Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Cant enable Internet connection: possibility of rootkits and malware


  • This topic is locked This topic is locked
2 replies to this topic

#1 ruin

ruin

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:11:56 PM

Posted 27 November 2010 - 12:38 AM

Im having problems with ICS(internet connection sharing) and viewing some administrative tools especially event viewer. It first started when I wanted to share my LAN internet through my wifi(adhoc) it worked before. Then an error saying a dependent service or group failed to start. So I opened Services and googled possible solutions. then when i try to enable it it says it started and stopped working,some services stops when not in used.

So it tried to diagnose it then another error says diagnostic policy service not start started, so I opened services again doing the same procedures with same result "started and stopped". So I tried to go to administrative tools to view something suspicious,verify the service is available verify that the service is running'. Same steps with same error. Ive done the guides and did the DDS and Defogger ,but when I try to scan with gmer "ive unchecked all the said options".
MY COMPUTER GOES BLUE SCREEN" so it restarted my pc and of course I tried again to make sure that the blue screen was not just coincidental with it, as it turns out gmer caused the blue screen because I experienced blue screen when I did the scan again but. The third time I just clicked save and did the ark.txt.
Please help me!


DDS (Ver_10-11-26.01) - NTFSx86
Run by ryujin at 12:12:19.47 on Sat 11/27/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.1894.757 [GMT -8:00]

SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Stardock\MyColors\VistaSrv.exe
C:\Program Files\Stardock\MyColors\WBVista.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\FBAgent.exe
C:\Program Files\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\alg.exe
C:\Windows\system32\SupportAppXL\cdrom_mon.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files\ASUS\Wireless Console 3\wcourier.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Program Files\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Windows\System32\ACEngSvr.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Rainmeter\Rainmeter.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Stardock\CursorFX\CursorFX.exe
C:\Program Files\DAP\DAP.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
C:\Program Files\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Windows\AsScrPro.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
D:\Downloads\dds.scr
C:\Windows\system32\conhost.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.facebook.com/
uInternet Settings,ProxyServer = 192.168.195.2:8080
uInternet Settings,ProxyOverride = <local>
BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GR469A~1.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
BHO: DAPIELoader Class: {ff6c3cf0-4b15-11d1-abed-709549c10000} - c:\progra~1\dap\DAPIEL~1.DLL
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
uRun: [Rainmeter - A Customizable Resource Meter] c:\program files\rainmeter\Rainmeter.exe
uRun: [CursorFX] "c:\program files\stardock\cursorfx\CursorFX.exe"
uRun: [DownloadAccelerator] "c:\program files\dap\DAP.EXE" /STARTUP
mRun: [ATKOSD2] c:\program files\asus\atk package\atkosd2\ATKOSD2.exe
mRun: [ATKMEDIA] c:\program files\asus\atk package\atk media\DMedia.exe
mRun: [HControlUser] c:\program files\asus\atk package\atk hotkey\HControlUser.exe
mRun: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [<NO NAME>]
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"
StartupFolder: c:\users\ryujin\appdata\roaming\micros~1\windows\startm~1\programs\startup\stardo~1.lnk - c:\program files\stardock\objectdock\ObjectDock.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\fancys~1.lnk - c:\windows\installer\{2b81872b-a054-48da-be3b-fa5c164c303a}\_C4A2FC3E3722966204FDD8.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\srspre~1.lnk - c:\windows\installer\{e5cf6b9c-3abe-43c9-9413-ad5ffc98f049}\NewShortcut4_E9C83B3EDF9141A39DA5EC05C79BBB91.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\stardo~1.lnk - c:\program files\stardock\mycolors\SDDelayedLaunch.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: &Clean Traces - c:\program files\dap\privacy package\dapcleanerie.htm
IE: &Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Download with &DAP - c:\program files\dap\dapextie.htm
IE: &Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202
IE: Download &all with DAP - c:\program files\dap\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
TCP: {0B18004A-DA04-441F-B720-CB26EA191C50} = 192.168.2.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GRA32A~1.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\nvinit.dll
STS: Windows DreamScene: {e31004d1-a431-41b8-826f-e902f9d95c81} - %SystemRoot%\System32\DreamScene.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GR469A~1.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\users\ryujin\appdata\roaming\mozilla\firefox\profiles\dgnv1lbl.default\
FF - prefs.js: browser.startup.homepage - hxxp://wyzo.wyzostart.com/?cfg=2-47-0-0
FF - prefs.js: network.proxy.ftp - 192.168.195.2
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - 192.168.195.2
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - 192.168.195.2
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - 192.168.195.2
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - 192.168.195.2
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 1
FF - component: c:\program files\dap\dapfirefox\components\DAPFireFox.dll
FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
FF - component: c:\program files\orbitdownloader\addons\oneclickyoutubedownloader\components\GrabXpcom.dll
FF - component: c:\users\ryujin\appdata\roaming\mozilla\firefox\profiles\dgnv1lbl.default\extensions\firetorrent@radicalsoft.com\components\firetorrent.dll
FF - plugin: c:\program files\opera\program\plugins\nporbit.dll
FF - plugin: c:\users\ryujin\appdata\local\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============

R0 nvpciflt;nvpciflt;c:\windows\system32\drivers\nvpciflt.sys [2010-10-7 19656]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-11-20 162640]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [2010-10-6 303744]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-11-20 19024]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-11-20 51792]
R2 Autorun CDROM Monitor;Autorun CDROM Monitor;c:\windows\system32\supportappxl\cdrom_mon.exe [2008-11-25 81920]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-11-20 40384]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-10-7 304464]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2010-10-7 1620584]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2010\TuneUpUtilitiesService32.exe [2009-10-30 1021256]
R2 UNS;Intel® Management & Security Application User Notification Service;c:\program files\intel\intel® management engine components\uns\UNS.exe [2010-10-6 2314240]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-11-20 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-11-20 40384]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-10-6 43944]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2010-10-6 29472]
R3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\drivers\ETD.sys [2010-10-6 102400]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2010-10-6 132480]
R3 IntcDAud;Intel® Display Audio;c:\windows\system32\drivers\IntcDAud.sys [2010-10-6 232960]
R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2010-10-6 119408]
R3 JME;JMicron Ethernet Adapter NDIS6.20 Driver;c:\windows\system32\drivers\JME.sys [2010-10-6 98928]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-10-7 20952]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxLiveShare10.exe [2008-5-14 309744]
S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxWatch10.exe [2008-5-14 166384]
S2 SessionLauncher;SessionLauncher;c:\users\ryujin\appdata\local\temp\dx9\sessionlauncher.exe --> c:\users\ryujin\appdata\local\temp\dx9\SessionLauncher.exe [?]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 MSSQL$SONY_MEDIAMGR2;SQL Server (SONY_MEDIAMGR2);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2007-2-10 29178224]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2010-10-7 27192]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxMediaDB10.exe [2008-5-14 1120752]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-10-8 1343400]

=============== Created Last 30 ================

2010-11-27 17:48:30 -------- d-----w- C:\getservice
2010-11-27 00:31:32 -------- d-----w- c:\users\ryujin\appdata\roaming\GetRightToGo
2010-11-26 17:55:22 -------- d-----w- c:\users\ryujin\appdata\local\Activision
2010-11-26 17:51:00 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-11-26 17:51:00 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-11-26 17:51:00 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-11-26 17:37:08 -------- d-----w- c:\program files\Activision
2010-11-26 05:09:07 -------- d-----w- c:\program files\Pcsx2
2010-11-26 04:28:12 -------- d-----w- c:\program files\Garena
2010-11-25 06:53:07 -------- d-----w- c:\users\ryujin\appdata\local\Radical Software Ltd
2010-11-24 03:18:22 20268032 ------w- c:\windows\system32\imageres.dll
2010-11-24 02:22:34 -------- d-----w- c:\program files\common files\Corel
2010-11-24 02:20:53 -------- d-----w- c:\program files\Corel
2010-11-20 20:46:52 51792 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-11-20 18:55:09 2614272 ----a-w- c:\windows\explorer_edit_w7sbc.exe
2010-11-20 18:55:09 2614272 ----a-w- c:\windows\explorer_backup_w7sbc.exe
2010-11-20 18:55:09 -------- d-----w- c:\windows\W7SBC
2010-11-19 05:02:35 257440 ----a-w- c:\windows\system32\DreamScene.dll
2010-11-18 23:37:26 506368 ----a-w- c:\windows\system32\sqlite3.dll
2010-11-18 22:42:26 -------- d-----w- c:\users\ryujin\appdata\roaming\Rainmeter
2010-11-18 22:05:52 -------- d-----w- c:\program files\Rainmeter
2010-11-18 21:45:07 -------- dc-h--w- c:\progra~2\{D16EDDBE-DCD6-49D5-A590-2C78DCB6E5A3}
2010-11-18 21:45:02 -------- d-sh--w- c:\windows\Installer
2010-11-18 21:44:50 -------- d-----w- c:\users\ryujin\appdata\local\PackageAware
2010-11-18 21:44:14 -------- d-----w- C:\dell
2010-11-18 19:48:14 -------- d-----w- c:\program files\SpeedFan
2010-11-18 17:29:00 -------- dc-h--w- c:\progra~2\{03B3EED6-BE84-4EE0-AB1E-BF091841DA15}
2010-11-18 16:38:20 49152 ----a-w- c:\windows\system32\DartObjects.dll
2010-11-18 16:38:20 221184 ----a-w- c:\windows\system32\DartSock.dll
2010-11-18 16:38:20 118784 ----a-w- c:\windows\system32\DartWeb.dll
2010-11-18 15:59:30 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2010-11-18 15:59:29 462864 ----a-w- c:\windows\system32\d3dx10_37.dll
2010-11-18 15:59:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-11-18 15:59:29 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll
2010-11-18 15:59:28 81768 ----a-w- c:\windows\system32\xinput1_3.dll
2010-11-18 15:59:28 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll
2010-11-18 15:41:05 172032 ----a-w- c:\windows\system32\AniGIF.ocx
2010-11-18 15:23:40 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2010-11-18 14:37:12 -------- d-----w- c:\progra~2\Stardock
2010-11-18 14:05:36 -------- d-----w- c:\progra~2\SpeedBit
2010-11-18 14:05:31 -------- d-----w- c:\program files\DAP
2010-11-18 13:37:25 -------- d-----w- c:\users\ryujin\appdata\local\Yahoo
2010-11-17 19:43:14 -------- dc-h--w- c:\progra~2\{E568B6A0-8E02-46C8-8954-00ECD7CD3554}
2010-11-17 18:25:03 -------- d-----w- c:\users\ryujin\appdata\local\Deployment
2010-11-17 18:25:03 -------- d-----w- c:\users\ryujin\appdata\local\Apps
2010-11-17 00:48:30 -------- d-----r- c:\program files\Skype
2010-11-16 19:00:08 -------- d-----w- c:\users\ryujin\appdata\local\Stardock
2010-11-16 18:59:37 -------- d-----w- c:\program files\Stardock
2010-11-16 18:59:37 -------- d-----w- c:\program files\common files\Stardock
2010-11-15 23:55:59 249856 ----a-w- c:\windows\system32\uxtheme.dll.backup
2010-11-15 23:55:54 37376 ----a-w- c:\windows\system32\themeservice.dll.backup
2010-11-15 23:55:52 2755072 ----a-w- c:\windows\system32\themeui.dll.backup
2010-11-10 23:45:17 -------- d-----w- c:\users\ryujin\yf
2010-11-09 22:33:02 -------- d-----w- c:\users\ryujin\appdata\roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2010-11-09 22:33:02 -------- d-----w- c:\users\ryujin\appdata\roaming\Adobe Mini Bridge CS5
2010-11-09 22:03:51 122880 ----a-r- c:\users\ryujin\appdata\roaming\microsoft\installer\{65eea363-8d47-4268-bbce-85cd54acdc15}\NewShortcut5_FA22C8B36029437A9646719DBA760EAE.exe
2010-11-09 22:03:51 122880 ----a-r- c:\users\ryujin\appdata\roaming\microsoft\installer\{65eea363-8d47-4268-bbce-85cd54acdc15}\ARPPRODUCTICON.exe
2010-11-09 22:03:28 -------- d-----w- c:\program files\Electric Rain
2010-11-09 16:31:45 -------- d-----w- c:\users\ryujin\appdata\local\Google
2010-11-06 12:16:36 -------- d-----w- c:\users\ryujin\appdata\roaming\Artisteer
2010-11-05 17:49:24 -------- d-----w- c:\program files\City Interactive
2010-11-04 01:51:36 -------- d-----w- c:\progra~2\ALM
2010-11-03 23:11:23 -------- d-----w- c:\users\ryujin\appdata\roaming\Desktop Apps
2010-11-03 23:11:19 -------- d-----w- c:\program files\Mioplanet
2010-11-03 22:42:35 -------- d-----w- c:\users\ryujin\appdata\roaming\PeerNetworking
2010-11-03 22:20:20 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-11-03 22:19:01 -------- d-----w- c:\program files\Microsoft Expression
2010-11-03 12:37:59 -------- d-----w- c:\users\ryujin\appdata\local\Macromedia
2010-11-03 12:31:57 761856 ----a-w- c:\program files\common files\installshield\driver\10\intel 32\IDriver2.exe
2010-11-03 12:26:28 -------- d-----w- c:\program files\Macromedia
2010-11-03 12:26:28 -------- d-----w- c:\program files\common files\Macromedia
2010-11-03 12:26:02 180224 ------w- c:\program files\common files\installshield\driver\10\intel 32\iGdiCnv.dll
2010-11-03 12:26:01 409600 ------w- c:\program files\common files\installshield\driver\10\intel 32\ISRT.dll
2010-11-03 12:26:01 32768 ------w- c:\program files\common files\installshield\driver\10\intel 32\objpscnv.dll
2010-11-03 12:26:01 266240 ------w- c:\program files\common files\installshield\driver\10\intel 32\IScrCnv.dll
2010-11-03 12:26:01 172032 ------w- c:\program files\common files\installshield\driver\10\intel 32\IUserCnv.dll
2010-11-03 12:25:57 761856 ------w- c:\program files\common files\installshield\driver\10\intel 32\IDriver.exe
2010-11-03 12:25:56 540772 ------w- c:\program files\common files\installshield\driver\10\intel 32\_ISRES1033.dll
2010-11-03 12:25:37 -------- d-----w- c:\windows\Downloaded Installations
2010-11-01 17:13:57 96160 ----a-w- c:\windows\system32\AERTARen.dll
2010-11-01 17:13:57 305568 ----a-w- c:\windows\system32\FMAPO.dll
2010-11-01 17:13:56 175200 ----a-w- c:\windows\system32\AERTACap.dll
2010-11-01 17:13:52 1251944 ----a-w- c:\windows\RtlExUpd.dll
2010-11-01 17:13:50 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\DotNetInstaller.exe

==================== Find3M ====================

2010-11-24 03:43:24 2828 --sha-w- c:\progra~2\KGyGaAvL.sys
2010-11-24 02:23:09 88 --sh--r- c:\progra~2\90F585B742.sys
2010-10-27 15:30:11 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-10-14 09:36:52 15451288 ----a-w- c:\windows\system32\xlive.dll
2010-10-14 09:36:50 13642904 ----a-w- c:\windows\system32\xlivefnt.dll
2010-10-06 23:58:19 520192 ----a-w- c:\windows\system32\K_Series_ScreenSaver_EN.scr
2010-10-06 23:58:00 3054136 ----a-w- c:\windows\AsScrPro.exe
2010-10-06 02:57:22 1084008 ----a-w- c:\windows\system32\RTSndMgr.cpl
2010-10-06 02:57:10 1843816 ----a-w- c:\windows\system32\RtkPgExt.dll
2010-10-06 02:56:58 66152 ----a-w- c:\windows\system32\RtkCoInst.dll
2010-10-06 02:56:58 453224 ----a-w- c:\windows\system32\RtkApoApi.dll
2010-10-06 02:56:48 3610216 ----a-w- c:\windows\system32\RtkAPO.dll
2010-09-14 08:00:00 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-09-08 04:30:04 978432 ----a-w- c:\windows\system32\wininet.dll
2010-09-08 04:28:15 44544 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-08 03:22:31 386048 ----a-w- c:\windows\system32\html.iec
2010-09-08 02:48:16 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-09-01 04:23:49 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-09-01 02:34:52 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-08-31 04:32:30 954752 ----a-w- c:\windows\system32\mfc40.dll
2010-08-31 04:32:30 954288 ----a-w- c:\windows\system32\mfc40u.dll

============= FINISH: 12:13:35.94 ===============

Attached Files


Edited by Orange Blossom, 27 November 2010 - 09:49 PM.
Forum glitch ~ OB


BC AdBot (Login to Remove)

 


#2 B-boy/StyLe/

B-boy/StyLe/

    Bleepin' Freestyler


  • Malware Response Team
  • 8,307 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bulgaria
  • Local time:07:56 AM

Posted 04 December 2010 - 05:11 AM

Hello and welcome to Bleeping Computer :welcome:

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review your topic an do their best to resolve your issues.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.

Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

We also need a new log from the GMER anti-rootkit scanner. Please first disable any CD emulation programs using the steps found in this topic:

Why we request you disable CD Emulation when receiving Malware Removal Advice

Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here:

How to create a GMER log



Regards,
Georgi :hello:

cXfZ4wS.png


#3 thcbytes

thcbytes

  • Malware Response Team
  • 14,790 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:56 PM

Posted 15 December 2010 - 02:13 PM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic
Proud member - Unified Network of Instructors and Trained Eliminators
Posted Image

I do not accept personal donations for assistance provided. I would ask that you instead consider donating the greatest gift - Organ Donation. Your organs are of no use to you when your gone. You will save a life that would otherwise be lost!

http://donatelife.net/register-now/




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users