Andreousb
Topic Starter
Hi i am also haveing this problem. my norton 360 will not scan anything and i can't seem to get rid of it. I did the DDS and gmer. they will be listed below.
DDS (Ver_09-05-14.01)
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 4/10/2006 1:47:26 AM
System Uptime: 6/19/2009 9:42:20 AM (4 hours ago)
Motherboard: Quanta | | 30B7
Processor: AMD Turion™ 64 X2 Mobile Technology TL-56 | Socket S1 | 1600/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 141 GiB total, 102.143 GiB free.
D: is FIXED (NTFS) - 8 GiB total, 5.774 GiB free.
E: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
==== Installed Programs ======================
AccessMV
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.1.2
GEAR driver installer for x86 and x64
GearDrvs
Google Toolbar for Internet Explorer
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
ImagXpress
LightScribe System Software
Microsoft .NET Framework 3.5 SP1
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP2 (KB954430)
neroxml
Norton 360
Norton Internet Security
NVIDIA Drivers
Xvid 1.2.1 final uninstall
==== End Of File ===========================
============== Pseudo HJT Report ===============
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.0.0.134\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.0.0.134\IPSBHO.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.0.0.134\coIEPlg.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [ColdWare] c:\windows\temp\278932611.tmp.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 85.255.112.143,85.255.112.203
TCP: {73DB8B95-2CB3-418D-A989-1DA3BB4AA4AF} = 85.255.112.143,85.255.112.203
TCP: {A6B4EBB5-F746-4D61-ACAC-203572C56B3B} = 85.255.112.143,85.255.112.203
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.0.0.134\CoIEPlg.dll
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0300000.086\SymEFA.sys [2009-6-17 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0300000.086\BHDrvx86.sys [2009-6-17 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0300000.086\cchpx86.sys [2009-6-17 482352]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090618.002\IDSvix86.sys [2009-6-19 292912]
R2 N360;Norton 360;c:\program files\norton 360\engine\3.0.0.134\ccSvcHst.exe [2009-6-17 115560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-6-17 101936]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0300000.086\symndisv.sys [2009-6-17 39984]
S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\nbservice.exe –> c:\program files\common files\nero\nero backitup 4\NBService.exe [?]
=============== Created Last 30 ================
2009-06-19 13:30 431 a——- C:\spyhunter.fix
2009-06-19 13:29 –d—– c:\program files\Enigma Software Group
2009-06-17 17:39 107,368 a——- c:\windows\system32\GEARAspi.dll
2009-06-17 17:39 23,848 a——- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-17 17:39 –d—– c:\programdata\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-06-17 17:39 –d—– c:\progra~2\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-06-17 17:39 25,136 a—-r– c:\windows\system32\drivers\SymIMV.sys
2009-06-17 17:39 124,464 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-06-17 17:39 7,386 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2009-06-17 17:39 805 a——- c:\windows\system32\drivers\SYMEVENT.INF
2009-06-17 17:39 –d—– c:\program files\Symantec
2009-06-17 17:38 –d—– c:\windows\system32\drivers\N360
2009-06-17 17:38 –d—– c:\program files\Norton 360
2009-06-17 17:38 –d—– c:\programdata\Norton
2009-06-17 17:38 –d—– c:\progra~2\Norton
2009-06-17 17:37 –d—– c:\programdata\NortonInstaller
2009-06-17 17:37 –d—– c:\program files\NortonInstaller
2009-06-17 17:37 –d—– c:\progra~2\NortonInstaller
2009-06-15 22:18 –d—– c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP
2009-06-14 19:16 –d—– c:\windows\system32\N360_BACKUP
2009-06-14 18:08 –d—– c:\programdata\Adobe
2009-06-14 18:07 –d—– c:\programdata\Google
2009-06-14 18:07 –d—– c:\programdata\NOS
2009-06-14 14:29 1,905 a——- c:\windows\diagwrn.xml
2009-06-14 14:29 1,905 a——- c:\windows\diagerr.xml
2009-06-14 12:25 –d—– c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-06-14 12:25 –d—– c:\progra~2\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-06-14 12:03 –d—– c:\users\unbrel~1\appdata\roaming\Symantec
2009-06-14 11:53 –d—– c:\programdata\Symantec
2009-06-14 11:53 –d—– c:\progra~2\Symantec
2009-06-14 11:53 –d—– c:\program files\common files\Symantec Shared
2009-06-12 16:12 –d—– c:\program files\AccessMV
2009-06-11 17:39 2,033,152 a——- c:\windows\system32\win32k.sys
2009-06-09 11:44 29,169 a——- c:\programdata\nvModes.dat
2009-06-09 11:44 29,169 a——- c:\progra~2\nvModes.dat
2009-06-07 23:04 –d—– c:\program files\MSXML 4.0
2009-06-07 09:15 815,104 a——- c:\windows\system32\xvidcore.dll
2009-06-07 09:15 180,224 a——- c:\windows\system32\xvidvfw.dll
2009-06-07 09:15 77,824 a——- c:\windows\system32\xvid.ax
2009-06-07 09:15 –d—– c:\program files\Xvid
2009-06-07 01:00 –d—– c:\programdata\LightScribe
2009-06-07 01:00 –d—– c:\progra~2\LightScribe
2009-06-06 23:47 39 a——- c:\windows\Irremote.ini
2009-06-06 23:36 –d—– c:\program files\Nero
2009-06-06 23:35 –d—– c:\programdata\Nero
2009-06-06 23:35 –d—– c:\progra~2\Nero
2009-06-06 23:35 1,315,328 a——- c:\windows\system32\ole32.dll
2009-06-06 22:41 –d—– c:\programdata\NVIDIA
2009-06-06 20:24 2,048 a——- c:\windows\system32\tzres.dll
2009-06-06 20:18 873,310 a——- c:\windows\system32\oem8.inf
2009-06-06 20:10 1,079,840 a——- c:\windows\system32\nvcpluir.dll
2009-06-06 20:10 768,544 a——- c:\windows\system32\nvcplui.exe
2009-06-06 20:10 420,384 a——- c:\windows\system32\nvcpl.cpl
2009-06-06 20:10 313,888 a——- c:\windows\system32\nvexpbar.dll
2009-06-06 20:05 –dsh— c:\windows\Installer
2009-06-06 20:00 105,016 a——- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-06 20:00 97,800 a——- c:\windows\system32\infocardapi.dll
2009-06-06 20:00 37,384 a——- c:\windows\system32\infocardcpl.cpl
2009-06-06 20:00 622,080 a——- c:\windows\system32\icardagt.exe
2009-06-06 20:00 43,544 a——- c:\windows\system32\PresentationHostProxy.dll
2009-06-06 20:00 11,264 a——- c:\windows\system32\icardres.dll
2009-06-06 20:00 781,344 a——- c:\windows\system32\PresentationNative_v0300.dll
2009-06-06 20:00 326,160 a——- c:\windows\system32\PresentationHost.exe
2009-06-06 19:51 96,760 a——- c:\windows\system32\dfshim.dll
2009-06-06 19:51 282,112 a——- c:\windows\system32\mscoree.dll
2009-06-06 19:51 41,984 a——- c:\windows\system32\netfxperf.dll
2009-06-06 19:50 158,720 a——- c:\windows\system32\mscorier.dll
2009-06-06 19:50 83,968 a——- c:\windows\system32\mscories.dll
2009-06-06 19:46 303,616 a——- c:\windows\system32\wmpeffects.dll
2009-06-06 19:46 19,000 a——- c:\windows\system32\kd1394.dll
2009-06-06 19:46 988,216 a——- c:\windows\system32\winload.exe
2009-06-06 19:46 927,288 a——- c:\windows\system32\winresume.exe
2009-06-06 19:46 615,992 a——- c:\windows\system32\ci.dll
2009-06-06 19:46 378,368 a——- c:\windows\system32\srcore.dll
2009-06-06 19:46 318,464 a——- c:\windows\system32\rstrui.exe
2009-06-06 19:46 46,592 a——- c:\windows\system32\setbcdlocale.dll
2009-06-06 19:46 40,960 a——- c:\windows\system32\srclient.dll
2009-06-06 19:46 14,848 a——- c:\windows\system32\srdelayed.exe
2009-06-06 19:46 6,656 a——- c:\windows\system32\kbd106n.dll
2009-06-06 19:46 1,314,816 a——- c:\windows\system32\quartz.dll
2009-06-06 19:45 12,240,896 a——- c:\windows\system32\NlsLexicons0007.dll
2009-06-06 19:45 2,644,480 a——- c:\windows\system32\NlsLexicons0009.dll
2009-06-06 19:45 801,280 a——- c:\windows\system32\NaturalLanguage6.dll
2009-06-06 19:43 3,903 a——- c:\windows\system32\nvnrm.nvu
2009-06-06 19:43 428,544 a——- c:\windows\system32\EncDec.dll
2009-06-06 19:43 217,088 a——- c:\windows\system32\psisrndr.ax
2009-06-06 19:43 293,376 a——- c:\windows\system32\psisdecd.dll
2009-06-06 19:43 177,664 a——- c:\windows\system32\mpg2splt.ax
2009-06-06 19:43 80,896 a——- c:\windows\system32\MSNP.ax
2009-06-06 19:43 57,856 a——- c:\windows\system32\MSDvbNP.ax
2009-06-06 19:42 356,352 a——- c:\windows\system32\nvusmu.exe
2009-06-06 19:42 528 a——- c:\windows\system32\nvsmu.nvu
2009-06-06 19:40 2,868,736 a——- c:\windows\system32\mf.dll
2009-06-06 19:34 –d—– c:\users\unbrel~1\appdata\roaming\uTorrent
2009-06-06 19:31 1,334,272 a——- c:\windows\system32\msxml6.dll
2009-06-06 19:25 –d—– c:\users\UNBRELLA COPORATION
2009-06-06 19:25 1,524,736 a——- c:\windows\system32\wucltux.dll
2009-06-06 19:24 83,456 a——- c:\windows\system32\wudriver.dll
2009-06-06 19:24 162,064 a——- c:\windows\system32\wuwebv.dll
2009-06-06 19:24 31,232 a——- c:\windows\system32\wuapp.exe
==================== Find3M ====================
2009-06-17 17:39 86,016 a——- c:\windows\inf\infstrng.dat
2009-06-17 17:39 86,016 a——- c:\windows\inf\infstor.dat
2009-06-17 17:39 51,200 a——- c:\windows\inf\infpub.dat
2009-06-06 22:35 665,600 a——- c:\windows\inf\drvindex.dat
2009-04-24 09:05 827,904 a——- c:\windows\system32\wininet.dll
2009-04-24 09:02 78,336 a——- c:\windows\system32\ieencode.dll
2009-04-24 06:44 26,624 a——- c:\windows\system32\ieUnatt.exe
2009-04-23 05:43 784,896 a——- c:\windows\system32\rpcrt4.dll
2009-04-23 05:42 636,928 a——- c:\windows\system32\localspl.dll
2008-01-20 19:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 13:42:14.87 ===============
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-19 14:03:13
Windows 6.0.6001 Service Pack 1
—- System - GMER 1.0.15 —-
Code 8BA58308 ZwEnumerateKey
Code 8B0BB130 ZwFlushInstructionCache
Code 8BA5B2ED IofCallDriver
Code 8BA5C2BE IofCompleteRequest
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\tdx \Device\Ip SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\RawIp SYMTDI.SYS
—- Services - GMER 1.0.15 —-
Service C:\Windows\system32\drivers\MSIVXenxienqyhrcvpuwtdxbxoqmqxrempxcn.sys (*** hidden *** ) [SYSTEM] MSIVXserv.sys <– ROOTKIT !!!
—- EOF - GMER 1.0.15 —-
DDS (Ver_09-05-14.01)
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 4/10/2006 1:47:26 AM
System Uptime: 6/19/2009 9:42:20 AM (4 hours ago)
Motherboard: Quanta | | 30B7
Processor: AMD Turion™ 64 X2 Mobile Technology TL-56 | Socket S1 | 1600/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 141 GiB total, 102.143 GiB free.
D: is FIXED (NTFS) - 8 GiB total, 5.774 GiB free.
E: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
==== Installed Programs ======================
AccessMV
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.1.2
GEAR driver installer for x86 and x64
GearDrvs
Google Toolbar for Internet Explorer
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
ImagXpress
LightScribe System Software
Microsoft .NET Framework 3.5 SP1
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP2 (KB954430)
neroxml
Norton 360
Norton Internet Security
NVIDIA Drivers
Xvid 1.2.1 final uninstall
==== End Of File ===========================
============== Pseudo HJT Report ===============
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.0.0.134\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.0.0.134\IPSBHO.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.0.0.134\coIEPlg.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [ColdWare] c:\windows\temp\278932611.tmp.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 85.255.112.143,85.255.112.203
TCP: {73DB8B95-2CB3-418D-A989-1DA3BB4AA4AF} = 85.255.112.143,85.255.112.203
TCP: {A6B4EBB5-F746-4D61-ACAC-203572C56B3B} = 85.255.112.143,85.255.112.203
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.0.0.134\CoIEPlg.dll
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0300000.086\SymEFA.sys [2009-6-17 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0300000.086\BHDrvx86.sys [2009-6-17 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0300000.086\cchpx86.sys [2009-6-17 482352]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090618.002\IDSvix86.sys [2009-6-19 292912]
R2 N360;Norton 360;c:\program files\norton 360\engine\3.0.0.134\ccSvcHst.exe [2009-6-17 115560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-6-17 101936]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0300000.086\symndisv.sys [2009-6-17 39984]
S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\nbservice.exe –> c:\program files\common files\nero\nero backitup 4\NBService.exe [?]
=============== Created Last 30 ================
2009-06-19 13:30 431 a——- C:\spyhunter.fix
2009-06-19 13:29 –d—– c:\program files\Enigma Software Group
2009-06-17 17:39 107,368 a——- c:\windows\system32\GEARAspi.dll
2009-06-17 17:39 23,848 a——- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-17 17:39 –d—– c:\programdata\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-06-17 17:39 –d—– c:\progra~2\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-06-17 17:39 25,136 a—-r– c:\windows\system32\drivers\SymIMV.sys
2009-06-17 17:39 124,464 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-06-17 17:39 7,386 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2009-06-17 17:39 805 a——- c:\windows\system32\drivers\SYMEVENT.INF
2009-06-17 17:39 –d—– c:\program files\Symantec
2009-06-17 17:38 –d—– c:\windows\system32\drivers\N360
2009-06-17 17:38 –d—– c:\program files\Norton 360
2009-06-17 17:38 –d—– c:\programdata\Norton
2009-06-17 17:38 –d—– c:\progra~2\Norton
2009-06-17 17:37 –d—– c:\programdata\NortonInstaller
2009-06-17 17:37 –d—– c:\program files\NortonInstaller
2009-06-17 17:37 –d—– c:\progra~2\NortonInstaller
2009-06-15 22:18 –d—– c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP
2009-06-14 19:16 –d—– c:\windows\system32\N360_BACKUP
2009-06-14 18:08 –d—– c:\programdata\Adobe
2009-06-14 18:07 –d—– c:\programdata\Google
2009-06-14 18:07 –d—– c:\programdata\NOS
2009-06-14 14:29 1,905 a——- c:\windows\diagwrn.xml
2009-06-14 14:29 1,905 a——- c:\windows\diagerr.xml
2009-06-14 12:25 –d—– c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-06-14 12:25 –d—– c:\progra~2\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-06-14 12:03 –d—– c:\users\unbrel~1\appdata\roaming\Symantec
2009-06-14 11:53 –d—– c:\programdata\Symantec
2009-06-14 11:53 –d—– c:\progra~2\Symantec
2009-06-14 11:53 –d—– c:\program files\common files\Symantec Shared
2009-06-12 16:12 –d—– c:\program files\AccessMV
2009-06-11 17:39 2,033,152 a——- c:\windows\system32\win32k.sys
2009-06-09 11:44 29,169 a——- c:\programdata\nvModes.dat
2009-06-09 11:44 29,169 a——- c:\progra~2\nvModes.dat
2009-06-07 23:04 –d—– c:\program files\MSXML 4.0
2009-06-07 09:15 815,104 a——- c:\windows\system32\xvidcore.dll
2009-06-07 09:15 180,224 a——- c:\windows\system32\xvidvfw.dll
2009-06-07 09:15 77,824 a——- c:\windows\system32\xvid.ax
2009-06-07 09:15 –d—– c:\program files\Xvid
2009-06-07 01:00 –d—– c:\programdata\LightScribe
2009-06-07 01:00 –d—– c:\progra~2\LightScribe
2009-06-06 23:47 39 a——- c:\windows\Irremote.ini
2009-06-06 23:36 –d—– c:\program files\Nero
2009-06-06 23:35 –d—– c:\programdata\Nero
2009-06-06 23:35 –d—– c:\progra~2\Nero
2009-06-06 23:35 1,315,328 a——- c:\windows\system32\ole32.dll
2009-06-06 22:41 –d—– c:\programdata\NVIDIA
2009-06-06 20:24 2,048 a——- c:\windows\system32\tzres.dll
2009-06-06 20:18 873,310 a——- c:\windows\system32\oem8.inf
2009-06-06 20:10 1,079,840 a——- c:\windows\system32\nvcpluir.dll
2009-06-06 20:10 768,544 a——- c:\windows\system32\nvcplui.exe
2009-06-06 20:10 420,384 a——- c:\windows\system32\nvcpl.cpl
2009-06-06 20:10 313,888 a——- c:\windows\system32\nvexpbar.dll
2009-06-06 20:05 –dsh— c:\windows\Installer
2009-06-06 20:00 105,016 a——- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-06 20:00 97,800 a——- c:\windows\system32\infocardapi.dll
2009-06-06 20:00 37,384 a——- c:\windows\system32\infocardcpl.cpl
2009-06-06 20:00 622,080 a——- c:\windows\system32\icardagt.exe
2009-06-06 20:00 43,544 a——- c:\windows\system32\PresentationHostProxy.dll
2009-06-06 20:00 11,264 a——- c:\windows\system32\icardres.dll
2009-06-06 20:00 781,344 a——- c:\windows\system32\PresentationNative_v0300.dll
2009-06-06 20:00 326,160 a——- c:\windows\system32\PresentationHost.exe
2009-06-06 19:51 96,760 a——- c:\windows\system32\dfshim.dll
2009-06-06 19:51 282,112 a——- c:\windows\system32\mscoree.dll
2009-06-06 19:51 41,984 a——- c:\windows\system32\netfxperf.dll
2009-06-06 19:50 158,720 a——- c:\windows\system32\mscorier.dll
2009-06-06 19:50 83,968 a——- c:\windows\system32\mscories.dll
2009-06-06 19:46 303,616 a——- c:\windows\system32\wmpeffects.dll
2009-06-06 19:46 19,000 a——- c:\windows\system32\kd1394.dll
2009-06-06 19:46 988,216 a——- c:\windows\system32\winload.exe
2009-06-06 19:46 927,288 a——- c:\windows\system32\winresume.exe
2009-06-06 19:46 615,992 a——- c:\windows\system32\ci.dll
2009-06-06 19:46 378,368 a——- c:\windows\system32\srcore.dll
2009-06-06 19:46 318,464 a——- c:\windows\system32\rstrui.exe
2009-06-06 19:46 46,592 a——- c:\windows\system32\setbcdlocale.dll
2009-06-06 19:46 40,960 a——- c:\windows\system32\srclient.dll
2009-06-06 19:46 14,848 a——- c:\windows\system32\srdelayed.exe
2009-06-06 19:46 6,656 a——- c:\windows\system32\kbd106n.dll
2009-06-06 19:46 1,314,816 a——- c:\windows\system32\quartz.dll
2009-06-06 19:45 12,240,896 a——- c:\windows\system32\NlsLexicons0007.dll
2009-06-06 19:45 2,644,480 a——- c:\windows\system32\NlsLexicons0009.dll
2009-06-06 19:45 801,280 a——- c:\windows\system32\NaturalLanguage6.dll
2009-06-06 19:43 3,903 a——- c:\windows\system32\nvnrm.nvu
2009-06-06 19:43 428,544 a——- c:\windows\system32\EncDec.dll
2009-06-06 19:43 217,088 a——- c:\windows\system32\psisrndr.ax
2009-06-06 19:43 293,376 a——- c:\windows\system32\psisdecd.dll
2009-06-06 19:43 177,664 a——- c:\windows\system32\mpg2splt.ax
2009-06-06 19:43 80,896 a——- c:\windows\system32\MSNP.ax
2009-06-06 19:43 57,856 a——- c:\windows\system32\MSDvbNP.ax
2009-06-06 19:42 356,352 a——- c:\windows\system32\nvusmu.exe
2009-06-06 19:42 528 a——- c:\windows\system32\nvsmu.nvu
2009-06-06 19:40 2,868,736 a——- c:\windows\system32\mf.dll
2009-06-06 19:34 –d—– c:\users\unbrel~1\appdata\roaming\uTorrent
2009-06-06 19:31 1,334,272 a——- c:\windows\system32\msxml6.dll
2009-06-06 19:25 –d—– c:\users\UNBRELLA COPORATION
2009-06-06 19:25 1,524,736 a——- c:\windows\system32\wucltux.dll
2009-06-06 19:24 83,456 a——- c:\windows\system32\wudriver.dll
2009-06-06 19:24 162,064 a——- c:\windows\system32\wuwebv.dll
2009-06-06 19:24 31,232 a——- c:\windows\system32\wuapp.exe
==================== Find3M ====================
2009-06-17 17:39 86,016 a——- c:\windows\inf\infstrng.dat
2009-06-17 17:39 86,016 a——- c:\windows\inf\infstor.dat
2009-06-17 17:39 51,200 a——- c:\windows\inf\infpub.dat
2009-06-06 22:35 665,600 a——- c:\windows\inf\drvindex.dat
2009-04-24 09:05 827,904 a——- c:\windows\system32\wininet.dll
2009-04-24 09:02 78,336 a——- c:\windows\system32\ieencode.dll
2009-04-24 06:44 26,624 a——- c:\windows\system32\ieUnatt.exe
2009-04-23 05:43 784,896 a——- c:\windows\system32\rpcrt4.dll
2009-04-23 05:42 636,928 a——- c:\windows\system32\localspl.dll
2008-01-20 19:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 13:42:14.87 ===============
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-19 14:03:13
Windows 6.0.6001 Service Pack 1
—- System - GMER 1.0.15 —-
Code 8BA58308 ZwEnumerateKey
Code 8B0BB130 ZwFlushInstructionCache
Code 8BA5B2ED IofCallDriver
Code 8BA5C2BE IofCompleteRequest
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\tdx \Device\Ip SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS
AttachedDevice \Driver\tdx \Device\RawIp SYMTDI.SYS
—- Services - GMER 1.0.15 —-
Service C:\Windows\system32\drivers\MSIVXenxienqyhrcvpuwtdxbxoqmqxrempxcn.sys (*** hidden *** ) [SYSTEM] MSIVXserv.sys <– ROOTKIT !!!
—- EOF - GMER 1.0.15 —-