This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan.zbot infected my computer

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I started getting messages from my Norton Security that it was blocking a trojan.zbot's attempts to connect to the internet. Occassionaly i would have one about a trojan 3gen.
At first it seemed to make very little difference to my computer perhaps making it a little slower. As i started to perform the checks neessary to obtain the logs you need the downloads were very slow and then my computer froze. It has taken several attempts to to turn on the computer as it wasn't responding and now seems to have turned off my virus protection.
Any help with this will be great

here are the logs

Malwarebytes' Anti-Malware 1.44
Database version: 3539
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865

11/01/2010 13:32:16
mbam-log-2010-01-11 (13-32-12).txt

Scan type: Quick Scan
Objects scanned: 99102
Time elapsed: 6 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 3
Registry Data Items Infected: 4
Folders Infected: 1
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\LREC75DND7 (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\E8WECRKKMV (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> No action taken.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\losalamos (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lrec75dnd7 (Trojan.Agent) -> No action taken.

Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: c:\windows\system32\sdra64.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: system32\sdra64.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\Windows\system32\userinit.exe,C:\Windows\system32\sdra64.exe,) Good: (Userinit.exe) -> No action taken.

Folders Infected:
C:\Windows\System32\lowsec (Stolen.data) -> No action taken.

Files Infected:
C:\Windows\Temp\fbqd.tmp\svchost.exe (Spyware.Passwords) -> No action taken.
C:\Users\david\downloads\ZwinkySetup2.3.50.57.ZJfox000.exe (Adware.MyWebSearch) -> No action taken.
C:\Windows\System32\lowsec\local.ds (Stolen.data) -> No action taken.
C:\Windows\System32\lowsec\user.ds (Stolen.data) -> No action taken.
C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> No action taken.
C:\Windows\System32\sdra64.exe (Spyware.Zbot) -> No action taken.
C:\Windows\System32\sshnas.dll (Trojan.Agent) -> No action taken.




GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-11 13:55:47
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\david\AppData\Local\Temp\awtdikod.sys


—- System - GMER 1.0.15 —-

SSDT 875F3C60 ZwAlertResumeThread
SSDT 8761B150 ZwAlertThread
SSDT 87622A48 ZwAllocateVirtualMemory
SSDT 85B72FB0 ZwAlpcConnectPort
SSDT 8765C808 ZwAssignProcessToJobObject
SSDT 876574F0 ZwCreateMutant
SSDT 8765D5F8 ZwCreateSymbolicLinkObject
SSDT 8764B668 ZwCreateThread
SSDT 87656048 ZwDebugActiveProcess
SSDT 87622C60 ZwDuplicateObject
SSDT 87622428 ZwFreeVirtualMemory
SSDT 876493A8 ZwImpersonateAnonymousToken
SSDT 876504E0 ZwImpersonateThread
SSDT 8723A430 ZwLoadDriver
SSDT 876222C8 ZwMapViewOfSection
SSDT 8761F048 ZwOpenEvent
SSDT 87623008 ZwOpenProcess
SSDT 87580068 ZwOpenProcessToken
SSDT 87624048 ZwOpenSection
SSDT 87622DB0 ZwOpenThread
SSDT 8765C2B8 ZwProtectVirtualMemory
SSDT 87574B98 ZwResumeThread
SSDT 875CBAF0 ZwSetContextThread
SSDT 876220F0 ZwSetInformationProcess
SSDT 87625048 ZwSetSystemInformation
SSDT 87623050 ZwSuspendProcess
SSDT 875FA048 ZwSuspendThread
SSDT 875666B8 ZwTerminateProcess
SSDT 875D0B98 ZwTerminateThread
SSDT 875B7C50 ZwUnmapViewOfSection
SSDT 87622738 ZwWriteVirtualMemory
SSDT 8765DA68 ZwCreateThreadEx

INT 0x82 ? 86BAFBF8
INT 0x82 ? 86BAFBF8
INT 0x82 ? 86BAFBF8
INT 0x91 ? 86BAFBF8
INT 0xA2 ? 86BAFBF8

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 851661F8
Device \FileSystem\fastfat \FatCdrom 878F41F8

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device \Driver\volmgr \Device\VolMgrControl 851621F8
Device \Driver\usbohci \Device\USBPDO-0 86BD11F8
Device \Driver\usbohci \Device\USBPDO-1 86BD11F8
Device \Driver\usbehci \Device\USBPDO-2 86BD31F8
Device \Driver\usbohci \Device\USBPDO-3 86BD11F8
Device \Driver\netbt \Device\NetBT_Tcpip_{17EEA341-584A-4D54-A539-5E24325FCE5D} 874ED1F8
Device \Driver\usbehci \Device\USBPDO-4 86BD31F8

AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\volmgr \Device\HarddiskVolume1 851621F8
Device \Driver\volmgr \Device\HarddiskVolume2 851621F8
Device \Driver\cdrom \Device\CdRom0 86BB21F8
Device \Driver\volmgr \Device\HarddiskVolume3 851621F8
Device \Driver\netbt \Device\NetBt_Wins_Export 874ED1F8
Device \Driver\Smb \Device\NetbiosSmb 874F91F8

AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\iScsiPrt \Device\RaidPort1 86BEF1F8

AttachedDevice \Driver\tdx \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\usbohci \Device\USBFDO-0 86BD11F8
Device \Driver\usbohci \Device\USBFDO-1 86BD11F8
Device \Driver\usbehci \Device\USBFDO-2 86BD31F8
Device \Driver\usbohci \Device\USBFDO-3 86BD11F8
Device \Driver\netbt \Device\NetBT_Tcpip_{AAF7D1EC-25F8-482E-B66D-42E0FF000732} 874ED1F8
Device \Driver\usbehci \Device\USBFDO-4 86BD31F8
Device \FileSystem\fastfat \Fat 878F41F8

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\cdfs \Cdfs 88EEB1F8
Device -> \Driver\ahcix86s \Device\Harddisk0\DR0 85289841

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x95 0x5E 0xAE 0xD0 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xE8 0x02 0x1A 0x51 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF6 0x2C 0x68 0x4A …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x95 0x5E 0xAE 0xD0 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xE8 0x02 0x1A 0x51 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF6 0x2C 0x68 0x4A …

—- Files - GMER 1.0.15 —-

File C:\Windows\system32\drivers\ahcix86s.sys suspicious modification

—- EOF - GMER 1.0.15 —-




Nero DriveSpeed
Nero Express Help
Nero InfoTool
Nero Installer
Nero PhotoSnap
Nero PhotoSnap Help
Nero Recode
Nero Recode Help
Nero Rescue Agent
Nero RescueAgent Help
Nero ShowTime
Nero StartSmart
Nero StartSmart Help
Nero Vision
Nero WaveEditor
Nero WaveEditor Help
NeroBurningROM
NeroExpress
neroxml
Norton 360
NTI Backup Now 5
NTI Backup Now Standard
NTI Media Maker 8
PhotoNow!
QuickTime
RealPlayer
Realtek High Definition Audio Driver
Realtek USB 2.0 Card Reader
SAMSUNG Mobile Composite Device Software
SAMSUNG Mobile Modem Driver Set
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung PC Studio 3
Samsung PC Studio 3 USB Driver Installer
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Sid Meier's Civilization III: Complete
Skype™ 4.0
SoulSeek 157 NS 13c
SoundTrax
Steam
Synaptics Pointing Device Driver
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
VC80CRTRedist - 8.0.50727.762
Virtual DJ - Atomix Productions
VLC media player 1.0.2
WinAVIVideoConverter
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
WinRAR archiver
WinZip 12.0
Wireless Manager

==== Event Viewer Messages From Past Week ========

11/01/2010 14:25:50, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.
11/01/2010 14:25:15, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume Acer.
11/01/2010 14:16:24, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: IDSVix86 SRTSP
11/01/2010 14:16:24, Error: Service Control Manager [7023] - The WinDefend service terminated with the following error: The specified module could not be found.
11/01/2010 14:16:24, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
11/01/2010 14:16:24, Error: Service Control Manager [7000] - The NTIPPKernel service failed to start due to the following error: The file or directory is corrupted and unreadable.
11/01/2010 14:15:55, Error: SRTSP [5] - Error loading Symantec real time Anti-Virus driver.
11/01/2010 14:15:55, Error: SRTSP [4] - Error loading virus definitions.
11/01/2010 14:08:05, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the N360 service.
10/01/2010 19:17:19, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Ati External Event Utility service.
08/01/2010 19:27:04, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
08/01/2010 19:27:04, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
08/01/2010 19:27:04, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
05/01/2010 10:31:42, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
05/01/2010 08:08:29, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
05/01/2010 08:08:29, Error: Service Control Manager [7000] - The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
05/01/2010 08:06:05, Error: Service Control Manager [7022] - The KtmRm for Distributed Transaction Coordinator service hung on starting.

==== End Of File ===========================



irefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0305020.00b\SymEFA.sys [2009-11-26 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0305020.00b\BHDrvx86.sys [2009-11-26 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0305020.00b\cchpx86.sys [2009-11-26 482432]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\acer arcade deluxe\playmovie\000.fcl [2008-8-20 61424]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 CLHNService;CLHNService;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\CLHNService.exe [2008-8-20 81504]
R2 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2008-8-20 24576]
R2 N360;Norton 360;c:\program files\norton 360\engine\3.5.2.11\ccSvcHst.exe [2009-11-26 117640]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\NBService.exe [2008-11-25 935208]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-26 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-26 131072]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-3-28 210432]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0305020.00b\symndisv.sys [2009-11-26 48688]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2008-11-18 22072]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]

=============== Created Last 30 ================

2010-01-11 14:21 –dsh— c:\windows\system32\lowsec
2010-01-11 13:23 –d—– c:\users\david\appdata\roaming\Malwarebytes
2010-01-11 13:23 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-11 13:22 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-11 13:22 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-11 12:11 195,456 ——– c:\windows\system32\MpSigStub.exe
2010-01-10 14:10 –d–r– c:\program files\Norton Support
2010-01-04 22:31 –d—– c:\program files\Musicnotes

==================== Find3M ====================

2009-11-27 14:35 691,696 a——- c:\windows\system32\drivers\sptd.sys
2009-11-26 11:59 143,360 a——- c:\windows\inf\infstrng.dat
2009-11-26 11:59 86,016 a——- c:\windows\inf\infstor.dat
2009-11-26 11:59 51,200 a——- c:\windows\inf\infpub.dat
2009-11-26 11:59 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-11-26 11:59 7,456 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2009-11-26 11:59 806 a——- c:\windows\system32\drivers\SYMEVENT.INF
2009-11-26 11:58 26,600 a—-r– c:\windows\system32\drivers\GEARAspiWDM.sys
2009-11-26 11:58 25,648 a—-r– c:\windows\system32\drivers\SymIMV.sys
2009-11-26 11:58 107,368 a—-r– c:\windows\system32\GEARAspi.dll
2009-11-21 06:40 916,480 a——- c:\windows\system32\wininet.dll
2009-11-21 06:34 109,056 a——- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-11-21 04:59 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-11-19 03:20 665,600 a——- c:\windows\inf\drvindex.dat
2009-11-19 03:19 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-29 09:17 2,048 a——- c:\windows\system32\tzres.dll
2009-04-30 15:58 87,608 a——- c:\users\david\appdata\roaming\inst.exe
2009-04-30 15:58 47,360 a——- c:\users\david\appdata\roaming\pcouffin.sys
2008-01-21 02:57 174 a–sh— c:\program files\desktop.ini
2006-11-02 12:39 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:39 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 12:39 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:39 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 09:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 14:26:17.48 ===============
Hi,

Please do the following:

Open Notepad

Click Start >Run type notepad into the run box click OK
Click Format and make certain that Word Wrap is NOT checked.

Copy the text inside of the code box, Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Now paste the copied text into the open notepad, press CTRL+V (or right click and choose 'paste')

Note: There must be NO blank lines in front of the pasted text, but ensure that there is a blank line at the end of the text, otherwise the registry merge will not work.

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\windows\\system32\\userinit.exe,"

Now go to File > and click Save As,
From the drop down menu at the top of the box choose Desktop as the location to save this file.
Go down to the File Name box and type in fixme.reg as the file name, then choose All Files as the save as file type.
Then click the save button.
Once you have clicked the save button, close Notepad.

You should now see a file on your desktop that looks like this:

[external image: Posted Image]

Locate the fixme.reg icon on your desktop and double click it, an information box will pop up asking if you want to merge the information in the file into the registry, click YES.

Once the file has run, the information will have merged with your registry so you can delete fixme.reg from your desktop as you won't be needing it any more.


NEXT



Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Hi

Thanks for the help…..it's very much appreciated.

Did as you said. The computer crashed a couple of times during combofix and was slightly difficult to start afterwards…..also when i connectted to the internet again i got some pop ups that had never happened before.

Here's the combo log

ComboFix 10-01-04.01 - david 11/01/2010 17:10:34.2.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.44.1033.18.2814.1869 [GMT 0:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-164424331-24194484-381687128-500
c:\users\david\AppData\Roaming\.#
c:\users\david\AppData\Roaming\.#\MBX@B30@1D02990.###
c:\users\david\AppData\Roaming\.#\MBX@B30@1D029C0.###
c:\users\david\AppData\Roaming\.#\MBX@B30@1D029F0.###
c:\users\david\AppData\Roaming\inst.exe
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds

.
((((((((((((((((((((((((( Files Created from 2009-12-11 to 2010-01-11 )))))))))))))))))))))))))))))))
.

2010-01-11 17:23 . 2010-01-11 17:23 ——– d—–w- c:\users\david\AppData\Local\temp
2010-01-11 17:23 . 2010-01-11 17:23 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-01-11 14:19 . 2010-01-11 14:19 ——– d—–w- c:\users\david\AppData\Local\Symantec
2010-01-11 13:23 . 2010-01-11 13:23 ——– d—–w- c:\users\david\AppData\Roaming\Malwarebytes
2010-01-11 13:23 . 2010-01-07 16:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-11 13:22 . 2010-01-11 13:22 ——– d—–w- c:\programdata\Malwarebytes
2010-01-11 13:22 . 2010-01-07 16:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-11 13:22 . 2010-01-11 13:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-11 12:11 . 2009-11-02 20:42 195456 ——w- c:\windows\system32\MpSigStub.exe
2010-01-11 08:35 . 2009-11-25 19:30 84912 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100110.017\NAVENG.SYS
2010-01-11 08:35 . 2009-11-25 19:30 177520 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100110.017\NAVENG32.DLL
2010-01-11 08:35 . 2009-11-25 19:30 1647984 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100110.017\NAVEX32A.DLL
2010-01-11 08:35 . 2009-11-25 19:30 1323568 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100110.017\NAVEX15.SYS
2010-01-11 08:35 . 2009-12-09 09:00 2747440 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100110.017\CCERASER.DLL
2010-01-11 08:35 . 2009-11-25 19:30 371248 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100110.017\EECTRL.SYS
2010-01-11 08:35 . 2009-11-25 19:30 259440 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100110.017\ECMSVR32.DLL
2010-01-11 08:35 . 2009-11-25 19:30 102448 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100110.017\ERASER.SYS
2010-01-10 14:10 . 2010-01-10 14:10 ——– d—–r- c:\program files\Norton Support
2010-01-08 22:23 . 2009-10-28 22:37 343088 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100106.001\IDSvix86.sys
2010-01-08 22:23 . 2009-10-28 22:37 329592 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100106.001\IDSXpx86.sys
2010-01-08 22:23 . 2009-10-28 22:37 811896 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100106.001\Scxpx86.dll
2010-01-08 22:23 . 2009-10-28 22:37 488312 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100106.001\IDSxpx86.dll
2010-01-08 22:23 . 2009-10-28 22:37 466992 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100106.001\IDSviA64.sys
2010-01-04 22:35 . 2010-01-04 22:35 ——– d—–w- c:\programdata\Musicnotes
2010-01-04 22:31 . 2010-01-04 22:32 ——– d—–w- c:\program files\Musicnotes
2010-01-04 21:06 . 2009-10-28 22:37 343088 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091230.004\IDSvix86.sys
2010-01-04 21:06 . 2009-10-28 22:37 329592 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091230.004\IDSXpx86.sys
2010-01-04 21:06 . 2009-10-28 22:37 811896 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091230.004\Scxpx86.dll
2010-01-04 21:06 . 2009-10-28 22:37 488312 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091230.004\IDSxpx86.dll
2010-01-04 21:06 . 2009-10-28 22:37 466992 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091230.004\IDSviA64.sys
2009-12-18 21:38 . 2009-10-28 22:37 343088 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\IDSvix86.sys
2009-12-18 21:38 . 2009-10-28 22:37 329592 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\IDSXpx86.sys
2009-12-18 21:38 . 2009-10-28 22:37 811896 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\Scxpx86.dll
2009-12-18 21:38 . 2009-10-28 22:37 488312 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\IDSxpx86.dll
2009-12-18 21:38 . 2009-10-28 22:37 466992 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\IDSviA64.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-11 17:15 . 2009-04-28 17:27 ——– d—–w- c:\program files\Steam
2010-01-10 14:12 . 2009-11-26 11:59 ——– d—–w- c:\program files\Symantec
2010-01-10 06:09 . 2009-04-06 14:25 ——– d—–w- c:\users\david\AppData\Roaming\uTorrent
2010-01-09 17:42 . 2009-06-18 13:19 ——– d—–w- c:\program files\VirtualDJ
2010-01-08 19:27 . 2008-08-20 21:37 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-08 16:17 . 2009-04-06 13:34 ——– d—–w- c:\programdata\Soulseek
2010-01-05 19:08 . 2009-04-28 17:27 ——– d—–w- c:\program files\Common Files\Steam
2010-01-05 13:19 . 2009-05-20 13:02 ——– d—–w- c:\program files\Image-Line
2010-01-05 12:12 . 2008-08-20 21:18 ——– d—–w- c:\program files\Acer GameZone
2010-01-05 12:12 . 2009-10-21 20:39 ——– d—–w- c:\program files\Yahoo!
2010-01-05 12:12 . 2009-07-11 13:36 ——– d—–w- c:\program files\MSN Games
2010-01-05 08:05 . 2009-03-31 15:46 87328 —-a-w- c:\users\david\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-20 16:42 . 2009-04-06 13:16 ——– d—–w- c:\users\david\AppData\Roaming\Skype
2009-12-10 03:21 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-12-10 03:05 . 2008-08-20 21:12 ——– d—–w- c:\programdata\Microsoft Help
2009-11-29 11:37 . 2009-04-06 17:47 ——– d—–w- c:\program files\Common Files\Real
2009-11-29 11:37 . 2009-11-29 11:37 ——– d—–w- c:\program files\Common Files\xing shared
2009-11-29 11:37 . 2009-11-29 11:37 ——– d—–w- c:\program files\real
2009-11-27 14:35 . 2009-05-08 22:05 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-11-27 09:32 . 2009-11-26 16:08 ——– d—–w- c:\program files\Java
2009-11-27 08:00 . 2009-11-27 08:00 ——– d—–w- c:\programdata\Symantec
2009-11-26 12:35 . 2009-04-09 19:49 ——– d—–w- c:\program files\GOPlayer
2009-11-26 12:17 . 2009-11-26 11:59 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-11-26 11:59 . 2009-11-26 11:59 806 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-11-26 11:59 . 2009-11-26 11:59 7456 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-11-26 11:59 . 2009-11-26 11:59 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-11-26 11:58 . 2009-11-26 11:59 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-11-26 11:58 . 2009-11-26 11:59 25648 —-a-r- c:\windows\system32\drivers\SymIMV.sys
2009-11-26 11:58 . 2009-11-26 11:58 1291104 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-11-26 11:58 . 2009-11-26 11:58 136840 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2009-11-26 11:58 . 2009-11-26 11:58 165240 —-a-r- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2009-11-26 11:58 . 2009-11-26 11:59 107368 —-a-r- c:\windows\system32\GEARAspi.dll
2009-11-26 11:58 . 2009-11-26 11:59 554352 —-a-r- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
2009-11-26 11:58 . 2009-11-26 11:58 771440 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-11-26 11:57 . 2009-11-26 11:57 ——– d—–w- c:\program files\Norton 360
2009-11-26 11:57 . 2009-11-26 11:57 ——– d—–w- c:\programdata\Norton
2009-11-26 11:56 . 2008-08-20 21:08 ——– d—–w- c:\programdata\McAfee
2009-11-26 11:56 . 2009-11-26 11:51 ——– d—–w- c:\programdata\NortonInstaller
2009-11-26 11:55 . 2008-08-20 21:09 ——– d—–w- c:\program files\McAfee
2009-11-26 11:51 . 2009-11-26 11:51 ——– d—–w- c:\program files\NortonInstaller
2009-11-23 19:05 . 2009-11-23 19:05 439816 —-a-w- c:\users\david\AppData\Roaming\Real\Update\setup3.09\setup.exe
2009-11-21 11:33 . 2009-11-21 11:33 ——– d—–w- c:\users\david\AppData\Roaming\Yahoo!
2009-11-21 06:40 . 2009-12-09 11:22 916480 —-a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-09 11:22 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 . 2009-12-09 11:22 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-11-21 04:59 . 2009-12-09 11:22 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-11-19 03:20 . 2009-11-19 03:20 ——– d—–w- c:\program files\Windows Portable Devices
2009-11-19 03:20 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-19 03:19 . 2009-11-19 03:19 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-16 11:30 . 2008-08-20 07:25 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-11-16 11:23 . 2009-05-20 13:08 ——– d—–w- c:\program files\VstPlugins
2009-11-16 11:20 . 2009-10-02 13:04 ——– d—–w- c:\program files\Common Files\Apple
2009-11-13 18:40 . 2009-10-02 13:19 ——– d—–w- c:\users\david\AppData\Roaming\Apple Computer
2009-11-06 09:41 . 2009-03-31 16:24 5632 —-a-w- c:\windows\system32\drivers\StarOpen.sys
2009-10-29 09:17 . 2009-11-26 07:52 2048 —-a-w- c:\windows\system32\tzres.dll
2009-10-28 22:37 . 2009-10-28 22:37 343088 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvix86.sys
2009-10-28 22:37 . 2009-10-28 22:37 329592 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSXpx86.sys
2009-10-28 22:37 . 2009-10-28 22:37 811896 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\Scxpx86.dll
2009-10-28 22:37 . 2009-10-28 22:37 488312 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.dll
2009-10-28 22:37 . 2009-10-28 22:37 466992 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSviA64.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-05-15 01:05 121392 —-a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1049896]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-26 28672]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-05-30 167936]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-21 6144000]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-09-10 809480]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-05-15 526896]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-06-11 409600]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe" [2008-09-23 6144]
"Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 585728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-11-29 198160]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-01-07 1394000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^david^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Orion.lnk]
path=c:\users\david\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Orion.lnk
backup=c:\windows\pss\Orion.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):92,7d,e5,2e,da,59,ca,01

R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\N360\0305020.00B\SymEFA.sys [26/11/2009 11:58 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\N360\0305020.00B\BHDrvx86.sys [26/11/2009 11:58 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\N360\0305020.00B\cchpx86.sys [26/11/2009 11:58 482432]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100106.001\IDSvix86.sys [08/01/2010 22:23 343088]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl [20/08/2008 21:40 61424]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [03/03/2008 20:11 16384]
R2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [20/08/2008 21:40 81504]
R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [20/08/2008 21:36 24576]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe [26/11/2009 11:58 117640]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [26/04/2008 04:36 45056]
R2 NTIPPKernel;NTIPPKernel;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [20/08/2008 21:40 122368]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [28/03/2008 11:44 210432]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [11/01/2010 08:35 102448]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\N360\0305020.00B\symndisv.sys [26/11/2009 11:58 48688]
R3 usbfilter;AMD USB Filter Driver;c:\windows\System32\drivers\usbfilter.sys [18/11/2008 19:53 22072]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [08/05/2009 22:05 691696]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [26/04/2008 04:36 131072]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [21/01/2008 02:33 21504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=0809&s;=2&o;=vb32&d;=1108&m;=aspire_5535
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\david\AppData\Roaming\Mozilla\Firefox\Profiles\5rqcz58a.default\
FF - prefs.js: keyword.URL - hxxp://www.sicto.com/search/?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&rls;=hQVhFcXf&q;=
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Musicnotes\npmusicn.dll
FF - plugin: c:\program files\Musicnotes\NPSibelius.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-

FF - user.js: keyword.URL - hxxp://www.sicto.com/search/?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&rls;=hQVhFcXf&q;=
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-DAEMON Tools - c:\program files\DAEMON Tools\daemon.exe
AddRemove-GOPlayer - c:\program files\GOPlayer\Uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-11 17:23
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x84DDE841]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x897a4d24
\Driver\ACPI -> acpi.sys @ 0x8060fd68
\Driver\atapi -> ataport.SYS @ 0x8071ea2c
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.5.2.11\diMaster.dll\" /prefetch:1"

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-164424331-24194484-381687128-1000\Software\SecuROM\License information*]
"datasecu"=hex:89,18,1b,9b,60,bb,89,27,27,0e,18,18,8e,9f,74,65,ea,d5,32,8d,c8,
b6,49,e4,65,ab,68,4f,1a,b4,86,84,34,8c,01,ac,73,3b,8c,16,1c,2d,18,5d,f7,28,\
"rkeysecu"=hex:db,bd,dc,9c,b1,64,a5,43,fa,16,2b,1a,74,e5,49,65

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-01-11 17:28:13
ComboFix-quarantined-files.txt 2010-01-11 17:28

Pre-Run: 53,315,256,320 bytes free
Post-Run: 53,959,397,376 bytes free

- - End Of File - - 241366FBDE5302A33FA65421BEE30C3E
Just to update my previous post i am now getting a different message every few minutes from my virus protection saying my computer is under attack from…..HTTPS tidserv c and c domain request………coming from device\harddiskvolume2\windows\system32\svchost.exe
Hi,

Please do the following:

you have CD emulation software which may be interfering with our tools, we will diable them until you are clean:


please do the following:

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.


NEXT

Is there another ComboFix log from the first time you tried to run it? It should be located at C:\qoobox\comboFix2.txt, if you find it, please post it.


NEXT


Please delete the copy of comboFix that you have on your desktop and download a fresh copy. Make sure all your security programs are disabled and run it.

Post the resulting log.

NEXT


  • Open your Malwarebytes Antimalware Select the Update tab.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.



NEXT

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *ahcix86s*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Just to let you know that following the first step of the last set of ations the computer needed restarting. It then would not restart. many times it would try to start whenn it got to the screen to log into windows it would turn off or restart again. This coninued for about 16 hours. I have reset it to settings from a few weeks ago using safe mode…..not sure if this was the correct thing to do or not but…. It is now working ok…..though i imagine the virus is still here….in fact i have just received a anti virus message saying a trojan has been blocked. What should i do now?
Are you referring to the defogger step or running the MalwareBytes program?

Restoring was the correct thing to do, but unfortunately the infection will be back. It appears to have hijacked your disk controller as well as your userinit.

we will need to tread carefully.

Please re run the DDS and GMER scans and export the winlogon registry key:

Press Start => Run, Copy/Paste the command below into the run dialog box and press OK:

reg export "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" "%userprofile%\desktop\look.txt"

You should see a new file on your Desktop named look.txt. Please post the contents of look.txt in your next reply

If you could also follow the System Look step as we know we will need to replace the ahcix86s.sys file
The computer wouldn't turn on again after trying to run the defogger.

Thanks again for the help

All the logs are below

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-12 22:15:10
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\david\AppData\Local\Temp\awtdikod.sys


—- System - GMER 1.0.15 —-

SSDT 87EE0C48 ZwAlertResumeThread
SSDT 87EE0D08 ZwAlertThread
SSDT 87789F80 ZwAllocateVirtualMemory
SSDT 8702D9B0 ZwAlpcConnectPort
SSDT 87E80B88 ZwAssignProcessToJobObject
SSDT 87BB1970 ZwCreateMutant
SSDT 8796E6D8 ZwCreateSymbolicLinkObject
SSDT 87633F20 ZwCreateThread
SSDT 87E80C68 ZwDebugActiveProcess
SSDT 88042EF0 ZwDuplicateObject
SSDT 87789DE0 ZwFreeVirtualMemory
SSDT 87BB1E68 ZwImpersonateAnonymousToken
SSDT 87EE0B88 ZwImpersonateThread
SSDT 8702D938 ZwLoadDriver
SSDT 877897C8 ZwMapViewOfSection
SSDT 87E80FD0 ZwOpenEvent
SSDT 871199D0 ZwOpenProcess
SSDT 8737BF30 ZwOpenProcessToken
SSDT 87E80E50 ZwOpenSection
SSDT 88042FC0 ZwOpenThread
SSDT 87E80A98 ZwProtectVirtualMemory
SSDT 872F6670 ZwResumeThread
SSDT 87EE0F48 ZwSetContextThread
SSDT 87789670 ZwSetInformationProcess
SSDT 87E80D48 ZwSetSystemInformation
SSDT 87E80F10 ZwSuspendProcess
SSDT 87EE0DC8 ZwSuspendThread
SSDT 8783AB50 ZwTerminateProcess
SSDT 87EE0E88 ZwTerminateThread
SSDT 87789DA8 ZwUnmapViewOfSection
SSDT 87789EB0 ZwWriteVirtualMemory
SSDT 87E80998 ZwCreateThreadEx

INT 0x82 ? 86706DC0
INT 0x82 ? 86706DC0
INT 0x82 ? 86706DC0
INT 0x91 ? 86706DC0
INT 0xA2 ? 86706DC0

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 84F661F8
Device \FileSystem\fastfat \FatCdrom 87FAC1F8

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device \Driver\volmgr \Device\VolMgrControl 84F621F8
Device \Driver\usbohci \Device\USBPDO-0 867051F8
Device \Driver\usbohci \Device\USBPDO-1 867051F8
Device \Driver\usbehci \Device\USBPDO-2 866FD1F8
Device \Driver\usbohci \Device\USBPDO-3 867051F8
Device \Driver\netbt \Device\NetBT_Tcpip_{17EEA341-584A-4D54-A539-5E24325FCE5D} 870671F8
Device \Driver\usbehci \Device\USBPDO-4 866FD1F8

AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\volmgr \Device\HarddiskVolume1 84F621F8
Device \Driver\volmgr \Device\HarddiskVolume2 84F621F8
Device \Driver\cdrom \Device\CdRom0 8670D1F8
Device \Driver\volmgr \Device\HarddiskVolume3 84F621F8
Device \Driver\netbt \Device\NetBt_Wins_Export 870671F8
Device \Driver\Smb \Device\NetbiosSmb 86FFA1F8

AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\iScsiPrt \Device\RaidPort1 8680A1F8

AttachedDevice \Driver\tdx \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\usbohci \Device\USBFDO-0 867051F8
Device \Driver\usbohci \Device\USBFDO-1 867051F8
Device \Driver\usbehci \Device\USBFDO-2 866FD1F8
Device \Driver\usbohci \Device\USBFDO-3 867051F8
Device \Driver\netbt \Device\NetBT_Tcpip_{AAF7D1EC-25F8-482E-B66D-42E0FF000732} 870671F8
Device \Driver\usbehci \Device\USBFDO-4 866FD1F8
Device \FileSystem\fastfat \Fat 87FAC1F8

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\cdfs \Cdfs 847F31F8

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x95 0x5E 0xAE 0xD0 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xE8 0x02 0x1A 0x51 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF6 0x2C 0x68 0x4A …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x95 0x5E 0xAE 0xD0 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xE8 0x02 0x1A 0x51 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF6 0x2C 0x68 0x4A …

—- Files - GMER 1.0.15 —-

File C:\Users\david\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4CBYJ1M3\114[1] 150 bytes

—- EOF - GMER 1.0.15 —-




DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 22:16:53.03 on 12/01/2010
Internet Explorer: 8.0.6001.18865 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.44.1033.18.2814.1084 [GMT 0:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Program Files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\david\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vb32&d=1108&m=aspire_5535
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vb32&d=1108&m=aspire_5535
mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vb32&d=1108&m=aspire_5535
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.5.2.11\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.5.2.11\IPSBHO.DLL
BHO: ShowBarObj Class: {83a2f9b1-01a2-4aa5-87d1-45b6b8505e96} - c:\program files\acer\empowering technology\edatasecurity\x86\ActiveToolBand.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\program files\acer\empowering technology\edatasecurity\x86\eDStoolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.5.2.11\coIEPlg.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [DAEMON Tools] "c:\program files\daemon tools\daemon.exe" -lang 1033
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [BkupTray] "c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe"
mRun: [CLMLServer] "c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\CLMLSvc.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Skytel] Skytel.exe
mRun: [LManager] c:\progra~1\launch~1\LManager.exe
mRun: [eDataSecurity Loader] c:\program files\acer\empowering technology\edatasecurity\x86\eDSloader.exe
mRun: [ePower_DMC] c:\program files\acer\empowering technology\epower\ePower_DMC.exe
mRun: [eRecoveryService]
mRun: [ProductReg] "c:\program files\acer\wr_popup\ProductReg.exe"
mRun: [Wireless Manager] "c:\program files\virgin broadband wireless\Wireless Manager.exe" startup
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\freene~1.lnk - c:\program files\freenet\bin\freenettray.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.5.2.11\CoIEPlg.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\david\appdata\roaming\mozilla\firefox\profiles\5rqcz58a.default\
FF - prefs.js: browser.search.selectedEngine - Search
FF - prefs.js: keyword.URL - hxxp://www.sicto.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=hQVhFcXf&q=
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-

FF - user.js: browser.search.selectedEngine - Search
FF - user.js: keyword.URL - hxxp://www.sicto.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=hQVhFcXf&q=
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0305020.00b\SymEFA.sys [2009-11-26 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0305020.00b\BHDrvx86.sys [2009-11-26 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0305020.00b\cchpx86.sys [2009-11-26 482432]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20091217.002\IDSvix86.sys [2009-12-18 343088]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\acer arcade deluxe\playmovie\000.fcl [2008-8-20 61424]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 CLHNService;CLHNService;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\CLHNService.exe [2008-8-20 81504]
R2 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2008-8-20 24576]
R2 N360;Norton 360;c:\program files\norton 360\engine\3.5.2.11\ccSvcHst.exe [2009-11-26 117640]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\NBService.exe [2008-11-25 935208]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-26 45056]
R2 NTIPPKernel;NTIPPKernel;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\NTIPPKernel.sys [2008-8-20 122368]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-26 131072]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-3-28 210432]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0305020.00b\symndisv.sys [2009-11-26 48688]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2008-11-18 22072]
S2 freenet;Freenet background service;c:\program files\freenet\bin\wrapper-windows-x86-32.exe [2009-10-23 241664]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]

============== File Associations ===============

regfile="regedit.exe" "%1"

=============== Created Last 30 ================

2010-01-11 20:14 –d—– c:\programdata\SUPERAntiSpyware.com
2010-01-11 20:14 –d—– c:\progra~2\SUPERAntiSpyware.com
2010-01-11 20:14 –d—– c:\program files\SUPERAntiSpyware
2010-01-11 20:14 –d—– c:\users\david\appdata\roaming\SUPERAntiSpyware.com
2010-01-11 13:23 –d—– c:\users\david\appdata\roaming\Malwarebytes
2010-01-11 13:22 –d—– c:\programdata\Malwarebytes
2010-01-11 13:22 –d—– c:\progra~2\Malwarebytes
2010-01-11 13:22 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-10 14:10 –d–r– c:\program files\Norton Support
2010-01-04 22:35 –d—– c:\programdata\Musicnotes
2010-01-04 22:35 –d—– c:\progra~2\Musicnotes
2010-01-04 22:31 –d—– c:\program files\Musicnotes
2009-12-28 17:01 –d—– c:\program files\RealArcade

==================== Find3M ====================

2009-11-27 14:35 691,696 a——- c:\windows\system32\drivers\sptd.sys
2009-11-26 11:59 143,360 a——- c:\windows\inf\infstrng.dat
2009-11-26 11:59 86,016 a——- c:\windows\inf\infstor.dat
2009-11-26 11:59 51,200 a——- c:\windows\inf\infpub.dat
2009-11-26 11:59 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-11-26 11:59 7,456 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2009-11-26 11:59 806 a——- c:\windows\system32\drivers\SYMEVENT.INF
2009-11-26 11:58 26,600 a—-r– c:\windows\system32\drivers\GEARAspiWDM.sys
2009-11-26 11:58 25,648 a—-r– c:\windows\system32\drivers\SymIMV.sys
2009-11-26 11:58 107,368 a—-r– c:\windows\system32\GEARAspi.dll
2009-11-21 06:40 916,480 a——- c:\windows\system32\wininet.dll
2009-11-21 06:34 109,056 a——- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-11-21 04:59 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-11-19 03:20 665,600 a——- c:\windows\inf\drvindex.dat
2009-11-19 03:19 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-29 09:17 2,048 a——- c:\windows\system32\tzres.dll
2009-04-30 15:58 87,608 a——- c:\users\david\appdata\roaming\inst.exe
2009-04-30 15:58 47,360 a——- c:\users\david\appdata\roaming\pcouffin.sys
2008-01-21 02:57 174 a–sh— c:\program files\desktop.ini
2006-11-02 12:39 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:39 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 12:39 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:39 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 09:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 22:17:29.95 ===============


Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"ReportBootOk"="1"
"Shell"="explorer.exe"
"Userinit"="C:\\Windows\\system32\\userinit.exe,"
"VmApplet"="rundll32 shell32,Control_RunDLL \"sysdm.cpl\""
"AutoRestartShell"=dword:00000001
"LegalNoticeCaption"=""
"LegalNoticeText"=""
"PowerdownAfterShutdown"="0"
"ShutdownWithoutLogon"="0"
"cachedlogonscount"="10"
"forceunlocklogon"=dword:00000000
"passwordexpirywarning"=dword:0000000e
"Background"="0 0 0"
"DebugServerCommand"="no"
"WinStationsDisabled"="0"
"DisableCAD"=dword:00000001
"scremoveoption"="0"
"ShutdownFlags"=dword:00000087

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}]
@="Wireless Group Policy"
"DisplayName"=hex(2):40,00,77,00,6c,00,67,00,70,00,63,00,6c,00,6e,00,74,00,2e,\
00,64,00,6c,00,6c,00,2c,00,2d,00,31,00,30,00,30,00,00,00
"ProcessGroupPolicyEx"="ProcessWLANPolicyEx"
"GenerateGroupPolicy"="GenerateWLANPolicy"
"DllName"=hex(2):77,00,6c,00,67,00,70,00,63,00,6c,00,6e,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}]
@="Folder Redirection"
"ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
"DllName"=hex(2):66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,00,6c,00,\
6c,00,00,00
"NoMachinePolicy"=dword:00000001
"NoSlowLink"=dword:00000001
"PerUserLocalSettings"=dword:00000001
"NoGPOListChanges"=dword:00000000
"NoBackgroundPolicy"=dword:00000000
"GenerateGroupPolicy"="GenerateGroupPolicy"
"EventSources"=hex(7):28,00,46,00,6f,00,6c,00,64,00,65,00,72,00,20,00,52,00,65,\
00,64,00,69,00,72,00,65,00,63,00,74,00,69,00,6f,00,6e,00,2c,00,41,00,70,00,\
70,00,6c,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,00,29,00,00,00,00,00
"DisplayName"=hex(2):40,00,66,00,64,00,65,00,70,00,6c,00,6f,00,79,00,2e,00,64,\
00,6c,00,6c,00,2c,00,2d,00,32,00,36,00,31,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{35378EAC-683F-11D2-A89A-00C04FBBCFA2}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}]
@="Microsoft Disk Quota"
"DisplayName"=hex(2):40,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,64,00,73,00,6b,00,71,00,75,00,6f,00,74,00,61,00,2e,00,64,00,6c,00,6c,\
00,2c,00,2d,00,31,00,30,00,30,00,00,00
"NoMachinePolicy"=dword:00000000
"NoUserPolicy"=dword:00000001
"NoSlowLink"=dword:00000001
"NoBackgroundPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"PerUserLocalSettings"=dword:00000000
"RequiresSuccessfulRegistry"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000000
"DllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,\
00,73,00,6b,00,71,00,75,00,6f,00,74,00,61,00,2e,00,64,00,6c,00,6c,00,00,00
"ProcessGroupPolicy"="ProcessGroupPolicy"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}]
@="QoS Packet Scheduler"
"DisplayName"=hex(2):40,00,67,00,70,00,74,00,65,00,78,00,74,00,2e,00,64,00,6c,\
00,6c,00,2c,00,2d,00,32,00,30,00,31,00,00,00
"ProcessGroupPolicy"="ProcessPSCHEDPolicy"
"DllName"=hex(2):67,00,70,00,74,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,\
00,00
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}]
"ProcessGroupPolicy"="ProcessGroupPolicyForZoneMap"
"DllName"="C:\\Windows\\System32\\iedkcs32.dll"
@="Internet Explorer Zonemapping"
"NoGPOListChanges"=dword:00000001
"DisplayName"="@C:\\Windows\\System32\\iedkcs32.dll,-3051"
"RequiresSuccessfulRegistry"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7933F41E-56F8-41d6-A31C-4148A711EE93}]
@="Windows Search Group Policy Extension"
"DllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,72,00,63,00,68,00,61,00,64,00,6d,00,69,00,6e,00,2e,00,64,00,6c,00,6c,00,\
00,00
"EnableAsynchronousProcessing"=dword:00000001
"NoBackgroundPolicy"=dword:00000000
"NoGPOListChanges"=dword:00000001
"NoMachinePolicy"=dword:00000000
"NoSlowLink"=dword:00000000
"NoUserPolicy"=dword:00000000
"PerUserLocalSettings"=dword:00000000
"ProcessGroupPolicy"="ProcessGroupPolicy"
"RequiresSuccessfulRegistry"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}]
@="Internet Explorer User Accelerators"
"ProcessGroupPolicy"="ProcessGroupPolicyForActivities"
"DllName"="C:\\Windows\\System32\\iedkcs32.dll"
"RequiresSuccessfulRegistry"=dword:00000001
"ProcessGroupPolicyEx"="ProcessGroupPolicyForActivitiesEx"
"NoGPOListChanges"=dword:00000001
"DisplayName"="@C:\\Windows\\System32\\iedkcs32.dll,-3051"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}]
@="Security"
"DisplayName"=hex(2):40,00,28,00,72,00,75,00,6e,00,74,00,69,00,6d,00,65,00,2e,\
00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,29,00,5c,00,73,00,63,00,\
65,00,63,00,6c,00,69,00,2e,00,64,00,6c,00,6c,00,2c,00,2d,00,37,00,36,00,35,\
00,30,00,00,00
"ProcessGroupPolicy"="SceProcessSecurityPolicyGPO"
"GenerateGroupPolicy"="SceGenerateGroupPolicy"
"ExtensionRsopPlanningDebugLevel"=dword:00000001
"ProcessGroupPolicyEx"="SceProcessSecurityPolicyGPOEx"
"ExtensionDebugLevel"=dword:00000001
"DllName"=hex(2):73,00,63,00,65,00,63,00,6c,00,69,00,2e,00,64,00,6c,00,6c,00,\
00,00
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
"MaxNoGPOListChangesInterval"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}]
"ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
"GenerateGroupPolicy"="GenerateGroupPolicy"
"ProcessGroupPolicy"="ProcessGroupPolicy"
"DllName"="C:\\Windows\\System32\\iedkcs32.dll"
@="Internet Explorer Branding"
"NoSlowLink"=dword:00000001
"NoBackgroundPolicy"=dword:00000000
"NoGPOListChanges"=dword:00000001
"NoMachinePolicy"=dword:00000001
"DisplayName"="@C:\\Windows\\System32\\iedkcs32.dll,-3014"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}]
"ProcessGroupPolicy"="SceProcessEFSRecoveryGPO"
"DllName"=hex(2):73,00,63,00,65,00,63,00,6c,00,69,00,2e,00,64,00,6c,00,6c,00,\
00,00
@="EFS recovery"
"DisplayName"="@(runtime.system32)\\scecli.dll,-7651"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"RequiresSuccessfulRegistry"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}]
@="802.3 Group Policy"
"DisplayName"=hex(2):40,00,64,00,6f,00,74,00,33,00,67,00,70,00,63,00,6c,00,6e,\
00,74,00,2e,00,64,00,6c,00,6c,00,2c,00,2d,00,31,00,30,00,30,00,00,00
"ProcessGroupPolicyEx"="ProcessLANPolicyEx"
"GenerateGroupPolicy"="GenerateLANPolicy"
"DllName"=hex(2):64,00,6f,00,74,00,33,00,67,00,70,00,63,00,6c,00,6e,00,74,00,\
2e,00,64,00,6c,00,6c,00,00,00
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}]
@="Internet Explorer Machine Accelerators"
"ProcessGroupPolicy"="ProcessGroupPolicyForActivities"
"DllName"="C:\\Windows\\System32\\iedkcs32.dll"
"RequiresSuccessfulRegistry"=dword:00000001
"ProcessGroupPolicyEx"="ProcessGroupPolicyForActivitiesEx"
"NoGPOListChanges"=dword:00000001
"DisplayName"="@C:\\Windows\\System32\\iedkcs32.dll,-3051"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}]
@="IP Security"
"ProcessGroupPolicyEx"="ProcessIPSECPolicyEx"
"GenerateGroupPolicy"="GenerateIPSECPolicy"
"DllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,70,\
00,6f,00,6c,00,73,00,74,00,6f,00,72,00,65,00,2e,00,64,00,6c,00,6c,00,00,00
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000000
"DisplayName"=hex(2):40,00,43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,\
00,73,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,70,00,\
6f,00,6c,00,73,00,74,00,6f,00,72,00,65,00,2e,00,64,00,6c,00,6c,00,2c,00,2d,\
00,35,00,30,00,31,00,32,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{FB2CA36D-0B40-4307-821B-A13B252DE56C}]
@="Enterprise QoS"
"DisplayName"=hex(2):40,00,67,00,70,00,74,00,65,00,78,00,74,00,2e,00,64,00,6c,\
00,6c,00,2c,00,2d,00,32,00,30,00,33,00,00,00
"ProcessGroupPolicy"="ProcessEQoSPolicy"
"DllName"=hex(2):67,00,70,00,74,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,\
00,00
"RequiresSuccessfulRegistry"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AutoLogonChecked]





SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 22:23 on 12/01/2010 by david (Administrator - Elevation successful)

========== filefind ==========

Searching for "*ahcix86s*"
C:\Acer\Preload\Autorun\DRV\AHCI\ahcix86s –a— 7 bytes [20:37 18/11/2008] [20:40 17/03/2008] C53E7A6C548B754B425B0DA0A0D21ED7
C:\Acer\Preload\Autorun\DRV\AHCI\ahcix86s.cat –a— 30077 bytes [20:37 18/11/2008] [02:53 02/07/2008] A4F21E40211569525759532E9AA1E555
C:\Acer\Preload\Autorun\DRV\AHCI\ahcix86s.inf –a— 13449 bytes [20:37 18/11/2008] [18:53 23/06/2008] 773CC3FB0C259013E50A9F9424A635A4
C:\Acer\Preload\Autorun\DRV\AHCI\ahcix86s.msi –a— 76288 bytes [20:37 18/11/2008] [00:48 12/07/2008] 6B94A79A1161E220EBBE59C08E5061E1
C:\Acer\Preload\Autorun\DRV\AHCI\ahcix86s.sys –a— 173576 bytes [20:37 18/11/2008] [21:55 27/05/2008] FBE4016F9EF3AB3DB547E40A936B6CD9
C:\Acer\Preload\Autorun\DRV\ATIVGA\Packages\Drivers\SBDrv\SB7xx\RAID\LH\ahcix86s.cat –a— 30077 bytes [20:37 18/11/2008] [02:53 02/07/2008] A4F21E40211569525759532E9AA1E555
C:\Acer\Preload\Autorun\DRV\ATIVGA\Packages\Drivers\SBDrv\SB7xx\RAID\LH\ahcix86s.inf –a— 13449 bytes [20:37 18/11/2008] [18:53 23/06/2008] 773CC3FB0C259013E50A9F9424A635A4
C:\Acer\Preload\Autorun\DRV\ATIVGA\Packages\Drivers\SBDrv\SB7xx\RAID\LH\ahcix86s.sys –a— 173576 bytes [20:37 18/11/2008] [21:55 27/05/2008] FBE4016F9EF3AB3DB547E40A936B6CD9
C:\Windows\System32\DriverStore\FileRepository\ahcix86s.inf_c617648e\ahcix86s.cat –a— 30077 bytes [20:37 18/11/2008] [02:53 02/07/2008] A4F21E40211569525759532E9AA1E555
C:\Windows\System32\DriverStore\FileRepository\ahcix86s.inf_c617648e\ahcix86s.inf –a— 13449 bytes [20:37 18/11/2008] [18:53 23/06/2008] 773CC3FB0C259013E50A9F9424A635A4
C:\Windows\System32\DriverStore\FileRepository\ahcix86s.inf_c617648e\ahcix86s.PNF –a— 32560 bytes [19:48 18/11/2008] [19:48 18/11/2008] 55D21F252AB381B6CA097ABD8E57114A
C:\Windows\System32\DriverStore\FileRepository\ahcix86s.inf_c617648e\ahcix86s.sys –a— 173576 bytes [20:37 18/11/2008] [21:55 27/05/2008] FBE4016F9EF3AB3DB547E40A936B6CD9
C:\Windows\System32\DriverStore\Temp\{51666723-d34d-4049-b6d6-a53eb2f7da9a}\Package\ahcix86s.cat –a— 30077 bytes [20:37 18/11/2008] [02:53 02/07/2008] A4F21E40211569525759532E9AA1E555
C:\Windows\System32\drivers\ahcix86s.sys –a— 173576 bytes [20:37 18/11/2008] [21:55 27/05/2008] FBE4016F9EF3AB3DB547E40A936B6CD9

-=End Of File=-
Hi, something must be amiss with that driver if running defogger caused a non boot situation as the log in key looks fine. So let's re run ComboFix. Delete the copy you have from your desktop and download a fresh copy from the previous link provided. Disable your security programs ad run it. Post the resulting log.
Here's the combofix log

ComboFix 10-01-12.04 - david 13/01/2010 9:40.1.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.44.1033.18.2814.2070 [GMT 0:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-164424331-24194484-381687128-500
c:\users\david\AppData\Roaming\inst.exe

.
((((((((((((((((((((((((( Files Created from 2009-12-13 to 2010-01-13 )))))))))))))))))))))))))))))))
.

2010-01-13 04:31 . 2010-01-11 13:40 84912 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100112.025\NAVENG.SYS
2010-01-13 04:31 . 2010-01-11 13:40 371248 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100112.025\EECTRL.SYS
2010-01-13 04:31 . 2010-01-11 13:40 2747440 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100112.025\CCERASER.DLL
2010-01-13 04:31 . 2010-01-11 13:40 259440 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100112.025\ECMSVR32.DLL
2010-01-13 04:31 . 2010-01-11 13:40 177520 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100112.025\NAVENG32.DLL
2010-01-13 04:31 . 2010-01-11 13:40 1647984 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100112.025\NAVEX32A.DLL
2010-01-13 04:31 . 2010-01-11 13:40 1323568 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100112.025\NAVEX15.SYS
2010-01-13 04:31 . 2010-01-11 13:40 102448 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100112.025\ERASER.SYS
2010-01-11 20:14 . 2010-01-11 20:14 ——– d—–w- c:\programdata\SUPERAntiSpyware.com
2010-01-11 20:14 . 2010-01-11 20:14 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-01-11 20:14 . 2010-01-11 20:14 ——– d—–w- c:\users\david\AppData\Roaming\SUPERAntiSpyware.com
2010-01-11 17:49 . 2010-01-11 17:49 ——– d—–w- c:\users\david\AppData\Local\Apple
2010-01-11 17:28 . 2010-01-11 22:53 ——– d—–w- c:\users\david\AppData\Local\temp(73)
2010-01-11 14:19 . 2010-01-11 14:19 ——– d—–w- c:\users\david\AppData\Local\Symantec
2010-01-11 13:23 . 2010-01-11 13:23 ——– d—–w- c:\users\david\AppData\Roaming\Malwarebytes
2010-01-11 13:22 . 2010-01-11 13:22 ——– d—–w- c:\programdata\Malwarebytes
2010-01-11 13:22 . 2010-01-11 13:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-10 14:10 . 2010-01-12 16:33 ——– d—–r- c:\program files\Norton Support
2010-01-04 22:35 . 2010-01-04 22:35 ——– d—–w- c:\programdata\Musicnotes
2010-01-04 22:31 . 2010-01-04 22:32 ——– d—–w- c:\program files\Musicnotes
2009-12-28 17:01 . 2010-01-13 00:10 ——– d—–w- c:\program files\RealArcade
2009-12-18 21:38 . 2009-10-28 22:37 343088 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\IDSvix86.sys
2009-12-18 21:38 . 2009-10-28 22:37 329592 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\IDSXpx86.sys
2009-12-18 21:38 . 2009-10-28 22:37 811896 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\Scxpx86.dll
2009-12-18 21:38 . 2009-10-28 22:37 488312 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\IDSxpx86.dll
2009-12-18 21:38 . 2009-10-28 22:37 466992 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\IDSviA64.sys
2009-12-18 12:10 . 2009-10-28 22:37 329592 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091216.001\IDSXpx86.sys
2009-12-18 12:10 . 2009-10-28 22:37 811896 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091216.001\Scxpx86.dll
2009-12-18 12:10 . 2009-10-28 22:37 343088 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091216.001\IDSvix86.sys
2009-12-18 12:10 . 2009-10-28 22:37 488312 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091216.001\IDSxpx86.dll
2009-12-18 12:10 . 2009-10-28 22:37 466992 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091216.001\IDSviA64.sys
2009-12-15 09:38 . 2009-10-28 22:37 329592 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091211.001\IDSXpx86.sys
2009-12-15 09:38 . 2009-10-28 22:37 811896 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091211.001\Scxpx86.dll
2009-12-15 09:37 . 2009-10-28 22:37 343088 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091211.001\IDSvix86.sys
2009-12-15 09:37 . 2009-10-28 22:37 488312 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091211.001\IDSxpx86.dll
2009-12-15 09:37 . 2009-10-28 22:37 466992 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091211.001\IDSviA64.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-13 09:44 . 2009-04-28 17:27 ——– d—–w- c:\program files\Steam
2010-01-13 09:44 . 2009-04-28 17:27 ——– d—–w- c:\program files\Common Files\Steam
2010-01-13 00:13 . 2009-04-06 14:25 ——– d—–w- c:\users\david\AppData\Roaming\uTorrent
2010-01-13 00:13 . 2009-11-21 11:33 ——– d—–w- c:\programdata\Yahoo! Companion
2010-01-13 00:13 . 2009-11-26 16:08 ——– d—–w- c:\program files\Freenet
2010-01-13 00:13 . 2009-06-18 13:19 ——– d—–w- c:\program files\VirtualDJ
2010-01-13 00:13 . 2009-05-20 13:02 ——– d—–w- c:\program files\Image-Line
2010-01-13 00:13 . 2009-04-26 07:41 ——– d—–w- c:\program files\RegCure
2010-01-13 00:13 . 2009-04-06 14:25 ——– d—–w- c:\program files\uTorrent
2010-01-13 00:13 . 2008-08-20 21:14 ——– d—–w- c:\program files\Microsoft Works
2010-01-13 00:13 . 2008-08-20 07:25 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-01-12 22:34 . 2009-04-06 13:34 ——– d—–w- c:\programdata\Soulseek
2010-01-12 16:33 . 2009-03-31 15:46 72440 —-a-w- c:\users\david\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-08 19:27 . 2008-08-20 21:37 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-05 12:12 . 2008-08-20 21:18 ——– d—–w- c:\program files\Acer GameZone
2010-01-05 12:12 . 2009-10-21 20:39 ——– d—–w- c:\program files\Yahoo!
2010-01-05 12:12 . 2009-07-11 13:36 ——– d—–w- c:\program files\MSN Games
2009-12-20 16:42 . 2009-04-06 13:16 ——– d—–w- c:\users\david\AppData\Roaming\Skype
2009-12-10 03:21 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-12-10 03:05 . 2008-08-20 21:12 ——– d—–w- c:\programdata\Microsoft Help
2009-11-29 11:37 . 2009-04-06 17:47 ——– d—–w- c:\program files\Common Files\Real
2009-11-29 11:37 . 2009-11-29 11:37 ——– d—–w- c:\program files\Common Files\xing shared
2009-11-29 11:37 . 2009-11-29 11:37 ——– d—–w- c:\program files\real
2009-11-27 14:35 . 2009-05-08 22:05 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-11-27 09:32 . 2009-11-26 16:08 ——– d—–w- c:\program files\Java
2009-11-27 08:00 . 2009-11-27 08:00 ——– d—–w- c:\programdata\Symantec
2009-11-26 12:35 . 2009-04-09 19:49 ——– d—–w- c:\program files\GOPlayer
2009-11-26 12:17 . 2009-11-26 11:59 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-11-26 11:59 . 2009-11-26 11:59 ——– d—–w- c:\program files\Symantec
2009-11-26 11:59 . 2009-11-26 11:59 806 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-11-26 11:59 . 2009-11-26 11:59 7456 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-11-26 11:59 . 2009-11-26 11:59 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-11-26 11:58 . 2009-11-26 11:59 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-11-26 11:58 . 2009-11-26 11:59 25648 —-a-r- c:\windows\system32\drivers\SymIMV.sys
2009-11-26 11:58 . 2009-11-26 11:58 1291104 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-11-26 11:58 . 2009-11-26 11:58 136840 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2009-11-26 11:58 . 2009-11-26 11:58 165240 —-a-r- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2009-11-26 11:58 . 2009-11-26 11:59 107368 —-a-r- c:\windows\system32\GEARAspi.dll
2009-11-26 11:58 . 2009-11-26 11:59 554352 —-a-r- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
2009-11-26 11:58 . 2009-11-26 11:58 771440 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-11-26 11:57 . 2009-11-26 11:57 ——– d—–w- c:\program files\Norton 360
2009-11-26 11:57 . 2009-11-26 11:57 ——– d—–w- c:\programdata\Norton
2009-11-26 11:56 . 2008-08-20 21:08 ——– d—–w- c:\programdata\McAfee
2009-11-26 11:56 . 2009-11-26 11:51 ——– d—–w- c:\programdata\NortonInstaller
2009-11-26 11:55 . 2008-08-20 21:09 ——– d—–w- c:\program files\McAfee
2009-11-26 11:51 . 2009-11-26 11:51 ——– d—–w- c:\program files\NortonInstaller
2009-11-23 19:05 . 2009-11-23 19:05 439816 —-a-w- c:\users\david\AppData\Roaming\Real\Update\setup3.09\setup.exe
2009-11-21 11:33 . 2009-11-21 11:33 ——– d—–w- c:\users\david\AppData\Roaming\Yahoo!
2009-11-21 06:40 . 2009-12-09 11:22 916480 —-a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-09 11:22 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 . 2009-12-09 11:22 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-11-21 04:59 . 2009-12-09 11:22 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-11-19 03:20 . 2009-11-19 03:20 ——– d—–w- c:\program files\Windows Portable Devices
2009-11-19 03:20 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-19 03:19 . 2009-11-19 03:19 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-16 11:23 . 2009-05-20 13:08 ——– d—–w- c:\program files\VstPlugins
2009-11-16 11:20 . 2009-10-02 13:04 ——– d—–w- c:\program files\Common Files\Apple
2009-11-06 09:41 . 2009-03-31 16:24 5632 —-a-w- c:\windows\system32\drivers\StarOpen.sys
2009-10-29 09:17 . 2009-11-26 07:52 2048 —-a-w- c:\windows\system32\tzres.dll
2009-10-28 22:37 . 2009-10-28 22:37 343088 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvix86.sys
2009-10-28 22:37 . 2009-10-28 22:37 329592 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSXpx86.sys
2009-10-28 22:37 . 2009-10-28 22:37 811896 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\Scxpx86.dll
2009-10-28 22:37 . 2009-10-28 22:37 488312 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.dll
2009-10-28 22:37 . 2009-10-28 22:37 466992 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSviA64.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-05-15 01:05 121392 —-a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1049896]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-26 28672]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-05-30 167936]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-21 6144000]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-09-10 809480]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-05-15 526896]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-06-11 409600]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe" [2008-09-23 6144]
"Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 585728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-11-29 198160]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Freenet Tray.lnk - c:\program files\Freenet\bin\freenettray.exe [2009-11-4 252244]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^david^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Orion.lnk]
path=c:\users\david\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Orion.lnk
backup=c:\windows\pss\Orion.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):92,7d,e5,2e,da,59,ca,01

R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\N360\0305020.00B\SymEFA.sys [26/11/2009 11:58 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\N360\0305020.00B\BHDrvx86.sys [26/11/2009 11:58 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\N360\0305020.00B\cchpx86.sys [26/11/2009 11:58 482432]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\IDSvix86.sys [18/12/2009 21:38 343088]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl [20/08/2008 21:40 61424]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [03/03/2008 20:11 16384]
R2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [20/08/2008 21:40 81504]
R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [20/08/2008 21:36 24576]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe [26/11/2009 11:58 117640]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [26/04/2008 04:36 45056]
R2 NTIPPKernel;NTIPPKernel;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [20/08/2008 21:40 122368]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [28/03/2008 11:44 210432]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [13/01/2010 04:31 102448]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\N360\0305020.00B\symndisv.sys [26/11/2009 11:58 48688]
R3 usbfilter;AMD USB Filter Driver;c:\windows\System32\drivers\usbfilter.sys [18/11/2008 19:53 22072]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [08/05/2009 22:05 691696]
S2 freenet;Freenet background service;c:\program files\Freenet\bin\wrapper-windows-x86-32.exe [23/10/2009 18:43 241664]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [26/04/2008 04:36 131072]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [21/01/2008 02:33 21504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-01-12 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2009-12-11 19:00]

2010-01-13 c:\windows\Tasks\RegCure Startup.job
- c:\program files\RegCure\RegCure.exe [2009-12-11 19:00]

2010-01-12 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2009-12-11 19:00]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=0809&s;=2&o;=vb32&d;=1108&m;=aspire_5535
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\david\AppData\Roaming\Mozilla\Firefox\Profiles\5rqcz58a.default\
FF - prefs.js: keyword.URL - hxxp://www.sicto.com/search/?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&rls;=hQVhFcXf&q;=
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-

FF - user.js: keyword.URL - hxxp://www.sicto.com/search/?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&rls;=hQVhFcXf&q;=
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-DAEMON Tools - c:\program files\DAEMON Tools\daemon.exe
HKLM-Run-eRecoveryService - (no file)
AddRemove-GOPlayer - c:\program files\GOPlayer\Uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-13 09:48
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.5.2.11\diMaster.dll\" /prefetch:1"

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-164424331-24194484-381687128-1000\Software\SecuROM\License information*]
"datasecu"=hex:89,18,1b,9b,60,bb,89,27,27,0e,18,18,8e,9f,74,65,ea,d5,32,8d,c8,
b6,49,e4,65,ab,68,4f,1a,b4,86,84,34,8c,01,ac,73,3b,8c,16,1c,2d,18,5d,f7,28,\
"rkeysecu"=hex:db,bd,dc,9c,b1,64,a5,43,fa,16,2b,1a,74,e5,49,65

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-01-13 09:51:50
ComboFix-quarantined-files.txt 2010-01-13 09:51

Pre-Run: 53,643,403,264 bytes free
Post-Run: 54,546,280,448 bytes free

- - End Of File - - CCA31EE699A7F9A52A5A3923213F862B
Hi,

Can you please see if there is a file on your desktop called defogger_disable.log, please post the contents:

Please do the following:
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.




NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • Defogger log
  • MBAM Log
  • Kaspersky report
The only item i can find on my computer regarding defogger is a file called defogger_reenable….which doesn't even say what kind of file it is. When i used combofix it did still say my computer had cd emulation software running which it would disable it while it was working. Malwarebytes' Anti-Malware 1.44 Database version: 3554 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18865 13/01/2010 14:21:48 mbam-log-2010-01-13 (14-21-48).txt Scan type: Quick Scan Objects scanned: 98681 Time elapsed: 5 minute(s), 46 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, January 13, 2010 Operating system: Microsoft Windows Vista Home Basic Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, January 13, 2010 12:24:05 Records in database: 3305565 Scan settings scan using the following database extended Scan archives yes Scan e-mail databases yes Scan area My Computer C:\ D:\ E:\ Scan statistics Objects scanned 185027 Threats found 0 Infected objects found 0 Suspicious objects found 0 Scan duration 03:39:08 No threats found. Scanned area is clean. Selected area has been scanned.
Seems to be running fine now…..i haven't received any anti virus warnings for a while have nothing outstanding….though not quite sure i understand how it's gone DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 18:57:42.68 on 13/01/2010 Internet Explorer: 8.0.6001.18865 BrowserJavaVersion: 1.6.0_17 Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.44.1033.18.2814.1167 [GMT 0:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Cyberlink\Shared files\RichVideo.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\taskeng.exe C:\Program Files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\Steam\Steam.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Common Files\Steam\SteamService.exe C:\Program Files\Acer\Empowering Technology\Service\ETService.exe C:\Windows\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Windows\System32\mobsync.exe C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe C:\Program Files\Java\jre6\bin\java.exe C:\Users\david\AppData\Local\temp\jkos-david\binaries\ScanningProcess.exe C:\Users\david\AppData\Local\temp\jkos-david\binaries\ScanningProcess.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\david\Downloads\dds(2).scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/ mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vb32&d=1108&m=aspire_5535 uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.5.2.11\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.5.2.11\IPSBHO.DLL BHO: ShowBarObj Class: {83a2f9b1-01a2-4aa5-87d1-45b6b8505e96} - c:\program files\acer\empowering technology\edatasecurity\x86\ActiveToolBand.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\program files\acer\empowering technology\edatasecurity\x86\eDStoolbar.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.5.2.11\coIEPlg.dll uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [BkupTray] "c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe" mRun: [CLMLServer] "c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\CLMLSvc.exe" mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [Skytel] Skytel.exe mRun: [LManager] c:\progra~1\launch~1\LManager.exe mRun: [eDataSecurity Loader] c:\program files\acer\empowering technology\edatasecurity\x86\eDSloader.exe mRun: [ePower_DMC] c:\program files\acer\empowering technology\epower\ePower_DMC.exe mRun: [ProductReg] "c:\program files\acer\wr_popup\ProductReg.exe" mRun: [Wireless Manager] "c:\program files\virgin broadband wireless\Wireless Manager.exe" startup mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\freene~1.lnk - c:\program files\freenet\bin\freenettray.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.5.2.11\CoIEPlg.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\david\appdata\roaming\mozilla\firefox\profiles\5rqcz58a.default\ FF - prefs.js: keyword.URL - hxxp://www.sicto.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=hQVhFcXf&q= FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: keyword.URL - hxxp://www.sicto.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=hQVhFcXf&q= c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0305020.00b\SymEFA.sys [2009-11-26 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0305020.00b\BHDrvx86.sys [2009-11-26 259632] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0305020.00b\cchpx86.sys [2009-11-26 482432] R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20091217.002\IDSvix86.sys [2009-12-18 343088] R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\acer arcade deluxe\playmovie\000.fcl [2008-8-20 61424] R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384] R2 CLHNService;CLHNService;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\CLHNService.exe [2008-8-20 81504] R2 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2008-8-20 24576] R2 N360;Norton 360;c:\program files\norton 360\engine\3.5.2.11\ccSvcHst.exe [2009-11-26 117640] R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\NBService.exe [2008-11-25 935208] R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-26 45056] R2 NTIPPKernel;NTIPPKernel;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\NTIPPKernel.sys [2008-8-20 122368] R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-3-28 210432] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-1-13 102448] R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0305020.00b\symndisv.sys [2009-11-26 48688] R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2008-11-18 22072] S2 freenet;Freenet background service;c:\program files\freenet\bin\wrapper-windows-x86-32.exe [2009-10-23 241664] S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-26 131072] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504] =============== Created Last 30 ================ 2010-01-13 14:14 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-13 14:14 19,160 a——- c:\windows\system32\drivers\mbam.sys 2010-01-13 09:51 –dsh— C:\$RECYCLE.BIN 2010-01-13 09:39 261,632 a——- c:\windows\PEV.exe 2010-01-13 09:39 161,792 a——- c:\windows\SWREG.exe 2010-01-13 09:39 98,816 a——- c:\windows\sed.exe 2010-01-13 09:39 77,312 a——- c:\windows\MBR.exe 2010-01-11 20:14 –d—– c:\programdata\SUPERAntiSpyware.com 2010-01-11 20:14 –d—– c:\progra~2\SUPERAntiSpyware.com 2010-01-11 20:14 –d—– c:\program files\SUPERAntiSpyware 2010-01-11 20:14 –d—– c:\users\david\appdata\roaming\SUPERAntiSpyware.com 2010-01-11 13:23 –d—– c:\users\david\appdata\roaming\Malwarebytes 2010-01-11 13:22 –d—– c:\programdata\Malwarebytes 2010-01-11 13:22 –d—– c:\progra~2\Malwarebytes 2010-01-11 13:22 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-01-10 14:10 –d–r– c:\program files\Norton Support 2010-01-04 22:35 –d—– c:\programdata\Musicnotes 2010-01-04 22:35 –d—– c:\progra~2\Musicnotes 2010-01-04 22:31 –d—– c:\program files\Musicnotes 2009-12-28 17:01 –d—– c:\program files\RealArcade ==================== Find3M ==================== 2009-11-27 14:35 691,696 a——- c:\windows\system32\drivers\sptd.sys 2009-11-26 11:59 143,360 a——- c:\windows\inf\infstrng.dat 2009-11-26 11:59 86,016 a——- c:\windows\inf\infstor.dat 2009-11-26 11:59 51,200 a——- c:\windows\inf\infpub.dat 2009-11-26 11:59 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS 2009-11-26 11:59 7,456 a——- c:\windows\system32\drivers\SYMEVENT.CAT 2009-11-26 11:59 806 a——- c:\windows\system32\drivers\SYMEVENT.INF 2009-11-26 11:58 26,600 a—-r– c:\windows\system32\drivers\GEARAspiWDM.sys 2009-11-26 11:58 25,648 a—-r– c:\windows\system32\drivers\SymIMV.sys 2009-11-26 11:58 107,368 a—-r– c:\windows\system32\GEARAspi.dll 2009-11-21 06:40 916,480 a——- c:\windows\system32\wininet.dll 2009-11-21 06:34 109,056 a——- c:\windows\system32\iesysprep.dll 2009-11-21 06:34 71,680 a——- c:\windows\system32\iesetup.dll 2009-11-21 04:59 133,632 a——- c:\windows\system32\ieUnatt.exe 2009-11-19 03:20 665,600 a——- c:\windows\inf\drvindex.dat 2009-11-19 03:19 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf 2009-10-29 09:17 2,048 a——- c:\windows\system32\tzres.dll 2009-04-30 15:58 47,360 a——- c:\users\david\appdata\roaming\pcouffin.sys 2008-01-21 02:57 174 a–sh— c:\program files\desktop.ini 2006-11-02 12:39 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 12:39 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 12:39 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 12:39 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 09:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 18:59:13.87 ===============
Please run the following command


Click Start > Run then copy/paste the following single-line command into the Run box and click OK:


C:\Qoobox\Add-Remove Programs.txt

A text file should open.

Post the contents of that file in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI