This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Trojandownloader:Win32/Renos.IO

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi i am also haveing this problem. my norton 360 will not scan anything and i can't seem to get rid of it. I did the DDS and gmer. they will be listed below.

DDS (Ver_09-05-14.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 4/10/2006 1:47:26 AM
System Uptime: 6/19/2009 9:42:20 AM (4 hours ago)

Motherboard: Quanta | | 30B7
Processor: AMD Turion™ 64 X2 Mobile Technology TL-56 | Socket S1 | 1600/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 141 GiB total, 102.143 GiB free.
D: is FIXED (NTFS) - 8 GiB total, 5.774 GiB free.
E: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================


==== Installed Programs ======================

AccessMV
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.1.2
GEAR driver installer for x86 and x64
GearDrvs
Google Toolbar for Internet Explorer
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
ImagXpress
LightScribe System Software
Microsoft .NET Framework 3.5 SP1
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP2 (KB954430)
neroxml
Norton 360
Norton Internet Security
NVIDIA Drivers
Xvid 1.2.1 final uninstall

==== End Of File ===========================



============== Pseudo HJT Report ===============

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.0.0.134\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.0.0.134\IPSBHO.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.0.0.134\coIEPlg.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [ColdWare] c:\windows\temp\278932611.tmp.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 85.255.112.143,85.255.112.203
TCP: {73DB8B95-2CB3-418D-A989-1DA3BB4AA4AF} = 85.255.112.143,85.255.112.203
TCP: {A6B4EBB5-F746-4D61-ACAC-203572C56B3B} = 85.255.112.143,85.255.112.203
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.0.0.134\CoIEPlg.dll

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0300000.086\SymEFA.sys [2009-6-17 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0300000.086\BHDrvx86.sys [2009-6-17 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0300000.086\cchpx86.sys [2009-6-17 482352]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090618.002\IDSvix86.sys [2009-6-19 292912]
R2 N360;Norton 360;c:\program files\norton 360\engine\3.0.0.134\ccSvcHst.exe [2009-6-17 115560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-6-17 101936]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0300000.086\symndisv.sys [2009-6-17 39984]
S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\nbservice.exe –> c:\program files\common files\nero\nero backitup 4\NBService.exe [?]

=============== Created Last 30 ================

2009-06-19 13:30 431 a——- C:\spyhunter.fix
2009-06-19 13:29 –d—– c:\program files\Enigma Software Group
2009-06-17 17:39 107,368 a——- c:\windows\system32\GEARAspi.dll
2009-06-17 17:39 23,848 a——- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-17 17:39 –d—– c:\programdata\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-06-17 17:39 –d—– c:\progra~2\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-06-17 17:39 25,136 a—-r– c:\windows\system32\drivers\SymIMV.sys
2009-06-17 17:39 124,464 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-06-17 17:39 7,386 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2009-06-17 17:39 805 a——- c:\windows\system32\drivers\SYMEVENT.INF
2009-06-17 17:39 –d—– c:\program files\Symantec
2009-06-17 17:38 –d—– c:\windows\system32\drivers\N360
2009-06-17 17:38 –d—– c:\program files\Norton 360
2009-06-17 17:38 –d—– c:\programdata\Norton
2009-06-17 17:38 –d—– c:\progra~2\Norton
2009-06-17 17:37 –d—– c:\programdata\NortonInstaller
2009-06-17 17:37 –d—– c:\program files\NortonInstaller
2009-06-17 17:37 –d—– c:\progra~2\NortonInstaller
2009-06-15 22:18 –d—– c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP
2009-06-14 19:16 –d—– c:\windows\system32\N360_BACKUP
2009-06-14 18:08 –d—– c:\programdata\Adobe
2009-06-14 18:07 –d—– c:\programdata\Google
2009-06-14 18:07 –d—– c:\programdata\NOS
2009-06-14 14:29 1,905 a——- c:\windows\diagwrn.xml
2009-06-14 14:29 1,905 a——- c:\windows\diagerr.xml
2009-06-14 12:25 –d—– c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-06-14 12:25 –d—– c:\progra~2\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-06-14 12:03 –d—– c:\users\unbrel~1\appdata\roaming\Symantec
2009-06-14 11:53 –d—– c:\programdata\Symantec
2009-06-14 11:53 –d—– c:\progra~2\Symantec
2009-06-14 11:53 –d—– c:\program files\common files\Symantec Shared
2009-06-12 16:12 –d—– c:\program files\AccessMV
2009-06-11 17:39 2,033,152 a——- c:\windows\system32\win32k.sys
2009-06-09 11:44 29,169 a——- c:\programdata\nvModes.dat
2009-06-09 11:44 29,169 a——- c:\progra~2\nvModes.dat
2009-06-07 23:04 –d—– c:\program files\MSXML 4.0
2009-06-07 09:15 815,104 a——- c:\windows\system32\xvidcore.dll
2009-06-07 09:15 180,224 a——- c:\windows\system32\xvidvfw.dll
2009-06-07 09:15 77,824 a——- c:\windows\system32\xvid.ax
2009-06-07 09:15 –d—– c:\program files\Xvid
2009-06-07 01:00 –d—– c:\programdata\LightScribe
2009-06-07 01:00 –d—– c:\progra~2\LightScribe
2009-06-06 23:47 39 a——- c:\windows\Irremote.ini
2009-06-06 23:36 –d—– c:\program files\Nero
2009-06-06 23:35 –d—– c:\programdata\Nero
2009-06-06 23:35 –d—– c:\progra~2\Nero
2009-06-06 23:35 1,315,328 a——- c:\windows\system32\ole32.dll
2009-06-06 22:41 –d—– c:\programdata\NVIDIA
2009-06-06 20:24 2,048 a——- c:\windows\system32\tzres.dll
2009-06-06 20:18 873,310 a——- c:\windows\system32\oem8.inf
2009-06-06 20:10 1,079,840 a——- c:\windows\system32\nvcpluir.dll
2009-06-06 20:10 768,544 a——- c:\windows\system32\nvcplui.exe
2009-06-06 20:10 420,384 a——- c:\windows\system32\nvcpl.cpl
2009-06-06 20:10 313,888 a——- c:\windows\system32\nvexpbar.dll
2009-06-06 20:05 –dsh— c:\windows\Installer
2009-06-06 20:00 105,016 a——- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-06 20:00 97,800 a——- c:\windows\system32\infocardapi.dll
2009-06-06 20:00 37,384 a——- c:\windows\system32\infocardcpl.cpl
2009-06-06 20:00 622,080 a——- c:\windows\system32\icardagt.exe
2009-06-06 20:00 43,544 a——- c:\windows\system32\PresentationHostProxy.dll
2009-06-06 20:00 11,264 a——- c:\windows\system32\icardres.dll
2009-06-06 20:00 781,344 a——- c:\windows\system32\PresentationNative_v0300.dll
2009-06-06 20:00 326,160 a——- c:\windows\system32\PresentationHost.exe
2009-06-06 19:51 96,760 a——- c:\windows\system32\dfshim.dll
2009-06-06 19:51 282,112 a——- c:\windows\system32\mscoree.dll
2009-06-06 19:51 41,984 a——- c:\windows\system32\netfxperf.dll
2009-06-06 19:50 158,720 a——- c:\windows\system32\mscorier.dll
2009-06-06 19:50 83,968 a——- c:\windows\system32\mscories.dll
2009-06-06 19:46 303,616 a——- c:\windows\system32\wmpeffects.dll
2009-06-06 19:46 19,000 a——- c:\windows\system32\kd1394.dll
2009-06-06 19:46 988,216 a——- c:\windows\system32\winload.exe
2009-06-06 19:46 927,288 a——- c:\windows\system32\winresume.exe
2009-06-06 19:46 615,992 a——- c:\windows\system32\ci.dll
2009-06-06 19:46 378,368 a——- c:\windows\system32\srcore.dll
2009-06-06 19:46 318,464 a——- c:\windows\system32\rstrui.exe
2009-06-06 19:46 46,592 a——- c:\windows\system32\setbcdlocale.dll
2009-06-06 19:46 40,960 a——- c:\windows\system32\srclient.dll
2009-06-06 19:46 14,848 a——- c:\windows\system32\srdelayed.exe
2009-06-06 19:46 6,656 a——- c:\windows\system32\kbd106n.dll
2009-06-06 19:46 1,314,816 a——- c:\windows\system32\quartz.dll
2009-06-06 19:45 12,240,896 a——- c:\windows\system32\NlsLexicons0007.dll
2009-06-06 19:45 2,644,480 a——- c:\windows\system32\NlsLexicons0009.dll
2009-06-06 19:45 801,280 a——- c:\windows\system32\NaturalLanguage6.dll
2009-06-06 19:43 3,903 a——- c:\windows\system32\nvnrm.nvu
2009-06-06 19:43 428,544 a——- c:\windows\system32\EncDec.dll
2009-06-06 19:43 217,088 a——- c:\windows\system32\psisrndr.ax
2009-06-06 19:43 293,376 a——- c:\windows\system32\psisdecd.dll
2009-06-06 19:43 177,664 a——- c:\windows\system32\mpg2splt.ax
2009-06-06 19:43 80,896 a——- c:\windows\system32\MSNP.ax
2009-06-06 19:43 57,856 a——- c:\windows\system32\MSDvbNP.ax
2009-06-06 19:42 356,352 a——- c:\windows\system32\nvusmu.exe
2009-06-06 19:42 528 a——- c:\windows\system32\nvsmu.nvu
2009-06-06 19:40 2,868,736 a——- c:\windows\system32\mf.dll
2009-06-06 19:34 –d—– c:\users\unbrel~1\appdata\roaming\uTorrent
2009-06-06 19:31 1,334,272 a——- c:\windows\system32\msxml6.dll
2009-06-06 19:25 –d—– c:\users\UNBRELLA COPORATION
2009-06-06 19:25 1,524,736 a——- c:\windows\system32\wucltux.dll
2009-06-06 19:24 83,456 a——- c:\windows\system32\wudriver.dll
2009-06-06 19:24 162,064 a——- c:\windows\system32\wuwebv.dll
2009-06-06 19:24 31,232 a——- c:\windows\system32\wuapp.exe

==================== Find3M ====================

2009-06-17 17:39 86,016 a——- c:\windows\inf\infstrng.dat
2009-06-17 17:39 86,016 a——- c:\windows\inf\infstor.dat
2009-06-17 17:39 51,200 a——- c:\windows\inf\infpub.dat
2009-06-06 22:35 665,600 a——- c:\windows\inf\drvindex.dat
2009-04-24 09:05 827,904 a——- c:\windows\system32\wininet.dll
2009-04-24 09:02 78,336 a——- c:\windows\system32\ieencode.dll
2009-04-24 06:44 26,624 a——- c:\windows\system32\ieUnatt.exe
2009-04-23 05:43 784,896 a——- c:\windows\system32\rpcrt4.dll
2009-04-23 05:42 636,928 a——- c:\windows\system32\localspl.dll
2008-01-20 19:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 13:42:14.87 ===============



GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-19 14:03:13
Windows 6.0.6001 Service Pack 1


—- System - GMER 1.0.15 —-

Code 8BA58308 ZwEnumerateKey
Code 8B0BB130 ZwFlushInstructionCache
Code 8BA5B2ED IofCallDriver
Code 8BA5C2BE IofCompleteRequest

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\tdx \Device\Ip SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\RawIp SYMTDI.SYS

—- Services - GMER 1.0.15 —-

Service C:\Windows\system32\drivers\MSIVXenxienqyhrcvpuwtdxbxoqmqxrempxcn.sys (*** hidden *** ) [SYSTEM] MSIVXserv.sys <– ROOTKIT !!!

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:

Please download ComboFix from Here or Here to your Desktop.
**Note:  In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    [external image: Posted Image]

    [external image: Posted Image]
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.  
  • Please post the "C:\Combo-Fix.txt" for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
ok thank you for the help here is the log.


ComboFix 09-06-22.04 - UNBRELLA COPORATION 06/22/2009 17:51.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.958.179 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-507921405-630328440-839522115-1003
c:\recycler\S-1-5-21-507921405-630328440-839522115-1003\desktop.ini
c:\recycler\S-1-5-21-507921405-630328440-839522115-1003\INFO2
c:\windows\system32\drivers\MSIVXenxienqyhrcvpuwtdxbxoqmqxrempxcn.sys
c:\windows\system32\MSIVXbsrnwubxdgtdgqqfneeelflbpafjuiws.dll
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXxmidnkopvlidrjtpslvekuktmqsabcev.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_MSIVXserv.sys


((((((((((((((((((((((((( Files Created from 2009-05-23 to 2009-06-23 )))))))))))))))))))))))))))))))
.

2009-06-23 00:57 . 2009-06-23 00:58 ——– d—–w- c:\users\UNBRELLA COPORATION\AppData\Local\temp
2009-06-19 20:29 . 2009-06-19 20:30 ——– d—–w- c:\program files\Enigma Software Group
2009-06-18 00:39 . 2009-01-15 19:19 23848 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-18 00:39 . 2008-04-17 19:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-06-18 00:39 . 2009-06-18 00:39 ——– d—–w- c:\progra~2\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-06-18 00:39 . 2009-06-18 00:39 ——– d—–w- c:\users\UNBRELLA COPORATION\AppData\Local\Downloaded Installations
2009-06-18 00:39 . 2009-06-18 00:39 25136 —-a-r- c:\windows\system32\drivers\SymIMV.sys
2009-06-18 00:39 . 2009-06-18 00:39 124464 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-06-18 00:39 . 2009-06-18 00:39 ——– d—–w- c:\program files\Symantec
2009-06-18 00:38 . 2009-06-18 00:38 ——– d—–w- c:\windows\system32\drivers\N360
2009-06-18 00:38 . 2009-06-18 00:39 ——– d—–w- c:\program files\Norton 360
2009-06-18 00:38 . 2009-06-18 00:40 ——– d—–w- c:\progra~2\Norton
2009-06-18 00:37 . 2009-06-18 00:37 ——– d—–w- c:\program files\NortonInstaller
2009-06-18 00:37 . 2009-06-18 00:37 ——– d—–w- c:\progra~2\NortonInstaller
2009-06-16 06:26 . 2009-06-16 06:26 ——– d—–w- c:\users\UNBRELLA COPORATION\AppData\Local\Symantec
2009-06-16 05:18 . 2009-06-16 05:18 ——– d—–w- c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP
2009-06-15 02:16 . 2009-06-15 02:16 ——– d—–w- c:\windows\system32\N360_BACKUP
2009-06-15 01:21 . 2009-06-15 01:48 ——– d—–w- c:\users\UNBRELLA COPORATION\AppData\Local\Google
2009-06-15 01:10 . 2009-06-15 01:10 ——– d—–w- c:\program files\Common Files\Adobe
2009-06-15 01:08 . 2009-02-12 09:35 38208 —-a-w- c:\users\UNBRELLA COPORATION\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-06-15 01:08 . 2009-06-15 01:08 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-06-15 01:07 . 2009-06-17 02:59 ——– d—–w- c:\users\UNBRELLA COPORATION\AppData\Local\Adobe
2009-06-15 01:07 . 2009-06-15 01:07 ——– d—–w- c:\program files\Google
2009-06-15 01:07 . 2009-06-15 02:46 ——– d—–w- c:\program files\NOS
2009-06-15 01:07 . 2009-06-15 02:46 ——– d—–w- c:\progra~2\NOS
2009-06-14 19:25 . 2009-06-18 00:39 ——– dc—-w- c:\windows\system32\DRVSTORE
2009-06-14 19:25 . 2009-06-14 19:25 ——– d—–w- c:\progra~2\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-06-14 19:03 . 2009-06-18 00:11 ——– d—–w- c:\users\UNBRELLA COPORATION\AppData\Roaming\Symantec
2009-06-14 18:53 . 2009-06-18 00:38 ——– d—–w- c:\progra~2\Symantec
2009-06-14 18:53 . 2009-06-18 00:39 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-12 23:12 . 2009-06-12 23:12 ——– d—–w- c:\program files\AccessMV
2009-06-12 00:39 . 2009-04-21 11:55 2033152 —-a-w- c:\windows\system32\win32k.sys
2009-06-08 06:04 . 2009-06-08 06:04 ——– d—–w- c:\program files\MSXML 4.0
2009-06-07 16:15 . 2009-06-07 16:15 ——– d—–w- c:\program files\Xvid
2009-06-07 16:15 . 2008-12-05 04:46 180224 —-a-w- c:\windows\system32\xvidvfw.dll
2009-06-07 16:15 . 2008-12-05 04:42 815104 —-a-w- c:\windows\system32\xvidcore.dll
2009-06-07 16:12 . 2009-06-07 16:12 ——– d—–w- c:\users\UNBRELLA COPORATION\AppData\Local\Nero
2009-06-07 08:00 . 2009-06-07 08:00 ——– d—–w- c:\progra~2\LightScribe
2009-06-07 08:00 . 2009-06-07 08:00 ——– d—–w- c:\users\UNBRELLA COPORATION\AppData\Roaming\Nero
2009-06-07 06:36 . 2009-06-16 05:24 ——– d—–w- c:\program files\Nero
2009-06-07 06:35 . 2009-06-16 05:31 ——– d—–w- c:\program files\Common Files\Nero
2009-06-07 06:35 . 2009-06-16 05:31 ——– d—–w- c:\progra~2\Nero
2009-06-07 06:35 . 2008-08-20 03:33 1315328 —-a-w- c:\windows\system32\ole32.dll
2009-06-07 06:33 . 2009-06-07 06:33 ——– d—–w- c:\program files\Common Files\LightScribe
2009-06-07 05:41 . 2009-06-07 05:42 ——– d—–w- c:\progra~2\NVIDIA
2009-06-07 03:24 . 2008-10-22 01:22 2048 —-a-w- c:\windows\system32\tzres.dll
2009-06-07 03:10 . 2008-12-04 09:42 768544 —-a-w- c:\windows\system32\nvcplui.exe
2009-06-07 03:10 . 2008-12-04 09:42 313888 —-a-w- c:\windows\system32\nvexpbar.dll
2009-06-07 03:10 . 2008-12-04 09:42 1079840 —-a-w- c:\windows\system32\nvcpluir.dll
2009-06-07 03:05 . 2009-06-18 00:39 ——– d-sh–w- c:\windows\Installer
2009-06-07 03:00 . 2008-06-20 01:14 105016 —-a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-07 03:00 . 2008-06-20 01:14 97800 —-a-w- c:\windows\system32\infocardapi.dll
2009-06-07 03:00 . 2008-06-20 01:14 43544 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2009-06-07 03:00 . 2008-06-20 01:14 11264 —-a-w- c:\windows\system32\icardres.dll
2009-06-07 03:00 . 2008-06-20 01:14 622080 —-a-w- c:\windows\system32\icardagt.exe
2009-06-07 03:00 . 2008-06-20 01:14 781344 —-a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-06-07 03:00 . 2008-06-20 01:14 326160 —-a-w- c:\windows\system32\PresentationHost.exe
2009-06-07 02:51 . 2009-06-07 02:51 ——– d—–w- c:\windows\system32\Macromed
2009-06-07 02:51 . 2008-07-27 18:03 96760 —-a-w- c:\windows\system32\dfshim.dll
2009-06-07 02:51 . 2008-07-27 18:03 282112 —-a-w- c:\windows\system32\mscoree.dll
2009-06-07 02:51 . 2008-07-27 18:03 41984 —-a-w- c:\windows\system32\netfxperf.dll
2009-06-07 02:50 . 2008-07-27 18:03 158720 —-a-w- c:\windows\system32\mscorier.dll
2009-06-07 02:50 . 2008-07-27 18:03 83968 —-a-w- c:\windows\system32\mscories.dll
2009-06-07 02:46 . 2008-06-26 03:29 303616 —-a-w- c:\windows\system32\wmpeffects.dll
2009-06-07 02:46 . 2008-02-29 07:14 19000 —-a-w- c:\windows\system32\kd1394.dll
2009-06-07 02:46 . 2008-02-29 07:11 927288 —-a-w- c:\windows\system32\winresume.exe
2009-06-07 02:46 . 2008-02-29 07:11 988216 —-a-w- c:\windows\system32\winload.exe
2009-06-07 02:46 . 2008-02-22 05:05 615992 —-a-w- c:\windows\system32\ci.dll
2009-06-07 02:46 . 2008-02-29 06:53 378368 —-a-w- c:\windows\system32\srcore.dll
2009-06-07 02:46 . 2008-02-29 06:53 40960 —-a-w- c:\windows\system32\srclient.dll
2009-06-07 02:46 . 2008-02-29 06:53 46592 —-a-w- c:\windows\system32\setbcdlocale.dll
2009-06-07 02:46 . 2008-02-29 06:35 6656 —-a-w- c:\windows\system32\kbd106n.dll
2009-06-07 02:46 . 2008-02-29 04:12 318464 —-a-w- c:\windows\system32\rstrui.exe
2009-06-07 02:46 . 2008-02-29 04:12 14848 —-a-w- c:\windows\system32\srdelayed.exe
2009-06-07 02:46 . 2008-04-26 08:08 1314816 —-a-w- c:\windows\system32\quartz.dll
2009-06-07 02:45 . 2008-06-26 01:45 12240896 —-a-w- c:\windows\system32\NlsLexicons0007.dll
2009-06-07 02:45 . 2008-06-26 01:45 2644480 —-a-w- c:\windows\system32\NlsLexicons0009.dll
2009-06-07 02:45 . 2008-06-26 03:29 801280 —-a-w- c:\windows\system32\NaturalLanguage6.dll
2009-06-07 02:43 . 2008-12-05 04:32 428544 —-a-w- c:\windows\system32\EncDec.dll
2009-06-07 02:43 . 2008-12-05 04:32 293376 —-a-w- c:\windows\system32\psisdecd.dll
2009-06-07 02:42 . 2007-02-14 16:55 356352 —-a-w- c:\windows\system32\nvusmu.exe
2009-06-07 02:40 . 2008-06-23 01:59 2868736 —-a-w- c:\windows\system32\mf.dll
2009-06-07 02:34 . 2009-06-16 03:59 ——– d—–w- c:\users\UNBRELLA COPORATION\AppData\Roaming\uTorrent
2009-06-07 02:31 . 2008-09-10 03:40 1334272 —-a-w- c:\windows\system32\msxml6.dll
2009-06-07 02:26 . 2009-06-13 06:32 51704 —-a-w- c:\users\UNBRELLA COPORATION\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-07 02:26 . 2009-06-19 20:03 ——– d—–w- c:\users\UNBRELLA COPORATION\AppData\Local\VirtualStore
2009-06-07 02:26 . 2009-06-07 02:29 680 —-a-w- c:\users\UNBRELLA COPORATION\AppData\Local\d3d9caps.dat
2009-06-07 02:24 . 2008-10-16 21:12 561688 —-a-w- c:\windows\system32\wuapi.dll
2009-06-07 02:24 . 2008-10-16 21:08 34328 —-a-w- c:\windows\system32\wups.dll
2009-06-07 02:24 . 2008-10-16 20:55 83456 —-a-w- c:\windows\system32\wudriver.dll
2009-06-07 02:24 . 2008-10-16 21:08 162064 —-a-w- c:\windows\system32\wuwebv.dll
2009-06-07 02:24 . 2008-10-16 20:56 31232 —-a-w- c:\windows\system32\wuapp.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-23 00:26 . 2009-06-09 18:44 29169 —-a-w- c:\progra~2\nvModes.dat
2009-06-19 21:03 . 2009-06-19 21:03 1364 —-a-w- c:\program files\gmer.txt
2009-06-18 00:39 . 2009-06-18 00:39 805 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-06-18 00:39 . 2009-06-18 00:39 7386 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-06-14 22:54 . 2006-11-02 12:37 ——– d—–w- c:\program files\Microsoft Games
2009-06-07 05:35 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-06-07 05:35 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-06-07 02:41 . 2009-06-07 02:41 ——– d—–w- c:\users\UNBRELLA COPORATION\AppData\Roaming\InstallShield
2009-04-24 16:05 . 2009-06-12 00:38 827904 —-a-w- c:\windows\system32\wininet.dll
2009-04-24 16:02 . 2009-06-12 00:38 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-24 13:44 . 2009-06-12 00:38 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-04-23 12:43 . 2009-06-12 00:38 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-12 00:38 636928 —-a-w- c:\windows\system32\localspl.dll
.

——- Sigcheck ——-

[7] 2008-01-21 02:23 21504 3794B461C45882E06856F282EEF025AF c:\windows\System32\svchost.exe
[7] 2008-01-21 02:23 21504 3794B461C45882E06856F282EEF025AF c:\windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe

[7] 2008-01-21 02:24 627200 B974D9F06DC7D1908E825DC201681269 c:\windows\System32\user32.dll
[7] 2008-01-21 02:24 627200 B974D9F06DC7D1908E825DC201681269 c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll

[7] 2008-01-21 02:24 179200 B304D47D5744BA20FCB99FB8B2C07B0B c:\windows\System32\ws2_32.dll
[7] 2008-01-21 02:24 179200 B304D47D5744BA20FCB99FB8B2C07B0B c:\windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6001.18000_none_f2b7b0c2ce5605c4\ws2_32.dll

[7] 2009-04-24 16:05 827904 64EAF7CF461A15DB4EAEB1D50A10E88E c:\windows\System32\wininet.dll
[7] 2009-03-03 04:20 826368 BA68744F8FE1BAAC35362F18774972A3 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16830_none_ffe248dfa4c4cf16\wininet.dll
[7] 2009-04-24 16:22 827392 D94BDEEF2E47EB4A46B957253C697F01 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16851_none_ffcda951a4d4204f\wininet.dll
[7] 2009-03-03 04:18 828416 88B57405AC5B2BF513069086F8963635 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.21023_none_00798e96bdd7d236\wininet.dll
[7] 2009-04-24 16:01 828928 E7D90AF9B0C7FA98DF353E022EE1C63E c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.21046_none_0066ef9cbde5561d\wininet.dll
[7] 2008-01-21 02:24 825856 455D715A840579BDC1CF8E5C1DA76849 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18000_none_01e8f37da1d311e6\wininet.dll
[7] 2009-03-03 04:40 827392 6E115E2D3FAE5077A361A5BCE78FF170 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18226_none_01d9592da1dddc20\wininet.dll
[7] 2009-04-24 16:05 827904 64EAF7CF461A15DB4EAEB1D50A10E88E c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18248_none_01c5b9e9a1ec46b0\wininet.dll
[7] 2009-03-03 04:32 827904 3ED9859939928CA568F487AB42175A33 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22389_none_0225174ebb296f95\wininet.dll
[7] 2009-04-24 16:00 828416 77C60DD61D21777734B1C945540473A4 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22418_none_026fc85ebaf18fce\wininet.dll
[7] 2009-04-23 12:15 828416 24CBE22F35941FBFD6144A5C011EA999 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18024_none_03bdcc679f05fbbd\wininet.dll
[7] 2009-04-24 15:43 828416 07DBFC0759F61E95901AF2B2D4E83451 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.22121_none_04446854b8264f82\wininet.dll

[7] 2008-04-26 08:26 891448 82E266BEE5F0167E41C6ECFDD2A79C02 c:\windows\System32\drivers\tcpip.sys
[7] 2008-01-21 02:25 891448 FC6E2835D667774D409C7C7021EAF9C4 c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18000_none_b31e1252666640f6\tcpip.sys
[7] 2008-04-26 08:26 891448 82E266BEE5F0167E41C6ECFDD2A79C02 c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.18063_none_b2e033a8669434a1\tcpip.sys
[7] 2008-04-26 08:08 891448 01EC1E92595F839BEE70D439C46796E3 c:\windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22167_none_b36dd19b7fae39c7\tcpip.sys

[7] 2008-01-21 02:24 314880 C2610B6BDBEFC053BBDAB4F1B965CB24 c:\windows\System32\winlogon.exe
[7] 2008-01-21 02:24 314880 C2610B6BDBEFC053BBDAB4F1B965CB24 c:\windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

[7] 2008-01-21 02:23 529464 9BDC71790FA08F0A0B5F10462B1BD0B1 c:\windows\System32\drivers\ndis.sys
[7] 2008-01-21 02:23 529464 9BDC71790FA08F0A0B5F10462B1BD0B1 c:\windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.18000_none_a7c72bc71c0f0d18\ndis.sys


[7] 2009-03-03 04:46 3599328 FEB3FB3309EBA85917BDE7F4FD019C9D c:\windows\System32\ntkrnlpa.exe
[7] 2009-03-03 04:24 3503584 06BCF21AAA1890328D1F58F0ACBE668D c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16830_none_6a29b702b714cf98\ntkrnlpa.exe
[7] 2009-03-03 04:22 3505120 191C702B48681FB2BA5A96F416207ACF c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.21023_none_6ac0fcb9d027d2b8\ntkrnlpa.exe
[7] 2008-01-21 02:24 3600440 FE51E8DBBEF2D01EF886499FECBF2D78 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18000_none_6c3061a0b4231268\ntkrnlpa.exe
[7] 2008-04-26 08:25 3600952 6BB1994F5B62FEF6268F1EBB4014E293 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18063_none_6bf282f6b4510613\ntkrnlpa.exe
[7] 2009-03-03 04:46 3599328 FEB3FB3309EBA85917BDE7F4FD019C9D c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18226_none_6c20c750b42ddca2\ntkrnlpa.exe
[7] 2008-04-26 08:11 3601464 68EEF02A8846442FE98AD0E0517EE6BC c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22167_none_6c8020e9cd6b0b39\ntkrnlpa.exe
[7] 2009-03-03 04:37 3600880 641C0F376136E5B6F389016EC48374D2 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22389_none_6c6c8571cd797017\ntkrnlpa.exe

[7] 2009-03-03 04:46 3547632 393BB8FE05D66ABA7B091E6032179272 c:\windows\System32\ntoskrnl.exe
[7] 2009-03-03 04:24 3469280 3910FE042C707E6BACD0FEC5AB9ECDE6 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16830_none_6a29b702b714cf98\ntoskrnl.exe
[7] 2009-03-03 04:22 3471328 808C86316AED98716C5F305A6265F393 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.21023_none_6ac0fcb9d027d2b8\ntoskrnl.exe
[7] 2008-01-21 02:24 3548728 6700F35EBA206E5C89AC27C9A124DC01 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18000_none_6c3061a0b4231268\ntoskrnl.exe
[7] 2008-04-26 08:25 3549240 C9CD31B3CBA8134F2B47FB5E78376ACC c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18063_none_6bf282f6b4510613\ntoskrnl.exe
[7] 2009-03-03 04:46 3547632 393BB8FE05D66ABA7B091E6032179272 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18226_none_6c20c750b42ddca2\ntoskrnl.exe
[7] 2008-04-26 08:11 3549240 22D444D3D88A4C299894B3638A114BF7 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22167_none_6c8020e9cd6b0b39\ntoskrnl.exe
[7] 2009-03-03 04:37 3548656 DFF34C5D66AB4BF1EED47BF19D1267BB c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22389_none_6c6c8571cd797017\ntoskrnl.exe

[7] 2008-10-29 06:29 2927104 4F554999D7D5F05DAAEBBA7B5BA1089D c:\windows\explorer.exe
[7] 2008-10-29 06:20 2923520 37440D09DEAE0B672A04DCCF7ABF06BE c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[7] 2008-10-28 02:15 2923520 E7156B0B74762D9DE0E66BDCDE06E5FB c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[7] 2008-01-21 02:24 2927104 FFA764631CB70A30065C12EF8E174F9F c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
[7] 2008-10-29 06:29 2927104 4F554999D7D5F05DAAEBBA7B5BA1089D c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[7] 2008-10-30 03:59 2927616 50BA5850147410CDE89C523AD3BC606E c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe

[7] 2008-01-21 02:24 279040 2B336AB6286D6C81FA02CBAB914E3C6C c:\windows\System32\services.exe
[7] 2008-01-21 02:24 279040 2B336AB6286D6C81FA02CBAB914E3C6C c:\windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe

[7] 2008-01-21 02:24 9728 DCF733788C7D088D814E5F80EB4B3E0F c:\windows\System32\lsass.exe
[7] 2009-02-13 07:26 7680 59DE082968FDD257FFF0D209B9A5B460 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16820_none_a44eb0105fb4d975\lsass.exe
[7] 2009-02-13 04:58 7680 AFF8A58280863629CA4FFA9E0B259F1E c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21010_none_a4e2f4e978ca9090\lsass.exe
[7] 2008-01-21 02:24 9728 DCF733788C7D088D814E5F80EB4B3E0F c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_a64a8ac25ccb3836\lsass.exe
[7] 2008-01-21 02:24 9728 DCF733788C7D088D814E5F80EB4B3E0F c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18215_none_a644c0145ccecd28\lsass.exe
[7] 2009-02-13 08:20 9728 F4C62B07E5BF96F1FDCA9DB393ECED22 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22376_none_a68e7da1761c2def\lsass.exe

[7] 2006-11-02 09:45 8704 22BFD03DF51065A9ED8D17F8FB72296B c:\windows\System32\ctfmon.exe
[7] 2006-11-02 09:45 8704 22BFD03DF51065A9ED8D17F8FB72296B c:\windows\winsxs\x86_microsoft-windows-t..cesframework-ctfmon_31bf3856ad364e35_6.0.6000.16386_none_9af9cad793a67953\ctfmon.exe

[7] 2008-01-21 02:24 125952 846CDF9A3CF4DA9B306ADFB7D55EE4C2 c:\windows\System32\spoolsv.exe
[7] 2008-01-21 02:24 125952 846CDF9A3CF4DA9B306ADFB7D55EE4C2 c:\windows\winsxs\x86_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6001.18000_none_d64ba321c188c516\spoolsv.exe

[7] 2008-10-16 21:09 51224 E654B78D2F1D791B30D0ED9A8195EC22 c:\windows\System32\wuauclt.exe
[7] 2006-11-02 09:46 41472 FF81090B6EF1A42A19DF226632711D25 c:\windows\winsxs\x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_6.0.6000.16386_none_acab9aecacae685d\wuauclt.exe
[7] 2008-01-21 02:25 43008 8E93CDF0EA8EDBA63F07E2898A9B2147 c:\windows\winsxs\x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.0.6001.18000_none_a052d92e34802200\wuauclt.exe
[7] 2008-10-16 21:09 51224 E654B78D2F1D791B30D0ED9A8195EC22 c:\windows\winsxs\x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.2.6001.788_none_2a6539a96682e474\wuauclt.exe

[7] 2008-01-21 02:24 25088 0E135526E9785D085BCD9AEDE6FBCBF9 c:\windows\System32\userinit.exe
[7] 2008-01-21 02:24 25088 0E135526E9785D085BCD9AEDE6FBCBF9 c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe

[7] 2008-01-21 02:24 448512 D605031E225AACCBCEB5B76A4F1603A6 c:\windows\System32\termsrv.dll
[7] 2008-01-21 02:24 448512 D605031E225AACCBCEB5B76A4F1603A6 c:\windows\winsxs\x86_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.0.6001.18000_none_8e9f41c854441762\termsrv.dll

[7] 2009-02-13 08:49 888832 DB6E3731E6F5C8AE2843F80B5787F7C6 c:\windows\System32\kernel32.dll
[7] 2009-02-13 07:26 875520 B82C7AC1D559F0FD088792171D64C7F3 c:\windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6000.16820_none_91c20a8f593529ed\kernel32.dll
[7] 2009-02-13 07:13 875520 BB792054BD990EC05D9E260D50FEAD39 c:\windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6000.21010_none_92564f68724ae108\kernel32.dll
[7] 2008-01-21 02:24 888320 DC2338093F91BA4E0512208E60206DDD c:\windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18000_none_93bde541564b88ae\kernel32.dll
[7] 2009-02-13 08:49 888832 DB6E3731E6F5C8AE2843F80B5787F7C6 c:\windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18215_none_93b81a93564f1da0\kernel32.dll
[7] 2009-02-13 08:21 890880 1987D817D08F5EAF0B7F334026FDDB79 c:\windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.22376_none_9401d8206f9c7e67\kernel32.dll

[7] 2008-01-21 02:25 97280 51832219A52C3535BF4771C375E63F9B c:\windows\System32\powrprof.dll
[7] 2008-01-21 02:25 97280 51832219A52C3535BF4771C375E63F9B c:\windows\winsxs\x86_microsoft-windows-userpowermanagement_31bf3856ad364e35_6.0.6001.18000_none_a3199e60fcd85f71\powrprof.dll

[7] 2008-01-21 02:24 114688 EC17194A193CD8E90D27CFB93DFA9A2E c:\windows\System32\imm32.dll
[7] 2008-01-21 02:24 114688 EC17194A193CD8E90D27CFB93DFA9A2E c:\windows\winsxs\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6001.18000_none_5c561e167a6afd02\imm32.dll



[7] 2008-01-21 02:23 35384 37605E0A8CF00CBBA538E753E4344C6E c:\windows\System32\drivers\kbdclass.sys
[7] 2006-11-02 09:49 32872 1A48765F92BA1A88445FC25C9C9D94FC c:\windows\System32\DriverStore\FileRepository\keyboard.inf_93b1c41f\kbdclass.sys
[7] 2008-01-21 02:09 35384 B076B2AB806B3F696DAB21375389101C c:\windows\System32\DriverStore\FileRepository\keyboard.inf_a81145df\kbdclass.sys
[7] 2008-01-21 02:23 35384 37605E0A8CF00CBBA538E753E4344C6E c:\windows\System32\DriverStore\FileRepository\keyboard.inf_da7e599e\kbdclass.sys
[7] 2008-01-21 02:09 35384 B076B2AB806B3F696DAB21375389101C c:\windows\winsxs\x86_keyboard.inf_31bf3856ad364e35_6.0.6000.16609_none_957131ccdbca3f9c\kbdclass.sys
[7] 2008-01-21 02:09 35384 C9B0CF786D5F151A43C7BE8E243F2819 c:\windows\winsxs\x86_keyboard.inf_31bf3856ad364e35_6.0.6000.20734_none_95d55d61f504b486\kbdclass.sys
[7] 2008-01-21 02:23 35384 37605E0A8CF00CBBA538E753E4344C6E c:\windows\winsxs\x86_keyboard.inf_31bf3856ad364e35_6.0.6001.18000_none_974e6dd8d8f8ec7e\kbdclass.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-04-13 2387968]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-15 39408]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2008-01-21 2153472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-04 13556256]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-04 92704]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\N360\0300000.086\SymEFA.sys [6/17/2009 5:39 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\N360\0300000.086\BHDrvx86.sys [6/17/2009 5:39 PM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\N360\0300000.086\cchpx86.sys [6/17/2009 5:39 PM 482352]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090618.002\IDSvix86.sys [6/19/2009 12:30 PM 292912]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.0.0.134\ccSvcHst.exe [6/17/2009 5:39 PM 115560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/17/2009 5:45 PM 101936]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\N360\0300000.086\symndisv.sys [6/17/2009 5:39 PM 39984]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
.
——- Supplementary Scan ——-
.
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-22 17:58
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.0.0.134\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.0.0.134\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-06-23 18:01
ComboFix-quarantined-files.txt 2009-06-23 01:01

Pre-Run: 109,749,952,512 bytes free
Post-Run: 109,783,580,672 bytes free

283 — E O F — 2009-06-14 01:03
Hi,

Please do the following:

I would like you to upload a file to be scanned
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    c:\windows\System32\drivers\ndis.sys

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


Please do the same for the following files:

c:\windows\System32\wininet.dll
c:\windows\System32\userinit.exe
c:\windows\explorer.exe

1. c:\windows\System32\drivers\ndis.sys

VirSCAN.org Scanned Report :
Scanned time : 2009/06/22 21:55:38 (MDT)
Scanner results: All Scanners reported not find malware!
File Name : ndis.sys
File Size : 529464 byte
File Type : PE32 executable for MS Windows (native) Intel 80386 32-bit
MD5 : 9bdc71790fa08f0a0b5f10462b1bd0b1
SHA1 : fbdc2506d424c36f4ebf12b5861eb564d0ba872d
Online report : http://virscan.org/report/3907e997f4abed68…3808e93f21.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090622152941 2009-06-22 3.75 -
AhnLab V3 2009.06.23.02 2009.06.23 2009-06-23 0.82 -
AntiVir 8.2.0.193 7.1.4.125 2009-06-22 0.10 -
Antiy 2.0.18 2.0.18. 0002-18-00 0.12 -
Arcavir 2009 200906221815 2009-06-22 0.07 -
Authentium 5.1.1 200906222139 2009-06-22 2.45 -
AVAST! 4.7.4 090622-0 2009-06-22 0.03 -
AVG 8.5.286 270.12.88/2196 2009-06-23 5.24 -
BitDefender 7.81008.3440472 7.26144 2009-06-23 3.29 -
CA (VET) 9.0.0.143 31.6.6570 2009-06-22 10.93 -
ClamAV 0.95.1 9495 2009-06-22 0.10 -
Comodo 3.9 1395 2009-06-22 0.76 -
CP Secure 1.1.0.715 2009.06.23 2009-06-23 11.43 -
Dr.Web 4.44.0.9170 2009.06.22 2009-06-22 4.83 -
F-Prot 4.4.4.56 20090622 2009-06-22 2.40 -
F-Secure 5.51.6100 2009.06.23.01 2009-06-23 0.07 -
Fortinet 2.81-3.117 10.523 2009-06-22 0.23 -
GData 19.5997/19.372 20090623 2009-06-23 4.37 -
ViRobot 20090622 2009.06.22 2009-06-22 0.46 -
Ikarus T3.1.01.59 2009.06.22.72906 2009-06-22 3.33 -
JiangMin 11.0.706 2009.06.22 2009-06-22 3.32 -
Kaspersky 5.5.10 2009.06.23 2009-06-23 0.06 -
KingSoft 2009.2.5.15 2009.6.23.7 2009-06-23 0.65 -
McAfee 5.3.00 5654 2009-06-22 3.11 -
Microsoft 1.4803 2009.06.23 2009-06-23 5.54 -
mks_vir 2.01 2009.06.23 2009-06-23 3.23 -
Norman 6.01.09 6.01.00 2009-06-22 4.01 -
Panda 9.05.01 2009.06.22 2009-06-22 1.85 -
Trend Micro 8.700-1004 6.214.05 2009-06-22 0.05 -
Quick Heal 10.00 2009.06.22 2009-06-22 1.70 -
Rising 20.0 21.35.10.00 2009-06-23 0.80 -
Sophos 2.87.1 4.42 2009-06-23 2.88 -
Sunbelt 5203 5203 2009-06-22 1.61 -
Symantec 1.3.0.24 20090622.002 2009-06-22 0.26 -
nProtect 20090622.02 4386075 2009-06-22 6.82 -
The Hacker 6.3.4.3 v00351 2009-06-22 0.66 -
VBA32 3.12.10.7 20090622.1529 2009-06-22 2.26 -
VirusBuster 4.5.11.10 10.107.21/1649114 2009-06-22 2.23 -

2. c:\windows\System32\wininet.dll

VirSCAN.org Scanned Report :
Scanned time : 2009/06/22 22:03:05 (MDT)
Scanner results: All Scanners reported not find malware!
File Name : wininet.dll
File Size : 827904 byte
File Type : PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bi
MD5 : 64eaf7cf461a15db4eaeb1d50a10e88e
SHA1 : cc1064ef8ece52ff20370a0e4e18a5b45dee0ded
Online report : http://virscan.org/report/2c8e3c86f144745e…26f5ea7b5c.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090622152941 2009-06-22 3.00 -
AhnLab V3 2009.06.23.02 2009.06.23 2009-06-23 0.75 -
AntiVir 8.2.0.193 7.1.4.125 2009-06-22 0.39 -
Antiy 2.0.18 2.0.18. 0002-18-00 0.12 -
Arcavir 2009 200906221815 2009-06-22 0.07 -
Authentium 5.1.1 200906222139 2009-06-22 5.18 -
AVAST! 4.7.4 090622-0 2009-06-22 0.05 -
AVG 8.5.286 270.12.88/2196 2009-06-23 3.53 -
BitDefender 7.81008.3440472 7.26144 2009-06-23 4.07 -
CA (VET) 9.0.0.143 31.6.6570 2009-06-22 8.23 -
ClamAV 0.95.1 9495 2009-06-22 0.17 -
Comodo 3.9 1395 2009-06-22 0.78 -
CP Secure 1.1.0.715 2009.06.23 2009-06-23 10.53 -
Dr.Web 4.44.0.9170 2009.06.22 2009-06-22 4.74 -
F-Prot 4.4.4.56 20090622 2009-06-22 4.89 -
F-Secure 5.51.6100 2009.06.23.01 2009-06-23 0.08 -
Fortinet 2.81-3.117 10.523 2009-06-22 0.53 -
GData 19.5997/19.372 20090623 2009-06-23 4.69 -
ViRobot 20090622 2009.06.22 2009-06-22 0.43 -
Ikarus T3.1.01.59 2009.06.22.72906 2009-06-22 3.66 -
JiangMin 11.0.706 2009.06.22 2009-06-22 2.16 -
Kaspersky 5.5.10 2009.06.23 2009-06-23 0.05 -
KingSoft 2009.2.5.15 2009.6.23.7 2009-06-23 0.51 -
McAfee 5.3.00 5654 2009-06-22 3.10 -
Microsoft 1.4803 2009.06.23 2009-06-23 4.90 -
mks_vir 2.01 2009.06.23 2009-06-23 3.29 -
Norman 6.01.09 6.01.00 2009-06-22 4.01 -
Panda 9.05.01 2009.06.22 2009-06-22 1.65 -
Trend Micro 8.700-1004 6.214.05 2009-06-22 0.03 -
Quick Heal 10.00 2009.06.22 2009-06-22 1.25 -
Rising 20.0 21.35.10.00 2009-06-23 0.80 -
Sophos 2.87.1 4.42 2009-06-23 2.58 -
Sunbelt 5203 5203 2009-06-22 0.89 -
Symantec 1.3.0.24 20090622.002 2009-06-22 0.08 -
nProtect 20090622.02 4386075 2009-06-22 5.50 -
The Hacker 6.3.4.3 v00351 2009-06-22 0.65 -
VBA32 3.12.10.7 20090622.1529 2009-06-22 2.34 -
VirusBuster 4.5.11.10 10.107.21/1649114 2009-06-22 2.24 -

3. c:\windows\System32\userinit.exe

VirSCAN.org Scanned Report :
Scanned time : 2009/06/22 22:07:20 (MDT)
Scanner results: All Scanners reported not find malware!
File Name : userinit.exe
File Size : 25088 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 0e135526e9785d085bcd9aede6fbcbf9
SHA1 : d15244d41efddbab08d53fe032aedff39091d3af
Online report : http://virscan.org/report/a12bd117d62b254f…37b354f9e0.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090622152941 2009-06-22 40.13 -
AhnLab V3 2009.06.23.02 2009.06.23 2009-06-23 0.92 -
AntiVir 8.2.0.193 7.1.4.125 2009-06-22 0.14 -
Antiy 2.0.18 2.0.18. 0002-18-00 0.12 -
Arcavir 2009 200906221815 2009-06-22 0.04 -
Authentium 5.1.1 200906222139 2009-06-22 1.19 -
AVAST! 4.7.4 090622-0 2009-06-22 0.01 -
AVG 8.5.286 270.12.88/2196 2009-06-23 3.40 -
BitDefender 7.81008.3440472 7.26144 2009-06-23 3.09 -
CA (VET) 9.0.0.143 31.6.6570 2009-06-22 7.40 -
ClamAV 0.95.1 9495 2009-06-22 0.01 -
Comodo 3.9 1395 2009-06-22 0.75 -
CP Secure 1.1.0.715 2009.06.23 2009-06-23 10.38 -
Dr.Web 4.44.0.9170 2009.06.22 2009-06-22 4.76 -
F-Prot 4.4.4.56 20090622 2009-06-22 1.17 -
F-Secure 5.51.6100 2009.06.23.01 2009-06-23 5.93 -
Fortinet 2.81-3.117 10.523 2009-06-22 0.23 -
GData 19.5997/19.372 20090623 2009-06-23 4.67 -
ViRobot 20090622 2009.06.22 2009-06-22 0.43 -
Ikarus T3.1.01.59 2009.06.22.72906 2009-06-22 3.39 -
JiangMin 11.0.706 2009.06.22 2009-06-22 2.06 -
Kaspersky 5.5.10 2009.06.23 2009-06-23 0.06 -
KingSoft 2009.2.5.15 2009.6.23.7 2009-06-23 0.51 -
McAfee 5.3.00 5654 2009-06-22 3.06 -
Microsoft 1.4803 2009.06.23 2009-06-23 6.26 -
mks_vir 2.01 2009.06.23 2009-06-23 3.21 -
Norman 6.01.09 6.01.00 2009-06-22 4.00 -
Panda 9.05.01 2009.06.22 2009-06-22 1.68 -
Trend Micro 8.700-1004 6.214.05 2009-06-22 0.03 -
Quick Heal 10.00 2009.06.22 2009-06-22 0.99 -
Rising 20.0 21.35.10.00 2009-06-23 0.98 -
Sophos 2.87.1 4.42 2009-06-23 2.60 -
Sunbelt 5203 5203 2009-06-22 1.08 -
Symantec 1.3.0.24 20090622.002 2009-06-22 0.07 -
nProtect 20090622.02 4386075 2009-06-22 6.11 -
The Hacker 6.3.4.3 v00351 2009-06-22 0.65 -
VBA32 3.12.10.7 20090622.1529 2009-06-22 2.00 -
VirusBuster 4.5.11.10 10.107.21/1649114 2009-06-22 2.10 -

4. c:\windows\explorer.exe

VirSCAN.org Scanned Report :
Scanned time : 2009/06/22 22:12:49 (MDT)
Scanner results: All Scanners reported not find malware!
File Name : explorer.exe
File Size : 2927104 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 4f554999d7d5f05daaebba7b5ba1089d
SHA1 : e509a42554cc0e5888ac8bf494d3c02223238609
Online report : http://virscan.org/report/9ae7031785874073…f18d2c02d1.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090622152941 2009-06-22 2.32 -
AhnLab V3 2009.06.23.02 2009.06.23 2009-06-23 0.87 -
AntiVir 8.2.0.193 7.1.4.125 2009-06-22 0.14 -
Antiy 2.0.18 2.0.18. 0002-18-00 0.12 -
Arcavir 2009 200906221815 2009-06-22 0.09 -
Authentium 5.1.1 200906222139 2009-06-22 2.29 -
AVAST! 4.7.4 090622-0 2009-06-22 0.15 -
AVG 8.5.286 270.12.88/2196 2009-06-23 3.50 -
BitDefender 7.81008.3440472 7.26144 2009-06-23 3.09 -
CA (VET) 9.0.0.143 31.6.6570 2009-06-22 5.32 -
ClamAV 0.95.1 9495 2009-06-22 0.33 -
Comodo 3.9 1395 2009-06-22 0.84 -
CP Secure 1.1.0.715 2009.06.23 2009-06-23 10.65 -
Dr.Web 4.44.0.9170 2009.06.22 2009-06-22 4.71 -
F-Prot 4.4.4.56 20090622 2009-06-22 2.22 -
F-Secure 5.51.6100 2009.06.23.01 2009-06-23 0.11 -
Fortinet 2.81-3.117 10.523 2009-06-22 0.31 -
GData 19.5999/19.372 20090623 2009-06-23 4.74 -
ViRobot 20090622 2009.06.22 2009-06-22 0.42 -
Ikarus T3.1.01.59 2009.06.22.72906 2009-06-22 3.28 -
JiangMin 11.0.706 2009.06.22 2009-06-22 2.22 -
Kaspersky 5.5.10 2009.06.23 2009-06-23 0.06 -
KingSoft 2009.2.5.15 2009.6.23.7 2009-06-23 0.91 -
McAfee 5.3.00 5654 2009-06-22 3.14 -
Microsoft 1.4803 2009.06.23 2009-06-23 6.14 -
mks_vir 2.01 2009.06.23 2009-06-23 3.26 -
Norman 6.01.09 6.01.00 2009-06-22 4.01 -
Panda 9.05.01 2009.06.22 2009-06-22 1.77 -
Trend Micro 8.700-1004 6.214.05 2009-06-22 0.03 -
Quick Heal 10.00 2009.06.22 2009-06-22 1.76 -
Rising 20.0 21.35.10.00 2009-06-23 0.95 -
Sophos 2.87.1 4.42 2009-06-23 2.58 -
Sunbelt 5203 5203 2009-06-22 0.87 -
Symantec 1.3.0.24 20090622.002 2009-06-22 0.13 -
nProtect 20090622.02 4386075 2009-06-22 6.56 -
The Hacker 6.3.4.3 v00351 2009-06-22 0.65 -
VBA32 3.12.10.7 20090622.1529 2009-06-22 2.38 -
VirusBuster 4.5.11.10 10.107.21/1649114 2009-06-22 2.68 -
Ok it does seem to be working again and my norton 360 is actually scanning. Does that mean it's gone or is there still more to do? THANK YOU SO MUCH FOR HELPING!!!!
Hi,

Little more work to do,

Please do the following:

please do the following
Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.

NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
1. Malwarebytes' Anti-Malware 1.38 Database version: 2325 Windows 6.0.6001 Service Pack 1 6/23/2009 11:29:03 AM mbam-log-2009-06-23 (11-29-03).txt Scan type: Quick Scan Objects scanned: 70887 Time elapsed: 4 minute(s), 38 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 2 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\AccessMV (Trojan.DNSChanger) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AccessMV (Trojan.DNSChanger) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\Users\UNBRELLA COPORATION\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AccessMV (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\Program Files\AccessMV (Trojan.DNSChanger) -> Quarantined and deleted successfully. Files Infected: 2.

Attachments:

——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Tuesday, June 23, 2009 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Tuesday, June 23, 2009 21:18:12 Records in database: 2384572 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Files scanned: 80011 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 01:50:05 File name / Threat name / Threats count C:\Qoobox\Quarantine\C\Windows\System32\drivers\_MSIVXenxienqyhrcvpuwtdxbxoqmqxrempxcn_.sys.zip Infected: Trojan.Win32.Tdss.ahpu 1 The selected area was scanned.
Hi, Kaspersky has identified an item in quarantine, which we will clean up shortly, please post a fresh DDS log and advise how your computer is running now and if there are any outstanding issues.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI