This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hijack This Log - please help! can't get onto

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

well, i had the fowarding set up and it stopped working a few weeks ago. i was simply having a copy of any message in the inbox forwarded to an alternate address, so, some with attachments, mostly without. now, the fowarding worked again yesterday, and then i began to have them for the reason given below. it appears to work again now, but i will monitor this over today. do you think it is related? thunderbird is picking something up that my antiviral software isn't? i've never encountered this before and, being part of some gmail groups, i have to say - it's frustrating. thanks so much for your help!!!
Ok, so your Gmail is auto-forwarding to another account. Well, it could be that the alternative account's service provider is picking up spam-like messages in some of your emails and rejecting them because it comes from Gmail (an account provider that is known to be used by spammers).When it happens, do all your emails get forwarded regardless of content? Let me know if it starts happening again. Thanks.
i'm using thunderbird. i've been able to get forwarded content from gmail and gmail groups, the group is what seems to be affected, up until all of this hinky trojan business. thunderbird is now rejected gmail groups messages as spam. i was also just redirected to an entirely RANDOM page (muchmusic.com) from a google search link (http://www.google.ca/click?sa=T&ct=res&cd=1&url=http%3A%2F%2Fglogger.mobi%2Fsearch.php%3Fs%3Daquaplay&q=aquaplay&pid=0&u=aHR0cDovLzcyLjIzMy43NS4xOTUvY2xpY2sucGhwP2M9YTA3MWY2NjUwMDZiOTdkNWM1Nzg1Nz E3NDIwNA==) and i have no idea what that is about. needless to say, i'm still a little nervous that my computer is still compromised. any advice? thanks again. i really appreciate any and all help that you can give. :)
Hi :)

Please run DDS again and post the first log (DDS.txt).

In Thunderbird hit Tools >> Message Filters. If you have any, see if there's any chance they may have something to do with blocking gmail.

Thanks.
DDS (Ver_09-01-18.01) - NTFSx86 Run by [removed] at 9:06:30.90 on Fri 01/23/2009 Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_11 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1789.986 [GMT -5:00] AV: Trend Micro AntiVirus *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Windows\system32\Ati2evxx.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Acer\Mobility Center\MobilityService.exe C:\Program Files\O2Micro Oz128 Driver\o2flash.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\Wacom_Tablet.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe C:\Program Files\Trend Micro\BM\TMBMSRV.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Trend Micro\Internet Security\TmProxy.exe C:\Windows\system32\taskeng.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\WTablet\Wacom_TabletUser.exe C:\Windows\Explorer.EXE C:\Windows\system32\Wacom_Tablet.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Windows\system32\wbem\unsecapp.exe C:\Users\Owner\AppData\Local\Temp\RtkBtMnt.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Skype\Phone\Skype.exe C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\Dropbox\dropbox.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Owner\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.ca/ uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mStart Page = hxxp://en.us.acer.yahoo.com uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com BHO: MRI_DISABLED - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - No File BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll uRun: [Sidebar] "c:\program files\windows sidebar\sidebar.exe" /autoRun uRun: [StartCCC] "c:\program files\ati" technologies\ati.ace\core-static\CLIStart.exe uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [RunSpySweeperScheduleAtStartup] "c:\windows\system32\msfeedssync.exe" /ScheduleSweep=User_Feed_Synchronization-{562807D3-12E1-4214-B2D7-680F190A2229} uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Simplify Media] "c:\program files\simplify media\SimplifyMedia.exe" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [UfSeAgnt.exe] "c:\program files\trend micro\internet security\UfSeAgnt.exe" mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe" mRun: [Adobe_ID0EYTHM] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [{7ABCACD8-3F1E-EB4A-995A-4D0B73EC4F57}] "c:\users\owner\appdata\local\temp\ixp004.tmp\WMPupdate.exe" /r mRun: [SYSTEM.rt32] c:\users\owner\appdata\local\temp\lsass.exe StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\program files\dropbox\dropbox.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{4c271126-c295-4828-a901-5910ae0c258b}\Icon3E5562ED7.ico StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mri_di~1\empowe~1.lnk - c:\acer\empowering technology\eAPLauncher.exe uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll Trusted Zone: ffffound.com\www Trusted Zone: megapixel.net\www Trusted Zone: stepinsidedesign.com\assets TCP: NameServer = 85.255.114.73,85.255.112.227 TCP: {1ACD1FFD-EA70-465D-8ECB-120286EBD4E3} = 85.255.114.73,85.255.112.227 TCP: {8AD01C8D-FEA9-435F-8270-73B4C2FD24A8} = 85.255.114.73,85.255.112.227 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL ================= FIREFOX =================== FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\mzinexth.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/ FF - component: c:\program files\mozilla firefox\components\iamfamous.dll FF - component: c:\users\owner\appdata\roaming\mozilla\firefox\profiles\mzinexth.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2007-4-3 39680] R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [2007-4-2 35712] R3 tmproxy;Trend Micro Proxy Service;c:\program files\trend micro\internet security\TmProxy.exe [2008-2-2 648456] R4 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};c:\program files\cyberlink\powerdvd\000.fcl [2007-12-19 13560] R4 Maxtor Sync Service;Maxtor Service;c:\program files\maxtor\sync\SyncServices.exe [2007-9-28 156976] R4 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2008-10-6 2748200] R4 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2008-2-14 52240] R4 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2007-9-28 36368] S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2008-10-6 15656] =============== Created Last 30 ================ 2009-01-22 13:36 181,029,175 a——- c:\windows\MEMORY.DMP 2009-01-22 13:21 –d—– c:\programdata\Adobe Systems 2009-01-22 12:44 –d—– c:\program files\common files\Adobe Systems Shared 2009-01-22 11:34 –dshr– C:\resycled 2009-01-22 11:34 255 —shr– C:\autorun.inf 2009-01-20 11:49 56 a—h— c:\programdata\ezsidmv.dat 2009-01-20 11:49 56 a—h— c:\progra~2\ezsidmv.dat 2009-01-20 10:48 250 a——- c:\windows\gmer.ini 2009-01-20 00:22 288,768 a——- c:\windows\system32\drivers\srv.sys 2009-01-19 16:21 161,792 a——- c:\windows\SWREG.exe 2009-01-19 16:21 98,816 a——- c:\windows\sed.exe 2009-01-19 16:16 –d—– C:\ComboFix 2009-01-09 14:36 6,200 a——- c:\windows\system32\INT13EXT.VXD 2009-01-09 14:36 –d—– c:\program files\PC Inspector File Recovery 2009-01-08 17:14 –d—– c:\program files\Lavasoft 2009-01-08 17:13 –d—– c:\programdata\Lavasoft 2009-01-08 17:11 –d—– c:\program files\common files\Wise Installation Wizard 2009-01-07 13:03 –d—– c:\users\owner\.housecall6.6 ==================== Find3M ==================== 2008-11-10 05:43 410,984 a——- c:\windows\system32\deploytk.dll 2008-10-31 22:44 52,736 a——- c:\windows\apppatch\iebrshim.dll 2008-10-31 22:44 2,154,496 a——- c:\windows\apppatch\AcGenral.dll 2008-10-31 22:44 541,696 a——- c:\windows\apppatch\AcLayers.dll 2008-10-31 22:44 460,288 a——- c:\windows\apppatch\AcSpecfc.dll 2008-10-31 22:44 173,056 a——- c:\windows\apppatch\AcXtrnal.dll 2008-10-31 22:44 28,672 a——- c:\windows\system32\Apphlpdm.dll 2008-10-31 20:21 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll 2008-10-29 01:29 2,927,104 a——- c:\windows\explorer.exe 2008-10-07 08:53 86,016 a——- c:\windows\inf\infstor.dat 2008-10-07 08:53 51,200 a——- c:\windows\inf\infpub.dat 2008-10-07 08:53 143,360 a——- c:\windows\inf\infstrng.dat 2008-09-05 09:17 174 a–sh— c:\program files\desktop.ini 2008-09-05 09:04 665,600 a——- c:\windows\inf\drvindex.dat 2007-09-10 18:34 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2007-09-10 18:34 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2007-09-10 18:34 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2007-09-10 18:34 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 9:08:58.68 =============== no message filter issues. this is a new problem that only seems to affect gmail groups. my latest concern is that lsass.exe is no longer working on start-up. should this concern me? isn't that a security file? again, many thanks.
Hi,

You seem to have contracted a new infection. MalwareBytes' should work for you now.

Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.
Post a new HijackThis as well.

Thanks.
i cannot access the malwarebytes page! "The browser could not find the host server for the provided address." anywhere else i can get that exe? also, i am concerned as to how i got a new infection? would that be related to the old one (still propagating, etc)? i don't engage in any crazy high-risk online activity, and thought that i was pretty net savvy, so i'm concerned. thanks.
Hi,

Looks like the old nasty is back as well :( This is always a tricky one, it may be that there was still some left that respawned. Could be something else.

Please run ComboFix again. Post the log in your next reply.

Try and access MalwareBytes' website again straight after running ComboFix. If that still doesn't work, download the setup file from here:
http://jpshortstuff.247fixes.com/mbam.exe

Follow the instructions in my previous post to install and run MalwareBytes' and post the log from that as well.

Please also run DDS again and post the first log.

Thanks.
ComboFix 09-01-21.04 - Owner 2009-01-26 9:35:39.4 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1789.1054 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
AV: Trend Micro AntiVirus *On-access scanning enabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
c:\program files\Mozilla Firefox\components\iamfamous.dll
C:\resycled
c:\resycled\ntldr.com
c:\users\Owner\AppData\Local\Temp\lsass.exe
c:\windows\system32\drivers\gaopdxiqpnycnt.sys
c:\windows\system32\gaopdxpfnieqhw.dll
D:\Autorun.inf
D:\resycled
d:\resycled\ntldr.com

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_gaopdxserv.sys


((((((((((((((((((((((((( Files Created from 2008-12-26 to 2009-01-26 )))))))))))))))))))))))))))))))
.

2009-01-24 17:06 . 2009-01-24 17:06 d——– c:\program files\Simplify Media
2009-01-22 13:36 . 2009-01-23 08:59 181,029,175 –a—— c:\windows\MEMORY.DMP
2009-01-22 13:21 . 2009-01-22 13:21 d——– c:\users\All Users\Adobe Systems
2009-01-22 13:21 . 2009-01-22 13:21 d——– c:\programdata\Adobe Systems
2009-01-22 12:44 . 2009-01-22 12:44 d——– c:\program files\Common Files\Adobe Systems Shared
2009-01-20 11:49 . 2009-01-20 11:49 56 –ah—– c:\users\All Users\ezsidmv.dat
2009-01-20 11:49 . 2009-01-20 11:49 56 –ah—– c:\programdata\ezsidmv.dat
2009-01-20 10:48 . 2009-01-20 11:08 250 –a—— c:\windows\gmer.ini
2009-01-20 00:22 . 2008-12-15 21:42 288,768 –a—— c:\windows\System32\drivers\srv.sys
2009-01-20 00:07 . 2009-01-20 00:07 d——– c:\windows\Sun
2009-01-19 16:16 . 2009-01-19 16:21 d——– C:\ComboFix
2009-01-09 14:36 . 2009-01-09 14:36 d——– c:\program files\PC Inspector File Recovery
2009-01-09 14:36 . 2002-02-18 18:40 6,200 –a—— c:\windows\System32\INT13EXT.VXD
2009-01-08 23:18 . 2009-01-08 23:18 d——– c:\program files\ERUNT
2009-01-08 17:14 . 2009-01-08 17:14 d——– c:\program files\Lavasoft
2009-01-08 17:13 . 2009-01-08 17:23 d——– c:\users\All Users\Lavasoft
2009-01-08 17:13 . 2009-01-08 17:23 d——– c:\programdata\Lavasoft
2009-01-08 17:11 . 2009-01-08 17:11 d——– c:\program files\Common Files\Wise Installation Wizard
2009-01-07 15:17 . 2009-01-08 01:46 d——– c:\program files\Trillian
2009-01-07 13:03 . 2009-01-07 13:21 d——– c:\users\Owner\.housecall6.6

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-26 14:33 ——— d—–w c:\users\Owner\AppData\Roaming\WTablet
2009-01-25 18:36 ——— d—–w c:\users\Owner\AppData\Roaming\Skype
2009-01-25 17:03 ——— d—–w c:\users\Owner\AppData\Roaming\skypePM
2009-01-25 15:35 ——— d—–w c:\users\Owner\AppData\Roaming\uTorrent
2009-01-24 22:02 ——— d—–w c:\users\Owner\AppData\Roaming\Dropbox
2009-01-22 17:44 ——— d—–w c:\program files\Common Files\Adobe
2009-01-20 08:02 ——— d—–w c:\program files\Windows Mail
2009-01-09 19:36 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-09 19:25 ——— d—–w c:\program files\TaskCoach
2009-01-07 17:47 ——— d—–w c:\program files\Common Files\AOL
2009-01-07 15:11 ——— d—–w c:\program files\Ontrack
2009-01-02 14:01 ——— d—–w c:\program files\Mozilla Thunderbird
2008-12-22 19:56 ——— d—–w c:\program files\Java
2008-12-19 20:00 ——— d—–w c:\programdata\FLEXnet
2008-12-19 19:36 ——— d—–w c:\users\Owner\AppData\Roaming\NCH Swift Sound
2008-12-19 19:36 ——— d—–w c:\programdata\Viewpoint
2008-12-19 19:36 ——— d—–w c:\program files\NCH Swift Sound
2008-12-19 19:35 ——— d—–w c:\program files\DivX
2008-11-10 10:43 410,984 —-a-w c:\windows\System32\deploytk.dll
2008-11-01 03:44 541,696 —-a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 —-a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 —-a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 28,672 —-a-w c:\windows\System32\Apphlpdm.dll
2008-11-01 03:44 2,154,496 —-a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 —-a-w c:\windows\AppPatch\AcXtrnal.dll
2008-11-01 01:21 4,240,384 —-a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-29 06:29 2,927,104 —-a-w c:\windows\explorer.exe
2008-09-05 14:17 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((( snapshot_2009-01-20_22.48.44.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-22 17:44:15 65,536 —-a-r c:\windows\Installer\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\ARPPRODUCTICON.exe
+ 2009-01-22 17:44:15 65,536 —-a-r c:\windows\Installer\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\AuditionCommonShortc_01CEC7E570FD4D068FADBF21DF0CC6DC.exe
+ 2009-01-22 17:44:15 65,536 —-a-r c:\windows\Installer\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\NewShortcut1_E3A4979EE8C048379F3D271B50BA9E7C_1.exe
+ 2009-01-22 17:44:15 65,536 —-a-r c:\windows\Installer\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\NewShortcut2_E3A4979EE8C048379F3D271B50BA9E7C_1.exe
+ 2009-01-22 17:44:15 65,536 —-a-r c:\windows\Installer\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\NewShortcut3_E3A4979EE8C048379F3D271B50BA9E7C.exe
+ 2009-01-24 22:06:52 218,616 —-a-r c:\windows\Installer\{B4219E32-45A8-4E49-9311-AF1FF19AD47D}\ARPPRODUCTICON.exe
+ 2009-01-24 22:06:52 218,616 —-a-r c:\windows\Installer\{B4219E32-45A8-4E49-9311-AF1FF19AD47D}\NewShortcut1_6DC4595DE47A4E6EA70352D9C4F77BA6.exe
+ 2009-01-24 22:06:52 46,584 —-a-r c:\windows\Installer\{B4219E32-45A8-4E49-9311-AF1FF19AD47D}\NewShortcut2_610DD1A56B944D82B51DB3D04A70F4A1.exe
+ 2009-01-24 22:06:52 46,584 —-a-r c:\windows\Installer\{B4219E32-45A8-4E49-9311-AF1FF19AD47D}\NewShortcut3_D9B767669BDD4A529941C41D72EF6071.exe
- 2009-01-20 04:51:50 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-01-26 14:32:49 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-01-20 04:51:50 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-01-26 14:32:49 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-01-20 04:54:22 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-01-26 14:35:03 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2009-01-21 03:47:52 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-01-26 14:54:26 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-01-26 14:54:26 262,144 —ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-01-19 03:51:14 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-01-22 06:13:35 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-01-19 03:51:14 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-22 06:13:35 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-01-19 03:51:14 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-01-22 06:13:35 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-01-21 03:44:44 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-01-26 14:29:01 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
- 2009-01-20 04:52:10 1,810,608 —-a-w c:\windows\System32\FNTCACHE.DAT
+ 2009-01-26 14:33:07 1,810,696 —-a-w c:\windows\System32\FNTCACHE.DAT
+ 2009-01-22 03:55:09 2,456 —-a-w c:\windows\System32\networklist\icons\{FEEEB0C3-D91D-4081-AB3A-36DAFDF6675E}_24.bin
+ 2009-01-22 03:55:09 4,280 —-a-w c:\windows\System32\networklist\icons\{FEEEB0C3-D91D-4081-AB3A-36DAFDF6675E}_32.bin
+ 2009-01-22 03:55:09 9,560 —-a-w c:\windows\System32\networklist\icons\{FEEEB0C3-D91D-4081-AB3A-36DAFDF6675E}_48.bin
- 2009-01-20 05:21:40 6,553,600 —-a-w c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-01-22 00:50:18 6,553,600 —-a-w c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2009-01-20 04:54:35 12,284 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-504179511-533580499-2079182871-1003_UserData.bin
+ 2009-01-26 14:35:35 12,388 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-504179511-533580499-2079182871-1003_UserData.bin
- 2009-01-20 04:54:34 82,434 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-01-26 14:35:35 82,612 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-01-20 04:54:29 68,904 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-01-26 14:35:31 69,144 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2008-06-19 19:51 143360 –a—— c:\program files\Dropbox\DropboxExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2008-06-19 19:51 143360 –a—— c:\program files\Dropbox\DropboxExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2008-06-19 19:51 143360 –a—— c:\program files\Dropbox\DropboxExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"RunSpySweeperScheduleAtStartup"="c:\windows\system32\msfeedssync.exe" [2008-01-19 12800]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Simplify Media"="c:\program files\Simplify Media\SimplifyMedia.exe" [2009-01-08 8079880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1398024]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-09-06 169264]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
"Adobe_ID0EYTHM"="c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 1884160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-17 c:\windows\RtHDVCpl.exe]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\program files\Dropbox\dropbox.exe [2008-07-03 8767575]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
VPN Client.lnk - c:\windows\Installer\{4C271126-C295-4828-A901-5910AE0C258B}\Icon3E5562ED7.ico [2008-09-08 6144]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-04-13 415072]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\MRI_DISABLED
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-09-10 535336]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
–a—— 2007-02-07 19:21 54832 c:\program files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSet]
–a—— 2007-04-25 16:47 45056 c:\windows\PLFSet.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
——— 2007-03-15 00:01 71216 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
–a—— 2006-11-10 15:35 90112 c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{E87E10E6-607C-4C76-8E3E-A0DAEB82EC3F}"= c:\program files\CyberLink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
"{6A759421-33E0-4E26-8A06-F1965CF848A0}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{240C7D58-A421-48B5-BFA3-FF1975EDEF8D}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{98511BB7-AC96-476D-938E-A3A0050D85FB}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{E13DE3F5-A8B0-4E6D-9DAB-6BDD2DD8D84D}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{C2BB2A4C-3AB5-4163-8BC4-4DCC232F7129}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C98D39D4-DDB0-44A2-9E59-02DB96E28B1F}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{E93CAF6A-3787-4246-B057-83349F3FD40D}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{ECDFDD91-0221-4035-AFB5-571E90852F4A}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{9F307CDF-D310-433C-B133-454EA024C5AE}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{97F3FE01-E32C-4CBB-ABB4-64A66EBBB183}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{FD8F2145-725A-487F-BA6E-E068AE65082C}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{5070C06C-1D38-4555-BD95-EFBB69EAEC61}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{0995ACC1-808C-45EF-A616-7674E5E0D180}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{F4C5A106-7349-4EF2-AE8D-F60F6D00BA35}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{04B5FFD7-7EF4-4D7F-A632-C377C0A4A898}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{06F876BE-78F4-4D88-9C19-1B9C5D952E15}c:\\program files\\mirc\\mirc.exe"= UDP:c:\program files\mirc\mirc.exe:mIRC
"UDP Query User{CEB36888-70AE-46B6-97D3-141A365B8D55}c:\\program files\\mirc\\mirc.exe"= TCP:c:\program files\mirc\mirc.exe:mIRC
"{6F5B6776-1299-4352-BA3F-64BC664DD84C}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{00FA71D1-77B6-4385-B67C-5A659CBE228E}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"TCP Query User{D21F129E-05AA-49F0-80E6-A58063C839AA}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{958EE9C0-8F87-4AAE-A9F1-D5BFE184E6F3}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"{B13CDBBA-47BB-49F8-8C13-8888AFCDE9A8}"= UDP:3703:Adobe Version Cue CS3 Server
"{02B1DD75-0F20-435B-BD96-10781A85B8E5}"= UDP:3704:Adobe Version Cue CS3 Server
"{CE2B38A5-4908-41FC-BCAC-77FFA8FB8EA8}"= UDP:50900:Adobe Version Cue CS3 Server
"{DA3D0563-E7F8-4592-8407-07A260AB8A69}"= UDP:50901:Adobe Version Cue CS3 Server
"{80330BAF-B3EB-483E-94AF-E810EF6527E4}"= UDP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{741DA650-4F15-430B-B01A-9446CCF12B4A}"= TCP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{488EA232-7349-4F8B-BF7A-1A0B5199F54A}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{616BEBB8-A52E-4552-8183-3BE2FEE90CB8}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{7C343614-2B03-4F80-9FEE-C61B6225E3D8}"= TCP:62515:vpn
"{C7D5728D-DE2B-4650-B66F-4151C0D17BB2}"= TCP:10000:vpn1
"TCP Query User{D06C4765-9B7E-42ED-B004-5A5DE1AD6751}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts
"UDP Query User{A1669D33-B90F-4FCD-AD99-3C431B397F47}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts
"TCP Query User{EADF93A5-72AE-429D-AB84-A0B344F24853}c:\\program files\\crossloop\\crossloopconnect.exe"= UDP:c:\program files\crossloop\crossloopconnect.exe:CrossLoop - Simple Secure Screen Sharing
"UDP Query User{8DD1EB09-8F5B-4A29-B176-05DEED3A7D0D}c:\\program files\\crossloop\\crossloopconnect.exe"= TCP:c:\program files\crossloop\crossloopconnect.exe:CrossLoop - Simple Secure Screen Sharing
"{1AC56B75-D75C-4973-857A-590D51AC2BFC}"= UDP:c:\program files\Cisco Systems\VPN Client\ipsecdialer.exe:ipsecdialer.exe
"{E0B922AC-6B7D-4A51-86DF-28CDC2D32CF5}"= TCP:c:\program files\Cisco Systems\VPN Client\ipsecdialer.exe:ipsecdialer.exe
"{9BD1B4D1-5DF5-4A25-B53C-9EC2BD1AB276}"= UDP:c:\program files\Cisco Systems\VPN Client\vpngui.exe:vpngui
"{C325F49B-24C9-4185-B7BB-BECDACCF218F}"= TCP:c:\program files\Cisco Systems\VPN Client\vpngui.exe:vpngui
"{6CEA28DF-39AF-46D2-A7AC-9910E4AD0A74}"= UDP:c:\program files\Cisco Systems\VPN Client\vpnclient.exe:vpnclient
"{082B33CA-EB15-49B8-9B74-0BAF49E39C99}"= TCP:c:\program files\Cisco Systems\VPN Client\vpnclient.exe:vpnclient
"TCP Query User{65073DFC-387F-47B8-A202-B1948B1F4D54}c:\\program files\\videolan\\vlc\\vlc.exe"= UDP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"UDP Query User{37475A7E-AC04-4476-9E93-36A3A1F78E21}c:\\program files\\videolan\\vlc\\vlc.exe"= TCP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"{6A879FF1-FAC5-4CD2-9EE4-CA8BE83D87D4}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{046873A2-6672-4CFA-A4BE-DCB9ABD6150B}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{287E0296-FA80-4604-AD0B-D4962A1CE4B9}c:\\program files\\simplify media\\simplifymedia.exe"= UDP:c:\program files\simplify media\simplifymedia.exe:Simplify Media
"UDP Query User{02C4F824-DAE5-4BA5-977F-91D9D84C3D29}c:\\program files\\simplify media\\simplifymedia.exe"= TCP:c:\program files\simplify media\simplifymedia.exe:Simplify Media
"{1CFCAC39-0FB9-4646-91E7-7B749037A2B5}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{E66EDF58-2A3D-4B63-A212-A6D26519AE77}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{D039383D-2689-4C64-B10B-41E3606A970E}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{8E3AB21D-8415-49F2-BE66-B554D4E17DBE}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{2F29F264-EA24-4B1E-9208-AE51A0E916EE}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP000.TMP\adobe.exe:TCP
"{3165DB0A-E0B8-47B7-BF6A-A42E3B95C28D}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP000.TMP\adobe.exe:TCP
"{7E9F1F85-1B1C-4D52-A827-CFF28ABD1610}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP003.TMP\adobe.exe:TCP
"{64A82E9A-4A1F-4267-8E5B-E0C2B6F3571E}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP003.TMP\adobe.exe:TCP
"{D1865ABA-FBBD-4662-A4FE-14DA5FF95AC0}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP007.TMP\adobe.exe:TCP
"{5C64C674-0690-404D-8D46-0CD960FEABF1}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP007.TMP\adobe.exe:TCP
"{548B18D8-48F7-46EB-8C09-359AB280A6F3}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP012.TMP\adobe.exe:TCP
"{74B5972D-28A2-4D20-8708-8CDC9B20360C}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP012.TMP\adobe.exe:TCP
"{D17BF34F-2896-407A-85D6-6D514B0E1529}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP001.TMP\adobe.exe:TCP
"{0F862BB8-CC03-4F38-9E00-3D320A7B7BAD}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP001.TMP\adobe.exe:TCP
"{D8343A8E-062C-438E-A75D-48F4DC9568A3}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP006.TMP\adobe.exe:TCP
"{5FB6AD1F-B219-44C1-8B9A-05B247A609C7}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP006.TMP\adobe.exe:TCP
"TCP Query User{59C24D90-EE94-42E6-AE92-9C5E1179946E}c:\\program files\\trillian\\trillian.exe"= UDP:c:\program files\trillian\trillian.exe:Trillian
"UDP Query User{FAAFD621-79F0-408E-9E22-2B3A66758A7D}c:\\program files\\trillian\\trillian.exe"= TCP:c:\program files\trillian\trillian.exe:Trillian
"{A4D70ABA-1626-4AB4-9281-CBF104CA00B0}"= UDP:c:\users\Owner\AppData\Local\Temp\IXP002.TMP\adobe.exe:TCP
"{9479A986-8B72-4699-8728-BE3C1CF7AA11}"= TCP:c:\users\Owner\AppData\Local\Temp\IXP002.TMP\adobe.exe:TCP

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP000.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP000.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP003.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP003.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP007.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP007.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP012.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP012.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP001.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP001.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP006.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP006.TMP\adobe.exe:*:Enabled:Windows Messanger
"c:\\Users\\Owner\\AppData\\Local\\Temp\\IXP002.TMP\\adobe.exe"= c:\users\Owner\AppData\Local\Temp\IXP002.TMP\adobe.exe:*:Enabled:Windows Messanger

R0 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [2007-04-03 39680]
R0 O2SDRDR;O2SDRDR;c:\windows\System32\drivers\o2sd.sys [2007-04-02 35712]
R3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-02-02 648456]
R4 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};c:\program files\CyberLink\PowerDVD\000.fcl [2007-12-19 06:53:51 13560]
R4 TabletServiceWacom;TabletServiceWacom;c:\windows\System32\Wacom_Tablet.exe [2008-10-06 2748200]
R4 tmevtmgr;tmevtmgr;c:\windows\System32\drivers\tmevtmgr.sys [2008-02-14 52240]
R4 tmpreflt;tmpreflt;c:\windows\System32\drivers\tmpreflt.sys [2007-09-28 36368]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\System32\drivers\wacmoumonitor.sys [2008-10-06 15656]
.
Contents of the 'Scheduled Tasks' folder

2009-01-25 c:\windows\Tasks\User_Feed_Synchronization-{562807D3-12E1-4214-B2D7-680F190A2229}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 02:33]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mStart Page = hxxp://en.us.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: ffffound.com\www
Trusted Zone: megapixel.net\www
Trusted Zone: stepinsidedesign.com\assets
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\mzinexth.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\mzinexth.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-26 09:55:10
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************
.
Completion time: 2009-01-26 9:58:21
ComboFix-quarantined-files.txt 2009-01-26 14:58:16
ComboFix2.txt 2009-01-21 03:50:48
ComboFix3.txt 2009-01-20 05:04:36
ComboFix4.txt 2009-01-19 21:43:06

Pre-Run: 4,461,862,912 bytes free
Post-Run: 4,254,638,080 bytes free

321 — E O F — 2009-01-20 08:02:27


i was still unable to access that malwarebytes link, so will run it from the alternate link you provided. also, i turned off trend micro when combofix prompted me to, but it noted that it was still running after reboot (that was a worrisome few minutes). just fyi.

d/ling malwarebytes now - thankyou!
Malwarebytes' Anti-Malware 1.33 Database version: 1695 Windows 6.0.6001 Service Pack 1 1/26/2009 12:45:22 PM mbam-log-2009-01-26 (12-44-53).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 192436 Time elapsed: 2 hour(s), 19 minute(s), 34 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 3 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.114.73,85.255.112.227 -> No action taken. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{1acd1ffd-ea70-465d-8ecb-120286ebd4e3}\NameServer (Trojan.DNSChanger) -> Data: 85.255.114.73,85.255.112.227 -> No action taken. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{8ad01c8d-fea9-435f-8270-73b4c2fd24a8}\NameServer (Trojan.DNSChanger) -> Data: 85.255.114.73,85.255.112.227 -> No action taken. Folders Infected: (No malicious items detected) Files Infected: C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\components\iamfamous.dll.vir (Spyware.Passwords) -> No action taken. C:\Windows\System32\gaopdxpfnieqhw.dll (Trojan.DNSChanger) -> No action taken. C:\Windows\System32\drivers\gaopdxiqpnycnt.sys (Trojan.Agent) -> No action taken.
DDS (Ver_09-01-18.01) - NTFSx86 Run by [removed] at 12:56:15.17 on Mon 01/26/2009 Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_11 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1789.873 [GMT -5:00] AV: Trend Micro AntiVirus *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Ati2evxx.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Acer\Mobility Center\MobilityService.exe C:\Program Files\O2Micro Oz128 Driver\o2flash.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\Wacom_Tablet.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Trend Micro\BM\TMBMSRV.exe C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Trend Micro\Internet Security\TmProxy.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\taskeng.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\WTablet\Wacom_TabletUser.exe C:\Windows\system32\Wacom_Tablet.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Skype\Phone\Skype.exe C:\Users\Owner\AppData\Local\Temp\RtkBtMnt.exe C:\Windows\ehome\ehtray.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Simplify Media\SimplifyMedia.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\Dropbox\dropbox.exe C:\Windows\servicing\TrustedInstaller.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Owner\Desktop\dds.scr C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.ca/ uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mStart Page = hxxp://en.us.acer.yahoo.com uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com BHO: MRI_DISABLED - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - No File BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll uRun: [Sidebar] "c:\program files\windows sidebar\sidebar.exe" /autoRun uRun: [StartCCC] "c:\program files\ati" technologies\ati.ace\core-static\CLIStart.exe uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [RunSpySweeperScheduleAtStartup] "c:\windows\system32\msfeedssync.exe" /ScheduleSweep=User_Feed_Synchronization-{562807D3-12E1-4214-B2D7-680F190A2229} uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [Simplify Media] "c:\program files\simplify media\SimplifyMedia.exe" mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [UfSeAgnt.exe] "c:\program files\trend micro\internet security\UfSeAgnt.exe" mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe" mRun: [Adobe_ID0EYTHM] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\program files\dropbox\dropbox.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{4c271126-c295-4828-a901-5910ae0c258b}\Icon3E5562ED7.ico StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mri_di~1\empowe~1.lnk - c:\acer\empowering technology\eAPLauncher.exe uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll Trusted Zone: ffffound.com\www Trusted Zone: megapixel.net\www Trusted Zone: stepinsidedesign.com\assets Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL ================= FIREFOX =================== FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\mzinexth.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/ FF - component: c:\users\owner\appdata\roaming\mozilla\firefox\profiles\mzinexth.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== =============== Created Last 30 ================ 2009-01-26 10:23 –d—– c:\users\owner\appdata\roaming\Malwarebytes 2009-01-26 10:23 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-01-26 10:23 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-01-26 10:23 –d—– c:\programdata\Malwarebytes 2009-01-26 10:23 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-01-26 10:23 –d—– c:\progra~2\Malwarebytes 2009-01-24 17:06 –d—– c:\program files\Simplify Media 2009-01-22 13:36 181,029,175 a——- c:\windows\MEMORY.DMP 2009-01-22 13:21 –d—– c:\programdata\Adobe Systems 2009-01-22 12:44 –d—– c:\program files\common files\Adobe Systems Shared 2009-01-20 11:49 56 a—h— c:\programdata\ezsidmv.dat 2009-01-20 11:49 56 a—h— c:\progra~2\ezsidmv.dat 2009-01-20 10:48 250 a——- c:\windows\gmer.ini 2009-01-20 00:22 288,768 a——- c:\windows\system32\drivers\srv.sys 2009-01-19 16:21 161,792 a——- c:\windows\SWREG.exe 2009-01-19 16:21 98,816 a——- c:\windows\sed.exe 2009-01-19 16:16 –d—– C:\ComboFix 2009-01-09 14:36 6,200 a——- c:\windows\system32\INT13EXT.VXD 2009-01-09 14:36 –d—– c:\program files\PC Inspector File Recovery 2009-01-08 17:14 –d—– c:\program files\Lavasoft 2009-01-08 17:13 –d—– c:\programdata\Lavasoft 2009-01-08 17:11 –d—– c:\program files\common files\Wise Installation Wizard 2009-01-07 13:03 –d—– c:\users\owner\.housecall6.6 ==================== Find3M ==================== 2008-11-10 05:43 410,984 a——- c:\windows\system32\deploytk.dll 2008-10-31 22:44 52,736 a——- c:\windows\apppatch\iebrshim.dll 2008-10-31 22:44 2,154,496 a——- c:\windows\apppatch\AcGenral.dll 2008-10-31 22:44 541,696 a——- c:\windows\apppatch\AcLayers.dll 2008-10-31 22:44 460,288 a——- c:\windows\apppatch\AcSpecfc.dll 2008-10-31 22:44 173,056 a——- c:\windows\apppatch\AcXtrnal.dll 2008-10-31 22:44 28,672 a——- c:\windows\system32\Apphlpdm.dll 2008-10-31 20:21 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll 2008-10-29 01:29 2,927,104 a——- c:\windows\explorer.exe 2008-10-07 08:53 86,016 a——- c:\windows\inf\infstor.dat 2008-10-07 08:53 51,200 a——- c:\windows\inf\infpub.dat 2008-10-07 08:53 143,360 a——- c:\windows\inf\infstrng.dat 2008-09-05 09:17 174 a–sh— c:\program files\desktop.ini 2008-09-05 09:04 665,600 a——- c:\windows\inf\drvindex.dat 2007-09-10 18:34 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2007-09-10 18:34 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2007-09-10 18:34 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2007-09-10 18:34 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 12:59:12.81 ===============
DDS (Ver_09-01-18.01) - NTFSx86 Run by [removed] at 12:56:15.17 on Mon 01/26/2009 Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_11 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1789.873 [GMT -5:00] AV: Trend Micro AntiVirus *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Ati2evxx.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Acer\Mobility Center\MobilityService.exe C:\Program Files\O2Micro Oz128 Driver\o2flash.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\Wacom_Tablet.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Trend Micro\BM\TMBMSRV.exe C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Trend Micro\Internet Security\TmProxy.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\taskeng.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\WTablet\Wacom_TabletUser.exe C:\Windows\system32\Wacom_Tablet.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Skype\Phone\Skype.exe C:\Users\Owner\AppData\Local\Temp\RtkBtMnt.exe C:\Windows\ehome\ehtray.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Simplify Media\SimplifyMedia.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\Dropbox\dropbox.exe C:\Windows\servicing\TrustedInstaller.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Owner\Desktop\dds.scr C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.ca/ uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mStart Page = hxxp://en.us.acer.yahoo.com uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com BHO: MRI_DISABLED - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - No File BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll uRun: [Sidebar] "c:\program files\windows sidebar\sidebar.exe" /autoRun uRun: [StartCCC] "c:\program files\ati" technologies\ati.ace\core-static\CLIStart.exe uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [RunSpySweeperScheduleAtStartup] "c:\windows\system32\msfeedssync.exe" /ScheduleSweep=User_Feed_Synchronization-{562807D3-12E1-4214-B2D7-680F190A2229} uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [Simplify Media] "c:\program files\simplify media\SimplifyMedia.exe" mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [UfSeAgnt.exe] "c:\program files\trend micro\internet security\UfSeAgnt.exe" mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe" mRun: [Adobe_ID0EYTHM] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\program files\dropbox\dropbox.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{4c271126-c295-4828-a901-5910ae0c258b}\Icon3E5562ED7.ico StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mri_di~1\empowe~1.lnk - c:\acer\empowering technology\eAPLauncher.exe uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll Trusted Zone: ffffound.com\www Trusted Zone: megapixel.net\www Trusted Zone: stepinsidedesign.com\assets Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL ================= FIREFOX =================== FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\mzinexth.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/ FF - component: c:\users\owner\appdata\roaming\mozilla\firefox\profiles\mzinexth.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== =============== Created Last 30 ================ 2009-01-26 10:23 –d—– c:\users\owner\appdata\roaming\Malwarebytes 2009-01-26 10:23 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-01-26 10:23 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-01-26 10:23 –d—– c:\programdata\Malwarebytes 2009-01-26 10:23 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-01-26 10:23 –d—– c:\progra~2\Malwarebytes 2009-01-24 17:06 –d—– c:\program files\Simplify Media 2009-01-22 13:36 181,029,175 a——- c:\windows\MEMORY.DMP 2009-01-22 13:21 –d—– c:\programdata\Adobe Systems 2009-01-22 12:44 –d—– c:\program files\common files\Adobe Systems Shared 2009-01-20 11:49 56 a—h— c:\programdata\ezsidmv.dat 2009-01-20 11:49 56 a—h— c:\progra~2\ezsidmv.dat 2009-01-20 10:48 250 a——- c:\windows\gmer.ini 2009-01-20 00:22 288,768 a——- c:\windows\system32\drivers\srv.sys 2009-01-19 16:21 161,792 a——- c:\windows\SWREG.exe 2009-01-19 16:21 98,816 a——- c:\windows\sed.exe 2009-01-19 16:16 –d—– C:\ComboFix 2009-01-09 14:36 6,200 a——- c:\windows\system32\INT13EXT.VXD 2009-01-09 14:36 –d—– c:\program files\PC Inspector File Recovery 2009-01-08 17:14 –d—– c:\program files\Lavasoft 2009-01-08 17:13 –d—– c:\programdata\Lavasoft 2009-01-08 17:11 –d—– c:\program files\common files\Wise Installation Wizard 2009-01-07 13:03 –d—– c:\users\owner\.housecall6.6 ==================== Find3M ==================== 2008-11-10 05:43 410,984 a——- c:\windows\system32\deploytk.dll 2008-10-31 22:44 52,736 a——- c:\windows\apppatch\iebrshim.dll 2008-10-31 22:44 2,154,496 a——- c:\windows\apppatch\AcGenral.dll 2008-10-31 22:44 541,696 a——- c:\windows\apppatch\AcLayers.dll 2008-10-31 22:44 460,288 a——- c:\windows\apppatch\AcSpecfc.dll 2008-10-31 22:44 173,056 a——- c:\windows\apppatch\AcXtrnal.dll 2008-10-31 22:44 28,672 a——- c:\windows\system32\Apphlpdm.dll 2008-10-31 20:21 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll 2008-10-29 01:29 2,927,104 a——- c:\windows\explorer.exe 2008-10-07 08:53 86,016 a——- c:\windows\inf\infstor.dat 2008-10-07 08:53 51,200 a——- c:\windows\inf\infpub.dat 2008-10-07 08:53 143,360 a——- c:\windows\inf\infstrng.dat 2008-09-05 09:17 174 a–sh— c:\program files\desktop.ini 2008-09-05 09:04 665,600 a——- c:\windows\inf\drvindex.dat 2007-09-10 18:34 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2007-09-10 18:34 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2007-09-10 18:34 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2007-09-10 18:34 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 12:59:12.81 ===============
Hi :)

also, i turned off trend micro when combofix prompted me to, but it noted that it was still running after reboot (that was a worrisome few minutes). just fyi.

That's fine, it just needs to be disabled for the main part of the scan. We expect the AntiVirus programs to start again on reboot and there is no problem there.

After running MalwareBytes', did you allow it to "Remove" what it found?

Is the computer running any better now?

Thanks.
yeah - sorry! i did hit "remove": i thought to repost the log, but then got caught up in work - with little distraction from the computer! i'm hopeful that the malwarebytes did the trick, but i will be keeping an eye on it over the next few days. i've had the same skype and IM issues the other day, so i will be watching for these as well as the redirects over the next few days. *hopefully* that is it! if that is the case, THANK-YOU very much for your diligent attention and assistance! i mean, even a little thing like rehosting that .exe file for me might have (fingers crossed) made a huge difference to me, so i do hope you realize how much i appreciate your help. i will report back on the status of the computer in the next 24 hours and hopefully it will be uneventful. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI