Larry Cunningham
New member
First, I want to thank Safer Networking; nearly two years ago I had a Virtumonde infection and was walked through to a solution by this crew.
Now, unfortunately, I have managed to contract virtumonde.sd (?) and need your help again.
I have read the preliminary information. Teatimer has been turned off and I have used ERUNT to back up my registry. System Restore is enabled. I have downloaded dds.scr but it has not been run yet. (How do I run it?)
My computer is running XP Pro with all service packs and security upgrades installed.
I'm all set to get started. Can you help me?
Thank you in advance,
Larry E. Cunningham
apologies, I downloaded dds.com and ran it after all.. Here is its log output:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Larry at 9:51:48.07 on Fri 06/18/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2471 [GMT -6:00]
AV: Norton 360 *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\Logi_MwX.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Larry\Application Data\GabPath\gabpath.exe
C:\Documents and Settings\Larry\Application Data\Microsoft\Windows\jnipmo.exe
C:\Program Files\Cloudmark\SpamNet\OE\snoe.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\quartusii9.1\quartus\bin\jtagserver.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
C:\_Program Files\Mozilla Firefox 3.5\firefox.exe
C:\Documents and Settings\Larry\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\Larry\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.stephaniemiller.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080606
uInternet Settings,ProxyOverride = 127.0.0.1
mWinlogon: UIHost=c:\documents and settings\all users\application data\tuneup software\tuneup utilities\winstyler\tu_logonui.exe
BHO: {0487695d-d8ef-4d89-ac67-2c32a6f77419} - c:\windows\system32\dgrpsetu32.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\4.2.0.12\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\4.2.0.12\IPSBHO.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\_program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: 94284d9c: {af046029-1398-9332-e871-6a2f848d88c3} - c:\windows\system32\dfrgsnap32.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\4.2.0.12\coIEPlg.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\_program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\_program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [GabPath] c:\documents and settings\larry\application data\gabpath\gabpath.exe
uRun: [SfKg6wIPuSp] c:\documents and settings\larry\application data\microsoft\windows\jnipmo.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [Logitech Utility] Logi_MwX.Exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\cloudm~1.lnk - c:\windows\installer\{5ab0a110-c60a-4037-b9a5-f772bc647367}\SC_1.ico
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpaiod~1.lnk - c:\program files\hewlett-packard\aio\hp officejet k series\bin\hpoorn07.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ultramon.lnk - c:\windows\installer\{83cccbdc-3a56-4f3b-89df-69386c3b7d62}\IcoUltraMon.ico
uPolicies-explorer: NoWinKeys = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\_progr~1\office~1\office11\EXCEL.EXE/3000
IE: View old version at &archives.org - c:\documents and settings\all users\application data\tuneup software\tuneup utilities\web\tuarch.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\_progr~1\office~1\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: intuit.com\ttlc
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} - file:///C:/Program%20Files/AutoCAD%20LT%202000i/AcDcToday.ocx
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {C6637286-300D-11D4-AE0A-0010830243BD} - file:///C:/Program%20Files/AutoCAD%20LT%202000i/InstFred.ocx
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F281A59C-7B65-11D3-8617-0010830243BD} - file:///C:/Program%20Files/AutoCAD%20LT%202000i/AcPreview.ocx
Notify: e45b1dc9957 - c:\windows\system32\dfrgsnap32.dll
Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
AppInit_DLLs: zcfnws.dll,c:\windows\system32\dfrgsnap32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\larry\applic~1\mozilla\firefox\profiles\z1dtubqb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1300293&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Newsgroup Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.stephaniemiller.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=en&q=
FF - component: c:\_program files\mozilla firefox 3.5\components\browserdirprovider.dll
FF - component: c:\_program files\mozilla firefox 3.5\components\brwsrcmp.dll
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\coffplgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\ipsffplgn\components\IPSFFPl.dll
FF - component: c:\documents and settings\larry\application data\mozilla\firefox\profiles\z1dtubqb.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\_program files\mozilla firefox 3.5\plugins\npnul32.dll
FF - plugin: c:\_program files\quicktime\plugins\npqtplugin.dll
FF - plugin: c:\_program files\quicktime\plugins\npqtplugin2.dll
FF - plugin: c:\_program files\quicktime\plugins\npqtplugin3.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: browser.urlbar.autoFill - true
FF - user.js: content.switch.threshold - 600000
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("ui.use_native_colors", true);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("svg.smil.enabled", false);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.formfill.debug", false);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("html5.enable", false);
c:\_program files\mozilla firefox 3.5\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\_program files\mozilla firefox 3.5\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\_program files\mozilla firefox 3.5\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\_program files\mozilla firefox 3.5\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\_program files\mozilla firefox 3.5\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0402000.00c\symds.sys [2010-5-20 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0402000.00c\symefa.sys [2010-5-20 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\bashdefs\20100522.001\BHDrvx86.sys [2010-5-22 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0402000.00c\cchpx86.sys [2010-5-20 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0402000.00c\ironx86.sys [2010-5-20 116784]
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\broadcom\asfipmon\AsfIpMon.exe [2007-6-20 79168]
R2 N360;Norton 360;c:\program files\norton 360\engine\4.2.0.12\ccsvchst.exe [2010-5-20 126392]
R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\nvidia corporation\performance drivers\nvPDsvc.exe [2008-12-11 3575808]
R2 UltraMonUtility;UltraMon Utility Driver;c:\program files\common files\realtime soft\ultramonmirrordrv\x32\UltraMonUtility.sys [2008-11-14 17184]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-6-9 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20100617.001\IDSXpx86.sys [2010-6-17 331640]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20100617.051\NAVENG.SYS [2010-6-18 85552]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20100617.051\NAVEX15.SYS [2010-6-18 1347504]
S2 gupdate1c99a29c2ed1eca;Google Update Service (gupdate1c99a29c2ed1eca);c:\program files\google\update\GoogleUpdate.exe [2009-2-28 133104]
S3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-6-9 18432]
S3 pmxps2m;PMXPS2M;c:\windows\system32\drivers\pmxps2m.sys [2008-6-11 16384]
S3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-6-9 14336]
S3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys --> c:\windows\system32\drivers\rt2870.sys [?]
S3 sprtlisten;SupportSoft Listener Service;c:\program files\common files\supportsoft\bin\sprtlisten.exe [2008-1-8 1213728]
S3 UltraMonMirror;UltraMonMirror;c:\windows\system32\drivers\ultramonmirror.sys --> c:\windows\system32\drivers\UltraMonMirror.sys [?]
============== File Associations ===============
.scr=ft000001
=============== Created Last 30 ================
2010-06-18 15:44:15 525824 ----a-w- C:\dds.scr
2010-06-18 15:26:51 365 --sha-w- c:\windows\system32\873155993
2010-06-18 14:45:14 817 ----a-w- c:\windows\system32\1683693001
2010-06-18 06:53:17 17 ----a-w- c:\windows\system32\34db1ace
2010-06-18 05:44:10 0 d-----w- c:\docume~1\larry\applic~1\LimeWire
2010-06-18 05:30:29 0 ---ha-w- c:\documents and settings\larry\skdbhyjzjr.tmp
2010-06-18 05:18:21 1908 ----a-w- c:\windows\GnuHashes.ini
2010-06-18 05:10:24 113 ----a-w- c:\windows\system32\sl1441455883
2010-06-18 05:10:24 0 d-sh--w- c:\windows\system32\SysWoW32
2010-06-18 05:10:09 203776 --sh--w- c:\windows\system32\unrar.exe
2010-06-18 05:10:09 0 d-----w- c:\windows\system32\1449753262
2010-06-18 05:09:44 320512 ----a-w- c:\windows\system32\dgrpsetu32.dll
2010-06-18 05:09:43 1097216 --sha-w- c:\windows\system32\49E2.tmp
2010-06-18 05:09:42 208896 ----a-w- c:\windows\system32\dfrgsnap32.dll
2010-06-18 05:05:46 0 d-----w- c:\docume~1\larry\applic~1\GabPath
2010-06-18 04:43:52 0 d-----w- c:\documents and settings\larry\Incomplete
2010-06-18 04:43:32 0 d-----w- c:\documents and settings\larry\Shared
2010-06-18 04:42:48 0 d-----w- c:\program files\360Share Pro
2010-06-09 19:52:16 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
==================== Find3M ====================
2010-05-24 21:25:58 298526 ----a-w- c:\windows\fonts\AdobeFnt07.lst
2010-05-21 16:13:34 9800 ----a-w- c:\windows\fonts\Blank__0.ttf
2010-05-21 16:13:34 509920 ----a-w- c:\windows\fonts\SEGOEUI.TTF
2010-05-21 16:13:34 134108 ----a-w- c:\windows\fonts\trebuc.ttf
2010-05-21 16:13:27 365264 ----a-w- c:\windows\fonts\Segoe UI .ttf
2010-05-21 16:13:27 12056 ----a-w- c:\windows\fonts\Blank.ttf
2010-05-12 03:01:58 3264 ----a-w- C:\drmHeader.bin
2010-05-05 13:30:57 173056 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe
2010-05-02 05:22:50 1851264 ------w- c:\windows\system32\win32k.sys
2010-05-02 05:22:50 1851264 ------w- c:\windows\system32\dllcache\win32k.sys
2010-04-29 21:52:46 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-04-29 21:52:46 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-04-29 21:52:46 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-04-29 21:52:46 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-04-29 21:39:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 21:39:26 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 05:30:08 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-20 05:30:08 285696 ------w- c:\windows\system32\dllcache\atmfd.dll
2010-04-06 10:52:46 2462720 ----a-w- c:\windows\system32\dllcache\WMVCore.dll
2009-09-13 06:53:40 382 ----a-w- c:\program files\Program Files.lnk
2009-01-10 01:39:48 525216 ----a-w- c:\program files\Norton360Setup.exe
2009-02-12 01:38:29 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009021120090212\index.dat
============= FINISH: 9:53:28.90 ===============
Now, unfortunately, I have managed to contract virtumonde.sd (?) and need your help again.
I have read the preliminary information. Teatimer has been turned off and I have used ERUNT to back up my registry. System Restore is enabled. I have downloaded dds.scr but it has not been run yet. (How do I run it?)
My computer is running XP Pro with all service packs and security upgrades installed.
I'm all set to get started. Can you help me?
Thank you in advance,
Larry E. Cunningham
apologies, I downloaded dds.com and ran it after all.. Here is its log output:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Larry at 9:51:48.07 on Fri 06/18/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2471 [GMT -6:00]
AV: Norton 360 *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\Logi_MwX.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Larry\Application Data\GabPath\gabpath.exe
C:\Documents and Settings\Larry\Application Data\Microsoft\Windows\jnipmo.exe
C:\Program Files\Cloudmark\SpamNet\OE\snoe.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\quartusii9.1\quartus\bin\jtagserver.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
C:\_Program Files\Mozilla Firefox 3.5\firefox.exe
C:\Documents and Settings\Larry\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\Larry\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.stephaniemiller.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080606
uInternet Settings,ProxyOverride = 127.0.0.1
mWinlogon: UIHost=c:\documents and settings\all users\application data\tuneup software\tuneup utilities\winstyler\tu_logonui.exe
BHO: {0487695d-d8ef-4d89-ac67-2c32a6f77419} - c:\windows\system32\dgrpsetu32.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\4.2.0.12\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\4.2.0.12\IPSBHO.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\_program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: 94284d9c: {af046029-1398-9332-e871-6a2f848d88c3} - c:\windows\system32\dfrgsnap32.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\4.2.0.12\coIEPlg.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\_program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\_program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [GabPath] c:\documents and settings\larry\application data\gabpath\gabpath.exe
uRun: [SfKg6wIPuSp] c:\documents and settings\larry\application data\microsoft\windows\jnipmo.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [Logitech Utility] Logi_MwX.Exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\cloudm~1.lnk - c:\windows\installer\{5ab0a110-c60a-4037-b9a5-f772bc647367}\SC_1.ico
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpaiod~1.lnk - c:\program files\hewlett-packard\aio\hp officejet k series\bin\hpoorn07.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ultramon.lnk - c:\windows\installer\{83cccbdc-3a56-4f3b-89df-69386c3b7d62}\IcoUltraMon.ico
uPolicies-explorer: NoWinKeys = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\_progr~1\office~1\office11\EXCEL.EXE/3000
IE: View old version at &archives.org - c:\documents and settings\all users\application data\tuneup software\tuneup utilities\web\tuarch.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\_progr~1\office~1\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: intuit.com\ttlc
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} - file:///C:/Program%20Files/AutoCAD%20LT%202000i/AcDcToday.ocx
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {C6637286-300D-11D4-AE0A-0010830243BD} - file:///C:/Program%20Files/AutoCAD%20LT%202000i/InstFred.ocx
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F281A59C-7B65-11D3-8617-0010830243BD} - file:///C:/Program%20Files/AutoCAD%20LT%202000i/AcPreview.ocx
Notify: e45b1dc9957 - c:\windows\system32\dfrgsnap32.dll
Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
AppInit_DLLs: zcfnws.dll,c:\windows\system32\dfrgsnap32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\larry\applic~1\mozilla\firefox\profiles\z1dtubqb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1300293&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Newsgroup Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.stephaniemiller.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=en&q=
FF - component: c:\_program files\mozilla firefox 3.5\components\browserdirprovider.dll
FF - component: c:\_program files\mozilla firefox 3.5\components\brwsrcmp.dll
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\coffplgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\ipsffplgn\components\IPSFFPl.dll
FF - component: c:\documents and settings\larry\application data\mozilla\firefox\profiles\z1dtubqb.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\_program files\mozilla firefox 3.5\plugins\npnul32.dll
FF - plugin: c:\_program files\quicktime\plugins\npqtplugin.dll
FF - plugin: c:\_program files\quicktime\plugins\npqtplugin2.dll
FF - plugin: c:\_program files\quicktime\plugins\npqtplugin3.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: browser.urlbar.autoFill - true
FF - user.js: content.switch.threshold - 600000
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("ui.use_native_colors", true);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("svg.smil.enabled", false);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.formfill.debug", false);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\_program files\mozilla firefox 3.5\greprefs\all.js - pref("html5.enable", false);
c:\_program files\mozilla firefox 3.5\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\_program files\mozilla firefox 3.5\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\_program files\mozilla firefox 3.5\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\_program files\mozilla firefox 3.5\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\_program files\mozilla firefox 3.5\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\_program files\mozilla firefox 3.5\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0402000.00c\symds.sys [2010-5-20 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0402000.00c\symefa.sys [2010-5-20 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\bashdefs\20100522.001\BHDrvx86.sys [2010-5-22 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0402000.00c\cchpx86.sys [2010-5-20 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0402000.00c\ironx86.sys [2010-5-20 116784]
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\broadcom\asfipmon\AsfIpMon.exe [2007-6-20 79168]
R2 N360;Norton 360;c:\program files\norton 360\engine\4.2.0.12\ccsvchst.exe [2010-5-20 126392]
R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\nvidia corporation\performance drivers\nvPDsvc.exe [2008-12-11 3575808]
R2 UltraMonUtility;UltraMon Utility Driver;c:\program files\common files\realtime soft\ultramonmirrordrv\x32\UltraMonUtility.sys [2008-11-14 17184]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-6-9 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20100617.001\IDSXpx86.sys [2010-6-17 331640]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20100617.051\NAVENG.SYS [2010-6-18 85552]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20100617.051\NAVEX15.SYS [2010-6-18 1347504]
S2 gupdate1c99a29c2ed1eca;Google Update Service (gupdate1c99a29c2ed1eca);c:\program files\google\update\GoogleUpdate.exe [2009-2-28 133104]
S3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-6-9 18432]
S3 pmxps2m;PMXPS2M;c:\windows\system32\drivers\pmxps2m.sys [2008-6-11 16384]
S3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-6-9 14336]
S3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys --> c:\windows\system32\drivers\rt2870.sys [?]
S3 sprtlisten;SupportSoft Listener Service;c:\program files\common files\supportsoft\bin\sprtlisten.exe [2008-1-8 1213728]
S3 UltraMonMirror;UltraMonMirror;c:\windows\system32\drivers\ultramonmirror.sys --> c:\windows\system32\drivers\UltraMonMirror.sys [?]
============== File Associations ===============
.scr=ft000001
=============== Created Last 30 ================
2010-06-18 15:44:15 525824 ----a-w- C:\dds.scr
2010-06-18 15:26:51 365 --sha-w- c:\windows\system32\873155993
2010-06-18 14:45:14 817 ----a-w- c:\windows\system32\1683693001
2010-06-18 06:53:17 17 ----a-w- c:\windows\system32\34db1ace
2010-06-18 05:44:10 0 d-----w- c:\docume~1\larry\applic~1\LimeWire
2010-06-18 05:30:29 0 ---ha-w- c:\documents and settings\larry\skdbhyjzjr.tmp
2010-06-18 05:18:21 1908 ----a-w- c:\windows\GnuHashes.ini
2010-06-18 05:10:24 113 ----a-w- c:\windows\system32\sl1441455883
2010-06-18 05:10:24 0 d-sh--w- c:\windows\system32\SysWoW32
2010-06-18 05:10:09 203776 --sh--w- c:\windows\system32\unrar.exe
2010-06-18 05:10:09 0 d-----w- c:\windows\system32\1449753262
2010-06-18 05:09:44 320512 ----a-w- c:\windows\system32\dgrpsetu32.dll
2010-06-18 05:09:43 1097216 --sha-w- c:\windows\system32\49E2.tmp
2010-06-18 05:09:42 208896 ----a-w- c:\windows\system32\dfrgsnap32.dll
2010-06-18 05:05:46 0 d-----w- c:\docume~1\larry\applic~1\GabPath
2010-06-18 04:43:52 0 d-----w- c:\documents and settings\larry\Incomplete
2010-06-18 04:43:32 0 d-----w- c:\documents and settings\larry\Shared
2010-06-18 04:42:48 0 d-----w- c:\program files\360Share Pro
2010-06-09 19:52:16 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
==================== Find3M ====================
2010-05-24 21:25:58 298526 ----a-w- c:\windows\fonts\AdobeFnt07.lst
2010-05-21 16:13:34 9800 ----a-w- c:\windows\fonts\Blank__0.ttf
2010-05-21 16:13:34 509920 ----a-w- c:\windows\fonts\SEGOEUI.TTF
2010-05-21 16:13:34 134108 ----a-w- c:\windows\fonts\trebuc.ttf
2010-05-21 16:13:27 365264 ----a-w- c:\windows\fonts\Segoe UI .ttf
2010-05-21 16:13:27 12056 ----a-w- c:\windows\fonts\Blank.ttf
2010-05-12 03:01:58 3264 ----a-w- C:\drmHeader.bin
2010-05-05 13:30:57 173056 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe
2010-05-02 05:22:50 1851264 ------w- c:\windows\system32\win32k.sys
2010-05-02 05:22:50 1851264 ------w- c:\windows\system32\dllcache\win32k.sys
2010-04-29 21:52:46 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-04-29 21:52:46 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-04-29 21:52:46 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-04-29 21:52:46 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-04-29 21:39:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 21:39:26 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 05:30:08 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-20 05:30:08 285696 ------w- c:\windows\system32\dllcache\atmfd.dll
2010-04-06 10:52:46 2462720 ----a-w- c:\windows\system32\dllcache\WMVCore.dll
2009-09-13 06:53:40 382 ----a-w- c:\program files\Program Files.lnk
2009-01-10 01:39:48 525216 ----a-w- c:\program files\Norton360Setup.exe
2009-02-12 01:38:29 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009021120090212\index.dat
============= FINISH: 9:53:28.90 ===============