dpan
Topic Starter
Hi,
First I want to thank you guys in advance for providing this site. It's awesome!! I believe I was infected from a crack/keygen (I allowed it to run even though warned by AV). Norton AV 2009 unable to clean after infected. Before familiarizing myself with the rules of posting, my computer had/has the symtoms described in the title and description. I have followed the steps in the 'Are you infected' section. However SysRestorePoint would not launch but I was able use the Windows Wizard. Further, GMER caused a Windows error but I saved the log at that time - may be incomplete. Ran GMER a second time (without reboot) and got the windows shutdown blue screen. After finishing the steps outlined in the 'Are you infected' section, pop-ups seem to be gone, task manager is enabled, ieaskie32.dll add on is no longer visable. I have not tested the safe mode yet. Your advise is greatly appreciated
Here are the logs:
Malwarebytes' Anti-Malware 1.42
Database version: 3439
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
12/27/2009 11:40:47 AM
mbam-log-2009-12-27 (11-40-29).txt
Scan type: Quick Scan
Objects scanned: 135706
Time elapsed: 4 minute(s), 23 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 4
Registry Keys Infected: 6
Registry Values Infected: 2
Registry Data Items Infected: 12
Folders Infected: 2
Files Infected: 31
Memory Processes Infected:
C:\Program Files\InternetSecurity2010\IS2010.exe (Rogue.Installer) -> No action taken.
C:\WINDOWS\system32\winupdate86.exe (Trojan.FakeAlert) -> No action taken.
Memory Modules Infected:
C:\WINDOWS\system32\icwdial32.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\2C9.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\__c0046212.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\__c00C9112.dat (Trojan.Agent) -> No action taken.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0f3f5df4-b7a9-48c4-9b4e-7a691ab4e84f} (Trojan.BHO.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{0f3f5df4-b7a9-48c4-9b4e-7a691ab4e84f} (Trojan.BHO.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cb1f7a0720 (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0f3f5df4-b7a9-48c4-9b4e-7a691ab4e84f} (Trojan.Tracur) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{0f3f5df4-b7a9-48c4-9b4e-7a691ab4e84f} (Trojan.Tracur) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0046212 (Trojan.Agent) -> No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\internet security 2010 (Rogue.Installer) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupdate86.exe (Trojan.Downloader) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Agent) -> Data: c:\windows\system32\icwdial32.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Agent) -> Data: system32\icwdial32.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\winlogon86.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\winlogon86.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\winlogon86.exe) Good: (Userinit.exe) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.
Folders Infected:
C:\WINDOWS\system32\SysWoW32 (Worm.Archive) -> No action taken.
C:\Program Files\InternetSecurity2010 (Rogue.InternetSecurity2010) -> No action taken.
Files Infected:
C:\WINDOWS\system32\ieaksie32.dll (Trojan.BHO.H) -> No action taken.
C:\WINDOWS\system32\icwdial32.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\2C9.tmp (Trojan.Agent) -> No action taken.
C:\Program Files\InternetSecurity2010\IS2010.exe (Rogue.Installer) -> No action taken.
C:\WINDOWS\system32\1.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\2.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\winhelper86.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\SysWoW32\mi1458286074v4.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\mi1458286074v6.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\mi1458286074v7.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\mu1458286074v5 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\mu1458286074v5.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v0 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v0.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v1 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v1.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v2 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v2.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v3 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v3.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\_u1458286074v0 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\_u1458286074v1 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\_u1458286074v2 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\_u1458286074v3 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\__c0046212.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\__c00B843E.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\__c00C9112.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\GnuHashes.ini (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\winupdate86.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\41.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\Winlogon86.exe (Trojan.FakeAlert) -> No action taken.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-27 11:50:33
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\DUANEP~1\LOCALS~1\Temp\pwldapog.sys
—- System - GMER 1.0.15 —-
SSDT 8900A6A0 ZwAlertResumeThread
SSDT 89027EF0 ZwAlertThread
SSDT 890326D8 ZwAllocateVirtualMemory
SSDT 8900E0C0 ZwAssignProcessToJobObject
SSDT 89113A08 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xA8A01130]
SSDT 890274E0 ZwCreateMutant
SSDT 8900D100 ZwCreateSymbolicLinkObject
SSDT 890150C0 ZwCreateThread
SSDT 8900E1A0 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA8A013B0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA8A01910]
SSDT 890006D0 ZwDuplicateObject
SSDT 88FFD6B0 ZwFreeVirtualMemory
SSDT 890275B0 ZwImpersonateAnonymousToken
SSDT 88FDC7D8 ZwImpersonateThread
SSDT 897D4648 ZwLoadDriver
SSDT 88FD5870 ZwMapViewOfSection
SSDT 8900F1A0 ZwOpenEvent
SSDT 89010710 ZwOpenProcess
SSDT 89010650 ZwOpenProcessToken
SSDT 890101E0 ZwOpenSection
SSDT 890007A0 ZwOpenThread
SSDT 8900D1D0 ZwProtectVirtualMemory
SSDT 89048E88 ZwResumeThread
SSDT 89031660 ZwSetContextThread
SSDT 89031740 ZwSetInformationProcess
SSDT 89010098 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA8A01B60]
SSDT 8900F0C0 ZwSuspendProcess
SSDT 89027FD0 ZwSuspendThread
SSDT 88FD7658 ZwTerminateProcess
SSDT 88FDC2D8 ZwTerminateThread
SSDT 88FDA6A8 ZwUnmapViewOfSection
SSDT 88FFD7A0 ZwWriteVirtualMemory
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] on Sun 12/27/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2013.1579 [GMT -6:00]
============== Running Processes ===============
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Quicken\Online Backup\OnlineBackup.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Duane Pankhurst\Desktop\whatthetech\dds.scr
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.live.com
uStart Page = hxxp://my.att.net/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\norton antivirus\engine\16.7.2.11\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Windows; Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [@BackupScheduler] c:\program files\quicken\online backup\OnlineBackup.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe"
mRun: [IJNetworkScanUtility] c:\program files\canon\canon ij network scan utility\CNMNSUT.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Notify: igfxcui - igfxdev.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1007020.00b\SymEFA.sys [2009-11-27 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1007020.00b\BHDrvx86.sys [2009-11-27 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1007020.00b\cchpx86.sys [2009-11-27 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20091217.002\IDSXpx86.sys [2009-12-18 329592]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-11 30312]
R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-12-18 155648]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\norton antivirus\engine\16.7.2.11\ccSvcHst.exe [2009-11-27 117640]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-12-23 102448]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2009-5-27 29262680]
S3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20091226.025\NAVENG.SYS [2009-12-27 84912]
S3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20091226.025\NAVEX15.SYS [2009-12-27 1323568]
=============== Created Last 30 ================
2009-12-27 11:33 –d—– c:\docume~1\duanep~1\applic~1\Malwarebytes
2009-12-27 11:33 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-27 11:33 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-27 11:33 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-12-27 11:33 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-12-27 08:29 0 a——- c:\windows\system32\18467.exe
2009-12-23 20:18 35 a——- c:\windows\system32\5c31f0a7
2009-12-23 19:50 1,254 a–sh— c:\windows\system32\1558292464
2009-12-23 19:50 817 a——- c:\windows\system32\212989856
2009-12-23 19:49 –d—– c:\windows\system32\1048809671
2009-12-23 19:49 203,776 —sh— c:\windows\system32\unrar.exe
2009-12-23 19:36 –d—– c:\docume~1\duanep~1\applic~1\LimeWire
2009-12-17 19:30 –d—– c:\docume~1\duanep~1\applic~1\Final Draft
2009-12-17 19:25 1,073,152 a—-r– c:\windows\system32\cdintf210.dll
2009-12-17 19:25 –d—– c:\docume~1\alluse~1\applic~1\Final Draft
2009-12-17 19:24 –d—– c:\program files\Final Draft Tagger
2009-12-17 19:24 –d—– c:\program files\Final Draft 7
2009-12-17 19:24 –d—– c:\program files\common files\Wise Installation Wizard
2009-12-01 18:56 –d—– C:\UBCD4Win
2009-12-01 18:37 –d—– C:\xpcd
2009-12-01 17:49 –d—– C:\vista cd
2009-12-01 17:48 1,905 a——- c:\windows\diagwrn.xml
2009-12-01 17:48 1,905 a——- c:\windows\diagerr.xml
2009-11-29 08:10 –d—– C:\Intel
2009-11-28 08:29 36,400 a—-r– c:\windows\system32\drivers\SymIM.sys
==================== Find3M ====================
2009-11-27 16:02 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-11-27 16:02 60,808 a——- c:\windows\system32\S32EVNT1.DLL
2009-11-27 16:02 7,456 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2009-11-27 16:02 806 a——- c:\windows\system32\drivers\SYMEVENT.INF
2009-10-29 01:45 916,480 a——- c:\windows\system32\wininet.dll
2009-10-27 20:21 614 a——- c:\docume~1\duanep~1\applic~1\wklnhst.dat
2009-10-20 23:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-20 23:38 25,088 a——- c:\windows\system32\httpapi.dll
2009-10-13 04:30 270,336 a——- c:\windows\system32\oakley.dll
2009-10-12 07:38 149,504 a——- c:\windows\system32\rastls.dll
2009-10-12 07:38 79,872 a——- c:\windows\system32\raschap.dll
2009-10-09 17:54 77,824 a——- c:\windows\setpwr32.exe
2009-10-09 15:08 410,984 a——- c:\windows\system32\deploytk.dll
2009-10-09 15:01 87,263 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
============= FINISH: 11:56:28.06 ===============
First I want to thank you guys in advance for providing this site. It's awesome!! I believe I was infected from a crack/keygen (I allowed it to run even though warned by AV). Norton AV 2009 unable to clean after infected. Before familiarizing myself with the rules of posting, my computer had/has the symtoms described in the title and description. I have followed the steps in the 'Are you infected' section. However SysRestorePoint would not launch but I was able use the Windows Wizard. Further, GMER caused a Windows error but I saved the log at that time - may be incomplete. Ran GMER a second time (without reboot) and got the windows shutdown blue screen. After finishing the steps outlined in the 'Are you infected' section, pop-ups seem to be gone, task manager is enabled, ieaskie32.dll add on is no longer visable. I have not tested the safe mode yet. Your advise is greatly appreciated
Here are the logs:
Malwarebytes' Anti-Malware 1.42
Database version: 3439
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
12/27/2009 11:40:47 AM
mbam-log-2009-12-27 (11-40-29).txt
Scan type: Quick Scan
Objects scanned: 135706
Time elapsed: 4 minute(s), 23 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 4
Registry Keys Infected: 6
Registry Values Infected: 2
Registry Data Items Infected: 12
Folders Infected: 2
Files Infected: 31
Memory Processes Infected:
C:\Program Files\InternetSecurity2010\IS2010.exe (Rogue.Installer) -> No action taken.
C:\WINDOWS\system32\winupdate86.exe (Trojan.FakeAlert) -> No action taken.
Memory Modules Infected:
C:\WINDOWS\system32\icwdial32.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\2C9.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\__c0046212.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\__c00C9112.dat (Trojan.Agent) -> No action taken.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0f3f5df4-b7a9-48c4-9b4e-7a691ab4e84f} (Trojan.BHO.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{0f3f5df4-b7a9-48c4-9b4e-7a691ab4e84f} (Trojan.BHO.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cb1f7a0720 (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0f3f5df4-b7a9-48c4-9b4e-7a691ab4e84f} (Trojan.Tracur) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{0f3f5df4-b7a9-48c4-9b4e-7a691ab4e84f} (Trojan.Tracur) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0046212 (Trojan.Agent) -> No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\internet security 2010 (Rogue.Installer) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupdate86.exe (Trojan.Downloader) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Agent) -> Data: c:\windows\system32\icwdial32.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Agent) -> Data: system32\icwdial32.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\winlogon86.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\winlogon86.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\winlogon86.exe) Good: (Userinit.exe) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.
Folders Infected:
C:\WINDOWS\system32\SysWoW32 (Worm.Archive) -> No action taken.
C:\Program Files\InternetSecurity2010 (Rogue.InternetSecurity2010) -> No action taken.
Files Infected:
C:\WINDOWS\system32\ieaksie32.dll (Trojan.BHO.H) -> No action taken.
C:\WINDOWS\system32\icwdial32.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\2C9.tmp (Trojan.Agent) -> No action taken.
C:\Program Files\InternetSecurity2010\IS2010.exe (Rogue.Installer) -> No action taken.
C:\WINDOWS\system32\1.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\2.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\winhelper86.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\SysWoW32\mi1458286074v4.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\mi1458286074v6.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\mi1458286074v7.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\mu1458286074v5 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\mu1458286074v5.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v0 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v0.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v1 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v1.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v2 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v2.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v3 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v3.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\_u1458286074v0 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\_u1458286074v1 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\_u1458286074v2 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\_u1458286074v3 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\__c0046212.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\__c00B843E.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\__c00C9112.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\GnuHashes.ini (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\winupdate86.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\41.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\Winlogon86.exe (Trojan.FakeAlert) -> No action taken.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-27 11:50:33
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\DUANEP~1\LOCALS~1\Temp\pwldapog.sys
—- System - GMER 1.0.15 —-
SSDT 8900A6A0 ZwAlertResumeThread
SSDT 89027EF0 ZwAlertThread
SSDT 890326D8 ZwAllocateVirtualMemory
SSDT 8900E0C0 ZwAssignProcessToJobObject
SSDT 89113A08 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xA8A01130]
SSDT 890274E0 ZwCreateMutant
SSDT 8900D100 ZwCreateSymbolicLinkObject
SSDT 890150C0 ZwCreateThread
SSDT 8900E1A0 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA8A013B0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA8A01910]
SSDT 890006D0 ZwDuplicateObject
SSDT 88FFD6B0 ZwFreeVirtualMemory
SSDT 890275B0 ZwImpersonateAnonymousToken
SSDT 88FDC7D8 ZwImpersonateThread
SSDT 897D4648 ZwLoadDriver
SSDT 88FD5870 ZwMapViewOfSection
SSDT 8900F1A0 ZwOpenEvent
SSDT 89010710 ZwOpenProcess
SSDT 89010650 ZwOpenProcessToken
SSDT 890101E0 ZwOpenSection
SSDT 890007A0 ZwOpenThread
SSDT 8900D1D0 ZwProtectVirtualMemory
SSDT 89048E88 ZwResumeThread
SSDT 89031660 ZwSetContextThread
SSDT 89031740 ZwSetInformationProcess
SSDT 89010098 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA8A01B60]
SSDT 8900F0C0 ZwSuspendProcess
SSDT 89027FD0 ZwSuspendThread
SSDT 88FD7658 ZwTerminateProcess
SSDT 88FDC2D8 ZwTerminateThread
SSDT 88FDA6A8 ZwUnmapViewOfSection
SSDT 88FFD7A0 ZwWriteVirtualMemory
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] on Sun 12/27/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2013.1579 [GMT -6:00]
============== Running Processes ===============
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Quicken\Online Backup\OnlineBackup.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Duane Pankhurst\Desktop\whatthetech\dds.scr
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.live.com
uStart Page = hxxp://my.att.net/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\norton antivirus\engine\16.7.2.11\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Windows; Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [@BackupScheduler] c:\program files\quicken\online backup\OnlineBackup.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe"
mRun: [IJNetworkScanUtility] c:\program files\canon\canon ij network scan utility\CNMNSUT.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Notify: igfxcui - igfxdev.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1007020.00b\SymEFA.sys [2009-11-27 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1007020.00b\BHDrvx86.sys [2009-11-27 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1007020.00b\cchpx86.sys [2009-11-27 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20091217.002\IDSXpx86.sys [2009-12-18 329592]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-11 30312]
R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-12-18 155648]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\norton antivirus\engine\16.7.2.11\ccSvcHst.exe [2009-11-27 117640]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-12-23 102448]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2009-5-27 29262680]
S3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20091226.025\NAVENG.SYS [2009-12-27 84912]
S3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20091226.025\NAVEX15.SYS [2009-12-27 1323568]
=============== Created Last 30 ================
2009-12-27 11:33 –d—– c:\docume~1\duanep~1\applic~1\Malwarebytes
2009-12-27 11:33 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-27 11:33 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-27 11:33 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-12-27 11:33 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-12-27 08:29 0 a——- c:\windows\system32\18467.exe
2009-12-23 20:18 35 a——- c:\windows\system32\5c31f0a7
2009-12-23 19:50 1,254 a–sh— c:\windows\system32\1558292464
2009-12-23 19:50 817 a——- c:\windows\system32\212989856
2009-12-23 19:49 –d—– c:\windows\system32\1048809671
2009-12-23 19:49 203,776 —sh— c:\windows\system32\unrar.exe
2009-12-23 19:36 –d—– c:\docume~1\duanep~1\applic~1\LimeWire
2009-12-17 19:30 –d—– c:\docume~1\duanep~1\applic~1\Final Draft
2009-12-17 19:25 1,073,152 a—-r– c:\windows\system32\cdintf210.dll
2009-12-17 19:25 –d—– c:\docume~1\alluse~1\applic~1\Final Draft
2009-12-17 19:24 –d—– c:\program files\Final Draft Tagger
2009-12-17 19:24 –d—– c:\program files\Final Draft 7
2009-12-17 19:24 –d—– c:\program files\common files\Wise Installation Wizard
2009-12-01 18:56 –d—– C:\UBCD4Win
2009-12-01 18:37 –d—– C:\xpcd
2009-12-01 17:49 –d—– C:\vista cd
2009-12-01 17:48 1,905 a——- c:\windows\diagwrn.xml
2009-12-01 17:48 1,905 a——- c:\windows\diagerr.xml
2009-11-29 08:10 –d—– C:\Intel
2009-11-28 08:29 36,400 a—-r– c:\windows\system32\drivers\SymIM.sys
==================== Find3M ====================
2009-11-27 16:02 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-11-27 16:02 60,808 a——- c:\windows\system32\S32EVNT1.DLL
2009-11-27 16:02 7,456 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2009-11-27 16:02 806 a——- c:\windows\system32\drivers\SYMEVENT.INF
2009-10-29 01:45 916,480 a——- c:\windows\system32\wininet.dll
2009-10-27 20:21 614 a——- c:\docume~1\duanep~1\applic~1\wklnhst.dat
2009-10-20 23:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-20 23:38 25,088 a——- c:\windows\system32\httpapi.dll
2009-10-13 04:30 270,336 a——- c:\windows\system32\oakley.dll
2009-10-12 07:38 149,504 a——- c:\windows\system32\rastls.dll
2009-10-12 07:38 79,872 a——- c:\windows\system32\raschap.dll
2009-10-09 17:54 77,824 a——- c:\windows\setpwr32.exe
2009-10-09 15:08 410,984 a——- c:\windows\system32\deploytk.dll
2009-10-09 15:01 87,263 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
============= FINISH: 11:56:28.06 ===============