This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Browser Hijack

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

About half the time I try to click on to a Google link I get redirected to page with ads. I have to cut and paste bottom link into adress bar to get right results. When I try to use Yahoo search and click on link it opens new window with ad sight.

I have run Norton 360 and Nod 32 and neither found problem. I have also used Spybot and Spyware Terminator with no success. I'vve also uninstalled and reinstalled Firefox with no positive results either.

I have Vista Home and use current Firefox browser.

HijackThis Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:19:13 AM, on 5/18/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Lexmark 4900 Series\lxdrmon.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
C:\Program Files\Xmarks\IE Extension\xmarkssync.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Lexmark 4900 Series\lxdrMsdMon.exe
C:\Program Files\Registry Clean Expert\RCHelper.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\Explorer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.0.0.135\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Lexmark Printable Web - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O2 - BHO: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [lxdrmon.exe] "C:\Program Files\Lexmark 4900 Series\lxdrmon.exe"
O4 - HKLM\..\Run: [lxdramon] "C:\Program Files\Lexmark 4900 Series\lxdramon.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Xmarks] C:\Program Files\Xmarks\IE Extension\xmarkssync.exe -q
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [RegClean Expert Scheduler] "C:\Program Files\Registry Clean Expert\RCHelper.exe" /startup
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [uidenhiufgsduiazghs] C:\Windows\TEMP\n7gf3yuud.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [uidenhiufgsduiazghs] C:\Windows\TEMP\n7gf3yuud.exe (User 'Default user')
O4 - Startup: Anapod Manager.lnk = C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: lxdrCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdrserv.exe
O23 - Service: lxdr_device - - C:\Windows\system32\lxdrcoms.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 11691 bytes

********************************************************************************
*********************************************************************************
**********************
Malware Bytes Log:

Malwarebytes' Anti-Malware 1.36
Database version: 2147
Windows 6.0.6001 Service Pack 1

5/18/2009 8:17:28 AM
mbam-log-2009-05-18 (08-17-28).txt

Scan type: Quick Scan
Objects scanned: 73205
Time elapsed: 4 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

********************************************************************************
*********************************************************************************
**********************

Thanks in advance for any help.
Hi,

Please do the following:

Download Combofix from any of the links below, and save it to your desktop.

Link 1
Link 2
Link 3


**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Thanks for the fast reply. Following is the ComboFix information: ComboFix 09-05-17.08 - Computer 05/18/2009 11:17:36.1 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2814.1118 [GMT -7:00] Running from: C:\Users\[removed]\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} SP: ESET NOD32 Antivirus 3.0 *disabled* (Updated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Users\Computer\AppData\Roaming\inst.exe C:\Windows\system32\systeminfo3.dll . ((((((((((((((((((((((((( Files Created from 2009-04-18 to 2009-05-18 ))))))))))))))))))))))))))))))) . 2009-05-18 14:54:15 . 2009-05-18 14:54:25 0 d—–w C:\Program Files\ERUNT 2009-05-17 00:18:11 . 2009-05-17 00:18:12 0 d—–r C:\Program Files\Norton Support 2009-05-16 03:58:17 . 2009-05-16 03:58:17 0 d—–w C:\ProgramData\TVU Networks 2009-05-16 03:58:17 . 2009-05-16 03:58:17 0 d—–w C:\Users\All Users\TVU Networks 2009-05-16 03:58:17 . 2009-05-16 03:58:17 0 d—–w C:\Users\Computer\AppData\Local\TVU Networks 2009-05-16 03:58:00 . 2009-05-16 03:58:17 0 d—–w C:\Program Files\TVUPlayer 2009-05-15 17:43:47 . 2009-05-15 17:43:47 0 d—–w C:\Users\Computer\AppData\Roaming\iExpert Software 2009-05-15 17:43:00 . 2009-05-15 17:43:30 0 d—–w C:\Program Files\Registry Clean Expert 2009-05-14 09:54:27 . 2009-05-14 09:54:27 0 d—–w C:\Users\Computer\AppData\Local\Symantec 2009-05-13 21:56:08 . 2009-05-16 23:28:46 0 d—–w C:\Users\Computer\Tracing 2009-05-13 21:53:56 . 2009-05-13 21:53:56 0 d—–w C:\Program Files\Microsoft Sync Framework 2009-05-13 21:52:35 . 2006-11-29 20:06:18 3426072 —-a-w C:\Windows\system32\d3dx9_32.dll 2009-05-13 21:52:26 . 2009-05-13 21:52:26 0 d—–w C:\Program Files\Microsoft SQL Server Compact Edition 2009-05-13 21:50:52 . 2009-05-13 21:50:52 0 d—–w C:\Program Files\Microsoft 2009-05-13 21:50:30 . 2009-05-13 21:50:30 0 d—–w C:\Program Files\Windows Live SkyDrive 2009-05-13 21:49:39 . 2009-05-13 21:54:42 0 d—–w C:\Program Files\Windows Live 2009-05-13 21:41:27 . 2009-05-13 21:41:27 0 d—–w C:\Program Files\Common Files\Windows Live 2009-05-12 17:26:04 . 2007-12-25 00:37:00 138384 —-a-w C:\Windows\system32\drivers\tmcomm.sys 2009-05-12 17:24:26 . 2009-05-12 17:24:26 0 d—–w C:\Windows\Sun 2009-05-12 17:20:44 . 2009-05-12 17:20:44 0 d—–w C:\Program Files\Trend Micro 2009-05-12 16:17:21 . 2009-05-12 16:17:21 0 d—–w C:\Users\Computer\AppData\Roaming\Malwarebytes 2009-05-12 16:17:19 . 2009-04-06 22:32:46 15504 —-a-w C:\Windows\system32\drivers\mbam.sys 2009-05-12 16:17:15 . 2009-04-06 22:32:54 38496 —-a-w C:\Windows\system32\drivers\mbamswissarmy.sys 2009-05-12 16:17:13 . 2009-05-12 16:17:13 0 d—–w C:\ProgramData\Malwarebytes 2009-05-12 16:17:13 . 2009-05-12 16:17:13 0 d—–w C:\Users\All Users\Malwarebytes 2009-05-12 16:17:12 . 2009-05-12 16:17:21 0 d—–w C:\Program Files\Malwarebytes' Anti-Malware 2009-05-12 15:19:50 . 2009-05-12 15:20:09 0 d—–w C:\Program Files\Crawler 2009-05-12 15:19:31 . 2009-05-12 15:19:31 141312 —-a-w C:\Windows\system32\drivers\sp_rsdrv2.sys 2009-05-12 15:19:30 . 2009-05-13 16:24:52 0 d—–w C:\ProgramData\Spyware Terminator 2009-05-12 15:19:30 . 2009-05-13 16:24:52 0 d—–w C:\Users\All Users\Spyware Terminator 2009-05-12 15:19:30 . 2009-05-14 23:27:17 0 d—–w C:\Users\Computer\AppData\Roaming\Spyware Terminator 2009-05-12 15:19:26 . 2009-05-14 23:27:13 0 d—–w C:\Program Files\Spyware Terminator 2009-05-12 13:31:01 . 2009-05-12 13:31:01 0 d—–w C:\Program Files\Alwil Software 2009-05-11 15:53:17 . 2008-04-17 19:12:54 107368 —-a-w C:\Windows\system32\GEARAspi.dll 2009-05-11 15:53:17 . 2009-01-15 19:19:36 23848 —-a-w C:\Windows\system32\drivers\GEARAspiWDM.sys 2009-05-11 15:53:17 . 2009-05-11 15:53:17 0 dc—-w C:\Windows\system32\DRVSTORE 2009-05-11 15:53:16 . 2009-05-11 15:53:16 0 d—–w C:\ProgramData\{7B6BA59A-FB0E-4499-8536-A7420338BF3B} 2009-05-11 15:53:16 . 2009-05-11 15:53:16 0 d—–w C:\Users\All Users\{7B6BA59A-FB0E-4499-8536-A7420338BF3B} 2009-05-11 15:53:04 . 2009-05-11 15:52:48 25136 —-a-r C:\Windows\system32\drivers\SymIMV.sys 2009-05-11 15:52:59 . 2009-05-11 15:52:59 124464 —-a-w C:\Windows\system32\drivers\SYMEVENT.SYS 2009-05-11 15:52:59 . 2009-05-11 15:53:00 0 d—–w C:\Program Files\Symantec 2009-05-11 15:52:28 . 2009-05-11 15:52:28 0 d—–w C:\Windows\system32\drivers\N360 2009-05-11 15:52:26 . 2009-05-11 15:52:37 0 d—–w C:\Program Files\Norton 360 2009-05-11 15:52:16 . 2009-05-11 15:52:16 0 d—–w C:\Program Files\NortonInstaller 2009-05-11 14:44:19 . 2009-05-11 15:52:26 0 d—–w C:\ProgramData\Norton 2009-05-11 14:44:19 . 2009-05-11 15:52:26 0 d—–w C:\Users\All Users\Norton 2009-05-11 14:44:07 . 2009-05-11 15:52:20 0 d—–w C:\ProgramData\NortonInstaller 2009-05-11 14:44:07 . 2009-05-11 15:52:20 0 d—–w C:\Users\All Users\NortonInstaller 2009-05-10 15:41:18 . 2009-05-10 15:41:18 0 d-sh–w C:\found.000 2009-05-08 23:03:43 . 2009-05-08 23:11:25 0 d—a-w C:\ProgramData\TEMP 2009-05-08 23:03:43 . 2009-05-08 23:11:25 0 d—a-w C:\Users\All Users\TEMP 2009-05-08 23:03:35 . 2004-08-04 15:00:00 506368 —-a-w C:\Windows\system32\msxml.dll 2009-05-08 21:40:18 . 2009-05-08 21:40:18 0 d—–w C:\Windows\system32\config\systemprofile\AppData\Local\ESET 2009-05-08 17:10:58 . 2009-05-16 23:58:18 0 d—–w C:\ProgramData\Spybot - Search & Destroy 2009-05-08 17:10:58 . 2009-05-16 23:58:18 0 d—–w C:\Users\All Users\Spybot - Search & Destroy 2009-05-08 17:10:57 . 2009-05-16 23:59:37 0 d—–w C:\Program Files\Spybot - Search & Destroy 2009-05-08 15:18:13 . 2009-05-08 15:18:13 0 d—–w C:\Program Files\ESET 2009-05-08 01:30:11 . 2009-05-08 01:30:11 0 d—–w C:\Users\Computer\AppData\Local\ESET 2009-05-08 00:03:34 . 2009-05-08 00:03:34 0 d—–w C:\ProgramData\ESET 2009-05-08 00:03:34 . 2009-05-08 00:03:34 0 d—–w C:\Users\All Users\ESET 2009-05-07 20:46:20 . 2008-04-23 16:34:21 360448 —-a-w C:\Windows\system32\lxdrcoin.dll 2009-05-07 20:44:44 . 2008-05-16 15:12:03 40960 —-a-w C:\Windows\system32\lxdrvs.dll 2009-05-07 20:43:41 . 2008-05-09 16:32:38 81920 —-a-w C:\Windows\system32\lxdrcaps.dll 2009-05-07 20:43:41 . 2008-05-09 16:22:41 69632 —-a-w C:\Windows\system32\lxdrcnv4.dll 2009-05-07 20:43:41 . 2008-05-09 16:32:34 1036288 —-a-w C:\Windows\system32\lxdrdrs.dll 2009-05-07 20:39:56 . 2009-05-07 20:39:56 0 d—–w C:\Program Files\Lexmark Printable Web 2009-05-07 20:39:48 . 2008-05-16 15:39:00 17064 —-a-w C:\Windows\system32\LXDRwupd.exe 2009-05-07 20:39:48 . 2008-04-15 11:08:49 352256 —-a-w C:\Windows\system32\LXDRwupd.dll 2009-05-07 20:36:33 . 2009-05-07 21:55:03 0 d—–w C:\Program Files\Lexmark 4900 Series 2009-05-07 18:03:52 . 2008-06-20 01:14:34 97800 —-a-w C:\Windows\system32\infocardapi.dll 2009-05-07 18:03:51 . 2008-06-20 01:14:45 105016 —-a-w C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2009-05-07 18:03:51 . 2008-06-20 01:14:33 622080 —-a-w C:\Windows\system32\icardagt.exe 2009-05-07 18:03:51 . 2008-06-20 01:14:34 11264 —-a-w C:\Windows\system32\icardres.dll 2009-05-07 18:03:51 . 2008-06-20 01:14:45 43544 —-a-w C:\Windows\system32\PresentationHostProxy.dll 2009-05-07 18:03:48 . 2008-06-20 01:14:45 781344 —-a-w C:\Windows\system32\PresentationNative_v0300.dll 2009-05-07 18:03:46 . 2008-06-20 01:14:45 326160 —-a-w C:\Windows\system32\PresentationHost.exe 2009-05-07 17:55:30 . 2008-07-27 18:03:16 96760 —-a-w C:\Windows\system32\dfshim.dll 2009-05-07 17:55:27 . 2008-07-27 18:03:17 282112 —-a-w C:\Windows\system32\mscoree.dll 2009-05-07 17:55:27 . 2008-07-27 18:03:17 41984 —-a-w C:\Windows\system32\netfxperf.dll 2009-05-07 17:55:17 . 2008-07-27 18:03:17 158720 —-a-w C:\Windows\system32\mscorier.dll 2009-05-07 17:55:14 . 2008-07-27 18:03:17 83968 —-a-w C:\Windows\system32\mscories.dll 2009-05-07 17:05:22 . 2009-05-11 14:07:36 0 d—–w C:\Program Files\Loaris Trojan Remover 2009-05-07 16:50:08 . 2009-05-07 21:54:59 0 d—–w C:\Program Files\GridinSoft Trojan Killer 2009-05-07 16:34:37 . 2009-05-12 14:53:19 0 d-sh–w C:\Users\Computer\AppData\Roaming\lowsec 2009-05-07 16:32:52 . 2009-05-07 16:38:01 0 d—–w C:\ProgramData\13935234 2009-05-07 16:32:52 . 2009-05-07 16:38:01 0 d—–w C:\Users\All Users\13935234 2009-05-07 12:46:40 . 2009-05-07 12:46:43 66048 —-a-w C:\Windows\system32\lds.exe 2009-05-05 17:36:20 . 2008-09-10 09:36:13 32768 —-a-w C:\Windows\system32\LXF3FXPU.DLL 2009-05-05 17:36:20 . 2008-04-01 01:59:03 45056 —-a-w C:\Windows\system32\LXF3PMON.DLL 2009-05-05 17:35:48 . 2009-05-07 22:13:07 0 d—–w C:\Program Files\Lexmark Fax Solutions 2009-05-05 17:35:36 . 2009-05-07 20:42:32 0 d—–w C:\Program Files\Lexmark Tools for Office 2009-05-05 17:33:23 . 2009-05-07 20:42:28 0 d—–w C:\Program Files\Lexmark Toolbar 2009-05-05 17:22:41 . 2009-05-07 21:10:49 0 d—–w C:\Users\Computer\AppData\Roaming\Lexmark Productivity Studio 2009-05-05 17:11:47 . 2009-05-05 17:11:51 0 d—–w C:\Users\Computer\AppData\Roaming\GTek 2009-05-05 17:05:44 . 2009-05-05 17:05:53 0 d—–w C:\Users\Computer\AppData\Local\MigWiz 2009-05-04 22:15:35 . 2009-05-04 22:15:35 0 d—–w C:\Users\Computer\AppData\Roaming\TrojanHunter 2009-05-04 22:13:58 . 2009-05-05 17:26:19 0 d—–w C:\Program Files\TrojanHunter 4.7 2009-05-04 17:21:56 . 2009-05-04 17:35:51 0 d—–w C:\Users\Computer\AppData\Local\Nero 2009-05-04 17:15:17 . 2009-05-04 17:16:11 0 d—–w C:\Users\Computer\AppData\Roaming\Nero 2009-05-04 16:47:37 . 2009-05-04 17:32:31 0 d—–w C:\Program Files\Nero 2009-05-04 16:47:11 . 2009-05-04 17:48:18 0 d—–w C:\ProgramData\Nero 2009-05-04 16:47:11 . 2009-05-04 17:48:18 0 d—–w C:\Users\All Users\Nero 2009-05-04 16:47:11 . 2009-05-04 17:32:40 0 d—–w C:\Program Files\Common Files\Nero 2009-05-04 16:19:38 . 2009-05-04 16:19:38 0 d—–w C:\Program Files\Aimersoft 2009-05-04 02:21:52 . 2009-05-04 02:24:56 0 d—–w C:\Users\Computer\AppData\Roaming\Kelpiesoft Food File 2009-05-04 02:21:41 . 2009-05-04 02:21:44 0 d—–w C:\Program Files\Food File 2009-05-04 00:28:36 . 2009-05-04 00:28:37 0 d—–w C:\Program Files\AVI MPEG RM WMV Joiner 2009-05-03 23:35:43 . 2009-05-03 23:35:43 0 d—–w C:\Windows\system32\config\systemprofile\AppData\Roaming\Yahoo! 2009-05-03 23:25:33 . 2009-05-03 23:35:31 0 d—–w C:\Windows\system32\config\systemprofile\AppData\Roaming\GrabPro 2009-05-03 04:13:02 . 2009-05-03 04:13:17 0 d—–w C:\Users\Computer\AppData\Roaming\FairStars Audio Converter 2009-05-03 04:11:25 . 2009-05-05 17:26:04 0 d—–w C:\Program Files\FairStars Audio Converter 2009-05-03 04:04:48 . 2009-05-03 04:04:48 0 d—–w C:\ProgramData\AVS4YOU 2009-05-03 04:04:48 . 2009-05-03 04:04:48 0 d—–w C:\Users\All Users\AVS4YOU 2009-05-03 04:04:47 . 2009-05-03 04:04:47 0 d—–w C:\Users\Computer\AppData\Roaming\AVS4YOU 2009-05-03 04:04:17 . 2003-05-21 19:50:38 24576 —-a-w C:\Windows\system32\msxml3a.dll 2009-05-02 21:47:39 . 2009-05-02 21:47:39 0 d—–w C:\Program Files\Common Files\EZB Systems 2009-05-02 21:47:39 . 2009-05-05 17:26:19 0 d—–w C:\Program Files\UltraISO 2009-05-02 21:14:40 . 2009-05-02 21:14:40 0 d—–w C:\Users\Public\CyberLink 2009-05-01 17:17:00 . 2009-05-01 17:17:00 0 d—–w C:\ProgramData\Azureus 2009-05-01 17:17:00 . 2009-05-01 17:17:00 0 d—–w C:\Users\All Users\Azureus 2009-05-01 17:16:58 . 2009-05-17 13:00:47 0 d—–w C:\Users\Computer\AppData\Roaming\Azureus 2009-05-01 17:16:18 . 2009-05-01 17:16:39 0 d—–w C:\Program Files\Vuze 2009-05-01 05:56:02 . 2009-05-01 05:56:02 0 d—–w C:\Users\Computer\AppData\Local\HP 2009-05-01 04:00:11 . 2009-05-01 04:00:11 0 d—–w C:\Program Files\Common Files\xing shared 2009-05-01 04:00:03 . 2009-05-01 04:00:03 0 d—–w C:\Program Files\Real . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-18 14:02:55 . 2008-09-30 18:32:42 162164 —-a-w C:\Users\All Users\nvModes.dat 2009-05-18 14:02:55 . 2008-09-30 18:32:42 162164 —-a-w C:\ProgramData\nvModes.dat 2009-05-13 21:33:47 . 2006-11-02 11:18:33 0 d—–w C:\Program Files\Windows Mail 2009-05-11 16:13:24 . 2008-05-21 10:28:11 0 d—–w C:\Program Files\Common Files\Symantec Shared 2009-05-11 15:52:59 . 2009-05-11 15:52:59 805 —-a-w C:\Windows\system32\drivers\SYMEVENT.INF 2009-05-11 15:52:59 . 2009-05-11 15:52:59 7386 —-a-w C:\Windows\system32\drivers\SYMEVENT.CAT 2009-05-11 04:07:50 . 2008-05-21 12:01:04 0 d—–w C:\Program Files\Common Files\Adobe 2009-05-09 18:37:11 . 2001-01-01 06:12:59 1356 —-a-w C:\Users\Computer\AppData\Local\d3d9caps.dat 2009-05-09 18:36:05 . 2009-04-28 23:45:20 484352 –sha-w C:\Windows\system32\drivers\fidbox.idx 2009-05-05 18:06:37 . 2009-05-05 18:06:37 5889522 —-a-w C:\Users\All Users\SPLC087.tmp 2009-05-05 18:06:37 . 2009-05-05 18:06:37 5889522 —-a-w C:\ProgramData\SPLC087.tmp 2009-05-05 17:26:21 . 2006-11-02 12:37:34 0 d—–w C:\Program Files\Windows Sidebar 2009-05-01 00:32:32 . 2009-05-01 00:32:32 2101561 —-a-w C:\Users\All Users\SPL20FA.tmp 2009-05-01 00:32:32 . 2009-05-01 00:32:32 2101561 —-a-w C:\ProgramData\SPL20FA.tmp 2009-05-01 00:31:12 . 2009-05-01 00:31:12 2101561 —-a-w C:\Users\All Users\SPLE812.tmp 2009-05-01 00:31:12 . 2009-05-01 00:31:12 2101561 —-a-w C:\ProgramData\SPLE812.tmp 2009-04-29 02:59:18 . 2006-11-02 12:37:34 0 d—–w C:\Program Files\MSBuild 2009-03-26 15:00:02 . 2009-03-26 15:00:02 64000 —-a-w C:\Windows\system32\drivers\RTSTOR.sys 2009-03-17 03:38:46 . 2009-04-29 02:59:32 13824 —-a-w C:\Windows\system32\apilogen.dll 2009-03-17 03:38:44 . 2009-04-29 02:59:32 24064 —-a-w C:\Windows\system32\amxread.dll 2009-03-08 11:34:57 . 2007-09-05 12:15:21 914944 —-a-w C:\Windows\system32\wininet.dll 2009-03-08 11:34:28 . 2007-09-05 12:15:25 43008 —-a-w C:\Windows\system32\licmgr10.dll 2009-03-08 11:33:38 . 2007-09-05 12:15:27 18944 —-a-w C:\Windows\system32\corpol.dll 2009-03-08 11:33:17 . 2007-09-05 12:15:22 109056 —-a-w C:\Windows\system32\iesysprep.dll 2009-03-08 11:33:16 . 2007-09-05 12:15:22 109568 —-a-w C:\Windows\system32\PDMSetup.exe 2009-03-08 11:33:15 . 2007-09-05 12:15:22 132608 —-a-w C:\Windows\system32\ieUnatt.exe 2009-03-08 11:33:15 . 2007-09-05 12:15:22 107520 —-a-w C:\Windows\system32\RegisterIEPKEYs.exe 2009-03-08 11:33:15 . 2007-09-05 12:15:22 107008 —-a-w C:\Windows\system32\SetIEInstalledDate.exe 2009-03-08 11:33:15 . 2007-09-05 12:15:22 103936 —-a-w C:\Windows\system32\SetDepNx.exe 2009-03-08 11:33:04 . 2007-09-05 12:15:23 420352 —-a-w C:\Windows\system32\vbscript.dll 2009-03-08 11:32:54 . 2007-09-05 12:15:27 72704 —-a-w C:\Windows\system32\admparse.dll 2009-03-08 11:32:49 . 2007-09-05 12:15:25 71680 —-a-w C:\Windows\system32\iesetup.dll 2009-03-08 11:32:38 . 2007-09-05 12:15:25 66560 —-a-w C:\Windows\system32\wextract.exe 2009-03-08 11:32:32 . 2007-09-05 12:15:22 169472 —-a-w C:\Windows\system32\iexpress.exe 2009-03-08 11:31:37 . 2007-09-05 12:15:26 34816 —-a-w C:\Windows\system32\imgutil.dll 2009-03-08 11:31:17 . 2007-09-05 12:15:27 48128 —-a-w C:\Windows\system32\mshtmler.dll 2009-03-08 11:31:00 . 2007-09-05 12:15:22 45568 —-a-w C:\Windows\system32\mshta.exe 2009-03-08 11:22:37 . 2007-09-05 12:15:27 156160 —-a-w C:\Windows\system32\msls31.dll 2009-03-03 04:46:01 . 2009-04-29 02:59:57 3547632 —-a-w C:\Windows\system32\ntoskrnl.exe 2009-03-03 04:46:01 . 2009-04-29 02:59:56 3599328 —-a-w C:\Windows\system32\ntkrnlpa.exe 2009-03-03 04:39:36 . 2009-04-29 02:59:50 183296 —-a-w C:\Windows\system32\sdohlp.dll 2009-03-03 04:39:32 . 2009-04-29 02:59:57 551424 —-a-w C:\Windows\system32\rpcss.dll 2009-03-03 04:39:22 . 2009-04-29 02:59:50 26112 —-a-w C:\Windows\system32\printfilterpipelineprxy.dll 2009-03-03 04:37:11 . 2009-04-29 02:59:50 98304 —-a-w C:\Windows\system32\iasrecst.dll 2009-03-03 04:37:11 . 2009-04-29 02:59:50 54784 —-a-w C:\Windows\system32\iasads.dll 2009-03-03 04:37:11 . 2009-04-29 02:59:50 44032 —-a-w C:\Windows\system32\iasdatastore.dll 2009-03-03 03:04:59 . 2009-04-29 02:59:52 666624 —-a-w C:\Windows\system32\printfilterpipelinesvc.exe 2009-03-03 02:38:13 . 2009-04-29 02:59:50 17408 —-a-w C:\Windows\system32\iashost.exe 2008-01-21 02:43:21 . 2006-11-02 12:50:50 174 –sha-w C:\Program Files\desktop.ini . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "C:\Program Files\BS_Player\tbBS_P.dll" [2009-03-10 18:47:48 2079256] [HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}] 2009-03-10 18:47:48 2079256 —-a-w C:\Program Files\BS_Player\tbBS_P.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "C:\Program Files\BS_Player\tbBS_P.dll" [2009-03-10 18:47:48 2079256] [HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "C:\Program Files\BS_Player\tbBS_P.dll" [2009-03-10 18:47:48 2079256] [HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-21 02:23:29 1233920] "Xmarks"="C:\Program Files\Xmarks\IE Extension\xmarkssync.exe" [2009-04-22 00:16:36 999424] "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-21 02:25:11 125952] "RegClean Expert Scheduler"="C:\Program Files\Registry Clean Expert\RCHelper.exe" [2009-05-12 13:52:40 601848] "WindowsWelcomeCenter"="oobefldr.dll" - C:\WINDOWS\System32\oobefldr.dll [2008-01-21 02:23:39 2153472] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 18:05:10 1049896] "QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2008-04-02 02:31:28 468264] "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-05-03 12:39:00 13535776] "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-05-03 12:39:00 92704] "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 18:44:34 31072] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2009-05-01 04:00:01 198160] "FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2008-09-10 10:24:14 320168] "lxdrmon.exe"="C:\Program Files\Lexmark 4900 Series\lxdrmon.exe" [2008-09-10 10:24:21 676520] "lxdramon"="C:\Program Files\Lexmark 4900 Series\lxdramon.exe" [2008-09-10 10:24:19 16040] "egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-07-01 16:01:04 1447168] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 08:04:34 39792] "SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-05-12 15:19:30 1817600] C:\Users\Computer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Anapod Manager.lnk - C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe [2008-6-7 1076276] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys] @="FSFilter Activity Monitor" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{0FA8513C-B35D-4763-AF6A-854A922287CA}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play "{523FA3FA-14B4-4DC3-97D9-A5FF46106D1C}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program "{C3FCA21C-4D34-4616-A6EE-5A8B377D2BD3}"= C:\Program Files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector "TCP Query User{5CB33E97-7F0A-4ADD-AC54-A3F2947A5345}C:\\program files\\orbitdownloader\\orbitnet.exe"= UDP:C:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader "UDP Query User{6A1479C4-B6DC-4C50-84B5-BEEBE055BDFB}C:\\program files\\orbitdownloader\\orbitnet.exe"= TCP:C:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader "TCP Query User{AB5C7E05-5CF4-4E5A-B526-D9635FFE5B04}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer "UDP Query User{B17A0F72-57A0-4372-BECD-078B9B937555}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer "TCP Query User{D74485B2-E05E-4F1D-A1D5-EA60A47079C0}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox "UDP Query User{4CE655E6-B39C-4CEB-879D-C5E88B361098}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox "{7532B700-69CC-4B07-A20C-B7D1A3309422}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{19BF8AB7-9252-4028-B80C-A38751DC58A4}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{3CD35A15-E81B-443E-BA3E-9593B5E340D7}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{39D5BCE6-BF43-4783-95C9-2B1B125B3E6B}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{4579BFCD-2369-4FEE-8A3C-76AB3413489B}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "TCP Query User{4ADC50F6-6F6F-4049-8738-9F867601C46E}C:\\program files\\tvants\\tvants.exe"= UDP:C:\program files\tvants\tvants.exe:TVAnts "UDP Query User{3E61E1F9-DBFA-4D20-810E-8A7EA7722341}C:\\program files\\tvants\\tvants.exe"= TCP:C:\program files\tvants\tvants.exe:TVAnts "TCP Query User{BA8FD897-714A-4321-B216-077D9F4569BB}C:\\program files\\vuze\\azureus.exe"= UDP:C:\program files\vuze\azureus.exe:Azureus "UDP Query User{ED0E7A0A-280A-4E9C-B6D4-A77768A6009E}C:\\program files\\vuze\\azureus.exe"= TCP:C:\program files\vuze\azureus.exe:Azureus "{1B4C021C-8C0A-4BB4-B395-CFB3606A2321}"= UDP:C:\Program Files\Lexmark 3600-4600 Series\lxdxamon.exe:Lexmark Device Monitor "{F294B7C1-57F0-44D3-9925-A6BA8EABE174}"= TCP:C:\Program Files\Lexmark 3600-4600 Series\lxdxamon.exe:Lexmark Device Monitor "{32C2EFBC-0055-4BD0-83E1-A002BFA22AE1}"= UDP:C:\Program Files\Lexmark 3600-4600 Series\frun.exe:Lexmark Productivity Studio "{75B86A3C-2363-4DFD-B42C-F676A7E562B0}"= TCP:C:\Program Files\Lexmark 3600-4600 Series\frun.exe:Lexmark Productivity Studio "TCP Query User{B2542884-10AE-4A0B-886A-96C4CBEBB1F2}C:\\windows\\explorer.exe"= UDP:C:\windows\explorer.exe:Windows Explorer "UDP Query User{E168A851-DA0D-4AF5-8B26-F0FB9BB97031}C:\\windows\\explorer.exe"= TCP:C:\windows\explorer.exe:Windows Explorer "{24B851A4-7D32-4BC5-8C27-AF7FA7D967DF}"= UDP:C:\WINDOWS\System32\lxdrcoms.exe:Lexmark Communications System "{FECCCAF1-8041-4043-95E2-92A94E49F4C5}"= TCP:C:\WINDOWS\System32\lxdrcoms.exe:Lexmark Communications System "{B9DAC796-9920-4858-B9F0-0ED9A2DD753B}"= UDP:C:\Program Files\Lexmark 4900 Series\lxdramon.exe:Lexmark Device Monitor "{F56BC95C-E50F-4822-98A9-9FED8E7F7A58}"= TCP:C:\Program Files\Lexmark 4900 Series\lxdramon.exe:Lexmark Device Monitor "{2AA7AA2F-74E2-4516-9CCD-A115456B186B}"= UDP:C:\Program Files\Lexmark 4900 Series\frun.exe:Lexmark Productivity Studio "{DDD709D8-CED0-470D-8745-BFB819ED16CA}"= TCP:C:\Program Files\Lexmark 4900 Series\frun.exe:Lexmark Productivity Studio "{315BA571-D90F-47F3-B9AD-C2400872C332}"= UDP:C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader "{174ED0C9-ED69-4E91-ADB2-9640ACEF19CE}"= TCP:C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader "{0B7B4B34-C86B-4AF3-B5A6-FA46A07034FE}"= UDP:C:\Program Files\Lexmark Fax Solutions\FaxCtr.exe:Fax software "{BCCCFB60-D4EF-4D6A-B0EA-BB925FFE848C}"= TCP:C:\Program Files\Lexmark Fax Solutions\FaxCtr.exe:Fax software "{2D579BFF-A8E7-4A01-AC63-350F166142BF}"= Disabled:UDP:C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe:Anapod Xtreamer "{2468CA57-10B9-45EC-BE16-4B0FD0914C11}"= Disabled:TCP:C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe:Anapod Xtreamer "{B0941A98-684F-40D3-B156-FBE3D8E76CFC}"= C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List] "C:\\Program Files\\Orbitdownloader\\orbitdm.exe"= C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit "C:\\Program Files\\Orbitdownloader\\orbitnet.exe"= C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit R0 SymEFA;Symantec Extended File Attributes;C:\WINDOWS\System32\drivers\N360\0300000.087\SymEFA.sys [5/11/2009 8:52:48 AM 310320] R1 BHDrvx86;Symantec Heuristics Driver;C:\WINDOWS\System32\drivers\N360\0300000.087\BHDrvx86.sys [5/11/2009 8:52:48 AM 258608] R1 ccHP;Symantec Hash Provider;C:\WINDOWS\System32\drivers\N360\0300000.087\cchpx86.sys [5/11/2009 8:52:48 AM 482352] R1 epfwtdir;epfwtdir;C:\WINDOWS\System32\drivers\epfwtdir.sys [7/1/2008 9:04:40 AM 34312] R1 IDSVix86;IDSVix86;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090508.002\IDSvix86.sys [5/11/2009 8:59:07 AM 292912] R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\System32\drivers\sp_rsdrv2.sys [5/12/2009 8:19:31 AM 141312] R2 ekrn;Eset Service;C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [7/1/2008 9:02:28 AM 468224] R2 lxdr_device;lxdr_device;C:\Windows\system32\lxdrcoms.exe -service –> C:\Windows\system32\lxdrcoms.exe -service [?] R2 lxdrCATSCustConnectService;lxdrCATSCustConnectService;C:\WINDOWS\System32\spool\drivers\w32x86\3\lxdrserv.exe [5/16/2008 8:39:03 AM 98984] R2 N360;Norton 360;C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe [5/11/2009 8:52:46 AM 115560] R2 Recovery Service for Windows;Recovery Service for Windows;C:\WINDOWS\SMINST\BLService.exe [5/21/2008 5:20:37 AM 361808] R2 SeaPort;SeaPort;C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [1/14/2009 5:53:02 PM 226656] R2 YahooAUService;Yahoo! Updater;C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe [11/9/2008 1:48:14 PM 602392] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/11/2009 8:52:48 AM 101936] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\WINDOWS\System32\drivers\nvhda32v.sys [5/3/2008 5:39:00 AM 42528] R3 SYMNDISV;Symantec Network Filter Driver;C:\WINDOWS\System32\drivers\N360\0300000.087\symndisv.sys [5/11/2009 8:52:48 AM 39984] S3 Com4QLBEx;Com4QLBEx;C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [5/21/2008 3:56:25 AM 193840] S3 DsAudioDevice_310;DsAudioDevice_310;C:\WINDOWS\System32\drivers\DsAudioDevice_310.sys [4/29/2009 9:52:20 AM 16640] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] C:\Windows\system32\rundll32.exe C:\Windows\system32\advpack.dll,LaunchINFSectionEx C:\Program Files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12 . Contents of the 'Scheduled Tasks' folder 2009-05-18 C:\Windows\Tasks\NeroLiveEpgUpdate-Computer-PC_Computer.job - C:\Program Files\Nero\Nero 9\Nero Live\NeroLive.exe [2008-09-18 20:51:06 . 2008-09-18 20:51:06] . - - - - ORPHANS REMOVED - - - - HKU-Default-Run-uidenhiufgsduiazghs - C:\Windows\TEMP\n7gf3yuud.exe HKU-Default-Run-Diagnostic Manager - C:\Windows\TEMP\1438558680.exe . ——- Supplementary Scan ——- . uStart Page = hxxp://www.aol.com/ IE: &Download; by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/201 IE: &Grab; video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/204 IE: Crawler Search - tbr:iemenu IE: Do&wnload; selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/203 IE: Down&load; all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/202 IE: E&xport; to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll FF - ProfilePath - C:\Users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\wp0x49j0.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;= FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;= FF - component: C:\Program Files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll FF - component: C:\Users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\wp0x49j0.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll FF - plugin: C:\Program Files\Veetle\Player\npvlc.dll FF - plugin: C:\Program Files\Veetle\plugins\npVeetle.dll FF - plugin: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\wp0x49j0.default\extensions\[removed]\plugins\npTVUAx.dll . Thanks agaon.
Hi,

I notice you have ESET as well as Norton 360. Running two antivirus programs can cause system instability and slowdowns, ultimately providing less protection not more, so I recommend uninstalling one of them.

NEXT

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
C:\Users\All Users\SPLC087.tmp
C:\ProgramData\SPLC087.tmp
C:\Users\All Users\SPL20FA.tmp
C:\ProgramData\SPL20FA.tmp
C:\Users\All Users\SPLE812.tmp
C:\ProgramData\SPLE812.tmp

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

NEXT

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Double-click GooredFix.exe to run it.
  • Select 1. Find Goored (no fix) by typing 1 and pressing Enter.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).Note: Do not run GooredFix option #2 yet


NEXT

Run an on-line scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.


  • Open the Kaspersky WebScanner
    page.
  • Click on the 🖼Click to load external image (Posted Image) button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the 🖼Click to load external image (Posted Image) button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the 🖼Click to load external image (Posted Image) …button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the 🖼Click to load external image (Posted Image) button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis.
Thanks for the advice on the anti-virus issue. What would your preference to keep be; Norton 360 or ESET Nob32? Following are the three logs you requested:

Combofix:


ComboFix 09-05-18.01 - Computer 05/18/2009 13:44.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2814.1321 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Computer\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
SP: ESET NOD32 Antivirus 3.0 *disabled* (Updated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
c:\programdata\SPL20FA.tmp
c:\programdata\SPLC087.tmp
c:\programdata\SPLE812.tmp
c:\users\All Users\SPL20FA.tmp
c:\users\All Users\SPLC087.tmp
c:\users\All Users\SPLE812.tmp
.

((((((((((((((((((((((((( Files Created from 2009-04-18 to 2009-05-18 )))))))))))))))))))))))))))))))
.

2009-05-18 14:54 . 2009-05-18 14:54 ——– d—–w c:\program files\ERUNT
2009-05-17 00:18 . 2009-05-17 00:18 ——– d—–r c:\program files\Norton Support
2009-05-16 03:58 . 2009-05-16 03:58 ——– d—–w c:\programdata\TVU Networks
2009-05-16 03:58 . 2009-05-16 03:58 ——– d—–w c:\users\All Users\TVU Networks
2009-05-16 03:58 . 2009-05-16 03:58 ——– d—–w c:\users\Computer\AppData\Local\TVU Networks
2009-05-16 03:58 . 2009-05-16 03:58 ——– d—–w c:\program files\TVUPlayer
2009-05-15 17:43 . 2009-05-15 17:43 ——– d—–w c:\users\Computer\AppData\Roaming\iExpert Software
2009-05-15 17:43 . 2009-05-15 17:43 ——– d—–w c:\program files\Registry Clean Expert
2009-05-14 09:54 . 2009-05-14 09:54 ——– d—–w c:\users\Computer\AppData\Local\Symantec
2009-05-13 21:56 . 2009-05-16 23:28 ——– d—–w c:\users\Computer\Tracing
2009-05-13 21:53 . 2009-05-13 21:53 ——– d—–w c:\program files\Microsoft Sync Framework
2009-05-13 21:52 . 2006-11-29 20:06 3426072 —-a-w c:\windows\system32\d3dx9_32.dll
2009-05-13 21:52 . 2009-05-13 21:52 ——– d—–w c:\program files\Microsoft SQL Server Compact Edition
2009-05-13 21:50 . 2009-05-13 21:50 ——– d—–w c:\program files\Microsoft
2009-05-13 21:50 . 2009-05-13 21:50 ——– d—–w c:\program files\Windows Live SkyDrive
2009-05-13 21:49 . 2009-05-13 21:54 ——– d—–w c:\program files\Windows Live
2009-05-13 21:41 . 2009-05-13 21:41 ——– d—–w c:\program files\Common Files\Windows Live
2009-05-12 17:26 . 2007-12-25 00:37 138384 —-a-w c:\windows\system32\drivers\tmcomm.sys
2009-05-12 17:24 . 2009-05-12 17:24 ——– d—–w c:\windows\Sun
2009-05-12 17:20 . 2009-05-12 17:20 ——– d—–w c:\program files\Trend Micro
2009-05-12 16:17 . 2009-05-12 16:17 ——– d—–w c:\users\Computer\AppData\Roaming\Malwarebytes
2009-05-12 16:17 . 2009-04-06 22:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-12 16:17 . 2009-04-06 22:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-12 16:17 . 2009-05-12 16:17 ——– d—–w c:\programdata\Malwarebytes
2009-05-12 16:17 . 2009-05-12 16:17 ——– d—–w c:\users\All Users\Malwarebytes
2009-05-12 16:17 . 2009-05-12 16:17 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-12 15:19 . 2009-05-12 15:20 ——– d—–w c:\program files\Crawler
2009-05-12 15:19 . 2009-05-12 15:19 141312 —-a-w c:\windows\system32\drivers\sp_rsdrv2.sys
2009-05-12 15:19 . 2009-05-13 16:24 ——– d—–w c:\programdata\Spyware Terminator
2009-05-12 15:19 . 2009-05-13 16:24 ——– d—–w c:\users\All Users\Spyware Terminator
2009-05-12 15:19 . 2009-05-14 23:27 ——– d—–w c:\users\Computer\AppData\Roaming\Spyware Terminator
2009-05-12 15:19 . 2009-05-14 23:27 ——– d—–w c:\program files\Spyware Terminator
2009-05-12 13:31 . 2009-05-12 13:31 ——– d—–w c:\program files\Alwil Software
2009-05-11 15:53 . 2008-04-17 19:12 107368 —-a-w c:\windows\system32\GEARAspi.dll
2009-05-11 15:53 . 2009-01-15 19:19 23848 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-11 15:53 . 2009-05-11 15:53 ——– dc—-w c:\windows\system32\DRVSTORE
2009-05-11 15:53 . 2009-05-11 15:53 ——– d—–w c:\programdata\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-05-11 15:53 . 2009-05-11 15:53 ——– d—–w c:\users\All Users\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-05-11 15:53 . 2009-05-11 15:52 25136 —-a-r c:\windows\system32\drivers\SymIMV.sys
2009-05-11 15:52 . 2009-05-11 15:52 124464 —-a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-05-11 15:52 . 2009-05-11 15:53 ——– d—–w c:\program files\Symantec
2009-05-11 15:52 . 2009-05-11 15:52 ——– d—–w c:\windows\system32\drivers\N360
2009-05-11 15:52 . 2009-05-11 15:52 ——– d—–w c:\program files\Norton 360
2009-05-11 15:52 . 2009-05-11 15:52 ——– d—–w c:\program files\NortonInstaller
2009-05-11 14:44 . 2009-05-11 15:52 ——– d—–w c:\programdata\Norton
2009-05-11 14:44 . 2009-05-11 15:52 ——– d—–w c:\users\All Users\Norton
2009-05-11 14:44 . 2009-05-11 15:52 ——– d—–w c:\programdata\NortonInstaller
2009-05-11 14:44 . 2009-05-11 15:52 ——– d—–w c:\users\All Users\NortonInstaller
2009-05-10 15:41 . 2009-05-10 15:41 ——– d-sh–w C:\found.000
2009-05-08 23:03 . 2009-05-08 23:11 ——– d—a-w c:\programdata\TEMP
2009-05-08 23:03 . 2009-05-08 23:11 ——– d—a-w c:\users\All Users\TEMP
2009-05-08 23:03 . 2004-08-04 15:00 506368 —-a-w c:\windows\system32\msxml.dll
2009-05-08 21:40 . 2009-05-08 21:40 ——– d—–w c:\windows\system32\config\systemprofile\AppData\Local\ESET
2009-05-08 17:10 . 2009-05-16 23:58 ——– d—–w c:\programdata\Spybot - Search & Destroy
2009-05-08 17:10 . 2009-05-16 23:58 ——– d—–w c:\users\All Users\Spybot - Search & Destroy
2009-05-08 17:10 . 2009-05-16 23:59 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-05-08 15:18 . 2009-05-08 15:18 ——– d—–w c:\program files\ESET
2009-05-08 01:30 . 2009-05-08 01:30 ——– d—–w c:\users\Computer\AppData\Local\ESET
2009-05-08 00:03 . 2009-05-08 00:03 ——– d—–w c:\programdata\ESET
2009-05-08 00:03 . 2009-05-08 00:03 ——– d—–w c:\users\All Users\ESET
2009-05-07 20:46 . 2008-04-23 16:34 360448 —-a-w c:\windows\system32\lxdrcoin.dll
2009-05-07 20:44 . 2008-05-16 15:12 40960 —-a-w c:\windows\system32\lxdrvs.dll
2009-05-07 20:43 . 2008-05-09 16:32 81920 —-a-w c:\windows\system32\lxdrcaps.dll
2009-05-07 20:43 . 2008-05-09 16:22 69632 —-a-w c:\windows\system32\lxdrcnv4.dll
2009-05-07 20:43 . 2008-05-09 16:32 1036288 —-a-w c:\windows\system32\lxdrdrs.dll
2009-05-07 20:39 . 2009-05-07 20:39 ——– d—–w c:\program files\Lexmark Printable Web
2009-05-07 20:39 . 2008-05-16 15:39 17064 —-a-w c:\windows\system32\LXDRwupd.exe
2009-05-07 20:39 . 2008-04-15 11:08 352256 —-a-w c:\windows\system32\LXDRwupd.dll
2009-05-07 20:36 . 2009-05-07 21:55 ——– d—–w c:\program files\Lexmark 4900 Series
2009-05-07 18:03 . 2008-06-20 01:14 97800 —-a-w c:\windows\system32\infocardapi.dll
2009-05-07 18:03 . 2008-06-20 01:14 105016 —-a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-05-07 18:03 . 2008-06-20 01:14 622080 —-a-w c:\windows\system32\icardagt.exe
2009-05-07 18:03 . 2008-06-20 01:14 11264 —-a-w c:\windows\system32\icardres.dll
2009-05-07 18:03 . 2008-06-20 01:14 43544 —-a-w c:\windows\system32\PresentationHostProxy.dll
2009-05-07 18:03 . 2008-06-20 01:14 781344 —-a-w c:\windows\system32\PresentationNative_v0300.dll
2009-05-07 18:03 . 2008-06-20 01:14 326160 —-a-w c:\windows\system32\PresentationHost.exe
2009-05-07 17:55 . 2008-07-27 18:03 96760 —-a-w c:\windows\system32\dfshim.dll
2009-05-07 17:55 . 2008-07-27 18:03 282112 —-a-w c:\windows\system32\mscoree.dll
2009-05-07 17:55 . 2008-07-27 18:03 41984 —-a-w c:\windows\system32\netfxperf.dll
2009-05-07 17:55 . 2008-07-27 18:03 158720 —-a-w c:\windows\system32\mscorier.dll
2009-05-07 17:55 . 2008-07-27 18:03 83968 —-a-w c:\windows\system32\mscories.dll
2009-05-07 17:05 . 2009-05-11 14:07 ——– d—–w c:\program files\Loaris Trojan Remover
2009-05-07 16:50 . 2009-05-07 21:54 ——– d—–w c:\program files\GridinSoft Trojan Killer
2009-05-07 16:34 . 2009-05-12 14:53 ——– d-sh–w c:\users\Computer\AppData\Roaming\lowsec
2009-05-07 16:32 . 2009-05-07 16:38 ——– d—–w c:\programdata\13935234
2009-05-07 16:32 . 2009-05-07 16:38 ——– d—–w c:\users\All Users\13935234
2009-05-07 12:46 . 2009-05-07 12:46 66048 —-a-w c:\windows\system32\lds.exe
2009-05-05 17:36 . 2008-09-10 09:36 32768 —-a-w c:\windows\system32\LXF3FXPU.DLL
2009-05-05 17:36 . 2008-04-01 01:59 45056 —-a-w c:\windows\system32\LXF3PMON.DLL
2009-05-05 17:35 . 2009-05-07 22:13 ——– d—–w c:\program files\Lexmark Fax Solutions
2009-05-05 17:35 . 2009-05-07 20:42 ——– d—–w c:\program files\Lexmark Tools for Office
2009-05-05 17:33 . 2009-05-07 20:42 ——– d—–w c:\program files\Lexmark Toolbar
2009-05-05 17:22 . 2009-05-07 21:10 ——– d—–w c:\users\Computer\AppData\Roaming\Lexmark Productivity Studio
2009-05-05 17:11 . 2009-05-05 17:11 ——– d—–w c:\users\Computer\AppData\Roaming\GTek
2009-05-05 17:05 . 2009-05-05 17:05 ——– d—–w c:\users\Computer\AppData\Local\MigWiz
2009-05-04 22:15 . 2009-05-04 22:15 ——– d—–w c:\users\Computer\AppData\Roaming\TrojanHunter
2009-05-04 22:13 . 2009-05-05 17:26 ——– d—–w c:\program files\TrojanHunter 4.7
2009-05-04 17:21 . 2009-05-04 17:35 ——– d—–w c:\users\Computer\AppData\Local\Nero
2009-05-04 17:15 . 2009-05-04 17:16 ——– d—–w c:\users\Computer\AppData\Roaming\Nero
2009-05-04 16:47 . 2009-05-04 17:32 ——– d—–w c:\program files\Nero
2009-05-04 16:47 . 2009-05-04 17:48 ——– d—–w c:\programdata\Nero
2009-05-04 16:47 . 2009-05-04 17:48 ——– d—–w c:\users\All Users\Nero
2009-05-04 16:47 . 2009-05-04 17:32 ——– d—–w c:\program files\Common Files\Nero
2009-05-04 16:19 . 2009-05-04 16:19 ——– d—–w c:\program files\Aimersoft
2009-05-04 02:21 . 2009-05-04 02:24 ——– d—–w c:\users\Computer\AppData\Roaming\Kelpiesoft Food File
2009-05-04 02:21 . 2009-05-04 02:21 ——– d—–w c:\program files\Food File
2009-05-04 00:28 . 2009-05-04 00:28 ——– d—–w c:\program files\AVI MPEG RM WMV Joiner
2009-05-03 23:35 . 2009-05-03 23:35 ——– d—–w c:\windows\system32\config\systemprofile\AppData\Roaming\Yahoo!
2009-05-03 23:25 . 2009-05-03 23:35 ——– d—–w c:\windows\system32\config\systemprofile\AppData\Roaming\GrabPro
2009-05-03 04:13 . 2009-05-03 04:13 ——– d—–w c:\users\Computer\AppData\Roaming\FairStars Audio Converter
2009-05-03 04:11 . 2009-05-05 17:26 ——– d—–w c:\program files\FairStars Audio Converter
2009-05-03 04:04 . 2009-05-03 04:04 ——– d—–w c:\programdata\AVS4YOU
2009-05-03 04:04 . 2009-05-03 04:04 ——– d—–w c:\users\All Users\AVS4YOU
2009-05-03 04:04 . 2009-05-03 04:04 ——– d—–w c:\users\Computer\AppData\Roaming\AVS4YOU
2009-05-03 04:04 . 2003-05-21 19:50 24576 —-a-w c:\windows\system32\msxml3a.dll
2009-05-02 21:47 . 2009-05-02 21:47 ——– d—–w c:\program files\Common Files\EZB Systems
2009-05-02 21:47 . 2009-05-05 17:26 ——– d—–w c:\program files\UltraISO
2009-05-02 21:14 . 2009-05-02 21:14 ——– d—–w c:\users\Public\CyberLink
2009-05-01 17:17 . 2009-05-01 17:17 ——– d—–w c:\programdata\Azureus
2009-05-01 17:17 . 2009-05-01 17:17 ——– d—–w c:\users\All Users\Azureus
2009-05-01 17:16 . 2009-05-17 13:00 ——– d—–w c:\users\Computer\AppData\Roaming\Azureus
2009-05-01 17:16 . 2009-05-01 17:16 ——– d—–w c:\program files\Vuze
2009-05-01 05:56 . 2009-05-01 05:56 ——– d—–w c:\users\Computer\AppData\Local\HP
2009-05-01 04:00 . 2009-05-01 04:00 ——– d—–w c:\program files\Common Files\xing shared
2009-05-01 04:00 . 2009-05-01 04:00 ——– d—–w c:\program files\Real

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-18 14:02 . 2008-09-30 18:32 162164 —-a-w c:\users\All Users\nvModes.dat
2009-05-18 14:02 . 2008-09-30 18:32 162164 —-a-w c:\programdata\nvModes.dat
2009-05-13 21:33 . 2006-11-02 11:18 ——– d—–w c:\program files\Windows Mail
2009-05-11 16:13 . 2008-05-21 10:28 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-05-11 15:52 . 2009-05-11 15:52 805 —-a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-05-11 15:52 . 2009-05-11 15:52 7386 —-a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-05-11 04:07 . 2008-05-21 12:01 ——– d—–w c:\program files\Common Files\Adobe
2009-05-09 18:37 . 2001-01-01 06:12 1356 —-a-w c:\users\Computer\AppData\Local\d3d9caps.dat
2009-05-09 18:36 . 2009-04-28 23:45 484352 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-05 17:26 . 2006-11-02 12:37 ——– d—–w c:\program files\Windows Sidebar
2009-04-29 02:59 . 2006-11-02 12:37 ——– d—–w c:\program files\MSBuild
2009-03-26 15:00 . 2009-03-26 15:00 64000 —-a-w c:\windows\system32\drivers\RTSTOR.sys
2009-03-17 03:38 . 2009-04-29 02:59 13824 —-a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-29 02:59 24064 —-a-w c:\windows\system32\amxread.dll
2009-03-08 11:34 . 2007-09-05 12:15 914944 —-a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2007-09-05 12:15 43008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2007-09-05 12:15 18944 —-a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2007-09-05 12:15 109056 —-a-w c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2007-09-05 12:15 109568 —-a-w c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2007-09-05 12:15 132608 —-a-w c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2007-09-05 12:15 107520 —-a-w c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2007-09-05 12:15 107008 —-a-w c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2007-09-05 12:15 103936 —-a-w c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2007-09-05 12:15 420352 —-a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2007-09-05 12:15 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2007-09-05 12:15 71680 —-a-w c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2007-09-05 12:15 66560 —-a-w c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2007-09-05 12:15 169472 —-a-w c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2007-09-05 12:15 34816 —-a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2007-09-05 12:15 48128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2007-09-05 12:15 45568 —-a-w c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2007-09-05 12:15 156160 —-a-w c:\windows\system32\msls31.dll
2009-03-03 04:46 . 2009-04-29 02:59 3547632 —-a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:46 . 2009-04-29 02:59 3599328 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:39 . 2009-04-29 02:59 183296 —-a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-29 02:59 551424 —-a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-29 02:59 26112 —-a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-29 02:59 98304 —-a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-29 02:59 54784 —-a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-29 02:59 44032 —-a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-29 02:59 666624 —-a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-29 02:59 17408 —-a-w c:\windows\system32\iashost.exe
2008-01-21 02:43 . 2006-11-02 12:50 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((( SnapShot@2009-05-18_18.21.26 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-30 19:07 . 2009-05-18 15:28 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-09-30 19:07 . 2009-05-18 18:43 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-09-30 19:07 . 2009-05-18 15:28 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-30 19:07 . 2009-05-18 18:43 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-30 19:07 . 2009-05-18 15:28 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-09-30 19:07 . 2009-05-18 18:43 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-09-05 12:21 . 2009-05-18 18:43 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2007-09-05 12:21 . 2009-05-18 15:28 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-03-10 2079256]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2009-03-10 18:47 2079256 —-a-w c:\program files\BS_Player\tbBS_P.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-03-10 2079256]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-03-10 2079256]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"Xmarks"="c:\program files\Xmarks\IE Extension\xmarkssync.exe" [2009-04-22 999424]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"RegClean Expert Scheduler"="c:\program files\Registry Clean Expert\RCHelper.exe" [2009-05-12 601848]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2008-01-21 2153472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-02 468264]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 92704]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-01 198160]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2008-09-10 320168]
"lxdrmon.exe"="c:\program files\Lexmark 4900 Series\lxdrmon.exe" [2008-09-10 676520]
"lxdramon"="c:\program files\Lexmark 4900 Series\lxdramon.exe" [2008-09-10 16040]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-07-01 1447168]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-05-12 1817600]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"uidenhiufgsduiazghs"="c:\windows\TEMP\n7gf3yuud.exe" [BU]
"Diagnostic Manager"="c:\windows\TEMP\1438558680.exe" [BU]

c:\users\Computer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Anapod Manager.lnk - c:\program files\Red Chair Software\Anapod Explorer\anamgr.exe [2008-6-7 1076276]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{0FA8513C-B35D-4763-AF6A-854A922287CA}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{523FA3FA-14B4-4DC3-97D9-A5FF46106D1C}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{C3FCA21C-4D34-4616-A6EE-5A8B377D2BD3}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"TCP Query User{5CB33E97-7F0A-4ADD-AC54-A3F2947A5345}c:\\program files\\orbitdownloader\\orbitnet.exe"= UDP:c:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader
"UDP Query User{6A1479C4-B6DC-4C50-84B5-BEEBE055BDFB}c:\\program files\\orbitdownloader\\orbitnet.exe"= TCP:c:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader
"TCP Query User{AB5C7E05-5CF4-4E5A-B526-D9635FFE5B04}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{B17A0F72-57A0-4372-BECD-078B9B937555}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{D74485B2-E05E-4F1D-A1D5-EA60A47079C0}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{4CE655E6-B39C-4CEB-879D-C5E88B361098}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{7532B700-69CC-4B07-A20C-B7D1A3309422}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{19BF8AB7-9252-4028-B80C-A38751DC58A4}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{3CD35A15-E81B-443E-BA3E-9593B5E340D7}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{39D5BCE6-BF43-4783-95C9-2B1B125B3E6B}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4579BFCD-2369-4FEE-8A3C-76AB3413489B}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{4ADC50F6-6F6F-4049-8738-9F867601C46E}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts
"UDP Query User{3E61E1F9-DBFA-4D20-810E-8A7EA7722341}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts
"TCP Query User{BA8FD897-714A-4321-B216-077D9F4569BB}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{ED0E7A0A-280A-4E9C-B6D4-A77768A6009E}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"{1B4C021C-8C0A-4BB4-B395-CFB3606A2321}"= UDP:c:\program files\Lexmark 3600-4600 Series\lxdxamon.exe:Lexmark Device Monitor
"{F294B7C1-57F0-44D3-9925-A6BA8EABE174}"= TCP:c:\program files\Lexmark 3600-4600 Series\lxdxamon.exe:Lexmark Device Monitor
"{32C2EFBC-0055-4BD0-83E1-A002BFA22AE1}"= UDP:c:\program files\Lexmark 3600-4600 Series\frun.exe:Lexmark Productivity Studio
"{75B86A3C-2363-4DFD-B42C-F676A7E562B0}"= TCP:c:\program files\Lexmark 3600-4600 Series\frun.exe:Lexmark Productivity Studio
"TCP Query User{B2542884-10AE-4A0B-886A-96C4CBEBB1F2}c:\\windows\\explorer.exe"= UDP:c:\windows\explorer.exe:Windows Explorer
"UDP Query User{E168A851-DA0D-4AF5-8B26-F0FB9BB97031}c:\\windows\\explorer.exe"= TCP:c:\windows\explorer.exe:Windows Explorer
"{24B851A4-7D32-4BC5-8C27-AF7FA7D967DF}"= UDP:c:\windows\System32\lxdrcoms.exe:Lexmark Communications System
"{FECCCAF1-8041-4043-95E2-92A94E49F4C5}"= TCP:c:\windows\System32\lxdrcoms.exe:Lexmark Communications System
"{B9DAC796-9920-4858-B9F0-0ED9A2DD753B}"= UDP:c:\program files\Lexmark 4900 Series\lxdramon.exe:Lexmark Device Monitor
"{F56BC95C-E50F-4822-98A9-9FED8E7F7A58}"= TCP:c:\program files\Lexmark 4900 Series\lxdramon.exe:Lexmark Device Monitor
"{2AA7AA2F-74E2-4516-9CCD-A115456B186B}"= UDP:c:\program files\Lexmark 4900 Series\frun.exe:Lexmark Productivity Studio
"{DDD709D8-CED0-470D-8745-BFB819ED16CA}"= TCP:c:\program files\Lexmark 4900 Series\frun.exe:Lexmark Productivity Studio
"{315BA571-D90F-47F3-B9AD-C2400872C332}"= UDP:c:\program files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader
"{174ED0C9-ED69-4E91-ADB2-9640ACEF19CE}"= TCP:c:\program files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader
"{0B7B4B34-C86B-4AF3-B5A6-FA46A07034FE}"= UDP:c:\program files\Lexmark Fax Solutions\FaxCtr.exe:Fax software
"{BCCCFB60-D4EF-4D6A-B0EA-BB925FFE848C}"= TCP:c:\program files\Lexmark Fax Solutions\FaxCtr.exe:Fax software
"{2D579BFF-A8E7-4A01-AC63-350F166142BF}"= Disabled:UDP:c:\program files\Red Chair Software\Anapod Explorer\anamgr.exe:Anapod Xtreamer
"{2468CA57-10B9-45EC-BE16-4B0FD0914C11}"= Disabled:TCP:c:\program files\Red Chair Software\Anapod Explorer\anamgr.exe:Anapod Xtreamer
"{B0941A98-684F-40D3-B156-FBE3D8E76CFC}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"= c:\program files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"= c:\program files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit

R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\N360\0300000.087\SymEFA.sys [5/11/2009 8:52 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\N360\0300000.087\BHDrvx86.sys [5/11/2009 8:52 AM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\N360\0300000.087\cchpx86.sys [5/11/2009 8:52 AM 482352]
R1 epfwtdir;epfwtdir;c:\windows\System32\drivers\epfwtdir.sys [7/1/2008 9:04 AM 34312]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090508.002\IDSvix86.sys [5/11/2009 8:59 AM 292912]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\System32\drivers\sp_rsdrv2.sys [5/12/2009 8:19 AM 141312]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [7/1/2008 9:02 AM 468224]
R2 lxdr_device;lxdr_device;c:\windows\system32\lxdrcoms.exe -service –> c:\windows\system32\lxdrcoms.exe -service [?]
R2 lxdrCATSCustConnectService;lxdrCATSCustConnectService;c:\windows\System32\spool\drivers\w32x86\3\lxdrserv.exe [5/16/2008 8:39 AM 98984]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe [5/11/2009 8:52 AM 115560]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [5/21/2008 5:20 AM 361808]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [1/14/2009 5:53 PM 226656]
R2 YahooAUService;Yahoo! Updater;c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe [11/9/2008 1:48 PM 602392]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/11/2009 8:52 AM 101936]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [5/3/2008 5:39 AM 42528]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\N360\0300000.087\symndisv.sys [5/11/2009 8:52 AM 39984]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [5/21/2008 3:56 AM 193840]
S3 DsAudioDevice_310;DsAudioDevice_310;c:\windows\System32\drivers\DsAudioDevice_310.sys [4/29/2009 9:52 AM 16640]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder

2009-05-18 c:\windows\Tasks\NeroLiveEpgUpdate-Computer-PC_Computer.job
- c:\program files\Nero\Nero 9\Nero Live\NeroLive.exe [2008-09-18 20:51]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.aol.com/
IE: &Download; by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab; video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Crawler Search - tbr:iemenu
IE: Do&wnload; selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load; all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\wp0x49j0.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;=
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;=
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\wp0x49j0.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\wp0x49j0.default\extensions\[removed]\plugins\npTVUAx.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-18 13:47
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.0.0.135\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-501789590-1159742304-1750928594-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\L*i*n*k*s* \Microsoft Websites]
"Order"=hex:08,00,00,00,02,00,00,00,f6,02,00,00,01,00,00,00,06,00,00,00,78,00,
00,00,00,00,00,00,6a,00,32,00,cd,00,00,00,00,e7,ec,09,20,00,49,45,41,44,44,\

[HKEY_USERS\S-1-5-21-501789590-1159742304-1750928594-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\L*i*n*k*s* \Microsoft Websites]
"Order"=hex:08,00,00,00,02,00,00,00,f6,02,00,00,01,00,00,00,06,00,00,00,78,00,
00,00,00,00,00,00,6a,00,32,00,cd,00,00,00,00,cc,a9,4c,20,00,49,45,41,44,44,\

[HKEY_USERS\S-1-5-21-501789590-1159742304-1750928594-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\W*i*n*d*o*w*s* *L*i*v*e* \HP]
"Order"=hex:08,00,00,00,02,00,00,00,e4,07,00,00,01,00,00,00,10,00,00,00,6e,00,
00,00,06,00,00,00,60,00,31,00,00,00,00,00,00,d7,24,56,10,00,4d,4f,5a,49,4c,\

[HKEY_USERS\S-1-5-21-501789590-1159742304-1750928594-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\W*i*n*d*o*w*s* *L*i*v*e* \HP\Mozilla Firefox]
"Order"=hex:08,00,00,00,02,00,00,00,ea,01,00,00,01,00,00,00,04,00,00,00,6c,00,
00,00,00,00,00,00,5e,00,32,00,cd,00,00,00,00,23,df,cf,20,00,41,42,4f,55,54,\

[HKEY_USERS\S-1-5-21-501789590-1159742304-1750928594-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\W*i*n*d*o*w*s* *L*i*v*e* \HP\MSN Websites]
"Order"=hex:08,00,00,00,02,00,00,00,a2,02,00,00,01,00,00,00,06,00,00,00,5c,00,
00,00,04,00,00,00,4e,00,32,00,cd,00,00,00,00,57,1f,e2,20,00,4d,53,4e,2e,75,\

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(2680)
c:\windows\System32\NLSData0009.dll
.
Completion time: 2009-05-18 13:49
ComboFix-quarantined-files.txt 2009-05-18 20:49
ComboFix2.txt 2009-05-18 20:39

Pre-Run: 84,497,874,944 bytes free
Post-Run: 84,447,944,704 bytes free

397 — E O F — 2009-05-13 22:09

********************************************************************************
********************************************

GooredLog:

GooredFix v1.92 by jpshortstuff
Log created at 13:51 on 18/05/2009 running Option #1 (Computer)
Firefox version 3.0.10 (en-US)

=====Suspect Goored Entries=====

C:\Program Files\Mozilla Firefox\extensions\{5F30C81E-EAFB-4F83-8097-170827311DE9}

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{4B3803EA-5230-4DC3-A7FC-33638F3D3542}"="C:\Program Files\Crawler\Toolbar\firefox\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\Program Files\Real\RealPlayer\browserrecord"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"[removed]"="C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2"

********************************************************************************
********************************************

Kapersky:

KASPERSKY ONLINE SCANNER 7.0 REPORT
Monday, May 18, 2009
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Tuesday, May 19, 2009 00:29:19
Records in database: 2192478
Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes
Scan area My Computer
C:\
D:\
E:\
Scan statistics
Files scanned 153777
Threat name 0
Infected objects 0
Suspicious objects 0
Duration of the scan 02:24:49

No malware has been detected. The scan area is clean.
The selected area was scanned.

********************************************************************************
********************************************

Thanks again for all your help.
Hi,

Please do the following:


Option #2:
Please double-click GooredFix.exe on your Desktop to run it.
  • Select "2. Fix Goored" by typing 2 and pressing Enter.
  • Make sure all instances of Firefox are closed at this point.
  • Type y at the prompt and press Enter again.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Note: If you receive a message saying that GooredFix needs your system to be restarted, please close all applications and reboot your system. Please also allow any registry changes that may be prompted by any of your security programs.


Post a fresh HJT log along with the Gooredfix Log
To answer your question re the AV Are they both paid for versions? Which one has the longest subscription remaining. Keep whichever one has the longest subscription as it's very important that your AV be kept up to date with the latest virus definitions. Nod is a little lighter on resources. If both subscriptions have expired I can recommend an excellent free alternative let me know
Both Anti virus programs are trials that will end soon. If you know of a free program that is as good I would love to get the information. Following are the requested logs:

GooredLog:

GooredFix v1.92 by jpshortstuff
Log created at 19:09 on 18/05/2009 running Option #2 (Computer)
Firefox version 3.0.10 (en-US)
(Subsequent Run)

=====Goored Deletions=====
C:\Program Files\Mozilla Firefox\extensions\{5F30C81E-EAFB-4F83-8097-170827311DE9}
->Backing up folder… Failed.

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{4B3803EA-5230-4DC3-A7FC-33638F3D3542}"="C:\Program Files\Crawler\Toolbar\firefox\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\Program Files\Real\RealPlayer\browserrecord"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"[removed]"="C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2"

********************************************************************************
********************************************

Hijackhis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:16:32 PM, on 5/18/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Lexmark 4900 Series\lxdrmon.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Xmarks\IE Extension\xmarkssync.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Registry Clean Expert\RCHelper.exe
C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
C:\Program Files\Lexmark 4900 Series\lxdrMsdMon.exe
C:\Windows\system32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\Explorer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.0.0.135\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Lexmark Printable Web - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O2 - BHO: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [lxdrmon.exe] "C:\Program Files\Lexmark 4900 Series\lxdrmon.exe"
O4 - HKLM\..\Run: [lxdramon] "C:\Program Files\Lexmark 4900 Series\lxdramon.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Xmarks] C:\Program Files\Xmarks\IE Extension\xmarkssync.exe -q
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [RegClean Expert Scheduler] "C:\Program Files\Registry Clean Expert\RCHelper.exe" /startup
O4 - HKUS\S-1-5-18\..\Run: [uidenhiufgsduiazghs] C:\Windows\TEMP\n7gf3yuud.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Diagnostic Manager] C:\Windows\TEMP\1438558680.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [uidenhiufgsduiazghs] C:\Windows\TEMP\n7gf3yuud.exe (User 'Default user')
O4 - Startup: Anapod Manager.lnk = C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: lxdrCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdrserv.exe
O23 - Service: lxdr_device - - C:\Windows\system32\lxdrcoms.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 11108 bytes


Thank You
Both Anti virus programs are trials that will end soon. If you know of a free program that is as good I would love to get the information. Following are the requested logs:

GooredLog:

GooredFix v1.92 by jpshortstuff
Log created at 19:09 on 18/05/2009 running Option #2 (Computer)
Firefox version 3.0.10 (en-US)
(Subsequent Run)

=====Goored Deletions=====
C:\Program Files\Mozilla Firefox\extensions\{5F30C81E-EAFB-4F83-8097-170827311DE9}
->Backing up folder… Failed.

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{4B3803EA-5230-4DC3-A7FC-33638F3D3542}"="C:\Program Files\Crawler\Toolbar\firefox\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\Program Files\Real\RealPlayer\browserrecord"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"[removed]"="C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2"

********************************************************************************
********************************************

Hijackhis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:16:32 PM, on 5/18/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Lexmark 4900 Series\lxdrmon.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Xmarks\IE Extension\xmarkssync.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Registry Clean Expert\RCHelper.exe
C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
C:\Program Files\Lexmark 4900 Series\lxdrMsdMon.exe
C:\Windows\system32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\Explorer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.0.0.135\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Lexmark Printable Web - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O2 - BHO: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [lxdrmon.exe] "C:\Program Files\Lexmark 4900 Series\lxdrmon.exe"
O4 - HKLM\..\Run: [lxdramon] "C:\Program Files\Lexmark 4900 Series\lxdramon.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Xmarks] C:\Program Files\Xmarks\IE Extension\xmarkssync.exe -q
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [RegClean Expert Scheduler] "C:\Program Files\Registry Clean Expert\RCHelper.exe" /startup
O4 - HKUS\S-1-5-18\..\Run: [uidenhiufgsduiazghs] C:\Windows\TEMP\n7gf3yuud.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Diagnostic Manager] C:\Windows\TEMP\1438558680.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [uidenhiufgsduiazghs] C:\Windows\TEMP\n7gf3yuud.exe (User 'Default user')
O4 - Startup: Anapod Manager.lnk = C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: lxdrCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdrserv.exe
O23 - Service: lxdr_device - - C:\Windows\system32\lxdrcoms.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 11108 bytes


Thank You
Hi,

The back-up failed in GooredFix,

can you run it again but first right click GooredFix.exe and select run as administrator, then

We need to run another ComboFix script as well.

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Browser_Hijack_t103179.html&view=findpost&p=559989#entry559989

Collect::
c:\windows\TEMP\n7gf3yuud.exe
c:\windows\TEMP\1438558680.exe

Registry::
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"uidenhiufgsduiazghs"=-
"Diagnostic Manager"=-

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.






As for AV recommendations:

Recommended AV's (all free - personally I use Avira, but they are all very good)

Avira AntiVir
Avast
AVG

set the one you choose to receive automatic updates so you are always as fully protected as possible from the newest virus threats.

NOTE: DO NOT install more than one anti-virus program as they will conflict, and provide less protection, not more.
Thanks for the anti virus advice. I will uninstall the old ones and download from your suggestions. I ran the GooredFix as administrator but I think I got the same failed message. Following is the new log: GooredFix v1.92 by jpshortstuff Log created at 20:40 on 18/05/2009 running Option #2 (Computer) Firefox version 3.0.10 (en-US) (Subsequent Run) =====Goored Deletions===== C:\Program Files\Mozilla Firefox\extensions\{5F30C81E-EAFB-4F83-8097-170827311DE9} ->Backing up folder… Failed. =====Dumping Registry Values===== [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions] "Plugins"="C:\Program Files\Mozilla Firefox\plugins" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions] "Components"="C:\Program Files\Mozilla Firefox\components" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "{4B3803EA-5230-4DC3-A7FC-33638F3D3542}"="C:\Program Files\Crawler\Toolbar\firefox\" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\Program Files\Real\RealPlayer\browserrecord" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "[removed]"="C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2" ******************************************************************************** ********************************************************************************* ************************* I'm not sure what else you need me to do because the last post with instructions seemed cut off. Thanks
New ComboFix script:

ComboFix 09-05-18.02 - Computer 05/18/2009 21:12.4 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2814.1857 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-04-19 to 2009-05-19 )))))))))))))))))))))))))))))))
.

2009-05-18 20:55 . 2009-05-18 20:55 410984 —-a-w c:\windows\system32\deploytk.dll
2009-05-18 14:54 . 2009-05-18 14:54 ——– d—–w c:\program files\ERUNT
2009-05-17 00:18 . 2009-05-17 00:18 ——– d—–r c:\program files\Norton Support
2009-05-16 03:58 . 2009-05-16 03:58 ——– d—–w c:\programdata\TVU Networks
2009-05-16 03:58 . 2009-05-16 03:58 ——– d—–w c:\users\All Users\TVU Networks
2009-05-16 03:58 . 2009-05-16 03:58 ——– d—–w c:\users\Computer\AppData\Local\TVU Networks
2009-05-16 03:58 . 2009-05-16 03:58 ——– d—–w c:\program files\TVUPlayer
2009-05-15 17:43 . 2009-05-15 17:43 ——– d—–w c:\users\Computer\AppData\Roaming\iExpert Software
2009-05-15 17:43 . 2009-05-15 17:43 ——– d—–w c:\program files\Registry Clean Expert
2009-05-14 09:54 . 2009-05-14 09:54 ——– d—–w c:\users\Computer\AppData\Local\Symantec
2009-05-13 21:56 . 2009-05-16 23:28 ——– d—–w c:\users\Computer\Tracing
2009-05-13 21:53 . 2009-05-13 21:53 ——– d—–w c:\program files\Microsoft Sync Framework
2009-05-13 21:52 . 2006-11-29 20:06 3426072 —-a-w c:\windows\system32\d3dx9_32.dll
2009-05-13 21:52 . 2009-05-13 21:52 ——– d—–w c:\program files\Microsoft SQL Server Compact Edition
2009-05-13 21:50 . 2009-05-13 21:50 ——– d—–w c:\program files\Microsoft
2009-05-13 21:50 . 2009-05-13 21:50 ——– d—–w c:\program files\Windows Live SkyDrive
2009-05-13 21:49 . 2009-05-13 21:54 ——– d—–w c:\program files\Windows Live
2009-05-13 21:41 . 2009-05-13 21:41 ——– d—–w c:\program files\Common Files\Windows Live
2009-05-12 17:26 . 2007-12-25 00:37 138384 —-a-w c:\windows\system32\drivers\tmcomm.sys
2009-05-12 17:24 . 2009-05-12 17:24 ——– d—–w c:\windows\Sun
2009-05-12 17:20 . 2009-05-12 17:20 ——– d—–w c:\program files\Trend Micro
2009-05-12 16:17 . 2009-05-12 16:17 ——– d—–w c:\users\Computer\AppData\Roaming\Malwarebytes
2009-05-12 16:17 . 2009-04-06 22:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-12 16:17 . 2009-04-06 22:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-12 16:17 . 2009-05-12 16:17 ——– d—–w c:\programdata\Malwarebytes
2009-05-12 16:17 . 2009-05-12 16:17 ——– d—–w c:\users\All Users\Malwarebytes
2009-05-12 16:17 . 2009-05-12 16:17 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-12 15:19 . 2009-05-12 15:20 ——– d—–w c:\program files\Crawler
2009-05-12 15:19 . 2009-05-12 15:19 141312 —-a-w c:\windows\system32\drivers\sp_rsdrv2.sys
2009-05-12 15:19 . 2009-05-13 16:24 ——– d—–w c:\programdata\Spyware Terminator
2009-05-12 15:19 . 2009-05-13 16:24 ——– d—–w c:\users\All Users\Spyware Terminator
2009-05-12 15:19 . 2009-05-18 20:59 ——– d—–w c:\users\Computer\AppData\Roaming\Spyware Terminator
2009-05-12 15:19 . 2009-05-14 23:27 ——– d—–w c:\program files\Spyware Terminator
2009-05-12 13:31 . 2009-05-12 13:31 ——– d—–w c:\program files\Alwil Software
2009-05-11 15:53 . 2008-04-17 19:12 107368 —-a-w c:\windows\system32\GEARAspi.dll
2009-05-11 15:53 . 2009-01-15 19:19 23848 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-11 15:53 . 2009-05-11 15:53 ——– dc—-w c:\windows\system32\DRVSTORE
2009-05-11 15:53 . 2009-05-11 15:53 ——– d—–w c:\programdata\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-05-11 15:53 . 2009-05-11 15:53 ——– d—–w c:\users\All Users\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-05-11 15:53 . 2009-05-11 15:52 25136 —-a-r c:\windows\system32\drivers\SymIMV.sys
2009-05-11 15:52 . 2009-05-11 15:52 124464 —-a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-05-11 15:52 . 2009-05-11 15:53 ——– d—–w c:\program files\Symantec
2009-05-11 15:52 . 2009-05-11 15:52 ——– d—–w c:\windows\system32\drivers\N360
2009-05-11 15:52 . 2009-05-11 15:52 ——– d—–w c:\program files\Norton 360
2009-05-11 15:52 . 2009-05-11 15:52 ——– d—–w c:\program files\NortonInstaller
2009-05-11 14:44 . 2009-05-11 15:52 ——– d—–w c:\programdata\Norton
2009-05-11 14:44 . 2009-05-11 15:52 ——– d—–w c:\users\All Users\Norton
2009-05-11 14:44 . 2009-05-11 15:52 ——– d—–w c:\programdata\NortonInstaller
2009-05-11 14:44 . 2009-05-11 15:52 ——– d—–w c:\users\All Users\NortonInstaller
2009-05-10 15:41 . 2009-05-10 15:41 ——– d-sh–w C:\found.000
2009-05-08 23:03 . 2009-05-08 23:11 ——– d—a-w c:\programdata\TEMP
2009-05-08 23:03 . 2009-05-08 23:11 ——– d—a-w c:\users\All Users\TEMP
2009-05-08 23:03 . 2004-08-04 15:00 506368 —-a-w c:\windows\system32\msxml.dll
2009-05-08 21:40 . 2009-05-08 21:40 ——– d—–w c:\windows\system32\config\systemprofile\AppData\Local\ESET
2009-05-08 17:10 . 2009-05-16 23:58 ——– d—–w c:\programdata\Spybot - Search & Destroy
2009-05-08 17:10 . 2009-05-16 23:58 ——– d—–w c:\users\All Users\Spybot - Search & Destroy
2009-05-08 17:10 . 2009-05-16 23:59 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-05-08 01:30 . 2009-05-08 01:30 ——– d—–w c:\users\Computer\AppData\Local\ESET
2009-05-08 00:03 . 2009-05-08 00:03 ——– d—–w c:\programdata\ESET
2009-05-08 00:03 . 2009-05-08 00:03 ——– d—–w c:\users\All Users\ESET
2009-05-07 20:46 . 2008-04-23 16:34 360448 —-a-w c:\windows\system32\lxdrcoin.dll
2009-05-07 20:44 . 2008-05-16 15:12 40960 —-a-w c:\windows\system32\lxdrvs.dll
2009-05-07 20:43 . 2008-05-09 16:32 81920 —-a-w c:\windows\system32\lxdrcaps.dll
2009-05-07 20:43 . 2008-05-09 16:22 69632 —-a-w c:\windows\system32\lxdrcnv4.dll
2009-05-07 20:43 . 2008-05-09 16:32 1036288 —-a-w c:\windows\system32\lxdrdrs.dll
2009-05-07 20:39 . 2009-05-07 20:39 ——– d—–w c:\program files\Lexmark Printable Web
2009-05-07 20:39 . 2008-05-16 15:39 17064 —-a-w c:\windows\system32\LXDRwupd.exe
2009-05-07 20:39 . 2008-04-15 11:08 352256 —-a-w c:\windows\system32\LXDRwupd.dll
2009-05-07 20:36 . 2009-05-07 21:55 ——– d—–w c:\program files\Lexmark 4900 Series
2009-05-07 18:03 . 2008-06-20 01:14 97800 —-a-w c:\windows\system32\infocardapi.dll
2009-05-07 18:03 . 2008-06-20 01:14 105016 —-a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-05-07 18:03 . 2008-06-20 01:14 622080 —-a-w c:\windows\system32\icardagt.exe
2009-05-07 18:03 . 2008-06-20 01:14 11264 —-a-w c:\windows\system32\icardres.dll
2009-05-07 18:03 . 2008-06-20 01:14 43544 —-a-w c:\windows\system32\PresentationHostProxy.dll
2009-05-07 18:03 . 2008-06-20 01:14 781344 —-a-w c:\windows\system32\PresentationNative_v0300.dll
2009-05-07 18:03 . 2008-06-20 01:14 326160 —-a-w c:\windows\system32\PresentationHost.exe
2009-05-07 17:55 . 2008-07-27 18:03 96760 —-a-w c:\windows\system32\dfshim.dll
2009-05-07 17:55 . 2008-07-27 18:03 282112 —-a-w c:\windows\system32\mscoree.dll
2009-05-07 17:55 . 2008-07-27 18:03 41984 —-a-w c:\windows\system32\netfxperf.dll
2009-05-07 17:55 . 2008-07-27 18:03 158720 —-a-w c:\windows\system32\mscorier.dll
2009-05-07 17:55 . 2008-07-27 18:03 83968 —-a-w c:\windows\system32\mscories.dll
2009-05-07 17:05 . 2009-05-11 14:07 ——– d—–w c:\program files\Loaris Trojan Remover
2009-05-07 16:50 . 2009-05-07 21:54 ——– d—–w c:\program files\GridinSoft Trojan Killer
2009-05-07 16:34 . 2009-05-12 14:53 ——– d-sh–w c:\users\Computer\AppData\Roaming\lowsec
2009-05-07 16:32 . 2009-05-07 16:38 ——– d—–w c:\programdata\13935234
2009-05-07 16:32 . 2009-05-07 16:38 ——– d—–w c:\users\All Users\13935234
2009-05-07 12:46 . 2009-05-07 12:46 66048 —-a-w c:\windows\system32\lds.exe
2009-05-05 17:36 . 2008-09-10 09:36 32768 —-a-w c:\windows\system32\LXF3FXPU.DLL
2009-05-05 17:36 . 2008-04-01 01:59 45056 —-a-w c:\windows\system32\LXF3PMON.DLL
2009-05-05 17:35 . 2009-05-07 22:13 ——– d—–w c:\program files\Lexmark Fax Solutions
2009-05-05 17:35 . 2009-05-07 20:42 ——– d—–w c:\program files\Lexmark Tools for Office
2009-05-05 17:33 . 2009-05-07 20:42 ——– d—–w c:\program files\Lexmark Toolbar
2009-05-05 17:22 . 2009-05-07 21:10 ——– d—–w c:\users\Computer\AppData\Roaming\Lexmark Productivity Studio
2009-05-05 17:11 . 2009-05-05 17:11 ——– d—–w c:\users\Computer\AppData\Roaming\GTek
2009-05-05 17:05 . 2009-05-05 17:05 ——– d—–w c:\users\Computer\AppData\Local\MigWiz
2009-05-04 22:15 . 2009-05-04 22:15 ——– d—–w c:\users\Computer\AppData\Roaming\TrojanHunter
2009-05-04 22:13 . 2009-05-05 17:26 ——– d—–w c:\program files\TrojanHunter 4.7
2009-05-04 17:21 . 2009-05-04 17:35 ——– d—–w c:\users\Computer\AppData\Local\Nero
2009-05-04 17:15 . 2009-05-04 17:16 ——– d—–w c:\users\Computer\AppData\Roaming\Nero
2009-05-04 16:47 . 2009-05-04 17:32 ——– d—–w c:\program files\Nero
2009-05-04 16:47 . 2009-05-04 17:48 ——– d—–w c:\programdata\Nero
2009-05-04 16:47 . 2009-05-04 17:48 ——– d—–w c:\users\All Users\Nero
2009-05-04 16:47 . 2009-05-04 17:32 ——– d—–w c:\program files\Common Files\Nero
2009-05-04 16:19 . 2009-05-04 16:19 ——– d—–w c:\program files\Aimersoft
2009-05-04 02:21 . 2009-05-04 02:24 ——– d—–w c:\users\Computer\AppData\Roaming\Kelpiesoft Food File
2009-05-04 02:21 . 2009-05-04 02:21 ——– d—–w c:\program files\Food File
2009-05-04 00:28 . 2009-05-04 00:28 ——– d—–w c:\program files\AVI MPEG RM WMV Joiner
2009-05-03 23:35 . 2009-05-03 23:35 ——– d—–w c:\windows\system32\config\systemprofile\AppData\Roaming\Yahoo!
2009-05-03 23:25 . 2009-05-03 23:35 ——– d—–w c:\windows\system32\config\systemprofile\AppData\Roaming\GrabPro
2009-05-03 04:13 . 2009-05-03 04:13 ——– d—–w c:\users\Computer\AppData\Roaming\FairStars Audio Converter
2009-05-03 04:11 . 2009-05-05 17:26 ——– d—–w c:\program files\FairStars Audio Converter
2009-05-03 04:04 . 2009-05-03 04:04 ——– d—–w c:\programdata\AVS4YOU
2009-05-03 04:04 . 2009-05-03 04:04 ——– d—–w c:\users\All Users\AVS4YOU
2009-05-03 04:04 . 2009-05-03 04:04 ——– d—–w c:\users\Computer\AppData\Roaming\AVS4YOU
2009-05-03 04:04 . 2003-05-21 19:50 24576 —-a-w c:\windows\system32\msxml3a.dll
2009-05-02 21:47 . 2009-05-02 21:47 ——– d—–w c:\program files\Common Files\EZB Systems
2009-05-02 21:47 . 2009-05-05 17:26 ——– d—–w c:\program files\UltraISO
2009-05-02 21:14 . 2009-05-02 21:14 ——– d—–w c:\users\Public\CyberLink
2009-05-01 17:17 . 2009-05-01 17:17 ——– d—–w c:\programdata\Azureus
2009-05-01 17:17 . 2009-05-01 17:17 ——– d—–w c:\users\All Users\Azureus
2009-05-01 17:16 . 2009-05-17 13:00 ——– d—–w c:\users\Computer\AppData\Roaming\Azureus
2009-05-01 17:16 . 2009-05-01 17:16 ——– d—–w c:\program files\Vuze
2009-05-01 05:56 . 2009-05-01 05:56 ——– d—–w c:\users\Computer\AppData\Local\HP
2009-05-01 04:00 . 2009-05-01 04:00 ——– d—–w c:\program files\Common Files\xing shared
2009-05-01 04:00 . 2009-05-01 04:00 ——– d—–w c:\program files\Real

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-19 04:06 . 2008-09-30 18:32 162164 —-a-w c:\users\All Users\nvModes.dat
2009-05-19 04:06 . 2008-09-30 18:32 162164 —-a-w c:\programdata\nvModes.dat
2009-05-18 20:55 . 2008-05-21 12:26 ——– d—–w c:\program files\Java
2009-05-13 21:33 . 2006-11-02 11:18 ——– d—–w c:\program files\Windows Mail
2009-05-11 16:13 . 2008-05-21 10:28 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-05-11 15:52 . 2009-05-11 15:52 805 —-a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-05-11 15:52 . 2009-05-11 15:52 7386 —-a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-05-11 04:07 . 2008-05-21 12:01 ——– d—–w c:\program files\Common Files\Adobe
2009-05-09 18:37 . 2001-01-01 06:12 1356 —-a-w c:\users\Computer\AppData\Local\d3d9caps.dat
2009-05-09 18:36 . 2009-04-28 23:45 484352 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-05 17:26 . 2006-11-02 12:37 ——– d—–w c:\program files\Windows Sidebar
2009-04-29 02:59 . 2006-11-02 12:37 ——– d—–w c:\program files\MSBuild
2009-03-26 15:00 . 2009-03-26 15:00 64000 —-a-w c:\windows\system32\drivers\RTSTOR.sys
2009-03-17 03:38 . 2009-04-29 02:59 13824 —-a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-29 02:59 24064 —-a-w c:\windows\system32\amxread.dll
2009-03-08 11:34 . 2007-09-05 12:15 914944 —-a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2007-09-05 12:15 43008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2007-09-05 12:15 18944 —-a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2007-09-05 12:15 109056 —-a-w c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2007-09-05 12:15 109568 —-a-w c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2007-09-05 12:15 132608 —-a-w c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2007-09-05 12:15 107520 —-a-w c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2007-09-05 12:15 107008 —-a-w c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2007-09-05 12:15 103936 —-a-w c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2007-09-05 12:15 420352 —-a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2007-09-05 12:15 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2007-09-05 12:15 71680 —-a-w c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2007-09-05 12:15 66560 —-a-w c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2007-09-05 12:15 169472 —-a-w c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2007-09-05 12:15 34816 —-a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2007-09-05 12:15 48128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2007-09-05 12:15 45568 —-a-w c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2007-09-05 12:15 156160 —-a-w c:\windows\system32\msls31.dll
2009-03-03 04:46 . 2009-04-29 02:59 3547632 —-a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:46 . 2009-04-29 02:59 3599328 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:39 . 2009-04-29 02:59 183296 —-a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-29 02:59 551424 —-a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-29 02:59 26112 —-a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-29 02:59 98304 —-a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-29 02:59 54784 —-a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-29 02:59 44032 —-a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-29 02:59 666624 —-a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-29 02:59 17408 —-a-w c:\windows\system32\iashost.exe
2008-01-21 02:43 . 2006-11-02 12:50 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((( SnapShot@2009-05-18_18.21.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-05-19 04:07 51400 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-05-19 04:07 65078 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-09-30 19:07 . 2009-05-18 15:28 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-09-30 19:07 . 2009-05-19 04:06 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-09-30 19:07 . 2009-05-18 15:28 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-30 19:07 . 2009-05-19 04:06 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-30 19:07 . 2009-05-19 04:06 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-09-30 19:07 . 2009-05-18 15:28 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-09-30 19:07 . 2009-05-19 04:07 9542 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-501789590-1159742304-1750928594-1000_UserData.bin
+ 2009-05-19 04:05 . 2009-05-19 04:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-17 18:50 . 2009-05-17 18:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-17 18:50 . 2009-05-17 18:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-05-19 04:05 . 2009-05-19 04:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-05-19 04:12 595684 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-05-17 20:57 595684 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-05-17 20:57 101350 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-05-19 04:12 101350 c:\windows\System32\perfc009.dat
+ 2009-05-18 20:55 . 2009-05-18 20:55 148888 c:\windows\System32\javaws.exe
+ 2009-05-18 20:55 . 2009-05-18 20:55 144792 c:\windows\System32\javaw.exe
+ 2009-05-18 20:55 . 2009-05-18 20:55 144792 c:\windows\System32\java.exe
+ 2007-09-05 12:21 . 2009-05-19 04:06 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2007-09-05 12:21 . 2009-05-18 15:28 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-03-10 2079256]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2009-03-10 18:47 2079256 —-a-w c:\program files\BS_Player\tbBS_P.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-03-10 2079256]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-03-10 2079256]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"Xmarks"="c:\program files\Xmarks\IE Extension\xmarkssync.exe" [2009-04-22 999424]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"RegClean Expert Scheduler"="c:\program files\Registry Clean Expert\RCHelper.exe" [2009-05-12 601848]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2008-01-21 2153472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-02 468264]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 92704]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-01 198160]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2008-09-10 320168]
"lxdrmon.exe"="c:\program files\Lexmark 4900 Series\lxdrmon.exe" [2008-09-10 676520]
"lxdramon"="c:\program files\Lexmark 4900 Series\lxdramon.exe" [2008-09-10 16040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-05-12 1817600]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-18 148888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"uidenhiufgsduiazghs"="c:\windows\TEMP\n7gf3yuud.exe" [BU]
"Diagnostic Manager"="c:\windows\TEMP\1438558680.exe" [BU]

c:\users\Computer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Anapod Manager.lnk - c:\program files\Red Chair Software\Anapod Explorer\anamgr.exe [2008-6-7 1076276]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{0FA8513C-B35D-4763-AF6A-854A922287CA}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{523FA3FA-14B4-4DC3-97D9-A5FF46106D1C}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{C3FCA21C-4D34-4616-A6EE-5A8B377D2BD3}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"TCP Query User{5CB33E97-7F0A-4ADD-AC54-A3F2947A5345}c:\\program files\\orbitdownloader\\orbitnet.exe"= UDP:c:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader
"UDP Query User{6A1479C4-B6DC-4C50-84B5-BEEBE055BDFB}c:\\program files\\orbitdownloader\\orbitnet.exe"= TCP:c:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader
"TCP Query User{AB5C7E05-5CF4-4E5A-B526-D9635FFE5B04}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{B17A0F72-57A0-4372-BECD-078B9B937555}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{D74485B2-E05E-4F1D-A1D5-EA60A47079C0}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{4CE655E6-B39C-4CEB-879D-C5E88B361098}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{7532B700-69CC-4B07-A20C-B7D1A3309422}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{19BF8AB7-9252-4028-B80C-A38751DC58A4}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{3CD35A15-E81B-443E-BA3E-9593B5E340D7}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{39D5BCE6-BF43-4783-95C9-2B1B125B3E6B}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4579BFCD-2369-4FEE-8A3C-76AB3413489B}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{4ADC50F6-6F6F-4049-8738-9F867601C46E}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts
"UDP Query User{3E61E1F9-DBFA-4D20-810E-8A7EA7722341}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts
"TCP Query User{BA8FD897-714A-4321-B216-077D9F4569BB}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{ED0E7A0A-280A-4E9C-B6D4-A77768A6009E}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"{1B4C021C-8C0A-4BB4-B395-CFB3606A2321}"= UDP:c:\program files\Lexmark 3600-4600 Series\lxdxamon.exe:Lexmark Device Monitor
"{F294B7C1-57F0-44D3-9925-A6BA8EABE174}"= TCP:c:\program files\Lexmark 3600-4600 Series\lxdxamon.exe:Lexmark Device Monitor
"{32C2EFBC-0055-4BD0-83E1-A002BFA22AE1}"= UDP:c:\program files\Lexmark 3600-4600 Series\frun.exe:Lexmark Productivity Studio
"{75B86A3C-2363-4DFD-B42C-F676A7E562B0}"= TCP:c:\program files\Lexmark 3600-4600 Series\frun.exe:Lexmark Productivity Studio
"TCP Query User{B2542884-10AE-4A0B-886A-96C4CBEBB1F2}c:\\windows\\explorer.exe"= UDP:c:\windows\explorer.exe:Windows Explorer
"UDP Query User{E168A851-DA0D-4AF5-8B26-F0FB9BB97031}c:\\windows\\explorer.exe"= TCP:c:\windows\explorer.exe:Windows Explorer
"{24B851A4-7D32-4BC5-8C27-AF7FA7D967DF}"= UDP:c:\windows\System32\lxdrcoms.exe:Lexmark Communications System
"{FECCCAF1-8041-4043-95E2-92A94E49F4C5}"= TCP:c:\windows\System32\lxdrcoms.exe:Lexmark Communications System
"{B9DAC796-9920-4858-B9F0-0ED9A2DD753B}"= UDP:c:\program files\Lexmark 4900 Series\lxdramon.exe:Lexmark Device Monitor
"{F56BC95C-E50F-4822-98A9-9FED8E7F7A58}"= TCP:c:\program files\Lexmark 4900 Series\lxdramon.exe:Lexmark Device Monitor
"{2AA7AA2F-74E2-4516-9CCD-A115456B186B}"= UDP:c:\program files\Lexmark 4900 Series\frun.exe:Lexmark Productivity Studio
"{DDD709D8-CED0-470D-8745-BFB819ED16CA}"= TCP:c:\program files\Lexmark 4900 Series\frun.exe:Lexmark Productivity Studio
"{315BA571-D90F-47F3-B9AD-C2400872C332}"= UDP:c:\program files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader
"{174ED0C9-ED69-4E91-ADB2-9640ACEF19CE}"= TCP:c:\program files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader
"{0B7B4B34-C86B-4AF3-B5A6-FA46A07034FE}"= UDP:c:\program files\Lexmark Fax Solutions\FaxCtr.exe:Fax software
"{BCCCFB60-D4EF-4D6A-B0EA-BB925FFE848C}"= TCP:c:\program files\Lexmark Fax Solutions\FaxCtr.exe:Fax software
"{2D579BFF-A8E7-4A01-AC63-350F166142BF}"= Disabled:UDP:c:\program files\Red Chair Software\Anapod Explorer\anamgr.exe:Anapod Xtreamer
"{2468CA57-10B9-45EC-BE16-4B0FD0914C11}"= Disabled:TCP:c:\program files\Red Chair Software\Anapod Explorer\anamgr.exe:Anapod Xtreamer
"{B0941A98-684F-40D3-B156-FBE3D8E76CFC}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"= c:\program files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"= c:\program files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit

R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\N360\0300000.087\SymEFA.sys [5/11/2009 8:52 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\N360\0300000.087\BHDrvx86.sys [5/11/2009 8:52 AM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\N360\0300000.087\cchpx86.sys [5/11/2009 8:52 AM 482352]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090508.002\IDSvix86.sys [5/11/2009 8:59 AM 292912]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\System32\drivers\sp_rsdrv2.sys [5/12/2009 8:19 AM 141312]
R2 lxdr_device;lxdr_device;c:\windows\system32\lxdrcoms.exe -service –> c:\windows\system32\lxdrcoms.exe -service [?]
R2 lxdrCATSCustConnectService;lxdrCATSCustConnectService;c:\windows\System32\spool\drivers\w32x86\3\lxdrserv.exe [5/16/2008 8:39 AM 98984]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe [5/11/2009 8:52 AM 115560]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [5/21/2008 5:20 AM 361808]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [1/14/2009 5:53 PM 226656]
R2 YahooAUService;Yahoo! Updater;c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe [11/9/2008 1:48 PM 602392]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/11/2009 8:52 AM 101936]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [5/3/2008 5:39 AM 42528]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\N360\0300000.087\symndisv.sys [5/11/2009 8:52 AM 39984]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [5/21/2008 3:56 AM 193840]
S3 DsAudioDevice_310;DsAudioDevice_310;c:\windows\System32\drivers\DsAudioDevice_310.sys [4/29/2009 9:52 AM 16640]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder

2009-05-18 c:\windows\Tasks\NeroLiveEpgUpdate-Computer-PC_Computer.job
- c:\program files\Nero\Nero 9\Nero Live\NeroLive.exe [2008-09-18 20:51]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.aol.com/
IE: &Download; by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab; video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Crawler Search - tbr:iemenu
IE: Do&wnload; selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load; all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\wp0x49j0.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;=
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\wp0x49j0.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\wp0x49j0.default\extensions\[removed]\plugins\npTVUAx.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-18 21:17
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.0.0.135\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-501789590-1159742304-1750928594-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\L*i*n*k*s* \Microsoft Websites]
"Order"=hex:08,00,00,00,02,00,00,00,f6,02,00,00,01,00,00,00,06,00,00,00,78,00,
00,00,00,00,00,00,6a,00,32,00,cd,00,00,00,00,f3,5f,63,20,00,49,45,41,44,44,\

[HKEY_USERS\S-1-5-21-501789590-1159742304-1750928594-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\L*i*n*k*s* \Microsoft Websites]
"Order"=hex:08,00,00,00,02,00,00,00,f6,02,00,00,01,00,00,00,06,00,00,00,78,00,
00,00,00,00,00,00,6a,00,32,00,cd,00,00,00,00,cc,ee,11,20,00,49,45,41,44,44,\

[HKEY_USERS\S-1-5-21-501789590-1159742304-1750928594-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\W*i*n*d*o*w*s* *L*i*v*e* \HP]
"Order"=hex:08,00,00,00,02,00,00,00,e4,07,00,00,01,00,00,00,10,00,00,00,6e,00,
00,00,06,00,00,00,60,00,31,00,00,00,00,00,00,d0,7b,c5,10,00,4d,4f,5a,49,4c,\

[HKEY_USERS\S-1-5-21-501789590-1159742304-1750928594-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\W*i*n*d*o*w*s* *L*i*v*e* \HP\Mozilla Firefox]
"Order"=hex:08,00,00,00,02,00,00,00,ea,01,00,00,01,00,00,00,04,00,00,00,6c,00,
00,00,00,00,00,00,5e,00,32,00,cd,00,00,00,00,7b,d1,88,20,00,41,42,4f,55,54,\

[HKEY_USERS\S-1-5-21-501789590-1159742304-1750928594-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\W*i*n*d*o*w*s* *L*i*v*e* \HP\MSN Websites]
"Order"=hex:08,00,00,00,02,00,00,00,a2,02,00,00,01,00,00,00,06,00,00,00,5c,00,
00,00,04,00,00,00,4e,00,32,00,cd,00,00,00,00,c7,b2,76,20,00,4d,53,4e,2e,75,\

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(4344)
c:\windows\system32\FunDisc.dll
.
Completion time: 2009-05-19 21:18
ComboFix-quarantined-files.txt 2009-05-19 04:18
ComboFix2.txt 2009-05-18 20:49
ComboFix3.txt 2009-05-18 20:39

Pre-Run: 85,463,744,512 bytes free
Post-Run: 85,489,283,072 bytes free

402 — E O F — 2009-05-13 22:09


Thanks
Hi,

The previous ComboFix script didn't execute properly,


Please follow the directions outlined as carefully as possible….if you are having any difficulties at all, or the saved txt file will not drag into combofix as described, then please let me know.


Please do the following:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".


Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Browser_Hijack_t103179.html&view=findpost&p=560049#entry560049

Collect::
c:\windows\TEMP\n7gf3yuud.exe
c:\windows\TEMP\1438558680.exe
C:\Windows\system32\lds.exe

Folder::
C:\Users\Computer\AppData\Roaming\lowsec

DirLook:: 
c:\programdata\13935234
c:\users\All Users\13935234

Registry::
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"uidenhiufgsduiazghs"=-
"Diagnostic Manager"=-

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Hi.

Here is the new Combofix log:

ComboFix 09-05-18.06 - Computer 05/19/2009 7:25.5 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2814.1568 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Computer\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

file zipped: c:\windows\system32\lds.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Computer\AppData\Roaming\lowsec
c:\users\Computer\AppData\Roaming\lowsec\local.ds
c:\users\Computer\AppData\Roaming\lowsec\user.ds
c:\windows\system32\lds.exe

.
((((((((((((((((((((((((( Files Created from 2009-04-19 to 2009-05-19 )))))))))))))))))))))))))))))))
.

2009-05-19 09:29 . 2009-05-19 09:29 ——– d—–w c:\users\Computer\AppData\Local\Adobe
2009-05-18 20:55 . 2009-05-18 20:55 410984 —-a-w c:\windows\system32\deploytk.dll
2009-05-18 14:54 . 2009-05-18 14:54 ——– d—–w c:\program files\ERUNT
2009-05-17 00:18 . 2009-05-17 00:18 ——– d—–r c:\program files\Norton Support
2009-05-16 03:58 . 2009-05-16 03:58 ——– d—–w c:\programdata\TVU Networks
2009-05-16 03:58 . 2009-05-16 03:58 ——– d—–w c:\users\All Users\TVU Networks
2009-05-16 03:58 . 2009-05-16 03:58 ——– d—–w c:\users\Computer\AppData\Local\TVU Networks
2009-05-16 03:58 . 2009-05-16 03:58 ——– d—–w c:\program files\TVUPlayer
2009-05-15 17:43 . 2009-05-15 17:43 ——– d—–w c:\users\Computer\AppData\Roaming\iExpert Software
2009-05-15 17:43 . 2009-05-15 17:43 ——– d—–w c:\program files\Registry Clean Expert
2009-05-14 09:54 . 2009-05-14 09:54 ——– d—–w c:\users\Computer\AppData\Local\Symantec
2009-05-13 21:56 . 2009-05-16 23:28 ——– d—–w c:\users\Computer\Tracing
2009-05-13 21:53 . 2009-05-13 21:53 ——– d—–w c:\program files\Microsoft Sync Framework
2009-05-13 21:52 . 2006-11-29 20:06 3426072 —-a-w c:\windows\system32\d3dx9_32.dll
2009-05-13 21:52 . 2009-05-13 21:52 ——– d—–w c:\program files\Microsoft SQL Server Compact Edition
2009-05-13 21:50 . 2009-05-13 21:50 ——– d—–w c:\program files\Microsoft
2009-05-13 21:50 . 2009-05-13 21:50 ——– d—–w c:\program files\Windows Live SkyDrive
2009-05-13 21:49 . 2009-05-13 21:54 ——– d—–w c:\program files\Windows Live
2009-05-13 21:41 . 2009-05-13 21:41 ——– d—–w c:\program files\Common Files\Windows Live
2009-05-12 17:26 . 2007-12-25 00:37 138384 —-a-w c:\windows\system32\drivers\tmcomm.sys
2009-05-12 17:24 . 2009-05-12 17:24 ——– d—–w c:\windows\Sun
2009-05-12 17:20 . 2009-05-12 17:20 ——– d—–w c:\program files\Trend Micro
2009-05-12 16:17 . 2009-05-12 16:17 ——– d—–w c:\users\Computer\AppData\Roaming\Malwarebytes
2009-05-12 16:17 . 2009-04-06 22:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-12 16:17 . 2009-04-06 22:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-12 16:17 . 2009-05-12 16:17 ——– d—–w c:\programdata\Malwarebytes
2009-05-12 16:17 . 2009-05-12 16:17 ——– d—–w c:\users\All Users\Malwarebytes
2009-05-12 16:17 . 2009-05-12 16:17 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-12 15:19 . 2009-05-12 15:20 ——– d—–w c:\program files\Crawler
2009-05-12 15:19 . 2009-05-12 15:19 141312 —-a-w c:\windows\system32\drivers\sp_rsdrv2.sys
2009-05-12 15:19 . 2009-05-13 16:24 ——– d—–w c:\programdata\Spyware Terminator
2009-05-12 15:19 . 2009-05-13 16:24 ——– d—–w c:\users\All Users\Spyware Terminator
2009-05-12 15:19 . 2009-05-18 20:59 ——– d—–w c:\users\Computer\AppData\Roaming\Spyware Terminator
2009-05-12 15:19 . 2009-05-14 23:27 ——– d—–w c:\program files\Spyware Terminator
2009-05-12 13:31 . 2009-05-12 13:31 ——– d—–w c:\program files\Alwil Software
2009-05-11 15:53 . 2008-04-17 19:12 107368 —-a-w c:\windows\system32\GEARAspi.dll
2009-05-11 15:53 . 2009-01-15 19:19 23848 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-11 15:53 . 2009-05-11 15:53 ——– dc—-w c:\windows\system32\DRVSTORE
2009-05-11 15:53 . 2009-05-11 15:53 ——– d—–w c:\programdata\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-05-11 15:53 . 2009-05-11 15:53 ——– d—–w c:\users\All Users\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-05-11 15:53 . 2009-05-11 15:52 25136 —-a-r c:\windows\system32\drivers\SymIMV.sys
2009-05-11 15:52 . 2009-05-11 15:52 124464 —-a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-05-11 15:52 . 2009-05-11 15:53 ——– d—–w c:\program files\Symantec
2009-05-11 15:52 . 2009-05-11 15:52 ——– d—–w c:\windows\system32\drivers\N360
2009-05-11 15:52 . 2009-05-11 15:52 ——– d—–w c:\program files\Norton 360
2009-05-11 15:52 . 2009-05-11 15:52 ——– d—–w c:\program files\NortonInstaller
2009-05-11 14:44 . 2009-05-11 15:52 ——– d—–w c:\programdata\Norton
2009-05-11 14:44 . 2009-05-11 15:52 ——– d—–w c:\users\All Users\Norton
2009-05-11 14:44 . 2009-05-11 15:52 ——– d—–w c:\programdata\NortonInstaller
2009-05-11 14:44 . 2009-05-11 15:52 ——– d—–w c:\users\All Users\NortonInstaller
2009-05-10 15:41 . 2009-05-10 15:41 ——– d-sh–w C:\found.000
2009-05-08 23:03 . 2009-05-08 23:11 ——– d—a-w c:\programdata\TEMP
2009-05-08 23:03 . 2009-05-08 23:11 ——– d—a-w c:\users\All Users\TEMP
2009-05-08 23:03 . 2004-08-04 15:00 506368 —-a-w c:\windows\system32\msxml.dll
2009-05-08 21:40 . 2009-05-08 21:40 ——– d—–w c:\windows\system32\config\systemprofile\AppData\Local\ESET
2009-05-08 17:10 . 2009-05-16 23:58 ——– d—–w c:\programdata\Spybot - Search & Destroy
2009-05-08 17:10 . 2009-05-16 23:58 ——– d—–w c:\users\All Users\Spybot - Search & Destroy
2009-05-08 17:10 . 2009-05-16 23:59 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-05-08 01:30 . 2009-05-08 01:30 ——– d—–w c:\users\Computer\AppData\Local\ESET
2009-05-08 00:03 . 2009-05-08 00:03 ——– d—–w c:\programdata\ESET
2009-05-08 00:03 . 2009-05-08 00:03 ——– d—–w c:\users\All Users\ESET
2009-05-07 20:46 . 2008-04-23 16:34 360448 —-a-w c:\windows\system32\lxdrcoin.dll
2009-05-07 20:44 . 2008-05-16 15:12 40960 —-a-w c:\windows\system32\lxdrvs.dll
2009-05-07 20:43 . 2008-05-09 16:32 81920 —-a-w c:\windows\system32\lxdrcaps.dll
2009-05-07 20:43 . 2008-05-09 16:22 69632 —-a-w c:\windows\system32\lxdrcnv4.dll
2009-05-07 20:43 . 2008-05-09 16:32 1036288 —-a-w c:\windows\system32\lxdrdrs.dll
2009-05-07 20:39 . 2009-05-07 20:39 ——– d—–w c:\program files\Lexmark Printable Web
2009-05-07 20:39 . 2008-05-16 15:39 17064 —-a-w c:\windows\system32\LXDRwupd.exe
2009-05-07 20:39 . 2008-04-15 11:08 352256 —-a-w c:\windows\system32\LXDRwupd.dll
2009-05-07 20:36 . 2009-05-07 21:55 ——– d—–w c:\program files\Lexmark 4900 Series
2009-05-07 18:03 . 2008-06-20 01:14 97800 —-a-w c:\windows\system32\infocardapi.dll
2009-05-07 18:03 . 2008-06-20 01:14 105016 —-a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-05-07 18:03 . 2008-06-20 01:14 622080 —-a-w c:\windows\system32\icardagt.exe
2009-05-07 18:03 . 2008-06-20 01:14 11264 —-a-w c:\windows\system32\icardres.dll
2009-05-07 18:03 . 2008-06-20 01:14 43544 —-a-w c:\windows\system32\PresentationHostProxy.dll
2009-05-07 18:03 . 2008-06-20 01:14 781344 —-a-w c:\windows\system32\PresentationNative_v0300.dll
2009-05-07 18:03 . 2008-06-20 01:14 326160 —-a-w c:\windows\system32\PresentationHost.exe
2009-05-07 17:55 . 2008-07-27 18:03 96760 —-a-w c:\windows\system32\dfshim.dll
2009-05-07 17:55 . 2008-07-27 18:03 282112 —-a-w c:\windows\system32\mscoree.dll
2009-05-07 17:55 . 2008-07-27 18:03 41984 —-a-w c:\windows\system32\netfxperf.dll
2009-05-07 17:55 . 2008-07-27 18:03 158720 —-a-w c:\windows\system32\mscorier.dll
2009-05-07 17:55 . 2008-07-27 18:03 83968 —-a-w c:\windows\system32\mscories.dll
2009-05-07 17:05 . 2009-05-11 14:07 ——– d—–w c:\program files\Loaris Trojan Remover
2009-05-07 16:50 . 2009-05-07 21:54 ——– d—–w c:\program files\GridinSoft Trojan Killer
2009-05-07 16:32 . 2009-05-07 16:38 ——– d—–w c:\programdata\13935234
2009-05-07 16:32 . 2009-05-07 16:38 ——– d—–w c:\users\All Users\13935234
2009-05-05 17:36 . 2008-09-10 09:36 32768 —-a-w c:\windows\system32\LXF3FXPU.DLL
2009-05-05 17:36 . 2008-04-01 01:59 45056 —-a-w c:\windows\system32\LXF3PMON.DLL
2009-05-05 17:35 . 2009-05-07 22:13 ——– d—–w c:\program files\Lexmark Fax Solutions
2009-05-05 17:35 . 2009-05-07 20:42 ——– d—–w c:\program files\Lexmark Tools for Office
2009-05-05 17:33 . 2009-05-07 20:42 ——– d—–w c:\program files\Lexmark Toolbar
2009-05-05 17:22 . 2009-05-07 21:10 ——– d—–w c:\users\Computer\AppData\Roaming\Lexmark Productivity Studio
2009-05-05 17:11 . 2009-05-05 17:11 ——– d—–w c:\users\Computer\AppData\Roaming\GTek
2009-05-05 17:05 . 2009-05-05 17:05 ——– d—–w c:\users\Computer\AppData\Local\MigWiz
2009-05-04 22:15 . 2009-05-04 22:15 ——– d—–w c:\users\Computer\AppData\Roaming\TrojanHunter
2009-05-04 22:13 . 2009-05-05 17:26 ——– d—–w c:\program files\TrojanHunter 4.7
2009-05-04 17:21 . 2009-05-04 17:35 ——– d—–w c:\users\Computer\AppData\Local\Nero
2009-05-04 17:15 . 2009-05-04 17:16 ——– d—–w c:\users\Computer\AppData\Roaming\Nero
2009-05-04 16:47 . 2009-05-04 17:32 ——– d—–w c:\program files\Nero
2009-05-04 16:47 . 2009-05-04 17:48 ——– d—–w c:\programdata\Nero
2009-05-04 16:47 . 2009-05-04 17:48 ——– d—–w c:\users\All Users\Nero
2009-05-04 16:47 . 2009-05-04 17:32 ——– d—–w c:\program files\Common Files\Nero
2009-05-04 16:19 . 2009-05-04 16:19 ——– d—–w c:\program files\Aimersoft
2009-05-04 02:21 . 2009-05-04 02:24 ——– d—–w c:\users\Computer\AppData\Roaming\Kelpiesoft Food File
2009-05-04 02:21 . 2009-05-04 02:21 ——– d—–w c:\program files\Food File
2009-05-04 00:28 . 2009-05-04 00:28 ——– d—–w c:\program files\AVI MPEG RM WMV Joiner
2009-05-03 23:35 . 2009-05-03 23:35 ——– d—–w c:\windows\system32\config\systemprofile\AppData\Roaming\Yahoo!
2009-05-03 23:25 . 2009-05-03 23:35 ——– d—–w c:\windows\system32\config\systemprofile\AppData\Roaming\GrabPro
2009-05-03 04:13 . 2009-05-03 04:13 ——– d—–w c:\users\Computer\AppData\Roaming\FairStars Audio Converter
2009-05-03 04:11 . 2009-05-05 17:26 ——– d—–w c:\program files\FairStars Audio Converter
2009-05-03 04:04 . 2009-05-03 04:04 ——– d—–w c:\programdata\AVS4YOU
2009-05-03 04:04 . 2009-05-03 04:04 ——– d—–w c:\users\All Users\AVS4YOU
2009-05-03 04:04 . 2009-05-03 04:04 ——– d—–w c:\users\Computer\AppData\Roaming\AVS4YOU
2009-05-03 04:04 . 2003-05-21 19:50 24576 —-a-w c:\windows\system32\msxml3a.dll
2009-05-02 21:47 . 2009-05-02 21:47 ——– d—–w c:\program files\Common Files\EZB Systems
2009-05-02 21:47 . 2009-05-05 17:26 ——– d—–w c:\program files\UltraISO
2009-05-02 21:14 . 2009-05-02 21:14 ——– d—–w c:\users\Public\CyberLink
2009-05-01 17:17 . 2009-05-01 17:17 ——– d—–w c:\programdata\Azureus
2009-05-01 17:17 . 2009-05-01 17:17 ——– d—–w c:\users\All Users\Azureus
2009-05-01 17:16 . 2009-05-17 13:00 ——– d—–w c:\users\Computer\AppData\Roaming\Azureus
2009-05-01 17:16 . 2009-05-01 17:16 ——– d—–w c:\program files\Vuze
2009-05-01 05:56 . 2009-05-01 05:56 ——– d—–w c:\users\Computer\AppData\Local\HP
2009-05-01 04:00 . 2009-05-01 04:00 ——– d—–w c:\program files\Common Files\xing shared
2009-05-01 04:00 . 2009-05-01 04:00 ——– d—–w c:\program files\Real
2009-05-01 04:00 . 2009-05-01 04:00 ——– d—–w c:\program files\Common Files\Real

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-19 14:16 . 2008-09-30 18:32 162164 —-a-w c:\users\All Users\nvModes.dat
2009-05-19 14:16 . 2008-09-30 18:32 162164 —-a-w c:\programdata\nvModes.dat
2009-05-18 20:55 . 2008-05-21 12:26 ——– d—–w c:\program files\Java
2009-05-13 21:33 . 2006-11-02 11:18 ——– d—–w c:\program files\Windows Mail
2009-05-11 16:13 . 2008-05-21 10:28 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-05-11 15:52 . 2009-05-11 15:52 805 —-a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-05-11 15:52 . 2009-05-11 15:52 7386 —-a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-05-11 04:07 . 2008-05-21 12:01 ——– d—–w c:\program files\Common Files\Adobe
2009-05-09 18:37 . 2001-01-01 06:12 1356 —-a-w c:\users\Computer\AppData\Local\d3d9caps.dat
2009-05-09 18:36 . 2009-04-28 23:45 484352 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-05 17:26 . 2006-11-02 12:37 ——– d—–w c:\program files\Windows Sidebar
2009-04-29 02:59 . 2006-11-02 12:37 ——– d—–w c:\program files\MSBuild
2009-03-26 15:00 . 2009-03-26 15:00 64000 —-a-w c:\windows\system32\drivers\RTSTOR.sys
2009-03-17 03:38 . 2009-04-29 02:59 13824 —-a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-29 02:59 24064 —-a-w c:\windows\system32\amxread.dll
2009-03-08 11:34 . 2007-09-05 12:15 914944 —-a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2007-09-05 12:15 43008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2007-09-05 12:15 18944 —-a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2007-09-05 12:15 109056 —-a-w c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2007-09-05 12:15 109568 —-a-w c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2007-09-05 12:15 132608 —-a-w c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2007-09-05 12:15 107520 —-a-w c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2007-09-05 12:15 107008 —-a-w c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2007-09-05 12:15 103936 —-a-w c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2007-09-05 12:15 420352 —-a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2007-09-05 12:15 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2007-09-05 12:15 71680 —-a-w c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2007-09-05 12:15 66560 —-a-w c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2007-09-05 12:15 169472 —-a-w c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2007-09-05 12:15 34816 —-a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2007-09-05 12:15 48128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2007-09-05 12:15 45568 —-a-w c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2007-09-05 12:15 156160 —-a-w c:\windows\system32\msls31.dll
2009-03-03 04:46 . 2009-04-29 02:59 3547632 —-a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:46 . 2009-04-29 02:59 3599328 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:39 . 2009-04-29 02:59 183296 —-a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-29 02:59 551424 —-a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-29 02:59 26112 —-a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-29 02:59 98304 —-a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-29 02:59 54784 —-a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-29 02:59 44032 —-a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-29 02:59 666624 —-a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-29 02:59 17408 —-a-w c:\windows\system32\iashost.exe
2008-01-21 02:43 . 2006-11-02 12:50 174 –sha-w c:\program files\desktop.ini
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\programdata\13935234 —-


—- Directory of c:\users\All Users\13935234 —-



((((((((((((((((((((((((((((( SnapShot@2009-05-18_18.21.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-05-19 04:07 51400 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-05-19 04:07 65078 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-09-30 19:07 . 2009-05-18 15:28 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-09-30 19:07 . 2009-05-19 05:31 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-09-30 19:07 . 2009-05-18 15:28 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-30 19:07 . 2009-05-19 05:31 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-30 19:07 . 2009-05-19 05:31 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-09-30 19:07 . 2009-05-18 15:28 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-09-30 19:07 . 2009-05-19 04:07 9542 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-501789590-1159742304-1750928594-1000_UserData.bin
+ 2009-05-19 04:05 . 2009-05-19 04:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-17 18:50 . 2009-05-17 18:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-17 18:50 . 2009-05-17 18:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-05-19 04:05 . 2009-05-19 04:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-05-19 04:12 595684 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-05-17 20:57 595684 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-05-17 20:57 101350 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-05-19 04:12 101350 c:\windows\System32\perfc009.dat
+ 2009-05-18 20:55 . 2009-05-18 20:55 148888 c:\windows\System32\javaws.exe
+ 2009-05-18 20:55 . 2009-05-18 20:55 144792 c:\windows\System32\javaw.exe
+ 2009-05-18 20:55 . 2009-05-18 20:55 144792 c:\windows\System32\java.exe
+ 2007-09-05 12:21 . 2009-05-19 05:31 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2007-09-05 12:21 . 2009-05-18 15:28 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-03-10 2079256]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2009-03-10 18:47 2079256 —-a-w c:\program files\BS_Player\tbBS_P.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-03-10 2079256]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-03-10 2079256]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"Xmarks"="c:\program files\Xmarks\IE Extension\xmarkssync.exe" [2009-04-22 999424]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"RegClean Expert Scheduler"="c:\program files\Registry Clean Expert\RCHelper.exe" [2009-05-12 601848]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2008-01-21 2153472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-02 468264]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 92704]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-01 198160]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2008-09-10 320168]
"lxdrmon.exe"="c:\program files\Lexmark 4900 Series\lxdrmon.exe" [2008-09-10 676520]
"lxdramon"="c:\program files\Lexmark 4900 Series\lxdramon.exe" [2008-09-10 16040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-05-12 1817600]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-18 148888]

c:\users\Computer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Anapod Manager.lnk - c:\program files\Red Chair Software\Anapod Explorer\anamgr.exe [2008-6-7 1076276]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{0FA8513C-B35D-4763-AF6A-854A922287CA}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{523FA3FA-14B4-4DC3-97D9-A5FF46106D1C}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{C3FCA21C-4D34-4616-A6EE-5A8B377D2BD3}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"TCP Query User{5CB33E97-7F0A-4ADD-AC54-A3F2947A5345}c:\\program files\\orbitdownloader\\orbitnet.exe"= UDP:c:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader
"UDP Query User{6A1479C4-B6DC-4C50-84B5-BEEBE055BDFB}c:\\program files\\orbitdownloader\\orbitnet.exe"= TCP:c:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader
"TCP Query User{AB5C7E05-5CF4-4E5A-B526-D9635FFE5B04}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{B17A0F72-57A0-4372-BECD-078B9B937555}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{D74485B2-E05E-4F1D-A1D5-EA60A47079C0}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{4CE655E6-B39C-4CEB-879D-C5E88B361098}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{7532B700-69CC-4B07-A20C-B7D1A3309422}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{19BF8AB7-9252-4028-B80C-A38751DC58A4}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{3CD35A15-E81B-443E-BA3E-9593B5E340D7}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{39D5BCE6-BF43-4783-95C9-2B1B125B3E6B}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4579BFCD-2369-4FEE-8A3C-76AB3413489B}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{4ADC50F6-6F6F-4049-8738-9F867601C46E}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts
"UDP Query User{3E61E1F9-DBFA-4D20-810E-8A7EA7722341}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts
"TCP Query User{BA8FD897-714A-4321-B216-077D9F4569BB}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{ED0E7A0A-280A-4E9C-B6D4-A77768A6009E}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"{1B4C021C-8C0A-4BB4-B395-CFB3606A2321}"= UDP:c:\program files\Lexmark 3600-4600 Series\lxdxamon.exe:Lexmark Device Monitor
"{F294B7C1-57F0-44D3-9925-A6BA8EABE174}"= TCP:c:\program files\Lexmark 3600-4600 Series\lxdxamon.exe:Lexmark Device Monitor
"{32C2EFBC-0055-4BD0-83E1-A002BFA22AE1}"= UDP:c:\program files\Lexmark 3600-4600 Series\frun.exe:Lexmark Productivity Studio
"{75B86A3C-2363-4DFD-B42C-F676A7E562B0}"= TCP:c:\program files\Lexmark 3600-4600 Series\frun.exe:Lexmark Productivity Studio
"TCP Query User{B2542884-10AE-4A0B-886A-96C4CBEBB1F2}c:\\windows\\explorer.exe"= UDP:c:\windows\explorer.exe:Windows Explorer
"UDP Query User{E168A851-DA0D-4AF5-8B26-F0FB9BB97031}c:\\windows\\explorer.exe"= TCP:c:\windows\explorer.exe:Windows Explorer
"{24B851A4-7D32-4BC5-8C27-AF7FA7D967DF}"= UDP:c:\windows\System32\lxdrcoms.exe:Lexmark Communications System
"{FECCCAF1-8041-4043-95E2-92A94E49F4C5}"= TCP:c:\windows\System32\lxdrcoms.exe:Lexmark Communications System
"{B9DAC796-9920-4858-B9F0-0ED9A2DD753B}"= UDP:c:\program files\Lexmark 4900 Series\lxdramon.exe:Lexmark Device Monitor
"{F56BC95C-E50F-4822-98A9-9FED8E7F7A58}"= TCP:c:\program files\Lexmark 4900 Series\lxdramon.exe:Lexmark Device Monitor
"{2AA7AA2F-74E2-4516-9CCD-A115456B186B}"= UDP:c:\program files\Lexmark 4900 Series\frun.exe:Lexmark Productivity Studio
"{DDD709D8-CED0-470D-8745-BFB819ED16CA}"= TCP:c:\program files\Lexmark 4900 Series\frun.exe:Lexmark Productivity Studio
"{315BA571-D90F-47F3-B9AD-C2400872C332}"= UDP:c:\program files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader
"{174ED0C9-ED69-4E91-ADB2-9640ACEF19CE}"= TCP:c:\program files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader
"{0B7B4B34-C86B-4AF3-B5A6-FA46A07034FE}"= UDP:c:\program files\Lexmark Fax Solutions\FaxCtr.exe:Fax software
"{BCCCFB60-D4EF-4D6A-B0EA-BB925FFE848C}"= TCP:c:\program files\Lexmark Fax Solutions\FaxCtr.exe:Fax software
"{2D579BFF-A8E7-4A01-AC63-350F166142BF}"= Disabled:UDP:c:\program files\Red Chair Software\Anapod Explorer\anamgr.exe:Anapod Xtreamer
"{2468CA57-10B9-45EC-BE16-4B0FD0914C11}"= Disabled:TCP:c:\program files\Red Chair Software\Anapod Explorer\anamgr.exe:Anapod Xtreamer
"{B0941A98-684F-40D3-B156-FBE3D8E76CFC}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"= c:\program files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"= c:\program files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit

R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\N360\0300000.087\SymEFA.sys [5/11/2009 8:52 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\N360\0300000.087\BHDrvx86.sys [5/11/2009 8:52 AM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\N360\0300000.087\cchpx86.sys [5/11/2009 8:52 AM 482352]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090508.002\IDSvix86.sys [5/11/2009 8:59 AM 292912]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\System32\drivers\sp_rsdrv2.sys [5/12/2009 8:19 AM 141312]
R2 lxdr_device;lxdr_device;c:\windows\system32\lxdrcoms.exe -service –> c:\windows\system32\lxdrcoms.exe -service [?]
R2 lxdrCATSCustConnectService;lxdrCATSCustConnectService;c:\windows\System32\spool\drivers\w32x86\3\lxdrserv.exe [5/16/2008 8:39 AM 98984]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe [5/11/2009 8:52 AM 115560]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [5/21/2008 5:20 AM 361808]
R2 YahooAUService;Yahoo! Updater;c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe [11/9/2008 1:48 PM 602392]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/11/2009 8:52 AM 101936]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [5/3/2008 5:39 AM 42528]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\N360\0300000.087\symndisv.sys [5/11/2009 8:52 AM 39984]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [5/21/2008 3:56 AM 193840]
S3 DsAudioDevice_310;DsAudioDevice_310;c:\windows\System32\drivers\DsAudioDevice_310.sys [4/29/2009 9:52 AM 16640]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder

2009-05-19 c:\windows\Tasks\NeroLiveEpgUpdate-Computer-PC_Computer.job
- c:\program files\Nero\Nero 9\Nero Live\NeroLive.exe [2008-09-18 20:51]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.aol.com/
IE: &Download; by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab; video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Crawler Search - tbr:iemenu
IE: Do&wnload; selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load; all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\wp0x49j0.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;=
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\wp0x49j0.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\wp0x49j0.default\extensions\[removed]\plugins\npTVUAx.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-19 07:28
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.0.0.135\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-501789590-1159742304-1750928594-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\L*i*n*k*s* \Microsoft Websites]
"Order"=hex:08,00,00,00,02,00,00,00,f6,02,00,00,01,00,00,00,06,00,00,00,78,00,
00,00,00,00,00,00,6a,00,32,00,cd,00,00,00,00,0b,ae,1f,20,00,49,45,41,44,44,\

[HKEY_USERS\S-1-5-21-501789590-1159742304-1750928594-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\L*i*n*k*s* \Microsoft Websites]
"Order"=hex:08,00,00,00,02,00,00,00,f6,02,00,00,01,00,00,00,06,00,00,00,78,00,
00,00,00,00,00,00,6a,00,32,00,cd,00,00,00,00,5c,79,6c,20,00,49,45,41,44,44,\

[HKEY_USERS\S-1-5-21-501789590-1159742304-1750928594-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\W*i*n*d*o*w*s* *L*i*v*e* \HP]
"Order"=hex:08,00,00,00,02,00,00,00,e4,07,00,00,01,00,00,00,10,00,00,00,6e,00,
00,00,06,00,00,00,60,00,31,00,00,00,00,00,00,30,ef,2b,10,00,4d,4f,5a,49,4c,\

[HKEY_USERS\S-1-5-21-501789590-1159742304-1750928594-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\W*i*n*d*o*w*s* *L*i*v*e* \HP\Mozilla Firefox]
"Order"=hex:08,00,00,00,02,00,00,00,ea,01,00,00,01,00,00,00,04,00,00,00,6c,00,
00,00,00,00,00,00,5e,00,32,00,cd,00,00,00,00,9f,8f,fb,20,00,41,42,4f,55,54,\

[HKEY_USERS\S-1-5-21-501789590-1159742304-1750928594-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\W*i*n*d*o*w*s* *L*i*v*e* \HP\MSN Websites]
"Order"=hex:08,00,00,00,02,00,00,00,a2,02,00,00,01,00,00,00,06,00,00,00,5c,00,
00,00,04,00,00,00,4e,00,32,00,cd,00,00,00,00,b3,01,2e,20,00,4d,53,4e,2e,75,\

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-05-19 7:30
ComboFix-quarantined-files.txt 2009-05-19 14:30
ComboFix2.txt 2009-05-19 04:18
ComboFix3.txt 2009-05-18 20:49
ComboFix4.txt 2009-05-18 20:39

Pre-Run: 85,325,246,464 bytes free
Post-Run: 85,278,359,552 bytes free

408 — E O F — 2009-05-13 22:09
Upload was successful


Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI