This is my first post and hopefully I’ve followed the procedures correctly.
My laptop is infected by a redirect virus, “Google Redirect” I presume. I’ve scanned using Norton 360, Malwarebytes, and SpyBot with no effect.
I’m connected to my Linksys router utilizing wifi only. The router is fed from a Time Warner cable modem.
I did a SpyBot scan and the results were negative.
DDS (Ver_10-12-12.02) - NTFSx86
Run by Dan Werner at 7:54:59.65 on Tue 12/21/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.60 [GMT -8:00]
AV: Norton 360 *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *Enabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Memeo\AutoBackupPro\MemeoBackgroundService.exe
C:\Program Files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
C:\Program Files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
C:\Program Files\ClickTray Calendar\ClickTray.exe
C:\Program Files\PdaNet for Android\PdaNetPC.exe
C:\Program Files\Seagate\Seagate Dashboard\MemeoDashboard.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Dan Werner\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\4.3.0.5\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\4.3.0.5\IPSBHO.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\4.3.0.5\coIEPlg.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [Seagate Dashboard] c:\program files\seagate\seagate dashboard\MemeoLauncher.exe --silent --no_ui
mRun: [Memeo Backup Premium] c:\program files\memeo\autobackuppro\MemeoLauncher2.exe --silent --no_ui
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\danwer~1\startm~1\programs\startup\clickt~1.lnk - c:\program files\clicktray calendar\ClickTray.exe
StartupFolder: c:\docume~1\danwer~1\startm~1\programs\startup\pdanet~1.lnk - c:\program files\pdanet for android\PdaNetPC.exe
StartupFolder: c:\docume~1\danwer~1\startm~1\programs\startup\seagat~1.lnk - c:\documents and settings\dan werner\application data\leadertech\powerregister\Seagate Product Registration.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\google~1.lnk - c:\program files\google\google calendar sync\GoogleCalendarSync.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\danwer~1\applic~1\mozilla\firefox\profiles\zp8eoqbx.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\coffplgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: AniWeather: {4176DFF4-4698-11DE-BEEB-45DA55D89593} - %profile%\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}
FF - Ext: Favicon Picker 2: {446c03e0-2c35-11db-a98b-0800200c9a66} - %profile%\extensions\{446c03e0-2c35-11db-a98b-0800200c9a66}
FF - Ext: NoRedirect: {c1970c0d-dbe6-4d91-804f-c9c0de643a57} - %profile%\extensions\{c1970c0d-dbe6-4d91-804f-c9c0de643a57}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Norton IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\IPSFFPlgn
FF - Ext: Norton Toolbar: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62} - c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\coFFPlgn
============= SERVICES / DRIVERS ===============
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0403000.005\symds.sys [2010-12-17 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0403000.005\symefa.sys [2010-12-17 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\bashdefs\20101123.003\BHDrvx86.sys [2010-11-23 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0403000.005\cchpx86.sys [2010-12-17 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0403000.005\ironx86.sys [2010-12-17 116784]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\memeo\autobackuppro\MemeoBackgroundService.exe [2010-4-22 25824]
R2 N360;Norton 360;c:\program files\norton 360\engine\4.3.0.5\ccsvchst.exe [2010-12-17 126392]
R2 SeagateDashboardService;Seagate Dashboard Service;c:\program files\seagate\seagate dashboard\SeagateDashboardService.exe [2010-4-30 14088]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-12-17 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20101217.001\IDSXpx86.sys [2010-12-20 341944]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20101221.002\NAVENG.SYS [2010-12-21 86008]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20101221.002\NAVEX15.SYS [2010-12-21 1360760]
R3 pneteth;PdaNet Broadband;c:\windows\system32\drivers\pneteth.sys [2010-12-13 13312]
S0 cerc6;cerc6; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-13 135664]
=============== Created Last 30 ================
2010-12-21 01:22:43 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-12-21 01:21:28 -------- d-----w- c:\docume~1\alluse~1\applic~1\Hitman Pro
2010-12-19 21:53:15 -------- d-----w- c:\docume~1\danwer~1\locals~1\applic~1\Identities
2010-12-18 22:39:17 -------- d-----w- C:\tmp
2010-12-18 22:39:07 -------- d-----w- C:\Cool RingTone Maker
2010-12-17 23:43:36 385024 ----a-w- c:\windows\system32\vbar332.dll
2010-12-17 23:43:35 -------- d-----w- c:\program files\VoptXP v7
2010-12-17 20:22:41 501888 ----a-w- c:\windows\system32\drivers\n360\0403000.005\cchpx86.sys
2010-12-17 20:22:41 43696 ----a-w- c:\windows\system32\drivers\n360\0403000.005\srtspx.sys
2010-12-17 20:22:41 361904 ----a-w- c:\windows\system32\drivers\n360\0403000.005\symtdi.sys
2010-12-17 20:22:41 339504 ----a-w- c:\windows\system32\drivers\n360\0403000.005\symtdiv.sys
2010-12-17 20:22:41 328752 ----a-r- c:\windows\system32\drivers\n360\0403000.005\symds.sys
2010-12-17 20:22:41 325680 ----a-w- c:\windows\system32\drivers\n360\0403000.005\srtsp.sys
2010-12-17 20:22:41 173104 ----a-w- c:\windows\system32\drivers\n360\0403000.005\symefa.sys
2010-12-17 20:22:41 116784 ----a-w- c:\windows\system32\drivers\n360\0403000.005\ironx86.sys
2010-12-17 20:22:01 -------- d-----w- c:\windows\system32\drivers\n360\0403000.005
2010-12-16 20:26:50 107368 ----a-r- c:\windows\system32\GEARAspi.dll
2010-12-16 20:26:21 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-12-16 20:26:21 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-12-16 20:26:20 -------- d-----w- c:\program files\Symantec
2010-12-16 20:25:07 -------- d-----w- c:\windows\system32\drivers\N360
2010-12-16 20:25:03 -------- d-----w- c:\program files\Norton 360
2010-12-16 20:17:45 -------- d-----w- c:\program files\NortonInstaller
2010-12-16 18:45:28 -------- d-----w- c:\docume~1\danwer~1\applic~1\Tific
2010-12-15 20:03:37 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-12-15 19:28:54 -------- d-----w- c:\program files\Garmin
2010-12-15 18:57:30 577 ----a-w- c:\windows\system32\gmsblist.dll
2010-12-15 18:57:06 -------- d-----w- c:\docume~1\danwer~1\locals~1\applic~1\Help
2010-12-15 18:54:59 -------- d-----w- c:\program files\GSAK
2010-12-15 01:26:53 -------- d-----w- c:\docume~1\danwer~1\locals~1\applic~1\WMTools Downloaded Files
2010-12-15 00:04:10 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-12-15 00:04:10 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-14 18:18:34 49152 ------w- c:\windows\system32\INETWH32.dll
2010-12-14 18:18:34 1089536 ------w- c:\windows\system32\ROBOEX32.DLL
2010-12-14 18:18:34 -------- d-----w- C:\Garmin
2010-12-14 04:56:03 -------- d-----w- c:\program files\HyperSnap-DX 4
2010-12-14 04:46:53 -------- d-----w- c:\program files\HyperSnap 6
2010-12-14 04:24:27 -------- d-----w- c:\program files\GlobalSCAPE
2010-12-14 04:24:07 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2010-12-14 04:24:07 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2010-12-14 04:24:07 225280 ----a-w- c:\program files\common files\installshield\iscript\iscript.dll
2010-12-14 04:24:07 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2010-12-14 04:24:06 614532 ------w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe
2010-12-14 04:20:11 -------- d-----w- c:\program files\common files\Vbox
2010-12-14 04:18:36 306688 ----a-w- c:\windows\IsUninst.exe
2010-12-14 04:15:19 -------- d-----w- c:\program files\ClickTray Calendar
2010-12-14 03:46:51 -------- d-----w- c:\program files\Auction Sentry
2010-12-14 03:46:32 -------- d-----w- c:\windows\Downloaded Installations
2010-12-14 03:33:38 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-12-14 03:33:38 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-12-14 03:22:46 286720 ----a-w- c:\windows\iun506.exe
2010-12-14 02:54:51 13312 ----a-w- c:\windows\system32\drivers\pneteth.sys
2010-12-14 02:47:32 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2010-12-14 02:47:00 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-12-14 02:47:00 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-12-14 02:44:41 581192 ----a-w- c:\windows\system32\WinUSBCoInstaller.dll
2010-12-14 02:44:41 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2010-12-14 02:44:40 -------- d-----w- c:\program files\PdaNet for Android
2010-12-14 01:07:48 37 ----a-w- c:\windows\system32\gr6rlzay.dll
2010-12-14 01:00:19 -------- d-----w- c:\docume~1\danwer~1\applic~1\GARMIN
2010-12-14 01:00:19 -------- d-----w- c:\docume~1\alluse~1\applic~1\GARMIN
2010-12-14 00:48:27 -------- d-----w- c:\windows\system32\XPSViewer
2010-12-14 00:48:00 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-12-14 00:47:42 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-12-14 00:47:42 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-12-14 00:47:42 597504 ------w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-12-14 00:47:42 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-12-14 00:47:42 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-12-14 00:47:42 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-12-14 00:47:42 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-12-14 00:47:42 117760 ------w- c:\windows\system32\prntvpt.dll
2010-12-14 00:47:42 -------- d-----w- C:\30af5d22e69d662677
2010-12-14 00:36:31 -------- d-----w- c:\docume~1\danwer~1\locals~1\applic~1\Google
2010-12-13 23:48:13 -------- d-----w- C:\gsak
2010-12-13 23:28:42 -------- d-----w- C:\e18a05fd45ecaad9b471
2010-12-13 23:28:08 -------- d-----w- C:\drivers
2010-12-13 20:23:38 -------- d-----w- C:\DJ's 2010
2010-12-13 20:23:26 -------- d-----w- C:\c653913046ee4a6c69ae8de1105fed
2010-12-13 17:24:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-13 17:24:43 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-13 17:24:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-13 17:16:05 -------- d-----w- c:\docume~1\danwer~1\applic~1\Malwarebytes
2010-12-13 17:15:57 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-12-13 17:04:46 -------- d-----w- c:\docume~1\alluse~1\applic~1\PCSettings
2010-12-13 17:01:33 -------- d-----w- c:\docume~1\alluse~1\applic~1\NortonInstaller
2010-12-13 16:41:05 -------- d-----w- c:\docume~1\danwer~1\locals~1\applic~1\Symantec
2010-12-13 03:07:04 -------- d-----w- c:\docume~1\alluse~1\applic~1\MemeoCommon
2010-12-13 01:54:55 -------- d-----w- c:\docume~1\alluse~1\applic~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2010-12-13 01:54:18 -------- d-----w- c:\docume~1\alluse~1\applic~1\Norton
2010-12-13 01:52:27 -------- d-----w- c:\docume~1\danwer~1\applic~1\Memeo
2010-12-13 01:52:14 -------- d-----w- c:\docume~1\danwer~1\applic~1\Seagate
2010-12-13 01:50:46 -------- d-----w- c:\program files\common files\Memeo
2010-12-13 01:50:39 -------- d-----w- c:\program files\Memeo
2010-12-13 01:50:35 -------- d-----w- c:\docume~1\danwer~1\locals~1\applic~1\temp
2010-12-13 01:48:06 -------- d-----w- c:\program files\Seagate
2010-12-13 01:27:54 -------- d-----w- c:\docume~1\danwer~1\locals~1\applic~1\Adobe
2010-12-13 01:12:59 -------- d-----w- c:\docume~1\alluse~1\applic~1\Symantec
2010-12-13 00:48:29 -------- d-----w- c:\program files\common files\Symantec Shared
2010-12-13 00:41:34 -------- d-----w- c:\docume~1\danwer~1\applic~1\Symantec
2010-12-13 00:00:56 -------- d-----w- c:\windows\ie8updates
2010-12-13 00:00:07 21504 ----a-w- c:\windows\system32\drivers\hidserv.dll
2010-12-12 23:56:50 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-12-12 23:52:49 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-12-12 23:52:49 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-12-12 23:52:48 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-12-12 23:52:48 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-12-12 23:52:48 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-12-12 23:52:47 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-12-12 23:52:45 11080704 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-12-12 23:52:30 2146304 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-12-12 23:52:29 2189952 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-12-12 23:52:28 2024448 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-12-12 23:50:24 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-12-12 23:50:24 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-12-12 23:48:35 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-12-12 23:46:26 -------- d-----w- c:\windows\system32\PreInstall
2010-12-12 23:46:24 -------- d--h--w- c:\windows\$hf_mig$
2010-12-12 23:37:02 -------- d-----w- c:\windows\system32\LogFiles
2010-12-12 23:35:57 -------- d-----w- c:\windows\system32\SoftwareDistribution
2010-12-12 22:27:51 -------- d-sh--w- c:\documents and settings\dan werner\IECompatCache
2010-12-12 22:27:33 -------- d-sh--w- c:\documents and settings\dan werner\PrivacIE
2010-12-12 22:27:09 -------- d-sh--w- c:\documents and settings\dan werner\IETldCache
2010-12-12 22:24:31 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2010-12-12 22:23:45 -------- dc-h--w- c:\windows\ie8
2010-12-12 22:18:14 99176 ----a-w- c:\windows\system32\drivers\DRVMCDB.SYS
2010-12-12 22:18:14 92920 ----a-w- c:\windows\DLA.EXE
2010-12-12 22:18:14 56056 ----a-w- c:\windows\system32\DLAAPI_W.DLL
2010-12-12 22:18:14 51768 ----a-w- c:\windows\system32\drivers\DRVNDDM.SYS
2010-12-12 22:18:14 28120 ----a-w- c:\windows\system32\drivers\DLARTL_M.SYS
2010-12-12 22:18:14 12856 ----a-w- c:\windows\system32\drivers\DLACDBHM.SYS
2010-12-12 22:18:14 -------- d-----w- c:\windows\system32\DLA
2010-12-12 22:15:03 819200 ----a-w- c:\program files\windows media player\wmsetsdk.exe
2010-12-12 22:15:03 47616 ----a-w- c:\program files\windows media player\msoobci.dll
2010-12-12 22:14:45 -------- d-----w- c:\windows\RegisteredPackages
2010-12-12 22:14:18 -------- d-----w- c:\program files\common files\SureThing Shared
2010-12-12 22:13:43 -------- d-----w- c:\program files\common files\Sonic Shared
2010-12-12 22:13:04 -------- d-----w- c:\program files\Roxio
2010-12-12 22:06:04 28552 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
2010-12-12 22:06:04 28040 ----a-w- c:\windows\system32\mdimon.dll
2010-12-12 22:05:26 -------- d-----w- c:\program files\common files\L&H
2010-12-12 22:05:13 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-12-12 22:04:39 -------- d-----w- c:\windows\SHELLNEW
2010-12-12 21:56:24 21425 ----a-w- c:\windows\system32\drivers\AegisP.sys
2010-12-12 21:55:48 679936 ----a-w- c:\windows\system32\NETw4c32.dll
2010-12-12 21:55:48 2756608 ----a-w- c:\windows\system32\NETw4r32.dll
2010-12-12 21:55:48 2203520 ----a-w- c:\windows\system32\drivers\NETw4x32.sys
2010-12-12 21:34:59 -------- d-----w- c:\windows\system32\wbem\repository\FS
2010-12-12 21:34:59 -------- d-----w- c:\windows\system32\wbem\Repository
2010-12-12 21:34:19 -------- d-----w- c:\program files\Broadcom
2010-12-12 21:28:54 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2010-12-12 21:03:59 958464 ----a-w- c:\windows\system32\nvmobls.dll
2010-12-12 21:02:56 -------- d-----w- c:\docume~1\danwer~1\applic~1\Intel
2010-12-12 21:02:50 319488 ----a-w- c:\windows\system32\AegisI5Installer.exe
2010-12-12 21:01:16 45568 ----a-r- c:\windows\system32\drivers\bcm4sbxp.sys
==================== Find3M ====================
2010-11-18 18:12:44 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-06 00:26:58 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26:58 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26:58 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25:54 385024 ----a-w- c:\windows\system32\html.iec
2010-10-28 13:13:22 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25:00 1853312 ----a-w- c:\windows\system32\win32k.sys
============= FINISH: 7:56:40.85 ===============
My laptop is infected by a redirect virus, “Google Redirect” I presume. I’ve scanned using Norton 360, Malwarebytes, and SpyBot with no effect.
I’m connected to my Linksys router utilizing wifi only. The router is fed from a Time Warner cable modem.
I did a SpyBot scan and the results were negative.
DDS (Ver_10-12-12.02) - NTFSx86
Run by Dan Werner at 7:54:59.65 on Tue 12/21/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.60 [GMT -8:00]
AV: Norton 360 *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *Enabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Memeo\AutoBackupPro\MemeoBackgroundService.exe
C:\Program Files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
C:\Program Files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
C:\Program Files\ClickTray Calendar\ClickTray.exe
C:\Program Files\PdaNet for Android\PdaNetPC.exe
C:\Program Files\Seagate\Seagate Dashboard\MemeoDashboard.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Dan Werner\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\4.3.0.5\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\4.3.0.5\IPSBHO.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\4.3.0.5\coIEPlg.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [Seagate Dashboard] c:\program files\seagate\seagate dashboard\MemeoLauncher.exe --silent --no_ui
mRun: [Memeo Backup Premium] c:\program files\memeo\autobackuppro\MemeoLauncher2.exe --silent --no_ui
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\danwer~1\startm~1\programs\startup\clickt~1.lnk - c:\program files\clicktray calendar\ClickTray.exe
StartupFolder: c:\docume~1\danwer~1\startm~1\programs\startup\pdanet~1.lnk - c:\program files\pdanet for android\PdaNetPC.exe
StartupFolder: c:\docume~1\danwer~1\startm~1\programs\startup\seagat~1.lnk - c:\documents and settings\dan werner\application data\leadertech\powerregister\Seagate Product Registration.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\google~1.lnk - c:\program files\google\google calendar sync\GoogleCalendarSync.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\danwer~1\applic~1\mozilla\firefox\profiles\zp8eoqbx.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\coffplgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: AniWeather: {4176DFF4-4698-11DE-BEEB-45DA55D89593} - %profile%\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}
FF - Ext: Favicon Picker 2: {446c03e0-2c35-11db-a98b-0800200c9a66} - %profile%\extensions\{446c03e0-2c35-11db-a98b-0800200c9a66}
FF - Ext: NoRedirect: {c1970c0d-dbe6-4d91-804f-c9c0de643a57} - %profile%\extensions\{c1970c0d-dbe6-4d91-804f-c9c0de643a57}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Norton IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\IPSFFPlgn
FF - Ext: Norton Toolbar: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62} - c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\coFFPlgn
============= SERVICES / DRIVERS ===============
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0403000.005\symds.sys [2010-12-17 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0403000.005\symefa.sys [2010-12-17 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\bashdefs\20101123.003\BHDrvx86.sys [2010-11-23 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0403000.005\cchpx86.sys [2010-12-17 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0403000.005\ironx86.sys [2010-12-17 116784]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\memeo\autobackuppro\MemeoBackgroundService.exe [2010-4-22 25824]
R2 N360;Norton 360;c:\program files\norton 360\engine\4.3.0.5\ccsvchst.exe [2010-12-17 126392]
R2 SeagateDashboardService;Seagate Dashboard Service;c:\program files\seagate\seagate dashboard\SeagateDashboardService.exe [2010-4-30 14088]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-12-17 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20101217.001\IDSXpx86.sys [2010-12-20 341944]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20101221.002\NAVENG.SYS [2010-12-21 86008]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20101221.002\NAVEX15.SYS [2010-12-21 1360760]
R3 pneteth;PdaNet Broadband;c:\windows\system32\drivers\pneteth.sys [2010-12-13 13312]
S0 cerc6;cerc6; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-13 135664]
=============== Created Last 30 ================
2010-12-21 01:22:43 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-12-21 01:21:28 -------- d-----w- c:\docume~1\alluse~1\applic~1\Hitman Pro
2010-12-19 21:53:15 -------- d-----w- c:\docume~1\danwer~1\locals~1\applic~1\Identities
2010-12-18 22:39:17 -------- d-----w- C:\tmp
2010-12-18 22:39:07 -------- d-----w- C:\Cool RingTone Maker
2010-12-17 23:43:36 385024 ----a-w- c:\windows\system32\vbar332.dll
2010-12-17 23:43:35 -------- d-----w- c:\program files\VoptXP v7
2010-12-17 20:22:41 501888 ----a-w- c:\windows\system32\drivers\n360\0403000.005\cchpx86.sys
2010-12-17 20:22:41 43696 ----a-w- c:\windows\system32\drivers\n360\0403000.005\srtspx.sys
2010-12-17 20:22:41 361904 ----a-w- c:\windows\system32\drivers\n360\0403000.005\symtdi.sys
2010-12-17 20:22:41 339504 ----a-w- c:\windows\system32\drivers\n360\0403000.005\symtdiv.sys
2010-12-17 20:22:41 328752 ----a-r- c:\windows\system32\drivers\n360\0403000.005\symds.sys
2010-12-17 20:22:41 325680 ----a-w- c:\windows\system32\drivers\n360\0403000.005\srtsp.sys
2010-12-17 20:22:41 173104 ----a-w- c:\windows\system32\drivers\n360\0403000.005\symefa.sys
2010-12-17 20:22:41 116784 ----a-w- c:\windows\system32\drivers\n360\0403000.005\ironx86.sys
2010-12-17 20:22:01 -------- d-----w- c:\windows\system32\drivers\n360\0403000.005
2010-12-16 20:26:50 107368 ----a-r- c:\windows\system32\GEARAspi.dll
2010-12-16 20:26:21 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-12-16 20:26:21 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-12-16 20:26:20 -------- d-----w- c:\program files\Symantec
2010-12-16 20:25:07 -------- d-----w- c:\windows\system32\drivers\N360
2010-12-16 20:25:03 -------- d-----w- c:\program files\Norton 360
2010-12-16 20:17:45 -------- d-----w- c:\program files\NortonInstaller
2010-12-16 18:45:28 -------- d-----w- c:\docume~1\danwer~1\applic~1\Tific
2010-12-15 20:03:37 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-12-15 19:28:54 -------- d-----w- c:\program files\Garmin
2010-12-15 18:57:30 577 ----a-w- c:\windows\system32\gmsblist.dll
2010-12-15 18:57:06 -------- d-----w- c:\docume~1\danwer~1\locals~1\applic~1\Help
2010-12-15 18:54:59 -------- d-----w- c:\program files\GSAK
2010-12-15 01:26:53 -------- d-----w- c:\docume~1\danwer~1\locals~1\applic~1\WMTools Downloaded Files
2010-12-15 00:04:10 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-12-15 00:04:10 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-14 18:18:34 49152 ------w- c:\windows\system32\INETWH32.dll
2010-12-14 18:18:34 1089536 ------w- c:\windows\system32\ROBOEX32.DLL
2010-12-14 18:18:34 -------- d-----w- C:\Garmin
2010-12-14 04:56:03 -------- d-----w- c:\program files\HyperSnap-DX 4
2010-12-14 04:46:53 -------- d-----w- c:\program files\HyperSnap 6
2010-12-14 04:24:27 -------- d-----w- c:\program files\GlobalSCAPE
2010-12-14 04:24:07 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2010-12-14 04:24:07 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2010-12-14 04:24:07 225280 ----a-w- c:\program files\common files\installshield\iscript\iscript.dll
2010-12-14 04:24:07 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2010-12-14 04:24:06 614532 ------w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe
2010-12-14 04:20:11 -------- d-----w- c:\program files\common files\Vbox
2010-12-14 04:18:36 306688 ----a-w- c:\windows\IsUninst.exe
2010-12-14 04:15:19 -------- d-----w- c:\program files\ClickTray Calendar
2010-12-14 03:46:51 -------- d-----w- c:\program files\Auction Sentry
2010-12-14 03:46:32 -------- d-----w- c:\windows\Downloaded Installations
2010-12-14 03:33:38 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-12-14 03:33:38 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-12-14 03:22:46 286720 ----a-w- c:\windows\iun506.exe
2010-12-14 02:54:51 13312 ----a-w- c:\windows\system32\drivers\pneteth.sys
2010-12-14 02:47:32 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2010-12-14 02:47:00 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-12-14 02:47:00 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-12-14 02:44:41 581192 ----a-w- c:\windows\system32\WinUSBCoInstaller.dll
2010-12-14 02:44:41 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2010-12-14 02:44:40 -------- d-----w- c:\program files\PdaNet for Android
2010-12-14 01:07:48 37 ----a-w- c:\windows\system32\gr6rlzay.dll
2010-12-14 01:00:19 -------- d-----w- c:\docume~1\danwer~1\applic~1\GARMIN
2010-12-14 01:00:19 -------- d-----w- c:\docume~1\alluse~1\applic~1\GARMIN
2010-12-14 00:48:27 -------- d-----w- c:\windows\system32\XPSViewer
2010-12-14 00:48:00 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-12-14 00:47:42 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-12-14 00:47:42 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-12-14 00:47:42 597504 ------w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-12-14 00:47:42 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-12-14 00:47:42 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-12-14 00:47:42 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-12-14 00:47:42 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-12-14 00:47:42 117760 ------w- c:\windows\system32\prntvpt.dll
2010-12-14 00:47:42 -------- d-----w- C:\30af5d22e69d662677
2010-12-14 00:36:31 -------- d-----w- c:\docume~1\danwer~1\locals~1\applic~1\Google
2010-12-13 23:48:13 -------- d-----w- C:\gsak
2010-12-13 23:28:42 -------- d-----w- C:\e18a05fd45ecaad9b471
2010-12-13 23:28:08 -------- d-----w- C:\drivers
2010-12-13 20:23:38 -------- d-----w- C:\DJ's 2010
2010-12-13 20:23:26 -------- d-----w- C:\c653913046ee4a6c69ae8de1105fed
2010-12-13 17:24:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-13 17:24:43 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-13 17:24:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-13 17:16:05 -------- d-----w- c:\docume~1\danwer~1\applic~1\Malwarebytes
2010-12-13 17:15:57 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-12-13 17:04:46 -------- d-----w- c:\docume~1\alluse~1\applic~1\PCSettings
2010-12-13 17:01:33 -------- d-----w- c:\docume~1\alluse~1\applic~1\NortonInstaller
2010-12-13 16:41:05 -------- d-----w- c:\docume~1\danwer~1\locals~1\applic~1\Symantec
2010-12-13 03:07:04 -------- d-----w- c:\docume~1\alluse~1\applic~1\MemeoCommon
2010-12-13 01:54:55 -------- d-----w- c:\docume~1\alluse~1\applic~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2010-12-13 01:54:18 -------- d-----w- c:\docume~1\alluse~1\applic~1\Norton
2010-12-13 01:52:27 -------- d-----w- c:\docume~1\danwer~1\applic~1\Memeo
2010-12-13 01:52:14 -------- d-----w- c:\docume~1\danwer~1\applic~1\Seagate
2010-12-13 01:50:46 -------- d-----w- c:\program files\common files\Memeo
2010-12-13 01:50:39 -------- d-----w- c:\program files\Memeo
2010-12-13 01:50:35 -------- d-----w- c:\docume~1\danwer~1\locals~1\applic~1\temp
2010-12-13 01:48:06 -------- d-----w- c:\program files\Seagate
2010-12-13 01:27:54 -------- d-----w- c:\docume~1\danwer~1\locals~1\applic~1\Adobe
2010-12-13 01:12:59 -------- d-----w- c:\docume~1\alluse~1\applic~1\Symantec
2010-12-13 00:48:29 -------- d-----w- c:\program files\common files\Symantec Shared
2010-12-13 00:41:34 -------- d-----w- c:\docume~1\danwer~1\applic~1\Symantec
2010-12-13 00:00:56 -------- d-----w- c:\windows\ie8updates
2010-12-13 00:00:07 21504 ----a-w- c:\windows\system32\drivers\hidserv.dll
2010-12-12 23:56:50 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-12-12 23:52:49 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-12-12 23:52:49 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-12-12 23:52:48 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-12-12 23:52:48 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-12-12 23:52:48 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-12-12 23:52:47 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-12-12 23:52:45 11080704 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-12-12 23:52:30 2146304 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-12-12 23:52:29 2189952 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-12-12 23:52:28 2024448 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-12-12 23:50:24 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-12-12 23:50:24 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-12-12 23:48:35 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-12-12 23:46:26 -------- d-----w- c:\windows\system32\PreInstall
2010-12-12 23:46:24 -------- d--h--w- c:\windows\$hf_mig$
2010-12-12 23:37:02 -------- d-----w- c:\windows\system32\LogFiles
2010-12-12 23:35:57 -------- d-----w- c:\windows\system32\SoftwareDistribution
2010-12-12 22:27:51 -------- d-sh--w- c:\documents and settings\dan werner\IECompatCache
2010-12-12 22:27:33 -------- d-sh--w- c:\documents and settings\dan werner\PrivacIE
2010-12-12 22:27:09 -------- d-sh--w- c:\documents and settings\dan werner\IETldCache
2010-12-12 22:24:31 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2010-12-12 22:23:45 -------- dc-h--w- c:\windows\ie8
2010-12-12 22:18:14 99176 ----a-w- c:\windows\system32\drivers\DRVMCDB.SYS
2010-12-12 22:18:14 92920 ----a-w- c:\windows\DLA.EXE
2010-12-12 22:18:14 56056 ----a-w- c:\windows\system32\DLAAPI_W.DLL
2010-12-12 22:18:14 51768 ----a-w- c:\windows\system32\drivers\DRVNDDM.SYS
2010-12-12 22:18:14 28120 ----a-w- c:\windows\system32\drivers\DLARTL_M.SYS
2010-12-12 22:18:14 12856 ----a-w- c:\windows\system32\drivers\DLACDBHM.SYS
2010-12-12 22:18:14 -------- d-----w- c:\windows\system32\DLA
2010-12-12 22:15:03 819200 ----a-w- c:\program files\windows media player\wmsetsdk.exe
2010-12-12 22:15:03 47616 ----a-w- c:\program files\windows media player\msoobci.dll
2010-12-12 22:14:45 -------- d-----w- c:\windows\RegisteredPackages
2010-12-12 22:14:18 -------- d-----w- c:\program files\common files\SureThing Shared
2010-12-12 22:13:43 -------- d-----w- c:\program files\common files\Sonic Shared
2010-12-12 22:13:04 -------- d-----w- c:\program files\Roxio
2010-12-12 22:06:04 28552 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
2010-12-12 22:06:04 28040 ----a-w- c:\windows\system32\mdimon.dll
2010-12-12 22:05:26 -------- d-----w- c:\program files\common files\L&H
2010-12-12 22:05:13 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-12-12 22:04:39 -------- d-----w- c:\windows\SHELLNEW
2010-12-12 21:56:24 21425 ----a-w- c:\windows\system32\drivers\AegisP.sys
2010-12-12 21:55:48 679936 ----a-w- c:\windows\system32\NETw4c32.dll
2010-12-12 21:55:48 2756608 ----a-w- c:\windows\system32\NETw4r32.dll
2010-12-12 21:55:48 2203520 ----a-w- c:\windows\system32\drivers\NETw4x32.sys
2010-12-12 21:34:59 -------- d-----w- c:\windows\system32\wbem\repository\FS
2010-12-12 21:34:59 -------- d-----w- c:\windows\system32\wbem\Repository
2010-12-12 21:34:19 -------- d-----w- c:\program files\Broadcom
2010-12-12 21:28:54 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2010-12-12 21:03:59 958464 ----a-w- c:\windows\system32\nvmobls.dll
2010-12-12 21:02:56 -------- d-----w- c:\docume~1\danwer~1\applic~1\Intel
2010-12-12 21:02:50 319488 ----a-w- c:\windows\system32\AegisI5Installer.exe
2010-12-12 21:01:16 45568 ----a-r- c:\windows\system32\drivers\bcm4sbxp.sys
==================== Find3M ====================
2010-11-18 18:12:44 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-06 00:26:58 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26:58 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26:58 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25:54 385024 ----a-w- c:\windows\system32\html.iec
2010-10-28 13:13:22 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25:00 1853312 ----a-w- c:\windows\system32\win32k.sys
============= FINISH: 7:56:40.85 ===============