- Windows Security Center is disabled and cannot be restarted
- Windows Security Essentials is disabled
- Google (and other) searches redirect incorrectly
I have pretty much tried every documented removal strategy/tool with no success. Please find attached the requested documentation. Note that GMER did not allow me to select/deselect the options you require (another symptom of the rootkit?)
Appreciate any help you can provide.
Cheers
/Ph.
.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 8.0.7600.16385
Run by Phil.Geyskens at 9:31:01 on 2011-05-22
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.3958.2047 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
AV: Sophos Anti-Virus *Enabled/Updated* {479CCF92-4960-B3E0-7373-BF453B467D2C}
SP: Sophos Anti-Virus *Enabled/Updated* {FCFD2E76-6F5A-BC6E-49C3-843740C13791}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\LANDesk\Shared Files\residentagent.exe
C:\Program Files (x86)\CheckPoint\SSL Network Extender\slimsvc.exe
C:\Program Files (x86)\Dell\Reader 2.1\DVMExportService.exe
C:\Program Files (x86)\LANDesk\LDClient\LocalSch.EXE
C:\Windows\SysWOW64\CBA\pds.exe
C:\PROGRA~2\LANDesk\LDClient\issuser.exe
C:\Program Files (x86)\LANDesk\LDClient\policy.client.invoker.exe
C:\Program Files (x86)\LANDesk\LDClient\collector.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\LANDesk\LDClient\tmcsvc.exe
C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kDell.exe
C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files (x86)\LANDesk\LDClient\softmon.exe
C:\Program Files (x86)\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files (x86)\Sophos\Remote Management System\RouterNT.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe
C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Windows\System32\rundll32.exe
C:\PROGRA~2\LANDesk\LDClient\rcgui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\igfxtray.exe
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Users\phil.geyskens\AppData\Local\Plaxo\3.26.0.13\PlaxoHelper_en.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\phil.geyskens\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Dell\Reader 2.1\DellBtrEvent.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\phil.geyskens\Desktop\gmer.exe
C:\Windows\system32\DllHost.exe
C:\Users\phil.geyskens\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\phil.geyskens\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\phil.geyskens\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\phil.geyskens\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\phil.geyskens\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\phil.geyskens\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\phil.geyskens\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\phil.geyskens\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\phil.geyskens\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\phil.geyskens\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Users\phil.geyskens\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\phil.geyskens\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\phil.geyskens\Desktop\dds.scr
C:\Windows\SysWOW64\WSCRIPT.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.bing.com/
mWinlogon: Userinit=userinit.exe,
BHO: {00C6482D-C502-44C8-8409-FCE54AD9C208} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Sophos Web Content Scanner: {39ea7695-b3f2-4c44-a4bc-297ada8fd235} - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SophosBHO.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - No File
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [PlaxoUpdate] C:\Users\phil.geyskens\AppData\Local\Plaxo\3.26.0.13\PlaxoHelper_en.exe -a
uRun: [PlaxoSysTray] C:\Users\phil.geyskens\AppData\Local\Plaxo\3.26.0.13\PlaxoSysTray.exe
uRun: [Google Update] "C:\Users\phil.geyskens\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe
mRun: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
mRun: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [DellBtrEvent] C:\Program Files (x86)\Dell\Reader 2.1\DellBtrEvent.exe
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
StartupFolder: C:\Users\PHIL~1.GEY\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\phil.geyskens\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\PHIL~1.GEY\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\EVERNO~1.LNK - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SNAGIT~1.LNK - C:\Program Files (x86)\TechSmith\Snagit 10\Snagit32.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\WDDMST~1.LNK - C:\Program Files (x86)\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
uPolicies-explorer: NoWelcomeScreen = 1 (0x1)
uPolicies-explorer: NoSimpleStartMenu = 1 (0x1)
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
mPolicies-system: SoftwareSASGeneration = 1 (0x1)
mPolicies-system: HideShutdownScripts = 1 (0x1)
mPolicies-system: MaxGPOScriptWait = 600 (0x258)
IE: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
Trusted Zone: hhcc.com\vpn
DPF: {08496B45-6BB1-4F92-A8E6-B9E7978634CB} - hxxps://vpn.hhcc.com/nortel_cacheable/TrustSite.cab
DPF: {7FA319FB-FFB9-4089-87EB-63179244E6E6} - hxxps://vpn.hhcc.com/nortel_cacheable/NetDirect.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {A2505C6C-6F17-456F-89D2-4301FBDC6EC7} - hxxps://vpn.hhcc.com/nortel_cacheable/iewiper.cab
DPF: {ACDB1787-986D-434D-9857-2172CDB2108D} - hxxps://vpn.hhcc.com/nortel_cacheable/punblock.cab
DPF: {B4CB50E4-0309-4906-86EA-10B6641C8392} - hxxps://cpvpn.hhcc.com/SNX/CSHELL/extender.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: qvp - {4BA78E3D-CA25-4BFF-B8F0-8A3359E4B520} - C:\Program Files (x86)\QlikView\QvProtocol\qvp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL
mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
BHO-X64: {00C6482D-C502-44C8-8409-FCE54AD9C208} - No File
BHO-X64: Sophos Web Content Scanner: {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SophosBHOX64.dll
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
TB-X64: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - No File
TB-X64: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
mRun-x64: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
mRun-x64: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
mRun-x64: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
mRun-x64: [Broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe
mRun-x64: [Apoint] C:\Program Files\DellTPad\Apoint.exe
AppInit_DLLs-X64: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\system32\DRIVERS\stdcfltn.sys --> C:\Windows\system32\DRIVERS\stdcfltn.sys [?]
R1 DVMIO;DVMIO;C:\Program Files (x86)\Dell\Reader 2.1\dvmio_x64.sys [2010-5-4 20624]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 SAVOnAccess;SAVOnAccess;C:\Windows\system32\DRIVERS\savonaccess.sys --> C:\Windows\system32\DRIVERS\savonaccess.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2011-4-20 89600]
R2 CBA8;LANDesk® Management Agent;C:\Program Files (x86)\LANDesk\Shared Files\residentAgent.exe [2009-11-4 147456]
R2 CISMBIOS;CISMBIOS;\??\C:\Windows\system32\drivers\cismbios.sys --> C:\Windows\system32\drivers\cismbios.sys [?]
R2 cpextender;Check Point SSL Network Extender;C:\Program Files (x86)\CheckPoint\SSL Network Extender\slimsvc.exe [2010-11-28 353800]
R2 DvmMDES;DeviceVM Meta Data Export Service;C:\Program Files (x86)\Dell\Reader 2.1\DVMExportService.exe [2010-5-4 327680]
R2 LANDesk Policy Invoker;LANDesk Policy Invoker;C:\Program Files (x86)\LANDesk\LDClient\policy.client.invoker.exe [2011-4-20 195072]
R2 LANDesk Targeted Multicast;LANDesk Targeted Multicast;C:\Program Files (x86)\LANDesk\LDClient\tmcsvc.exe [2011-4-20 182272]
R2 QDLService2kDell_CTC;Qualcomm Gobi 2000 Download Service (Dell_CTC);C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kDell.exe [2010-5-17 331512]
R2 risdpcie;risdpcie;C:\Windows\system32\DRIVERS\risdpe64.sys --> C:\Windows\system32\DRIVERS\risdpe64.sys [?]
R2 SAVAdminService;Sophos Anti-Virus status reporter;C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2011-4-20 163056]
R2 SAVService;Sophos Anti-Virus;C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [2011-4-20 97520]
R2 Softmon;LANDesk® Software Monitoring Service;C:\Program Files (x86)\LANDesk\LDClient\softmon.exe [2011-4-20 385024]
R2 Sophos Agent;Sophos Agent;C:\Program Files (x86)\Sophos\Remote Management System\ManagementAgentNT.exe [2011-4-20 282624]
R2 Sophos AutoUpdate Service;Sophos AutoUpdate Service;C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [2010-9-30 230640]
R2 Sophos Message Router;Sophos Message Router;C:\Program Files (x86)\Sophos\Remote Management System\RouterNT.exe [2011-4-20 806912]
R2 swi_service;Sophos Web Intelligence Service;C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2011-4-20 1541360]
R2 WDDMService;WDDMService;C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2011-3-9 288768]
R2 WDFME;WD File Management Engine;C:\Program Files (x86)\Western Digital\WD Smartware\Front Parlor\WDFME\WDFME.exe [2011-3-9 1066896]
R2 WDSC;WD File Management Shadow Engine;C:\Program Files (x86)\Western Digital\WD Smartware\Front Parlor\WDSC.exe [2011-3-9 491920]
R2 WMCoreService;Mobile Broadband Service;C:\Program Files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe servicemode --> C:\Program Files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe servicemode [?]
R3 Acceler;Accelerometer Service;C:\Windows\system32\DRIVERS\Accelern.sys --> C:\Windows\system32\DRIVERS\Accelern.sys [?]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;C:\Windows\system32\DRIVERS\e1k62x64.sys --> C:\Windows\system32\DRIVERS\e1k62x64.sys [?]
R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --> C:\Windows\system32\DRIVERS\Impcd.sys [?]
R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 ldmirror;ldmirror;C:\Windows\system32\DRIVERS\ldmirror.sys --> C:\Windows\system32\DRIVERS\ldmirror.sys [?]
R3 mirrorflt;Mirror Filter Driver for Uninstall;C:\Windows\system32\DRIVERS\mirrorflt.sys --> C:\Windows\system32\DRIVERS\mirrorflt.sys [?]
R3 VNA;Check Point Virtual Network Adapter;C:\Windows\system32\DRIVERS\vna.sys --> C:\Windows\system32\DRIVERS\vna.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot\SDWinSec.exe [2011-5-10 1153368]
S3 ldblank;Screen Blanking driver for Remote Control;C:\Windows\system32\DRIVERS\ldblank.sys --> C:\Windows\system32\DRIVERS\ldblank.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\C:\Windows\system32\20BA.tmp --> C:\Windows\system32\20BA.tmp [?]
S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 sdcfilter;sdcfilter;C:\Windows\system32\DRIVERS\sdcfilter.sys --> C:\Windows\system32\DRIVERS\sdcfilter.sys [?]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\system32\DRIVERS\wdcsam64.sys --> C:\Windows\system32\DRIVERS\wdcsam64.sys [?]
S4 ProcTrigger;LANDesk® Process Trigger Service;C:\Program Files (x86)\LANDesk\LDClient\ProcTriggerSvc.exe [2011-4-20 73216]
S4 SophosBootDriver;SophosBootDriver;C:\Windows\system32\DRIVERS\SophosBootDriver.sys --> C:\Windows\system32\DRIVERS\SophosBootDriver.sys [?]
S4 tracksvc;LANDesk® Power Management Track Service;C:\Program Files (x86)\LANDesk\LDClient\tracksvc.exe [2011-4-20 66048]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-05-20 14:14:36 72080 ----a-w- C:\Users\phil.geyskens\g2mdlhlpx.exe
2011-05-17 19:17:25 -------- d-----w- C:\Windows\5BCC634A58AD42F9B3C62EA52F81CF85.TMP
2011-05-16 09:23:17 388096 ----a-r- C:\Users\phil.geyskens\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-15 23:18:31 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\2D87.tmp
2011-05-15 23:18:31 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\2D67.tmp
2011-05-15 23:18:31 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\2CF9.tmp
2011-05-15 19:35:54 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\56E9.tmp
2011-05-15 19:35:54 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\56B9.tmp
2011-05-15 19:35:54 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\5699.tmp
2011-05-15 18:30:22 65736 ----a-w- C:\Windows\System32\drivers\pxrts.sys
2011-05-13 13:37:47 -------- d-----w- C:\Program Files\Speccy
2011-05-13 13:37:21 -------- d-----w- C:\Program Files\Defraggler
2011-05-12 17:57:16 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2011-05-12 09:40:34 20040 ----a-w- C:\Windows\System32\drivers\hitmanpro35.sys
2011-05-12 09:40:05 -------- d-----w- C:\ProgramData\Hitman Pro
2011-05-11 22:29:23 34560 ----a-w- C:\Windows\SysWow64\drivers\Normandy.sys
2011-05-10 17:56:04 -------- d-----w- C:\ProgramData\PrevxCSI
2011-05-10 17:40:41 6144 ------w- C:\Windows\System32\20BA.tmp
2011-05-10 17:39:19 6144 ------w- C:\Windows\System32\DF65.tmp
2011-05-10 16:29:59 6144 ------w- C:\Windows\System32\3ABF.tmp
2011-05-10 16:28:36 6144 ------w- C:\Windows\System32\F99A.tmp
2011-05-10 15:25:25 -------- d-----w- C:\Program Files (x86)\Trend Micro
2011-05-10 15:20:46 -------- d-----w- C:\Windows\pss
2011-05-10 13:36:40 -------- d-----w- C:\Users\phil.geyskens\AppData\Local\{D6908907-8732-4EF9-AF9E-44F43EED5366}
2011-05-10 13:36:25 -------- d-----w- C:\Users\phil.geyskens\Tracing
2011-05-10 13:28:15 -------- d-----w- C:\Windows\en
2011-05-10 13:22:33 69464 ----a-w- C:\Windows\SysWow64\XAPOFX1_3.dll
2011-05-10 13:22:33 523088 ----a-w- C:\Windows\System32\d3dx10_42.dll
2011-05-10 13:22:33 515416 ----a-w- C:\Windows\SysWow64\XAudio2_5.dll
2011-05-10 13:22:33 453456 ----a-w- C:\Windows\SysWow64\d3dx10_42.dll
2011-05-10 13:22:28 4398360 ----a-w- C:\Windows\System32\d3dx9_32.dll
2011-05-10 13:22:28 3426072 ----a-w- C:\Windows\SysWow64\d3dx9_32.dll
2011-05-10 13:22:12 1164800 ----a-w- C:\Windows\SysWow64\UIRibbonRes.dll
2011-05-10 13:22:11 3860992 ----a-w- C:\Windows\System32\UIRibbon.dll
2011-05-10 13:22:11 2983424 ----a-w- C:\Windows\SysWow64\UIRibbon.dll
2011-05-10 13:22:11 1164800 ----a-w- C:\Windows\System32\UIRibbonRes.dll
2011-05-10 13:19:00 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\d359f80a1cc0f1419\MeshBetaRemover.exe
2011-05-10 13:18:56 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\d08960781cc0f1418\DSETUP.dll
2011-05-10 13:18:56 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\d08960781cc0f1418\DXSETUP.exe
2011-05-10 13:18:56 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\d08960781cc0f1418\dsetup32.dll
2011-05-10 13:18:52 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cd7e56771cc0f1417\DSETUP.dll
2011-05-10 13:18:52 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cd7e56771cc0f1417\DXSETUP.exe
2011-05-10 13:18:52 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\cd7e56771cc0f1417\dsetup32.dll
2011-05-10 13:16:37 -------- d-----w- C:\Users\phil.geyskens\AppData\Local\Windows Live
2011-05-10 13:16:36 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2011-05-10 12:04:49 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-05-10 12:04:49 -------- d-----w- C:\Program Files (x86)\Spybot
2011-05-09 06:53:33 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\117F.tmp
2011-05-09 06:53:33 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\116E.tmp
2011-05-09 06:53:33 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\115E.tmp
2011-05-09 04:00:44 -------- d-----w- C:\Program Files (x86)\LinkedIn
2011-05-09 03:58:49 -------- d-----w- C:\Program Files (x86)\MSECache
2011-05-09 03:57:47 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\1E18.tmp
2011-05-09 03:57:47 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\1E17.tmp
2011-05-09 03:57:47 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\1E16.tmp
2011-05-08 06:49:08 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-05-08 06:49:07 -------- d-----w- C:\ProgramData\Malwarebytes
2011-05-07 15:26:54 178688 --sha-r- C:\Windows\SysWow64\wsecedit7.dll
2011-05-06 20:18:01 8802128 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{19E57FCD-375D-4B7D-A6F7-4CF68E2A905D}\mpengine.dll
2011-05-06 11:07:08 -------- d-----w- C:\Users\phil.geyskens\AppData\Roaming\KeePass
2011-05-06 10:56:55 -------- d-----w- C:\Program Files (x86)\KeePass Password Safe 2
2011-05-03 23:49:58 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\B211.tmp
2011-05-03 23:49:58 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\B174.tmp
2011-05-03 23:49:58 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\B173.tmp
2011-05-03 03:03:45 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\2717.tmp
2011-05-03 03:03:45 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\2716.tmp
2011-05-03 03:03:45 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\2705.tmp
2011-04-28 21:26:10 -------- d-----w- C:\Users\phil.geyskens\AppData\Local\ElevatedDiagnostics
2011-04-28 19:47:57 -------- d-----w- C:\Program Files\Kyocera
2011-04-28 10:59:56 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\7CDE.tmp
2011-04-28 10:59:56 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\7C41.tmp
2011-04-28 10:59:55 0 ----a-w- C:\Users\phil.geyskens\AppData\Local\7C31.tmp
2011-04-27 15:17:08 -------- d-----w- C:\Program Files (x86)\CheckPoint
2011-04-27 15:03:03 -------- d-----w- C:\Users\phil.geyskens\AppData\Roaming\webex
2011-04-27 14:12:24 -------- d-----w- C:\ProgramData\WebEx
2011-04-27 13:00:22 -------- d-----w- C:\Program Files (x86)\Citrix
2011-04-27 12:07:53 -------- d-----w- C:\Users\phil.geyskens\AppData\Local\Apple Computer
2011-04-27 01:08:23 -------- d-----w- C:\Users\phil.geyskens\AppData\Local\Plaxo
2011-04-26 12:12:58 -------- d-----w- C:\Program Files\Common Files\Intel
2011-04-26 12:12:57 -------- d-----w- C:\Program Files (x86)\Common Files\Intel
2011-04-25 04:31:11 -------- d-----w- C:\Users\phil.geyskens\AppData\Roaming\PrimoPDF
2011-04-23 15:12:58 -------- d-----w- C:\Program Files\Western Digital
2011-04-23 15:05:36 -------- d-----w- C:\Users\phil.geyskens\AppData\Local\Western_Digital
2011-04-23 15:04:16 -------- d-----w- C:\ProgramData\Western Digital
2011-04-23 15:03:34 -------- d-----w- C:\Program Files (x86)\Western Digital
2011-04-23 14:59:49 -------- d-----w- C:\Program Files\WDCSAM
2011-04-23 14:55:11 -------- d-----w- C:\Users\phil.geyskens\AppData\Local\Western Digital
2011-04-23 01:16:27 8802128 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-04-22 20:37:38 -------- d--h--w- C:\Users\phil.geyskens\AppData\Local\dvmexp
2011-04-22 20:29:08 -------- d-----w- C:\Program Files\QlikView
2011-04-22 20:29:06 -------- d-----w- C:\Program Files (x86)\QlikView
2011-04-22 20:29:05 -------- d-----w- C:\Users\phil.geyskens\AppData\Roaming\QlikTech
2011-04-22 20:28:10 -------- d-----w- C:\Users\phil.geyskens\AppData\Roaming\JAM Software
2011-04-22 20:28:01 -------- d-----w- C:\Program Files (x86)\JAM Software
2011-04-22 20:25:50 -------- d-----w- C:\Program Files\R
2011-04-22 20:21:37 -------- d-----w- C:\Users\phil.geyskens\AppData\Local\Downloaded Installations
2011-04-22 20:05:39 -------- d-----w- C:\Program Files (x86)\Auslogics
2011-04-22 19:53:56 -------- d-----w- C:\Program Files (x86)\2BrightSparks
2011-04-22 19:43:51 -------- d-----w- C:\Users\phil.geyskens\AppData\Local\Research In Motion
2011-04-22 19:43:49 -------- d-----w- C:\Users\phil.geyskens\AppData\Roaming\Research In Motion
2011-04-22 19:42:40 31744 ----a-w- C:\Windows\System32\drivers\RimSerial_AMD64.sys
2011-04-22 19:42:10 -------- d-----w- C:\ProgramData\Research In Motion
2011-04-22 19:41:43 -------- d-----w- C:\Program Files (x86)\Research In Motion
2011-04-22 19:41:43 -------- d-----w- C:\Program Files (x86)\Common Files\Research In Motion
2011-04-22 18:23:51 -------- d-----w- C:\Users\phil.geyskens\AppData\Local\Microsoft Help
2011-04-22 18:18:33 -------- d-----w- C:\ProgramData\{D499C757-18A6-4CC3-9B9E-7EC7DDB5E414}
2011-04-22 18:17:29 -------- d-----w- C:\Users\phil.geyskens\AppData\Local\Apple
2011-04-22 17:02:40 95008 ----a-w- C:\Windows\System32\Primomonnt.dll
2011-04-22 17:02:38 -------- d-----w- C:\Program Files (x86)\Nitro PDF
2011-04-22 17:00:09 -------- d-----w- C:\Users\phil.geyskens\AppData\Roaming\HandBrake
2011-04-22 17:00:09 -------- d-----w- C:\Users\phil.geyskens\AppData\Local\HandBrake
2011-04-22 17:00:02 -------- d-----w- C:\Program Files (x86)\Handbrake
2011-04-22 16:59:36 -------- d-----w- C:\Users\phil.geyskens\AppData\Roaming\Canneverbe Limited
2011-04-22 16:59:36 -------- d-----w- C:\ProgramData\Canneverbe Limited
.
==================== Find3M ====================
.
2011-04-20 19:36:27 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-04-20 16:23:27 25592 ----a-w- C:\Windows\System32\drivers\sdcfilter.sys
2011-04-20 16:23:20 35568 ----a-w- C:\Windows\System32\SophosBootTasks.exe
2011-04-20 16:23:19 142328 ----a-w- C:\Windows\System32\drivers\savonaccess.sys
2011-04-20 16:23:07 183024 ----a-w- C:\Windows\System32\sdccoinstaller.dll
2011-04-20 16:23:04 25608 ----a-w- C:\Windows\System32\drivers\SophosBootDriver.sys
2011-04-20 14:46:48 29480 ----a-w- C:\Windows\SysWow64\msxml3a.dll
2011-04-20 14:46:47 505128 ----a-w- C:\Windows\SysWow64\msvcp71.dll
2011-04-20 14:46:47 353576 ----a-w- C:\Windows\SysWow64\msvcr71.dll
2011-04-12 17:31:32 507904 ----a-r- C:\Windows\SysWow64\btwapi.dll
2011-04-06 20:26:58 96544 ----a-w- C:\Windows\System32\dnssd.dll
2011-04-06 20:26:58 69408 ----a-w- C:\Windows\System32\jdns_sd.dll
2011-04-06 20:26:58 237856 ----a-w- C:\Windows\System32\dnssdX.dll
2011-04-06 20:26:58 119584 ----a-w- C:\Windows\System32\dns-sd.exe
2011-04-06 20:20:16 91424 ----a-w- C:\Windows\SysWow64\dnssd.dll
2011-04-06 20:20:16 75040 ----a-w- C:\Windows\SysWow64\jdns_sd.dll
2011-04-06 20:20:16 197920 ----a-w- C:\Windows\SysWow64\dnssdX.dll
2011-04-06 20:20:16 107808 ----a-w- C:\Windows\SysWow64\dns-sd.exe
2011-03-08 06:14:30 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-03-08 05:38:13 740864 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-03-03 06:17:10 182272 ----a-w- C:\Windows\System32\dnsrslvr.dll
2011-03-03 06:14:38 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
2011-03-03 05:27:30 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
.
============= FINISH: 9:31:48.53 ===============
Attached File(s)
-
Attach.txt (11.47K)
Number of downloads: 1 -
gmer.log (393bytes)
Number of downloads: 0

Help
This topic is locked


Back to top












