PDA

View Full Version : Hijacked e-mail account sending out spam



eyedr90
2010-08-21, 03:48
Hi,
Don't know where else to turn and thought you guys could help. My e-mail contacts keep getting spam from "me" and after running several virus and other scans and getting a brand new computer it is still happening. If you can't help, please direct me to some other help. Thanks a lot.



DDS (Ver_10-03-17.01) - NTFSX64
Run by Bigler at 19:37:15.99 on Fri 08/20/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.6136.4360 [GMT -6:00]

SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\atieclxx.exe
C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0369.0\mswinext.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\DllHost.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\SysWOW64\WinMsgBalloonServer.exe
C:\Windows\SysWOW64\WinMsgBalloonClient.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Bigler\Desktop\dds.scr
C:\Windows\system32\conhost.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://my.msn.com
mLocal Page = c:\windows\syswow64\blank.htm
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files (x86)\norton internet security\engine\17.7.0.12\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files (x86)\norton internet security\engine\17.7.0.12\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files (x86)\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~2\micros~1\office14\URLREDIR.DLL
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files (x86)\msn toolbar\platform\4.0.0369.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files (x86)\msn toolbar\platform\4.0.0369.0\npwinext.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files (x86)\norton internet security\engine\17.7.0.12\coIEPlg.dll
uRun: [Google Update] "c:\users\bigler\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Steam] "c:\program files (x86)\steam\Steam.exe" -silent
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [StartCCC] "c:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [HP Software Update] c:\program files (x86)\hp\hp software update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [NortonOnlineBackupReminder] "c:\program files (x86)\symantec\norton online backup\activation\NOBuActivation.exe" UNATTENDED
mRun: [MSN Toolbar] "c:\program files (x86)\msn toolbar\platform\4.0.0369.0\mswinext.exe"
mRun: [Microsoft Default Manager] "c:\program files (x86)\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [SunJavaUpdateSched] "c:\program files (x86)\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\pictur~1.lnk - c:\program files (x86)\picturemover\bin\PictureMover.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files (x86)\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files (x86)\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\common files\microsoft shared\office14\MSOXMLMF.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
mRun-x64: [hpsysdrv] c:\program files (x86)\hewlett-packard\hp odometer\hpsysdrv.exe
mRun-x64: [SmartMenu] c:\program files\hewlett-packard\hp mediasmart\SmartMenu.exe /background

============= SERVICES / DRIVERS ===============

R0 ahcix64s;ahcix64s;c:\windows\system32\drivers\ahcix64s.sys [2010-8-13 230456]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nisx64\1107000.00c\symds64.sys [2010-8-19 433200]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nisx64\1107000.00c\symefa64.sys [2010-8-19 221232]
R1 BHDrvx64;BHDrvx64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\bashdefs\20100810.004\BHDrvx64.sys [2010-8-10 945200]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nisx64\1107000.00c\cchpx64.sys [2010-8-19 615040]
R1 IDSVia64;IDSVia64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\ipsdefs\20100818.002\IDSviA64.sys [2010-8-20 463408]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv64.sys [2010-2-17 14920]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\saskutil64.sys [2010-2-17 12360]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nisx64\1107000.00c\ironx64.sys [2010-8-19 150064]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\nisx64\1107000.00c\symtdiv.sys [2010-8-19 451120]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore64.exe [2010-6-29 128752]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-8-13 202752]
R2 AMD_RAIDXpert;AMD RAIDXpert;c:\program files (x86)\amd\raidxpert\bin\RAIDXpertService.exe [2009-12-15 122880]
R2 CinemaNow Service;CinemaNow Service;c:\program files (x86)\cinemanow\cinemanow media manager\CinemaNowSvc.exe [2010-2-26 127984]
R2 NIS;Norton Internet Security;c:\program files (x86)\norton internet security\engine\17.7.0.12\ccsvchst.exe [2010-8-19 126392]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atipmdag.sys [2010-8-13 6327296]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-8-13 185344]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-8-19 132656]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt64win7.sys [2010-8-13 346144]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2010-8-13 39480]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0;PCDSRVC{F36B3A4C-F95654BD-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms [2010-1-19 23536]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-8-20 1255736]

=============== Created Last 30 ================

2010-08-21 00:53:28 0 d-----w- c:\program files\Microsoft Office
2010-08-21 00:53:18 0 d-----w- c:\program files (x86)\Microsoft Analysis Services
2010-08-21 00:52:28 0 d-----w- c:\programdata\Microsoft Help
2010-08-20 22:08:28 0 d--h--w- c:\programdata\{0E8E33D8-193A-414A-A909-0F101A142D26}
2010-08-20 21:59:27 0 d-----w- c:\program files (x86)\Stardock Games
2010-08-20 21:37:21 0 d-----w- c:\users\bigler\appdata\roaming\WildTangent
2010-08-20 20:41:49 0 d-----w- c:\windows\syswow64\Wat
2010-08-20 20:41:49 0 d-----w- c:\windows\system32\Wat
2010-08-20 20:35:54 0 d-----w- c:\program files (x86)\MSXML 4.0
2010-08-20 20:35:20 99176 ----a-w- c:\windows\syswow64\PresentationHostProxy.dll
2010-08-20 20:35:20 49472 ----a-w- c:\windows\syswow64\netfxperf.dll
2010-08-20 20:35:20 48960 ----a-w- c:\windows\system32\netfxperf.dll
2010-08-20 20:35:20 444752 ----a-w- c:\windows\system32\mscoree.dll
2010-08-20 20:35:20 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2010-08-20 20:35:20 297808 ----a-w- c:\windows\syswow64\mscoree.dll
2010-08-20 20:35:20 295264 ----a-w- c:\windows\syswow64\PresentationHost.exe
2010-08-20 20:35:20 1942856 ----a-w- c:\windows\system32\dfshim.dll
2010-08-20 20:35:20 1130824 ----a-w- c:\windows\syswow64\dfshim.dll
2010-08-20 20:35:20 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-08-20 19:59:30 0 d-----w- c:\program files (x86)\LucasArts
2010-08-20 19:58:46 0 d-s---w- c:\program files (x86)\Xfire
2010-08-20 19:58:46 0 d-----w- c:\users\bigler\appdata\roaming\Xfire
2010-08-20 16:49:41 74576 ----a-w- c:\windows\system32\XAPOFX1_2.dll
2010-08-20 16:49:41 70992 ----a-w- c:\windows\syswow64\XAPOFX1_2.dll
2010-08-20 16:49:41 518480 ----a-w- c:\windows\system32\XAudio2_3.dll
2010-08-20 16:49:41 514384 ----a-w- c:\windows\syswow64\XAudio2_3.dll
2010-08-20 16:49:41 235856 ----a-w- c:\windows\syswow64\xactengine3_3.dll
2010-08-20 16:49:41 175440 ----a-w- c:\windows\system32\xactengine3_3.dll
2010-08-20 16:49:40 25936 ----a-w- c:\windows\system32\X3DAudio1_5.dll
2010-08-20 16:49:40 23376 ----a-w- c:\windows\syswow64\X3DAudio1_5.dll
2010-08-20 15:17:06 0 d-----w- c:\windows\syswow64\AGEIA
2010-08-20 15:17:00 0 d-----w- c:\program files (x86)\common files\Wise Installation Wizard
2010-08-20 15:15:59 2337488 ----a-w- c:\windows\syswow64\d3dx9_25.dll
2010-08-20 15:15:59 2222800 ----a-w- c:\windows\syswow64\d3dx9_24.dll
2010-08-20 09:11:03 84992 ----a-w- c:\windows\system32\asycfilt.dll
2010-08-20 09:11:03 67584 ----a-w- c:\windows\syswow64\asycfilt.dll
2010-08-20 09:11:00 463360 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-20 09:11:00 404992 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-08-20 09:11:00 162304 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-08-20 09:09:59 389632 ----a-w- c:\windows\system32\winlogon.exe
2010-08-20 09:08:57 46080 ----a-w- c:\windows\system32\atmlib.dll
2010-08-20 09:08:57 366080 ----a-w- c:\windows\system32\atmfd.dll
2010-08-20 09:08:57 34304 ----a-w- c:\windows\syswow64\atmlib.dll
2010-08-20 09:08:57 293888 ----a-w- c:\windows\syswow64\atmfd.dll
2010-08-20 09:08:56 2048 ----a-w- c:\windows\syswow64\tzres.dll
2010-08-20 09:08:56 2048 ----a-w- c:\windows\system32\tzres.dll
2010-08-20 04:30:46 0 d-----w- c:\users\bigler\appdata\roaming\SUPERAntiSpyware.com
2010-08-20 04:30:46 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2010-08-20 04:30:43 0 d-----w- c:\programdata\!SASCORE
2010-08-20 04:30:42 0 d-----w- c:\program files\SUPERAntiSpyware
2010-08-20 04:09:32 0 d-----w- c:\programdata\Adobe
2010-08-20 03:58:14 0 d-----w- c:\program files (x86)\common files\Symantec Shared
2010-08-20 02:58:50 0 d-----w- c:\program files (x86)\SystemRequirementsLab
2010-08-20 02:53:14 0 d-----w- c:\programdata\Sun
2010-08-20 02:52:29 423656 ----a-w- c:\windows\syswow64\deployJava1.dll
2010-08-20 02:52:29 153376 ----a-w- c:\windows\syswow64\javaws.exe
2010-08-20 02:52:29 145184 ----a-w- c:\windows\syswow64\javaw.exe
2010-08-20 02:52:29 145184 ----a-w- c:\windows\syswow64\java.exe
2010-08-20 02:47:47 0 d-----w- c:\program files (x86)\common files\Steam
2010-08-20 02:47:46 0 d-----w- c:\program files (x86)\Steam
2010-08-20 02:30:27 854 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.INF
2010-08-20 02:30:27 7440 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.CAT
2010-08-20 02:30:27 173104 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2010-08-20 02:30:27 0 d-----w- c:\program files\Symantec
2010-08-20 02:30:27 0 d-----w- c:\program files\common files\Symantec Shared
2010-08-20 02:29:11 0 d-----w- c:\users\bigler\appdata\roaming\PictureMover
2010-08-20 02:28:54 220672 ----a-w- c:\windows\system32\wintrust.dll
2010-08-20 02:28:54 172032 ----a-w- c:\windows\syswow64\wintrust.dll
2010-08-20 02:28:53 139264 ----a-w- c:\windows\system32\cabview.dll
2010-08-20 02:28:53 132608 ----a-w- c:\windows\syswow64\cabview.dll
2010-08-14 05:41:07 0 --sha-r- C:\OS
2010-08-14 04:59:23 51712 ----a-w- c:\windows\system32\drivers\usbehci.sys
2010-08-14 04:59:23 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2010-08-14 04:58:31 311808 ----a-w- c:\windows\system32\msv1_0.dll
2010-08-14 04:58:31 257024 ----a-w- c:\windows\syswow64\msv1_0.dll
2010-08-14 04:58:14 960512 ----a-w- c:\windows\system32\CPFilters.dll
2010-08-14 04:58:14 641536 ----a-w- c:\windows\syswow64\CPFilters.dll
2010-08-14 04:58:05 46592 ----a-w- c:\windows\system32\msasn1.dll
2010-08-14 04:58:05 34816 ----a-w- c:\windows\syswow64\msasn1.dll
2010-08-14 04:57:40 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2010-08-14 04:57:40 12625408 ----a-w- c:\windows\syswow64\wmploc.DLL
2010-08-14 04:57:40 11406336 ----a-w- c:\windows\syswow64\wmp.dll
2010-08-14 04:57:39 982600 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2010-08-14 04:57:39 1975296 ----a-w- c:\windows\system32\CertEnroll.dll
2010-08-14 04:57:39 1320960 ----a-w- c:\windows\syswow64\CertEnroll.dll
2010-08-14 04:56:50 70656 ----a-w- c:\windows\syswow64\fontsub.dll
2010-08-14 04:56:50 148480 ----a-w- c:\windows\system32\t2embed.dll
2010-08-14 04:56:50 108544 ----a-w- c:\windows\syswow64\t2embed.dll
2010-08-14 04:56:50 100864 ----a-w- c:\windows\system32\fontsub.dll
2010-08-14 04:48:56 16440 ----a-w- c:\windows\system32\drivers\AtiPcie64.sys
2010-08-14 04:48:55 230456 ----a-w- c:\windows\system32\drivers\ahcix64s.sys
2010-08-14 04:48:54 74272 ----a-w- c:\windows\system32\RtNicProp64.dll
2010-08-14 04:48:54 346144 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2010-08-14 04:48:54 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2010-08-14 04:39:26 0 d-sh--w- C:\$RECYCLE.BIN
2010-08-14 04:33:48 0 d-----w- c:\windows\system32\drivers\NISx64
2010-08-14 04:33:46 0 d-----w- c:\programdata\Norton
2010-08-14 04:33:46 0 d-----w- c:\program files (x86)\Norton Internet Security
2010-08-14 04:33:33 0 d-----w- c:\programdata\NortonInstaller
2010-08-14 04:33:33 0 d-----w- c:\program files (x86)\NortonInstaller
2010-08-14 04:33:07 4398360 ----a-w- c:\windows\system32\d3dx9_32.dll
2010-08-14 04:33:07 3426072 ----a-w- c:\windows\syswow64\d3dx9_32.dll
2010-08-14 04:33:05 20 ----a-w- c:\windows\àóÒ
2010-08-14 04:33:05 0 d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2010-08-14 04:32:22 0 d-----w- c:\program files (x86)\Windows Live SkyDrive
2010-08-14 04:31:59 0 d-----w- c:\windows\PCHEALTH
2010-08-14 04:31:35 0 d-----w- c:\program files (x86)\common files\Windows Live
2010-08-14 04:31:20 0 d-----w- c:\program files (x86)\Microsoft
2010-08-14 04:31:19 0 d-----w- c:\program files (x86)\MSN Toolbar
2010-08-14 04:31:12 0 d-----w- c:\program files (x86)\MSN Toolbar Installer
2010-08-14 04:30:43 0 d-----w- c:\program files\PlayReady
2010-08-14 04:25:24 0 d---a-w- c:\program files (x86)\common files\LS Getting Started
2010-08-14 04:22:02 0 d-----w- c:\programdata\WildTangent
2010-08-14 04:22:02 0 d-----w- c:\program files (x86)\HP Games
2010-08-14 04:21:55 0 d-----w- c:\programdata\PictureMover
2010-08-14 04:21:55 0 d-----w- c:\program files (x86)\PictureMover
2010-08-14 04:21:51 0 d-----w- c:\programdata\Symantec
2010-08-14 04:21:51 0 d-----w- c:\program files (x86)\Symantec
2010-08-14 04:21:48 0 d-----r- c:\program files (x86)\Online Services
2010-08-14 04:17:37 0 d-----w- c:\programdata\Uninstall
2010-08-14 04:17:33 0 d-----w- c:\programdata\CinemaNow
2010-08-14 04:17:32 0 d-----w- c:\program files (x86)\CinemaNow
2010-08-14 04:17:30 0 d-----w- c:\program files (x86)\Microsoft WSE
2010-08-14 04:17:28 0 d-----w- c:\programdata\Sonic
2010-08-14 04:17:18 0 d-----w- c:\programdata\Macrovision
2010-08-14 04:16:45 0 d-----w- c:\programdata\CyberLink
2010-08-14 04:11:37 253952 ----a-w- c:\windows\syswow64\cPC_DMIRD.dll
2010-08-14 04:11:32 0 d-----w- c:\program files (x86)\Hp
2010-08-14 04:11:00 0 d-----w- c:\programdata\Temp
2010-08-14 04:10:56 0 d-----w- c:\programdata\PC-Doctor for Windows
2010-08-14 04:10:33 0 d-----w- c:\program files\PC-Doctor for Windows
2010-08-14 04:09:53 0 d-----w- c:\windows\Downloaded Installations
2010-08-14 04:07:47 64000 ------w- c:\windows\syswow64\agrsmdel.exe
2010-08-14 04:07:47 27648 ------w- c:\windows\syswow64\agrsco64.dll
2010-08-14 04:07:46 0 d-----w- c:\windows\Options
2010-08-14 04:07:40 0 d-----w- c:\programdata\ATI
2010-08-14 04:07:12 0 d-----w- c:\program files\ATI
2010-08-14 04:07:12 0 d-----w- c:\program files (x86)\ATI Technologies
2010-08-14 04:06:54 0 d-----w- c:\program files\DIFX
2010-08-14 04:06:53 39480 ----a-w- c:\windows\system32\drivers\usbfilter.sys
2010-08-14 04:06:53 0 d-----w- c:\program files (x86)\AMD
2010-08-14 04:06:16 0 d-----w- c:\program files (x86)\Realtek
2010-08-14 04:06:15 1247776 ----a-w- c:\windows\RtlExUpd.dll
2010-08-14 04:06:15 0 d--h--w- c:\program files (x86)\Temp
2010-08-14 04:05:47 0 d-----w- c:\programdata\Hewlett-Packard
2010-08-14 04:05:20 0 d-----w- c:\programdata\{657095DF-DBDB-4B17-8245-B38845C97069}
2010-08-14 04:05:01 0 d-----w- c:\program files\hp
2010-08-14 04:04:59 0 d-----w- c:\windows\syswow64\Macromed
2010-08-14 04:04:53 0 d-----w- c:\program files\Hewlett-Packard
2010-08-14 04:04:32 0 d-sh--w- c:\windows\Installer
2010-08-14 04:01:57 0 d-----w- c:\windows\syswow64\RTCOM
2010-08-14 04:01:57 0 d-----w- c:\program files\Realtek
2010-08-14 04:01:52 0 ----a-w- c:\windows\ativpsrm.bin
2010-08-14 04:01:34 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-08-06 16:35:28 0 d-sha-r- C:\hp

==================== Find3M ====================

2010-08-20 02:27:53 0 --sha-r- c:\windows\system32\drivers\103C_HP_53316J G D_HPE-300z_Y53316J G D_0U_Q2MD032_E2MD0320H6P DPS_4A_I2A92_SFOXCONN_V1.01_6.05_T100702_WU3-0_L409_M6136_J750_7AMD_8F43_92.80_#100819_N10EC8168_(WS387AV#ABA)_X_CD3_Z_2_G100268D9.MRK
2010-07-29 06:30:34 82944 ----a-w- c:\windows\syswow64\iccvid.dll
2010-07-27 14:03:24 12867584 ----a-w- c:\windows\syswow64\shell32.dll
2010-06-30 07:13:46 1192960 ----a-w- c:\windows\system32\wininet.dll
2010-06-30 06:25:31 978432 ----a-w- c:\windows\syswow64\wininet.dll
2010-06-30 06:25:18 1226240 ----a-w- c:\windows\syswow64\urlmon.dll
2010-06-30 06:22:45 606208 ----a-w- c:\windows\syswow64\mstime.dll
2010-06-30 06:22:34 5971456 ----a-w- c:\windows\syswow64\mshtml.dll
2010-06-30 06:22:33 64512 ----a-w- c:\windows\syswow64\msfeedsbs.dll
2010-06-30 06:21:57 48128 ----a-w- c:\windows\syswow64\jsproxy.dll
2010-06-30 06:21:47 185856 ----a-w- c:\windows\syswow64\iepeers.dll
2010-06-30 06:21:47 176640 ----a-w- c:\windows\syswow64\ieui.dll
2010-06-30 06:21:46 10985472 ----a-w- c:\windows\syswow64\ieframe.dll
2010-06-30 06:21:44 381440 ----a-w- c:\windows\syswow64\iedkcs32.dll
2010-06-30 06:19:16 12800 ----a-w- c:\windows\syswow64\msfeedssync.exe
2010-06-19 07:05:01 5507968 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-06-19 06:53:18 52224 ----a-w- c:\windows\system32\rtutils.dll
2010-06-19 06:33:29 3955080 ----a-w- c:\windows\syswow64\ntkrnlpa.exe
2010-06-19 06:33:29 3899784 ----a-w- c:\windows\syswow64\ntoskrnl.exe
2010-06-19 06:23:50 37376 ----a-w- c:\windows\syswow64\rtutils.dll
2010-06-19 04:32:34 3122688 ----a-w- c:\windows\system32\win32k.sys
2010-06-16 06:11:10 340992 ----a-w- c:\windows\system32\schannel.dll
2010-06-16 05:48:35 224256 ----a-w- c:\windows\syswow64\schannel.dll
2010-06-08 06:02:06 1233920 ----a-w- c:\windows\syswow64\msxml3.dll
2010-06-08 05:36:31 1877504 ----a-w- c:\windows\system32\msxml3.dll
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:54:24 174 --sha-w- c:\program files\desktop.ini
2009-07-14 04:54:24 174 --sha-w- c:\program files (x86)\desktop.ini
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 20:44:08 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 04:55:03 16384 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-07-14 04:55:03 32768 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-07-14 04:55:03 16384 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\roaming\microsoft\windows\cookies\index.dat
2009-07-14 01:39:53 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 19:37:26.90 ===============

shelf life
2010-08-24, 23:04
hi,

Your log is a few days old. If you still need help post back. Are you using a web based client like gmail, yahoo or hotmail?

eyedr90
2010-08-25, 02:28
Hi, I'm using an MSN account

DDS (Ver_10-03-17.01) - NTFSX64
Run by Bigler at 18:24:34.92 on Tue 08/24/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.6136.4206 [GMT -6:00]

SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
C:\Windows\system32\conhost.exe
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0369.0\mswinext.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\SysWOW64\WinMsgBalloonServer.exe
C:\Windows\SysWOW64\WinMsgBalloonClient.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Bigler\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\splwow64.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsf.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Solutions\hpsaupdaterobj.exe
C:\ProgramData\Hewlett-Packard\HPSAUpgrade2\HpSAUpgrade.exe
C:\Users\Bigler\Desktop\dds.scr
C:\Windows\system32\conhost.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://my.msn.com
mLocal Page = c:\windows\syswow64\blank.htm
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files (x86)\norton internet security\engine\17.7.0.12\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files (x86)\norton internet security\engine\17.7.0.12\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files (x86)\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~2\micros~1\office14\URLREDIR.DLL
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files (x86)\msn toolbar\platform\4.0.0369.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files (x86)\msn toolbar\platform\4.0.0369.0\npwinext.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files (x86)\norton internet security\engine\17.7.0.12\coIEPlg.dll
uRun: [Google Update] "c:\users\bigler\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Steam] "c:\program files (x86)\steam\Steam.exe" -silent
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [StartCCC] "c:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [HP Software Update] c:\program files (x86)\hp\hp software update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [NortonOnlineBackupReminder] "c:\program files (x86)\symantec\norton online backup\activation\NOBuActivation.exe" UNATTENDED
mRun: [MSN Toolbar] "c:\program files (x86)\msn toolbar\platform\4.0.0369.0\mswinext.exe"
mRun: [Microsoft Default Manager] "c:\program files (x86)\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [SunJavaUpdateSched] "c:\program files (x86)\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\pictur~1.lnk - c:\program files (x86)\picturemover\bin\PictureMover.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~2\micros~1\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\micros~1\office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files (x86)\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files (x86)\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\common files\microsoft shared\office14\MSOXMLMF.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
mRun-x64: [hpsysdrv] c:\program files (x86)\hewlett-packard\hp odometer\hpsysdrv.exe
mRun-x64: [SmartMenu] c:\program files\hewlett-packard\hp mediasmart\SmartMenu.exe /background

============= SERVICES / DRIVERS ===============

R0 ahcix64s;ahcix64s;c:\windows\system32\drivers\ahcix64s.sys [2010-8-13 230456]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nisx64\1107000.00c\symds64.sys [2010-8-19 433200]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nisx64\1107000.00c\symefa64.sys [2010-8-19 221232]
R1 BHDrvx64;BHDrvx64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\bashdefs\20100810.004\BHDrvx64.sys [2010-8-10 945200]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nisx64\1107000.00c\cchpx64.sys [2010-8-19 615040]
R1 IDSVia64;IDSVia64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\ipsdefs\20100823.002\IDSviA64.sys [2010-8-24 463408]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv64.sys [2010-2-17 14920]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\saskutil64.sys [2010-2-17 12360]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nisx64\1107000.00c\ironx64.sys [2010-8-19 150064]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\nisx64\1107000.00c\symtdiv.sys [2010-8-19 451120]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore64.exe [2010-6-29 128752]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-8-13 202752]
R2 AMD_RAIDXpert;AMD RAIDXpert;c:\program files (x86)\amd\raidxpert\bin\RAIDXpertService.exe [2009-12-15 122880]
R2 CinemaNow Service;CinemaNow Service;c:\program files (x86)\cinemanow\cinemanow media manager\CinemaNowSvc.exe [2010-2-26 127984]
R2 NIS;Norton Internet Security;c:\program files (x86)\norton internet security\engine\17.7.0.12\ccsvchst.exe [2010-8-19 126392]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atipmdag.sys [2010-8-13 6327296]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-8-13 185344]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-8-19 132656]
R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt64win7.sys [2010-8-13 346144]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2010-8-13 39480]
S3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0;PCDSRVC{F36B3A4C-F95654BD-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms [2010-1-19 23536]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-8-20 1255736]

=============== Created Last 30 ================

2010-08-25 00:20:00 0 d-----w- c:\users\bigler\appdata\roaming\HP Support Assistant
2010-08-23 20:52:51 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2010-08-22 21:21:24 1613824 ----a-w- c:\windows\syswow64\cdintf250.dll
2010-08-22 21:21:15 0 d-----w- c:\program files (x86)\common files\Palo Alto Software
2010-08-22 21:21:11 0 d-----w- c:\program files (x86)\common files\Intuit
2010-08-22 21:21:04 0 d-----w- c:\users\bigler\appdata\roaming\Intuit
2010-08-22 21:21:04 0 d-----w- c:\program files (x86)\Quicken
2010-08-22 21:21:02 194 ----a-w- c:\windows\QUICKEN.INI
2010-08-22 21:20:40 0 d-----w- c:\programdata\Intuit
2010-08-21 04:53:54 108144 ----a-w- c:\windows\syswow64\CmdLineExt.dll
2010-08-21 04:51:37 0 d-----w- C:\temp
2010-08-21 04:51:07 0 d-----w- c:\programdata\Media Center Programs
2010-08-21 04:41:23 0 d-----w- c:\program files (x86)\THQ
2010-08-21 04:37:08 0 d-----w- c:\programdata\InstallShield
2010-08-21 03:25:29 0 d-----w- c:\users\bigler\appdata\roaming\HpUpdate
2010-08-21 00:53:28 0 d-----w- c:\program files\Microsoft Office
2010-08-21 00:53:18 0 d-----w- c:\program files (x86)\Microsoft Analysis Services
2010-08-21 00:52:28 0 d-----w- c:\programdata\Microsoft Help
2010-08-20 22:08:28 0 d--h--w- c:\programdata\{0E8E33D8-193A-414A-A909-0F101A142D26}
2010-08-20 21:59:27 0 d-----w- c:\program files (x86)\Stardock Games
2010-08-20 21:37:21 0 d-----w- c:\users\bigler\appdata\roaming\WildTangent
2010-08-20 20:41:49 0 d-----w- c:\windows\syswow64\Wat
2010-08-20 20:41:49 0 d-----w- c:\windows\system32\Wat
2010-08-20 20:35:54 0 d-----w- c:\program files (x86)\MSXML 4.0
2010-08-20 20:35:20 99176 ----a-w- c:\windows\syswow64\PresentationHostProxy.dll
2010-08-20 20:35:20 49472 ----a-w- c:\windows\syswow64\netfxperf.dll
2010-08-20 20:35:20 48960 ----a-w- c:\windows\system32\netfxperf.dll
2010-08-20 20:35:20 444752 ----a-w- c:\windows\system32\mscoree.dll
2010-08-20 20:35:20 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2010-08-20 20:35:20 297808 ----a-w- c:\windows\syswow64\mscoree.dll
2010-08-20 20:35:20 295264 ----a-w- c:\windows\syswow64\PresentationHost.exe
2010-08-20 20:35:20 1942856 ----a-w- c:\windows\system32\dfshim.dll
2010-08-20 20:35:20 1130824 ----a-w- c:\windows\syswow64\dfshim.dll
2010-08-20 20:35:20 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-08-20 19:59:30 0 d-----w- c:\program files (x86)\LucasArts
2010-08-20 19:58:46 0 d-s---w- c:\program files (x86)\Xfire
2010-08-20 19:58:46 0 d-----w- c:\users\bigler\appdata\roaming\Xfire
2010-08-20 16:49:41 74576 ----a-w- c:\windows\system32\XAPOFX1_2.dll
2010-08-20 16:49:41 70992 ----a-w- c:\windows\syswow64\XAPOFX1_2.dll
2010-08-20 16:49:41 518480 ----a-w- c:\windows\system32\XAudio2_3.dll
2010-08-20 16:49:41 514384 ----a-w- c:\windows\syswow64\XAudio2_3.dll
2010-08-20 16:49:41 235856 ----a-w- c:\windows\syswow64\xactengine3_3.dll
2010-08-20 16:49:41 175440 ----a-w- c:\windows\system32\xactengine3_3.dll
2010-08-20 16:49:40 25936 ----a-w- c:\windows\system32\X3DAudio1_5.dll
2010-08-20 16:49:40 23376 ----a-w- c:\windows\syswow64\X3DAudio1_5.dll
2010-08-20 15:17:06 0 d-----w- c:\windows\syswow64\AGEIA
2010-08-20 15:17:00 0 d-----w- c:\program files (x86)\common files\Wise Installation Wizard
2010-08-20 15:15:59 2337488 ----a-w- c:\windows\syswow64\d3dx9_25.dll
2010-08-20 15:15:59 2222800 ----a-w- c:\windows\syswow64\d3dx9_24.dll
2010-08-20 09:11:03 84992 ----a-w- c:\windows\system32\asycfilt.dll
2010-08-20 09:11:03 67584 ----a-w- c:\windows\syswow64\asycfilt.dll
2010-08-20 09:11:00 463360 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-20 09:11:00 404992 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-08-20 09:11:00 162304 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-08-20 09:09:59 389632 ----a-w- c:\windows\system32\winlogon.exe
2010-08-20 09:08:57 46080 ----a-w- c:\windows\system32\atmlib.dll
2010-08-20 09:08:57 366080 ----a-w- c:\windows\system32\atmfd.dll
2010-08-20 09:08:57 34304 ----a-w- c:\windows\syswow64\atmlib.dll
2010-08-20 09:08:57 293888 ----a-w- c:\windows\syswow64\atmfd.dll
2010-08-20 09:08:56 2048 ----a-w- c:\windows\syswow64\tzres.dll
2010-08-20 09:08:56 2048 ----a-w- c:\windows\system32\tzres.dll
2010-08-20 04:30:46 0 d-----w- c:\users\bigler\appdata\roaming\SUPERAntiSpyware.com
2010-08-20 04:30:46 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2010-08-20 04:30:43 0 d-----w- c:\programdata\!SASCORE
2010-08-20 04:30:42 0 d-----w- c:\program files\SUPERAntiSpyware
2010-08-20 04:09:32 0 d-----w- c:\programdata\Adobe
2010-08-20 03:58:14 0 d-----w- c:\program files (x86)\common files\Symantec Shared
2010-08-20 02:58:50 0 d-----w- c:\program files (x86)\SystemRequirementsLab
2010-08-20 02:53:14 0 d-----w- c:\programdata\Sun
2010-08-20 02:52:29 423656 ----a-w- c:\windows\syswow64\deployJava1.dll
2010-08-20 02:52:29 153376 ----a-w- c:\windows\syswow64\javaws.exe
2010-08-20 02:52:29 145184 ----a-w- c:\windows\syswow64\javaw.exe
2010-08-20 02:52:29 145184 ----a-w- c:\windows\syswow64\java.exe
2010-08-20 02:47:47 0 d-----w- c:\program files (x86)\common files\Steam
2010-08-20 02:47:46 0 d-----w- c:\program files (x86)\Steam
2010-08-20 02:30:27 854 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.INF
2010-08-20 02:30:27 7440 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.CAT
2010-08-20 02:30:27 173104 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2010-08-20 02:30:27 0 d-----w- c:\program files\Symantec
2010-08-20 02:30:27 0 d-----w- c:\program files\common files\Symantec Shared
2010-08-20 02:29:11 0 d-----w- c:\users\bigler\appdata\roaming\PictureMover
2010-08-20 02:28:54 220672 ----a-w- c:\windows\system32\wintrust.dll
2010-08-20 02:28:54 172032 ----a-w- c:\windows\syswow64\wintrust.dll
2010-08-20 02:28:53 139264 ----a-w- c:\windows\system32\cabview.dll
2010-08-20 02:28:53 132608 ----a-w- c:\windows\syswow64\cabview.dll
2010-08-14 05:41:07 0 --sha-r- C:\OS
2010-08-14 04:59:23 51712 ----a-w- c:\windows\system32\drivers\usbehci.sys
2010-08-14 04:59:23 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2010-08-14 04:58:31 311808 ----a-w- c:\windows\system32\msv1_0.dll
2010-08-14 04:58:31 257024 ----a-w- c:\windows\syswow64\msv1_0.dll
2010-08-14 04:58:14 960512 ----a-w- c:\windows\system32\CPFilters.dll
2010-08-14 04:58:14 641536 ----a-w- c:\windows\syswow64\CPFilters.dll
2010-08-14 04:58:05 46592 ----a-w- c:\windows\system32\msasn1.dll
2010-08-14 04:58:05 34816 ----a-w- c:\windows\syswow64\msasn1.dll
2010-08-14 04:57:40 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2010-08-14 04:57:40 12625408 ----a-w- c:\windows\syswow64\wmploc.DLL
2010-08-14 04:57:40 11406336 ----a-w- c:\windows\syswow64\wmp.dll
2010-08-14 04:57:39 982600 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2010-08-14 04:57:39 1975296 ----a-w- c:\windows\system32\CertEnroll.dll
2010-08-14 04:57:39 1320960 ----a-w- c:\windows\syswow64\CertEnroll.dll
2010-08-14 04:56:50 70656 ----a-w- c:\windows\syswow64\fontsub.dll
2010-08-14 04:56:50 148480 ----a-w- c:\windows\system32\t2embed.dll
2010-08-14 04:56:50 108544 ----a-w- c:\windows\syswow64\t2embed.dll
2010-08-14 04:56:50 100864 ----a-w- c:\windows\system32\fontsub.dll
2010-08-14 04:48:56 16440 ----a-w- c:\windows\system32\drivers\AtiPcie64.sys
2010-08-14 04:48:55 230456 ----a-w- c:\windows\system32\drivers\ahcix64s.sys
2010-08-14 04:48:54 74272 ----a-w- c:\windows\system32\RtNicProp64.dll
2010-08-14 04:48:54 346144 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2010-08-14 04:48:54 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2010-08-14 04:39:26 0 d-sh--w- C:\$RECYCLE.BIN
2010-08-14 04:33:48 0 d-----w- c:\windows\system32\drivers\NISx64
2010-08-14 04:33:46 0 d-----w- c:\programdata\Norton
2010-08-14 04:33:46 0 d-----w- c:\program files (x86)\Norton Internet Security
2010-08-14 04:33:33 0 d-----w- c:\programdata\NortonInstaller
2010-08-14 04:33:33 0 d-----w- c:\program files (x86)\NortonInstaller
2010-08-14 04:33:07 4398360 ----a-w- c:\windows\system32\d3dx9_32.dll
2010-08-14 04:33:07 3426072 ----a-w- c:\windows\syswow64\d3dx9_32.dll
2010-08-14 04:33:05 20 ----a-w- c:\windows\àóÒ
2010-08-14 04:33:05 0 d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2010-08-14 04:32:22 0 d-----w- c:\program files (x86)\Windows Live SkyDrive
2010-08-14 04:31:59 0 d-----w- c:\windows\PCHEALTH
2010-08-14 04:31:35 0 d-----w- c:\program files (x86)\common files\Windows Live
2010-08-14 04:31:20 0 d-----w- c:\program files (x86)\Microsoft
2010-08-14 04:31:19 0 d-----w- c:\program files (x86)\MSN Toolbar
2010-08-14 04:31:12 0 d-----w- c:\program files (x86)\MSN Toolbar Installer
2010-08-14 04:30:43 0 d-----w- c:\program files\PlayReady
2010-08-14 04:25:24 0 d---a-w- c:\program files (x86)\common files\LS Getting Started
2010-08-14 04:22:02 0 d-----w- c:\programdata\WildTangent
2010-08-14 04:22:02 0 d-----w- c:\program files (x86)\HP Games
2010-08-14 04:21:55 0 d-----w- c:\programdata\PictureMover
2010-08-14 04:21:55 0 d-----w- c:\program files (x86)\PictureMover
2010-08-14 04:21:51 0 d-----w- c:\programdata\Symantec
2010-08-14 04:21:51 0 d-----w- c:\program files (x86)\Symantec
2010-08-14 04:21:48 0 d-----r- c:\program files (x86)\Online Services
2010-08-14 04:17:37 0 d-----w- c:\programdata\Uninstall
2010-08-14 04:17:33 0 d-----w- c:\programdata\CinemaNow
2010-08-14 04:17:32 0 d-----w- c:\program files (x86)\CinemaNow
2010-08-14 04:17:30 0 d-----w- c:\program files (x86)\Microsoft WSE
2010-08-14 04:17:28 0 d-----w- c:\programdata\Sonic
2010-08-14 04:17:18 0 d-----w- c:\programdata\Macrovision
2010-08-14 04:16:45 0 d-----w- c:\programdata\CyberLink
2010-08-14 04:11:37 253952 ----a-w- c:\windows\syswow64\cPC_DMIRD.dll
2010-08-14 04:11:32 0 d-----w- c:\program files (x86)\Hp
2010-08-14 04:11:00 0 d-----w- c:\programdata\Temp
2010-08-14 04:10:56 0 d-----w- c:\programdata\PC-Doctor for Windows
2010-08-14 04:10:33 0 d-----w- c:\program files\PC-Doctor for Windows
2010-08-14 04:09:53 0 d-----w- c:\windows\Downloaded Installations
2010-08-14 04:07:47 64000 ------w- c:\windows\syswow64\agrsmdel.exe
2010-08-14 04:07:47 27648 ------w- c:\windows\syswow64\agrsco64.dll
2010-08-14 04:07:46 0 d-----w- c:\windows\Options
2010-08-14 04:07:40 0 d-----w- c:\programdata\ATI
2010-08-14 04:07:12 0 d-----w- c:\program files\ATI
2010-08-14 04:07:12 0 d-----w- c:\program files (x86)\ATI Technologies
2010-08-14 04:06:54 0 d-----w- c:\program files\DIFX
2010-08-14 04:06:53 39480 ----a-w- c:\windows\system32\drivers\usbfilter.sys
2010-08-14 04:06:53 0 d-----w- c:\program files (x86)\AMD
2010-08-14 04:06:16 0 d-----w- c:\program files (x86)\Realtek
2010-08-14 04:06:15 1247776 ----a-w- c:\windows\RtlExUpd.dll
2010-08-14 04:06:15 0 d--h--w- c:\program files (x86)\Temp
2010-08-14 04:05:47 0 d-----w- c:\programdata\Hewlett-Packard
2010-08-14 04:05:20 0 d-----w- c:\programdata\{657095DF-DBDB-4B17-8245-B38845C97069}
2010-08-14 04:05:01 0 d-----w- c:\program files\hp
2010-08-14 04:04:59 0 d-----w- c:\windows\syswow64\Macromed
2010-08-14 04:04:53 0 d-----w- c:\program files\Hewlett-Packard
2010-08-14 04:04:32 0 d-sh--w- c:\windows\Installer
2010-08-14 04:01:57 0 d-----w- c:\windows\syswow64\RTCOM
2010-08-14 04:01:57 0 d-----w- c:\program files\Realtek
2010-08-14 04:01:52 0 ----a-w- c:\windows\ativpsrm.bin
2010-08-14 04:01:34 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-08-06 16:35:28 0 d-sha-r- C:\hp

==================== Find3M ====================

2010-08-20 02:27:53 0 --sha-r- c:\windows\system32\drivers\103C_HP_53316J G D_HPE-300z_Y53316J G D_0U_Q2MD032_E2MD0320H6P DPS_4A_I2A92_SFOXCONN_V1.01_6.05_T100702_WU3-0_L409_M6136_J750_7AMD_8F43_92.80_#100819_N10EC8168_(WS387AV#ABA)_X_CD3_Z_2_G100268D9.MRK
2010-07-29 06:30:34 82944 ----a-w- c:\windows\syswow64\iccvid.dll
2010-07-27 14:03:24 12867584 ----a-w- c:\windows\syswow64\shell32.dll
2010-06-30 07:13:46 1192960 ----a-w- c:\windows\system32\wininet.dll
2010-06-30 06:25:31 978432 ----a-w- c:\windows\syswow64\wininet.dll
2010-06-30 06:25:18 1226240 ----a-w- c:\windows\syswow64\urlmon.dll
2010-06-30 06:22:45 606208 ----a-w- c:\windows\syswow64\mstime.dll
2010-06-30 06:22:34 5971456 ----a-w- c:\windows\syswow64\mshtml.dll
2010-06-30 06:22:33 64512 ----a-w- c:\windows\syswow64\msfeedsbs.dll
2010-06-30 06:21:57 48128 ----a-w- c:\windows\syswow64\jsproxy.dll
2010-06-30 06:21:47 185856 ----a-w- c:\windows\syswow64\iepeers.dll
2010-06-30 06:21:47 176640 ----a-w- c:\windows\syswow64\ieui.dll
2010-06-30 06:21:46 10985472 ----a-w- c:\windows\syswow64\ieframe.dll
2010-06-30 06:21:44 381440 ----a-w- c:\windows\syswow64\iedkcs32.dll
2010-06-30 06:19:16 12800 ----a-w- c:\windows\syswow64\msfeedssync.exe
2010-06-19 07:05:01 5507968 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-06-19 06:53:18 52224 ----a-w- c:\windows\system32\rtutils.dll
2010-06-19 06:33:29 3955080 ----a-w- c:\windows\syswow64\ntkrnlpa.exe
2010-06-19 06:33:29 3899784 ----a-w- c:\windows\syswow64\ntoskrnl.exe
2010-06-19 06:23:50 37376 ----a-w- c:\windows\syswow64\rtutils.dll
2010-06-19 04:32:34 3122688 ----a-w- c:\windows\system32\win32k.sys
2010-06-16 06:11:10 340992 ----a-w- c:\windows\system32\schannel.dll
2010-06-16 05:48:35 224256 ----a-w- c:\windows\syswow64\schannel.dll
2010-06-08 06:02:06 1233920 ----a-w- c:\windows\syswow64\msxml3.dll
2010-06-08 05:36:31 1877504 ----a-w- c:\windows\system32\msxml3.dll
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:54:24 174 --sha-w- c:\program files\desktop.ini
2009-07-14 04:54:24 174 --sha-w- c:\program files (x86)\desktop.ini
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 20:44:08 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:39:53 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 18:25:00.38 ===============

shelf life
2010-08-25, 03:25
About all we can do is check you machine for malware. Its seems you have already done this. You said you got a new computer and the emails continue. This makes me believe that a spammer is using your email address to send out spam that looks like its coming from you.
If the e-mails where really originating from your personal computer you probably would have heard from your ISP by now, not to mention have malware on board also.
Visit this link (http://support.microsoft.com/kb/316659) and this one (http://help.uk.msn.com/windowslivehotmail/article.aspx?cp-documentid=4374062) for some info about E-mail.

Lets see if this can dig up anything:
Please download Malwarebytes (http://www.malwarebytes.org/mbam.php) to your desktop.

Double-click mbam-setup.exe and follow the prompts to install the program.

Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded, select Perform FULL SCAN, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.

Be sure that everything is checked, and click *Remove Selected.*

*A restart of your computer may be required to remove some items. If prompted please restart your computer to complete the fix.*

When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Post the log in your reply.

eyedr90
2010-08-25, 22:41
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4475

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

8/25/2010 2:16:10 PM
mbam-log-2010-08-25 (14-16-10).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 298127
Time elapsed: 38 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

shelf life
2010-08-25, 23:26
that result couldn't be any better. run a copy of TDSSkiller also:

Please download TDSS Killer.exe (http://support.kaspersky.com/downloads/utils/tdsskiller.exe) and save it to your desktop
Double click to launch the utility. click the start scan button.
(For Vista and W7: right click and "run as admin" allow the UAC prompts)

Once the scan completes you can click the continue button.

"The utility will automatically selects an action (Cure or Delete) for known malacious objects. A suspicious object will be skipped by default."

"After clicking Next, the utility applies selected actions and outputs the result."

"A reboot might require after disinfection."

A report will be found in your Root drive Local Disk (C:) as TDSSKiller.2.4.0.0_01.08.2010_17.32.21_log.txt (name, version, date, time)
Please post the log report

eyedr90
2010-08-26, 14:46
Hi, Here is the report.


2010/08/26 06:44:34.0980 TDSS rootkit removing tool 2.4.1.2 Aug 16 2010 09:46:23
2010/08/26 06:44:34.0980 ================================================================================
2010/08/26 06:44:34.0980 SystemInfo:
2010/08/26 06:44:34.0980
2010/08/26 06:44:34.0980 OS Version: 6.1.7600 ServicePack: 0.0
2010/08/26 06:44:34.0980 Product type: Workstation
2010/08/26 06:44:34.0980 ComputerName: BIGLER-HP
2010/08/26 06:44:34.0981 UserName: Bigler
2010/08/26 06:44:34.0981 Windows directory: C:\Windows
2010/08/26 06:44:34.0981 System windows directory: C:\Windows
2010/08/26 06:44:34.0981 Running under WOW64
2010/08/26 06:44:34.0981 Processor architecture: Intel x64
2010/08/26 06:44:34.0981 Number of processors: 4
2010/08/26 06:44:34.0981 Page size: 0x1000
2010/08/26 06:44:34.0981 Boot type: Normal boot
2010/08/26 06:44:34.0981 ================================================================================
2010/08/26 06:44:34.0981 Utility is running under WOW64, functionality is limited.
2010/08/26 06:44:35.0239 Initialize success
2010/08/26 06:44:39.0759 ================================================================================
2010/08/26 06:44:39.0759 Scan started
2010/08/26 06:44:39.0759 Mode: Manual;
2010/08/26 06:44:39.0759 ================================================================================
2010/08/26 06:44:40.0649 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
2010/08/26 06:44:40.0686 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
2010/08/26 06:44:40.0719 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
2010/08/26 06:44:40.0771 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
2010/08/26 06:44:40.0822 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
2010/08/26 06:44:40.0861 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
2010/08/26 06:44:40.0932 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys
2010/08/26 06:44:41.0007 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
2010/08/26 06:44:41.0069 ahcix64s (aa3f73ccbf498bd56800f840d75e40e4) C:\Windows\system32\DRIVERS\ahcix64s.sys
2010/08/26 06:44:41.0132 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
2010/08/26 06:44:41.0170 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
2010/08/26 06:44:41.0207 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
2010/08/26 06:44:41.0332 amdkmdag (9673319070166e26660eba4edf316fa2) C:\Windows\system32\DRIVERS\atipmdag.sys
2010/08/26 06:44:41.0534 amdkmdap (430d06d63952848e64cbbf23b5c1479e) C:\Windows\system32\DRIVERS\atikmpag.sys
2010/08/26 06:44:41.0609 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
2010/08/26 06:44:41.0673 amdsata (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
2010/08/26 06:44:41.0717 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
2010/08/26 06:44:41.0753 amdxata (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
2010/08/26 06:44:41.0805 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
2010/08/26 06:44:41.0873 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
2010/08/26 06:44:41.0902 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
2010/08/26 06:44:41.0943 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
2010/08/26 06:44:41.0966 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
2010/08/26 06:44:42.0011 AtiHdmiService (d481083348138b4933acfe95812db71c) C:\Windows\system32\drivers\AtiHdmi.sys
2010/08/26 06:44:42.0063 AtiPcie (e82e61f46d1336447f4deff8c074f13e) C:\Windows\system32\DRIVERS\AtiPcie64.sys
2010/08/26 06:44:42.0160 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
2010/08/26 06:44:42.0191 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
2010/08/26 06:44:42.0240 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
2010/08/26 06:44:42.0415 BHDrvx64 (95da658498248d5832aa240850706150) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100810.004\BHDrvx64.sys
2010/08/26 06:44:42.0482 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
2010/08/26 06:44:42.0515 bowser (91ce0d3dc57dd377e690a2d324022b08) C:\Windows\system32\DRIVERS\bowser.sys
2010/08/26 06:44:42.0544 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2010/08/26 06:44:42.0577 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2010/08/26 06:44:42.0608 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
2010/08/26 06:44:42.0629 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
2010/08/26 06:44:42.0648 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
2010/08/26 06:44:42.0667 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
2010/08/26 06:44:42.0710 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
2010/08/26 06:44:42.0774 ccHP (da66e851e76766d2c84502fe682ab175) C:\Windows\system32\drivers\NISx64\1107000.00C\ccHPx64.sys
2010/08/26 06:44:42.0826 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
2010/08/26 06:44:42.0856 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
2010/08/26 06:44:42.0909 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
2010/08/26 06:44:42.0951 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
2010/08/26 06:44:43.0007 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
2010/08/26 06:44:43.0031 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
2010/08/26 06:44:43.0055 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
2010/08/26 06:44:43.0075 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
2010/08/26 06:44:43.0105 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
2010/08/26 06:44:43.0133 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
2010/08/26 06:44:43.0216 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys
2010/08/26 06:44:43.0256 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
2010/08/26 06:44:43.0283 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
2010/08/26 06:44:43.0342 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
2010/08/26 06:44:43.0403 DXGKrnl (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys
2010/08/26 06:44:43.0508 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
2010/08/26 06:44:43.0646 eeCtrl (066108ae4c35835081598827a1a7d08d) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
2010/08/26 06:44:43.0756 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
2010/08/26 06:44:43.0806 EraserUtilRebootDrv (12866876e3851f1e5d462b2a83e25578) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
2010/08/26 06:44:43.0835 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
2010/08/26 06:44:43.0911 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
2010/08/26 06:44:43.0955 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
2010/08/26 06:44:43.0991 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
2010/08/26 06:44:44.0044 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
2010/08/26 06:44:44.0074 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
2010/08/26 06:44:44.0093 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
2010/08/26 06:44:44.0132 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
2010/08/26 06:44:44.0191 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
2010/08/26 06:44:44.0217 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
2010/08/26 06:44:44.0250 fvevol (b8b2a6e1558f8f5de5ce431c5b2c7b09) C:\Windows\system32\DRIVERS\fvevol.sys
2010/08/26 06:44:44.0273 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
2010/08/26 06:44:44.0334 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
2010/08/26 06:44:44.0382 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
2010/08/26 06:44:44.0435 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
2010/08/26 06:44:44.0466 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
2010/08/26 06:44:44.0497 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
2010/08/26 06:44:44.0516 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
2010/08/26 06:44:44.0553 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
2010/08/26 06:44:44.0641 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
2010/08/26 06:44:44.0668 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
2010/08/26 06:44:44.0707 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
2010/08/26 06:44:44.0733 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
2010/08/26 06:44:44.0764 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
2010/08/26 06:44:44.0915 IDSVia64 (c3292140bf458b46cf8abbfd7e177bbe) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100823.002\IDSvia64.sys
2010/08/26 06:44:44.0957 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
2010/08/26 06:44:45.0053 IntcAzAudAddService (28ceefbd2c63f91dc17ded3e8d27ecf5) C:\Windows\system32\drivers\RTKVHD64.sys
2010/08/26 06:44:45.0082 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
2010/08/26 06:44:45.0114 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
2010/08/26 06:44:45.0163 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2010/08/26 06:44:45.0196 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2010/08/26 06:44:45.0223 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
2010/08/26 06:44:45.0260 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
2010/08/26 06:44:45.0289 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
2010/08/26 06:44:45.0324 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
2010/08/26 06:44:45.0362 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
2010/08/26 06:44:45.0387 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
2010/08/26 06:44:45.0420 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
2010/08/26 06:44:45.0462 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
2010/08/26 06:44:45.0487 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
2010/08/26 06:44:45.0572 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
2010/08/26 06:44:45.0623 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
2010/08/26 06:44:45.0645 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
2010/08/26 06:44:45.0679 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2010/08/26 06:44:45.0709 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2010/08/26 06:44:45.0763 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
2010/08/26 06:44:45.0813 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
2010/08/26 06:44:45.0867 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
2010/08/26 06:44:45.0918 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
2010/08/26 06:44:45.0950 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
2010/08/26 06:44:45.0976 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
2010/08/26 06:44:45.0994 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
2010/08/26 06:44:46.0024 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
2010/08/26 06:44:46.0053 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
2010/08/26 06:44:46.0112 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
2010/08/26 06:44:46.0185 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
2010/08/26 06:44:46.0233 mrxsmb (767a4c3bcf9410c286ced15a2db17108) C:\Windows\system32\DRIVERS\mrxsmb.sys
2010/08/26 06:44:46.0263 mrxsmb10 (920ee0ff995fcfdeb08c41605a959e1c) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2010/08/26 06:44:46.0307 mrxsmb20 (740d7ea9d72c981510a5292cf6adc941) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2010/08/26 06:44:46.0330 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
2010/08/26 06:44:46.0371 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
2010/08/26 06:44:46.0430 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
2010/08/26 06:44:46.0475 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
2010/08/26 06:44:46.0511 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
2010/08/26 06:44:46.0594 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
2010/08/26 06:44:46.0627 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
2010/08/26 06:44:46.0659 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
2010/08/26 06:44:46.0696 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
2010/08/26 06:44:46.0746 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
2010/08/26 06:44:46.0776 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
2010/08/26 06:44:46.0806 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
2010/08/26 06:44:46.0839 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
2010/08/26 06:44:46.0881 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
2010/08/26 06:44:47.0005 NAVENG (a507b7d1c5f957a1aab98794eb377654) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100825.024\ENG64.SYS
2010/08/26 06:44:47.0075 NAVEX15 (0d7d6c0fd46f12780c3bab6af891ede3) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100825.024\EX64.SYS
2010/08/26 06:44:47.0117 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
2010/08/26 06:44:47.0142 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
2010/08/26 06:44:47.0176 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
2010/08/26 06:44:47.0216 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
2010/08/26 06:44:47.0236 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
2010/08/26 06:44:47.0276 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
2010/08/26 06:44:47.0319 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
2010/08/26 06:44:47.0351 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
2010/08/26 06:44:47.0435 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
2010/08/26 06:44:47.0510 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
2010/08/26 06:44:47.0573 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
2010/08/26 06:44:47.0621 Ntfs (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
2010/08/26 06:44:47.0675 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
2010/08/26 06:44:47.0727 nvraid (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
2010/08/26 06:44:47.0781 nvstor (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
2010/08/26 06:44:47.0808 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
2010/08/26 06:44:47.0844 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
2010/08/26 06:44:47.0946 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
2010/08/26 06:44:47.0988 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
2010/08/26 06:44:48.0085 PCDSRVC{F36B3A4C-F95654BD-06000000}_0 (51209fbdb13a46e05c1b0077a9310264) c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms
2010/08/26 06:44:48.0175 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
2010/08/26 06:44:48.0206 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
2010/08/26 06:44:48.0234 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
2010/08/26 06:44:48.0262 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
2010/08/26 06:44:48.0303 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
2010/08/26 06:44:48.0439 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
2010/08/26 06:44:48.0476 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
2010/08/26 06:44:48.0542 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
2010/08/26 06:44:48.0590 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
2010/08/26 06:44:48.0643 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
2010/08/26 06:44:48.0693 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
2010/08/26 06:44:48.0718 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
2010/08/26 06:44:48.0748 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
2010/08/26 06:44:48.0781 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
2010/08/26 06:44:48.0818 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
2010/08/26 06:44:48.0857 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
2010/08/26 06:44:48.0885 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
2010/08/26 06:44:48.0907 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
2010/08/26 06:44:48.0934 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
2010/08/26 06:44:48.0968 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
2010/08/26 06:44:49.0006 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
2010/08/26 06:44:49.0040 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
2010/08/26 06:44:49.0076 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
2010/08/26 06:44:49.0171 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
2010/08/26 06:44:49.0210 RTL8167 (7ea8d2eb9bbfd2ab8a3117a1e96d3b3a) C:\Windows\system32\DRIVERS\Rt64win7.sys
2010/08/26 06:44:49.0279 SASDIFSV (99df79c258b3342b6c8a5f802998de56) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
2010/08/26 06:44:49.0307 SASKUTIL (2859c35c0651e8eb0d86d48e740388f2) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
2010/08/26 06:44:49.0345 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
2010/08/26 06:44:49.0388 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
2010/08/26 06:44:49.0484 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2010/08/26 06:44:49.0582 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
2010/08/26 06:44:49.0618 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
2010/08/26 06:44:49.0643 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
2010/08/26 06:44:49.0696 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
2010/08/26 06:44:49.0716 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2010/08/26 06:44:49.0736 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
2010/08/26 06:44:49.0756 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
2010/08/26 06:44:49.0811 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2010/08/26 06:44:49.0840 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
2010/08/26 06:44:49.0866 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
2010/08/26 06:44:49.0915 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
2010/08/26 06:44:50.0035 SRTSP (96babc4906ecdb1c69d1176f8647ad8e) C:\Windows\System32\Drivers\NISx64\1107000.00C\SRTSP64.SYS
2010/08/26 06:44:50.0085 SRTSPX (c7f491a290e0e4222f5cdcd50eeb8167) C:\Windows\system32\drivers\NISx64\1107000.00C\SRTSPX64.SYS
2010/08/26 06:44:50.0136 srv (43067a65522eaec33d31a12d6fa8e3f4) C:\Windows\system32\DRIVERS\srv.sys
2010/08/26 06:44:50.0184 srv2 (03715cf9c30b563da35fc5f2b8f7b8e0) C:\Windows\system32\DRIVERS\srv2.sys
2010/08/26 06:44:50.0218 srvnet (fbd09635227a8026c0f7790f604343c6) C:\Windows\system32\DRIVERS\srvnet.sys
2010/08/26 06:44:50.0272 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
2010/08/26 06:44:50.0318 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
2010/08/26 06:44:50.0366 SymDS (659b227a72b76115975a6a9491b2fe1f) C:\Windows\system32\drivers\NISx64\1107000.00C\SYMDS64.SYS
2010/08/26 06:44:50.0423 SymEFA (42c952d131eff724a9959bb6d78c1b63) C:\Windows\system32\drivers\NISx64\1107000.00C\SYMEFA64.SYS
2010/08/26 06:44:50.0486 SymEvent (3f9d5fe52585e2653e59fdbfdf09a94c) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
2010/08/26 06:44:50.0520 SymIRON (f57588546e738db1583981d8f44e9bc2) C:\Windows\system32\drivers\NISx64\1107000.00C\Ironx64.SYS
2010/08/26 06:44:50.0559 SYMTDIv (8abb6e5b7d75cd3f0a988695d0d9186a) C:\Windows\System32\Drivers\NISx64\1107000.00C\SYMTDIV.SYS
2010/08/26 06:44:50.0683 Tcpip (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\drivers\tcpip.sys
2010/08/26 06:44:50.0741 TCPIP6 (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\DRIVERS\tcpip.sys
2010/08/26 06:44:50.0794 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
2010/08/26 06:44:50.0830 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
2010/08/26 06:44:50.0851 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
2010/08/26 06:44:50.0891 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
2010/08/26 06:44:50.0919 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
2010/08/26 06:44:51.0005 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
2010/08/26 06:44:51.0031 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
2010/08/26 06:44:51.0066 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
2010/08/26 06:44:51.0103 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
2010/08/26 06:44:51.0148 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
2010/08/26 06:44:51.0176 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
2010/08/26 06:44:51.0202 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
2010/08/26 06:44:51.0239 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
2010/08/26 06:44:51.0264 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
2010/08/26 06:44:51.0285 usbehci (df9f9afc9aaabd8ed47975d44e38169a) C:\Windows\system32\DRIVERS\usbehci.sys
2010/08/26 06:44:51.0322 usbfilter (858be9c0e498c8e505e198e17eece0d9) C:\Windows\system32\DRIVERS\usbfilter.sys
2010/08/26 06:44:51.0348 usbhub (372a91bc3c6603080a793880b0873785) C:\Windows\system32\DRIVERS\usbhub.sys
2010/08/26 06:44:51.0381 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
2010/08/26 06:44:51.0403 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
2010/08/26 06:44:51.0442 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
2010/08/26 06:44:51.0470 USBSTOR (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2010/08/26 06:44:51.0496 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
2010/08/26 06:44:51.0548 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
2010/08/26 06:44:51.0588 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
2010/08/26 06:44:51.0621 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
2010/08/26 06:44:51.0694 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
2010/08/26 06:44:51.0762 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
2010/08/26 06:44:51.0804 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
2010/08/26 06:44:51.0859 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
2010/08/26 06:44:51.0901 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
2010/08/26 06:44:51.0947 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
2010/08/26 06:44:52.0005 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
2010/08/26 06:44:52.0045 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
2010/08/26 06:44:52.0084 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
2010/08/26 06:44:52.0100 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
2010/08/26 06:44:52.0185 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
2010/08/26 06:44:52.0219 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
2010/08/26 06:44:52.0326 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
2010/08/26 06:44:52.0349 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
2010/08/26 06:44:52.0458 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
2010/08/26 06:44:52.0515 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
2010/08/26 06:44:52.0584 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
2010/08/26 06:44:52.0665 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
2010/08/26 06:44:52.0698 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
2010/08/26 06:44:52.0763 ================================================================================
2010/08/26 06:44:52.0763 Scan finished
2010/08/26 06:44:52.0763 ================================================================================

shelf life
2010-08-26, 23:38
Hi,

That logs looks ok also. I would start with changing your E-mail log in password. Where those two links any help? Some tips on creating strong passwords:



At least fifteen (15) characters in length.
Does not contain your user name, real name, organization name, family member's names or names of your pets.
Does not contain your birth date.
Does not contain a complete dictionary word.
Is significantly different from your previous password.

Should contain three (3) of the following character types.

* Lowercase Alphabetical (a, b, c, etc.)
* Uppercase Alphabetical (A, B, C, etc.)
* Numerics (0, 1, 2, etc.)
* Special Characters (@, %, !, etc.)

tashi
2010-09-03, 20:52
This thread has been closed due to inactivity.

Thank you shelf life. :)