Somehow I got infected with something which disabled Security Center, firewall & defender. Their registry records were removed and I had to add them back via reg files.
I did not think of a current or past infection, until I realised that all 3 were down. I only thought firewall was not working right.
Currently have no symptoms, the services are back in action after reg import and reboot.
But just to be sure, in case theres a backdoor or super deep rootkit infection (malwarebytes and avira showed nothing)
So.. hopefully you guys can give me a peace of mind.
GMER doesn't allow me to unselect certain options? everything seems greyed out (see apic.jpg attachment), so I just scanned as it is.
cheers.
btw, as a side issue/knowledge for myself, avira antivira premium has a rootkit scanner inbuilt right? does it use the GMER engine?
DDS:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1
Run by Alvin at 15:00:37 on 2012-08-18
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.65.1033.18.3071.410 [GMT 10:00]
.
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Acronis\Agent\agent.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
C:\Windows\SysWOW64\vmnat.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\SysWOW64\vmnetdhcp.exe
C:\Program Files (x86)\Acronis\DiskDirectorAdvanced\mms.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe
C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe
C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat.exe
C:\Windows\splwow64.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Users\Alvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alvin\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Windows\system32\mmc.exe
C:\Users\Alvin\AppData\Local\Temp\Rar$EX83.064\gmer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.au/
uInternet Settings,ProxyOverride = proxy.singnet.com.sg:8080;127.0.0.1;192.168.1.1;10.0.0.1;<local>
uInternet Settings,ProxyServer = 118.139.163.241:8888
uURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: 5CC9F367-9125-CA5C-B5BD-A560352F41BC Class: {5cc9f367-9125-ca5c-b5bd-a560352f41bc} - C:\Program Files (x86)\Funshion Online\Funshion\FunshionAddr\funshionAddr.dll
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [Google Update] "C:\Users\Alvin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Funshion] C:\Program Files (x86)\Funshion Online\Funshion\Funshion.exe startbywindows tray
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun: [<NO NAME>]
mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
mRunOnce: [GrpConv] grpconv -o
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to &Teleport - E:\Program Files\Teleport Pro\teleport.htm
IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
LSP: C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{F788ED93-5157-4D83-A7E3-2160CC04ADD3} : DhcpNameServer = 192.168.0.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: 5CC9F367-9125-CA5C-B5BD-A560352F41BC Class: {5CC9F367-9125-CA5C-B5BD-A560352F41BC} - C:\Program Files (x86)\Funshion Online\Funshion\FunshionAddr\funshionAddr.dll
BHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
BHO-X64: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: SmartSelect - No File
TB-X64: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB-X64: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
mRun-x64: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
mRun-x64: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
mRun-x64: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
mRun-x64: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun-x64: [(Default)]
mRun-x64: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
mRunOnce-x64: [GrpConv] grpconv -o
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Alvin\AppData\Roaming\Mozilla\Firefox\Profiles\ow6rg82d.FFnew\
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
FF - plugin: C:\Users\Alvin\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Users\Alvin\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Alvin\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R0 BtHidBus;Bluetooth HID Bus Service;C:\Windows\system32\Drivers\BtHidBus.sys --> C:\Windows\system32\Drivers\BtHidBus.sys [?]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R2 avgntflt;avgntflt;C:\Windows\system32\DRIVERS\avgntflt.sys --> C:\Windows\system32\DRIVERS\avgntflt.sys [?]
R3 NETwLv64; Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\NETwLv64.sys --> C:\Windows\system32\DRIVERS\NETwLv64.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
RUnknown 64253122;64253122; [x]
RUnknown 8645359drv;8645359drv; [x]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;C:\Windows\system32\Drivers\ssadadb.sys --> C:\Windows\system32\Drivers\ssadadb.sys [?]
S3 btnetBUs;Bluetooth PAN Bus Service;C:\Windows\system32\Drivers\btnetBus.sys --> C:\Windows\system32\Drivers\btnetBus.sys [?]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 IvtBtBUs;IVT Bluetooth Bus Service;C:\Windows\system32\Drivers\IvtBtBus.sys --> C:\Windows\system32\Drivers\IvtBtBus.sys [?]
S3 massfilter_lte;LTE Device Mass Storage Filter Driver;\??\C:\Windows\system32\drivers\massfilter_lte.sys --> C:\Windows\system32\drivers\massfilter_lte.sys [?]
S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 pwdrvio;pwdrvio;\??\C:\Windows\system32\pwdrvio.sys --> C:\Windows\system32\pwdrvio.sys [?]
S3 pwdspio;pwdspio;\??\C:\Windows\system32\pwdspio.sys --> C:\Windows\system32\pwdspio.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\system32\DRIVERS\ssadbus.sys --> C:\Windows\system32\DRIVERS\ssadbus.sys [?]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\system32\DRIVERS\ssadmdfl.sys --> C:\Windows\system32\DRIVERS\ssadmdfl.sys [?]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\system32\DRIVERS\ssadmdm.sys --> C:\Windows\system32\DRIVERS\ssadmdm.sys [?]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\system32\drivers\synth3dvsc.sys --> C:\Windows\system32\drivers\synth3dvsc.sys [?]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys --> C:\Windows\system32\drivers\terminpt.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 tsusbhub;tsusbhub;C:\Windows\system32\drivers\tsusbhub.sys --> C:\Windows\system32\drivers\tsusbhub.sys [?]
.
=============== Created Last 30 ================
.
2012-08-18 03:20:05 -------- d-----w- C:\ProgramData\Kaspersky Lab
2012-08-17 10:11:37 552960 ----a-w- C:\Windows\System32\drivers\bthport.sys
2012-08-17 05:07:03 1462272 ----a-w- C:\Windows\System32\crypt32.dll
2012-08-17 05:07:03 1158656 ----a-w- C:\Windows\SysWow64\crypt32.dll
2012-08-17 05:07:02 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2012-08-17 05:07:02 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-08-17 05:07:02 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2012-08-17 05:07:02 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2012-08-17 05:06:23 3216384 ----a-w- C:\Windows\System32\msi.dll
2012-08-17 05:06:22 2342400 ----a-w- C:\Windows\SysWow64\msi.dll
2012-08-17 05:06:20 209920 ----a-w- C:\Windows\System32\profsvc.dll
2012-08-17 05:06:17 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-08-17 05:06:16 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-08-17 05:06:15 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-08-17 05:03:25 59392 ----a-w- C:\Windows\System32\browcli.dll
2012-08-17 05:03:25 41984 ----a-w- C:\Windows\SysWow64\browcli.dll
2012-08-17 05:03:25 136704 ----a-w- C:\Windows\System32\browser.dll
2012-08-17 04:47:01 1499136 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll
2012-08-17 04:47:00 1019904 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
2012-08-17 04:46:59 466944 ----a-w- C:\Program Files\Common Files\System\ado\msadomd.dll
2012-08-17 04:46:58 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2012-08-17 04:46:58 57344 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msador15.dll
2012-08-17 04:46:58 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll
2012-08-17 04:46:58 352256 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll
2012-08-17 04:46:58 258048 ----a-w- C:\Program Files\Common Files\System\msadc\msadco.dll
2012-08-17 04:46:57 61440 ----a-w- C:\Program Files\Common Files\System\ado\msador15.dll
2012-08-17 04:46:57 212992 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll
2012-08-17 04:46:56 372736 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll
2012-08-17 04:46:56 143360 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msjro.dll
2012-08-17 04:46:56 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2012-08-17 04:45:54 956928 ----a-w- C:\Windows\System32\localspl.dll
2012-08-17 03:10:25 -------- d-----w- C:\Program Files (x86)\IVT Corporation
2012-08-16 13:10:38 -------- d-----w- C:\Windows\XSxS
2012-08-16 13:10:38 -------- d-----w- C:\Program Files (x86)\Xenocode
2012-08-15 03:47:28 -------- d-----w- C:\Program Files (x86)\Resource Hacker
2012-08-09 09:42:17 3982240 ----a-w- C:\Windows\SysWow64\Flash10d.ocx
2012-08-09 09:42:16 -------- d-----w- C:\Program Files (x86)\StreamTransport
2012-08-07 10:50:16 -------- d-----w- C:\Program Files (x86)\Ico's Immo Cleaner
2012-08-02 10:52:55 -------- d-----w- C:\Users\Alvin\AppData\Roaming\gpdf2swf
.
==================== Find3M ====================
.
2012-08-17 10:51:01 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-17 10:51:01 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-08-17 10:48:21 151552 ----a-w- C:\Windows\KMSEmulator.exe
2012-07-18 18:15:06 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-03 03:46:44 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-06-29 03:56:34 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2012-06-29 03:49:11 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-06-29 03:48:07 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-06-29 03:43:49 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-06-29 03:39:48 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-29 00:16:58 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-29 00:09:01 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-29 00:08:59 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-29 00:04:43 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-29 00:00:45 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-08 16:37:32 942744 ----a-w- C:\Windows\System32\vnetlib64.dll
2012-06-08 16:37:26 63128 ----a-w- C:\Windows\System32\drivers\vmx86.sys
2012-06-08 16:37:04 433816 ----a-w- C:\Windows\SysWow64\vmnat.exe
2012-06-08 16:36:36 354456 ----a-w- C:\Windows\SysWow64\vmnetdhcp.exe
2012-06-08 16:36:16 32920 ----a-w- C:\Windows\System32\drivers\VMkbd.sys
2012-06-08 16:35:38 30360 ----a-w- C:\Windows\System32\drivers\vmnetuserif.sys
2012-06-08 14:29:42 252056 ----a-w- C:\Windows\SysWow64\vmnc.dll
2012-06-08 13:52:20 62064 ----a-w- C:\Windows\System32\vmnetbridge.dll
2012-06-08 13:52:20 48752 ----a-w- C:\Windows\System32\vnetinst.dll
2012-06-08 13:52:20 45680 ----a-w- C:\Windows\System32\drivers\vmnetbridge.sys
2012-06-08 13:52:20 24176 ----a-w- C:\Windows\System32\drivers\vmnet.sys
2012-06-08 13:52:20 20080 ----a-w- C:\Windows\System32\drivers\vmnetadapter.sys
2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll
2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 05:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 05:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
.
============= FINISH: 15:02:49.39 ===============


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked


Back to top











