Link to post: http://www.bleepingcomputer.com/forums/topic461669.html
Here's the deal. Yesterday, at around 2:30am (meaning it was basically today,haha)I was on a video-streaming website watching TV shows, and I foolishly allowed the outdated Java script to run. After this, MSE, Windows Firewall, and Windows Update became disabled and i got error 0x80070424 when I tried to enable it. Scans with various programs showed that I had a decent amount of trojans. Then I decided to perform a system restore, and restored my PC to a restore point 2 days ago (july 18th). at this point, everything was working correcty, so i performed a scan with MSE and found the dreaded sirefef trojan. I deleted it, and to my surprise MSE actually said that it worked...and further scans showed up clean. I then did a scan with MBAM, and found a few trojans and adware programs that I promptly deleted..again it worked. i ran more and more scans throughout the day...and nothing was showing up - HOWEVER, during a full scan of MSE, my computer randomly restarted for no apparent reason...this has not happened since.
I've run scans with MBAM, MSE, HitmanPro, TDSSKiller, Norton Power Eraser, ESET Online Scanner (which found and removed a trojan and an adware program), EZ_Sirefix, ESESirefefRemover, SuperAntiSpyware, and ComboFix (I know I shouldn't have, but I did anyways - stupid, I know)
... and all of them have come up negative, other than the ESET Online scanner which i mentioned.
My question is: is it safe to say that my computer is free of this Sirefef/ZeroAccess malware, or should I simply do a nuke and pave (as I am aware that once the system is compromised with something like this, it really can't be trusted)?
also, if i were to do a nuke and pave, would it be safe for me to back up my documents? because the only thing that is important on my "infected" computer is some school documents..everything else is unimportant. will simple word documents and powerpoint files be infected as well?
thanks!
and just to add, i am running windows 7 x64
here are my DDS logs:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Karanbir at 23:21:32 on 2012-07-20
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.2.1033.18.5942.3607 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\Hpservice.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\system32\taskmgr.exe
C:\Users\Karanbir\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Users\Karanbir\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Karanbir\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{1B10E8E7-6E18-4E26-8BB9-9048F14E710E} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{1B10E8E7-6E18-4E26-8BB9-9048F14E710E}\054435247457563747 : DhcpNameServer = 192.168.16.4 192.168.16.6
TCP: Interfaces\{1B10E8E7-6E18-4E26-8BB9-9048F14E710E}\055616368664963786D27657563747 : DhcpNameServer = 64.71.255.198
TCP: Interfaces\{1B10E8E7-6E18-4E26-8BB9-9048F14E710E}\157756374775966696 : DhcpNameServer = 192.168.9.1 64.134.255.2 64.134.255.10
TCP: Interfaces\{1B10E8E7-6E18-4E26-8BB9-9048F14E710E}\16474777966696 : DhcpNameServer = 192.168.6.1 64.134.255.2 64.134.255.10
TCP: Interfaces\{1B10E8E7-6E18-4E26-8BB9-9048F14E710E}\25F6765627371313630313 : DhcpNameServer = 64.71.255.198
TCP: Interfaces\{1B10E8E7-6E18-4E26-8BB9-9048F14E710E}\378656271647F6E6 : DhcpNameServer = 4.53.41.66
TCP: Interfaces\{1B10E8E7-6E18-4E26-8BB9-9048F14E710E}\4656661657C647 : DhcpNameServer = 192.168.0.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Karanbir\AppData\Roaming\Mozilla\Firefox\Profiles\vydyowc8.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=ConduitEngine&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - google.ca
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=
FF - prefs.js: network.proxy.type - 0
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 DVMIO;DeviceVM IO Service;C:\Windows\system32\DRIVERS\dvmio.sys --> C:\Windows\system32\DRIVERS\dvmio.sys [?]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2010-9-11 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 cpuz135;cpuz135;\??\C:\Windows\system32\drivers\cpuz135_x64.sys --> C:\Windows\system32\drivers\cpuz135_x64.sys [?]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-9 86072]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-3-28 94264]
R2 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe --> C:\Windows\system32\Hpservice.exe [?]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-8-4 13336]
R2 SSPORT;SSPORT;\??\C:\Windows\system32\Drivers\SSPORT.sys --> C:\Windows\system32\Drivers\SSPORT.sys [?]
R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-8-4 2320920]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 clwvd;HP Webcam Splitter;C:\Windows\system32\DRIVERS\clwvd.sys --> C:\Windows\system32\DRIVERS\clwvd.sys [?]
R3 HECIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --> C:\Windows\system32\DRIVERS\Impcd.sys [?]
R3 intelkmd;intelkmd;C:\Windows\system32\DRIVERS\igdpmd64.sys --> C:\Windows\system32\DRIVERS\igdpmd64.sys [?]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;C:\Windows\system32\DRIVERS\MijXfilt.sys --> C:\Windows\system32\DRIVERS\MijXfilt.sys [?]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2011-3-24 148072]
S1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-5-3 136176]
S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-4-5 1153368]
S2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-7-5 3048136]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-29 158856]
S3 AmUStor;AM USB Stroage Driver;C:\Windows\system32\drivers\AmUStor.SYS --> C:\Windows\system32\drivers\AmUStor.SYS [?]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-5-3 136176]
S3 hpdoccardsvc;HP Documention Flash Card Detection Service;C:\Program Files (x86)\Hewlett-Packard\HP ENVY Document Card Utilities\doccardsvc.exe [2010-3-24 83240]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 51740536]
S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 Revoflt;Revoflt;C:\Windows\system32\DRIVERS\revoflt.sys --> C:\Windows\system32\DRIVERS\revoflt.sys [?]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
.
=============== Created Last 30 ================
.
2012-07-21 00:28:24 69000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C5024758-72C9-4D4F-B50A-5F9FE9378AA2}\offreg.dll
2012-07-21 00:27:34 9133488 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C5024758-72C9-4D4F-B50A-5F9FE9378AA2}\mpengine.dll
2012-07-21 00:15:09 98816 ----a-w- C:\Windows\sed.exe
2012-07-21 00:15:09 518144 ----a-w- C:\Windows\SWREG.exe
2012-07-21 00:15:09 256000 ----a-w- C:\Windows\PEV.exe
2012-07-21 00:15:09 208896 ----a-w- C:\Windows\MBR.exe
2012-07-20 20:02:52 -------- d-----w- C:\FRST
2012-07-20 19:05:53 -------- d-----w- C:\Program Files (x86)\ESET
2012-07-20 18:50:27 -------- d-----w- C:\Users\Karanbir\AppData\Roaming\SUPERAntiSpyware.com
2012-07-20 18:50:09 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2012-07-20 18:50:09 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2012-07-20 17:25:59 955888 ----a-w- C:\Windows\System32\npDeployJava1.dll
2012-07-20 17:25:59 839152 ----a-w- C:\Windows\System32\deployJava1.dll
2012-07-20 07:54:56 -------- d-----w- C:\Program Files\HitmanPro
2012-07-20 07:52:39 -------- d-----w- C:\ProgramData\HitmanPro
2012-07-20 07:16:09 -------- d-----w- C:\Users\Karanbir\AppData\Local\NPE
2012-07-20 06:54:13 9013136 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-07-20 06:41:44 -------- d-----w- C:\TDSSKiller_Quarantine
2012-07-20 06:19:35 -------- d-----w- C:\Users\Karanbir\AppData\Local\ElevatedDiagnostics
2012-07-20 05:53:40 -------- d-----w- C:\Users\Karanbir\AppData\Local\{F4C346B1-D22E-11E1-8270-B8AC6F996F26}
2012-07-20 05:51:40 -------- d-----w- C:\Users\Karanbir\AppData\Local\{F4C314F9-D22E-11E1-8270-B8AC6F996F26}
2012-07-20 04:36:20 -------- d-----w- C:\Users\Karanbir\AppData\Local\{DA1BC50E-980B-460B-887F-DEAEB7B464AC}
2012-07-20 04:36:07 -------- d-----w- C:\Users\Karanbir\AppData\Local\{17957705-AC87-49B5-B980-5B72FF4BD9A6}
2012-07-19 05:21:15 -------- d-----w- C:\Users\Karanbir\AppData\Local\{2499F575-87B1-4DAC-880E-C090D4CDBC79}
2012-07-19 05:21:05 -------- d-----w- C:\Users\Karanbir\AppData\Local\{8FC3423A-F623-435F-9683-AF547AE4C350}
2012-07-18 17:20:30 -------- d-----w- C:\Users\Karanbir\AppData\Local\{908EA756-7192-422D-9BB0-3B2396E6DC11}
2012-07-18 17:20:20 -------- d-----w- C:\Users\Karanbir\AppData\Local\{7D82BA72-E509-4984-94BE-9B4CA14A426A}
2012-07-16 21:41:40 -------- d-----w- C:\Users\Karanbir\AppData\Local\{849F53D2-B558-493D-A6FA-3012C35E7868}
2012-07-16 21:41:31 -------- d-----w- C:\Users\Karanbir\AppData\Local\{D0E3A267-FD28-4FB2-97D0-8017765FB2C4}
2012-07-15 21:06:04 -------- d-----w- C:\Users\Karanbir\AppData\Local\{367AED7D-23AA-4CE5-B9A6-D1A0441CC5E5}
2012-07-15 21:05:53 -------- d-----w- C:\Users\Karanbir\AppData\Local\{56EDF668-D3C6-4792-942B-2DF33010634B}
2012-07-14 18:42:09 -------- d-----w- C:\Users\Karanbir\AppData\Local\{F4E598C6-A397-46E9-BA6B-9ADB664CB93C}
2012-07-14 18:41:58 -------- d-----w- C:\Users\Karanbir\AppData\Local\{CD49B0DB-2C2D-4301-8F67-9A89B521BC56}
2012-07-13 23:27:18 -------- d-----w- C:\Users\Karanbir\AppData\Local\{B64BC966-8D36-47B1-BB3F-FF8140A76E2B}
2012-07-13 23:27:08 -------- d-----w- C:\Users\Karanbir\AppData\Local\{59697213-932C-4935-9F2C-244755127184}
2012-07-12 23:41:02 -------- d-----w- C:\Users\Karanbir\AppData\Local\{ABA83E2F-B536-44F4-9D4A-1D59A0366C7C}
2012-07-12 23:40:52 -------- d-----w- C:\Users\Karanbir\AppData\Local\{3F5D5347-C528-4A5C-B6EC-25158A2C2510}
2012-07-11 04:04:13 3147264 ----a-w- C:\Windows\System32\win32k.sys
2012-07-11 03:58:59 887296 ----a-w- C:\Program Files\Internet Explorer\iedvtool.dll
2012-07-11 02:41:36 2003968 ----a-w- C:\Windows\System32\msxml6.dll
2012-07-11 02:41:36 1880064 ----a-w- C:\Windows\System32\msxml3.dll
2012-07-11 02:41:35 1389568 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-07-11 02:41:35 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-07-11 02:40:59 459216 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-07-11 02:40:59 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-07-11 02:40:59 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-07-11 02:40:58 95088 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-07-11 02:40:58 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-07-11 02:40:58 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-07-11 02:40:58 152432 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-07-11 02:40:57 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2012-07-11 02:40:57 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-07-11 02:40:56 1425408 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll
2012-07-11 02:40:54 987136 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
2012-07-11 02:35:04 -------- d-----w- C:\Users\Karanbir\AppData\Local\{2D6A7F8A-4FF3-4BA2-9029-33B16DA4234A}
2012-07-11 02:34:49 -------- d-----w- C:\Users\Karanbir\AppData\Local\{273A18D6-0D92-4A8B-8D13-1DDBF5BFD327}
2012-07-09 23:12:50 -------- d-----w- C:\Users\Karanbir\AppData\Local\{05646279-BDC0-403F-AFB3-2F5726BCBBA2}
2012-07-09 23:12:40 -------- d-----w- C:\Users\Karanbir\AppData\Local\{6B786A15-8F93-40F2-AF6B-EA5AD18C9C83}
2012-07-08 18:49:26 -------- d-----w- C:\Users\Karanbir\AppData\Local\{9896AA7C-7DDD-4AF0-AFDE-D55A9F8ED25E}
2012-07-08 18:49:11 -------- d-----w- C:\Users\Karanbir\AppData\Local\{DF2583CD-F4EE-4066-9831-C7DBC8ADDFB8}
2012-07-08 06:42:26 -------- d-----w- C:\Users\Karanbir\AppData\Local\{AB288C42-C8AC-4D1A-A843-1CA04CF7525F}
2012-07-08 06:42:13 -------- d-----w- C:\Users\Karanbir\AppData\Local\{B673950F-5D83-48C2-8249-59BD47CE1A3D}
2012-07-07 18:42:02 -------- d-----w- C:\Users\Karanbir\AppData\Local\{DDB71713-A4FF-4285-8DAF-2C5538E55791}
2012-07-07 18:41:52 -------- d-----w- C:\Users\Karanbir\AppData\Local\{D8DC55C0-ADB9-4BBF-8028-502087BC83F2}
2012-07-07 02:26:22 -------- d-----w- C:\Users\Karanbir\AppData\Local\{0268EBD9-D74B-4056-85D3-55C56AF13593}
2012-07-07 02:26:13 -------- d-----w- C:\Users\Karanbir\AppData\Local\{C970E866-941F-44BF-997A-C906F2D8482B}
2012-07-07 02:26:01 -------- d-----w- C:\Users\Karanbir\AppData\Local\{6690E933-E572-4EEF-9F6B-02DFED8212A3}
2012-07-06 02:49:17 -------- d-----w- C:\Users\Karanbir\AppData\Local\Macromedia
2012-07-05 22:45:34 5030088 ----a-w- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2012-07-05 22:40:50 -------- d-----w- C:\Users\Karanbir\AppData\Local\{30F687F3-452E-4082-82FE-2AA6EEE97060}
2012-07-05 22:40:40 -------- d-----w- C:\Users\Karanbir\AppData\Local\{B61B53C8-A395-4D1A-808F-A0D4BA07B96A}
2012-07-04 23:23:25 -------- d-----w- C:\Users\Karanbir\AppData\Local\{820E17F3-938D-4806-A5DF-8D07BF8EA7D9}
2012-07-04 23:23:14 -------- d-----w- C:\Users\Karanbir\AppData\Local\{0FCE677D-80AA-4EAE-AA01-B5709945F63B}
2012-07-03 23:54:10 927800 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{AEF0A2A4-53A6-4628-9F40-712AE5B20A3D}\gapaengine.dll
2012-07-03 23:44:38 -------- d-----w- C:\Users\Karanbir\AppData\Local\{A450C4B0-11FE-4830-B83F-FE43717A6DD5}
2012-07-03 23:44:26 -------- d-----w- C:\Users\Karanbir\AppData\Local\{FA9AFA18-3AEF-480B-ADD0-EB20FF2EA221}
2012-07-02 22:59:25 -------- d-----w- C:\Users\Karanbir\AppData\Local\{594470E3-31AF-4444-BCA2-A7BC7943D532}
2012-07-02 22:59:13 -------- d-----w- C:\Users\Karanbir\AppData\Local\{498823F2-9762-4D78-9C27-C6B2324EC8EB}
2012-07-01 23:02:17 -------- d-----w- C:\Users\Karanbir\AppData\Local\{FABB0115-FCAA-43E0-9E5F-D2BF0B244E29}
2012-07-01 23:02:04 -------- d-----w- C:\Users\Karanbir\AppData\Local\{5C2F4C52-0E41-4B51-8F12-A46D37B7B51F}
2012-07-01 05:12:08 -------- d-----w- C:\Users\Karanbir\AppData\Local\{0DDF3E19-3019-4C5B-8EEC-62A413780B0E}
2012-07-01 05:11:48 -------- d-----w- C:\Users\Karanbir\AppData\Local\{614F0757-41C7-417E-A95D-FCA7AB462D78}
2012-06-30 15:58:13 -------- d-----w- C:\Users\Karanbir\AppData\Local\{D9A505AD-3D5B-4167-87F2-4A94EF73206F}
2012-06-30 15:58:01 -------- d-----w- C:\Users\Karanbir\AppData\Local\{076EE3BD-9B32-4797-A1E4-2ADDCD789BC1}
2012-06-30 15:57:36 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-06-28 18:58:24 -------- d-----w- C:\Users\Karanbir\AppData\Local\{2201D667-4FE4-4ECF-B7E1-EB59DBDF8328}
2012-06-28 18:58:11 -------- d-----w- C:\Users\Karanbir\AppData\Local\{3964D54F-3003-4E95-A87C-45E5B08A7A58}
2012-06-27 21:16:24 -------- d-----w- C:\Users\Karanbir\AppData\Local\{CA8FB17F-74FA-45F3-8216-C7E1AE717C86}
2012-06-27 21:16:12 -------- d-----w- C:\Users\Karanbir\AppData\Local\{A7CE0FC5-4EA2-4012-8E1C-BFA65337DEBE}
2012-06-26 21:17:09 -------- d-----w- C:\Users\Karanbir\AppData\Local\{E6E6AE4E-856E-4259-8BFC-F6A88BC32C1C}
2012-06-25 18:35:31 -------- d-----w- C:\Users\Karanbir\AppData\Local\{AFD982C9-98D7-4D5A-8108-9173D3A20488}
2012-06-25 18:35:19 -------- d-----w- C:\Users\Karanbir\AppData\Local\{6902801E-43E4-4EBE-9350-5CEB3E83E24A}
2012-06-25 00:32:25 -------- d-----w- C:\Users\Karanbir\AppData\Local\{5B72E059-2C07-45E6-B029-31C3C0FA46B6}
2012-06-25 00:32:14 -------- d-----w- C:\Users\Karanbir\AppData\Local\{A448A1C0-194B-4831-AEDA-7DD17BBA05B2}
2012-06-25 00:29:19 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\8f507a8b1cd526905\MeshBetaRemover.exe
2012-06-24 17:39:30 -------- d-----w- C:\Users\Karanbir\AppData\Local\{64EF0696-5BC8-4A87-BE2F-64EFB6AA7A1F}
2012-06-23 23:14:26 -------- d-----w- C:\Users\Karanbir\AppData\Local\{B62ABCCF-1A45-4B64-8E37-EC7B41792F71}
2012-06-23 03:06:17 -------- d-----w- C:\Users\Karanbir\AppData\Local\{0FCF16EB-2EE6-48E7-8490-A1499325AF46}
2012-06-23 03:06:07 -------- d-----w- C:\Users\Karanbir\AppData\Local\{60604845-AEB2-44A6-ADBB-FD4655C1044E}
2012-06-21 19:32:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-21 19:31:57 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-21 19:31:23 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-21 19:31:23 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-21 19:28:52 -------- d-----w- C:\Users\Karanbir\AppData\Local\{B944F7E7-66C5-4991-A902-AFF0258EF5E1}
2012-06-21 19:28:38 -------- d-----w- C:\Users\Karanbir\AppData\Local\{89452482-209C-4E43-90E9-E6DDC963278F}
.
==================== Find3M ====================
.
2012-07-03 17:46:44 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-06-30 15:57:36 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-02 12:12:17 2311680 ----a-w- C:\Windows\System32\jscript9.dll
2012-06-02 12:05:28 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-06-02 12:04:50 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-06-02 12:01:40 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-06-02 11:57:08 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-02 08:33:25 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-02 08:25:08 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-02 08:25:03 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-02 08:20:33 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-02 08:16:52 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-05-04 10:52:22 5505392 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:08:16 3958128 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:08:15 3902320 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-02 05:32:43 208896 ----a-w- C:\Windows\System32\profsvc.dll
2012-04-28 03:50:40 204800 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-26 05:34:38 76288 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:34:37 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-26 05:28:32 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-04-24 05:59:45 182272 ----a-w- C:\Windows\System32\cryptsvc.dll
2012-04-24 05:59:45 1460224 ----a-w- C:\Windows\System32\crypt32.dll
2012-04-24 05:59:45 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2012-04-24 04:47:04 139264 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-04-24 04:47:04 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2012-04-24 04:47:03 1156608 ----a-w- C:\Windows\SysWow64\crypt32.dll
2010-10-16 22:19:48 328568 ----a-w- C:\Program Files\uTorrent.exe
.
============= FINISH: 23:22:16.95 ===============
Thanks so much for any help you can give me


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked
Back to top










