08 PM 64160]
R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [1/28/2009 1:58 PM 17264]
R0 nielprt;Nielsen Patch Service;c:\windows\system32\drivers\nielprt.sys [5/12/2009 6:55 AM 21888]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SymEFA.sys [3/23/2009 11:39 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1005000.087\BHDrvx86.sys [3/23/2009 11:39 AM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1005000.087\cchpx86.sys [3/23/2009 11:39 AM 482352]
R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [12/7/2008 2:41 PM 14336]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [4/28/2009 11:33 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [4/28/2009 11:33 AM 72944]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [11/13/2008 7:20 PM 13360]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [1/11/2008 6:50 PM 30312]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 6:45 AM 13088]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 5:34 PM 953168]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/4/2009 11:20 AM 195856]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [3/23/2009 11:39 AM 115560]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [11/13/2008 7:20 PM 69168]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/25/2009 5:00 AM 101936]
R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [12/7/2008 2:41 PM 8832]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/26/2008 7:11 PM 19096]
R3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [11/24/2008 10:31 PM 29263712]
S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys [6/30/2009 5:57 PM 276344]
S2 gupdate1c9a2515ee9ac6;Google Update Service (gupdate1c9a2515ee9ac6);c:\program files\Google\Update\GoogleUpdate.exe [3/11/2009 9:55 AM 133104]
S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys [5/12/2009 6:55 AM 9088]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/6/2007 4:22 PM 34064]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [4/28/2009 11:33 AM 7408]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [10/23/2008 5:09 AM 92464]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - APPMGMT
*NewlyCreated* - QRGFBRNH
*Deregistered* - qrgfbrnh

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
yogtgxzm

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-30 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 00:08]

2008-05-22 c:\windows\Tasks\Ad-Aware.job
- c:\progra~1\Lavasoft\Ad-Aware\Ad-Aware.exe [2009-01-18 00:08]

2009-07-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57]

2009-07-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-11 16:29]

2009-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-11 13:55]

2009-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-11 13:55]

2009-07-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1362977303-1881232705-3471229379-1006Core.job
- c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 06:35]

2009-07-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1362977303-1881232705-3471229379-1006UA.job
- c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 06:35]

2009-07-01 c:\windows\Tasks\User_Feed_Synchronization-{F028BE97-6493-45D6-98BA-3C4460D4AD4D}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://comcast.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Trusted Zone: download.com
Trusted Zone: intuit.com
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-01 17:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRT]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNDSrvc]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMTDI]
"ImagePath"="-"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000003
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000002
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1152)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(2172)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-07-01 17:12
ComboFix-quarantined-files.txt 2009-07-01 21:12
ComboFix2.txt 2009-07-01 19:25

Pre-Run: 138,699,505,664 bytes free
Post-Run: 138,680,795,136 bytes free

362 --- E O F --- 2009-06-14 20:01



--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Wednesday, July 1, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Wednesday, July 01, 2009 20:50:31
Records in database: 2412125
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 80221
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 01:26:48


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_qrgfbrnh_.sys.zip Infected: Trojan.Win32.BHO.ext 1

The selected area was scanned.
Go to the top of the page
 
+Quote Post
jpshortstuff
post Jul 2 2009, 04:33 AM
Post #13


SuperHelper
Group Icon

Group: Classroom Teacher
Posts: 5,027
Joined: 28-April 07
From: UK
Member No.: 69,799
Operating System: Windows XP (Professional), Windows Vista (Home Business), Windows 7 (Ultimate), Ubuntu Linux



Hi,

I've got another CFScript for you to run, do the same as before:
CODE
File::
c:\windows\system32\B735C90A02.sys

Folder::
c:\documents and settings\NetworkService\Application Data\gsdljreq
c:\documents and settings\Roy Bristow\Application Data\gsdljreq

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=-


Your logs are looking good. Are you having any more problems? What happens if you try and delete that Spybot folder now? Please give the error message if it still doesn't work.
Go to the top of the page
 
+Quote Post
royb
post Jul 2 2009, 11:42 AM
Post #14


New Member
*

Group: Authentic Member
Posts: 18
Joined: 29-June 09
Member No.: 86,469
Operating System: XP SP3



Hi

Spybot folder deleted without problems. Here is my lastest log.

Thanks


ComboFix 09-07-01.01 - Roy Bristow 07/02/2009 13:27.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.498 [GMT -4:00]
Running from: c:\documents and settings\Roy Bristow\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Roy Bristow\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

FILE ::
"c:\windows\system32\B735C90A02.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\NetworkService\Application Data\gsdljreq
c:\documents and settings\NetworkService\Application Data\gsdljreq\profiles.ini
c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\cert8.db
c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\compatibility.ini
c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\compreg.dat
c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\cookies.sqlite
c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\formhistory.sqlite
c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\key3.db
c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\localstore.rdf
c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\permissions.sqlite
c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\places.sqlite-journal
c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\places.sqlite
c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\pluginreg.dat
c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\prefs.js
c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\secmod.db
c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\webappsstore.sqlite
c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\xpti.dat
c:\documents and settings\Roy Bristow\Application Data\gsdljreq
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\profiles.ini
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\cert8.db
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\compatibility.ini
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\compreg.dat
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\cookies.sqlite
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\formhistory.sqlite
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\key3.db
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\localstore.rdf
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\permissions.sqlite
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\places.sqlite-journal
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\places.sqlite
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\pluginreg.dat
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\prefs.js
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\secmod.db
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\webappsstore.sqlite
c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\xpti.dat
c:\windows\system32\B735C90A02.sys

.
((((((((((((((((((((((((( Files Created from 2009-06-02 to 2009-07-02 )))))))))))))))))))))))))))))))
.

2009-07-02 12:05 . 2009-02-25 09:00 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\EECTRL.SYS
2009-07-02 12:05 . 2009-02-25 09:00 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\CCERASER.DLL
2009-07-02 12:05 . 2009-02-25 09:00 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\ERASER.SYS
2009-07-02 12:05 . 2009-02-19 09:00 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVENG.SYS
2009-07-02 12:05 . 2009-02-19 09:00 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVEX15.SYS
2009-07-02 12:05 . 2009-02-19 09:00 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVENG32.DLL
2009-07-02 12:05 . 2009-02-19 09:00 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVEX32A.DLL
2009-07-02 12:05 . 2009-01-18 07:18 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\ECMSVR32.DLL
2009-06-30 21:57 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\Scxpx86.dll
2009-06-30 21:57 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys
2009-06-30 21:57 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSvix86.sys
2009-06-30 21:57 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSxpx86.dll
2009-06-30 21:57 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSviA64.sys
2009-06-29 21:34 . 2009-06-29 21:34 -------- d-----w- c:\program files\Flip Words
2009-06-29 19:17 . 2009-06-29 19:18 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\ZoomBrowser EX
2009-06-29 19:09 . 2009-06-29 19:17 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\CameraWindowDC
2009-06-29 19:09 . 2009-06-29 19:09 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\CANON INC
2009-06-24 01:35 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\Scxpx86.dll
2009-06-24 01:35 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSXpx86.sys
2009-06-24 01:35 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSvix86.sys
2009-06-24 01:35 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSxpx86.dll
2009-06-24 01:35 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSviA64.sys
2009-06-23 21:28 . 2009-06-23 21:28 152576 ----a-w- c:\documents and settings\Roy Bristow\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-22 18:17 . 2009-06-22 18:20 -------- dc-h--w- c:\windows\ie8
2009-06-22 18:04 . 2007-01-24 19:27 255848 ----a-w- c:\windows\system32\xactengine2_6.dll
2009-06-22 18:03 . 2009-06-23 21:35 -------- d--h--w- c:\windows\msdownld.tmp
2009-06-22 18:02 . 2009-06-22 18:02 -------- d-----w- c:\windows\Logs
2009-06-21 23:27 . 2009-06-28 17:28 16 ----a-w- c:\documents and settings\Roy Bristow\FlipWords.dat
2009-06-21 18:55 . 2009-06-21 18:55 16 ----a-w- c:\documents and settings\Owen\FlipWords.dat
2009-06-20 20:46 . 2009-06-20 20:46 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-06-18 23:07 . 2009-06-18 23:07 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-06-18 23:07 . 2009-06-18 23:08 -------- d-----w- c:\program files\Canon
2009-06-18 23:04 . 2009-06-18 23:04 -------- d-----w- c:\program files\Common Files\Canon
2009-06-10 08:52 . 2009-04-30 21:22 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-06-10 08:52 . 2009-04-30 21:22 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-09 19:37 . 2009-06-09 19:37 -------- d-sh--w- c:\documents and settings\Roy Bristow\IECompatCache
2009-06-09 13:16 . 2009-06-09 13:16 -------- d-sh--w- c:\documents and settings\Margaret\PrivacIE
2009-06-08 22:22 . 2009-06-08 22:22 -------- d-sh--w- c:\documents and settings\Owen\PrivacIE
2009-06-08 21:06 . 2009-06-08 21:06 -------- d-----w- c:\documents and settings\Eden\Application Data\CyberLink
2009-06-08 11:49 . 2009-06-08 11:49 -------- d-----w- c:\documents and settings\Margaret\Local Settings\Application Data\Symantec
2009-06-07 15:18 . 2009-06-07 15:18 -------- d-sh--w- c:\documents and settings\Eden\PrivacIE
2009-06-07 15:08 . 2009-06-07 15:08 -------- d-----w- c:\documents and settings\Margaret\Application Data\Logitech
2009-06-04 03:24 . 2009-06-04 03:24 -------- d-sh--w- c:\documents and settings\Roy Bristow\PrivacIE
2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-06-04 03:21 . 2009-06-04 03:21 -------- d-sh--w- c:\documents and settings\Roy Bristow\IETldCache
2009-06-04 03:18 . 2009-06-22 18:09 -------- d-----w- c:\windows\ie8updates
2009-06-04 03:18 . 2009-05-12 05:11 102912 ------w- c:\windows\system32\dllcache\iecompat.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-01 20:39 . 2009-03-11 13:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-01 20:31 . 2008-05-16 01:27 -------- d-----w- c:\program files\LimeWire
2009-07-01 20:31 . 2008-05-14 14:57 -------- d-----w- c:\program files\Java
2009-06-28 17:29 . 2009-05-08 22:58 117760 ----a-w- c:\documents and settings\Roy Bristow\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-28 17:29 . 2009-05-08 21:10 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-06-28 17:14 . 2008-11-20 15:47 188501 ----a-w- c:\documents and settings\Roy Bristow\Application Data\ContentGuard\CGGuard2.dll
2009-06-21 18:13 . 2008-12-07 19:08 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-19 12:12 . 2008-11-20 15:47 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\ContentGuard
2009-06-19 01:23 . 2009-01-04 15:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-19 01:21 . 2009-01-05 03:07 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-17 15:27 . 2008-09-26 23:11 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 15:27 . 2008-09-26 23:11 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-15 01:48 . 2008-05-16 01:27 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\LimeWire
2009-06-14 20:01 . 2008-07-30 18:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-12 00:15 . 2008-06-05 01:14 -------- d-----w- c:\program files\SpiralFrog
2009-06-08 22:21 . 2009-06-08 22:21 -------- d-----w- c:\documents and settings\Owen\Application Data\Logitech
2009-06-08 22:21 . 2009-06-08 22:21 -------- d-----w- c:\documents and settings\Owen\Application Data\Sunbelt
2009-06-07 15:16 . 2009-06-07 15:16 -------- d-----w- c:\documents and settings\Eden\Application Data\Logitech
2009-06-07 15:16 . 2009-06-07 15:16 -------- d-----w- c:\documents and settings\Eden\Application Data\Sunbelt
2009-06-07 15:08 . 2009-06-07 15:07 73872 ----a-w- c:\documents and settings\Margaret\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-07 15:08 . 2009-06-07 15:08 -------- d-----w- c:\documents and settings\Margaret\Application Data\Sunbelt
2009-05-21 15:33 . 2009-01-25 21:52 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-21 08:34 . 2008-05-14 15:01 -------- d-----w- c:\program files\Google
2009-05-13 05:15 . 2004-08-10 17:51 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-12 12:16 . 2009-05-09 16:58 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-05-12 10:56 . 2009-05-12 10:56 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_nielprt_01007.Wdf
2009-05-12 10:55 . 2009-05-12 10:55 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-05-09 16:58 . 2009-05-09 16:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-05-08 21:10 . 2009-05-08 21:10 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-08 21:10 . 2009-05-08 21:10 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\SUPERAntiSpyware.com
2009-05-08 21:10 . 2008-05-22 00:29 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-08 17:12 . 2008-05-14 15:05 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-07 15:32 . 2004-08-10 17:51 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-28 00:08 . 2009-04-28 00:08 299352 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-04-23 00:09 . 2009-05-08 10:43 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-04-23 00:09 . 2009-04-23 00:09 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-04-23 00:09 . 2009-04-23 00:09 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-04-23 00:09 . 2009-04-23 00:09 165728 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-04-23 00:09 . 2009-04-23 00:09 343888 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-04-23 00:09 . 2009-04-23 00:09 289632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-04-23 00:09 . 2009-04-23 00:09 82784 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-04-23 00:08 . 2009-04-23 00:08 1629024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-04-23 00:08 . 2009-04-23 00:08 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-04-23 00:08 . 2009-04-23 00:08 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-04-23 00:08 . 2009-04-23 00:08 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-04-23 00:08 . 2009-02-26 01:08 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-04-23 00:08 . 2009-04-23 00:08 632680 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-04-23 00:08 . 2009-04-23 00:08 539512 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-04-23 00:08 . 2009-04-23 00:08 552808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-04-23 00:08 . 2009-04-23 00:08 2324808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-04-23 00:08 . 2009-04-23 00:08 626000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-04-23 00:08 . 2009-04-23 00:08 516440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-04-23 00:08 . 2009-04-23 00:08 953168 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-04-17 12:26 . 2004-08-10 17:51 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-10 17:51 585216 ----a-w- c:\windows\system32\rpcrt4.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-07-01_19.21.11 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-02 16:57 . 2009-07-02 16:57 16384 c:\windows\Temp\Perflib_Perfdata_598.dat
+ 2009-07-02 16:56 . 2009-07-02 16:56 16384 c:\windows\Temp\Perflib_Perfdata_4c4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"Google Update"="c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-06 133104]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-05-22 160592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-06-17 414992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-9-23 805392]
Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1997-7-11 111376]
Office Startup.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1997-7-11 51984]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 06:42 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/25/2009 9:08 PM 64160]
R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [1/28/2009 1:58 PM 17264]
R0 nielprt;Nielsen Patch Service;c:\windows\system32\drivers\nielprt.sys [5/12/2009 6:55 AM 21888]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SymEFA.sys [3/23/2009 11:39 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1005000.087\BHDrvx86.sys [3/23/2009 11:39 AM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1005000.087\cchpx86.sys [3/23/2009 11:39 AM 482352]
R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [12/7/2008 2:41 PM 14336]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [4/28/2009 11:33 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [4/28/2009 11:33 AM 72944]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [11/13/2008 7:20 PM 13360]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [1/11/2008 6:50 PM 30312]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 6:45 AM 13088]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 5:34 PM 953168]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/4/2009 11:20 AM 195856]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [3/23/2009 11:39 AM 115560]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [11/13/2008 7:20 PM 69168]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/25/2009 5:00 AM 101936]
R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [12/7/2008 2:41 PM 8832]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/26/2008 7:11 PM 19096]
R3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [11/24/2008 10:31 PM 29263712]
S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys [6/30/2009 5:57 PM 276344]
S2 gupdate1c9a2515ee9ac6;Google Update Service (gupdate1c9a2515ee9ac6);c:\program files\Google\Update\GoogleUpdate.exe [3/11/2009 9:55 AM 133104]
S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys [5/12/2009 6:55 AM 9088]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/6/2007 4:22 PM 34064]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [4/28/2009 11:33 AM 7408]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [10/23/2008 5:09 AM 92464]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
yogtgxzm

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 00:08]

2008-05-22 c:\windows\Tasks\Ad-Aware.job
- c:\progra~1\Lavasoft\Ad-Aware\Ad-Aware.exe [2009-01-18 00:08]

2009-07-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57]

2009-07-02 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-11 16:29]

2009-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-11 13:55]

2009-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-11 13:55]

2009-07-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1362977303-1881232705-3471229379-1006Core.job
- c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 06:35]

2009-07-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1362977303-1881232705-3471229379-1006UA.job
- c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 06:35]

2009-07-02 c:\windows\Tasks\User_Feed_Synchronization-{F028BE97-6493-45D6-98BA-3C4460D4AD4D}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://comcast.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Trusted Zone: download.com
Trusted Zone: intuit.com
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-02 13:33
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRT]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNDSrvc]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMTDI]
"ImagePath"="-"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000003
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000002
"State"=dword:0000000b

[HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1140)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2009-07-02 13:35
ComboFix-quarantined-files.txt 2009-07-02 17:35
ComboFix2.txt 2009-07-01 21:12
ComboFix3.txt 2009-07-01 19:25

Pre-Run: 138,628,837,376 bytes free
Post-Run: 138,694,291,456 bytes free

331 --- E O F --- 2009-06-14 20:01
Go to the top of the page
 
+Quote Post
jpshortstuff
post Jul 3 2009, 02:32 AM
Post #15


SuperHelper
Group Icon

Group: Classroom Teacher
Posts: 5,027
Joined: 28-April 07
From: UK
Member No.: 69,799
Operating System: Windows XP (Professional), Windows Vista (Home Business), Windows 7 (Ultimate), Ubuntu Linux



Hi,

Something keeps coming back. Please delete your existing copy of ComboFix, and download a new one (there have been some updates recently that may be pertinent to what we are trying to remove).

Then, run the new ComboFix with this CFScript:
CODE
Driver::
yogtgxzm

NetSvc::
yogtgxzm
Let me know how things are running after that, and please show me the new ComboFix log.
Go to the top of the page
 
+Quote Post

3 Pages V   1 2 3 >
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 7th November 2009 - 12:57 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy