xxx Before I begin describing my problem, I am currently using Windows 7 (64 bit) on a Bootcamp partition of my MacBook Pro, so if you see something about an :E partition in these logs I'm about to post, that's my Mac side. In addition, my windows partition is currently running low on space (only ~9GB of free space remain)--I don't know if that matters, but I just wanted to mention it.
Earlier today a website which I have previously had no problems with asked to run a Java applet. I obliged and immediately found my Sophos antivirus giving me constant notifications that "suspicious behavior" had been detected and that it was moving stuff to quaratine. I immediately started looking online for a fix, but before I could get very far I found myself locked out of my computer, unable to open any programs besides Internet Explorer (I would get an error message saying the program was infected) and even then unable to access any webpages (redirecting to a page that said the page I was attempting to access was dangerous). I had apparently lost all privileges as a user--in fact, I couldn't even access my Sophos antivirus controls (they were greyed out as if I did not have permission to use them).
A few seconds later I found myself beset by messages telling me to purchase Live Security Platinum for some price per month to uninstall all the malware that was infected on my computer (of course I recognized that the Live Security Platinum stuff was in fact malware itself).
Using another computer, I followed this guide word-for-word (http://malwaretips.com/blogs/uninstall-live-security-platinum/), running my computer in Safe Mode and downloading and running MBAM. After restarting my computer, I found that my computer was functioning normally again, which is to say I had regained full control of it, but additional scans with Hitman Pro (trial version) and Sophos revealed that the threat (identified as a trojan, Sophos calls it ZAccInf-A, Hitman calls it Sirefef.A) was still present. They both point to two files: C:\Windows\assembly\GAC_32\Desktop.ini and C:\\Windows\system32\services.exe, and neither antvirus program is able to "clean up" or "restore" the infected files (they merely provide a message that says "Delete failed" or "Cleanup failed").
Even now as I type this, every few minutes or so, I get a notification from Sophos saying "W32/ZAccInf-A has been detected and moved to quarantine," but obviously the quarantine move keeps failing as these notifications aren't stopping. It makes me pretty nervous.
Please help. Thanks very much in advance. The DDS logs are posted and attached, I didn't do a GMER log per the preparation instructions because I am using a 64 bit machine.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514
Run by xxx at 19:47:27 on 2012-07-21
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4007.2343 [GMT -5:00]
.
AV: Sophos Anti-Virus *Enabled/Updated* {479CCF92-4960-B3E0-7373-BF453B467D2C}
SP: Sophos Anti-Virus *Enabled/Updated* {FCFD2E76-6F5A-BC6E-49C3-843740C13791}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Boot Camp\Bootcamp.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Windows\system32\AppleOSSMgr.exe
C:\Windows\system32\AppleTimeSrv.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files (x86)\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Sophos\Remote Management System\RouterNT.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_257_ActiveX.exe
C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page =
uSearch Bar =
mWinlogon: Userinit=userinit.exe,
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO: Sophos Web Content Scanner: {39ea7695-b3f2-4c44-a4bc-297ada8fd235} - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SophosBHO.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll"
uRun: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
uRun: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Google Update] "C:\Users\xxx\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
LSP: mswsock.dll
Trusted Zone: freetoolsassociation.com\activegs
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444552440000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{065C0EF0-D506-488F-B219-3592324798D1} : DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{065C0EF0-D506-488F-B219-3592324798D1}\8686F6E6F62737F5847494 : DhcpNameServer = 192.168.7.1 64.134.255.2 64.134.255.10
TCP: Interfaces\{065C0EF0-D506-488F-B219-3592324798D1}\A4847457563747E65647 : DhcpNameServer = 128.220.1.75 162.129.253.134
TCP: Interfaces\{065C0EF0-D506-488F-B219-3592324798D1}\D45627C61657 : DhcpNameServer = 68.87.72.134 68.87.77.134
TCP: Interfaces\{065C0EF0-D506-488F-B219-3592324798D1}\D45627C616570234163716 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{CFA1E157-47BB-428F-96EA-F0AB89B3171B} : DhcpNameServer = 10.1.1.2 10.1.1.3
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL
mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
BHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO-X64: Sophos Web Content Scanner: {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SophosBHO.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll"
mRun-x64: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
AppInit_DLLs-X64: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\5xl6kmhd.default\
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Users\xxx\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AppleHFS;AppleHFS;C:\Windows\system32\drivers\AppleHFS.sys --> C:\Windows\system32\drivers\AppleHFS.sys [?]
R0 AppleMNT;AppleMNT;C:\Windows\system32\drivers\AppleMNT.sys --> C:\Windows\system32\drivers\AppleMNT.sys [?]
R1 SAVOnAccess;SAVOnAccess;C:\Windows\system32\DRIVERS\savonaccess.sys --> C:\Windows\system32\DRIVERS\savonaccess.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 AppleOSSMgr;Apple OS Switch Manager;C:\Windows\system32\AppleOSSMgr.exe --> C:\Windows\system32\AppleOSSMgr.exe [?]
R2 AppleTimeSrv;Apple Time Service;C:\Windows\system32\AppleTimeSrv.exe --> C:\Windows\system32\AppleTimeSrv.exe [?]
R2 KeyAgent;KeyAgent;\??\C:\Windows\system32\drivers\KeyAgent.sys --> C:\Windows\system32\drivers\KeyAgent.sys [?]
R2 MacHALDriver;Mac HAL;\??\C:\Windows\system32\drivers\MacHALDriver.sys --> C:\Windows\system32\drivers\MacHALDriver.sys [?]
R2 SAVAdminService;Sophos Anti-Virus status reporter;C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2011-4-26 163056]
R2 SAVService;Sophos Anti-Virus;C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [2011-4-26 97520]
R2 Sophos Agent;Sophos Agent;C:\Program Files (x86)\Sophos\Remote Management System\ManagementAgentNT.exe [2011-4-26 282624]
R2 Sophos AutoUpdate Service;Sophos AutoUpdate Service;C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [2012-5-13 232472]
R2 Sophos Message Router;Sophos Message Router;C:\Program Files (x86)\Sophos\Remote Management System\RouterNT.exe [2011-4-26 806912]
R2 swi_service;Sophos Web Intelligence Service;C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2012-3-8 1543704]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-4-24 2655768]
R3 acpials;ALS Sensor Filter;C:\Windows\system32\DRIVERS\acpials.sys --> C:\Windows\system32\DRIVERS\acpials.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AppleBtBc;Apple Broadcom Built-in Bluetooth;C:\Windows\system32\DRIVERS\AppleBtBc.sys --> C:\Windows\system32\DRIVERS\AppleBtBc.sys [?]
R3 applemtm;Apple Multitouch Mouse;C:\Windows\system32\DRIVERS\applemtm.sys --> C:\Windows\system32\DRIVERS\applemtm.sys [?]
R3 applemtp;Apple Multitouch;C:\Windows\system32\DRIVERS\applemtp.sys --> C:\Windows\system32\DRIVERS\applemtp.sys [?]
R3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE [2012-2-10 240408]
R3 bScsiSDa;bScsiSDa;C:\Windows\system32\DRIVERS\bScsiSDa.sys --> C:\Windows\system32\DRIVERS\bScsiSDa.sys [?]
R3 CirrusFilter;CS420xLowerFilter;C:\Windows\system32\DRIVERS\CS420x64.sys --> C:\Windows\system32\DRIVERS\CS420x64.sys [?]
R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);C:\Windows\system32\DRIVERS\vrtaucbl.sys --> C:\Windows\system32\DRIVERS\vrtaucbl.sys [?]
R3 IRRemoteFlt;IR Receiver Filter Driver;C:\Windows\system32\DRIVERS\IRFilter.sys --> C:\Windows\system32\DRIVERS\IRFilter.sys [?]
R3 KeyMagic;USB Keyboard HID Filter;C:\Windows\system32\DRIVERS\KeyMagic.sys --> C:\Windows\system32\DRIVERS\KeyMagic.sys [?]
R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 ScreamBAudioSvc;ScreamBee Audio;C:\Windows\system32\drivers\ScreamingBAudio64.sys --> C:\Windows\system32\drivers\ScreamingBAudio64.sys [?]
S2 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.EXE [2012-2-10 193816]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-7-2 113120]
S3 sdcfilter;sdcfilter;C:\Windows\system32\DRIVERS\sdcfilter.sys --> C:\Windows\system32\DRIVERS\sdcfilter.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 SophosBootDriver;SophosBootDriver;C:\Windows\system32\DRIVERS\SophosBootDriver.sys --> C:\Windows\system32\DRIVERS\SophosBootDriver.sys [?]
.
=============== Created Last 30 ================
.
2012-07-22 00:09:57 -------- d-----w- C:\Program Files\HitmanPro
2012-07-22 00:09:07 -------- d-----w- C:\ProgramData\HitmanPro
2012-07-21 21:14:04 -------- d-----w- C:\Users\xxx\AppData\Roaming\Malwarebytes
2012-07-21 21:13:30 -------- d-----w- C:\ProgramData\Malwarebytes
2012-07-21 21:13:29 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-07-21 21:13:29 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-21 20:44:37 -------- d-----w- C:\ProgramData\225932FD1A797471813CA379F875F002
2012-07-21 17:59:46 -------- d-----w- C:\Users\xxx\AppData\Local\{E4ED0285-A339-41F2-B07B-DA4708569B9C}
2012-07-21 17:59:34 -------- d-----w- C:\Users\xxx\AppData\Local\{D8D533A3-3CC9-49FA-88EB-1223C9D894C3}
2012-07-21 05:59:07 -------- d-----w- C:\Users\xxx\AppData\Local\{61E253A7-519D-48D4-8146-78A84AC4E1DE}
2012-07-21 05:58:55 -------- d-----w- C:\Users\xxx\AppData\Local\{A71244C2-E3C9-4236-B519-2E94ADEFC984}
2012-07-20 21:44:10 -------- d-----w- C:\Users\xxx\AppData\Roaming\foobar2000
2012-07-20 21:43:54 -------- d-----w- C:\Program Files (x86)\foobar2000
2012-07-20 21:42:21 66728 ----a-w- C:\Windows\System32\drivers\vrtaucbl.sys
2012-07-20 21:42:21 -------- d-----w- C:\Program Files\Virtual Audio Cable
2012-07-20 17:58:26 -------- d-----w- C:\Users\xxx\AppData\Local\{2F9BBF2F-7E40-40A5-9926-874256DF4983}
2012-07-20 17:58:13 -------- d-----w- C:\Users\xxx\AppData\Local\{9A295D5A-3588-4E33-8336-A1076100685E}
2012-07-20 16:26:44 9133488 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{89BDDC2A-C551-4EF9-B1A2-1C940F5FF59F}\mpengine.dll
2012-07-20 05:57:57 -------- d-----w- C:\Users\xxx\AppData\Local\{6431DB9B-F2BC-466A-AD53-F4D2645C9119}
2012-07-20 05:57:46 -------- d-----w- C:\Users\xxx\AppData\Local\{C13FB841-DE7D-4A8D-98D1-9AC906518DF2}
2012-07-19 17:57:29 -------- d-----w- C:\Users\xxx\AppData\Local\{A3B95644-2A64-4926-A324-7E43BA29D6B4}
2012-07-19 17:57:15 -------- d-----w- C:\Users\xxx\AppData\Local\{E69B228C-4B2C-487A-9B85-0A7032EFBD20}
2012-07-19 05:28:35 -------- d-----w- C:\Users\xxx\AppData\Local\{3D30E2DB-2383-4867-816B-075A49EFA99D}
2012-07-19 05:28:23 -------- d-----w- C:\Users\xxx\AppData\Local\{A2C1CF13-D674-4ADA-804B-DF1145D7FE4C}
2012-07-18 17:28:09 -------- d-----w- C:\Users\xxx\AppData\Local\{12E9A36E-C93E-4125-A158-66CAB6F7463C}
2012-07-18 17:27:55 -------- d-----w- C:\Users\xxx\AppData\Local\{A8325438-27E7-4C66-B50D-5CAC27D9D512}
2012-07-18 05:13:14 -------- d-----w- C:\Users\xxx\AppData\Local\{A0BA40C1-32B8-4A0A-9465-1CA2D191076D}
2012-07-18 05:12:52 -------- d-----w- C:\Users\xxx\AppData\Local\{B3D3D990-8768-4B35-B25B-EDDBF49C5993}
2012-07-17 17:12:38 -------- d-----w- C:\Users\xxx\AppData\Local\{BF4171B8-CE74-40EE-BE28-EB00D3BD0C90}
2012-07-17 17:12:17 -------- d-----w- C:\Users\xxx\AppData\Local\{2F9B81DD-BF36-4D05-B3AE-0B9552F94EC9}
2012-07-17 05:12:02 -------- d-----w- C:\Users\xxx\AppData\Local\{5F3E4A69-CFF9-434D-BBCE-1CB910AFF645}
2012-07-17 05:11:39 -------- d-----w- C:\Users\xxx\AppData\Local\{D48D8071-C000-41B7-B76A-C8BC61B34FC6}
2012-07-16 17:11:26 -------- d-----w- C:\Users\xxx\AppData\Local\{67269A29-508B-42DF-B3E4-CC238B7354BD}
2012-07-16 17:11:12 -------- d-----w- C:\Users\xxx\AppData\Local\{3107A8A4-32D7-46B4-B2EB-C4AA9C4FA45B}
2012-07-16 04:52:37 -------- d-----w- C:\Users\xxx\AppData\Local\{A6BD928D-21F6-4D6C-B132-D511E9AF811D}
2012-07-16 04:52:25 -------- d-----w- C:\Users\xxx\AppData\Local\{B7CF00B7-143D-49FC-B492-31E4EAC6579D}
2012-07-15 16:52:10 -------- d-----w- C:\Users\xxx\AppData\Local\{66700CA9-50FC-476A-8BDA-19DE6B932DFB}
2012-07-15 04:51:43 -------- d-----w- C:\Users\xxx\AppData\Local\{3627EF06-B868-4FF2-BEBA-3350193902CD}
2012-07-15 04:51:32 -------- d-----w- C:\Users\xxx\AppData\Local\{EC1C2954-035A-4EFB-A208-7828E5025FA4}
2012-07-14 16:50:44 -------- d-----w- C:\Users\xxx\AppData\Local\{8F69290F-BD5F-4FE8-B884-8C72F9B9D0E3}
2012-07-13 22:43:37 -------- d-----w- C:\Users\xxx\AppData\Local\{8DB5F643-E575-4622-8CF2-6CBA44BB6FC9}
2012-07-13 22:43:15 -------- d-----w- C:\Users\xxx\AppData\Local\{3651CE10-F084-4DC6-918B-CA156C65DBD5}
2012-07-13 14:21:24 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-12 18:12:19 -------- d-----w- C:\Users\xxx\AppData\Local\{BE64965F-10F9-4AA7-A41B-2D878945B695}
2012-07-12 18:11:57 -------- d-----w- C:\Users\xxx\AppData\Local\{5F7C3ED6-8859-459C-93F5-5025AFE99379}
2012-07-12 06:11:43 -------- d-----w- C:\Users\xxx\AppData\Local\{9D3DF1E5-E842-4A59-A8E1-D43B877EFD2F}
2012-07-12 06:11:22 -------- d-----w- C:\Users\xxx\AppData\Local\{205B18C9-AF37-4029-8D38-FF4362817148}
2012-07-11 18:22:48 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll
2012-07-11 18:22:48 2048 ----a-w- C:\Windows\System32\msxml3r.dll
2012-07-11 18:22:48 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2012-07-11 18:22:48 1881600 ----a-w- C:\Windows\System32\msxml3.dll
2012-07-11 18:22:48 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-07-11 18:22:48 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-07-11 18:19:33 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2012-07-11 18:19:33 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-07-11 18:19:33 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-07-11 18:19:33 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-07-11 18:19:33 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-07-11 18:19:33 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-07-11 18:19:33 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-07-11 18:19:33 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-07-11 18:19:33 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-07-11 18:11:07 -------- d-----w- C:\Users\xxx\AppData\Local\{2D7E57B9-9257-42A6-AC8E-1F63A23A63E1}
2012-07-11 18:10:45 -------- d-----w- C:\Users\xxx\AppData\Local\{5ABEB317-DCA6-498A-B6E9-068C09698CC5}
2012-07-11 04:22:26 -------- d-----w- C:\Users\xxx\AppData\Local\{013F4BDE-86E5-4AF8-B171-7E72779F2549}
2012-07-11 04:22:04 -------- d-----w- C:\Users\xxx\AppData\Local\{14738685-C2F0-4D26-B41B-5CE7FE1427E4}
2012-07-10 16:21:37 -------- d-----w- C:\Users\xxx\AppData\Local\{F221DCF2-DA64-48FA-A8EA-48CD75C0E038}
2012-07-10 16:21:16 -------- d-----w- C:\Users\xxx\AppData\Local\{16539C37-339D-4FA2-A1F8-292A00E9BF59}
2012-07-10 14:34:16 -------- d-----w- C:\Program Files\Microsoft IntelliPoint
2012-07-10 04:20:49 -------- d-----w- C:\Users\xxx\AppData\Local\{4ACC5476-E73C-41A0-946F-04782B28338A}
2012-07-10 04:20:28 -------- d-----w- C:\Users\xxx\AppData\Local\{F6B1EF2C-FF57-4EB3-83CC-E753DE79E571}
2012-07-09 16:20:01 -------- d-----w- C:\Users\xxx\AppData\Local\{62AC3818-12D8-4E94-9B34-F0C0BA24A45C}
2012-07-09 16:19:37 -------- d-----w- C:\Users\xxx\AppData\Local\{C3773540-6088-4477-A2DC-CE757673FA28}
2012-07-09 04:19:23 -------- d-----w- C:\Users\xxx\AppData\Local\{A640DA97-E2FD-46C9-941B-148946FC037F}
2012-07-09 04:19:00 -------- d-----w- C:\Users\xxx\AppData\Local\{6C8CD909-AED1-4D85-BC58-C2111BE7EF6E}
2012-07-08 16:18:44 -------- d-----w- C:\Users\xxx\AppData\Local\{D9F7D074-3A27-4F2B-8BAF-9C39E80B9D96}
2012-07-08 16:18:31 -------- d-----w- C:\Users\xxx\AppData\Local\{8602CC92-45F9-482E-8E95-C5A0C34C0ED3}
2012-07-08 02:05:26 -------- d-----w- C:\Users\xxx\AppData\Local\{5ED8198E-674E-4728-9E1F-75DB6B4D89AE}
2012-07-08 02:05:04 -------- d-----w- C:\Users\xxx\AppData\Local\{BAF562E8-48C7-4F28-A46E-729FADF91205}
2012-07-07 14:04:51 -------- d-----w- C:\Users\xxx\AppData\Local\{9332F7A3-A5F8-4898-B9E4-19EA5CE8E3FA}
2012-07-07 14:04:30 -------- d-----w- C:\Users\xxx\AppData\Local\{9C9B8535-FE8E-48BD-99DA-58F11E99CD02}
2012-07-07 02:04:16 -------- d-----w- C:\Users\xxx\AppData\Local\{E7B8E7B8-C011-4BBB-8EEB-5F92D09924AA}
2012-07-07 02:03:54 -------- d-----w- C:\Users\xxx\AppData\Local\{369FD7EE-4E07-4CCF-B1E7-AA739EE9AA70}
2012-07-06 14:03:06 -------- d-----w- C:\Users\xxx\AppData\Local\{E36528A9-1F7F-4F6D-B137-733D7F413F74}
2012-07-06 14:02:45 -------- d-----w- C:\Users\xxx\AppData\Local\{39F6C924-66FE-4D29-A5ED-16AA7902531C}
2012-07-05 21:00:26 -------- d-----w- C:\Users\xxx\AppData\Local\{12D148D8-DABB-472D-AC08-5B6A243AEEF4}
2012-07-05 21:00:04 -------- d-----w- C:\Users\xxx\AppData\Local\{28934A35-426F-4CD1-96CA-B4A1B9E0D02F}
2012-07-05 08:59:38 -------- d-----w- C:\Users\xxx\AppData\Local\{A09D55D7-BC40-4D6C-81F1-E72260B49FF5}
2012-07-05 08:59:16 -------- d-----w- C:\Users\xxx\AppData\Local\{6E313CCA-F2A1-4270-83DB-E062EF84A1EB}
2012-07-04 20:58:36 -------- d-----w- C:\Users\xxx\AppData\Local\{0C7FF8F9-4E84-4BDF-9CC1-20D7FDB9C119}
2012-07-04 20:58:12 -------- d-----w- C:\Users\xxx\AppData\Local\{BB3CD240-82EE-431D-AAEA-368DF97EA3FD}
2012-07-04 02:03:35 -------- d-----w- C:\Users\xxx\AppData\Local\{394ADA24-DA1B-4769-B8B5-8B2FC60EF4CE}
2012-07-04 02:03:13 -------- d-----w- C:\Users\xxx\AppData\Local\{742131F4-AB52-4B19-B276-396950371403}
2012-07-03 14:03:00 -------- d-----w- C:\Users\xxx\AppData\Local\{E31A735E-8235-44D8-87BE-0A7649B68214}
2012-07-03 14:02:39 -------- d-----w- C:\Users\xxx\AppData\Local\{8B3C53ED-3E9E-463E-A446-F663A22C3ACC}
2012-07-03 02:02:24 -------- d-----w- C:\Users\xxx\AppData\Local\{DF214CF4-0AB4-47B2-A314-7076753C970F}
2012-07-02 14:01:48 -------- d-----w- C:\Users\xxx\AppData\Local\{1D4EE35B-BC28-4D2B-8DFD-0FB1D4936AF4}
2012-07-02 14:01:25 -------- d-----w- C:\Users\xxx\AppData\Local\{DF3BF1A6-5986-4AB1-B77A-0B224C6EB0A1}
2012-07-02 04:24:31 -------- d-----w- C:\Program Files (x86)\WinDirStat
2012-07-01 17:54:27 -------- d-----w- C:\Users\xxx\AppData\Local\{8F0FCD4C-7CFD-4F2B-8CDC-5C00FDBFEF50}
2012-07-01 17:54:05 -------- d-----w- C:\Users\xxx\AppData\Local\{20ADB3C9-D344-44CC-A382-5DB50E4ADCF8}
2012-07-01 05:53:50 -------- d-----w- C:\Users\xxx\AppData\Local\{B14C24CA-8A71-4C91-B659-6920B2F42420}
2012-07-01 05:53:39 -------- d-----w- C:\Users\xxx\AppData\Local\{FBA35CCF-F17E-4D1D-BBB5-DC9A925EABD0}
2012-06-30 17:53:25 -------- d-----w- C:\Users\xxx\AppData\Local\{78E098EF-A5EC-49A6-94B6-61D7BFA97256}
2012-06-30 17:53:03 -------- d-----w- C:\Users\xxx\AppData\Local\{3ABC7F2C-FC5C-4295-AAC4-54E3E444C130}
2012-06-30 05:52:49 -------- d-----w- C:\Users\xxx\AppData\Local\{E94C6717-F177-4C80-ADE3-0A5126867FE0}
2012-06-30 05:52:27 -------- d-----w- C:\Users\xxx\AppData\Local\{DCC2F5B3-3A11-45E1-AF87-E5D25D9B74A3}
2012-06-29 17:52:13 -------- d-----w- C:\Users\xxx\AppData\Local\{5181597E-6650-4AA6-84EE-447E4BCEF608}
2012-06-29 17:51:51 -------- d-----w- C:\Users\xxx\AppData\Local\{2A293C9F-A391-41B5-AF41-BECE08E8281D}
2012-06-29 05:51:38 -------- d-----w- C:\Users\xxx\AppData\Local\{657DAE26-C629-4860-A72B-9AC76BC95B7F}
2012-06-29 05:51:16 -------- d-----w- C:\Users\xxx\AppData\Local\{1B8DE6AF-29DC-4640-BFEC-756CC031CC6B}
2012-06-28 17:50:49 -------- d-----w- C:\Users\xxx\AppData\Local\{B1D46611-42ED-4C8D-A6DA-3B03251FCFBE}
2012-06-28 17:50:27 -------- d-----w- C:\Users\xxx\AppData\Local\{05C9A621-A911-48C7-96E9-FB049652E208}
2012-06-28 05:50:13 -------- d-----w- C:\Users\xxx\AppData\Local\{E3062577-29F5-4F45-BB45-8DA6ABEE845A}
2012-06-28 05:49:50 -------- d-----w- C:\Users\xxx\AppData\Local\{ABAA2888-D107-4965-964B-D7014791699E}
2012-06-27 17:49:37 -------- d-----w- C:\Users\xxx\AppData\Local\{43CEE7AC-C5A9-4D55-86D0-5A9864192C8B}
2012-06-27 17:49:15 -------- d-----w- C:\Users\xxx\AppData\Local\{912C6847-F1C0-4B25-A2B9-25A0EDB00A0B}
2012-06-27 05:49:01 -------- d-----w- C:\Users\xxx\AppData\Local\{E438DB75-6999-4622-B4C1-DA092B09757C}
2012-06-27 05:48:39 -------- d-----w- C:\Users\xxx\AppData\Local\{DBF0B545-9308-4ABA-963C-E276B075F7CF}
2012-06-27 00:38:18 -------- d--h--w- C:\Windows\msdownld.tmp
2012-06-27 00:38:13 -------- d-----w- C:\Windows\SysWow64\directx
2012-06-26 17:48:13 -------- d-----w- C:\Users\xxx\AppData\Local\{1884F285-6DE7-4A91-A68D-F8C24571B9A5}
2012-06-26 05:47:37 -------- d-----w- C:\Users\xxx\AppData\Local\{4B67FD99-BDE5-4CCF-AC64-F2327C73E18E}
2012-06-25 17:46:59 -------- d-----w- C:\Users\xxx\AppData\Local\{3EB9DFC2-679B-4C21-8230-86387F944AB8}
2012-06-25 05:46:22 -------- d-----w- C:\Users\xxx\AppData\Local\{B00041E3-B787-40EE-B200-CDDD0B6107DC}
2012-06-25 05:46:11 -------- d-----w- C:\Users\xxx\AppData\Local\{2A55398F-D5D6-467F-94F9-80A61201B589}
2012-06-24 17:45:37 -------- d-----w- C:\Users\xxx\AppData\Local\{FFE4F7B2-D95B-4CA8-9FAA-19E6C774027B}
2012-06-24 17:45:26 -------- d-----w- C:\Users\xxx\AppData\Local\{80A102A3-7888-4F3C-A182-C322EEA022E4}
2012-06-24 04:38:13 -------- d-----w- C:\Users\xxx\AppData\Local\{6198C06A-D84A-40CD-B71D-1B0ACBE9E295}
2012-06-24 04:37:51 -------- d-----w- C:\Users\xxx\AppData\Local\{29784086-7E01-414F-B9FE-3B2B19EB4306}
2012-06-23 16:37:23 -------- d-----w- C:\Users\xxx\AppData\Local\{FD59D59F-78C5-4C7B-A3DA-642717C0FC13}
2012-06-23 16:36:53 -------- d-----w- C:\Users\xxx\AppData\Local\{ABD733D9-17C1-48BC-9326-5E4E5B397102}
2012-06-22 22:47:23 -------- d-----w- C:\Users\xxx\AppData\Local\{1D542165-937B-40B6-B0E8-022461E2FFBA}
2012-06-22 22:47:08 -------- d-----w- C:\Users\xxx\AppData\Local\{E773719B-2090-468B-9CC4-749C7C7C46E8}
2012-06-22 10:46:41 -------- d-----w- C:\Users\xxx\AppData\Local\{47DB3943-CF79-449F-AF5A-C3F3620991B3}
2012-06-22 10:46:25 -------- d-----w- C:\Users\xxx\AppData\Local\{E6064608-CC00-4C5F-BA87-90180C691D64}
2012-06-22 04:36:01 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-06-22 02:45:37 -------- d-----w- C:\Users\xxx\AppData\Local\{F15CE1D0-79BF-4219-B7FE-550905B5E32F}
.
==================== Find3M ====================
.
2012-06-22 04:36:01 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-02 19:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 19:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-05-31 17:25:12 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-05-15 04:01:31 1188864 ----a-w- C:\Windows\System32\wininet.dll
2012-05-15 03:03:54 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-05-04 11:06:22 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll
2012-04-28 03:55:21 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-26 05:34:27 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-04-24 05:37:37 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2012-04-24 05:37:37 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2012-04-24 05:37:36 1462272 ----a-w- C:\Windows\System32\crypt32.dll
2012-04-24 04:36:42 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-04-24 04:36:42 1158656 ----a-w- C:\Windows\SysWow64\crypt32.dll
2012-04-24 04:36:42 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
.
============= FINISH: 19:48:03.98 ===============


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Back to top











