This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] many infections incl. Trojan.FakeAlert, Malware.Trace, Spyw

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I'm unable to boot into Vista normally. I have to use safe mode. When I try to boot normally all I see is a black screen and my cursor. However if I press ctrl-alt-delete, a screen will come up that will give me options such as switch users, shut off computer, etc.
I've run ATF cleaner, ERUNT, MBAM, GMER Rootkit Scanner and DDS. I've also run SuperAntiSpyware. I was unable to use SysRestorePoint because I can't run it in safemode.
Any help would be appreciated.


**********************MBAM log*************************
Malwarebytes' Anti-Malware 1.43
Database version: 3495
Windows 6.0.6002 Service Pack 2 (Safe Mode)
Internet Explorer 8.0.6001.18828

05/01/2010 1:49:20 AM
mbam-log-2010-01-05 (01-49-20).txt

Scan type: Quick Scan
Objects scanned: 122583
Time elapsed: 4 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 4
Registry Data Items Infected: 9
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\LEO0WTUNO7 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AvScan (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\J8RPLTROBQ (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls\appsecdll (Spyware.Passwords) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\losalamos (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Spyware.Passwords) -> Data: c:\windows\system32\kbdsock.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Spyware.Passwords) -> Data: system32\kbdsock.dll -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\kbdsock.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\Windows\System32\41.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\System32\flags.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\Windows\System32\uses32.dat (Malware.Trace) -> Quarantined and deleted successfully.




**********************GMER log*************************
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-05 13:13:12
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\sonam\AppData\Local\Temp\fglcypow.sys


—- Devices - GMER 1.0.15 —-

Device \FileSystem\fastfat \Fat 8EBAAA7A

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-




**********************DDS log*************************
DDS (Ver_09-06-26.01) - NTFSx86 NETWORK
Run by [removed] at 13:16:27.98 on 05/01/2010
Internet Explorer: 8.0.6001.18828
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.3070.2110 [GMT -5:00]

AV: Symantec AntiVirus *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
SP: Symantec AntiVirus *enabled* (Updated) {6C85A515-B91D-4D2B-AF18-40984A4A8493}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Users\sonam\Downloads\dds.scr

============== Pseudo HJT Report ===============

uWindow Title = Internet Explorer provided by Dell
uDefault_Page_URL = hxxp://www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=0081004
BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
TB: Veoh Browser Plug-in: {d0943516-5076-4020-a3b5-aefaf26ab263} - c:\program files\veoh networks\veoh\plugins\reg\VeohToolbar.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll
TB: Veoh Video Compass: {52836eb0-631a-47b1-94a6-61f9d9112dae} - c:\program files\veoh networks\veoh video compass\SearchRecsPlugin.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: []
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [VeohPlugin] "c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [PMX Daemon] ICO.EXE
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: []
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [QuickTime Task] "c:\program files\qt lite\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRunOnce: [TSC] "c:\users\sonam\appdata\local\temp\housecall\tsc.exe" /HD
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\users\sonam\appdata\roaming\micros~1\windows\startm~1\programs\startup\delldo~1.lnk - c:\program files\dell\delldock\DellDock.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\users\sonam\appdata\roaming\mozilla\firefox\profiles\1arsg2p9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.sciencedaily.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\users\sonam\appdata\roaming\mozilla\firefox\profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\opera\program\plugins\npdivx32.dll
FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\sonam\appdata\roaming\mozilla\firefox\profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\users\sonam\appdata\roaming\mozilla\plugins\npoctoshape.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R3 HssDrv;Hotspot Shield Helper Miniport;c:\windows\system32\drivers\HssDrv.sys [2009-11-12 37376]
R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-10-3 18432]
R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-10-3 19008]
R3 taphss;Anchorfree HSS Adapter;c:\windows\system32\drivers\taphss.sys [2009-11-12 32768]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2010-1-4 28552]
S1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-6-23 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 74480]
S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2008-10-4 73728]
S2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-5-2 161048]
S2 HssSrv;Hotspot Shield Routing Service;c:\program files\hotspot shield\hsswpr\hsssrv.exe [2009-11-12 331824]
S2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt60.sys [2008-10-3 27648]
S2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-9-4 102448]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-10-27 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 HssTrayService;Hotspot Shield Tray Service;c:\program files\hotspot shield\bin\HssTrayService.exe [2009-11-17 57640]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2008-12-23 50704]
S3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v2.sys [2007-12-26 288768]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 7408]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-11-28 122008]

=============== Created Last 30 ================

2010-01-05 02:03 0 a——- c:\windows\system32\cd.dat
2010-01-05 02:00 267,570,562 a——- c:\windows\MEMORY.DMP
2010-01-05 01:42 –d—– c:\users\sonam\appdata\roaming\Malwarebytes
2010-01-05 01:42 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-05 01:42 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-05 01:42 –d—– c:\programdata\Malwarebytes
2010-01-05 01:42 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-05 01:42 –d—– c:\progra~2\Malwarebytes
2010-01-04 23:27 28,552 a——- c:\windows\system32\drivers\pavboot.sys
2010-01-04 23:27 –d—– c:\program files\Panda Security
2010-01-04 23:24 –d—– c:\users\sonam\appdata\roaming\QuickScan
2010-01-04 23:21 -cd—– c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2010-01-04 23:21 -cd—– c:\progra~2\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2009-12-27 01:47 0 a——- c:\windows\system32\29798.exe
2009-12-27 01:27 0 a——- c:\windows\system32\17746.exe
2009-12-27 01:07 0 a——- c:\windows\system32\21764.exe
2009-12-27 00:47 0 a——- c:\windows\system32\24373.exe
2009-12-27 00:27 0 a——- c:\windows\system32\14196.exe
2009-12-27 00:07 0 a——- c:\windows\system32\11825.exe
2009-12-26 23:47 0 a——- c:\windows\system32\9603.exe
2009-12-26 23:27 0 a——- c:\windows\system32\22095.exe
2009-12-26 23:07 0 a——- c:\windows\system32\30457.exe
2009-12-26 22:47 0 a——- c:\windows\system32\1629.exe
2009-12-26 22:27 0 a——- c:\windows\system32\31454.exe
2009-12-26 22:07 0 a——- c:\windows\system32\16390.exe
2009-12-26 21:47 0 a——- c:\windows\system32\2555.exe
2009-12-26 21:27 0 a——- c:\windows\system32\28195.exe
2009-12-26 21:23 744 a——- c:\windows\system32\wininit.dll
2009-12-26 20:27 0 a——- c:\windows\system32\19912.exe
2009-12-26 20:07 0 a——- c:\windows\system32\1869.exe
2009-12-26 19:47 0 a——- c:\windows\system32\11538.exe
2009-12-26 19:27 0 a——- c:\windows\system32\14771.exe
2009-12-26 19:07 0 a——- c:\windows\system32\21726.exe
2009-12-26 18:47 0 a——- c:\windows\system32\5447.exe
2009-12-26 18:27 0 a——- c:\windows\system32\19895.exe
2009-12-26 18:07 0 a——- c:\windows\system32\19718.exe
2009-12-26 17:47 0 a——- c:\windows\system32\18716.exe
2009-12-26 17:27 0 a——- c:\windows\system32\17421.exe
2009-12-26 17:07 0 a——- c:\windows\system32\12382.exe
2009-12-26 16:47 0 a——- c:\windows\system32\292.exe
2009-12-26 16:27 0 a——- c:\windows\system32\153.exe
2009-12-26 16:07 0 a——- c:\windows\system32\3902.exe
2009-12-26 15:47 0 a——- c:\windows\system32\14604.exe
2009-12-26 15:27 0 a——- c:\windows\system32\32391.exe
2009-12-26 15:07 0 a——- c:\windows\system32\5436.exe
2009-12-26 14:47 0 a——- c:\windows\system32\4827.exe
2009-12-26 14:27 0 a——- c:\windows\system32\11942.exe
2009-12-26 14:07 0 a——- c:\windows\system32\2995.exe
2009-12-26 13:47 0 a——- c:\windows\system32\491.exe
2009-12-26 13:27 0 a——- c:\windows\system32\9961.exe
2009-12-26 13:07 0 a——- c:\windows\system32\16827.exe
2009-12-26 12:47 0 a——- c:\windows\system32\23281.exe
2009-12-26 12:27 0 a——- c:\windows\system32\28145.exe
2009-12-26 12:07 0 a——- c:\windows\system32\5705.exe
2009-12-26 11:47 0 a——- c:\windows\system32\24464.exe
2009-12-26 11:27 0 a——- c:\windows\system32\26962.exe
2009-12-26 11:07 0 a——- c:\windows\system32\29358.exe
2009-12-26 10:47 0 a——- c:\windows\system32\11478.exe
2009-12-26 10:27 0 a——- c:\windows\system32\15724.exe
2009-12-26 10:07 0 a——- c:\windows\system32\19169.exe
2009-12-26 09:47 0 a——- c:\windows\system32\26500.exe
2009-12-26 09:27 0 a——- c:\windows\system32\6334.exe
2009-12-26 09:07 0 a——- c:\windows\system32\18467.exe
2009-12-26 08:42 1 a——- C:\s
2009-12-25 16:44 –d—– c:\program files\VirtualDubMOD
2009-12-25 14:32 –d—– c:\users\sonam\appdata\roaming\GetRightToGo
2009-12-25 14:18 –d—– c:\users\sonam\appdata\roaming\AVSMedia
2009-12-25 14:16 221,215 a——- c:\windows\system32\divxdec.ax
2009-12-10 03:00 –d—– C:\Hotspot Shield

==================== Find3M ====================

2009-12-10 03:00 143,360 a——- c:\windows\inf\infstrng.dat
2009-12-10 03:00 51,200 a——- c:\windows\inf\infpub.dat
2009-12-10 03:00 143,360 a——- c:\windows\inf\infstor.dat
2009-12-05 19:42 85,504 a——- c:\windows\system32\ff_vfw.dll
2009-11-18 03:21 665,600 a——- c:\windows\inf\drvindex.dat
2009-11-18 03:20 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-12 16:42 37,376 a——- c:\windows\system32\drivers\HssDrv.sys
2009-11-12 16:42 32,768 a——- c:\windows\system32\drivers\taphss.sys
2009-11-02 20:42 195,456 ——– c:\windows\system32\MpSigStub.exe
2009-10-29 04:17 2,048 a——- c:\windows\system32\tzres.dll
2009-10-16 15:01 319,456 a——- c:\windows\DIFxAPI.dll
2009-10-16 15:00 315,392 a——- c:\windows\HideWin.exe
2009-10-08 16:08 555,520 a——- c:\windows\system32\UIAutomationCore.dll
2009-10-08 16:08 234,496 a——- c:\windows\system32\oleacc.dll
2009-10-08 16:07 4,096 a——- c:\windows\system32\oleaccrc.dll
2009-10-08 14:53 413,696 a——- c:\windows\system32\wrap_oal.dll
2009-10-08 14:53 110,592 a——- c:\windows\system32\OpenAL32.dll
2008-10-22 10:56 87,608 a——- c:\users\sonam\appdata\roaming\inst.exe
2008-10-22 10:56 47,360 a——- c:\users\sonam\appdata\roaming\pcouffin.sys
2008-10-16 17:00 61,224 a——- c:\users\sonam\GoToAssistDownloadHelper.exe
2008-01-20 21:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 13:16:39.65 ===============



DDS (Ver_09-06-26.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 03/10/2008 6:35:47 PM
System Uptime: 01/05/2010 2:12:14 AM (-2773 hours ago)

Motherboard: Dell Inc. | | 0M017G
Processor: Intel® Core™2 Quad CPU Q6600 @ 2.40GHz | CPU 1 | 2400/267mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 916 GiB total, 104.547 GiB free.
D: is FIXED (NTFS) - 15 GiB total, 10.172 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is FIXED (NTFS) - 298 GiB total, 32.069 GiB free.

==== Disabled Device Manager Items =============

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

7-Zip 4.60 beta
AAC Decoder
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9
AnyDVD
Apple Mobile Device Support
Apple Software Update
Ares 2.1.1
ATI Catalyst Install Manager
µTorrent
Audacity 1.2.6
Audacity Recovery Utility
AutoUpdate
AviSynth 2.5
AVS Video Converter 6
AVS4YOU Software Navigator 1.3
BlackBerry Desktop Software 5.0
Bonjour
Boxee
Browser Address Error Redirector
Burn4Free CD and DVD
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
ccc-utility
CCC Help English
CCleaner
CDBurnerXP
Citrix Presentation Server Client - Web Only
CloneDVD [removed]
Compatibility Pack for the 2007 Office system
ConvertXtoDVD [removed]
d2mp
Dell-eBay
Dell Dock
Dell Driver Download Manager
Dell Getting Started Guide
Dell Support Center (Support Software)
Dell Video Chat (remove only)
DeVeDe 3.11b
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
DVD Decrypter (Remove Only)
DVD Flick 1.3.0.7
DVD Shrink 3.2
EDocs
eMule
ERUNT 1.1j
ffdshow [rev 3164] [2009-12-14]
Free Ipod Video Converter V 2.6
FrostWire 4.18.4
Google Desktop
GoToAssist 8.0.0.514
Graboid Video 1.65
H.264 Decoder
Haali Media Splitter
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotspot Shield 1.34
ImgBurn
Intel® Graphics Media Accelerator Driver
iPodifier
iTunes
IZArc 3.81
Java™ 6 Update 7
Junk Mail filter update
Livestation
LiveUpdate 3.2 (Symantec Corporation)
Malwarebytes' Anti-Malware
MediaCoder 0.6.2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Live Add-in 1.3
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Works
MKV Splitter
MKVtoolnix 2.2.0
Mouse Suite for Desktop Computers
Mozilla ActiveX Control v1.7.12
Mozilla Firefox (3.5.6)
MP3 Cutter Joiner 3.00
MPEG Joiner
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 8
neroxml
Octoshape Streaming Services
OpenAL
Opera 10.10
Orbit Downloader
Panda ActiveScan 2.0
PowerDVD
QT Lite 2.7.0
QuickTime
Real Alternative 1.9.0
RealPlayer
Realtek 8169 8168 8101E 8102E Ethernet Driver
Realtek Ethernet Network Card Diagnostic tool for Windows Vista
Roxio Creator Audio
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Express Labeler 3
Roxio Media Manager
Roxio Update Manager
Safari
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB969693)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Skins
Sothink Movie DVD Maker
SoulSeek 157 NS 13c
StaxRip 1.1.1.0
SUPERAntiSpyware Free Edition
Symantec AntiVirus
TVAnts 1.0
TVUPlayer [removed]
Ultra QuickTime Converter 2.3.0916
Ultra RM Converter 4.0.1127
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (kb975960)
URL Snooper v2.23.01
VC80CRTRedist - 8.0.50727.762
Veoh Video Compass
Veoh Web Player
VeohTV BETA
VideoLAN VLC media player 0.8.6d
Videora iPod Converter 4.08
VirtualDubMOD [removed] US
WinAVI MP4 Converter
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live OneCare safety scanner
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Player Firefox Plugin
WinPcap 4.1 beta5
WinRAR archiver
XviD 1.1 final uninstall

==== Event Viewer Messages From Past Week ========

29/12/2009 9:38:45 PM, Error: EventLog [6008] - The previous system shutdown at 9:35:26 PM on 29/12/2009 was unexpected.
29/12/2009 9:28:30 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WSearch service.
29/12/2009 2:59:31 AM, Error: Microsoft-Windows-Windows Defender [1008] - Windows Defender has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=370…threatid=136837 Scan ID: {D747AAA7-78E0-404A-9CE3-1C8494930B38} Scan Type: AntiMalware User: NT AUTHORITY\NETWORK SERVICE Name: Trojan:Win32/Alureon.BF ID: 136837 Severity ID: 5 Category ID: 8 Path: Action: Remove Error Code: 0x80508022 Error description: To finish removing spyware and other potentially unwanted software, restart the computer.
05/01/2010 2:16:36 AM, Error: Service Control Manager [7001] - The PnP-X IP Bus Enumerator service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
05/01/2010 2:15:40 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: eeCtrl ElbyCDIO pavboot SASDIFSV SASKUTIL SPBBCDrv spldr SRTSP SRTSPX SYMTDI Wanarpv6
05/01/2010 2:15:40 AM, Error: Service Control Manager [7001] - The Windows Media Center Extender Service service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
05/01/2010 2:15:40 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
05/01/2010 2:15:03 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
05/01/2010 2:14:54 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
05/01/2010 2:14:48 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
05/01/2010 2:14:36 AM, Error: Microsoft-Windows-TerminalServices-LocalSessionManager [1048] - Terminal Service start failed. The relevant status code was This service cannot be started in Safe Mode .
05/01/2010 2:14:36 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service TermService with arguments "" in order to run the server: {F9A874B6-F8A8-4D73-B5A8-AB610816828B}
05/01/2010 2:14:36 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
05/01/2010 2:06:35 AM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume OS.
05/01/2010 2:04:36 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Roxio Hard Drive Watcher 9 service to connect.
05/01/2010 2:03:03 AM, Error: EventLog [6008] - The previous system shutdown at 1:57:46 AM on 05/01/2010 was unexpected.
05/01/2010 2:02:11 AM, Error: volsnap [27] - The shadow copies of volume C: were aborted during detection because a critical control file could not be opened.
05/01/2010 2:01:28 AM, Error: volsnap [25] - The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time. Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied.
05/01/2010 12:01:19 AM, Error: EventLog [6008] - The previous system shutdown at 11:57:39 PM on 04/01/2010 was unexpected.
04/01/2010 11:56:05 PM, Error: Service Control Manager [7034] - The SupportSoft Sprocket Service (dellsupportcenter) service terminated unexpectedly. It has done this 1 time(s).
04/01/2010 11:50:53 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the SeaPort service to connect.
04/01/2010 11:50:53 PM, Error: Service Control Manager [7000] - The SeaPort service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
04/01/2010 11:21:25 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
04/01/2010 11:09:20 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service LiveUpdate with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}
04/01/2010 11:07:40 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service Symantec AntiVirus with arguments "" in order to run the server: {98694799-6891-4FD7-A91D-FB43B78AEC8C}
04/01/2010 11:05:04 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: eeCtrl ElbyCDIO SASDIFSV SASKUTIL SPBBCDrv spldr SRTSP SRTSPX SYMTDI Wanarpv6
03/01/2010 11:01:27 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Hi , welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

uTorrent
You have uTorrent, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it. It's not the program itself that is the problem, but what can be downloaded with it, usually from an unknown source.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall uTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

NEXT

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Right click on ComboFix.exe, click Run as Administrator & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please post back with
  • combofix log
Can you get into normal windows now?

Thanks
Hi oldman960, thank you for replying. I was about to run combofix. I thought no antivirus programs were running but combofix notified me that symantec antivirus was active. The symantec icon is not in the taskbar notification area so I can't disable it from there. My computer is running in safemode. When I open windows task manager, symantec isn't listed under the processes tab so I'm not sure if it is running. Could you tell me how I can disable symantec so I can run combofix? Thank you
Hi houngan,

We'll run it a bit differently. If combofix still complains just continue the scan.

This will only work if combofix is directly on the desktop.

Click the Windows 'Start' button > Select 'Run' - then copy/paste this into the run box & click OK:

"%userprofile%\desktop\combofix.exe" /killall
Thanks a lot oldman960, windows is now loading normally.

Combofix produced 2 logs.

here's the first one at C:\ComboFix.txt


ComboFix 10-01-04.01 - sonam 05/01/2010 16:58:24.1.4 - x86 NETWORK
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.3070.2445 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\combofix.exe
Command switches used :: /killall
AV: Symantec AntiVirus *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Symantec AntiVirus *enabled* (Updated) {6C85A515-B91D-4D2B-AF18-40984A4A8493}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
ADS - Windows: deleted 24 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2773397201-2855733099-4214572315-500
c:\$recycle.bin\S-1-5-21-807892715-3149862127-586907164-500
C:\s
c:\users\sonam\AppData\Roaming\inst.exe
c:\users\sonam\Documents\cc_20081229_190759.reg
c:\windows\system32\11478.exe
c:\windows\system32\11538.exe
c:\windows\system32\11825.exe
c:\windows\system32\11942.exe
c:\windows\system32\12382.exe
c:\windows\system32\14196.exe
c:\windows\system32\14604.exe
c:\windows\system32\14771.exe
c:\windows\system32\153.exe
c:\windows\system32\15724.exe
c:\windows\system32\1629.exe
c:\windows\system32\16390.exe
c:\windows\system32\16827.exe
c:\windows\system32\17421.exe
c:\windows\system32\17746.exe
c:\windows\system32\18467.exe
c:\windows\system32\1869.exe
c:\windows\system32\18716.exe
c:\windows\system32\19169.exe
c:\windows\system32\19718.exe
c:\windows\system32\19895.exe
c:\windows\system32\19912.exe
c:\windows\system32\21726.exe
c:\windows\system32\21764.exe
c:\windows\system32\22095.exe
c:\windows\system32\23281.exe
c:\windows\system32\24373.exe
c:\windows\system32\24464.exe
c:\windows\system32\2555.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\28145.exe
c:\windows\system32\28195.exe
c:\windows\system32\292.exe
c:\windows\system32\29358.exe
c:\windows\system32\29798.exe
c:\windows\system32\2995.exe
c:\windows\system32\30457.exe
c:\windows\system32\31454.exe
c:\windows\system32\32391.exe
c:\windows\system32\3902.exe
c:\windows\system32\4827.exe
c:\windows\system32\491.exe
c:\windows\system32\5436.exe
c:\windows\system32\5447.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\9603.exe
c:\windows\system32\9961.exe
c:\windows\system32\wininit.dll

.
((((((((((((((((((((((((( Files Created from 2009-12-05 to 2010-01-05 )))))))))))))))))))))))))))))))
.

2010-01-05 22:09 . 2010-01-05 22:09 ——– d—–w- c:\users\sonam\AppData\Local\Adobe
2010-01-05 22:03 . 2010-01-05 22:09 ——– d—–w- c:\users\sonam\AppData\Local\temp
2010-01-05 22:03 . 2010-01-05 22:03 ——– d—–w- c:\users\Mcx1\AppData\Local\temp
2010-01-05 22:03 . 2010-01-05 22:03 ——– d—–w- c:\users\Guest\AppData\Local\temp
2010-01-05 22:03 . 2010-01-05 22:03 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-01-05 07:03 . 2010-01-05 07:03 0 —-a-w- c:\windows\system32\cd.dat
2010-01-05 06:42 . 2010-01-05 06:42 ——– d—–w- c:\users\sonam\AppData\Roaming\Malwarebytes
2010-01-05 06:42 . 2009-12-30 19:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-05 06:42 . 2010-01-05 06:42 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-05 06:42 . 2010-01-05 06:42 ——– d—–w- c:\programdata\Malwarebytes
2010-01-05 06:42 . 2009-12-30 19:54 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-05 06:39 . 2010-01-05 06:39 ——– d—–w- c:\program files\ERUNT
2010-01-05 04:27 . 2009-06-30 14:37 28552 —-a-w- c:\windows\system32\drivers\pavboot.sys
2010-01-05 04:27 . 2010-01-05 04:27 ——– d—–w- c:\program files\Panda Security
2010-01-05 04:24 . 2010-01-05 05:14 ——– d—–w- c:\users\sonam\AppData\Roaming\QuickScan
2010-01-05 04:21 . 2010-01-05 04:21 ——– dc—-w- c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2009-12-26 13:43 . 2009-12-30 03:22 ——– d—–w- c:\users\sonam\AppData\Local\kksrvn
2009-12-26 06:18 . 2009-12-26 06:18 ——– d—–w- c:\windows\Sun
2009-12-25 21:44 . 2009-12-25 21:44 ——– d—–w- c:\program files\VirtualDubMOD
2009-12-25 19:32 . 2009-12-25 19:32 ——– d—–w- c:\users\sonam\AppData\Roaming\GetRightToGo
2009-12-25 19:18 . 2009-12-25 19:20 ——– d—–w- c:\users\sonam\AppData\Roaming\AVSMedia
2009-12-25 19:15 . 2009-12-25 19:15 ——– d—–w- c:\users\sonam\AppData\Roaming\Download Manager
2009-12-10 08:00 . 2009-12-10 08:00 ——– d—–w- C:\Hotspot Shield
2009-12-10 07:31 . 2009-12-10 07:31 ——– d—–w- c:\users\sonam\AppData\Local\Graboid

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-05 21:45 . 2008-11-17 04:21 ——– d—–w- c:\program files\7-Zip
2010-01-05 21:05 . 2009-11-23 23:41 ——– d—–w- c:\program files\Real
2010-01-05 21:05 . 2009-11-23 23:41 ——– d—–w- c:\program files\Common Files\Real
2010-01-05 19:22 . 2009-07-29 19:38 ——– d—–w- c:\users\sonam\AppData\Roaming\vlc
2010-01-05 19:22 . 2008-10-16 21:06 7512 —-a-w- c:\users\sonam\AppData\Local\d3d9caps.dat
2010-01-05 05:19 . 2009-12-26 00:04 52224 —-a-w- c:\users\sonam\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-05 05:19 . 2009-07-17 16:06 117760 —-a-w- c:\users\sonam\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-03 05:26 . 2010-01-05 04:24 789320 —-a-w- c:\users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
2010-01-03 05:26 . 2010-01-05 04:24 697672 —-a-w- c:\users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
2009-12-30 02:33 . 2008-10-16 00:07 117304 —-a-w- c:\users\sonam\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-30 02:26 . 2009-10-11 05:08 ——– d—–w- c:\users\sonam\AppData\Roaming\Orbit
2009-12-26 00:20 . 2008-10-22 15:56 ——– d—–w- c:\users\sonam\AppData\Roaming\Vso
2009-12-26 00:01 . 2009-07-17 16:05 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-12-26 00:00 . 2008-10-18 01:09 ——– d—–w- c:\program files\Common Files\AVSMedia
2009-12-25 23:59 . 2008-10-18 01:41 ——– d—–w- c:\program files\AVSMedia
2009-12-25 21:47 . 2008-10-16 18:22 ——– d—–w- c:\users\sonam\AppData\Roaming\dvdcss
2009-12-24 05:50 . 2008-10-16 04:07 ——– d—–w- c:\users\sonam\AppData\Roaming\uTorrent
2009-12-24 04:33 . 2008-11-02 20:48 ——– d—–w- c:\program files\ffdshow
2009-12-18 00:30 . 2008-10-16 01:54 ——– d—–w- c:\users\sonam\AppData\Roaming\FrostWire
2009-12-14 09:00 . 2010-01-05 04:56 259440 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20100104.004\ECMSVR32.DLL
2009-12-14 09:00 . 2010-01-05 04:56 2747440 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20100104.004\CCERASER.DLL
2009-12-14 09:00 . 2009-12-14 09:00 2747440 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\cceraser.dll
2009-12-14 09:00 . 2009-12-14 09:00 259440 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ecmsvr32.dll
2009-12-10 16:17 . 2009-12-10 16:17 5562672 —-a-w- c:\users\sonam\AppData\Roaming\TVU networks\AutoUpgrade\TVUPlayer2.4.9.1.exe
2009-12-10 16:17 . 2008-12-14 00:19 ——– d—–w- c:\users\sonam\AppData\Roaming\TVU networks
2009-12-10 09:00 . 2009-12-29 09:01 2747440 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20091228.004\CCERASER.DLL
2009-12-10 08:01 . 2008-10-17 01:46 ——– d—–w- c:\program files\Hotspot Shield
2009-12-10 07:30 . 2009-01-03 23:46 ——– d—–w- c:\program files\Graboid
2009-12-06 00:42 . 2008-11-02 21:05 85504 —-a-w- c:\windows\system32\ff_vfw.dll
2009-12-05 12:16 . 2009-12-05 12:16 764168 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-04 05:56 . 2009-04-07 01:15 ——– d—–w- c:\program files\Opera
2009-11-18 08:21 . 2009-11-18 08:21 ——– d—–w- c:\program files\Windows Portable Devices
2009-11-18 08:21 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-18 08:20 . 2009-11-18 08:20 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-17 20:53 . 2009-11-17 18:39 ——– d—–w- c:\users\sonam\AppData\Roaming\ICAClient
2009-11-17 18:35 . 2009-11-17 18:35 38480 —-a-r- c:\users\sonam\AppData\Roaming\Microsoft\Installer\{C49067A8-8212-4A82-A4D9-1519701644F0}\Icon80951CEC.exe.C76E2E86_AE54_4AF5_997C_63EBB83C7651.exe
2009-11-17 18:35 . 2009-11-17 18:35 38480 —-a-r- c:\users\sonam\AppData\Roaming\Microsoft\Installer\{C49067A8-8212-4A82-A4D9-1519701644F0}\Icon80951CEC.exe.20FBBF0A_A7E5_4BDE_9798_9811C3D135AC.exe
2009-11-17 18:35 . 2009-11-17 18:35 38480 —-a-r- c:\users\sonam\AppData\Roaming\Microsoft\Installer\{C49067A8-8212-4A82-A4D9-1519701644F0}\ARPICON.80486C74_ABED_4227_AF5C_9B1791CFA89C.exe
2009-11-17 18:35 . 2009-11-17 18:35 26192 —-a-r- c:\users\sonam\AppData\Roaming\Microsoft\Installer\{C49067A8-8212-4A82-A4D9-1519701644F0}\Iconlights.ico.827545C6_7013_4DE1_8E6C_DAEE4C57F54A.exe
2009-11-17 03:52 . 2008-10-16 01:54 ——– d—–w- c:\program files\FrostWire
2009-11-12 21:42 . 2009-11-12 21:42 37376 —-a-w- c:\windows\system32\drivers\HssDrv.sys
2009-11-12 21:42 . 2009-11-12 21:42 32768 —-a-w- c:\windows\system32\drivers\taphss.sys
2009-11-11 07:07 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-11-11 06:55 . 2008-12-06 18:54 ——– d—–w- c:\programdata\Microsoft Help
2009-11-03 01:42 . 2009-10-03 04:29 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-10-29 09:17 . 2009-11-25 08:01 2048 —-a-w- c:\windows\system32\tzres.dll
2009-10-16 20:01 . 2009-10-16 20:01 319456 —-a-w- c:\windows\DIFxAPI.dll
2009-10-16 20:00 . 2009-10-16 20:00 315392 —-a-w- c:\windows\HideWin.exe
2009-10-16 19:45 . 2009-10-16 19:45 10134 —-a-r- c:\users\sonam\AppData\Roaming\Microsoft\Installer\{04FDC8D5-704E-D6FF-6C0F-F243EB1EA544}\ARPPRODUCTICON.exe
2009-10-16 08:00 . 2009-12-29 09:01 259440 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20091228.004\ECMSVR32.DLL
2009-10-11 05:01 . 2009-10-11 05:01 46 —-a-w- c:\windows\system32\DonationCoder_urlsnooper_InstallInfo.dat
2009-10-10 19:38 . 2009-10-10 19:38 117304 —-a-w- c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2009-10-08 21:08 . 2009-11-18 08:00 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-11-18 08:00 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-11-18 08:00 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2009-10-08 19:53 . 2009-10-08 19:53 413696 —-a-w- c:\windows\system32\wrap_oal.dll
2009-10-08 19:53 . 2009-10-08 19:53 110592 —-a-w- c:\windows\system32\OpenAL32.dll
2009-04-15 20:24 . 2009-04-15 20:24 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-04-15 20:24 . 2009-04-15 20:24 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-04-15 20:24 . 2009-04-15 20:24 1044480 —-a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-04-15 20:24 . 2009-04-15 20:24 200704 —-a-w- c:\program files\opera\program\plugins\ssldivx.dll
2008-10-04 06:22 . 2008-10-04 06:21 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-12-10 07:57 218160 —-a-w- c:\program files\Hotspot Shield\hssie\HssIE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-10-06 2075384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"PMX Daemon"="ICO.EXE" [2006-11-08 49152]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-10-04 29744]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-17 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-17 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-17 145944]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-11-22 107112]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-11-28 134808]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-07-02 623960]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2009-04-11 236016]
"QuickTime Task"="c:\program files\QT Lite\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-01-28 61440]

c:\users\sonam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-10-20 15:25 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-10-04 04:01 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"VistaSp2"=hex(B):42,01,7e,d3,31,4e,ca,01

R0 pavboot;pavboot;c:\windows\System32\drivers\pavboot.sys [04/01/2010 11:27 PM 28552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23/06/2009 10:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23/06/2009 10:01 AM 74480]
R2 AERTFilters;Andrea RT Filters Service;c:\windows\System32\AERTSrv.exe [04/10/2008 1:28 AM 73728]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [02/05/2008 2:09 PM 161048]
R2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\System32\drivers\RtNdPt60.sys [03/10/2008 10:47 PM 27648]
R3 pmxmouse;PMXMOUSE;c:\windows\System32\drivers\pmxmouse.sys [03/10/2008 10:46 PM 18432]
R3 pmxusblf;PMXUSBLF;c:\windows\System32\drivers\pmxusblf.sys [03/10/2008 10:46 PM 19008]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [20/01/2008 9:23 PM 21504]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [27/10/2009 10:29 PM 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 9:48 PM 704864]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\System32\drivers\npf.sys [23/12/2008 10:35 AM 50704]
S3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\System32\drivers\wg111v2.sys [26/12/2007 2:46 AM 288768]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [23/06/2009 10:01 AM 7408]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [28/11/2006 6:34 AM 122008]

— Other Services/Drivers In Memory —

*NewlyCreated* - ERASERUTILDRVI9
*Deregistered* - EraserUtilDrvI9

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-01-05 c:\windows\Tasks\RtlNICDiagVistaStart.job
- c:\program files\Realtek\RTNICDiag\RTNICDiag.exe [2008-10-04 11:18]
.
.
——- Supplementary Scan ——-
.
IE: &Download; by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab; video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload; selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load; all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
FF - ProfilePath - c:\users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.sciencedaily.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;=
FF - component: c:\users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\users\sonam\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-05 17:09
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Hotspot Shield\HssWPR\hsssrv.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Hotspot Shield\bin\openvpntray.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\vssvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2010-01-05 17:15:39 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-05 22:15

Pre-Run: The system cannot find message text for message number 0x2379 in the message file for Application.
Post-Run: 122,838,011,904 bytes free

- - End Of File - - 9F01B5F0536D09DD3E73B886892579A7








and this another log by combofix after it rebooted my computer and ran itself

ComboFix 10-01-04.01 - sonam 05/01/2010 16:58:24.1.4 - x86 NETWORK
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.3070.2445 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\combofix.exe
Command switches used :: /killall
AV: Symantec AntiVirus *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Symantec AntiVirus *enabled* (Updated) {6C85A515-B91D-4D2B-AF18-40984A4A8493}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
ADS - Windows: deleted 24 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2773397201-2855733099-4214572315-500
c:\$recycle.bin\S-1-5-21-807892715-3149862127-586907164-500
C:\s
c:\users\sonam\AppData\Roaming\inst.exe
c:\users\sonam\Documents\cc_20081229_190759.reg
c:\windows\system32\11478.exe
c:\windows\system32\11538.exe
c:\windows\system32\11825.exe
c:\windows\system32\11942.exe
c:\windows\system32\12382.exe
c:\windows\system32\14196.exe
c:\windows\system32\14604.exe
c:\windows\system32\14771.exe
c:\windows\system32\153.exe
c:\windows\system32\15724.exe
c:\windows\system32\1629.exe
c:\windows\system32\16390.exe
c:\windows\system32\16827.exe
c:\windows\system32\17421.exe
c:\windows\system32\17746.exe
c:\windows\system32\18467.exe
c:\windows\system32\1869.exe
c:\windows\system32\18716.exe
c:\windows\system32\19169.exe
c:\windows\system32\19718.exe
c:\windows\system32\19895.exe
c:\windows\system32\19912.exe
c:\windows\system32\21726.exe
c:\windows\system32\21764.exe
c:\windows\system32\22095.exe
c:\windows\system32\23281.exe
c:\windows\system32\24373.exe
c:\windows\system32\24464.exe
c:\windows\system32\2555.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\28145.exe
c:\windows\system32\28195.exe
c:\windows\system32\292.exe
c:\windows\system32\29358.exe
c:\windows\system32\29798.exe
c:\windows\system32\2995.exe
c:\windows\system32\30457.exe
c:\windows\system32\31454.exe
c:\windows\system32\32391.exe
c:\windows\system32\3902.exe
c:\windows\system32\4827.exe
c:\windows\system32\491.exe
c:\windows\system32\5436.exe
c:\windows\system32\5447.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\9603.exe
c:\windows\system32\9961.exe
c:\windows\system32\wininit.dll

.
((((((((((((((((((((((((( Files Created from 2009-12-05 to 2010-01-05 )))))))))))))))))))))))))))))))
.

2010-01-05 22:09 . 2010-01-05 22:09 ——– d—–w- c:\users\sonam\AppData\Local\Adobe
2010-01-05 22:03 . 2010-01-05 22:09 ——– d—–w- c:\users\sonam\AppData\Local\temp
2010-01-05 22:03 . 2010-01-05 22:03 ——– d—–w- c:\users\Mcx1\AppData\Local\temp
2010-01-05 22:03 . 2010-01-05 22:03 ——– d—–w- c:\users\Guest\AppData\Local\temp
2010-01-05 22:03 . 2010-01-05 22:03 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-01-05 07:03 . 2010-01-05 07:03 0 —-a-w- c:\windows\system32\cd.dat
2010-01-05 06:42 . 2010-01-05 06:42 ——– d—–w- c:\users\sonam\AppData\Roaming\Malwarebytes
2010-01-05 06:42 . 2009-12-30 19:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-05 06:42 . 2010-01-05 06:42 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-05 06:42 . 2010-01-05 06:42 ——– d—–w- c:\programdata\Malwarebytes
2010-01-05 06:42 . 2009-12-30 19:54 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-05 06:39 . 2010-01-05 06:39 ——– d—–w- c:\program files\ERUNT
2010-01-05 04:27 . 2009-06-30 14:37 28552 —-a-w- c:\windows\system32\drivers\pavboot.sys
2010-01-05 04:27 . 2010-01-05 04:27 ——– d—–w- c:\program files\Panda Security
2010-01-05 04:24 . 2010-01-05 05:14 ——– d—–w- c:\users\sonam\AppData\Roaming\QuickScan
2010-01-05 04:21 . 2010-01-05 04:21 ——– dc—-w- c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2009-12-26 13:43 . 2009-12-30 03:22 ——– d—–w- c:\users\sonam\AppData\Local\kksrvn
2009-12-26 06:18 . 2009-12-26 06:18 ——– d—–w- c:\windows\Sun
2009-12-25 21:44 . 2009-12-25 21:44 ——– d—–w- c:\program files\VirtualDubMOD
2009-12-25 19:32 . 2009-12-25 19:32 ——– d—–w- c:\users\sonam\AppData\Roaming\GetRightToGo
2009-12-25 19:18 . 2009-12-25 19:20 ——– d—–w- c:\users\sonam\AppData\Roaming\AVSMedia
2009-12-25 19:15 . 2009-12-25 19:15 ——– d—–w- c:\users\sonam\AppData\Roaming\Download Manager
2009-12-10 08:00 . 2009-12-10 08:00 ——– d—–w- C:\Hotspot Shield
2009-12-10 07:31 . 2009-12-10 07:31 ——– d—–w- c:\users\sonam\AppData\Local\Graboid

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-05 21:45 . 2008-11-17 04:21 ——– d—–w- c:\program files\7-Zip
2010-01-05 21:05 . 2009-11-23 23:41 ——– d—–w- c:\program files\Real
2010-01-05 21:05 . 2009-11-23 23:41 ——– d—–w- c:\program files\Common Files\Real
2010-01-05 19:22 . 2009-07-29 19:38 ——– d—–w- c:\users\sonam\AppData\Roaming\vlc
2010-01-05 19:22 . 2008-10-16 21:06 7512 —-a-w- c:\users\sonam\AppData\Local\d3d9caps.dat
2010-01-05 05:19 . 2009-12-26 00:04 52224 —-a-w- c:\users\sonam\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-05 05:19 . 2009-07-17 16:06 117760 —-a-w- c:\users\sonam\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-03 05:26 . 2010-01-05 04:24 789320 —-a-w- c:\users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
2010-01-03 05:26 . 2010-01-05 04:24 697672 —-a-w- c:\users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
2009-12-30 02:33 . 2008-10-16 00:07 117304 —-a-w- c:\users\sonam\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-30 02:26 . 2009-10-11 05:08 ——– d—–w- c:\users\sonam\AppData\Roaming\Orbit
2009-12-26 00:20 . 2008-10-22 15:56 ——– d—–w- c:\users\sonam\AppData\Roaming\Vso
2009-12-26 00:01 . 2009-07-17 16:05 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-12-26 00:00 . 2008-10-18 01:09 ——– d—–w- c:\program files\Common Files\AVSMedia
2009-12-25 23:59 . 2008-10-18 01:41 ——– d—–w- c:\program files\AVSMedia
2009-12-25 21:47 . 2008-10-16 18:22 ——– d—–w- c:\users\sonam\AppData\Roaming\dvdcss
2009-12-24 05:50 . 2008-10-16 04:07 ——– d—–w- c:\users\sonam\AppData\Roaming\uTorrent
2009-12-24 04:33 . 2008-11-02 20:48 ——– d—–w- c:\program files\ffdshow
2009-12-18 00:30 . 2008-10-16 01:54 ——– d—–w- c:\users\sonam\AppData\Roaming\FrostWire
2009-12-14 09:00 . 2010-01-05 04:56 259440 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20100104.004\ECMSVR32.DLL
2009-12-14 09:00 . 2010-01-05 04:56 2747440 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20100104.004\CCERASER.DLL
2009-12-14 09:00 . 2009-12-14 09:00 2747440 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\cceraser.dll
2009-12-14 09:00 . 2009-12-14 09:00 259440 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ecmsvr32.dll
2009-12-10 16:17 . 2009-12-10 16:17 5562672 —-a-w- c:\users\sonam\AppData\Roaming\TVU networks\AutoUpgrade\TVUPlayer2.4.9.1.exe
2009-12-10 16:17 . 2008-12-14 00:19 ——– d—–w- c:\users\sonam\AppData\Roaming\TVU networks
2009-12-10 09:00 . 2009-12-29 09:01 2747440 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20091228.004\CCERASER.DLL
2009-12-10 08:01 . 2008-10-17 01:46 ——– d—–w- c:\program files\Hotspot Shield
2009-12-10 07:30 . 2009-01-03 23:46 ——– d—–w- c:\program files\Graboid
2009-12-06 00:42 . 2008-11-02 21:05 85504 —-a-w- c:\windows\system32\ff_vfw.dll
2009-12-05 12:16 . 2009-12-05 12:16 764168 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-04 05:56 . 2009-04-07 01:15 ——– d—–w- c:\program files\Opera
2009-11-18 08:21 . 2009-11-18 08:21 ——– d—–w- c:\program files\Windows Portable Devices
2009-11-18 08:21 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-18 08:20 . 2009-11-18 08:20 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-17 20:53 . 2009-11-17 18:39 ——– d—–w- c:\users\sonam\AppData\Roaming\ICAClient
2009-11-17 18:35 . 2009-11-17 18:35 38480 —-a-r- c:\users\sonam\AppData\Roaming\Microsoft\Installer\{C49067A8-8212-4A82-A4D9-1519701644F0}\Icon80951CEC.exe.C76E2E86_AE54_4AF5_997C_63EBB83C7651.exe
2009-11-17 18:35 . 2009-11-17 18:35 38480 —-a-r- c:\users\sonam\AppData\Roaming\Microsoft\Installer\{C49067A8-8212-4A82-A4D9-1519701644F0}\Icon80951CEC.exe.20FBBF0A_A7E5_4BDE_9798_9811C3D135AC.exe
2009-11-17 18:35 . 2009-11-17 18:35 38480 —-a-r- c:\users\sonam\AppData\Roaming\Microsoft\Installer\{C49067A8-8212-4A82-A4D9-1519701644F0}\ARPICON.80486C74_ABED_4227_AF5C_9B1791CFA89C.exe
2009-11-17 18:35 . 2009-11-17 18:35 26192 —-a-r- c:\users\sonam\AppData\Roaming\Microsoft\Installer\{C49067A8-8212-4A82-A4D9-1519701644F0}\Iconlights.ico.827545C6_7013_4DE1_8E6C_DAEE4C57F54A.exe
2009-11-17 03:52 . 2008-10-16 01:54 ——– d—–w- c:\program files\FrostWire
2009-11-12 21:42 . 2009-11-12 21:42 37376 —-a-w- c:\windows\system32\drivers\HssDrv.sys
2009-11-12 21:42 . 2009-11-12 21:42 32768 —-a-w- c:\windows\system32\drivers\taphss.sys
2009-11-11 07:07 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-11-11 06:55 . 2008-12-06 18:54 ——– d—–w- c:\programdata\Microsoft Help
2009-11-03 01:42 . 2009-10-03 04:29 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-10-29 09:17 . 2009-11-25 08:01 2048 —-a-w- c:\windows\system32\tzres.dll
2009-10-16 20:01 . 2009-10-16 20:01 319456 —-a-w- c:\windows\DIFxAPI.dll
2009-10-16 20:00 . 2009-10-16 20:00 315392 —-a-w- c:\windows\HideWin.exe
2009-10-16 19:45 . 2009-10-16 19:45 10134 —-a-r- c:\users\sonam\AppData\Roaming\Microsoft\Installer\{04FDC8D5-704E-D6FF-6C0F-F243EB1EA544}\ARPPRODUCTICON.exe
2009-10-16 08:00 . 2009-12-29 09:01 259440 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20091228.004\ECMSVR32.DLL
2009-10-11 05:01 . 2009-10-11 05:01 46 —-a-w- c:\windows\system32\DonationCoder_urlsnooper_InstallInfo.dat
2009-10-10 19:38 . 2009-10-10 19:38 117304 —-a-w- c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2009-10-08 21:08 . 2009-11-18 08:00 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-11-18 08:00 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-11-18 08:00 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2009-10-08 19:53 . 2009-10-08 19:53 413696 —-a-w- c:\windows\system32\wrap_oal.dll
2009-10-08 19:53 . 2009-10-08 19:53 110592 —-a-w- c:\windows\system32\OpenAL32.dll
2009-04-15 20:24 . 2009-04-15 20:24 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-04-15 20:24 . 2009-04-15 20:24 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-04-15 20:24 . 2009-04-15 20:24 1044480 —-a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-04-15 20:24 . 2009-04-15 20:24 200704 —-a-w- c:\program files\opera\program\plugins\ssldivx.dll
2008-10-04 06:22 . 2008-10-04 06:21 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-12-10 07:57 218160 —-a-w- c:\program files\Hotspot Shield\hssie\HssIE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-10-06 2075384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"PMX Daemon"="ICO.EXE" [2006-11-08 49152]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-10-04 29744]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-17 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-17 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-17 145944]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-11-22 107112]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-11-28 134808]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-07-02 623960]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2009-04-11 236016]
"QuickTime Task"="c:\program files\QT Lite\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-01-28 61440]

c:\users\sonam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-10-20 15:25 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-10-04 04:01 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"VistaSp2"=hex(B):42,01,7e,d3,31,4e,ca,01

R0 pavboot;pavboot;c:\windows\System32\drivers\pavboot.sys [04/01/2010 11:27 PM 28552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23/06/2009 10:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23/06/2009 10:01 AM 74480]
R2 AERTFilters;Andrea RT Filters Service;c:\windows\System32\AERTSrv.exe [04/10/2008 1:28 AM 73728]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [02/05/2008 2:09 PM 161048]
R2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\System32\drivers\RtNdPt60.sys [03/10/2008 10:47 PM 27648]
R3 pmxmouse;PMXMOUSE;c:\windows\System32\drivers\pmxmouse.sys [03/10/2008 10:46 PM 18432]
R3 pmxusblf;PMXUSBLF;c:\windows\System32\drivers\pmxusblf.sys [03/10/2008 10:46 PM 19008]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [20/01/2008 9:23 PM 21504]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [27/10/2009 10:29 PM 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 9:48 PM 704864]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\System32\drivers\npf.sys [23/12/2008 10:35 AM 50704]
S3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\System32\drivers\wg111v2.sys [26/12/2007 2:46 AM 288768]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [23/06/2009 10:01 AM 7408]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [28/11/2006 6:34 AM 122008]

— Other Services/Drivers In Memory —

*NewlyCreated* - ERASERUTILDRVI9
*Deregistered* - EraserUtilDrvI9

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-01-05 c:\windows\Tasks\RtlNICDiagVistaStart.job
- c:\program files\Realtek\RTNICDiag\RTNICDiag.exe [2008-10-04 11:18]
.
.
——- Supplementary Scan ——-
.
IE: &Download; by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab; video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload; selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load; all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
FF - ProfilePath - c:\users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.sciencedaily.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;=
FF - component: c:\users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\users\sonam\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-05 17:09
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Hotspot Shield\HssWPR\hsssrv.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Hotspot Shield\bin\openvpntray.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\vssvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2010-01-05 17:15:39 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-05 22:15

Pre-Run: The system cannot find message text for message number 0x2379 in the message file for Application.
Post-Run: 122,838,011,904 bytes free

- - End Of File - - 9F01B5F0536D09DD3E73B886892579A7
Hi houngan,

MBAM has been updated.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


You have old vulnerable java installed.
  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 17"
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u17-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.

When the download is complete, close your browser.

Click on the Start button > Control Panel

Depending on your setings, either
  • click on the Uninstall a program option under the Programs category.
  • If you are using the Classic View of the Control Panel, then you would double-click on the Programs and Features icon instead.
Uninstall the following program

Java™ 6 Update 7

Do not uninstall Java TM 6 Update 17 if found! :yeah:

Reboot your computer.

  • Right click on the saved file ( jre-6u17-windows-i586-p.exe) and click "Run as Adminstrator" to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.

One more scan to check our work.

In order to do this scan you must run your browser (either Internet Explorer or FireFox) with Adminstrator rights.
  • Right click your browser icon and select "Run as Adminstrator"
  • Use that browser to go to this site listed below
  • Do not surf anywhere else with this instance of your browser
  • After the scan is complete and you have saved the reseluts, close that instance of your browser
  • Open a browser the normal way and return here to post the requested logs


*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.

Please post back with
  • MBAM log
  • Kaspersky log
  • new DDS.txt
Everything still ok?

Thanks
Oldman960, everything seems fine so far. Thanks.
Here are the logs.


**********************MBAM log*************************

Malwarebytes' Anti-Malware 1.43
Database version: 3508
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865

07/01/2010 12:29:23 PM
mbam-log-2010-01-07 (12-29-23).txt

Scan type: Quick Scan
Objects scanned: 131326
Time elapsed: 4 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)





**********************Kaspersky log*************************
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, January 7, 2010
Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, January 07, 2010 18:09:45
Records in database: 3329061
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan statistics:
Objects scanned: 177862
Threats found: 22
Infected objects found: 51
Suspicious objects found: 4
Scan duration: 07:44:10


File name / Threat / Threats count
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0114010F.VBN Infected: Trojan.Win32.Agent.deou 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240060\4B2C9C0A.VBN Infected: Trojan-Downloader.Java.OpenConnection.at 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240062\4B2C9CFC.VBN Infected: Packed.Win32.Krap.ag 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240063\4B2C9D25.VBN Infected: Trojan.Win32.Cosmu.ceo 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240064\4B2C9D3B.VBN Infected: Trojan.Win32.Cosmu.cda 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240065.VBN Infected: Backdoor.Win32.Agent.amcc 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240066.VBN Infected: Packed.Win32.Krap.ag 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240067.VBN Infected: Packed.Win32.Krap.ag 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240068.VBN Infected: Packed.Win32.Krap.ag 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240069.VBN Infected: Packed.Win32.Krap.ag 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0924006A.VBN Suspicious: Packed.Win32.PECompact 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0924006B.VBN Infected: Trojan.Win32.Vilsel.kfh 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0924006C.VBN Infected: Backdoor.Win32.Bredavi.aoh 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0924006D.VBN Infected: Packed.Win32.TDSS.z 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0924006E.VBN Suspicious: Packed.Win32.PECompact 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0924006F.VBN Infected: Packed.Win32.Krap.x 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AC40000\4BE70A9F.VBN Infected: Trojan-Downloader.WMA.GetCodec.r 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C7C0000\4D7ECD31.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F180002.VBN Infected: not-a-virus:RemoteAdmin.Win32.NetCat.a 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F180003.VBN Infected: not-a-virus:RemoteAdmin.Win32.NetCat.a 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\116C0001.VBN Infected: not-a-virus:PSWTool.Win32.AirCrack.c 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\116C0002.VBN Infected: Trojan.Win32.Monder.gen 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\116C0002.VBN Infected: Trojan.Win32.Shutdowner.hv 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\13280000\5B6BC156.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\16800000\5E907C94.VBN Infected: Exploit.Win32.Pidief.auu 1
C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\16800001\5E9C5424.VBN Infected: Trojan-Downloader.HTML.Agent.ij 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0114010F.VBN Infected: Trojan.Win32.Agent.deou 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240060\4B2C9C0A.VBN Infected: Trojan-Downloader.Java.OpenConnection.at 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240062\4B2C9CFC.VBN Infected: Packed.Win32.Krap.ag 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240063\4B2C9D25.VBN Infected: Trojan.Win32.Cosmu.ceo 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240064\4B2C9D3B.VBN Infected: Trojan.Win32.Cosmu.cda 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240065.VBN Infected: Backdoor.Win32.Agent.amcc 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240066.VBN Infected: Packed.Win32.Krap.ag 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240067.VBN Infected: Packed.Win32.Krap.ag 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240068.VBN Infected: Packed.Win32.Krap.ag 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09240069.VBN Infected: Packed.Win32.Krap.ag 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0924006A.VBN Suspicious: Packed.Win32.PECompact 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0924006B.VBN Infected: Trojan.Win32.Vilsel.kfh 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0924006C.VBN Infected: Backdoor.Win32.Bredavi.aoh 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0924006D.VBN Infected: Packed.Win32.TDSS.z 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0924006E.VBN Suspicious: Packed.Win32.PECompact 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0924006F.VBN Infected: Packed.Win32.Krap.x 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AC40000\4BE70A9F.VBN Infected: Trojan-Downloader.WMA.GetCodec.r 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C7C0000\4D7ECD31.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F180002.VBN Infected: not-a-virus:RemoteAdmin.Win32.NetCat.a 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F180003.VBN Infected: not-a-virus:RemoteAdmin.Win32.NetCat.a 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\116C0001.VBN Infected: not-a-virus:PSWTool.Win32.AirCrack.c 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\116C0002.VBN Infected: Trojan.Win32.Monder.gen 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\116C0002.VBN Infected: Trojan.Win32.Shutdowner.hv 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\13280000\5B6BC156.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\16800000\5E907C94.VBN Infected: Exploit.Win32.Pidief.auu 1
C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\16800001\5E9C5424.VBN Infected: Trojan-Downloader.HTML.Agent.ij 1
C:\Users\sonam\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\6e49cf76-3d3d03ab Infected: Trojan-Downloader.Java.Agent.t 1
C:\Users\sonam\Documents\FrostWire\Saved\02 - Timbaland Presents Shock Value - Apologize.wma Infected: Trojan-Downloader.WMA.Wimad.v 1
C:\Users\sonam\Documents\FrostWire\Saved\star is born instrumental top #1 hit.au Infected: Trojan-Downloader.WMA.GetCodec.s 1

Selected area has been scanned.





**********************DDS log*************************

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 21:23:35.25 on 07/01/2010
Internet Explorer: 8.0.6001.18865 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.3070.1678 [GMT -5:00]

AV: Symantec AntiVirus *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
SP: Symantec AntiVirus *disabled* (Updated) {6C85A515-B91D-4D2B-AF18-40984A4A8493}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Dwm.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\ico.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Windows\system32\AERTSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Opera\program\plugins\NPSWF32_FlashUtil.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Windows\system32\IoctlSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\Pmxmiced.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Hotspot Shield\bin\openvpntray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskmgr.exe
C:\Program Files\VSO\ConvertX\3.7\3\ConvertXtoDvd.exe
C:\Windows\System32\notepad.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Windows\System32\mobsync.exe
C:\Windows\explorer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\sonam\Downloads\dds.scr

============== Pseudo HJT Report ===============

BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
TB: Veoh Browser Plug-in: {d0943516-5076-4020-a3b5-aefaf26ab263} - c:\program files\veoh networks\veoh\plugins\reg\VeohToolbar.dll
TB: &Windows; Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll
TB: Veoh Video Compass: {52836eb0-631a-47b1-94a6-61f9d9112dae} - c:\program files\veoh networks\veoh video compass\SearchRecsPlugin.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [VeohPlugin] "c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [PMX Daemon] ICO.EXE
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [QuickTime Task] "c:\program files\qt lite\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\users\sonam\appdata\roaming\micros~1\windows\startm~1\programs\startup\delldo~1.lnk - c:\program files\dell\delldock\DellDock.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Download; by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Grab; video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204
IE: Do&wnload; selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load; all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\users\sonam\appdata\roaming\mozilla\firefox\profiles\1arsg2p9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.sciencedaily.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;=
FF - component: c:\program files\orbitdownloader\addons\oneclickyoutubedownloader\components\GrabXpcom.dll
FF - component: c:\users\sonam\appdata\roaming\mozilla\firefox\profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\opera\program\plugins\npdivx32.dll
FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\sonam\appdata\roaming\mozilla\firefox\profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\users\sonam\appdata\roaming\mozilla\plugins\npoctoshape.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2010-1-4 28552]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-6-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 74480]
R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2008-10-4 73728]
R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-5-2 161048]
R2 HssSrv;Hotspot Shield Routing Service;c:\program files\hotspot shield\hsswpr\hsssrv.exe [2009-11-12 331824]
R2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt60.sys [2008-10-3 27648]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-1-4 102448]
R3 HssDrv;Hotspot Shield Helper Miniport;c:\windows\system32\drivers\HssDrv.sys [2009-11-12 37376]
R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-10-3 18432]
R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-10-3 19008]
R3 taphss;Anchorfree HSS Adapter;c:\windows\system32\drivers\taphss.sys [2009-11-12 32768]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-10-27 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 HssTrayService;Hotspot Shield Tray Service;c:\program files\hotspot shield\bin\HssTrayService.exe [2009-11-17 57640]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2008-12-23 50704]
S3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v2.sys [2007-12-26 288768]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 7408]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-11-28 122008]

=============== Created Last 30 ================

2010-01-07 13:06 411,368 a——- c:\windows\system32\deploytk.dll
2010-01-07 12:44 –d—– c:\users\sonam\.SunDownloadManager
2010-01-06 03:09 24,064 a——- c:\windows\system32\nshhttp.dll
2010-01-06 03:09 411,648 a——- c:\windows\system32\drivers\http.sys
2010-01-06 03:09 30,720 a——- c:\windows\system32\httpapi.dll
2010-01-05 19:31 –d—– c:\users\sonam\appdata\roaming\GrabPro
2010-01-05 17:08 –d—– C:\$RECYCLE.BIN
2010-01-05 16:57 261,632 a——- c:\windows\PEV.exe
2010-01-05 16:57 161,792 a——- c:\windows\SWREG.exe
2010-01-05 16:57 98,816 a——- c:\windows\sed.exe
2010-01-05 16:57 77,312 a——- c:\windows\MBR.exe
2010-01-05 02:03 0 a——- c:\windows\system32\cd.dat
2010-01-05 02:00 267,570,562 a——- c:\windows\MEMORY.DMP
2010-01-05 01:42 –d—– c:\users\sonam\appdata\roaming\Malwarebytes
2010-01-05 01:42 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-05 01:42 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-05 01:42 –d—– c:\programdata\Malwarebytes
2010-01-05 01:42 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-05 01:42 –d—– c:\progra~2\Malwarebytes
2010-01-04 23:27 28,552 a——- c:\windows\system32\drivers\pavboot.sys
2010-01-04 23:27 –d—– c:\program files\Panda Security
2010-01-04 23:24 –d—– c:\users\sonam\appdata\roaming\QuickScan
2010-01-04 23:21 -cd—– c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2010-01-04 23:21 -cd—– c:\progra~2\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2009-12-25 16:44 –d—– c:\program files\VirtualDubMOD
2009-12-25 14:32 –d—– c:\users\sonam\appdata\roaming\GetRightToGo
2009-12-25 14:18 –d—– c:\users\sonam\appdata\roaming\AVSMedia
2009-12-25 14:16 221,215 a——- c:\windows\system32\divxdec.ax
2009-12-10 03:00 –d—– C:\Hotspot Shield

==================== Find3M ====================

2009-12-10 03:00 143,360 a——- c:\windows\inf\infstrng.dat
2009-12-10 03:00 51,200 a——- c:\windows\inf\infpub.dat
2009-12-10 03:00 143,360 a——- c:\windows\inf\infstor.dat
2009-12-05 19:42 85,504 a——- c:\windows\system32\ff_vfw.dll
2009-11-21 01:40 916,480 a——- c:\windows\system32\wininet.dll
2009-11-21 01:34 109,056 a——- c:\windows\system32\iesysprep.dll
2009-11-21 01:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-11-20 23:59 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-11-18 03:21 665,600 a——- c:\windows\inf\drvindex.dat
2009-11-18 03:20 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-12 16:42 37,376 a——- c:\windows\system32\drivers\HssDrv.sys
2009-11-12 16:42 32,768 a——- c:\windows\system32\drivers\taphss.sys
2009-11-02 20:42 195,456 ——– c:\windows\system32\MpSigStub.exe
2009-10-29 04:17 2,048 a——- c:\windows\system32\tzres.dll
2009-10-16 15:01 319,456 a——- c:\windows\DIFxAPI.dll
2009-10-16 15:00 315,392 a——- c:\windows\HideWin.exe
2008-10-22 10:56 47,360 a——- c:\users\sonam\appdata\roaming\pcouffin.sys
2008-10-16 17:00 61,224 a——- c:\users\sonam\GoToAssistDownloadHelper.exe
2008-01-20 21:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 21:24:26.39 ===============


Thank you
Hi houngan,

I gave you the wrong name of the P2P program you have installed. It's FrostWire 4.18.4. As you can see 2 of the detections are downloads made with that program. 48 of the detections are in the Symantec Quarantined folder.

I suggest you empty the Quarantined folder, we will remove the other 3 and clean out the temp files.


Download OTL to your desktop.

Next, Right click on OTL.exe and chose Run as Administrator to run it
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Reg

:Files
C:\Users\sonam\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\6e49cf76-3d3d03ab 
C:\Users\sonam\Documents\FrostWire\Saved\02 - Timbaland Presents Shock Value - Apologize.wma
C:\Users\sonam\Documents\FrostWire\Saved\star is born instrumental top #1 hit.au 

:Commands
[purity]
[emptytemp]

Then click the Run Fix button at the top
  • Let the program run unhindered
Please post the OTL fix log.

It looks like you rean an online scan with Panda, you can uninstall Panda ActiveScan 2.0

Run that little fix and we will clean up the tools when you post back.

Please post back with
  • OTL fix log

Thanks.
Hi oldman360, sorry for the late response. I've been away from home and unable to access my computer. I will be home tomorrow so I will be able to continue with fixing my computer. Thanks again for all your help.
Oldman360, here's the OTL fix log. Thank you. All processes killed ========== REGISTRY ========== ========== FILES ========== C:\Users\sonam\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\6e49cf76-3d3d03ab moved successfully. C:\Users\sonam\Documents\FrostWire\Saved\02 - Timbaland Presents Shock Value - Apologize.wma moved successfully. C:\Users\sonam\Documents\FrostWire\Saved\star is born instrumental top #1 hit.au moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->FireFox cache emptied: 63864216 bytes User: Mcx1 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Public ->Temp folder emptied: 0 bytes User: sonam ->Temp folder emptied: 120512962 bytes ->Temporary Internet Files folder emptied: 42491579 bytes ->Java cache emptied: 25113149 bytes ->FireFox cache emptied: 104545602 bytes ->Opera cache emptied: 0 bytes User: TEMP ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 120638 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 11821721570 bytes Total Files Cleaned = 11,614.00 mb OTL by OldTimer - Version 3.1.24.0 log created on 01132010_024159 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Hi houngan,


If no other problems, we can clean up our tools.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • GMER.zip
  • GMER.exe
  • DDS.scr

Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /uninstall


Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


I suggest you keep MBAM. Keep MBAM updated and use it regularly.

Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. You have those.

You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.

See the extra note for Vista users.

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis

- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.

- Keep your antivirus program updated, as well as any other security programs you have.

-More tips and programs can be found HERE

- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI