HHelms
Topic Starter
I have a Trojan Virus with a Rootkit. It was identified by Windows Defender and Mircosoft Security Essentials. They were able to remove the Trojan(I think) but not something called a Rootkit. The path is file:C:\WINDOWS\SYSTEM32\DRIVERS\vreoreqb.sys. I tried like hell to delete and remove this file without success. I deleted too much other stuff could not log on and had to reinstall XP. It seems to reinstall the Trojan when I restart the computer and pops up a fake security center and hijacks the browser and who knows what else! (This happened even after I reinstalled XP).I followed the instructions and here are the requested logs. I have two MBAM logs the second was after the restart that the program prompted to remove a virus. I ran the ERUNT last because it did not work until I ran the other programs.
Can I get this off the system or is it time to trash my hardrive and buy a MAC.
Please help. Thanks
———————————————————————————————————————————————————————————–
MBAM LOG #1
Malwarebytes' Anti-Malware 1.44
Database version: 3573
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
1/15/2010 6:20:36 PM
mbam-log-2010-01-15 (18-20-36).txt
Scan type: Quick Scan
Objects scanned: 140183
Time elapsed: 20 minute(s), 17 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 11
Registry Data Items Infected: 11
Folders Infected: 1
Files Infected: 37
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\IS2010 (Rogue.InternetSecurity2010) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AvScan (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{a5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls\appsecdll (Spyware.Passwords) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\internet security 2010 (Rogue.InternetSecurity2010) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ygua8e7yhuiesfha876yfauy8fe (Trojan.Downloader) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Rootkit.Agent) -> Data: c:\windows\system32\kbdsock.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Rootkit.Agent) -> Data: system32\kbdsock.dll -> Quarantined and deleted successfully.
Folders Infected:
C:\WINDOWS\SYSTEM32\AppCert (Trojan.Downloader) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\SYSTEM32\mshlps.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ font-family (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ background-color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ border (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ border-bottom (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ border-left (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ border-right (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ border-top (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ font-family (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ font-size (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ font-sizw (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ font-weight (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ link (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ padding (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ scrollbar-3dlight-color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ scrollbar-darkshadow-color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ scrollbar-face-color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ scrollbar-highlight-color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ scrollbar-shadow-color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ scrollbar-track-color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ text-decoration (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ vlink (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\hb20g.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\options.dat (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry\Local Settings\Temp\csrss.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry\Local Settings\Temp\lsass.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry\Local Settings\Temp\services.exe (Password.Stealer) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry\Local Settings\Temp\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry\Local Settings\Temp\taskmgr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry\Local Settings\Temp\win32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry\Local Settings\Temp\winlogon.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\41.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\flags.ini (Malware.Trace) -> Delete on reboot.
C:\WINDOWS\SYSTEM32\uses32.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\warning.html (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\kbdsock.dll (Rootkit.Agent) -> Quarantined and deleted successfully.
——————————————————————————————————————————————————————————-
MBAM LOG #2
alwarebytes' Anti-Malware 1.44
Database version: 3573
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
1/15/2010 8:41:26 PM
mbam-log-2010-01-15 (20-41-26).txt
Scan type: Quick Scan
Objects scanned: 139944
Time elapsed: 6 minute(s), 10 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
———————————————————————————————————————————————————————————–
GMER LOG
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-16 00:49:38
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Henry\LOCALS~1\Temp\pwloapog.sys
—- System - GMER 1.0.15 —-
SSDT IPVNMon.sys (IPVNMon/Visual Networks) ZwDeviceIoControlFile [0xF840ACEF] <– ROOTKIT !!!
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Ntfs \Ntfs 82F8EAE0
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
—- Services - GMER 1.0.15 —-
Service C:\WINDOWS\system32\drivers\pgplitna.dat (*** hidden *** ) [BOOT] rpljspfv <– ROOTKIT !!!
Service (*** hidden *** ) [BOOT] vreoreqb <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\ControlSet001\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\ControlSet001\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\ControlSet001\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet001\Services\vreoreqb@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet003\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\ControlSet003\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\ControlSet003\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet003\Services\vreoreqb@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet004\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\ControlSet004\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\ControlSet004\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet004\Services\vreoreqb@Group Boot Bus Extender
Reg HKLM\SYSTEM\CurrentControlSet\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\vreoreqb@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet006\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\ControlSet006\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\ControlSet006\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet006\Services\vreoreqb@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet007\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\ControlSet007\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\ControlSet007\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet007\Services\vreoreqb@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet008\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\ControlSet008\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\ControlSet008\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet008\Services\vreoreqb@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet009\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\ControlSet009\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\ControlSet009\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet009\Services\vreoreqb@Group Boot Bus Extender
—- EOF - GMER 1.0.15 —-
———————————————————————————————————————————————————————————-
DDS 1
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 1/4/2010 8:32:15 PM
System Uptime: 1/16/2010 6:44:37 AM (13 hours ago)
Motherboard: Dell Computer Corp. | | 02Y832
Processor: Intel® Pentium® 4 CPU 2.80GHz | Microprocessor | 2793/800mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 112 GiB total, 16.234 GiB free.
D: is CDROM ()
E: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
ABBYY FineReader 5.0 Sprint Plus
Ad-Aware SE Personal
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player ActiveX
Adobe Reader 7.0
Apple Mobile Device Support
Apple Software Update
ATT-AACE
Banctec Service Agreement
BitTornado 0.3.7
Bonjour
CA Landlord Rights Forms
Camera Support Core Library
Camera Window DS
Camera Window DVC
Camera Window MC
Canon Camera Support Core Library
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DS for ZoomBrowser EX
Canon Camera Window MC 5 for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon ZoomBrowser EX
Conexant SmartHSFi V92 56K DF PCI Modem
Dell Digital Jukebox Driver
Dell Networking Guide
Dell Picture Studio - Dell Image Expert
Dell Solution Center
Dell Support
Dell Support 5.0.0 (766)
Digital Line Detect
Drive Manager
Drivers Install For Linksys Easylink Advisor
DS21Patch
DVD Decrypter (Remove Only)
DVDSentry
EarthLink Setup Files
ERUNT 1.1j
Google Earth
Help and Support Customization
ImageMixer for Sony
Intel® PRO Network Adapters and Drivers
Intel® PROSet
iPod for Windows 2005-03-23
iTunes
Java 2 Runtime Environment, SE v1.4.2
Lexmark X6100 Series
Linksys EasyLink Advisor 1.6 (0032)
LiveReg (Symantec Corporation)
LiveUpdate 2.6 (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Encarta Encyclopedia Standard 2004
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2003
Microsoft Security Essentials
Microsoft User-Mode Driver Framework Feature Pack 1.0
Modem Helper
MovieEdit Task
MSN Messenger 6.0
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser (KB933579)
Norton AntiVirus 2003
Norton WMI Update
NVIDIA Windows 2000/XP Display Drivers
Paint Shop Pro 7
PhotoStitch
PowerDVD
Print to Fax
QuickTime
RAW Image Task 2.1
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB953155)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB976325)
Sonic DLA
Sonic MyDVD
Sonic RecordNow!
Sonic Update Manager
Sony USB Driver
Spybot - Search & Destroy 1.3
Symantec Network Drivers Update
TrueSwitch Wizard SBC
Update for Windows XP (KB955759)
Viewpoint Manager (Remove Only)
Visual IP InSight(SBC)
WebFldrs XP
Windows Defender
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage v1.3.0254.0
Windows Internet Explorer 7
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
WordPerfect Office 11
Yahoo! Companion
Yahoo! Install Manager
==== Event Viewer Messages From Past Week ========
1/11/2010 10:10:41 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: rpljspfv
1/11/2010 10:10:32 PM, error: Service Control Manager [7000] - The OMCI WDM Device Controller service failed to start due to the following error: The executable program that this service is configured to run in does not implement the service.
==== End Of File ===========================
———————————————————————————————————————————————————————————–
DDS LOG #2
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 19:13:18.03 on Sat 01/16/2010
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.148 [GMT -8:00]
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Norton AntiVirus *On-access scanning disabled* (Outdated) {B5510F6F-87E1-47F7-A411-360BC453007C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\WINDOWS\system32\lexpps.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\TrueAssistant\TrueAssistant.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Henry\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://att.my.yahoo.com/
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
BHO: : {0ed59684-b985-41a1-b1de-bd9948c70b28} - c:\windows\system32\avifil32r.dll
TB: Norton AntiVirus: {42cdd1bf-3ffb-4238-8ad1-7859df00b1d6} - c:\program files\norton antivirus\NavShExt.dll
TB: Yahoo! Companion: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\ycomp5_3_19_0.dll
TB: {4E7BD74F-2B8D-469E-A0E4-EA6FA787AD2D} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup
mRun: [DVDSentry] c:\windows\system32\DSentry.exe
mRun: [ccRegVfy] "c:\program files\common files\symantec shared\ccRegVfy.exe"
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [IPInSightLAN 01] "c:\program files\visual networks\visual ip insight\sbc\IPClient.exe" -l
mRun: [IPInSightMonitor 01] "c:\program files\visual networks\visual ip insight\sbc\IPMon32.exe"
mRun: [Symantec NetDriver Monitor] c:\progra~1\symnet~1\SNDMon.exe /Consumer
mRun: [DwlClient] c:\program files\common files\dell\eusw\Support.exe
mRun: [Lexmark X6100 Series] "c:\program files\lexmark x6100 series\lxbfbmgr.exe"
mRun: [basicsmssmenu] "c:\program files\seagate\basics\basics status\MaxMenuMgrBasics.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\henry\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\henry\startm~1\programs\startup\trueas~1.lnk - c:\program files\trueassistant\TrueAssistant.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\windows\system32\msjava.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} - hxxp://housecall60.trendmicro.com/housecall/xscan60.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1262675105390
DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - hxxp://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5861/mcfscan.cab
Notify: ddpndavx - avifil32r.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
============= SERVICES / DRIVERS ===============
R2 navapsvc;Norton AntiVirus Auto Protect Service;c:\program files\norton antivirus\NAVAPSVC.EXE [2003-12-3 116336]
R2 SAVRTPEL;SAVRTPEL;c:\windows\system32\drivers\SAVRTPEL.SYS [2004-1-2 35552]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20040218.021\NAVENG.Sys [2004-2-18 67568]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20040218.021\NavEx15.Sys [2004-2-18 598224]
S0 rpljspfv;rpljspfv;c:\windows\system32\drivers\pgplitna.dat [2008-4-30 20608]
S2 SBService;ScriptBlocking Service;c:\progra~1\common~1\symant~1\script~1\SBServ.exe [2001-8-13 54408]
S2 sqdtronn;OMCI WDM Device Controller;c:\windows\system32\svchost.exe -k netsvcs [2003-7-16 14336]
S3 06014;06014;\??\c:\windows\system32\06014.sys –> c:\windows\system32\06014.sys [?]
S3 0781C;0781C;\??\c:\windows\system32\0781c.sys –> c:\windows\system32\0781C.sys [?]
S3 15617;15617;\??\c:\windows\system32\15617.sys –> c:\windows\system32\15617.sys [?]
S3 1f713;1f713;\??\c:\windows\system32\1f713.sys –> c:\windows\system32\1f713.sys [?]
S3 2ed16;2ed16;\??\c:\windows\system32\2ed16.sys –> c:\windows\system32\2ed16.sys [?]
S3 3732E;3732E;c:\windows\system32\3732E.sys [2010-1-14 54624]
S3 3901E;3901E;\??\c:\windows\system32\3901e.sys –> c:\windows\system32\3901E.sys [?]
S3 3c07;3c07;\??\c:\windows\system32\3c07.sys –> c:\windows\system32\3c07.sys [?]
S3 3fc4;3fc4;\??\c:\windows\system32\3fc4.sys –> c:\windows\system32\3fc4.sys [?]
S3 53dC;53dC;\??\c:\windows\system32\53dc.sys –> c:\windows\system32\53dC.sys [?]
S3 5933;5933;\??\c:\windows\system32\5933.sys –> c:\windows\system32\5933.sys [?]
S3 73676;73676;\??\c:\windows\system32\73676.sys –> c:\windows\system32\73676.sys [?]
S3 7796;7796;\??\c:\windows\system32\7796.sys –> c:\windows\system32\7796.sys [?]
S3 78273;78273;\??\c:\windows\system32\78273.sys –> c:\windows\system32\78273.sys [?]
S3 78912;78912;\??\c:\windows\system32\78912.sys –> c:\windows\system32\78912.sys [?]
S3 88775;88775;\??\c:\windows\system32\88775.sys –> c:\windows\system32\88775.sys [?]
S3 8b81B;8b81B;\??\c:\windows\system32\8b81b.sys –> c:\windows\system32\8b81B.sys [?]
S3 8d38;8d38;\??\c:\windows\system32\8d38.sys –> c:\windows\system32\8d38.sys [?]
S3 91872;91872;\??\c:\windows\system32\91872.sys –> c:\windows\system32\91872.sys [?]
S3 9ba20;9ba20;\??\c:\windows\system32\9ba20.sys –> c:\windows\system32\9ba20.sys [?]
S3 9fe10;9fe10;\??\c:\windows\system32\9fe10.sys –> c:\windows\system32\9fe10.sys [?]
S3 ad3A;ad3A;\??\c:\windows\system32\ad3a.sys –> c:\windows\system32\ad3A.sys [?]
S3 b95F;b95F;\??\c:\windows\system32\b95f.sys –> c:\windows\system32\b95F.sys [?]
S3 ba4B;ba4B;\??\c:\windows\system32\ba4b.sys –> c:\windows\system32\ba4B.sys [?]
S3 ccPwdSvc;Symantec Password Validation Service;c:\program files\common files\symantec shared\ccPwdSvc.exe [2003-12-20 99352]
S3 d2bE;d2bE;\??\c:\windows\system32\d2be.sys –> c:\windows\system32\d2bE.sys [?]
S3 d5718;d5718;\??\c:\windows\system32\d5718.sys –> c:\windows\system32\d5718.sys [?]
S3 d8d2;d8d2;\??\c:\windows\system32\d8d2.sys –> c:\windows\system32\d8d2.sys [?]
S3 eb177;eb177;\??\c:\windows\system32\eb177.sys –> c:\windows\system32\eb177.sys [?]
S3 ef071;ef071;\??\c:\windows\system32\ef071.sys –> c:\windows\system32\ef071.sys [?]
S3 f1f1A;f1f1A;\??\c:\windows\system32\f1f1a.sys –> c:\windows\system32\f1f1A.sys [?]
S3 f921F;f921F;\??\c:\windows\system32\f921f.sys –> c:\windows\system32\f921F.sys [?]
S4 ccEvtMgr;Symantec Event Manager;- –> - [?]
S4 SAVRT;SAVRT;- –> - [?]
=============== Created Last 30 ================
2010-01-15 17:56 –d—– c:\docume~1\henry\applic~1\Malwarebytes
2010-01-15 17:56 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-15 17:56 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-01-15 17:56 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-15 17:56 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-14 19:16 –d—– c:\windows\McAfee.com
2010-01-14 18:27 128,352 a——- c:\windows\system32\3732E.dll
2010-01-14 18:26 714,752 a——- c:\windows\system32\9a82F.tmp
2010-01-14 18:26 54,624 a——- c:\windows\system32\3732E.sys
2010-01-14 18:26 2,335,270 a——- c:\windows\system32\8f82D.mht
2010-01-13 20:39 –d—– c:\program files\Microsoft Security Essentials
2010-01-11 22:34 157,712 a——- c:\windows\system32\drivers\tmcomm.sys
2010-01-10 18:46 27,899 a——- c:\windows\system32\R4UN0ACVTC.dat
2010-01-10 18:46 1,860 a——- c:\windows\system32\CQMRUWK00.dat
2010-01-08 22:07 471,552 -c—— c:\windows\system32\dllcache\aclayers.dll
2010-01-05 18:49 459,264 -c—— c:\windows\system32\dllcache\msfeeds.dll
2010-01-05 18:49 268,288 -c—— c:\windows\system32\dllcache\iertutil.dll
2010-01-05 18:49 52,224 -c—— c:\windows\system32\dllcache\msfeedsbs.dll
2010-01-05 18:49 6,067,200 -c—— c:\windows\system32\dllcache\ieframe.dll
2010-01-05 18:49 2,452,872 -c—— c:\windows\system32\dllcache\ieapfltr.dat
2010-01-05 18:49 63,488 -c—— c:\windows\system32\dllcache\icardie.dll
2010-01-05 18:40 274,288 a——- c:\windows\system32\mucltui.dll
2010-01-05 18:40 16,736 a——- c:\windows\system32\mucltui.dll.mui
2010-01-05 17:53 –d—– C:\2b8b0647a0f2913448acf516
2010-01-05 09:58 473,600 -c—— c:\windows\system32\dllcache\fastprox.dll
2010-01-05 09:58 401,408 -c—— c:\windows\system32\dllcache\rpcss.dll
2010-01-05 09:58 284,160 -c—— c:\windows\system32\dllcache\pdh.dll
2010-01-05 09:58 110,592 -c—— c:\windows\system32\dllcache\services.exe
2010-01-05 09:58 714,752 -c—— c:\windows\system32\dllcache\ntdll.dll
2010-01-05 09:58 617,472 -c—— c:\windows\system32\dllcache\advapi32.dll
2010-01-05 09:58 453,120 -c—— c:\windows\system32\dllcache\wmiprvsd.dll
2010-01-05 09:58 227,840 -c—— c:\windows\system32\dllcache\wmiprvse.exe
2010-01-05 09:57 153,088 -c—— c:\windows\system32\dllcache\triedit.dll
2010-01-05 09:57 128,512 -c—— c:\windows\system32\dllcache\dhtmled.ocx
2010-01-05 09:56 203,136 -c—— c:\windows\system32\dllcache\rmcast.sys
2010-01-05 09:56 455,296 -c—— c:\windows\system32\dllcache\mrxsmb.sys
2010-01-05 09:56 333,952 -c—— c:\windows\system32\dllcache\srv.sys
2010-01-05 09:56 331,776 -c—— c:\windows\system32\dllcache\msadce.dll
2010-01-05 09:56 1,315,328 -c—— c:\windows\system32\dllcache\msoe.dll
2010-01-05 09:56 691,712 -c—— c:\windows\system32\dllcache\inetcomm.dll
2010-01-05 09:55 2,145,280 -c—— c:\windows\system32\dllcache\ntkrnlmp.exe
2010-01-05 09:55 2,066,048 -c—— c:\windows\system32\dllcache\ntkrnlpa.exe
2010-01-05 09:55 2,023,936 -c—— c:\windows\system32\dllcache\ntkrpamp.exe
2010-01-05 09:55 337,408 -c—— c:\windows\system32\dllcache\netapi32.dll
2010-01-05 09:55 1,172,480 -c—— c:\windows\system32\dllcache\msxml3.dll
2010-01-05 09:55 1,206,508 -c—— c:\windows\system32\dllcache\sysmain.sdb
2010-01-05 09:55 215,552 -c—— c:\windows\system32\dllcache\wordpad.exe
2010-01-05 09:24 1,372,672 -c—— c:\windows\system32\dllcache\msxml6.dll
2010-01-05 09:24 79,872 -c—— c:\windows\system32\dllcache\msxml6r.dll
2010-01-05 09:23 19,569 a——- c:\windows\005948_.tmp
2010-01-05 08:46 –d—– c:\program files\Microsoft CAPICOM 2.1.0.2
2010-01-05 08:05 –d—– c:\windows\system32\wbem\Repository.001
2010-01-04 23:48 7,208 ——– c:\windows\system32\secupd.sig
2010-01-04 23:48 4,569 ——– c:\windows\system32\secupd.dat
2010-01-04 23:48 56,700 a——- c:\windows\system32\ieuinit.inf
2010-01-04 22:28 354,816 a——- c:\windows\system32\winhttp.dll
2010-01-04 22:28 18,944 a——- c:\windows\system32\qmgrprxy.dll
2010-01-04 20:42 217,816 a——- c:\windows\system32\wuaucpl.cpl
2010-01-04 20:32 41,600 ac—— c:\windows\system32\dllcache\weitekp9.dll
2010-01-04 20:32 31,232 ac—— c:\windows\system32\dllcache\weitekp9.sys
2010-01-04 20:32 48,256 ac—— c:\windows\system32\dllcache\w32.dll
2010-01-04 20:30 5,632 ac—— c:\windows\system32\dllcache\kbdvntc.dll
2010-01-04 20:29 312,832 ac—— c:\windows\system32\dllcache\EXCH_aqueue.dll
2010-01-04 20:29 45,056 ac—— c:\windows\system32\dllcache\EXCH_aqadmin.dll
2010-01-04 20:29 5,632 ac—— c:\windows\system32\dllcache\EXCH_adsiisex.dll
2010-01-04 20:29 2,134,528 ac—— c:\windows\system32\dllcache\EXCH_smtpsnap.dll
2010-01-04 20:29 175,104 ac—— c:\windows\system32\dllcache\EXCH_smtpadm.dll
2010-01-04 20:17 184,320 a——- c:\windows\system32\accwiz.exe
2010-01-04 20:16 178,176 a——- c:\windows\system32\wbem\repdrvfs.dll
2010-01-04 20:16 123,904 a——- c:\windows\system32\wbem\mofd.dll
2010-01-04 20:16 47,104 a——- c:\windows\system32\wbem\ncprov.dll
2010-01-04 20:16 16,384 a——- c:\windows\system32\wbem\mofcomp.exe
2010-01-04 20:16 1,358,848 a——- c:\windows\system32\wbem\cimwin32.dll
2010-01-04 20:16 473,600 a——- c:\windows\system32\wbem\fastprox.dll
2010-01-04 20:16 247,808 a——- c:\windows\system32\wbem\esscli.dll
2010-01-04 20:16 58,880 a——- c:\windows\system32\licwmi.dll
2010-01-04 20:16 196,224 a——- c:\windows\system32\drivers\rdpdr.sys
2010-01-04 20:15 6,272 a——- c:\windows\system32\drivers\splitter.sys
2010-01-04 20:15 52,864 a——- c:\windows\system32\drivers\dmusic.sys
2010-01-04 20:14 15,104 a——- c:\windows\system32\drivers\usbscan.sys
2010-01-04 20:13 25,856 a——- c:\windows\system32\drivers\usbprint.sys
2010-01-04 20:13 57,600 a——- c:\windows\system32\drivers\redbook.sys
2010-01-04 20:12 40,840 a——- c:\windows\system32\drivers\termdd.sys
2010-01-04 20:08 1,040,870 a——- c:\windows\setupapi.log.0.old
2010-01-03 00:00 2,206 a——- c:\windows\system32\wpa.dbl
2010-01-02 22:38 767,488 a——- c:\windows\system32\drivers\vreoreqb.sys
2010-01-02 22:38 1 a——- C:\s
==================== Find3M ====================
2010-01-14 11:12 181,120 ——– c:\windows\system32\MpSigStub.exe
2010-01-11 21:32 20,608 a——- c:\windows\system32\drivers\pgplitna.dat
2010-01-04 20:18 23,348 ac—— c:\windows\system32\emptyregdb.dat
2009-11-21 07:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-10-28 23:46 832,512 a——- c:\windows\system32\wininet.dll
2009-10-28 23:46 78,336 a——- c:\windows\system32\ieencode.dll
2009-10-28 23:46 17,408 a——- c:\windows\system32\corpol.dll
2009-10-20 21:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-20 21:38 25,088 a——- c:\windows\system32\httpapi.dll
2008-07-16 07:11 1,071 a——- c:\docume~1\alluse~1\applic~1\ustore.dat
2003-11-14 14:34 32 a–sh— c:\windows\{4B147FBF-8E7F-4093-A315-4A9F37C4DE22}.dat
2003-11-14 14:34 32 a–sh— c:\windows\system32\{09FE7CFD-F7CF-406F-B89E-8BDE0652F0F6}.dat
============= FINISH: 19:14:03.96 ===============
Can I get this off the system or is it time to trash my hardrive and buy a MAC.
Please help. Thanks
———————————————————————————————————————————————————————————–
MBAM LOG #1
Malwarebytes' Anti-Malware 1.44
Database version: 3573
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
1/15/2010 6:20:36 PM
mbam-log-2010-01-15 (18-20-36).txt
Scan type: Quick Scan
Objects scanned: 140183
Time elapsed: 20 minute(s), 17 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 11
Registry Data Items Infected: 11
Folders Infected: 1
Files Infected: 37
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\IS2010 (Rogue.InternetSecurity2010) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AvScan (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{a5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls\appsecdll (Spyware.Passwords) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\internet security 2010 (Rogue.InternetSecurity2010) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ygua8e7yhuiesfha876yfauy8fe (Trojan.Downloader) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Rootkit.Agent) -> Data: c:\windows\system32\kbdsock.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Rootkit.Agent) -> Data: system32\kbdsock.dll -> Quarantined and deleted successfully.
Folders Infected:
C:\WINDOWS\SYSTEM32\AppCert (Trojan.Downloader) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\SYSTEM32\mshlps.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ font-family (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ background-color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ border (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ border-bottom (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ border-left (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ border-right (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ border-top (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ font-family (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ font-size (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ font-sizw (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ font-weight (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ link (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ padding (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ scrollbar-3dlight-color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ scrollbar-darkshadow-color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ scrollbar-face-color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ scrollbar-highlight-color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ scrollbar-shadow-color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ scrollbar-track-color (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ text-decoration (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\ vlink (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\hb20g.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\AppCert\options.dat (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry\Local Settings\Temp\csrss.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry\Local Settings\Temp\lsass.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry\Local Settings\Temp\services.exe (Password.Stealer) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry\Local Settings\Temp\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry\Local Settings\Temp\taskmgr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry\Local Settings\Temp\win32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Henry\Local Settings\Temp\winlogon.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\41.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\flags.ini (Malware.Trace) -> Delete on reboot.
C:\WINDOWS\SYSTEM32\uses32.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\warning.html (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\kbdsock.dll (Rootkit.Agent) -> Quarantined and deleted successfully.
——————————————————————————————————————————————————————————-
MBAM LOG #2
alwarebytes' Anti-Malware 1.44
Database version: 3573
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
1/15/2010 8:41:26 PM
mbam-log-2010-01-15 (20-41-26).txt
Scan type: Quick Scan
Objects scanned: 139944
Time elapsed: 6 minute(s), 10 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
———————————————————————————————————————————————————————————–
GMER LOG
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-16 00:49:38
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Henry\LOCALS~1\Temp\pwloapog.sys
—- System - GMER 1.0.15 —-
SSDT IPVNMon.sys (IPVNMon/Visual Networks) ZwDeviceIoControlFile [0xF840ACEF] <– ROOTKIT !!!
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Ntfs \Ntfs 82F8EAE0
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
—- Services - GMER 1.0.15 —-
Service C:\WINDOWS\system32\drivers\pgplitna.dat (*** hidden *** ) [BOOT] rpljspfv <– ROOTKIT !!!
Service (*** hidden *** ) [BOOT] vreoreqb <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\ControlSet001\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\ControlSet001\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\ControlSet001\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet001\Services\vreoreqb@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet003\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\ControlSet003\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\ControlSet003\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet003\Services\vreoreqb@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet004\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\ControlSet004\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\ControlSet004\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet004\Services\vreoreqb@Group Boot Bus Extender
Reg HKLM\SYSTEM\CurrentControlSet\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\vreoreqb@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet006\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\ControlSet006\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\ControlSet006\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet006\Services\vreoreqb@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet007\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\ControlSet007\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\ControlSet007\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet007\Services\vreoreqb@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet008\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\ControlSet008\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\ControlSet008\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet008\Services\vreoreqb@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet009\Services\vreoreqb@Type 1
Reg HKLM\SYSTEM\ControlSet009\Services\vreoreqb@Start 0
Reg HKLM\SYSTEM\ControlSet009\Services\vreoreqb@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet009\Services\vreoreqb@Group Boot Bus Extender
—- EOF - GMER 1.0.15 —-
———————————————————————————————————————————————————————————-
DDS 1
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 1/4/2010 8:32:15 PM
System Uptime: 1/16/2010 6:44:37 AM (13 hours ago)
Motherboard: Dell Computer Corp. | | 02Y832
Processor: Intel® Pentium® 4 CPU 2.80GHz | Microprocessor | 2793/800mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 112 GiB total, 16.234 GiB free.
D: is CDROM ()
E: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
ABBYY FineReader 5.0 Sprint Plus
Ad-Aware SE Personal
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player ActiveX
Adobe Reader 7.0
Apple Mobile Device Support
Apple Software Update
ATT-AACE
Banctec Service Agreement
BitTornado 0.3.7
Bonjour
CA Landlord Rights Forms
Camera Support Core Library
Camera Window DS
Camera Window DVC
Camera Window MC
Canon Camera Support Core Library
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DS for ZoomBrowser EX
Canon Camera Window MC 5 for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon ZoomBrowser EX
Conexant SmartHSFi V92 56K DF PCI Modem
Dell Digital Jukebox Driver
Dell Networking Guide
Dell Picture Studio - Dell Image Expert
Dell Solution Center
Dell Support
Dell Support 5.0.0 (766)
Digital Line Detect
Drive Manager
Drivers Install For Linksys Easylink Advisor
DS21Patch
DVD Decrypter (Remove Only)
DVDSentry
EarthLink Setup Files
ERUNT 1.1j
Google Earth
Help and Support Customization
ImageMixer for Sony
Intel® PRO Network Adapters and Drivers
Intel® PROSet
iPod for Windows 2005-03-23
iTunes
Java 2 Runtime Environment, SE v1.4.2
Lexmark X6100 Series
Linksys EasyLink Advisor 1.6 (0032)
LiveReg (Symantec Corporation)
LiveUpdate 2.6 (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Encarta Encyclopedia Standard 2004
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2003
Microsoft Security Essentials
Microsoft User-Mode Driver Framework Feature Pack 1.0
Modem Helper
MovieEdit Task
MSN Messenger 6.0
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser (KB933579)
Norton AntiVirus 2003
Norton WMI Update
NVIDIA Windows 2000/XP Display Drivers
Paint Shop Pro 7
PhotoStitch
PowerDVD
Print to Fax
QuickTime
RAW Image Task 2.1
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB953155)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB976325)
Sonic DLA
Sonic MyDVD
Sonic RecordNow!
Sonic Update Manager
Sony USB Driver
Spybot - Search & Destroy 1.3
Symantec Network Drivers Update
TrueSwitch Wizard SBC
Update for Windows XP (KB955759)
Viewpoint Manager (Remove Only)
Visual IP InSight(SBC)
WebFldrs XP
Windows Defender
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage v1.3.0254.0
Windows Internet Explorer 7
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
WordPerfect Office 11
Yahoo! Companion
Yahoo! Install Manager
==== Event Viewer Messages From Past Week ========
1/11/2010 10:10:41 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: rpljspfv
1/11/2010 10:10:32 PM, error: Service Control Manager [7000] - The OMCI WDM Device Controller service failed to start due to the following error: The executable program that this service is configured to run in does not implement the service.
==== End Of File ===========================
———————————————————————————————————————————————————————————–
DDS LOG #2
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 19:13:18.03 on Sat 01/16/2010
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.148 [GMT -8:00]
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Norton AntiVirus *On-access scanning disabled* (Outdated) {B5510F6F-87E1-47F7-A411-360BC453007C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\WINDOWS\system32\lexpps.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\TrueAssistant\TrueAssistant.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Henry\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://att.my.yahoo.com/
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
BHO: : {0ed59684-b985-41a1-b1de-bd9948c70b28} - c:\windows\system32\avifil32r.dll
TB: Norton AntiVirus: {42cdd1bf-3ffb-4238-8ad1-7859df00b1d6} - c:\program files\norton antivirus\NavShExt.dll
TB: Yahoo! Companion: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\ycomp5_3_19_0.dll
TB: {4E7BD74F-2B8D-469E-A0E4-EA6FA787AD2D} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup
mRun: [DVDSentry] c:\windows\system32\DSentry.exe
mRun: [ccRegVfy] "c:\program files\common files\symantec shared\ccRegVfy.exe"
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [IPInSightLAN 01] "c:\program files\visual networks\visual ip insight\sbc\IPClient.exe" -l
mRun: [IPInSightMonitor 01] "c:\program files\visual networks\visual ip insight\sbc\IPMon32.exe"
mRun: [Symantec NetDriver Monitor] c:\progra~1\symnet~1\SNDMon.exe /Consumer
mRun: [DwlClient] c:\program files\common files\dell\eusw\Support.exe
mRun: [Lexmark X6100 Series] "c:\program files\lexmark x6100 series\lxbfbmgr.exe"
mRun: [basicsmssmenu] "c:\program files\seagate\basics\basics status\MaxMenuMgrBasics.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\henry\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\henry\startm~1\programs\startup\trueas~1.lnk - c:\program files\trueassistant\TrueAssistant.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\windows\system32\msjava.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} - hxxp://housecall60.trendmicro.com/housecall/xscan60.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1262675105390
DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - hxxp://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5861/mcfscan.cab
Notify: ddpndavx - avifil32r.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
============= SERVICES / DRIVERS ===============
R2 navapsvc;Norton AntiVirus Auto Protect Service;c:\program files\norton antivirus\NAVAPSVC.EXE [2003-12-3 116336]
R2 SAVRTPEL;SAVRTPEL;c:\windows\system32\drivers\SAVRTPEL.SYS [2004-1-2 35552]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20040218.021\NAVENG.Sys [2004-2-18 67568]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20040218.021\NavEx15.Sys [2004-2-18 598224]
S0 rpljspfv;rpljspfv;c:\windows\system32\drivers\pgplitna.dat [2008-4-30 20608]
S2 SBService;ScriptBlocking Service;c:\progra~1\common~1\symant~1\script~1\SBServ.exe [2001-8-13 54408]
S2 sqdtronn;OMCI WDM Device Controller;c:\windows\system32\svchost.exe -k netsvcs [2003-7-16 14336]
S3 06014;06014;\??\c:\windows\system32\06014.sys –> c:\windows\system32\06014.sys [?]
S3 0781C;0781C;\??\c:\windows\system32\0781c.sys –> c:\windows\system32\0781C.sys [?]
S3 15617;15617;\??\c:\windows\system32\15617.sys –> c:\windows\system32\15617.sys [?]
S3 1f713;1f713;\??\c:\windows\system32\1f713.sys –> c:\windows\system32\1f713.sys [?]
S3 2ed16;2ed16;\??\c:\windows\system32\2ed16.sys –> c:\windows\system32\2ed16.sys [?]
S3 3732E;3732E;c:\windows\system32\3732E.sys [2010-1-14 54624]
S3 3901E;3901E;\??\c:\windows\system32\3901e.sys –> c:\windows\system32\3901E.sys [?]
S3 3c07;3c07;\??\c:\windows\system32\3c07.sys –> c:\windows\system32\3c07.sys [?]
S3 3fc4;3fc4;\??\c:\windows\system32\3fc4.sys –> c:\windows\system32\3fc4.sys [?]
S3 53dC;53dC;\??\c:\windows\system32\53dc.sys –> c:\windows\system32\53dC.sys [?]
S3 5933;5933;\??\c:\windows\system32\5933.sys –> c:\windows\system32\5933.sys [?]
S3 73676;73676;\??\c:\windows\system32\73676.sys –> c:\windows\system32\73676.sys [?]
S3 7796;7796;\??\c:\windows\system32\7796.sys –> c:\windows\system32\7796.sys [?]
S3 78273;78273;\??\c:\windows\system32\78273.sys –> c:\windows\system32\78273.sys [?]
S3 78912;78912;\??\c:\windows\system32\78912.sys –> c:\windows\system32\78912.sys [?]
S3 88775;88775;\??\c:\windows\system32\88775.sys –> c:\windows\system32\88775.sys [?]
S3 8b81B;8b81B;\??\c:\windows\system32\8b81b.sys –> c:\windows\system32\8b81B.sys [?]
S3 8d38;8d38;\??\c:\windows\system32\8d38.sys –> c:\windows\system32\8d38.sys [?]
S3 91872;91872;\??\c:\windows\system32\91872.sys –> c:\windows\system32\91872.sys [?]
S3 9ba20;9ba20;\??\c:\windows\system32\9ba20.sys –> c:\windows\system32\9ba20.sys [?]
S3 9fe10;9fe10;\??\c:\windows\system32\9fe10.sys –> c:\windows\system32\9fe10.sys [?]
S3 ad3A;ad3A;\??\c:\windows\system32\ad3a.sys –> c:\windows\system32\ad3A.sys [?]
S3 b95F;b95F;\??\c:\windows\system32\b95f.sys –> c:\windows\system32\b95F.sys [?]
S3 ba4B;ba4B;\??\c:\windows\system32\ba4b.sys –> c:\windows\system32\ba4B.sys [?]
S3 ccPwdSvc;Symantec Password Validation Service;c:\program files\common files\symantec shared\ccPwdSvc.exe [2003-12-20 99352]
S3 d2bE;d2bE;\??\c:\windows\system32\d2be.sys –> c:\windows\system32\d2bE.sys [?]
S3 d5718;d5718;\??\c:\windows\system32\d5718.sys –> c:\windows\system32\d5718.sys [?]
S3 d8d2;d8d2;\??\c:\windows\system32\d8d2.sys –> c:\windows\system32\d8d2.sys [?]
S3 eb177;eb177;\??\c:\windows\system32\eb177.sys –> c:\windows\system32\eb177.sys [?]
S3 ef071;ef071;\??\c:\windows\system32\ef071.sys –> c:\windows\system32\ef071.sys [?]
S3 f1f1A;f1f1A;\??\c:\windows\system32\f1f1a.sys –> c:\windows\system32\f1f1A.sys [?]
S3 f921F;f921F;\??\c:\windows\system32\f921f.sys –> c:\windows\system32\f921F.sys [?]
S4 ccEvtMgr;Symantec Event Manager;- –> - [?]
S4 SAVRT;SAVRT;- –> - [?]
=============== Created Last 30 ================
2010-01-15 17:56 –d—– c:\docume~1\henry\applic~1\Malwarebytes
2010-01-15 17:56 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-15 17:56 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-01-15 17:56 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-15 17:56 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-14 19:16 –d—– c:\windows\McAfee.com
2010-01-14 18:27 128,352 a——- c:\windows\system32\3732E.dll
2010-01-14 18:26 714,752 a——- c:\windows\system32\9a82F.tmp
2010-01-14 18:26 54,624 a——- c:\windows\system32\3732E.sys
2010-01-14 18:26 2,335,270 a——- c:\windows\system32\8f82D.mht
2010-01-13 20:39 –d—– c:\program files\Microsoft Security Essentials
2010-01-11 22:34 157,712 a——- c:\windows\system32\drivers\tmcomm.sys
2010-01-10 18:46 27,899 a——- c:\windows\system32\R4UN0ACVTC.dat
2010-01-10 18:46 1,860 a——- c:\windows\system32\CQMRUWK00.dat
2010-01-08 22:07 471,552 -c—— c:\windows\system32\dllcache\aclayers.dll
2010-01-05 18:49 459,264 -c—— c:\windows\system32\dllcache\msfeeds.dll
2010-01-05 18:49 268,288 -c—— c:\windows\system32\dllcache\iertutil.dll
2010-01-05 18:49 52,224 -c—— c:\windows\system32\dllcache\msfeedsbs.dll
2010-01-05 18:49 6,067,200 -c—— c:\windows\system32\dllcache\ieframe.dll
2010-01-05 18:49 2,452,872 -c—— c:\windows\system32\dllcache\ieapfltr.dat
2010-01-05 18:49 63,488 -c—— c:\windows\system32\dllcache\icardie.dll
2010-01-05 18:40 274,288 a——- c:\windows\system32\mucltui.dll
2010-01-05 18:40 16,736 a——- c:\windows\system32\mucltui.dll.mui
2010-01-05 17:53 –d—– C:\2b8b0647a0f2913448acf516
2010-01-05 09:58 473,600 -c—— c:\windows\system32\dllcache\fastprox.dll
2010-01-05 09:58 401,408 -c—— c:\windows\system32\dllcache\rpcss.dll
2010-01-05 09:58 284,160 -c—— c:\windows\system32\dllcache\pdh.dll
2010-01-05 09:58 110,592 -c—— c:\windows\system32\dllcache\services.exe
2010-01-05 09:58 714,752 -c—— c:\windows\system32\dllcache\ntdll.dll
2010-01-05 09:58 617,472 -c—— c:\windows\system32\dllcache\advapi32.dll
2010-01-05 09:58 453,120 -c—— c:\windows\system32\dllcache\wmiprvsd.dll
2010-01-05 09:58 227,840 -c—— c:\windows\system32\dllcache\wmiprvse.exe
2010-01-05 09:57 153,088 -c—— c:\windows\system32\dllcache\triedit.dll
2010-01-05 09:57 128,512 -c—— c:\windows\system32\dllcache\dhtmled.ocx
2010-01-05 09:56 203,136 -c—— c:\windows\system32\dllcache\rmcast.sys
2010-01-05 09:56 455,296 -c—— c:\windows\system32\dllcache\mrxsmb.sys
2010-01-05 09:56 333,952 -c—— c:\windows\system32\dllcache\srv.sys
2010-01-05 09:56 331,776 -c—— c:\windows\system32\dllcache\msadce.dll
2010-01-05 09:56 1,315,328 -c—— c:\windows\system32\dllcache\msoe.dll
2010-01-05 09:56 691,712 -c—— c:\windows\system32\dllcache\inetcomm.dll
2010-01-05 09:55 2,145,280 -c—— c:\windows\system32\dllcache\ntkrnlmp.exe
2010-01-05 09:55 2,066,048 -c—— c:\windows\system32\dllcache\ntkrnlpa.exe
2010-01-05 09:55 2,023,936 -c—— c:\windows\system32\dllcache\ntkrpamp.exe
2010-01-05 09:55 337,408 -c—— c:\windows\system32\dllcache\netapi32.dll
2010-01-05 09:55 1,172,480 -c—— c:\windows\system32\dllcache\msxml3.dll
2010-01-05 09:55 1,206,508 -c—— c:\windows\system32\dllcache\sysmain.sdb
2010-01-05 09:55 215,552 -c—— c:\windows\system32\dllcache\wordpad.exe
2010-01-05 09:24 1,372,672 -c—— c:\windows\system32\dllcache\msxml6.dll
2010-01-05 09:24 79,872 -c—— c:\windows\system32\dllcache\msxml6r.dll
2010-01-05 09:23 19,569 a——- c:\windows\005948_.tmp
2010-01-05 08:46 –d—– c:\program files\Microsoft CAPICOM 2.1.0.2
2010-01-05 08:05 –d—– c:\windows\system32\wbem\Repository.001
2010-01-04 23:48 7,208 ——– c:\windows\system32\secupd.sig
2010-01-04 23:48 4,569 ——– c:\windows\system32\secupd.dat
2010-01-04 23:48 56,700 a——- c:\windows\system32\ieuinit.inf
2010-01-04 22:28 354,816 a——- c:\windows\system32\winhttp.dll
2010-01-04 22:28 18,944 a——- c:\windows\system32\qmgrprxy.dll
2010-01-04 20:42 217,816 a——- c:\windows\system32\wuaucpl.cpl
2010-01-04 20:32 41,600 ac—— c:\windows\system32\dllcache\weitekp9.dll
2010-01-04 20:32 31,232 ac—— c:\windows\system32\dllcache\weitekp9.sys
2010-01-04 20:32 48,256 ac—— c:\windows\system32\dllcache\w32.dll
2010-01-04 20:30 5,632 ac—— c:\windows\system32\dllcache\kbdvntc.dll
2010-01-04 20:29 312,832 ac—— c:\windows\system32\dllcache\EXCH_aqueue.dll
2010-01-04 20:29 45,056 ac—— c:\windows\system32\dllcache\EXCH_aqadmin.dll
2010-01-04 20:29 5,632 ac—— c:\windows\system32\dllcache\EXCH_adsiisex.dll
2010-01-04 20:29 2,134,528 ac—— c:\windows\system32\dllcache\EXCH_smtpsnap.dll
2010-01-04 20:29 175,104 ac—— c:\windows\system32\dllcache\EXCH_smtpadm.dll
2010-01-04 20:17 184,320 a——- c:\windows\system32\accwiz.exe
2010-01-04 20:16 178,176 a——- c:\windows\system32\wbem\repdrvfs.dll
2010-01-04 20:16 123,904 a——- c:\windows\system32\wbem\mofd.dll
2010-01-04 20:16 47,104 a——- c:\windows\system32\wbem\ncprov.dll
2010-01-04 20:16 16,384 a——- c:\windows\system32\wbem\mofcomp.exe
2010-01-04 20:16 1,358,848 a——- c:\windows\system32\wbem\cimwin32.dll
2010-01-04 20:16 473,600 a——- c:\windows\system32\wbem\fastprox.dll
2010-01-04 20:16 247,808 a——- c:\windows\system32\wbem\esscli.dll
2010-01-04 20:16 58,880 a——- c:\windows\system32\licwmi.dll
2010-01-04 20:16 196,224 a——- c:\windows\system32\drivers\rdpdr.sys
2010-01-04 20:15 6,272 a——- c:\windows\system32\drivers\splitter.sys
2010-01-04 20:15 52,864 a——- c:\windows\system32\drivers\dmusic.sys
2010-01-04 20:14 15,104 a——- c:\windows\system32\drivers\usbscan.sys
2010-01-04 20:13 25,856 a——- c:\windows\system32\drivers\usbprint.sys
2010-01-04 20:13 57,600 a——- c:\windows\system32\drivers\redbook.sys
2010-01-04 20:12 40,840 a——- c:\windows\system32\drivers\termdd.sys
2010-01-04 20:08 1,040,870 a——- c:\windows\setupapi.log.0.old
2010-01-03 00:00 2,206 a——- c:\windows\system32\wpa.dbl
2010-01-02 22:38 767,488 a——- c:\windows\system32\drivers\vreoreqb.sys
2010-01-02 22:38 1 a——- C:\s
==================== Find3M ====================
2010-01-14 11:12 181,120 ——– c:\windows\system32\MpSigStub.exe
2010-01-11 21:32 20,608 a——- c:\windows\system32\drivers\pgplitna.dat
2010-01-04 20:18 23,348 ac—— c:\windows\system32\emptyregdb.dat
2009-11-21 07:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-10-28 23:46 832,512 a——- c:\windows\system32\wininet.dll
2009-10-28 23:46 78,336 a——- c:\windows\system32\ieencode.dll
2009-10-28 23:46 17,408 a——- c:\windows\system32\corpol.dll
2009-10-20 21:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-20 21:38 25,088 a——- c:\windows\system32\httpapi.dll
2008-07-16 07:11 1,071 a——- c:\docume~1\alluse~1\applic~1\ustore.dat
2003-11-14 14:34 32 a–sh— c:\windows\{4B147FBF-8E7F-4093-A315-4A9F37C4DE22}.dat
2003-11-14 14:34 32 a–sh— c:\windows\system32\{09FE7CFD-F7CF-406F-B89E-8BDE0652F0F6}.dat
============= FINISH: 19:14:03.96 ===============