I've run Malwarebytes Antimalware, TDSSKiller, Combofix (which won't run in normal mode), housecall etc. usually they find nothing but there's obviously something wrong here.
Somebody pointed out to me that HDD usage and Network usage caused by Rootkits can be hidden from the Microsoft Resource Monitor, which would explain the behaviour that I'm seeing.
Windows 7 Ultimate x64
8GB DDR3 Ram
1.2 TB RAID0 2x640GB 7200rpm HDD
Core2Quad @ 2Ghz (Intel Q9000)
2xNvidia 260M GTX (SLi)
I was asked to post logs of combofix and DDS, can't run GMER using 64 bit OS.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30
Run by AluminumHaste at 14:16:53 on 2012-01-04
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8190.5338 [GMT -5:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ec0230c23ac63514\STacSV64.exe
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ec0230c23ac63514\AESTSr64.exe
C:\Program Files\Bigfoot Networks\Killer Network Manager\BFNService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files\OSD\Service1.exe
C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\alg.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Raxco\PerfectDisk\PDAgentS1.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files (x86)\Office\Office14\MSOSYNC.EXE
C:\Program Files\OSD\Launch_CC.exe
C:\Program Files\Bigfoot Networks\Killer Network Manager\KillerNetManager.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\Creative\Volume Panel\VolPanlu.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Acronis\Timounter\TimounterMonitor.exe
C:\Program Files (x86)\ACD Systems\ACDSee Pro\5.0\ACDSeeProInTouch2.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Alienware\Command Center\AlienFXHook32Mngr.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Alienware\Command Center\AlienFXHook64Mngr.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Everything\Everything.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\ALUMIN~1\AppData\Local\Temp\HouseCall\housecall.bin
C:\Windows\system32\taskhost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\AUDIODG.EXE
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
BHO: AutorunsDisabled - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\Office\Office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\Office\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
uRun: [AdobeBridge]
uRun: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s
uRun: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
uRun: [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe"
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [RGSC] C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
uRun: [OfficeSyncProcess] "C:\Program Files (x86)\Office\Office14\MSOSYNC.EXE"
uRun: [Launch_CC] c:\Program Files\OSD\Launch_CC.exe
uRun: [igndlm.exe] C:\Program Files (x86)\Download Manager\DLM.exe /windowsstart /startifwork
uRun: [EADM] "C:\Program Files (x86)\Electronic Arts\EADM\EADMUI.exe"
mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun: [FAStartup]
mRun: [VolPanel] "C:\Program Files (x86)\Creative\Volume Panel\VolPanlu.exe" /r
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [TrayMonitor.exe] C:\Program Files (x86)\Acronis\TrayMonitor\TrayMonitor.exe
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [OSD] c:\Program Files\OSD\Launch.exe
mRun: [FLxHCIm64] "C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe"
mRun: [FATrayAlert] C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe
mRun: [BCSSync] "C:\Program Files (x86)\Office\Office14\BCSSync.exe" /DelayServices
mRun: [BackupAndRecoveryMonitor.exe] C:\Program Files (x86)\Acronis\BackupAndRecovery\BackupAndRecoveryMonitor.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
mRun: [AcronisTimounterMonitor] C:\Program Files (x86)\Common Files\Acronis\Timounter\TimounterMonitor.exe
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
mRun: [ACPW05EN] "C:\Program Files (x86)\ACD Systems\ACDSee Pro\5.0\ACDSeeProInTouch2.exe" /pid ACPW05EN
StartupFolder: C:\Users\AluminumHaste\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BIGFOO~1.LNK - C:\Program Files (x86)\Bigfoot Networks\Killer Network Manager\KillerNetManager.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\Office\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\Office\Office14\ONBttnIE.dll/105
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Office\Office14\ONBttnIELinkedNotes.dll
LSP: %SYSTEMROOT%\system32\BfLLR.dll
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15118/CTPID.cab
TCP: DhcpNameServer = 192.168.1.159
TCP: Interfaces\{2CC16828-DC4F-4504-B26A-0881C0482C9D} : DhcpNameServer = 192.168.42.129
TCP: Interfaces\{A5725FFA-D724-4ECD-84AE-56F783723945} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{A5725FFA-D724-4ECD-84AE-56F783723945}\343594356716E6132333 : DhcpNameServer = 192.168.137.1
TCP: Interfaces\{A5725FFA-D724-4ECD-84AE-56F783723945}\343594356716E64323 : DhcpNameServer = 192.168.137.1
TCP: Interfaces\{A5725FFA-D724-4ECD-84AE-56F783723945}\4656C6C61677162756024656374727F6975627 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{A5725FFA-D724-4ECD-84AE-56F783723945}\A5F626F6F6D61666F6F6 : DhcpNameServer = 192.168.1.159
TCP: Interfaces\{A5725FFA-D724-4ECD-84AE-56F783723945}\A5F626F6F6D61666F6F6537486A7 : DhcpNameServer = 192.168.1.159
TCP: Interfaces\{A5725FFA-D724-4ECD-84AE-56F783723945}\A5F626F6F6D61666F6F6F50535B4 : DhcpNameServer = 216.8.137.203 216.8.137.204 0.45.0.0 64.245.229.160
TCP: Interfaces\{C000129D-561D-4CB5-825B-7139B7640414} : DhcpNameServer = 192.168.1.159
TCP: Interfaces\{E2017AE5-503C-4992-A699-7FE01E97ACB9} : DhcpNameServer = 192.168.1.159
TCP: Interfaces\{E2017AE5-503C-4992-A699-7FE01E97ACB9}\75946494D244435353 : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{E2017AE5-503C-4992-A699-7FE01E97ACB9}\A5F626F6F6D61666F6F623E2437486A7 : DhcpNameServer = 192.168.1.159
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Notify: FastAccess - C:\Program Files\Alienware\Command Center\AlienSense\FALogNot.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\Office\Office14\GROOVEEX.DLL
BHO-X64: AutorunsDisabled - No File
BHO-X64: URLRedirectionBHO - No File
BHO-X64: SSOIEAddonBHO - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\Office\Office14\GROOVEEX.DLL
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\Office\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: SmartSelect - No File
TB-X64: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
mRun-x64: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun-x64: [FAStartup]
mRun-x64: [VolPanel] "C:\Program Files (x86)\Creative\Volume Panel\VolPanlu.exe" /r
mRun-x64: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [TrayMonitor.exe] C:\Program Files (x86)\Acronis\TrayMonitor\TrayMonitor.exe
mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun-x64: [OSD] c:\Program Files\OSD\Launch.exe
mRun-x64: [FLxHCIm64] "C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe"
mRun-x64: [FATrayAlert] C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe
mRun-x64: [BCSSync] "C:\Program Files (x86)\Office\Office14\BCSSync.exe" /DelayServices
mRun-x64: [BackupAndRecoveryMonitor.exe] C:\Program Files (x86)\Acronis\BackupAndRecovery\BackupAndRecoveryMonitor.exe
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
mRun-x64: [AcronisTimounterMonitor] C:\Program Files (x86)\Common Files\Acronis\Timounter\TimounterMonitor.exe
mRun-x64: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
mRun-x64: [ACPW05EN] "C:\Program Files (x86)\ACD Systems\ACDSee Pro\5.0\ACDSeeProInTouch2.exe" /pid ACPW05EN
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\Office\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\AluminumHaste\AppData\Roaming\Mozilla\Firefox\Profiles\tfm27kgw.Default User\
FF - plugin: C:\PROGRA~2\Office\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\Office\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Download Manager\npfpdlm.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\ProgramData\id Software\QuakeLive\npquakezero.dll
FF - plugin: C:\Users\AluminumHaste\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Users\AluminumHaste\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\AluminumHaste\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 BfLwf;Bigfoot Networks Bandwidth Control;C:\Windows\system32\DRIVERS\bflwfx64.sys --> C:\Windows\system32\DRIVERS\bflwfx64.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ec0230c23ac63514\AESTSr64.exe [2011-7-28 89600]
R2 Bigfoot Networks Killer Service;Bigfoot Networks Killer Service;C:\Program Files\Bigfoot Networks\Killer Network Manager\BFNService.exe [2011-11-7 467456]
R2 cpuz134;cpuz134;\??\C:\Windows\system32\drivers\cpuz134_x64.sys --> C:\Windows\system32\drivers\cpuz134_x64.sys [?]
R2 CustomSvc;Vista Session Launcher Service;C:\Program Files\OSD\Service1.exe [2010-9-23 13312]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-9-16 2253120]
R2 OS Selector;Acronis OS Selector activator;C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe [2010-5-25 2139400]
R2 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2011-4-22 92592]
R3 Ak27x64;Killer Wireless-N 1102 device driver;C:\Windows\system32\DRIVERS\Ak27x64.sys --> C:\Windows\system32\DRIVERS\Ak27x64.sys [?]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
R3 nvoclk64;NVIDIA Enthusiasts Platform KDM;C:\Windows\system32\DRIVERS\nvoclk64.sys --> C:\Windows\system32\DRIVERS\nvoclk64.sys [?]
R3 OA007Vid;Creative Camera OA007 Function Driver;C:\Windows\system32\DRIVERS\OA007Vid.sys --> C:\Windows\system32\DRIVERS\OA007Vid.sys [?]
S2 AlienFusionService;Alienware Fusion Service;C:\Program Files\Alienware\Command Center\AlienFusionService.exe [2010-5-21 14648]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-2-15 136176]
S3 AcronisAgent;Acronis Remote Agent;C:\Program Files (x86)\Common Files\Acronis\Agent\agent.exe [2009-11-27 1865560]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;C:\Windows\system32\Drivers\ssadadb.sys --> C:\Windows\system32\Drivers\ssadadb.sys [?]
S3 btusbflt;Bluetooth USB Filter;C:\Windows\system32\drivers\btusbflt.sys --> C:\Windows\system32\drivers\btusbflt.sys [?]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-12-28 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-7-7 79360]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;C:\Program Files (x86)\Dragon Age\bin_ship\daupdatersvc.service.exe [2011-3-7 25832]
S3 Desura Install Service;Desura Install Service;C:\Program Files (x86)\Common Files\Desura\desura_service.exe [2011-10-7 131912]
S3 FACAP;facap, FastAccess Video Capture;C:\Windows\system32\DRIVERS\facap.sys --> C:\Windows\system32\DRIVERS\facap.sys [?]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-10-21 1315592]
S3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver;C:\Windows\system32\DRIVERS\FLxHCIc.sys --> C:\Windows\system32\DRIVERS\FLxHCIc.sys [?]
S3 FLxHCIh;Fresco Logic xHCI (USB3) Hub Device Driver;C:\Windows\system32\DRIVERS\FLxHCIh.sys --> C:\Windows\system32\DRIVERS\FLxHCIh.sys [?]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-2-15 136176]
S3 itecir;ITECIR Infrared Receiver;C:\Windows\system32\DRIVERS\itecir.sys --> C:\Windows\system32\DRIVERS\itecir.sys [?]
S3 ksaud;Creative USB Audio Driver;C:\Windows\system32\drivers\ksaud.sys --> C:\Windows\system32\drivers\ksaud.sys [?]
S3 MMS;Acronis Managed Machine Service;C:\Program Files (x86)\Acronis\BackupAndRecovery\mms.exe [2009-11-27 4285664]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys --> C:\Windows\system32\DRIVERS\NETwNs64.sys [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\system32\DRIVERS\ssadbus.sys --> C:\Windows\system32\DRIVERS\ssadbus.sys [?]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\system32\DRIVERS\ssadmdfl.sys --> C:\Windows\system32\DRIVERS\ssadmdfl.sys [?]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\system32\DRIVERS\ssadmdm.sys --> C:\Windows\system32\DRIVERS\ssadmdm.sys [?]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 VSPerfDrv100;Performance Tools Driver 10.0;C:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2011-1-18 68440]
S3 WatAdminSvc;WatAdminSvc;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 xhc200w;xhc200w;C:\Users\AluminumHaste\Downloads\RenesasFW\firmware\uPD720200_uPD720200A_FW_Updater\xhc200w.sys [2011-12-28 30344]
S4 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2010-6-29 128752]
S4 FAService;FAService;C:\Program Files\Alienware\Command Center\AlienSense\FAService.exe [2010-4-4 2409800]
S4 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Office\Office14\GROOVE.EXE [2010-1-21 30963576]
.
=============== File Associations ===============
.
vbefile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
vbsfile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
jsefile\shell\open2\command=C:\Windows\System32\CScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2012-01-04 15:19:58 -------- d-sh--w- C:\$RECYCLE.BIN
2012-01-04 09:09:00 -------- d-----w- C:\Users\AluminumHaste\AppData\Local\Rockstar Games
2012-01-04 09:07:07 -------- d-----w- C:\Users\AluminumHaste\AppData\Local\Electronic Arts
2012-01-04 06:59:40 -------- d-----w- C:\d158daefa447ba4acc77
2012-01-03 03:13:02 -------- d-----w- C:\Program Files (x86)\Geeks3D
2011-12-30 18:57:57 924672 ----a-w- C:\Windows\System32\fdco2.dll
2011-12-30 18:57:57 845736 ----a-w- C:\Windows\System32\DPInst.exe
2011-12-30 18:57:57 645224 ----a-w- C:\Windows\System32\nvunrm.exe
2011-12-30 18:57:57 348264 ----a-w- C:\Windows\System32\drivers\nvmf6264.sys
2011-12-30 18:57:57 199272 ----a-w- C:\Windows\System32\nvconrm.dll
2011-12-30 03:40:30 -------- d-----w- C:\Users\AluminumHaste\Calibre Library
2011-12-30 03:40:29 -------- d-----w- C:\Users\AluminumHaste\AppData\Roaming\calibre
2011-12-30 03:40:07 -------- d-----w- C:\Program Files (x86)\Calibre2
2011-12-28 19:34:33 -------- d-----w- C:\ProgramData\Sendori
2011-12-28 19:34:21 -------- d-----w- C:\Users\AluminumHaste\AppData\Roaming\OpenCandy
2011-12-27 02:01:12 -------- d-----w- C:\ogmodautodownloader_windows(3)
2011-12-26 07:03:36 626688 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcr80.dll
2011-12-26 07:03:36 548864 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcp80.dll
2011-12-26 07:03:36 479232 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcm80.dll
2011-12-26 07:03:36 43992 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozutils.dll
2011-12-24 07:47:25 -------- d-----w- C:\VirtualDub-1.10.0-AMD64
2011-12-24 07:43:17 9210382 ----a-w- C:\Program Files (x86)\mmg.exe
2011-12-24 07:43:17 8614926 ----a-w- C:\Program Files (x86)\mkvmerge.exe
2011-12-24 07:43:17 7839246 ----a-w- C:\Program Files (x86)\mkvinfo.exe
2011-12-24 07:43:17 6518798 ----a-w- C:\Program Files (x86)\mkvextract.exe
2011-12-24 07:43:17 5829134 ----a-w- C:\Program Files (x86)\mkvpropedit.exe
2011-12-24 07:43:17 -------- d-----w- C:\Program Files (x86)\locale
2011-12-24 07:43:17 -------- d-----w- C:\Program Files (x86)\examples
2011-12-24 07:43:17 -------- d-----w- C:\Program Files (x86)\doc
2011-12-24 07:43:17 -------- d-----w- C:\Program Files (x86)\data
2011-12-24 07:18:36 -------- d-----w- C:\Program Files (x86)\TagJet
2011-12-19 02:15:44 -------- d-----w- C:\DarkloaderSRC
2011-12-15 19:05:25 539680 ----a-w- C:\Windows\System32\nvusmu.exe
2011-12-15 19:05:25 28704 ----a-w- C:\Windows\System32\drivers\nvsmu.sys
2011-12-15 19:05:25 167936 ----a-w- C:\Windows\System32\NVCOSMU.DLL
2011-12-15 08:49:56 90112 ----a-w- C:\Windows\MAMCityDownload.ocx
2011-12-15 08:49:56 325552 ----a-w- C:\Windows\MASetupCaller.dll
2011-12-15 08:49:56 30568 ----a-w- C:\Windows\MusiccityDownload.exe
2011-12-15 05:19:27 -------- d-----w- C:\Users\AluminumHaste\Flash Samsung Fascinate_files
2011-12-15 04:25:48 -------- d-----w- C:\Program Files (x86)\SuperOneClick
2011-12-15 04:16:58 -------- d-----w- C:\Users\AluminumHaste\AppData\Roaming\ODIN
2011-12-15 04:16:46 -------- d-----w- C:\Program Files (x86)\ODIN
2011-12-14 23:41:12 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2011-12-14 23:41:10 3145216 ----a-w- C:\Windows\System32\win32k.sys
2011-12-14 23:41:08 723456 ----a-w- C:\Windows\System32\EncDec.dll
2011-12-14 23:41:08 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2011-12-14 23:41:06 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-12-14 23:41:06 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-12-13 05:40:29 -------- d-----w- C:\Program Files (x86)\Common Files\TortoiseOverlays
2011-12-13 05:40:28 -------- d-----w- C:\Program Files\TortoiseSVN
2011-12-13 05:40:28 -------- d-----w- C:\Program Files\Common Files\TortoiseOverlays
2011-12-10 07:36:34 -------- d-----w- C:\Program Files (x86)\PowerArchiver
2011-12-09 14:52:39 -------- d-----w- C:\Users\AluminumHaste\AppData\Local\MetaGeek,_LLC
2011-12-09 14:33:23 -------- d-----w- C:\Users\AluminumHaste\AppData\Roaming\mkvtoolnix
2011-12-09 14:31:56 -------- d-----w- C:\Program Files (x86)\MKVToolNix
.
==================== Find3M ====================
.
2011-12-30 18:28:01 525544 ----a-w- C:\Windows\System32\deployJava1.dll
2011-12-30 18:27:18 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-12-10 20:24:08 23152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-12-02 16:38:43 61440 ----a-w- C:\Windows\SysWow64\nvPhotoshopUtil.dll
2011-12-02 16:38:43 40960 ----a-w- C:\Windows\SysWow64\nvISWOW64.dll
2011-12-02 16:38:43 151552 ----a-w- C:\Windows\SysWow64\nvRegDev.dll
2011-11-24 06:45:56 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-18 15:14:58 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2011-11-08 02:53:04 69224 ----a-w- C:\Windows\System32\drivers\bflwfx64.sys
2011-11-08 02:53:04 2740328 ----a-w- C:\Windows\System32\drivers\Ak27x64.sys
2011-11-08 02:53:02 195688 ----a-w- C:\Windows\System32\BfLLR.dll
2011-11-08 02:53:00 180840 ----a-w- C:\Windows\SysWow64\BfLLR.dll
2011-11-08 02:53:00 160360 ----a-w- C:\Windows\System32\kstat.exe
2011-11-08 02:52:58 145512 ----a-w- C:\Windows\SysWow64\kstat.exe
2011-11-08 02:52:54 163432 ----a-w- C:\Windows\System32\xstat.exe
2011-11-08 02:52:52 148584 ----a-w- C:\Windows\SysWow64\xstat.exe
2011-11-07 23:53:44 321856 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2011-11-04 01:53:39 2309120 ----a-w- C:\Windows\System32\jscript9.dll
2011-11-04 01:44:47 1390080 ----a-w- C:\Windows\System32\wininet.dll
2011-11-04 01:44:21 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl
2011-11-04 01:34:43 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-11-03 22:47:42 1798144 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-11-03 22:40:21 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2011-11-03 22:39:47 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-11-03 22:31:57 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-10-28 06:04:33 14848 ----a-w- C:\Windows\System32\slwga.dll
2011-10-28 06:04:33 13824 ----a-w- C:\Windows\SysWow64\slwga.dll
2011-10-28 06:04:32 419840 ----a-w- C:\Windows\System32\systemcpl.dll
2011-10-26 22:48:20 90472 ----a-w- C:\Windows\System32\nusb3co2.dll
2011-10-25 14:57:38 96768 ----a-w- C:\Windows\System32\drivers\nusb3hub.sys
2011-10-25 14:57:38 213504 ----a-w- C:\Windows\System32\drivers\nusb3xhc.sys
2011-10-22 11:05:10 71680 ----a-w- C:\Windows\System32\frapsv64.dll
2011-10-22 11:05:08 65536 ----a-w- C:\Windows\SysWow64\frapsvid.dll
2011-10-17 21:53:56 51 ----a-w- C:\OGModAutoDownloader.bat
2011-10-17 05:29:08 69888 ----a-w- C:\Windows\System32\drivers\FLxHCIh.sys
2011-10-17 05:29:08 202496 ----a-w- C:\Windows\System32\drivers\FLxHCIc.sys
.
============= FINISH: 14:17:43.61 ===============
I tried pasting the contents of the combofix log here but the post is too long so I've attached it.
Combofix.txt:
ComboFix.txt (205.96K)
Number of downloads: 0
Attach.zip:
Attach.zip (5.94K)
Number of downloads: 0
Attach.txt:
Attach.txt (18.37K)
Number of downloads: 0

Help
This topic is locked

Back to top









