This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Followed the steps in "Are You Infected" and my computer is

45 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is still lagging really really badly. It still is taking about 8 minutes to load up, and my nortons says that an attempt to attack my computer has been blocked every 3 minutes. I have done the "Are You Infected" tips, and nothing has changed. The Malwarebytes Anti-Malware did not find anything infected. Here is the log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4392 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 8/9/2010 11:28:12 AM mbam-log-2010-08-09 (11-28-12).txt Scan type: Quick scan Objects scanned: 140224 Time elapsed: 33 minute(s), 14 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Can anyone help me any further. All tips will greatly be appreciated. Thank you
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Ok, thanks for the tips. Here is that MBR CHECK: MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0001001c Kernel Drivers (total 185): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806D0000 \WINDOWS\system32\hal.dll 0xF7A87000 \WINDOWS\system32\KDCOM.DLL 0xF7997000 \WINDOWS\system32\BOOTVID.dll 0xF7458000 ACPI.sys 0xF7A89000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF7447000 pci.sys 0xF7587000 isapnp.sys 0xF7597000 ohci1394.sys 0xF75A7000 \WINDOWS\system32\DRIVERS\1394BUS.SYS 0xF799B000 compbatt.sys 0xF799F000 \WINDOWS\system32\DRIVERS\BATTC.SYS 0xF7B4F000 pciide.sys 0xF7807000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF7A8B000 aliide.sys 0xF7A8D000 intelide.sys 0xF7A8F000 toside.sys 0xF7A91000 viaide.sys 0xF7A93000 cmdide.sys 0xF7429000 pcmcia.sys 0xF75B7000 MountMgr.sys 0xF740A000 ftdisk.sys 0xF79A3000 ACPIEC.sys 0xF7B50000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS 0xF780F000 PartMgr.sys 0xF75C7000 VolSnap.sys 0xF79A7000 cpqarray.sys 0xF73F2000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS 0xF73DA000 atapi.sys 0xF79AB000 aha154x.sys 0xF7817000 sparrow.sys 0xF79AF000 symc810.sys 0xF75D7000 aic78xx.sys 0xF79B3000 dac960nt.sys 0xF75E7000 ql10wnt.sys 0xF79B7000 amsint.sys 0xF781F000 asc.sys 0xF79BB000 asc3550.sys 0xF7827000 mraid35x.sys 0xF782F000 i2omp.sys 0xF79BF000 ini910u.sys 0xF75F7000 ql1240.sys 0xF7607000 aic78u2.sys 0xF7837000 symc8xx.sys 0xF783F000 sym_hi.sys 0xF7847000 sym_u3.sys 0xF784F000 ABP480N5.SYS 0xF7857000 asc3350p.sys 0xF7A95000 cd20xrnt.sys 0xF7617000 ultra.sys 0xF73C1000 adpu160m.sys 0xF785F000 dpti2o.sys 0xF7627000 ql1080.sys 0xF7637000 ql1280.sys 0xF7647000 ql12160.sys 0xF7867000 perc2.sys 0xF7A97000 perc2hib.sys 0xF786F000 hpn.sys 0xF79C3000 cbidf2k.sys 0xF7395000 dac2w2k.sys 0xF7657000 disk.sys 0xF7667000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF7375000 fltmgr.sys 0xF731F000 SYMDS.SYS 0xF730D000 sr.sys 0xF72E0000 SYMEFA.SYS 0xF72C9000 KSecDD.sys 0xF723C000 Ntfs.sys 0xF720F000 NDIS.sys 0xF7677000 sisagp.sys 0xF7687000 viaagp.sys 0xF71F5000 Mup.sys 0xF7697000 alim1541.sys 0xF76A7000 amdagp.sys 0xF76B7000 agp440.sys 0xF76C7000 agpCPQ.sys 0xF7185000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF5E80000 \SystemRoot\system32\DRIVERS\igxpmp32.sys 0xF5E6C000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF5E44000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xF78F7000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF5E20000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF78FF000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF5D14000 \SystemRoot\system32\DRIVERS\AGRSM.sys 0xF4036000 \SystemRoot\system32\DRIVERS\ks.sys 0xF794F000 \SystemRoot\System32\Drivers\Modem.SYS 0xF7967000 \SystemRoot\system32\DRIVERS\RTL8139.SYS 0xF5FB1000 \SystemRoot\system32\DRIVERS\serial.sys 0xF60EA000 \SystemRoot\system32\DRIVERS\serenum.sys 0xF276E000 \SystemRoot\system32\DRIVERS\parport.sys 0xF7747000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF7757000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF7767000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF791F000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0xF7C3B000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF7777000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF70E5000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF2757000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF6031000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF6021000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF7927000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF26A6000 \SystemRoot\system32\DRIVERS\psched.sys 0xF6011000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF621A000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF6212000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF5FF1000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF620A000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF6202000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7ABD000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF2648000 \SystemRoot\system32\DRIVERS\update.sys 0xF7A53000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF5FD1000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xAA3DB000 \SystemRoot\system32\drivers\RtkHDAud.sys 0xAA3B7000 \SystemRoot\system32\drivers\portcls.sys 0xF5FC1000 \SystemRoot\system32\drivers\drmk.sys 0xF2D25000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7AC5000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF28D5000 \SystemRoot\System32\Drivers\i2omgmt.SYS 0xF7ADD000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7C88000 \SystemRoot\System32\Drivers\Null.SYS 0xF7ADF000 \SystemRoot\System32\Drivers\Beep.SYS 0xF7937000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF793F000 \SystemRoot\System32\drivers\vga.sys 0xF7AE1000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7AE3000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF795F000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF7957000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF28CD000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xAA384000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xAA32B000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xAA2D4000 \SystemRoot\System32\Drivers\N360\0402000.00C\SYMTDI.SYS 0xAA2AF000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 0xAA25A000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20100805.004\IDSxpx86.sys 0xAA234000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF2CF5000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xAA20C000 \SystemRoot\system32\DRIVERS\netbt.sys 0xAA1EA000 \SystemRoot\System32\drivers\afd.sys 0xF2CE5000 \SystemRoot\system32\DRIVERS\netbios.sys 0xAA1CB000 \SystemRoot\system32\drivers\N360\0402000.00C\Ironx86.SYS 0xF798F000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0xF78A7000 \SystemRoot\system32\DRIVERS\usbprint.sys 0xF7105000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xF2C95000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF28D9000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0xF5FA1000 \SystemRoot\system32\drivers\N360\0402000.00C\SRTSPX.SYS 0xAA1A0000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xAA130000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF7787000 \SystemRoot\System32\Drivers\Fips.SYS 0xF78B7000 \SystemRoot\system32\DRIVERS\NuidFltr.sys 0xF69ED000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS 0xAA0B5000 \SystemRoot\system32\DRIVERS\Wdf01000.sys 0xF60DE000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xAA057000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 0xAA03A000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 0xA9FBB000 \SystemRoot\system32\drivers\N360\0402000.00C\ccHPx86.sys 0xA9F0F000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20100719.001\BHDrvx86.sys 0xA9EEB000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xF7A63000 \SystemRoot\System32\drivers\Dxapi.sys 0xF2C6B000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7C21000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF024000 \SystemRoot\System32\igxpgd32.dll 0xBF012000 \SystemRoot\System32\igxprd32.dll 0xBF04D000 \SystemRoot\System32\igxpdv32.DLL 0xBF1AE000 \SystemRoot\System32\igxpdx32.DLL 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xA9EE3000 \??\C:\WINDOWS\system32\drivers\mbam.sys 0xA9EDB000 \SystemRoot\system32\DRIVERS\Sftvolxp.sys 0xA8CF7000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xA8BDA000 \SystemRoot\system32\drivers\wdmaud.sys 0xA9663000 \SystemRoot\system32\drivers\sysaudio.sys 0xA8AE5000 \SystemRoot\system32\DRIVERS\srv.sys 0xA8947000 \SystemRoot\system32\DRIVERS\Sftfsxp.sys 0xA87AC000 \SystemRoot\system32\DRIVERS\Sftplayxp.sys 0xA8660000 \SystemRoot\system32\DRIVERS\Sftredirxp.sys 0xF7BE3000 \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys 0xA81DD000 \SystemRoot\System32\Drivers\N360\0402000.00C\SRTSP.SYS 0xA87FF000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xA7DB9000 \SystemRoot\System32\Drivers\HTTP.sys 0xA7E6D000 \SystemRoot\system32\DRIVERS\ipfltdrv.sys 0xA76A2000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20100809.002\NAVEX15.SYS 0xA768E000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20100809.002\NAVENG.SYS 0xA7663000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 41): 0 System Idle Process 4 System 540 C:\WINDOWS\system32\smss.exe 800 csrss.exe 968 C:\WINDOWS\system32\winlogon.exe 1032 C:\WINDOWS\system32\services.exe 1044 C:\WINDOWS\system32\lsass.exe 1216 C:\WINDOWS\system32\svchost.exe 1296 svchost.exe 1400 C:\WINDOWS\system32\svchost.exe 1572 svchost.exe 1736 C:\WINDOWS\explorer.exe 1760 svchost.exe 1928 C:\WINDOWS\system32\spoolsv.exe 312 C:\Program Files\Canon\IJPLM\ijplmsvc.exe 404 C:\Program Files\Java\jre6\bin\jqs.exe 428 C:\WINDOWS\system32\srvany.exe 460 C:\WINDOWS\KMService.exe 468 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 616 C:\Program Files\Norton 360\Engine\4.2.0.12\ccsvchst.exe 664 C:\Program Files\Norton PC Checkup\Engine\2.0.1.247\SymcPCCULaunchSvc.exe 704 C:\Program Files\Norton PC Checkup\Engine\2.0.1.247\ccSvcHst.exe 732 C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS 1232 C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe 1392 C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe 1556 C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe 1580 C:\Program Files\Norton PC Checkup\Engine\2.0.1.247\ccSvcHst.exe 2672 C:\Program Files\Norton 360\Engine\4.2.0.12\ccsvchst.exe 2896 C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE 3324 C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe 4036 C:\WINDOWS\RTHDCPL.EXE 4064 C:\Program Files\Common Files\Java\Java Update\jusched.exe 4080 C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe 212 C:\WINDOWS\system32\ctfmon.exe 2144 alg.exe 3628 C:\Program Files\Norton PC Checkup\Engine\2.0.1.247\hsplayer.exe 2876 C:\WINDOWS\system32\svchost.exe 2280 C:\Program Files\Internet Explorer\iexplore.exe 3764 C:\Program Files\Internet Explorer\iexplore.exe 504 C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\5QBU7R6A\MBRCheck[1].exe 1348 C:\WINDOWS\system32\wscntfy.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000001`51cae200 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (FAT32) \\.\Q: –> error 5 PhysicalDrive0 Model Number: HitachiHDS721616PLA380, Rev: P22OABEA Size Device Name MBR Status ——————————————– 149 GB \\.\PhysicalDrive0 Unknown MBR code SHA1: 24F4D9A8B7E8AB4273B81931886015864FFD7C51 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done!
Ok, Here is the DDS.txt: DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 10:37:38.51 on Tue 08/10/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.283 [GMT -4:00] AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton 360 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\srvany.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\WINDOWS\KMService.exe C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe C:\Program Files\Norton PC Checkup\Engine\2.0.1.247\SymcPCCULaunchSvc.exe C:\Program Files\Norton PC Checkup\Engine\2.0.1.247\ccSvcHst.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Norton PC Checkup\Engine\2.0.1.247\ccSvcHst.exe C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\internet explorer\iexplore.exe C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QQC4BPNO\dds[1].com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=EM&Loc=ENG_US&Sys=DTP&M=W3650 uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = uSearchURL,(Default) = hxxp://www.google.com/keyword/%s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\4.2.0.12\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\4.2.0.12\IPSBHO.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\4.2.0.12\coIEPlg.dll TB: {CB789373-04D5-4EF4-9C16-871463FD0830} - No File uRun: [Norton Download Manager{N360S_NUC_prod_1.19_4.1.0.32}] c:\documents and settings\all users\documents\norton\{n360s_nuc_prod_1.19_4.1.0.32}\N360Downloader[1].exe /m uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE mRun: [RTHDCPL] RTHDCPL.EXE mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1229017357765 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll Hosts: 127.0.0.1 www.spywareinfo.com ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\gyk9q362.default\ FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\coffplgn\components\coFFPlgn.dll FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\ipsffplgn\components\IPSFFPl.dll FF - plugin: c:\progra~1\micros~3\office14\NPSPWRAP.DLL FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0402000.00c\symds.sys [2010-6-30 328752] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0402000.00c\symefa.sys [2010-6-30 173104] R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\bashdefs\20100719.001\BHDrvx86.sys [2010-7-19 692272] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0402000.00c\cchpx86.sys [2010-6-30 501888] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0402000.00c\ironx86.sys [2010-6-30 116784] R2 cvhsvc;Client Virtualization Handler;c:\program files\common files\microsoft shared\virtualization handler\CVHSVC.EXE [2010-2-28 821664] R2 KMService;KMService;c:\windows\system32\srvany.exe [2010-7-28 8192] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-8-5 304464] R2 N360;Norton 360;c:\program files\norton 360\engine\4.2.0.12\ccsvchst.exe [2010-6-30 126392] R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\norton pc checkup\engine\2.0.1.247\SymcPCCULaunchSvc.exe [2009-12-30 115056] R2 PCCUJobMgr;Common Client Job Manager Service;c:\program files\norton pc checkup\engine\2.0.1.247\ccSvcHst.exe [2009-12-30 126392] R2 sftlist;Application Virtualization Client;c:\program files\microsoft application virtualization client\sftlist.exe [2010-4-24 483688] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-6-24 102448] R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20100805.004\IDSXpx86.sys [2010-8-6 331640] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-8-5 20952] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20100809.002\NAVENG.SYS [2010-8-9 85424] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20100809.002\NAVEX15.SYS [2010-8-9 1362608] R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [2009-12-2 554344] R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [2009-12-2 211432] R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [2009-12-2 20584] R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [2009-12-2 18280] R3 sftvsa;Application Virtualization Service Agent;c:\program files\microsoft application virtualization client\sftvsa.exe [2010-4-24 209768] R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064] S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2010\TuneUpUtilitiesService32.exe [2010-7-6 1051968] S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\windows\system32\drivers\el575ND5.sys [2006-7-1 69692] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys –> c:\windows\system32\drivers\npf.sys [?] S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] =============== Created Last 30 ================ 2010-08-10 05:36:48 17 —-a-w- c:\windows\system32\shortcut_ex.dat 2010-08-05 14:04:06 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-08-05 14:04:02 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-08-05 14:04:01 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-07-30 15:14:56 30016 —-a-w- c:\windows\system32\uxtuneup.dll 2010-07-28 23:41:59 0 d—–w- c:\docume~1\alluse~1\applic~1\VirtualizedApplications 2010-07-28 21:11:33 0 d—–w- c:\docume~1\owner\applic~1\SoftGrid Client 2010-07-28 21:06:07 0 d—–w- c:\program files\Microsoft Application Virtualization Client 2010-07-28 21:06:07 0 d—–w- c:\documents and settings\all users\Microsoft 2010-07-28 20:59:57 0 d—–w- c:\docume~1\owner\applic~1\TP 2010-07-28 20:41:15 8192 —-a-w- c:\windows\system32\srvany.exe 2010-07-28 20:41:15 151552 —-a-w- c:\windows\KMService.exe 2010-07-14 19:15:05 744448 -c—-w- c:\windows\system32\dllcache\helpsvc.exe 2010-07-12 22:57:09 0 d—–w- c:\windows\$regcmp$ ==================== Find3M ==================== 2010-07-21 19:27:22 1232 —-a-w- c:\docume~1\owner\applic~1\wklnhst.dat 2010-07-06 11:58:24 30528 —-a-w- c:\windows\system32\TURegOpt.exe 2010-06-30 20:55:26 805 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF 2010-06-30 20:55:26 7443 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT 2010-06-30 20:55:26 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL 2010-06-30 20:55:26 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2010-06-04 22:14:07 411368 —-a-w- c:\windows\system32\deployJava1.dll 2009-12-29 01:50:56 16384 –sha-w- c:\windows\system32\config\systemprofile\ietldcache\index.dat 2008-12-11 17:25:58 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat 2008-12-19 18:36:50 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008120820081215\index.dat 2008-12-19 18:36:50 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008121920081220\index.dat ============= FINISH: 10:40:17.03 ===============
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hello, Here is the combofix log. Thanks

ComboFix 10-08-09.03 - Owner 08/10/2010 14:09:16.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.507 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\GoToAssistDownloadHelper.exe
c:\windows\system32\CBUTTON.OCX

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF
——-\Legacy_OSPPSVC
——-\Service_NPF
——-\Service_osppsvc


((((((((((((((((((((((((( Files Created from 2010-07-10 to 2010-08-10 )))))))))))))))))))))))))))))))
.

2010-08-10 05:36 . 2010-08-10 05:36 17 —-a-w- c:\windows\system32\shortcut_ex.dat
2010-08-09 21:20 . 2010-08-09 21:21 503808 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4ff360e5-n\msvcp71.dll
2010-08-09 21:20 . 2010-08-09 21:20 499712 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4ff360e5-n\jmc.dll
2010-08-09 21:20 . 2010-08-09 21:20 12800 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-2cd5803d-n\decora-d3d.dll
2010-08-09 21:20 . 2010-08-09 21:20 61440 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-2cd5803d-n\decora-sse.dll
2010-08-09 21:20 . 2010-08-09 21:20 348160 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4ff360e5-n\msvcr71.dll
2010-08-05 14:04 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-05 14:04 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-05 14:04 . 2010-08-05 14:04 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-30 15:14 . 2010-07-06 11:52 30016 —-a-w- c:\windows\system32\uxtuneup.dll
2010-07-30 14:31 . 2010-07-30 14:31 388096 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-28 23:41 . 2010-07-28 23:41 ——– d—–w- c:\documents and settings\All Users\Application Data\VirtualizedApplications
2010-07-28 21:11 . 2010-07-28 21:11 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\SoftGrid Client
2010-07-28 21:11 . 2010-07-31 10:06 ——– d—–w- c:\documents and settings\Owner\Application Data\SoftGrid Client
2010-07-28 21:10 . 2010-07-28 21:10 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\{90140011-0061-0409-0000-0000000FF1CE}
2010-07-28 21:09 . 2010-08-10 18:24 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\SoftGrid Client
2010-07-28 21:06 . 2010-07-31 10:05 ——– d—–w- c:\program files\Microsoft Application Virtualization Client
2010-07-28 21:06 . 2010-07-28 21:06 ——– d—–w- c:\documents and settings\All Users\Microsoft
2010-07-28 20:59 . 2010-07-28 21:17 ——– d—–w- c:\documents and settings\Owner\Application Data\TP
2010-07-28 20:41 . 2010-07-28 20:40 8192 —-a-w- c:\windows\system32\srvany.exe
2010-07-28 20:41 . 2010-07-28 20:40 151552 —-a-w- c:\windows\KMService.exe
2010-07-14 19:15 . 2010-06-14 14:31 744448 -c—-w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-12 22:57 . 2010-07-12 23:00 ——– d—–w- c:\windows\$regcmp$

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-02 21:53 . 2010-06-21 23:38 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2010-07-30 15:15 . 2010-04-30 02:01 ——– d—–w- c:\program files\TuneUp Utilities 2010
2010-07-21 19:27 . 2010-05-07 15:56 1232 —-a-w- c:\documents and settings\Owner\Application Data\wklnhst.dat
2010-07-17 21:30 . 2009-09-20 20:31 ——– d—–w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2010-07-14 19:32 . 2008-12-11 16:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-06 11:58 . 2010-04-30 02:01 30528 —-a-w- c:\windows\system32\TURegOpt.exe
2010-07-03 18:58 . 2009-01-04 03:23 71152 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-30 20:59 . 2009-02-17 01:37 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-06-30 20:55 . 2010-02-08 22:18 ——– d—–w- c:\program files\Symantec
2010-06-30 20:55 . 2010-02-08 22:18 805 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-06-30 20:55 . 2010-02-08 22:18 7443 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-06-30 20:55 . 2010-02-08 22:18 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2010-06-30 20:55 . 2010-02-08 22:18 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-06-30 20:38 . 2010-06-30 20:38 ——– d—–w- c:\program files\Norton Support
2010-06-14 14:31 . 2006-05-07 01:36 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-04 22:15 . 2010-06-04 22:15 503808 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-34857b00-n\msvcp71.dll
2010-06-04 22:15 . 2010-06-04 22:15 499712 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-34857b00-n\jmc.dll
2010-06-04 22:15 . 2010-06-04 22:15 348160 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-34857b00-n\msvcr71.dll
2010-06-04 22:15 . 2010-06-04 22:15 61440 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4b5c59e1-n\decora-sse.dll
2010-06-04 22:15 . 2010-06-04 22:15 12800 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4b5c59e1-n\decora-d3d.dll
2010-06-04 22:14 . 2010-06-04 22:14 411368 —-a-w- c:\windows\system32\deployJava1.dll
.

((((((((((((((((((((((((((((( SnapShot_2010-07-07_18.06.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-10 18:04 . 2010-08-10 18:04 16384 c:\windows\Temp\Perflib_Perfdata_7d0.dat
+ 2010-08-10 18:27 . 2010-08-10 18:27 16384 c:\windows\Temp\Perflib_Perfdata_784.dat
+ 2010-08-10 18:26 . 2010-08-10 18:26 16384 c:\windows\Temp\Perflib_Perfdata_704.dat
+ 2010-07-28 21:12 . 2010-03-30 00:26 54656 c:\windows\system32\spool\drivers\w32x86\SendToOneNoteUI.dll
+ 2010-07-28 21:12 . 2010-03-30 00:26 94088 c:\windows\system32\spool\drivers\w32x86\SendToOneNoteFilter.dll
+ 2010-07-28 21:12 . 2010-03-30 00:26 54656 c:\windows\system32\spool\drivers\w32x86\3\SendToOneNoteUI.dll
+ 2010-07-28 21:12 . 2010-03-30 00:26 94088 c:\windows\system32\spool\drivers\w32x86\3\SendToOneNoteFilter.dll
+ 2006-05-07 01:24 . 2010-07-31 10:05 72090 c:\windows\system32\perfc009.dat
+ 2010-06-30 23:38 . 2010-04-22 02:29 43696 c:\windows\system32\drivers\srtspx.sys
+ 2009-12-03 02:23 . 2010-04-24 05:10 18280 c:\windows\system32\drivers\Sftvolxp.sys
+ 2009-12-03 02:23 . 2010-04-24 05:10 20584 c:\windows\system32\drivers\Sftredirxp.sys
- 2010-04-16 20:04 . 2010-06-11 03:50 35088 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 35088 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 18704 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 18704 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 20240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 20240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
+ 2010-07-31 10:05 . 2010-07-31 10:05 89952 c:\windows\Installer\{90140000-006D-0409-0000-0000000FF1CE}\cvhicon.exe
+ 2010-07-28 21:12 . 2008-03-13 04:52 761344 c:\windows\system32\spool\drivers\w32x86\unires.dll
+ 2010-07-28 21:12 . 2008-07-06 12:06 744960 c:\windows\system32\spool\drivers\w32x86\unidrvui.dll
+ 2010-07-28 21:12 . 2008-07-06 12:06 373248 c:\windows\system32\spool\drivers\w32x86\unidrv.dll
+ 2010-07-28 21:12 . 2008-07-06 12:06 765440 c:\windows\system32\spool\drivers\w32x86\mxdwdrv.dll
+ 2006-05-07 01:24 . 2010-07-31 10:05 444472 c:\windows\system32\perfh009.dat
+ 2010-07-13 16:09 . 2010-07-13 16:09 231888 c:\windows\system32\Macromed\Flash\FlashUtil10h_Plugin.exe
+ 2010-06-30 23:38 . 2010-05-06 04:01 361904 c:\windows\system32\drivers\symtdi.sys
+ 2010-06-30 23:38 . 2010-04-22 03:02 173104 c:\windows\system32\drivers\symefa.sys
+ 2010-06-30 23:38 . 2010-02-04 01:40 328752 c:\windows\system32\drivers\symds.sys
+ 2009-12-03 02:23 . 2010-04-24 05:10 211432 c:\windows\system32\drivers\Sftplayxp.sys
+ 2009-12-03 02:23 . 2010-04-24 05:10 554344 c:\windows\system32\drivers\Sftfsxp.sys
+ 2010-06-30 23:38 . 2010-04-29 05:03 116784 c:\windows\system32\drivers\ironx86.sys
+ 2010-06-30 23:38 . 2010-02-26 00:22 501888 c:\windows\system32\drivers\cchpx86.sys
+ 2010-06-14 21:04 . 2010-06-14 21:04 605696 c:\windows\Installer\54beda.msp
+ 2010-07-06 18:30 . 2010-07-06 18:30 747520 c:\windows\Installer\54bd87.msp
+ 2010-06-14 21:04 . 2010-06-14 21:04 549376 c:\windows\Installer\54bd86.msp
+ 2010-04-16 20:04 . 2010-07-14 19:32 888080 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 888080 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 272648 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 272648 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 922384 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 922384 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 845584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 845584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 217864 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 217864 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
+ 2009-03-06 06:37 . 2009-03-06 06:37 501640 c:\windows\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6425\SOA.DLL
+ 2008-10-26 10:26 . 2008-10-26 10:26 162680 c:\windows\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6425\ACCWIZ.DLL
+ 2010-07-28 21:12 . 2008-07-06 12:06 1676288 c:\windows\system32\spool\drivers\w32x86\XpsSvcs.dll
+ 2006-05-07 01:24 . 2010-07-27 06:30 8462336 c:\windows\system32\shell32.dll
+ 2010-04-24 05:10 . 2010-04-24 05:10 1015144 c:\windows\system32\sftldr.dll
+ 2010-01-27 01:07 . 2010-07-13 16:09 5612496 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2008-06-17 19:02 . 2010-07-27 06:30 8462336 c:\windows\system32\dllcache\shell32.dll
+ 2010-07-28 21:08 . 2010-07-28 21:08 4201984 c:\windows\Installer\6ccb50.msi
+ 2010-07-06 18:29 . 2010-07-06 18:29 1460224 c:\windows\Installer\54bedb.msp
+ 2010-06-11 00:22 . 2010-06-11 00:22 8934912 c:\windows\Installer\460c461.msp
+ 2010-06-11 00:22 . 2010-06-11 00:22 5893120 c:\windows\Installer\460c460.msp
+ 2010-07-30 14:31 . 2010-07-30 14:31 1094656 c:\windows\Installer\2f61f4.msi
+ 2010-05-20 23:57 . 2010-05-20 23:57 4989952 c:\windows\Installer\2130d55.msp
+ 2010-05-20 23:57 . 2010-05-20 23:57 5907456 c:\windows\Installer\2130d54.msp
+ 2010-06-11 15:03 . 2010-06-11 15:03 5021184 c:\windows\Installer\2130d37.msp
+ 2010-04-16 20:04 . 2010-07-14 19:32 1172240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 1172240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 1165584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 1165584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
+ 2010-02-28 06:33 . 2010-02-28 06:33 4817336 c:\windows\Installer\$PatchCache$\Managed\00004109D60090400000000000F01FEC\14.0.4763\CVH.DLL
+ 2008-12-11 18:00 . 2010-07-02 19:39 34045896 c:\windows\system32\MRT.exe
+ 2010-05-20 23:58 . 2010-05-20 23:58 12114432 c:\windows\Installer\2130d23.msp
+ 2009-03-06 06:37 . 2009-03-06 06:37 10222432 c:\windows\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6425\MSACCESS.EXE
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 14854144]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"CanonSolutionMenu"=c:\program files\Canon\SolutionMenu\CNSLMAIN.exe /logon
"Persistence"=c:\windows\system32\igfxpers.exe
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"IgfxTray"=c:\windows\system32\igfxtray.exe
"CanonMyPrinter"=c:\program files\Canon\MyPrinter\BJMyPrt.exe /logon
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0402000.00C\symds.sys [6/30/2010 7:38 PM 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0402000.00C\symefa.sys [6/30/2010 7:38 PM 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20100719.001\BHDrvx86.sys [7/19/2010 7:28 PM 692272]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0402000.00C\cchpx86.sys [6/30/2010 7:38 PM 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0402000.00C\ironx86.sys [6/30/2010 7:38 PM 116784]
R2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2/28/2010 2:33 AM 821664]
R2 KMService;KMService;c:\windows\system32\srvany.exe [7/28/2010 4:41 PM 8192]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/5/2010 10:04 AM 304464]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\4.2.0.12\ccsvchst.exe [6/30/2010 7:37 PM 126392]
R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\Norton PC Checkup\Engine\2.0.1.247\SymcPCCULaunchSvc.exe [12/30/2009 5:48 PM 115056]
R2 PCCUJobMgr;Common Client Job Manager Service;c:\program files\Norton PC Checkup\Engine\2.0.1.247\ccSvcHst.exe [12/30/2009 5:48 PM 126392]
R2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [4/24/2010 1:10 AM 483688]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/24/2010 2:28 AM 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20100805.004\IDSXpx86.sys [8/6/2010 6:18 AM 331640]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/5/2010 10:04 AM 20952]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [12/2/2009 10:23 PM 554344]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [12/2/2009 10:23 PM 211432]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [12/2/2009 10:23 PM 20584]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [12/2/2009 10:23 PM 18280]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [4/24/2010 1:10 AM 209768]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10/14/2009 7:24 AM 10064]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [7/6/2010 7:55 AM 1051968]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\windows\system32\drivers\el575ND5.sys [7/1/2006 1:44 AM 69692]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-07-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2010-07-23 c:\windows\Tasks\Automatic maintenance.job
- c:\program files\TuneUp Utilities 2010\OneClickStarter.exe [2010-07-06 12:02]

2008-12-11 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2006-05-07 00:12]

2008-12-11 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2006-05-07 00:12]

2008-12-11 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2006-05-07 00:12]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=EM&Loc=ENG_US&Sys=DTP&M=W3650
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\gyk9q362.default\
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\progra~1\MICROS~3\Office14\NPSPWRAP.DLL
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-10 14:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\4.2.0.12\diMaster.dll\" /prefetch:1"
–

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCCUJobMgr]
"ImagePath"="\"c:\program files\Norton PC Checkup\Engine\2.0.1.247\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files\Norton PC Checkup\Engine\2.0.1.247\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1716337210-622666185-3795375381-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2164)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\KMService.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\RTHDCPL.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-08-10 14:37:08 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-10 18:37
ComboFix2.txt 2010-07-07 18:12
ComboFix3.txt 2010-06-14 14:09
ComboFix4.txt 2010-05-29 02:56
ComboFix5.txt 2010-08-10 16:36

Pre-Run: 116,731,428,864 bytes free
Post-Run: 116,619,464,704 bytes free

- - End Of File - - C0B85F1DB0D092789274C960F8C2F5E4
Hi,

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Ok, the Malwarebytes did not find anything infected. Here is the log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4414 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 8/10/2010 3:57:16 PM mbam-log-2010-08-10 (15-57-16).txt Scan type: Quick scan Objects scanned: 139126 Time elapsed: 23 minute(s), 42 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Try this scanner instead:


**Vista users - right click on the IE icon and run as administrator

Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
Ok, ESET found 13 infected files. Here is the log: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=1f7d846044925b49bcfed2ae21f5a3d3 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-08-10 11:04:53 # local_time=2010-08-10 07:04:53 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=3589 16777189 100 86 2574246 44751440 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=68109 # found=13 # cleaned=0 # scan_time=8356 C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBankerfgv.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBankerfgv1.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBankerfgv2.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBankerfgv3.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBankerfgv4.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBankerfgv5.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\0\43120580-228894f3 a variant of Java/TrojanDownloader.Agent.NAN trojan 00000000000000000000000000000000 I C:\Qoobox\32788R22FWJFW\acpiec.sys Win32/Olmarik.ZC trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\Process.exe.vir Win32/PrcView application 00000000000000000000000000000000 I C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP406\A0072729.exe multiple threats 00000000000000000000000000000000 I C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP406\A0072745.exe Win32/PrcView application 00000000000000000000000000000000 I C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP406\A0072748.exe Win32/Shutdown.NAA application 00000000000000000000000000000000 I C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP406\A0072772.exe Win32/PrcView application 00000000000000000000000000000000 I
Hi

Most of those files are in quarantine or old system restore points, you can empty the Spybot quarantine, the rest we will clean up shortly


Please do the following:

[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 20 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.


Clear Sun Jave cache

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup) If you do not see the icon, look to your left and click 'Switch to Classic View'.
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT

Please advise how your computer is running and if there are any outstanding issues
Hello, I just want to thank you for taking your time to help. I am at work all day today, so I wont be able to do the last instruction you gave me untill later.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI