Results 1 to 7 of 7

Thread: Norton constantly says it has stopped trojan.zeroaccess

  1. #1
    Join Date
    Jun 2012
    Posts
    4

    Norton constantly says it has stopped trojan.zeroaccess

    Here is my DDS text and Attach.txt
    Thank you.

    .
    DDS (Ver_2011-08-26.01) - NTFSAMD64
    Internet Explorer: 9.0.8112.16421
    Run by User at 11:36:00 on 2012-06-14
    Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.16301.12324 [GMT -4:00]
    .
    AV: ESET NOD32 Antivirus 5.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
    SP: ESET NOD32 Antivirus 5.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\atieclxx.exe
    C:\Windows\System32\spoolsv.exe
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyS ervice.exe
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\Workspace\offSyncService.exe
    C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files (x86)\Norton Security Suite\Engine\6.2.1.5\ccSvcHst.exe
    C:\Program Files (x86)\Splashtop\Splashtop Connect\BackService.exe
    C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe
    C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe
    C:\Program Files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe
    C:\Program Files (x86)\X-Rite\Devices\Services\xritedeviced.exe
    C:\Program Files (x86)\X-Rite\Devices\Services\ColorMunki\ColorMunkiDeviceS ervice.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\taskhost.exe
    C:\Program Files (x86)\Norton Security Suite\Engine\6.2.1.5\ccSvcHst.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\GIGABYTE\SMART6\Recovery\RPMDaemon.exe
    C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files (x86)\Workspace\workspaceupdate.exe
    C:\Program Files\MysticCoder\MysticThumbs\MysticThumbs.exe
    C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpy. exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files (x86)\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    C:\Windows\sysWOW64\wbem\wmiprvse.exe
    C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
    C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe
    C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files (x86)\Nero\Update\NASvc.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\AlarmClock.exe
    C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Splashtop\Splashtop Connect IE\STCHelper.exe
    C:\Program Files (x86)\Task Timer\Task Timer.exe
    C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\Photoshop.exe
    C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.ex e
    C:\Program Files (x86)\Adobe\Adobe InDesign CS6\InDesign.exe
    C:\Program Files (x86)\Adobe\Adobe InDesign CS6\Utilities\adb.exe
    C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.com/
    mWinlogon: Userinit=userinit.exe,
    BHO: Splashtop Connect VisualBookmark: {0e5680d1-bf44-4929-94af-fd30d784ad1d} - C:\Program Files (x86)\Splashtop\Splashtop Connect IE\STC.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Security Suite\Engine\6.2.1.5\coIEPlg.dll
    BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Security Suite\Engine\6.2.1.5\IPS\IPSBHO.DLL
    BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Security Suite\Engine\6.2.1.5\coIEPlg.dll
    {e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
    uRun: [Starfield Updater] "C:\Program Files (x86)\Workspace\WorkspaceUpdate.exe"
    uRun: [MysticThumbs] C:\Program Files\MysticCoder\MysticThumbs\MysticThumbs.exe
    uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    uRun: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    uRun: [Google Update] "C:\Users\User\AppData\Local\Google\Update\GoogleU pdate.exe" /c
    uRun: [ComcastAntispyClient] "C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntispy. exe" /hide
    uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    uRun: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
    mRun: [<NO NAME>]
    mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun: [STCAgent] "C:\Program Files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe"
    mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
    mRun: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
    mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
    mRun: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.ex e" -launchedbylogin
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
    mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
    mRun: [ZyngaGamesAgent] "C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe"
    StartupFolder: C:\Users\User\AppData\Roaming\MICROS~1\Windows\STA RTM~1\Programs\Startup\MAPBAT~1.LNK - C:\archived\map.bat
    StartupFolder: C:\Users\User\AppData\Roaming\MICROS~1\Windows\STA RTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Sta rtup\COLORM~2.LNK - C:\Program Files (x86)\X-Rite\ColorMunki Photo\Gamma\CalibrationLoader.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Sta rtup\COLORM~1.LNK - C:\Program Files (x86)\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe
    uPolicies-explorer: HideSCAHealth = 1 (0x1)
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
    IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    IE: Open Client to monitor &1 - C:\Windows\web\AOpenClient.htm
    IE: Open Client to monitor &2 - C:\Windows\web\AOpenClient.htm
    IE: {36ECAF82-3300-8F84-092E-AFF36D6C7040} - {86529161-034E-4F8A-88D2-3C625E612E04} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
    TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
    TCP: Interfaces\{FBBA00C2-02D4-4726-ACE0-F9A8F4DD00AB} : DhcpNameServer = 75.75.75.75 75.75.76.76
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
    BHO-X64: Splashtop Connect VisualBookmark: {0E5680D1-BF44-4929-94AF-FD30D784AD1D} - C:\Program Files (x86)\Splashtop\Splashtop Connect IE\STC.dll
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\6.2.1.5\coIEPlg.dll
    BHO-X64: Norton Identity Protection - No File
    BHO-X64: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\6.2.1.5\IPS\IPSBHO.DLL
    BHO-X64: Norton Vulnerability Protection - No File
    BHO-X64: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO-X64: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    BHO-X64: SmartSelect - No File
    TB-X64: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\6.2.1.5\coIEPlg.dll
    mRun-x64: [(Default)]
    mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun-x64: [STCAgent] "C:\Program Files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe"
    mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun-x64: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
    mRun-x64: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
    mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    mRun-x64: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
    mRun-x64: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.ex e" -launchedbylogin
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun-x64: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
    mRun-x64: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
    mRun-x64: [ZyngaGamesAgent] "C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe"
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Prof iles\r5mhjqg9.default\
    FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
    FF - plugin: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll
    FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
    FF - plugin: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDet ect32.dll
    FF - plugin: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDet ect64.dll
    FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrlui.dll
    FF - plugin: C:\Users\User\AppData\Local\Google\Update\1.3.21.1 11\npGoogleUpdate3.dll
    FF - plugin: C:\Users\User\AppData\Roaming\Mozilla\Plugins\npof f.dll
    FF - plugin: C:\Users\User\AppData\Roaming\Mozilla\plugins\npof f.dll
    FF - plugin: C:\Users\User\AppData\Roaming\Mozilla\plugins\npof f64.dll
    FF - plugin: C:\Users\User\AppData\Roaming\Mozilla\Plugins\npof f64.dll
    FF - plugin: C:\Users\User\AppData\Roaming\Mozilla\Plugins\npwb e.dll
    FF - plugin: C:\Users\User\AppData\Roaming\Mozilla\plugins\npwb e.dll
    FF - plugin: C:\Users\User\AppData\Roaming\Mozilla\plugins\npwb e64.dll
    FF - plugin: C:\Users\User\AppData\Roaming\Mozilla\Plugins\npwb e64.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_20 2_235.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHl pa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
    R0 SymDS;Symantec Data Store;C:\Windows\system32\drivers\N360x64\0602010. 005\SYMDS64.SYS --> C:\Windows\system32\drivers\N360x64\0602010.005\SY MDS64.SYS [?]
    R0 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\N360x64\060 2010.005\SYMEFA64.SYS --> C:\Windows\system32\drivers\N360x64\0602010.005\SY MEFA64.SYS [?]
    R1 AppleCharger;AppleCharger;C:\Windows\system32\DRIV ERS\AppleCharger.sys --> C:\Windows\system32\DRIVERS\AppleCharger.sys [?]
    R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\ 20120531.001\BHDrvx64.sys [2012-5-31 1160824]
    R1 ccSet_N360;Norton Security Suite Settings Manager;C:\Windows\system32\drivers\N360x64\060201 0.005\ccSetx64.sys --> C:\Windows\system32\drivers\N360x64\0602010.005\cc Setx64.sys [?]
    R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\2 0120613.007\IDSviA64.sys [2012-6-13 488568]
    R1 SymIRON;Symantec Iron Driver;C:\Windows\system32\drivers\N360x64\0602010 .005\Ironx64.SYS --> C:\Windows\system32\drivers\N360x64\0602010.005\Ir onx64.SYS [?]
    R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\system32\Drivers\N360x64\0602010 .005\SYMNETS.SYS --> C:\Windows\system32\Drivers\N360x64\0602010.005\SY MNETS.SYS [?]
    R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
    R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
    R2 AntiSpywareService;Comcast AntiSpyware;C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyS ervice.exe [2009-6-17 616408]
    R2 ColorMunkiService;X-Rite Device ColorMunki;C:\Program Files (x86)\X-Rite\Devices\Services\ColorMunki\ColorMunkiDeviceS ervice.exe [2012-2-21 147968]
    R2 File Backup;File Backup Service;C:\Program Files (x86)\Workspace\offSyncService.exe [2012-2-21 1168680]
    R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-2-2 13592]
    R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-6-8 654408]
    R2 N360;Norton Security Suite;C:\Program Files (x86)\Norton Security Suite\Engine\6.2.1.5\ccsvchst.exe [2012-6-11 138232]
    R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400]
    R2 SCBackService;Splashtop Connect Service;C:\Program Files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000]
    R2 Smart TimeLock;Smart TimeLock Service;C:\Program Files (x86)\GIGABYTE\smart6\timelock\TimeMgmtDaemon.exe [2012-2-2 114688]
    R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-2-2 2655768]
    R2 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;C:\Program Files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-3-24 493384]
    R2 WCUService_STC_IE;Splashtop Connect IE Software Updater Service;C:\Program Files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [2011-3-22 497480]
    R2 xritedeviced;X-Rite Device Manager;C:\Program Files (x86)\X-Rite\Devices\Services\xritedeviced.exe [2012-2-21 130048]
    R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atik mdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
    R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atik mpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
    R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-6-11 138912]
    R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:\Windows\system32\Drivers\EtronHub3.sys --> C:\Windows\system32\Drivers\EtronHub3.sys [?]
    R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:\Windows\system32\Drivers\EtronXHCI.sys --> C:\Windows\system32\Drivers\EtronXHCI.sys [?]
    R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
    R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system3 2\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
    R3 MEIx64;Intel(R) Management Engine Interface ;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\ v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework6 4\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPl ayerUpdateService.exe [2012-4-19 257696]
    S3 colormunki;colormunki;C:\Windows\system32\Drivers\ colormunki_x64.sys --> C:\Windows\system32\Drivers\colormunki_x64.sys [?]
    S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
    S3 GVTDrv64;GVTDrv64;C:\Windows\GVTDrv64.sys [2012-2-2 30528]
    S3 mbamchameleon;mbamchameleon;\??\C:\Windows\system3 2\drivers\mbamchameleon.sys --> C:\Windows\system32\drivers\mbamchameleon.sys [?]
    S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-4-30 129976]
    S3 MSSQL$SONY_MEDIAMGR2;SQL Server (SONY_MEDIAMGR2);C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2007-2-10 29178224]
    S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
    S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsus bflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
    S4 AppleChargerSrv;AppleChargerSrv;system32\AppleChar gerSrv.exe --> system32\AppleChargerSrv.exe [?]
    .
    =============== Created Last 30 ================
    .
    2012-06-13 12:14:36 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
    2012-06-12 14:04:02 -------- d-----w- C:\Users\User\AppData\Local\NPE
    2012-06-11 21:00:22 -------- d-----w- C:\TDSSKiller_Quarantine
    2012-06-11 18:30:29 388096 ----a-r- C:\Users\User\AppData\Roaming\Microsoft\Installer\ {45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
    2012-06-11 18:30:29 -------- d-----w- C:\Program Files (x86)\Trend Micro
    2012-06-11 17:21:34 27256 ----a-w- C:\Windows\System32\drivers\FixZeroAccess.sys
    2012-06-11 13:12:14 737912 ----a-w- C:\Windows\System32\drivers\N360x64\0602010.005\sr tsp64.sys
    2012-06-11 13:12:14 451192 ----a-r- C:\Windows\System32\drivers\N360x64\0602010.005\sy mds64.sys
    2012-06-11 13:12:14 405624 ----a-r- C:\Windows\System32\drivers\N360x64\0602010.005\sy mnets.sys
    2012-06-11 13:12:14 37496 ----a-w- C:\Windows\System32\drivers\N360x64\0602010.005\sr tspx64.sys
    2012-06-11 13:12:14 190072 ----a-r- C:\Windows\System32\drivers\N360x64\0602010.005\ir onx64.sys
    2012-06-11 13:12:14 167048 ----a-r- C:\Windows\System32\drivers\N360x64\0602010.005\cc setx64.sys
    2012-06-11 13:12:14 1092728 ----a-r- C:\Windows\System32\drivers\N360x64\0602010.005\sy mefa64.sys
    2012-06-11 13:12:11 -------- d-----w- C:\Windows\System32\drivers\N360x64\0602010.005
    2012-06-11 13:08:05 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
    2012-06-11 13:02:02 175736 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
    2012-06-11 13:02:02 -------- d-----w- C:\Program Files\Symantec
    2012-06-11 13:02:02 -------- d-----w- C:\Program Files\Common Files\Symantec Shared
    2012-06-11 13:01:56 -------- d-----w- C:\Windows\System32\drivers\N360x64
    2012-06-11 13:01:55 -------- d-----w- C:\Program Files (x86)\Norton Security Suite
    2012-06-11 13:01:50 -------- d-----w- C:\Program Files (x86)\NortonInstaller
    2012-06-11 12:56:04 -------- d-----w- C:\Program Files (x86)\Constant Guard Protection Suite
    2012-06-08 20:59:05 -------- d-----w- C:\Users\User\AppData\Roaming\Wise Registry Cleaner
    2012-06-08 20:58:23 -------- d-----w- C:\Program Files (x86)\Wise
    2012-06-08 20:42:15 -------- d-----w- C:\Program Files (x86)\AVG
    2012-06-08 20:39:33 -------- d--h--w- C:\ProgramData\Common Files
    2012-06-08 20:39:19 -------- d-----w- C:\ProgramData\MFAData
    2012-06-08 20:35:48 33096 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
    2012-06-08 20:18:25 -------- d-----w- C:\Users\User\AppData\Roaming\Malwarebytes
    2012-06-08 20:18:21 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2012-06-08 20:18:21 -------- d-----w- C:\ProgramData\Malwarebytes
    2012-06-08 20:18:21 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-06-08 19:34:26 -------- d-----w- C:\Windows\pss
    2012-06-08 19:20:51 -------- d-sh--w- C:\Windows\System32\%APPDATA%
    2012-06-08 19:17:34 -------- d-----w- C:\Users\User\AppData\Local\{A11BB931-B19E-11E1-8270-B8AC6F996F26}
    2012-06-08 19:17:33 -------- d-----w- C:\Users\User\AppData\Local\{A11B8120-B19E-11E1-8270-B8AC6F996F26}
    2012-06-08 19:16:52 -------- d-----w- C:\ProgramData\99058D9B000083BB0004264BB4EB2331
    2012-06-08 19:16:50 -------- d-----w- C:\Users\User\AppData\Local\ESET
    2012-06-08 16:10:00 -------- d-----w- C:\Program Files (x86)\AMD APP
    2012-06-08 12:04:46 8955792 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45BA0100-9539-4512-9D1E-E37DAD0F9CDF}\mpengine.dll
    2012-06-01 14:47:59 -------- d-----w- C:\Program Files (x86)\Adobe Muse
    2012-06-01 14:28:46 -------- d-----w- C:\New folder
    2012-05-30 14:43:53 -------- d-----w- C:\Program Files\MysticCoder
    2012-05-25 21:50:58 -------- d-----w- C:\Users\User\AppData\Roaming\PACE Anti-Piracy
    2012-05-25 21:50:58 -------- d-----w- C:\Users\User\AppData\Local\PACE Anti-Piracy
    2012-05-25 21:50:58 -------- d-----w- C:\ProgramData\PACE Anti-Piracy
    2012-05-25 21:50:58 -------- d-----w- C:\Program Files\Common Files\PACE Anti-Piracy
    2012-05-24 11:39:15 -------- d-----w- C:\Program Files (x86)\VS Revo Group
    2012-05-24 01:54:26 -------- d-----w- C:\Users\User\Adobe Flash Builder 4.6
    2012-05-23 03:15:36 10248704 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
    2012-05-23 02:43:24 20467200 ----a-w- C:\Windows\SysWow64\atioglxx.dll
    2012-05-23 02:28:36 187392 ----a-w- C:\Windows\System32\clinfo.exe
    2012-05-23 02:28:20 75264 ----a-w- C:\Windows\System32\OpenVideo64.dll
    2012-05-23 02:28:14 65024 ----a-w- C:\Windows\SysWow64\OpenVideo.dll
    2012-05-23 02:28:08 63488 ----a-w- C:\Windows\System32\OVDecode64.dll
    2012-05-23 02:28:04 56320 ----a-w- C:\Windows\SysWow64\OVDecode.dll
    2012-05-23 0256 16457728 ----a-w- C:\Windows\System32\amdocl64.dll
    2012-05-23 0210 13008896 ----a-w- C:\Windows\SysWow64\amdocl.dll
    2012-05-23 02:08:42 163840 ----a-w- C:\Windows\System32\atiapfxx.exe
    2012-05-23 02:03:22 532992 ----a-w- C:\Windows\System32\atieclxx.exe
    2012-05-23 02:02:36 239616 ----a-w- C:\Windows\System32\atiesrxx.exe
    2012-05-23 02:01:18 120320 ----a-w- C:\Windows\System32\atitmm64.dll
    2012-05-23 02:01:04 21504 ----a-w- C:\Windows\System32\atimuixx.dll
    2012-05-23 02:00:58 59392 ----a-w- C:\Windows\System32\atiedu64.dll
    2012-05-23 02:00:54 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
    2012-05-23 01:56:24 70144 ----a-w- C:\Windows\System32\coinst_8.98.dll
    2012-05-23 01:26:44 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
    2012-05-23 01:26:42 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
    2012-05-23 01:26:38 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
    2012-05-23 01:26:36 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
    2012-05-23 01:26:24 15703040 ----a-w- C:\Windows\System32\aticaldd64.dll
    2012-05-23 01:22:10 13277696 ----a-w- C:\Windows\SysWow64\aticaldd.dll
    2012-05-23 01:09:14 368640 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
    2012-05-23 01:08:58 14848 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
    2012-05-23 01:08:58 14848 ----a-w- C:\Windows\System32\atiglpxx.dll
    2012-05-23 01:08:48 33280 ----a-w- C:\Windows\SysWow64\atigktxx.dll
    2012-05-23 01:08:40 367616 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
    2012-05-23 01:06:54 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
    2012-05-23 01:05:22 56320 ----a-w- C:\Windows\System32\atimpc64.dll
    2012-05-23 01:05:22 56320 ----a-w- C:\Windows\System32\amdpcom64.dll
    2012-05-23 01:05:18 56832 ----a-w- C:\Windows\SysWow64\atimpc32.dll
    2012-05-23 01:05:18 56832 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
    2012-05-22 19:11:48 -------- d-----w- C:\My Web Sites
    2012-05-22 19:10:48 -------- d-----w- C:\Program Files\WinHTTrack
    .
    ==================== Find3M ====================
    .
    2012-06-14 12:00:03 25640 ----a-w- C:\Windows\gdrv.sys
    2012-05-23 03:11:56 24826368 ----a-w- C:\Windows\System32\atio6axx.dll
    2012-05-23 02:08:34 924160 ----a-w- C:\Windows\SysWow64\aticfx32.dll
    2012-05-23 02:06:46 1090560 ----a-w- C:\Windows\System32\aticfx64.dll
    2012-05-23 02:03:26 442368 ----a-w- C:\Windows\System32\ATIDEMGX.dll
    2012-05-23 02:00:12 6301184 ----a-w- C:\Windows\SysWow64\atidxx32.dll
    2012-05-23 01:44:48 6914560 ----a-w- C:\Windows\System32\atidxx64.dll
    2012-05-23 01:31:04 4246528 ----a-w- C:\Windows\System32\atiumd6a.dll
    2012-05-23 01:28:20 5480448 ----a-w- C:\Windows\SysWow64\atiumdag.dll
    2012-05-23 01:23:34 4729344 ----a-w- C:\Windows\SysWow64\atiumdva.dll
    2012-05-23 01:19:28 6605312 ----a-w- C:\Windows\System32\atiumd64.dll
    2012-05-23 01:09:24 539136 ----a-w- C:\Windows\System32\atiadlxx.dll
    2012-05-23 01:09:02 17920 ----a-w- C:\Windows\System32\atig6pxx.dll
    2012-05-23 01:08:54 41984 ----a-w- C:\Windows\System32\atig6txx.dll
    2012-05-23 01:07:48 54784 ----a-w- C:\Windows\System32\atiuxp64.dll
    2012-05-23 01:07:42 42496 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
    2012-05-23 01:07:36 45056 ----a-w- C:\Windows\System32\atiu9p64.dll
    2012-05-23 01:07:28 32768 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
    2012-05-18 02:06:48 2311680 ----a-w- C:\Windows\System32\jscript9.dll
    2012-05-18 01:59:14 1392128 ----a-w- C:\Windows\System32\wininet.dll
    2012-05-18 01:58:39 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
    2012-05-18 01:55:22 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
    2012-05-18 01:51:30 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
    2012-05-17 22:45:37 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll
    2012-05-17 22:35:47 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
    2012-05-17 22:35:39 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
    2012-05-17 22:29:45 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
    2012-05-17 22:24:45 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2012-05-15 01:32:33 3146752 ----a-w- C:\Windows\System32\win32k.sys
    2012-05-07 13:15:03 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-05-07 13:15:03 419488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
    2012-05-07 13:15:02 8744608 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
    2012-05-04 11:06:22 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll
    2012-04-28 03:55:21 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
    2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
    2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
    2012-04-24 05:37:37 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
    2012-04-24 05:37:37 140288 ----a-w- C:\Windows\System32\cryptnet.dll
    2012-04-24 05:37:36 1462272 ----a-w- C:\Windows\System32\crypt32.dll
    2012-04-24 04:36:42 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
    2012-04-24 04:36:42 1158656 ----a-w- C:\Windows\SysWow64\crypt32.dll
    2012-04-24 04:36:42 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
    2012-04-07 12:31:40 3216384 ----a-w- C:\Windows\System32\msi.dll
    2012-04-07 11:26:29 2342400 ----a-w- C:\Windows\SysWow64\msi.dll
    2012-04-06 01:35:24 1120768 ----a-w- C:\Windows\System32\atiumd6v.dll
    2012-04-06 01:34:50 1831424 ----a-w- C:\Windows\SysWow64\atiumdmv.dll
    2012-03-30 11:35:47 1918320 ----a-w- C:\Windows\System32\drivers\tcpip.sys
    2012-03-17 07:58:57 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys
    .
    ============= FINISH: 11:36:13.68 ===============


    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft Windows 7 Professional
    Boot Device: \Device\HarddiskVolume2
    Install Date: 2/2/2012 1:16:05 AM
    System Uptime: 6/11/2012 2:53:19 PM (1 hours ago)
    .
    Motherboard: Gigabyte Technology Co., Ltd. | | Z68A-D3H-B3
    Processor: Intel(R) Core(TM) i7-2600K CPU @ 3.40GHz | Socket 1155 | 3701/100mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 112 GiB total, 23.019 GiB free.
    D: is CDROM ()
    E: is FIXED (NTFS) - 1863 GiB total, 1737.074 GiB free.
    F: is FIXED (NTFS) - 466 GiB total, 84.759 GiB free.
    H: is Removable
    I: is Removable
    Z: is NetworkDisk (NTFS) - 8383 GiB total, 5105.629 GiB free.
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
    Description: Flash HS-COMBO
    Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_ USBSTOR#DISK&VEN_GENERIC&PROD_FLASH_HS-COMBO&REV_5.39#080805201743&1#
    Manufacturer: Generic
    Name: I:\
    PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_ USBSTOR#DISK&VEN_GENERIC&PROD_FLASH_HS-COMBO&REV_5.39#080805201743&1#
    Service: WUDFRd
    .
    Class GUID: {6bdd1fc1-810f-11d0-bec7-08002be2092f}
    Description: Texas Instruments 1394 OHCI Compliant Host Controller
    Device ID: PCI\VEN_104C&DEV_8025&SUBSYS_80250F2E&REV_01\5&23C 7ABC9&0&2000E0
    Manufacturer: Texas Instruments
    Name: Texas Instruments 1394 OHCI Compliant Host Controller
    PNP Device ID: PCI\VEN_104C&DEV_8025&SUBSYS_80250F2E&REV_01\5&23C 7ABC9&0&2000E0
    Service: 1394ohci
    .
    Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
    Description: Flash HS-CF
    Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_ USBSTOR#DISK&VEN_GENERIC&PROD_FLASH_HS-CF&REV_5.39#080805201743&0#
    Manufacturer: Generic
    Name: H:\
    PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_ USBSTOR#DISK&VEN_GENERIC&PROD_FLASH_HS-CF&REV_5.39#080805201743&0#
    Service: WUDFRd
    .
    ==== System Restore Points ===================
    .
    RP72: 6/8/2012 12:09:05 PM - Device Driver Package Install: Advanced Micro Devices, Inc. Display adapters
    RP73: 6/8/2012 4:42:08 PM - Installed AVG 2012
    RP74: 6/8/2012 4:42:17 PM - Installed AVG 2012
    RP75: 6/11/2012 8:49:21 AM - Removed AVG 2012
    RP76: 6/11/2012 8:50:33 AM - Removed AVG 2012
    RP77: 6/11/2012 9:04:14 AM - Revo Uninstaller's restore point - Constant Guard Protection Suite
    RP78: 6/11/2012 9:06:44 AM - Norton Security Suite Registry
    RP79: 6/11/2012 2:04:19 PM - Norton Security Suite Registry
    RP80: 6/11/2012 2:30:26 PM - Installed HiJackThis
    .
    ==== Installed Programs ======================
    .
    @BIOS
    Acrobat X Pro
    Adobe Acrobat X Pro - English, Français, Deutsch
    Adobe After Effects CS6
    Adobe AIR
    Adobe Audition CS6
    Adobe Dreamweaver CS6
    Adobe Edge Preview
    Adobe Fireworks CS6
    Adobe Flash Professional CS6
    Adobe Help Manager
    Adobe Illustrator CS6
    Adobe InDesign CS6
    Adobe Media Player
    Adobe Muse
    Adobe Photoshop CS6
    Adobe Prelude CS6
    Adobe Premiere Pro CS6
    Adobe Reader X (10.1.3)
    Adobe Shockwave Player 11.6
    Adobe SpeedGrade CS6
    Adobe Story
    Adobe Touch App Plugins
    Adobe Widget Browser
    Adobe® Content Viewer
    Apple Application Support
    Apple Software Update
    Audacity 1.3.14 (Unicode)
    AutoGreen B10.1021.1
    AVI2Clipboard 2.18
    bl
    Bryce 7.0 Content
    Bryce 7.1
    Bryce Lightning 7.0
    Canon IJ Network Scan Utility
    Canon IJ Network Tool
    Canon MX870 series User Registration
    Catalyst Control Center
    Catalyst Control Center - Branding
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center InstallProxy
    Catalyst Control Center Localization All
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help Czech
    CCC Help Danish
    CCC Help Dutch
    CCC Help English
    CCC Help Finnish
    CCC Help French
    CCC Help German
    CCC Help Greek
    CCC Help Hungarian
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Norwegian
    CCC Help Polish
    CCC Help Portuguese
    CCC Help Russian
    CCC Help Spanish
    CCC Help Swedish
    CCC Help Thai
    CCC Help Turkish
    ColorMunki Photo 1.1.1
    DDC Driver 1.5
    DVD Architect Pro 5.2
    Easy Tune 6 B11.0630.1
    Etron USB3.0 Host Controller
    Express Thumbnail Creator 1.81
    FileZilla Client 3.5.3
    Flash Builder
    Google Chrome
    Google Earth
    GPL Ghostscript
    High-Definition Video Playback
    HiJackThis
    HydraVision
    ImgBurn
    Intel(R) Control Center
    Intel(R) Management Engine Components
    Intel(R) Processor Graphics
    Intel(R) Rapid Storage Technology
    Java Auto Updater
    Java(TM) 6 Update 22
    Java(TM) 6 Update 30
    LightScribe System Software
    Logo Design Studio
    Magic Recovery Professional 3.5
    Malwarebytes Anti-Malware version 1.61.0.1400
    Media Manager 2.4
    Microsoft Silverlight
    Microsoft SQL Server 2005
    Microsoft SQL Server 2005 Express Edition (SONY_MEDIAMGR2)
    Microsoft SQL Server Setup Support Files (English)
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    Microsoft_VC80_ATL_x86
    Microsoft_VC80_CRT_x86
    Microsoft_VC80_MFC_x86
    Microsoft_VC80_MFCLOC_x86
    Microsoft_VC90_ATL_x86
    Microsoft_VC90_CRT_x86
    Microsoft_VC90_MFC_x86
    Microsoft_VC90_MFCLOC_x86
    MiniTool Power Data Recovery
    Mozilla Firefox 12.0 (x86 en-US)
    Mozilla Maintenance Service
    MSVCRT Redists
    Nero 10 Menu TemplatePack Basic
    Nero 10 Movie ThemePack Basic
    Nero Burning ROM 10
    Nero Control Center 10
    Nero Core Components 10
    Nero Dolby Files 10
    Nero Express 10
    Nero InfoTool 10
    Nero Multimedia Suite 10 Platinum HD
    Nero Recode 10
    Nero Update
    Norton Security Suite
    ON_OFF Charge B11.0110.1
    OpenOffice.org 3.3
    Pavtube Video Converter Ver 3.7.3.1865
    PDF Settings CS6
    ph
    PocketWizard Utility
    PxMergeModule
    QuickTime
    Realtek Ethernet Controller Driver
    Realtek High Definition Audio Driver
    Revo Uninstaller 1.93
    Safari
    SDK
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Smart 6 B11.0512.1
    Splashtop Connect for Firefox
    Splashtop Connect IE
    Stellar Phoenix Photo Recovery
    Task Timer 5.0.8
    UninstallDeviceDll 1.1
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    Visual Studio 2008 x64 Redistributables
    Wise Registry Cleaner 7.31
    Workspace Desktop
    X-Rite Device ColorMunki Service
    X-Rite Device Manager
    .
    ==== Event Viewer Messages From Past Week ========
    .
    6/8/2012 4:30:57 PM, Error: Service Control Manager [7003] - The epfwwfpr service depends the following service: BFE. This service might not be installed.
    6/8/2012 4:20:47 PM, Error: Service Control Manager [7001] - The Task Scheduler service depends on the Windows Event Log service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    6/8/2012 4:02:20 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AppleCharger discache eamonm ehdrv luafv spldr Wanarpv6
    6/8/2012 3:34:26 PM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Start with the following error: Access is denied.
    6/8/2012 3:33:14 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Intel(R) Management and Security Application Local Management Service service, but this action failed with the following error: An instance of the service is already running.
    6/8/2012 3:33:07 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the X-Rite Device Manager service, but this action failed with the following error: An instance of the service is already running.
    6/8/2012 3:33:06 PM, Error: Service Control Manager [7031] - The Smart TimeLock Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
    6/8/2012 3:33:05 PM, Error: Service Control Manager [7031] - The X-Rite Device Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 2000 milliseconds: Restart the service.
    6/8/2012 3:33:05 PM, Error: Service Control Manager [7031] - The X-Rite Device ColorMunki service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 2000 milliseconds: Restart the service.
    6/8/2012 3:33:04 PM, Error: Service Control Manager [7031] - The Intel(R) Management and Security Application Local Management Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
    6/8/2012 3:32:32 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 5 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    6/8/2012 3:31:32 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 4 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    6/8/2012 3:30:32 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    6/8/2012 3:30:13 PM, Error: Service Control Manager [7034] - The Intel(R) Management and Security Application User Notification Service service terminated unexpectedly. It has done this 1 time(s).
    6/8/2012 3:29:31 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    6/8/2012 3:28:31 PM, Error: Service Control Manager [7034] - The SQL Server VSS Writer service terminated unexpectedly. It has done this 1 time(s).
    6/8/2012 3:28:31 PM, Error: Service Control Manager [7034] - The Splashtop Connect Service service terminated unexpectedly. It has done this 1 time(s).
    6/8/2012 3:28:31 PM, Error: Service Control Manager [7034] - The Splashtop Connect IE Software Updater Service service terminated unexpectedly. It has done this 1 time(s).
    6/8/2012 3:28:31 PM, Error: Service Control Manager [7034] - The Splashtop Connect Firefox Software Updater Service service terminated unexpectedly. It has done this 1 time(s).
    6/8/2012 3:28:31 PM, Error: Service Control Manager [7034] - The LightScribeService Direct Disc Labeling Service service terminated unexpectedly. It has done this 1 time(s).
    6/8/2012 3:28:31 PM, Error: Service Control Manager [7034] - The File Backup Service service terminated unexpectedly. It has done this 1 time(s).
    6/8/2012 3:28:31 PM, Error: Service Control Manager [7034] - The AMD External Events Utility service terminated unexpectedly. It has done this 1 time(s).
    6/8/2012 3:28:31 PM, Error: Service Control Manager [7034] - The Adobe Acrobat Update Service service terminated unexpectedly. It has done this 1 time(s).
    6/8/2012 3:28:31 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    6/8/2012 3:26:26 PM, Error: Service Control Manager [7000] - The Intel(R) Management and Security Application Local Management Service service failed to start due to the following error: The pipe has been ended.
    6/8/2012 3:23:53 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Apple Mobile Device service to connect.
    6/8/2012 3:23:53 PM, Error: Service Control Manager [7000] - The Apple Mobile Device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/8/2012 3:21:53 PM, Error: Service Control Manager [7034] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 3 time(s).
    6/8/2012 3:21:23 PM, Error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
    6/8/2012 3:21:03 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the X-Rite Device Manager service to connect.
    6/8/2012 3:21:03 PM, Error: Service Control Manager [7000] - The X-Rite Device Manager service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/8/2012 3:21:01 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the X-Rite Device ColorMunki service to connect.
    6/8/2012 3:21:01 PM, Error: Service Control Manager [7000] - The X-Rite Device ColorMunki service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/8/2012 3:20:53 PM, Error: Service Control Manager [7034] - The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated unexpectedly. It has done this 2 time(s).
    6/8/2012 3:20:53 PM, Error: Service Control Manager [7034] - The Nero Update service terminated unexpectedly. It has done this 1 time(s).
    6/8/2012 3:20:53 PM, Error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
    6/8/2012 3:20:53 PM, Error: Service Control Manager [7031] - The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
    6/8/2012 3:20:53 PM, Error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
    6/8/2012 12:09:19 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the AMD External Events Utility service to connect.
    6/8/2012 12:09:19 PM, Error: Service Control Manager [7000] - The AMD External Events Utility service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/11/2012 8:56:36 AM, Error: Service Control Manager [7030] - The CGPS Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
    6/11/2012 2:53:31 PM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.
    6/11/2012 2:53:29 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: luafv
    6/11/2012 2:53:29 PM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.
    6/11/2012 2:53:29 PM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.
    .
    ==== End Of File ===========================

  2. #2
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    77
    Posts
    4,079
    Well several things I see here....
    1.AV: ESET NOD32 Antivirus 5.2 *Enabled/Updated*>>>>Obviously this program is someplace on the computer because DDS found it to be enable, updated and running
    SP: ESET NOD32 Antivirus 5.2 *Enabled/Updated*
    ***************
    2.RP73: 6/8/2012 4:42:08 PM - Installed AVG 2012>>>>for some reason, installed twice
    RP74: 6/8/2012 4:42:17 PM - Installed AVG 2012
    RP75: 6/11/2012 8:49:21 AM - Removed AVG 2012>>>>for some reason uninstalled twice
    RP76: 6/11/2012 8:50:33 AM - Removed AVG 2012
    ********************************************
    3.RP78: 6/11/2012 9:06:44 AM - Norton Security Suite Registry
    RP79: 6/11/2012 2:04:19 PM - Norton Security Suite Registry
    *********
    So three anti-virus programs, one of them uninstalled, two of them still running. Puts the computer at great risk because neither of them run correctly because they fight each other. But NO Firewall running unless you are using the Windows Firewall, are you?

    I also see you ran the TDSSKiller...as noted by this created file
    2012-06-11 21:00:22 -------- d-----w- C:\TDSSKiller_Quarantine
    yet you chose not to note this nor post the log that would have been created and nobody here told you to run this.

    You have MBA-M installed, have you updated it and run a Full Scan with it? If not, please do and post back with the full log.

  3. #3
    Join Date
    Jun 2012
    Posts
    4
    Thank you for your help. I waited six days without a reply so I searched google my exact thread title and found http://www.techspot.com/community/to...ection.181661/
    Which let me to combofix.exe and I run and it found a number of problems. i restarted and ran agian and so far so good.
    Its been a half day and I have not got one message telling me that Norton blocked anything, so i think I am clean.
    If there is a log that you still want me to post, I will.

  4. #4
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    77
    Posts
    4,079
    Quote Originally Posted by wcalvin View Post
    Thank you for your help. I waited six days without a reply so I searched google my exact thread title and found http://www.techspot.com/community/to...ection.181661/
    Which let me to combofix.exe and I run and it found a number of problems. i restarted and ran agian and so far so good.
    Its been a half day and I have not got one message telling me that Norton blocked anything, so i think I am clean.
    If there is a log that you still want me to post, I will.
    Not sure where a thread you created here six days ago would be located. You only show two threads created, both created yesterday.
    Since you are receiving help at TechSpots under normal circumstances I recommend that you continue THERE with them but I see after reading through that thread that you neglected to inform them at the outset that this is a corporate PC and they told you there that you would have to work with your Corporate IT department. Obviously you didn't inform your Corporate IT department, instead you came here and posted without giving full information and again omitting the fact that this is a Company computer.

    I do have to say, the two DDS logs posted, one here and one there are not even remotely similar, so am not sure what's really "being pulled" here but something is for sure.
    There is no notation in your logs there concerning either ESET Nod AV or AVG 2012 so those two programs were loaded in the middle of your fixes being done there.
    There were five programs they had you run there that you made no mention of in your post here:
    MBA-M, Bootkit Remover, aswMBR, TDSKiller (which I saw in your DDS log here) and now you mention here, Combofix which you say there you could not get to run. However, HERE you say you DID run Combofix and it found problems and you rebooted and ran it again. You aren't being truthful here and you obviously were not truthful there, if you had been then you would have posted the Combofix log.
    You also DID NOT follow the instructions given to you there before you posted here:
    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!

    You obviously installed two other anti-virus programs before you posted here, your DDS log shows that very clearly.

    I am giving you the same answer that you were given there and obviously chose NOT to follow:
    Well, you'll have to talk to your IT people.
    There is not much I can do.
    Is your computer clean? I very much doubt it. In fact by doing all of this other stuff that THEY did not tell you to do....adding two more anti-virus programs since the posting of the last log there for sure....No the computer is NOT clean. Could your job be in jeopardy because you failed to contact the Corporate IT department? Yes.
    But that is your problem and not ours and not TechSpots either.

  5. #5
    Join Date
    Jun 2012
    Posts
    4
    I did NOT start that thread. It wasn't me... I just google searched my problem.
    It was a week since I started the tread here, with no replies.

  6. #6
    Join Date
    Jun 2012
    Posts
    4
    I do appreciate you taking your time to help.

    I will however say that people that respond to these threads are (for a lack of a better word) rude.
    For us newbies all of this is overwhelming and confusing. Please keep that in mind...
    so when we don't post something exactly to your liking, scolding us isn't the answer.

    So turn about is fair play.

    PLEASE REREAD MY POST... IT CLEARLY STATES THAT AFTER 6 DAYS WITH NO HELP...
    I GOOGLE SEARCHED AND FOUND A DIFFERENT PERSON WITH THE SAME ISSUE.
    I FOLLOWED THE STEPS THAT THAT FORUM RECOMMENDED AND IT WORKED.

    so if you would like to reply with a human reply, great! if not great...
    but calling someone out for not doing something to your liking when in actuallity you are the one that is off ...
    not cool

  7. #7
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    77
    Posts
    4,079
    I DID read your post. You claim to have had a thread here for six days without a response. Where IS this thread? Your User information shows TWO threads begun here, one of them begun on June 12th. This one begun on June 15...that is NOT six days, it is THREE days. Our helpers are limited here, in fact I am the only one.
    I have no idea what was contained in the first thread since you chose to delete the contents. I had only what you posted here to go by and all your initial post contained was the DDS log, period. No other logs, no other information. We are not mind readers here. Just a DDS log without reason of the running or posting gives no information. Just a log.
    I am sorry I mis-understood your post about another forum, that was not terribly clear since you say that only that you did a google search for your thread title...which implied to me that this was also YOUR thread. I am sorry for that misunderstanding.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •