This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Hijacked Computer

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I did something really dumb… I clicked open on some random .exe and then my computer went nutso. Soon after when I rebooted the computer I didn't see anything on my desktop and couldnt even open the Start menu by hitting the windows key (even in Safe Mode!). I was finally able to get everything to show up after doing a a Run Task "control" and opening the control panel. I have tried Ad Aware, Windows One Care and Norton. I know I still have a trojan (or something) because DoubleClick, quantserve.com etc (the list is long) cookies keep showing up.

I am at the point now that I am going to wipe the slate clean. Unless, of course, someone can point out what the heck is going on. Any help is very much needed! :pullhair:

Here is my log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:54:13 PM, on 4/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MioNet\MioNetManager.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
C:\Program Files\MioNet\jvm\bin\MioNet.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\TiVo\Desktop\TranscodingService.exe
C:\Program Files\TiVo\Desktop\TiVoNotify.exe
C:\Program Files\TiVo\Desktop\TiVoServer.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe
C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\MioNet\jvm\bin\MioNet.exe
C:\Program Files\Memeo\AutoSync\MemeoAutoSync.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=Userinit.exe,
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.0.0.135\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [MioNet] C:\Program Files\MioNet\MioNetLauncher.exe /p
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [TranscodingService] "C:\Program Files\TiVo\Desktop\TranscodingService.exe" /auto
O4 - HKCU\..\Run: [TivoNotify] "C:\Program Files\TiVo\Desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify
O4 - HKCU\..\Run: [TivoServer] "C:\Program Files\TiVo\Desktop\TiVoServer.exe" /service /registry /auto:TivoServer
O4 - Startup: Dropbox.lnk = C:\Program Files\Dropbox\Dropbox.exe
O4 - Startup: Memeo AutoSync Launcher.lnk = C:\Program Files\Memeo\AutoSync\MemeoLauncher.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1198957203871
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1198957197418
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MioNet - Unknown owner - C:\Program Files\MioNet\MioNetManager.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

–
End of file - 9281 bytes
Hi

Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop. Post them back to your topic.
Woo, I was starting to think I stumped you guys :P Below are the log files: DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 11:06:44.51 on Sun 04/19/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1250 [GMT -5:00] AV: Norton 360 *On-access scanning enabled* (Updated) FW: Norton 360 *enabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\MioNet\MioNetManager.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\MioNet\jvm\bin\MioNet.exe c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe C:\Program Files\MioNet\jvm\bin\MioNet.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\TiVo\Desktop\TiVoNotify.exe C:\Program Files\TiVo\Desktop\TiVoServer.exe C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Documents and Settings\Pichu\Desktop\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com mStart Page = hxxp://www.yahoo.com uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: &Yahoo;! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.0.0.135\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.0.0.135\IPSBHO.DLL BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: &Google; Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.0.0.135\coIEPlg.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" uRun: [Cha-Ching!] "c:\program files\cha-ching!\Cha-Ching!.exe" /BOOT uRun: [TranscodingService] "c:\program files\tivo\desktop\TranscodingService.exe" /auto uRun: [TivoNotify] "c:\program files\tivo\desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify uRun: [TivoServer] "c:\program files\tivo\desktop\TiVoServer.exe" /service /registry /auto:TivoServer mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe" mRun: [RTHDCPL] RTHDCPL.EXE mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [MioNet] c:\program files\mionet\MioNetLauncher.exe /p StartupFolder: c:\docume~1\pichu\startm~1\programs\startup\memeoa~2.lnk - c:\program files\memeo\autosync\MemeoLauncher.exe StartupFolder: c:\docume~1\pichu\startm~1\programs\startup\yahoo!~1.lnk - c:\program files\yahoo!\widgets\YahooWidgets.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1198957203871 DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1198957197418 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.0.0.135\CoIEPlg.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0300000.087\SymEFA.sys [2009-4-15 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0300000.087\BHDrvx86.sys [2009-4-15 258608] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0300000.087\cchpx86.sys [2009-4-15 482352] R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090414.001\IDSXpx86.sys [2009-4-16 276344] R2 MioNet;MioNet;c:\program files\mionet\MioNetManager.exe [2008-6-10 139264] R2 N360;Norton 360;c:\program files\norton 360\engine\3.0.0.135\ccSvcHst.exe [2009-4-15 115560] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-4-15 101936] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090419.005\NAVENG.SYS [2009-4-19 89104] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090419.005\NAVEX15.SYS [2009-4-19 876144] S3 XDva090;XDva090;\??\c:\windows\system32\xdva090.sys –> c:\windows\system32\XDva090.sys [?] S4 AutoSyncService;Memeo AutoSync ;c:\program files\memeo\autosync\MemeoService.exe [2007-7-6 31768] =============== Created Last 30 ================ 2009-04-18 09:08 –d—– c:\docume~1\pichu\applic~1\Malwarebytes 2009-04-18 09:08 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-04-18 09:08 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-04-18 09:08 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-04-18 09:08 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-04-18 08:04 –d—– c:\program files\Oberon Media 2009-04-16 13:58 a-dshr– C:\cmdcons 2009-04-16 13:57 161,792 a——- c:\windows\SWREG.exe 2009-04-16 13:57 98,816 a——- c:\windows\sed.exe 2009-04-16 13:57 –d—– C:\ComboFix 2009-04-16 07:07 –d—– c:\docume~1\pichu\applic~1\Cha-Ching! 2009-04-16 07:07 –d—– c:\program files\Cha-Ching! 2009-04-15 22:31 –d—– C:\N360_BACKUP 2009-04-15 22:22 –d—– c:\docume~1\alluse~1\applic~1\{7B6BA59A-FB0E-4499-8536-A7420338BF3B} 2009-04-15 22:22 36,400 a—-r– c:\windows\system32\drivers\SymIM.sys 2009-04-15 22:22 124,464 a——- c:\windows\system32\drivers\SYMEVENT.SYS 2009-04-15 22:22 60,808 a——- c:\windows\system32\S32EVNT1.DLL 2009-04-15 22:22 7,386 a——- c:\windows\system32\drivers\SYMEVENT.CAT 2009-04-15 22:22 805 a——- c:\windows\system32\drivers\SYMEVENT.INF 2009-04-15 22:22 –d—– c:\program files\Symantec 2009-04-15 22:21 –d—– c:\windows\system32\drivers\N360 2009-04-15 22:21 –d—– c:\program files\Norton 360 2009-04-15 22:21 –d—– c:\docume~1\alluse~1\applic~1\Symantec 2009-04-15 22:21 –d—– c:\docume~1\alluse~1\applic~1\Norton 2009-04-15 22:17 –d—– c:\program files\NortonInstaller 2009-04-15 22:17 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller 2009-04-15 22:01 –d—– c:\program files\Trend Micro 2009-04-15 20:33 1,203,922 -c—— c:\windows\system32\dllcache\sysmain.sdb 2009-04-15 20:33 215,552 -c—— c:\windows\system32\dllcache\wordpad.exe 2009-04-15 20:33 2,560 ——– c:\windows\system32\xpsp4res.dll 2009-04-15 20:32 284,160 -c—— c:\windows\system32\dllcache\pdh.dll 2009-04-15 20:32 729,088 -c—— c:\windows\system32\dllcache\lsasrv.dll 2009-04-15 20:32 473,600 -c—— c:\windows\system32\dllcache\fastprox.dll 2009-04-15 20:32 453,120 -c—— c:\windows\system32\dllcache\wmiprvsd.dll 2009-04-15 20:32 401,408 -c—— c:\windows\system32\dllcache\rpcss.dll 2009-04-15 20:32 227,840 -c—— c:\windows\system32\dllcache\wmiprvse.exe 2009-04-15 20:32 110,592 -c—— c:\windows\system32\dllcache\services.exe 2009-04-15 20:32 714,752 -c—— c:\windows\system32\dllcache\ntdll.dll 2009-04-15 20:32 617,472 -c—— c:\windows\system32\dllcache\advapi32.dll 2009-04-15 20:22 –d—– c:\program files\AVG 2009-04-15 19:03 –d-h— C:\_Memeo 2009-04-15 18:28 –d—– c:\docume~1\pichu\applic~1\MioNet 2009-04-15 18:28 –d—– c:\program files\MioNet 2009-04-15 18:16 –d—– c:\program files\common files\eSellerate 2009-04-15 17:29 –d—– c:\program files\Memeo 2009-04-15 17:29 –ds—- c:\docume~1\alluse~1\applic~1\Memeo 2009-04-14 17:49 410,984 a——- c:\windows\system32\deploytk.dll 2009-04-12 12:04 –d—– c:\program files\TiVo 2009-04-12 12:04 –d—– c:\docume~1\alluse~1\applic~1\TiVo 2009-04-10 12:32 –d—– c:\windows\Supermarket Mania 2009-04-09 16:19 –d—– c:\program files\iPod 2009-04-09 16:19 –d—– c:\program files\iTunes 2009-04-09 16:19 –d—– c:\docume~1\alluse~1\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-04-05 20:53 –d—– c:\windows\Build a lot 3 Passport to Europe 2009-04-04 14:37 –d—– c:\docume~1\pichu\applic~1\Alawar 2009-04-04 09:54 –d—– c:\windows\Wedding Dash 2 - Rings Around the World 2009-04-04 09:54 –d—– c:\program files\Wedding Dash 2 - Rings Around the World 2009-04-03 18:27 –d—– c:\windows\Fix-it-up - Kates Adventure 2009-04-02 17:41 –d—– c:\docume~1\alluse~1\applic~1\FarmFrenzy-PizzaParty 2009-03-31 19:07 –d—– c:\docume~1\alluse~1\applic~1\SugarGames 2009-03-29 19:36 –d—– c:\docume~1\pichu\applic~1\World-LooM 2009-03-29 17:04 –d—– c:\docume~1\pichu\applic~1\Boolat Games 2009-03-27 19:07 –d—– c:\docume~1\alluse~1\applic~1\Shockwave 2009-03-27 19:07 –d—– c:\docume~1\pichu\applic~1\Shockwave 2009-03-21 09:06 989,696 -c—— c:\windows\system32\dllcache\kernel32.dll ==================== Find3M ==================== 2009-04-16 17:01 1,674 a——- c:\windows\system32\ealregsnapshot1.reg 2009-03-19 16:32 23,400 a——- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-03-06 09:22 284,160 a——- c:\windows\system32\pdh.dll 2009-03-02 19:18 826,368 a——- c:\windows\system32\wininet.dll 2009-02-20 13:09 78,336 a——- c:\windows\system32\ieencode.dll 2009-02-09 07:10 729,088 a——- c:\windows\system32\lsasrv.dll 2009-02-09 07:10 714,752 a——- c:\windows\system32\ntdll.dll 2009-02-09 07:10 617,472 a——- c:\windows\system32\advapi32.dll 2009-02-09 07:10 401,408 a——- c:\windows\system32\rpcss.dll 2009-02-09 06:13 1,846,784 a——- c:\windows\system32\win32k.sys 2009-02-06 06:11 110,592 a——- c:\windows\system32\services.exe 2009-02-06 06:06 2,145,280 a——- c:\windows\system32\ntoskrnl.exe 2009-02-06 05:39 35,328 a——- c:\windows\system32\sc.exe 2009-02-06 05:32 2,023,936 a——- c:\windows\system32\ntkrnlpa.exe 2009-02-03 14:59 56,832 a——- c:\windows\system32\secur32.dll 2008-09-03 14:37 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090320080904\index.dat ============= FINISH: 11:07:00.75 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-03-16.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 12/29/2007 1:17:38 PM System Uptime: 4/18/2009 9:13:59 AM (26 hours ago) Motherboard: EVGA | | NF75 Processor: Intel® Core™2 Duo CPU E6850 @ 3.00GHz | Socket 478 | 3000/333mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 128 GiB total, 84.786 GiB free. D: is CDROM () K: is NetworkDisk (NTFS) - 913 GiB total, 885.582 GiB free. ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP430: 1/19/2009 11:02:28 PM - System Checkpoint RP431: 1/20/2009 11:03:57 PM - System Checkpoint RP432: 1/22/2009 12:25:29 AM - System Checkpoint RP433: 1/23/2009 1:01:28 AM - System Checkpoint RP434: 1/24/2009 2:01:28 AM - System Checkpoint RP435: 1/25/2009 3:02:05 AM - System Checkpoint RP436: 1/26/2009 4:01:00 AM - System Checkpoint RP437: 1/27/2009 5:01:00 AM - System Checkpoint RP438: 1/28/2009 6:01:00 AM - System Checkpoint RP439: 1/29/2009 7:00:59 AM - System Checkpoint RP440: 1/30/2009 8:02:05 AM - System Checkpoint RP441: 1/31/2009 9:01:00 AM - System Checkpoint RP442: 2/1/2009 1:48:48 PM - System Checkpoint RP443: 2/1/2009 11:19:14 PM - Removed MobileMe Control Panel RP444: 2/2/2009 11:39:47 PM - System Checkpoint RP445: 2/3/2009 11:53:31 PM - System Checkpoint RP446: 2/5/2009 12:29:31 AM - System Checkpoint RP447: 2/6/2009 12:53:31 AM - System Checkpoint RP448: 2/7/2009 2:53:11 AM - System Checkpoint RP449: 2/8/2009 3:53:01 AM - System Checkpoint RP450: 2/9/2009 4:53:01 AM - System Checkpoint RP451: 2/10/2009 5:53:01 AM - System Checkpoint RP452: 2/11/2009 6:08:43 AM - System Checkpoint RP453: 2/12/2009 6:23:30 AM - System Checkpoint RP454: 2/13/2009 7:27:16 AM - System Checkpoint RP455: 2/14/2009 8:22:25 AM - System Checkpoint RP456: 2/15/2009 3:00:14 AM - Software Distribution Service 3.0 RP457: 2/16/2009 3:11:16 AM - System Checkpoint RP458: 2/17/2009 4:11:16 AM - System Checkpoint RP459: 2/18/2009 5:11:16 AM - System Checkpoint RP460: 2/19/2009 6:22:36 AM - System Checkpoint RP461: 2/20/2009 7:10:36 AM - System Checkpoint RP462: 2/21/2009 8:10:36 AM - System Checkpoint RP463: 2/22/2009 9:11:41 AM - System Checkpoint RP464: 2/23/2009 9:13:56 AM - System Checkpoint RP465: 2/24/2009 10:13:56 AM - System Checkpoint RP466: 2/25/2009 11:13:56 AM - System Checkpoint RP467: 2/26/2009 11:25:29 AM - System Checkpoint RP468: 2/27/2009 12:13:30 PM - System Checkpoint RP469: 2/28/2009 1:13:29 PM - System Checkpoint RP470: 3/1/2009 3:00:13 AM - Software Distribution Service 3.0 RP471: 3/2/2009 3:10:24 AM - System Checkpoint RP472: 3/3/2009 4:10:24 AM - System Checkpoint RP473: 3/4/2009 5:10:23 AM - System Checkpoint RP474: 3/5/2009 5:33:56 AM - System Checkpoint RP475: 3/6/2009 6:09:56 AM - System Checkpoint RP476: 3/10/2009 2:10:20 PM - System Checkpoint RP477: 3/11/2009 2:46:35 PM - System Checkpoint RP478: 3/12/2009 3:22:54 PM - System Checkpoint RP479: 3/13/2009 4:22:54 PM - System Checkpoint RP480: 3/14/2009 7:58:46 PM - System Checkpoint RP481: 3/15/2009 3:00:13 AM - Software Distribution Service 3.0 RP482: 3/16/2009 3:10:34 AM - System Checkpoint RP483: 3/17/2009 4:10:33 AM - System Checkpoint RP484: 3/18/2009 5:10:34 AM - System Checkpoint RP485: 3/19/2009 5:58:07 AM - System Checkpoint RP486: 3/20/2009 6:10:07 AM - System Checkpoint RP487: 3/21/2009 7:10:07 AM - System Checkpoint RP488: 3/22/2009 3:00:12 AM - Software Distribution Service 3.0 RP489: 3/23/2009 3:10:07 AM - System Checkpoint RP490: 3/24/2009 4:10:07 AM - System Checkpoint RP491: 3/25/2009 5:10:07 AM - System Checkpoint RP492: 3/26/2009 6:21:22 AM - System Checkpoint RP493: 3/27/2009 7:09:21 AM - System Checkpoint RP494: 3/28/2009 8:09:21 AM - System Checkpoint RP495: 3/29/2009 9:44:52 AM - System Checkpoint RP496: 3/30/2009 10:09:22 AM - System Checkpoint RP497: 3/31/2009 6:47:46 AM - Removed Netflix Movie Viewer RP498: 4/1/2009 7:10:26 AM - System Checkpoint RP499: 4/2/2009 8:20:52 AM - System Checkpoint RP500: 4/3/2009 9:08:52 AM - System Checkpoint RP501: 4/4/2009 9:25:24 AM - System Checkpoint RP502: 4/5/2009 3:00:13 AM - Software Distribution Service 3.0 RP503: 4/6/2009 3:32:11 AM - System Checkpoint RP504: 4/7/2009 4:28:12 AM - System Checkpoint RP505: 4/8/2009 4:42:49 AM - System Checkpoint RP506: 4/9/2009 5:06:31 AM - System Checkpoint RP507: 4/10/2009 5:30:28 AM - System Checkpoint RP508: 4/11/2009 5:42:28 AM - System Checkpoint RP509: 4/12/2009 12:03:43 PM - Removed TiVo Desktop 2.6.2 RP510: 4/12/2009 12:04:30 PM - Installed TiVo Desktop 2.7 RP511: 4/13/2009 12:05:34 PM - System Checkpoint RP512: 4/13/2009 7:02:17 PM - Installed Windows XP WgaNotify. RP513: 4/14/2009 5:47:09 PM - Installed Windows Defender RP514: 4/14/2009 5:47:57 PM - Software Distribution Service 3.0 RP515: 4/14/2009 5:48:50 PM - Windows Defender Checkpoint RP516: 4/14/2009 5:49:11 PM - Installed Java™ 6 Update 11 RP517: 4/15/2009 6:30:02 AM - Removed Ad-Aware RP518: 4/15/2009 11:34:38 AM - Microsoft OneCare Protection Checkpoint RP519: 4/15/2009 5:29:28 PM - Installed Memeo AutoBackup RP520: 4/15/2009 6:16:08 PM - Installed Memeo AutoSync RP521: 4/15/2009 6:25:46 PM - Configured Memeo AutoBackup RP522: 4/15/2009 6:28:12 PM - Installed MioNet. RP523: 4/15/2009 8:22:25 PM - Installed AVG Free 8.5 RP524: 4/15/2009 8:24:48 PM - Avg8 Update RP525: 4/15/2009 10:00:41 PM - Removed Windows Defender RP526: 4/15/2009 10:21:07 PM - Removed AVG Free 8.5 RP527: 4/15/2009 10:21:57 PM - Installed AVG Free 8.5 RP528: 4/15/2009 10:56:42 PM - Norton 360 Registry Clean RP529: 4/16/2009 7:25:45 AM - Norton 360 Registry Clean RP530: 4/16/2009 1:58:08 PM - ComboFix created restore point RP531: 4/16/2009 5:01:23 PM - Configured EA Download Manager RP532: 4/17/2009 6:57:17 AM - Software Distribution Service 3.0 RP533: 4/17/2009 7:36:06 AM - Norton 360 Registry Clean RP534: 4/18/2009 6:13:27 PM - System Checkpoint ==== Installed Programs ====================== Acrobat.com Adobe Flash Player 10 ActiveX Adobe Reader 8.1.4 Adobe Shockwave Player Apple Mobile Device Support Apple Software Update AutoUpdate Beach Party Craze (remove only) Bonjour CA Yahoo! Anti-Spy (remove only) Cha-Ching! (remove only) Critical Update for Windows Media Player 11 (KB959772) DirectVobSub (remove only) DivX Codec DivX Converter DivX Player DivX Web Player Dropbox GEAR driver installer for x86 and x64 Google Toolbar for Internet Explorer High Definition Audio Driver Package - KB888111 HijackThis 2.0.2 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) iTunes Java 2 Runtime Environment, SE v1.4.2_15 Java™ 6 Update 11 Java™ 6 Update 3 Java™ 6 Update 7 Malwarebytes' Anti-Malware Marvell Miniport Driver Memeo AutoSync Microsoft .NET Framework 2.0 Service Pack 1 Microsoft Application Error Reporting Microsoft Compression Client Pack 1.0 for Windows XP Microsoft IntelliPoint 6.2 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable MioNet MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 6.0 Parser (KB933579) Nero 7 Essentials neroxml NGWave 4.0 Norton 360 NVIDIA Drivers QuickTime Realtek High Definition Audio Driver Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) TiVo Desktop 2.7 Trillian Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Ventrilo Client WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Live OneCare safety scanner Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 WinRAR archiver Yahoo! Install Manager Yahoo! Messenger Yahoo! Toolbar Yahoo! Widgets ==== Event Viewer Messages From Past Week ======== 4/18/2009 9:14:40 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. 4/15/2009 5:05:08 PM, error: MSFWDrv [9] - 4/15/2009 11:34:44 AM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file userinit.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.5512. 4/14/2009 5:43:41 PM, error: System Error [1003] - Error code 100000ea, parameter1 89dc87a8, parameter2 89a78f60, parameter3 bacdfcbc, parameter4 00000001. 4/14/2009 5:20:50 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s). 4/14/2009 5:20:04 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 4/13/2009 8:11:21 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 4/13/2009 7:22:27 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046} 4/13/2009 7:21:33 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 4/13/2009 7:08:05 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip 4/13/2009 7:08:05 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning. 4/13/2009 7:08:05 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 4/13/2009 7:08:05 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 4/13/2009 7:08:05 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 4/13/2009 7:08:05 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 4/13/2009 7:08:05 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 4/13/2009 7:07:10 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} ==== End Of File ===========================
Hi again,

Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:

  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
    Remember to re-enable them afterwards.

  • Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds.txt log.


A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
Here is the log it generated:

ComboFix 09-04-19.05 - Pichu 04/19/2009 13:52.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1240 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Updated)
FW: Norton 360 *disabled*
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-03-19 to 2009-04-19 )))))))))))))))))))))))))))))))
.

2009-04-18 14:08 . 2009-04-18 14:08 ——– d—–w c:\documents and settings\Pichu\Application Data\Malwarebytes
2009-04-18 14:08 . 2009-04-06 20:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-18 14:08 . 2009-04-06 20:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-18 14:08 . 2009-04-18 14:08 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-16 12:07 . 2009-04-19 18:51 ——– d—–w c:\documents and settings\Pichu\Application Data\Cha-Ching!
2009-04-16 03:31 . 2009-04-16 03:31 ——– d—–w C:\N360_BACKUP
2009-04-16 03:22 . 2009-04-16 03:22 ——– d—–w c:\documents and settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-04-16 03:22 . 2009-04-16 03:21 36400 —-a-r c:\windows\system32\drivers\SymIM.sys
2009-04-16 03:22 . 2009-04-16 03:22 805 —-a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-04-16 03:22 . 2009-04-16 03:22 7386 —-a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-04-16 03:22 . 2009-04-16 03:22 60808 —-a-w c:\windows\system32\S32EVNT1.DLL
2009-04-16 03:22 . 2009-04-16 03:22 124464 —-a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-04-16 03:21 . 2009-04-16 03:21 ——– d—–w c:\windows\system32\drivers\N360
2009-04-16 03:21 . 2009-04-16 09:22 ——– d—–w c:\documents and settings\All Users\Application Data\Symantec
2009-04-16 03:21 . 2009-04-16 03:22 ——– d—–w c:\documents and settings\All Users\Application Data\Norton
2009-04-16 03:17 . 2009-04-16 03:17 ——– d—–w c:\documents and settings\All Users\Application Data\NortonInstaller
2009-04-16 01:33 . 2009-03-27 06:58 1203922 -c—-w c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 01:33 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-16 01:33 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-04-16 01:32 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-04-16 01:32 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 01:32 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 01:32 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 01:32 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 01:32 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-04-16 01:32 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 01:32 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 01:32 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 00:03 . 2009-04-16 00:03 ——– d–h–w C:\_Memeo
2009-04-15 23:28 . 2009-04-19 03:29 ——– d—–w c:\documents and settings\Pichu\Application Data\MioNet
2009-04-15 23:28 . 2009-04-15 23:28 ——– d—–w c:\documents and settings\Pichu\Local Settings\Application Data\MioNet
2009-04-15 23:16 . 2009-04-15 23:16 ——– d—–w c:\documents and settings\All Users\Application Data\InstallShield
2009-04-15 23:16 . 2009-04-15 23:16 ——– d—–w c:\documents and settings\Pichu\Local Settings\Application Data\{4F717BFB-FF31-477F-85D1-7BABC44363EC}
2009-04-15 22:29 . 2009-04-15 23:25 ——– d-s—w c:\documents and settings\Pichu\Local Settings\Application Data\Memeo
2009-04-15 22:29 . 2009-04-15 23:25 ——– d-s—w c:\documents and settings\All Users\Application Data\Memeo
2009-04-15 22:29 . 2009-04-15 22:29 ——– d—–w c:\documents and settings\Pichu\Local Settings\Application Data\{73DF8C24-FEEC-41AF-B020-3FABC7890954}
2009-04-14 22:49 . 2009-04-14 22:49 410984 —-a-w c:\windows\system32\deploytk.dll
2009-04-13 23:53 . 2009-04-16 03:21 ——– d—–w c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft
2009-04-12 17:04 . 2009-04-12 17:04 ——– d—–w c:\documents and settings\All Users\Application Data\TiVo
2009-04-10 17:32 . 2009-04-10 17:32 ——– d—–w c:\windows\Supermarket Mania
2009-04-09 21:19 . 2009-04-09 21:20 ——– d—–w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-06 01:53 . 2009-04-06 01:53 ——– d—–w c:\windows\Build a lot 3 Passport to Europe
2009-04-04 19:37 . 2009-04-04 19:37 ——– d—–w c:\documents and settings\Pichu\Application Data\Alawar
2009-04-04 14:54 . 2009-04-04 14:54 ——– d—–w c:\windows\Wedding Dash 2 - Rings Around the World
2009-04-03 23:27 . 2009-04-03 23:27 ——– d—–w c:\windows\Fix-it-up - Kates Adventure
2009-04-02 22:41 . 2009-04-02 22:42 ——– d—–w c:\documents and settings\All Users\Application Data\FarmFrenzy-PizzaParty
2009-04-01 00:07 . 2009-04-01 00:07 ——– d—–w c:\documents and settings\All Users\Application Data\SugarGames
2009-03-30 00:36 . 2009-03-30 00:36 ——– d—–w c:\documents and settings\Pichu\Application Data\World-LooM
2009-03-29 22:04 . 2009-03-29 22:04 ——– d—–w c:\documents and settings\Pichu\Application Data\Boolat Games
2009-03-28 00:07 . 2009-03-28 00:07 ——– d—–w c:\documents and settings\All Users\Application Data\Shockwave
2009-03-28 00:07 . 2009-03-28 00:07 ——– d—–w c:\documents and settings\Pichu\Application Data\Shockwave
2009-03-21 14:06 . 2009-03-21 14:06 989696 -c—-w c:\windows\system32\dllcache\kernel32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-18 15:57 . 2007-12-30 01:35 ——– d—–w c:\program files\MSN Games
2009-04-18 15:54 . 2007-12-30 01:35 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-18 14:53 . 2009-04-18 13:04 ——– d—–w c:\program files\Oberon Media
2009-04-18 14:15 . 2009-04-15 23:28 ——– d—–w c:\program files\MioNet
2009-04-18 14:08 . 2009-04-18 14:08 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-16 22:02 . 2008-09-19 20:25 ——– d—–w c:\documents and settings\Pichu\Application Data\IGN_DLM
2009-04-16 22:02 . 2007-12-29 21:34 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-16 22:01 . 2008-09-09 00:40 1674 —-a-w c:\windows\system32\ealregsnapshot1.reg
2009-04-16 12:07 . 2009-04-16 12:07 ——– d—–w c:\program files\Cha-Ching!
2009-04-16 04:28 . 2008-09-19 13:44 ——– d—–w c:\documents and settings\Pichu\Application Data\Dropbox
2009-04-16 03:25 . 2009-01-17 01:27 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-04-16 03:22 . 2009-04-16 03:22 ——– d—–w c:\program files\Symantec
2009-04-16 03:21 . 2009-04-16 03:21 ——– d—–w c:\program files\Norton 360
2009-04-16 03:21 . 2009-04-16 03:21 ——– d—–w c:\program files\Windows Sidebar
2009-04-16 03:17 . 2009-04-16 03:17 ——– d—–w c:\program files\NortonInstaller
2009-04-16 03:01 . 2009-04-16 03:01 ——– d—–w c:\program files\Trend Micro
2009-04-16 01:22 . 2009-04-16 01:22 ——– d—–w c:\program files\AVG
2009-04-15 23:30 . 2007-12-29 20:25 15168 —-a-w c:\documents and settings\Pichu\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-15 23:25 . 2009-04-15 22:29 ——– d—–w c:\program files\Memeo
2009-04-15 23:16 . 2009-04-15 23:16 ——– d—–w c:\program files\Common Files\eSellerate
2009-04-15 23:16 . 2007-12-29 21:33 ——– d—–w c:\program files\Common Files\InstallShield
2009-04-15 11:30 . 2007-12-29 21:50 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-04-15 00:27 . 2009-04-14 22:54 ——– d—–w c:\program files\Windows Live Safety Center
2009-04-14 22:49 . 2008-01-08 22:06 ——– d—–w c:\program files\Java
2009-04-14 22:23 . 2007-12-29 20:35 ——– d—–w c:\program files\CA Yahoo! Anti-Spy
2009-04-14 01:12 . 2009-04-14 01:12 ——– d—–w c:\program files\microsoft frontpage
2009-04-13 23:24 . 2007-12-29 20:48 ——– d—–w c:\program files\Trillian
2009-04-12 17:04 . 2009-04-12 17:04 ——– d—–w c:\program files\TiVo
2009-04-12 17:04 . 2008-06-28 00:08 ——– d—–w c:\program files\Common Files\TiVo Shared
2009-04-09 21:20 . 2009-04-09 21:19 ——– d—–w c:\program files\iTunes
2009-04-09 21:19 . 2009-04-09 21:19 ——– d—–w c:\program files\iPod
2009-04-09 21:19 . 2007-12-29 20:50 ——– d—–w c:\program files\Common Files\Apple
2009-04-04 22:27 . 2008-02-06 19:57 ——– d—–w c:\documents and settings\Pichu\Application Data\PlayFirst
2009-04-04 22:27 . 2008-02-06 19:57 ——– d—–w c:\documents and settings\All Users\Application Data\PlayFirst
2009-03-31 11:48 . 2008-07-09 00:36 ——– d—–w c:\program files\Yahoo! Games
2009-03-28 18:21 . 2009-01-11 16:52 ——– d—–w c:\documents and settings\Pichu\Application Data\EleFun Games
2009-03-19 21:32 . 2008-01-29 17:01 23400 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-12 12:55 . 2009-03-12 12:54 ——– d—–w c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-12 12:54 . 2009-03-12 12:54 ——– d—–w c:\program files\Bonjour
2009-03-12 12:54 . 2009-03-12 12:53 ——– d—–w c:\program files\QuickTime
2009-03-06 14:22 . 2001-08-23 12:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2001-08-23 12:00 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-08-04 07:56 78336 —-a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2001-08-23 12:00 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2007-12-29 19:52 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2001-08-23 12:00 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2001-08-23 12:00 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2001-08-23 12:00 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2001-08-23 12:00 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2001-08-23 12:00 2145280 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2001-08-23 12:00 35328 —-a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2001-08-17 13:48 2023936 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 19:59 . 2001-08-23 12:00 56832 —-a-w c:\windows\system32\secur32.dll
2008-09-03 19:37 . 2008-09-03 19:38 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090320080904\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-04-16_18.59.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-18 14:15 . 2009-04-18 14:15 16384 c:\windows\Temp\Perflib_Perfdata_4d0.dat
+ 2009-04-18 14:14 . 2009-04-18 14:14 16384 c:\windows\Temp\Perflib_Perfdata_370.dat
+ 2007-12-29 20:16 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe
- 2007-12-29 20:16 . 2007-07-27 14:41 26488 c:\windows\system32\spupdsvc.exe
- 2008-07-02 00:42 . 2007-11-30 11:18 17272 c:\windows\system32\spmsg.dll
+ 2008-07-02 00:42 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 44544 c:\windows\system32\pngfilt.dll
- 2001-08-23 12:00 . 2008-12-20 23:15 44544 c:\windows\system32\pngfilt.dll
+ 2001-08-23 12:00 . 2009-04-17 12:05 59780 c:\windows\system32\perfc009.dat
- 2001-08-23 12:00 . 2009-04-15 23:36 59780 c:\windows\system32\perfc009.dat
- 2007-12-29 19:53 . 2008-04-14 00:12 91648 c:\windows\system32\mtxoci.dll
+ 2007-12-29 19:53 . 2008-06-12 14:23 91648 c:\windows\system32\mtxoci.dll
+ 2007-12-29 19:53 . 2008-06-12 14:23 66560 c:\windows\system32\mtxclu.dll
- 2007-12-29 19:53 . 2008-04-14 00:12 66560 c:\windows\system32\mtxclu.dll
+ 2007-08-14 00:54 . 2009-02-20 18:09 52224 c:\windows\system32\msfeedsbs.dll
- 2007-08-14 00:54 . 2008-12-20 23:15 52224 c:\windows\system32\msfeedsbs.dll
+ 2007-12-29 19:14 . 2008-06-12 14:23 58880 c:\windows\system32\msdtclog.dll
- 2007-12-29 19:14 . 2008-04-14 00:11 58880 c:\windows\system32\msdtclog.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 27648 c:\windows\system32\jsproxy.dll
- 2001-08-23 12:00 . 2008-12-20 23:15 27648 c:\windows\system32\jsproxy.dll
+ 2007-08-14 00:39 . 2009-02-20 10:20 13824 c:\windows\system32\ieudinit.exe
- 2007-08-14 00:39 . 2008-12-19 09:10 13824 c:\windows\system32\ieudinit.exe
- 2001-08-23 12:00 . 2008-12-20 23:15 44544 c:\windows\system32\iernonce.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 44544 c:\windows\system32\iernonce.dll
- 2001-08-23 12:00 . 2008-12-19 09:10 70656 c:\windows\system32\ie4uinit.exe
+ 2001-08-23 12:00 . 2009-02-20 10:20 70656 c:\windows\system32\ie4uinit.exe
- 2007-08-14 00:36 . 2008-12-20 23:15 63488 c:\windows\system32\icardie.dll
+ 2007-08-14 00:36 . 2009-02-20 18:09 63488 c:\windows\system32\icardie.dll
+ 2009-02-03 19:59 . 2009-02-03 19:59 56832 c:\windows\system32\dllcache\secur32.dll
+ 2001-08-23 12:00 . 2009-02-06 10:39 35328 c:\windows\system32\dllcache\sc.exe
- 2007-08-14 00:36 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2007-08-14 00:36 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 91648 c:\windows\system32\dllcache\mtxoci.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 66560 c:\windows\system32\dllcache\mtxclu.dll
- 2007-12-29 20:28 . 2008-12-20 23:15 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2007-12-29 20:28 . 2009-02-20 18:09 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 58880 c:\windows\system32\dllcache\msdtclog.dll
+ 2007-08-14 00:54 . 2009-02-20 18:09 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2007-08-14 00:54 . 2008-12-20 23:15 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2007-12-29 20:28 . 2008-12-19 09:10 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2007-12-29 20:28 . 2009-02-20 10:20 13824 c:\windows\system32\dllcache\ieudinit.exe
- 2007-08-14 00:39 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2007-08-14 00:39 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2009-02-20 18:09 . 2009-02-20 18:09 78336 c:\windows\system32\dllcache\ieencode.dll
- 2007-08-14 00:39 . 2008-12-19 09:10 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-08-14 00:39 . 2009-02-20 10:20 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-12-29 20:28 . 2009-02-20 18:09 63488 c:\windows\system32\dllcache\icardie.dll
- 2007-12-29 20:28 . 2008-12-20 23:15 63488 c:\windows\system32\dllcache\icardie.dll
+ 2009-03-12 12:54 . 2009-04-18 03:39 86016 c:\windows\Installer\{07287123-B8AC-41CE-8346-3D777245C35B}\PrntWzrdIco.exe
- 2009-03-12 12:54 . 2009-03-12 12:54 86016 c:\windows\Installer\{07287123-B8AC-41CE-8346-3D777245C35B}\PrntWzrdIco.exe
+ 2009-04-17 11:59 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\pngfilt.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 52224 c:\windows\ie7updates\KB963027-IE7\msfeedsbs.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 27648 c:\windows\ie7updates\KB963027-IE7\jsproxy.dll
+ 2009-04-17 11:59 . 2008-12-19 09:10 13824 c:\windows\ie7updates\KB963027-IE7\ieudinit.exe
+ 2009-04-17 11:59 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\iernonce.dll
+ 2009-04-17 11:59 . 2008-04-14 00:11 81920 c:\windows\ie7updates\KB963027-IE7\ieencode.dll
+ 2009-04-17 11:59 . 2008-12-19 09:10 70656 c:\windows\ie7updates\KB963027-IE7\ie4uinit.exe
+ 2009-04-17 11:59 . 2008-12-20 23:15 63488 c:\windows\ie7updates\KB963027-IE7\icardie.dll
- 2007-12-29 19:41 . 2008-04-14 00:12 354304 c:\windows\system32\winhttp.dll
+ 2007-12-29 19:41 . 2008-12-16 12:30 354304 c:\windows\system32\winhttp.dll
- 2001-08-23 12:00 . 2008-12-20 23:15 233472 c:\windows\system32\webcheck.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 233472 c:\windows\system32\webcheck.dll
+ 2007-12-29 19:14 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2007-12-29 19:14 . 2009-02-09 12:10 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2007-12-29 19:14 . 2009-02-09 12:10 473600 c:\windows\system32\wbem\fastprox.dll
- 2001-08-23 12:00 . 2008-12-20 23:15 105984 c:\windows\system32\url.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll
- 2001-08-23 12:00 . 2009-04-15 23:36 397560 c:\windows\system32\perfh009.dat
+ 2001-08-23 12:00 . 2009-04-17 12:05 397560 c:\windows\system32\perfh009.dat
+ 2001-08-23 12:00 . 2009-02-20 18:09 102912 c:\windows\system32\occache.dll
- 2001-08-23 12:00 . 2008-12-20 23:15 102912 c:\windows\system32\occache.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 671232 c:\windows\system32\mstime.dll
- 2001-08-23 12:00 . 2008-12-20 23:15 671232 c:\windows\system32\mstime.dll
- 2001-08-23 12:00 . 2008-12-20 23:15 193024 c:\windows\system32\msrating.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 193024 c:\windows\system32\msrating.dll
- 2001-08-23 12:00 . 2008-12-20 23:15 477696 c:\windows\system32\mshtmled.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 477696 c:\windows\system32\mshtmled.dll
+ 2007-08-14 00:54 . 2009-02-20 18:09 459264 c:\windows\system32\msfeeds.dll
- 2007-08-14 00:54 . 2008-12-20 23:15 459264 c:\windows\system32\msfeeds.dll
+ 2007-12-29 19:53 . 2008-06-12 14:23 161792 c:\windows\system32\msdtcuiu.dll
- 2007-12-29 19:53 . 2008-04-14 00:11 161792 c:\windows\system32\msdtcuiu.dll
- 2007-12-29 19:52 . 2008-04-14 00:11 956928 c:\windows\system32\msdtctm.dll
+ 2007-12-29 19:52 . 2008-06-12 14:23 956928 c:\windows\system32\msdtctm.dll
+ 2007-12-29 19:52 . 2008-06-12 14:23 428032 c:\windows\system32\msdtcprx.dll
- 2001-08-23 12:00 . 2008-04-14 00:11 989696 c:\windows\system32\kernel32.dll
+ 2001-08-23 12:00 . 2009-03-21 14:06 989696 c:\windows\system32\kernel32.dll
+ 2007-08-14 00:34 . 2009-02-20 18:09 268288 c:\windows\system32\iertutil.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 385024 c:\windows\system32\iedkcs32.dll
- 2007-07-11 18:27 . 2008-12-20 23:15 383488 c:\windows\system32\ieapfltr.dll
+ 2007-07-11 18:27 . 2009-02-20 18:09 383488 c:\windows\system32\ieapfltr.dll
+ 2001-08-23 12:00 . 2009-02-20 05:14 161792 c:\windows\system32\ieakui.dll
- 2001-08-23 12:00 . 2008-12-19 05:23 161792 c:\windows\system32\ieakui.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 230400 c:\windows\system32\ieaksie.dll
- 2001-08-23 12:00 . 2008-12-20 23:15 230400 c:\windows\system32\ieaksie.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 153088 c:\windows\system32\ieakeng.dll
- 2001-08-23 12:00 . 2008-12-20 23:15 153088 c:\windows\system32\ieakeng.dll
- 2004-08-04 07:56 . 2008-12-20 23:15 133120 c:\windows\system32\extmgr.dll
+ 2004-08-04 07:56 . 2009-02-20 18:09 133120 c:\windows\system32\extmgr.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 214528 c:\windows\system32\dxtrans.dll
- 2001-08-23 12:00 . 2008-12-20 23:15 214528 c:\windows\system32\dxtrans.dll
- 2001-08-23 12:00 . 2008-12-20 23:15 347136 c:\windows\system32\dxtmsft.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 347136 c:\windows\system32\dxtmsft.dll
- 2007-08-14 00:54 . 2008-12-20 23:15 826368 c:\windows\system32\dllcache\wininet.dll
+ 2007-08-14 00:54 . 2009-03-03 00:18 826368 c:\windows\system32\dllcache\wininet.dll
+ 2008-12-16 12:30 . 2008-12-16 12:30 354304 c:\windows\system32\dllcache\winhttp.dll
+ 2007-08-14 00:54 . 2009-02-20 18:09 233472 c:\windows\system32\dllcache\webcheck.dll
- 2007-08-14 00:54 . 2008-12-20 23:15 233472 c:\windows\system32\dllcache\webcheck.dll
- 2007-08-14 00:44 . 2008-12-20 23:15 105984 c:\windows\system32\dllcache\url.dll
+ 2007-08-14 00:44 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll
- 2007-08-14 00:44 . 2008-12-20 23:15 102912 c:\windows\system32\dllcache\occache.dll
+ 2007-08-14 00:44 . 2009-02-20 18:09 102912 c:\windows\system32\dllcache\occache.dll
+ 2007-08-14 00:54 . 2009-02-20 18:09 671232 c:\windows\system32\dllcache\mstime.dll
- 2007-08-14 00:54 . 2008-12-20 23:15 671232 c:\windows\system32\dllcache\mstime.dll
- 2007-08-14 00:44 . 2008-12-20 23:15 193024 c:\windows\system32\dllcache\msrating.dll
+ 2007-08-14 00:44 . 2009-02-20 18:09 193024 c:\windows\system32\dllcache\msrating.dll
- 2007-08-14 00:54 . 2008-12-20 23:15 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-08-14 00:54 . 2009-02-20 18:09 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-12-29 20:28 . 2009-02-20 18:09 459264 c:\windows\system32\dllcache\msfeeds.dll
- 2007-12-29 20:28 . 2008-12-20 23:15 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 161792 c:\windows\system32\dllcache\msdtcuiu.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 428032 c:\windows\system32\dllcache\msdtcprx.dll
+ 2007-08-14 00:43 . 2009-02-28 04:54 636072 c:\windows\system32\dllcache\iexplore.exe
+ 2007-12-29 20:28 . 2009-02-20 18:09 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2007-08-14 00:39 . 2009-02-20 18:09 385024 c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-12-29 20:28 . 2009-02-20 18:09 383488 c:\windows\system32\dllcache\ieapfltr.dll
- 2007-12-29 20:28 . 2008-12-20 23:15 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2001-08-23 12:00 . 2009-02-20 05:14 161792 c:\windows\system32\dllcache\ieakui.dll
- 2001-08-23 12:00 . 2008-12-19 05:23 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2007-08-14 00:39 . 2009-02-20 18:09 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2007-08-14 00:39 . 2008-12-20 23:15 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2007-08-14 00:39 . 2009-02-20 18:09 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2007-08-14 00:39 . 2008-12-20 23:15 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2007-08-14 00:54 . 2008-12-20 23:15 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2007-08-14 00:54 . 2009-02-20 18:09 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2007-08-14 00:35 . 2009-02-20 18:09 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2007-08-14 00:35 . 2008-12-20 23:15 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2007-08-14 00:35 . 2009-02-20 18:09 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2007-08-14 00:35 . 2008-12-20 23:15 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2007-08-14 00:39 . 2008-12-20 23:15 124928 c:\windows\system32\dllcache\advpack.dll
+ 2007-08-14 00:39 . 2009-02-20 18:09 124928 c:\windows\system32\dllcache\advpack.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 124928 c:\windows\system32\advpack.dll
- 2001-08-23 12:00 . 2008-12-20 23:15 124928 c:\windows\system32\advpack.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 826368 c:\windows\ie7updates\KB963027-IE7\wininet.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 233472 c:\windows\ie7updates\KB963027-IE7\webcheck.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 105984 c:\windows\ie7updates\KB963027-IE7\url.dll
+ 2009-04-17 11:59 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB963027-IE7\spuninst\updspapi.dll
+ 2009-04-17 11:59 . 2008-07-08 13:02 231288 c:\windows\ie7updates\KB963027-IE7\spuninst\spuninst.exe
+ 2009-04-17 11:59 . 2008-12-20 23:15 102912 c:\windows\ie7updates\KB963027-IE7\occache.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 671232 c:\windows\ie7updates\KB963027-IE7\mstime.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 193024 c:\windows\ie7updates\KB963027-IE7\msrating.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 477696 c:\windows\ie7updates\KB963027-IE7\mshtmled.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 459264 c:\windows\ie7updates\KB963027-IE7\msfeeds.dll
+ 2009-04-17 11:59 . 2008-12-19 05:25 634024 c:\windows\ie7updates\KB963027-IE7\iexplore.exe
+ 2009-04-17 11:59 . 2008-12-20 23:15 267776 c:\windows\ie7updates\KB963027-IE7\iertutil.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 384512 c:\windows\ie7updates\KB963027-IE7\iedkcs32.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 383488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dll
+ 2009-04-17 11:59 . 2008-12-19 05:23 161792 c:\windows\ie7updates\KB963027-IE7\ieakui.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 230400 c:\windows\ie7updates\KB963027-IE7\ieaksie.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 153088 c:\windows\ie7updates\KB963027-IE7\ieakeng.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 133120 c:\windows\ie7updates\KB963027-IE7\extmgr.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 214528 c:\windows\ie7updates\KB963027-IE7\dxtrans.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 347136 c:\windows\ie7updates\KB963027-IE7\dxtmsft.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 124928 c:\windows\ie7updates\KB963027-IE7\advpack.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 1160192 c:\windows\system32\urlmon.dll
- 2001-08-23 12:00 . 2008-12-20 23:15 1160192 c:\windows\system32\urlmon.dll
- 2001-08-23 12:00 . 2008-05-07 05:12 1288192 c:\windows\system32\quartz.dll
+ 2001-08-23 12:00 . 2008-12-20 22:14 1288192 c:\windows\system32\quartz.dll
+ 2001-08-23 12:00 . 2009-02-20 18:09 3595264 c:\windows\system32\mshtml.dll
+ 2007-08-14 00:54 . 2009-02-20 18:09 6066176 c:\windows\system32\ieframe.dll
+ 2007-02-12 22:10 . 2008-07-09 14:25 2455488 c:\windows\system32\ieapfltr.dat
- 2007-02-12 22:10 . 2007-07-01 03:31 2455488 c:\windows\system32\ieapfltr.dat
- 2007-08-14 00:54 . 2008-12-20 23:15 1160192 c:\windows\system32\dllcache\urlmon.dll
+ 2007-08-14 00:54 . 2009-02-20 18:09 1160192 c:\windows\system32\dllcache\urlmon.dll
+ 2008-05-07 05:12 . 2008-12-20 22:14 1288192 c:\windows\system32\dllcache\quartz.dll
- 2008-05-07 05:12 . 2008-05-07 05:12 1288192 c:\windows\system32\dllcache\quartz.dll
+ 2008-10-15 00:01 . 2009-02-06 11:08 2189056 c:\windows\system32\dllcache\ntoskrnl.exe
- 2008-10-15 00:01 . 2008-08-14 09:33 2023936 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-10-15 00:01 . 2009-02-06 10:32 2023936 c:\windows\system32\dllcache\ntkrpamp.exe
- 2008-10-15 00:01 . 2008-08-14 09:33 2066048 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2008-10-15 00:01 . 2009-02-08 00:02 2066048 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2008-10-15 00:01 . 2008-08-14 10:09 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-10-15 00:01 . 2009-02-06 11:06 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2007-08-14 00:54 . 2009-02-20 18:09 3595264 c:\windows\system32\dllcache\mshtml.dll
+ 2007-12-29 20:28 . 2009-02-20 18:09 6066176 c:\windows\system32\dllcache\ieframe.dll
+ 2007-12-29 20:28 . 2008-07-09 14:25 2455488 c:\windows\system32\dllcache\ieapfltr.dat
- 2007-12-29 20:28 . 2007-07-01 03:31 2455488 c:\windows\system32\dllcache\ieapfltr.dat
+ 2009-04-17 11:59 . 2008-12-20 23:15 1160192 c:\windows\ie7updates\KB963027-IE7\urlmon.dll
+ 2009-04-17 11:59 . 2009-01-17 03:35 3594752 c:\windows\ie7updates\KB963027-IE7\mshtml.dll
+ 2009-04-17 11:59 . 2008-12-20 23:15 6066688 c:\windows\ie7updates\KB963027-IE7\ieframe.dll
+ 2009-04-17 11:59 . 2007-07-01 03:31 2455488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dat
+ 2008-10-15 00:01 . 2009-02-06 11:08 2189056 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2008-10-15 00:01 . 2008-08-14 09:33 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-10-15 00:01 . 2009-02-06 10:32 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2008-10-15 00:01 . 2008-08-14 09:33 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-15 00:01 . 2009-02-08 00:02 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-15 00:01 . 2009-02-06 11:06 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2008-10-15 00:01 . 2008-08-14 10:09 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2007-12-29 19:50 . 2009-04-06 14:57 24921544 c:\windows\system32\MRT.exe
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2008-09-07 07:20 143360 —-a-w c:\program files\Dropbox\DropboxExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2008-09-07 07:20 143360 —-a-w c:\program files\Dropbox\DropboxExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2008-09-07 07:20 143360 —-a-w c:\program files\Dropbox\DropboxExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-07 68856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-04-24 149040]
"Cha-Ching!"="c:\program files\Cha-Ching!\Cha-Ching!.exe" [2009-04-16 1963712]
"TranscodingService"="c:\program files\TiVo\Desktop\TranscodingService.exe" [2009-01-27 520192]
"TivoNotify"="c:\program files\TiVo\Desktop\TiVoNotify.exe" [2009-01-27 425472]
"TivoServer"="c:\program files\TiVo\Desktop\TiVoServer.exe" [2009-01-27 2143232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2007-08-13 8466432]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2007-08-13 81920]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-14 136600]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-16 153136]
"MioNet"="c:\program files\MioNet\MioNetLauncher.exe" [2008-06-10 32768]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-08-13 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-09-11 16844800]

c:\documents and settings\Pichu\Start Menu\Programs\Startup\
Memeo AutoSync Launcher.lnk - c:\program files\Memeo\AutoSync\MemeoLauncher.exe [2007-7-6 125976]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2007-12-11 3746856]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MioNet\\MioNetManager.exe"=
"c:\\Program Files\\MioNet\\jvm\\bin\\MioNet.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access 0
"1701:TCP"= 1701:TCP:MioNet Remote Drive Access 1
"1702:TCP"= 1702:TCP:MioNet Remote Drive Access 2
"1703:TCP"= 1703:TCP:MioNet Remote Drive Access 3
"1704:TCP"= 1704:TCP:MioNet Remote Drive Access 4
"1705:TCP"= 1705:TCP:MioNet Remote Drive Access 5
"1706:TCP"= 1706:TCP:MioNet Remote Drive Access 6
"1707:TCP"= 1707:TCP:MioNet Remote Drive Access 7
"1708:TCP"= 1708:TCP:MioNet Remote Drive Access 8
"1709:TCP"= 1709:TCP:MioNet Remote Drive Access 9
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification
"1647:TCP"= 1647:TCP:MioNet Storage Device Configuration
"5432:UDP"= 5432:UDP:MioNet Storage Device Discovery

R3 XDva090;XDva090; [x]
R4 AutoSyncService;Memeo AutoSync ;c:\program files\Memeo\AutoSync\MemeoService.exe [2007-07-06 31768]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0300000.087\SYMEFA.SYS [2009-04-16 03:21 310320]
S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0300000.087\BHDrvx86.sys [2009-04-16 03:21 258608]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0300000.087\ccHPx86.sys [2009-04-16 03:21 482352]
S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090414.001\IDSxpx86.sys [2009-04-16 276344]
S2 MioNet;MioNet;c:\program files\MioNet\MioNetManager.exe [2008-06-10 139264]
S2 N360;Norton 360;c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe [2009-04-16 115560]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-04-16 101936]


— Other Services/Drivers In Memory —

*Deregistered* - NDISRD
.
Contents of the 'Scheduled Tasks' folder

2009-04-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-19 13:53
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.0.0.135\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1606980848-2000478354-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:e2,27,b9,97,a8,73,f7,fc,82,f0,4f,50,db,ec,13,67,11,c3,c0,5e,88,e9,50,
42,cd,e4,37,30,99,75,a9,a4,89,43,92,71,e3,63,99,34,fa,25,c6,f9,ab,fa,88,b6,\
"??"=hex:d9,eb,e8,87,54,a1,8d,80,f0,7a,3a,0f,c2,c7,4d,2a

[HKEY_USERS\S-1-5-21-1606980848-2000478354-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:a6,2e,fb,b8,cb,55,8b,bc,3a,e3,7e,b2,ab,b3,a0,7f,cb,a2,05,58,a2,
3c,20,7e,47,29,4b,a4,52,3b,fb,8f,1a,6d,9e,86,ea,ed,e8,12,83,55,b1,38,b7,99,\
"rkeysecu"=hex:e2,26,6d,94,9c,ba,ad,1d,64,79,70,1b,d8,19,de,23
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2484)
c:\program files\Dropbox\DropboxExt.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-04-19 13:54
ComboFix-quarantined-files.txt 2009-04-19 18:54
ComboFix2.txt 2009-04-16 19:00

Pre-Run: 94,276,968,448 bytes free
Post-Run: 94,365,024,256 bytes free

449 — E O F — 2009-04-17 11:59
Hi

Looks quite good :) A few things next.


Uninstall old Adobe Reader versions and get the latest one here or get Foxit Reader here. Make sure you don't install toolbar if choose Foxit Reader!


Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version…

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 13.
  • Click the
    Download
    button to the right.
  • Select Windows on platform combobox and check the box that says:
    Accept License Agreement. Click continue.
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u13-windows-i586-p.exe to install the newest version. Uncheck MSN toolbar if it's offered there.

Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Please run an online scan with Kaspersky Online Scanner as instructed in the screenshot here. If you get a message that latest Java must be installed "enable" the Java add-ons in IE7. Do that using "manage add-ons" from the IE7 toolbar.


Post back its report, a fresh dds.txt log and let me know how's the system running.
My computer seems to be running smoother even though it looks like the spyware didn't find anything.

Here are the logs:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Monday, April 20, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Monday, April 20, 2009 12:29:24
Records in database: 2062878
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
K:\

Scan statistics:
Files scanned: 58198
Threat name: 0
Infected objects: 0
Suspicious objects: 0
Duration of the scan: 00:29:43

No malware has been detected. The scan area is clean.

The selected area was scanned.


ComboFix 09-04-21.06 - Pichu 04/20/2009 17:50.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1292 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Updated)
FW: Norton 360 *disabled*
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-03-21 to 2009-04-21 )))))))))))))))))))))))))))))))
.

2009-04-20 11:50 . 2009-04-20 11:50 73728 —-a-w c:\windows\system32\javacpl.cpl
2009-04-20 11:41 . 2009-04-20 11:44 ——– d—–w c:\documents and settings\Pichu\.SunDownloadManager
2009-04-18 14:08 . 2009-04-18 14:08 ——– d—–w c:\documents and settings\Pichu\Application Data\Malwarebytes
2009-04-18 14:08 . 2009-04-06 20:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-18 14:08 . 2009-04-06 20:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-18 14:08 . 2009-04-18 14:08 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-16 12:07 . 2009-04-20 22:41 ——– d—–w c:\documents and settings\Pichu\Application Data\Cha-Ching!
2009-04-16 03:31 . 2009-04-16 03:31 ——– d—–w C:\N360_BACKUP
2009-04-16 03:22 . 2009-04-16 03:22 ——– d—–w c:\documents and settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-04-16 03:22 . 2009-04-16 03:21 36400 —-a-r c:\windows\system32\drivers\SymIM.sys
2009-04-16 03:22 . 2009-04-16 03:22 805 —-a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-04-16 03:22 . 2009-04-16 03:22 7386 —-a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-04-16 03:22 . 2009-04-16 03:22 60808 —-a-w c:\windows\system32\S32EVNT1.DLL
2009-04-16 03:22 . 2009-04-16 03:22 124464 —-a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-04-16 03:21 . 2009-04-16 03:21 ——– d—–w c:\windows\system32\drivers\N360
2009-04-16 03:21 . 2009-04-16 09:22 ——– d—–w c:\documents and settings\All Users\Application Data\Symantec
2009-04-16 03:21 . 2009-04-16 03:22 ——– d—–w c:\documents and settings\All Users\Application Data\Norton
2009-04-16 03:17 . 2009-04-16 03:17 ——– d—–w c:\documents and settings\All Users\Application Data\NortonInstaller
2009-04-16 01:33 . 2009-03-27 06:58 1203922 -c—-w c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 01:33 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-16 01:33 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-04-16 01:32 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-04-16 01:32 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 01:32 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 01:32 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 01:32 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 01:32 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-04-16 01:32 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 01:32 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 01:32 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 00:03 . 2009-04-16 00:03 ——– d–h–w C:\_Memeo
2009-04-15 23:28 . 2009-04-20 11:54 ——– d—–w c:\documents and settings\Pichu\Application Data\MioNet
2009-04-15 23:28 . 2009-04-15 23:28 ——– d—–w c:\documents and settings\Pichu\Local Settings\Application Data\MioNet
2009-04-15 23:16 . 2009-04-15 23:16 ——– d—–w c:\documents and settings\All Users\Application Data\InstallShield
2009-04-15 23:16 . 2009-04-15 23:16 ——– d—–w c:\documents and settings\Pichu\Local Settings\Application Data\{4F717BFB-FF31-477F-85D1-7BABC44363EC}
2009-04-15 22:29 . 2009-04-15 23:25 ——– d-s—w c:\documents and settings\Pichu\Local Settings\Application Data\Memeo
2009-04-15 22:29 . 2009-04-15 23:25 ——– d-s—w c:\documents and settings\All Users\Application Data\Memeo
2009-04-15 22:29 . 2009-04-15 22:29 ——– d—–w c:\documents and settings\Pichu\Local Settings\Application Data\{73DF8C24-FEEC-41AF-B020-3FABC7890954}
2009-04-14 22:49 . 2009-04-20 11:50 410984 —-a-w c:\windows\system32\deploytk.dll
2009-04-13 23:53 . 2009-04-16 03:21 ——– d—–w c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft
2009-04-12 17:04 . 2009-04-12 17:04 ——– d—–w c:\documents and settings\All Users\Application Data\TiVo
2009-04-10 17:32 . 2009-04-10 17:32 ——– d—–w c:\windows\Supermarket Mania
2009-04-09 21:19 . 2009-04-09 21:20 ——– d—–w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-06 01:53 . 2009-04-06 01:53 ——– d—–w c:\windows\Build a lot 3 Passport to Europe
2009-04-04 19:37 . 2009-04-04 19:37 ——– d—–w c:\documents and settings\Pichu\Application Data\Alawar
2009-04-04 14:54 . 2009-04-04 14:54 ——– d—–w c:\windows\Wedding Dash 2 - Rings Around the World
2009-04-03 23:27 . 2009-04-03 23:27 ——– d—–w c:\windows\Fix-it-up - Kates Adventure
2009-04-02 22:41 . 2009-04-02 22:42 ——– d—–w c:\documents and settings\All Users\Application Data\FarmFrenzy-PizzaParty
2009-04-01 00:07 . 2009-04-01 00:07 ——– d—–w c:\documents and settings\All Users\Application Data\SugarGames
2009-03-30 00:36 . 2009-03-30 00:36 ——– d—–w c:\documents and settings\Pichu\Application Data\World-LooM
2009-03-29 22:04 . 2009-03-29 22:04 ——– d—–w c:\documents and settings\Pichu\Application Data\Boolat Games
2009-03-28 00:07 . 2009-03-28 00:07 ——– d—–w c:\documents and settings\All Users\Application Data\Shockwave
2009-03-28 00:07 . 2009-03-28 00:07 ——– d—–w c:\documents and settings\Pichu\Application Data\Shockwave

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-20 11:50 . 2008-01-08 22:06 ——– d—–w c:\program files\Java
2009-04-20 11:48 . 2008-02-27 12:37 ——– d—–w c:\program files\Common Files\Adobe
2009-04-18 15:57 . 2007-12-30 01:35 ——– d—–w c:\program files\MSN Games
2009-04-18 15:54 . 2007-12-30 01:35 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-18 14:53 . 2009-04-18 13:04 ——– d—–w c:\program files\Oberon Media
2009-04-18 14:15 . 2009-04-15 23:28 ——– d—–w c:\program files\MioNet
2009-04-18 14:08 . 2009-04-18 14:08 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-16 22:02 . 2008-09-19 20:25 ——– d—–w c:\documents and settings\Pichu\Application Data\IGN_DLM
2009-04-16 22:02 . 2007-12-29 21:34 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-16 22:01 . 2008-09-09 00:40 1674 —-a-w c:\windows\system32\ealregsnapshot1.reg
2009-04-16 12:07 . 2009-04-16 12:07 ——– d—–w c:\program files\Cha-Ching!
2009-04-16 04:28 . 2008-09-19 13:44 ——– d—–w c:\documents and settings\Pichu\Application Data\Dropbox
2009-04-16 03:25 . 2009-01-17 01:27 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-04-16 03:22 . 2009-04-16 03:22 ——– d—–w c:\program files\Symantec
2009-04-16 03:21 . 2009-04-16 03:21 ——– d—–w c:\program files\Norton 360
2009-04-16 03:21 . 2009-04-16 03:21 ——– d—–w c:\program files\Windows Sidebar
2009-04-16 03:17 . 2009-04-16 03:17 ——– d—–w c:\program files\NortonInstaller
2009-04-16 03:01 . 2009-04-16 03:01 ——– d—–w c:\program files\Trend Micro
2009-04-16 01:22 . 2009-04-16 01:22 ——– d—–w c:\program files\AVG
2009-04-15 23:30 . 2007-12-29 20:25 15168 —-a-w c:\documents and settings\Pichu\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-15 23:25 . 2009-04-15 22:29 ——– d—–w c:\program files\Memeo
2009-04-15 23:16 . 2009-04-15 23:16 ——– d—–w c:\program files\Common Files\eSellerate
2009-04-15 23:16 . 2007-12-29 21:33 ——– d—–w c:\program files\Common Files\InstallShield
2009-04-15 11:30 . 2007-12-29 21:50 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-04-15 00:27 . 2009-04-14 22:54 ——– d—–w c:\program files\Windows Live Safety Center
2009-04-14 22:23 . 2007-12-29 20:35 ——– d—–w c:\program files\CA Yahoo! Anti-Spy
2009-04-14 01:12 . 2009-04-14 01:12 ——– d—–w c:\program files\microsoft frontpage
2009-04-13 23:24 . 2007-12-29 20:48 ——– d—–w c:\program files\Trillian
2009-04-12 17:04 . 2009-04-12 17:04 ——– d—–w c:\program files\TiVo
2009-04-12 17:04 . 2008-06-28 00:08 ——– d—–w c:\program files\Common Files\TiVo Shared
2009-04-09 21:20 . 2009-04-09 21:19 ——– d—–w c:\program files\iTunes
2009-04-09 21:19 . 2009-04-09 21:19 ——– d—–w c:\program files\iPod
2009-04-09 21:19 . 2007-12-29 20:50 ——– d—–w c:\program files\Common Files\Apple
2009-04-04 22:27 . 2008-02-06 19:57 ——– d—–w c:\documents and settings\Pichu\Application Data\PlayFirst
2009-04-04 22:27 . 2008-02-06 19:57 ——– d—–w c:\documents and settings\All Users\Application Data\PlayFirst
2009-03-31 11:48 . 2008-07-09 00:36 ——– d—–w c:\program files\Yahoo! Games
2009-03-28 18:21 . 2009-01-11 16:52 ——– d—–w c:\documents and settings\Pichu\Application Data\EleFun Games
2009-03-19 21:32 . 2008-01-29 17:01 23400 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-12 12:55 . 2009-03-12 12:54 ——– d—–w c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-12 12:54 . 2009-03-12 12:54 ——– d—–w c:\program files\Bonjour
2009-03-12 12:54 . 2009-03-12 12:53 ——– d—–w c:\program files\QuickTime
2009-03-06 14:22 . 2001-08-23 12:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2001-08-23 12:00 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-08-04 07:56 78336 —-a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2001-08-23 12:00 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2007-12-29 19:52 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2001-08-23 12:00 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2001-08-23 12:00 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2001-08-23 12:00 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2001-08-23 12:00 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2001-08-23 12:00 2145280 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2001-08-23 12:00 35328 —-a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2001-08-17 13:48 2023936 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 19:59 . 2001-08-23 12:00 56832 —-a-w c:\windows\system32\secur32.dll
2008-09-03 19:37 . 2008-09-03 19:38 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090320080904\index.dat
.

((((((((((((((((((((((((((((( SnapShot_2009-04-19_18.53.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-20 11:53 . 2009-04-20 11:53 16384 c:\windows\Temp\Perflib_Perfdata_4e4.dat
+ 2009-04-20 11:53 . 2009-04-20 11:53 16384 c:\windows\Temp\Perflib_Perfdata_318.dat
+ 2009-04-20 11:50 . 2009-04-20 11:50 148888 c:\windows\system32\javaws.exe
- 2008-08-09 00:57 . 2009-04-14 22:49 148888 c:\windows\system32\javaws.exe
+ 2009-04-20 11:50 . 2009-04-20 11:50 144792 c:\windows\system32\javaw.exe
- 2008-08-09 00:57 . 2009-04-14 22:49 144792 c:\windows\system32\javaw.exe
+ 2009-04-20 11:50 . 2009-04-20 11:50 144792 c:\windows\system32\java.exe
- 2008-08-09 00:57 . 2009-04-14 22:49 144792 c:\windows\system32\java.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2008-09-07 07:20 143360 —-a-w c:\program files\Dropbox\DropboxExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2008-09-07 07:20 143360 —-a-w c:\program files\Dropbox\DropboxExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2008-09-07 07:20 143360 —-a-w c:\program files\Dropbox\DropboxExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-07 68856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-04-24 149040]
"Cha-Ching!"="c:\program files\Cha-Ching!\Cha-Ching!.exe" [2009-04-16 1963712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2007-08-13 8466432]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2007-08-13 81920]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-16 153136]
"MioNet"="c:\program files\MioNet\MioNetLauncher.exe" [2008-06-10 32768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-20 148888]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-08-13 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-09-11 16844800]

c:\documents and settings\Pichu\Start Menu\Programs\Startup\
Memeo AutoSync Launcher.lnk - c:\program files\Memeo\AutoSync\MemeoLauncher.exe [2007-7-6 125976]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2007-12-11 3746856]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MioNet\\MioNetManager.exe"=
"c:\\Program Files\\MioNet\\jvm\\bin\\MioNet.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access 0
"1701:TCP"= 1701:TCP:MioNet Remote Drive Access 1
"1702:TCP"= 1702:TCP:MioNet Remote Drive Access 2
"1703:TCP"= 1703:TCP:MioNet Remote Drive Access 3
"1704:TCP"= 1704:TCP:MioNet Remote Drive Access 4
"1705:TCP"= 1705:TCP:MioNet Remote Drive Access 5
"1706:TCP"= 1706:TCP:MioNet Remote Drive Access 6
"1707:TCP"= 1707:TCP:MioNet Remote Drive Access 7
"1708:TCP"= 1708:TCP:MioNet Remote Drive Access 8
"1709:TCP"= 1709:TCP:MioNet Remote Drive Access 9
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification
"1647:TCP"= 1647:TCP:MioNet Storage Device Configuration
"5432:UDP"= 5432:UDP:MioNet Storage Device Discovery

R3 XDva090;XDva090; [x]
R4 AutoSyncService;Memeo AutoSync ;c:\program files\Memeo\AutoSync\MemeoService.exe [2007-07-06 31768]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0300000.087\SYMEFA.SYS [2009-04-16 03:21 310320]
S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0300000.087\BHDrvx86.sys [2009-04-16 03:21 258608]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0300000.087\ccHPx86.sys [2009-04-16 03:21 482352]
S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090414.001\IDSxpx86.sys [2009-04-16 276344]
S2 MioNet;MioNet;c:\program files\MioNet\MioNetManager.exe [2008-06-10 139264]
S2 N360;Norton 360;c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe [2009-04-16 115560]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-04-16 101936]


— Other Services/Drivers In Memory —

*Deregistered* - NDISRD
.
Contents of the 'Scheduled Tasks' folder

2009-04-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-20 17:51
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.0.0.135\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1606980848-2000478354-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:e2,27,b9,97,a8,73,f7,fc,82,f0,4f,50,db,ec,13,67,11,c3,c0,5e,88,e9,50,
42,cd,e4,37,30,99,75,a9,a4,89,43,92,71,e3,63,99,34,fa,25,c6,f9,ab,fa,88,b6,\
"??"=hex:d9,eb,e8,87,54,a1,8d,80,f0,7a,3a,0f,c2,c7,4d,2a

[HKEY_USERS\S-1-5-21-1606980848-2000478354-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:a6,2e,fb,b8,cb,55,8b,bc,3a,e3,7e,b2,ab,b3,a0,7f,cb,a2,05,58,a2,
3c,20,7e,47,29,4b,a4,52,3b,fb,8f,1a,6d,9e,86,ea,ed,e8,12,83,55,b1,38,b7,99,\
"rkeysecu"=hex:e2,26,6d,94,9c,ba,ad,1d,64,79,70,1b,d8,19,de,23
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(4236)
c:\program files\Dropbox\DropboxExt.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-04-20 17:52
ComboFix-quarantined-files.txt 2009-04-20 22:52
ComboFix2.txt 2009-04-19 18:54
ComboFix3.txt 2009-04-16 19:00

Pre-Run: 94,137,094,144 bytes free
Post-Run: 94,185,758,720 bytes free

257 — E O F — 2009-04-17 11:59
DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 20:26:14.37 on Sat 04/25/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1168 [GMT -5:00] AV: Norton 360 *On-access scanning enabled* (Updated) FW: Norton 360 *enabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\WINDOWS\RTHDCPL.EXE svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\MioNet\MioNetManager.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\MioNet\jvm\bin\MioNet.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe C:\Program Files\MioNet\jvm\bin\MioNet.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\TiVo\Desktop\TranscodingService.exe C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\explorer.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Java\jre6\bin\java.exe C:\Documents and Settings\Pichu\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com mStart Page = hxxp://www.yahoo.com uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.0.0.135\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.0.0.135\IPSBHO.DLL BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.0.0.135\coIEPlg.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" uRun: [Cha-Ching!] "c:\program files\cha-ching!\Cha-Ching!.exe" /BOOT mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe" mRun: [RTHDCPL] RTHDCPL.EXE mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [MioNet] c:\program files\mionet\MioNetLauncher.exe /p mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript StartupFolder: c:\docume~1\pichu\startm~1\programs\startup\memeoa~2.lnk - c:\program files\memeo\autosync\MemeoLauncher.exe StartupFolder: c:\docume~1\pichu\startm~1\programs\startup\yahoo!~1.lnk - c:\program files\yahoo!\widgets\YahooWidgets.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1198957203871 DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1198957197418 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.0.0.135\CoIEPlg.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0300000.087\SymEFA.sys [2009-4-15 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0300000.087\BHDrvx86.sys [2009-4-15 258608] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0300000.087\cchpx86.sys [2009-4-15 482352] R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090420.001\IDSXpx86.sys [2009-4-24 276344] R2 MioNet;MioNet;c:\program files\mionet\MioNetManager.exe [2008-6-10 139264] R2 N360;Norton 360;c:\program files\norton 360\engine\3.0.0.135\ccSvcHst.exe [2009-4-15 115560] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-4-15 101936] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090425.020\NAVENG.SYS [2009-4-25 89104] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090425.020\NAVEX15.SYS [2009-4-25 876144] S3 XDva090;XDva090;\??\c:\windows\system32\xdva090.sys –> c:\windows\system32\XDva090.sys [?] S4 AutoSyncService;Memeo AutoSync ;c:\program files\memeo\autosync\MemeoService.exe [2007-7-6 31768] =============== Created Last 30 ================ 2009-04-25 19:18 61,440 a——- c:\windows\system32\drivers\elcsjzo.sys 2009-04-24 22:31 –d—– c:\docume~1\alluse~1\applic~1\PopCap 2009-04-20 17:50 –d—– C:\ComboFix 2009-04-20 06:50 73,728 a——- c:\windows\system32\javacpl.cpl 2009-04-20 06:41 –d—– c:\documents and settings\pichu\.SunDownloadManager 2009-04-18 09:08 –d—– c:\docume~1\pichu\applic~1\Malwarebytes 2009-04-18 09:08 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-04-18 09:08 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-04-18 09:08 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-04-18 09:08 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-04-18 08:04 –d—– c:\program files\Oberon Media 2009-04-16 13:58 a-dshr– C:\cmdcons 2009-04-16 13:57 161,792 a——- c:\windows\SWREG.exe 2009-04-16 13:57 98,816 a——- c:\windows\sed.exe 2009-04-16 07:07 –d—– c:\docume~1\pichu\applic~1\Cha-Ching! 2009-04-16 07:07 –d—– c:\program files\Cha-Ching! 2009-04-15 22:31 –d—– C:\N360_BACKUP 2009-04-15 22:22 –d—– c:\docume~1\alluse~1\applic~1\{7B6BA59A-FB0E-4499-8536-A7420338BF3B} 2009-04-15 22:22 36,400 a—-r– c:\windows\system32\drivers\SymIM.sys 2009-04-15 22:22 124,464 a——- c:\windows\system32\drivers\SYMEVENT.SYS 2009-04-15 22:22 60,808 a——- c:\windows\system32\S32EVNT1.DLL 2009-04-15 22:22 7,386 a——- c:\windows\system32\drivers\SYMEVENT.CAT 2009-04-15 22:22 805 a——- c:\windows\system32\drivers\SYMEVENT.INF 2009-04-15 22:22 –d—– c:\program files\Symantec 2009-04-15 22:21 –d—– c:\windows\system32\drivers\N360 2009-04-15 22:21 –d—– c:\program files\Norton 360 2009-04-15 22:21 –d—– c:\docume~1\alluse~1\applic~1\Symantec 2009-04-15 22:21 –d—– c:\docume~1\alluse~1\applic~1\Norton 2009-04-15 22:17 –d—– c:\program files\NortonInstaller 2009-04-15 22:17 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller 2009-04-15 22:01 –d—– c:\program files\Trend Micro 2009-04-15 20:33 1,203,922 -c—— c:\windows\system32\dllcache\sysmain.sdb 2009-04-15 20:33 215,552 -c—— c:\windows\system32\dllcache\wordpad.exe 2009-04-15 20:33 2,560 ——– c:\windows\system32\xpsp4res.dll 2009-04-15 20:32 284,160 -c—— c:\windows\system32\dllcache\pdh.dll 2009-04-15 20:32 729,088 -c—— c:\windows\system32\dllcache\lsasrv.dll 2009-04-15 20:32 473,600 -c—— c:\windows\system32\dllcache\fastprox.dll 2009-04-15 20:32 453,120 -c—— c:\windows\system32\dllcache\wmiprvsd.dll 2009-04-15 20:32 401,408 -c—— c:\windows\system32\dllcache\rpcss.dll 2009-04-15 20:32 227,840 -c—— c:\windows\system32\dllcache\wmiprvse.exe 2009-04-15 20:32 110,592 -c—— c:\windows\system32\dllcache\services.exe 2009-04-15 20:32 714,752 -c—— c:\windows\system32\dllcache\ntdll.dll 2009-04-15 20:32 617,472 -c—— c:\windows\system32\dllcache\advapi32.dll 2009-04-15 20:22 –d—– c:\program files\AVG 2009-04-15 19:03 –d-h— C:\_Memeo 2009-04-15 18:28 –d—– c:\docume~1\pichu\applic~1\MioNet 2009-04-15 18:28 –d—– c:\program files\MioNet 2009-04-15 18:16 –d—– c:\program files\common files\eSellerate 2009-04-15 17:29 –d—– c:\program files\Memeo 2009-04-15 17:29 –ds—- c:\docume~1\alluse~1\applic~1\Memeo 2009-04-14 17:49 410,984 a——- c:\windows\system32\deploytk.dll 2009-04-12 12:04 –d—– c:\program files\TiVo 2009-04-12 12:04 –d—– c:\docume~1\alluse~1\applic~1\TiVo 2009-04-09 16:19 –d—– c:\program files\iPod 2009-04-09 16:19 –d—– c:\program files\iTunes 2009-04-09 16:19 –d—– c:\docume~1\alluse~1\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-04-04 14:37 –d—– c:\docume~1\pichu\applic~1\Alawar 2009-04-02 17:41 –d—– c:\docume~1\alluse~1\applic~1\FarmFrenzy-PizzaParty 2009-03-31 19:07 –d—– c:\docume~1\alluse~1\applic~1\SugarGames 2009-03-29 19:36 –d—– c:\docume~1\pichu\applic~1\World-LooM 2009-03-29 17:04 –d—– c:\docume~1\pichu\applic~1\Boolat Games 2009-03-27 19:07 –d—– c:\docume~1\alluse~1\applic~1\Shockwave 2009-03-27 19:07 –d—– c:\docume~1\pichu\applic~1\Shockwave ==================== Find3M ==================== 2009-04-16 17:01 1,674 a——- c:\windows\system32\ealregsnapshot1.reg 2009-03-19 16:32 23,400 a——- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-03-06 09:22 284,160 a——- c:\windows\system32\pdh.dll 2009-03-02 19:18 826,368 a——- c:\windows\system32\wininet.dll 2009-02-20 13:09 78,336 a——- c:\windows\system32\ieencode.dll 2009-02-09 07:10 729,088 a——- c:\windows\system32\lsasrv.dll 2009-02-09 07:10 714,752 a——- c:\windows\system32\ntdll.dll 2009-02-09 07:10 617,472 a——- c:\windows\system32\advapi32.dll 2009-02-09 07:10 401,408 a——- c:\windows\system32\rpcss.dll 2009-02-09 06:13 1,846,784 a——- c:\windows\system32\win32k.sys 2009-02-06 06:11 110,592 a——- c:\windows\system32\services.exe 2009-02-06 06:06 2,145,280 a——- c:\windows\system32\ntoskrnl.exe 2009-02-06 05:39 35,328 a——- c:\windows\system32\sc.exe 2009-02-06 05:32 2,023,936 a——- c:\windows\system32\ntkrnlpa.exe 2009-02-03 14:59 56,832 a——- c:\windows\system32\secur32.dll 2008-09-03 14:37 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090320080904\index.dat ============= FINISH: 20:26:41.53 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-03-16.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 12/29/2007 1:17:38 PM System Uptime: 4/20/2009 6:52:51 AM (134 hours ago) Motherboard: EVGA | | NF75 Processor: Intel® Core™2 Duo CPU E6850 @ 3.00GHz | Socket 478 | 3000/333mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 128 GiB total, 87.4 GiB free. D: is CDROM () K: is NetworkDisk (NTFS) - 913 GiB total, 885.582 GiB free. ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP436: 1/26/2009 4:01:00 AM - System Checkpoint RP437: 1/27/2009 5:01:00 AM - System Checkpoint RP438: 1/28/2009 6:01:00 AM - System Checkpoint RP439: 1/29/2009 7:00:59 AM - System Checkpoint RP440: 1/30/2009 8:02:05 AM - System Checkpoint RP441: 1/31/2009 9:01:00 AM - System Checkpoint RP442: 2/1/2009 1:48:48 PM - System Checkpoint RP443: 2/1/2009 11:19:14 PM - Removed MobileMe Control Panel RP444: 2/2/2009 11:39:47 PM - System Checkpoint RP445: 2/3/2009 11:53:31 PM - System Checkpoint RP446: 2/5/2009 12:29:31 AM - System Checkpoint RP447: 2/6/2009 12:53:31 AM - System Checkpoint RP448: 2/7/2009 2:53:11 AM - System Checkpoint RP449: 2/8/2009 3:53:01 AM - System Checkpoint RP450: 2/9/2009 4:53:01 AM - System Checkpoint RP451: 2/10/2009 5:53:01 AM - System Checkpoint RP452: 2/11/2009 6:08:43 AM - System Checkpoint RP453: 2/12/2009 6:23:30 AM - System Checkpoint RP454: 2/13/2009 7:27:16 AM - System Checkpoint RP455: 2/14/2009 8:22:25 AM - System Checkpoint RP456: 2/15/2009 3:00:14 AM - Software Distribution Service 3.0 RP457: 2/16/2009 3:11:16 AM - System Checkpoint RP458: 2/17/2009 4:11:16 AM - System Checkpoint RP459: 2/18/2009 5:11:16 AM - System Checkpoint RP460: 2/19/2009 6:22:36 AM - System Checkpoint RP461: 2/20/2009 7:10:36 AM - System Checkpoint RP462: 2/21/2009 8:10:36 AM - System Checkpoint RP463: 2/22/2009 9:11:41 AM - System Checkpoint RP464: 2/23/2009 9:13:56 AM - System Checkpoint RP465: 2/24/2009 10:13:56 AM - System Checkpoint RP466: 2/25/2009 11:13:56 AM - System Checkpoint RP467: 2/26/2009 11:25:29 AM - System Checkpoint RP468: 2/27/2009 12:13:30 PM - System Checkpoint RP469: 2/28/2009 1:13:29 PM - System Checkpoint RP470: 3/1/2009 3:00:13 AM - Software Distribution Service 3.0 RP471: 3/2/2009 3:10:24 AM - System Checkpoint RP472: 3/3/2009 4:10:24 AM - System Checkpoint RP473: 3/4/2009 5:10:23 AM - System Checkpoint RP474: 3/5/2009 5:33:56 AM - System Checkpoint RP475: 3/6/2009 6:09:56 AM - System Checkpoint RP476: 3/10/2009 2:10:20 PM - System Checkpoint RP477: 3/11/2009 2:46:35 PM - System Checkpoint RP478: 3/12/2009 3:22:54 PM - System Checkpoint RP479: 3/13/2009 4:22:54 PM - System Checkpoint RP480: 3/14/2009 7:58:46 PM - System Checkpoint RP481: 3/15/2009 3:00:13 AM - Software Distribution Service 3.0 RP482: 3/16/2009 3:10:34 AM - System Checkpoint RP483: 3/17/2009 4:10:33 AM - System Checkpoint RP484: 3/18/2009 5:10:34 AM - System Checkpoint RP485: 3/19/2009 5:58:07 AM - System Checkpoint RP486: 3/20/2009 6:10:07 AM - System Checkpoint RP487: 3/21/2009 7:10:07 AM - System Checkpoint RP488: 3/22/2009 3:00:12 AM - Software Distribution Service 3.0 RP489: 3/23/2009 3:10:07 AM - System Checkpoint RP490: 3/24/2009 4:10:07 AM - System Checkpoint RP491: 3/25/2009 5:10:07 AM - System Checkpoint RP492: 3/26/2009 6:21:22 AM - System Checkpoint RP493: 3/27/2009 7:09:21 AM - System Checkpoint RP494: 3/28/2009 8:09:21 AM - System Checkpoint RP495: 3/29/2009 9:44:52 AM - System Checkpoint RP496: 3/30/2009 10:09:22 AM - System Checkpoint RP497: 3/31/2009 6:47:46 AM - Removed Netflix Movie Viewer RP498: 4/1/2009 7:10:26 AM - System Checkpoint RP499: 4/2/2009 8:20:52 AM - System Checkpoint RP500: 4/3/2009 9:08:52 AM - System Checkpoint RP501: 4/4/2009 9:25:24 AM - System Checkpoint RP502: 4/5/2009 3:00:13 AM - Software Distribution Service 3.0 RP503: 4/6/2009 3:32:11 AM - System Checkpoint RP504: 4/7/2009 4:28:12 AM - System Checkpoint RP505: 4/8/2009 4:42:49 AM - System Checkpoint RP506: 4/9/2009 5:06:31 AM - System Checkpoint RP507: 4/10/2009 5:30:28 AM - System Checkpoint RP508: 4/11/2009 5:42:28 AM - System Checkpoint RP509: 4/12/2009 12:03:43 PM - Removed TiVo Desktop 2.6.2 RP510: 4/12/2009 12:04:30 PM - Installed TiVo Desktop 2.7 RP511: 4/13/2009 12:05:34 PM - System Checkpoint RP512: 4/13/2009 7:02:17 PM - Installed Windows XP WgaNotify. RP513: 4/14/2009 5:47:09 PM - Installed Windows Defender RP514: 4/14/2009 5:47:57 PM - Software Distribution Service 3.0 RP515: 4/14/2009 5:48:50 PM - Windows Defender Checkpoint RP516: 4/14/2009 5:49:11 PM - Installed Java™ 6 Update 11 RP517: 4/15/2009 6:30:02 AM - Removed Ad-Aware RP518: 4/15/2009 11:34:38 AM - Microsoft OneCare Protection Checkpoint RP519: 4/15/2009 5:29:28 PM - Installed Memeo AutoBackup RP520: 4/15/2009 6:16:08 PM - Installed Memeo AutoSync RP521: 4/15/2009 6:25:46 PM - Configured Memeo AutoBackup RP522: 4/15/2009 6:28:12 PM - Installed MioNet. RP523: 4/15/2009 8:22:25 PM - Installed AVG Free 8.5 RP524: 4/15/2009 8:24:48 PM - Avg8 Update RP525: 4/15/2009 10:00:41 PM - Removed Windows Defender RP526: 4/15/2009 10:21:07 PM - Removed AVG Free 8.5 RP527: 4/15/2009 10:21:57 PM - Installed AVG Free 8.5 RP528: 4/15/2009 10:56:42 PM - Norton 360 Registry Clean RP529: 4/16/2009 7:25:45 AM - Norton 360 Registry Clean RP530: 4/16/2009 1:58:08 PM - ComboFix created restore point RP531: 4/16/2009 5:01:23 PM - Configured EA Download Manager RP532: 4/17/2009 6:57:17 AM - Software Distribution Service 3.0 RP533: 4/17/2009 7:36:06 AM - Norton 360 Registry Clean RP534: 4/18/2009 6:13:27 PM - System Checkpoint RP535: 4/19/2009 1:52:35 PM - ComboFix created restore point RP536: 4/19/2009 2:54:20 PM - Norton 360 Registry Clean RP537: 4/20/2009 6:39:01 AM - Removed Acrobat.com RP538: 4/20/2009 6:45:40 AM - Removed Java 2 Runtime Environment, SE v1.4.2_15 RP539: 4/20/2009 6:46:04 AM - Removed Java™ 6 Update 3 RP540: 4/20/2009 6:46:27 AM - Removed Java™ 6 Update 7 RP541: 4/20/2009 6:47:44 AM - Removed Adobe Reader 8.1.4 RP542: 4/20/2009 6:48:11 AM - Installed Adobe Reader 9.1. RP543: 4/20/2009 6:50:05 AM - Removed Java™ 6 Update 11 RP544: 4/20/2009 6:50:33 AM - Installed Java™ 6 Update 13 RP545: 4/20/2009 5:50:22 PM - ComboFix created restore point RP546: 4/21/2009 6:05:17 PM - System Checkpoint RP547: 4/22/2009 6:33:09 PM - System Checkpoint RP548: 4/23/2009 10:27:12 PM - System Checkpoint RP549: 4/25/2009 1:13:19 AM - System Checkpoint ==== Installed Programs ====================== Adobe Flash Player 10 ActiveX Adobe Reader 9.1 Adobe Shockwave Player Apple Mobile Device Support Apple Software Update AutoUpdate Beach Party Craze (remove only) Bonjour CA Yahoo! Anti-Spy (remove only) Cha-Ching! (remove only) Critical Update for Windows Media Player 11 (KB959772) DirectVobSub (remove only) DivX Codec DivX Converter DivX Player DivX Web Player Dropbox GEAR driver installer for x86 and x64 Google Toolbar for Internet Explorer High Definition Audio Driver Package - KB888111 HijackThis 2.0.2 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) iTunes Java™ 6 Update 13 Malwarebytes' Anti-Malware Marvell Miniport Driver Memeo AutoSync Microsoft .NET Framework 2.0 Service Pack 1 Microsoft Application Error Reporting Microsoft Compression Client Pack 1.0 for Windows XP Microsoft IntelliPoint 6.2 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable MioNet MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 6.0 Parser (KB933579) Nero 7 Essentials neroxml NGWave 4.0 Norton 360 NVIDIA Drivers QuickTime Realtek High Definition Audio Driver Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) TiVo Desktop 2.7 Trillian Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Ventrilo Client WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Live OneCare safety scanner Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 WinRAR archiver Yahoo! Install Manager Yahoo! Messenger Yahoo! Toolbar Yahoo! Widgets ==== Event Viewer Messages From Past Week ======== 4/18/2009 9:14:40 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. ==== End Of File ===========================
Hi again,


Open notepad and copy/paste the text in the quotebox below into it:

http://forums.whatthetech.com/Hijacked_Computer_t102155.html&pid=553033#entry553033

Collect::
c:\windows\system32\drivers\elcsjzo.sys


Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

[external image: Posted Image]

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe. You'll be asked to submit some samples. Please follow the instructions to do submitting successfully.
Then post the resultant log & a fresh dds.txt log. How's the system running?


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI