This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

i think i have a virus...

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer freezes for no reason on a routine basis. I think there is a virus on my computer. thanks for your help. Malwarebytes' Anti-Malware 1.44 Database version: 3703 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 2/7/2010 3:26:08 PM mbam-log-2010-02-07 (15-26-08).txt Scan type: Quick Scan Objects scanned: 132537 Time elapsed: 9 minute(s), 45 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 1/10/2010 12:55:16 PM System Uptime: 2/7/2010 10:23:17 PM (0 hours ago) Motherboard: Gateway | | Processor: Intel® Core™2 CPU T5200 @ 1.60GHz | uFCPGA2 | 1596/533mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 105 GiB total, 33.101 GiB free. D: is FIXED (FAT32) - 7 GiB total, 3.424 GiB free. E: is CDROM () F: is Removable G: is FIXED (NTFS) - 298 GiB total, 79.616 GiB free. ==== Disabled Device Manager Items ============= Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Marvell Yukon 88E8038 PCI-E Fast Ethernet Controller Device ID: PCI\VEN_11AB&DEV_4352&SUBSYS_0366107B&REV_14\4&9EE4DCE&0&00E0 Manufacturer: Marvell Name: Marvell Yukon 88E8038 PCI-E Fast Ethernet Controller PNP Device ID: PCI\VEN_11AB&DEV_4352&SUBSYS_0366107B&REV_14\4&9EE4DCE&0&00E0 Service: yukonwxp Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Intel® PRO/Wireless 3945ABG Network Connection Device ID: PCI\VEN_8086&DEV_4222&SUBSYS_10008086&REV_02\4&115ADF0F&0&00E1 Manufacturer: Intel Corporation Name: Intel® PRO/Wireless 3945ABG Network Connection PNP Device ID: PCI\VEN_8086&DEV_4222&SUBSYS_10008086&REV_02\4&115ADF0F&0&00E1 Service: w39n51 Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: PANTECH USB Modem WWAN Driver Device ID: USB\VID_106C&PID_3711&MI_F0\6&14D2AB6D&0&00F0 Manufacturer: PANTECH CO., LTD Name: PANTECH USB Modem WWAN Driver #2 PNP Device ID: USB\VID_106C&PID_3711&MI_F0\6&14D2AB6D&0&00F0 Service: PTDMWWAN Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: 1394 Net Adapter Device ID: V1394\NIC1394\6603FDE7E0B803 Manufacturer: Microsoft Name: 1394 Net Adapter PNP Device ID: V1394\NIC1394\6603FDE7E0B803 Service: NIC1394 ==== System Restore Points =================== RP1: 1/10/2010 12:55:19 PM - System Checkpoint RP2: 1/10/2010 11:25:18 AM - Installed VZAccess Manager. RP3: 1/10/2010 12:01:51 PM - Removed Napster RP4: 1/10/2010 12:56:03 PM - Software Distribution Service 3.0 RP5: 1/10/2010 2:25:48 PM - Installed DirectX RP6: 1/10/2010 3:26:39 PM - Software Distribution Service 3.0 RP7: 1/10/2010 3:55:16 PM - Software Distribution Service 3.0 RP8: 1/10/2010 4:05:32 PM - Software Distribution Service 3.0 RP9: 1/10/2010 4:23:08 PM - Software Distribution Service 3.0 RP10: 1/11/2010 7:19:28 PM - System Checkpoint RP11: 1/11/2010 9:44:39 PM - Installed Windows Media Player 10 RP12: 1/11/2010 9:49:46 PM - Software Distribution Service 3.0 RP13: 1/11/2010 10:22:19 PM - Software Distribution Service 3.0 RP14: 1/12/2010 11:12:39 AM - Software Distribution Service 3.0 RP15: 1/12/2010 11:51:56 AM - Installed Java™ 6 Update 17 RP16: 1/12/2010 11:52:27 AM - Installed MSN Toolbar Setup RP17: 1/13/2010 10:06:51 AM - Software Distribution Service 3.0 RP18: 1/13/2010 1:31:32 PM - Installed Microsoft Office Enterprise 2007 RP19: 1/13/2010 1:45:18 PM - Printer Driver Send To Microsoft OneNote Driver Installed RP20: 1/13/2010 3:06:15 PM - Installed iTunes RP21: 1/14/2010 5:38:56 PM - System Checkpoint RP22: 1/16/2010 10:50:09 AM - System Checkpoint RP23: 1/18/2010 10:23:23 AM - System Checkpoint RP24: 1/22/2010 2:57:42 PM - Software Distribution Service 3.0 RP25: 2/5/2010 2:19:11 PM - System Checkpoint ==== Installed Programs ====================== Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 7.0 Adobe Shockwave Player 11.5 Apple Application Support Apple Mobile Device Support Apple Software Update BitComet 1.17 Bonjour CCleaner DVD Solution ERUNT 1.1j gtw_logo High Definition Audio Driver Package - KB888111 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB976098-v2) Intel Matrix Storage Manager Intel® Graphics Media Accelerator Driver Intel® PROSet/Wireless Software iTunes J2SE Runtime Environment 5.0 Update 2 Java™ 6 Update 17 LimeWire PRO 5.3.6 Malwarebytes' Anti-Malware mCore mDriver mDrWiFi mHelp Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Default Manager Microsoft Digital Image Library 9 - Blocker Microsoft Digital Image Starter Edition 2006 Microsoft Digital Image Starter Edition 2006 Editor Microsoft Digital Image Starter Edition 2006 Library Microsoft Money 2006 Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Search Enhancement Pack Microsoft Software Update for Web Folders (English) 12 Microsoft UI Engine Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Works mIRC mIWA mLogView mMHouse Motorola SM56 Data Fax Modem mPfMgr mPfWiz mProSafe MSN Toolbar MSN Toolbar Platform MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6.0 Parser (KB933579) mWlsSafe mXML mZConfig Napster Burn Engine Norton 360 PANTECH PC USB Modem Software PeerBlock 1.0.0 (r181) Power2Go 4.0 PowerDVD QuickTime RealPlayer Basic Recovery Software Suite Gateway Security Update for Step By Step Interactive Training (KB898458) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB913433) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371-v2) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB976325) SigmaTel Audio Sonic Encoders Synaptics Pointing Device Driver Texas Instruments PCIxx21/x515/xx12 drivers. TIPCI UM150 Firmware Updates Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Media Player 10 (KB910393) Update for Windows Media Player 10 (KB913800) Update for Windows Media Player 10 (KB926251) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update Rollup 2 for Windows XP Media Center Edition 2005 Viewpoint Media Player VZAccess Manager WebFldrs XP Winamp Winamp Application Detect Windows Genuine Advantage Validation Tool Windows Imaging Component Windows Internet Explorer 8 Windows Live ID Sign-in Assistant Windows Media Format 11 runtime Windows Media Player 11 Windows XP Media Center Edition 2005 KB925766 Windows XP Media Center Edition 2005 KB973768 Windows XP Service Pack 3 WinRAR archiver Xvid 1.2.2 final uninstall ==== Event Viewer Messages From Past Week ======== 2/7/2010 6:46:12 PM, error: System Error [1003] - Error code 0000004e, parameter1 00000007, parameter2 00002a03, parameter3 00000002, parameter4 00000000. 2/7/2010 4:55:44 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the N360 service. 2/7/2010 4:55:14 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the PolicyAgent service. 2/7/2010 4:54:48 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the JavaQuickStarterService service. 2/7/2010 10:26:32 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the iPod Service service to connect. 2/7/2010 10:26:32 PM, error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 2/7/2010 10:26:32 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE} 2/3/2010 9:38:43 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: IDSxpx86 ==== End Of File =========================== DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 22:32:16.34 on Sun 02/07/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.414 [GMT -5:00] AV: Norton 360 *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} FW: Norton 360 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe svchost.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe C:\WINDOWS\stsystra.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Owner.Brandon\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearch Bar = hxxp://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MX6930 uStart Page = hxxp://www.google.com/ uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/first_usage&s=1zyx0oR3NubSyGmPUbYMTFRIUAU mSearchAssistant = hxxp://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MX6930 BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.8.0.41\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.8.0.41\IPSBHO.DLL BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.8.0.41\coIEPlg.dll TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k StartupFolder: c:\docume~1\owner~1.bra\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: {4D4CEAC8-D2B9-4815-BC9F-36BF5DA35F2A} = 66.174.95.44 66.174.92.14 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.8.0.41\CoIEPlg.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL ============= SERVICES / DRIVERS =============== R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0308000.029\SymEFA.sys [2010-2-2 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0308000.029\BHDrvx86.sys [2010-2-2 259632] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0308000.029\cchpx86.sys [2010-2-2 482432] R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100204.001\IDSXpx86.sys [2010-2-6 329592] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 N360;Norton 360;c:\program files\norton 360\engine\3.8.0.41\ccSvcHst.exe [2010-2-2 117640] R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-8-7 242048] R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-8-18 1529728] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-1-9 102448] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100206.035\NAVENG.SYS [2010-2-6 84912] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100206.035\NAVEX15.SYS [2010-2-6 1324720] R3 PTDMBus;PANTECH USB Modem Composite Device Driver ;c:\windows\system32\drivers\PTDMBus.sys [2010-1-10 55056] R3 PTDMMdm;PANTECH USB Modem Drivers ;c:\windows\system32\drivers\PTDMMdm.sys [2010-1-10 160912] R3 PTDMVsp;PANTECH USB Modem Serial Port ;c:\windows\system32\drivers\PTDMVsp.sys [2010-1-10 160912] R3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\verizo~1\vzacce~1\SMSIVZAM5.SYS [2009-5-25 32408] S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2010-1-10 14424] S3 PTDMWFLT;PTDMWWAN Filter Driver;c:\windows\system32\drivers\PTDMWFLT.sys [2010-1-10 13456] S3 PTDMWWAN;PANTECH USB Modem WWAN Driver;c:\windows\system32\drivers\PTDMWWAN.sys [2010-1-10 118800] =============== Created Last 30 ================ 2010-02-07 15:13 –d—– c:\docume~1\owner~1.bra\applic~1\Malwarebytes 2010-02-07 15:13 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-07 15:13 19,160 a——- c:\windows\system32\drivers\mbam.sys 2010-02-07 15:13 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-02-07 15:13 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-02-05 09:47 –d—– c:\program files\iPod 2010-02-05 09:47 –d—– c:\program files\iTunes 2010-02-01 16:35 –d—– c:\windows\system32\Adobe 2010-01-27 11:26 3,247 a——- c:\windows\system32\wbem\Outlook_01ca9f6d8b2664a2.mof 2010-01-14 10:02 –d-h— c:\windows\PIF 2010-01-13 15:06 –d—– c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2010-01-13 15:05 –d—– c:\program files\Bonjour 2010-01-13 13:45 32,592 a——- c:\windows\system32\msonpmon.dll 2010-01-13 13:34 –d—– c:\program files\Microsoft Visual Studio 8 2010-01-13 10:04 –d—– c:\program files\mIRC 2010-01-13 10:04 –d—– c:\docume~1\owner~1.bra\applic~1\mIRC 2010-01-13 09:42 471,552 -c—— c:\windows\system32\dllcache\aclayers.dll 2010-01-12 11:56 –d—– c:\program files\Microsoft 2010-01-12 11:56 –d—– c:\program files\MSN Toolbar 2010-01-12 11:53 –d—– c:\program files\MSN Toolbar Installer 2010-01-12 11:44 –d—– c:\docume~1\owner~1.bra\applic~1\LimeWire 2010-01-12 11:43 411,368 a——- c:\windows\system32\deploytk.dll 2010-01-12 11:43 73,728 a——- c:\windows\system32\javacpl.cpl 2010-01-12 11:41 –d—– c:\program files\LimeWire 2010-01-12 11:13 –d—– c:\windows\ie8updates 2010-01-12 11:02 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat 2010-01-12 11:01 594,432 -c—— c:\windows\system32\dllcache\msfeeds.dll 2010-01-12 11:01 55,296 -c—— c:\windows\system32\dllcache\msfeedsbs.dll 2010-01-12 11:01 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll 2010-01-12 11:01 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll 2010-01-12 11:01 1,985,536 -c—— c:\windows\system32\dllcache\iertutil.dll 2010-01-12 11:01 11,070,464 -c—— c:\windows\system32\dllcache\ieframe.dll 2010-01-11 22:02 819,200 a——- c:\windows\system32\xvidcore.dll 2010-01-11 22:02 180,224 a——- c:\windows\system32\xvidvfw.dll 2010-01-11 22:02 77,824 a——- c:\windows\system32\xvid.ax 2010-01-11 22:02 –d—– c:\program files\Xvid 2010-01-11 21:52 –d—– c:\program files\Windows Media Connect 2 2010-01-11 10:25 –d—– c:\windows\system32\LogFiles 2010-01-10 23:34 –d—– c:\program files\PeerBlock 2010-01-10 20:47 –d—– c:\docume~1\alluse~1\applic~1\Symantec 2010-01-10 18:55 –dsh— c:\documents and settings\owner.brandon\IECompatCache 2010-01-10 18:55 –dsh— c:\documents and settings\owner.brandon\PrivacIE 2010-01-10 16:49 –d—– c:\windows\system32\scripting 2010-01-10 16:49 –d—– c:\windows\l2schemas 2010-01-10 16:49 –d—– c:\windows\system32\en 2010-01-10 16:48 –d—– c:\windows\system32\bits 2010-01-10 16:39 –d—– c:\windows\network diagnostic 2010-01-10 16:10 –d—– c:\windows\system32\XPSViewer 2010-01-10 16:10 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2010-01-10 16:10 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2010-01-10 16:10 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2010-01-10 16:10 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2010-01-10 16:10 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2010-01-10 16:10 575,488 ——– c:\windows\system32\xpsshhdr.dll 2010-01-10 16:10 117,760 ——– c:\windows\system32\prntvpt.dll 2010-01-10 16:10 –d—– C:\de196db147f4fc6b34378c875a82bf 2010-01-10 16:06 –d—– c:\program files\MSXML 6.0 2010-01-10 16:00 –dsh— c:\documents and settings\owner.brandon\IETldCache 2010-01-10 15:57 -cd-h— c:\windows\ie8 2010-01-10 15:32 –d—– c:\windows\ServicePackFiles 2010-01-10 15:28 –d—– c:\program files\MSXML 4.0 2010-01-10 14:48 25,471 ——– c:\windows\system32\drivers\watv10nt.sys 2010-01-10 14:48 22,271 ——– c:\windows\system32\drivers\watv06nt.sys 2010-01-10 14:48 11,935 ——– c:\windows\system32\drivers\wadv11nt.sys 2010-01-10 14:48 11,871 ——– c:\windows\system32\drivers\wadv09nt.sys 2010-01-10 14:48 11,807 ——– c:\windows\system32\drivers\wadv07nt.sys 2010-01-10 14:48 11,295 ——– c:\windows\system32\drivers\wadv08nt.sys 2010-01-10 14:48 404,990 ——– c:\windows\system32\drivers\slntamr.sys 2010-01-10 14:48 129,535 ——– c:\windows\system32\drivers\slnt7554.sys 2010-01-10 14:48 95,424 ——– c:\windows\system32\drivers\slnthal.sys 2010-01-10 14:48 13,240 ——– c:\windows\system32\drivers\slwdmsup.sys 2010-01-10 14:48 166,912 ——– c:\windows\system32\drivers\s3gnbm.sys 2010-01-10 14:47 13,776 ——– c:\windows\system32\drivers\recagent.sys 2010-01-10 14:47 1,897,408 ——– c:\windows\system32\drivers\nv4_mini.sys 2010-01-10 14:47 180,360 ——– c:\windows\system32\drivers\ntmtlfax.sys 2010-01-10 14:47 67,866 ——– c:\windows\system32\drivers\netwlan5.img 2010-01-10 14:47 452,736 ——– c:\windows\system32\drivers\mtxparhm.sys 2010-01-10 14:47 1,309,184 ——– c:\windows\system32\drivers\mtlstrm.sys 2010-01-10 14:47 126,686 ——– c:\windows\system32\drivers\mtlmnt5.sys 2010-01-10 14:47 11,868 ——– c:\windows\system32\drivers\mdmxsdk.sys 2010-01-10 14:46 1,041,536 ——– c:\windows\system32\drivers\hsfdpsp2.sys 2010-01-10 14:46 685,056 ——– c:\windows\system32\drivers\hsfcxts2.sys 2010-01-10 14:46 220,032 ——– c:\windows\system32\drivers\hsfbs2s2.sys 2010-01-10 14:46 129,045 ——– c:\windows\system32\drivers\cxthsfs2.cty 2010-01-10 14:25 3,426,072 a——- c:\windows\system32\d3dx9_32.dll 2010-01-10 14:25 2,414,360 a——- c:\windows\system32\d3dx9_31.dll 2010-01-10 14:25 –d—– c:\windows\Logs 2010-01-10 14:25 –d—– c:\program files\Winamp Detect 2010-01-10 14:24 129,520 ——– c:\windows\system32\pxafs.dll 2010-01-10 13:30 272,128 -c—— c:\windows\system32\dllcache\bthport.sys 2010-01-10 13:30 272,128 ——– c:\windows\system32\drivers\bthport.sys 2010-01-10 13:27 153,088 -c—— c:\windows\system32\dllcache\triedit.dll 2010-01-10 13:23 128,512 -c—— c:\windows\system32\dllcache\dhtmled.ocx 2010-01-10 13:21 203,136 -c—— c:\windows\system32\dllcache\rmcast.sys 2010-01-10 13:21 455,296 -c—— c:\windows\system32\dllcache\mrxsmb.sys 2010-01-10 13:21 333,952 -c—— c:\windows\system32\dllcache\srv.sys 2010-01-10 13:21 331,776 -c—— c:\windows\system32\dllcache\msadce.dll 2010-01-10 13:15 1,315,328 -c—— c:\windows\system32\dllcache\msoe.dll 2010-01-10 13:15 –d—– C:\Downloads 2010-01-10 13:14 691,712 -c—— c:\windows\system32\dllcache\inetcomm.dll 2010-01-10 13:14 –d—– c:\program files\BitComet 2010-01-10 13:10 2,066,432 -c—— c:\windows\system32\dllcache\mstscax.dll 2010-01-10 13:07 337,408 -c—— c:\windows\system32\dllcache\netapi32.dll 2010-01-10 13:07 1,172,480 -c—— c:\windows\system32\dllcache\msxml3.dll 2010-01-10 12:57 1,206,508 -c—— c:\windows\system32\dllcache\sysmain.sdb 2010-01-10 12:57 2,560 ——– c:\windows\system32\xpsp4res.dll 2010-01-10 12:57 215,552 -c—— c:\windows\system32\dllcache\wordpad.exe 2010-01-10 12:56 –d—– c:\windows\system32\PreInstall 2010-01-10 12:55 –d—– c:\documents and settings\owner.brandon\WINDOWS 2010-01-10 12:55 –d—– c:\documents and settings\Owner.Brandon 2010-01-10 12:55 –d—– c:\docume~1\owner~1.bra\applic~1\You've Got Pictures Screensaver 2010-01-10 12:55 –d—– c:\docume~1\owner~1.bra\applic~1\Intel 2010-01-10 12:37 107,368 a—-r– c:\windows\system32\GEARAspi.dll 2010-01-10 12:37 26,600 a—-r– c:\windows\system32\drivers\GEARAspiWDM.sys 2010-01-10 12:37 36,400 a—-r– c:\windows\system32\drivers\SymIM.sys 2010-01-10 12:37 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS 2010-01-10 12:37 60,808 a——- c:\windows\system32\S32EVNT1.DLL 2010-01-10 12:37 7,456 a——- c:\windows\system32\drivers\SYMEVENT.CAT 2010-01-10 12:37 806 a——- c:\windows\system32\drivers\SYMEVENT.INF 2010-01-10 12:37 –d—– c:\program files\Symantec 2010-01-10 12:37 –d—– c:\program files\common files\Symantec Shared 2010-01-10 12:36 –d—– c:\windows\system32\drivers\N360 2010-01-10 12:36 –d—– c:\program files\Norton 360 2010-01-10 12:36 –d—– c:\docume~1\alluse~1\applic~1\Norton 2010-01-10 12:36 –d—– c:\program files\NortonInstaller 2010-01-10 12:36 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller 2010-01-10 12:20 –d—– c:\documents and settings\all users\Symantec Temporary Files 2010-01-10 12:16 –dsh— c:\documents and settings\owner.brandon\UserData 2010-01-10 11:49 –d—– c:\docume~1\owner~1.bra\applic~1\McAfee.com Personal Firewall 2010-01-10 11:36 2 a——- c:\windows\msoffice.ini 2010-01-10 11:32 –d—– c:\program files\CCleaner 2010-01-10 11:25 –d—– c:\docume~1\owner~1.bra\applic~1\Verizon Wireless 2010-01-10 11:25 –d—– c:\docume~1\alluse~1\applic~1\WEngineLite 2010-01-10 11:25 –d—– c:\docume~1\alluse~1\applic~1\Verizon Wireless 2010-01-10 11:24 160,912 a——- c:\windows\system32\drivers\PTDMVsp.sys 2010-01-10 11:24 118,800 a——- c:\windows\system32\drivers\PTDMWWAN.sys 2010-01-10 11:24 13,456 a——- c:\windows\system32\drivers\PTDMWFLT.sys 2010-01-10 11:24 6,656 a——- c:\windows\system32\ptdmcit.dll 2010-01-10 11:24 160,912 a——- c:\windows\system32\drivers\PTDMMdm.sys 2010-01-10 11:24 55,056 a——- c:\windows\system32\drivers\PTDMBus.sys 2010-01-10 11:24 95,248 a——- c:\windows\system32\PTDMWmcp64.dll 2010-01-10 11:16 –d—– c:\windows\system32\SoftwareDistribution 2010-01-10 11:13 –d—– c:\docume~1\owner~1.bra\applic~1\Smith Micro 2010-01-10 11:11 319,456 a——- c:\windows\system32\DIFxAPI.dll 2010-01-10 11:11 88,592 a——- c:\windows\system32\PTDMWmcp.dll 2010-01-10 11:11 –d—– c:\program files\PANTECH 2010-01-10 11:10 –d—– c:\program files\Verizon Wireless 2010-01-10 05:14 8,192 a——- c:\windows\REGLOCS.OLD 2010-01-10 05:08 0 a——- c:\windows\system32\Gateway_MX6930_Rev.1_T336AP1014440.MRK 2010-01-10 05:08 333 a——- c:\windows\system32\$ncsp$.inf 2010-01-10 05:07 139,264 a——- c:\windows\system32\igfxres.dll 2010-01-10 05:05 2,752 a——- c:\windows\system32\Status.MPF 2010-01-10 05:00 21,275 a——- c:\windows\system32\drivers\AegisP.sys 2010-01-10 04:59 –d—– c:\program files\McAfee 2010-01-10 04:59 –d—– c:\docume~1\alluse~1\applic~1\McAfee.com Personal Firewall 2010-01-10 04:58 –d—– c:\docume~1\alluse~1\applic~1\McAfee.com 2010-01-10 04:56 23,552 a——- c:\windows\system32\jesterss.dll 2010-01-10 04:56 1,150 a——- c:\windows\system32\gtw.ico 2010-01-10 04:56 1,239,209 a——- c:\windows\system32\gtw_logo.scr 2010-01-10 04:56 –d—– c:\program files\gtw_logo 2010-01-10 04:53 –d—– c:\windows\tiinst 2010-01-10 04:51 –d—– c:\program files\Motorola 2010-01-10 04:50 1,179,784 a——- c:\windows\system32\drivers\sthda.sys 2010-01-10 04:50 217,088 a——- c:\windows\system32\stacapi.dll 2010-01-10 04:50 –d—– c:\program files\SigmaTel 2010-01-10 04:50 67,072 a——- c:\windows\POWERCFG.EXE 2010-01-10 04:50 –d—– c:\program files\Microsoft Money 2006 2010-01-10 04:48 –d—– c:\program files\MSN Encarta Plus 2010-01-10 04:48 –d—– c:\program files\common files\Nullsoft 2010-01-10 04:48 –d—– c:\program files\common files\Real 2010-01-10 04:48 –d—– c:\docume~1\alluse~1\applic~1\Viewpoint 2010-01-10 04:48 –d—– c:\program files\Viewpoint 2010-01-10 04:48 –d—– c:\docume~1\alluse~1\applic~1\Pure Networks 2010-01-10 04:48 –d—– c:\program files\Pure Networks 2010-01-10 04:47 1,189 a—h— C:\IPH.PH 2010-01-10 04:47 –d—– c:\program files\common files\AOL 2010-01-10 04:47 –d—– c:\docume~1\alluse~1\applic~1\Napster 2010-01-10 04:47 –d—– c:\program files\Napster 2010-01-10 04:46 17,992 a——- c:\windows\system32\drivers\bcm42rly.sys 2010-01-10 04:46 –d—– C:\ses2_client_bin_2_8_13g 2010-01-10 04:46 4 a——- c:\windows\Pix11.dat 2010-01-10 04:45 –d—– c:\program files\Microsoft Digital Image 2006 2010-01-10 04:45 89,088 a—-r– c:\windows\system32\atl71.dll 2010-01-10 04:44 –d—– c:\docume~1\alluse~1\applic~1\WildTangent 2010-01-10 04:44 –d—– c:\program files\WildTangent 2010-01-10 04:43 –d—– c:\program files\Gateway Games 2010-01-10 04:42 –d—– c:\program files\Synaptics 2010-01-10 04:42 –d—– c:\program files\BigFix 2010-01-10 04:41 –d—– c:\windows\SHELLNEW 2010-01-10 04:40 51,656 a——- c:\windows\system32\OEMLOGO.bmp 2010-01-10 04:40 2 a——- C:\AUDIT_INSTALL_IN_PROGRESS 2010-01-10 04:34 20,480 a——- c:\windows\system32\Marker32.exe 2010-01-10 04:32 0 a——- C:\REQUEST_OEMRESET_ENDUSER 2010-01-10 04:32 2 —shr– C:\USER 2010-01-09 21:36 –d—– c:\windows\creator 2010-01-09 21:34 244,480 a——- c:\windows\system32\drivers\yk51x86.sys 2010-01-09 21:34 –d—– c:\windows\SMINST 2010-01-09 21:34 –d—– c:\windows\I386 2010-01-09 21:34 13,824 a——- c:\windows\system32\wowfaxui.dll 2010-01-09 21:34 3,200 a——- c:\windows\system32\wowfax.dll 2010-01-09 21:34 23,552 a——- c:\windows\system32\wdmaud.drv 2010-01-09 21:34 49,211 a——- c:\windows\system32\usrvpa.dll 2010-01-09 21:34 45,116 a——- c:\windows\system32\usrvoica.dll 2010-01-09 21:34 49,209 a——- c:\windows\system32\usrv80a.dll 2010-01-09 21:34 102,457 a——- c:\windows\system32\usrv42a.dll 2010-01-09 21:32 70,656 a——- c:\windows\system32\sprio600.dll 2010-01-09 21:31 12,288 a——- c:\windows\system32\drivers\tunmp.sys 2010-01-09 21:25 64 a——- C:\MOVE_RECOVERY 2010-01-09 21:25 –d—– C:\My Backup – 10-01-09 0725PM ==================== Find3M ==================== 2010-01-10 16:57 86,811 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2010-01-10 04:48 8,552 a——- c:\windows\system32\drivers\asctrm.sys 2009-12-21 14:14 916,480 a——- c:\windows\system32\wininet.dll 2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll ============= FINISH: 22:33:06.79 ===============
Due, in part, to the large numbers of logs being posted, there are four things that you need to be aware of.

1) If you have already posted this log at another forum, you need to post here that you have done so and this topic will be closed.
Multiple posting not only ties up valuable resources, but could also result is some unpleasant side-effects for your system if you follow two sets of instructions at the same time.
If, during research, an identical log is identified at another forum, this thread will be closed.

2) If you don't post a meaningful reply to any of my posts within five days, this thread will be closed. Due to limited free time I can only have so many open threads at any one time and if yours isn't active, somebody else's will be.
If, by omission, the thread hasn't be closed after five days and you post, it will just serve as a reminder to me to close it.
Please note that "I just dropped in to say Hi!" isn't a meaningful reply!

3) Malware removal is a tricky business, and malware writers don't tend to worry about the damage their creations do, so it is advisable to back-up all important files BEFORE we start. Although most cases have a successful conclusion, on occasion things don't go according to plan and it is better to be prepared for the worst.

4) Back-ups can get lost or damaged, so make two if the files are that important to you!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pay a visit to the ESET Online Scanner.
  • Click the ESET Online Scanner button, read the info in the new window, check the appropriate box and click Start.
  • Accept the ActiveX download, and allow it to install.
  • Once this has been completed, you will see the Computer Scan settings page - ensure that you uncheck the "Remove found threats" box and then click Start.
  • The virus signature database will now need to be downloaded, so don't forget to instruct your firewall to permit it if it asks.
  • The above will take a little time, so now is a good time to fire up the kettle and open the biccies.
  • Once the scan has completed you will be shown the results - assuming that the scanner has found anything.
  • Click List of found threats and then Export to text file… and save the log somewhere convenient.
  • You can then close out the scanner - don't bother uninstalling it as you may need to use it again.
  • Please post the contents of this file in your next reply, or let me know that nothing was identified.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download Sec-Info2.zip from here and save it to your Desktop. You will need to extract the file.

Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


You should now see a folder with a file in it - double click Sec-info2.vbs to run it.
Once you have been informed that the script has completed, a text file called Sec-Info.txt should be created in the same folder - you may need to wait a couple of seconds for it to appear..
Please copy and paste the contents of the text file into your next reply and then you can delete both of the folders and their contents.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download RootRepeal from one of the locations below and save it to your Desktop:
Location 1
Location 2
Location 3
  • Double click RootRepeal.exe to fire up the tool and OK any Windows confirmation if necessary.
  • Ensure that the Report Tab is selected at the bottom.
  • Click the Scan button, check ALL the boxes in the window that appears and then click OK.
  • Check the box next to your main hard drive - usually C: and click OK
  • Put the kettle on and perhaps open a packet of biscuits - the scan will take some time.
  • Once the scan has completed a Notepad window will open with the results in.
  • These results will also be saved to the root of your main drive as \RootRepeal report date time.txt
Let me have a copy of the contents in your next reply.
The reason that I use the ESET scan is that it can be configured to leave anything it identifies alone. There is a possibility with some scanners that they will attempt removal of infected files and this can in the worse of cases render a PC unbootable. I would prefer it if you just let me know when a problem occurs and i'll decide on a fresh course of action.
i ran a second ESET scan and the computer froze again…not too sure what to do at this point. My computer runs really slow and I'm not sure if its from a virus or what. It also still freezes for no reason usually after its idle for a while. any help would be great thanks T
sec info log: Script run: 2/11/2010 5:05:23 PM ~~~~~~~~~~~~~~~~~~~~~~~~ Company Name: Symantec Corporation AV Name: Norton 360 Version Number: 3.5.2.11 On-Access Scanning Enabled: Yes Product up-to-date: Yes ~~~~~~~~~~~~~~~~~~~~~~~~ Company Name: McAfee AV Name: Version Number: On-Access Scanning Enabled: No Product up-to-date: Yes ~~~~~~~~~~~~~~~~~~~~~~~~ Company Name: McAfee Firewall Name: Version Number: Enabled: No ~~~~~~~~~~~~~~~~~~~~~~~~ Company Name: Symantec Corporation Firewall Name: Norton 360 Version Number: 3.5.2.11 Enabled: Yes ~~~~~~~~~~~~~~~~~~~~~~~~ The Windows Firewall is disabled. ~~~~~~~~~~~~~~~~~~~~~~~~ The Security Center Anti-Virus Alerts are enabled. The Security Center Firewall Alerts are enabled. ~~~~~~~~~~~~~~~~~~~~~~~~ Number of Restore Points found: 25 ~~~~~~~~~~~~~~~~~~~~~~~~ ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2010/02/11 17:10 Program Version: Version 1.3.5.0 Windows Version: Windows XP Media Center Edition SP3 ================================================== Drivers ——————- Name: dump_iaStor.sys Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys Address: 0x9F7E7000 Size: 876544 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0x9D929000 Size: 49152 File Visible: No Signed: - Status: - Name: SYMEFA.SYS Image Path: SYMEFA.SYS Address: 0xF714F000 Size: 323584 File Visible: No Signed: - Status: - Hidden/Locked Files ——————- Path: C:\hiberfil.sys Status: Locked to the Windows API! SSDT ——————- #: 012 Function Name: NtAlertResumeThread Status: Hooked by "" at address 0x849bb1a8 #: 013 Function Name: NtAlertThread Status: Hooked by "" at address 0x84afc1a8 #: 017 Function Name: NtAllocateVirtualMemory Status: Hooked by "" at address 0x85738438 #: 019 Function Name: NtAssignProcessToJobObject Status: Hooked by "" at address 0x84b64388 #: 031 Function Name: NtConnectPort Status: Hooked by "" at address 0x857cd960 #: 041 Function Name: NtCreateKey Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xaa72b130 #: 043 Function Name: NtCreateMutant Status: Hooked by "" at address 0x84a8a008 #: 052 Function Name: NtCreateSymbolicLinkObject Status: Hooked by "" at address 0x84af8210 #: 053 Function Name: NtCreateThread Status: Hooked by "" at address 0x84aa70e0 #: 057 Function Name: NtDebugActiveProcess Status: Hooked by "" at address 0x84ad2530 #: 063 Function Name: NtDeleteKey Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xaa72b3b0 #: 065 Function Name: NtDeleteValueKey Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xaa72b910 #: 068 Function Name: NtDuplicateObject Status: Hooked by "" at address 0x84a06c60 #: 083 Function Name: NtFreeVirtualMemory Status: Hooked by "" at address 0x849df078 #: 089 Function Name: NtImpersonateAnonymousToken Status: Hooked by "" at address 0x849d31a8 #: 091 Function Name: NtImpersonateThread Status: Hooked by "" at address 0x849ba1a8 #: 097 Function Name: NtLoadDriver Status: Hooked by "" at address 0x857cdc50 #: 108 Function Name: NtMapViewOfSection Status: Hooked by "" at address 0x849d1228 #: 114 Function Name: NtOpenEvent Status: Hooked by "" at address 0x84a1c108 #: 122 Function Name: NtOpenProcess Status: Hooked by "" at address 0x84a06f80 #: 123 Function Name: NtOpenProcessToken Status: Hooked by "" at address 0x84ad61a8 #: 125 Function Name: NtOpenSection Status: Hooked by "" at address 0x849a4108 #: 128 Function Name: NtOpenThread Status: Hooked by "" at address 0x84a06db0 #: 137 Function Name: NtProtectVirtualMemory Status: Hooked by "" at address 0x84b63110 #: 206 Function Name: NtResumeThread Status: Hooked by "" at address 0x84a73108 #: 213 Function Name: NtSetContextThread Status: Hooked by "" at address 0x84b65108 #: 228 Function Name: NtSetInformationProcess Status: Hooked by "" at address 0x849d0278 #: 240 Function Name: NtSetSystemInformation Status: Hooked by "" at address 0x84acd388 #: 247 Function Name: NtSetValueKey Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xaa72bb60 #: 253 Function Name: NtSuspendProcess Status: Hooked by "" at address 0x849a5108 #: 254 Function Name: NtSuspendThread Status: Hooked by "" at address 0x856ee470 #: 257 Function Name: NtTerminateProcess Status: Hooked by "" at address 0x84a87108 #: 258 Function Name: NtTerminateThread Status: Hooked by "" at address 0x84b61108 #: 267 Function Name: NtUnmapViewOfSection Status: Hooked by "" at address 0x856be108 #: 277 Function Name: NtWriteVirtualMemory Status: Hooked by "" at address 0x84a2e280 Shadow SSDT ——————- #: 307 Function Name: NtUserAttachThreadInput Status: Hooked by "" at address 0x857906c8 #: 383 Function Name: NtUserGetAsyncKeyState Status: Hooked by "" at address 0x85789498 #: 414 Function Name: NtUserGetKeyboardState Status: Hooked by "" at address 0x857892a8 #: 416 Function Name: NtUserGetKeyState Status: Hooked by "" at address 0x85793a90 #: 428 Function Name: NtUserGetRawInputData Status: Hooked by "" at address 0x857313e0 #: 460 Function Name: NtUserMessageCall Status: Hooked by "" at address 0x85712298 #: 475 Function Name: NtUserPostMessage Status: Hooked by "" at address 0x85729420 #: 476 Function Name: NtUserPostThreadMessage Status: Hooked by "" at address 0x857293d8 #: 549 Function Name: NtUserSetWindowsHookEx Status: Hooked by "" at address 0x8572e3e8 #: 552 Function Name: NtUserSetWinEventHook Status: Hooked by "" at address 0x85783618 ==EOF==
Take a trip to this webpage for download links and instructions for running Combofix by sUBs: http://www.bleepingcomputer.com/combofix/how-to-use-combofix *
  • Please be aware that this tool may require the PC to be rebooted so close any programs you have open before you start.
  • When CF has finished, it will produce a log - C:\ComboFix.txt - copy and paste it into your next reply.
  • Post a fresh DDS log as well.
  • Let me know how the PC is behaving.
* There are two points to note from the instructions page:

1) The Recovery Console.

It is recommended that you install this as, in certain circumstances, it may be the difference between a successful repair and a reformat. If you are uncertain as to whether or not you already have the Recovery Console installed, simply run CF and it will prompt you if it does not detect it.
CF will complete some, but not all, of it's removal tasks without the installation of the Console so, should you choose not to allow the installation, you may not get the results you hoped for.

2) Disabling your Anti-Virus.

CF has been the victim of false-positive detections on occasion and a resident AV may incorrectly identify and delete part of the tool which won't do it much good. If you don't disable your AV, you may not get the results you hoped for!
ComboFix 10-02-12.01 - Owner 02/14/2010 20:33:28.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.500 [GMT -5:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} FW: Norton 360 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\recycler\S-1-5-21-3720901572-3328388745-1107845492-500 c:\windows\ModemLog_PANTECH USB Modem .txt . ((((((((((((((((((((((((( Files Created from 2010-01-15 to 2010-02-15 ))))))))))))))))))))))))))))))) . 2010-02-13 14:39 . 2010-02-03 09:00 1324720 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\NAVEX15.SYS 2010-02-13 14:39 . 2010-01-09 09:27 1647984 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\NAVEX32A.DLL 2010-02-13 14:39 . 2010-02-03 09:00 84912 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\NAVENG.SYS 2010-02-13 14:39 . 2010-01-09 09:27 371248 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\EECTRL.SYS 2010-02-13 14:39 . 2010-01-09 09:27 2747440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\CCERASER.DLL 2010-02-13 14:39 . 2010-01-09 09:27 259440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\ECMSVR32.DLL 2010-02-13 14:39 . 2010-01-09 09:27 177520 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\NAVENG32.DLL 2010-02-13 14:39 . 2010-01-09 09:27 102448 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100212.039\ERASER.SYS 2010-02-12 21:38 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100210.001\IDSvix86.sys 2010-02-12 21:38 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100210.001\IDSXpx86.sys 2010-02-12 21:38 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100210.001\Scxpx86.dll 2010-02-12 21:38 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100210.001\IDSxpx86.dll 2010-02-12 21:38 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100210.001\IDSviA64.sys 2010-02-08 21:32 . 2010-02-08 21:32 ——– d—–w- c:\program files\ESET 2010-02-07 20:13 . 2010-02-07 20:13 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\Malwarebytes 2010-02-07 20:13 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-07 20:13 . 2010-02-07 20:13 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-02-07 20:13 . 2010-02-07 20:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-02-07 20:13 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-02-07 20:06 . 2010-02-07 20:06 ——– d—–w- c:\program files\ERUNT 2010-02-06 23:57 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSXpx86.sys 2010-02-06 23:57 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\Scxpx86.dll 2010-02-06 23:57 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSxpx86.dll 2010-02-06 23:57 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSvix86.sys 2010-02-06 23:57 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSviA64.sys 2010-02-05 14:47 . 2010-02-05 14:47 ——– d—–w- c:\program files\iPod 2010-02-05 14:47 . 2010-02-05 14:49 ——– d—–w- c:\program files\iTunes 2010-02-05 14:31 . 2010-02-05 14:31 72488 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe 2010-02-01 21:35 . 2010-02-01 21:37 ——– d—–w- c:\windows\system32\Adobe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-05 14:47 . 2010-01-13 20:02 ——– d—–w- c:\program files\Common Files\Apple 2010-02-04 16:30 . 2010-01-13 20:07 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\Apple Computer 2010-01-27 23:06 . 2010-01-10 18:14 ——– d—–w- c:\program files\BitComet 2010-01-27 18:38 . 2010-01-10 19:24 ——– d—–w- c:\program files\Winamp 2010-01-27 18:38 . 2010-01-10 19:25 ——– d—–w- c:\program files\Winamp Detect 2010-01-18 14:35 . 2010-01-11 04:34 ——– d—–w- c:\program files\PeerBlock 2010-01-18 14:35 . 2010-01-12 16:44 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\LimeWire 2010-01-15 17:23 . 2010-01-10 19:24 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\Winamp 2010-01-14 02:45 . 2010-01-14 02:45 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\AdobeUM 2010-01-13 21:54 . 2010-01-13 15:04 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\mIRC 2010-01-13 21:26 . 2010-01-13 15:04 ——– d—–w- c:\program files\mIRC 2010-01-13 21:23 . 2006-06-19 04:25 72392 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-01-13 20:06 . 2010-01-13 20:06 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2010-01-13 20:06 . 2010-01-13 20:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer 2010-01-13 20:05 . 2010-01-13 20:05 ——– d—–w- c:\program files\Bonjour 2010-01-13 20:05 . 2010-01-13 20:04 ——– d—–w- c:\program files\QuickTime 2010-01-13 20:03 . 2010-01-13 20:03 ——– d—–w- c:\program files\Apple Software Update 2010-01-13 20:02 . 2010-01-13 20:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple 2010-01-13 18:51 . 2010-01-13 18:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help 2010-01-13 18:49 . 2010-01-13 18:34 ——– d—–w- c:\program files\Microsoft Visual Studio 8 2010-01-13 18:42 . 2010-01-10 09:49 ——– d—–w- c:\program files\Microsoft Works 2010-01-13 18:42 . 2010-01-10 21:10 ——– d—–w- c:\program files\MSBuild 2010-01-13 18:40 . 2010-01-13 18:40 ——– d—–w- c:\program files\Microsoft.NET 2010-01-12 16:56 . 2010-01-12 16:53 ——– d—–w- c:\program files\MSN Toolbar Installer 2010-01-12 16:56 . 2010-01-12 16:56 ——– d—–w- c:\program files\Microsoft 2010-01-12 16:56 . 2010-01-12 16:56 ——– d—–w- c:\program files\MSN Toolbar 2010-01-12 16:52 . 2010-01-10 09:43 ——– d—–w- c:\program files\Java 2010-01-12 16:49 . 2010-01-12 16:49 152576 —-a-w- c:\documents and settings\Owner.Brandon\Application Data\Sun\Java\jre1.6.0_17\lzma.dll 2010-01-12 16:49 . 2010-01-12 16:49 79488 —-a-w- c:\documents and settings\Owner.Brandon\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2010-01-12 16:43 . 2010-01-12 16:43 152576 —-a-w- c:\documents and settings\Owner.Brandon\Application Data\Sun\Java\jre1.6.0_16\lzma.dll 2010-01-12 03:02 . 2010-01-12 03:02 ——– d—–w- c:\program files\Xvid 2010-01-12 02:52 . 2010-01-12 02:52 ——– d—–w- c:\program files\Windows Media Connect 2 2010-01-11 15:30 . 2010-01-10 09:38 ——– d—–w- c:\program files\Google 2010-01-11 01:47 . 2010-01-11 01:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec 2010-01-10 21:57 . 2006-06-17 09:39 86811 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat 2010-01-10 21:10 . 2010-01-10 21:10 ——– d—–w- c:\program files\Reference Assemblies 2010-01-10 21:06 . 2010-01-10 21:06 ——– d—–w- c:\program files\MSXML 6.0 2010-01-10 20:28 . 2010-01-10 20:28 ——– d—–w- c:\program files\MSXML 4.0 2010-01-10 18:26 . 2010-01-10 17:37 ——– d—–w- c:\program files\Common Files\Symantec Shared 2010-01-10 17:37 . 2010-01-10 17:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton 2010-01-10 17:37 . 2010-01-10 17:37 806 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF 2010-01-10 17:37 . 2010-01-10 17:37 7456 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT 2010-01-10 17:37 . 2010-01-10 17:37 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL 2010-01-10 17:37 . 2010-01-10 17:37 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2010-01-10 17:37 . 2010-01-10 17:37 ——– d—–w- c:\program files\Symantec 2010-01-10 17:37 . 2010-01-10 17:37 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys 2010-01-10 17:37 . 2010-01-10 17:37 36400 —-a-r- c:\windows\system32\drivers\SymIM.sys 2010-01-10 17:36 . 2010-01-10 17:36 1291104 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll 2010-01-10 17:36 . 2010-01-10 17:36 136840 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll 2010-01-10 17:36 . 2010-01-10 17:37 107368 —-a-r- c:\windows\system32\GEARAspi.dll 2010-01-10 17:36 . 2010-01-10 17:36 771440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll 2010-01-10 17:36 . 2010-01-10 17:36 ——– d—–w- c:\program files\Norton 360 2010-01-10 17:36 . 2010-01-10 17:36 ——– d—–w- c:\program files\Windows Sidebar 2010-01-10 17:36 . 2010-01-10 17:36 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller 2010-01-10 17:36 . 2010-01-10 17:36 ——– d—–w- c:\program files\NortonInstaller 2010-01-10 17:04 . 2010-01-10 09:43 ——– d—–w- c:\program files\Gateway Games 2010-01-10 17:01 . 2010-01-10 09:47 ——– d—–w- c:\program files\Napster 2010-01-10 17:01 . 2010-01-10 09:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Napster 2010-01-10 17:00 . 2010-01-10 09:44 ——– d—–w- c:\documents and settings\All Users\Application Data\WildTangent 2010-01-10 17:00 . 2010-01-10 09:44 ——– d—–w- c:\program files\WildTangent 2010-01-10 16:55 . 2010-01-10 09:42 ——– d—–w- c:\program files\BigFix 2010-01-10 16:49 . 2010-01-10 16:49 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\McAfee.com Personal Firewall 2010-01-10 16:38 . 2010-01-10 09:48 ——– d—–w- c:\program files\Pure Networks 2010-01-10 16:36 . 2010-01-10 09:47 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL 2010-01-10 16:36 . 2010-01-10 09:47 ——– d—–w- c:\program files\Common Files\AOL 2010-01-10 16:32 . 2010-01-10 16:32 ——– d—–w- c:\program files\CCleaner 2010-01-10 16:28 . 2010-01-10 16:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Verizon Wireless 2010-01-10 16:25 . 2010-01-10 16:25 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\Verizon Wireless 2010-01-10 16:25 . 2010-01-10 16:25 ——– d—–w- c:\documents and settings\All Users\Application Data\WEngineLite 2010-01-10 16:25 . 2010-01-10 16:10 ——– d—–w- c:\program files\Verizon Wireless 2010-01-10 16:24 . 2010-01-10 16:24 25214 —-a-r- c:\documents and settings\Owner.Brandon\Application Data\Microsoft\Installer\{E296E0ED-038F-4A5A-9513-642F2FA17A59}\ARPPRODUCTICON.exe 2010-01-10 16:23 . 2010-01-10 16:23 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\InstallShield 2010-01-10 16:23 . 2010-01-10 16:15 32262536 —-a-w- c:\documents and settings\Owner.Brandon\Application Data\Smith Micro\Updates\VZAM_7.2.1_2420b_Pantech_UM150.exe 2010-01-10 16:15 . 2010-01-10 16:13 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\Smith Micro 2010-01-10 16:11 . 2010-01-10 16:11 ——– d—–w- c:\program files\PANTECH 2010-01-10 10:00 . 2010-01-10 17:55 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\Intel 2010-01-10 10:00 . 2010-01-10 10:00 ——– d—–w- c:\documents and settings\Administrator\Application Data\Intel 2010-01-10 10:00 . 2010-01-10 10:00 21275 —-a-w- c:\windows\system32\drivers\AegisP.sys 2010-01-10 10:00 . 2010-01-10 10:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Intel 2010-01-10 09:59 . 2010-01-10 09:46 ——– d—–w- c:\program files\Intel 2010-01-10 09:59 . 2010-01-10 09:59 ——– d—–w- c:\program files\McAfee 2010-01-10 09:59 . 2010-01-10 09:59 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee 2010-01-10 09:59 . 2010-01-10 09:59 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com Personal Firewall 2010-01-10 09:58 . 2010-01-10 09:58 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com 2010-01-10 09:56 . 2010-01-10 09:56 ——– d—–w- c:\program files\gtw_logo 2010-01-10 09:51 . 2010-01-10 09:51 ——– d—–w- c:\program files\Motorola 2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\program files\MSN Encarta Plus 2010-01-10 09:48 . 2010-01-10 17:55 ——– d—–w- c:\documents and settings\Owner.Brandon\Application Data\You've Got Pictures Screensaver 2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\documents and settings\Administrator\Application Data\You've Got Pictures Screensaver 2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\program files\Common Files\Nullsoft 2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\documents and settings\All Users\Application Data\QuickTime 2010-01-10 09:48 . 2010-01-10 09:48 8552 —-a-w- c:\windows\system32\drivers\asctrm.sys 2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\program files\Common Files\Real 2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\program files\Real 2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint 2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\program files\Viewpoint 2010-01-10 09:48 . 2010-01-10 09:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Pure Networks 2010-01-10 09:47 . 2010-01-10 09:47 335 —-a-w- c:\windows\nsreg.dat 2010-01-10 09:47 . 2010-01-10 09:47 ——– d—–w- c:\program files\Common Files\Roxio Shared 2010-01-10 09:47 . 2010-01-10 09:40 ——– d—–w- c:\program files\Common Files\InstallShield . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512] "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 98394] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 688218] "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 139264] "SigmatelSysTrayApp"="stsystra.exe" [2005-12-27 413696] "igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys] @="FSFilter Activity Monitor" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\BitComet\\BitComet.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "7518:TCP"= 7518:TCP:BitComet 7518 TCP "7518:UDP"= 7518:UDP:BitComet 7518 UDP R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0308000.029\SymEFA.sys [2/2/2010 8:32 PM 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0308000.029\BHDrvx86.sys [2/2/2010 8:32 PM 259632] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0308000.029\cchpx86.sys [2/2/2010 8:32 PM 482432] R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100210.001\IDSXpx86.sys [2/12/2010 4:38 PM 329592] R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe [2/2/2010 8:31 PM 117640] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [1/9/2010 4:27 AM 102448] R3 PTDMBus;PANTECH USB Modem Composite Device Driver ;c:\windows\system32\drivers\PTDMBus.sys [1/10/2010 11:24 AM 55056] R3 PTDMMdm;PANTECH USB Modem Drivers ;c:\windows\system32\drivers\PTDMMdm.sys [1/10/2010 11:24 AM 160912] R3 PTDMVsp;PANTECH USB Modem Serial Port ;c:\windows\system32\drivers\PTDMVsp.sys [1/10/2010 11:24 AM 160912] S3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [1/10/2010 11:34 PM 14424] S3 PTDMWFLT;PTDMWWAN Filter Driver;c:\windows\system32\drivers\PTDMWFLT.sys [1/10/2010 11:24 AM 13456] S3 PTDMWWAN;PANTECH USB Modem WWAN Driver;c:\windows\system32\drivers\PTDMWWAN.sys [1/10/2010 11:24 AM 118800] S3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS [5/25/2009 3:43 PM 32408] . Contents of the 'Scheduled Tasks' folder 2010-02-11 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/first_usage&s=1zyx0oR3NubSyGmPUbYMTFRIUAU IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360] "ImagePath"="\"c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.8.0.41\diMaster.dll\" /prefetch:1" . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'explorer.exe'(3400) c:\windows\system32\WININET.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ———————— Other Running Processes ———————— . c:\program files\Intel\Wireless\Bin\EvtEng.exe c:\program files\Intel\Wireless\Bin\S24EvMon.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\eHome\ehRecvr.exe c:\windows\eHome\ehSched.exe c:\program files\Intel\Intel Matrix Storage Manager\iaantmon.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS c:\program files\Intel\Wireless\Bin\RegSrvc.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\windows\ehome\mcrdsvc.exe c:\windows\system32\dllhost.exe c:\windows\system32\wscntfy.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\stsystra.exe c:\windows\eHome\ehmsas.exe c:\windows\system32\igfxsrvc.exe . ************************************************************************** . Completion time: 2010-02-14 20:50:17 - machine was rebooted ComboFix-quarantined-files.txt 2010-02-15 01:50 Pre-Run: 35,041,906,688 bytes free Post-Run: 35,290,120,192 bytes free - - End Of File - - FD232A29DF1F3E8F44A488B1093DAE60 DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 20:54:38.90 on Sun 02/14/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.549 [GMT -5:00] AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} FW: Norton 360 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe svchost.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\WINDOWS\system32\dllhost.exe C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe C:\WINDOWS\stsystra.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\Owner.Brandon\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/first_usage&s=1zyx0oR3NubSyGmPUbYMTFRIUAU BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.8.0.41\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.8.0.41\IPSBHO.DLL BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.8.0.41\coIEPlg.dll TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.8.0.41\CoIEPlg.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL ============= SERVICES / DRIVERS =============== R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0308000.029\SymEFA.sys [2010-2-2 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0308000.029\BHDrvx86.sys [2010-2-2 259632] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0308000.029\cchpx86.sys [2010-2-2 482432] R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100210.001\IDSXpx86.sys [2010-2-12 329592] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 N360;Norton 360;c:\program files\norton 360\engine\3.8.0.41\ccSvcHst.exe [2010-2-2 117640] R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-8-7 242048] R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-8-18 1529728] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-1-9 102448] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100212.039\NAVENG.SYS [2010-2-13 84912] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100212.039\NAVEX15.SYS [2010-2-13 1324720] R3 PTDMBus;PANTECH USB Modem Composite Device Driver ;c:\windows\system32\drivers\PTDMBus.sys [2010-1-10 55056] R3 PTDMMdm;PANTECH USB Modem Drivers ;c:\windows\system32\drivers\PTDMMdm.sys [2010-1-10 160912] R3 PTDMVsp;PANTECH USB Modem Serial Port ;c:\windows\system32\drivers\PTDMVsp.sys [2010-1-10 160912] S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2010-1-10 14424] S3 PTDMWFLT;PTDMWWAN Filter Driver;c:\windows\system32\drivers\PTDMWFLT.sys [2010-1-10 13456] S3 PTDMWWAN;PANTECH USB Modem WWAN Driver;c:\windows\system32\drivers\PTDMWWAN.sys [2010-1-10 118800] S3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\verizo~1\vzacce~1\SMSIVZAM5.SYS [2009-5-25 32408] =============== Created Last 30 ================ 2010-02-14 20:31 261,632 a——- c:\windows\PEV.exe 2010-02-14 20:31 161,792 a——- c:\windows\SWREG.exe 2010-02-14 20:31 98,816 a——- c:\windows\sed.exe 2010-02-14 20:31 77,312 a——- c:\windows\MBR.exe 2010-02-14 20:31 –d—– C:\ComboFix 2010-02-12 00:06 1,374 a——- c:\windows\imsins.BAK 2010-02-08 16:32 –d—– c:\program files\ESET 2010-02-07 15:13 –d—– c:\docume~1\owner~1.bra\applic~1\Malwarebytes 2010-02-07 15:13 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-07 15:13 19,160 a——- c:\windows\system32\drivers\mbam.sys 2010-02-07 15:13 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-02-07 15:13 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-02-05 09:47 –d—– c:\program files\iPod 2010-02-05 09:47 –d—– c:\program files\iTunes 2010-02-01 16:35 –d—– c:\windows\system32\Adobe 2010-01-27 11:26 3,247 a——- c:\windows\system32\wbem\Outlook_01ca9f6d8b2664a2.mof ==================== Find3M ==================== 2010-01-10 16:57 86,811 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2010-01-10 12:37 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS 2010-01-10 12:37 60,808 a——- c:\windows\system32\S32EVNT1.DLL 2010-01-10 12:37 7,456 a——- c:\windows\system32\drivers\SYMEVENT.CAT 2010-01-10 12:37 806 a——- c:\windows\system32\drivers\SYMEVENT.INF 2010-01-10 12:37 36,400 a—-r– c:\windows\system32\drivers\SymIM.sys 2010-01-10 12:37 26,600 a—-r– c:\windows\system32\drivers\GEARAspiWDM.sys 2010-01-10 12:36 107,368 a—-r– c:\windows\system32\GEARAspi.dll 2010-01-10 05:00 21,275 a——- c:\windows\system32\drivers\AegisP.sys 2010-01-10 04:48 8,552 a——- c:\windows\system32\drivers\asctrm.sys 2009-12-31 11:50 353,792 a——- c:\windows\system32\drivers\srv.sys 2009-12-21 14:14 916,480 ——– c:\windows\system32\wininet.dll 2009-12-16 13:43 343,040 a——- c:\windows\system32\mspaint.exe 2009-12-14 02:08 33,280 a——- c:\windows\system32\csrsrv.dll 2009-12-08 14:26 2,145,280 ——– c:\windows\system32\ntoskrnl.exe 2009-12-08 13:43 2,023,936 ——– c:\windows\system32\ntkrnlpa.exe 2009-11-27 12:11 1,291,776 a——- c:\windows\system32\quartz.dll 2009-11-27 12:11 17,920 a——- c:\windows\system32\msyuv.dll 2009-11-27 11:07 28,672 a——- c:\windows\system32\msvidc32.dll 2009-11-27 11:07 8,704 a——- c:\windows\system32\tsbyuv.dll 2009-11-27 11:07 84,992 a——- c:\windows\system32\avifil32.dll 2009-11-27 11:07 48,128 a——- c:\windows\system32\iyuv_32.dll 2009-11-27 11:07 11,264 a——- c:\windows\system32\msrle32.dll 2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll ============= FINISH: 20:54:56.54 ===============
Good to hear.

I suggest you follow the instructions here and run the McAfee removal tool as their security products have a habit of leaving crud behind and there's no reason to clutter up your hard drive.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Your version of Sun Java needs updating:

1) Go here and click on the Windows XP/Vista/2000/2003 Offline link in the Windows section near the top and save it to your Desktop.

2) Download JavaRa from here and save it to your Desktop.
You will need to extract the file(s):
Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


***Please close any instances of Internet Explorer before continuing!***
  • Double-click JavaRa.exe to begin.
  • Pick your preferred language from the drop-down menu and click Select.
  • Click on Remove Older Versions to remove older version of Java - obvious really, isn't it!
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location, just in case you have any problems with Java afterwards.
3) Run the installer that you downloaded earlier.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

The following steps will serve as a spring clean for your PC. Not all of them will be of benefit to your PC as this is a general post, but the overall effect should be positive.

1) Go to Start > Control Panel > Add/Remove Programs and remove any programs that you no longer use and then reboot your PC.

2) Download TFC by OldTimer from here and save it to your Desktop.
  • You will need to close all open programs and save any work as TFC will require a reboot.
  • Double-click TFC.exe to run it. (Note: If you are using Vista, right-click the file and select Run As Administrator from the menu that appears).
  • Click the Start button to begin. Depending on how often you clean temp files, execution time could be anywhere from a few seconds to a minute or two - just sit back and enjoy the view.
  • Once it has finished it should reboot your PC all by itself. If it does not, please manually reboot.
  • Once rebooted your PC will run like a Cray supercomputer, or at least have less junk on the hard drive - OT's not a miracle worker you know!
  • Please note that this tool will empty the Recycle Bin as part of it's actions. If you have anything in there that you haven't finished with, move it first.

3) Double click My Computer.
Right click the disc drive you wish to check.
Click Properties.
In the Properties dialog box, click the Tools Tab.
Under Error-checking, click the Check Now button.
In the "Check Disc Local Disk (C:)" dialog box, check both Automatically fix file system errors and Scan for and attempt recovery of bad sectors, and then click Start.

This will look for and attempt to repair any errors that your hard drive has.

4) Defragment your hard drive. A tutorial for disc defragmentation is available here.

I happen to prefer a third-party defrag tool to the one that Windows offers. You can read about it, and find a linky, here - it's free too!

Let me know how the PC is behaving after the above.
so i went through all the steps you listed and the computer froze when trying to run the defragmenter!! I'm trying to defrag again just to see if it was a one time thing or not….
i tried a second defrag with auslogics and the cpu froze again. then i tried a defrag with the windows defragmenter and the computer froze! Not sure what's going on….
It could be one of the processes running on your machine is interfering. Are you able to boot into Safe Mode and run the defrag tool in there?
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI