This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hacktool.Rootkit Infection

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have Comcast Security Suite (Norton) on my computer, and it keeps finding the infection of hacktool.rootkit and cleaning it. (I already had and was running AVG when my computer got infected - most like through a malicious Javascript on FF). I also now have CCleaner amongst others… :(

MalwareBytes says that \windows\system32\drivers\oycvey.sys is infected but I cannot delete it or do anything to the file - not even in Safe Mode and not even with FileAssasin.

GMER gave me the BSOD (BlueScreen) both times that I tried to run it.
I have already run
sfc /scanow
in Safe Mode.

I am also attaching the HJT (HijackThis) logs and MBAM (Malware) logs

Please help - its driving me crazzzzzy…. What should I do? What CAN I do???? Heeeeeeeeeeeeeeeeeeeeelp
(deperate cry!!)



Here is the Hijack This log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:49:16 PM, on 1/27/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Norton Security Suite\Engine\3.5.2.11\ccSvcHst.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Nokia\PC Suite for Nokia 3650\ectaskscheduler.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\PROGRA~1\Nokia\PCSUIT~1\Elogerr.exe
C:\PROGRA~1\Nokia\PCSUIT~1\BROADC~1.EXE
C:\PROGRA~1\Intuwave\Shared\MROUTE~1\MROUTE~2.EXE
C:\PROGRA~1\Nokia\PCSUIT~1\SCRFS.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Rohit\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Rohit\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\Rohit\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://roohit.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Roohit Plg - {5DC83F10-8335-403d-8AA8-66E266A82471} - C:\Windows\Downloaded Program Files\RoohitP.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\3.5.2.11\coIEPlg.dll
O2 - BHO: DebugBar BHO - {69FC0024-10EB-480A-BBF2-3BF4E78E17B1} - C:\Program Files\Core Services\DebugBar\DebugInfoBar.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\3.5.2.11\IPSBHO.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Companion.JS BHO - {ADDEE521-F1CC-4B89-8C88-B2CF625B9163} - C:\Program Files\Core Services\Companion.JS\CompanionJS.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\3.5.2.11\coIEPlg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: DebugBar - {3E1201F4-1707-409F-BB45-A5F192381DA0} - C:\Program Files\Core Services\DebugBar\DebugToolBar.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Rohit\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: PCSuiteForNokia3650 TS.lnk = ?
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: &Hilight This Page - http://roohit.com/site/hilightit.php
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagea…en/preview.html
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Bluetooth\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: Companion.JS - {0402343A-B530-482b-AA27-A61CEC3E4D2E} - C:\Program Files\Core Services\Companion.JS\CompanionJS.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Click here to Hilight This Page - {5DC83F10-8335-403d-8AA8-66E266A82471} - http://roohit.com/site/hilightit.php (file missing)
O9 - Extra 'Tools' menuitem: &Hilight This Page - {5DC83F10-8335-403d-8AA8-66E266A82471} - http://roohit.com/site/hilightit.php (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://utilities.pcpitstop.com/Nirvana/con…s/PCPitStop.CAB
O16 - DPF: {5DC83F10-8335-403D-8AA8-66E266A82471} (Roohit Plg) - http://roohit.com/site/RoohitP.CAB
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.modestogov.com/gis/home/maps/mgaxctrl.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} (diskhealth Class) - http://utilities.pcpitstop.com/Nirvana/con…DiskMD3Ctrl.dll
O16 - DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} (PCPitstop AntiVirus) - http://utilities.pcpitstop.com/Nirvana/con…opAntiVirus.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Nirvana/con…/pcpitstop2.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Security Suite\Engine\3.5.2.11\coIEPlg.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\xampp\apache\bin\httpd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Bluetooth\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: mysql - Unknown owner - c:\xampp\mysql\bin\mysqld.exe
O23 - Service: Norton Security Suite (N360) - Symantec Corporation - C:\Program Files\Norton Security Suite\Engine\3.5.2.11\ccSvcHst.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: StumbleUponUpdateService - stumbleupon.com - C:\Program Files\StumbleUpon\StumbleUponUpdateService.exe
O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Service.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 18260 bytes


And here's a log file from MBAM:

Malwarebytes' Anti-Malware 1.44
Database version: 3581
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882

1/27/2010 1:17:48 PM
mbam-log-2010-01-27 (13-17-48).txt

Scan type: Quick Scan
Objects scanned: 72145
Time elapsed: 8 minute(s), 48 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\system32\Drivers\oycvey.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
Hi,

Please do the following:

Download Combofix from either of the links below. You must rename it to combo.exe before saving it.
Save it to your desktop. Change the save as file type to "all files"

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2

———————————————————–


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on the renamed ComboFix.exe & follow the prompts. When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

———————————————————–

I am running Norton Securoty Suite (from Comcast) and I followd your instructions to disable it,
BUT ComboFix still complained about it. I ran it anyways. Here is the log file

ComboFix 10-01-31.03 - Rohit 02/01/2010 11:14:24.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3061.1226 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\combo.exe
SP: Norton Internet Security *enabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2773397201-2855733099-4214572315-500
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\AV Care
c:\programdata\Microsoft\Windows\Start Menu\Programs\AV Care\AV Care.lnk
c:\users\admin\AppData\Local\{5EA08E40-76E7-4417-8B88-CCDA55462ACA}
c:\users\admin\AppData\Local\{5EA08E40-76E7-4417-8B88-CCDA55462ACA}\chrome.manifest
c:\users\admin\AppData\Local\{5EA08E40-76E7-4417-8B88-CCDA55462ACA}\chrome\content\_cfg.js
c:\users\admin\AppData\Local\{5EA08E40-76E7-4417-8B88-CCDA55462ACA}\chrome\content\overlay.xul
c:\users\admin\AppData\Local\{5EA08E40-76E7-4417-8B88-CCDA55462ACA}\install.rdf
c:\windows\Fonts\MyriadPro-Regular.otf
c:\windows\system32\drivers\npf.sys
c:\windows\system32\drivers\oycvey.sys
c:\windows\system32\oem8.inf
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\twain_32.dll
c:\windows\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF
——-\Service_npf
——-\Legacy_oycvey
——-\Service_oycvey


((((((((((((((((((((((((( Files Created from 2010-01-01 to 2010-02-01 )))))))))))))))))))))))))))))))
.

2010-02-01 19:28 . 2010-02-01 19:28 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2010-02-01 19:28 . 2010-02-01 19:28 ——– d—–w- c:\users\TEMP\AppData\Local\temp
2010-02-01 19:28 . 2010-02-01 19:28 ——– d—–w- c:\users\TEMP.new-laptop\AppData\Local\temp
2010-02-01 19:28 . 2010-02-01 19:28 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-02-01 19:28 . 2010-02-01 19:28 ——– d—–w- c:\users\Administrator\AppData\Local\temp
2010-02-01 19:28 . 2010-02-01 19:28 ——– d—–w- c:\users\admin\AppData\Local\temp
2010-01-29 07:41 . 2010-01-29 07:43 ——– d—–w- c:\windows\system32\config\systemprofile\.jedit
2010-01-28 00:05 . 2010-01-28 00:05 ——– d—–r- c:\program files\Norton Support
2010-01-28 00:03 . 2010-01-28 00:03 ——– d—–w- c:\users\Rohit\AppData\Local\Symantec
2010-01-27 22:21 . 2010-01-27 22:21 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\Symantec
2010-01-27 20:43 . 2010-01-27 20:43 ——– d—–w- c:\program files\CCleaner
2010-01-27 19:57 . 2010-01-27 19:57 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Roaming\Notepad++
2010-01-27 19:55 . 2010-01-27 19:55 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Roaming\Malwarebytes
2010-01-27 19:53 . 2010-01-27 19:53 ——– d-sh–w- c:\windows\system32\%APPDATA%
2010-01-25 23:23 . 2010-01-25 23:23 ——– d—–w- c:\users\Rohit\AppData\Roaming\PCPitstop
2010-01-21 19:14 . 2010-01-21 19:13 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-21 19:14 . 2010-01-21 19:13 107368 —-a-r- c:\windows\system32\GEARAspi.dll
2010-01-21 19:14 . 2010-01-21 19:13 25648 —-a-r- c:\windows\system32\drivers\SymIMV.sys
2010-01-21 19:14 . 2010-01-21 19:14 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-01-21 19:14 . 2010-01-21 19:14 ——– d—–w- c:\program files\Symantec
2010-01-21 19:07 . 2010-01-21 19:07 ——– d—–w- c:\windows\system32\drivers\N360
2010-01-21 19:07 . 2010-01-21 19:15 ——– d—–w- c:\programdata\Norton
2010-01-21 19:07 . 2010-01-21 19:07 ——– d—–w- c:\program files\Norton Security Suite
2010-01-21 19:03 . 2010-01-21 19:03 ——– d—–w- c:\programdata\NortonInstaller
2010-01-21 19:03 . 2010-01-21 19:03 ——– d—–w- c:\program files\NortonInstaller
2010-01-17 21:44 . 2010-01-17 21:44 ——– d—–w- c:\users\Rohit\AppData\Roaming\DivX
2010-01-17 21:43 . 2010-01-17 21:43 ——– d—–w- c:\users\Rohit\AppData\Roaming\GeoVid
2010-01-17 21:42 . 2005-06-07 23:11 60416 —-a-w- c:\windows\system32\dsetup.dll
2010-01-17 21:42 . 2010-01-17 21:42 ——– d—–w- c:\programdata\GeoVid
2010-01-17 21:42 . 2010-01-17 21:42 ——– d—–w- c:\program files\Common Files\GeoVid
2010-01-17 21:42 . 2010-01-17 21:42 ——– d—–w- c:\program files\GeoVid
2010-01-13 01:09 . 2009-10-19 13:38 156672 —-a-w- c:\windows\system32\t2embed.dll
2010-01-13 01:09 . 2009-10-19 13:35 72704 —-a-w- c:\windows\system32\fontsub.dll
2010-01-10 04:50 . 2010-01-10 04:50 ——– d—–w- c:\windows\system32\custom matrices
2010-01-10 04:50 . 2010-01-10 04:50 ——– d—–w- c:\windows\system32\C2MP
2010-01-10 04:50 . 2010-01-10 04:50 ——– d—–w- c:\windows\system32\QuickTime
2010-01-10 03:35 . 2010-01-10 03:35 ——– d—–w- c:\program files\Veoh Networks
2010-01-09 01:47 . 2010-01-09 01:47 ——– d—–w- c:\users\Rohit\AppData\Roaming\Malwarebytes
2010-01-09 01:47 . 2010-01-08 00:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-09 01:47 . 2010-01-09 01:47 ——– d—–w- c:\programdata\Malwarebytes
2010-01-09 01:47 . 2010-01-09 01:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-09 01:47 . 2010-01-08 00:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-08 22:30 . 2010-01-08 22:30 ——– d—–w- c:\program files\MSECache
2010-01-07 18:35 . 2010-01-25 23:51 ——– d—–w- c:\programdata\PCPitstop
2010-01-07 18:35 . 2010-01-25 23:23 ——– d—–w- c:\program files\PCPitstop
2010-01-07 03:07 . 2010-01-07 03:07 ——– d—–w- c:\users\admin\AppData\Roaming\Notepad++
2010-01-07 03:07 . 2010-01-07 03:07 ——– d—–w- c:\users\admin\AppData\Local\Adobe
2010-01-07 03:07 . 2010-01-07 03:07 ——– d—–w- c:\users\admin\AppData\Roaming\Subversion
2010-01-07 03:07 . 2010-01-07 03:07 ——– d—–w- c:\users\admin\AppData\Local\Google
2010-01-06 21:20 . 2010-01-12 16:26 0 —-a-w- c:\users\Rohit\AppData\Local\Ewobofivutamux.bin
2010-01-06 21:20 . 2010-01-12 16:26 120 —-a-w- c:\users\Rohit\AppData\Local\Jfuwipokidupap.dat
2010-01-06 21:20 . 2010-01-06 21:20 ——– d—–w- c:\users\Rohit\AppData\Local\{6A24776B-50CD-4801-9E52-E19055FEFC76}

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-01 19:30 . 2009-03-16 19:49 12 —-a-w- c:\windows\bthservsdp.dat
2010-01-29 05:43 . 2008-09-18 21:44 ——– d—–w- c:\users\Rohit\AppData\Roaming\FileZilla
2010-01-29 00:28 . 2009-10-05 22:07 ——– d—–w- c:\users\Rohit\AppData\Roaming\Audacity
2010-01-27 19:18 . 2008-11-09 18:44 ——– d—–w- c:\users\Rohit\AppData\Roaming\Skype
2010-01-27 19:17 . 2008-11-09 18:45 ——– d—–w- c:\users\Rohit\AppData\Roaming\skypePM
2010-01-26 22:46 . 2008-12-22 08:24 ——– d—–w- c:\users\Rohit\AppData\Roaming\Subversion
2010-01-21 19:18 . 2008-08-03 06:52 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-01-21 19:14 . 2010-01-21 19:14 806 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-01-21 19:14 . 2010-01-21 19:14 7456 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-01-21 19:07 . 2009-03-01 08:34 ——– d—–w- c:\programdata\avg8
2010-01-20 06:44 . 2009-05-13 23:24 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-16 19:55 . 2008-10-04 14:03 680 —-a-w- c:\users\Rohit\AppData\Local\d3d9caps.dat
2010-01-07 03:06 . 2008-09-17 00:58 87040 —-a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-01-07 03:06 . 2010-01-07 03:06 680 —-a-w- c:\users\admin\AppData\Local\d3d9caps.dat
2010-01-06 22:22 . 2008-10-18 11:32 ——– d—–w- c:\programdata\FLEXnet
2010-01-02 06:38 . 2010-01-21 19:55 916480 —-a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-21 19:55 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-01-02 06:32 . 2010-01-21 19:55 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-01-02 04:57 . 2010-01-21 19:55 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-12-23 00:41 . 2009-11-20 23:09 ——– d—–w- c:\program files\CamStudio
2009-12-22 01:23 . 2009-05-11 07:49 ——– d—–w- c:\program files\Mozilla Thunderbird
2009-12-22 01:21 . 2009-05-11 07:49 ——– d—–w- c:\users\Rohit\AppData\Roaming\Thunderbird
2009-12-17 18:46 . 2008-08-03 06:45 ——– d—–w- c:\program files\Google
2009-12-14 19:15 . 2009-12-14 19:15 2146304 —-a-w- c:\windows\system32\GPhotos.scr
2009-12-06 02:52 . 2009-03-10 19:25 ——– d—–w- c:\users\Rohit\AppData\Roaming\Notepad++
2009-12-06 02:52 . 2009-05-21 22:48 ——– d—–w- c:\programdata\HP Product Assistant
2009-12-06 02:52 . 2009-12-01 21:34 ——– d—–w- c:\program files\Dimdim
2009-12-06 02:37 . 2009-12-06 00:26 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Roaming\FileZilla
2009-12-05 23:44 . 2009-12-05 23:40 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Roaming\Apple Computer
2009-12-05 23:44 . 2008-09-09 02:29 87040 —-a-w- c:\windows\system32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-05 20:01 . 2009-12-05 20:01 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Roaming\Subversion
2009-12-05 19:49 . 2009-12-05 19:49 ——– d—–w- c:\users\TEMP.new-laptop\AppData\Roaming\Subversion
2009-12-04 17:49 . 2009-03-05 05:48 ——– d—–w- c:\programdata\HP
2009-12-02 17:02 . 2009-12-02 17:02 1632887 —-a-w- c:\windows\system32\ffmpegmt.dll
2009-12-02 16:56 . 2009-12-02 16:56 4840081 —-a-w- c:\windows\system32\libavcodec.dll
2009-12-01 21:32 . 2009-12-01 21:32 2031616 —-a-w- c:\users\Rohit\Dimdim.msi
2009-12-01 21:32 . 2009-12-01 21:32 100232 —-a-w- c:\users\Rohit\DimdimSetup.exe
2009-11-24 01:24 . 2009-05-20 07:18 736 —-a-w- c:\users\Rohit\AppData\Roaming\wklnhst.dat
2009-11-09 12:31 . 2009-12-09 11:12 24064 —-a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-09 11:12 30720 —-a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-09 11:12 411648 —-a-w- c:\windows\system32\drivers\http.sys
2009-11-04 18:45 . 2009-11-04 18:45 611638 —-a-w- c:\windows\system32\libmplayer.dll
2009-11-04 18:43 . 2009-11-04 18:43 324096 —-a-w- c:\windows\system32\TomsMoComp_ff.dll
2009-11-03 20:11 . 2009-11-03 20:11 113152 —-a-w- c:\windows\system32\ff_unrar.dll
2009-11-03 20:11 . 2009-11-03 20:11 146944 —-a-w- c:\windows\system32\ff_tremor.dll
2009-11-03 20:10 . 2009-11-03 20:10 183296 —-a-w- c:\windows\system32\ff_samplerate.dll
2009-11-03 20:09 . 2009-11-03 20:09 178688 —-a-w- c:\windows\system32\ff_libmad.dll
2009-11-03 20:08 . 2009-11-03 20:08 484864 —-a-w- c:\windows\system32\ff_libfaad2.dll
2009-11-03 20:08 . 2009-11-03 20:08 257024 —-a-w- c:\windows\system32\ff_libdts.dll
2009-11-03 20:07 . 2009-11-03 20:07 142848 —-a-w- c:\windows\system32\ff_liba52.dll
2008-08-03 06:39 . 2008-08-03 06:39 76 –sh–r- c:\windows\CT4CET.bin
2008-08-03 09:18 . 2008-08-03 09:18 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-05-04 167936]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-05-19 3444736]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-11-12 405504]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-8-2 50688]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ExSearchOptions"= 105444 (0x19be4)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-03 06:56 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PCSuiteForNokia3650 Detect.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\PCSuiteForNokia3650 Detect.lnk
backup=c:\windows\pss\PCSuiteForNokia3650 Detect.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Rohit^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^eFax 4.4.lnk]
path=c:\users\Rohit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\eFax 4.4.lnk
backup=c:\windows\pss\eFax 4.4.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eFax 4.4]
2008-10-07 20:25 95744 —-a-w- c:\program files\eFax Messenger 4.4\J2GDllCmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-03-06 07:58 166424 —-a-w- c:\windows\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-10-15 04:17 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-03-06 07:58 141848 —-a-w- c:\windows\System32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-03-06 07:58 133656 —-a-w- c:\windows\System32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 08:54 417792 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):3a,62,12,81,5f,56,ca,01

R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\N360\0305020.00B\SymEFA.sys [1/21/2010 11:13 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\N360\0305020.00B\BHDrvx86.sys [1/21/2010 11:13 AM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\N360\0305020.00B\cchpx86.sys [1/21/2010 11:13 AM 482432]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSvix86.sys [1/29/2010 2:40 PM 343088]
R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [12/9/2008 3:10 PM 24636]
R2 N360;Norton Security Suite;c:\program files\Norton Security Suite\Engine\3.5.2.11\ccSvcHst.exe [1/21/2010 11:13 AM 117640]
R2 TeamViewer;TeamViewer 3;c:\program files\TeamViewer3\TeamViewer_Service.exe [8/5/2008 10:42 PM 181544]
R3 dfmirage;dfmirage;c:\windows\System32\drivers\dfmirage.sys [3/28/2009 7:08 PM 34128]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [1/21/2010 5:36 PM 102448]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\System32\drivers\IntcHdmi.sys [8/3/2008 1:20 AM 111616]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\N360\0305020.00B\symndisv.sys [1/21/2010 11:13 AM 48688]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/17/2009 10:46 AM 135664]
S3 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [8/2/2008 5:24 PM 73728]
S3 StumbleUponUpdateService;StumbleUponUpdateService;c:\program files\StumbleUpon\StumbleUponUpdateService.exe [6/3/2009 12:52 PM 120168]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [1/25/2010 3:23 PM 85504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
bthsvcs REG_MULTI_SZ BthServ
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-17 18:46]

2010-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-17 18:46]

2010-02-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4090199657-2502665127-528636376-1000Core.job
- c:\users\Rohit\AppData\Local\Google\Update\GoogleUpdate.exe [2009-01-12 12:54]

2010-02-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4090199657-2502665127-528636376-1000UA.job
- c:\users\Rohit\AppData\Local\Google\Update\GoogleUpdate.exe [2009-01-12 12:54]

2010-02-01 c:\windows\Tasks\User_Feed_Synchronization-{E5ABE8E8-982E-4C11-B7F5-4E1BA822B8BD}.job
- c:\windows\system32\msfeedssync.exe [2010-01-21 04:56]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://roohit.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uInternet Settings,ProxyOverride = cdn
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &Hilight; This Page - http://roohit.com/site/hilightit.php
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagea…en/preview.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send To &Bluetooth; - c:\program files\Bluetooth\Bluetooth Software\btsendto_ie_ctx.htm
IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage
IE: {{0402343A-B530-482b-AA27-A61CEC3E4D2E} - {C30B6FCB-F8B0-4DD4-9207-AA4952BB3F52} - c:\program files\Core Services\Companion.JS\CompanionJS.dll
Trusted Zone: turbotax.com
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\users\Rohit\AppData\Roaming\Mozilla\Firefox\Profiles\it3vi0w9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://spreadsheets.google.com/ccc?key=t5SLwKBZJ6b6oy0VS5GOdxg&hl;=en#
FF - prefs.js: keyword.URL - hxxp://recovery.alexa.com/helper/?aid=lxX891W9aN00iK&plugin;=spkyf-1.4.7&reason;=keyword&location;=
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\users\Rohit\AppData\Roaming\Mozilla\Firefox\Profiles\it3vi0w9.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npDimdimControl.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Rohit\AppData\Local\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\windows\system32\C2MP\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: XULRunner: {6A24776B-50CD-4801-9E52-E19055FEFC76} - c:\users\Rohit\AppData\Local\{6A24776B-50CD-4801-9E52-E19055FEFC76}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Search Protection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
MSConfigStartUp-CTFMON - c:\windows\Temp\_ex-08.exe
MSConfigStartUp-Ihudub - c:\users\Rohit\AppData\Local\inovemomixef.dll
MSConfigStartUp-MSMSGS - c:\program files\Messenger\msmsgs.exe
MSConfigStartUp-Wvulabokogikewej - c:\users\Rohit\AppData\Local\nfegmpng.dll
AddRemove-8FBFA08E-5232-40EC-87D8-E65474B0E2BF - c:\program files\TkDiff\uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-01 11:41
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton Security Suite\Engine\3.5.2.11\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\3.5.2.11\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(4848)
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
c:\windows\System32\NLSData0009.dll
c:\windows\system32\btneighborhood.dll
c:\windows\system32\wbtapi.dll
c:\windows\system32\MFC42.DLL
c:\windows\system32\MSVCP60.dll
c:\windows\system32\btwpimif.dll
c:\windows\system32\btosif.dll
c:\windows\system32\btrez.dll
c:\windows\system32\CSH.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\PC Suite for Nokia 3650\eccopyhook.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\system32\WLANExt.exe
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\STacSV.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\DllHost.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2010-02-01 11:49:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-01 19:49

Pre-Run: 49,574,649,856 bytes free
Post-Run: 49,314,443,264 bytes free

- - End Of File - - DD52223FADD47CA35BF0E2059B07A8A8
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Hacktool_Rootkit_Infection_t109872.html&view=findpost&p=629461#entry629461

Collect::
c:\users\Rohit\AppData\Local\Jfuwipokidupap.dat

File::
c:\users\Rohit\AppData\Local\Ewobofivutamux.bin

DirLook::
c:\windows\system32\config\systemprofile\.jedit

Folder::
c:\users\Rohit\AppData\Local\{6A24776B-50CD-4801-9E52-E19055FEFC76}

FireFox::
FF - ProfilePath - c:\users\Rohit\AppData\Roaming\Mozilla\Firefox\Profiles\it3vi0w9.default\
FF - HiddenExtension: XULRunner: {6A24776B-50CD-4801-9E52-E19055FEFC76} - c:\users\Rohit\AppData\Local\{6A24776B-50CD-4801-9E52-E19055FEFC76}

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


NEXT



  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Like the last time I disabled Norton Security Suite and combo.exe was not convinced that I had. The logs are: (THANKS for your help)

ComboFix 10-01-31.03 - Rohit 02/01/2010 15:50:39.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3061.1161 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\combo.exe
Command switches used :: c:\users\Rohit\Desktop\CFScript
SP: Norton Internet Security *enabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
"c:\users\Rohit\AppData\Local\Ewobofivutamux.bin"

file zipped: c:\users\Rohit\AppData\Local\Jfuwipokidupap.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Rohit\AppData\Local\{6A24776B-50CD-4801-9E52-E19055FEFC76}
c:\users\Rohit\AppData\Local\{6A24776B-50CD-4801-9E52-E19055FEFC76}\chrome.manifest
c:\users\Rohit\AppData\Local\{6A24776B-50CD-4801-9E52-E19055FEFC76}\chrome\content\_cfg.js
c:\users\Rohit\AppData\Local\{6A24776B-50CD-4801-9E52-E19055FEFC76}\chrome\content\overlay.xul
c:\users\Rohit\AppData\Local\{6A24776B-50CD-4801-9E52-E19055FEFC76}\install.rdf
c:\users\Rohit\AppData\Local\Ewobofivutamux.bin
c:\users\Rohit\AppData\Local\Jfuwipokidupap.dat

.
((((((((((((((((((((((((( Files Created from 2010-01-02 to 2010-02-02 )))))))))))))))))))))))))))))))
.

2010-02-02 00:03 . 2010-02-02 00:03 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2010-02-02 00:03 . 2010-02-02 00:03 ——– d—–w- c:\users\TEMP\AppData\Local\temp
2010-02-02 00:03 . 2010-02-02 00:03 ——– d—–w- c:\users\TEMP.new-laptop\AppData\Local\temp
2010-02-02 00:03 . 2010-02-02 00:03 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-02-02 00:03 . 2010-02-02 00:03 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-02-02 00:03 . 2010-02-02 00:03 ——– d—–w- c:\users\Administrator\AppData\Local\temp
2010-02-02 00:03 . 2010-02-02 00:03 ——– d—–w- c:\users\admin\AppData\Local\temp
2010-02-01 19:49 . 2010-02-02 00:04 ——– d—–w- c:\users\Rohit\AppData\Local\temp
2010-02-01 19:09 . 2010-02-01 19:49 ——– d—–w- C:\combo
2010-01-29 07:41 . 2010-01-29 07:43 ——– d—–w- c:\windows\system32\config\systemprofile\.jedit
2010-01-28 00:05 . 2010-01-28 00:05 ——– d—–r- c:\program files\Norton Support
2010-01-28 00:03 . 2010-01-28 00:03 ——– d—–w- c:\users\Rohit\AppData\Local\Symantec
2010-01-27 22:21 . 2010-01-27 22:21 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\Symantec
2010-01-27 20:43 . 2010-01-27 20:43 ——– d—–w- c:\program files\CCleaner
2010-01-27 19:57 . 2010-01-27 19:57 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Roaming\Notepad++
2010-01-27 19:55 . 2010-01-27 19:55 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Roaming\Malwarebytes
2010-01-27 19:53 . 2010-01-27 19:53 ——– d-sh–w- c:\windows\system32\%APPDATA%
2010-01-25 23:23 . 2010-01-25 23:23 ——– d—–w- c:\users\Rohit\AppData\Roaming\PCPitstop
2010-01-21 19:14 . 2010-01-21 19:13 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-21 19:14 . 2010-01-21 19:13 107368 —-a-r- c:\windows\system32\GEARAspi.dll
2010-01-21 19:14 . 2010-01-21 19:13 25648 —-a-r- c:\windows\system32\drivers\SymIMV.sys
2010-01-21 19:14 . 2010-01-21 19:14 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-01-21 19:14 . 2010-01-21 19:14 ——– d—–w- c:\program files\Symantec
2010-01-21 19:07 . 2010-01-21 19:07 ——– d—–w- c:\windows\system32\drivers\N360
2010-01-21 19:07 . 2010-01-21 19:15 ——– d—–w- c:\programdata\Norton
2010-01-21 19:07 . 2010-01-21 19:07 ——– d—–w- c:\program files\Norton Security Suite
2010-01-21 19:03 . 2010-01-21 19:03 ——– d—–w- c:\programdata\NortonInstaller
2010-01-21 19:03 . 2010-01-21 19:03 ——– d—–w- c:\program files\NortonInstaller
2010-01-17 21:44 . 2010-01-17 21:44 ——– d—–w- c:\users\Rohit\AppData\Roaming\DivX
2010-01-17 21:43 . 2010-01-17 21:43 ——– d—–w- c:\users\Rohit\AppData\Roaming\GeoVid
2010-01-17 21:42 . 2005-06-07 23:11 60416 —-a-w- c:\windows\system32\dsetup.dll
2010-01-17 21:42 . 2010-01-17 21:42 ——– d—–w- c:\programdata\GeoVid
2010-01-17 21:42 . 2010-01-17 21:42 ——– d—–w- c:\program files\Common Files\GeoVid
2010-01-17 21:42 . 2010-01-17 21:42 ——– d—–w- c:\program files\GeoVid
2010-01-13 01:09 . 2009-10-19 13:38 156672 —-a-w- c:\windows\system32\t2embed.dll
2010-01-13 01:09 . 2009-10-19 13:35 72704 —-a-w- c:\windows\system32\fontsub.dll
2010-01-10 04:50 . 2010-01-10 04:50 ——– d—–w- c:\windows\system32\custom matrices
2010-01-10 04:50 . 2010-01-10 04:50 ——– d—–w- c:\windows\system32\C2MP
2010-01-10 04:50 . 2010-01-10 04:50 ——– d—–w- c:\windows\system32\QuickTime
2010-01-10 03:35 . 2010-01-10 03:35 ——– d—–w- c:\program files\Veoh Networks
2010-01-09 01:47 . 2010-01-09 01:47 ——– d—–w- c:\users\Rohit\AppData\Roaming\Malwarebytes
2010-01-09 01:47 . 2010-01-08 00:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-09 01:47 . 2010-01-09 01:47 ——– d—–w- c:\programdata\Malwarebytes
2010-01-09 01:47 . 2010-01-09 01:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-09 01:47 . 2010-01-08 00:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-08 22:30 . 2010-01-08 22:30 ——– d—–w- c:\program files\MSECache
2010-01-07 18:35 . 2010-01-25 23:51 ——– d—–w- c:\programdata\PCPitstop
2010-01-07 18:35 . 2010-01-25 23:23 ——– d—–w- c:\program files\PCPitstop
2010-01-07 03:07 . 2010-01-07 03:07 ——– d—–w- c:\users\admin\AppData\Roaming\Notepad++
2010-01-07 03:07 . 2010-01-07 03:07 ——– d—–w- c:\users\admin\AppData\Local\Adobe
2010-01-07 03:07 . 2010-01-07 03:07 ——– d—–w- c:\users\admin\AppData\Roaming\Subversion
2010-01-07 03:07 . 2010-01-07 03:07 ——– d—–w- c:\users\admin\AppData\Local\Google

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-01 23:44 . 2008-09-18 21:44 ——– d—–w- c:\users\Rohit\AppData\Roaming\FileZilla
2010-02-01 20:14 . 2009-03-16 19:49 12 —-a-w- c:\windows\bthservsdp.dat
2010-01-29 00:28 . 2009-10-05 22:07 ——– d—–w- c:\users\Rohit\AppData\Roaming\Audacity
2010-01-27 19:18 . 2008-11-09 18:44 ——– d—–w- c:\users\Rohit\AppData\Roaming\Skype
2010-01-27 19:17 . 2008-11-09 18:45 ——– d—–w- c:\users\Rohit\AppData\Roaming\skypePM
2010-01-27 13:08 . 2010-02-01 18:50 177520 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100201.009\NAVENG32.DLL
2010-01-27 13:08 . 2010-02-01 18:50 1647984 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100201.009\NAVEX32A.DLL
2010-01-27 13:08 . 2010-02-01 18:50 1323568 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100201.009\NAVEX15.SYS
2010-01-27 13:08 . 2010-02-01 18:50 84912 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100201.009\NAVENG.SYS
2010-01-27 13:08 . 2010-02-01 18:50 371248 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100201.009\EECTRL.SYS
2010-01-27 13:08 . 2010-02-01 18:50 259440 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100201.009\ECMSVR32.DLL
2010-01-27 13:08 . 2010-02-01 18:50 102448 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100201.009\ERASER.SYS
2010-01-27 13:08 . 2010-02-01 18:50 2747440 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100201.009\CCERASER.DLL
2010-01-26 22:46 . 2008-12-22 08:24 ——– d—–w- c:\users\Rohit\AppData\Roaming\Subversion
2010-01-21 19:18 . 2008-08-03 06:52 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-01-21 19:14 . 2010-01-21 19:14 806 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-01-21 19:14 . 2010-01-21 19:14 7456 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-01-21 19:13 . 2010-01-21 19:13 1291104 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2010-01-21 19:13 . 2010-01-21 19:13 136840 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2010-01-21 19:13 . 2010-01-21 19:07 165240 —-a-r- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2010-01-21 19:13 . 2010-01-21 19:14 554352 —-a-r- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
2010-01-21 19:13 . 2010-01-21 19:07 776952 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2010-01-21 19:07 . 2009-03-01 08:34 ——– d—–w- c:\programdata\avg8
2010-01-21 12:43 . 2010-01-27 07:48 84912 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100126.048\NAVENG.SYS
2010-01-21 12:43 . 2010-01-27 07:48 177520 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100126.048\NAVENG32.DLL
2010-01-21 12:43 . 2010-01-27 07:48 1647984 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100126.048\NAVEX32A.DLL
2010-01-21 12:43 . 2010-01-27 07:48 1323568 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100126.048\NAVEX15.SYS
2010-01-21 12:43 . 2010-01-27 07:48 371248 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100126.048\EECTRL.SYS
2010-01-21 12:43 . 2010-01-27 07:48 2747440 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100126.048\CCERASER.DLL
2010-01-21 12:43 . 2010-01-27 07:48 259440 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100126.048\ECMSVR32.DLL
2010-01-21 12:43 . 2010-01-27 07:48 102448 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100126.048\ERASER.SYS
2010-01-20 06:44 . 2009-05-13 23:24 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-16 19:55 . 2008-10-04 14:03 680 —-a-w- c:\users\Rohit\AppData\Local\d3d9caps.dat
2010-01-09 01:47 . 2010-01-09 01:47 5115824 —-a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-07 03:06 . 2008-09-17 00:58 87040 —-a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-01-07 03:06 . 2010-01-07 03:06 680 —-a-w- c:\users\admin\AppData\Local\d3d9caps.dat
2010-01-06 22:22 . 2008-10-18 11:32 ——– d—–w- c:\programdata\FLEXnet
2010-01-02 06:38 . 2010-01-21 19:55 916480 —-a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-21 19:55 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-01-02 06:32 . 2010-01-21 19:55 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-01-02 04:57 . 2010-01-21 19:55 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-12-26 00:24 . 2009-12-26 00:24 658184 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-23 00:41 . 2009-11-20 23:09 ——– d—–w- c:\program files\CamStudio
2009-12-22 01:23 . 2009-05-11 07:49 ——– d—–w- c:\program files\Mozilla Thunderbird
2009-12-22 01:21 . 2009-05-11 07:49 ——– d—–w- c:\users\Rohit\AppData\Roaming\Thunderbird
2009-12-17 18:46 . 2008-08-03 06:45 ——– d—–w- c:\program files\Google
2009-12-16 22:42 . 2009-12-22 17:50 872960 —-a-w- c:\users\Rohit\AppData\Roaming\Mozilla\Firefox\Profiles\it3vi0w9.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-16 22:42 . 2009-12-22 17:50 43008 —-a-w- c:\users\Rohit\AppData\Roaming\Mozilla\Firefox\Profiles\it3vi0w9.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-16 22:42 . 2009-12-22 17:50 340480 —-a-w- c:\users\Rohit\AppData\Roaming\Mozilla\Firefox\Profiles\it3vi0w9.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-16 22:41 . 2009-12-22 17:50 346624 —-a-w- c:\users\Rohit\AppData\Roaming\Mozilla\Firefox\Profiles\it3vi0w9.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-12-14 19:15 . 2009-12-14 19:15 2146304 —-a-w- c:\windows\system32\GPhotos.scr
2009-12-06 02:52 . 2009-03-10 19:25 ——– d—–w- c:\users\Rohit\AppData\Roaming\Notepad++
2009-12-06 02:52 . 2009-05-21 22:48 ——– d—–w- c:\programdata\HP Product Assistant
2009-12-06 02:52 . 2009-12-01 21:34 ——– d—–w- c:\program files\Dimdim
2009-12-06 02:37 . 2009-12-06 00:26 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Roaming\FileZilla
2009-12-05 23:44 . 2009-12-05 23:40 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Roaming\Apple Computer
2009-12-05 23:44 . 2008-09-09 02:29 87040 —-a-w- c:\windows\system32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-05 20:01 . 2009-12-05 20:01 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Roaming\Subversion
2009-12-05 19:49 . 2009-12-05 19:49 ——– d—–w- c:\users\TEMP.new-laptop\AppData\Roaming\Subversion
2009-12-04 17:49 . 2009-03-05 05:48 ——– d—–w- c:\programdata\HP
2009-12-02 17:02 . 2009-12-02 17:02 1632887 —-a-w- c:\windows\system32\ffmpegmt.dll
2009-12-02 16:56 . 2009-12-02 16:56 4840081 —-a-w- c:\windows\system32\libavcodec.dll
2009-12-01 21:32 . 2009-12-01 21:32 2031616 —-a-w- c:\users\Rohit\Dimdim.msi
2009-12-01 21:32 . 2009-12-01 21:32 100232 —-a-w- c:\users\Rohit\DimdimSetup.exe
2009-11-24 01:24 . 2009-05-20 07:18 736 —-a-w- c:\users\Rohit\AppData\Roaming\wklnhst.dat
2009-11-12 01:58 . 2009-11-12 01:58 25214 —-a-r- c:\users\Rohit\AppData\Roaming\Microsoft\Installer\{C1FCDCA1-2759-4E5E-84EE-3A665BB2F513}\_E38944F26F8D876B004311.exe
2009-11-12 01:58 . 2009-11-12 01:58 10398 —-a-r- c:\users\Rohit\AppData\Roaming\Microsoft\Installer\{C1FCDCA1-2759-4E5E-84EE-3A665BB2F513}\_6FA99008F6BBB97A091E2D.exe
2009-11-09 12:31 . 2009-12-09 11:12 24064 —-a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-09 11:12 30720 —-a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-09 11:12 411648 —-a-w- c:\windows\system32\drivers\http.sys
2009-11-08 02:39 . 2009-11-08 02:39 79144 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-04 18:45 . 2009-11-04 18:45 611638 —-a-w- c:\windows\system32\libmplayer.dll
2009-11-04 18:43 . 2009-11-04 18:43 324096 —-a-w- c:\windows\system32\TomsMoComp_ff.dll
2008-08-03 06:39 . 2008-08-03 06:39 76 –sh–r- c:\windows\CT4CET.bin
2008-08-03 09:18 . 2008-08-03 09:18 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\windows\system32\config\systemprofile\.jedit —-

2010-01-29 07:43 . 2010-01-29 07:43 109 —-a-w- c:\windows\system32\config\systemprofile\.jedit\killring.xml
2010-01-29 07:43 . 2010-01-29 07:43 451 —-a-w- c:\windows\system32\config\systemprofile\.jedit\properties
2010-01-29 07:43 . 2010-01-29 07:43 239 —-a-w- c:\windows\system32\config\systemprofile\.jedit\recent.xml
2010-01-29 07:42 . 2010-01-29 07:42 458 —-a-w- c:\windows\system32\config\systemprofile\.jedit\perspective.xml
2010-01-29 07:42 . 2010-01-29 07:42 101 —-a-w- c:\windows\system32\config\systemprofile\.jedit\DockableWindowManager\perspective-view0.xml
2010-01-29 07:42 . 2010-01-29 07:42 458 —-a-w- c:\windows\system32\config\systemprofile\.jedit\settings-backup\perspective.xml~1~
2010-01-29 07:42 . 2010-01-29 07:42 458 —-a-w- c:\windows\system32\config\systemprofile\.jedit\settings-backup\perspective.xml~2~
2010-01-29 07:42 . 2010-01-29 07:42 458 —-a-w- c:\windows\system32\config\systemprofile\.jedit\settings-backup\perspective.xml~3~
2010-01-29 07:41 . 2010-01-29 07:41 217 —-a-w- c:\windows\system32\config\systemprofile\.jedit\modes\catalog
2010-01-29 07:41 . 2010-01-29 07:41 4027 —-a-w- c:\windows\system32\config\systemprofile\.jedit\jars-cache\QuickNotepad.jar.summary
2010-01-29 07:41 . 2010-01-29 07:41 3615 —-a-w- c:\windows\system32\config\systemprofile\.jedit\jars-cache\LatestVersion.jar.summary
2010-01-29 07:41 . 2010-01-29 07:43 21492 —-a-w- c:\windows\system32\config\systemprofile\.jedit\activity.log


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2008-01-17 01:52 80384 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-03 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-05-04 167936]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-05-19 3444736]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-11-12 405504]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-8-2 50688]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ExSearchOptions"= 105444 (0x19be4)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-03 06:56 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PCSuiteForNokia3650 Detect.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\PCSuiteForNokia3650 Detect.lnk
backup=c:\windows\pss\PCSuiteForNokia3650 Detect.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Rohit^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^eFax 4.4.lnk]
path=c:\users\Rohit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\eFax 4.4.lnk
backup=c:\windows\pss\eFax 4.4.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eFax 4.4]
2008-10-07 20:25 95744 —-a-w- c:\program files\eFax Messenger 4.4\J2GDllCmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-03-06 07:58 166424 —-a-w- c:\windows\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-10-15 04:17 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-03-06 07:58 141848 —-a-w- c:\windows\System32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-03-06 07:58 133656 —-a-w- c:\windows\System32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 08:54 417792 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):3a,62,12,81,5f,56,ca,01

R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\N360\0305020.00B\SymEFA.sys [1/21/2010 11:13 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\N360\0305020.00B\BHDrvx86.sys [1/21/2010 11:13 AM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\N360\0305020.00B\cchpx86.sys [1/21/2010 11:13 AM 482432]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSvix86.sys [1/29/2010 2:40 PM 343088]
R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [12/9/2008 3:10 PM 24636]
R2 N360;Norton Security Suite;c:\program files\Norton Security Suite\Engine\3.5.2.11\ccSvcHst.exe [1/21/2010 11:13 AM 117640]
R2 TeamViewer;TeamViewer 3;c:\program files\TeamViewer3\TeamViewer_Service.exe [8/5/2008 10:42 PM 181544]
R3 dfmirage;dfmirage;c:\windows\System32\drivers\dfmirage.sys [3/28/2009 7:08 PM 34128]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [1/21/2010 5:36 PM 102448]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\System32\drivers\IntcHdmi.sys [8/3/2008 1:20 AM 111616]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\N360\0305020.00B\symndisv.sys [1/21/2010 11:13 AM 48688]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/17/2009 10:46 AM 135664]
S3 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [8/2/2008 5:24 PM 73728]
S3 StumbleUponUpdateService;StumbleUponUpdateService;c:\program files\StumbleUpon\StumbleUponUpdateService.exe [6/3/2009 12:52 PM 120168]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [1/25/2010 3:23 PM 85504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
bthsvcs REG_MULTI_SZ BthServ
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-17 18:46]

2010-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-17 18:46]

2010-02-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4090199657-2502665127-528636376-1000Core.job
- c:\users\Rohit\AppData\Local\Google\Update\GoogleUpdate.exe [2009-01-12 12:54]

2010-02-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4090199657-2502665127-528636376-1000UA.job
- c:\users\Rohit\AppData\Local\Google\Update\GoogleUpdate.exe [2009-01-12 12:54]

2010-02-02 c:\windows\Tasks\User_Feed_Synchronization-{E5ABE8E8-982E-4C11-B7F5-4E1BA822B8BD}.job
- c:\windows\system32\msfeedssync.exe [2010-01-21 04:56]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://roohit.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uInternet Settings,ProxyOverride = cdn
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &Hilight; This Page - http://roohit.com/site/hilightit.php
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagea…en/preview.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send To &Bluetooth; - c:\program files\Bluetooth\Bluetooth Software\btsendto_ie_ctx.htm
IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage
IE: {{0402343A-B530-482b-AA27-A61CEC3E4D2E} - {C30B6FCB-F8B0-4DD4-9207-AA4952BB3F52} - c:\program files\Core Services\Companion.JS\CompanionJS.dll
Trusted Zone: turbotax.com
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\users\Rohit\AppData\Roaming\Mozilla\Firefox\Profiles\it3vi0w9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://spreadsheets.google.com/ccc?key=t5SLwKBZJ6b6oy0VS5GOdxg&hl;=en#
FF - prefs.js: keyword.URL - hxxp://recovery.alexa.com/helper/?aid=lxX891W9aN00iK&plugin;=spkyf-1.4.7&reason;=keyword&location;=
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\users\Rohit\AppData\Roaming\Mozilla\Firefox\Profiles\it3vi0w9.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npDimdimControl.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Rohit\AppData\Local\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\windows\system32\C2MP\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-01 16:04
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton Security Suite\Engine\3.5.2.11\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\3.5.2.11\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-02-01 16:10:33
ComboFix-quarantined-files.txt 2010-02-02 00:10
ComboFix2.txt 2010-02-01 19:49

Pre-Run: 50,257,403,904 bytes free
Post-Run: 50,652,893,184 bytes free

- - End Of File - - C34775248793C36C44FC502ED9BE6F20
Upload was successful
MBAM did not find anything, here's the log file: Malwarebytes' Anti-Malware 1.44 Database version: 3675 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18882 2/1/2010 4:22:48 PM mbam-log-2010-02-01 (16-22-48).txt Scan type: Quick Scan Objects scanned: 142161 Time elapsed: 7 minute(s), 19 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Kaspersky ran for almost an entire day & night, but here's the report: KASPERSKY ONLINE SCANNER 7.0: scan report Tuesday, February 2, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Monday, February 01, 2010 13:54:30 Records in database: 3393933 Scan settings scan using the following database extended Scan archives yes Scan e-mail databases yes Scan area My Computer C:\ D:\ E:\ Scan statistics Objects scanned 629846 Threats found 17 Infected objects found 48 Suspicious objects found 41 Scan duration 15:51:04 File name Threat Threats count C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\cl-beta\Deleted Items\7FF548D3-00001CCE.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\cl-beta\Inbox\6D5946D8-000000B8.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\mail.RohitC 631\Inbox\366B66C4-00000BB5.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\05255F7E-00000D69.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\06095010-00000DB2.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\099C0FF1-000008D8.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\0B0B511B-00000DC1.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\17054BCD-00000DEB.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\1779712E-0000126A.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\272F4B51-00000B50.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 2 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\2D315F24-00000C8B.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 2 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\2F6D3B8D-00000CC4.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\31754394-00000CCC.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\31CD709D-00000D86.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\32E773E4-00000D3D.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\3488716C-0000126D.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\348B2F8B-00000D73.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\49077A9F-00000D93.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\4D3B3BF2-00000CBE.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\4E3B081B-00000D8C.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\532F5A7E-000008BD.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\57084758-000008B9.eml Infected: Trojan-Spy.HTML.Fraud.ha 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\5C79110D-00000CA1.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\5E6E5EBB-00000DB8.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\62D73E8A-00000B5C.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 2 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\680403E9-00000D0D.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\79161A92-00000D9B.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\7AC2174D-00000D5E.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Deleted Items\7EFE3A6E-00000CD7.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 2 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Inbox\001E702F-000001AA.eml Infected: Trojan-Downloader.JS.Agent.cye 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Inbox\149E1E51-000001DE.eml Infected: Trojan-Clicker.HTML.IFrame.abn 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Inbox\545C47D6-000001A8.eml Infected: Trojan-Downloader.JS.Agent.cye 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\roohit – Rohit\Junk E-mail\0C4D32EA-0000144C.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\_WonFineDay\Inbox\26354CCD-00000BEF.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\AppData\Local\Microsoft\Windows Live Mail\_WonFineDay\Inbox\39E31854-00000C41.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\Downloads\fjse.exe Suspicious: Packed.Win32.Black.d 1 C:\Users\Rohit\Downloads\fjse.zip Suspicious: Packed.Win32.Black.d 1 C:\Users\Rohit\_from ACER\Dnloads\backup-rohitchandra.com-6-27-2006.tar.gz Infected: Email-Worm.Win32.Nyxem.e 10 C:\Users\Rohit\_from ACER\Dnloads\backup-rohitchandra.com-6-27-2006.tar.gz Infected: Trojan-Spy.HTML.Fraud.f 2 C:\Users\Rohit\_from ACER\OEMail\cl-beta.dbx Infected: Email-Worm.Win32.Mydoom.l 1 C:\Users\Rohit\_from ACER\OEMail\cl-beta.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\_from ACER\OEMail\Deleted Items (1).dbx Infected: Trojan-Downloader.Win32.Injecter.ga 10 C:\Users\Rohit\_from ACER\OEMail\Deleted Items (1).dbx Infected: Email-Worm.Win32.Mydoom.l 1 C:\Users\Rohit\_from ACER\OEMail\Deleted Items (1).dbx Infected: Backdoor.Win32.Hijack.e 1 C:\Users\Rohit\_from ACER\OEMail\Deleted Items (1).dbx Infected: Trojan.Win32.Pakes.kih 1 C:\Users\Rohit\_from ACER\OEMail\Deleted Items (1).dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Rohit\_from ACER\OEMail\Deleted Items (1).dbx Infected: Trojan-Downloader.Win32.Small.aeqm 1 C:\Users\Rohit\_from ACER\OEMail\Deleted Items (1).dbx Infected: Worm.Win32.AutoRun.qrj 1 C:\Users\Rohit\_from ACER\OEMail\Deleted Items (1).dbx Infected: Trojan.Win32.Agent.akrt 1 C:\Users\Rohit\_from ACER\OEMail\Deleted Items (1).dbx Infected: Trojan-Downloader.JS.Agent.cye 1 C:\Users\Rohit\_from ACER\OEMail\Deleted Items (1).dbx Infected: Trojan-Clicker.HTML.IFrame.abn 5 C:\Users\Rohit\_from ACER\OEMail\Deleted Items (1).dbx Infected: Trojan-Clicker.JS.Agent.cg 1 C:\Users\Rohit\_from ACER\OEMail\Roohit.dbx Infected: Trojan-Downloader.JS.Agent.cye 3 C:\Users\Rohit\_from ACER\OEMail\Roohit.dbx Infected: Trojan-Clicker.HTML.IFrame.abn 1 C:\Users\Rohit\_from ACER\OEMail\Sent Items.dbx Infected: Email-Worm.Win32.Warezov.hb 1 C:\Users\Rohit\_from ACER\OEMail\WonFineDay.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 2 C:\Users\Rohit\_from ACER\Outlook Migration\DBX Files\Hotmail - Inbox.dbx Infected: Trojan.JS.Redirector.b 3 Selected area has been scanned.
Hi,

Most of the items found are in your email boxes.

Unfortunately the scanner can't identify which particular emails are infected, so please delete all the emails you no longer need, empty the trash bins,

delete any from anyone you don't know or any with attachments such as jokes or videos.

then do the following:

  • Go to Start->Run and type in notepad and hit OK.
  • Then copy and paste the content of the following codebox into Notepad:

    @echo off 
    if exist "%temp%\log.txt" del "%temp%\log.txt"
    
    for %%g in ( 
    "C:\Users\Rohit\Downloads\fjse.exe"
    "C:\Users\Rohit\_from ACER\Dnloads\backup-rohitchandra.com-6-27-2006.tar.gz"
    ) do (
    del /a/f/q %%g >nul 2>&1
    if exist %%g echo.%%g>>"%temp%\log.txt"
    )
    if exist "%temp%\log.txt" ( start notepad "%temp%\log.txt"
    ) else echo.Deleted Successfully !!
    pause
    del %0
  • Save the file to your DESKTOP as "find.bat". Make sure to save it with the quotes.
  • Once saved, the icon to click should look like this on your desktop:

    [external image: Posted Image]
  • Double click find.bat. to run it. A small black box should open and close - this is normal.
  • Let me know if it deletes successfully.


NEXT

Post a fresh DDS and Attach.txt and advise how your computer is running now and if there are any outstanding issues.
BTW did yo notice a virus in this file C:\Users\Rohit\_from ACER\Dnloads\backup-rohitchandra.com-6-27-2006.tar.gz (I have this file on another computer too, if so then I ned to delete it there as well.)
Thanks for your help, here is the Attach.txt and DDS.txt (I figured out what DDS is) UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-12-01.01) Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume3 Install Date: 8/2/2008 6:26:23 PM System Uptime: 2/2/2010 10:37:11 AM (0 hours ago) Motherboard: Dell Inc. | | 0U990C Processor: Intel® Core™2 Duo CPU T5750 @ 2.00GHz | Microprocessor | 2000/166mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 221 GiB total, 46.999 GiB free. D: is FIXED (NTFS) - 10 GiB total, 4.917 GiB free. E: is CDROM (CDFS) ==== Disabled Device Manager Items ============= Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: Officejet J6400 series Device ID: ROOT\MULTIFUNCTION\0000 Manufacturer: HP Name: Officejet J6400 series PNP Device ID: ROOT\MULTIFUNCTION\0000 Service: Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: hp LaserJet 2430 Device ID: ROOT\MULTIFUNCTION\0001 Manufacturer: Hewlett-Packard Name: hp LaserJet 2430 PNP Device ID: ROOT\MULTIFUNCTION\0001 Service: Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: HP LaserJet 2100 Series Device ID: ROOT\MULTIFUNCTION\0002 Manufacturer: Hewlett-Packard Name: HP LaserJet 2100 Series PNP Device ID: ROOT\MULTIFUNCTION\0002 Service: Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: Officejet Pro 8500 A909a Device ID: ROOT\MULTIFUNCTION\0003 Manufacturer: HP Name: Officejet Pro 8500 A909a PNP Device ID: ROOT\MULTIFUNCTION\0003 Service: Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: HP LaserJet M2727nf MFP Device ID: ROOT\MULTIFUNCTION\0004 Manufacturer: Hewlett-Packard Name: HP LaserJet M2727nf MFP PNP Device ID: ROOT\MULTIFUNCTION\0004 Service: Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: HP LaserJet P2015 Series Device ID: ROOT\MULTIFUNCTION\0005 Manufacturer: Hewlett-Packard Name: HP LaserJet P2015 Series PNP Device ID: ROOT\MULTIFUNCTION\0005 Service: Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: hp color LaserJet 3700 Device ID: ROOT\MULTIFUNCTION\0006 Manufacturer: Hewlett-Packard Name: hp color LaserJet 3700 PNP Device ID: ROOT\MULTIFUNCTION\0006 Service: Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: HP LaserJet 4100 Series Device ID: ROOT\MULTIFUNCTION\0007 Manufacturer: Hewlett-Packard Name: HP LaserJet 4100 Series PNP Device ID: ROOT\MULTIFUNCTION\0007 Service: Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: HP LaserJet 4100 MFP Device ID: ROOT\MULTIFUNCTION\0008 Manufacturer: Hewlett-Packard Name: HP LaserJet 4100 MFP PNP Device ID: ROOT\MULTIFUNCTION\0008 Service: Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: hp LaserJet 9050 MFP Device ID: ROOT\MULTIFUNCTION\0009 Manufacturer: Hewlett-Packard Name: hp LaserJet 9050 MFP PNP Device ID: ROOT\MULTIFUNCTION\0009 Service: Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: HP LaserJet 4100 Series Device ID: ROOT\MULTIFUNCTION\0010 Manufacturer: Hewlett-Packard Name: HP LaserJet 4100 Series PNP Device ID: ROOT\MULTIFUNCTION\0010 Service: Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: hp LaserJet 4250 Device ID: ROOT\MULTIFUNCTION\0011 Manufacturer: Hewlett-Packard Name: hp LaserJet 4250 PNP Device ID: ROOT\MULTIFUNCTION\0011 Service: Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: Officejet Pro L7700 Device ID: ROOT\MULTIFUNCTION\0012 Manufacturer: HP Name: Officejet Pro L7700 PNP Device ID: ROOT\MULTIFUNCTION\0012 Service: Class GUID: {4d36e979-e325-11ce-bfc1-08002be10318} Description: Officejet J6400 series Device ID: ROOT\PRINTER\0000 Manufacturer: HP Name: Officejet J6400 series PNP Device ID: ROOT\PRINTER\0000 Service: ==== System Restore Points =================== ==== Installed Programs ====================== 32 Bit HP CIO Components Installer 6400_Help Add or Remove Adobe Creative Suite 3 Design Premium Adobe Acrobat 8 Professional Adobe Acrobat 8.1.7 - CPSID_50029 Adobe Acrobat 8.1.7 Professional Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) Adobe Anchor Service CS3 Adobe Asset Services CS3 Adobe Bridge CS3 Adobe Bridge Start Meeting Adobe BridgeTalk Plugin CS3 Adobe Camera Raw 4.0 Adobe CMaps Adobe Color - Photoshop Specific Adobe Color Common Settings Adobe Color EU Extra Settings Adobe Color JA Extra Settings Adobe Color NA Recommended Settings Adobe Creative Suite Adobe Creative Suite 3 Design Premium Adobe Default Language CS3 Adobe Device Central CS3 Adobe Dreamweaver CS3 Adobe ExtendScript Toolkit 2 Adobe Extension Manager CS3 Adobe Flash CS3 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Flash Video Encoder Adobe Fonts All Adobe Help Viewer CS3 Adobe Illustrator CS3 Adobe InDesign CS3 Adobe InDesign CS3 Icon Handler Adobe Linguistics CS3 Adobe MotionPicture Color Files Adobe PDF Library Files Adobe Photoshop CS3 Adobe Premiere Pro 1.5 Adobe Reader 8.1.7 Adobe Setup Adobe SING CS3 Adobe Stock Photos CS3 Adobe SVG Viewer 3.0 Adobe Type Support Adobe Update Manager CS3 Adobe Version Cue CS3 Client Adobe Version Cue CS3 Server {ko_KR} Adobe WAS CS3 Adobe WinSoft Linguistics Plugin Adobe XMP Panels CS3 Advanced Audio FX Engine Advanced Video FX Engine AHV content for Acrobat and Flash AnalogX LinkExaminer AnswerWorks 4.0 Runtime - English AnswerWorks 5.0 English Runtime Apple Application Support Apple Mobile Device Support Apple Software Update AscToTab Audacity 1.3.9 (Unicode) Bluetooth Software Bonjour bpd_scan BPDSoftware BPDSoftware_Ini Browser Address Error Redirector BufferChm Bullzip PDF Printer 6.0.0.744 CamStudio Canon Camera WIA Driver Canon EOS 10D WIA Driver CCleaner Cisco EAP-FAST Module Cisco LEAP Module Cisco PEAP Module Comcast High-Speed Internet Install Wizard Companion.JS v0.5 for Internet Explorer (remove only) Compatibility Pack for the 2007 Office system Conexant HDA D330 MDC V.92 Modem DebugBar v5.2.2 for Internet Explorer (remove only) Dell Getting Started Guide Dell Support Center (Support Software) Dell Touchpad Dell Webcam Center Dell Webcam Manager Dell Wireless WLAN Card Destination Component DeviceDiscovery DeviceManagementQFolder Digital Line Detect DocMgr DocProc DocProcQFolder EDocs eFax Messenger Email Subscriber Pro eSupportQFolder Exterminate3 Fax FileZilla Client [removed] Flash to Video Encoder GnuWin32: Gzip-1.3.12-1 Google Chrome Google Talk (remove only) Google Toolbar for Internet Explorer Google Update Helper GoToAssist 8.0.0.514 GPBaseService GPL Ghostscript Lite 8.63 HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Document Manager 1.0 HP Imaging Device Functions 10.0 HP Officejet J6400 Series HP Photosmart Essential 2.5 HP Smart Web Printing HP Solution Center 10.0 HP Update HP_Network_UserGuide HPProductAssistant Infix 3.32 Intel® Matrix Storage Manager Internet Explorer Developer Toolbar iPhone Configuration Utility iPhoneBrowser iTunes J6400 Java™ 6 Update 5 jEdit 4.3pre16 JGsoft PowerGREP 3 DEMO 3.5.2 Junk Mail filter update LAME v3.98.2 for Audacity Laptop Integrated Webcam Driver (1.04.01.1011) LeechFTP Live! Cam Avatar Creator Live! Cam Avatar v1.0 Malwarebytes' Anti-Malware Media Player Codec Pack 3.9.1 MediaDirect MediaWidget 5.0 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Office Live Add-in 1.3 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Professional Edition 2003 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Works Modem Diagnostic Tool Mozilla Firefox (3.5.7) Mozilla Thunderbird (3.0) Mp3tag v2.42 MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Music, Photos & Videos Launcher NetObjects Fusion Essentials NetWaiting Network Norton Security Suite Notepad++ OCR Software by I.R.I.S. 10.0 OGA Notifier 2.0.0048.0 OutlookAddinSetup PC Matic 1.0.0.0 PC Pitstop Exterminate2 2.0 PC Pitstop Optimize3 3.0 PC Suite for Nokia 3650 PDF Settings PHP Obfuscator Picasa 3 Product Documentation Launcher ProductContext PSSWCORE QuickSet QuickTime Roxio Creator Audio Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Express Labeler 3 Roxio Update Manager Scan Screencaster Plug-in for FF SecondLife (remove only) Skype™ 4.1 SmartWebPrintingOC SolutionCenter SolveigMM AVI Trimmer Status StumbleUpon IE Toolbar TeamViewer 3 TextPad 5 The Regex Coach 0.9.2 Toolbox TortoiseSVN 1.5.7.15182 (32 bit) TrayApp Turbo Tax Audit Support Center 2.0 TurboTax 2008 TurboTax 2008 wcaiper TurboTax 2008 WinPerFedFormset TurboTax 2008 WinPerProgramHelp TurboTax 2008 WinPerReleaseEngine TurboTax 2008 WinPerTaxSupport TurboTax 2008 WinPerUserEducation TurboTax 2008 wrapper TurboTax Deluxe Deduction Maximizer 2006 TurboTax ItsDeductible 2006 TurboTax Premier 2007 UnloadSupport Update for Microsoft .NET Framework 3.5 SP1 (KB963707) VideoToolkit01 WebReg WexTech AnswerWorks Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Mail Windows Live Messenger Windows Live Movie Maker Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Upload Tool Windows Live Writer WinRAR archiver XAMPP 1.7.1 ==== End Of File ===========================
From your Kaspersky scan


C:\Users\Rohit\_from ACER\Dnloads\backup-rohitchandra.com-6-27-2006.tar.gz Infected: Email-Worm.Win32.Nyxem.e 10
C:\Users\Rohit\_from ACER\Dnloads\backup-rohitchandra.com-6-27-2006.tar.gz Infected: Trojan-Spy.HTML.Fraud.f 2

Yes I would remove it from the other computer.

NEXT

Visit ADOBEand download the latest version of Acrobat Reader (version 9.3)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT

[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 18 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 18 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u18 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u18-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT

Do you have the DDS log on your desktop (that was just the Attach.txt) If so, please post it,
Here's the DDS log.

THANKS YOU SO MUCH for your help.


DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 10:51:28.58 on Tue 02/02/2010
Internet Explorer: 8.0.6001.18882
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3061.1727 [GMT -8:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Norton Internet Security *enabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\xampp\apache\bin\httpd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Norton Security Suite\Engine\3.5.2.11\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TeamViewer3\TeamViewer_Service.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Norton Security Suite\Engine\3.5.2.11\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\xampp\apache\bin\httpd.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\DllHost.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Windows\system32\Taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Rohit\Desktop\dds.com
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://roohit.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uInternet Settings,ProxyOverride = cdn
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: StumbleUpon Launcher: {145b29f4-a56b-4b90-bbac-45784ebebbb7} - c:\program files\stumbleupon\StumbleUponIEBar.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Roohit Plg: {5dc83f10-8335-403d-8aa8-66e266a82471} - c:\windows\downloaded program files\RoohitP.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton security suite\engine\3.5.2.11\coIEPlg.dll
BHO: DebugBar BHO: {69fc0024-10eb-480a-bbf2-3bf4e78e17b1} - c:\program files\core services\debugbar\DebugInfoBar.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton security suite\engine\3.5.2.11\IPSBHO.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Companion.JS BHO: {addee521-f1cc-4b89-8c88-b2cf625b9163} - c:\program files\core services\companion.js\CompanionJS.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - Google Dictionary Compression sdch
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: IE Developer Toolbar BHO: {cc7e636d-39aa-49b6-b511-65413da137a1} - c:\program files\microsoft\internet explorer developer toolbar\IEDevToolbar.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton security suite\engine\3.5.2.11\coIEPlg.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: DebugBar: {3e1201f4-1707-409f-bb45-a5f192381da0} - c:\program files\core services\debugbar\DebugToolBar.dll
TB: StumbleUpon Toolbar: {5093eb4c-3e93-40ab-9266-b607ba87bdc8} - c:\program files\stumbleupon\StumbleUponIEBar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: DebugBar: {947e34e9-1d85-43cb-9cbf-5c492118fdd5} - c:\program files\core services\debugbar\DebugInfoBar.dll
EB: IE Developer Toolbar: {a202b231-ef71-4a08-bdb9-4ce5ae8bde0a} - c:\program files\microsoft\internet explorer developer toolbar\IEDevToolbar.dll
EB: {E16DC1FE-7C34-43F2-B754-F3AD12DDF97C} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe
uPolicies-explorer: ExSearchOptions = 105444 (0x19be4)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Hilight This Page - http://roohit.com/site/hilightit.php
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagea…en/preview.html
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send To &Bluetooth - c:\program files\bluetooth\bluetooth software\btsendto_ie_ctx.htm
IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage
IE: {5DC83F10-8335-403d-8AA8-66E266A82471} - http://roohit.com/site/hilightit.php
IE: {0402343A-B530-482b-AA27-A61CEC3E4D2E} - {C30B6FCB-F8B0-4DD4-9207-AA4952BB3F52} - c:\program files\core services\companion.js\CompanionJS.dll
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - {CC962137-2E78-4F94-975E-FC0C07DBD78F} - c:\program files\microsoft\internet explorer developer toolbar\IEDevToolbar.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
Trusted Zone: turbotax.com
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://utilities.pcpitstop.com/Nirvana/controls/PCPitStop.CAB
DPF: {5DC83F10-8335-403D-8AA8-66E266A82471} - hxxp://roohit.com/site/RoohitP.CAB
DPF: {62789780-B744-11D0-986B-00609731A21D} - hxxp://www.modestogov.com/gis/home/maps/mgaxctrl.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstop2.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton security suite\engine\3.5.2.11\CoIEPlg.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\rohit\appdata\roaming\mozilla\firefox\profiles\it3vi0w9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://spreadsheets.google.com/ccc?key=t5SLwKBZJ6b6oy0VS5GOdxg&hl=en#
FF - prefs.js: keyword.URL - hxxp://recovery.alexa.com/helper/?aid=lxX891W9aN00iK&plugin=spkyf-1.4.7&reason=keyword&location=
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll
FF - component: c:\users\rohit\appdata\roaming\mozilla\firefox\profiles\it3vi0w9.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npDimdimControl.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\rohit\appdata\local\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\windows\system32\c2mp\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0305020.00b\SymEFA.sys [2010-1-21 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0305020.00b\BHDrvx86.sys [2010-1-21 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0305020.00b\cchpx86.sys [2010-1-21 482432]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100128.002\IDSvix86.sys [2010-1-29 343088]
R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2008-12-9 24636]
R2 N360;Norton Security Suite;c:\program files\norton security suite\engine\3.5.2.11\ccSvcHst.exe [2010-1-21 117640]
R2 TeamViewer;TeamViewer 3;c:\program files\teamviewer3\TeamViewer_Service.exe [2008-8-5 181544]
R3 dfmirage;dfmirage;c:\windows\system32\drivers\dfmirage.sys [2009-3-28 34128]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-1-21 102448]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2008-8-3 111616]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0305020.00b\symndisv.sys [2010-1-21 48688]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-12-17 135664]
S3 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-8-2 73728]
S3 StumbleUponUpdateService;StumbleUponUpdateService;c:\program files\stumbleupon\StumbleUponUpdateService.exe [2009-6-3 120168]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2010-1-25 85504]

=============== Created Last 30 ================

2010-02-02 00:11:13 0 d-sh–w- C:\$RECYCLE.BIN
2010-02-01 19:10:06 98816 —-a-w- c:\windows\sed.exe
2010-02-01 19:10:06 77312 —-a-w- c:\windows\MBR.exe
2010-02-01 19:10:06 261632 —-a-w- c:\windows\PEV.exe
2010-02-01 19:10:06 161792 —-a-w- c:\windows\SWREG.exe
2010-02-01 19:09:30 0 d—–w- C:\combo
2010-01-28 00:05:41 0 d—–r- c:\program files\Norton Support
2010-01-27 23:59:56 366287134 —-a-w- c:\windows\MEMORY.DMP
2010-01-27 20:43:23 0 d—–w- c:\program files\CCleaner
2010-01-27 19:53:53 0 d-sh–w- c:\windows\system32\%APPDATA%
2010-01-25 23:23:53 0 d—–w- c:\users\rohit\appdata\roaming\PCPitstop
2010-01-21 19:14:38 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-21 19:14:38 107368 —-a-r- c:\windows\system32\GEARAspi.dll
2010-01-21 19:14:36 25648 —-a-r- c:\windows\system32\drivers\SymIMV.sys
2010-01-21 19:14:32 806 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-01-21 19:14:32 7456 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-01-21 19:14:32 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-01-21 19:14:01 0 d—–w- c:\program files\Symantec
2010-01-21 19:07:09 0 d—–w- c:\windows\system32\drivers\N360
2010-01-21 19:07:07 0 d—–w- c:\programdata\Norton
2010-01-21 19:07:07 0 d—–w- c:\program files\Norton Security Suite
2010-01-21 19:03:01 0 d—–w- c:\programdata\NortonInstaller
2010-01-21 19:03:01 0 d—–w- c:\program files\NortonInstaller
2010-01-21 19:00:44 53292 —-a-w- c:\windows\system32\Inv_14137_from_RC_Unlimited.pdf
2010-01-19 02:30:00 31744 —-a-w- c:\windows\system32\CARVER 1800 ESTIMATE REVISED 3 LOWEST.xls
2010-01-18 19:47:20 22528 —-a-w- c:\windows\system32\CARVER 1800 ESTIMATE REVISED 3.xls
2010-01-17 21:43:08 0 d—–w- c:\users\rohit\appdata\roaming\GeoVid
2010-01-17 21:42:30 60416 —-a-w- c:\windows\system32\dsetup.dll
2010-01-17 21:42:23 77824 —-a-w- c:\windows\system32\xvid.ax
2010-01-17 21:42:23 0 d—–w- c:\programdata\GeoVid
2010-01-17 21:42:23 0 d—–w- c:\program files\common files\GeoVid
2010-01-17 21:42:16 0 d—–w- c:\program files\GeoVid
2010-01-13 01:09:29 72704 —-a-w- c:\windows\system32\fontsub.dll
2010-01-13 01:09:29 156672 —-a-w- c:\windows\system32\t2embed.dll
2010-01-12 23:06:59 1715787 —-a-w- c:\windows\system32\BANK FORMS_20100112113713.pdf
2010-01-11 19:14:13 11785 —-a-w- c:\windows\system32\CURRENT LIST AS OF 1_4.pdf
2010-01-10 04:50:22 0 d—–w- c:\windows\system32\custom matrices
2010-01-10 04:50:01 0 d—–w- c:\windows\system32\QuickTime
2010-01-10 04:50:01 0 d—–w- c:\windows\system32\C2MP
2010-01-10 03:35:50 0 d—–w- c:\program files\Veoh Networks
2010-01-09 01:47:34 0 d—–w- c:\users\rohit\appdata\roaming\Malwarebytes
2010-01-09 01:47:28 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-09 01:47:26 0 d—–w- c:\programdata\Malwarebytes
2010-01-09 01:47:25 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-09 01:47:25 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-08 23:47:29 57667 —-a-w- c:\windows\system32\ieuinit.inf
2010-01-08 22:30:30 0 d—–w- c:\program files\MSECache
2010-01-07 18:35:25 0 d—–w- c:\programdata\PCPitstop
2010-01-07 18:35:25 0 d—–w- c:\program files\PCPitstop
2010-01-07 06:52:26 26 —-a-w- c:\windows\Zone.Identifier
2010-01-07 06:52:25 14775 —-a-w- c:\windows\system32\CM email edited 12172009.docx

==================== Find3M ====================

2010-01-21 19:14:33 86016 —-a-w- c:\windows\inf\infstor.dat
2010-01-21 19:14:33 51200 —-a-w- c:\windows\inf\infpub.dat
2010-01-21 19:14:33 143360 —-a-w- c:\windows\inf\infstrng.dat
2010-01-07 03:06:50 87040 —-a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-01-02 06:38:20 916480 —-a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32:33 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32:33 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57:00 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-12-14 19:15:14 2146304 —-a-w- c:\windows\system32\GPhotos.scr
2009-12-02 17:02:50 1632887 —-a-w- c:\windows\system32\ffmpegmt.dll
2009-12-02 16:56:10 4840081 —-a-w- c:\windows\system32\libavcodec.dll
2009-12-01 21:32:43 100232 —-a-w- c:\users\rohit\DimdimSetup.exe
2009-11-24 01:24:48 736 —-a-w- c:\users\rohit\appdata\roaming\wklnhst.dat
2009-11-09 12:31:42 24064 —-a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30:03 30720 —-a-w- c:\windows\system32\httpapi.dll
2009-10-26 16:59:45 665600 —-a-w- c:\windows\inf\drvindex.dat
2008-01-21 02:43:21 174 –sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-08-03 06:39:41 76 –sh–r- c:\windows\CT4CET.bin
2008-08-03 09:18:54 8192 –sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 10:54:15.23 ===============

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI