HydePryde
Posts: 22 +0
Hi everyone - I thought I was doing what I was supposed to do as far as keeping my PC safe, but apparently not. My PC got slower and slower (even though I had Symantec Endpoint Protection running constantly), so I finally used Symantec to do a full scan. It came up with multiple viruses, but it was able to deal with most of those. However, it found a couple more today that it can't get rid of or quarantine. Here's an image of the viruses that Symantec found and what it did with them.
http://www.screencast.com/t/kubSWv5um
I'm also wondering if this might be related to the fact that I have this in my recovery drive:
http://www.screencast.com/t/GfjURZeoeM
When I upgraded to Windows 7 from Vista, did I somehow install into the wrong drive? If I did that, would it mean that a bunch of files that need to be monitored/scanned regularly aren't being monitored/scanned because they're on a different drive?
I'm also running into an issue that may or may not be related to these viruses where Firefox crashes constantly (I have uninstalled it, reinstalled it, and updated to Firefox 4) and also takes FOREVER to open. As in, I click the Firefox icon and wait 5-10 minutes for it to open, and sometimes even then it never does. So, of course, I get all impatient with it and click it 4 or 5 times over the course of that 10 minutes, and when it finally opens it opens 4 or 5 windows.
Perhaps totally unrelated to the viruses, but I'm including that info just in case.
Thanks in advance for the help; I think I have just enough knowledge to be dangerous, so I'm afraid of screwing things up if I try to fix anything myself.
I followed the 8 steps to the best of my ability, and here are the logs. Let me know if I screwed something up and I'll do it again:
Malwarebytes:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6202
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
3/29/2011 9:08:39 AM
mbam-log-2011-03-29 (09-08-39).txt
Scan type: Quick scan
Objects scanned: 164321
Time elapsed: 6 minute(s), 9 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER:
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-03-29 10:33:47
Windows 6.1.7600
Running: 0oettx48.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002269be3c19
Reg HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application@Sources MSDMine?STacS
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002269be3c19 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\eventlog\Application@Sources MSDMine?STacS
---- EOF - GMER 1.0.15 ----
DDS:
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by Corinne at 10:36:50.63 on Tue 03/29/2011
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_24
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4094.2525 [GMT -5:00]
.
AV: Symantec Endpoint Protection *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Symantec Endpoint Protection *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Program Files\WTouch\WTouchService.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Fingerprint Reader Suite\upeksvr.exe
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\WTouch\WTouchUser.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_295b5b4710f6d77b\AESTSr64.exe
C:\Windows\SysWOW64\svchost.exe -k Akamai
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_295b5b4710f6d77b\STacSV64.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Windows\system32\Pen_Tablet.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray64.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\TechSmith\Jing\Jing.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Users\Corinne\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\system32\Pen_Tablet.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\OEM02Mon.exe
C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\splwow64.exe
c:\program files\windows defender\MpCmdRun.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Corinne\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Jing] C:\Program Files (x86)\TechSmith\Jing\Jing.exe
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
mRun: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
mRun: [ccApp] "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\Corinne\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Corinne\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\Corinne\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\EVERNO~1.LNK - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: DisableCAD = 1 (0x1)
IE: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
LSA: Notification Packages = scecli psqlpwd
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
mRun-x64: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray64.exe
mRun-x64: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
mRun-x64: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
mRun-x64: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
mRun-x64: [PLF1330] C:\Windows\PLF1330.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Corinne\AppData\Roaming\Mozilla\Firefox\Profiles\0m3ep9ul.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en
FF - component: C:\Users\Corinne\AppData\Roaming\Mozilla\Firefox\Profiles\0m3ep9ul.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\FFExternalAlert.dll
FF - component: C:\Users\Corinne\AppData\Roaming\Mozilla\Firefox\Profiles\0m3ep9ul.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCore.dll
FF - component: C:\Users\Corinne\AppData\Roaming\Mozilla\Firefox\Profiles\0m3ep9ul.default\extensions\engine@conduit.com\components\FFExternalAlert.dll
FF - component: C:\Users\Corinne\AppData\Roaming\Mozilla\Firefox\Profiles\0m3ep9ul.default\extensions\engine@conduit.com\components\RadioWMPCore.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60129.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Corinne\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Users\Corinne\AppData\Roaming\Mozilla\Firefox\Profiles\0m3ep9ul.default\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}\plugins\npietab2.dll
FF - plugin: C:\Users\Corinne\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Corinne\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-10-12 55856]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-9-16 169312]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_295b5b4710f6d77b\AESTSr64.exe [2009-12-28 86016]
R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 27136]
R2 Symantec AntiVirus;Symantec Endpoint Protection;C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe [2010-12-25 1839776]
R2 TabletServicePen;TabletServicePen;C:\Windows\System32\Pen_Tablet.exe [2010-10-12 5556520]
R2 WTouchService;WTouch Service;C:\Program Files\WTouch\WTouchService.exe [2010-10-12 127784]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-10-10 132656]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-13 17920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-4-29 136176]
S3 phaudlwr;Philips Audio Filter;C:\Windows\System32\drivers\phaudlwr.sys [2008-5-7 113664]
S3 SPC1330;USB2.0 PC Camera (SPC1330);C:\Windows\System32\drivers\spc1330.sys [2008-8-28 3297920]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-2-18 51712]
S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\System32\drivers\wacmoumonitor.sys [2010-10-12 18216]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-3-26 1255736]
.
=============== Created Last 30 ================
.
2011-03-29 14:15:24 521448 ----a-w- C:\Windows\System32\deployJava1.dll
2011-03-27 18:29:43 -------- d-----w- C:\Windows\pss
2011-03-27 03:12:23 -------- d-----w- C:\Tools
2011-03-27 03:12:22 -------- d-----w- C:\sources
2011-03-27 02:39:01 -------- d-----w- C:\Users\Corinne\AppData\Roaming\Auslogics
2011-03-27 02:38:36 -------- d-----w- C:\Program Files (x86)\Auslogics
2011-03-27 02:13:02 -------- d-----w- C:\Windows\en
2011-03-27 02:10:22 69464 ----a-w- C:\Windows\SysWow64\XAPOFX1_3.dll
2011-03-27 02:10:22 515416 ----a-w- C:\Windows\SysWow64\XAudio2_5.dll
2011-03-27 02:10:19 523088 ----a-w- C:\Windows\System32\d3dx10_42.dll
2011-03-27 02:10:19 453456 ----a-w- C:\Windows\SysWow64\d3dx10_42.dll
2011-03-27 02:09:58 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\116f481f1cbec2407\DSETUP.dll
2011-03-27 02:09:58 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\116f481f1cbec2407\DXSETUP.exe
2011-03-27 02:09:58 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\116f481f1cbec2407\dsetup32.dll
2011-03-27 02:09:54 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fff8b041cbec2406\DSETUP.dll
2011-03-27 02:09:54 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fff8b041cbec2406\DXSETUP.exe
2011-03-27 02:09:54 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fff8b041cbec2406\dsetup32.dll
2011-03-27 02:09:36 -------- d-----w- C:\Users\Corinne\AppData\Local\Windows Live
2011-03-25 17:00:22 453456 ----a-w- C:\Windows\SysWow64\d3dx10_41.dll
2011-03-25 17:00:22 4178264 ----a-w- C:\Windows\SysWow64\D3DX9_41.dll
2011-03-25 17:00:22 1846632 ----a-w- C:\Windows\SysWow64\D3DCompiler_41.dll
2011-03-25 17:00:21 517448 ----a-w- C:\Windows\SysWow64\XAudio2_4.dll
2011-03-25 17:00:21 22360 ----a-w- C:\Windows\SysWow64\X3DAudio1_6.dll
2011-03-25 17:00:17 -------- d-----w- C:\Program Files (x86)\Lightworks
2011-03-25 16:48:33 2851328 ----a-w- C:\Windows\System32\themeui.dll.backup
2011-03-25 16:48:32 44544 ----a-w- C:\Windows\System32\themeservice.dll.backup
2011-03-25 16:48:31 332288 ----a-w- C:\Windows\System32\uxtheme.dll.backup
2011-03-20 00:05:00 -------- d-----w- C:\Users\Corinne\AppData\Local\Easy CD-DA Extractor
2011-03-20 00:04:50 -------- d-----w- C:\PROGRA~3\Easy CD-DA Extractor
2011-03-20 00:04:47 -------- d-----w- C:\Program Files\Easy CD-DA Extractor 2010
2011-03-19 22:32:53 -------- d-----w- C:\Users\Corinne\AppData\Local\FLVService
2011-03-19 22:32:42 -------- d-----w- C:\Windows\Freecorder
2011-03-19 22:31:12 -------- d-----w- C:\Program Files\iPod
2011-03-19 22:31:07 -------- d-----w- C:\Program Files\iTunes
2011-03-19 22:28:18 -------- d-----w- C:\Program Files (x86)\ConvertHelper
2011-03-19 22:26:42 -------- d-----w- C:\Users\Corinne\dwhelper
2011-03-18 15:17:44 723968 ----a-w- C:\Windows\System32\EncDec.dll
2011-03-18 15:17:43 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2011-03-18 15:17:42 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2011-03-18 15:17:41 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2011-03-18 15:17:40 1118720 ----a-w- C:\Windows\System32\sbe.dll
2011-03-18 15:17:39 259072 ----a-w- C:\Windows\System32\mpg2splt.ax
2011-03-18 15:17:38 850432 ----a-w- C:\Windows\SysWow64\sbe.dll
2011-03-18 15:17:37 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2011-03-18 15:17:33 3138048 ----a-w- C:\Windows\System32\mstscax.dll
2011-03-18 15:17:33 2690560 ----a-w- C:\Windows\SysWow64\mstscax.dll
2011-03-18 15:17:32 1097216 ----a-w- C:\Windows\System32\mstsc.exe
2011-03-18 15:17:32 1034240 ----a-w- C:\Windows\SysWow64\mstsc.exe
2011-03-09 12:37:22 -------- d-----w- C:\Users\Corinne\AppData\Roaming\crawl
2011-03-09 12:35:14 -------- d-----w- C:\Program Files (x86)\Crawl
2011-03-08 00:33:12 -------- d-----w- C:\Users\Corinne\AppData\Local\Evernote
2011-03-08 00:32:01 -------- d-----w- C:\Program Files (x86)\Evernote
2011-03-05 02:29:18 -------- d-----w- C:\Program Files (x86)\iTunes
2011-03-05 02:23:10 -------- d-----w- C:\Program Files\Bonjour
2011-03-05 02:23:10 -------- d-----w- C:\Program Files (x86)\Bonjour
2011-03-03 23:18:11 367104 ----a-w- C:\Windows\System32\wcncsvc.dll
2011-03-03 23:18:04 276992 ----a-w- C:\Windows\SysWow64\wcncsvc.dll
.
==================== Find3M ====================
.
2011-03-29 14:17:49 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-03-25 16:48:33 2851328 ----a-w- C:\Windows\System32\themeui.dll
2011-03-25 16:48:32 44544 ----a-w- C:\Windows\System32\themeservice.dll
2011-03-25 16:48:31 332288 ----a-w- C:\Windows\System32\uxtheme.dll
2011-02-18 22:36:58 51712 ----a-w- C:\Windows\System32\drivers\usbaapl64.sys
2011-02-18 22:36:58 4184352 ----a-w- C:\Windows\System32\usbaaplrc.dll
2011-01-26 06:53:10 982912 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2011-01-26 06:53:10 265088 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2011-01-26 06:31:20 144384 ----a-w- C:\Windows\System32\cdd.dll
2011-01-07 08:07:24 662528 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-01-07 08:07:24 475648 ----a-w- C:\Windows\System32\XpsGdiConverter.dll
2011-01-07 08:06:50 46080 ----a-w- C:\Windows\System32\atmlib.dll
2011-01-07 07:31:10 442880 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-01-07 07:31:10 288256 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2011-01-07 07:27:11 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2011-01-07 05:49:20 366080 ----a-w- C:\Windows\System32\atmfd.dll
2011-01-07 05:33:11 294400 ----a-w- C:\Windows\SysWow64\atmfd.dll
2011-01-05 06:20:30 612352 ----a-w- C:\Windows\System32\vbscript.dll
2011-01-05 05:37:33 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll
2011-01-05 04:00:16 3127808 ----a-w- C:\Windows\System32\win32k.sys
.
============= FINISH: 10:37:54.82 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 12/27/2009 1:33:49 PM
System Uptime: 3/29/2011 8:55:58 AM (2 hours ago)
.
Motherboard: Dell Inc. | | 0U8042
Processor: Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz | Microprocessor | 2101/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 285 GiB total, 81.563 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 0.054 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318}
Description: HID-compliant mouse
Device ID: HID\VID_0A5C&PID_4503&COL01\7&2000BAC2&0&0000
Manufacturer: Microsoft
Name: HID-compliant mouse
PNP Device ID: HID\VID_0A5C&PID_4503&COL01\7&2000BAC2&0&0000
Service: mouhid
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
Adobe Acrobat Connect Add-in
Adobe AIR
Adobe Community Help
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Media Player
Adobe Photoshop Elements 7.0
Adobe Shockwave Player 11.5
Akamai NetSession Interface
Apple Application Support
Apple Software Update
Auslogics Disk Defrag
Bamboo
Barnes & Noble Desktop Reader
CamStudio
Character Builder
ConvertHelper 2.2
Cubis Gold 2
D3DX10
Dell Driver Download Manager
DivX Setup
Dropbox
Dungeon Crawl Stone Soup
Easy CD-DA Extractor 2010
Epson Event Manager
Epson FAX Utility
Epson PC-FAX Driver
EPSON Scan
EpsonNet Print
EpsonNet Setup
Evernote v. 4.2.3
Foxit Reader
Google Apps
Google Chrome
Google Talk Plugin
Google Update Helper
Java Auto Updater
Java(TM) 6 Update 24
Jing
LiveUpdate 3.3 (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Live Add-in 1.5
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Mozaki Blocks Deluxe
Mozilla Firefox 4.0 (x86 en-US)
MSVCRT
Pdf995
Picasa 3
QuickTime
RICOH R5C83x/84x Media Driver Ver.3.53.02
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
SigmaTel Audio
Skype™ 5.0
Update for 2007 Microsoft Office System (KB2284654)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Uplink Demo (remove only)
VC80CRTRedist - 8.0.50727.4053
WebTablet IE Plugin
WebTablet Netscape Plugin
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
XPS2OneNote
Xvid 1.2.1 final uninstall
.
==== Event Viewer Messages From Past Week ========
.
3/29/2011 8:52:50 AM, Error: Service Control Manager [7031] - The Symantec Settings Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
3/29/2011 8:52:50 AM, Error: Service Control Manager [7031] - The Symantec Event Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 200 milliseconds: Restart the service.
3/29/2011 1:29:07 AM, Error: BTHUSB [17] - The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.
3/27/2011 10:45:42 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WTouchService service.
3/26/2011 9:35:14 PM, Error: Service Control Manager [7022] - The Windows Font Cache Service service hung on starting.
3/26/2011 8:22:38 PM, Error: Service Control Manager [7034] - The Amazon Unbox Video Service service terminated unexpectedly. It has done this 1 time(s).
3/26/2011 11:54:53 PM, Error: atapi [11] - The driver detected a controller error on \Device\Ide\IdePort1.
3/25/2011 3:45:23 PM, Error: Service Control Manager [7023] - The WMI Performance Adapter service terminated with the following error: %%-2147467259
.
==== End Of File ===========================
http://www.screencast.com/t/kubSWv5um
I'm also wondering if this might be related to the fact that I have this in my recovery drive:
http://www.screencast.com/t/GfjURZeoeM
When I upgraded to Windows 7 from Vista, did I somehow install into the wrong drive? If I did that, would it mean that a bunch of files that need to be monitored/scanned regularly aren't being monitored/scanned because they're on a different drive?
I'm also running into an issue that may or may not be related to these viruses where Firefox crashes constantly (I have uninstalled it, reinstalled it, and updated to Firefox 4) and also takes FOREVER to open. As in, I click the Firefox icon and wait 5-10 minutes for it to open, and sometimes even then it never does. So, of course, I get all impatient with it and click it 4 or 5 times over the course of that 10 minutes, and when it finally opens it opens 4 or 5 windows.
Thanks in advance for the help; I think I have just enough knowledge to be dangerous, so I'm afraid of screwing things up if I try to fix anything myself.
I followed the 8 steps to the best of my ability, and here are the logs. Let me know if I screwed something up and I'll do it again:
Malwarebytes:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6202
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
3/29/2011 9:08:39 AM
mbam-log-2011-03-29 (09-08-39).txt
Scan type: Quick scan
Objects scanned: 164321
Time elapsed: 6 minute(s), 9 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER:
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-03-29 10:33:47
Windows 6.1.7600
Running: 0oettx48.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002269be3c19
Reg HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application@Sources MSDMine?STacS
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002269be3c19 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\eventlog\Application@Sources MSDMine?STacS
---- EOF - GMER 1.0.15 ----
DDS:
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by Corinne at 10:36:50.63 on Tue 03/29/2011
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_24
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4094.2525 [GMT -5:00]
.
AV: Symantec Endpoint Protection *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Symantec Endpoint Protection *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Program Files\WTouch\WTouchService.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Fingerprint Reader Suite\upeksvr.exe
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\WTouch\WTouchUser.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_295b5b4710f6d77b\AESTSr64.exe
C:\Windows\SysWOW64\svchost.exe -k Akamai
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_295b5b4710f6d77b\STacSV64.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Windows\system32\Pen_Tablet.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray64.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\TechSmith\Jing\Jing.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Users\Corinne\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\system32\Pen_Tablet.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\OEM02Mon.exe
C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\splwow64.exe
c:\program files\windows defender\MpCmdRun.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Corinne\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Jing] C:\Program Files (x86)\TechSmith\Jing\Jing.exe
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
mRun: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
mRun: [ccApp] "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\Corinne\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Corinne\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\Corinne\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\EVERNO~1.LNK - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: DisableCAD = 1 (0x1)
IE: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
LSA: Notification Packages = scecli psqlpwd
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
mRun-x64: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray64.exe
mRun-x64: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
mRun-x64: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
mRun-x64: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
mRun-x64: [PLF1330] C:\Windows\PLF1330.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Corinne\AppData\Roaming\Mozilla\Firefox\Profiles\0m3ep9ul.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en
FF - component: C:\Users\Corinne\AppData\Roaming\Mozilla\Firefox\Profiles\0m3ep9ul.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\FFExternalAlert.dll
FF - component: C:\Users\Corinne\AppData\Roaming\Mozilla\Firefox\Profiles\0m3ep9ul.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCore.dll
FF - component: C:\Users\Corinne\AppData\Roaming\Mozilla\Firefox\Profiles\0m3ep9ul.default\extensions\engine@conduit.com\components\FFExternalAlert.dll
FF - component: C:\Users\Corinne\AppData\Roaming\Mozilla\Firefox\Profiles\0m3ep9ul.default\extensions\engine@conduit.com\components\RadioWMPCore.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60129.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Corinne\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Users\Corinne\AppData\Roaming\Mozilla\Firefox\Profiles\0m3ep9ul.default\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}\plugins\npietab2.dll
FF - plugin: C:\Users\Corinne\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Corinne\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-10-12 55856]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-9-16 169312]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_295b5b4710f6d77b\AESTSr64.exe [2009-12-28 86016]
R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 27136]
R2 Symantec AntiVirus;Symantec Endpoint Protection;C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe [2010-12-25 1839776]
R2 TabletServicePen;TabletServicePen;C:\Windows\System32\Pen_Tablet.exe [2010-10-12 5556520]
R2 WTouchService;WTouch Service;C:\Program Files\WTouch\WTouchService.exe [2010-10-12 127784]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-10-10 132656]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-13 17920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-4-29 136176]
S3 phaudlwr;Philips Audio Filter;C:\Windows\System32\drivers\phaudlwr.sys [2008-5-7 113664]
S3 SPC1330;USB2.0 PC Camera (SPC1330);C:\Windows\System32\drivers\spc1330.sys [2008-8-28 3297920]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-2-18 51712]
S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\System32\drivers\wacmoumonitor.sys [2010-10-12 18216]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-3-26 1255736]
.
=============== Created Last 30 ================
.
2011-03-29 14:15:24 521448 ----a-w- C:\Windows\System32\deployJava1.dll
2011-03-27 18:29:43 -------- d-----w- C:\Windows\pss
2011-03-27 03:12:23 -------- d-----w- C:\Tools
2011-03-27 03:12:22 -------- d-----w- C:\sources
2011-03-27 02:39:01 -------- d-----w- C:\Users\Corinne\AppData\Roaming\Auslogics
2011-03-27 02:38:36 -------- d-----w- C:\Program Files (x86)\Auslogics
2011-03-27 02:13:02 -------- d-----w- C:\Windows\en
2011-03-27 02:10:22 69464 ----a-w- C:\Windows\SysWow64\XAPOFX1_3.dll
2011-03-27 02:10:22 515416 ----a-w- C:\Windows\SysWow64\XAudio2_5.dll
2011-03-27 02:10:19 523088 ----a-w- C:\Windows\System32\d3dx10_42.dll
2011-03-27 02:10:19 453456 ----a-w- C:\Windows\SysWow64\d3dx10_42.dll
2011-03-27 02:09:58 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\116f481f1cbec2407\DSETUP.dll
2011-03-27 02:09:58 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\116f481f1cbec2407\DXSETUP.exe
2011-03-27 02:09:58 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\116f481f1cbec2407\dsetup32.dll
2011-03-27 02:09:54 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fff8b041cbec2406\DSETUP.dll
2011-03-27 02:09:54 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fff8b041cbec2406\DXSETUP.exe
2011-03-27 02:09:54 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fff8b041cbec2406\dsetup32.dll
2011-03-27 02:09:36 -------- d-----w- C:\Users\Corinne\AppData\Local\Windows Live
2011-03-25 17:00:22 453456 ----a-w- C:\Windows\SysWow64\d3dx10_41.dll
2011-03-25 17:00:22 4178264 ----a-w- C:\Windows\SysWow64\D3DX9_41.dll
2011-03-25 17:00:22 1846632 ----a-w- C:\Windows\SysWow64\D3DCompiler_41.dll
2011-03-25 17:00:21 517448 ----a-w- C:\Windows\SysWow64\XAudio2_4.dll
2011-03-25 17:00:21 22360 ----a-w- C:\Windows\SysWow64\X3DAudio1_6.dll
2011-03-25 17:00:17 -------- d-----w- C:\Program Files (x86)\Lightworks
2011-03-25 16:48:33 2851328 ----a-w- C:\Windows\System32\themeui.dll.backup
2011-03-25 16:48:32 44544 ----a-w- C:\Windows\System32\themeservice.dll.backup
2011-03-25 16:48:31 332288 ----a-w- C:\Windows\System32\uxtheme.dll.backup
2011-03-20 00:05:00 -------- d-----w- C:\Users\Corinne\AppData\Local\Easy CD-DA Extractor
2011-03-20 00:04:50 -------- d-----w- C:\PROGRA~3\Easy CD-DA Extractor
2011-03-20 00:04:47 -------- d-----w- C:\Program Files\Easy CD-DA Extractor 2010
2011-03-19 22:32:53 -------- d-----w- C:\Users\Corinne\AppData\Local\FLVService
2011-03-19 22:32:42 -------- d-----w- C:\Windows\Freecorder
2011-03-19 22:31:12 -------- d-----w- C:\Program Files\iPod
2011-03-19 22:31:07 -------- d-----w- C:\Program Files\iTunes
2011-03-19 22:28:18 -------- d-----w- C:\Program Files (x86)\ConvertHelper
2011-03-19 22:26:42 -------- d-----w- C:\Users\Corinne\dwhelper
2011-03-18 15:17:44 723968 ----a-w- C:\Windows\System32\EncDec.dll
2011-03-18 15:17:43 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2011-03-18 15:17:42 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2011-03-18 15:17:41 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2011-03-18 15:17:40 1118720 ----a-w- C:\Windows\System32\sbe.dll
2011-03-18 15:17:39 259072 ----a-w- C:\Windows\System32\mpg2splt.ax
2011-03-18 15:17:38 850432 ----a-w- C:\Windows\SysWow64\sbe.dll
2011-03-18 15:17:37 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2011-03-18 15:17:33 3138048 ----a-w- C:\Windows\System32\mstscax.dll
2011-03-18 15:17:33 2690560 ----a-w- C:\Windows\SysWow64\mstscax.dll
2011-03-18 15:17:32 1097216 ----a-w- C:\Windows\System32\mstsc.exe
2011-03-18 15:17:32 1034240 ----a-w- C:\Windows\SysWow64\mstsc.exe
2011-03-09 12:37:22 -------- d-----w- C:\Users\Corinne\AppData\Roaming\crawl
2011-03-09 12:35:14 -------- d-----w- C:\Program Files (x86)\Crawl
2011-03-08 00:33:12 -------- d-----w- C:\Users\Corinne\AppData\Local\Evernote
2011-03-08 00:32:01 -------- d-----w- C:\Program Files (x86)\Evernote
2011-03-05 02:29:18 -------- d-----w- C:\Program Files (x86)\iTunes
2011-03-05 02:23:10 -------- d-----w- C:\Program Files\Bonjour
2011-03-05 02:23:10 -------- d-----w- C:\Program Files (x86)\Bonjour
2011-03-03 23:18:11 367104 ----a-w- C:\Windows\System32\wcncsvc.dll
2011-03-03 23:18:04 276992 ----a-w- C:\Windows\SysWow64\wcncsvc.dll
.
==================== Find3M ====================
.
2011-03-29 14:17:49 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-03-25 16:48:33 2851328 ----a-w- C:\Windows\System32\themeui.dll
2011-03-25 16:48:32 44544 ----a-w- C:\Windows\System32\themeservice.dll
2011-03-25 16:48:31 332288 ----a-w- C:\Windows\System32\uxtheme.dll
2011-02-18 22:36:58 51712 ----a-w- C:\Windows\System32\drivers\usbaapl64.sys
2011-02-18 22:36:58 4184352 ----a-w- C:\Windows\System32\usbaaplrc.dll
2011-01-26 06:53:10 982912 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2011-01-26 06:53:10 265088 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2011-01-26 06:31:20 144384 ----a-w- C:\Windows\System32\cdd.dll
2011-01-07 08:07:24 662528 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-01-07 08:07:24 475648 ----a-w- C:\Windows\System32\XpsGdiConverter.dll
2011-01-07 08:06:50 46080 ----a-w- C:\Windows\System32\atmlib.dll
2011-01-07 07:31:10 442880 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-01-07 07:31:10 288256 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2011-01-07 07:27:11 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2011-01-07 05:49:20 366080 ----a-w- C:\Windows\System32\atmfd.dll
2011-01-07 05:33:11 294400 ----a-w- C:\Windows\SysWow64\atmfd.dll
2011-01-05 06:20:30 612352 ----a-w- C:\Windows\System32\vbscript.dll
2011-01-05 05:37:33 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll
2011-01-05 04:00:16 3127808 ----a-w- C:\Windows\System32\win32k.sys
.
============= FINISH: 10:37:54.82 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 12/27/2009 1:33:49 PM
System Uptime: 3/29/2011 8:55:58 AM (2 hours ago)
.
Motherboard: Dell Inc. | | 0U8042
Processor: Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz | Microprocessor | 2101/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 285 GiB total, 81.563 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 0.054 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318}
Description: HID-compliant mouse
Device ID: HID\VID_0A5C&PID_4503&COL01\7&2000BAC2&0&0000
Manufacturer: Microsoft
Name: HID-compliant mouse
PNP Device ID: HID\VID_0A5C&PID_4503&COL01\7&2000BAC2&0&0000
Service: mouhid
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
Adobe Acrobat Connect Add-in
Adobe AIR
Adobe Community Help
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Media Player
Adobe Photoshop Elements 7.0
Adobe Shockwave Player 11.5
Akamai NetSession Interface
Apple Application Support
Apple Software Update
Auslogics Disk Defrag
Bamboo
Barnes & Noble Desktop Reader
CamStudio
Character Builder
ConvertHelper 2.2
Cubis Gold 2
D3DX10
Dell Driver Download Manager
DivX Setup
Dropbox
Dungeon Crawl Stone Soup
Easy CD-DA Extractor 2010
Epson Event Manager
Epson FAX Utility
Epson PC-FAX Driver
EPSON Scan
EpsonNet Print
EpsonNet Setup
Evernote v. 4.2.3
Foxit Reader
Google Apps
Google Chrome
Google Talk Plugin
Google Update Helper
Java Auto Updater
Java(TM) 6 Update 24
Jing
LiveUpdate 3.3 (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Live Add-in 1.5
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Mozaki Blocks Deluxe
Mozilla Firefox 4.0 (x86 en-US)
MSVCRT
Pdf995
Picasa 3
QuickTime
RICOH R5C83x/84x Media Driver Ver.3.53.02
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
SigmaTel Audio
Skype™ 5.0
Update for 2007 Microsoft Office System (KB2284654)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Uplink Demo (remove only)
VC80CRTRedist - 8.0.50727.4053
WebTablet IE Plugin
WebTablet Netscape Plugin
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
XPS2OneNote
Xvid 1.2.1 final uninstall
.
==== Event Viewer Messages From Past Week ========
.
3/29/2011 8:52:50 AM, Error: Service Control Manager [7031] - The Symantec Settings Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
3/29/2011 8:52:50 AM, Error: Service Control Manager [7031] - The Symantec Event Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 200 milliseconds: Restart the service.
3/29/2011 1:29:07 AM, Error: BTHUSB [17] - The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.
3/27/2011 10:45:42 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WTouchService service.
3/26/2011 9:35:14 PM, Error: Service Control Manager [7022] - The Windows Font Cache Service service hung on starting.
3/26/2011 8:22:38 PM, Error: Service Control Manager [7034] - The Amazon Unbox Video Service service terminated unexpectedly. It has done this 1 time(s).
3/26/2011 11:54:53 PM, Error: atapi [11] - The driver detected a controller error on \Device\Ide\IdePort1.
3/25/2011 3:45:23 PM, Error: Service Control Manager [7023] - The WMI Performance Adapter service terminated with the following error: %%-2147467259
.
==== End Of File ===========================