I recently removed TDSS, my compter was running fine for a while now what happens is that windows explorer will freeze up for a minute ( I can still move my mouse and my music is still playing but I cant click anything ) and every now and then Trend Micro will detect TROJ_SPNR trying to run. I recently removed TDSS but I think maybe it's still lingering around. I ran the TDSS tool again and its not found.
Here are the logs:
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Run by Brendan at 16:43:19 on 2011-11-11
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.6134.3050 [GMT 11:00]
.
AV: Trend Micro Titanium Maximum Security 2012 *Disabled/Updated* {7193B549-236F-55EE-9AEC-F65279E59A92}
SP: Trend Micro Titanium Maximum Security 2012 *Disabled/Updated* {CAF254AD-0555-5A60-A05C-CD200262D02F}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiWatchDog.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\UnHackMe\hackmon.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
C:\Windows\System32\tlntsvr.exe
C:\Program Files\Viscosity\ViscosityService.exe
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
C:\Windows\SysWOW64\vmnat.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\svchost.exe -k bthaudiosvc
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
C:\Windows\SysWOW64\vmnetdhcp.exe
C:\Windows\System32\alg.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiSeAgnt.exe
C:\Program Files (x86)\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files (x86)\Origin\Origin.exe
C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe
C:\Program Files (x86)\Freecorder\FLVSrvc.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\SysWOW64\DeltaIITray.exe
C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe
C:\Program Files (x86)\Razer\DeathAdder\vdDaemon.exe
C:\Program Files (x86)\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files (x86)\Common Files\Teleca Shared\logger.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Common Files\Teleca Shared\Generic.exe
C:\Program Files (x86)\HTC\HTC Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe
C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\epmworker.exe
C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\HTCVBTServer.exe
C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\FsynSrvStarter.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\iTunes\iTunes.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\mIRC\mirc.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Windows\explorer.exe
C:\Users\Brendan\Desktop\putty.exe
C:\Program Files (x86)\GlobalSCAPE\CuteFTP 8 Professional\cuteftppro.exe
C:\Program Files (x86)\GlobalSCAPE\CuteFTP 8 Professional\ftpte.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\WinSCP\WinSCP.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brendan\AppData\Local\Akamai\netsession_win.exe
C:\Users\Brendan\AppData\Local\Akamai\netsession_win.exe
C:\Windows\SysWOW64\svchost.exe -k Akamai
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brendan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2612669
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: TmIEPlugInBHO Class: {1ca1377b-dc1d-4a52-9585-6e06050fac53} - C:\Program Files\Trend Micro\AMSP\Module\20004\2.0.1313\6.8.1072\TmIEPlg32.dll
BHO: FGCatchUrl: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - C:\Program Files (x86)\FlashGet\jccatch.dll
BHO: TSToolbarBHO: {43c6d902-a1c5-45c9-91f6-fd9e90337e18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: TmBpIeBHO Class: {bbacbafd-fa5e-4079-8b33-00eb9f13d4ac} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.0.1086\7.0.1086\TmBpIe32.dll
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: FlashGet GetFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - C:\Program Files (x86)\FlashGet\getflash.dll
TB: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
TB: Trend Micro Toolbar: {ccac5586-44d7-4c43-b64a-f042461a97d2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {90B49673-5506-483E-B92B-CA0265BD9CA8} - No File
uRun: [PlayNC Launcher]
uRun: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe /autoRun
uRun: [Google Update] "C:\Users\Brendan\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [WindowsLivePhone] "C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe" /AutoRun
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [EVEREST AutoStart] C:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\everest_start.exe
uRun: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
uRun: [Akamai NetSession Interface] C:\Users\Brendan\AppData\Local\Akamai\netsession_win.exe
uRun: [Proxifier] "c:\program files (x86)\proxifier\proxifier.exe" aut
mRun: [WindowsLivePhone] C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe /AutoRun
mRun: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
mRun: [Mobile Connectivity Suite] "C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe" /startoptions
mRun: [Freecorder FLV Service] "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [M-Audio Taskbar Icon] C:\Windows\system32\DeltaIITray.exe
mRun: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
dRunOnce: [mmc165] C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Adobe\plugs\mmc165.exe
StartupFolder: C:\Users\Brendan\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\RealTemp.lnk - G:\Downloads\RealTemp_360\RealTemp.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: &Download All with FlashGet - C:\Program Files (x86)\FlashGet\jc_all.htm
IE: &Download with FlashGet - C:\Program Files (x86)\FlashGet\jc_link.htm
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: Download with GetRight Pro - C:\Program Files (x86)\GetRight\GRdownload.htm
IE: Open with GetRight Pro Browser - C:\Program Files (x86)\GetRight\GRbrowse.htm
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files (x86)\FlashGet\FlashGet.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
LSP: %SystemRoot%\system32\PrxerDrv.dll
LSP: %SystemRoot%\system32\vsocklib.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{73F77040-D278-4C50-9D09-FF5742DDF1C7} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{73F77040-D278-4C50-9D09-FF5742DDF1C7}\C4F65796370534 : DhcpNameServer = 61.9.134.49
TCP: Interfaces\{A9AA9746-623E-46C0-84B5-82D7BB24DBD6} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{D3336F3E-4070-4141-8E95-8DEA2D65A4F3} : DhcpNameServer = 10.176.66.71 10.188.66.103
TCP: Interfaces\{E98CEFD1-6214-4DF3-9136-274E2DFF65DC} : DhcpNameServer = 208.67.222.222 208.67.220.220
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\7.0.1086\7.0.1086\TmBpIe32.dll
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\2.0.1313\6.8.1072\TmIEPlg32.dll
Handler: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\2.0.1313\6.8.1072\TmIEPlg32.dll
BHO-X64: Trend Micro NSC BHO - No File
BHO-X64: FGCatchUrl: {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files (x86)\FlashGet\jccatch.dll
BHO-X64: flashget urlcatch - No File
BHO-X64: TSToolbarBHO: {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
BHO-X64: Trend Micro Toolbar BHO - No File
BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO-X64: Search Helper - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: TmBpIeBHO Class: {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.0.1086\7.0.1086\TmBpIe32.dll
BHO-X64: TmBpIeBHO - No File
BHO-X64: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: FlashGet GetFlash Class: {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files (x86)\FlashGet\getflash.dll
TB-X64: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
TB-X64: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
TB-X64: Trend Micro Toolbar: {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB-X64: {90B49673-5506-483E-B92B-CA0265BD9CA8} - No File
mRun-x64: [WindowsLivePhone] C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe /AutoRun
mRun-x64: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
mRun-x64: [Mobile Connectivity Suite] "C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe" /startoptions
mRun-x64: [Freecorder FLV Service] "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [M-Audio Taskbar Icon] C:\Windows\system32\DeltaIITray.exe
mRun-x64: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
IE-X64: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files (x86)\FlashGet\FlashGet.exe
Hosts: 192.168.1.105 vector
Hosts: 192.168.1.101 akira
Hosts: 192.168.1.107 xan.efvfs.org
Hosts: 192.168.1.107 xan
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Brendan\AppData\Roaming\Mozilla\Firefox\Profiles\escd6z3z.default\
FF - prefs.js: browser.startup.homepage - www.google.com.au
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\1.96.0\npesnlaunch.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.3\npesnsonar.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Brendan\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
.
============= SERVICES / DRIVERS ===============
.
R0 BtHidBus;Bluetooth HID Bus Service;C:\Windows\system32\Drivers\BtHidBus.sys --> C:\Windows\system32\Drivers\BtHidBus.sys [?]
R0 DSFKSVCS;Kernel Services for DSF;C:\Windows\system32\DRIVERS\dsfksvcs.sys --> C:\Windows\system32\DRIVERS\dsfksvcs.sys [?]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R1 tmevtmgr;tmevtmgr;C:\Windows\system32\DRIVERS\tmevtmgr.sys --> C:\Windows\system32\DRIVERS\tmevtmgr.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-14 20992]
R2 Amsp;Trend Micro Solution Platform;C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe [2011-10-28 275912]
R2 HFGService;Handsfree Headset Service;C:\Windows\system32\svchost.exe -k bthaudiosvc [2009-7-14 20992]
R2 NIHardwareService;NIHardwareService;C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2009-7-18 4948992]
R2 StarWindServiceAE;StarWind AE Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-5-29 275968]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248]
R2 TeamViewer6;TeamViewer 6;C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-4-18 2271608]
R2 ViscosityService;Viscosity Service;C:\Program Files\Viscosity\ViscosityService.exe [2011-11-10 27176]
R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-8-21 846448]
R3 BthAudioHF;BthAudioHF Service;C:\Windows\system32\DRIVERS\BthAudioHF.sys --> C:\Windows\system32\DRIVERS\BthAudioHF.sys [?]
R3 DELTAII;Service for M-Audio Delta Driver (WDM);C:\Windows\system32\DRIVERS\MAudioDelta.sys --> C:\Windows\system32\DRIVERS\MAudioDelta.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
R3 VKbms;Virtual HID Minidriver;C:\Windows\system32\DRIVERS\VKbms.sys --> C:\Windows\system32\DRIVERS\VKbms.sys [?]
S0 dsfroot;root enumerated bus driver;C:\Windows\system32\DRIVERS\dsfroot.sys --> C:\Windows\system32\DRIVERS\dsfroot.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 VMwareHostd;VMware Workstation Server;C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [2011-8-22 11837440]
S3 androidusb;ADB Interface Driver;C:\Windows\system32\Drivers\androidusb.sys --> C:\Windows\system32\Drivers\androidusb.sys [?]
S3 btnetBUs;Bluetooth PAN Bus Service;C:\Windows\system32\Drivers\btnetBus.sys --> C:\Windows\system32\Drivers\btnetBus.sys [?]
S3 copperhd;Razer Copperhead Driver;C:\Windows\system32\drivers\copperhd.sys --> C:\Windows\system32\drivers\copperhd.sys [?]
S3 cpuz132;cpuz132;\??\C:\Windows\system32\drivers\cpuz132_x64.sys --> C:\Windows\system32\drivers\cpuz132_x64.sys [?]
S3 CYUSB;Cypress Generic USB Driver;C:\Windows\system32\Drivers\CYUSB.sys --> C:\Windows\system32\Drivers\CYUSB.sys [?]
S3 danewFltr;NewDeathAdder Mouse;C:\Windows\system32\drivers\danew.sys --> C:\Windows\system32\drivers\danew.sys [?]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;C:\Program Files (x86)\Dragon Age\bin_ship\daupdatersvc.service.exe [2009-12-9 25832]
S3 hitmanpro35;Hitman Pro 3.5 Support Driver;\??\C:\Windows\system32\drivers\hitmanpro35.sys --> C:\Windows\system32\drivers\hitmanpro35.sys [?]
S3 HRMCFGSPC;DSF General Configuration Space Redirection Module;C:\Windows\system32\DRIVERS\HRMCFGSPC.SYS --> C:\Windows\system32\DRIVERS\HRMCFGSPC.SYS [?]
S3 HRMINTS;DSF Interrupt Redirection Module;C:\Windows\system32\DRIVERS\HRMINTS.SYS --> C:\Windows\system32\DRIVERS\HRMINTS.SYS [?]
S3 HRMPORTS;DSF IO Port Redirection Module;C:\Windows\system32\DRIVERS\HRMPORTS.SYS --> C:\Windows\system32\DRIVERS\HRMPORTS.SYS [?]
S3 HTCAND64;HTC Device Driver;C:\Windows\system32\Drivers\ANDROIDUSB.sys --> C:\Windows\system32\Drivers\ANDROIDUSB.sys [?]
S3 IvtBtBUs;IVT Bluetooth Bus Service;C:\Windows\system32\Drivers\IvtBtBus.sys --> C:\Windows\system32\Drivers\IvtBtBus.sys [?]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys [2011-10-28 17152]
S3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\system32\DRIVERS\netaapl64.sys --> C:\Windows\system32\DRIVERS\netaapl64.sys [?]
S3 netr28ux;Compact Wireless-G USB Network Adapter;C:\Windows\system32\DRIVERS\netr28ux.sys --> C:\Windows\system32\DRIVERS\netr28ux.sys [?]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?]
S3 RivaTuner64;RivaTuner64;C:\Program Files (x86)\RivaTuner v2.24\RivaTuner64.sys [2009-2-26 19952]
S3 RTCore64;RTCore64;C:\Program Files (x86)\EVGA Precision\RTCore64.sys [2009-8-19 14352]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 tapoas;TAP-Win32 Adapter OAS;C:\Windows\system32\DRIVERS\tapoas.sys --> C:\Windows\system32\DRIVERS\tapoas.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 VBoxUSB;VirtualBox USB;C:\Windows\system32\Drivers\VBoxUSB.sys --> C:\Windows\system32\Drivers\VBoxUSB.sys [?]
S3 visctap0901;Viscosity Virtual Adapter V9.1;C:\Windows\system32\DRIVERS\visctap0901.sys --> C:\Windows\system32\DRIVERS\visctap0901.sys [?]
S3 vpcuxd;USB Virtualization Stub Service;C:\Windows\system32\DRIVERS\vpcuxd.sys --> C:\Windows\system32\DRIVERS\vpcuxd.sys [?]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-11-2 366152]
.
=============== Created Last 30 ================
.
2011-11-11 03:36:12 -------- d-----w- C:\Users\Brendan\AppData\Local\{2F1F3462-296C-4DEA-8340-1E60E4431120}
2011-11-11 03:35:57 -------- d-----w- C:\Users\Brendan\AppData\Local\{0576EA60-CF58-474B-B2C2-6CE1CB4FFCBF}
2011-11-11 03:22:05 24416 ----a-w- C:\Windows\SysWow64\drivers\regguard.sys
2011-11-11 03:15:38 39192 ----a-w- C:\Windows\SysWow64\Partizan.exe
2011-11-11 03:15:38 35816 ----a-w- C:\Windows\SysWow64\drivers\Partizan.sys
2011-11-11 03:14:31 12808 ----a-w- C:\Windows\SysWow64\drivers\UnHackMeDrv.sys
2011-11-10 15:27:28 -------- d-----w- C:\Users\Brendan\AppData\Local\GlobalSCAPE
2011-11-10 15:27:28 -------- d-----w- C:\ProgramData\GlobalSCAPE
2011-11-10 15:26:50 -------- d-----w- C:\Program Files (x86)\GlobalSCAPE
2011-11-10 13:09:57 -------- d-----w- C:\Users\Brendan\AppData\Roaming\GetRight Pro
2011-11-10 13:09:49 -------- d-----w- C:\Program Files (x86)\GetRight
2011-11-10 12:42:24 -------- d-----w- C:\Users\Brendan\AppData\Roaming\Viscosity
2011-11-10 12:27:56 -------- d-----w- C:\Users\Brendan\AppData\Local\{E2252C9E-57B2-4EA1-81A4-FD63D2A7E7B6}
2011-11-10 12:27:42 -------- d-----w- C:\Users\Brendan\AppData\Local\{99B3CB91-A8B8-4930-8F5D-1776652AF221}
2011-11-10 12:03:22 837952 ----a-w- C:\Windows\System32\easyupdatusapiu64.dll
2011-11-10 12:03:22 5067584 ----a-w- C:\Windows\System32\nvsvc64.dll
2011-11-10 12:03:22 222528 ----a-w- C:\Windows\System32\nvmctray.dll
2011-11-10 12:03:22 1640768 ----a-w- C:\Windows\System32\nvvsvc.exe
2011-11-10 12:03:22 137536 ----a-w- C:\Windows\System32\nvshext.dll
2011-11-10 12:03:22 10406208 ----a-w- C:\Windows\System32\nvcpl.dll
2011-11-10 12:03:13 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2011-11-10 00:25:46 -------- d-----w- C:\Users\Brendan\AppData\Local\{ED2F47A6-DB88-4182-A284-27EC2256E66B}
2011-11-10 00:25:34 -------- d-----w- C:\Users\Brendan\AppData\Local\{240DFACD-0827-49CF-9694-B528BDC0403C}
2011-11-09 19:34:06 -------- d-----w- C:\Users\Brendan\AppData\Local\Akamai
2011-11-09 14:12:19 -------- d-----w- C:\Users\Brendan\deskstop
2011-11-09 12:25:09 -------- d-----w- C:\Users\Brendan\AppData\Local\{B1847D2F-B8F5-49ED-84AB-A4B9CB3E1650}
2011-11-09 12:24:57 -------- d-----w- C:\Users\Brendan\AppData\Local\{9E9ECC11-1D4F-4FD4-99B6-6AD7F73AEAD5}
2011-11-08 12:25:25 -------- d-----w- C:\Program Files\openvpn
2011-11-08 03:14:44 -------- d-----w- C:\Users\Brendan\AppData\Local\{584901C3-AD3E-4121-A647-F86EDAA61FE5}
2011-11-08 03:14:33 -------- d-----w- C:\Users\Brendan\AppData\Local\{BC2D0C3C-B415-441F-BC53-F8C4CE01A71E}
2011-11-07 15:14:17 -------- d-----w- C:\Users\Brendan\AppData\Local\{F8263C7B-0181-4B67-B06C-89D0409B96F1}
2011-11-07 15:13:48 -------- d-----w- C:\Users\Brendan\AppData\Local\{3A7F28FB-C988-4559-AF3B-B98483FAD712}
2011-11-07 03:13:32 -------- d-----w- C:\Users\Brendan\AppData\Local\{7550D602-60CD-4FC9-B2EC-DB173CD241DA}
2011-11-07 03:13:21 -------- d-----w- C:\Users\Brendan\AppData\Local\{30501CCA-8FBF-47A7-8604-13061C4937C0}
2011-11-06 15:12:55 -------- d-----w- C:\Users\Brendan\AppData\Local\{8F7DB127-B42F-4504-9904-9C2CBCB90504}
2011-11-06 03:12:16 -------- d-----w- C:\Users\Brendan\AppData\Local\{F487AD24-4BDC-431D-A026-B8A296B90FA7}
2011-11-06 03:12:03 -------- d-----w- C:\Users\Brendan\AppData\Local\{3E0673D5-B1C8-4AD3-AE80-FD02E74726D7}
2011-11-06 02:57:17 -------- d-----w- C:\Users\Brendan\AppData\Roaming\Proxifier
2011-11-06 02:56:47 88816 ----a-w- C:\Windows\SysWow64\ProxifierShellExt.dll
2011-11-06 02:56:47 73968 ----a-w- C:\Windows\System32\PrxerDrv.dll
2011-11-06 02:56:47 67824 ----a-w- C:\Windows\SysWow64\PrxerDrv.dll
2011-11-06 02:56:47 55024 ----a-w- C:\Windows\System32\PrxerNsp.dll
2011-11-06 02:56:47 54000 ----a-w- C:\Windows\SysWow64\PrxerNsp.dll
2011-11-06 02:56:47 100592 ----a-w- C:\Windows\System32\ProxifierShellExt.dll
2011-11-05 13:48:47 -------- d-----w- C:\Users\Brendan\AppData\Local\{D95F339B-D2DA-4479-9138-876C49B705C8}
2011-11-05 13:47:38 -------- d-----w- C:\Users\Brendan\AppData\Local\{4EB351B4-B538-4CB1-A0FF-8F9E1049DE67}
2011-11-05 11:40:46 11264 ----a-w- C:\Windows\SysWow64\SPORDER.DLL
2011-11-05 11:40:44 -------- d-----w- C:\Program Files (x86)\Proxifier
2011-11-05 08:31:03 -------- d-----w- C:\Users\Brendan\UnixUtils
2011-11-05 06:17:59 -------- d-----w- C:\Users\Brendan\AppData\Local\MediaGet2
2011-11-05 06:17:59 -------- d-----w- C:\Users\Brendan\AppData\Local\Media Get LLC
2011-11-05 01:47:23 -------- d-----w- C:\Users\Brendan\AppData\Local\{6BDA7B1E-7B91-41A0-AA52-59C0F89527A5}
2011-11-05 01:46:09 -------- d-----w- C:\Users\Brendan\AppData\Local\{380C5689-4FCC-4126-8FFD-A96473BBC86D}
2011-11-04 13:45:40 -------- d-----w- C:\Users\Brendan\AppData\Local\{F78483EF-0476-4177-B431-9C54844B2F8F}
2011-11-04 13:45:29 -------- d-----w- C:\Users\Brendan\AppData\Local\{0886D9A1-388A-42CB-9CE9-AFCB7A045601}
2011-11-04 09:33:32 -------- d-----w- C:\Users\Brendan\.eclipse
2011-11-04 07:54:38 39408 ----a-w- C:\Windows\System32\drivers\visctap0901.sys
2011-11-04 07:54:37 -------- d-----w- C:\Program Files\Viscosity
2011-11-04 06:00:19 -------- d-----w- C:\Program Files (x86)\OpenVPN
2011-11-04 05:48:13 -------- d-----w- C:\Program Files (x86)\OpenVPN Technologies
2011-11-04 05:28:58 -------- d-----w- C:\Users\Brendan\AppData\Local\uTorrent
2011-11-04 01:45:01 -------- d-----w- C:\Users\Brendan\AppData\Local\{FB5B9729-AC8C-48B1-9E9D-0074AD73AE9F}
2011-11-04 01:43:45 -------- d-----w- C:\Users\Brendan\AppData\Local\{1ACBC7BF-3A68-4457-B55D-5E9C1DEF70DF}
2011-11-03 22:44:41 -------- d-----w- C:\Program Files (x86)\DAMN NFO Viewer
2011-11-03 13:43:32 -------- d-----w- C:\Users\Brendan\AppData\Local\{98EA47C6-FC98-4D7E-A6FF-CCF989F3116C}
2011-11-03 13:42:35 -------- d-----w- C:\Users\Brendan\AppData\Local\{58866B49-3AD7-4109-B1A3-4F528A3DF7D8}
2011-11-03 02:26:06 -------- d-----w- C:\Program Files\QuickSFV
2011-11-03 01:42:22 -------- d-----w- C:\Users\Brendan\AppData\Local\{2A877331-95E7-490A-A019-0B48CD2FC06D}
2011-11-03 01:42:10 -------- d-----w- C:\Users\Brendan\AppData\Local\{CE2EA6EE-4355-4565-A96F-CE50C04B4571}
2011-11-02 13:41:58 -------- d-----w- C:\Users\Brendan\AppData\Local\{B8C2CA0B-1463-4864-9989-E5EC18DB7613}
2011-11-02 13:41:14 -------- d-----w- C:\Users\Brendan\AppData\Local\{8C0AAD61-7F80-4394-BB88-EA7E315BBF8D}
2011-11-02 05:57:36 -------- d-----w- C:\Users\Brendan\AppData\Local\QuickPar
2011-11-02 05:52:39 688 ----a-w- C:\Users\Brendan\sc3.tmp
2011-11-02 04:06:28 -------- d-----w- C:\Program Files (x86)\QuickPar
2011-11-02 02:01:05 -------- d-----w- C:\TDSSKiller_Quarantine
2011-11-02 01:54:08 35712 ----a-w- C:\Windows\SysWow64\drivers\BlackBox.sys
2011-11-02 01:40:29 -------- d-----w- C:\Users\Brendan\AppData\Local\{6D42DAEE-74C0-4FE5-AD7C-14FC8303E2A3}
2011-11-02 01:40:14 -------- d-----w- C:\Users\Brendan\AppData\Local\{6E51F70B-0EED-4156-A0CB-D0421A9B4241}
2011-11-01 23:20:23 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-11-01 23:10:12 -------- d-----w- C:\Users\Brendan\AppData\Roaming\NewsLeecher
2011-11-01 23:09:58 -------- d-----w- C:\Program Files (x86)\NewsLeecher
2011-11-01 14:40:37 -------- d-----w- C:\Users\Brendan\AppData\Local\Newsbin
2011-11-01 14:40:36 -------- d-----w- C:\Program Files\Newsbin
2011-11-01 13:39:27 -------- d-----w- C:\Users\Brendan\AppData\Local\{63AEC530-61C1-4DDB-8C9B-CF3A70417155}
2011-11-01 13:38:28 -------- d-----w- C:\Users\Brendan\AppData\Local\{3CB26778-67E1-43FF-8FFB-E64D09893DCA}
2011-11-01 11:03:47 -------- d-----w- C:\Users\Brendan\AppData\Local\DOSBox
2011-11-01 11:03:40 -------- d-----w- C:\Program Files (x86)\DOSBox-0.74
2011-11-01 03:10:15 -------- d-----w- C:\Users\Brendan\AppData\Local\ESN Sonar
2011-11-01 01:38:01 -------- d-----w- C:\Users\Brendan\AppData\Local\{18B42069-6500-4817-B310-AA9678F123FC}
2011-11-01 01:37:50 -------- d-----w- C:\Users\Brendan\AppData\Local\{4272709D-F9DC-40E2-B05F-3332E4838434}
2011-10-31 13:36:55 -------- d-----w- C:\Users\Brendan\AppData\Local\{8532AB3D-6091-46DE-9B9F-02381E0D3153}
2011-10-31 13:36:43 -------- d-----w- C:\Users\Brendan\AppData\Local\{CC0EE475-9900-4A94-BBA8-3718E3228E78}
2011-10-31 11:44:46 -------- d-----w- C:\Users\Brendan\AppData\Local\VMware
2011-10-31 11:43:26 62064 ----a-w- C:\Windows\System32\drivers\vmx86.sys
2011-10-31 11:42:55 354416 ----a-w- C:\Windows\SysWow64\vmnetdhcp.exe
2011-10-31 11:42:51 432752 ----a-w- C:\Windows\SysWow64\vmnat.exe
2011-10-31 11:42:50 30320 ----a-w- C:\Windows\System32\drivers\vmnetuserif.sys
2011-10-31 11:42:42 942192 ----a-w- C:\Windows\System32\vnetlib64.dll
2011-10-31 11:42:38 39024 ----a-w- C:\Windows\System32\drivers\hcmon.sys
2011-10-31 11:41:56 -------- d-----w- C:\Program Files (x86)\VMware
2011-10-31 11:41:56 -------- d-----w- C:\Program Files (x86)\Common Files\VMware
2011-10-31 11:41:35 -------- d-----w- C:\Program Files\Common Files\VMware
2011-10-31 08:11:05 -------- d-----w- C:\Program Files\iPod
2011-10-31 08:11:04 -------- d-----w- C:\Program Files\iTunes
2011-10-31 08:11:04 -------- d-----w- C:\Program Files (x86)\iTunes
2011-10-31 08:09:15 -------- d-----w- C:\Program Files\Bonjour
2011-10-31 08:09:15 -------- d-----w- C:\Program Files (x86)\Bonjour
2011-10-31 01:36:16 -------- d-----w- C:\Users\Brendan\AppData\Local\{5061143E-B0EE-4888-99D5-C11D6CBCE1DB}
2011-10-31 01:36:05 -------- d-----w- C:\Users\Brendan\AppData\Local\{4122AB83-3E5A-458D-AD9F-7D4F8D72BACB}
2011-10-31 00:57:37 -------- d-----w- C:\Users\Brendan\AppData\Roaming\Razer
2011-10-31 00:48:50 85504 ----a-w- C:\Windows\SysWow64\DeathAdder64.cpl
2011-10-31 00:48:48 6656 ----a-w- C:\Windows\System32\drivers\hidkmdf.sys
2011-10-31 00:48:48 13312 ----a-w- C:\Windows\System32\drivers\VKbms.sys
2011-10-31 00:48:47 47104 ----a-w- C:\Windows\System32\drivers\CYUSB.sys
2011-10-31 00:48:47 12032 ----a-w- C:\Windows\System32\drivers\danew.sys
2011-10-30 13:35:39 -------- d-----w- C:\Users\Brendan\AppData\Local\{E940A2CC-EC9C-4A5B-BC52-88BF7AE9DDD0}
2011-10-30 13:35:19 -------- d-----w- C:\Users\Brendan\AppData\Local\{4271F9BD-947B-41ED-BEFE-E655AC23C32D}
2011-10-30 11:51:52 -------- d-----w- C:\Users\Brendan\AppData\Roaming\FabFilter
2011-10-30 11:51:00 -------- d-----w- C:\Program Files\Common Files\VST3
2011-10-30 04:24:26 -------- dc-h--w- C:\ProgramData\{3FF56E78-3AAB-4596-A1AC-32869EB9463A}
2011-10-30 04:22:37 -------- dc-h--w- C:\ProgramData\{C78336EC-F2EB-4640-99A4-DFE96581B90B}
2011-10-30 01:42:42 -------- d-----w- C:\ProgramData\4Front
2011-10-30 01:34:47 -------- d-----w- C:\Users\Brendan\AppData\Local\{FCBE68C9-258A-44AD-B974-35D8A15C2F96}
2011-10-30 01:33:43 -------- d-----w- C:\Users\Brendan\AppData\Local\{A048843A-522C-4723-AC23-F47E0B2D1F21}
2011-10-30 00:59:44 -------- d-----w- C:\Program Files (x86)\4Front
2011-10-30 00:47:58 21520 ----a-w- C:\Windows\DCEBoot64.exe
2011-10-29 13:32:55 -------- d-----w- C:\Users\Brendan\AppData\Local\{810E0583-5E51-4088-A490-CF90C57185DC}
2011-10-29 13:32:43 -------- d-----w- C:\Users\Brendan\AppData\Local\{E9FFD3B0-44F1-4747-AA7D-6C17512A5FD1}
2011-10-29 12:46:29 -------- d-----w- C:\Program Files\M-Audio
2011-10-29 11:36:47 338432 ----a-w- C:\Windows\SysWow64\REX Shared Library.dll
2011-10-29 08:59:19 37600 ----a-w- C:\Windows\System32\Partizan.exe
2011-10-29 08:57:13 2 --shatr- C:\Windows\winstart.bat
2011-10-29 08:57:04 -------- d-----w- C:\Program Files (x86)\UnHackMe
2011-10-29 06:19:06 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2011-10-29 06:19:06 31232 ----a-w- C:\Windows\System32\prevhost.exe
2011-10-29 01:32:16 -------- d-----w- C:\Users\Brendan\AppData\Local\{B76A6BA5-F07A-4163-BB53-C0132DDE826B}
2011-10-28 13:30:44 -------- d-----w- C:\Users\Brendan\AppData\Local\{9DF82661-0FE4-4C6B-AFEB-936C0C8BC09A}
2011-10-28 13:30:33 -------- d-----w- C:\Users\Brendan\AppData\Local\{81A004C7-D231-4924-AD6D-F2EF510C2CB0}
2011-10-28 11:06:19 105744 ----a-w- C:\Windows\System32\drivers\tmtdi.sys
2011-10-28 11:06:10 91920 ----a-w- C:\Windows\System32\drivers\tmactmon.sys
2011-10-28 11:06:10 70928 ----a-w- C:\Windows\System32\drivers\tmevtmgr.sys
2011-10-28 11:06:10 167696 ----a-w- C:\Windows\System32\drivers\tmcomm.sys
2011-10-28 11:05:31 56 ----a-w- C:\Windows\System32\SupportTool.exe.bat
2011-10-28 11:05:09 -------- d-----w- C:\Program Files\Trend Micro
2011-10-28 10:27:16 25160 ----a-w- C:\Windows\System32\drivers\hitmanpro35.sys
2011-10-28 10:26:59 -------- d-----w- C:\ProgramData\Hitman Pro
2011-10-28 10:16:00 -------- d-----w- C:\Program Files (x86)\Sophos
2011-10-28 09:56:07 -------- d-----w- C:\Program Files (x86)\ESET
2011-10-28 07:34:34 -------- d-----w- C:\faggatory
2011-10-28 05:57:07 55384 ----a-w- C:\Windows\System32\drivers\SBREDrv.sys
2011-10-28 05:56:44 -------- d-----w- C:\Program Files (x86)\Toolbar Cleaner
2011-10-28 05:56:40 -------- d-----w- C:\Program Files (x86)\Lavasoft
2011-10-28 02:11:28 3138048 ----a-w- C:\Windows\System32\win32k.sys
2011-10-28 02:09:15 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-10-28 02:09:15 331776 ----a-w- C:\Windows\System32\oleacc.dll
2011-10-28 02:09:15 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-10-28 02:09:14 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2011-10-28 02:09:12 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-10-28 02:09:12 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-10-28 02:09:12 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-10-28 01:29:43 -------- d-----w- C:\Users\Brendan\AppData\Local\{427D344C-8C83-4DA3-B264-83B51A229CD1}
2011-10-28 01:29:16 -------- d-----w- C:\Users\Brendan\AppData\Local\{B6C2461A-DD85-48DF-B32B-A096898D3A7B}
2011-10-27 11:10:57 -------- d-----w- C:\Users\Brendan\AppData\Roaming\KORG
2011-10-27 11:10:05 -------- d-----w- C:\ProgramData\KORG
2011-10-27 11:10:00 -------- d-----w- C:\Program Files (x86)\Common Files\KORG
2011-10-27 02:31:43 -------- dc-h--w- C:\ProgramData\{CD847476-CA4B-4BA7-A433-A0DF81E35617}
2011-10-27 02:23:36 -------- d-----w- C:\Users\Brendan\AppData\Local\{59A2AFBC-00FF-4862-B620-68ACFA9FC4A1}
2011-10-27 02:23:24 -------- d-----w- C:\Users\Brendan\AppData\Local\{8B2B808E-C1AD-4532-8BF3-EC9BACA7ECE4}
2011-10-26 21:37:10 -------- d-----w- C:\Fraps
2011-10-26 14:22:57 -------- d-----w- C:\Users\Brendan\AppData\Local\{21873656-0854-4A54-87D7-C9C75B62C80C}
2011-10-26 14:22:44 -------- d-----w- C:\Users\Brendan\AppData\Local\{635BFBFD-C6CC-4CD2-BD3B-8FB51C620637}
2011-10-26 13:52:27 -------- d-----w- C:\Program Files (x86)\Battlelog Web Plugins
2011-10-26 02:22:16 -------- d-----w- C:\Users\Brendan\AppData\Local\{E6239D40-5C04-4E8D-B926-DB4677527789}
2011-10-25 16:19:01 -------- d--h--w- C:\Program Files (x86)\Common Files\EAInstaller
2011-10-25 14:21:50 -------- d-----w- C:\Users\Brendan\AppData\Local\{7A05416F-B193-4C5F-B4B2-C326EC7198E6}
2011-10-25 04:56:21 -------- d-----w- C:\Users\Brendan\AppData\Roaming\Origin
2011-10-25 04:56:20 -------- d-----w- C:\Users\Brendan\AppData\Local\Origin
2011-10-25 04:56:12 -------- d-----w- C:\Program Files (x86)\Origin Games
2011-10-25 04:56:01 -------- d-----w- C:\Program Files (x86)\Origin
2011-10-25 04:55:21 -------- d-----w- C:\ProgramData\EA Core
2011-10-25 02:21:25 -------- d-----w- C:\Users\Brendan\AppData\Local\{2B907CD2-C9F7-4B91-A40D-09FA5C324BD6}
2011-10-24 14:20:59 -------- d-----w- C:\Users\Brendan\AppData\Local\{6F8E2932-FDA7-495E-BC41-511BB9E0FEF6}
2011-10-24 03:29:02 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2011-10-24 03:29:02 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
2011-10-24 02:20:34 -------- d-----w- C:\Users\Brendan\AppData\Local\{756B2F4A-A0AA-442C-991C-47C26F726276}
2011-10-23 14:20:07 -------- d-----w- C:\Users\Brendan\AppData\Local\{FD321DC0-6782-4BFA-A501-73FE26AE3019}
2011-10-23 02:19:43 -------- d-----w- C:\Users\Brendan\AppData\Local\{D39B2EFE-7691-4F88-8123-8E0156C882FB}
2011-10-22 14:19:17 -------- d-----w- C:\Users\Brendan\AppData\Local\{828066F0-03B7-44E2-83BA-8D4A67415BEA}
2011-10-22 11:21:42 71680 ----a-w- C:\Windows\System32\frapsv64.dll
2011-10-22 11:21:38 65536 ----a-w- C:\Windows\SysWow64\frapsvid.dll
2011-10-22 02:18:52 -------- d-----w- C:\Users\Brendan\AppData\Local\{ED7E2930-5CD0-4879-9DBD-6CB80A2F5429}
2011-10-21 14:18:27 -------- d-----w- C:\Users\Brendan\AppData\Local\{0E442637-5F3D-42B7-BCA4-149EEDF9BA21}
2011-10-21 14:18:15 -------- d-----w- C:\Users\Brendan\AppData\Local\{1249A95B-1326-4CE5-B1B4-8701B16511DE}
2011-10-21 02:17:49 -------- d-----w- C:\Users\Brendan\AppData\Local\{71FE7794-3189-429E-9175-98B236D8B621}
2011-10-20 14:17:24 -------- d-----w- C:\Users\Brendan\AppData\Local\{01D13129-C3FF-4CCF-98D5-20063818D0DC}
2011-10-20 02:16:58 -------- d-----w- C:\Users\Brendan\AppData\Local\{0B9F2F6F-7743-4966-8593-8DB86826F76C}
2011-10-19 14:16:33 -------- d-----w- C:\Users\Brendan\AppData\Local\{26C0F4B8-2BD8-4667-9D72-E9554A8F1649}
2011-10-19 14:16:21 -------- d-----w- C:\Users\Brendan\AppData\Local\{54F36669-4E6E-4D2D-8368-F30C91C94760}
2011-10-19 02:15:55 -------- d-----w- C:\Users\Brendan\AppData\Local\{DC40E485-66D9-4DA5-82D9-86439B1F71A9}
2011-10-19 02:15:44 -------- d-----w- C:\Users\Brendan\AppData\Local\{30B547FD-3312-435C-A3E3-CB51E5745E99}
2011-10-18 14:15:30 -------- d-----w- C:\Users\Brendan\AppData\Local\{1FFFE7ED-970E-4806-A12A-7B5D72EE2F6C}
2011-10-18 14:15:18 -------- d-----w- C:\Users\Brendan\AppData\Local\{28B09F53-466D-436B-89E8-9CFDF94222EC}
2011-10-18 02:15:01 -------- d-----w- C:\Users\Brendan\AppData\Local\{F09DC01B-43CF-4ECC-8880-F1398C945259}
2011-10-18 02:14:47 -------- d-----w- C:\Users\Brendan\AppData\Local\{CD2D8075-FEED-4E09-859B-1604853550FF}
2011-10-17 07:45:34 -------- d-----w- C:\Users\Brendan\AppData\Local\{33A51A5A-3CF2-4DF1-AD27-2E25297F8E39}
2011-10-16 19:45:08 -------- d-----w- C:\Users\Brendan\AppData\Local\{466E8209-89C5-4B94-A678-52593B4C3FF9}
2011-10-16 19:44:56 -------- d-----w- C:\Users\Brendan\AppData\Local\{4A159626-810A-46B6-94B0-B0CF626B3589}
2011-10-16 07:44:29 -------- d-----w- C:\Users\Brendan\AppData\Local\{DD562EE6-DE4D-47FA-8985-AF83ADA4CAB5}
2011-10-15 19:44:03 -------- d-----w- C:\Users\Brendan\AppData\Local\{6BBBA2BD-D354-43DC-AC48-D07F37874AE3}
2011-10-15 07:43:38 -------- d-----w- C:\Users\Brendan\AppData\Local\{0E1A86AB-606F-449E-9A18-99E36D1BB4B8}
2011-10-14 19:43:12 -------- d-----w- C:\Users\Brendan\AppData\Local\{B842E530-2BC9-4F81-9C6C-555953BD8ED4}
2011-10-14 13:54:52 321856 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2011-10-14 07:42:47 -------- d-----w- C:\Users\Brendan\AppData\Local\{55B5761B-B536-492C-BB23-FE6A6DFFE10D}
2011-10-14 07:42:35 -------- d-----w- C:\Users\Brendan\AppData\Local\{271820DF-7982-4C18-A2E4-CEFF6CAE1116}
2011-10-13 19:42:08 -------- d-----w- C:\Users\Brendan\AppData\Local\{7AA94988-1F30-46EC-A2B7-0E827122F79F}
2011-10-13 07:41:41 -------- d-----w- C:\Users\Brendan\AppData\Local\{A3D3C8AB-6A01-44E5-8632-D59C8E6AE8D9}
2011-10-13 07:41:28 -------- d-----w- C:\Users\Brendan\AppData\Local\{1BE9A1D9-CEEF-49E6-8F19-1FAEAE01942C}
2011-10-12 06:28:17 -------- d-----w- C:\Users\Brendan\AppData\Local\{D7A18767-D987-489E-812F-14C092B681C4}
2011-10-12 06:28:03 -------- d-----w- C:\Users\Brendan\AppData\Local\{AC525FCE-3B9C-466C-943F-B1FA0FB66D22}
.
==================== Find3M ====================
.
2011-11-10 11:25:29 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2011-11-10 11:25:29 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-11-10 11:21:28 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2011-10-25 16:18:46 75136 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-10-02 18:06:03 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-08-31 06:00:50 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-30 12:05:32 96104 ----a-w- C:\Windows\System32\dns-sd.exe
2011-08-30 12:05:32 85864 ----a-w- C:\Windows\System32\dnssd.dll
2011-08-30 12:05:04 83816 ----a-w- C:\Windows\SysWow64\dns-sd.exe
2011-08-30 12:05:04 73064 ----a-w- C:\Windows\SysWow64\dnssd.dll
2011-08-22 04:40:08 252016 ----a-w- C:\Windows\SysWow64\vmnc.dll
2011-08-22 04:12:26 62064 ----a-w- C:\Windows\System32\vmnetbridge.dll
2011-08-22 04:12:26 48752 ----a-w- C:\Windows\System32\vnetinst.dll
2011-08-22 04:12:26 45680 ----a-w- C:\Windows\System32\drivers\vmnetbridge.sys
2011-08-22 04:12:26 24176 ----a-w- C:\Windows\System32\drivers\vmnet.sys
2011-08-22 04:12:26 20080 ----a-w- C:\Windows\System32\drivers\vmnetadapter.sys
2011-08-18 14:46:06 30720 ----a-w- C:\Windows\System32\drivers\tapoas.sys
2011-08-17 05:26:46 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2011-08-17 05:25:08 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2011-08-17 04:24:12 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2011-08-17 04:19:27 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
.
============= FINISH: 16:46:08.27 ===============
This post has been edited by hamluis: 11 November 2011 - 12:28 PM
Reason for edit: Moved from Am I Infected to Malware Removal Logs.

Help
This topic is locked

Back to top










