While trying to fix an unrelated problem I attempted a system restoration under Windows 7 64 bits. Windows said the system couldn't be restored because of my antivirus, so I disabled it (it still didn't work), forgot to turn it back on, and quickly got infected by TDSS/Rootkit/Alureon. The main symptom is that my Google searches get redirected.
I've downloaded both Kasperksy's TDSSKiller and Avast's aswMBR, which according to what I've read are able to fix this problem, but I can't run them. I save the .exe to my desktop, run it, I see a process start, but it closes on its own (even in safe mode). DDS logs are as follows; GMER logs could not be created because of 64 bit OS.
Anyone who can help me with this will have my eternal gratitude.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514
Run by Guil at 0:29:23 on 2012-01-09
Microsoft Windows 7 Édition Familiale Premium 6.1.7601.1.1252.2.1036.18.6126.4054 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\lxdjcoms.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\Lexmark 1400 Series\lxdjamon.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Windows\explorer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://gateway.msn.com
uDefault_Page_URL = hxxp://gateway.msn.com
mDefault_Page_URL = hxxp://gateway.msn.com
mStart Page = hxxp://gateway.msn.com
uURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe,
BHO: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Programme d'aide de l'Assistant de connexion Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{1E0C7D4C-48FC-4228-A398-5A61C2FB11AB} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{EC21D03C-6BAB-4762-8E8E-7BB27DD17D49} : DhcpNameServer = 192.168.0.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
BHO-X64: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
{53707962-6F74-2D53-2644-206D7942484F}
{72853161-30C5-4D22-B7F9-0BBC1D38A37E}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{B4F3A835-0E21-4959-BA22-42B3008E02FF}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun-x64: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRunOnce-x64: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript
SEH-X64: {B5A7F190-DDA6-4420-B3BA-52453494E6CD}: Groove GFS Stub Execution Hook
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Guil\AppData\Roaming\Mozilla\Firefox\Profiles\38riohlt.default\
FF - prefs.js: browser.startup.homepage - hxxp://en.wikipedia.org/wiki/Main_Page
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-1-6 44768]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-1 13336]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-5-31 1153368]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-9-14 508264]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-8-6 235624]
R3 e1cexpress;Intel® PRO/1000 PCI Express Network Connection Driver C;C:\Windows\system32\DRIVERS\e1c62x64.sys --> C:\Windows\system32\DRIVERS\e1c62x64.sys [?]
R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --> C:\Windows\system32\DRIVERS\Sftfslh.sys [?]
R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?]
R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]
R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --> C:\Windows\system32\DRIVERS\Sftvollh.sys [?]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-9-14 219496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 31125880]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\system32\DRIVERS\netr28x.sys --> C:\Windows\system32\DRIVERS\netr28x.sys [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Service Windows Activation Technologies;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-01-09 00:41:34 -------- d-----w- C:\Users\Guil\AppData\Local\{D26FB650-E9E8-40ED-BAD7-678D43294F8B}
2012-01-09 00:41:22 -------- d-----w- C:\Users\Guil\AppData\Local\{2DC4BCC6-D317-4CAC-AF5F-52BC4FA4889D}
2012-01-08 12:41:03 -------- d-----w- C:\Users\Guil\AppData\Local\{891401FB-3EDE-457A-A8DE-DDA6552D2D1C}
2012-01-08 12:40:42 -------- d-----w- C:\Users\Guil\AppData\Local\{0FC29B37-21C8-40A1-8149-526D3D06D813}
2012-01-08 02:53:56 133632 ----a-w- C:\MbrFix64.exe
2012-01-07 23:28:29 -------- d-----w- C:\Users\Guil\AppData\Local\{0E87CB94-DCB0-42B1-AA06-3783771B6AFB}
2012-01-07 23:28:02 -------- d-----w- C:\Users\Guil\AppData\Local\{7277EBE4-067F-4420-A702-2A49D093BB5B}
2012-01-07 04:51:07 -------- d-----w- C:\Users\Guil\AppData\Local\{FD93609C-B865-4E19-B7D9-EEF50AD9E7CB}
2012-01-07 04:50:40 -------- d-----w- C:\Users\Guil\AppData\Local\{EE7A1907-E48A-4888-85EC-BC06B7EFC843}
2012-01-06 15:57:11 -------- d-----w- C:\Users\Guil\AppData\Local\{0753E816-3DFE-4964-8C3A-EB68C38D0433}
2012-01-06 15:57:00 -------- d-----w- C:\Users\Guil\AppData\Local\{81EFE799-FD91-442A-A658-98D1E5528AC1}
2012-01-06 10:37:30 8822856 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A8AD1D13-CAB3-401E-A165-064068604BF2}\mpengine.dll
2012-01-06 05:08:35 -------- d-----w- C:\Users\Guil\AppData\Local\{6E5C8F83-A243-4C8F-9FFC-B1F0AB375C66}
2012-01-04 23:00:30 -------- d-----w- C:\Users\Guil\AppData\Local\{AA9D1A6D-BC94-4503-A24B-42EAD88486F6}
2012-01-04 23:00:03 -------- d-----w- C:\Users\Guil\AppData\Local\{7951303E-3823-40AF-A464-614B6DF9BA6D}
2012-01-04 06:41:17 -------- d-----w- C:\Users\Guil\AppData\Roaming\Malwarebytes
2012-01-04 06:41:07 -------- d-----w- C:\ProgramData\Malwarebytes
2012-01-04 06:41:07 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-01-04 06:38:05 6189952 ----a-w- C:\ARO2011_bt.exe
2012-01-04 06:35:21 -------- d-----w- C:\MGtools
2012-01-04 06:35:14 2448941 ----a-w- C:\MGtools.exe
2012-01-04 06:21:01 -------- d-----w- C:\Users\Guil\AppData\Local\{8B93659C-E38C-4EA8-B186-7A81716A7063}
2012-01-04 06:20:33 -------- d-----w- C:\Users\Guil\AppData\Local\{32379A7F-916E-44EC-A8F1-3E9959F7306B}
2011-12-31 04:46:34 -------- d-----w- C:\Program Files (x86)\PC Tools Security
2011-12-31 04:46:34 -------- d-----w- C:\Program Files (x86)\Common Files\PC Tools
2011-12-31 04:03:10 -------- d-----w- C:\ProgramData\PC Tools
2011-12-31 04:01:26 -------- d-----w- C:\Users\Guil\AppData\Local\{DE6B4CE6-7A65-4E53-A2FC-93850AB3F1F9}
2011-12-31 04:01:09 -------- d-----w- C:\Users\Guil\AppData\Local\{3E7D0B1C-0F6A-4A76-B78E-D48C9D7EE6D8}
2011-12-30 16:00:36 -------- d-----w- C:\Users\Guil\AppData\Local\{E0668F49-DE7C-4C65-8384-4514D763CA78}
2011-12-30 16:00:00 -------- d-----w- C:\Users\Guil\AppData\Local\{B816C32C-9E22-4F37-B903-6A2F1033F6C0}
2011-12-29 22:10:44 -------- d-----w- C:\Users\Guil\AppData\Local\{0230414A-1670-4FC0-9B34-445A7E81C8E8}
2011-12-29 22:10:17 -------- d-----w- C:\Users\Guil\AppData\Local\{FE39AAB0-3305-47E8-AF79-47760162CD99}
2011-12-29 21:54:25 -------- d-----w- C:\Program Files (x86)\NirSoft
2011-12-29 21:47:00 -------- d-----w- C:\Users\Guil\AppData\Local\{7569C851-01C4-4FA8-B30B-4BF0E25DCBAA}
2011-12-29 21:46:49 -------- d-----w- C:\Users\Guil\AppData\Local\{CFCAE92F-2787-4BDF-B156-5773EE4398BA}
2011-12-29 08:36:58 -------- d-----w- C:\Users\Guil\AppData\Local\{E6F1F0B4-9C23-4CB8-95D9-5852330753A5}
2011-12-29 08:36:47 -------- d-----w- C:\Users\Guil\AppData\Local\{D16CCD4B-CFB0-4573-9BCC-0AA82EE3CE48}
2011-12-28 20:36:34 -------- d-----w- C:\Users\Guil\AppData\Local\{375FDF42-1756-4447-99DF-3EFC22C57500}
2011-12-28 20:36:22 -------- d-----w- C:\Users\Guil\AppData\Local\{1B347D23-BF6D-4683-88FF-12F5D9142093}
2011-12-28 02:14:22 -------- d-----w- C:\Users\Guil\AppData\Local\{FA520722-AA8B-41D7-A9BE-079F67A25920}
2011-12-28 02:14:11 -------- d-----w- C:\Users\Guil\AppData\Local\{67BCE994-3277-4391-91BF-E3F70D8A579F}
2011-12-27 14:13:45 -------- d-----w- C:\Users\Guil\AppData\Local\{559F80FB-654C-48CE-9897-F9FED9325044}
2011-12-27 14:13:18 -------- d-----w- C:\Users\Guil\AppData\Local\{AE07AACD-0161-44B0-AB06-07DB535E3447}
2011-12-26 23:55:45 -------- d-----w- C:\Users\Guil\AppData\Local\{4A1EBB79-CDBA-4E9E-9E5C-AF0CF1C001D3}
2011-12-26 23:55:16 -------- d-----w- C:\Users\Guil\AppData\Local\{42F03F94-9061-4F92-A6D3-7E2FCC235490}
2011-12-26 06:26:40 -------- d-----w- C:\Users\Guil\AppData\Local\{2E8FD2FD-6162-4EF5-AD87-EB585931AF4A}
2011-12-26 06:26:13 -------- d-----w- C:\Users\Guil\AppData\Local\{7B2CDA9D-EFA8-4859-94E4-6819B682A522}
2011-12-24 17:03:56 -------- d-----w- C:\Users\Guil\AppData\Local\{22FE3F8A-7AA3-4E7B-A4B6-62CC87EF5B1B}
2011-12-24 17:03:29 -------- d-----w- C:\Users\Guil\AppData\Local\{88165539-38AB-41F1-BFD4-B9D061CF8538}
2011-12-24 04:10:37 -------- d-----w- C:\Users\Guil\AppData\Local\{71C66302-E2E5-4749-AD30-1C1DDD5C1135}
2011-12-24 04:10:16 -------- d-----w- C:\Users\Guil\AppData\Local\{EDFC9DDC-5C7C-4713-A77B-AF5984579A41}
2011-12-23 16:09:51 -------- d-----w- C:\Users\Guil\AppData\Local\{0610D01D-3EA5-4931-B567-51C3CED2FE26}
2011-12-23 16:09:40 -------- d-----w- C:\Users\Guil\AppData\Local\{92F0F111-97B9-48FE-9A93-D93F92E7A988}
2011-12-23 04:09:10 -------- d-----w- C:\Users\Guil\AppData\Local\{D7E0A420-E89A-496B-88EF-9EDE7EC2F945}
2011-12-23 04:08:59 -------- d-----w- C:\Users\Guil\AppData\Local\{18CD7A89-FB2D-401D-84DB-7524934533D3}
2011-12-22 16:28:38 1146984 ----a-w- C:\Windows\System32\RTSnMg64.cpl
2011-12-22 16:28:30 65024 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
2011-12-22 16:28:30 1251944 ----a-w- C:\Windows\RtlExUpd.dll
2011-12-22 16:08:31 -------- d-----w- C:\Users\Guil\AppData\Local\{2B7744B2-0570-4FDD-BE2F-CC11F6582E1A}
2011-12-22 16:08:09 -------- d-----w- C:\Users\Guil\AppData\Local\{9434CF4A-F38E-4A35-9818-62EFED1B4A07}
2011-12-22 03:10:28 -------- d-----w- C:\Users\Guil\AppData\Local\{8A2D2CDF-D6BE-460D-83B5-7E6BBE9ADEB5}
2011-12-22 03:10:00 -------- d-----w- C:\Users\Guil\AppData\Local\{3D0B0575-E66F-417C-9A9C-2F97B9B663DA}
2011-12-21 07:04:37 -------- d-----w- C:\Users\Guil\AppData\Local\{7CB5BD39-1CB3-48C9-B833-5B27551536A0}
2011-12-21 07:04:20 -------- d-----w- C:\Users\Guil\AppData\Local\{4EF61ED3-6C40-466D-A948-F521705BAF65}
2011-12-20 19:03:50 -------- d-----w- C:\Users\Guil\AppData\Local\{3D2305A7-1B7C-4901-BF6D-510E1CF9A3F0}
2011-12-20 19:03:23 -------- d-----w- C:\Users\Guil\AppData\Local\{BA3D0298-F29B-4641-B5A1-334D0BB6E378}
2011-12-20 00:34:53 -------- d-----w- C:\Users\Guil\AppData\Local\{8AD3B1FC-232F-4151-942D-5D46C5B39CD7}
2011-12-20 00:34:42 -------- d-----w- C:\Users\Guil\AppData\Local\{90033567-AC23-4A0E-AD6D-60D9474F13BA}
2011-12-19 01:59:46 -------- d-----w- C:\Users\Guil\AppData\Local\{89352EEB-FDEB-4A7C-BA28-FB7F4A590F2F}
2011-12-19 01:59:16 -------- d-----w- C:\Users\Guil\AppData\Local\{83F8C506-92C3-4517-B1F9-E58715B249D3}
2011-12-18 05:08:35 -------- d-----w- C:\Users\Guil\AppData\Local\{551CA179-63DE-4158-B4F2-1EB1939ABDF7}
2011-12-18 05:08:24 -------- d-----w- C:\Users\Guil\AppData\Local\{2026E6A5-45FB-4D22-B4E6-5A9C08C42FE5}
2011-12-18 03:09:09 -------- d-----w- C:\Program Files (x86)\raidcall
2011-12-17 17:16:01 563168 ----a-w- C:\ProgramData\SPLBBDF.tmp
2011-12-17 17:07:57 -------- d-----w- C:\Users\Guil\AppData\Local\{15241DD7-320C-49B6-B249-BEB354D706A0}
2011-12-17 17:07:31 -------- d-----w- C:\Users\Guil\AppData\Local\{F7888F38-BA7E-47DD-8DDD-2D6A8B0B231F}
2011-12-17 04:07:39 -------- d-----w- C:\Users\Guil\AppData\Local\{4A5B1743-9F29-4424-9334-43BACD0B3BB3}
2011-12-17 04:07:28 -------- d-----w- C:\Users\Guil\AppData\Local\{D916104E-8309-4EF5-BAF3-5C97EBF19524}
2011-12-16 16:07:02 -------- d-----w- C:\Users\Guil\AppData\Local\{1D3DF098-C661-41FB-8395-6BB3626C0B34}
2011-12-16 16:06:36 -------- d-----w- C:\Users\Guil\AppData\Local\{416CAF56-2865-470B-B71C-77FF1FE45431}
2011-12-16 03:58:16 -------- d-----w- C:\Users\Guil\AppData\Local\{8CF45DB5-86DF-4852-92D3-56D4C6980C0D}
2011-12-16 03:57:15 -------- d-----w- C:\Users\Guil\AppData\Local\{8F1C2481-9F10-45FC-9C2C-1E00B5AD409D}
2011-12-15 15:56:48 -------- d-----w- C:\Users\Guil\AppData\Local\{E2B972AA-A831-4D7A-BCBB-F9ED728381DF}
2011-12-15 15:56:36 -------- d-----w- C:\Users\Guil\AppData\Local\{AF7845FD-05CC-40BB-A6C4-4B78DC40B2BD}
2011-12-15 03:35:58 3145216 ----a-w- C:\Windows\System32\win32k.sys
2011-12-15 03:35:50 723456 ----a-w- C:\Windows\System32\EncDec.dll
2011-12-15 03:35:50 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2011-12-15 03:35:44 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-12-15 03:35:44 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-12-15 02:49:00 -------- d-----w- C:\Users\Guil\AppData\Local\{779BD002-24C1-4695-8B57-0685EEB7D388}
2011-12-15 02:48:29 -------- d-----w- C:\Users\Guil\AppData\Local\{80C748A9-3AEE-4BBE-92B8-A3A150B62B1B}
2011-12-14 05:28:37 -------- d-----w- C:\Users\Guil\AppData\Local\{AC26C6E2-C7FA-4790-A033-F8996DE125D9}
2011-12-14 05:28:25 -------- d-----w- C:\Users\Guil\AppData\Local\{C67ED582-05C0-445C-9C99-08DCD83FDD21}
2011-12-13 17:27:55 -------- d-----w- C:\Users\Guil\AppData\Local\{60781A75-ECDD-4B08-9641-F1C02F7B7615}
2011-12-13 17:27:27 -------- d-----w- C:\Users\Guil\AppData\Local\{BEC7EEA6-BBE2-4A11-BE50-9FE07D503CE8}
2011-12-12 20:18:59 -------- d-----w- C:\Users\Guil\AppData\Local\{8CB35BFF-6324-4CA9-B85F-DC20FA664F7C}
2011-12-12 20:18:34 -------- d-----w- C:\Users\Guil\AppData\Local\{F119F42E-9FB0-4F89-BC44-1BF90E475039}
2011-12-11 23:47:15 -------- d-----w- C:\Users\Guil\AppData\Local\{CB80D50B-C779-4BFD-80A1-CF21D124B48C}
2011-12-11 23:46:35 -------- d-----w- C:\Users\Guil\AppData\Local\{06448F9D-9268-4F06-94A0-823969167BB8}
2011-12-11 04:36:07 -------- d-----w- C:\Users\Guil\AppData\Local\{23D166BB-6DA1-45C8-933D-229945DCA50B}
2011-12-11 04:35:41 -------- d-----w- C:\Users\Guil\AppData\Local\{9C98079B-822F-497A-A043-E96A51865FDB}
2011-12-10 16:35:14 -------- d-----w- C:\Users\Guil\AppData\Local\{D773C022-E0F2-46A7-BC15-D69C26C73A2B}
2011-12-10 16:34:42 -------- d-----w- C:\Users\Guil\AppData\Local\{7B3D9E2F-E552-4297-B2D6-43D729F507BF}
.
==================== Find3M ====================
.
2012-01-08 05:37:59 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-28 18:01:25 41184 ----a-w- C:\Windows\avastSS.scr
2011-11-28 17:54:06 591192 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2011-11-28 17:52:11 66904 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2011-11-05 05:41:43 1188864 ----a-w- C:\Windows\System32\wininet.dll
2011-11-05 04:35:00 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-11-05 03:32:47 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-11-05 02:48:51 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-10-26 05:21:20 43520 ----a-w- C:\Windows\System32\csrsrv.dll
.
============= FINISH: 0:40:27,76 ===============
Attached File(s)
-
Attach.txt (7.43K)
Number of downloads: 1
This post has been edited by Guil50: 09 January 2012 - 12:48 AM

Help
This topic is locked

Back to top











