no what made me suspect there was something wrong is that one day there was a printer connected to my devices list, in investigated and it was printing off xml documents but in command or powershell form somehow also dritek launch manager comes back every time i reboot and system preparation tools with an option to enter a system out of box experience or something
could this cause my system to think its the first time its been turned on? x64-Run: [Trigger New Acer AlaunchX] c:\OEM\Preload\Command\AlaunchX\AppInRun.exe
i think i have removed the virus but maybe some things the virus used to run were left behind heres a recent dds let me know if anything looks to be out of order
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer:
Run by Dankman at 17:22:06 on 2012-11-26
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2814.1976 [GMT -6:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Google\Update\1.3.21.123\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.21.123\GoogleCrashHandler64.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
mRun: [OOTag] C:\Program Files (x86)\Gateway\OOBEOffer\OOTag.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 68.105.28.11 68.105.29.11 68.105.28.12
TCP: Interfaces\{2E9DD83D-B9D2-4267-B754-918072B088EA} : DHCPNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
SSODL: WebCheck - <orphaned>
x64-Run: [Trigger New Acer AlaunchX] c:\OEM\Preload\Command\AlaunchX\AppInRun.exe
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2009-8-18 203264]
R3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2009-6-10 270848]
R3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
R3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
R3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-24 19456]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-11-24 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2012-11-24 30208]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-11-24 1255736]
.
=============== File Associations ===============
.
FileExt: .com: Applications\cmd.exe.exe="C:\Windows\System32\cmd.exe.exe" "%1" [UserChoice]
.
=============== Created Last 30 ================
.
2012-11-26 20:20:19 -------- d-----w- C:\Users\Dankman\AppData\Local\Google
2012-11-26 20:20:01 73656 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-11-26 20:20:01 697272 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-11-26 19:52:52 -------- d-----w- C:\220ba1745afac0120176e5
2012-11-25 09:51:31 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2012-11-25 09:51:30 9728 ----a-w- C:\Windows\System32\Wdfres.dll
2012-11-25 09:51:30 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys
2012-11-25 09:51:30 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys
2012-11-25 09:51:13 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2012-11-25 09:51:13 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2012-11-25 09:51:13 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2012-11-25 09:51:13 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2012-11-25 09:51:12 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2012-11-25 09:51:12 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2012-11-25 09:51:12 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2012-11-25 05:47:36 -------- d-----w- C:\Users\Dankman\AppData\Local\temp
2012-11-25 05:44:41 -------- d-sh--w- C:\$RECYCLE.BIN
2012-11-25 05:38:30 98816 ----a-w- C:\Windows\sed.exe
2012-11-25 05:38:30 256000 ----a-w- C:\Windows\PEV.exe
2012-11-25 05:38:30 208896 ----a-w- C:\Windows\MBR.exe
2012-11-24 19:19:15 0 ----a-w- C:\Windows\ativpsrm.bin
2012-11-24 16:25:32 -------- d-----w- C:\Users\Dankman\AppData\Local\Apps
2012-11-24 16:24:57 -------- d-----w- C:\Users\Dankman\AppData\Local\ElevatedDiagnostics
2012-11-24 16:08:36 -------- d-----w- C:\Windows\OEMTemp
2012-11-24 14:29:16 -------- d-----w- C:\Windows\SysWow64\Wat
2012-11-24 14:29:16 -------- d-----w- C:\Windows\System32\Wat
2012-11-24 14:00:07 3072 ----a-w- C:\Windows\System32\drivers\en-US\tsusbflt.sys.mui
2012-11-24 13:55:54 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-11-24 13:55:54 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-11-24 13:55:54 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-11-24 13:55:54 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-11-24 13:55:54 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-11-24 13:54:42 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2012-11-24 13:54:42 366592 ----a-w- C:\Windows\System32\qdvd.dll
2012-11-24 13:54:41 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2012-11-24 13:54:41 458712 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-11-24 13:54:41 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-11-24 13:54:41 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-11-24 13:54:41 247808 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-11-24 13:54:41 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-11-24 13:54:41 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-11-24 13:54:41 154480 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-11-24 13:54:41 1448448 ----a-w- C:\Windows\System32\lsasrv.dll
2012-11-24 13:54:40 1659760 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2012-11-24 13:17:58 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-11-24 13:16:52 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2012-11-24 13:16:52 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2012-11-24 13:16:52 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2012-11-24 13:16:52 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2012-11-24 13:16:51 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-11-24 13:16:41 498688 ----a-w- C:\Windows\System32\drivers\afd.sys
2012-11-24 13:16:40 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys
2012-11-24 13:16:39 715776 ----a-w- C:\Windows\System32\kerberos.dll
2012-11-24 13:16:39 542208 ----a-w- C:\Windows\SysWow64\kerberos.dll
2012-11-24 13:16:37 3216384 ----a-w- C:\Windows\System32\msi.dll
2012-11-24 13:16:36 95744 ----a-w- C:\Windows\System32\synceng.dll
2012-11-24 13:16:36 78336 ----a-w- C:\Windows\SysWow64\synceng.dll
2012-11-24 13:16:36 2342400 ----a-w- C:\Windows\SysWow64\msi.dll
2012-11-24 13:09:58 1731920 ----a-w- C:\Windows\System32\ntdll.dll
2012-11-24 13:06:42 -------- d-----w- C:\Users\Dankman\AppData\Roaming\WildTangent
2012-11-24 13:01:54 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2012-11-24 13:01:54 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-11-24 13:01:54 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2012-11-24 12:57:14 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-11-24 12:57:10 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-11-24 12:57:06 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-11-24 12:57:06 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-11-24 06:55:53 -------- d-----w- C:\Users\Dankman\AppData\Local\Microsoft Games
2012-11-24 06:43:37 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2012-11-24 06:08:23 -------- d-----w- C:\Users\Dankman\AppData\Local\Diagnostics
2012-11-24 06:07:31 -------- d-----w- C:\Users\Dankman\AppData\Local\VirtualStore
2012-11-23 21:06:06 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2012-11-23 21:05:34 180736 ----a-w- C:\Windows\System32\ifsutil.dll
2012-11-23 21:05:34 148992 ----a-w- C:\Windows\SysWow64\ifsutil.dll
2012-11-23 20:57:15 -------- d-----w- C:\Windows\NAPP_Dism_Log
.
==================== Find3M ====================
.
2012-10-18 18:25:58 3149824 ----a-w- C:\Windows\System32\win32k.sys
2012-10-09 18:17:13 55296 ----a-w- C:\Windows\System32\dhcpcsvc6.dll
2012-10-09 18:17:13 226816 ----a-w- C:\Windows\System32\dhcpcore6.dll
2012-10-09 17:40:31 44032 ----a-w- C:\Windows\SysWow64\dhcpcsvc6.dll
2012-10-09 17:40:31 193536 ----a-w- C:\Windows\SysWow64\dhcpcore6.dll
2012-10-08 11:31:03 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2012-10-08 11:23:52 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-10-08 11:22:55 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-10-08 11:18:22 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-10-08 11:17:35 599040 ----a-w- C:\Windows\System32\vbscript.dll
2012-10-08 11:13:33 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-10-08 07:56:24 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-10-08 07:48:03 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-10-08 07:47:44 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-10-08 07:44:05 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-10-08 07:43:21 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2012-10-08 07:40:56 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-10-03 17:56:54 1914248 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-10-03 17:44:21 70656 ----a-w- C:\Windows\System32\nlaapi.dll
2012-10-03 17:44:21 303104 ----a-w- C:\Windows\System32\nlasvc.dll
2012-10-03 17:44:17 246272 ----a-w- C:\Windows\System32\netcorehc.dll
2012-10-03 17:44:17 18944 ----a-w- C:\Windows\System32\netevent.dll
2012-10-03 17:44:16 216576 ----a-w- C:\Windows\System32\ncsi.dll
2012-10-03 17:42:16 569344 ----a-w- C:\Windows\System32\iphlpsvc.dll
2012-10-03 16:42:24 18944 ----a-w- C:\Windows\SysWow64\netevent.dll
2012-10-03 16:42:24 175104 ----a-w- C:\Windows\SysWow64\netcorehc.dll
2012-10-03 16:42:23 156672 ----a-w- C:\Windows\SysWow64\ncsi.dll
2012-10-03 16:07:26 45568 ----a-w- C:\Windows\System32\drivers\tcpipreg.sys
2012-09-14 19:19:29 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-09-14 18:28:53 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-08-30 17:12:02 3968880 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:12:02 3914096 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
.
============= FINISH: 17:22:36.55 ===============
attach.txt 4.71K
1 downloads