After i close Internet explorer down, i get new iexplore.exe 's opening up in task manager.
Thanks in advance here are the logs
--------------------------------
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-11-10 23:30:20
Windows 6.1.7601 Service Pack 1
Running: r7jhme7j.exe
---- Files - GMER 1.0.15 ----
File C:\Users\sc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1Z6HEAX0\statstracker[2].htm 0 bytes
File C:\Users\sc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1Z6HEAX0\like[1].htm 0 bytes
File C:\Users\sc\AppData\Roaming\Microsoft\Windows\Cookies\THCDTSYH.txt 569 bytes
File C:\Users\sc\AppData\Roaming\Microsoft\Windows\Cookies\CQ42Q59W.txt 0 bytes
File C:\Users\sc\AppData\Roaming\Microsoft\Windows\Cookies\NQ1AUFAS.txt 0 bytes
File C:\Users\sc\AppData\Roaming\Microsoft\Windows\Cookies\R67K3AET.txt 0 bytes
File C:\Users\sc\AppData\Roaming\Microsoft\Windows\Cookies\DZCW5IC3.txt 0 bytes
File C:\Users\sc\AppData\Roaming\Microsoft\Windows\Cookies\F1YUPV8W.txt 92 bytes
File C:\Users\sc\AppData\Roaming\Microsoft\Windows\Cookies\64XLKYFH.txt 0 bytes
File C:\Users\sc\AppData\Roaming\Microsoft\Windows\Cookies\M1FYECDT.txt 0 bytes
---- EOF - GMER 1.0.15 ----
ComboFix 11-11-06.02 - sc 07/11/2011 16:08:18.2.8 - x64 MINIMAL
Microsoft Windows 7 Professional 6.1.7601.1.1252.61.1033.18.8183.7339 [GMT 11:00]
Running from: c:\users\sc\Downloads\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\startup
c:\programdata\startup\desktop.ini
.
.
((((((((((((((((((((((((( Files Created from 2011-10-07 to 2011-11-07 )))))))))))))))))))))))))))))))
.
.
2011-11-07 05:40 . 2011-11-07 05:40 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1B24D70C-D7D2-44DC-90D6-AD724914B932}\offreg.dll
2011-11-07 05:38 . 2011-11-07 05:38 -------- d-----w- c:\users\S\AppData\Local\temp
2011-11-07 05:38 . 2011-11-07 05:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-11-07 04:41 . 2011-10-06 10:16 8570192 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-07 04:41 . 2011-10-06 10:16 8570192 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1B24D70C-D7D2-44DC-90D6-AD724914B932}\mpengine.dll
2011-11-07 03:41 . 2011-11-07 03:41 -------- d-----w- c:\programdata\!SASCORE
2011-11-07 03:41 . 2011-11-07 04:30 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-11-07 03:41 . 2011-11-07 03:41 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-11-07 03:40 . 2011-11-07 03:40 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-11-07 03:39 . 2011-11-07 04:02 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-11-07 03:39 . 2011-11-07 03:39 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-11-07 01:32 . 2011-11-07 01:52 -------- d-----w- c:\users\sc
2011-11-06 04:11 . 2011-11-06 04:11 917840 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{502B0438-8147-46EC-B6EA-F0C7B68BF884}\gapaengine.dll
2011-11-06 04:10 . 2011-11-06 04:10 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2011-11-06 03:35 . 2011-11-06 04:10 -------- d-----w- c:\program files\Microsoft Security Client
2011-11-05 04:22 . 2011-11-06 04:00 -------- d-----w- c:\program files\CCleaner
2011-10-27 03:44 . 2011-10-27 03:44 -------- d-----w- c:\program files (x86)\EverythingAccess.com
2011-10-24 10:53 . 2011-11-07 01:34 -------- d-----w- c:\users\UpdatusUser
2011-10-24 10:52 . 2011-10-15 08:53 837952 ----a-w- c:\windows\system32\easyupdatusapiu64.dll
2011-10-24 10:52 . 2011-10-15 08:53 5067584 ----a-w- c:\windows\system32\nvsvc64.dll
2011-10-24 10:52 . 2011-10-15 08:53 222528 ----a-w- c:\windows\system32\nvmctray.dll
2011-10-24 10:52 . 2011-10-15 08:53 1640768 ----a-w- c:\windows\system32\nvvsvc.exe
2011-10-24 10:52 . 2011-10-15 08:53 137536 ----a-w- c:\windows\system32\nvshext.dll
2011-10-24 10:52 . 2011-10-15 08:53 10406208 ----a-w- c:\windows\system32\nvcpl.dll
2011-10-24 10:52 . 2011-11-03 02:14 -------- d-----w- c:\programdata\NVIDIA Corporation
2011-10-23 02:53 . 2011-10-23 02:54 -------- d-----w- c:\program files (x86)\PlatinumHideIP
2011-10-23 02:18 . 2011-10-23 02:23 -------- d-----w- c:\program files (x86)\OpenVPN
2011-10-23 01:53 . 2009-01-22 14:40 163840 ----a-w- c:\windows\SysWow64\SecureNet.dll
2011-10-23 01:53 . 2008-11-03 17:45 204800 ----a-w- c:\windows\SysWow64\ssleay32.dll
2011-10-23 01:53 . 2008-11-03 17:45 1126400 ----a-w- c:\windows\SysWow64\libeay32.dll
2011-10-23 01:53 . 2011-10-23 02:13 -------- d-----w- c:\program files (x86)\Hide My IP 2009
2011-10-23 01:26 . 2011-10-23 01:26 -------- d-----w- c:\users\S\AppData\Roaming\PlatinumHideIP
2011-10-23 01:26 . 2011-10-23 01:26 -------- d-----w- c:\programdata\PlatinumHideIP
2011-10-23 01:20 . 2011-06-03 14:56 424296 ----a-w- c:\windows\system32\HMIPCore64.dll
2011-10-23 01:20 . 2011-10-23 01:53 196608 ----a-w- c:\windows\SysWow64\HMIPCore.dll
2011-10-23 00:04 . 2011-11-06 04:00 -------- d-----w- c:\programdata\FlyVPN
2011-10-19 10:14 . 2011-02-13 15:42 34816 ----a-w- c:\windows\system32\drivers\lgx64modem.sys
2011-10-19 10:14 . 2011-02-13 15:42 28160 ----a-w- c:\windows\system32\drivers\lgx64diag.sys
2011-10-19 10:14 . 2011-02-13 15:42 17920 ----a-w- c:\windows\system32\drivers\lgx64bus.sys
2011-10-19 10:14 . 2010-12-07 03:23 34304 ----a-w- c:\windows\system32\drivers\lgandmodem64.sys
2011-10-19 10:13 . 2010-12-07 03:23 27648 ----a-w- c:\windows\system32\drivers\lganddiag64.sys
2011-10-19 10:13 . 2010-12-07 03:23 27136 ----a-w- c:\windows\system32\drivers\lgandgps64.sys
2011-10-19 10:13 . 2010-12-07 03:22 19456 ----a-w- c:\windows\system32\drivers\lgandbus64.sys
2011-10-19 10:10 . 2011-10-19 10:10 -------- d-----w- c:\users\S\AppData\Local\LG Electronics
2011-10-19 09:25 . 2011-10-19 10:14 -------- d-----w- c:\program files (x86)\LG Electronics
2011-10-19 09:21 . 2011-10-19 10:07 -------- d-----w- C:\LGP990
2011-10-19 09:20 . 2011-05-10 02:37 655872 ----a-w- c:\windows\SysWow64\msvcr90.dll
2011-10-19 09:20 . 2011-05-10 02:37 568832 ----a-w- c:\windows\SysWow64\msvcp90.dll
2011-10-19 09:20 . 2011-05-10 02:37 224768 ----a-w- c:\windows\SysWow64\msvcm90.dll
2011-10-19 09:20 . 2006-05-03 21:33 53248 ----a-w- c:\windows\SysWow64\CommonDL.dll
2011-10-19 09:20 . 2005-10-03 14:39 44544 ----a-w- c:\windows\SysWow64\msxml4a.dll
2011-10-19 09:20 . 2011-11-06 04:00 -------- d-----w- c:\programdata\LGMOBILEAX
2011-10-14 13:54 . 2011-10-14 13:54 321856 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2011-10-12 10:25 . 2011-09-06 03:03 3138048 ----a-w- c:\windows\system32\win32k.sys
2011-10-12 10:19 . 2011-08-17 05:26 613888 ----a-w- c:\windows\system32\psisdecd.dll
2011-10-12 10:19 . 2011-08-17 05:25 108032 ----a-w- c:\windows\system32\psisrndr.ax
2011-10-12 10:19 . 2011-08-17 04:24 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2011-10-12 10:19 . 2011-08-17 04:19 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2011-10-12 10:16 . 2011-08-27 05:37 861696 ----a-w- c:\windows\system32\oleaut32.dll
2011-10-12 10:16 . 2011-08-27 05:37 331776 ----a-w- c:\windows\system32\oleacc.dll
2011-10-12 10:16 . 2011-08-27 04:26 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-10-12 10:16 . 2011-08-27 04:26 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-07 06:52 . 2011-03-02 02:55 25640 ----a-w- c:\windows\gdrv.sys
2011-11-07 03:47 . 2011-09-08 08:21 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-11-07 03:47 . 2011-01-12 04:53 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-10-26 14:25 . 2011-01-10 04:30 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2011-10-22 02:26 . 2011-01-10 04:30 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-10-16 01:55 . 2011-05-14 04:08 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-02 18:06 . 2011-02-15 01:45 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-09-06 20:45 . 2011-03-31 00:46 41184 ----a-w- c:\windows\avastSS.scr
2011-09-06 20:45 . 2011-03-31 00:46 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-09-06 20:45 . 2011-03-31 00:46 254400 ----a-w- c:\windows\system32\aswBoot.exe
2011-09-06 20:38 . 2011-03-31 00:46 601944 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-09-06 20:38 . 2011-03-31 00:46 301912 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-09-06 20:36 . 2011-03-31 00:46 42328 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-09-06 20:36 . 2011-03-31 00:46 65368 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-09-06 20:36 . 2011-03-31 00:46 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-08-31 07:00 . 2010-09-17 00:23 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-22 00:53 . 2011-08-22 00:53 0 ----a-w- c:\windows\SysWow64\ConduitEngine.tmp
2010-09-06 07:31 2048 --sha-w- c:\windows\actofvl\clip.exe
2010-09-06 07:31 127232 --sha-w- c:\windows\actofvl\osppc.dll
2010-09-06 07:31 14176 --sha-w- c:\windows\actofvl\ospprearm.exe
2010-09-06 07:31 122880 --sha-w- c:\windows\actofvl\reg.exe
2010-09-06 07:31 72738 --sha-w- c:\windows\actofvl\Uninstall.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-07_03.13.10 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:54 . 2011-11-07 05:41 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-11-07 03:11 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-11-07 05:41 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-11-07 03:11 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-11-07 03:11 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-11-07 05:41 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-08-09 04:36 . 2011-11-07 04:32 93466 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-11-07 04:32 40704 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2010-08-09 02:02 . 2011-11-07 02:33 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-08-09 02:02 . 2011-11-07 06:23 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-08-09 02:02 . 2011-11-07 06:23 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-08-09 02:02 . 2011-11-07 02:33 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-11-07 02:33 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-11-07 06:23 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-11-07 05:40 . 2011-11-07 05:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-11-07 03:10 . 2011-11-07 03:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-11-07 05:40 . 2011-11-07 05:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-11-07 03:10 . 2011-11-07 03:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-11-07 03:40 . 2011-10-02 18:06 157472 c:\windows\SysWOW64\javaws.exe
- 2011-03-15 04:19 . 2011-03-15 04:19 145184 c:\windows\SysWOW64\javaw.exe
+ 2011-11-07 03:40 . 2011-10-02 18:06 145184 c:\windows\SysWOW64\javaw.exe
+ 2011-11-07 03:40 . 2011-10-02 18:06 145184 c:\windows\SysWOW64\java.exe
- 2011-03-15 04:19 . 2011-03-15 04:19 145184 c:\windows\SysWOW64\java.exe
+ 2009-07-14 02:36 . 2011-11-07 05:45 633392 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2011-11-07 01:39 633392 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2011-11-07 01:39 112416 c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2011-11-07 05:45 112416 c:\windows\system32\perfc009.dat
- 2009-07-14 04:46 . 2011-11-07 01:40 104400 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2009-07-14 04:46 . 2011-11-07 04:38 104400 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2009-07-14 05:01 . 2011-11-07 03:09 479400 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-11-07 04:57 479400 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-11-07 03:40 . 2011-11-07 03:40 207360 c:\windows\Installer\1a6944.msi
+ 2011-11-07 03:09 . 2011-11-07 04:57 3471788 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-157027001-3521155619-4037326970-1003-8192.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-11-07 5500800]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"SDBOK"="c:\program files (x86)\GIGABYTE\smart6\dbios\run.exe" [2009-07-06 207400]
.
c:\users\S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
mirc - Shortcut.lnk - c:\mirc\mirc.exe [2010-8-16 3184800]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 EraserSvc11010;Symantec Eraser Service;c:\program files (x86)\Common Files\Symantec Shared\ccSvcHst.exe [x]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-07 136176]
R3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [x]
R3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\DRIVERS\lgandbus64.sys [x]
R3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\DRIVERS\lganddiag64.sys [x]
R3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\DRIVERS\lgandgps64.sys [x]
R3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\DRIVERS\lgandmodem64.sys [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-07 136176]
R3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\DRIVERS\LVUSBS64.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 afcdpsrv;Acronis Nonstop Backup service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2010-09-15 3975088]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\DRIVERS\tdrpm273.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 HWiNFO32;HWiNFO32 Kernel Driver;c:\program files (x86)\HWiNFO32\HWiNFO64A.SYS [2010-07-25 28032]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-11-07 140672]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [2009-10-13 114688]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-30 2358656]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x]
S3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtpt64.sys [x]
S3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\DRIVERS\lgbtbs64.sys [x]
S3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmdm64.sys [x]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 WFLR6654;WinFast TV2000 XP Expert (FM1216MK3);c:\windows\system32\drivers\wfeaglxt.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-07 05:18]
.
2011-11-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-07 05:18]
.
2011-10-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-157027001-3521155619-4037326970-1000Core.job
- c:\users\S\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-28 10:15]
.
2011-11-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-157027001-3521155619-4037326970-1000UA.job
- c:\users\S\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-28 10:15]
.
2011-11-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-157027001-3521155619-4037326970-1003Core.job
- c:\users\sc\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-07 04:08]
.
2011-11-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-157027001-3521155619-4037326970-1003UA.job
- c:\users\sc\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-07 04:08]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45d30484-7ded-43d9-957a-d2fd1f046511}]
2010-11-04 06:57 444752 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1d09c093-f71e-43c3-b948-19316cbd695e}"= "mscoree.dll" [2010-11-04 444752]
.
[HKEY_CLASSES_ROOT\CLSID\{1d09c093-f71e-43c3-b948-19316cbd695e}]
[HKEY_CLASSES_ROOT\tGBandObj.tGBandObjClass]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 20:45 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-03-26 10135584]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-05 500208]
"Acronis Scheduler2 Service"="c:\program files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [2010-08-20 390736]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"RPMKickstart"="c:\program files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe" [2010-08-23 2552320]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\acaptuser64.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com.au/
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.254
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-ESN Sonar-0.70.0 - c:\program files (x86)\Battlelog Web Plugins\Sonar\esnsonar_uninstall.exe
AddRemove-ESN Sonar-0.70.4 - c:\program files (x86)\Battlelog Web Plugins\Sonar\esnsonar_uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files (x86)\GIGABYTE\smart6\dbios\SDBMSG.exe
c:\program files\WinFast\WFDTV\DVBTAP.exe
c:\program files (x86)\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2011-11-07 18:11:34 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-07 07:11
ComboFix2.txt 2011-11-07 03:34
.
Pre-Run: 256,318,889,984 bytes free
Post-Run: 251,807,346,688 bytes free
.
- - End Of File - - C415AAE7CCF2CF38D55BFCB68C710161
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by sc at 23:31:39 on 2011-11-10
Microsoft Windows 7 Professional 6.1.7601.1.1252.61.1033.18.8183.4642 [GMT 11:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\AlarmClock.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\GIGABYTE\SMART6\Recovery\RPMDaemon.exe
C:\Program Files (x86)\GIGABYTE\smart6\dbios\SDBMSG.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Origin\Origin.exe
C:\Windows\SysWOW64\PnkBstrB.exe
C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\mIRC\mirc.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Windows\system32\vssvc.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.au/
mURLSearchHooks: H - No File
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
mRunOnce: [SDBOK] C:\Program Files (x86)\GIGABYTE\smart6\dbios\run.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBC} - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} - hxxps://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.64.2.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{D9F891D4-7C1A-48B6-9582-88FF89784DE4} : DhcpNameServer = 192.168.1.254
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
mRunOnce-x64: [SDBOK] C:\Program Files (x86)\GIGABYTE\smart6\dbios\run.exe
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);C:\Windows\system32\DRIVERS\tdrpm273.sys --> C:\Windows\system32\DRIVERS\tdrpm273.sys [?]
R1 AppleCharger;AppleCharger;C:\Windows\system32\DRIVERS\AppleCharger.sys --> C:\Windows\system32\DRIVERS\AppleCharger.sys [?]
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 HWiNFO32;HWiNFO32 Kernel Driver;C:\Program Files (x86)\HWiNFO32\HWiNFO64A.SYS [2010-8-9 28032]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-9-14 44768]
R2 cpuz135;cpuz135;\??\C:\Windows\system32\drivers\cpuz135_x64.sys --> C:\Windows\system32\drivers\cpuz135_x64.sys [?]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-24 2253120]
R2 Smart TimeLock;Smart TimeLock Service;C:\Program Files (x86)\GIGABYTE\smart6\timelock\TimeMgmtDaemon.exe [2011-3-2 114688]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248]
R2 TeamViewer6;TeamViewer 6;C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-9-27 2358656]
R3 LgBttPort;LGE Bluetooth TransPort;C:\Windows\system32\DRIVERS\lgbtpt64.sys --> C:\Windows\system32\DRIVERS\lgbtpt64.sys [?]
R3 lgbusenum;LG Bluetooth Bus Enumerator;C:\Windows\system32\DRIVERS\lgbtbs64.sys --> C:\Windows\system32\DRIVERS\lgbtbs64.sys [?]
R3 LGVMODEM;LGE Virtual Modem;C:\Windows\system32\DRIVERS\lgvmdm64.sys --> C:\Windows\system32\DRIVERS\lgvmdm64.sys [?]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 WFLR6654;WinFast TV2000 XP Expert (FM1216MK3);C:\Windows\system32\drivers\wfeaglxt.sys --> C:\Windows\system32\drivers\wfeaglxt.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 EraserSvc11010;Symantec Eraser Service;"C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon --> C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe [?]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-7 136176]
S3 afcdp;afcdp;C:\Windows\system32\DRIVERS\afcdp.sys --> C:\Windows\system32\DRIVERS\afcdp.sys [?]
S3 Andbus;LGE Android Platform Composite USB Device;C:\Windows\system32\DRIVERS\lgandbus64.sys --> C:\Windows\system32\DRIVERS\lgandbus64.sys [?]
S3 AndDiag;LGE Android Platform USB Serial Port;C:\Windows\system32\DRIVERS\lganddiag64.sys --> C:\Windows\system32\DRIVERS\lganddiag64.sys [?]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;C:\Windows\system32\DRIVERS\lgandgps64.sys --> C:\Windows\system32\DRIVERS\lgandgps64.sys [?]
S3 ANDModem;LGE Android Platform USB Modem;C:\Windows\system32\DRIVERS\lgandmodem64.sys --> C:\Windows\system32\DRIVERS\lgandmodem64.sys [?]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-7 136176]
S3 LVUSBS64;Logitech USB Monitor Filter;C:\Windows\system32\DRIVERS\LVUSBS64.sys --> C:\Windows\system32\DRIVERS\LVUSBS64.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\C:\Windows\system32\33AE.tmp --> C:\Windows\system32\33AE.tmp [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-1-21 30963576]
S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 afcdpsrv;Acronis Nonstop Backup service;C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2010-9-15 3975088]
.
=============== Created Last 30 ================
.
2011-11-10 06:07:53 18816 ------w- C:\Windows\SysWow64\SAVRKBootTasks.sys
2011-11-10 05:59:50 -------- d-----w- C:\Users\sc\AppData\Roaming\uTorrent
2011-11-10 05:23:22 6144 ------w- C:\Windows\System32\33AE.tmp
2011-11-10 05:22:26 6144 ------w- C:\Windows\System32\58C9.tmp
2011-11-10 05:11:26 69000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{60482B70-71F2-4326-8A76-DD0241C53770}\offreg.dll
2011-11-10 04:10:35 4529299 ----a-w- C:\Users\sc\FileZilla_3.5.2_win32-setup.exe
2011-11-09 22:51:13 8570192 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{60482B70-71F2-4326-8A76-DD0241C53770}\mpengine.dll
2011-11-09 09:25:33 886784 ----a-w- C:\Program Files\Common Files\System\wab32.dll
2011-11-09 09:25:33 708608 ----a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2011-11-09 09:25:32 1923952 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-11-09 09:25:30 3144704 ----a-w- C:\Windows\System32\win32k.sys
2011-11-08 03:02:06 -------- d-----w- C:\Users\sc\AppData\Roaming\Malwarebytes
2011-11-07 11:42:44 6144 ------w- C:\Windows\System32\95FB.tmp
2011-11-07 11:42:37 -------- d-----w- C:\Program Files (x86)\Sophos
2011-11-07 11:38:56 -------- d-----w- C:\Users\sc\AppData\Roaming\Philipp Winterberg
2011-11-07 11:16:30 -------- d-----w- C:\Program Files (x86)\ESET
2011-11-07 10:43:46 -------- d-----w- C:\Users\sc\AppData\Roaming\NVIDIA
2011-11-07 08:56:38 -------- d-----w- C:\Users\sc\AppData\Roaming\mIRC
2011-11-07 06:52:11 -------- d-----w- C:\$RECYCLE.BIN
2011-11-07 04:41:56 8570192 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-07 03:47:28 -------- d-----w- C:\Users\sc\AppData\Local\PunkBuster
2011-11-07 03:45:30 -------- d-----w- C:\Users\sc\AppData\Roaming\Origin
2011-11-07 03:45:24 -------- d-----w- C:\Users\sc\AppData\Local\Origin
2011-11-07 03:41:33 -------- d-----w- C:\Users\sc\AppData\Roaming\SUPERAntiSpyware.com
2011-11-07 03:39:52 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-11-07 03:39:52 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2011-11-07 02:22:57 98816 ----a-w- C:\Windows\sed.exe
2011-11-07 02:22:57 518144 ----a-w- C:\Windows\SWREG.exe
2011-11-07 02:22:57 256000 ----a-w- C:\Windows\PEV.exe
2011-11-07 02:22:57 208896 ----a-w- C:\Windows\MBR.exe
2011-11-07 02:10:29 -------- d-----w- C:\Users\sc\AppData\Local\Google
2011-11-07 01:34:49 -------- d-----w- C:\Users\sc\AppData\Local\Adobe
2011-11-07 01:33:25 -------- d-----w- C:\Users\sc\AppData\Local\VirtualStore
2011-11-06 04:11:51 917840 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{502B0438-8147-46EC-B6EA-F0C7B68BF884}\gapaengine.dll
2011-11-06 04:10:19 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2011-11-06 03:35:33 -------- d-----w- C:\Program Files\Microsoft Security Client
2011-11-05 04:22:02 -------- d-----w- C:\Program Files\CCleaner
2011-10-27 03:44:52 -------- d-----w- C:\Program Files (x86)\EverythingAccess.com
2011-10-24 10:52:54 837952 ----a-w- C:\Windows\System32\easyupdatusapiu64.dll
2011-10-24 10:52:54 5067584 ----a-w- C:\Windows\System32\nvsvc64.dll
2011-10-24 10:52:54 222528 ----a-w- C:\Windows\System32\nvmctray.dll
2011-10-24 10:52:54 1640768 ----a-w- C:\Windows\System32\nvvsvc.exe
2011-10-24 10:52:54 137536 ----a-w- C:\Windows\System32\nvshext.dll
2011-10-24 10:52:54 10406208 ----a-w- C:\Windows\System32\nvcpl.dll
2011-10-24 10:52:46 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2011-10-23 02:18:50 -------- d-----w- C:\Program Files (x86)\OpenVPN
2011-10-23 01:53:44 163840 ----a-w- C:\Windows\SysWow64\SecureNet.dll
2011-10-23 01:53:42 204800 ----a-w- C:\Windows\SysWow64\ssleay32.dll
2011-10-23 01:53:42 1126400 ----a-w- C:\Windows\SysWow64\libeay32.dll
2011-10-23 01:53:41 -------- d-----w- C:\Program Files (x86)\Hide My IP 2009
2011-10-23 01:26:22 -------- d-----w- C:\ProgramData\PlatinumHideIP
2011-10-23 01:20:15 424296 ----a-w- C:\Windows\System32\HMIPCore64.dll
2011-10-23 01:20:12 196608 ----a-w- C:\Windows\SysWow64\HMIPCore.dll
2011-10-23 00:04:25 -------- d-----w- C:\ProgramData\FlyVPN
2011-10-19 10:14:01 34816 ----a-w- C:\Windows\System32\drivers\lgx64modem.sys
2011-10-19 10:14:00 34304 ----a-w- C:\Windows\System32\drivers\lgandmodem64.sys
2011-10-19 10:14:00 28160 ----a-w- C:\Windows\System32\drivers\lgx64diag.sys
2011-10-19 10:14:00 17920 ----a-w- C:\Windows\System32\drivers\lgx64bus.sys
2011-10-19 10:13:59 27648 ----a-w- C:\Windows\System32\drivers\lganddiag64.sys
2011-10-19 10:13:59 27136 ----a-w- C:\Windows\System32\drivers\lgandgps64.sys
2011-10-19 10:13:59 19456 ----a-w- C:\Windows\System32\drivers\lgandbus64.sys
2011-10-19 09:25:11 -------- d-----w- C:\Program Files (x86)\LG Electronics
2011-10-19 09:21:43 -------- d-----w- C:\LGP990
2011-10-19 09:20:33 655872 ----a-w- C:\Windows\SysWow64\msvcr90.dll
2011-10-19 09:20:33 568832 ----a-w- C:\Windows\SysWow64\msvcp90.dll
2011-10-19 09:20:33 224768 ----a-w- C:\Windows\SysWow64\msvcm90.dll
2011-10-19 09:20:24 53248 ----a-w- C:\Windows\SysWow64\CommonDL.dll
2011-10-19 09:20:24 44544 ----a-w- C:\Windows\SysWow64\msxml4a.dll
2011-10-19 09:20:06 -------- d-----w- C:\ProgramData\LGMOBILEAX
2011-10-14 13:54:52 321856 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2011-10-12 10:19:25 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2011-10-12 10:19:25 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2011-10-12 10:19:25 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2011-10-12 10:19:25 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2011-10-12 10:16:42 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2011-10-12 10:16:42 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-10-12 10:16:42 331776 ----a-w- C:\Windows\System32\oleacc.dll
2011-10-12 10:16:42 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
.
==================== Find3M ====================
.
2011-11-10 07:36:04 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2011-11-10 07:36:04 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-11-10 07:34:26 25640 ----a-w- C:\Windows\gdrv.sys
2011-11-10 07:32:51 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2011-10-22 02:26:54 75136 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-10-16 01:55:05 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-02 18:06:03 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-09-06 20:45:29 41184 ----a-w- C:\Windows\avastSS.scr
2011-09-06 20:38:18 601944 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2011-09-06 20:36:30 65368 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2011-09-01 05:24:07 2309120 ----a-w- C:\Windows\System32\jscript9.dll
2011-09-01 05:17:57 1389056 ----a-w- C:\Windows\System32\wininet.dll
2011-09-01 05:12:04 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-09-01 02:35:59 1798144 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-09-01 02:28:15 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-09-01 02:22:54 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-08-31 07:00:50 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-22 00:53:35 0 ----a-w- C:\Windows\SysWow64\ConduitEngine.tmp
2010-09-06 07:31:24 2048 --sha-w- C:\Windows\actofvl\clip.exe
2010-09-06 07:31:24 127232 --sha-w- C:\Windows\actofvl\osppc.dll
2010-09-06 07:31:24 14176 --sha-w- C:\Windows\actofvl\ospprearm.exe
2010-09-06 07:31:24 122880 --sha-w- C:\Windows\actofvl\reg.exe
2010-09-06 07:31:38 72738 --sha-w- C:\Windows\actofvl\Uninstall.exe
.
============= FINISH: 23:39:08.51 ===============
Attached File(s)
-
ark.txt (1.43K)
Number of downloads: 0 -
ComboFix.txt (27.73K)
Number of downloads: 0 -
DDS.txt (20.42K)
Number of downloads: 0
This post has been edited by don13342: 10 November 2011 - 07:48 AM

Help
This topic is locked

Back to top









