I was hacked by a ruthless pack of cyber-thugs - social networking gamers on Facebook. They even 'autographed' NT user dat files that I found hidden in temp directories. Since then, I've rolled my system back to the factory state 3 times. But, whatever they've done has changed the way my operating system installs. There are remote connections I can't get rid of, I'm locked out of system files, mysterious programs loading quietly in the background, and I can't seem to stop it. After this last factory reset, which included a complete format of all but recovery partition, while physically disconnected the internet... these programs are still installing themselves before the set up process is even complete, and I don't have 'permission' to get rid of them.

This is just one personal computer in my home - should not be connected to any networks, homegroups, workgroups. There should be no shared files. Before the last installation - my desktop was shared, my docss and settings were shared... and I couldn't unshare any of it. Not sure how to fix this. Any help would be greatly appreciated. The Erunt will only run once, but if I try to run it again... it produces errors, saying I'm not authorized. Here's my latest DDS log:

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385
Run by Leslie at 3:01:04 on 2011-09-05
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3839.2734 [GMT -6:00]
.
AV: Norton Internet Security *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
FW: Norton Internet Security *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe
C:\Program Files (x86)\Norton Internet Security\Engine\16.7.0.30\ccSvcHst.exe
C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS\A5E82D02\16.7.0.30\InstStub.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&m=et1331g&r=17360911g406p04e5v165r45n1s29p
uDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&m=et1331g&r=17360911g406p04e5v165r45n1s29p
mDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&m=et1331g&r=17360911g406p04e5v165r45n1s29p
mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&m=et1331g&r=17360911g406p04e5v165r45n1s29p
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.7.0.30\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\16.7.0.30\IPSBHO.DLL
BHO: Partner BHO Class: {83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} - C:\ProgramData\Partner\Partner.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\16.7.0.30\coIEPlg.dll
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
TCP: DhcpNameServer = 66.129.55.2 72.19.160.2 72.19.128.53
TCP: Interfaces\{189A7EA4-E3E5-4BEB-805A-E0A751964664} : DhcpNameServer = 66.129.55.2 72.19.160.2 72.19.128.53
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.7.0.30\CoIEPlg.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-X64: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.7.0.30\coIEPlg.dll
BHO-X64: Symantec NCO BHO - No File
BHO-X64: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.7.0.30\IPSBHO.DLL
BHO-X64: Symantec Intrusion Prevention - No File
BHO-X64: Partner BHO Class: {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll
BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
BHO-X64: Google Dictionary Compression sdch: {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
BHO-X64: Google Dictionary Compression sdch - No File
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.7.0.30\coIEPlg.dll
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
.
============= SERVICES / DRIVERS ===============
.
R2 Greg_Service;GRegService;C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe [2009-8-28 1150496]
R2 Norton Internet Security;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\16.7.0.30\ccSvcHst.exe [2009-11-24 117640]
R2 Updater Service;Updater Service;C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [2009-11-24 240160]
S3 Partner Service;Partner Service;C:\ProgramData\Partner\Partner.exe [2009-11-24 332272]
.
=============== Created Last 30 ================
.
2011-09-05 09:59:51 -------- d-----w- C:\Windows\NAPP_Dism_Log
2011-09-05 08:48:18 -------- d-----w- C:\ERUNT
2011-09-05 08:42:44 8862544 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{77A5DAAC-8DC6-49F9-B9B8-C4A270EF2173}\mpengine.dll
2011-09-05 08:42:43 270720 ------w- C:\Windows\System32\MpSigStub.exe
2011-09-05 08:29:31 -------- d-----w- C:\Users\Leslie\AppData\Local\Google
2011-09-05 08:28:52 -------- d-----w- C:\Users\Leslie\Tracing
2011-09-05 08:28:24 4398360 ----a-w- C:\Windows\System32\d3dx9_32.dll
2011-09-05 08:28:24 3426072 ----a-w- C:\Windows\SysWow64\d3dx9_32.dll
2011-09-05 08:28:02 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-09-05 08:27:16 -------- d-----w- C:\Program Files (x86)\Microsoft
2011-09-05 08:26:58 -------- d-----w- C:\Program Files (x86)\Windows Live SkyDrive
2011-09-05 08:26:02 74520 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\72d60be01cc6ba5\DSETUP.dll
2011-09-05 08:26:02 484632 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\72d60be01cc6ba5\DXSETUP.exe
2011-09-05 08:26:02 1670936 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\72d60be01cc6ba5\dsetup32.dll
2011-09-05 08:25:30 141402440 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\wlcCE65.tmp
2011-09-05 08:25:20 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2011-09-05 08:22:05 2868736 ----a-w- C:\Windows\explorer.exe
2011-09-05 08:22:05 2613248 ----a-w- C:\Windows\SysWow64\explorer.exe
2011-09-05 08:20:31 92160 ----a-w- C:\Program Files\Internet Explorer\iecompat.dll
2011-09-05 08:20:31 92160 ----a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll
2011-09-05 08:19:41 311808 ----a-w- C:\Windows\System32\msv1_0.dll
2011-09-05 08:19:41 257024 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2011-09-05 08:19:05 46592 ----a-w- C:\Windows\System32\msasn1.dll
2011-09-05 08:19:05 34816 ----a-w- C:\Windows\SysWow64\msasn1.dll
2011-09-05 08:16:11 1320960 ----a-w- C:\Windows\SysWow64\CertEnroll.dll
2011-09-05 08:16:10 71168 ----a-w- C:\Windows\SysWow64\fontsub.dll
2011-09-05 08:16:10 366080 ----a-w- C:\Windows\System32\atmfd.dll
2011-09-05 08:16:10 293888 ----a-w- C:\Windows\SysWow64\atmfd.dll
2011-09-05 08:16:10 1975296 ----a-w- C:\Windows\System32\CertEnroll.dll
2011-09-05 08:16:10 108544 ----a-w- C:\Windows\SysWow64\t2embed.dll
2011-09-05 08:16:09 982600 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2011-09-05 08:16:09 148480 ----a-w- C:\Windows\System32\t2embed.dll
2011-09-05 08:16:09 100864 ----a-w- C:\Windows\System32\fontsub.dll
2011-09-05 08:16:08 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2011-09-05 08:16:07 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2011-09-05 08:15:53 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2011-09-05 08:15:53 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2011-09-05 08:15:19 -------- d---a-w- C:\book
2011-09-05 08:14:51 -------- d-----w- C:\Users\Leslie\AppData\Local\VirtualStore
2011-09-05 08:13:04 -------- d-----w- C:\ProgramData\OEM_E471269A730D
2011-09-05 08:13:01 -------- d-----w- C:\Program Files (x86)\OEM
.
==================== Find3M ====================
.
2011-09-05 09:08:49 6 ----a-w- C:\Windows\System32\PLD_Framework.cmd
.
============= FINISH: 3:01:25.84 ===============