TechSpot

Followed rules and posting logs

By dtbayliss1
Oct 25, 2010
  1. have had problem with computer for the last 2 weeks....the computer freezes & states the following error "faulting application svchost.exe, version 5.1.2600.5512, faulting module ntdll.dll, version 5.1.2600.5755, fault address 0x00023845"

    we also have several browers open up..i have run malware bytes-no issues.. upgraded to norton 360 thurs and spoke to their tech. support, they had me run a program Eraser. nothing found.

    I reinstalled malwarebytes and also followed the 8 rules..i have attached the malware bytes log / the dds logs and the gmer. log
    there was this highlighted in red C:\WINDOWS\system32\DRIVERS\netbt.sys ..and is how I found the site and the recommended instructions for manual removal.

    GMER 1.0.15.15477 - http://www.gmer.net
    Rootkit scan 2010-10-25 18:17:13
    Windows 5.1.2600 Service Pack 3
    Running: gmer.exe; Driver: C:\DOCUME~1\DYLANB~1\LOCALS~1\Temp\pwlcipob.sys


    ---- System - GMER 1.0.15 ----

    SSDT 8A601C30 ZwAlertResumeThread
    SSDT 8A4CD798 ZwAlertThread
    SSDT 8A561BC0 ZwAllocateVirtualMemory
    SSDT 8A4550A8 ZwAssignProcessToJobObject
    SSDT 8A644950 ZwConnectPort
    SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xB512A210]
    SSDT 8A569D68 ZwCreateMutant
    SSDT 8A57F1D0 ZwCreateSymbolicLinkObject
    SSDT 8A4A10B0 ZwCreateThread
    SSDT 8A481108 ZwDebugActiveProcess
    SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xB512A490]
    SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xB512A9F0]
    SSDT 8A55FCB8 ZwDuplicateObject
    SSDT 8A4B60A8 ZwFreeVirtualMemory
    SSDT 8A4734E0 ZwImpersonateAnonymousToken
    SSDT 8A484320 ZwImpersonateThread
    SSDT 8A5A64D8 ZwLoadDriver
    SSDT 8A4960B0 ZwMapViewOfSection
    SSDT 8A44F320 ZwOpenEvent
    SSDT 8A5705F0 ZwOpenProcess
    SSDT 8A463A28 ZwOpenProcessToken
    SSDT 8A566108 ZwOpenSection
    SSDT 8A64ACA0 ZwOpenThread
    SSDT 8A44F8B8 ZwProtectVirtualMemory
    SSDT 8A4CB930 ZwResumeThread
    SSDT 8A554868 ZwSetContextThread
    SSDT 8A6AC2D0 ZwSetInformationProcess
    SSDT 8A475108 ZwSetSystemInformation
    SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xB512AC40]
    SSDT 8A447BC0 ZwSuspendProcess
    SSDT 8A4C84E0 ZwSuspendThread
    SSDT 8A4E2E50 ZwTerminateProcess
    SSDT 8A567BC0 ZwTerminateThread
    SSDT 8A44FBC0 ZwUnmapViewOfSection
    SSDT 8A7020E8 ZwWriteVirtualMemory

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntkrnlpa.exe!ZwCallbackReturn + 2554 80501D8C 5 Bytes [F0, 05, 57, 8A, 28]
    .text ntkrnlpa.exe!ZwCallbackReturn + 255A 80501D92 2 Bytes [46, 8A]
    .text ntkrnlpa.exe!ZwCallbackReturn + 27C0 80501FF8 4 Bytes CALL C4DA901D
    ? SYMDS.SYS The system cannot find the file specified. !
    ? SYMEFA.SYS The system cannot find the file specified. !
    .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB8796360, 0x2456AE, 0xE8000020]
    .rsrc C:\WINDOWS\system32\DRIVERS\netbt.sys entry point in ".rsrc" section [0xB5093A14]

    ---- User code sections - GMER 1.0.15 ----

    .text C:\Program Files\Mozilla Firefox\firefox.exe[584] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 013F000A
    .text C:\Program Files\Mozilla Firefox\firefox.exe[584] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0140000A
    .text C:\Program Files\Mozilla Firefox\firefox.exe[584] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 013E000C
    .text C:\Program Files\Mozilla Firefox\firefox.exe[584] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0275003A
    .text C:\WINDOWS\System32\svchost.exe[1052] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00CB000A
    .text C:\WINDOWS\System32\svchost.exe[1052] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00CC000A
    .text C:\WINDOWS\System32\svchost.exe[1052] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00CA000C
    .text C:\WINDOWS\System32\svchost.exe[1052] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00CD000A
    .text C:\WINDOWS\Explorer.EXE[3740] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00C2000A
    .text C:\WINDOWS\Explorer.EXE[3740] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C4000A
    .text C:\WINDOWS\Explorer.EXE[3740] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B7000C

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
    AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 8A0FFAEA
    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 8A0FFAEA
    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 8A0FFAEA
    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 8A0FFAEA
    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-e 8A0FFAEA

    AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
    AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
    AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    Device \FileSystem\Cdfs \Cdfs B14A5400
    Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
    Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskSAMSUNG_HD080HJ#P_______________________ZH100-34#5&71de149&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000

    ---- Disk sectors - GMER 1.0.15 ----

    Disk \Device\Harddisk0\DR0 sectors 156249744 (+254): rootkit-like behavior;

    ---- Files - GMER 1.0.15 ----

    File C:\Documents and Settings\NetworkService\Cookies\system@keenfind[2].txt 0 bytes
    File C:\WINDOWS\system32\DRIVERS\netbt.sys suspicious modification; TDL3 <-- ROOTKIT !!!

    ---- EOF - GMER 1.0.15 ----



    thanks again..
     
  2. dtbayliss1

    dtbayliss1 TS Rookie Topic Starter

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-10-21.02)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 12/29/2006 6:44:43 PM
    System Uptime: 10/25/2010 6:24:03 PM (0 hours ago)

    Motherboard: Dell Inc | | 0CT103
    Processor: AMD Athlon(tm) 64 Processor 3200+ | Socket M2 | 2004/1000mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 71 GiB total, 31.313 GiB free.
    D: is CDROM ()
    E: is FIXED (FAT32) - 112 GiB total, 46.749 GiB free.

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    No restore point in system.

    ==== Installed Programs ======================

    3ivx MPEG-4 5.0.3 (remove only)
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.4.0
    Adobe Shockwave Player 11.5
    Amazon MP3 Downloader 1.0.5
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    AT&T Self Support Tool
    bodybugg Software
    BodyMedia(R) USB Device Drivers
    Bonjour
    Canon Camera WIA Driver
    Delicious Add-on for Internet Explorer
    Dell CinePlayer
    Dell System Restore
    Digital Content Portal
    EarthLink Setup Files
    FlipShare
    Google Toolbar for Internet Explorer
    Google Update Helper
    High Definition Audio Driver Package - KB835221
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    Hotfix for Windows XP (KB979306)
    Hotfix for Windows XP (KB981793)
    iTunes
    Java Auto Updater
    Java(TM) 6 Update 21
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Access MUI (English) 2007
    Microsoft Office Access Setup Metadata MUI (English) 2007
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Professional 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Publisher MUI (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Plus! Photo Story 2 LE
    Microsoft Silverlight
    Microsoft Software Update for Web Folders (English) 12
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    MobileMe Control Panel
    Monopoly - SpongeBob SquarePants Edition
    Move Media Player
    Mozilla Firefox (3.6.11)
    Mozilla Thunderbird (2.0.0.22)
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 4.0 SP2 Parser and SDK
    MyShoppingGenie
    Norton 360
    Norton Security Scan
    NVIDIA Drivers
    Pdf995
    Picasa 3
    Quicken 2003 Deluxe
    QuickTime
    RAMpage
    RealFlight G3 R/C Simulator
    Rhapsody Player Engine
    Roxio DLA
    Roxio MyDVD LE
    Roxio RecordNow Audio
    Roxio RecordNow Copy
    Roxio RecordNow Data
    Safari
    SearchAssist
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB976321)
    Security Update for 2007 Microsoft Office System (KB982312)
    Security Update for 2007 Microsoft Office System (KB982331)
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft Office Access 2007 (KB979440)
    Security Update for Microsoft Office Excel 2007 (KB982308)
    Security Update for Microsoft Office InfoPath 2007 (KB979441)
    Security Update for Microsoft Office Outlook 2007 (KB980376)
    Security Update for Microsoft Office PowerPoint 2007 (KB982158)
    Security Update for Microsoft Office Publisher 2007 (KB982124)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB969613)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Security Update for Microsoft Office Word 2007 (KB982135)
    Security Update for Step By Step Interactive Training (KB898458)
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Internet Explorer 7 (KB938127-v2)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 7 (KB969897)
    Security Update for Windows Internet Explorer 7 (KB972260)
    Security Update for Windows Internet Explorer 7 (KB974455)
    Security Update for Windows Internet Explorer 7 (KB976325)
    Security Update for Windows Internet Explorer 7 (KB978207)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB976325)
    Security Update for Windows Internet Explorer 8 (KB978207)
    Security Update for Windows Internet Explorer 8 (KB981332)
    Security Update for Windows Internet Explorer 8 (KB982381)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB971961)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB977165)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978251)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Sonic Activation Module
    Sonic Update Manager
    Unity Web Player
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Outlook 2007 Junk Email Filter (kb2202131)
    Update for Windows Internet Explorer 7 (KB976749)
    Update for Windows Internet Explorer 8 (KB976662)
    Update for Windows Internet Explorer 8 (KB978506)
    Update for Windows Internet Explorer 8 (KB980182)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    URL Assistant
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player
    WebFldrs XP
    Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Imaging Component
    Windows Installer 3.1 (KB893803)
    Windows Installer Clean Up
    Windows Internet Explorer 7
    Windows Internet Explorer 8
    Windows Media Format 11 runtime
    Windows Media Player 10
    Windows Media Player 11
    Windows XP Service Pack 3
    Yahoo! Search Protection
    Yahoo! Software Update

    ==== Event Viewer Messages From Past Week ========

    10/25/2010 6:17:40 PM, error: Service Control Manager [7034] - The Yahoo! Updater service terminated unexpectedly. It has done this 1 time(s).
    10/25/2010 6:17:40 PM, error: Service Control Manager [7034] - The McciServiceHost service terminated unexpectedly. It has done this 1 time(s).
    10/25/2010 6:17:40 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    10/25/2010 6:17:40 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
    10/25/2010 6:17:39 PM, error: Service Control Manager [7034] - The Viewpoint Manager Service service terminated unexpectedly. It has done this 1 time(s).
    10/25/2010 6:17:39 PM, error: Service Control Manager [7034] - The McciCMService service terminated unexpectedly. It has done this 1 time(s).
    10/25/2010 6:17:39 PM, error: Service Control Manager [7034] - The FlipShare Service service terminated unexpectedly. It has done this 1 time(s).
    10/25/2010 6:17:39 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
    10/25/2010 6:17:39 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    10/24/2010 9:42:55 AM, error: DCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {0C0A3666-30C9-11D0-8F20-00805F2CD064} to the user BAYLISSHOME\Ethan SID (S-1-5-21-2635721055-1679008965-77389887-1010). This security permission can be modified using the Component Services administrative tool.
    10/22/2010 5:20:46 PM, error: PlugPlayManager [11] - The device Root\LEGACY_SYMSMR130\0000 disappeared from the system without first being prepared for removal.
    10/20/2010 8:01:13 AM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
    10/20/2010 7:59:53 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    10/20/2010 7:59:48 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 eeCtrl Fips IPSec MRxSmb NetBIOS NetBT nvatabus nvraid RasAcd Rdbss SAVRTPEL SPBBCDrv SYMTDI Tcpip
    10/20/2010 7:59:48 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
    10/20/2010 7:59:48 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/20/2010 7:59:48 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/20/2010 7:59:48 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
    10/20/2010 7:59:48 AM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/20/2010 7:59:48 AM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/20/2010 7:58:51 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
    10/20/2010 11:00:19 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: nvatabus nvraid
    10/20/2010 11:00:18 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
    10/20/2010 11:00:18 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
    10/20/2010 11:00:17 PM, error: Service Control Manager [7000] - The mrtRate service failed to start due to the following error: The system cannot find the file specified.
    10/19/2010 7:49:06 AM, error: Print [19] - Sharing printer failed + 1722, Printer Microsoft XPS Document Writer share name Printer.
    10/19/2010 7:44:26 AM, information: Windows File Protection [64017] - Windows File Protection file scan completed successfully.
    10/19/2010 7:34:27 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the NVSvc service.
    10/19/2010 7:18:54 AM, information: Windows File Protection [64016] - Windows File Protection file scan was started.

    ==== End Of File ===========================

    DDS (Ver_10-10-21.02) - NTFSx86
    Run by Dylan Bayliss at 18:33:10.90 on Mon 10/25/2010
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2494.1783 [GMT -5:00]

    AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
    FW: Norton 360 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Motive\McciCMService.exe
    C:\Program Files\Common Files\Motive\McciServiceHost.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\stsystra.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\RAMpage V1.3\RAMpage.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
    C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
    C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
    C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Documents and Settings\Dylan Bayliss\My Documents\Downloads\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.msn.com
    uSearch Page = hxxp://www.google.com
    uDefault_Page_URL = hxxp://www.msn.com
    uDefault_Search_URL = hxxp://www.google.com/ie
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
    uInternet Settings,ProxyServer = http=127.0.0.1:5555
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant = hxxp://www.google.com/ie
    BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\4.3.0.5\coIEPlg.dll
    BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\4.3.0.5\IPSBHO.DLL
    BHO: CDelHotkeys Object: {78875f5c-a685-4405-8dc5-d48dc65452b0} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: Delicious Toolbar: {61d1c847-df80-423a-8c6d-dc03b97e6ebe} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll
    TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\4.3.0.5\coIEPlg.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [Yahoo! Pager] 1
    uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
    uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
    uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
    uRun: [IMC] c:\program files\friendfinder\friendfinder messenger 4\imc.exe
    uRun: [FCACheck] c:\windows\system32\fca\FCACheck.exe
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [SigmatelSysTrayApp] stsystra.exe
    mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
    mRun: [RAMpage] c:\program files\rampage v1.3\RAMpage.exe LW B
    mRun: [ATT-SST_McciTrayApp] "c:\program files\att-sst\McciTrayApp.exe"
    mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
    mRun: [nwiz] nwiz.exe /install
    mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
    mRun: [Motive SmartBridge] c:\progra~1\sbcsel~1\smartb~1\MotiveSB.exe
    mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
    mRun: [BJCFD] c:\program files\broadjump\client foundation\CFD.exe
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
    mRun: [WinampAgent] c:\program files\winamp\winampa.exe
    mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
    mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
    mRun: [FamilyCyberAlert] c:\windows\system32\fca\syslogin.exe
    mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
    dRun: [Picasa Media Detector] c:\program files\picasa2\PicasaMediaDetector.exe
    dRunOnce: [RunNarrator] Narrator.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {2C887991-08F0-11DC-A9B2-0012F0B227DD} - {B8D8B1D0-83AF-451B-8CD9-8F1BF4ED8FEA} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll
    IE: {2C887992-08F0-11DC-A9B2-0012F0B227DD} - {9D19C405-BA93-461b-871F-97992CC45972} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll
    IE: {2C887993-08F0-11DC-A9B2-0012F0B227DD} - {4D3D441F-9543-4941-B664-2EDCF9FC1B56} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
    DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} - hxxp://download.microsoft.com/download/a/f/b/afba1967-2025-49da-8356-bc4132038945/VirtualEarth3D.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\dylanb~1\applic~1\mozilla\firefox\profiles\87kumd8w.default\
    FF - prefs.js: browser.startup.homepage - www.google.com
    FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\coffplgn\components\coFFPlgn.dll
    FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\ipsffplgn\components\IPSFFPl.dll
    FF - plugin: c:\documents and settings\dylan bayliss\application data\move networks\plugins\npqmp071503000010.dll
    FF - plugin: c:\documents and settings\dylan bayliss\application data\mozilla\firefox\profiles\87kumd8w.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
    FF - plugin: c:\program files\common files\motive\npMotive.dll
    FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
    FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified

    ============= SERVICES / DRIVERS ===============

    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-9-29 206256]
    R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0403000.005\symds.sys [2010-10-20 328752]
    R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0403000.005\symefa.sys [2010-10-20 173104]
    R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\bashdefs\20101001.001\BHDrvx86.sys [2010-10-2 692272]
    R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0403000.005\cchpx86.sys [2010-10-20 501888]
    R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0403000.005\ironx86.sys [2010-10-20 116784]
    R2 McciServiceHost;McciServiceHost;c:\program files\common files\motive\McciServiceHost.exe [2010-8-18 315392]
    R2 N360;Norton 360;c:\program files\norton 360\engine\4.3.0.5\ccsvchst.exe [2010-10-20 126392]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-7-11 24652]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-10-20 102448]
    R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20101021.003\IDSXpx86.sys [2010-10-19 341880]
    R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20101025.002\NAVENG.SYS [2010-10-25 86064]
    R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20101025.002\NAVEX15.SYS [2010-10-25 1371184]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-17 135664]
    S2 mrtRate;mrtRate; [x]

    =============== Created Last 30 ================

    2010-10-23 14:58:01 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-10-23 14:57:59 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-10-23 14:57:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-10-22 21:55:19 -------- d-----w- c:\docume~1\dylanb~1\locals~1\applic~1\NPE
    2010-10-21 03:53:55 -------- d-----w- c:\docume~1\dylanb~1\applic~1\Tific
    2010-10-21 03:42:31 501888 ----a-w- c:\windows\system32\drivers\n360\0403000.005\cchpx86.sys
    2010-10-21 03:42:31 43696 ----a-w- c:\windows\system32\drivers\n360\0403000.005\srtspx.sys
    2010-10-21 03:42:31 361904 ----a-w- c:\windows\system32\drivers\n360\0403000.005\symtdi.sys
    2010-10-21 03:42:31 339504 ----a-w- c:\windows\system32\drivers\n360\0403000.005\symtdiv.sys
    2010-10-21 03:42:31 328752 ----a-r- c:\windows\system32\drivers\n360\0403000.005\symds.sys
    2010-10-21 03:42:31 325680 ----a-w- c:\windows\system32\drivers\n360\0403000.005\srtsp.sys
    2010-10-21 03:42:31 173104 ----a-w- c:\windows\system32\drivers\n360\0403000.005\symefa.sys
    2010-10-21 03:42:31 116784 ----a-w- c:\windows\system32\drivers\n360\0403000.005\ironx86.sys
    2010-10-21 03:41:58 -------- d-----w- c:\windows\system32\drivers\n360\0403000.005
    2010-10-20 22:40:44 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
    2010-10-20 22:40:44 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
    2010-10-20 22:40:44 -------- d-----w- c:\program files\Symantec
    2010-10-20 22:39:29 -------- d-----w- c:\windows\system32\drivers\N360
    2010-10-20 22:39:27 -------- d-----w- c:\program files\Norton 360
    2010-10-20 22:26:33 -------- d-----w- c:\docume~1\alluse~1\applic~1\PCSettings
    2010-10-20 04:00:02 -------- d-sha-r- C:\cmdcons
    2010-10-20 03:49:41 98816 ----a-w- c:\windows\sed.exe
    2010-10-20 03:49:41 77312 ----a-w- c:\windows\MBR.exe
    2010-10-20 03:49:41 256512 ----a-w- c:\windows\PEV.exe
    2010-10-20 03:49:41 161792 ----a-w- c:\windows\SWREG.exe
    2010-10-20 03:48:39 -------- d-s---w- C:\ComboFix
    2010-10-19 12:44:25 116224 ----a-w- c:\windows\system32\dllcache\xrxwiadr.dll
    2010-10-19 12:44:21 23040 ----a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
    2010-10-19 12:44:20 18944 ----a-w- c:\windows\system32\dllcache\xrxscnui.dll
    2010-10-19 12:44:16 27648 ----a-w- c:\windows\system32\dllcache\xrxftplt.exe
    2010-10-19 12:44:12 4608 ----a-w- c:\windows\system32\dllcache\xrxflnch.exe
    2010-10-19 12:44:07 99865 ----a-w- c:\windows\system32\dllcache\xlog.exe
    2010-10-19 12:44:03 16970 ----a-w- c:\windows\system32\dllcache\xem336n5.sys
    2010-10-19 12:44:02 19455 ----a-w- c:\windows\system32\dllcache\wvchntxx.sys
    2010-10-19 12:42:56 19016 ----a-w- c:\windows\system32\dllcache\w926nd.sys
    2010-10-19 12:41:59 26112 ----a-w- c:\windows\system32\dllcache\usbser.sys
    2010-10-19 12:40:59 440576 ----a-w- c:\windows\system32\dllcache\tridkb.dll
    2010-10-19 12:39:58 36640 ----a-w- c:\windows\system32\dllcache\t2r4mini.sys
    2010-10-19 12:38:56 106584 ----a-w- c:\windows\system32\dllcache\spdports.dll
    2010-10-19 12:37:59 28160 ----a-w- c:\windows\system32\dllcache\sm91w.dll
    2010-10-19 12:36:58 6784 ----a-w- c:\windows\system32\dllcache\serscan.sys
    2010-10-19 12:35:58 182272 ----a-w- c:\windows\system32\dllcache\s3mt3d.dll
    2010-10-19 12:34:59 9728 ----a-w- c:\windows\system32\dllcache\query.exe
    2010-10-19 12:33:57 259328 ----a-w- c:\windows\system32\dllcache\perm3dd.dll
    2010-10-19 12:32:58 116736 ----a-w- c:\windows\system32\dllcache\ovcodec2.dll
    2010-10-19 12:31:58 9344 ----a-w- c:\windows\system32\dllcache\ntapm.sys
    2010-10-19 12:30:59 35392 ----a-w- c:\windows\system32\dllcache\n9i128.dll
    2010-10-19 12:29:58 16128 ----a-w- c:\windows\system32\dllcache\modemcsa.sys
    2010-10-19 12:28:59 20573 ----a-w- c:\windows\system32\dllcache\lne100.sys
    2010-10-19 12:27:59 90200 ----a-w- c:\windows\system32\dllcache\io8ports.dll
    2010-10-19 12:26:59 353184 ----a-w- c:\windows\system32\dllcache\i740dnt5.dll
    2010-10-19 12:25:59 126976 ----a-w- c:\windows\system32\dllcache\hpgt34tk.dll
    2010-10-19 12:24:59 71680 ----a-w- c:\windows\system32\dllcache\fnfilter.dll
    2010-10-19 12:23:58 144896 ----a-w- c:\windows\system32\dllcache\epcfw2k.sys
    2010-10-19 12:22:59 91305 ----a-w- c:\windows\system32\dllcache\dimaint.sys
    2010-10-19 12:21:59 18944 ----a-w- c:\windows\system32\dllcache\cprofile.exe
    2010-10-19 12:20:53 13824 ----a-w- c:\windows\system32\dllcache\bulltlp3.sys
    2010-10-19 12:19:59 6272 ----a-w- c:\windows\system32\dllcache\apmbatt.sys
    2010-10-10 14:59:42 -------- d-----w- c:\docume~1\dylanb~1\locals~1\applic~1\PCHealth
    2010-10-02 12:39:12 -------- d-----w- c:\windows\system32\wbem\repository\FS
    2010-10-02 12:39:12 -------- d-----w- c:\windows\system32\wbem\Repository

    ==================== Find3M ====================

    2010-09-22 05:56:11 59 ----a-w- c:\windows\wpd99.drv
    2010-08-10 10:15:58 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2010-08-10 10:15:58 69632 ----a-w- c:\windows\system32\QuickTime.qts

    ============= FINISH: 18:35:51.82 ===============
     
  3. dtbayliss1

    dtbayliss1 TS Rookie Topic Starter

  4. Broni

    Broni Malware Annihilator Posts: 52,897   +344

    Welcome aboard [​IMG]

    Malwarebytes log is missing.
    Please, post it.

    When done....

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
     
  5. dtbayliss1

    dtbayliss1 TS Rookie Topic Starter

    malware bytes log

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4927

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    10/23/2010 6:11:13 PM
    mbam-log-2010-10-23 (18-11-13).txt

    Scan type: Full scan (C:\|)
    Objects scanned: 278637
    Time elapsed: 2 hour(s), 8 minute(s), 19 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 2
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     
  6. dtbayliss1

    dtbayliss1 TS Rookie Topic Starter

    TDS killer Log

    2010/10/26 07:48:25.0062 TDSS rootkit removing tool 2.4.5.1 Oct 26 2010 11:28:49
    2010/10/26 07:48:25.0062 ================================================================================
    2010/10/26 07:48:25.0062 SystemInfo:
    2010/10/26 07:48:25.0062
    2010/10/26 07:48:25.0062 OS Version: 5.1.2600 ServicePack: 3.0
    2010/10/26 07:48:25.0062 Product type: Workstation
    2010/10/26 07:48:25.0062 ComputerName: BAYLISSHOME
    2010/10/26 07:48:25.0062 UserName: Dylan Bayliss
    2010/10/26 07:48:25.0062 Windows directory: C:\WINDOWS
    2010/10/26 07:48:25.0062 System windows directory: C:\WINDOWS
    2010/10/26 07:48:25.0062 Processor architecture: Intel x86
    2010/10/26 07:48:25.0062 Number of processors: 1
    2010/10/26 07:48:25.0062 Page size: 0x1000
    2010/10/26 07:48:25.0062 Boot type: Normal boot
    2010/10/26 07:48:25.0062 ================================================================================
    2010/10/26 07:48:26.0203 Initialize success
    2010/10/26 07:48:32.0671 ================================================================================
    2010/10/26 07:48:32.0671 Scan started
    2010/10/26 07:48:32.0671 Mode: Manual;
    2010/10/26 07:48:32.0671 ================================================================================
    2010/10/26 07:48:33.0437 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
    2010/10/26 07:48:33.0625 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
    2010/10/26 07:48:33.0796 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
    2010/10/26 07:48:33.0984 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
    2010/10/26 07:48:34.0203 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
    2010/10/26 07:48:34.0390 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
    2010/10/26 07:48:34.0609 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
    2010/10/26 07:48:34.0765 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
    2010/10/26 07:48:34.0953 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
    2010/10/26 07:48:35.0078 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
    2010/10/26 07:48:35.0312 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
    2010/10/26 07:48:35.0453 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
    2010/10/26 07:48:35.0578 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
    2010/10/26 07:48:35.0734 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
    2010/10/26 07:48:35.0921 AmdK8 (0a4d13b388c814560bd69c3a496ecfa8) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
    2010/10/26 07:48:36.0000 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
    2010/10/26 07:48:36.0109 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
    2010/10/26 07:48:36.0250 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
    2010/10/26 07:48:36.0375 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
    2010/10/26 07:48:36.0593 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
    2010/10/26 07:48:36.0750 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
    2010/10/26 07:48:36.0890 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
    2010/10/26 07:48:37.0109 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
    2010/10/26 07:48:37.0265 bcm4sbxp (78e7b52da292fa90bad2f887bbf22159) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
    2010/10/26 07:48:37.0421 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
    2010/10/26 07:48:37.0968 BHDrvx86 (5138da8715da5f9823b753b6cb36a9a9) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20101001.001\BHDrvx86.sys
    2010/10/26 07:48:38.0171 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
    2010/10/26 07:48:38.0281 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
    2010/10/26 07:48:38.0468 ccHP (e941e709847fa00e0dd6d58d2b8fb5e1) C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys
    2010/10/26 07:48:38.0625 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
    2010/10/26 07:48:38.0671 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
    2010/10/26 07:48:38.0875 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
    2010/10/26 07:48:39.0062 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
    2010/10/26 07:48:39.0250 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
    2010/10/26 07:48:39.0328 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
    2010/10/26 07:48:39.0468 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
    2010/10/26 07:48:39.0640 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
    2010/10/26 07:48:39.0859 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
    2010/10/26 07:48:40.0015 DLABOIOM (e2d0de31442390c35e3163c87cb6a9eb) C:\WINDOWS\system32\DLA\DLABOIOM.SYS
    2010/10/26 07:48:40.0140 DLACDBHM (d979bebcf7edcc9c9ee1857d1a68c67b) C:\WINDOWS\system32\Drivers\DLACDBHM.SYS
    2010/10/26 07:48:40.0203 DLADResN (83545593e297f50a8e2524b4c071a153) C:\WINDOWS\system32\DLA\DLADResN.SYS
    2010/10/26 07:48:40.0375 DLAIFS_M (96e01d901cdc98c7817155cc057001bf) C:\WINDOWS\system32\DLA\DLAIFS_M.SYS
    2010/10/26 07:48:40.0562 DLAOPIOM (0a60a39cc5e767980a31ca5d7238dfa9) C:\WINDOWS\system32\DLA\DLAOPIOM.SYS
    2010/10/26 07:48:40.0671 DLAPoolM (9fe2b72558fc808357f427fd83314375) C:\WINDOWS\system32\DLA\DLAPoolM.SYS
    2010/10/26 07:48:40.0828 DLARTL_N (7ee0852ae8907689df25049dcd2342e8) C:\WINDOWS\system32\Drivers\DLARTL_N.SYS
    2010/10/26 07:48:40.0953 DLAUDFAM (f08e1dafac457893399e03430a6a1397) C:\WINDOWS\system32\DLA\DLAUDFAM.SYS
    2010/10/26 07:48:41.0109 DLAUDF_M (e7d105ed1e694449d444a9933df8e060) C:\WINDOWS\system32\DLA\DLAUDF_M.SYS
    2010/10/26 07:48:41.0359 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
    2010/10/26 07:48:41.0656 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
    2010/10/26 07:48:41.0859 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
    2010/10/26 07:48:42.0031 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
    2010/10/26 07:48:42.0078 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
    2010/10/26 07:48:42.0171 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
    2010/10/26 07:48:42.0328 DRVMCDB (fd0f95981fef9073659d8ec58e40aa3c) C:\WINDOWS\system32\Drivers\DRVMCDB.SYS
    2010/10/26 07:48:42.0468 DRVNDDM (b4869d320428cdc5ec4d7f5e808e99b5) C:\WINDOWS\system32\Drivers\DRVNDDM.SYS
    2010/10/26 07:48:42.0687 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
    2010/10/26 07:48:42.0937 eeCtrl (089296aedb9b72b4916ac959752bdc89) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
    2010/10/26 07:48:43.0031 EraserUtilRebootDrv (850259334652d392e33ee3412562e583) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
    2010/10/26 07:48:43.0234 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
    2010/10/26 07:48:43.0375 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
    2010/10/26 07:48:43.0531 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
    2010/10/26 07:48:43.0625 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
    2010/10/26 07:48:43.0953 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
    2010/10/26 07:48:44.0125 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
    2010/10/26 07:48:44.0281 FTDIBUS (a36e8beedb3aaca09bf55a1d17904bc8) C:\WINDOWS\system32\drivers\ftdibus.sys
    2010/10/26 07:48:44.0437 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
    2010/10/26 07:48:44.0765 FTSER2K (a14a1f4bb391df9c233cb5dbd05feb70) C:\WINDOWS\system32\drivers\ftser2k.sys
    2010/10/26 07:48:45.0000 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
    2010/10/26 07:48:45.0109 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
    2010/10/26 07:48:45.0281 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
    2010/10/26 07:48:45.0406 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
    2010/10/26 07:48:45.0593 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
    2010/10/26 07:48:45.0750 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
    2010/10/26 07:48:45.0859 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
    2010/10/26 07:48:45.0937 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
    2010/10/26 07:48:46.0015 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
    2010/10/26 07:48:46.0453 IDSxpx86 (74e8463447101ecf0165ddc7e5168b7e) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20101025.001\IDSxpx86.sys
    2010/10/26 07:48:46.0609 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
    2010/10/26 07:48:46.0718 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
    2010/10/26 07:48:46.0812 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
    2010/10/26 07:48:46.0937 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
    2010/10/26 07:48:47.0062 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
    2010/10/26 07:48:47.0156 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
    2010/10/26 07:48:47.0312 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
    2010/10/26 07:48:47.0500 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
    2010/10/26 07:48:47.0625 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
    2010/10/26 07:48:47.0828 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
    2010/10/26 07:48:48.0015 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
    2010/10/26 07:48:48.0156 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
    2010/10/26 07:48:48.0281 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
    2010/10/26 07:48:48.0406 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
    2010/10/26 07:48:48.0546 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
    2010/10/26 07:48:48.0843 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
    2010/10/26 07:48:48.0968 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
    2010/10/26 07:48:49.0046 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
    2010/10/26 07:48:49.0187 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
    2010/10/26 07:48:49.0343 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
    2010/10/26 07:48:49.0453 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
    2010/10/26 07:48:49.0671 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
    2010/10/26 07:48:49.0906 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
    2010/10/26 07:48:50.0015 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
    2010/10/26 07:48:50.0203 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
    2010/10/26 07:48:50.0328 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
    2010/10/26 07:48:50.0515 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
    2010/10/26 07:48:50.0625 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
    2010/10/26 07:48:50.0750 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
    2010/10/26 07:48:50.0875 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
    2010/10/26 07:48:51.0015 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
    2010/10/26 07:48:51.0484 NAVENG (49d802531e5984cf1fe028c6c129b9d8) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20101025.040\NAVENG.SYS
    2010/10/26 07:48:51.0765 NAVEX15 (158676a5758c1fa519563b3e72fbf256) C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20101025.040\NAVEX15.SYS
    2010/10/26 07:48:51.0859 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
    2010/10/26 07:48:51.0984 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
    2010/10/26 07:48:52.0218 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
    2010/10/26 07:48:52.0312 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
    2010/10/26 07:48:52.0406 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
    2010/10/26 07:48:52.0484 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
    2010/10/26 07:48:52.0718 NetBT (c4602e537449754dc8fa98f0f1dea072) C:\WINDOWS\system32\DRIVERS\netbt.sys
    2010/10/26 07:48:52.0718 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\netbt.sys. Real md5: c4602e537449754dc8fa98f0f1dea072, Fake md5: 74b2b2f5bea5e9a3dc021d685551bd3d
    2010/10/26 07:48:52.0734 NetBT - detected Rootkit.Win32.TDSS.tdl3 (0)
    2010/10/26 07:48:52.0859 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
    2010/10/26 07:48:53.0062 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
    2010/10/26 07:48:53.0328 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
    2010/10/26 07:48:53.0781 nv (15a6306a0b958bf60f09688d0ee70479) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
    2010/10/26 07:48:54.0343 nvatabus (75562456aa672bb5fe56d3c64c6d1c7d) C:\WINDOWS\system32\drivers\nvatabus.sys
    2010/10/26 07:48:54.0531 nvraid (1d4781a5957300dc81b91161b45704bb) C:\WINDOWS\system32\drivers\nvraid.sys
    2010/10/26 07:48:54.0609 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
    2010/10/26 07:48:54.0765 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
    2010/10/26 07:48:54.0968 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
    2010/10/26 07:48:55.0109 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
    2010/10/26 07:48:55.0281 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
    2010/10/26 07:48:55.0390 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
    2010/10/26 07:48:55.0578 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
    2010/10/26 07:48:55.0718 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
    2010/10/26 07:48:55.0937 PCTCore (d302a59e6d1842a201930928a5bad68b) C:\WINDOWS\system32\drivers\PCTCore.sys
    2010/10/26 07:48:56.0796 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
    2010/10/26 07:48:56.0921 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
    2010/10/26 07:48:57.0156 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
    2010/10/26 07:48:57.0312 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
    2010/10/26 07:48:57.0484 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
    2010/10/26 07:48:57.0671 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
    2010/10/26 07:48:57.0906 PxHelp20 (49452bfcec22f36a7a9b9c2181bc3042) C:\WINDOWS\system32\Drivers\PxHelp20.sys
    2010/10/26 07:48:58.0046 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
    2010/10/26 07:48:58.0203 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
    2010/10/26 07:48:58.0312 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
    2010/10/26 07:48:58.0359 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
    2010/10/26 07:48:58.0453 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
    2010/10/26 07:48:58.0625 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
    2010/10/26 07:48:58.0750 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
    2010/10/26 07:48:58.0906 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
    2010/10/26 07:48:59.0000 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
    2010/10/26 07:48:59.0140 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
    2010/10/26 07:48:59.0328 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
    2010/10/26 07:48:59.0468 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
    2010/10/26 07:48:59.0656 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
    2010/10/26 07:48:59.0734 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
    2010/10/26 07:48:59.0953 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
    2010/10/26 07:49:00.0125 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
    2010/10/26 07:49:00.0281 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
    2010/10/26 07:49:00.0437 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
    2010/10/26 07:49:00.0656 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
    2010/10/26 07:49:00.0812 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS
    2010/10/26 07:49:00.0890 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
    2010/10/26 07:49:00.0968 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
    2010/10/26 07:49:01.0171 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
    2010/10/26 07:49:01.0406 SRTSP (ec5c3c6260f4019b03dfaa03ec8cbf6a) C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS
    2010/10/26 07:49:01.0515 SRTSPX (55d5c37ed41231e3ac2063d16df50840) C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS
    2010/10/26 07:49:01.0843 Srv (89220b427890aa1dffd1a02648ae51c3) C:\WINDOWS\system32\DRIVERS\srv.sys
    2010/10/26 07:49:02.0203 STHDA (8990440e4b2a7ca5a56a1833b03741fd) C:\WINDOWS\system32\drivers\sthda.sys
    2010/10/26 07:49:02.0343 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
    2010/10/26 07:49:02.0484 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
    2010/10/26 07:49:02.0593 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
    2010/10/26 07:49:02.0750 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
    2010/10/26 07:49:03.0000 SymDS (56890bf9d9204b93042089d4b45ae671) C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS
    2010/10/26 07:49:03.0234 SymEFA (1c91df5188150510a6f0cf78f7d94b69) C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS
    2010/10/26 07:49:03.0375 SymEvent (961b48b86f94d4cc8ceb483f8aa89374) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
    2010/10/26 07:49:03.0531 SymIRON (dc80fbf0a348e54853ef82eed4e11e35) C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS
    2010/10/26 07:49:03.0734 SYMTDI (41aad61f87ca8e3b5d0f7fe7fba0797d) C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS
    2010/10/26 07:49:03.0828 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
    2010/10/26 07:49:03.0875 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
    2010/10/26 07:49:03.0953 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
    2010/10/26 07:49:04.0093 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
    2010/10/26 07:49:04.0359 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
    2010/10/26 07:49:04.0468 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
    2010/10/26 07:49:04.0593 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
    2010/10/26 07:49:04.0718 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
    2010/10/26 07:49:04.0828 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
    2010/10/26 07:49:05.0062 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
    2010/10/26 07:49:05.0265 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
    2010/10/26 07:49:05.0640 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\WINDOWS\system32\Drivers\usbaapl.sys
    2010/10/26 07:49:05.0781 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
    2010/10/26 07:49:05.0937 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
    2010/10/26 07:49:06.0062 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
    2010/10/26 07:49:06.0265 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
    2010/10/26 07:49:06.0437 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
    2010/10/26 07:49:06.0625 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
    2010/10/26 07:49:06.0812 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
    2010/10/26 07:49:06.0937 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
    2010/10/26 07:49:07.0062 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
    2010/10/26 07:49:07.0250 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
    2010/10/26 07:49:07.0437 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
    2010/10/26 07:49:07.0578 vulfnths (c9a8ba443f809b70bccccd60cc73fa5c) C:\WINDOWS\System32\Drivers\vulfnth.sys
    2010/10/26 07:49:07.0687 vulfntrs (2d8c55889616f7767e9fb8adee37a02a) C:\WINDOWS\System32\Drivers\vulfntr.sys
    2010/10/26 07:49:07.0796 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
    2010/10/26 07:49:08.0140 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
    2010/10/26 07:49:08.0281 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys
    2010/10/26 07:49:08.0421 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
    2010/10/26 07:49:08.0609 ================================================================================
    2010/10/26 07:49:08.0609 Scan finished
    2010/10/26 07:49:08.0609 ================================================================================
    2010/10/26 07:49:08.0671 Detected object count: 1
    2010/10/26 07:49:18.0843 NetBT (c4602e537449754dc8fa98f0f1dea072) C:\WINDOWS\system32\DRIVERS\netbt.sys
    2010/10/26 07:49:18.0843 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\netbt.sys. Real md5: c4602e537449754dc8fa98f0f1dea072, Fake md5: 74b2b2f5bea5e9a3dc021d685551bd3d
    2010/10/26 07:49:41.0109 Backup copy found, using it..
    2010/10/26 07:49:43.0359 C:\WINDOWS\system32\DRIVERS\netbt.sys - will be cured after reboot
    2010/10/26 07:49:43.0359 Rootkit.Win32.TDSS.tdl3(NetBT) - User select action: Cure
    2010/10/26 07:49:59.0406 Deinitialize success
     
  7. Broni

    Broni Malware Annihilator Posts: 52,897   +344

    Good :)

    Download MBRCheck to your desktop

    Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
    It will show a black screen with some data on it.
    Enter N to exit.
    A report called MBRcheckxxxx.txt will be on your desktop
    Open this report and post its content in your next reply.

    ====================================================================

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  8. dtbayliss1

    dtbayliss1 TS Rookie Topic Starter

    mbr check

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Home Edition
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x0000001c

    Kernel Drivers (total 134):
    0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
    0x806D0000 \WINDOWS\system32\hal.dll
    0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
    0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
    0xB9F79000 ACPI.sys
    0xBA5AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
    0xB9F68000 pci.sys
    0xBA0A8000 isapnp.sys
    0xBA670000 pciide.sys
    0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
    0xBA0B8000 MountMgr.sys
    0xB9F49000 ftdisk.sys
    0xBA0C8000 \WINDOWS\system32\drivers\CLASSPNP.SYS
    0xBA330000 PartMgr.sys
    0xBA0D8000 VolSnap.sys
    0xB9F1B000 atapi.sys
    0xBA0E8000 disk.sys
    0xB9EE1000 fltmgr.sys
    0xB9E8B000 SYMDS.SYS
    0xB9E54000 PCTCore.sys
    0xB9E27000 SYMEFA.SYS
    0xB9E11000 DRVMCDB.SYS
    0xBA0F8000 PxHelp20.sys
    0xB9DFA000 KSecDD.sys
    0xB9DE7000 WudfPf.sys
    0xB9D5A000 Ntfs.sys
    0xB9D2D000 NDIS.sys
    0xB9D13000 Mup.sys
    0xBA148000 \SystemRoot\system32\DRIVERS\AmdK8.sys
    0xB8F0E000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
    0xB8EFA000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
    0xBA428000 \SystemRoot\system32\DRIVERS\usbohci.sys
    0xB8ED6000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0xBA430000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0xBA158000 \SystemRoot\system32\DRIVERS\imapi.sys
    0xBA5E8000 \SystemRoot\System32\Drivers\DLACDBHM.SYS
    0xBA168000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0xBA178000 \SystemRoot\system32\DRIVERS\redbook.sys
    0xB8EB3000 \SystemRoot\system32\DRIVERS\ks.sys
    0xBA438000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
    0xBA188000 \SystemRoot\system32\DRIVERS\bcm4sbxp.sys
    0xBA440000 \SystemRoot\system32\DRIVERS\usbuhci.sys
    0xBA5EA000 \SystemRoot\System32\Drivers\vulfnth.sys
    0xB8E8B000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
    0xBA762000 \SystemRoot\system32\DRIVERS\audstub.sys
    0xBA198000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0xB9CD3000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0xB8E74000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0xBA1A8000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0xBA1B8000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0xBA448000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0xB8E63000 \SystemRoot\system32\DRIVERS\psched.sys
    0xBA1C8000 \SystemRoot\system32\DRIVERS\msgpc.sys
    0xBA450000 \SystemRoot\system32\DRIVERS\ptilink.sys
    0xBA458000 \SystemRoot\system32\DRIVERS\raspti.sys
    0xBA1D8000 \SystemRoot\system32\DRIVERS\termdd.sys
    0xBA460000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0xBA468000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0xBA5EC000 \SystemRoot\system32\DRIVERS\swenum.sys
    0xB8E05000 \SystemRoot\system32\DRIVERS\update.sys
    0xBA548000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0xB8CF2000 \SystemRoot\system32\drivers\sthda.sys
    0xB8CCE000 \SystemRoot\system32\drivers\portcls.sys
    0xBA1E8000 \SystemRoot\system32\drivers\drmk.sys
    0xBA1F8000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0xBA208000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0xBA5F6000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0xBA564000 \SystemRoot\System32\Drivers\vulfntr.sys
    0xB92F9000 \SystemRoot\System32\Drivers\i2omgmt.SYS
    0xBA5FE000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0xBA6FA000 \SystemRoot\System32\Drivers\Null.SYS
    0xBA600000 \SystemRoot\System32\Drivers\Beep.SYS
    0xBA488000 \SystemRoot\System32\Drivers\DLARTL_N.SYS
    0xBA490000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0xBA498000 \SystemRoot\System32\drivers\vga.sys
    0xBA602000 \SystemRoot\System32\Drivers\mnmdd.SYS
    0xBA604000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0xBA4A0000 \SystemRoot\System32\Drivers\Msfs.SYS
    0xBA4A8000 \SystemRoot\System32\Drivers\Npfs.SYS
    0xB92ED000 \SystemRoot\system32\DRIVERS\rasacd.sys
    0xB6621000 \SystemRoot\system32\DRIVERS\ipsec.sys
    0xB65C8000 \SystemRoot\system32\DRIVERS\tcpip.sys
    0xB6571000 \SystemRoot\System32\Drivers\N360\0403000.005\SYMTDI.SYS
    0xB654C000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
    0xB5866000 \SystemRoot\system32\DRIVERS\ipnat.sys
    0xBA228000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0xBA360000 \SystemRoot\system32\DRIVERS\usbprint.sys
    0xB92D5000 \SystemRoot\system32\DRIVERS\hidusb.sys
    0xBA238000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    0xB57E6000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20101026.001\IDSxpx86.sys
    0xBA58C000 \SystemRoot\system32\DRIVERS\mouhid.sys
    0xB57BE000 \SystemRoot\system32\DRIVERS\netbt.sys
    0xB579C000 \SystemRoot\System32\drivers\afd.sys
    0xBA248000 \SystemRoot\system32\DRIVERS\netbios.sys
    0xB577D000 \SystemRoot\system32\drivers\N360\0403000.005\Ironx86.SYS
    0xBA278000 \SystemRoot\system32\drivers\N360\0403000.005\SRTSPX.SYS
    0xB5752000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0xB56E2000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0xBA288000 \SystemRoot\System32\Drivers\Fips.SYS
    0xBA598000 \SystemRoot\system32\DRIVERS\kbdhid.sys
    0xB5684000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
    0xB5667000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
    0xB55E8000 \SystemRoot\system32\drivers\N360\0403000.005\ccHPx86.sys
    0xB553C000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20101001.001\BHDrvx86.sys
    0xBA380000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
    0xB54F0000 \SystemRoot\System32\Drivers\Fastfat.SYS
    0xB54D8000 \SystemRoot\System32\Drivers\dump_atapi.sys
    0xBA62A000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
    0xBF800000 \SystemRoot\System32\win32k.sys
    0xB6660000 \SystemRoot\System32\drivers\Dxapi.sys
    0xBA3B0000 \SystemRoot\System32\watchdog.sys
    0xBF000000 \SystemRoot\System32\drivers\dxg.sys
    0xBA798000 \SystemRoot\System32\drivers\dxgthk.sys
    0xBF012000 \SystemRoot\System32\nv4_disp.dll
    0xBA2C8000 \SystemRoot\System32\Drivers\DRVNDDM.SYS
    0xBA72C000 \SystemRoot\System32\DLA\DLADResN.SYS
    0xB45A2000 \SystemRoot\System32\DLA\DLAIFS_M.SYS
    0xB4614000 \SystemRoot\System32\DLA\DLAOPIOM.SYS
    0xBA5B6000 \SystemRoot\System32\DLA\DLAPoolM.SYS
    0xBA4B0000 \SystemRoot\System32\DLA\DLABOIOM.SYS
    0xB4562000 \SystemRoot\System32\DLA\DLAUDFAM.SYS
    0xB454C000 \SystemRoot\System32\DLA\DLAUDF_M.SYS
    0xB44A0000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
    0xB3A4F000 \SystemRoot\system32\DRIVERS\mrxdav.sys
    0xB38DF000 \SystemRoot\system32\DRIVERS\srv.sys
    0xB33B0000 \SystemRoot\System32\Drivers\N360\0403000.005\SRTSP.SYS
    0xB323A000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20101026.048\NAVEX15.SYS
    0xB3226000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20101026.048\NAVENG.SYS
    0xBA418000 \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
    0xB30F9000 \SystemRoot\system32\drivers\wdmaud.sys
    0xB3817000 \SystemRoot\system32\drivers\sysaudio.sys
    0xB2C62000 \SystemRoot\System32\Drivers\HTTP.sys
    0x7C900000 \WINDOWS\system32\ntdll.dll

    Processes (total 49):
    0 System Idle Process
    4 System
    548 C:\WINDOWS\system32\smss.exe
    612 csrss.exe
    636 C:\WINDOWS\system32\winlogon.exe
    680 C:\WINDOWS\system32\services.exe
    692 C:\WINDOWS\system32\lsass.exe
    876 C:\WINDOWS\system32\svchost.exe
    940 svchost.exe
    1036 C:\WINDOWS\system32\svchost.exe
    1120 C:\WINDOWS\system32\svchost.exe
    1208 svchost.exe
    1304 svchost.exe
    1452 C:\WINDOWS\system32\spoolsv.exe
    1924 svchost.exe
    1956 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    1968 C:\Program Files\Bonjour\mDNSResponder.exe
    2008 C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
    304 C:\Program Files\Java\jre6\bin\jqs.exe
    340 C:\Program Files\Common Files\Motive\McciCMService.exe
    404 C:\Program Files\Common Files\Motive\McciServiceHost.exe
    596 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    712 C:\Program Files\Norton 360\Engine\4.3.0.5\ccsvchst.exe
    1108 C:\WINDOWS\system32\nvsvc32.exe
    1360 C:\WINDOWS\system32\svchost.exe
    1504 C:\Program Files\Viewpoint\Common\ViewpointService.exe
    1544 C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    252 alg.exe
    256 unsecapp.exe
    508 wmiprvse.exe
    2784 C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    5692 C:\Program Files\Norton 360\Engine\4.3.0.5\ccsvchst.exe
    2888 C:\WINDOWS\explorer.exe
    6024 C:\WINDOWS\stsystra.exe
    4792 C:\Program Files\Mozilla Firefox\firefox.exe
    4152 C:\WINDOWS\system32\DLA\DLACTRLW.EXE
    3760 C:\Program Files\RAMpage V1.3\RAMpage.exe
    4108 C:\WINDOWS\system32\rundll32.exe
    5040 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    5088 C:\Program Files\Common Files\Java\Java Update\jusched.exe
    4928 C:\Program Files\iTunes\iTunesHelper.exe
    4608 C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
    5240 C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
    5124 C:\WINDOWS\system32\ctfmon.exe
    4860 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    2232 C:\Program Files\iPod\bin\iPodService.exe
    4128 C:\WINDOWS\system32\wuauclt.exe
    6984 C:\Program Files\Mozilla Firefox\plugin-container.exe
    7616 C:\Documents and Settings\Dylan Bayliss\My Documents\Downloads\MBRCheck.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`02738a00 (NTFS)
    \\.\E: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (FAT32)

    PhysicalDrive0 Model Number: SAMSUNGHD080HJ/P, Rev: ZH100-34
    PhysicalDrive1 Model Number: IomegaIomega USB2/1394, Rev: 2.47

    Size Device Name MBR Status
    --------------------------------------------
    74 GB \\.\PhysicalDrive0 Dell MBR code detected
    SHA1: 57BDF501CE769EF2720C705B6C71C893DA31574E
    111 GB \\.\PhysicalDrive1 Unknown MBR code
    SHA1: 639AC5CDF8A5CF3245975932C6A4215450A7B98F


    Found non-standard or infected MBR.
    Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    Done!
     
  9. Broni

    Broni Malware Annihilator Posts: 52,897   +344

    That looks good :)

    Combofix log, please.
     
  10. dtbayliss1

    dtbayliss1 TS Rookie Topic Starter

    combix

    ComboFix 10-10-27.07 - Dylan Bayliss 10/28/2010 7:40.2.1 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2494.1804 [GMT -5:00]
    Running from: c:\documents and settings\Dylan Bayliss\Desktop\ComboFix.exe
    AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
    FW: Norton 360 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Dylan Bayliss\Local Settings\Application Data\{6B527840-F277-4F26-82CE-D9B4BE15D011}
    c:\documents and settings\Dylan Bayliss\Local Settings\Application Data\{6B527840-F277-4F26-82CE-D9B4BE15D011}\chrome\content\_cfg.js
    c:\documents and settings\Dylan Bayliss\Local Settings\Application Data\{6B527840-F277-4F26-82CE-D9B4BE15D011}\chrome\content\c.js
    c:\documents and settings\Dylan Bayliss\Local Settings\Application Data\{6B527840-F277-4F26-82CE-D9B4BE15D011}\chrome\content\overlay.xul
    c:\documents and settings\Dylan Bayliss\Local Settings\Application Data\{6B527840-F277-4F26-82CE-D9B4BE15D011}\install.rdf
    c:\documents and settings\Jane Bayliss\Local Settings\Application Data\{0AF56263-3C1D-4FEC-9FBD-98BDB40903E4}
    c:\documents and settings\Jane Bayliss\Local Settings\Application Data\{0AF56263-3C1D-4FEC-9FBD-98BDB40903E4}\chrome.manifest
    c:\documents and settings\Jane Bayliss\Local Settings\Application Data\{0AF56263-3C1D-4FEC-9FBD-98BDB40903E4}\chrome\content\_cfg.js
    c:\documents and settings\Jane Bayliss\Local Settings\Application Data\{0AF56263-3C1D-4FEC-9FBD-98BDB40903E4}\chrome\content\c.js
    c:\documents and settings\Jane Bayliss\Local Settings\Application Data\{0AF56263-3C1D-4FEC-9FBD-98BDB40903E4}\chrome\content\overlay.xul
    c:\documents and settings\Jane Bayliss\Local Settings\Application Data\{0AF56263-3C1D-4FEC-9FBD-98BDB40903E4}\install.rdf
    c:\documents and settings\Jane Bayliss\Local Settings\Application Data\Windows Server
    c:\documents and settings\Jane Bayliss\Local Settings\Application Data\Windows Server\flags.ini
    c:\documents and settings\Jane Bayliss\Local Settings\Application Data\Windows Server\uses32.dat
    c:\documents and settings\Reid Bayliss\gg2update.exe
    c:\documents and settings\Reid Bayliss\Local Settings\Application Data\{446F94DF-348E-4B38-861E-0D7481816895}
    c:\documents and settings\Reid Bayliss\Local Settings\Application Data\{446F94DF-348E-4B38-861E-0D7481816895}\chrome\content\_cfg.js
    c:\documents and settings\Reid Bayliss\Local Settings\Application Data\{446F94DF-348E-4B38-861E-0D7481816895}\chrome\content\c.js
    c:\documents and settings\Reid Bayliss\Local Settings\Application Data\{446F94DF-348E-4B38-861E-0D7481816895}\chrome\content\overlay.xul
    c:\documents and settings\Reid Bayliss\Local Settings\Application Data\{446F94DF-348E-4B38-861E-0D7481816895}\install.rdf
    C:\feed.txt

    .
    ((((((((((((((((((((((((( Files Created from 2010-09-28 to 2010-10-28 )))))))))))))))))))))))))))))))
    .

    2010-10-23 14:58 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-10-23 14:57 . 2010-10-23 14:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-10-23 14:57 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-10-23 12:40 . 2010-10-23 12:40 664 ----a-w- c:\documents and settings\Conner\Local Settings\Application Data\d3d9caps.tmp
    2010-10-23 12:29 . 2010-10-23 12:31 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
    2010-10-22 21:55 . 2010-10-22 21:57 -------- d-----w- c:\documents and settings\Dylan Bayliss\Local Settings\Application Data\NPE
    2010-10-22 21:52 . 2010-10-22 21:52 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\ICS
    2010-10-21 03:53 . 2010-10-21 03:53 -------- d-----w- c:\documents and settings\Dylan Bayliss\Application Data\Tific
    2010-10-20 22:40 . 2010-10-20 22:40 -------- d-----w- c:\program files\Symantec
    2010-10-20 22:40 . 2010-10-20 22:40 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
    2010-10-20 22:40 . 2010-10-20 22:40 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
    2010-10-20 22:39 . 2010-10-21 04:00 -------- d-----w- c:\windows\system32\drivers\N360
    2010-10-20 22:39 . 2010-10-20 22:39 -------- d-----w- c:\program files\Norton 360
    2010-10-20 22:39 . 2010-10-20 22:39 -------- d-----w- c:\program files\Windows Sidebar
    2010-10-20 22:26 . 2010-10-20 22:26 -------- d-----w- c:\documents and settings\All Users\Application Data\PCSettings
    2010-10-19 12:44 . 2008-04-14 00:12 116224 ----a-w- c:\windows\system32\dllcache\xrxwiadr.dll
    2010-10-19 12:44 . 2001-08-18 03:36 23040 ----a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
    2010-10-19 12:44 . 2008-04-14 00:12 18944 ----a-w- c:\windows\system32\dllcache\xrxscnui.dll
    2010-10-19 12:44 . 2001-08-18 03:37 27648 ----a-w- c:\windows\system32\dllcache\xrxftplt.exe
    2010-10-19 12:44 . 2001-08-18 03:37 4608 ----a-w- c:\windows\system32\dllcache\xrxflnch.exe
    2010-10-19 12:44 . 2001-08-18 03:37 99865 ----a-w- c:\windows\system32\dllcache\xlog.exe
    2010-10-19 12:44 . 2001-08-17 17:11 16970 ----a-w- c:\windows\system32\dllcache\xem336n5.sys
    2010-10-19 12:44 . 2004-08-04 03:29 19455 ----a-w- c:\windows\system32\dllcache\wvchntxx.sys
    2010-10-19 12:42 . 2001-08-17 17:13 19016 ----a-w- c:\windows\system32\dllcache\w926nd.sys
    2010-10-19 12:41 . 2008-04-13 18:45 26112 ----a-w- c:\windows\system32\dllcache\usbser.sys
    2010-10-19 12:40 . 2001-08-17 19:56 440576 ----a-w- c:\windows\system32\dllcache\tridkb.dll
    2010-10-19 12:39 . 2001-08-17 17:50 36640 ----a-w- c:\windows\system32\dllcache\t2r4mini.sys
    2010-10-19 12:38 . 2001-08-18 03:36 106584 ----a-w- c:\windows\system32\dllcache\spdports.dll
    2010-10-19 12:37 . 2004-08-04 11:00 26112 ----a-w- c:\windows\system32\dllcache\sm90w.dll
    2010-10-19 12:36 . 2001-08-17 18:53 6784 ----a-w- c:\windows\system32\dllcache\serscan.sys
    2010-10-19 12:35 . 2001-08-17 19:56 182272 ----a-w- c:\windows\system32\dllcache\s3mt3d.dll
    2010-10-19 12:34 . 2004-08-04 11:00 9728 ----a-w- c:\windows\system32\dllcache\query.exe
    2010-10-19 12:33 . 2008-04-14 00:10 259328 ----a-w- c:\windows\system32\dllcache\perm3dd.dll
    2010-10-19 12:32 . 2001-08-18 03:36 116736 ----a-w- c:\windows\system32\dllcache\ovcodec2.dll
    2010-10-19 12:31 . 2001-08-17 18:47 9344 ----a-w- c:\windows\system32\dllcache\ntapm.sys
    2010-10-19 12:30 . 2001-08-17 19:56 35392 ----a-w- c:\windows\system32\dllcache\n9i128.dll
    2010-10-19 12:29 . 2001-08-17 18:57 16128 ----a-w- c:\windows\system32\dllcache\modemcsa.sys
    2010-10-19 12:28 . 2001-08-17 17:12 20573 ----a-w- c:\windows\system32\dllcache\lne100.sys
    2010-10-19 12:27 . 2001-08-18 03:36 90200 ----a-w- c:\windows\system32\dllcache\io8ports.dll
    2010-10-19 12:26 . 2001-08-17 19:56 353184 ----a-w- c:\windows\system32\dllcache\i740dnt5.dll
    2010-10-19 12:25 . 2001-08-18 03:36 126976 ----a-w- c:\windows\system32\dllcache\hpgt34tk.dll
    2010-10-19 12:24 . 2001-08-18 03:36 71680 ----a-w- c:\windows\system32\dllcache\fnfilter.dll
    2010-10-19 12:23 . 2001-08-17 18:50 144896 ----a-w- c:\windows\system32\dllcache\epcfw2k.sys
    2010-10-19 12:22 . 2001-08-17 17:13 91305 ----a-w- c:\windows\system32\dllcache\dimaint.sys
    2010-10-19 12:21 . 2004-08-04 11:00 18944 ----a-w- c:\windows\system32\dllcache\cprofile.exe
    2010-10-19 12:20 . 2001-08-17 18:51 13824 ----a-w- c:\windows\system32\dllcache\bulltlp3.sys
    2010-10-19 12:19 . 2001-08-17 18:47 6272 ----a-w- c:\windows\system32\dllcache\apmbatt.sys
    2010-10-12 12:30 . 2010-10-12 12:30 -------- d-----w- c:\program files\Microsoft Silverlight
    2010-10-10 14:59 . 2010-10-10 14:59 -------- d-----w- c:\documents and settings\Dylan Bayliss\Local Settings\Application Data\PCHealth
    2010-10-10 14:53 . 2010-10-10 14:54 -------- d-----w- c:\program files\Common Files\Adobe
    2010-10-10 14:53 . 2010-10-10 14:53 -------- d-----w- c:\program files\Common Files\Adobe AIR
    2010-10-10 14:51 . 2010-10-10 14:57 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
    2010-10-10 14:51 . 2010-10-10 14:57 -------- d-----w- c:\program files\NOS
    2010-10-02 12:39 . 2010-10-02 12:39 -------- d-----w- c:\windows\system32\wbem\Repository
    2010-10-02 12:34 . 2010-10-02 12:37 -------- d-s---w- c:\documents and settings\Administrator

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-10-26 12:51 . 2004-08-10 18:51 162816 ----a-w- c:\windows\system32\drivers\netbt.sys
    2010-10-24 19:06 . 2010-08-09 23:48 664 ----a-w- c:\documents and settings\Ethan\Local Settings\Application Data\d3d9caps.tmp
    2010-09-18 17:23 . 2004-08-10 18:51 974848 ----a-w- c:\windows\system32\mfc42u.dll
    2010-09-18 06:53 . 2004-08-10 18:51 974848 ----a-w- c:\windows\system32\mfc42.dll
    2010-09-18 06:53 . 2004-08-10 18:51 954368 ----a-w- c:\windows\system32\mfc40.dll
    2010-09-18 06:53 . 2004-08-10 18:51 953856 ----a-w- c:\windows\system32\mfc40u.dll
    2010-09-10 05:58 . 2004-08-10 18:51 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-09-10 05:58 . 2004-08-10 18:51 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2010-09-10 05:58 . 2004-08-10 18:51 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2010-09-01 11:51 . 2004-08-10 18:50 285824 ----a-w- c:\windows\system32\atmfd.dll
    2010-08-31 13:42 . 2004-08-10 18:51 1852800 ----a-w- c:\windows\system32\win32k.sys
    2010-08-27 08:02 . 2004-08-10 18:51 119808 ----a-w- c:\windows\system32\t2embed.dll
    2010-08-27 05:57 . 2004-08-10 18:51 99840 ----a-w- c:\windows\system32\srvsvc.dll
    2010-08-26 13:39 . 2004-08-10 18:51 357248 ----a-w- c:\windows\system32\drivers\srv.sys
    2010-08-26 12:52 . 2009-04-14 18:30 5120 ----a-w- c:\windows\system32\xpsp4res.dll
    2010-08-24 23:22 . 2009-12-20 02:32 664 ----a-w- c:\documents and settings\Reid Bayliss\Local Settings\Application Data\d3d9caps.tmp
    2010-08-23 16:12 . 2004-08-10 18:50 617472 ----a-w- c:\windows\system32\comctl32.dll
    2010-08-17 13:17 . 2004-08-10 18:51 58880 ----a-w- c:\windows\system32\spoolsv.exe
    2010-08-16 08:45 . 2004-08-10 18:51 590848 ----a-w- c:\windows\system32\rpcrt4.dll
    2010-08-10 10:15 . 2010-08-10 10:15 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2010-08-10 10:15 . 2010-08-10 10:15 69632 ----a-w- c:\windows\system32\QuickTime.qts
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Yahoo! Pager"="1" [X]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-02 39408]
    "Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-23 7630848]
    "SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 282624]
    "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
    "RAMpage"="c:\program files\RAMpage V1.3\RAMpage.exe" [1999-11-27 45568]
    "ATT-SST_McciTrayApp"="c:\program files\ATT-SST\McciTrayApp.exe" [2010-07-27 1573888]
    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]
    "nwiz"="nwiz.exe" [2006-08-23 1617920]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-23 86016]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
    "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
    "Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-12-02 122880]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 443968]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "RunNarrator"="Narrator.exe" [2008-04-14 53760]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
    @=""

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
    backup=c:\windows\pss\McAfee Security Scan Plus.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
    2005-10-05 09:12 94208 ----a-w- c:\program files\Dell\Media Experience\DMXLauncher.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-08-10 10:15 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\Common Files\\Motive\\McciServiceHost.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"= 3389:TCP:mad:xpsp2res.dll,-22009

    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [9/29/2009 5:38 PM 206256]
    R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0403000.005\symds.sys [10/20/2010 10:42 PM 328752]
    R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0403000.005\symefa.sys [10/20/2010 10:42 PM 173104]
    R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20101001.001\BHDrvx86.sys [10/2/2010 12:00 AM 692272]
    R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0403000.005\cchpx86.sys [10/20/2010 10:42 PM 501888]
    R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0403000.005\ironx86.sys [10/20/2010 10:42 PM 116784]
    R2 McciServiceHost;McciServiceHost;c:\program files\Common Files\Motive\McciServiceHost.exe [8/18/2010 7:43 AM 315392]
    R2 N360;Norton 360;c:\program files\Norton 360\Engine\4.3.0.5\ccsvchst.exe [10/20/2010 10:42 PM 126392]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [7/11/2008 2:11 PM 24652]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [10/20/2010 7:09 PM 102448]
    R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20101027.001\IDSXpx86.sys [10/27/2010 10:06 PM 341880]
    S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/17/2010 9:02 AM 135664]
    S2 mrtRate;mrtRate; [x]

    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - SWPRV
    *NewlyCreated* - VSS
    .
    Contents of the 'Scheduled Tasks' folder

    2010-10-26 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

    2010-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-17 14:02]

    2010-10-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-17 14:02]

    2010-10-27 c:\windows\Tasks\Norton Security Scan for Jane Bayliss.job
    - c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.7.0.52\Nss.exe [2009-12-12 11:32]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.msn.com
    uDefault_Search_URL = hxxp://www.google.com/ie
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
    uInternet Settings,ProxyServer = http=127.0.0.1:5555
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\documents and settings\Dylan Bayliss\Application Data\Mozilla\Firefox\Profiles\87kumd8w.default\
    FF - prefs.js: browser.startup.homepage - www.google.com
    FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\components\coFFPlgn.dll
    FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\components\IPSFFPl.dll
    FF - plugin: c:\documents and settings\Dylan Bayliss\Application Data\Move Networks\plugins\npqmp071503000010.dll
    FF - plugin: c:\documents and settings\Dylan Bayliss\Application Data\Mozilla\Firefox\Profiles\87kumd8w.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
    FF - plugin: c:\program files\Common Files\Motive\npMotive.dll
    FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
    FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
    .
    - - - - ORPHANS REMOVED - - - -

    WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
    HKLM-Run-Motive SmartBridge - c:\progra~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
    HKLM-Run-BJCFD - c:\program files\BroadJump\Client Foundation\CFD.exe
    HKLM-Run-Google Desktop Search - c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
    SafeBoot-klmdb.sys
    MSConfigStartUp-FamilyCyberAlert - c:\windows\system32\FCA\syslogin.exe
    MSConfigStartUp-RealTray - c:\program files\Real\RealPlayer\RealPlay.exe
    MSConfigStartUp-WinampAgent - c:\program files\Winamp\winampa.exe
    AddRemove-SBC Self Support Tool - c:\docume~1\DYLANB~1\LOCALS~1\Temp\SST\CustomUninstall.exe
    AddRemove-SearchAssist - c:\dell\SearchAssist\UninstSA.bat
    AddRemove-UnityWebPlayer - c:\program files\Unity\WebPlayer\Uninstall.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-10-28 07:46
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
    "ImagePath"="\"c:\program files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\4.3.0.5\diMaster.dll\" /prefetch:1"
    .
    Completion time: 2010-10-28 07:49:47
    ComboFix-quarantined-files.txt 2010-10-28 12:49

    Pre-Run: 32,180,113,408 bytes free
    Post-Run: 34,337,988,608 bytes free

    - - End Of File - - 40A02F60210459B2FEFDA974C016E060
     
  11. Broni

    Broni Malware Annihilator Posts: 52,897   +344

    Unless you installed Viewpoint Manager knowledgeably...
    Go Start>Control Panel>Add\Remove (Programs and Features in Vista), and...
    Uninstall any of the following programs associated with Viewpoint:
    * Viewpoint Manager
    * Viewpoint Media Player
    * Viewpoint Toolbar
    This program does not do anything bad such as deliver ads or spy on you, but it is considered foistware ("drive-by-install") as it is installed without your consent through programs like AOL, AIM, Compuserve, etc.

    =====================================================================

    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    DDS::
    uInternet Settings,ProxyServer = http=127.0.0.1:5555
    
    
    Driver::
    mrtRate
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Yahoo! Pager"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=-
    
    

    3. Save the above as CFScript.txt

    4. Close/disable all anti virus and anti malware programs again, so they do not interfere with the running of ComboFix.

    5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
     
  12. dtbayliss1

    dtbayliss1 TS Rookie Topic Starter

    combo fix 10-28-10-thanks a lot for the help

    ComboFix 10-10-27.A3 - Dylan Bayliss 10/28/2010 20:27:51.3.1 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2494.1854 [GMT -5:00]
    Running from: c:\documents and settings\Dylan Bayliss\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Dylan Bayliss\Desktop\CFScript.txt
    AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
    FW: Norton 360 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_MRTRATE
    -------\Service_mrtRate


    ((((((((((((((((((((((((( Files Created from 2010-09-28 to 2010-10-29 )))))))))))))))))))))))))))))))
    .

    2010-10-23 14:58 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-10-23 14:57 . 2010-10-23 14:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-10-23 14:57 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-10-23 12:40 . 2010-10-23 12:40 664 ----a-w- c:\documents and settings\Conner\Local Settings\Application Data\d3d9caps.tmp
    2010-10-23 12:29 . 2010-10-23 12:31 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
    2010-10-22 21:55 . 2010-10-22 21:57 -------- d-----w- c:\documents and settings\Dylan Bayliss\Local Settings\Application Data\NPE
    2010-10-22 21:52 . 2010-10-22 21:52 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\ICS
    2010-10-21 03:53 . 2010-10-21 03:53 -------- d-----w- c:\documents and settings\Dylan Bayliss\Application Data\Tific
    2010-10-20 22:40 . 2010-10-20 22:40 -------- d-----w- c:\program files\Symantec
    2010-10-20 22:40 . 2010-10-20 22:40 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
    2010-10-20 22:40 . 2010-10-20 22:40 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
    2010-10-20 22:39 . 2010-10-21 04:00 -------- d-----w- c:\windows\system32\drivers\N360
    2010-10-20 22:39 . 2010-10-20 22:39 -------- d-----w- c:\program files\Norton 360
    2010-10-20 22:39 . 2010-10-20 22:39 -------- d-----w- c:\program files\Windows Sidebar
    2010-10-20 22:26 . 2010-10-20 22:26 -------- d-----w- c:\documents and settings\All Users\Application Data\PCSettings
    2010-10-19 12:44 . 2008-04-14 00:12 116224 ----a-w- c:\windows\system32\dllcache\xrxwiadr.dll
    2010-10-19 12:44 . 2001-08-18 03:36 23040 ----a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
    2010-10-19 12:44 . 2008-04-14 00:12 18944 ----a-w- c:\windows\system32\dllcache\xrxscnui.dll
    2010-10-19 12:44 . 2001-08-18 03:37 27648 ----a-w- c:\windows\system32\dllcache\xrxftplt.exe
    2010-10-19 12:44 . 2001-08-18 03:37 4608 ----a-w- c:\windows\system32\dllcache\xrxflnch.exe
    2010-10-19 12:44 . 2001-08-18 03:37 99865 ----a-w- c:\windows\system32\dllcache\xlog.exe
    2010-10-19 12:44 . 2001-08-17 17:11 16970 ----a-w- c:\windows\system32\dllcache\xem336n5.sys
    2010-10-19 12:44 . 2004-08-04 03:29 19455 ----a-w- c:\windows\system32\dllcache\wvchntxx.sys
    2010-10-19 12:42 . 2001-08-17 17:13 19016 ----a-w- c:\windows\system32\dllcache\w926nd.sys
    2010-10-19 12:41 . 2008-04-13 18:45 26112 ----a-w- c:\windows\system32\dllcache\usbser.sys
    2010-10-19 12:40 . 2001-08-17 19:56 440576 ----a-w- c:\windows\system32\dllcache\tridkb.dll
    2010-10-19 12:39 . 2001-08-17 17:50 36640 ----a-w- c:\windows\system32\dllcache\t2r4mini.sys
    2010-10-19 12:38 . 2001-08-18 03:36 106584 ----a-w- c:\windows\system32\dllcache\spdports.dll
    2010-10-19 12:37 . 2004-08-04 11:00 26112 ----a-w- c:\windows\system32\dllcache\sm90w.dll
    2010-10-19 12:36 . 2001-08-17 18:53 6784 ----a-w- c:\windows\system32\dllcache\serscan.sys
    2010-10-19 12:35 . 2001-08-17 19:56 182272 ----a-w- c:\windows\system32\dllcache\s3mt3d.dll
    2010-10-19 12:34 . 2004-08-04 11:00 9728 ----a-w- c:\windows\system32\dllcache\query.exe
    2010-10-19 12:33 . 2008-04-14 00:10 259328 ----a-w- c:\windows\system32\dllcache\perm3dd.dll
    2010-10-19 12:32 . 2001-08-18 03:36 116736 ----a-w- c:\windows\system32\dllcache\ovcodec2.dll
    2010-10-19 12:31 . 2001-08-17 18:47 9344 ----a-w- c:\windows\system32\dllcache\ntapm.sys
    2010-10-19 12:30 . 2001-08-17 19:56 35392 ----a-w- c:\windows\system32\dllcache\n9i128.dll
    2010-10-19 12:29 . 2001-08-17 18:57 16128 ----a-w- c:\windows\system32\dllcache\modemcsa.sys
    2010-10-19 12:28 . 2001-08-17 17:12 20573 ----a-w- c:\windows\system32\dllcache\lne100.sys
    2010-10-19 12:27 . 2001-08-18 03:36 90200 ----a-w- c:\windows\system32\dllcache\io8ports.dll
    2010-10-19 12:26 . 2001-08-17 19:56 353184 ----a-w- c:\windows\system32\dllcache\i740dnt5.dll
    2010-10-19 12:25 . 2001-08-18 03:36 126976 ----a-w- c:\windows\system32\dllcache\hpgt34tk.dll
    2010-10-19 12:24 . 2001-08-18 03:36 71680 ----a-w- c:\windows\system32\dllcache\fnfilter.dll
    2010-10-19 12:23 . 2001-08-17 18:50 144896 ----a-w- c:\windows\system32\dllcache\epcfw2k.sys
    2010-10-19 12:22 . 2001-08-17 17:13 91305 ----a-w- c:\windows\system32\dllcache\dimaint.sys
    2010-10-19 12:21 . 2004-08-04 11:00 18944 ----a-w- c:\windows\system32\dllcache\cprofile.exe
    2010-10-19 12:20 . 2001-08-17 18:51 13824 ----a-w- c:\windows\system32\dllcache\bulltlp3.sys
    2010-10-19 12:19 . 2001-08-17 18:47 6272 ----a-w- c:\windows\system32\dllcache\apmbatt.sys
    2010-10-12 12:30 . 2010-10-12 12:30 -------- d-----w- c:\program files\Microsoft Silverlight
    2010-10-10 14:59 . 2010-10-10 14:59 -------- d-----w- c:\documents and settings\Dylan Bayliss\Local Settings\Application Data\PCHealth
    2010-10-10 14:53 . 2010-10-10 14:54 -------- d-----w- c:\program files\Common Files\Adobe
    2010-10-10 14:53 . 2010-10-10 14:53 -------- d-----w- c:\program files\Common Files\Adobe AIR
    2010-10-10 14:51 . 2010-10-10 14:57 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
    2010-10-10 14:51 . 2010-10-10 14:57 -------- d-----w- c:\program files\NOS
    2010-10-02 12:39 . 2010-10-02 12:39 -------- d-----w- c:\windows\system32\wbem\Repository
    2010-10-02 12:34 . 2010-10-02 12:37 -------- d-s---w- c:\documents and settings\Administrator

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-10-26 12:51 . 2004-08-10 18:51 162816 ----a-w- c:\windows\system32\drivers\netbt.sys
    2010-10-24 19:06 . 2010-08-09 23:48 664 ----a-w- c:\documents and settings\Ethan\Local Settings\Application Data\d3d9caps.tmp
    2010-09-18 17:23 . 2004-08-10 18:51 974848 ----a-w- c:\windows\system32\mfc42u.dll
    2010-09-18 06:53 . 2004-08-10 18:51 974848 ----a-w- c:\windows\system32\mfc42.dll
    2010-09-18 06:53 . 2004-08-10 18:51 954368 ----a-w- c:\windows\system32\mfc40.dll
    2010-09-18 06:53 . 2004-08-10 18:51 953856 ----a-w- c:\windows\system32\mfc40u.dll
    2010-09-10 05:58 . 2004-08-10 18:51 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-09-10 05:58 . 2004-08-10 18:51 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2010-09-10 05:58 . 2004-08-10 18:51 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2010-09-01 11:51 . 2004-08-10 18:50 285824 ----a-w- c:\windows\system32\atmfd.dll
    2010-08-31 13:42 . 2004-08-10 18:51 1852800 ----a-w- c:\windows\system32\win32k.sys
    2010-08-27 08:02 . 2004-08-10 18:51 119808 ----a-w- c:\windows\system32\t2embed.dll
    2010-08-27 05:57 . 2004-08-10 18:51 99840 ----a-w- c:\windows\system32\srvsvc.dll
    2010-08-26 13:39 . 2004-08-10 18:51 357248 ----a-w- c:\windows\system32\drivers\srv.sys
    2010-08-26 12:52 . 2009-04-14 18:30 5120 ----a-w- c:\windows\system32\xpsp4res.dll
    2010-08-24 23:22 . 2009-12-20 02:32 664 ----a-w- c:\documents and settings\Reid Bayliss\Local Settings\Application Data\d3d9caps.tmp
    2010-08-23 16:12 . 2004-08-10 18:50 617472 ----a-w- c:\windows\system32\comctl32.dll
    2010-08-17 13:17 . 2004-08-10 18:51 58880 ----a-w- c:\windows\system32\spoolsv.exe
    2010-08-16 08:45 . 2004-08-10 18:51 590848 ----a-w- c:\windows\system32\rpcrt4.dll
    2010-08-10 10:15 . 2010-08-10 10:15 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2010-08-10 10:15 . 2010-08-10 10:15 69632 ----a-w- c:\windows\system32\QuickTime.qts
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-02 39408]
    "Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-23 7630848]
    "SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 282624]
    "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
    "RAMpage"="c:\program files\RAMpage V1.3\RAMpage.exe" [1999-11-27 45568]
    "ATT-SST_McciTrayApp"="c:\program files\ATT-SST\McciTrayApp.exe" [2010-07-27 1573888]
    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]
    "nwiz"="nwiz.exe" [2006-08-23 1617920]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-23 86016]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
    "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
    "Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-12-02 122880]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 443968]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "RunNarrator"="Narrator.exe" [2008-04-14 53760]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
    @=""

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
    backup=c:\windows\pss\McAfee Security Scan Plus.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
    2005-10-05 09:12 94208 ----a-w- c:\program files\Dell\Media Experience\DMXLauncher.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-08-10 10:15 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\Common Files\\Motive\\McciServiceHost.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"= 3389:TCP:mad:xpsp2res.dll,-22009

    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [9/29/2009 5:38 PM 206256]
    R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0403000.005\symds.sys [10/20/2010 10:42 PM 328752]
    R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0403000.005\symefa.sys [10/20/2010 10:42 PM 173104]
    R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20101001.001\BHDrvx86.sys [10/2/2010 12:00 AM 692272]
    R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0403000.005\cchpx86.sys [10/20/2010 10:42 PM 501888]
    R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0403000.005\ironx86.sys [10/20/2010 10:42 PM 116784]
    R2 McciServiceHost;McciServiceHost;c:\program files\Common Files\Motive\McciServiceHost.exe [8/18/2010 7:43 AM 315392]
    R2 N360;Norton 360;c:\program files\Norton 360\Engine\4.3.0.5\ccsvchst.exe [10/20/2010 10:42 PM 126392]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [7/11/2008 2:11 PM 24652]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [10/20/2010 7:09 PM 102448]
    R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20101027.001\IDSXpx86.sys [10/27/2010 10:06 PM 341880]
    S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/17/2010 9:02 AM 135664]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-10-26 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

    2010-10-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-17 14:02]

    2010-10-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-17 14:02]

    2010-10-28 c:\windows\Tasks\Norton Security Scan for Jane Bayliss.job
    - c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.7.0.52\Nss.exe [2009-12-12 11:32]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.msn.com
    uDefault_Search_URL = hxxp://www.google.com/ie
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\documents and settings\Dylan Bayliss\Application Data\Mozilla\Firefox\Profiles\87kumd8w.default\
    FF - prefs.js: browser.startup.homepage - www.google.com
    FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\components\coFFPlgn.dll
    FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\components\IPSFFPl.dll
    FF - plugin: c:\documents and settings\Dylan Bayliss\Application Data\Move Networks\plugins\npqmp071503000010.dll
    FF - plugin: c:\documents and settings\Dylan Bayliss\Application Data\Mozilla\Firefox\Profiles\87kumd8w.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
    FF - plugin: c:\program files\Common Files\Motive\npMotive.dll
    FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
    FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-10-28 20:54
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
    "ImagePath"="\"c:\program files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\4.3.0.5\diMaster.dll\" /prefetch:1"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'explorer.exe'(3008)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    c:\progra~1\SPYWAR~1\SDCONT~1.DLL
    c:\program files\Malwarebytes' Anti-Malware\mbamext.dll
    c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Flip Video\FlipShare\FlipShareService.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Common Files\Motive\McciCMService.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\windows\system32\nvsvc32.exe
    c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    c:\windows\system32\wbem\unsecapp.exe
    c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    c:\windows\stsystra.exe
    c:\windows\system32\RUNDLL32.EXE
    c:\program files\iPod\bin\iPodService.exe
    c:\program files\Common Files\Java\Java Update\jucheck.exe
    .
    **************************************************************************
    .
    Completion time: 2010-10-28 21:00:39 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-10-29 02:00
    ComboFix2.txt 2010-10-28 12:49

    Pre-Run: 34,237,583,360 bytes free
    Post-Run: 34,179,760,128 bytes free

    - - End Of File - - 00F82B839D5E91862D97963E3B5CABE5
     
  13. dtbayliss1

    dtbayliss1 TS Rookie Topic Starter

    also..one more thing..do you think my kid installing the TF2 game and the stream utility caused any of this mess..
    thanks again..
     
  14. Broni

    Broni Malware Annihilator Posts: 52,897   +344

    Unfortunately, it's impossible to answer your question.
    I can see, if your computer is infected, but I can't tell, where it came from.
    At the end of this topic, I'll post some more advice regarding computer security.

    How is computer doing at the moment?

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Under the Custom Scan box paste this in:


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  15. Broni

    Broni Malware Annihilator Posts: 52,897   +344

    Are you still out there?
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...