Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Strange behavior since reinstallation


  • Please log in to reply
1 reply to this topic

#1 WarriorKalia

WarriorKalia

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:12 PM

Posted 07 November 2010 - 03:47 AM

I recently reinstalled Windows because of a virus that would redirect my Google searches. Now that I've reinstalled, I'm worried I have yet another virus. Hoping someone can help me out with this- I noted winlogon.exe and csrss.exe have no description in Task Manager, but I'm unable to tell whether this is normal- I get conflicting messages. I also received two BSoDs in the past hour- unfortunately, I can't recall the text of the last one.

Here's my Hijackthis log.

Edit: Got another blue screen, window popped up with this info:

Problem signature:
Problem Event Name: BlueScreen
OS Version: 6.1.7600.2.0.0.768.3
Locale ID: 1033

Additional information about the problem:
BCCode: a
BCP1: FFFFFFFFFFFFFFD0
BCP2: 0000000000000002
BCP3: 0000000000000001
BCP4: FFFFF80002E956E0
OS Version: 6_1_7600
Service Pack: 0_0
Product: 768_1

Files that help describe the problem:
C:\Windows\Minidump\110710-22323-01.dmp
C:\Users\Kalia\AppData\Local\Temp\WER-1423353-0.sysdata.xml

Adding additional requested info


DDS (Ver_10-11-08.01) - NTFS_AMD64
Run by Kalia at 6:38:51.65 on Mon 11/08/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4085.2600 [GMT -8:00]

SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_056607ee0106e5e8\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_056607ee0106e5e8\AESTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\OSD\Service1.exe
C:\Program Files (x86)\STMicroelectronics\Accelerometer\InstallFilterService.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\OSD\Launch_CC.exe
C:\Users\Kalia\Desktop\Wowhead_Client.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Users\Kalia\AppData\Local\Apps\2.0\9BOQ32WN.X6X\J63MC9WH.J6K\curs..tion_eee711038731a406_0004.0000_1829574f2226d088\CurseClient.exe
C:\Program Files\OSD\OSD_Main.exe
C:\Program Files (x86)\LaCie\Shortcut Button\LaCieShortcutTrayApp.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\explorer.exe
C:\Users\Kalia\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Launch_CC] c:\Program Files\OSD\Launch_CC.exe
uRun: [Wowhead_Client] "C:\Users\Kalia\Desktop\Wowhead_Client.exe"
uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [OSD] c:\Program Files\OSD\Launch.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [LaCie Shortcut Startup] C:\Program Files (x86)\LaCie\Shortcut Button\LaCieShortcutTrayApp.exe
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\Kalia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
mRun-x64: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
mRun-x64: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe
mRun-x64: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
mRun-x64: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe

================= FIREFOX ===================

FF - ProfilePath - C:\Users\Kalia\AppData\Roaming\Mozilla\Firefox\Profiles\6xbzxkp1.default\
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;C:\Windows\System32\drivers\Lbd.sys [2010-11-5 69152]
R0 pavboot;pavboot;C:\Windows\System32\drivers\pavboot64.sys [2010-11-5 33800]
R0 stdflt;Disk Filter Driver for Accelerometer;C:\Windows\System32\drivers\stdflt.sys [2010-11-5 18792]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2010-3-25 173984]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2010-6-29 128752]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_056607ee0106e5e8\AESTSr64.exe [2010-11-5 89600]
R2 CustomSvc;Vista Session Launcher Service;C:\Program Files\OSD\Service1.exe [2010-11-5 13312]
R2 InstallFilterService;FF Install Filter Service;C:\Program Files (x86)\STMicroelectronics\Accelerometer\InstallFilterService.exe [2010-11-5 60928]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2010-9-22 1375992]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
R3 Acceler;Accelerometer Service;C:\Windows\System32\drivers\Acceler.sys [2010-11-5 23912]
R3 itecir;ITECIR Infrared Receiver;C:\Windows\System32\drivers\itecir.sys [2010-7-13 69736]
R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\netw5v64.sys [2009-6-10 5434368]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2010-11-7 155752]
R3 WinRing0_1_2_0;WinRing0_1_2_0;C:\Program Files\OSD\WinRing0x64.sys [2010-11-5 14544]
S2 {09BB444F-B2E2-4009-BAF2-7B727681223E};BuddyVM;C:\Program Files (x86)\VMLaunch\BuddyVM.sys [2004-10-5 15872]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys [2010-9-22 17440]
S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\System32\drivers\MpNWMon.sys [2010-3-25 40832]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-11-6 1255736]

=============== Created Last 30 ================

2010-11-08 05:40:43 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2010-11-08 05:28:44 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2010-11-08 05:18:56 -------- d-----w- C:\Windows\System32\drivers\NSSx64\0207030.022
2010-11-08 05:18:56 -------- d-----w- C:\Windows\System32\drivers\NSSx64
2010-11-08 05:18:56 -------- d-----w- C:\Program Files (x86)\Norton Security Scan
2010-11-08 05:18:56 -------- d-----w- C:\PROGRA~3\Norton
2010-11-08 05:18:55 -------- d-----w- C:\PROGRA~3\Symantec
2010-11-08 05:18:52 -------- d-----w- C:\Program Files (x86)\NortonInstaller
2010-11-08 05:18:52 -------- d-----w- C:\PROGRA~3\NortonInstaller
2010-11-08 05:09:02 8006480 ----a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{44C80880-9313-429A-B193-A5BF21D08D37}\mpengine.dll
2010-11-07 22:58:13 -------- d-----w- C:\Users\Kalia\AppData\Local\Microsoft Games
2010-11-07 15:13:23 511488 ----a-w- C:\Windows\System32\ctapo32.dll
2010-11-07 15:13:22 68608 ----a-w- C:\Windows\System32\AESTAR64.dll
2010-11-07 15:13:22 652288 ----a-w- C:\Windows\System32\ctapo64.dll
2010-11-07 15:13:22 444928 ----a-w- C:\Windows\System32\AESTEC64.dll
2010-11-07 15:13:22 162304 ----a-w- C:\Windows\System32\AESTAC64.dll
2010-11-07 15:13:21 90624 ----a-w- C:\Windows\System32\AESTCo64.dll
2010-11-07 15:13:21 57856 ----a-w- C:\Windows\System32\ctppld64.dll
2010-11-07 15:13:21 564224 ----a-w- C:\Windows\System32\idt64mp1.exe
2010-11-07 15:13:21 3038720 ----a-w- C:\Windows\System32\stlang64.dll
2010-11-07 15:13:21 12383232 ----a-w- C:\Windows\System32\idtcpl64.cpl
2010-11-07 15:13:19 -------- d-----w- C:\Windows\System32\SRSLabs
2010-11-07 14:59:59 -------- d-----w- C:\Users\Kalia\AppData\Roaming\DigitalCute
2010-11-06 22:36:14 8006480 ----a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2010-11-06 22:12:01 -------- d-----w- C:\Users\Kalia\AppData\Local\Apple Computer
2010-11-06 22:11:48 34152 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2010-11-06 22:11:48 126312 ----a-w- C:\Windows\System32\GEARAspi64.dll
2010-11-06 22:11:48 107368 ----a-w- C:\Windows\SysWow64\GEARAspi.dll
2010-11-06 22:11:17 -------- d-----w- C:\Program Files\iPod
2010-11-06 22:11:16 -------- d-----w- C:\Program Files\iTunes
2010-11-06 22:11:16 -------- d-----w- C:\Program Files (x86)\iTunes
2010-11-06 22:11:16 -------- d-----w- C:\PROGRA~3\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2010-11-06 21:52:47 -------- d-----w- C:\Users\Kalia\AppData\Local\Apple
2010-11-06 21:52:17 -------- d-----w- C:\Program Files\Bonjour
2010-11-06 21:52:17 -------- d-----w- C:\Program Files (x86)\Bonjour
2010-11-06 20:57:56 -------- d-----w- C:\Program Files (x86)\JRE
2010-11-06 20:54:25 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2010-11-06 20:54:25 472808 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2010-11-06 20:52:36 -------- d-----w- C:\Program Files (x86)\VideoLAN
2010-11-06 20:49:54 -------- d-----w- C:\Users\Kalia\AppData\Local\Deployment
2010-11-06 20:46:48 -------- d-----w- C:\Users\Kalia\AppData\Roaming\JAM Software
2010-11-06 20:46:19 -------- d-----w- C:\Program Files (x86)\JAM Software
2010-11-06 18:10:02 -------- d-----w- C:\Users\Kalia\AppData\Roaming\NJStar
2010-11-06 18:01:31 311808 ----a-w- C:\Windows\System32\msv1_0.dll
2010-11-06 18:01:31 257024 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2010-11-06 17:57:14 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2010-11-06 17:52:04 -------- d-----w- C:\Windows\SysWow64\Wat
2010-11-06 17:52:04 -------- d-----w- C:\Windows\System32\Wat
2010-11-06 17:46:37 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2010-11-06 17:46:37 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
2010-11-06 17:46:37 48960 ----a-w- C:\Windows\System32\netfxperf.dll
2010-11-06 17:46:37 444752 ----a-w- C:\Windows\System32\mscoree.dll
2010-11-06 17:46:37 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
2010-11-06 17:46:37 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
2010-11-06 17:46:37 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
2010-11-06 17:46:37 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2010-11-06 17:46:37 109912 ----a-w- C:\Windows\System32\PresentationHostProxy.dll
2010-11-06 17:46:36 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2010-11-06 17:21:43 -------- d-----w- C:\Program Files (x86)\LaCie
2010-11-06 17:17:43 -------- d-----w- C:\Users\Kalia\AppData\Local\ElevatedDiagnostics
2010-11-06 16:47:45 -------- d-----w- C:\Program Files (x86)\VMLaunch
2010-11-06 16:34:36 243712 ----a-w- C:\Windows\System32\drivers\ks.sys
2010-11-06 16:34:36 184832 ----a-w- C:\Windows\System32\drivers\usbvideo.sys
2010-11-06 10:13:57 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2010-11-06 10:12:54 558592 ----a-w- C:\Windows\System32\spoolsv.exe
2010-11-06 10:11:54 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2010-11-06 10:11:54 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2010-11-06 10:11:54 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2010-11-06 10:11:53 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2010-11-06 10:11:51 463360 ----a-w- C:\Windows\System32\drivers\srv.sys
2010-11-06 10:11:50 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2010-11-06 10:11:50 402944 ----a-w- C:\Windows\System32\drivers\srv2.sys
2010-11-06 10:11:50 236032 ----a-w- C:\Windows\System32\srvsvc.dll
2010-11-06 10:11:50 161792 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2010-11-06 10:09:11 3123712 ----a-w- C:\Windows\System32\win32k.sys
2010-11-06 06:14:09 -------- d-----w- C:\Users\Kalia\AppData\Roaming\SUPERAntiSpyware.com
2010-11-06 06:14:09 -------- d-----w- C:\PROGRA~3\SUPERAntiSpyware.com
2010-11-06 06:14:03 -------- d-----w- C:\PROGRA~3\!SASCORE
2010-11-06 06:13:59 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2010-11-06 05:50:48 33800 ----a-w- C:\Windows\System32\drivers\pavboot64.sys
2010-11-06 05:47:19 -------- d-----w- C:\Program Files (x86)\Panda Security
2010-11-06 04:51:37 189520 ----a-w- C:\Windows\SysWow64\drivers\tmcomm.sys
2010-11-06 03:54:14 -------- d-----w- C:\Users\Kalia\AppData\Local\Adobe
2010-11-06 00:54:35 15880 ----a-w- C:\Windows\System32\lsdelete.exe
2010-11-05 22:27:00 23912 ----a-w- C:\Windows\System32\drivers\Acceler.sys
2010-11-05 22:27:00 18792 ----a-w- C:\Windows\System32\drivers\stdflt.sys
2010-11-05 22:05:32 69152 ----a-w- C:\Windows\System32\drivers\Lbd.sys
2010-11-05 22:05:32 49752 ----a-w- C:\Windows\System32\drivers\SBREDrv.sys
2010-11-05 22:00:41 -------- d-----w- C:\Users\Kalia\AppData\Local\Sunbelt Software
2010-11-05 21:52:33 -------- d-----w- C:\Users\Kalia\AppData\Local\MediaMonkey
2010-11-05 21:49:51 -------- dc-h--w- C:\PROGRA~3\{E961CE1B-C3EA-4882-9F67-F859B555D097}
2010-11-05 21:44:40 -------- d-----w- C:\Users\Kalia\AppData\Roaming\Malwarebytes
2010-11-05 21:44:13 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2010-11-05 21:44:12 -------- d-----w- C:\PROGRA~3\Malwarebytes
2010-11-05 21:44:11 24664 ----a-w- C:\Windows\System32\drivers\mbam.sys
2010-11-05 21:30:06 -------- d-----w- C:\Program Files (x86)\Microsoft Antimalware
2010-11-05 21:30:02 -------- d-----w- C:\Program Files\Microsoft Security Essentials
2010-11-05 21:24:24 834544 ----a-w- C:\Windows\System32\drivers\sptd.sys
2010-11-05 21:24:04 -------- d-----w- C:\Program Files (x86)\DAEMON Tools Lite
2010-11-05 21:23:42 -------- d-----w- C:\Users\Kalia\AppData\Roaming\DAEMON Tools Lite
2010-11-05 21:23:35 -------- d-----w- C:\PROGRA~3\DAEMON Tools Lite
2010-11-05 20:58:07 -------- d-----w- C:\Users\Kalia\AppData\Local\Mozilla
2010-11-05 20:48:00 220672 ----a-w- C:\Windows\System32\wintrust.dll
2010-11-05 20:48:00 172032 ----a-w- C:\Windows\SysWow64\wintrust.dll
2010-11-05 20:47:55 139264 ----a-w- C:\Windows\System32\cabview.dll
2010-11-05 20:47:52 132608 ----a-w- C:\Windows\SysWow64\cabview.dll
2010-11-05 20:41:50 67584 ----a-w- C:\Windows\System32\drivers\rimmpx64.sys
2010-11-05 20:41:50 57856 ----a-w- C:\Windows\System32\drivers\rixdpx64.sys
2010-11-05 20:41:49 90112 ----a-w- C:\Windows\System32\snymsico.dll
2010-11-05 20:41:49 55296 ----a-w- C:\Windows\System32\drivers\rimspx64.sys
2010-11-05 20:41:48 172032 ----a-w- C:\Windows\System32\rixdicon.dll
2010-11-05 20:32:34 8006480 ----a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{DBB41DC6-C33B-44E6-A586-042D0E2714C2}\mpengine.dll
2010-11-05 20:32:33 270720 ------w- C:\Windows\System32\MpSigStub.exe
2010-11-05 20:26:34 -------- d-----w- C:\Program Files (x86)\uTorrent
2010-11-05 20:26:09 -------- d-----w- C:\Users\Kalia\AppData\Roaming\uTorrent
2010-11-05 20:21:47 -------- d-----w- C:\PROGRA~3\Wowhead
2010-11-05 19:46:42 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2010-11-05 19:46:26 -------- d-----w- C:\PROGRA~3\NVIDIA Corporation
2010-11-05 19:45:31 -------- d-----w- C:\Program Files\NVIDIA Corporation
2010-11-05 19:38:01 -------- d-----w- C:\Users\Kalia\AppData\Local\Broadcom
2010-11-05 19:36:10 -------- d-----w- C:\Program Files\WIDCOMM
2010-11-05 19:31:54 -------- d-----w- C:\Program Files (x86)\STMicroelectronics
2010-11-05 19:24:55 -------- d-----w- C:\Program Files\Synaptics
2010-11-05 19:11:14 -------- d-----w- C:\Users\Kalia\AppData\Local\Apps
2010-11-05 19:00:48 -------- d-----w- C:\Program Files\Alienware
2010-11-05 18:58:27 -------- d-----w- C:\Users\Kalia\AppData\Local\Downloaded Installations
2010-11-05 18:56:02 -------- d-----w- C:\Windows\Panther
2010-11-05 18:55:13 -------- d-----w- C:\Windows\SysWow64\OEM
2010-11-05 18:55:13 -------- d-----w- C:\Windows\System32\OEM
2010-11-05 18:54:11 605696 ------w- C:\Windows\System32\stapi64.dll
2010-11-05 18:54:11 499712 ----a-w- C:\Windows\System32\drivers\stwrt64.sys
2010-11-05 18:54:11 431616 ----a-w- C:\Windows\System32\stcplx64.dll
2010-11-05 18:54:11 209920 ----a-w- C:\Windows\System32\st646241.dll
2010-11-05 18:54:11 1433088 ----a-w- C:\Windows\System32\stapo64.dll
2010-11-05 18:54:10 511488 ----a-w- C:\Windows\SysWow64\ctapo32.dll
2010-11-05 18:54:10 -------- d-----w- C:\Program Files\IDT
2010-11-05 18:50:05 -------- d-sh--w- C:\Windows\Installer
2010-11-05 18:49:54 -------- d-----w- C:\Program Files\OSD
2010-11-05 18:45:05 -------- d-----w- C:\Users\Kalia\AppData\Local\Diagnostics
2010-11-05 18:39:03 -------- d-----w- C:\Users\Kalia\AppData\Local\VirtualStore
2010-11-05 14:34:14 -------- d-----w- C:\Program Files (x86)\Lavasoft
2010-11-05 04:26:05 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2010-11-05 00:11:57 -------- d-----w- C:\Program Files\Ventrilo
2010-10-16 21:13:46 5901416 ----a-w- C:\Windows\System32\nvcpl.dll
2010-10-16 21:13:26 2590824 ----a-w- C:\Windows\System32\nvsvc64.dll
2010-10-16 21:13:26 116328 ----a-w- C:\Windows\System32\nvmctray.dll
2010-10-16 21:13:24 989800 ----a-w- C:\Windows\System32\nvvsvc.exe
2010-10-16 21:13:24 61032 ----a-w- C:\Windows\System32\nvshext.dll
2010-10-16 21:13:24 302184 ----a-w- C:\Windows\System32\nvhotkey.dll
2010-10-16 21:13:24 1881704 ----a-w- C:\Windows\System32\nvsvcr.dll

==================== Find3M ====================

2010-09-10 05:35:44 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2010-09-10 05:35:43 347648 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2010-09-08 18:17:46 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2010-09-08 18:17:46 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
2010-09-08 05:36:17 1192960 ----a-w- C:\Windows\System32\wininet.dll
2010-09-08 05:34:34 57856 ----a-w- C:\Windows\System32\licmgr10.dll
2010-09-08 04:30:04 978432 ----a-w- C:\Windows\SysWow64\wininet.dll
2010-09-08 04:28:15 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
2010-09-08 04:16:38 482816 ----a-w- C:\Windows\System32\html.iec
2010-09-08 03:35:30 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2010-09-08 03:22:31 386048 ----a-w- C:\Windows\SysWow64\html.iec
2010-09-08 02:48:16 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2010-09-07 20:09:02 29288 ----a-w- C:\Windows\System32\nvhdap64.dll
2010-09-07 20:08:55 155752 ----a-w- C:\Windows\System32\drivers\nvhda64v.sys
2010-09-07 20:08:54 1308776 ----a-w- C:\Windows\System32\nvgenco64.dll
2010-08-31 04:32:30 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
2010-08-31 04:32:30 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
2010-08-26 05:27:28 148992 ----a-w- C:\Windows\System32\t2embed.dll
2010-08-26 04:39:58 109056 ----a-w- C:\Windows\SysWow64\t2embed.dll
2010-08-21 06:38:47 1024512 ----a-w- C:\Windows\System32\wmpmde.dll
2010-08-21 06:36:49 340992 ----a-w- C:\Windows\System32\schannel.dll
2010-08-21 06:31:06 633856 ----a-w- C:\Windows\System32\comctl32.dll
2010-08-21 05:36:33 738816 ----a-w- C:\Windows\SysWow64\wmpmde.dll
2010-08-21 05:36:24 224256 ----a-w- C:\Windows\SysWow64\schannel.dll
2010-08-21 05:33:24 530432 ----a-w- C:\Windows\SysWow64\comctl32.dll

============= FINISH: 6:39:51.93 ===============


GMER isn't working properly- can't check most of the options available. I'll try to run it in safe mode or something.

EDIT: Posts merged ~BP

Attached Files


Edited by Budapest, 08 November 2010 - 04:16 PM.


BC AdBot (Login to Remove)

 


#2 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:03:12 PM

Posted 14 November 2010 - 09:13 AM

Hello WarriorKalia

Welcome to BleepingComputer :)
==========================
  • Download OTL to your desktop.
  • Double click on OTL to run it.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
====================
Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users