I have iexplorer.exe and Trojan:JS/Medfos.B malware infecting my computer specifically in a guest account. The iexplorer.exe is visible in the task manager even if no IE9 is running. I hear weird sound clips play off and on and it takes a lot of ram. I also have several system32/rundll files that I find running in the task manager that are not normal. I am able to stop the process but they start back up on their own.
The Trojan:JS/Medfos.B, which I don't know if it's related to the iexplore.exe or not, is found by Microsoft security essentials. I remove it but it keeps either replicating or somehow coming back and is found again.
I took matters into my own hands and ran several other virus scanners in safemode without networking. spybot s&d, hitman and malwarebytes with found several items at first but nothing after that. I ran them again after restarting and still had problems so here I am.
I ran the gmer file even though my pc is 64bit because it has 32 bit also.
I notice the dds.txt file says I have Vista but I am running Windows 7 Ultimate
I do have the Windows 7 disk I used to upgrade from Vista.
DDS (Ver_10-03-17.01) - NTFSX64
Run by BH at 21:58:30.17 on Mon 10/04/2010
Internet Explorer: 8.0.6001.18943
Microsoft® Windows Vista Home Premium 6.0.6002.2.1252.1.1033.18.3965.1475 [GMT -7:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files (x86)\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\splwow64.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\explorer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\BH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q726SXW9\dds[1].scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
mLocal Page = c:\windows\syswow64\blank.htm
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Microsoft.Search.HRSToolBar.InitToolbarBHO: {1d970ed5-3eda-438d-bffd-715931e2775d} - mscoree.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files (x86)\norton antivirus\engine\18.1.0.37\IPSBHO.DLL
TB: Bing HRS Toolbar: {c9a6357b-25cc-4bcf-96c1-78736985d414} - mscoree.dll
uRun: [WMPNSCFG] c:\program files (x86)\windows media player\WMPNSCFG.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~1\office12\REFIEBAR.DLL
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Hosts: 127.0.0.1 Spyware Info | Spyware Info | spyware software | spyware program | protection spyware
================= FIREFOX ===================
FF - ProfilePath - c:\users\bh\appdata\roaming\mozilla\firefox\profiles\rl1mjkbe.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?#!/?ref=home
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.1.0.19\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files (x86)\google\picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
---- FIREFOX POLICIES ----
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\navx64\1201000.025\SymDS64.sys [2010-9-27 450096]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\navx64\1201000.025\SymEFA64.sys [2010-9-27 821808]
R1 BHDrvx64;BHDrvx64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_18.1.0.37\definitions\bashdefs\20100901.003\BHDrvx64.sys [2010-8-31 954928]
R1 IDSVia64;IDSVia64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_18.1.0.37\definitions\ipsdefs\20101004.002\IDSviA64.sys [2010-10-4 463408]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\navx64\1201000.025\Ironx64.sys [2010-9-27 168496]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\navx64\1201000.025\symtdiv.sys [2010-9-27 436272]
R2 NAV;Norton AntiVirus;c:\program files (x86)\norton antivirus\engine\18.1.0.37\ccSvcHst.exe [2010-9-27 126904]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-10-4 132656]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-12-6 337920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS [2010-9-7 35840]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
S3 PerfHost;Performance Counter DLL Host;c:\windows\syswow64\perfhost.exe [2008-1-20 19968]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework64\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe [2009-12-7 89920]
============== File Associations ===============
JSEFile=c:\windows\syswow64\WScript.exe "%1" %*
=============== Created Last 30 ================
2010-10-05 02:18:50 0 d-----w- c:\program files (x86)\Microsoft Corporation
2010-10-05 01:56:09 0 d-----w- c:\program files (x86)\oZone3D
2010-10-04 21:03:45 612864 ----a-w- c:\windows\system32\vbscript.dll
2010-10-04 21:03:45 420352 ----a-w- c:\windows\syswow64\vbscript.dll
2010-10-04 21:03:44 726528 ----a-w- c:\windows\syswow64\jscript.dll
2010-10-01 02:55:37 0 d-----w- c:\users\bh\{3101fdec-c7e7-479f-9be6-d5777e56bcb9}
2010-10-01 01:59:08 2048 ----a-w- c:\windows\syswow64\tzres.dll
2010-10-01 01:59:08 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-27 15:20:07 854 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.INF
2010-09-27 15:20:07 7440 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.CAT
2010-09-27 15:20:07 174640 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2010-09-27 15:20:07 0 d-----w- c:\program files\Symantec
2010-09-27 15:20:07 0 d-----w- c:\program files\common files\Symantec Shared
2010-09-27 15:19:46 0 d-----w- c:\windows\system32\drivers\NAVx64
2010-09-27 15:19:45 0 d-----w- c:\program files (x86)\Norton AntiVirus
2010-09-27 15:19:39 0 d-----w- c:\program files (x86)\NortonInstaller
2010-09-27 14:44:05 0 d-----w- c:\programdata\Symantec
2010-09-24 23:00:09 24664 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-16 18:58:05 0 d-----w- c:\users\bh\Tracing
2010-09-16 15:08:48 317952 ----a-w- c:\windows\syswow64\MP4SDECD.DLL
2010-09-16 15:08:47 295424 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-09-16 15:08:47 273920 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-16 15:08:45 975360 ----a-w- c:\windows\system32\inetcomm.dll
2010-09-16 15:08:45 739328 ----a-w- c:\windows\syswow64\inetcomm.dll
2010-09-16 15:08:20 621568 ----a-w- c:\windows\system32\usp10.dll
2010-09-16 15:08:20 502272 ----a-w- c:\windows\syswow64\usp10.dll
2010-09-12 00:36:29 0 d-----w- c:\program files (x86)\SystemRequirementsLab
2010-09-12 00:29:17 0 d-----w- C:\NVIDIA
2010-09-10 14:17:16 0 d-----w- c:\programdata\NVIDIA Corporation
2010-09-07 23:42:55 35840 ----a-r- c:\windows\system32\drivers\BVRPMPR5a64.SYS
2010-09-07 23:41:52 0 d-----w- C:\Netgear
2010-09-07 23:15:07 0 d-----w- c:\users\bh\appdata\roaming\Tific
2010-09-07 22:27:04 0 d-----w- c:\programdata\Google
2010-09-07 15:29:02 0 d-----w- c:\users\bh\appdata\roaming\Malwarebytes
2010-09-07 15:01:23 0 d-----w- c:\programdata\Malwarebytes
2010-09-07 15:01:22 0 d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
==================== Find3M ====================
2010-10-04 22:09:13 55509 ----a-w- c:\programdata\nvModes.dat
2010-10-01 02:55:40 51200 ----a-w- c:\windows\inf\infpub.dat
2010-10-01 02:55:39 86016 ----a-w- c:\windows\inf\infstor.dat
2010-10-01 02:55:39 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-07-26 15:51:48 11584512 ----a-w- c:\windows\syswow64\shell32.dll
2010-07-09 23:27:02 159336 ----a-w- c:\windows\system32\nvvsvc.exe
2010-07-09 23:27:02 1585256 ----a-w- c:\windows\system32\nvsvc64.dll
2010-07-09 23:27:02 15314024 ----a-w- c:\windows\system32\nvcpl.dll
2010-07-09 23:27:02 116328 ----a-w- c:\windows\system32\nvmctray.dll
2009-12-09 11:15:32 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 03:21:59 174 --sha-w- c:\program files\desktop.ini
2008-01-21 03:21:59 174 --sha-w- c:\program files (x86)\desktop.ini
2006-11-02 15:14:56 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 15:14:56 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 15:14:56 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 15:14:56 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 10:52:12 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:52:12 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:52:10 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:52:10 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2010-05-04 20:52:07 16384 --sha-w- c:\windows\system32\migwiz\%appdata%\microsoft\windows\ietldcache\index.dat
2008-01-21 02:47:31 400896 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6001.18000_none_4d76c90c0812a431\WinMail.exe
2008-01-21 02:47:31 400896 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6002.18005_none_4f62421805346f7d\WinMail.exe
============= FINISH: 21:59:02.17 ===============
The Trojan:JS/Medfos.B, which I don't know if it's related to the iexplore.exe or not, is found by Microsoft security essentials. I remove it but it keeps either replicating or somehow coming back and is found again.
I took matters into my own hands and ran several other virus scanners in safemode without networking. spybot s&d, hitman and malwarebytes with found several items at first but nothing after that. I ran them again after restarting and still had problems so here I am.
I ran the gmer file even though my pc is 64bit because it has 32 bit also.
I notice the dds.txt file says I have Vista but I am running Windows 7 Ultimate
I do have the Windows 7 disk I used to upgrade from Vista.
DDS (Ver_10-03-17.01) - NTFSX64
Run by BH at 21:58:30.17 on Mon 10/04/2010
Internet Explorer: 8.0.6001.18943
Microsoft® Windows Vista Home Premium 6.0.6002.2.1252.1.1033.18.3965.1475 [GMT -7:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files (x86)\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\splwow64.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\explorer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\BH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q726SXW9\dds[1].scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
mLocal Page = c:\windows\syswow64\blank.htm
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Microsoft.Search.HRSToolBar.InitToolbarBHO: {1d970ed5-3eda-438d-bffd-715931e2775d} - mscoree.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files (x86)\norton antivirus\engine\18.1.0.37\IPSBHO.DLL
TB: Bing HRS Toolbar: {c9a6357b-25cc-4bcf-96c1-78736985d414} - mscoree.dll
uRun: [WMPNSCFG] c:\program files (x86)\windows media player\WMPNSCFG.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~1\office12\REFIEBAR.DLL
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Hosts: 127.0.0.1 Spyware Info | Spyware Info | spyware software | spyware program | protection spyware
================= FIREFOX ===================
FF - ProfilePath - c:\users\bh\appdata\roaming\mozilla\firefox\profiles\rl1mjkbe.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?#!/?ref=home
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.1.0.19\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files (x86)\google\picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
---- FIREFOX POLICIES ----
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\navx64\1201000.025\SymDS64.sys [2010-9-27 450096]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\navx64\1201000.025\SymEFA64.sys [2010-9-27 821808]
R1 BHDrvx64;BHDrvx64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_18.1.0.37\definitions\bashdefs\20100901.003\BHDrvx64.sys [2010-8-31 954928]
R1 IDSVia64;IDSVia64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_18.1.0.37\definitions\ipsdefs\20101004.002\IDSviA64.sys [2010-10-4 463408]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\navx64\1201000.025\Ironx64.sys [2010-9-27 168496]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\navx64\1201000.025\symtdiv.sys [2010-9-27 436272]
R2 NAV;Norton AntiVirus;c:\program files (x86)\norton antivirus\engine\18.1.0.37\ccSvcHst.exe [2010-9-27 126904]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-10-4 132656]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-12-6 337920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS [2010-9-7 35840]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
S3 PerfHost;Performance Counter DLL Host;c:\windows\syswow64\perfhost.exe [2008-1-20 19968]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework64\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe [2009-12-7 89920]
============== File Associations ===============
JSEFile=c:\windows\syswow64\WScript.exe "%1" %*
=============== Created Last 30 ================
2010-10-05 02:18:50 0 d-----w- c:\program files (x86)\Microsoft Corporation
2010-10-05 01:56:09 0 d-----w- c:\program files (x86)\oZone3D
2010-10-04 21:03:45 612864 ----a-w- c:\windows\system32\vbscript.dll
2010-10-04 21:03:45 420352 ----a-w- c:\windows\syswow64\vbscript.dll
2010-10-04 21:03:44 726528 ----a-w- c:\windows\syswow64\jscript.dll
2010-10-01 02:55:37 0 d-----w- c:\users\bh\{3101fdec-c7e7-479f-9be6-d5777e56bcb9}
2010-10-01 01:59:08 2048 ----a-w- c:\windows\syswow64\tzres.dll
2010-10-01 01:59:08 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-27 15:20:07 854 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.INF
2010-09-27 15:20:07 7440 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.CAT
2010-09-27 15:20:07 174640 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2010-09-27 15:20:07 0 d-----w- c:\program files\Symantec
2010-09-27 15:20:07 0 d-----w- c:\program files\common files\Symantec Shared
2010-09-27 15:19:46 0 d-----w- c:\windows\system32\drivers\NAVx64
2010-09-27 15:19:45 0 d-----w- c:\program files (x86)\Norton AntiVirus
2010-09-27 15:19:39 0 d-----w- c:\program files (x86)\NortonInstaller
2010-09-27 14:44:05 0 d-----w- c:\programdata\Symantec
2010-09-24 23:00:09 24664 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-16 18:58:05 0 d-----w- c:\users\bh\Tracing
2010-09-16 15:08:48 317952 ----a-w- c:\windows\syswow64\MP4SDECD.DLL
2010-09-16 15:08:47 295424 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-09-16 15:08:47 273920 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-16 15:08:45 975360 ----a-w- c:\windows\system32\inetcomm.dll
2010-09-16 15:08:45 739328 ----a-w- c:\windows\syswow64\inetcomm.dll
2010-09-16 15:08:20 621568 ----a-w- c:\windows\system32\usp10.dll
2010-09-16 15:08:20 502272 ----a-w- c:\windows\syswow64\usp10.dll
2010-09-12 00:36:29 0 d-----w- c:\program files (x86)\SystemRequirementsLab
2010-09-12 00:29:17 0 d-----w- C:\NVIDIA
2010-09-10 14:17:16 0 d-----w- c:\programdata\NVIDIA Corporation
2010-09-07 23:42:55 35840 ----a-r- c:\windows\system32\drivers\BVRPMPR5a64.SYS
2010-09-07 23:41:52 0 d-----w- C:\Netgear
2010-09-07 23:15:07 0 d-----w- c:\users\bh\appdata\roaming\Tific
2010-09-07 22:27:04 0 d-----w- c:\programdata\Google
2010-09-07 15:29:02 0 d-----w- c:\users\bh\appdata\roaming\Malwarebytes
2010-09-07 15:01:23 0 d-----w- c:\programdata\Malwarebytes
2010-09-07 15:01:22 0 d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
==================== Find3M ====================
2010-10-04 22:09:13 55509 ----a-w- c:\programdata\nvModes.dat
2010-10-01 02:55:40 51200 ----a-w- c:\windows\inf\infpub.dat
2010-10-01 02:55:39 86016 ----a-w- c:\windows\inf\infstor.dat
2010-10-01 02:55:39 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-07-26 15:51:48 11584512 ----a-w- c:\windows\syswow64\shell32.dll
2010-07-09 23:27:02 159336 ----a-w- c:\windows\system32\nvvsvc.exe
2010-07-09 23:27:02 1585256 ----a-w- c:\windows\system32\nvsvc64.dll
2010-07-09 23:27:02 15314024 ----a-w- c:\windows\system32\nvcpl.dll
2010-07-09 23:27:02 116328 ----a-w- c:\windows\system32\nvmctray.dll
2009-12-09 11:15:32 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 03:21:59 174 --sha-w- c:\program files\desktop.ini
2008-01-21 03:21:59 174 --sha-w- c:\program files (x86)\desktop.ini
2006-11-02 15:14:56 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 15:14:56 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 15:14:56 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 15:14:56 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 10:52:12 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:52:12 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:52:10 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:52:10 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2010-05-04 20:52:07 16384 --sha-w- c:\windows\system32\migwiz\%appdata%\microsoft\windows\ietldcache\index.dat
2008-01-21 02:47:31 400896 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6001.18000_none_4d76c90c0812a431\WinMail.exe
2008-01-21 02:47:31 400896 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6002.18005_none_4f62421805346f7d\WinMail.exe
============= FINISH: 21:59:02.17 ===============