My computer freezes for no reason on a routine basis. I think there is a virus on my computer. thanks for your help.
Malwarebytes' Anti-Malware 1.44
Database version: 3703
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
2/7/2010 3:26:08 PM
mbam-log-2010-02-07 (15-26-08).txt
Scan type: Quick Scan
Objects scanned: 132537
Time elapsed: 9 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 1/10/2010 12:55:16 PM
System Uptime: 2/7/2010 10:23:17 PM (0 hours ago)
Motherboard: Gateway | |
Processor: Intel® Core™2 CPU T5200 @ 1.60GHz | uFCPGA2 | 1596/533mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 105 GiB total, 33.101 GiB free.
D: is FIXED (FAT32) - 7 GiB total, 3.424 GiB free.
E: is CDROM ()
F: is Removable
G: is FIXED (NTFS) - 298 GiB total, 79.616 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Marvell Yukon 88E8038 PCI-E Fast Ethernet Controller
Device ID: PCI\VEN_11AB&DEV_4352&SUBSYS_0366107B&REV_14\4&9EE4DCE&0&00E0
Manufacturer: Marvell
Name: Marvell Yukon 88E8038 PCI-E Fast Ethernet Controller
PNP Device ID: PCI\VEN_11AB&DEV_4352&SUBSYS_0366107B&REV_14\4&9EE4DCE&0&00E0
Service: yukonwxp
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Intel® PRO/Wireless 3945ABG Network Connection
Device ID: PCI\VEN_8086&DEV_4222&SUBSYS_10008086&REV_02\4&115ADF0F&0&00E1
Manufacturer: Intel Corporation
Name: Intel® PRO/Wireless 3945ABG Network Connection
PNP Device ID: PCI\VEN_8086&DEV_4222&SUBSYS_10008086&REV_02\4&115ADF0F&0&00E1
Service: w39n51
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: PANTECH USB Modem WWAN Driver
Device ID: USB\VID_106C&PID_3711&MI_F0\6&14D2AB6D&0&00F0
Manufacturer: PANTECH CO., LTD
Name: PANTECH USB Modem WWAN Driver #2
PNP Device ID: USB\VID_106C&PID_3711&MI_F0\6&14D2AB6D&0&00F0
Service: PTDMWWAN
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\6603FDE7E0B803
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\6603FDE7E0B803
Service: NIC1394
==== System Restore Points ===================
RP1: 1/10/2010 12:55:19 PM - System Checkpoint
RP2: 1/10/2010 11:25:18 AM - Installed VZAccess Manager.
RP3: 1/10/2010 12:01:51 PM - Removed Napster
RP4: 1/10/2010 12:56:03 PM - Software Distribution Service 3.0
RP5: 1/10/2010 2:25:48 PM - Installed DirectX
RP6: 1/10/2010 3:26:39 PM - Software Distribution Service 3.0
RP7: 1/10/2010 3:55:16 PM - Software Distribution Service 3.0
RP8: 1/10/2010 4:05:32 PM - Software Distribution Service 3.0
RP9: 1/10/2010 4:23:08 PM - Software Distribution Service 3.0
RP10: 1/11/2010 7:19:28 PM - System Checkpoint
RP11: 1/11/2010 9:44:39 PM - Installed Windows Media Player 10
RP12: 1/11/2010 9:49:46 PM - Software Distribution Service 3.0
RP13: 1/11/2010 10:22:19 PM - Software Distribution Service 3.0
RP14: 1/12/2010 11:12:39 AM - Software Distribution Service 3.0
RP15: 1/12/2010 11:51:56 AM - Installed Java™ 6 Update 17
RP16: 1/12/2010 11:52:27 AM - Installed MSN Toolbar Setup
RP17: 1/13/2010 10:06:51 AM - Software Distribution Service 3.0
RP18: 1/13/2010 1:31:32 PM - Installed Microsoft Office Enterprise 2007
RP19: 1/13/2010 1:45:18 PM - Printer Driver Send To Microsoft OneNote Driver Installed
RP20: 1/13/2010 3:06:15 PM - Installed iTunes
RP21: 1/14/2010 5:38:56 PM - System Checkpoint
RP22: 1/16/2010 10:50:09 AM - System Checkpoint
RP23: 1/18/2010 10:23:23 AM - System Checkpoint
RP24: 1/22/2010 2:57:42 PM - Software Distribution Service 3.0
RP25: 2/5/2010 2:19:11 PM - System Checkpoint
==== Installed Programs ======================
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0
Adobe Shockwave Player 11.5
Apple Application Support
Apple Mobile Device Support
Apple Software Update
BitComet 1.17
Bonjour
CCleaner
DVD Solution
ERUNT 1.1j
gtw_logo
High Definition Audio Driver Package - KB888111
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB976098-v2)
Intel Matrix Storage Manager
Intel® Graphics Media Accelerator Driver
Intel® PROSet/Wireless Software
iTunes
J2SE Runtime Environment 5.0 Update 2
Java™ 6 Update 17
LimeWire PRO 5.3.6
Malwarebytes' Anti-Malware
mCore
mDriver
mDrWiFi
mHelp
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Default Manager
Microsoft Digital Image Library 9 - Blocker
Microsoft Digital Image Starter Edition 2006
Microsoft Digital Image Starter Edition 2006 Editor
Microsoft Digital Image Starter Edition 2006 Library
Microsoft Money 2006
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Software Update for Web Folders (English) 12
Microsoft UI Engine
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Works
mIRC
mIWA
mLogView
mMHouse
Motorola SM56 Data Fax Modem
mPfMgr
mPfWiz
mProSafe
MSN Toolbar
MSN Toolbar Platform
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser (KB933579)
mWlsSafe
mXML
mZConfig
Napster Burn Engine
Norton 360
PANTECH PC USB Modem Software
PeerBlock 1.0.0 (r181)
Power2Go 4.0
PowerDVD
QuickTime
RealPlayer Basic
Recovery Software Suite Gateway
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB913433)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB976325)
SigmaTel Audio
Sonic Encoders
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515/xx12 drivers.
TIPCI
UM150 Firmware Updates
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
Viewpoint Media Player
VZAccess Manager
WebFldrs XP
Winamp
Winamp Application Detect
Windows Genuine Advantage Validation Tool
Windows Imaging Component
Windows Internet Explorer 8
Windows Live ID Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
WinRAR archiver
Xvid 1.2.2 final uninstall
==== Event Viewer Messages From Past Week ========
2/7/2010 6:46:12 PM, error: System Error [1003] - Error code 0000004e, parameter1 00000007, parameter2 00002a03, parameter3 00000002, parameter4 00000000.
2/7/2010 4:55:44 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the N360 service.
2/7/2010 4:55:14 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the PolicyAgent service.
2/7/2010 4:54:48 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the JavaQuickStarterService service.
2/7/2010 10:26:32 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the iPod Service service to connect.
2/7/2010 10:26:32 PM, error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/7/2010 10:26:32 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
2/3/2010 9:38:43 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: IDSxpx86
==== End Of File ===========================
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 22:32:16.34 on Sun 02/07/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.414 [GMT -5:00]
AV: Norton 360 *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: Norton 360 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner.Brandon\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Bar = hxxp://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MX6930
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/first_usage&s=1zyx0oR3NubSyGmPUbYMTFRIUAU
mSearchAssistant = hxxp://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MX6930
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.8.0.41\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.8.0.41\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.8.0.41\coIEPlg.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
StartupFolder: c:\docume~1\owner~1.bra\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: {4D4CEAC8-D2B9-4815-BC9F-36BF5DA35F2A} = 66.174.95.44 66.174.92.14
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.8.0.41\CoIEPlg.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0308000.029\SymEFA.sys [2010-2-2 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0308000.029\BHDrvx86.sys [2010-2-2 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0308000.029\cchpx86.sys [2010-2-2 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100204.001\IDSXpx86.sys [2010-2-6 329592]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 N360;Norton 360;c:\program files\norton 360\engine\3.8.0.41\ccSvcHst.exe [2010-2-2 117640]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-8-7 242048]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-8-18 1529728]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-1-9 102448]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100206.035\NAVENG.SYS [2010-2-6 84912]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100206.035\NAVEX15.SYS [2010-2-6 1324720]
R3 PTDMBus;PANTECH USB Modem Composite Device Driver ;c:\windows\system32\drivers\PTDMBus.sys [2010-1-10 55056]
R3 PTDMMdm;PANTECH USB Modem Drivers ;c:\windows\system32\drivers\PTDMMdm.sys [2010-1-10 160912]
R3 PTDMVsp;PANTECH USB Modem Serial Port ;c:\windows\system32\drivers\PTDMVsp.sys [2010-1-10 160912]
R3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\verizo~1\vzacce~1\SMSIVZAM5.SYS [2009-5-25 32408]
S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2010-1-10 14424]
S3 PTDMWFLT;PTDMWWAN Filter Driver;c:\windows\system32\drivers\PTDMWFLT.sys [2010-1-10 13456]
S3 PTDMWWAN;PANTECH USB Modem WWAN Driver;c:\windows\system32\drivers\PTDMWWAN.sys [2010-1-10 118800]
=============== Created Last 30 ================
2010-02-07 15:13 –d—– c:\docume~1\owner~1.bra\applic~1\Malwarebytes
2010-02-07 15:13 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-07 15:13 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-02-07 15:13 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-02-07 15:13 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-05 09:47 –d—– c:\program files\iPod
2010-02-05 09:47 –d—– c:\program files\iTunes
2010-02-01 16:35 –d—– c:\windows\system32\Adobe
2010-01-27 11:26 3,247 a——- c:\windows\system32\wbem\Outlook_01ca9f6d8b2664a2.mof
2010-01-14 10:02 –d-h— c:\windows\PIF
2010-01-13 15:06 –d—– c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-13 15:05 –d—– c:\program files\Bonjour
2010-01-13 13:45 32,592 a——- c:\windows\system32\msonpmon.dll
2010-01-13 13:34 –d—– c:\program files\Microsoft Visual Studio 8
2010-01-13 10:04 –d—– c:\program files\mIRC
2010-01-13 10:04 –d—– c:\docume~1\owner~1.bra\applic~1\mIRC
2010-01-13 09:42 471,552 -c—— c:\windows\system32\dllcache\aclayers.dll
2010-01-12 11:56 –d—– c:\program files\Microsoft
2010-01-12 11:56 –d—– c:\program files\MSN Toolbar
2010-01-12 11:53 –d—– c:\program files\MSN Toolbar Installer
2010-01-12 11:44 –d—– c:\docume~1\owner~1.bra\applic~1\LimeWire
2010-01-12 11:43 411,368 a——- c:\windows\system32\deploytk.dll
2010-01-12 11:43 73,728 a——- c:\windows\system32\javacpl.cpl
2010-01-12 11:41 –d—– c:\program files\LimeWire
2010-01-12 11:13 –d—– c:\windows\ie8updates
2010-01-12 11:02 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat
2010-01-12 11:01 594,432 -c—— c:\windows\system32\dllcache\msfeeds.dll
2010-01-12 11:01 55,296 -c—— c:\windows\system32\dllcache\msfeedsbs.dll
2010-01-12 11:01 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll
2010-01-12 11:01 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll
2010-01-12 11:01 1,985,536 -c—— c:\windows\system32\dllcache\iertutil.dll
2010-01-12 11:01 11,070,464 -c—— c:\windows\system32\dllcache\ieframe.dll
2010-01-11 22:02 819,200 a——- c:\windows\system32\xvidcore.dll
2010-01-11 22:02 180,224 a——- c:\windows\system32\xvidvfw.dll
2010-01-11 22:02 77,824 a——- c:\windows\system32\xvid.ax
2010-01-11 22:02 –d—– c:\program files\Xvid
2010-01-11 21:52 –d—– c:\program files\Windows Media Connect 2
2010-01-11 10:25 –d—– c:\windows\system32\LogFiles
2010-01-10 23:34 –d—– c:\program files\PeerBlock
2010-01-10 20:47 –d—– c:\docume~1\alluse~1\applic~1\Symantec
2010-01-10 18:55 –dsh— c:\documents and settings\owner.brandon\IECompatCache
2010-01-10 18:55 –dsh— c:\documents and settings\owner.brandon\PrivacIE
2010-01-10 16:49 –d—– c:\windows\system32\scripting
2010-01-10 16:49 –d—– c:\windows\l2schemas
2010-01-10 16:49 –d—– c:\windows\system32\en
2010-01-10 16:48 –d—– c:\windows\system32\bits
2010-01-10 16:39 –d—– c:\windows\network diagnostic
2010-01-10 16:10 –d—– c:\windows\system32\XPSViewer
2010-01-10 16:10 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll
2010-01-10 16:10 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-01-10 16:10 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll
2010-01-10 16:10 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-01-10 16:10 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2010-01-10 16:10 575,488 ——– c:\windows\system32\xpsshhdr.dll
2010-01-10 16:10 117,760 ——– c:\windows\system32\prntvpt.dll
2010-01-10 16:10 –d—– C:\de196db147f4fc6b34378c875a82bf
2010-01-10 16:06 –d—– c:\program files\MSXML 6.0
2010-01-10 16:00 –dsh— c:\documents and settings\owner.brandon\IETldCache
2010-01-10 15:57 -cd-h— c:\windows\ie8
2010-01-10 15:32 –d—– c:\windows\ServicePackFiles
2010-01-10 15:28 –d—– c:\program files\MSXML 4.0
2010-01-10 14:48 25,471 ——– c:\windows\system32\drivers\watv10nt.sys
2010-01-10 14:48 22,271 ——– c:\windows\system32\drivers\watv06nt.sys
2010-01-10 14:48 11,935 ——– c:\windows\system32\drivers\wadv11nt.sys
2010-01-10 14:48 11,871 ——– c:\windows\system32\drivers\wadv09nt.sys
2010-01-10 14:48 11,807 ——– c:\windows\system32\drivers\wadv07nt.sys
2010-01-10 14:48 11,295 ——– c:\windows\system32\drivers\wadv08nt.sys
2010-01-10 14:48 404,990 ——– c:\windows\system32\drivers\slntamr.sys
2010-01-10 14:48 129,535 ——– c:\windows\system32\drivers\slnt7554.sys
2010-01-10 14:48 95,424 ——– c:\windows\system32\drivers\slnthal.sys
2010-01-10 14:48 13,240 ——– c:\windows\system32\drivers\slwdmsup.sys
2010-01-10 14:48 166,912 ——– c:\windows\system32\drivers\s3gnbm.sys
2010-01-10 14:47 13,776 ——– c:\windows\system32\drivers\recagent.sys
2010-01-10 14:47 1,897,408 ——– c:\windows\system32\drivers\nv4_mini.sys
2010-01-10 14:47 180,360 ——– c:\windows\system32\drivers\ntmtlfax.sys
2010-01-10 14:47 67,866 ——– c:\windows\system32\drivers\netwlan5.img
2010-01-10 14:47 452,736 ——– c:\windows\system32\drivers\mtxparhm.sys
2010-01-10 14:47 1,309,184 ——– c:\windows\system32\drivers\mtlstrm.sys
2010-01-10 14:47 126,686 ——– c:\windows\system32\drivers\mtlmnt5.sys
2010-01-10 14:47 11,868 ——– c:\windows\system32\drivers\mdmxsdk.sys
2010-01-10 14:46 1,041,536 ——– c:\windows\system32\drivers\hsfdpsp2.sys
2010-01-10 14:46 685,056 ——– c:\windows\system32\drivers\hsfcxts2.sys
2010-01-10 14:46 220,032 ——– c:\windows\system32\drivers\hsfbs2s2.sys
2010-01-10 14:46 129,045 ——– c:\windows\system32\drivers\cxthsfs2.cty
2010-01-10 14:25 3,426,072 a——- c:\windows\system32\d3dx9_32.dll
2010-01-10 14:25 2,414,360 a——- c:\windows\system32\d3dx9_31.dll
2010-01-10 14:25 –d—– c:\windows\Logs
2010-01-10 14:25 –d—– c:\program files\Winamp Detect
2010-01-10 14:24 129,520 ——– c:\windows\system32\pxafs.dll
2010-01-10 13:30 272,128 -c—— c:\windows\system32\dllcache\bthport.sys
2010-01-10 13:30 272,128 ——– c:\windows\system32\drivers\bthport.sys
2010-01-10 13:27 153,088 -c—— c:\windows\system32\dllcache\triedit.dll
2010-01-10 13:23 128,512 -c—— c:\windows\system32\dllcache\dhtmled.ocx
2010-01-10 13:21 203,136 -c—— c:\windows\system32\dllcache\rmcast.sys
2010-01-10 13:21 455,296 -c—— c:\windows\system32\dllcache\mrxsmb.sys
2010-01-10 13:21 333,952 -c—— c:\windows\system32\dllcache\srv.sys
2010-01-10 13:21 331,776 -c—— c:\windows\system32\dllcache\msadce.dll
2010-01-10 13:15 1,315,328 -c—— c:\windows\system32\dllcache\msoe.dll
2010-01-10 13:15 –d—– C:\Downloads
2010-01-10 13:14 691,712 -c—— c:\windows\system32\dllcache\inetcomm.dll
2010-01-10 13:14 –d—– c:\program files\BitComet
2010-01-10 13:10 2,066,432 -c—— c:\windows\system32\dllcache\mstscax.dll
2010-01-10 13:07 337,408 -c—— c:\windows\system32\dllcache\netapi32.dll
2010-01-10 13:07 1,172,480 -c—— c:\windows\system32\dllcache\msxml3.dll
2010-01-10 12:57 1,206,508 -c—— c:\windows\system32\dllcache\sysmain.sdb
2010-01-10 12:57 2,560 ——– c:\windows\system32\xpsp4res.dll
2010-01-10 12:57 215,552 -c—— c:\windows\system32\dllcache\wordpad.exe
2010-01-10 12:56 –d—– c:\windows\system32\PreInstall
2010-01-10 12:55 –d—– c:\documents and settings\owner.brandon\WINDOWS
2010-01-10 12:55 –d—– c:\documents and settings\Owner.Brandon
2010-01-10 12:55 –d—– c:\docume~1\owner~1.bra\applic~1\You've Got Pictures Screensaver
2010-01-10 12:55 –d—– c:\docume~1\owner~1.bra\applic~1\Intel
2010-01-10 12:37 107,368 a—-r– c:\windows\system32\GEARAspi.dll
2010-01-10 12:37 26,600 a—-r– c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-10 12:37 36,400 a—-r– c:\windows\system32\drivers\SymIM.sys
2010-01-10 12:37 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2010-01-10 12:37 60,808 a——- c:\windows\system32\S32EVNT1.DLL
2010-01-10 12:37 7,456 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2010-01-10 12:37 806 a——- c:\windows\system32\drivers\SYMEVENT.INF
2010-01-10 12:37 –d—– c:\program files\Symantec
2010-01-10 12:37 –d—– c:\program files\common files\Symantec Shared
2010-01-10 12:36 –d—– c:\windows\system32\drivers\N360
2010-01-10 12:36 –d—– c:\program files\Norton 360
2010-01-10 12:36 –d—– c:\docume~1\alluse~1\applic~1\Norton
2010-01-10 12:36 –d—– c:\program files\NortonInstaller
2010-01-10 12:36 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller
2010-01-10 12:20 –d—– c:\documents and settings\all users\Symantec Temporary Files
2010-01-10 12:16 –dsh— c:\documents and settings\owner.brandon\UserData
2010-01-10 11:49 –d—– c:\docume~1\owner~1.bra\applic~1\McAfee.com Personal Firewall
2010-01-10 11:36 2 a——- c:\windows\msoffice.ini
2010-01-10 11:32 –d—– c:\program files\CCleaner
2010-01-10 11:25 –d—– c:\docume~1\owner~1.bra\applic~1\Verizon Wireless
2010-01-10 11:25 –d—– c:\docume~1\alluse~1\applic~1\WEngineLite
2010-01-10 11:25 –d—– c:\docume~1\alluse~1\applic~1\Verizon Wireless
2010-01-10 11:24 160,912 a——- c:\windows\system32\drivers\PTDMVsp.sys
2010-01-10 11:24 118,800 a——- c:\windows\system32\drivers\PTDMWWAN.sys
2010-01-10 11:24 13,456 a——- c:\windows\system32\drivers\PTDMWFLT.sys
2010-01-10 11:24 6,656 a——- c:\windows\system32\ptdmcit.dll
2010-01-10 11:24 160,912 a——- c:\windows\system32\drivers\PTDMMdm.sys
2010-01-10 11:24 55,056 a——- c:\windows\system32\drivers\PTDMBus.sys
2010-01-10 11:24 95,248 a——- c:\windows\system32\PTDMWmcp64.dll
2010-01-10 11:16 –d—– c:\windows\system32\SoftwareDistribution
2010-01-10 11:13 –d—– c:\docume~1\owner~1.bra\applic~1\Smith Micro
2010-01-10 11:11 319,456 a——- c:\windows\system32\DIFxAPI.dll
2010-01-10 11:11 88,592 a——- c:\windows\system32\PTDMWmcp.dll
2010-01-10 11:11 –d—– c:\program files\PANTECH
2010-01-10 11:10 –d—– c:\program files\Verizon Wireless
2010-01-10 05:14 8,192 a——- c:\windows\REGLOCS.OLD
2010-01-10 05:08 0 a——- c:\windows\system32\Gateway_MX6930_Rev.1_T336AP1014440.MRK
2010-01-10 05:08 333 a——- c:\windows\system32\$ncsp$.inf
2010-01-10 05:07 139,264 a——- c:\windows\system32\igfxres.dll
2010-01-10 05:05 2,752 a——- c:\windows\system32\Status.MPF
2010-01-10 05:00 21,275 a——- c:\windows\system32\drivers\AegisP.sys
2010-01-10 04:59 –d—– c:\program files\McAfee
2010-01-10 04:59 –d—– c:\docume~1\alluse~1\applic~1\McAfee.com Personal Firewall
2010-01-10 04:58 –d—– c:\docume~1\alluse~1\applic~1\McAfee.com
2010-01-10 04:56 23,552 a——- c:\windows\system32\jesterss.dll
2010-01-10 04:56 1,150 a——- c:\windows\system32\gtw.ico
2010-01-10 04:56 1,239,209 a——- c:\windows\system32\gtw_logo.scr
2010-01-10 04:56 –d—– c:\program files\gtw_logo
2010-01-10 04:53 –d—– c:\windows\tiinst
2010-01-10 04:51 –d—– c:\program files\Motorola
2010-01-10 04:50 1,179,784 a——- c:\windows\system32\drivers\sthda.sys
2010-01-10 04:50 217,088 a——- c:\windows\system32\stacapi.dll
2010-01-10 04:50 –d—– c:\program files\SigmaTel
2010-01-10 04:50 67,072 a——- c:\windows\POWERCFG.EXE
2010-01-10 04:50 –d—– c:\program files\Microsoft Money 2006
2010-01-10 04:48 –d—– c:\program files\MSN Encarta Plus
2010-01-10 04:48 –d—– c:\program files\common files\Nullsoft
2010-01-10 04:48 –d—– c:\program files\common files\Real
2010-01-10 04:48 –d—– c:\docume~1\alluse~1\applic~1\Viewpoint
2010-01-10 04:48 –d—– c:\program files\Viewpoint
2010-01-10 04:48 –d—– c:\docume~1\alluse~1\applic~1\Pure Networks
2010-01-10 04:48 –d—– c:\program files\Pure Networks
2010-01-10 04:47 1,189 a—h— C:\IPH.PH
2010-01-10 04:47 –d—– c:\program files\common files\AOL
2010-01-10 04:47 –d—– c:\docume~1\alluse~1\applic~1\Napster
2010-01-10 04:47 –d—– c:\program files\Napster
2010-01-10 04:46 17,992 a——- c:\windows\system32\drivers\bcm42rly.sys
2010-01-10 04:46 –d—– C:\ses2_client_bin_2_8_13g
2010-01-10 04:46 4 a——- c:\windows\Pix11.dat
2010-01-10 04:45 –d—– c:\program files\Microsoft Digital Image 2006
2010-01-10 04:45 89,088 a—-r– c:\windows\system32\atl71.dll
2010-01-10 04:44 –d—– c:\docume~1\alluse~1\applic~1\WildTangent
2010-01-10 04:44 –d—– c:\program files\WildTangent
2010-01-10 04:43 –d—– c:\program files\Gateway Games
2010-01-10 04:42 –d—– c:\program files\Synaptics
2010-01-10 04:42 –d—– c:\program files\BigFix
2010-01-10 04:41 –d—– c:\windows\SHELLNEW
2010-01-10 04:40 51,656 a——- c:\windows\system32\OEMLOGO.bmp
2010-01-10 04:40 2 a——- C:\AUDIT_INSTALL_IN_PROGRESS
2010-01-10 04:34 20,480 a——- c:\windows\system32\Marker32.exe
2010-01-10 04:32 0 a——- C:\REQUEST_OEMRESET_ENDUSER
2010-01-10 04:32 2 —shr– C:\USER
2010-01-09 21:36 –d—– c:\windows\creator
2010-01-09 21:34 244,480 a——- c:\windows\system32\drivers\yk51x86.sys
2010-01-09 21:34 –d—– c:\windows\SMINST
2010-01-09 21:34 –d—– c:\windows\I386
2010-01-09 21:34 13,824 a——- c:\windows\system32\wowfaxui.dll
2010-01-09 21:34 3,200 a——- c:\windows\system32\wowfax.dll
2010-01-09 21:34 23,552 a——- c:\windows\system32\wdmaud.drv
2010-01-09 21:34 49,211 a——- c:\windows\system32\usrvpa.dll
2010-01-09 21:34 45,116 a——- c:\windows\system32\usrvoica.dll
2010-01-09 21:34 49,209 a——- c:\windows\system32\usrv80a.dll
2010-01-09 21:34 102,457 a——- c:\windows\system32\usrv42a.dll
2010-01-09 21:32 70,656 a——- c:\windows\system32\sprio600.dll
2010-01-09 21:31 12,288 a——- c:\windows\system32\drivers\tunmp.sys
2010-01-09 21:25 64 a——- C:\MOVE_RECOVERY
2010-01-09 21:25 –d—– C:\My Backup – 10-01-09 0725PM
==================== Find3M ====================
2010-01-10 16:57 86,811 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2010-01-10 04:48 8,552 a——- c:\windows\system32\drivers\asctrm.sys
2009-12-21 14:14 916,480 a——- c:\windows\system32\wininet.dll
2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll
============= FINISH: 22:33:06.79 ===============
Due, in part, to the large numbers of logs being posted, there are four things that you need to be aware of.
1) If you have already posted this log at another forum, you need to post here that you have done so and this topic will be closed.
Multiple posting not only ties up valuable resources, but could also result is some unpleasant side-effects for your system if you follow two sets of instructions at the same time.
If, during research, an identical log is identified at another forum, this thread will be closed.
2) If you don't post a meaningful reply to any of my posts within five days, this thread will be closed. Due to limited free time I can only have so many open threads at any one time and if yours isn't active, somebody else's will be.
If, by omission, the thread hasn't be closed after five days and you post, it will just serve as a reminder to me to close it.
Please note that "I just dropped in to say Hi!" isn't a meaningful reply!
3) Malware removal is a tricky business, and malware writers don't tend to worry about the damage their creations do, so it is advisable to back-up all important files BEFORE we start. Although most cases have a successful conclusion, on occasion things don't go according to plan and it is better to be prepared for the worst.
4) Back-ups can get lost or damaged, so make two if the files are that important to you!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Pay a visit to the
ESET Online Scanner .
Click the ESET Online Scanner button, read the info in the new window, check the appropriate box and click Start . Accept the ActiveX download, and allow it to install. Once this has been completed, you will see the Computer Scan settings page - ensure that you uncheck the "Remove found threats " box and then click Start . The virus signature database will now need to be downloaded, so don't forget to instruct your firewall to permit it if it asks. The above will take a little time, so now is a good time to fire up the kettle and open the biccies. Once the scan has completed you will be shown the results - assuming that the scanner has found anything. Click List of found threats and then Export to text file… and save the log somewhere convenient. You can then close out the scanner - don't bother uninstalling it as you may need to use it again. Please post the contents of this file in your next reply, or let me know that nothing was identified.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Download
Sec-Info2.zip from
here and save it to your Desktop. You will need to extract the file.
Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish
You should now see a folder with a file in it - double click
Sec-info2.vbs to run it.
Once you have been informed that the script has completed, a text file called
Sec-Info.txt should be created in the same folder - you may need to wait a couple of seconds for it to appear..
Please copy and paste the contents of the text file into your next reply and then you can delete both of the folders and their contents.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Download
RootRepeal from one of the locations below and save it to your Desktop:
Location 1
Location 2
Location 3
Double click RootRepeal.exe to fire up the tool and OK any Windows confirmation if necessary. Ensure that the Report Tab is selected at the bottom. Click the Scan button, check ALL the boxes in the window that appears and then click OK . Check the box next to your main hard drive - usually C: and click OK Put the kettle on and perhaps open a packet of biscuits - the scan will take some time. Once the scan has completed a Notepad window will open with the results in. These results will also be saved to the root of your main drive as \RootRepeal report date time .txt
Let me have a copy of the contents in your next reply.
hi I ran the ESET scan and my computer froze while the scan was running…I'm trying another scan currently.
The reason that I use the ESET scan is that it can be configured to leave anything it identifies alone. There is a possibility with some scanners that they will attempt removal of infected files and this can in the worse of cases render a PC unbootable.
I would prefer it if you just let me know when a problem occurs and i'll decide on a fresh course of action.
i ran a second ESET scan and the computer froze again…not too sure what to do at this point. My computer runs really slow and I'm not sure if its from a virus or what. It also still freezes for no reason usually after its idle for a while.
any help would be great
thanks
T
Run the rest of the tools and post accordingly.
sec info log:
Script run: 2/11/2010 5:05:23 PM
~~~~~~~~~~~~~~~~~~~~~~~~
Company Name: Symantec Corporation
AV Name: Norton 360
Version Number: 3.5.2.11
On-Access Scanning Enabled: Yes
Product up-to-date: Yes
~~~~~~~~~~~~~~~~~~~~~~~~
Company Name: McAfee
AV Name:
Version Number:
On-Access Scanning Enabled: No
Product up-to-date: Yes
~~~~~~~~~~~~~~~~~~~~~~~~
Company Name: McAfee
Firewall Name:
Version Number:
Enabled: No
~~~~~~~~~~~~~~~~~~~~~~~~
Company Name: Symantec Corporation
Firewall Name: Norton 360
Version Number: 3.5.2.11
Enabled: Yes
~~~~~~~~~~~~~~~~~~~~~~~~
The Windows Firewall is disabled.
~~~~~~~~~~~~~~~~~~~~~~~~
The Security Center Anti-Virus Alerts are enabled.
The Security Center Firewall Alerts are enabled.
~~~~~~~~~~~~~~~~~~~~~~~~
Number of Restore Points found: 25
~~~~~~~~~~~~~~~~~~~~~~~~
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2010/02/11 17:10
Program Version: Version 1.3.5.0
Windows Version: Windows XP Media Center Edition SP3
==================================================
Drivers
——————-
Name: dump_iaStor.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys
Address: 0x9F7E7000 Size: 876544 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0x9D929000 Size: 49152 File Visible: No Signed: -
Status: -
Name: SYMEFA.SYS
Image Path: SYMEFA.SYS
Address: 0xF714F000 Size: 323584 File Visible: No Signed: -
Status: -
Hidden/Locked Files
——————-
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
SSDT
——————-
#: 012 Function Name: NtAlertResumeThread
Status: Hooked by "" at address 0x849bb1a8
#: 013 Function Name: NtAlertThread
Status: Hooked by "" at address 0x84afc1a8
#: 017 Function Name: NtAllocateVirtualMemory
Status: Hooked by "" at address 0x85738438
#: 019 Function Name: NtAssignProcessToJobObject
Status: Hooked by "" at address 0x84b64388
#: 031 Function Name: NtConnectPort
Status: Hooked by "" at address 0x857cd960
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xaa72b130
#: 043 Function Name: NtCreateMutant
Status: Hooked by "" at address 0x84a8a008
#: 052 Function Name: NtCreateSymbolicLinkObject
Status: Hooked by "" at address 0x84af8210
#: 053 Function Name: NtCreateThread
Status: Hooked by "" at address 0x84aa70e0
#: 057 Function Name: NtDebugActiveProcess
Status: Hooked by "" at address 0x84ad2530
#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xaa72b3b0
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xaa72b910
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "" at address 0x84a06c60
#: 083 Function Name: NtFreeVirtualMemory
Status: Hooked by "" at address 0x849df078
#: 089 Function Name: NtImpersonateAnonymousToken
Status: Hooked by "" at address 0x849d31a8
#: 091 Function Name: NtImpersonateThread
Status: Hooked by "" at address 0x849ba1a8
#: 097 Function Name: NtLoadDriver
Status: Hooked by "" at address 0x857cdc50
#: 108 Function Name: NtMapViewOfSection
Status: Hooked by "" at address 0x849d1228
#: 114 Function Name: NtOpenEvent
Status: Hooked by "" at address 0x84a1c108
#: 122 Function Name: NtOpenProcess
Status: Hooked by "" at address 0x84a06f80
#: 123 Function Name: NtOpenProcessToken
Status: Hooked by "" at address 0x84ad61a8
#: 125 Function Name: NtOpenSection
Status: Hooked by "" at address 0x849a4108
#: 128 Function Name: NtOpenThread
Status: Hooked by "" at address 0x84a06db0
#: 137 Function Name: NtProtectVirtualMemory
Status: Hooked by "" at address 0x84b63110
#: 206 Function Name: NtResumeThread
Status: Hooked by "" at address 0x84a73108
#: 213 Function Name: NtSetContextThread
Status: Hooked by "" at address 0x84b65108
#: 228 Function Name: NtSetInformationProcess
Status: Hooked by "" at address 0x849d0278
#: 240 Function Name: NtSetSystemInformation
Status: Hooked by "" at address 0x84acd388
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xaa72bb60
#: 253 Function Name: NtSuspendProcess
Status: Hooked by "" at address 0x849a5108
#: 254 Function Name: NtSuspendThread
Status: Hooked by "" at address 0x856ee470
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "" at address 0x84a87108
#: 258 Function Name: NtTerminateThread
Status: Hooked by "" at address 0x84b61108
#: 267 Function Name: NtUnmapViewOfSection
Status: Hooked by "" at address 0x856be108
#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "" at address 0x84a2e280
Shadow SSDT
——————-
#: 307 Function Name: NtUserAttachThreadInput
Status: Hooked by "" at address 0x857906c8
#: 383 Function Name: NtUserGetAsyncKeyState
Status: Hooked by "" at address 0x85789498
#: 414 Function Name: NtUserGetKeyboardState
Status: Hooked by "" at address 0x857892a8
#: 416 Function Name: NtUserGetKeyState
Status: Hooked by "" at address 0x85793a90
#: 428 Function Name: NtUserGetRawInputData
Status: Hooked by "" at address 0x857313e0
#: 460 Function Name: NtUserMessageCall
Status: Hooked by "" at address 0x85712298
#: 475 Function Name: NtUserPostMessage
Status: Hooked by "" at address 0x85729420
#: 476 Function Name: NtUserPostThreadMessage
Status: Hooked by "" at address 0x857293d8
#: 549 Function Name: NtUserSetWindowsHookEx
Status: Hooked by "" at address 0x8572e3e8
#: 552 Function Name: NtUserSetWinEventHook
Status: Hooked by "" at address 0x85783618
==EOF==
Take a trip to this webpage for download links and instructions for running
Combofix by sUBs : http://www.bleepingcomputer.com/combofix/how-to-use-combofix
*
Please be aware that this tool may require the PC to be rebooted so close any programs you have open before you start. When CF has finished, it will produce a log - C:\ComboFix.txt - copy and paste it into your next reply. Post a fresh DDS log as well. Let me know how the PC is behaving. * There are two points to note from the instructions page:
1) The Recovery Console.
It is recommended that you install this as, in certain circumstances, it may be the difference between a successful repair and a reformat. If you are uncertain as to whether or not you already have the Recovery Console installed, simply run CF and it will prompt you if it does not detect it.
CF will complete some, but not all, of it's removal tasks without the installation of the Console so, should you choose not to allow the installation, you may not get the results you hoped for.
2) Disabling your Anti-Virus.
CF has been the victim of false-positive detections on occasion and a resident AV may incorrectly identify and delete part of the tool which won't do it much good. If you don't disable your AV, you may not get the results you hoped for!
ComboFix 10-02-12.01 - Owner 02/14/2010 20:33:28.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.500 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: Norton 360 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-3720901572-3328388745-1107845492-500
c:\windows\ModemLog_PANTECH USB Modem .txt
.
((((((((((((((((((((((((( Files Created from 2010-01-15 to 2010-02-15 )))))))))))))))))))))))))))))))
.
2010-02-13 14:39 . 2010-02-03 09:00 1324720 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\NAVEX15.SYS
2010-02-13 14:39 . 2010-01-09 09:27 1647984 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\NAVEX32A.DLL
2010-02-13 14:39 . 2010-02-03 09:00 84912 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\NAVENG.SYS
2010-02-13 14:39 . 2010-01-09 09:27 371248 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\EECTRL.SYS
2010-02-13 14:39 . 2010-01-09 09:27 2747440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\CCERASER.DLL
2010-02-13 14:39 . 2010-01-09 09:27 259440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\ECMSVR32.DLL
2010-02-13 14:39 . 2010-01-09 09:27 177520 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\NAVENG32.DLL
2010-02-13 14:39 . 2010-01-09 09:27 102448 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\ERASER.SYS
2010-02-12 21:38 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100210.001\IDSvix86.sys
2010-02-12 21:38 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100210.001\IDSXpx86.sys
2010-02-12 21:38 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100210.001\Scxpx86.dll
2010-02-12 21:38 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100210.001\IDSxpx86.dll
2010-02-12 21:38 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100210.001\IDSviA64.sys
2010-02-08 21:32 . 2010-02-08 21:32 ——– d—–w- c:\program files\ESET
2010-02-07 20:13 . 2010-02-07 20:13 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\Malwarebytes
2010-02-07 20:13 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-07 20:13 . 2010-02-07 20:13 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-07 20:13 . 2010-02-07 20:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-07 20:13 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-07 20:06 . 2010-02-07 20:06 ——– d—–w- c:\program files\ERUNT
2010-02-06 23:57 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSXpx86.sys
2010-02-06 23:57 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\Scxpx86.dll
2010-02-06 23:57 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSxpx86.dll
2010-02-06 23:57 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSvix86.sys
2010-02-06 23:57 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSviA64.sys
2010-02-05 14:47 . 2010-02-05 14:47 ——– d—–w- c:\program files\iPod
2010-02-05 14:47 . 2010-02-05 14:49 ——– d—–w- c:\program files\iTunes
2010-02-05 14:31 . 2010-02-05 14:31 72488 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-01 21:35 . 2010-02-01 21:37 ——– d—–w- c:\windows\system32\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 14:47 . 2010-01-13 20:02 ——– d—–w- c:\program files\Common Files\Apple
2010-02-04 16:30 . 2010-01-13 20:07 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\Apple Computer
2010-01-27 23:06 . 2010-01-10 18:14 ——– d—–w- c:\program files\BitComet
2010-01-27 18:38 . 2010-01-10 19:24 ——– d—–w- c:\program files\Winamp
2010-01-27 18:38 . 2010-01-10 19:25 ——– d—–w- c:\program files\Winamp Detect
2010-01-18 14:35 . 2010-01-11 04:34 ——– d—–w- c:\program files\PeerBlock
2010-01-18 14:35 . 2010-01-12 16:44 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\LimeWire
2010-01-15 17:23 . 2010-01-10 19:24 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\Winamp
2010-01-14 02:45 . 2010-01-14 02:45 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\AdobeUM
2010-01-13 21:54 . 2010-01-13 15:04 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\mIRC
2010-01-13 21:26 . 2010-01-13 15:04 ——– d—–w- c:\program files\mIRC
2010-01-13 21:23 . 2006-06-19 04:25 72392 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-13 20:06 . 2010-01-13 20:06 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-13 20:06 . 2010-01-13 20:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-01-13 20:05 . 2010-01-13 20:05 ——– d—–w- c:\program files\Bonjour
2010-01-13 20:05 . 2010-01-13 20:04 ——– d—–w- c:\program files\QuickTime
2010-01-13 20:03 . 2010-01-13 20:03 ——– d—–w- c:\program files\Apple Software Update
2010-01-13 20:02 . 2010-01-13 20:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-01-13 18:51 . 2010-01-13 18:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-13 18:49 . 2010-01-13 18:34 ——– d—–w- c:\program files\Microsoft Visual Studio 8
2010-01-13 18:42 . 2010-01-10 09:49 ——– d—–w- c:\program files\Microsoft Works
2010-01-13 18:42 . 2010-01-10 21:10 ——– d—–w- c:\program files\MSBuild
2010-01-13 18:40 . 2010-01-13 18:40 ——– d—–w- c:\program files\Microsoft.NET
2010-01-12 16:56 . 2010-01-12 16:53 ——– d—–w- c:\program files\MSN Toolbar Installer
2010-01-12 16:56 . 2010-01-12 16:56 ——– d—–w- c:\program files\Microsoft
2010-01-12 16:56 . 2010-01-12 16:56 ——– d—–w- c:\program files\MSN Toolbar
2010-01-12 16:52 . 2010-01-10 09:43 ——– d—–w- c:\program files\Java
2010-01-12 16:49 . 2010-01-12 16:49 152576 —-a-w- c:\documents and settings\Owner.Brandon\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-12 16:49 . 2010-01-12 16:49 79488 —-a-w- c:\documents and settings\Owner.Brandon\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-12 16:43 . 2010-01-12 16:43 152576 —-a-w- c:\documents and settings\Owner.Brandon\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2010-01-12 03:02 . 2010-01-12 03:02 ——– d—–w- c:\program files\Xvid
2010-01-12 02:52 . 2010-01-12 02:52 ——– d—–w- c:\program files\Windows Media Connect 2
2010-01-11 15:30 . 2010-01-10 09:38 ——– d—–w- c:\program files\Google
2010-01-11 01:47 . 2010-01-11 01:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-01-10 21:57 . 2006-06-17 09:39 86811 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-01-10 21:10 . 2010-01-10 21:10 ——– d—–w- c:\program files\Reference Assemblies
2010-01-10 21:06 . 2010-01-10 21:06 ——– d—–w- c:\program files\MSXML 6.0
2010-01-10 20:28 . 2010-01-10 20:28 ——– d—–w- c:\program files\MSXML 4.0
2010-01-10 18:26 . 2010-01-10 17:37 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-01-10 17:37 . 2010-01-10 17:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-01-10 17:37 . 2010-01-10 17:37 806 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-01-10 17:37 . 2010-01-10 17:37 7456 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-01-10 17:37 . 2010-01-10 17:37 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2010-01-10 17:37 . 2010-01-10 17:37 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-01-10 17:37 . 2010-01-10 17:37 ——– d—–w- c:\program files\Symantec
2010-01-10 17:37 . 2010-01-10 17:37 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-10 17:37 . 2010-01-10 17:37 36400 —-a-r- c:\windows\system32\drivers\SymIM.sys
2010-01-10 17:36 . 2010-01-10 17:36 1291104 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2010-01-10 17:36 . 2010-01-10 17:36 136840 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2010-01-10 17:36 . 2010-01-10 17:37 107368 —-a-r- c:\windows\system32\GEARAspi.dll
2010-01-10 17:36 . 2010-01-10 17:36 771440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2010-01-10 17:36 . 2010-01-10 17:36 ——– d—–w- c:\program files\Norton 360
2010-01-10 17:36 . 2010-01-10 17:36 ——– d—–w- c:\program files\Windows Sidebar
2010-01-10 17:36 . 2010-01-10 17:36 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-01-10 17:36 . 2010-01-10 17:36 ——– d—–w- c:\program files\NortonInstaller
2010-01-10 17:04 . 2010-01-10 09:43 ——– d—–w- c:\program files\Gateway Games
2010-01-10 17:01 . 2010-01-10 09:47 ——– d—–w- c:\program files\Napster
2010-01-10 17:01 . 2010-01-10 09:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Napster
2010-01-10 17:00 . 2010-01-10 09:44 ——– d—–w- c:\documents and settings\All Users\Application Data\WildTangent
2010-01-10 17:00 . 2010-01-10 09:44 ——– d—–w- c:\program files\WildTangent
2010-01-10 16:55 . 2010-01-10 09:42 ——– d—–w- c:\program files\BigFix
2010-01-10 16:49 . 2010-01-10 16:49 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\McAfee.com Personal Firewall
2010-01-10 16:38 . 2010-01-10 09:48 ——– d—–w- c:\program files\Pure Networks
2010-01-10 16:36 . 2010-01-10 09:47 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2010-01-10 16:36 . 2010-01-10 09:47 ——– d—–w- c:\program files\Common Files\AOL
2010-01-10 16:32 . 2010-01-10 16:32 ——– d—–w- c:\program files\CCleaner
2010-01-10 16:28 . 2010-01-10 16:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Verizon Wireless
2010-01-10 16:25 . 2010-01-10 16:25 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\Verizon Wireless
2010-01-10 16:25 . 2010-01-10 16:25 ——– d—–w- c:\documents and settings\All Users\Application Data\WEngineLite
2010-01-10 16:25 . 2010-01-10 16:10 ——– d—–w- c:\program files\Verizon Wireless
2010-01-10 16:24 . 2010-01-10 16:24 25214 —-a-r- c:\documents and settings\Owner.Brandon\Application Data\Microsoft\Installer\{E296E0ED-038F-4A5A-9513-642F2FA17A59}\ARPPRODUCTICON.exe
2010-01-10 16:23 . 2010-01-10 16:23 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\InstallShield
2010-01-10 16:23 . 2010-01-10 16:15 32262536 —-a-w- c:\documents and settings\Owner.Brandon\Application Data\Smith Micro\Updates\VZAM_7.2.1_2420b_Pantech_UM150.exe
2010-01-10 16:15 . 2010-01-10 16:13 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\Smith Micro
2010-01-10 16:11 . 2010-01-10 16:11 ——– d—–w- c:\program files\PANTECH
2010-01-10 10:00 . 2010-01-10 17:55 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\Intel
2010-01-10 10:00 . 2010-01-10 10:00 ——– d—–w- c:\documents and settings\Administrator\Application Data\Intel
2010-01-10 10:00 . 2010-01-10 10:00 21275 —-a-w- c:\windows\system32\drivers\AegisP.sys
2010-01-10 10:00 . 2010-01-10 10:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Intel
2010-01-10 09:59 . 2010-01-10 09:46 ——– d—–w- c:\program files\Intel
2010-01-10 09:59 . 2010-01-10 09:59 ——– d—–w- c:\program files\McAfee
2010-01-10 09:59 . 2010-01-10 09:59 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2010-01-10 09:59 . 2010-01-10 09:59 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com Personal Firewall
2010-01-10 09:58 . 2010-01-10 09:58 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com
2010-01-10 09:56 . 2010-01-10 09:56 ——– d—–w- c:\program files\gtw_logo
2010-01-10 09:51 . 2010-01-10 09:51 ——– d—–w- c:\program files\Motorola
2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\program files\MSN Encarta Plus
2010-01-10 09:48 . 2010-01-10 17:55 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\You've Got Pictures Screensaver
2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\documents and settings\Administrator\Application Data\You've Got Pictures Screensaver
2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\program files\Common Files\Nullsoft
2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\documents and settings\All Users\Application Data\QuickTime
2010-01-10 09:48 . 2010-01-10 09:48 8552 —-a-w- c:\windows\system32\drivers\asctrm.sys
2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\program files\Common Files\Real
2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\program files\Real
2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\program files\Viewpoint
2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Pure Networks
2010-01-10 09:47 . 2010-01-10 09:47 335 —-a-w- c:\windows\nsreg.dat
2010-01-10 09:47 . 2010-01-10 09:47 ——– d—–w- c:\program files\Common Files\Roxio Shared
2010-01-10 09:47 . 2010-01-10 09:40 ——– d—–w- c:\program files\Common Files\InstallShield
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 688218]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 139264]
"SigmatelSysTrayApp"="stsystra.exe" [2005-12-27 413696]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7518:TCP"= 7518:TCP:BitComet 7518 TCP
"7518:UDP"= 7518:UDP:BitComet 7518 UDP
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0308000.029\SymEFA.sys [2/2/2010 8:32 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0308000.029\BHDrvx86.sys [2/2/2010 8:32 PM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0308000.029\cchpx86.sys [2/2/2010 8:32 PM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100210.001\IDSXpx86.sys [2/12/2010 4:38 PM 329592]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe [2/2/2010 8:31 PM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [1/9/2010 4:27 AM 102448]
R3 PTDMBus;PANTECH USB Modem Composite Device Driver ;c:\windows\system32\drivers\PTDMBus.sys [1/10/2010 11:24 AM 55056]
R3 PTDMMdm;PANTECH USB Modem Drivers ;c:\windows\system32\drivers\PTDMMdm.sys [1/10/2010 11:24 AM 160912]
R3 PTDMVsp;PANTECH USB Modem Serial Port ;c:\windows\system32\drivers\PTDMVsp.sys [1/10/2010 11:24 AM 160912]
S3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [1/10/2010 11:34 PM 14424]
S3 PTDMWFLT;PTDMWWAN Filter Driver;c:\windows\system32\drivers\PTDMWFLT.sys [1/10/2010 11:24 AM 13456]
S3 PTDMWWAN;PANTECH USB Modem WWAN Driver;c:\windows\system32\drivers\PTDMWWAN.sys [1/10/2010 11:24 AM 118800]
S3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS [5/25/2009 3:43 PM 32408]
.
Contents of the 'Scheduled Tasks' folder
2010-02-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/first_usage&s=1zyx0oR3NubSyGmPUbYMTFRIUAU
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.
**************************************************************************
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.8.0.41\diMaster.dll\" /prefetch:1"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(3400)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\stsystra.exe
c:\windows\eHome\ehmsas.exe
c:\windows\system32\igfxsrvc.exe
.
**************************************************************************
.
Completion time: 2010-02-14 20:50:17 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-15 01:50
Pre-Run: 35,041,906,688 bytes free
Post-Run: 35,290,120,192 bytes free
- - End Of File - - FD232A29DF1F3E8F44A488B1093DAE60
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 20:54:38.90 on Sun 02/14/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.549 [GMT -5:00]
AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: Norton 360 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Owner.Brandon\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/first_usage&s=1zyx0oR3NubSyGmPUbYMTFRIUAU
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.8.0.41\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.8.0.41\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.8.0.41\coIEPlg.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.8.0.41\CoIEPlg.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0308000.029\SymEFA.sys [2010-2-2 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0308000.029\BHDrvx86.sys [2010-2-2 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0308000.029\cchpx86.sys [2010-2-2 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100210.001\IDSXpx86.sys [2010-2-12 329592]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 N360;Norton 360;c:\program files\norton 360\engine\3.8.0.41\ccSvcHst.exe [2010-2-2 117640]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-8-7 242048]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-8-18 1529728]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-1-9 102448]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100212.039\NAVENG.SYS [2010-2-13 84912]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100212.039\NAVEX15.SYS [2010-2-13 1324720]
R3 PTDMBus;PANTECH USB Modem Composite Device Driver ;c:\windows\system32\drivers\PTDMBus.sys [2010-1-10 55056]
R3 PTDMMdm;PANTECH USB Modem Drivers ;c:\windows\system32\drivers\PTDMMdm.sys [2010-1-10 160912]
R3 PTDMVsp;PANTECH USB Modem Serial Port ;c:\windows\system32\drivers\PTDMVsp.sys [2010-1-10 160912]
S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2010-1-10 14424]
S3 PTDMWFLT;PTDMWWAN Filter Driver;c:\windows\system32\drivers\PTDMWFLT.sys [2010-1-10 13456]
S3 PTDMWWAN;PANTECH USB Modem WWAN Driver;c:\windows\system32\drivers\PTDMWWAN.sys [2010-1-10 118800]
S3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\verizo~1\vzacce~1\SMSIVZAM5.SYS [2009-5-25 32408]
=============== Created Last 30 ================
2010-02-14 20:31 261,632 a——- c:\windows\PEV.exe
2010-02-14 20:31 161,792 a——- c:\windows\SWREG.exe
2010-02-14 20:31 98,816 a——- c:\windows\sed.exe
2010-02-14 20:31 77,312 a——- c:\windows\MBR.exe
2010-02-14 20:31 –d—– C:\ComboFix
2010-02-12 00:06 1,374 a——- c:\windows\imsins.BAK
2010-02-08 16:32 –d—– c:\program files\ESET
2010-02-07 15:13 –d—– c:\docume~1\owner~1.bra\applic~1\Malwarebytes
2010-02-07 15:13 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-07 15:13 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-02-07 15:13 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-02-07 15:13 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-05 09:47 –d—– c:\program files\iPod
2010-02-05 09:47 –d—– c:\program files\iTunes
2010-02-01 16:35 –d—– c:\windows\system32\Adobe
2010-01-27 11:26 3,247 a——- c:\windows\system32\wbem\Outlook_01ca9f6d8b2664a2.mof
==================== Find3M ====================
2010-01-10 16:57 86,811 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2010-01-10 12:37 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2010-01-10 12:37 60,808 a——- c:\windows\system32\S32EVNT1.DLL
2010-01-10 12:37 7,456 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2010-01-10 12:37 806 a——- c:\windows\system32\drivers\SYMEVENT.INF
2010-01-10 12:37 36,400 a—-r– c:\windows\system32\drivers\SymIM.sys
2010-01-10 12:37 26,600 a—-r– c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-10 12:36 107,368 a—-r– c:\windows\system32\GEARAspi.dll
2010-01-10 05:00 21,275 a——- c:\windows\system32\drivers\AegisP.sys
2010-01-10 04:48 8,552 a——- c:\windows\system32\drivers\asctrm.sys
2009-12-31 11:50 353,792 a——- c:\windows\system32\drivers\srv.sys
2009-12-21 14:14 916,480 ——– c:\windows\system32\wininet.dll
2009-12-16 13:43 343,040 a——- c:\windows\system32\mspaint.exe
2009-12-14 02:08 33,280 a——- c:\windows\system32\csrsrv.dll
2009-12-08 14:26 2,145,280 ——– c:\windows\system32\ntoskrnl.exe
2009-12-08 13:43 2,023,936 ——– c:\windows\system32\ntkrnlpa.exe
2009-11-27 12:11 1,291,776 a——- c:\windows\system32\quartz.dll
2009-11-27 12:11 17,920 a——- c:\windows\system32\msyuv.dll
2009-11-27 11:07 28,672 a——- c:\windows\system32\msvidc32.dll
2009-11-27 11:07 8,704 a——- c:\windows\system32\tsbyuv.dll
2009-11-27 11:07 84,992 a——- c:\windows\system32\avifil32.dll
2009-11-27 11:07 48,128 a——- c:\windows\system32\iyuv_32.dll
2009-11-27 11:07 11,264 a——- c:\windows\system32\msrle32.dll
2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll
============= FINISH: 20:54:56.54 ===============
the compuer seems to be running better now. no freezing at this point.
Good to hear.
I suggest you follow the instructions
here and run the McAfee removal tool as their security products have a habit of leaving crud behind and there's no reason to clutter up your hard drive.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Your version of Sun Java needs updating:
1) Go here and click on the
Windows XP/Vista/2000/2003 Offline link in the
Windows section near the top and save it to your Desktop.
2) Download
JavaRa from
here and save it to your Desktop.
You will need to extract the file(s):
Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish
***Please close any instances of Internet Explorer before continuing!***
Double-click JavaRa.exe to begin. Pick your preferred language from the drop-down menu and click Select . Click on Remove Older Versions to remove older version of Java - obvious really, isn't it! Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK . A logfile will pop up. Please save it to a convenient location, just in case you have any problems with Java afterwards.
3) Run the installer that you downloaded earlier.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
The following steps will serve as a spring clean for your PC. Not all of them will be of benefit to your PC as this is a general post, but the overall effect should be positive.
1) Go to
Start > Control Panel > Add/Remove Programs and remove any programs that you no longer use and then reboot your PC.
2) Download
TFC by OldTimer from here and save it to your Desktop.
You will need to close all open programs and save any work as TFC will require a reboot. Double-click TFC.exe to run it. (Note: If you are using Vista, right-click the file and select Run As Administrator from the menu that appears). Click the Start button to begin. Depending on how often you clean temp files, execution time could be anywhere from a few seconds to a minute or two - just sit back and enjoy the view. Once it has finished it should reboot your PC all by itself. If it does not, please manually reboot. Once rebooted your PC will run like a Cray supercomputer, or at least have less junk on the hard drive - OT's not a miracle worker you know!
Please note that this tool will empty the Recycle Bin as part of it's actions. If you have anything in there that you haven't finished with, move it first.
3) Double click
My Computer .
Right click the disc drive you wish to check.
Click
Properties .
In the
Properties dialog box, click the
Tools Tab.
Under
Error-checking , click the
Check Now button.
In the "
Check Disc Local Disk (C:) " dialog box, check both
Automatically fix file system errors and
Scan for and attempt recovery of bad sectors , and then click
Start .
This will look for and attempt to repair any errors that your hard drive has.
4) Defragment your hard drive. A tutorial for disc defragmentation is available
here.
I happen to prefer a third-party defrag tool to the one that Windows offers. You can read about it, and find a linky,
here - it's free too!
Let me know how the PC is behaving after the above.
so i went through all the steps you listed and the computer froze when trying to run the defragmenter!! I'm trying to defrag again just to see if it was a one time thing or not….
i tried a second defrag with auslogics and the cpu froze again. then i tried a defrag with the windows defragmenter and the computer froze! Not sure what's going on….
It could be one of the processes running on your machine is interfering. Are you able to boot into Safe Mode and run the defrag tool in there?
If the computer is running, shut down Windows, and then turn off the power. Wait 30 seconds, and then turn the computer on. Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again. Ensure that the Safe Mode option is selected. Press Enter . The computer then begins to start in Safe mode. Login on your usual account.