Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

WIndows 7 Recovery Attack


  • Please log in to reply
13 replies to this topic

#1 bpatters69

bpatters69

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:15 AM

Posted 06 June 2011 - 06:45 PM

Hello All,

I downloaded Spyhunter and I was able to remove the Windows 7 Recovery virus\trojan or whatever it is. Now I need to restore my desktop. I am posting the results of systemlook below. I am running Windows 7 Premium Home. Thanks in advance.

Bill

SystemLook 04.09.10 by jpshortstuff
Log created at 19:41 on 06/06/2011 by Patterson_Desktop
Administrator - Elevation successful

========== dir ==========

C:\Users\PATTER~1\AppData\Local\Temp\smtmp - Parameters: "/s"

---Files---
None found.

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1 d--h--- [20:48 05/06/2011]
Default Programs.lnk --ah--- 1282 bytes [05:01 14/07/2009] [05:01 14/07/2009]
desktop.ini --ahs-- 442 bytes [04:49 14/07/2009] [05:01 14/07/2009]
Windows Update.lnk --ah--- 1266 bytes [04:49 14/07/2009] [04:49 14/07/2009]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs d--h--- [20:48 05/06/2011]
Adobe Help.lnk --ah--- 997 bytes [23:10 03/07/2010] [13:08 05/07/2010]
Adobe Reader 9.lnk --ah--- 2441 bytes [10:38 15/10/2010] [14:29 13/03/2011]
Apple Software Update.lnk --ah--- 2519 bytes [03:07 12/01/2011] [03:07 12/01/2011]
desktop.ini --ahs-- 1130 bytes [04:54 14/07/2009] [23:40 01/01/2010]
Media Center.lnk --ah--- 1345 bytes [23:40 01/01/2010] [23:40 01/01/2010]
Sidebar.lnk --ah--- 1330 bytes [04:57 14/07/2009] [04:57 14/07/2009]
Vuze.lnk --ah--- 1852 bytes [20:28 03/01/2010] [23:05 11/05/2011]
Windows Anytime Upgrade.lnk --ah--- 1352 bytes [04:57 14/07/2009] [04:57 14/07/2009]
Windows DVD Maker.lnk --ah--- 1326 bytes [23:40 01/01/2010] [23:40 01/01/2010]
Windows Fax and Scan.lnk --ah--- 1210 bytes [04:54 14/07/2009] [04:54 14/07/2009]
Windows Live ID.lnk --ah--- 1338 bytes [03:15 22/01/2010] [02:52 07/07/2010]
Windows Media Player.lnk --ah--- 1547 bytes [04:57 14/07/2009] [05:09 14/07/2009]
XPS Viewer.lnk --ah--- 1246 bytes [04:57 14/07/2009] [04:57 14/07/2009]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Accessories d--h--- [20:48 05/06/2011]
Calculator.lnk --ah--- 1230 bytes [04:55 14/07/2009] [04:55 14/07/2009]
Desktop.ini --ahs-- 1726 bytes [02:36 14/07/2009] [23:41 01/01/2010]
displayswitch.lnk --ah--- 1266 bytes [04:54 14/07/2009] [04:54 14/07/2009]
Math Input Panel.lnk --ah--- 1364 bytes [23:40 01/01/2010] [23:41 01/01/2010]
Mobility Center.lnk --ah--- 1238 bytes [23:40 01/01/2010] [23:40 01/01/2010]
Paint.lnk --ah--- 1242 bytes [04:54 14/07/2009] [04:54 14/07/2009]
Remote Desktop Connection.lnk --ah--- 1367 bytes [04:53 14/07/2009] [04:53 14/07/2009]
Snipping Tool.lnk --ah--- 1272 bytes [23:40 01/01/2010] [23:40 01/01/2010]
Sound Recorder.lnk --ah--- 1330 bytes [04:57 14/07/2009] [04:57 14/07/2009]
Sticky Notes.lnk --ah--- 1351 bytes [23:40 01/01/2010] [23:40 01/01/2010]
Sync Center.lnk --ah--- 1254 bytes [04:54 14/07/2009] [04:54 14/07/2009]
Welcome Center.lnk --ah--- 1579 bytes [04:57 14/07/2009] [04:57 14/07/2009]
Wordpad.lnk --ah--- 1322 bytes [04:54 14/07/2009] [04:54 14/07/2009]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Accessories\Accessibility d--h--- [20:48 05/06/2011]
Desktop.ini --ahs-- 370 bytes [02:36 14/07/2009] [04:57 14/07/2009]
Speech Recognition.lnk --ah--- 1388 bytes [04:57 14/07/2009] [04:57 14/07/2009]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Accessories\System Tools d--h--- [20:48 05/06/2011]
Character Map.lnk --ah--- 1248 bytes [04:55 14/07/2009] [04:55 14/07/2009]
Desktop.ini --ahs-- 1338 bytes [02:36 14/07/2009] [04:57 14/07/2009]
dfrgui.lnk --ah--- 1290 bytes [04:54 14/07/2009] [04:54 14/07/2009]
Disk Cleanup.lnk --ah--- 1252 bytes [04:54 14/07/2009] [04:54 14/07/2009]
Resource Monitor.lnk --ah--- 1242 bytes [04:53 14/07/2009] [04:53 14/07/2009]
System Information.lnk --ah--- 1250 bytes [04:53 14/07/2009] [04:53 14/07/2009]
System Restore.lnk --ah--- 1246 bytes [04:54 14/07/2009] [04:54 14/07/2009]
Task Scheduler.lnk --ah--- 1268 bytes [04:54 14/07/2009] [04:54 14/07/2009]
Windows Easy Transfer Reports.lnk --ah--- 1320 bytes [04:57 14/07/2009] [04:57 14/07/2009]
Windows Easy Transfer.lnk --ah--- 1316 bytes [04:57 14/07/2009] [04:57 14/07/2009]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Accessories\Tablet PC d--h--- [20:48 05/06/2011]
Desktop.ini --ahs-- 343 bytes [07:44 14/07/2009] [23:40 01/01/2010]
ShapeCollector.lnk --ah--- 1436 bytes [23:40 01/01/2010] [23:40 01/01/2010]
TabTip.lnk --ah--- 1386 bytes [23:40 01/01/2010] [23:40 01/01/2010]
Windows Journal.lnk --ah--- 1316 bytes [23:40 01/01/2010] [23:40 01/01/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Accessories\Windows PowerShell d--h--- [20:48 05/06/2011]
desktop.ini --ahs-- 216 bytes [04:57 14/07/2009] [04:57 14/07/2009]
Windows PowerShell (x86).lnk --ah--- 1989 bytes [05:32 14/07/2009] [05:32 14/07/2009]
Windows PowerShell ISE (x86).lnk --ah--- 1468 bytes [04:57 14/07/2009] [04:57 14/07/2009]
Windows PowerShell ISE.lnk --ah--- 1468 bytes [04:57 14/07/2009] [04:57 14/07/2009]
Windows PowerShell.lnk --ah--- 1899 bytes [05:32 14/07/2009] [05:32 14/07/2009]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Administrative Tools d--h--- [20:48 05/06/2011]
Component Services.lnk --ah--- 1242 bytes [04:57 14/07/2009] [04:57 14/07/2009]
Computer Management.lnk --ah--- 1294 bytes [04:54 14/07/2009] [04:54 14/07/2009]
Data Sources (ODBC).lnk --ah--- 1270 bytes [04:53 14/07/2009] [04:53 14/07/2009]
desktop.ini --ahs-- 1674 bytes [04:53 14/07/2009] [04:57 14/07/2009]
Event Viewer.lnk --ah--- 1298 bytes [04:54 14/07/2009] [04:54 14/07/2009]
iSCSI Initiator.lnk --ah--- 1274 bytes [04:54 14/07/2009] [04:54 14/07/2009]
Memory Diagnostics Tool.lnk --ah--- 1268 bytes [04:53 14/07/2009] [04:53 14/07/2009]
Performance Monitor.lnk --ah--- 1232 bytes [04:53 14/07/2009] [04:53 14/07/2009]
services.lnk --ah--- 1288 bytes [04:54 14/07/2009] [04:54 14/07/2009]
System Configuration.lnk --ah--- 1246 bytes [04:53 14/07/2009] [04:53 14/07/2009]
Task Scheduler.lnk --ah--- 1262 bytes [04:54 14/07/2009] [04:54 14/07/2009]
Windows Firewall with Advanced Security.lnk --ah--- 1274 bytes [04:53 14/07/2009] [04:53 14/07/2009]
Windows PowerShell Modules.lnk --ah--- 2741 bytes [05:32 14/07/2009] [05:32 14/07/2009]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Adobe d--h--- [20:48 05/06/2011]
Adobe Bridge CS5.lnk --ah--- 1179 bytes [23:12 03/07/2010] [23:12 03/07/2010]
Adobe Device Central CS5.lnk --ah--- 1272 bytes [23:15 03/07/2010] [23:15 03/07/2010]
Adobe Encore CS5.lnk --ah--- 1211 bytes [23:17 03/07/2010] [23:17 03/07/2010]
Adobe ExtendScript Toolkit CS5.lnk --ah--- 1529 bytes [23:10 03/07/2010] [23:10 03/07/2010]
Adobe Extension Manager CS5.lnk --ah--- 1363 bytes [23:11 03/07/2010] [23:11 03/07/2010]
Adobe Media Encoder CS5.lnk --ah--- 1096 bytes [23:11 03/07/2010] [23:11 03/07/2010]
Adobe Media Player.lnk --ah--- 989 bytes [23:12 03/07/2010] [23:12 03/07/2010]
Adobe OnLocation CS5.lnk --ah--- 1259 bytes [23:15 03/07/2010] [23:15 03/07/2010]
Adobe Premiere Pro CS5.lnk --ah--- 1084 bytes [23:19 03/07/2010] [23:19 03/07/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\AT&T d--h--- [20:48 05/06/2011]
Communication Manager.lnk --ah--- 1132 bytes [01:44 10/06/2010] [01:44 10/06/2010]
Location Finder.lnk --ah--- 2067 bytes [01:44 10/06/2010] [01:44 10/06/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Coupons d--h--- [20:48 05/06/2011]
Coupons.com - Print Coupons.lnk --ah--- 1919 bytes [16:00 11/09/2010] [16:00 11/09/2010]
Uninstall Coupon Printer for Windows.lnk --ah--- 2071 bytes [16:01 11/09/2010] [16:01 11/09/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Debugmode d--h--- [20:48 05/06/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Debugmode\FrameServer d--h--- [20:48 05/06/2011]
ChangeLog.lnk --ah--- 1149 bytes [16:17 05/07/2010] [16:17 05/07/2010]
FrameServer Network Client.lnk --ah--- 2072 bytes [16:17 05/07/2010] [16:17 05/07/2010]
Readme.lnk --ah--- 1132 bytes [16:17 05/07/2010] [16:17 05/07/2010]
Uninstall FrameServer.lnk --ah--- 1144 bytes [16:17 05/07/2010] [16:17 05/07/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\design-the d--h--- [20:48 05/06/2011]
Dust Extraction - Trial Version.LNK --ah--- 1177 bytes [22:07 08/08/2010] [22:07 08/08/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\DVD Flick d--h--- [20:48 05/06/2011]
DVD Flick.lnk --ah--- 1936 bytes [08:12 05/07/2010] [08:12 05/07/2010]
Uninstall DVD Flick.lnk --ah--- 1078 bytes [08:12 05/07/2010] [08:12 05/07/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\DVD Flick\Help and Support d--h--- [20:48 05/06/2011]
Changelog.lnk --ah--- 1067 bytes [08:12 05/07/2010] [08:12 05/07/2010]
DVD Flick on the Web.url --ah--- 49 bytes [08:12 05/07/2010] [08:12 05/07/2010]
GNU GPL License.lnk --ah--- 1067 bytes [08:12 05/07/2010] [08:12 05/07/2010]
Guide.lnk --ah--- 1165 bytes [08:12 05/07/2010] [08:12 05/07/2010]
Readme.lnk --ah--- 1044 bytes [08:12 05/07/2010] [08:12 05/07/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Games d--h--- [20:48 05/06/2011]
Age of Empires III.lnk --ah--- 214 bytes [02:21 04/09/2010] [02:21 04/09/2010]
Chess.lnk --ah--- 352 bytes [23:40 01/01/2010] [23:40 01/01/2010]
Desktop.ini --ahs-- 1128 bytes [05:32 14/07/2009] [23:40 01/01/2010]
FreeCell.lnk --ah--- 364 bytes [04:55 14/07/2009] [04:55 14/07/2009]
GameExplorer.lnk --ah--- 258 bytes [04:54 14/07/2009] [04:54 14/07/2009]
Hearts.lnk --ah--- 356 bytes [04:57 14/07/2009] [04:57 14/07/2009]
Internet Backgammon.lnk --ah--- 474 bytes [23:40 01/01/2010] [23:40 01/01/2010]
Internet Checkers.lnk --ah--- 470 bytes [23:40 01/01/2010] [23:40 01/01/2010]
Internet Spades.lnk --ah--- 466 bytes [23:40 01/01/2010] [23:40 01/01/2010]
Mahjong.lnk --ah--- 360 bytes [23:40 01/01/2010] [23:40 01/01/2010]
Minesweeper.lnk --ah--- 376 bytes [04:57 14/07/2009] [04:57 14/07/2009]
More Games from Microsoft.lnk --ah--- 370 bytes [04:57 14/07/2009] [04:57 14/07/2009]
Purble Place.lnk --ah--- 378 bytes [04:57 14/07/2009] [04:57 14/07/2009]
Solitaire.lnk --ah--- 368 bytes [04:55 14/07/2009] [04:55 14/07/2009]
Spider Solitaire.lnk --ah--- 392 bytes [04:57 14/07/2009] [04:57 14/07/2009]
World of Warcraft.lnk --ah--- 212 bytes [21:18 07/05/2011] [21:18 07/05/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Gamigo d--h--- [20:48 05/06/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Gamigo\Black Prophecy d--h--- [20:48 05/06/2011]
Launch Black Prophecy .lnk --ah--- 2312 bytes [10:07 01/04/2011] [10:07 01/04/2011]
Read help file.lnk --ah--- 1177 bytes [10:07 01/04/2011] [10:07 01/04/2011]
Register for Black Prophecy Beta.url --ah--- 148 bytes [10:07 01/04/2011] [10:07 01/04/2011]
Uninstall Black Prophecy .lnk --ah--- 1102 bytes [10:07 01/04/2011] [10:07 01/04/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Google Chrome d--h--- [20:48 05/06/2011]
Google Chrome.lnk --ah--- 2201 bytes [00:52 24/03/2010] [03:06 28/05/2011]
Uninstall Google Chrome.lnk --ah--- 2427 bytes [00:52 24/03/2010] [03:06 28/05/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\ImgBurn d--h--- [20:48 05/06/2011]
ImgBurn Read Me.lnk --ah--- 1880 bytes [19:55 03/07/2010] [19:55 03/07/2010]
ImgBurn.lnk --ah--- 1887 bytes [19:55 03/07/2010] [19:55 03/07/2010]
Uninstall.lnk --ah--- 1686 bytes [19:55 03/07/2010] [19:55 03/07/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\iTunes d--h--- [20:48 05/06/2011]
About iTunes.lnk --ah--- 2105 bytes [03:10 12/01/2011] [03:10 12/01/2011]
iTunes.lnk --ah--- 1801 bytes [03:10 12/01/2011] [03:10 12/01/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Maintenance d--h--- [20:48 05/06/2011]
Backup and Restore Center.lnk --ah--- 1304 bytes [04:57 14/07/2009] [04:57 14/07/2009]
Create Recovery Disc.lnk --ah--- 1248 bytes [04:57 14/07/2009] [04:57 14/07/2009]
Desktop.ini --ahs-- 606 bytes [02:36 14/07/2009] [04:57 14/07/2009]
Remote Assistance.lnk --ah--- 1212 bytes [04:57 14/07/2009] [04:57 14/07/2009]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\McAfee d--h--- [20:48 05/06/2011]
McAfee Total Protection.lnk --ah--- 1846 bytes [13:45 05/06/2011] [13:45 05/06/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\McAfee Online Backup d--h--- [20:48 05/06/2011]
desktop.ini --ahs-- 489 bytes [02:43 30/11/2010] [02:43 30/11/2010]
McAfee Online Backup Configuration.lnk --ah--- 1039 bytes [02:43 30/11/2010] [02:43 30/11/2010]
McAfee Online Backup Status.lnk --ah--- 1039 bytes [02:43 30/11/2010] [02:43 30/11/2010]
Online Help.url --ah--- 108 bytes [02:43 30/11/2010] [02:43 30/11/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\McAfee Security Scan Plus d--h--- [20:48 05/06/2011]
McAfee Security Scan Plus.lnk --ah--- 1884 bytes [00:39 17/10/2010] [00:39 17/10/2010]
Uninstall.lnk --ah--- 1186 bytes [00:39 17/10/2010] [00:39 17/10/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Microsoft Office d--h--- [20:48 05/06/2011]
Microsoft Office Access 2003.lnk --ah--- 2643 bytes [21:55 01/01/2010] [03:33 15/07/2010]
Microsoft Office Excel 2003.lnk --ah--- 2677 bytes [21:55 01/01/2010] [21:55 01/01/2010]
Microsoft Office InfoPath 2003.lnk --ah--- 2695 bytes [21:55 01/01/2010] [21:55 01/01/2010]
Microsoft Office Outlook 2003.lnk --ah--- 2693 bytes [21:55 01/01/2010] [21:55 01/01/2010]
Microsoft Office PowerPoint 2003.lnk --ah--- 2645 bytes [21:55 01/01/2010] [21:55 01/01/2010]
Microsoft Office Publisher 2003.lnk --ah--- 2611 bytes [21:55 01/01/2010] [21:55 01/01/2010]
Microsoft Office Word 2003.lnk --ah--- 2675 bytes [21:55 01/01/2010] [21:55 01/01/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools d--h--- [20:48 05/06/2011]
Digital Certificate for VBA Projects.lnk --ah--- 2647 bytes [21:55 01/01/2010] [21:55 01/01/2010]
Microsoft Clip Organizer.lnk --ah--- 2627 bytes [21:55 01/01/2010] [21:55 01/01/2010]
Microsoft Office 2003 Language Settings.lnk --ah--- 2527 bytes [21:55 01/01/2010] [21:55 01/01/2010]
Microsoft Office 2003 Save My Settings Wizard.lnk --ah--- 2547 bytes [21:55 01/01/2010] [21:55 01/01/2010]
Microsoft Office Access Snapshot Viewer.lnk --ah--- 2645 bytes [21:55 01/01/2010] [21:55 01/01/2010]
Microsoft Office Application Recovery.lnk --ah--- 2501 bytes [21:55 01/01/2010] [21:55 01/01/2010]
Microsoft Office Document Imaging.lnk --ah--- 2797 bytes [21:55 01/01/2010] [21:55 01/01/2010]
Microsoft Office Document Scanning.lnk --ah--- 2799 bytes [21:55 01/01/2010] [21:55 01/01/2010]
Microsoft Office Picture Manager.lnk --ah--- 2603 bytes [21:55 01/01/2010] [21:55 01/01/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Microsoft Office Live Add-in d--h--- [20:48 05/06/2011]
Office Live Add-in Help.lnk --ah--- 1194 bytes [02:52 07/07/2010] [02:52 07/07/2010]
Office Live Workspace.lnk --ah--- 1178 bytes [02:52 07/07/2010] [02:52 07/07/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Microsoft Silverlight d--h--- [20:48 05/06/2011]
Microsoft Silverlight.lnk --ah--- 2267 bytes [07:04 13/06/2010] [04:37 21/04/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Mozilla Firefox d--h--- [20:48 05/06/2011]
Mozilla Firefox (Safe Mode).lnk --ah--- 1983 bytes [12:06 02/01/2010] [12:06 02/01/2010]
Mozilla Firefox.lnk --ah--- 1961 bytes [12:06 02/01/2010] [12:06 02/01/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\NVIDIA Corporation d--h--- [20:48 05/06/2011]
NVIDIA nvProfile.lnk --ah--- 1136 bytes [03:51 03/01/2010] [03:52 03/01/2010]
NVIDIA System Monitor.lnk --ah--- 1252 bytes [03:52 03/01/2010] [03:52 03/01/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\NVIDIA Corporation\NVIDIA Control Panel d--h--- [20:48 05/06/2011]
Control Panel.lnk --ah--- 856 bytes [03:51 03/01/2010] [03:54 03/01/2010]
Performance.lnk --ah--- 946 bytes [03:51 03/01/2010] [03:51 03/01/2010]
System Update.lnk --ah--- 946 bytes [03:54 03/01/2010] [03:54 03/01/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\PeerBlock d--h--- [20:48 05/06/2011]
PeerBlock.lnk --ah--- 1754 bytes [20:41 03/01/2010] [01:51 24/11/2010]
Uninstall PeerBlock.lnk --ah--- 1747 bytes [20:41 03/01/2010] [01:51 24/11/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\PeerBlock\Help and Support d--h--- [20:48 05/06/2011]
Forums.url --ah--- 54 bytes [20:41 03/01/2010] [01:51 24/11/2010]
Homepage.url --ah--- 51 bytes [20:41 03/01/2010] [01:51 24/11/2010]
ReadMe.lnk --ah--- 869 bytes [20:41 03/01/2010] [01:51 24/11/2010]
User Manual.url --ah--- 60 bytes [20:41 03/01/2010] [01:51 24/11/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Photo Viewer d--h--- [20:48 05/06/2011]
Photo Viewer.lnk --ah--- 954 bytes [20:02 31/01/2010] [20:02 31/01/2010]
Uninstall .lnk --ah--- 1884 bytes [20:02 31/01/2010] [20:02 31/01/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Quicken 2010 d--h--- [20:48 05/06/2011]
Billminder.lnk --ah--- 1890 bytes [02:20 07/04/2010] [02:20 07/04/2010]
Quicken 2010.lnk --ah--- 1854 bytes [02:20 07/04/2010] [02:20 07/04/2010]
Quicken Online Backup.lnk --ah--- 1981 bytes [02:20 07/04/2010] [02:20 07/04/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\QuickTime d--h--- [20:48 05/06/2011]
About QuickTime.lnk --ah--- 2441 bytes [03:08 12/01/2011] [03:08 12/01/2011]
PictureViewer.lnk --ah--- 2471 bytes [03:08 12/01/2011] [03:08 12/01/2011]
QuickTime Player.lnk --ah--- 2441 bytes [03:08 12/01/2011] [03:08 12/01/2011]
Uninstall QuickTime.lnk --ah--- 1816 bytes [03:08 12/01/2011] [03:08 12/01/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Riot Games d--h--- [20:48 05/06/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Riot Games\League of Legends d--h--- [20:48 05/06/2011]
Play League of Legends.lnk --ah--- 681 bytes [22:44 18/02/2011] [22:44 18/02/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Sierra Wireless d--h--- [20:48 05/06/2011]
TRU-Install.lnk --ah--- 2229 bytes [01:44 10/06/2010] [01:44 10/06/2010]
User Guide.lnk --ah--- 1253 bytes [01:42 10/06/2010] [01:42 10/06/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Startup d--h--- [20:48 05/06/2011]
desktop.ini --ahs-- 404 bytes [04:54 14/07/2009] [02:43 30/11/2010]
McAfee Online Backup Status.lnk --ah--- 1039 bytes [02:43 30/11/2010] [02:43 30/11/2010]
McAfee Security Scan Plus.lnk --ah--- 1864 bytes [00:39 13/10/2010] [00:39 17/10/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Tablet PC d--h--- [20:48 05/06/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\TuneUp Companion d--h--- [20:48 05/06/2011]
TuneUp Companion.lnk --ah--- 1055 bytes [00:31 12/05/2011] [00:31 12/05/2011]
Uninstall TuneUp Companion.lnk --ah--- 1055 bytes [00:31 12/05/2011] [00:31 12/05/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\TurboTax Basic 2007 d--h--- [20:48 05/06/2011]
TurboTax Basic 2007.lnk --ah--- 2160 bytes [22:34 01/01/2010] [22:34 01/01/2010]
TurboTax Update.lnk --ah--- 2199 bytes [22:34 01/01/2010] [22:34 01/01/2010]
Uninstall.lnk --ah--- 2201 bytes [22:34 01/01/2010] [22:34 01/01/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\VideoLAN d--h--- [20:48 05/06/2011]
Documentation.lnk --ah--- 1144 bytes [16:47 02/01/2010] [16:47 02/01/2010]
Release Notes.lnk --ah--- 1095 bytes [16:47 02/01/2010] [16:47 02/01/2010]
VideoLAN Website.lnk --ah--- 1159 bytes [16:47 02/01/2010] [16:47 02/01/2010]
VLC media player.lnk --ah--- 1088 bytes [16:47 02/01/2010] [16:47 02/01/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\VideoLAN\Quick Settings d--h--- [20:48 05/06/2011]
Reset VLC media player preferences and cache files.lnk --ah--- 1190 bytes [16:47 02/01/2010] [16:47 02/01/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\VideoLAN\Quick Settings\Audio d--h--- [20:48 05/06/2011]
Set Audio mode to DirectX (default).lnk --ah--- 1190 bytes [16:47 02/01/2010] [16:47 02/01/2010]
Set Audio mode to Waveout.lnk --ah--- 1180 bytes [16:47 02/01/2010] [16:47 02/01/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\VideoLAN\Quick Settings\Interface d--h--- [20:48 05/06/2011]
Set Main Interface to Qt (default).lnk --ah--- 1162 bytes [16:47 02/01/2010] [16:47 02/01/2010]
Set Main Interface to Skinnable.lnk --ah--- 1168 bytes [16:47 02/01/2010] [16:47 02/01/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\VideoLAN\Quick Settings\Video d--h--- [20:48 05/06/2011]
Set Video mode to Direct3D (no hardware acceleration).lnk --ah--- 1242 bytes [16:47 02/01/2010] [16:47 02/01/2010]
Set Video mode to Direct3D.lnk --ah--- 1236 bytes [16:47 02/01/2010] [16:47 02/01/2010]
Set Video mode to DirectX (no hardware acceleration).lnk --ah--- 1246 bytes [16:47 02/01/2010] [16:47 02/01/2010]
Set Video mode to DirectX (no video overlay).lnk --ah--- 1240 bytes [16:47 02/01/2010] [16:47 02/01/2010]
Set Video mode to DirectX.lnk --ah--- 1234 bytes [16:47 02/01/2010] [16:47 02/01/2010]
Set Video mode to OpenGL.lnk --ah--- 1198 bytes [16:47 02/01/2010] [16:47 02/01/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Visual d--h--- [20:48 05/06/2011]
Visual - Basic Edition Help.lnk --ah--- 615 bytes [18:32 06/08/2010] [18:32 06/08/2010]
Visual - Basic Edition.lnk --ah--- 956 bytes [18:32 06/08/2010] [18:32 06/08/2010]
Visual - Professional Edition Help.lnk --ah--- 605 bytes [18:32 06/08/2010] [18:32 06/08/2010]
Visual - Professional Edition.lnk --ah--- 991 bytes [18:32 06/08/2010] [18:32 06/08/2010]
Visual - Roadway Tool Help.lnk --ah--- 585 bytes [18:32 06/08/2010] [18:32 06/08/2010]
Visual - Roadway Tool.lnk --ah--- 921 bytes [18:32 06/08/2010] [18:32 06/08/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\VSO d--h--- [20:48 05/06/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\VSO\ConvertXtoDVD 4 d--h--- [20:48 05/06/2011]
ConvertXtoDVD 4.lnk --ah--- 1224 bytes [23:31 03/04/2011] [23:31 03/04/2011]
l glp license.lnk --ah--- 1199 bytes [23:31 03/04/2011] [23:31 03/04/2011]
Uninstall ConvertXToDVD.lnk --ah--- 1199 bytes [23:31 03/04/2011] [23:31 03/04/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\VSO\ConvertXtoDVD 4\ Drivers d--h--- [20:48 05/06/2011]
Remove Driver (Compatibility Mode).lnk --ah--- 1291 bytes [23:31 03/04/2011] [23:31 03/04/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Windows Live d--h--- [20:48 05/06/2011]
Windows Live Call.lnk --ah--- 1959 bytes [16:59 02/01/2010] [00:09 18/02/2011]
Windows Live Messenger .lnk --ah--- 2108 bytes [16:59 02/01/2010] [00:09 18/02/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\World of Tanks Closed Beta d--h--- [20:48 05/06/2011]
Uninstall World of Tanks closed Beta.lnk --ah--- 856 bytes [00:08 16/02/2011] [00:08 16/02/2011]
World of Tanks closed Beta on the Web.pif --ah--- 2825 bytes [00:08 16/02/2011] [00:08 16/02/2011]
World of Tanks closed Beta.lnk --ah--- 871 bytes [00:08 16/02/2011] [00:08 16/02/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\World of Warcraft d--h--- [20:48 05/06/2011]
Account Billing.lnk --ah--- 1432 bytes [21:14 07/05/2011] [21:18 07/05/2011]
Blizzard Technical Support.lnk --ah--- 1439 bytes [21:14 07/05/2011] [21:18 07/05/2011]
World of Warcraft - Repair.lnk --ah--- 1222 bytes [21:14 07/05/2011] [21:18 07/05/2011]
World of Warcraft - Uninstall.lnk --ah--- 1567 bytes [21:14 07/05/2011] [21:18 07/05/2011]
World of Warcraft.lnk --ah--- 1086 bytes [21:14 07/05/2011] [22:22 11/05/2011]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Xfire d--h--- [20:48 05/06/2011]
Xfire.lnk --ah--- 985 bytes [22:50 25/10/2010] [22:50 25/10/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\1\Programs\Xvid d--h--- [20:48 05/06/2011]
Configure Decoder.lnk --ah--- 1654 bytes [08:02 05/07/2010] [08:02 05/07/2010]
Configure Encoder.lnk --ah--- 1664 bytes [08:02 05/07/2010] [08:02 05/07/2010]
INet-Doom9's Xvid Forum.lnk --ah--- 1007 bytes [08:02 05/07/2010] [08:02 05/07/2010]
INet-Koepi's Homepage (Updates).lnk --ah--- 1081 bytes [08:02 05/07/2010] [08:02 05/07/2010]
INet-Xvid Homepage.lnk --ah--- 1011 bytes [08:02 05/07/2010] [08:02 05/07/2010]
Koepi's OGMCalc.lnk --ah--- 1040 bytes [08:02 05/07/2010] [08:02 05/07/2010]
Nic's FourCC changer.lnk --ah--- 991 bytes [08:02 05/07/2010] [08:02 05/07/2010]
Nic's MiniCalc.lnk --ah--- 995 bytes [08:02 05/07/2010] [08:02 05/07/2010]
Release Notes.lnk --ah--- 1049 bytes [08:02 05/07/2010] [08:02 05/07/2010]
Some quantization matrices.lnk --ah--- 1072 bytes [08:02 05/07/2010] [08:02 05/07/2010]
StatsReader 2.1.lnk --ah--- 1028 bytes [08:02 05/07/2010] [08:02 05/07/2010]
StatsReader Notes.lnk --ah--- 1026 bytes [08:02 05/07/2010] [08:02 05/07/2010]
Uninstall Xvid.lnk --ah--- 1857 bytes [08:02 05/07/2010] [08:02 05/07/2010]
Vidc.Cleaner.lnk --ah--- 1958 bytes [08:02 05/07/2010] [08:02 05/07/2010]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\3 d--h--- [20:48 05/06/2011]
desktop.ini --ahs-- 151 bytes [20:57 01/01/2010] [04:12 05/03/2010]
Microsoft Office Outlook 2003.lnk --ah--- 2693 bytes [22:47 02/01/2010] [21:55 01/01/2010]
Mozilla Firefox.lnk --ah--- 1943 bytes [22:15 03/01/2010] [12:06 02/01/2010]
Quicken 2010.lnk --ah--- 1854 bytes [01:54 07/04/2010] [22:38 28/02/2010]
Windows Explorer.lnk --ah--- 1228 bytes [20:57 01/01/2010] [04:49 14/07/2009]
Windows Media Player.lnk --ah--- 1547 bytes [20:57 01/01/2010] [05:09 14/07/2009]

C:\Users\PATTER~1\AppData\Local\Temp\smtmp\4 d--h--- [20:48 05/06/2011]
Adobe Reader 9.lnk --ah--- 2014 bytes [10:38 15/10/2010] [14:29 13/03/2011]
at&t Communication Manager.lnk --ah--- 2126 bytes [01:44 10/06/2010] [01:44 10/06/2010]
desktop.ini --ahs-- 174 bytes [04:54 14/07/2009] [04:54 14/07/2009]
Google Chrome.lnk --ah--- 2344 bytes [00:52 24/03/2010] [03:06 28/05/2011]
ImgBurn.lnk --ah--- 1869 bytes [19:55 03/07/2010] [19:55 03/07/2010]
McAfee Security Scan Plus.lnk --ah--- 1866 bytes [00:39 13/10/2010] [00:39 17/10/2010]
Mozilla Firefox.lnk --ah--- 1943 bytes [12:06 02/01/2010] [12:06 02/01/2010]
NVIDIA System Monitor.lnk --ah--- 2254 bytes [03:53 03/01/2010] [03:53 03/01/2010]
Performance.lnk --ah--- 1975 bytes [03:52 03/01/2010] [03:52 03/01/2010]
Photo Viewer.lnk --ah--- 936 bytes [20:02 31/01/2010] [20:02 31/01/2010]
Quicken Deluxe 2010.lnk --ah--- 1818 bytes [02:20 07/04/2010] [02:20 07/04/2010]
Register for Black Prophecy Beta.url --ah--- 148 bytes [10:07 01/04/2011] [10:07 01/04/2011]
System Update.lnk --ah--- 1877 bytes [03:55 03/01/2010] [03:55 03/01/2010]
TuneUp Companion.lnk --ah--- 1037 bytes [00:31 12/05/2011] [00:31 12/05/2011]
VLC media player.lnk --ah--- 1070 bytes [16:47 02/01/2010] [16:47 02/01/2010]
Vuze.lnk --ah--- 1852 bytes [20:28 03/01/2010] [23:05 11/05/2011]
World of Tanks closed Beta.lnk --ah--- 853 bytes [00:08 16/02/2011] [00:08 16/02/2011]
World of Warcraft.lnk --ah--- 1068 bytes [21:14 07/05/2011] [21:24 07/05/2011]
Xfire.lnk --ah--- 967 bytes [22:50 25/10/2010] [22:50 25/10/2010]

-= EOF =-

BC AdBot (Login to Remove)

 


#2 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,756 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:06:15 AM

Posted 06 June 2011 - 06:50 PM

Before we go there...

Download Malwarebytes' Anti-Malware (aka MBAM): https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/ to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Be sure to restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#3 bpatters69

bpatters69
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:15 AM

Posted 06 June 2011 - 07:56 PM

Thanks....

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6791

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

6/6/2011 8:55:43 PM
mbam-log-2011-06-06 (20-55-37).txt

Scan type: Quick scan
Objects scanned: 173013
Time elapsed: 6 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\patterson_desktop\AppData\Local\Temp\Low\tmpF1D4.tmp (Trojan.FakeMS) -> No action taken.

#4 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,756 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:06:15 AM

Posted 06 June 2011 - 07:59 PM

Your log shows "No action taken" after each line.
Please, re-run MBAM and FIX all issues.

I asked for this topic to be moved to "Am I Infected?" forum.

My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#5 bpatters69

bpatters69
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:15 AM

Posted 06 June 2011 - 08:37 PM

Not sure what happened. Here is an updated log file:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6791

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

6/6/2011 9:32:53 PM
mbam-log-2011-06-06 (21-32-53).txt

Scan type: Quick scan
Objects scanned: 172974
Time elapsed: 3 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

#6 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,756 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:06:15 AM

Posted 06 June 2011 - 08:41 PM

Very well.
I'd like to see couple more scans.
We're doing this to make sure, your computer is fairly clean.

Download Security Check from HERE, and save it to your Desktop.

* Double-click SecurityCheck.exe
* Follow the onscreen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt; please post the contents of that document.

=============================================================================

Download MBRCheck to your desktop

Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
It will show a black screen with some data on it.
Enter N to exit.
A report called MBRcheckxxxx.txt will be on your desktop
Open this report and post its content in your next reply.

=========================================================================

Please download Rootkit Unhooker from one of the following links and save it to your desktop.
Link 1 (.exe file)
Link 2 (zipped file)
Link 3 (.rar file)In order to use this tool if you downloaded from either of the second two links, you will need to extract the RKUnhookerLE.exe file using a program capable of extracing ZIP and RAR compressed files. If you don't have an extraction program, you can downlaod, install and use the free 7-zip utility.

  • Double-click on RKUnhookerLE.exe to start the program.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • Click the Report tab, then click Scan.
  • Check Drivers, Stealth, and uncheck the rest.
  • Click OK.
  • Wait until it's finished and then go to File > Save Report.
  • Save the report to your Desktop.
  • Copy and paste the contents of the report into your next reply.
-- Note: You may get this warning...just ignore it, click OK and continue: "Rootkit Unhooker has detected a parasite inside itself! It is recommended to remove parasite, okay?".

My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#7 bpatters69

bpatters69
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:15 AM

Posted 06 June 2011 - 08:52 PM

Thanks... yawn... getting past my bedtime. I will download the files you suggest, run them on my machine and post them here tomorrow.

Thanks again...

#8 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,756 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:06:15 AM

Posted 06 June 2011 - 09:03 PM

No problem :)

My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#9 bpatters69

bpatters69
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:15 AM

Posted 07 June 2011 - 06:13 AM

Security Check Results

Results of screen317's Security Check version 0.99.7
Windows 7 (UAC is enabled)
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
McAfee Total Protection
McAfee Security Scan Plus
McAfee Online Backup
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
TuneUp Companion 2.0.9
Java™ 6 Update 20
Out of date Java installed!
Adobe Flash Player 10.3.181.14
Adobe Reader 9.4.2
Out of date Adobe Reader installed!
Mozilla Firefox (3.6.17)
````````````````````````````````
Process Check:
objlist.exe by Laurent

McAfee Online Backup MOBKbackup.exe
``````````End of Log````````````

MBRCheck Results
MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: ASUSTeK Computer INC.
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: ASUSTEK COMPUTER INC
System Product Name: P5W DH Deluxe
Logical Drives Mask: 0x0000003d

Kernel Drivers (total 208):
0x0324C000 \SystemRoot\system32\ntoskrnl.exe
0x03203000 \SystemRoot\system32\hal.dll
0x00BC8000 \SystemRoot\system32\kdcom.dll
0x00CA9000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00CED000 \SystemRoot\system32\PSHED.dll
0x00D01000 \SystemRoot\system32\CLFS.SYS
0x00EB2000 \SystemRoot\system32\CI.dll
0x00E00000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00F72000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00F81000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x00FD8000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x00FE1000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x00D5F000 \SystemRoot\system32\DRIVERS\pci.sys
0x00FEB000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x00D92000 \SystemRoot\System32\drivers\partmgr.sys
0x00DA7000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x00C00000 \SystemRoot\System32\drivers\volmgrx.sys
0x00FF8000 \SystemRoot\system32\DRIVERS\intelide.sys
0x00C5C000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x00EA4000 \SystemRoot\system32\DRIVERS\pciide.sys
0x00C6C000 \SystemRoot\system32\DRIVERS\jraid.sys
0x00DBC000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS
0x00C8C000 \SystemRoot\System32\drivers\mountmgr.sys
0x00DEB000 \SystemRoot\system32\DRIVERS\atapi.sys
0x010DD000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x01107000 \SystemRoot\system32\drivers\amdxata.sys
0x01112000 \SystemRoot\system32\drivers\fltmgr.sys
0x0115E000 \SystemRoot\system32\drivers\fileinfo.sys
0x01000000 \SystemRoot\system32\drivers\mfehidk.sys
0x0109A000 \SystemRoot\System32\Drivers\PxHlpa64.sys
0x0124F000 \SystemRoot\System32\Drivers\Ntfs.sys
0x01172000 \SystemRoot\System32\Drivers\msrpc.sys
0x01200000 \SystemRoot\System32\Drivers\ksecdd.sys
0x01491000 \SystemRoot\System32\Drivers\cng.sys
0x01504000 \SystemRoot\System32\drivers\pcw.sys
0x01515000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x016E8000 \SystemRoot\system32\drivers\ndis.sys
0x01600000 \SystemRoot\system32\drivers\NETIO.SYS
0x01660000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x0168B000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x016D7000 \SystemRoot\System32\Drivers\spldr.sys
0x0151F000 \SystemRoot\System32\drivers\rdyboost.sys
0x017DA000 \SystemRoot\System32\Drivers\mup.sys
0x017EC000 \SystemRoot\System32\drivers\hwpolicy.sys
0x01559000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x01593000 \SystemRoot\system32\DRIVERS\disk.sys
0x015A9000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x01413000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x0143D000 \SystemRoot\system32\DRIVERS\MOBK.sys
0x016DF000 \SystemRoot\System32\Drivers\Null.SYS
0x01453000 \SystemRoot\System32\Drivers\Beep.SYS
0x0145A000 \SystemRoot\System32\drivers\vga.sys
0x01468000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x0121A000 \SystemRoot\System32\drivers\watchdog.sys
0x015F3000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x0122A000 \SystemRoot\system32\drivers\rdpencdd.sys
0x01233000 \SystemRoot\system32\drivers\rdprefmp.sys
0x0123C000 \SystemRoot\System32\Drivers\Msfs.SYS
0x011D0000 \SystemRoot\System32\Drivers\Npfs.SYS
0x03800000 \SystemRoot\System32\drivers\tcpip.sys
0x03AAB000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x03AF5000 \SystemRoot\system32\drivers\mfewfpk.sys
0x03B38000 \SystemRoot\system32\DRIVERS\tdx.sys
0x03B56000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x03B63000 \SystemRoot\System32\DRIVERS\netbt.sys
0x03A00000 \SystemRoot\system32\drivers\afd.sys
0x03A8A000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x03BA8000 \SystemRoot\system32\DRIVERS\pacer.sys
0x03BCE000 \SystemRoot\system32\DRIVERS\mfenlfk.sys
0x03BDF000 \SystemRoot\system32\DRIVERS\netbios.sys
0x011E1000 \SystemRoot\system32\DRIVERS\serial.sys
0x010A6000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x03A93000 \SystemRoot\system32\DRIVERS\termdd.sys
0x03CA6000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x03CF7000 \SystemRoot\system32\drivers\nsiproxy.sys
0x03D03000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x03D0E000 \SystemRoot\System32\drivers\discache.sys
0x03D1D000 \SystemRoot\System32\Drivers\dfsc.sys
0x03D3B000 \SystemRoot\system32\DRIVERS\ctxusbm.sys
0x03D56000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x03D67000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x03D8D000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x04605000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x051DF000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
0x03E65000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x03F59000 \SystemRoot\System32\drivers\dxgmms1.sys
0x03F9F000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x03E00000 \SystemRoot\system32\DRIVERS\yk62x64.sys
0x03FC3000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x03DA3000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x03FD0000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x03C00000 \SystemRoot\system32\drivers\bender64.sys
0x03FE1000 \SystemRoot\system32\drivers\STREAM.SYS
0x03C3E000 \SystemRoot\system32\drivers\ks.sys
0x03FF2000 \SystemRoot\system32\drivers\ksthunk.sys
0x04066000 \SystemRoot\system32\DRIVERS\1394ohci.sys
0x040A4000 \SystemRoot\system32\DRIVERS\fdc.sys
0x040B1000 \SystemRoot\system32\DRIVERS\ASACPI.sys
0x040B9000 \SystemRoot\system32\DRIVERS\serenum.sys
0x040C5000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x040D2000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x040E2000 \SystemRoot\System32\Drivers\RootMdm.sys
0x040EA000 \SystemRoot\system32\drivers\modem.sys
0x040F9000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x0410F000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x04133000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x0413F000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x0416E000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x04189000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x041AA000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x041C4000 \SystemRoot\system32\DRIVERS\RimSerial_AMD64.sys
0x041CC000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x041DB000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x041EA000 \SystemRoot\system32\DRIVERS\swenum.sys
0x041EC000 \SystemRoot\system32\DRIVERS\nvoclk64.sys
0x04000000 \SystemRoot\system32\DRIVERS\umbus.sys
0x0428A000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x042E4000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0x042EF000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x04304000 \SystemRoot\system32\drivers\HdAudio.sys
0x04360000 \SystemRoot\system32\drivers\portcls.sys
0x0439D000 \SystemRoot\system32\drivers\drmk.sys
0x043BF000 \SystemRoot\system32\drivers\mfeavfk.sys
0x04200000 \SystemRoot\system32\drivers\mfefirek.sys
0x000C0000 \SystemRoot\System32\win32k.sys
0x04274000 \SystemRoot\System32\drivers\Dxapi.sys
0x04012000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x04280000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x0402F000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x0403D000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x043F5000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x04056000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x051E1000 \SystemRoot\system32\DRIVERS\monitor.sys
0x00490000 \SystemRoot\System32\TSDDD.dll
0x0201E000 \SystemRoot\system32\DRIVERS\udfs.sys
0x00630000 \SystemRoot\System32\cdd.dll
0x00990000 \SystemRoot\System32\ATMFD.DLL
0x02072000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x0208D000 \SystemRoot\system32\drivers\luafv.sys
0x020B0000 \SystemRoot\system32\DRIVERS\RTL8187.sys
0x0211C000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x02129000 \SystemRoot\system32\drivers\WudfPf.sys
0x0214A000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x0215F000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x021B2000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x021C5000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x03687000 \SystemRoot\system32\drivers\HTTP.sys
0x0374F000 \SystemRoot\System32\Drivers\crashdmp.sys
0x0375D000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x03769000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x03772000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x03785000 \SystemRoot\system32\DRIVERS\bowser.sys
0x037A3000 \SystemRoot\System32\drivers\mpsdrv.sys
0x037BB000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x03600000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x0364E000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x05879000 \SystemRoot\system32\drivers\peauth.sys
0x0591F000 \SystemRoot\System32\Drivers\secdrv.SYS
0x0592A000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x05957000 \SystemRoot\System32\drivers\tcpipreg.sys
0x05969000 \SystemRoot\System32\DRIVERS\srv2.sys
0x05CF1000 \SystemRoot\System32\DRIVERS\srv.sys
0x05D86000 \SystemRoot\System32\Drivers\fastfat.SYS
0x05DBC000 \SystemRoot\system32\drivers\cfwids.sys
0x05DCB000 \SystemRoot\system32\drivers\mfeapfk.sys
0x05C00000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0x05C31000 \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys
0x05CA8000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0x77480000 \Windows\System32\ntdll.dll
0x482B0000 \Windows\System32\smss.exe
0xFF7A0000 \Windows\System32\apisetschema.dll
0xFF5A0000 \Windows\System32\autochk.exe
0xFF710000 \Windows\System32\difxapi.dll
0xFF670000 \Windows\System32\msvcrt.dll
0xFF590000 \Windows\System32\oleaut32.dll
0xFF330000 \Windows\System32\iertutil.dll
0xFF2B0000 \Windows\System32\shlwapi.dll
0xFF180000 \Windows\System32\wininet.dll
0xFF000000 \Windows\System32\urlmon.dll
0x77380000 \Windows\System32\user32.dll
0xFEFF0000 \Windows\System32\lpk.dll
0xFEDE0000 \Windows\System32\ole32.dll
0xFED40000 \Windows\System32\comdlg32.dll
0xFECD0000 \Windows\System32\gdi32.dll
0xFEBA0000 \Windows\System32\rpcrt4.dll
0xFEB70000 \Windows\System32\imm32.dll
0xFEB20000 \Windows\System32\Wldap32.dll
0xFEA80000 \Windows\System32\clbcatq.dll
0xFEA70000 \Windows\System32\nsi.dll
0xFE990000 \Windows\System32\advapi32.dll
0x77260000 \Windows\System32\kernel32.dll
0xFE970000 \Windows\System32\imagehlp.dll
0xFE920000 \Windows\System32\ws2_32.dll
0xFE740000 \Windows\System32\setupapi.dll
0xFE720000 \Windows\System32\sechost.dll
0xFE650000 \Windows\System32\usp10.dll
0xFE540000 \Windows\System32\msctf.dll
0x77650000 \Windows\System32\normaliz.dll
0x77640000 \Windows\System32\psapi.dll
0xFD7B0000 \Windows\System32\shell32.dll
0xFD770000 \Windows\System32\wintrust.dll
0xFD600000 \Windows\System32\crypt32.dll
0xFD590000 \Windows\System32\KernelBase.dll
0xFD4F0000 \Windows\System32\comctl32.dll
0xFD4D0000 \Windows\System32\devobj.dll
0xFD490000 \Windows\System32\cfgmgr32.dll
0xFD480000 \Windows\System32\msasn1.dll
0x76D80000 \Windows\SysWOW64\normaliz.dll

Processes (total 80):
0 System Idle Process
4 System
252 C:\Windows\System32\smss.exe
376 csrss.exe
436 C:\Windows\System32\wininit.exe
448 csrss.exe
492 C:\Windows\System32\services.exe
508 C:\Windows\System32\lsass.exe
516 C:\Windows\System32\lsm.exe
632 C:\Windows\System32\winlogon.exe
664 C:\Windows\System32\svchost.exe
728 C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
752 C:\Windows\System32\nvvsvc.exe
792 C:\Windows\System32\svchost.exe
844 C:\Windows\System32\svchost.exe
924 C:\Windows\System32\svchost.exe
968 C:\Windows\System32\svchost.exe
184 C:\Windows\System32\audiodg.exe
384 C:\Windows\System32\svchost.exe
808 C:\Windows\System32\svchost.exe
1068 C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
1084 C:\Windows\System32\nvvsvc.exe
1248 C:\Windows\System32\spoolsv.exe
1340 C:\Windows\System32\svchost.exe
1456 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1480 C:\Windows\System32\taskhost.exe
1580 C:\Windows\System32\dwm.exe
1592 C:\Windows\explorer.exe
1724 C:\Program Files (x86)\AskBarDis\bar\bin\AskService.exe
1796 C:\Windows\System32\taskeng.exe
1876 C:\Program Files (x86)\AskBarDis\bar\bin\ASKUpgrade.exe
1904 C:\Program Files (x86)\Bonjour\mDNSResponder.exe
1972 C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
2008 C:\Windows\System32\mfevtps.exe
1396 C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
748 C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
1864 C:\Windows\System32\rundll32.exe
1872 C:\Windows\SysWOW64\rundll32.exe
2116 C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe
2176 C:\Windows\System32\svchost.exe
2236 C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe
2252 C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe
2284 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
2312 C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
2352 C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
2784 C:\Windows\System32\SearchIndexer.exe
2876 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
1016 C:\Windows\SysWOW64\svchost.exe
3080 C:\Windows\System32\svchost.exe
3224 C:\Windows\System32\svchost.exe
3304 C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
3448 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
3460 C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
3572 C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
3588 WUDFHost.exe
3600 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
3684 C:\Program Files\McAfee.com\Agent\mcagent.exe
3744 C:\Program Files (x86)\iTunes\iTunesHelper.exe
3756 C:\Program Files (x86)\Freecorder\FLVSrvc.exe
4024 C:\Program Files\iPod\bin\iPodService.exe
4056 C:\Program Files\Windows Media Player\wmpnetwk.exe
4476 C:\Windows\System32\svchost.exe
4568 WmiPrvSE.exe
4492 dllhost.exe
1760 C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe
1428 C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe
2964 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
3816 C:\Windows\System32\wuauclt.exe
2984 C:\Program Files (x86)\Internet Explorer\ielowutil.exe
3056 C:\Windows\servicing\TrustedInstaller.exe
1628 C:\Windows\explorer.exe
1196 C:\Spyware Kit\SecurityCheck.exe
4288 C:\Windows\SysWOW64\cmd.exe
3048 C:\Windows\System32\conhost.exe
2076 C:\Windows\System32\svchost.exe
4336 C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
2092 C:\Windows\SysWOW64\notepad.exe
4592 C:\Spyware Kit\MBRCheck.exe
4796 C:\Windows\System32\conhost.exe
1684 C:\Windows\System32\dllhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\E: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)

PhysicalDrive0 Model Number: ST3500320AS, Rev: SD15
PhysicalDrive1 Model Number: WDCWD3200YS-01PGB0, Rev: 21.00M21

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
298 GB \\.\PhysicalDrive1 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


Done!

RKUnhooker Results

I got an error:

Exception code : 0xC0000005
Instruction address : 0x00402EAA
Attempt to read at address : 0xFFFFFFFF

#10 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,756 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:06:15 AM

Posted 07 June 2011 - 06:43 PM

I aplogize, RKUnhooker won't run on64-bit.

Give me this instead....

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    Posted Image
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.

IMPORTANT! If for some reason GMER refuses to run, try again.
If it still fails, try to UN-check "Devices" in right pane.
If still no joy, try to run it from Safe Mode.

My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#11 bpatters69

bpatters69
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:15 AM

Posted 07 June 2011 - 09:25 PM

Maybe I did something wrong... GMER said that it could not find any system modification.... or does that mean that I am clean?

#12 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,756 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:06:15 AM

Posted 07 June 2011 - 09:28 PM

That's good :)

Let's see, if we can get your shortcuts back.

Download and run UnHide

My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#13 bpatters69

bpatters69
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:15 AM

Posted 08 June 2011 - 06:26 AM

Thanks Broni! My icons are back. I am going to drop some "thank you" in your paypal account.

#14 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,756 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:06:15 AM

Posted 08 June 2011 - 04:54 PM

Wonderful and thank you :)

Good luck!

My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users