This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Multiple and varied popups

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi all, I have had visual popups for games and such and audio only commercials plaguing me for about 2 weeks. I've trie Adaware, spybot, Malwarebytes, superantispyware, smitrem and my Norton AV . I also ran some of these in safemode without results. The popups will open anytime randomly. One says "Congratulations, You've won", another audio only is for Lysol Wipes about 20 secs. long Last night I was getting a high severity alert that was stopped and quarentined by Nortons, once a minute for over 2 hrs. Norton said it was in ' vji17e.tmp'. I also have a problem with hdmp files in iexplore filling up my temp folder and locking up my machine. My wife has her own desktop, just to give you all info.Thank you in advance for your help, friggit. Heres my Hijack log.Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:45:55 PM, on 7/26/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb02.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://buy.norton.com/rd/directrenewal?NOS…vendtag=B97NJ91
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=;ftp=;https=;
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\IPSBHO.DLL
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb02.exe
O4 - HKLM\..\Run: [UMonit] C:\WINDOWS\system32\UMonit.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Rich\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10e.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10e.exe (User 'Default user')
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} (Photo Upload Plugin Class) - http://www.cvsphoto.com/upload/activex/v3_…veX_Control.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe

–
End of file - 6625 bytes
Hello friggit and welcome to WhatTheTech. Please follow these guidelines while we work on your PC:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
🖼Click to load external image (Posted Image) Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.scr
DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
🖼Click to load external image (Posted Image) Download GMER Rootkit Scanner from here to your desktop.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If you have trouble running GEMR:
  • Make sure that your security software is disabled
  • Uncheck the box next to "Files" this time also
  • If you still can't run it, try in the Safe Mode
🖼Click to load external image (Posted Image) Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A small window will open and a .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your deskop. Please close the window and post the contents of that file.
Please include the following in your next post:
  • DDS and Attach.txt logs
  • GMER log
  • MBRCheck log
Hi RPMcMurphy, Thanks so much for your speedy response! Here are the log files you requested. Hope it all comes across OK. Friggit


DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 17:16:52.05 on Tue 07/27/2010
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.381 [GMT -4:00]

AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

============== Running Processes ===============

svchost.exe 4
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe 4
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb02.exe
C:\WINDOWS\system32\UMonit.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Rich\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
mDefault_Page_URL = hxxp://www.dell.com
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = https://buy.norton.com/rd/directrenewal?NOS…vendtag=B97NJ91
uInternet Settings,ProxyServer = http=;ftp=;https=;
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\17.7.0.12\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\17.7.0.12\IPSBHO.DLL
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\17.7.0.12\coIEPlg.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [Google Update] "c:\documents and settings\rich\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb02.exe
mRun: [UMonit] c:\windows\system32\UMonit.exe
dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10e.exe
uPolicies-explorer: NoThemesTab = 0 (0x0)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
uPolicies-system: NoColorChoice = 0 (0x0)
uPolicies-system: NoSizeChoice = 0 (0x0)
uPolicies-system: NoVisualStyleChoice = 0 (0x0)
uPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: musicmatch.com\online
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No File
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\rich\applic~1\mozilla\firefox\profiles\8k1mfdxw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\rich\local settings\application data\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nis\1107000.00c\symds.sys [2010-5-20 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1107000.00c\symefa.sys [2010-5-20 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.5.0.127\definitions\bashdefs\20100709.001\BHDrvx86.sys [2010-7-12 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nis\1107000.00c\cchpx86.sys [2010-5-20 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nis\1107000.00c\ironx86.sys [2010-5-20 116784]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 NIS;Norton Internet Security;c:\program files\norton internet security\engine\17.7.0.12\ccsvchst.exe [2010-5-20 126392]
R2 PDSched;PDScheduler;c:\program files\raxco\perfectdisk\PDSched.exe [2004-11-1 237635]
R3 Angel;Angel MPEG Device;c:\windows\system32\drivers\Angel.sys [2006-3-26 375936]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-27 102448]
R3 FIXUSTOR;FIXUSTOR;c:\windows\system32\drivers\fixustor.sys [2010-7-26 12416]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.5.0.127\definitions\ipsdefs\20100723.001\IDSXpx86.sys [2010-7-23 331640]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.5.0.127\definitions\virusdefs\20100727.005\NAVENG.SYS [2010-7-27 85424]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.5.0.127\definitions\virusdefs\20100727.005\NAVEX15.SYS [2010-7-27 1362608]
S1 SABKUTIL;SABKUTIL;\??\c:\documents and settings\administrator\desktop\superantispyware\sabkutil.sys –> c:\documents and settings\administrator\desktop\superantispyware\SABKUTIL.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\superantispyware\sasdifsv.sys –> c:\program files\superantispyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\superantispyware\saskutil.sys –> c:\program files\superantispyware\SASKUTIL.SYS [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-2 135664]

=============== Created Last 30 ================

2010-07-27 03:24:18 25992 —-a-w- c:\windows\system32\pgdfgsvc.exe
2010-07-26 22:44:59 0 d—–w- c:\program files\Trend Micro
2010-07-26 22:15:14 77312 —-a-w- c:\windows\MBR.exe
2010-07-26 22:15:13 98816 —-a-w- c:\windows\sed.exe
2010-07-26 22:15:13 256512 —-a-w- c:\windows\PEV.exe
2010-07-26 22:15:13 161792 —-a-w- c:\windows\SWREG.exe
2010-07-26 18:47:48 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-26 18:47:47 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-26 18:47:47 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-26 18:40:05 9584640 —-a-w- c:\windows\system32\GeneIcon.dll
2010-07-26 18:40:05 200704 —-a-w- c:\windows\system32\UMonit.exe
2010-07-26 18:40:05 167936 —-a-w- c:\windows\system32\ustor.dll
2010-07-26 18:39:24 12416 —-a-w- c:\windows\system32\drivers\fixustor.sys
2010-07-25 02:42:11 22436 —ha-w- c:\windows\system32\mlfcache.dat
2010-07-23 04:08:20 32768 —-a-w- c:\windows\~DF3278.tmp
2010-07-23 00:48:50 0 d—–w- c:\program files\TrendMicro
2010-07-23 00:45:49 0 d—–w- c:\docume~1\rich\applic~1\SUPERAntiSpyware.com
2010-07-23 00:45:49 0 d—–w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-07-22 22:07:01 0 d—–w- c:\docume~1\rich\applic~1\Malwarebytes
2010-07-22 22:06:46 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-07-21 02:33:45 0 d—–w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-07-21 02:27:29 34627584 —-a-w- c:\windows\system32\XUTEMYUHQ
2010-07-20 20:55:40 0 d—–w- c:\program files\CCleaner
2010-07-14 01:46:58 520192 ——w- c:\windows\system32\ati2sgag.exe
2010-07-13 23:05:23 743936 ——w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-07 00:53:20 0 d—–w- c:\program files\AviSynth 2.5
2010-07-07 00:22:46 0 d—–w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-06 18:15:36 0 d—–w- c:\docume~1\rich\applic~1\Yamb

==================== Find3M ====================

2010-07-25 21:59:47 608 —-a-w- c:\program files\smitrem.lnk
2010-07-03 15:39:01 134669 —-a-w- c:\program files\Ashley awake 2 weeks old (1000 x 750).jpg
2010-05-05 07:11:29 32768 —-a-w- c:\windows\~DF1AAD.tmp
2010-05-02 05:56:34 1850880 —-a-w- c:\windows\system32\win32k.sys
2010-05-02 05:56:34 1850880 ——w- c:\windows\system32\dllcache\win32k.sys
2006-05-19 08:57:34 532480 -c–a-w- c:\program files\cwshredder.exe
2010-02-07 03:52:41 56 –sh–r- c:\windows\system32\866971AEE0.sys
2010-02-07 03:52:43 3350 –sha-w- c:\windows\system32\KGyGaAvL.sys

============= FINISH: 17:17:38.93 ===============

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume4
Install Date: 1/30/2010 4:10:30 PM
System Uptime: 7/27/2010 4:10:03 AM (13 hours ago)

Motherboard: Dell Inc. | | 0YC523
Processor: Intel® Pentium® D CPU 2.80GHz | Microprocessor | 2793/800mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 70 GiB total, 19.562 GiB free.
D: is CDROM ()
E: is FIXED (FAT32) - 36 GiB total, 1.28 GiB free.
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is Removable
K: is Removable
Y: is FIXED (NTFS) - 5 GiB total, 0.553 GiB free.
Z: is FIXED (FAT32) - 6 GiB total, 0.267 GiB free.

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1: 7/26/2010 6:15:21 PM - System Checkpoint
RP2: 7/26/2010 6:44:58 PM - Installed HiJackThis

==== Installed Programs ======================

Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop Elements
Adobe Reader 9.3.3
Adobe Shockwave Player 11.5
Andrea VoiceCenter
Any Video Converter 3.0.5
AOLIcon
Apple Application Support
Apple Software Update
Applet_App
Applet_Copy
Applet_Creativity
Applet_Email
Applet_Epp
Applet_File
Applet_OCR
Applet_Web
ArcSoft PhotoImpression 3.0
ArcSoft Software Suite
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
CCleaner
Copy Utility
Coupon Printer for Windows
Creative MediaSource
Dell Digital Jukebox Driver
Dell Driver Download Manager
Dell Driver Reset Tool
Dell Support 3.1
Digital Content Portal
Dynex 6-in-1 card reader
easyHDR BASIC
ELIcon
EPSON Photo Print
EPSON Smart Panel
EPSON TWAIN 5
FastStone Image Viewer 4.0
GemMaster Mystic
Google Chrome
Google Earth
Google Update Helper
High Definition Audio Driver Package - KB835221
HiJackThis
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB888795)
Hotfix for Windows XP (KB891593)
Hotfix for Windows XP (KB895961)
Hotfix for Windows XP (KB896256)
Hotfix for Windows XP (KB899337)
Hotfix for Windows XP (KB899510)
Hotfix for Windows XP (KB902841)
Hotfix for Windows XP (KB906569)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB981793)
hp deskjet 950c series (Remove only)
Intel Matrix Storage Manager
Intel® 537EP V9x DF PCI Modem
Intel® PRO Network Connections Drivers
Intel® PROSet for Wired Connections
Intel® Viiv™
Java 2 Runtime Environment, SE v1.4.2_03
Java Auto Updater
Java™ 6 Update 18
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.0 Hotfix (KB979904)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft Office 2000 Premium
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft SQL Server Compact 3.5 SP1 English
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Modem Event Monitor
Modem Helper
Modem On Hold
Mozilla Firefox (3.6.8)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Musicmatch® Jukebox
Nero 7 Ultra Edition
Norton Internet Security
Norton Security Scan
PerfectDisk
PHOTOfunSTUDIO 4.0 HD Edition
PIXresizer 2.0.4
PowerDVD 5.5
QuickTime
RealPlayer Basic
Safari
ScanToWeb
Search Assist
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB944338-v2)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981350)
Security Update for Windows XP (KB982381)
SILKYPIX Developer Studio 3.0 SE
Sonic Advanced Decoder
Sonic DLA
Sonic Encoders
Sonic MyDVD LE
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Sound Blaster Audigy ADVANCED MB
Sound Blaster Audigy ADVANCED MB Product Registration
SpywareBlaster 4.3
tinySpell 1.9.01
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB978207)
Update for Windows XP (KB980182)
Update Rollup 2 for Windows XP Media Center Edition 2005
URL Assistant
Viewpoint Media Player
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebCyberCoach 3.2 Dell
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB889673
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890927
Windows XP Hotfix - KB891781
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB908250
Windows XP Media Center Edition 2005 KB973768

==== End Of File ===========================
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-07-27 17:05:41
Windows 5.1.2600 Service Pack 2
Running: ovtt8uum[1].exe; Driver: C:\DOCUME~1\Rich\LOCALS~1\Temp\agloapow.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

—- Processes - GMER 1.0.15 —-

Process C:\Program Files\Internet Explorer\iexplore.exe (*** hidden *** ) 2360
Process C:\Program Files\Internet Explorer\iexplore.exe (*** hidden *** ) 2640

—- EOF - GMER 1.0.15 —-
MBRCheck, version 1.2.2
© 2010, AD

Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 2 (build 2600)
Logical Drives Mask: 0x030007fc

Kernel Drivers (total 209):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806CF000 \WINDOWS\system32\hal.dll
0xF7B52000 \WINDOWS\system32\KDCOM.DLL
0xF7A62000 \WINDOWS\system32\BOOTVID.dll
0xF7523000 ACPI.sys
0xF7B54000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF7512000 pci.sys
0xF7652000 isapnp.sys
0xF7C1A000 pciide.sys
0xF78D2000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF7B56000 aliide.sys
0xF7B58000 cmdide.sys
0xF7B5A000 toside.sys
0xF7B5C000 viaide.sys
0xF7B5E000 intelide.sys
0xF7662000 MountMgr.sys
0xF74F3000 ftdisk.sys
0xF7B60000 dmload.sys
0xF74CD000 dmio.sys
0xF78DA000 PartMgr.sys
0xF7672000 VolSnap.sys
0xF7A66000 cpqarray.sys
0xF74B5000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
0xF73E0000 iastor.sys
0xF73C8000 atapi.sys
0xF7A6A000 aha154x.sys
0xF78E2000 sparrow.sys
0xF7A6E000 symc810.sys
0xF7682000 aic78xx.sys
0xF7A72000 dac960nt.sys
0xF7692000 ql10wnt.sys
0xF7A76000 amsint.sys
0xF78EA000 asc.sys
0xF7A7A000 asc3550.sys
0xF78F2000 mraid35x.sys
0xF78FA000 i2omp.sys
0xF7A7E000 ini910u.sys
0xF76A2000 ql1240.sys
0xF76B2000 aic78u2.sys
0xF7902000 symc8xx.sys
0xF790A000 sym_hi.sys
0xF7912000 sym_u3.sys
0xF791A000 ABP480N5.SYS
0xF7922000 asc3350p.sys
0xF7B62000 cd20xrnt.sys
0xF76C2000 ultra.sys
0xF73AF000 adpu160m.sys
0xF792A000 dpti2o.sys
0xF76D2000 ql1080.sys
0xF76E2000 ql1280.sys
0xF76F2000 ql12160.sys
0xF7932000 perc2.sys
0xF7B64000 perc2hib.sys
0xF793A000 hpn.sys
0xF7A82000 cbidf2k.sys
0xF7383000 dac2w2k.sys
0xF7702000 disk.sys
0xF7712000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF7363000 fltMgr.sys
0xF730D000 SYMDS.SYS
0xF72FB000 sr.sys
0xF72CE000 SYMEFA.SYS
0xF72B9000 drvmcdb.sys
0xF7942000 PxHelp20.sys
0xF72A2000 KSecDD.sys
0xF7722000 Defrag32b.sys
0xF7215000 Ntfs.sys
0xF71E8000 NDIS.sys
0xF7732000 sisagp.sys
0xF7742000 viaagp.sys
0xF71CD000 Mup.sys
0xF7752000 agp440.sys
0xF7762000 alim1541.sys
0xF7772000 amdagp.sys
0xF7782000 agpCPQ.sys
0xF77A2000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xF6F37000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
0xF6F23000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF6EFD000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xF6ED2000 \SystemRoot\system32\DRIVERS\e1e5132.sys
0xF7A02000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xF6EAF000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF7A32000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF6E53000 \SystemRoot\system32\DRIVERS\Angel.sys
0xF6E30000 \SystemRoot\system32\DRIVERS\ks.sys
0xF7BF2000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF77B2000 \SystemRoot\system32\DRIVERS\IntelC53.sys
0xF6D09000 \SystemRoot\system32\DRIVERS\IntelC51.sys
0xF6C74000 \SystemRoot\system32\DRIVERS\IntelC52.sys
0xF7962000 \SystemRoot\system32\DRIVERS\mohfilt.sys
0xF797A000 \SystemRoot\System32\Drivers\Modem.SYS
0xF77C2000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF799A000 \SystemRoot\system32\drivers\Afc.sys
0xF77D2000 \SystemRoot\System32\Drivers\cdrbsdrv.SYS
0xF7BFA000 \SystemRoot\system32\drivers\sscdbhk5.sys
0xF77E2000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF77F2000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF7D92000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF7802000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF70C4000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF6C5D000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF7812000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF7822000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF7A12000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF6C24000 \SystemRoot\system32\DRIVERS\psched.sys
0xF7832000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF7A42000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF7A52000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF6B53000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xF7842000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF79A2000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF79B2000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF7C04000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF6AFA000 \SystemRoot\system32\DRIVERS\update.sys
0xF7B32000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF71A9000 \SystemRoot\system32\drivers\MODEMCSA.sys
0xF7862000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xEEA5D000 \SystemRoot\system32\drivers\sthda.sys
0xEEA39000 \SystemRoot\system32\drivers\portcls.sys
0xF7892000 \SystemRoot\system32\drivers\drmk.sys
0xEE8EF000 \SystemRoot\system32\drivers\sigfilt.sys
0xF78B2000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF7C10000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0xEE850000 \SystemRoot\System32\Drivers\NIS\1107000.00C\SRTSP.SYS
0xEE831000 \SystemRoot\system32\drivers\NIS\1107000.00C\Ironx86.SYS
0xF7175000 \SystemRoot\system32\drivers\NIS\1107000.00C\SRTSPX.SYS
0xEE620000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
0xF7A0A000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xF7952000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xEE8C3000 \SystemRoot\system32\DRIVERS\fixustor.sys
0xEE42E000 \SystemRoot\system32\DRIVERS\VX1000.sys
0xF7135000 \SystemRoot\system32\DRIVERS\STREAM.SYS
0xF7125000 \SystemRoot\system32\drivers\usbaudio.sys
0xF7B70000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7C48000 \SystemRoot\System32\Drivers\Null.SYS
0xF7B74000 \SystemRoot\System32\Drivers\Beep.SYS
0xF79AA000 \SystemRoot\system32\drivers\ssrtln.sys
0xF79DA000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xF79F2000 \SystemRoot\System32\drivers\vga.sys
0xF7B86000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF7B8A000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF79FA000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF7A22000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF6AE2000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xEE383000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xEE32B000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xEE2D4000 \SystemRoot\System32\Drivers\NIS\1107000.00C\SYMTDI.SYS
0xEE2B3000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xF7145000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xF7185000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xEE7F1000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xF70E5000 \SystemRoot\system32\DRIVERS\IrBus.sys
0xEE25E000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100723.001\IDSxpx86.sys
0xEE236000 \SystemRoot\system32\DRIVERS\netbt.sys
0xEE214000 \SystemRoot\System32\drivers\afd.sys
0xEE821000 \SystemRoot\system32\DRIVERS\netbios.sys
0xEE1E9000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xF7A2A000 \SystemRoot\system32\DRIVERS\usbprint.sys
0xEE17A000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF6ABA000 \SystemRoot\system32\DRIVERS\usbscan.sys
0xF7105000 \SystemRoot\System32\Drivers\Fips.SYS
0xEE11C000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
0xEE3FE000 \SystemRoot\system32\DRIVERS\hidir.sys
0xEE8AF000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0xEE8A7000 \SystemRoot\system32\DRIVERS\mouhid.sys
0xEE0FF000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
0xEE058000 \SystemRoot\system32\drivers\NIS\1107000.00C\ccHPx86.sys
0xEDFAC000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20100709.001\BHDrvx86.sys
0xEDF89000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xEDE8C000 \SystemRoot\System32\Drivers\dump_iastor.sys
0xBF800000 \SystemRoot\System32\win32k.sys
0xF6AB2000 \SystemRoot\System32\drivers\Dxapi.sys
0xEE40E000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7CA6000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\ati2dvag.dll
0xBF049000 \SystemRoot\System32\ati2cqag.dll
0xBF07D000 \SystemRoot\System32\atikvmag.dll
0xBF0B2000 \SystemRoot\System32\ati3duag.dll
0xBF2F4000 \SystemRoot\System32\ativvaxx.dll
0xEE7B1000 \SystemRoot\system32\drivers\drvnddm.sys
0xF7D72000 \SystemRoot\system32\dla\tfsndres.sys
0xEBC96000 \SystemRoot\system32\dla\tfsnifs.sys
0xEBD8C000 \SystemRoot\system32\dla\tfsnopio.sys
0xF7BB6000 \SystemRoot\system32\dla\tfsnpool.sys
0xF79CA000 \SystemRoot\system32\dla\tfsnboio.sys
0xF6BE4000 \SystemRoot\system32\dla\tfsncofs.sys
0xF7C1E000 \SystemRoot\system32\dla\tfsndrct.sys
0xEBC7D000 \SystemRoot\system32\dla\tfsnudf.sys
0xEBC64000 \SystemRoot\system32\dla\tfsnudfa.sys
0xEBB48000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xEB9B8000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xF7BD6000 \SystemRoot\System32\Drivers\ASCTRM.SYS
0xEB928000 \SystemRoot\System32\Drivers\Defrag32.SYS
0xEB7BF000 \SystemRoot\System32\Drivers\HTTP.sys
0xEB685000 \SystemRoot\system32\drivers\ctusfsyn.sys
0xEB655000 \SystemRoot\system32\DRIVERS\ctoss2k.sys
0xEB607000 \SystemRoot\system32\DRIVERS\ctsfm2k.sys
0xBA7A9000 \SystemRoot\system32\DRIVERS\srv.sys
0xBA4C4000 \SystemRoot\system32\drivers\wdmaud.sys
0xEB888000 \SystemRoot\system32\drivers\sysaudio.sys
0xF7B6A000 \SystemRoot\system32\drivers\MSPQM.sys
0xB9D5F000 \SystemRoot\system32\drivers\kmixer.sys
0xB9D8A000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xB8D72000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100727.005\NAVEX15.SYS
0xB8D5E000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100727.005\NAVENG.SYS
0xF7C96000 \??\C:\WINDOWS\system32\Drivers\PAGEDFRG.SYS
0xB838F000 \??\C:\DOCUME~1\Rich\LOCALS~1\Temp\agloapow.sys
0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 41):
0 System Idle Process
4 System
708 C:\WINDOWS\system32\smss.exe
804 csrss.exe
836 C:\WINDOWS\system32\winlogon.exe
888 C:\WINDOWS\system32\services.exe
900 C:\WINDOWS\system32\lsass.exe
1072 C:\WINDOWS\system32\svchost.exe
1124 C:\WINDOWS\system32\ati2evxx.exe
1148 C:\WINDOWS\system32\svchost.exe
1260 C:\WINDOWS\system32\svchost.exe
1284 svchost.exe
1380 C:\WINDOWS\system32\svchost.exe
1472 svchost.exe
1600 svchost.exe
1792 C:\WINDOWS\system32\spoolsv.exe
1880 svchost.exe
1908 C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
1932 C:\WINDOWS\system32\bgsvcgen.exe
1972 C:\WINDOWS\system32\CTSVCCDA.EXE
1996 C:\WINDOWS\ehome\ehrecvr.exe
2012 C:\WINDOWS\ehome\ehSched.exe
372 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
492 C:\Program Files\Java\jre6\bin\jqs.exe
548 C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe
756 svchost.exe
792 C:\WINDOWS\system32\svchost.exe
1324 C:\Program Files\Raxco\PerfectDisk\PDSched.exe
1524 mcrdsvc.exe
3008 alg.exe
3704 C:\WINDOWS\system32\dllhost.exe
2708 C:\WINDOWS\system32\svchost.exe
2672 C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe
3364 C:\WINDOWS\explorer.exe
3484 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb02.exe
2140 C:\WINDOWS\system32\UMonit.exe
2852 C:\WINDOWS\system32\wscntfy.exe
2512 C:\WINDOWS\system32\notepad.exe
488 C:\WINDOWS\system32\notepad.exe
2504 C:\Documents and Settings\Rich\Local Settings\Temporary Internet Files\Content.IE5\DB0D5ISW\ovtt8uum[1].exe
3692 C:\Documents and Settings\Rich\Local Settings\Temporary Internet Files\Content.IE5\DB0D5ISW\MBRCheck_beta[1].exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00fb0400 (NTFS)
\\.\E: –> \\.\PhysicalDrive1 at offset 0x00000001`834faa00 (FAT32)
\\.\Y: –> \\.\PhysicalDrive0 at offset 0x00000011`763c3c00 (NTFS)
\\.\Z: –> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (FAT32)

Size Device Name MBR Status
——————————————–
74 GB \\.\PhysicalDrive0 Known-bad MBR code detected (Whistler / Black Internet)!
SHA1: C27D39757668E41BCFB7B4194C84A4D39EB0BCD6
41 GB \\.\PhysicalDrive1 Known-bad MBR code detected (Whistler / Black Internet)!
SHA1: C27D39757668E41BCFB7B4194C84A4D39EB0BCD6


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
friggit,

It looks like you ran ComboFix on this machine. It would help if I could see the log, this should open it:

🖼Click to load external image (Posted Image) Click Start > Run or press Windows Key + R copy/paste the following into the run box that opens and press OK:
c:\ComboFix.txt

For future reference, ComboFix is an excellent, but very powerful tool that isn't intended for unsupervised use. If used improperly, or under certain conditions it can render your PC unbootable.

Please include the following in your next post:
  • ComboFix log (if available)
Hi RPM, I was going to try Combofix but after reading about how I could screw up I never ran it. I checked as you asked and there is no file.friggit.
friggit,

OK. If you still have it on your desktop, delete it and grab a new copy:

🖼Click to load external image (Posted Image) Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please include the following in your next post:
  • ComboFix log
Hi RPM, Heres the Combofix log.ComboFix 10-07-26.04 - Rich 07/27/2010 18:36:29.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.367 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Shared
c:\windows\system32\Data

.
MBR is infected with the Whistler Bootkit !!

((((((((((((((((((((((((( Files Created from 2010-06-27 to 2010-07-27 )))))))))))))))))))))))))))))))
.

2010-07-27 03:24 . 2010-07-27 03:24 25992 —-a-w- c:\windows\system32\pgdfgsvc.exe
2010-07-26 22:44 . 2010-07-26 22:44 388096 —-a-r- c:\documents and settings\Rich\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-26 22:44 . 2010-07-26 22:44 ——– d—–w- c:\program files\Trend Micro
2010-07-26 18:47 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-26 18:47 . 2010-07-26 18:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-26 18:47 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-26 18:40 . 2009-03-23 20:35 200704 —-a-w- c:\windows\system32\UMonit.exe
2010-07-26 18:40 . 2008-10-21 21:59 9584640 —-a-w- c:\windows\system32\GeneIcon.dll
2010-07-26 18:40 . 2008-07-07 20:30 167936 —-a-w- c:\windows\system32\ustor.dll
2010-07-26 18:39 . 2007-06-11 14:27 12416 —-a-w- c:\windows\system32\drivers\fixustor.sys
2010-07-25 22:08 . 2010-07-25 22:08 63488 —-a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-25 22:08 . 2010-07-25 22:08 52224 —-a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-25 22:08 . 2010-07-25 22:08 117760 —-a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-25 22:08 . 2010-07-25 22:08 ——– d—–w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2010-07-25 02:42 . 2010-07-25 02:42 22436 —ha-w- c:\windows\system32\mlfcache.dat
2010-07-25 02:35 . 2010-07-25 06:01 ——– d—–w- c:\program files\Safari
2010-07-23 00:48 . 2010-07-23 00:48 ——– d—–w- c:\program files\TrendMicro
2010-07-23 00:46 . 2010-07-23 00:46 63488 —-a-w- c:\documents and settings\Rich\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-23 00:46 . 2010-07-23 00:46 52224 —-a-w- c:\documents and settings\Rich\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-23 00:46 . 2010-07-23 00:46 117760 —-a-w- c:\documents and settings\Rich\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-23 00:45 . 2010-07-23 00:45 ——– d—–w- c:\documents and settings\Rich\Application Data\SUPERAntiSpyware.com
2010-07-23 00:45 . 2010-07-23 00:45 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-07-22 22:07 . 2010-07-22 22:07 ——– d—–w- c:\documents and settings\Rich\Application Data\Malwarebytes
2010-07-22 22:06 . 2010-07-22 22:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-21 02:33 . 2010-07-21 02:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-07-20 20:55 . 2010-07-20 20:55 ——– d—–w- c:\program files\CCleaner
2010-07-14 01:46 . 2006-02-10 01:05 520192 ——w- c:\windows\system32\ati2sgag.exe
2010-07-14 01:41 . 2010-07-14 01:42 ——– d—–w- c:\documents and settings\Rich\Local Settings\Application Data\Deployment
2010-07-14 00:06 . 2010-07-14 00:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-07-14 00:06 . 2010-07-14 00:06 ——– d—–w- c:\program files\Common Files\Apple
2010-07-14 00:05 . 2010-07-14 00:05 ——– d—–w- c:\program files\Apple Software Update
2010-07-13 23:05 . 2010-06-14 14:30 743936 ——w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-11 16:37 . 2010-07-11 16:38 ——– d—–w- c:\documents and settings\Carol\Local Settings\Application Data\PhotoChannel
2010-07-07 00:53 . 2010-07-07 00:53 ——– d—–w- c:\documents and settings\Rich\Local Settings\Application Data\Geckofx
2010-07-07 00:53 . 2010-07-13 23:48 ——– d—–w- c:\program files\AviSynth 2.5
2010-07-07 00:22 . 2010-07-07 00:23 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-07 00:21 . 2010-07-14 00:06 ——– d—–w- c:\program files\QuickTime
2010-07-06 18:15 . 2010-07-06 18:15 ——– d—–w- c:\documents and settings\Rich\Application Data\Yamb
2010-07-06 18:15 . 2010-07-06 18:15 128682 —-a-w- c:\documents and settings\Rich\Application Data\Yamb\Uninstall.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-27 03:36 . 2010-05-09 07:02 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-27 03:35 . 2010-01-31 00:57 ——– d—–w- c:\program files\SpywareBlaster
2010-07-25 21:59 . 2010-07-25 21:59 608 —-a-w- c:\program files\smitrem.lnk
2010-07-25 02:41 . 2010-05-12 05:00 ——– d—–w- c:\documents and settings\Rich\Application Data\Apple Computer
2010-07-23 04:08 . 2010-07-23 04:08 32768 —-a-w- c:\windows\~DF3278.tmp
2010-07-21 00:35 . 2010-05-24 07:34 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-07-21 00:34 . 2010-05-24 07:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-21 00:32 . 2010-05-23 02:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-07-14 01:46 . 2010-01-30 18:14 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-07-09 00:58 . 2010-02-15 17:30 ——– d—–w- c:\documents and settings\Rich\Application Data\U3
2010-07-03 15:39 . 2010-07-03 15:39 134669 —-a-w- c:\program files\Ashley awake 2 weeks old (1000 x 750).jpg
2010-07-03 15:37 . 2010-01-31 00:57 ——– d—–w- c:\program files\PIXresizer
2010-06-24 14:17 . 2010-06-24 14:17 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2010-06-23 01:41 . 2010-06-23 01:41 50354 —-a-w- c:\documents and settings\Carol\Application Data\Facebook\uninstall.exe
2010-06-23 01:41 . 2010-06-23 01:41 ——– d—–w- c:\documents and settings\Carol\Application Data\Facebook
2010-06-14 14:30 . 2005-08-16 10:40 743936 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-09 14:55 . 2010-02-03 17:14 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-09 10:45 . 2010-06-09 10:45 5591040 —-a-w- c:\documents and settings\Carol\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-06-04 16:29 . 2010-06-04 16:29 71992 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-05-23 02:30 . 2010-05-23 02:30 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-05-05 07:11 . 2010-05-05 07:11 32768 —-a-w- c:\windows\~DF1AAD.tmp
2010-05-02 05:56 . 2005-08-16 10:18 1850880 —-a-w- c:\windows\system32\win32k.sys
2006-05-19 08:57 . 2010-01-31 01:31 532480 -c–a-w- c:\program files\cwshredder.exe
2010-02-07 03:52 . 2010-02-06 20:00 56 –sh–r- c:\windows\system32\866971AEE0.sys
2010-02-07 03:52 . 2010-02-06 19:59 3350 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Rich\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-07-25 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb02.exe" [2001-03-09 192512]
"UMonit"="c:\windows\system32\UMonit.exe" [2009-03-23 200704]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10e.exe" [2010-01-27 256280]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PHOTOfunSTUDIO 4.0 HD Edition.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PHOTOfunSTUDIO 4.0 HD Edition.lnk
backup=c:\windows\pss\PHOTOfunSTUDIO 4.0 HD Edition.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2009-06-19 15:44 195072 —-a-w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2006-02-10 01:05 344064 —-a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-10-09 16:28 139264 —-a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU]
2006-03-26 18:11 61440 —-a-w- c:\dell\bldbubg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
2004-12-03 00:23 102400 ——w- c:\program files\Creative\MediaSource\Detector\CTDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-10 11:00 15360 -c–a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2005-09-15 15:47 57344 ——w- c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2005-05-15 08:04 332800 —-a-w- c:\program files\Dell Support\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2004-12-06 07:05 127035 -c–a-w- c:\windows\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2005-02-23 22:19 53248 -c—-w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-09-29 20:01 67584 —-a-w- c:\windows\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HTAReg]
2005-07-15 23:06 552960 ——w- c:\program files\Creative\Sound Blaster Audigy ADVANCED MB\Product Registration\English\HTAReg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2005-06-17 13:56 139264 -c–a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
2003-09-04 02:12 221184 -c–a-w- c:\program files\Intel\Modem Event Monitor\IntelMEM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-06-10 16:44 249856 -c–a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-06-10 16:44 81920 -c–a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MBDef]
2005-02-17 01:41 20480 —-a-w- c:\windows\MBDEF.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MBMon]
2005-05-19 14:54 1345520 —-a-w- c:\windows\system32\CTMBHA.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
2005-09-09 01:20 8192 -c–a-w- c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2005-09-09 01:20 110592 -c–a-w- c:\progra~1\MUSICM~1\MUSICM~3\mm_tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-10-13 16:24 1694208 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 21:40 155648 —-a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 01:53 421888 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2010-01-30 20:53 26112 -c–a-w- c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefaultMIDI]
2004-12-22 23:40 24576 —-a-w- c:\windows\MIDIDEF.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2005-03-23 06:20 339968 -c–a-w- c:\windows\stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-11 20:21 246504 -c–a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UMonit]
2009-03-23 20:35 200704 —-a-w- c:\windows\system32\UMonit.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 07:00 90112 ——w- c:\windows\Updreg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoiceCenter]
2005-09-19 13:42 1159168 ——w- c:\program files\Creative\VoiceCenter\AndreaVC.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX1000]
2009-06-26 22:21 757248 -c–a-w- c:\windows\vVX1000.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1107000.00C\symds.sys [5/20/2010 8:04 PM 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1107000.00C\symefa.sys [5/20/2010 8:04 PM 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20100709.001\BHDrvx86.sys [7/12/2010 8:18 PM 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1107000.00C\cchpx86.sys [5/20/2010 8:04 PM 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1107000.00C\ironx86.sys [5/20/2010 8:04 PM 116784]
R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe [5/20/2010 8:04 PM 126392]
R2 PDSched;PDScheduler;c:\program files\Raxco\PerfectDisk\PDSched.exe [11/1/2004 1:56 PM 237635]
R3 Angel;Angel MPEG Device;c:\windows\system32\drivers\Angel.sys [3/26/2006 2:08 PM 375936]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/27/2010 12:07 AM 102448]
R3 FIXUSTOR;FIXUSTOR;c:\windows\system32\drivers\fixustor.sys [7/26/2010 2:39 PM 12416]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100723.001\IDSXpx86.sys [7/23/2010 8:28 PM 331640]
S1 SABKUTIL;SABKUTIL;\??\c:\documents and settings\Administrator\Desktop\SUPERAntiSpyware\SABKUTIL.sys –> c:\documents and settings\Administrator\Desktop\SUPERAntiSpyware\SABKUTIL.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS –> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.SYS –> c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/2/2010 10:17 AM 135664]

— Other Services/Drivers In Memory —

*NewlyCreated* - AGLOAPOW
*Deregistered* - agloapow
*Deregistered* - PAGEDFRG
.
Contents of the 'Scheduled Tasks' folder

2010-07-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2010-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 14:17]

2010-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 14:17]

2010-07-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2210250969-1846776457-4030474616-1005Core.job
- c:\documents and settings\Rich\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-25 03:59]

2010-07-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2210250969-1846776457-4030474616-1005UA.job
- c:\documents and settings\Rich\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-25 03:59]

2010-07-27 c:\windows\Tasks\Norton Security Scan for Rich.job
- c:\program files\Norton Security Scan\Engine\2.7.0.52\Nss.exe [2010-01-31 03:30]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = https://buy.norton.com/rd/directrenewal?NOS…vendtag=B97NJ91
uInternet Settings,ProxyServer = http=;ftp=;https=;
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
Trusted Zone: musicmatch.com\online
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
FF - ProfilePath - c:\documents and settings\Rich\Application Data\Mozilla\Firefox\Profiles\8k1mfdxw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\Rich\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
Notify-!SASWinLogon - c:\program files\SUPERAntiSpyware\SASWINLO.DLL
MSConfigStartUp-Corel Photo Downloader - c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
MSConfigStartUp-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
AddRemove-ArcSoft PhotoImpression 3.0 - c:\program files\ArcSoft\PhotoImpression\Uninst.isu
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-27 18:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
UMonit = c:\windows\system32\UMonit.exe?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\17.7.0.12\diMaster.dll\" /prefetch:1"
.
Completion time: 2010-07-27 18:54:27
ComboFix-quarantined-files.txt 2010-07-27 22:54

Pre-Run: 20,886,224,896 bytes free
Post-Run: 20,900,184,064 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

- - End Of File - - 57BC8D53A293D07BD44759A950C0F2C5
friggit,

You will be running MBRCheck 3 times in this step - Each time it's a little different, so please read the instructions carefully:

🖼Click to load external image (Posted Image) Run MBRCheck again
  • Double click the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window similar to this should open on your desktop:

    🖼Click to load external image (Posted Image)
  • At the prompt, enter Y and hit Enter
  • At the next prompt (Options), select 2 and hit Enter
  • At the "Enter the physical drive number to fix" option, select 0 and hit Enter
  • At the "Available MBR codes" prompt, select 1 and hit Enter
  • The program will prompt for confirmation. Type YES and hit Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop
  • Reboot your PC
  • Post the contents of the log
🖼Click to load external image (Posted Image) Run MBRCheck again
  • Double click the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window similar to this should open on your desktop:

    🖼Click to load external image (Posted Image)
  • At the prompt, enter Y and hit Enter
  • At the next prompt (Options), select 2 and hit Enter
  • At the "Enter the physical drive number to fix" option, select 1 and hit Enter
  • At the "Available MBR codes" prompt, select 1 and hit Enter
  • The program will prompt for confirmation. Type YES and hit Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop
  • Reboot your PC
  • Post the contents of the log
🖼Click to load external image (Posted Image) Run MBRCheck again
  • Double click the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window similar to this should open on your desktop:

    🖼Click to load external image (Posted Image)
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your deskop. Please post the contents of that file.
Please include the following in your next post:
  • All 3 MBRCheck logs
Hi RP, Here they are:MBRCheck, version 1.2.2 © 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 2 (build 2600) Logical Drives Mask: 0x030007fc Kernel Drivers (total 212): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806CF000 \WINDOWS\system32\hal.dll 0xF7B52000 \WINDOWS\system32\KDCOM.DLL 0xF7A62000 \WINDOWS\system32\BOOTVID.dll 0xF7523000 ACPI.sys 0xF7B54000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF7512000 pci.sys 0xF7652000 isapnp.sys 0xF7C1A000 pciide.sys 0xF78D2000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF7B56000 aliide.sys 0xF7B58000 cmdide.sys 0xF7B5A000 toside.sys 0xF7B5C000 viaide.sys 0xF7B5E000 intelide.sys 0xF7662000 MountMgr.sys 0xF74F3000 ftdisk.sys 0xF7B60000 dmload.sys 0xF74CD000 dmio.sys 0xF78DA000 PartMgr.sys 0xF7672000 VolSnap.sys 0xF7A66000 cpqarray.sys 0xF74B5000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS 0xF73E0000 iastor.sys 0xF73C8000 atapi.sys 0xF7A6A000 aha154x.sys 0xF78E2000 sparrow.sys 0xF7A6E000 symc810.sys 0xF7682000 aic78xx.sys 0xF7A72000 dac960nt.sys 0xF7692000 ql10wnt.sys 0xF7A76000 amsint.sys 0xF78EA000 asc.sys 0xF7A7A000 asc3550.sys 0xF78F2000 mraid35x.sys 0xF78FA000 i2omp.sys 0xF7A7E000 ini910u.sys 0xF76A2000 ql1240.sys 0xF76B2000 aic78u2.sys 0xF7902000 symc8xx.sys 0xF790A000 sym_hi.sys 0xF7912000 sym_u3.sys 0xF791A000 ABP480N5.SYS 0xF7922000 asc3350p.sys 0xF7B62000 cd20xrnt.sys 0xF76C2000 ultra.sys 0xF73AF000 adpu160m.sys 0xF792A000 dpti2o.sys 0xF76D2000 ql1080.sys 0xF76E2000 ql1280.sys 0xF76F2000 ql12160.sys 0xF7932000 perc2.sys 0xF7B64000 perc2hib.sys 0xF793A000 hpn.sys 0xF7A82000 cbidf2k.sys 0xF7383000 dac2w2k.sys 0xF7702000 disk.sys 0xF7712000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF7363000 fltMgr.sys 0xF730D000 SYMDS.SYS 0xF72FB000 sr.sys 0xF72CE000 SYMEFA.SYS 0xF72B9000 drvmcdb.sys 0xF7942000 PxHelp20.sys 0xF72A2000 KSecDD.sys 0xF7722000 Defrag32b.sys 0xF7215000 Ntfs.sys 0xF71E8000 NDIS.sys 0xF7732000 sisagp.sys 0xF7742000 viaagp.sys 0xF71CD000 Mup.sys 0xF7752000 agp440.sys 0xF7762000 alim1541.sys 0xF7772000 amdagp.sys 0xF7782000 agpCPQ.sys 0xF77A2000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF6F37000 \SystemRoot\system32\DRIVERS\ati2mtag.sys 0xF6F23000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF6EFD000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xF6ED2000 \SystemRoot\system32\DRIVERS\e1e5132.sys 0xF7A02000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF6EAF000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF7A32000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF6E53000 \SystemRoot\system32\DRIVERS\Angel.sys 0xF6E30000 \SystemRoot\system32\DRIVERS\ks.sys 0xF7BF2000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF77B2000 \SystemRoot\system32\DRIVERS\IntelC53.sys 0xF6D09000 \SystemRoot\system32\DRIVERS\IntelC51.sys 0xF6C74000 \SystemRoot\system32\DRIVERS\IntelC52.sys 0xF7962000 \SystemRoot\system32\DRIVERS\mohfilt.sys 0xF797A000 \SystemRoot\System32\Drivers\Modem.SYS 0xF77C2000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF799A000 \SystemRoot\system32\drivers\Afc.sys 0xF77D2000 \SystemRoot\System32\Drivers\cdrbsdrv.SYS 0xF7BFA000 \SystemRoot\system32\drivers\sscdbhk5.sys 0xF77E2000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF77F2000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF7D92000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF7802000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF70C4000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF6C5D000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF7812000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF7822000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF7A12000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF6C24000 \SystemRoot\system32\DRIVERS\psched.sys 0xF7832000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF7A42000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF7A52000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF6B53000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0xF7842000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF79A2000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF79B2000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7C04000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF6AFA000 \SystemRoot\system32\DRIVERS\update.sys 0xF7B32000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF71A9000 \SystemRoot\system32\drivers\MODEMCSA.sys 0xF7862000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xEEA5D000 \SystemRoot\system32\drivers\sthda.sys 0xEEA39000 \SystemRoot\system32\drivers\portcls.sys 0xF7892000 \SystemRoot\system32\drivers\drmk.sys 0xEE8EF000 \SystemRoot\system32\drivers\sigfilt.sys 0xF78B2000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7C10000 \SystemRoot\System32\Drivers\i2omgmt.SYS 0xEE850000 \SystemRoot\System32\Drivers\NIS\1107000.00C\SRTSP.SYS 0xEE831000 \SystemRoot\system32\drivers\NIS\1107000.00C\Ironx86.SYS 0xF7175000 \SystemRoot\system32\drivers\NIS\1107000.00C\SRTSPX.SYS 0xEE620000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 0xF7A0A000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0xF7952000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0xEE8C3000 \SystemRoot\system32\DRIVERS\fixustor.sys 0xEE42E000 \SystemRoot\system32\DRIVERS\VX1000.sys 0xF7135000 \SystemRoot\system32\DRIVERS\STREAM.SYS 0xF7125000 \SystemRoot\system32\drivers\usbaudio.sys 0xF7B70000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7C48000 \SystemRoot\System32\Drivers\Null.SYS 0xF7B74000 \SystemRoot\System32\Drivers\Beep.SYS 0xF79AA000 \SystemRoot\system32\drivers\ssrtln.sys 0xF79DA000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF79F2000 \SystemRoot\System32\drivers\vga.sys 0xF7B86000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7B8A000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF79FA000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF7A22000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF6AE2000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xEE383000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xEE32B000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xEE2D4000 \SystemRoot\System32\Drivers\NIS\1107000.00C\SYMTDI.SYS 0xEE2B3000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF7145000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xF7185000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xEE7F1000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF70E5000 \SystemRoot\system32\DRIVERS\IrBus.sys 0xEE25E000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100723.001\IDSxpx86.sys 0xEE236000 \SystemRoot\system32\DRIVERS\netbt.sys 0xEE214000 \SystemRoot\System32\drivers\afd.sys 0xEE821000 \SystemRoot\system32\DRIVERS\netbios.sys 0xEE1E9000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xF7A2A000 \SystemRoot\system32\DRIVERS\usbprint.sys 0xEE17A000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF6ABA000 \SystemRoot\system32\DRIVERS\usbscan.sys 0xF7105000 \SystemRoot\System32\Drivers\Fips.SYS 0xEE11C000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 0xEE3FE000 \SystemRoot\system32\DRIVERS\hidir.sys 0xEE8AF000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0xEE8A7000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xEE0FF000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 0xEE058000 \SystemRoot\system32\drivers\NIS\1107000.00C\ccHPx86.sys 0xEDFAC000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20100709.001\BHDrvx86.sys 0xEDF89000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xEDE8C000 \SystemRoot\System32\Drivers\dump_iastor.sys 0xBF800000 \SystemRoot\System32\win32k.sys 0xF6AB2000 \SystemRoot\System32\drivers\Dxapi.sys 0xEE40E000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7CA6000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\ati2dvag.dll 0xBF049000 \SystemRoot\System32\ati2cqag.dll 0xBF07D000 \SystemRoot\System32\atikvmag.dll 0xBF0B2000 \SystemRoot\System32\ati3duag.dll 0xBF2F4000 \SystemRoot\System32\ativvaxx.dll 0xEE7B1000 \SystemRoot\system32\drivers\drvnddm.sys 0xF7D72000 \SystemRoot\system32\dla\tfsndres.sys 0xEBC96000 \SystemRoot\system32\dla\tfsnifs.sys 0xEBD8C000 \SystemRoot\system32\dla\tfsnopio.sys 0xF7BB6000 \SystemRoot\system32\dla\tfsnpool.sys 0xF79CA000 \SystemRoot\system32\dla\tfsnboio.sys 0xF6BE4000 \SystemRoot\system32\dla\tfsncofs.sys 0xF7C1E000 \SystemRoot\system32\dla\tfsndrct.sys 0xEBC7D000 \SystemRoot\system32\dla\tfsnudf.sys 0xEBC64000 \SystemRoot\system32\dla\tfsnudfa.sys 0xEBB48000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xEB9B8000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xF7BD6000 \SystemRoot\System32\Drivers\ASCTRM.SYS 0xEB928000 \SystemRoot\System32\Drivers\Defrag32.SYS 0xEB7BF000 \SystemRoot\System32\Drivers\HTTP.sys 0xEB685000 \SystemRoot\system32\drivers\ctusfsyn.sys 0xEB655000 \SystemRoot\system32\DRIVERS\ctoss2k.sys 0xEB607000 \SystemRoot\system32\DRIVERS\ctsfm2k.sys 0xBA7A9000 \SystemRoot\system32\DRIVERS\srv.sys 0xBA4C4000 \SystemRoot\system32\drivers\wdmaud.sys 0xEB888000 \SystemRoot\system32\drivers\sysaudio.sys 0xF7B6A000 \SystemRoot\system32\drivers\MSPQM.sys 0xB9D5F000 \SystemRoot\system32\drivers\kmixer.sys 0xB9D8A000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xF7C96000 \??\C:\WINDOWS\system32\Drivers\PAGEDFRG.SYS 0xB838F000 \??\C:\DOCUME~1\Rich\LOCALS~1\Temp\agloapow.sys 0xEE3E6000 \??\C:\DOCUME~1\Rich\LOCALS~1\Temp\catchme.sys 0xB8F38000 \??\C:\WINDOWS\system32\Drivers\PROCEXP113.SYS 0xB925E000 \??\C:\DOCUME~1\Rich\LOCALS~1\Temp\mbr.sys 0xB8016000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100727.032\NAVEX15.SYS 0xB8002000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100727.032\NAVENG.SYS 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 37): 0 System Idle Process 4 System 708 C:\WINDOWS\system32\smss.exe 804 csrss.exe 836 C:\WINDOWS\system32\winlogon.exe 888 C:\WINDOWS\system32\services.exe 900 C:\WINDOWS\system32\lsass.exe 1124 C:\WINDOWS\system32\ati2evxx.exe 1148 C:\WINDOWS\system32\svchost.exe 1284 svchost.exe 1380 C:\WINDOWS\system32\svchost.exe 1472 svchost.exe 1600 svchost.exe 1792 C:\WINDOWS\system32\spoolsv.exe 1880 svchost.exe 1908 C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 1932 C:\WINDOWS\system32\bgsvcgen.exe 1972 C:\WINDOWS\system32\CTSVCCDA.EXE 1996 C:\WINDOWS\ehome\ehrecvr.exe 2012 C:\WINDOWS\ehome\ehSched.exe 372 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe 492 C:\Program Files\Java\jre6\bin\jqs.exe 548 C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe 756 svchost.exe 792 C:\WINDOWS\system32\svchost.exe 1324 C:\Program Files\Raxco\PerfectDisk\PDSched.exe 1524 mcrdsvc.exe 3008 alg.exe 3704 C:\WINDOWS\system32\dllhost.exe 2708 C:\WINDOWS\system32\svchost.exe 2672 C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe 3484 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb02.exe 1696 C:\WINDOWS\system32\svchost.exe 1244 C:\WINDOWS\system32\svchost.exe 3808 C:\WINDOWS\explorer.exe 3316 C:\Program Files\Internet Explorer\iexplore.exe 3296 C:\Documents and Settings\Rich\Desktop\MBRCheck_beta.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00fb0400 (NTFS) \\.\E: –> \\.\PhysicalDrive1 at offset 0x00000001`834faa00 (FAT32) \\.\Y: –> \\.\PhysicalDrive0 at offset 0x00000011`763c3c00 (NTFS) \\.\Z: –> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (FAT32) Size Device Name MBR Status ——————————————– 74 GB \\.\PhysicalDrive0 Known-bad MBR code detected (Whistler / Black Internet)! SHA1: C27D39757668E41BCFB7B4194C84A4D39EB0BCD6 41 GB \\.\PhysicalDrive1 Known-bad MBR code detected (Whistler / Black Internet)! SHA1: C27D39757668E41BCFB7B4194C84A4D39EB0BCD6 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Options: [1] Dump the MBR of a physical disk to file. [2] Restore the MBR of a physical disk with a standard boot code. [3] Exit. Enter your choice: Enter the physical disk number to fix (0-99, -1 to cancel): 0Available MBR codes: [ 0] Default (Windows XP) [ 1] Windows XP [ 2] Windows Server 2003 [ 3] Windows Vista [ 4] Windows 2008 [ 5] Windows 7 [-1] Cancel Please select the MBR code to write to this drive: 1 Do you want to fix the MBR code? Type 'YES' and hit ENTER to continue: yes Successfully wrote new MBR code! Please reboot your computer to complete the fix. MBRCheck, version 1.2.2 © 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 2 (build 2600) Logical Drives Mask: 0x030007fc Kernel Drivers (total 206): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806CF000 \WINDOWS\system32\hal.dll 0xF7B52000 \WINDOWS\system32\KDCOM.DLL 0xF7A62000 \WINDOWS\system32\BOOTVID.dll 0xF7523000 ACPI.sys 0xF7B54000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF7512000 pci.sys 0xF7652000 isapnp.sys 0xF7C1A000 pciide.sys 0xF78D2000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF7B56000 aliide.sys 0xF7B58000 cmdide.sys 0xF7B5A000 toside.sys 0xF7B5C000 viaide.sys 0xF7B5E000 intelide.sys 0xF7662000 MountMgr.sys 0xF74F3000 ftdisk.sys 0xF7B60000 dmload.sys 0xF74CD000 dmio.sys 0xF78DA000 PartMgr.sys 0xF7672000 VolSnap.sys 0xF7A66000 cpqarray.sys 0xF74B5000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS 0xF73E0000 iastor.sys 0xF73C8000 atapi.sys 0xF7A6A000 aha154x.sys 0xF78E2000 sparrow.sys 0xF7A6E000 symc810.sys 0xF7682000 aic78xx.sys 0xF7A72000 dac960nt.sys 0xF7692000 ql10wnt.sys 0xF7A76000 amsint.sys 0xF78EA000 asc.sys 0xF7A7A000 asc3550.sys 0xF78F2000 mraid35x.sys 0xF78FA000 i2omp.sys 0xF7A7E000 ini910u.sys 0xF76A2000 ql1240.sys 0xF76B2000 aic78u2.sys 0xF7902000 symc8xx.sys 0xF790A000 sym_hi.sys 0xF7912000 sym_u3.sys 0xF791A000 ABP480N5.SYS 0xF7922000 asc3350p.sys 0xF7B62000 cd20xrnt.sys 0xF76C2000 ultra.sys 0xF73AF000 adpu160m.sys 0xF792A000 dpti2o.sys 0xF76D2000 ql1080.sys 0xF76E2000 ql1280.sys 0xF76F2000 ql12160.sys 0xF7932000 perc2.sys 0xF7B64000 perc2hib.sys 0xF793A000 hpn.sys 0xF7A82000 cbidf2k.sys 0xF7383000 dac2w2k.sys 0xF7702000 disk.sys 0xF7712000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF7363000 fltMgr.sys 0xF730D000 SYMDS.SYS 0xF72FB000 sr.sys 0xF72CE000 SYMEFA.SYS 0xF72B9000 drvmcdb.sys 0xF7942000 PxHelp20.sys 0xF72A2000 KSecDD.sys 0xF7722000 Defrag32b.sys 0xF7215000 Ntfs.sys 0xF71E8000 NDIS.sys 0xF7732000 sisagp.sys 0xF7742000 viaagp.sys 0xF71CD000 Mup.sys 0xF7752000 agp440.sys 0xF7762000 alim1541.sys 0xF7772000 amdagp.sys 0xF7782000 agpCPQ.sys 0xF77A2000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF6F37000 \SystemRoot\system32\DRIVERS\ati2mtag.sys 0xF6F23000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF6EFD000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xF6ED2000 \SystemRoot\system32\DRIVERS\e1e5132.sys 0xF79FA000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF6EAF000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF7A2A000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF6E53000 \SystemRoot\system32\DRIVERS\Angel.sys 0xF6E30000 \SystemRoot\system32\DRIVERS\ks.sys 0xF7BE2000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF77B2000 \SystemRoot\system32\DRIVERS\IntelC53.sys 0xF6D09000 \SystemRoot\system32\DRIVERS\IntelC51.sys 0xF6C74000 \SystemRoot\system32\DRIVERS\IntelC52.sys 0xF795A000 \SystemRoot\system32\DRIVERS\mohfilt.sys 0xF7972000 \SystemRoot\System32\Drivers\Modem.SYS 0xF77C2000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF798A000 \SystemRoot\system32\drivers\Afc.sys 0xF77D2000 \SystemRoot\System32\Drivers\cdrbsdrv.SYS 0xF7BEE000 \SystemRoot\system32\drivers\sscdbhk5.sys 0xF77E2000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF77F2000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF7D70000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF7802000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF70C4000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF6C5D000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF7812000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF7822000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF7A12000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF6C24000 \SystemRoot\system32\DRIVERS\psched.sys 0xF7832000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF7A3A000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF7A4A000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF6B53000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0xF7842000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF79A2000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF79B2000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7BF4000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF6AFA000 \SystemRoot\system32\DRIVERS\update.sys 0xF7B2A000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF7B4A000 \SystemRoot\system32\drivers\MODEMCSA.sys 0xF7862000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xEEA5D000 \SystemRoot\system32\drivers\sthda.sys 0xEEA39000 \SystemRoot\system32\drivers\portcls.sys 0xF7892000 \SystemRoot\system32\drivers\drmk.sys 0xEE8EF000 \SystemRoot\system32\drivers\sigfilt.sys 0xF78B2000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7C00000 \SystemRoot\System32\Drivers\i2omgmt.SYS 0xEE850000 \SystemRoot\System32\Drivers\NIS\1107000.00C\SRTSP.SYS 0xEE831000 \SystemRoot\system32\drivers\NIS\1107000.00C\Ironx86.SYS 0xF7175000 \SystemRoot\system32\drivers\NIS\1107000.00C\SRTSPX.SYS 0xEE645000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100727.032\NAVEX15.SYS 0xEE620000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 0xEE60C000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100727.032\NAVENG.SYS 0xF7A0A000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0xF7952000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0xEE8C7000 \SystemRoot\system32\DRIVERS\fixustor.sys 0xEE42E000 \SystemRoot\system32\DRIVERS\VX1000.sys 0xF7135000 \SystemRoot\system32\DRIVERS\STREAM.SYS 0xF7125000 \SystemRoot\system32\drivers\usbaudio.sys 0xF7BF2000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7C69000 \SystemRoot\System32\Drivers\Null.SYS 0xF7BFA000 \SystemRoot\System32\Drivers\Beep.SYS 0xF796A000 \SystemRoot\system32\drivers\ssrtln.sys 0xF79AA000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF79C2000 \SystemRoot\System32\drivers\vga.sys 0xF7C10000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7C14000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF79E2000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF79F2000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF6ABE000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xEE383000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xEE32B000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xEE2D4000 \SystemRoot\System32\Drivers\NIS\1107000.00C\SYMTDI.SYS 0xEE2B3000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF7155000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xEE8BB000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xF6BC4000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF6BB4000 \SystemRoot\system32\DRIVERS\IrBus.sys 0xEE25E000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100723.001\IDSxpx86.sys 0xEE236000 \SystemRoot\system32\DRIVERS\netbt.sys 0xF7A5A000 \SystemRoot\system32\DRIVERS\usbprint.sys 0xEE214000 \SystemRoot\System32\drivers\afd.sys 0xEE8BF000 \SystemRoot\system32\DRIVERS\usbscan.sys 0xF6BE4000 \SystemRoot\system32\DRIVERS\netbios.sys 0xEE3E6000 \SystemRoot\system32\DRIVERS\hidir.sys 0xEE1E9000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xEE8AB000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0xEE17A000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF6C39000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xF6BA4000 \SystemRoot\System32\Drivers\Fips.SYS 0xEE11C000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 0xEE0D7000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 0xEE058000 \SystemRoot\system32\drivers\NIS\1107000.00C\ccHPx86.sys 0xEDFAC000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20100709.001\BHDrvx86.sys 0xEDF89000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xEDEB4000 \SystemRoot\System32\Drivers\dump_iastor.sys 0xBF800000 \SystemRoot\System32\win32k.sys 0xF6AB6000 \SystemRoot\System32\drivers\Dxapi.sys 0xEE416000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7C7B000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\ati2dvag.dll 0xBF049000 \SystemRoot\System32\ati2cqag.dll 0xBF07D000 \SystemRoot\System32\atikvmag.dll 0xBF0B2000 \SystemRoot\System32\ati3duag.dll 0xBF2F4000 \SystemRoot\System32\ativvaxx.dll 0xF70E5000 \SystemRoot\system32\drivers\drvnddm.sys 0xF7CCF000 \SystemRoot\system32\dla\tfsndres.sys 0xEBD36000 \SystemRoot\system32\dla\tfsnifs.sys 0xEDE94000 \SystemRoot\system32\dla\tfsnopio.sys 0xF7C08000 \SystemRoot\system32\dla\tfsnpool.sys 0xF7962000 \SystemRoot\system32\dla\tfsnboio.sys 0xEBDFC000 \SystemRoot\system32\dla\tfsncofs.sys 0xF7D13000 \SystemRoot\system32\dla\tfsndrct.sys 0xEBD1D000 \SystemRoot\system32\dla\tfsnudf.sys 0xEBD04000 \SystemRoot\system32\dla\tfsnudfa.sys 0xEBC00000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xEB9CF000 \SystemRoot\system32\drivers\wdmaud.sys 0xEBA8C000 \SystemRoot\system32\drivers\sysaudio.sys 0xBA6C3000 \SystemRoot\system32\drivers\ctusfsyn.sys 0xBA693000 \SystemRoot\system32\DRIVERS\ctoss2k.sys 0xBA66D000 \SystemRoot\system32\DRIVERS\ctsfm2k.sys 0xBA641000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xF7BFE000 \SystemRoot\System32\Drivers\ASCTRM.SYS 0xF70F5000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xF7145000 \SystemRoot\System32\Drivers\Defrag32.SYS 0xBA295000 \SystemRoot\System32\Drivers\HTTP.sys 0xBA14E000 \SystemRoot\system32\DRIVERS\srv.sys 0xF7C06000 \SystemRoot\system32\drivers\MSPQM.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 38): 0 System Idle Process 4 System 704 C:\WINDOWS\system32\smss.exe 800 csrss.exe 832 C:\WINDOWS\system32\winlogon.exe 884 C:\WINDOWS\system32\services.exe 896 C:\WINDOWS\system32\lsass.exe 1088 C:\WINDOWS\system32\ati2evxx.exe 1108 C:\WINDOWS\system32\svchost.exe 1240 svchost.exe 1336 C:\WINDOWS\system32\svchost.exe 1428 svchost.exe 1580 svchost.exe 1740 C:\WINDOWS\system32\spoolsv.exe 1944 C:\WINDOWS\explorer.exe 136 svchost.exe 316 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb02.exe 324 C:\WINDOWS\system32\UMonit.exe 504 C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 488 C:\WINDOWS\system32\bgsvcgen.exe 768 C:\WINDOWS\system32\CTSVCCDA.EXE 784 C:\WINDOWS\ehome\ehrecvr.exe 328 C:\WINDOWS\ehome\ehSched.exe 1456 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe 1480 C:\Program Files\Java\jre6\bin\jqs.exe 1524 C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe 2164 svchost.exe 2308 C:\WINDOWS\system32\svchost.exe 2416 C:\Program Files\Raxco\PerfectDisk\PDSched.exe 2648 mcrdsvc.exe 3112 C:\WINDOWS\system32\wuauclt.exe 3396 C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe 3964 alg.exe 4012 C:\WINDOWS\system32\dllhost.exe 2220 C:\WINDOWS\system32\svchost.exe 2568 C:\WINDOWS\system32\wscntfy.exe 2320 C:\Program Files\Internet Explorer\iexplore.exe 1140 C:\Documents and Settings\Rich\Desktop\MBRCheck_beta.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00fb0400 (NTFS) \\.\E: –> \\.\PhysicalDrive1 at offset 0x00000001`834faa00 (FAT32) \\.\Y: –> \\.\PhysicalDrive0 at offset 0x00000011`763c3c00 (NTFS) \\.\Z: –> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (FAT32) Size Device Name MBR Status ——————————————– 74 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: 31D100779DE502702C374F7C15687B56FCFD5528 41 GB \\.\PhysicalDrive1 Known-bad MBR code detected (Whistler / Black Internet)! SHA1: C27D39757668E41BCFB7B4194C84A4D39EB0BCD6 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Options: [1] Dump the MBR of a physical disk to file. [2] Restore the MBR of a physical disk with a standard boot code. [3] Exit. Enter your choice: Enter the physical disk number to fix (0-99, -1 to cancel): 1Available MBR codes: [ 0] Default (Windows XP) [ 1] Windows XP [ 2] Windows Server 2003 [ 3] Windows Vista [ 4] Windows 2008 [ 5] Windows 7 [-1] Cancel Please select the MBR code to write to this drive: 1 Do you want to fix the MBR code? Type 'YES' and hit ENTER to continue: yes Successfully wrote new MBR code! Please reboot your computer to complete the fix. Done! Done!MBRCheck, version 1.2.2 © 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 2 (build 2600) Logical Drives Mask: 0x030007fc Kernel Drivers (total 206): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806CF000 \WINDOWS\system32\hal.dll 0xF7B52000 \WINDOWS\system32\KDCOM.DLL 0xF7A62000 \WINDOWS\system32\BOOTVID.dll 0xF7523000 ACPI.sys 0xF7B54000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF7512000 pci.sys 0xF7652000 isapnp.sys 0xF7C1A000 pciide.sys 0xF78D2000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF7B56000 aliide.sys 0xF7B58000 cmdide.sys 0xF7B5A000 toside.sys 0xF7B5C000 viaide.sys 0xF7B5E000 intelide.sys 0xF7662000 MountMgr.sys 0xF74F3000 ftdisk.sys 0xF7B60000 dmload.sys 0xF74CD000 dmio.sys 0xF78DA000 PartMgr.sys 0xF7672000 VolSnap.sys 0xF7A66000 cpqarray.sys 0xF74B5000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS 0xF73E0000 iastor.sys 0xF73C8000 atapi.sys 0xF7A6A000 aha154x.sys 0xF78E2000 sparrow.sys 0xF7A6E000 symc810.sys 0xF7682000 aic78xx.sys 0xF7A72000 dac960nt.sys 0xF7692000 ql10wnt.sys 0xF7A76000 amsint.sys 0xF78EA000 asc.sys 0xF7A7A000 asc3550.sys 0xF78F2000 mraid35x.sys 0xF78FA000 i2omp.sys 0xF7A7E000 ini910u.sys 0xF76A2000 ql1240.sys 0xF76B2000 aic78u2.sys 0xF7902000 symc8xx.sys 0xF790A000 sym_hi.sys 0xF7912000 sym_u3.sys 0xF791A000 ABP480N5.SYS 0xF7922000 asc3350p.sys 0xF7B62000 cd20xrnt.sys 0xF76C2000 ultra.sys 0xF73AF000 adpu160m.sys 0xF792A000 dpti2o.sys 0xF76D2000 ql1080.sys 0xF76E2000 ql1280.sys 0xF76F2000 ql12160.sys 0xF7932000 perc2.sys 0xF7B64000 perc2hib.sys 0xF793A000 hpn.sys 0xF7A82000 cbidf2k.sys 0xF7383000 dac2w2k.sys 0xF7702000 disk.sys 0xF7712000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF7363000 fltMgr.sys 0xF730D000 SYMDS.SYS 0xF72FB000 sr.sys 0xF72CE000 SYMEFA.SYS 0xF72B9000 drvmcdb.sys 0xF7942000 PxHelp20.sys 0xF72A2000 KSecDD.sys 0xF7722000 Defrag32b.sys 0xF7215000 Ntfs.sys 0xF71E8000 NDIS.sys 0xF7732000 sisagp.sys 0xF7742000 viaagp.sys 0xF71CD000 Mup.sys 0xF7752000 agp440.sys 0xF7762000 alim1541.sys 0xF7772000 amdagp.sys 0xF7782000 agpCPQ.sys 0xF44F2000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF2065000 \SystemRoot\system32\DRIVERS\ati2mtag.sys 0xF2051000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF202B000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xF2000000 \SystemRoot\system32\DRIVERS\e1e5132.sys 0xF7A12000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF1FDD000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF7A22000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF1F81000 \SystemRoot\system32\DRIVERS\Angel.sys 0xF1F5E000 \SystemRoot\system32\DRIVERS\ks.sys 0xF7BAC000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF44E2000 \SystemRoot\system32\DRIVERS\IntelC53.sys 0xF1E37000 \SystemRoot\system32\DRIVERS\IntelC51.sys 0xF1DA2000 \SystemRoot\system32\DRIVERS\IntelC52.sys 0xF7A1A000 \SystemRoot\system32\DRIVERS\mohfilt.sys 0xF7A2A000 \SystemRoot\System32\Drivers\Modem.SYS 0xF44D2000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF28FF000 \SystemRoot\system32\drivers\Afc.sys 0xF7165000 \SystemRoot\System32\Drivers\cdrbsdrv.SYS 0xF7BB2000 \SystemRoot\system32\drivers\sscdbhk5.sys 0xF7155000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF7145000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF7D0C000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF7135000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF7B4E000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF19D4000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF7115000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF7125000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF28F7000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF19C3000 \SystemRoot\system32\DRIVERS\psched.sys 0xF7105000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF79A2000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF79AA000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF140C000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0xF697E000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF79B2000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF79BA000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7BCC000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF12B4000 \SystemRoot\system32\DRIVERS\update.sys 0xF7185000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF7B1E000 \SystemRoot\system32\drivers\MODEMCSA.sys 0xF690E000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xB27D3000 \SystemRoot\system32\drivers\sthda.sys 0xB27AF000 \SystemRoot\system32\drivers\portcls.sys 0xF7862000 \SystemRoot\system32\drivers\drmk.sys 0xB2665000 \SystemRoot\system32\drivers\sigfilt.sys 0xF77E2000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7BF2000 \SystemRoot\System32\Drivers\i2omgmt.SYS 0xF7BF6000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7CAA000 \SystemRoot\System32\Drivers\Null.SYS 0xF7BF8000 \SystemRoot\System32\Drivers\Beep.SYS 0xF7952000 \SystemRoot\system32\drivers\ssrtln.sys 0xF7A5A000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF795A000 \SystemRoot\System32\drivers\vga.sys 0xF7BFC000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7BFE000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF7962000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF796A000 \SystemRoot\System32\Drivers\Npfs.SYS 0xB0CDE000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xB0BF3000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xB0B9B000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xB0B44000 \SystemRoot\System32\Drivers\NIS\1107000.00C\SYMTDI.SYS 0xB0B1F000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 0xB0ACA000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100723.001\IDSxpx86.sys 0xB0AA2000 \SystemRoot\system32\DRIVERS\netbt.sys 0xB0A80000 \SystemRoot\System32\drivers\afd.sys 0xF7832000 \SystemRoot\system32\DRIVERS\netbios.sys 0xB0A61000 \SystemRoot\system32\drivers\NIS\1107000.00C\Ironx86.SYS 0xF4512000 \SystemRoot\system32\drivers\NIS\1107000.00C\SRTSPX.SYS 0xB0A40000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xB0A15000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xB09A6000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF4502000 \SystemRoot\System32\Drivers\Fips.SYS 0xF124C000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xB0260000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 0xB0243000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 0xB01C4000 \SystemRoot\system32\drivers\NIS\1107000.00C\ccHPx86.sys 0xB0118000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20100709.001\BHDrvx86.sys 0xB138A000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0xB0CFA000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xB12BF000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF290F000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0xAE960000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xF6B24000 \SystemRoot\system32\DRIVERS\fixustor.sys 0xAF27D000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0xAF279000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xAE782000 \SystemRoot\system32\DRIVERS\VX1000.sys 0xF699E000 \SystemRoot\system32\DRIVERS\STREAM.SYS 0xF698E000 \SystemRoot\system32\drivers\usbaudio.sys 0xF696E000 \SystemRoot\system32\DRIVERS\IrBus.sys 0xF2907000 \SystemRoot\system32\DRIVERS\usbprint.sys 0xAF265000 \SystemRoot\system32\DRIVERS\usbscan.sys 0xF28EF000 \SystemRoot\system32\DRIVERS\hidir.sys 0xAE6AD000 \SystemRoot\System32\Drivers\dump_iastor.sys 0xBF800000 \SystemRoot\System32\win32k.sys 0xAEE91000 \SystemRoot\System32\drivers\Dxapi.sys 0xF798A000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7C24000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\ati2dvag.dll 0xBF049000 \SystemRoot\System32\ati2cqag.dll 0xBF07D000 \SystemRoot\System32\atikvmag.dll 0xBF0B2000 \SystemRoot\System32\ati3duag.dll 0xBF2F4000 \SystemRoot\System32\ativvaxx.dll 0xF692E000 \SystemRoot\system32\drivers\drvnddm.sys 0xF7C5D000 \SystemRoot\system32\dla\tfsndres.sys 0xAAEE6000 \SystemRoot\system32\dla\tfsnifs.sys 0xAEE7D000 \SystemRoot\system32\dla\tfsnopio.sys 0xF7B7A000 \SystemRoot\system32\dla\tfsnpool.sys 0xF7A0A000 \SystemRoot\system32\dla\tfsnboio.sys 0xF125C000 \SystemRoot\system32\dla\tfsncofs.sys 0xF7C6A000 \SystemRoot\system32\dla\tfsndrct.sys 0xAAECD000 \SystemRoot\system32\dla\tfsnudf.sys 0xAAEB4000 \SystemRoot\system32\dla\tfsnudfa.sys 0xF11CC000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xAADE8000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xF7C08000 \SystemRoot\System32\Drivers\ASCTRM.SYS 0xAD445000 \SystemRoot\System32\Drivers\Defrag32.SYS 0xAAC86000 \SystemRoot\system32\drivers\ctusfsyn.sys 0xAAC56000 \SystemRoot\system32\DRIVERS\ctoss2k.sys 0xAAC15000 \SystemRoot\System32\Drivers\HTTP.sys 0xAABC7000 \SystemRoot\system32\DRIVERS\ctsfm2k.sys 0xAAB8A000 \SystemRoot\system32\drivers\wdmaud.sys 0xF44C2000 \SystemRoot\system32\drivers\sysaudio.sys 0xAAB33000 \SystemRoot\system32\DRIVERS\srv.sys 0xACF04000 \SystemRoot\system32\drivers\MSPQM.sys 0xAA5F8000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xA9FA4000 \SystemRoot\System32\Drivers\NIS\1107000.00C\SRTSP.SYS 0xA9E58000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100727.032\NAVEX15.SYS 0xA9E1C000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\VirusDefs\20100727.032\NAVENG.SYS 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 37): 0 System Idle Process 4 System 684 C:\WINDOWS\system32\smss.exe 752 csrss.exe 780 C:\WINDOWS\system32\winlogon.exe 824 C:\WINDOWS\system32\services.exe 836 C:\WINDOWS\system32\lsass.exe 1040 C:\WINDOWS\system32\ati2evxx.exe 1060 C:\WINDOWS\system32\svchost.exe 1152 svchost.exe 1268 C:\WINDOWS\system32\svchost.exe 1344 svchost.exe 1396 svchost.exe 1660 C:\WINDOWS\system32\spoolsv.exe 1772 svchost.exe 1800 C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 1824 C:\WINDOWS\system32\bgsvcgen.exe 1852 C:\WINDOWS\system32\CTSVCCDA.EXE 1888 C:\WINDOWS\ehome\ehrecvr.exe 1900 C:\WINDOWS\ehome\ehSched.exe 248 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe 280 C:\Program Files\Java\jre6\bin\jqs.exe 324 C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe 744 svchost.exe 840 C:\WINDOWS\system32\svchost.exe 1460 C:\Program Files\Raxco\PerfectDisk\PDSched.exe 1536 mcrdsvc.exe 2536 C:\WINDOWS\system32\wuauclt.exe 2840 C:\WINDOWS\system32\dllhost.exe 3164 alg.exe 3584 C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe 3796 C:\WINDOWS\explorer.exe 3952 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb02.exe 3972 C:\WINDOWS\system32\UMonit.exe 2476 C:\WINDOWS\system32\svchost.exe 2608 C:\Program Files\Internet Explorer\iexplore.exe 3352 C:\Documents and Settings\Rich\Desktop\MBRCheck_beta.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00fb0400 (NTFS) \\.\E: –> \\.\PhysicalDrive1 at offset 0x00000001`834faa00 (FAT32) \\.\Y: –> \\.\PhysicalDrive0 at offset 0x00000011`763c3c00 (NTFS) \\.\Z: –> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (FAT32) Size Device Name MBR Status ——————————————– 74 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: 31D100779DE502702C374F7C15687B56FCFD5528 41 GB \\.\PhysicalDrive1 Windows XP MBR code detected SHA1: 31D100779DE502702C374F7C15687B56FCFD5528 Done!
friggit,

That went well. we still have some things to take care of though:

🖼Click to load external image (Posted Image) Did you set up this proxy:
uInternet Settings,ProxyServer = http=;ftp=;https=;

🖼Click to load external image (Posted Image) SuperAntiSpyware seems to be corrupted or partially uninstalled. I'd recommend uninstalling it for now. You can reinstall it when we are done if you wish.

🖼Click to load external image (Posted Image) You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM
  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

🖼Click to load external image (Posted Image) Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.
  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please include the following in your next post:
  • MBAM log
  • Kaspersky log
Hi RPM, no I didn't set up the proxy you listed, I wouln't know how. Heres the logs.Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4360 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 7/27/2010 10:47:16 PM mbam-log-2010-07-27 (22-47-16).txt Scan type: Quick scan Objects scanned: 150796 Time elapsed: 9 minute(s), 6 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, July 28, 2010 Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Tuesday, July 27, 2010 08:05:37 Records in database: 4196059 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ K:\ Y:\ Z:\ Scan statistics: Objects scanned: 94192 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 01:51:28 No threats found. Scanned area is clean. Selected area has been scanned.
friggit,

How is it running now? Please do this next:

🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Accessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above DDS::

DDS::
uInternet Settings,ProxyServer = http=;ftp=;https=;

Save this as CFScript to your desktop.

Then disable your security programs and drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

Please include the following in your next post:
  • ComboFix log
  • How is your computer running?
I'm sorry but how do I get to the codebox to copy it into notepad? Also the popups seem to be gone,Thank you so much.friggit
Just copy and paste the content of that box (it's right under the directions) into notepad. This is what needs to be in notepad: DDS:: uInternet Settings,ProxyServer = http=;ftp=;https=;
Hi RPM, My computer seems to be running fine, no audio or visual popups! Thank you! About half way through, my icons on my desktop were changed and an original 'E' icon was put on the desktop for internet explorer. This new one works to get online as does Firefox. The other ones such as YahooTV and My yahoo wont work and my favorites wont work when I click on them.Thanks for hanging in there with me. Heres the log.FriggitComboFix 10-07-27.05 - Rich 07/28/2010 14:53:38.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.602 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Rich\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((( Files Created from 2010-06-28 to 2010-07-28 )))))))))))))))))))))))))))))))
.

2010-07-28 01:59 . 2010-07-28 01:59 ——– d—–w- c:\windows\system32\LogFiles
2010-07-28 01:19 . 2010-07-28 01:19 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2010-07-27 03:24 . 2010-07-27 03:24 25992 —-a-w- c:\windows\system32\pgdfgsvc.exe
2010-07-26 22:44 . 2010-07-26 22:44 388096 —-a-r- c:\documents and settings\Rich\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-26 22:44 . 2010-07-26 22:44 ——– d—–w- c:\program files\Trend Micro
2010-07-26 18:47 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-26 18:47 . 2010-07-26 18:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-26 18:47 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-26 18:40 . 2009-03-23 20:35 200704 —-a-w- c:\windows\system32\UMonit.exe
2010-07-26 18:40 . 2008-10-21 21:59 9584640 —-a-w- c:\windows\system32\GeneIcon.dll
2010-07-26 18:40 . 2008-07-07 20:30 167936 —-a-w- c:\windows\system32\ustor.dll
2010-07-26 18:39 . 2007-06-11 14:27 12416 —-a-w- c:\windows\system32\drivers\fixustor.sys
2010-07-25 22:08 . 2010-07-25 22:08 63488 —-a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-25 22:08 . 2010-07-25 22:08 52224 —-a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-25 22:08 . 2010-07-25 22:08 117760 —-a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-25 22:08 . 2010-07-25 22:08 ——– d—–w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2010-07-25 02:42 . 2010-07-25 02:42 22436 —ha-w- c:\windows\system32\mlfcache.dat
2010-07-25 02:35 . 2010-07-25 06:01 ——– d—–w- c:\program files\Safari
2010-07-23 00:48 . 2010-07-23 00:48 ——– d—–w- c:\program files\TrendMicro
2010-07-23 00:46 . 2010-07-23 00:46 63488 —-a-w- c:\documents and settings\Rich\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-23 00:46 . 2010-07-23 00:46 52224 —-a-w- c:\documents and settings\Rich\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-23 00:46 . 2010-07-23 00:46 117760 —-a-w- c:\documents and settings\Rich\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-23 00:45 . 2010-07-23 00:45 ——– d—–w- c:\documents and settings\Rich\Application Data\SUPERAntiSpyware.com
2010-07-23 00:45 . 2010-07-23 00:45 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-07-22 22:07 . 2010-07-22 22:07 ——– d—–w- c:\documents and settings\Rich\Application Data\Malwarebytes
2010-07-22 22:06 . 2010-07-22 22:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-21 02:33 . 2010-07-21 02:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-07-20 20:55 . 2010-07-20 20:55 ——– d—–w- c:\program files\CCleaner
2010-07-14 01:46 . 2006-02-10 01:05 520192 ——w- c:\windows\system32\ati2sgag.exe
2010-07-14 01:41 . 2010-07-14 01:42 ——– d—–w- c:\documents and settings\Rich\Local Settings\Application Data\Deployment
2010-07-14 00:06 . 2010-07-14 00:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-07-14 00:06 . 2010-07-14 00:06 ——– d—–w- c:\program files\Common Files\Apple
2010-07-14 00:05 . 2010-07-14 00:05 ——– d—–w- c:\program files\Apple Software Update
2010-07-13 23:05 . 2010-06-14 14:30 743936 ——w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-11 16:37 . 2010-07-11 16:38 ——– d—–w- c:\documents and settings\Carol\Local Settings\Application Data\PhotoChannel
2010-07-07 00:53 . 2010-07-07 00:53 ——– d—–w- c:\documents and settings\Rich\Local Settings\Application Data\Geckofx
2010-07-07 00:53 . 2010-07-13 23:48 ——– d—–w- c:\program files\AviSynth 2.5
2010-07-07 00:22 . 2010-07-07 00:23 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-07 00:21 . 2010-07-14 00:06 ——– d—–w- c:\program files\QuickTime
2010-07-06 18:15 . 2010-07-06 18:15 ——– d—–w- c:\documents and settings\Rich\Application Data\Yamb
2010-07-06 18:15 . 2010-07-06 18:15 128682 —-a-w- c:\documents and settings\Rich\Application Data\Yamb\Uninstall.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-27 03:36 . 2010-05-09 07:02 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-27 03:35 . 2010-01-31 00:57 ——– d—–w- c:\program files\SpywareBlaster
2010-07-25 21:59 . 2010-07-25 21:59 608 —-a-w- c:\program files\smitrem.lnk
2010-07-25 02:41 . 2010-05-12 05:00 ——– d—–w- c:\documents and settings\Rich\Application Data\Apple Computer
2010-07-23 04:08 . 2010-07-23 04:08 32768 —-a-w- c:\windows\~DF3278.tmp
2010-07-21 00:35 . 2010-05-24 07:34 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-07-21 00:34 . 2010-05-24 07:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-21 00:32 . 2010-05-23 02:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-07-14 01:46 . 2010-01-30 18:14 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-07-09 00:58 . 2010-02-15 17:30 ——– d—–w- c:\documents and settings\Rich\Application Data\U3
2010-07-03 15:39 . 2010-07-03 15:39 134669 —-a-w- c:\program files\Ashley awake 2 weeks old (1000 x 750).jpg
2010-07-03 15:37 . 2010-01-31 00:57 ——– d—–w- c:\program files\PIXresizer
2010-06-24 14:17 . 2010-06-24 14:17 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2010-06-23 01:41 . 2010-06-23 01:41 50354 —-a-w- c:\documents and settings\Carol\Application Data\Facebook\uninstall.exe
2010-06-23 01:41 . 2010-06-23 01:41 ——– d—–w- c:\documents and settings\Carol\Application Data\Facebook
2010-06-14 14:30 . 2005-08-16 10:40 743936 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-09 14:55 . 2010-02-03 17:14 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-09 10:45 . 2010-06-09 10:45 5591040 —-a-w- c:\documents and settings\Carol\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-06-04 16:29 . 2010-06-04 16:29 71992 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-05-23 02:30 . 2010-05-23 02:30 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-05-05 07:11 . 2010-05-05 07:11 32768 —-a-w- c:\windows\~DF1AAD.tmp
2010-05-02 05:56 . 2005-08-16 10:18 1850880 —-a-w- c:\windows\system32\win32k.sys
2006-05-19 08:57 . 2010-01-31 01:31 532480 -c–a-w- c:\program files\cwshredder.exe
2010-02-07 03:52 . 2010-02-06 20:00 56 –sh–r- c:\windows\system32\866971AEE0.sys
2010-02-07 03:52 . 2010-02-06 19:59 3350 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( SnapShot@2010-07-27_22.45.55 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-28 02:00 . 2010-07-28 02:00 16384 c:\windows\temp\Perflib_Perfdata_144.dat
+ 2010-07-28 01:58 . 2010-07-28 01:58 16384 c:\windows\temp\Perflib_Perfdata_118.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Rich\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-07-25 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb02.exe" [2001-03-09 192512]
"UMonit"="c:\windows\system32\UMonit.exe" [2009-03-23 200704]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10e.exe" [2010-01-27 256280]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PHOTOfunSTUDIO 4.0 HD Edition.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PHOTOfunSTUDIO 4.0 HD Edition.lnk
backup=c:\windows\pss\PHOTOfunSTUDIO 4.0 HD Edition.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2009-06-19 15:44 195072 —-a-w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2006-02-10 01:05 344064 —-a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-10-09 16:28 139264 —-a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU]
2006-03-26 18:11 61440 —-a-w- c:\dell\bldbubg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
2004-12-03 00:23 102400 ——w- c:\program files\Creative\MediaSource\Detector\CTDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-10 11:00 15360 -c–a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2005-09-15 15:47 57344 ——w- c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2005-05-15 08:04 332800 —-a-w- c:\program files\Dell Support\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2004-12-06 07:05 127035 -c–a-w- c:\windows\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2005-02-23 22:19 53248 -c—-w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-09-29 20:01 67584 —-a-w- c:\windows\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HTAReg]
2005-07-15 23:06 552960 ——w- c:\program files\Creative\Sound Blaster Audigy ADVANCED MB\Product Registration\English\HTAReg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2005-06-17 13:56 139264 -c–a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
2003-09-04 02:12 221184 -c–a-w- c:\program files\Intel\Modem Event Monitor\IntelMEM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-06-10 16:44 249856 -c–a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-06-10 16:44 81920 -c–a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MBDef]
2005-02-17 01:41 20480 —-a-w- c:\windows\MBDEF.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MBMon]
2005-05-19 14:54 1345520 —-a-w- c:\windows\system32\CTMBHA.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
2005-09-09 01:20 8192 -c–a-w- c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2005-09-09 01:20 110592 -c–a-w- c:\progra~1\MUSICM~1\MUSICM~3\mm_tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-10-13 16:24 1694208 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 21:40 155648 —-a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 01:53 421888 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2010-01-30 20:53 26112 -c–a-w- c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefaultMIDI]
2004-12-22 23:40 24576 —-a-w- c:\windows\MIDIDEF.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2005-03-23 06:20 339968 -c–a-w- c:\windows\stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-11 20:21 246504 -c–a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UMonit]
2009-03-23 20:35 200704 —-a-w- c:\windows\system32\UMonit.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 07:00 90112 ——w- c:\windows\Updreg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoiceCenter]
2005-09-19 13:42 1159168 ——w- c:\program files\Creative\VoiceCenter\AndreaVC.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX1000]
2009-06-26 22:21 757248 -c–a-w- c:\windows\vVX1000.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1107000.00C\symds.sys [5/20/2010 8:04 PM 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1107000.00C\symefa.sys [5/20/2010 8:04 PM 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20100709.001\BHDrvx86.sys [7/12/2010 8:18 PM 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1107000.00C\cchpx86.sys [5/20/2010 8:04 PM 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1107000.00C\ironx86.sys [5/20/2010 8:04 PM 116784]
R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe [5/20/2010 8:04 PM 126392]
R2 PDSched;PDScheduler;c:\program files\Raxco\PerfectDisk\PDSched.exe [11/1/2004 1:56 PM 237635]
R3 Angel;Angel MPEG Device;c:\windows\system32\drivers\Angel.sys [3/26/2006 2:08 PM 375936]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/27/2010 12:07 AM 102448]
R3 FIXUSTOR;FIXUSTOR;c:\windows\system32\drivers\fixustor.sys [7/26/2010 2:39 PM 12416]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100726.001\IDSXpx86.sys [7/27/2010 10:27 PM 331640]
S1 SABKUTIL;SABKUTIL;\??\c:\documents and settings\Administrator\Desktop\SUPERAntiSpyware\SABKUTIL.sys –> c:\documents and settings\Administrator\Desktop\SUPERAntiSpyware\SABKUTIL.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS –> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.SYS –> c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/2/2010 10:17 AM 135664]
.
Contents of the 'Scheduled Tasks' folder

2010-07-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2010-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 14:17]

2010-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 14:17]

2010-07-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2210250969-1846776457-4030474616-1005Core.job
- c:\documents and settings\Rich\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-25 03:59]

2010-07-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2210250969-1846776457-4030474616-1005UA.job
- c:\documents and settings\Rich\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-25 03:59]

2010-07-27 c:\windows\Tasks\Norton Security Scan for Rich.job
- c:\program files\Norton Security Scan\Engine\2.7.0.52\Nss.exe [2010-01-31 03:30]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = https://buy.norton.com/rd/directrenewal?NOS…vendtag=B97NJ91
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
Trusted Zone: musicmatch.com\online
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
FF - ProfilePath - c:\documents and settings\Rich\Application Data\Mozilla\Firefox\Profiles\8k1mfdxw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\Rich\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-28 14:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
UMonit = c:\windows\system32\UMonit.exe?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\17.7.0.12\diMaster.dll\" /prefetch:1"
.
Completion time: 2010-07-28 15:03:21
ComboFix-quarantined-files.txt 2010-07-28 19:03
ComboFix2.txt 2010-07-27 22:54

Pre-Run: 20,754,735,104 bytes free
Post-Run: 20,763,582,464 bytes free

- - End Of File - - FFF2831E63A80B1553773BFD0D7A240C

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI