Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HiJack This Log


  • This topic is locked This topic is locked
19 replies to this topic

#1 berlok

berlok

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:04 AM

Posted 15 August 2011 - 02:30 AM

My computer have not been running AV for a long time, recently just download AVG and Malwarebyte to do some cleanup. But decided to do a hijack this log to clean it further! Thank you!

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:53:47 PM, on 8/15/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe
D:\Program Files (x86)\Ray Adams\ATI Tray Tools\atitray.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
D:\Program Files\BitDefender\BitDefender 2011\antispam32\bdimguiaux.exe
D:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
D:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe
D:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
D:\Program Files (x86)\Garena Messenger\GarenaMessenger.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
D:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
D:\Program Files (x86)\Garena Messenger\Apps\HoN\hon.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
D:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: vShare Toolbar - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files (x86)\vShare\vshare_toolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files (x86)\AVG\AVG10\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - D:\PROGRA~1\FlashGet\getflash.dll
O2 - BHO: (no name) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - (no file)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: vShare Toolbar - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files (x86)\vShare\vshare_toolbar.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - D:\Program Files\BitDefender\BitDefender 2011\Antispam32\IEToolbar.dll
O4 - HKLM\..\Run: [WindowsLivePhone] C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe /AutoRun
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [BuffaloTools] C:\Program Files (x86)\BUFFALO\BuffaloTools\BuffaloTools.exe
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [PlusService] D:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "D:\Program Files\BitDefender\BitDefender 2011\Antispam32\ieshow.exe"
O4 - HKLM\..\Run: [AVG_TRAY] D:\Program Files (x86)\AVG\AVG10\avgtray.exe
O4 - HKCU\..\Run: [uTorrent] "D:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WindowsLivePhone] "C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe" /AutoRun
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Nick\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
O4 - HKCU\..\Run: [AtiTrayTools] "D:\Program Files (x86)\Ray Adams\ATI Tray Tools\atitray.exe"
O4 - HKCU\..\Run: [Steam] "D:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Advanced SystemCare 4] D:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Logitech . Product Registration.lnk = C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
O4 - Startup: Logitech Touch Mouse Server.lnk = D:\Program Files (x86)\Logitech Touch Mouse Server\iTouch-Server-Win.exe
O4 - Global Startup: PacketiX VPN Client Task Tray.lnk = D:\Program Files\PacketiX VPN Client 64-bit Edition English\vpncmgr_x64.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Download All by FlashGet - D:\Program Files (x86)\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - D:\Program Files (x86)\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} (IBM Lotus iNotes 8.5 Control) - https://www.sianet.com.sg/,DanaInfo=SINCCBLMSXP02.sq.com.sg,ST=1+/dwa85W.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B55D944D-AFB7-4133-9577-CA46E4E38812}: NameServer = 165.21.83.88,165.21.100.88
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files (x86)\AVG\AVG10\avgpp.dll
O18 - Protocol: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files (x86)\vShare\vshare_toolbar.dll
O20 - AppInit_DLLs: TeknoGods.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - D:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - D:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - D:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
O23 - Service: Backup Utility Service (BFBackupUtilityService) - BUFFALO INC. - C:\Program Files (x86)\BUFFALO\Backup_Utility\BUService.exe
O23 - Service: Backup Utility VSS Service (BFBackupUtilityVSSService) - BUFFALO INC. - C:\Program Files (x86)\BUFFALO\Backup_Utility\BUVSSService64.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Software Protection (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TunngleService - Tunngle.net GmbH - D:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: BitDefender Update Server v2 (Update Server) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
O23 - Service: BitDefender Desktop Update Service (Updatesrv) - BitDefender S.R.L. - D:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: PacketiX VPN Client (vpnclient) - SoftEther Corporation - D:\Program Files\PacketiX VPN Client 64-bit Edition English\vpnclient_x64.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - D:\Program Files\BitDefender\BitDefender 2011\vsserv.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 13967 bytes

BC AdBot (Login to Remove)

 


#2 berlok

berlok
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:04 AM

Posted 15 August 2011 - 02:39 AM

DDS Report

.
DDS (Ver_2011-06-23.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by Nick at 15:36:12 on 2011-08-15
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.4094.814 [GMT 8:00]
.
AV: BitDefender Antivirus *Enabled/Updated* {50909708-FF80-02AF-F814-B28405891E92}
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: BitDefender Antispyware *Enabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F}
FW: BitDefender Firewall *Disabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
D:\Program Files\BitDefender\BitDefender 2011\vsserv.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\svchost.exe -k NetworkService
D:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe
C:\Windows\system32\taskhost.exe
D:\Program Files\BitDefender\BitDefender 2011\bdagent.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\BUFFALO\Backup_Utility\BUService.exe
C:\Program Files (x86)\BUFFALO\Backup_Utility\BUVSSService64.exe
D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe
C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
D:\Program Files (x86)\Tunngle\TnglCtrl.exe
D:\Program Files (x86)\Ray Adams\ATI Tray Tools\atitray.exe
D:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe
D:\Program Files\PacketiX VPN Client 64-bit Edition English\vpnclient_x64.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
D:\Program Files\BitDefender\BitDefender 2011\antispam32\bdimguiaux.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
D:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
D:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iPod\bin\iPodService.exe
D:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\AUDIODG.EXE
D:\Program Files (x86)\Garena Messenger\GarenaMessenger.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
D:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
D:\Program Files (x86)\AVG\AVG10\avgtray.exe
D:\Program Files (x86)\AVG\AVG10\avgnsa.exe
D:\Program Files (x86)\AVG\AVG10\avgchsva.exe
D:\Program Files (x86)\AVG\AVG10\avgrsa.exe
D:\Program Files (x86)\AVG\AVG10\avgcsrva.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\ping.exe
C:\Windows\system32\conhost.exe
D:\Program Files (x86)\Garena Messenger\Apps\HoN\hon.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
D:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mStart Page = about:blank
uInternet Settings,ProxyServer = http=
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = about:blank
BHO: vShare Toolbar: {043c5167-00bb-4324-af7e-62013faedacf} - C:\Program Files (x86)\vShare\vshare_toolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: IeCatch5 Class: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - D:\PROGRA~1\FlashGet\jccatch.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - D:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - D:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: gFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - D:\PROGRA~1\FlashGet\getflash.dll
BHO: {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No File
TB: FlashGet Bar: {e0e899ab-f487-11d5-8d29-0050ba6940e3} - D:\PROGRA~1\FlashGet\fgiebar.dll
TB: vShare Toolbar: {043c5167-00bb-4324-af7e-62013faedacf} - C:\Program Files (x86)\vShare\vshare_toolbar.dll
TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - D:\Program Files\BitDefender\BitDefender 2011\Antispam32\IEToolbar.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [uTorrent] "D:\Program Files (x86)\uTorrent\uTorrent.exe"
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [WindowsLivePhone] "C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe" /AutoRun
uRun: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
uRun: [Google Update] "C:\Users\Nick\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [VeohPlugin] "C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
uRun: [AtiTrayTools] "D:\Program Files (x86)\Ray Adams\ATI Tray Tools\atitray.exe"
uRun: [Steam] "D:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [Advanced SystemCare 4] D:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe
mRun: [WindowsLivePhone] C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe /AutoRun
mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [GrooveMonitor] "D:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "D:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [BuffaloTools] C:\Program Files (x86)\BUFFALO\BuffaloTools\BuffaloTools.exe
mRun: [LogMeIn Hamachi Ui] "D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
mRun: [PlusService] D:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [BitDefender Antiphishing Helper] "D:\Program Files\BitDefender\BitDefender 2011\Antispam32\ieshow.exe"
mRun: [AVG_TRAY] D:\Program Files (x86)\AVG\AVG10\avgtray.exe
StartupFolder: C:\Users\Nick\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Logitech . Product Registration.lnk - C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
StartupFolder: C:\Users\Nick\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\LOGITE~1.LNK - D:\Program Files (x86)\Logitech Touch Mouse Server\iTouch-Server-Win.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\PACKET~1.LNK - D:\Program Files\PacketiX VPN Client 64-bit Edition English\vpncmgr_x64.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: Download All by FlashGet - D:\Program Files (x86)\FlashGet\jc_all.htm
IE: Download using FlashGet - D:\Program Files (x86)\FlashGet\jc_link.htm
IE: E&xport to Microsoft Excel - D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} - hxxps://www.sianet.com.sg/,DanaInfo=SINCCBLMSXP02.sq.com.sg,ST=1+/dwa85W.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{37D9D6F0-6782-49F2-A25D-B036D7621702} : DhcpNameServer = 178.32.51.4 76.73.18.50
TCP: Interfaces\{723E37E4-F216-4647-884E-0DCABFAF241E} : DhcpNameServer = 178.32.51.4 76.73.18.50
TCP: Interfaces\{B55D944D-AFB7-4133-9577-CA46E4E38812} : NameServer = 165.21.83.88,165.21.100.88
TCP: Interfaces\{B55D944D-AFB7-4133-9577-CA46E4E38812} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{C3D8FFB6-3CC3-442B-83D9-941C5BEE5ACA} : DhcpNameServer = 178.32.51.4 76.73.18.50
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files (x86)\AVG\AVG10\avgpp.dll
Handler: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files (x86)\vShare\vshare_toolbar.dll
AppInit_DLLs: TeknoGods.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - D:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: vShare Toolbar: {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files (x86)\vShare\vshare_toolbar.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: IeCatch5 Class: {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\PROGRA~1\FlashGet\jccatch.dll
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: gFlash Class: {F156768E-81EF-470C-9057-481BA8380DBA} - D:\PROGRA~1\FlashGet\getflash.dll
BHO-X64: {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No File
TB-X64: FlashGet Bar: {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\fgiebar.dll
TB-X64: vShare Toolbar: {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files (x86)\vShare\vshare_toolbar.dll
TB-X64: BitDefender Toolbar: {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - D:\Program Files\BitDefender\BitDefender 2011\Antispam32\IEToolbar.dll
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
mRun-x64: [WindowsLivePhone] C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe /AutoRun
mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun-x64: [GrooveMonitor] "D:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "D:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [BuffaloTools] C:\Program Files (x86)\BUFFALO\BuffaloTools\BuffaloTools.exe
mRun-x64: [LogMeIn Hamachi Ui] "D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
mRun-x64: [PlusService] D:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [BitDefender Antiphishing Helper] "D:\Program Files\BitDefender\BitDefender 2011\Antispam32\ieshow.exe"
mRun-x64: [AVG_TRAY] D:\Program Files (x86)\AVG\AVG10\avgtray.exe
IE-X64: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe
AppInit_DLLs-X64: TeknoGods.dll
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\0jvkwx1e.default\
FF - prefs.js: browser.search.selectedEngine - Facemoods Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sg/
FF - prefs.js: network.proxy.http - 89.74.147.143
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: C:\Users\Nick\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - plugin: D:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: D:\Program Files (x86)\Veetle\Player\npvlc.dll
FF - plugin: D:\Program Files (x86)\Veetle\plugins\npVeetle.dll
FF - plugin: D:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
R0 BFRD4G;BUFFALO RAM Disk Driver;C:\Windows\system32\DRIVERS\BFRD4G.sys --> C:\Windows\system32\DRIVERS\BFRD4G.sys [?]
R0 bftpdskc64;BUFFALO TurboPC Cache Filter;C:\Windows\system32\drivers\bftpdskc64.sys --> C:\Windows\system32\drivers\bftpdskc64.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
R1 bdfwfpf;bdfwfpf;C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys [2010-7-15 99920]
R2 AdvancedSystemCareService;Advanced SystemCare Service;D:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe [2011-8-8 353168]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 avgwd;AVG WatchDog;D:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2011-2-8 269520]
R2 BFBackupUtilityService;Backup Utility Service;C:\Program Files (x86)\BUFFALO\Backup_Utility\BUService.exe -Service_Execute --> C:\Program Files (x86)\BUFFALO\Backup_Utility\BUService.exe -Service_Execute [?]
R2 BFBackupUtilityVSSService;Backup Utility VSS Service;C:\Program Files (x86)\BUFFALO\Backup_Utility\BUVSSService64.exe -Service_Execute --> C:\Program Files (x86)\BUFFALO\Backup_Utility\BUVSSService64.exe -Service_Execute [?]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-8-4 2329480]
R2 StarWindServiceAE;StarWind AE Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe [2007-5-29 275968]
R2 TunngleService;TunngleService;D:\Program Files (x86)\Tunngle\TnglCtrl.exe [2010-5-28 716024]
R2 Updatesrv;BitDefender Desktop Update Service;D:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe [2010-7-21 51176]
R2 vpnclient;PacketiX VPN Client;D:\Program Files\PacketiX VPN Client 64-bit Edition English\vpnclient_x64.exe [2008-5-15 4601344]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 BDFM;BDFM;C:\Windows\system32\DRIVERS\bdfm.sys --> C:\Windows\system32\DRIVERS\bdfm.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
S3 AVGIDSAgent;AVGIDSAgent;D:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-4-18 7398752]
S3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
S3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
S3 bftpusbx64;BUFFALO TurboPC USB Filter;C:\Windows\system32\drivers\bftpusbx64.sys --> C:\Windows\system32\drivers\bftpusbx64.sys [?]
S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2010-5-4 14216]
S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2010-5-4 8456]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;C:\Windows\system32\DRIVERS\MijXfilt.sys --> C:\Windows\system32\DRIVERS\MijXfilt.sys [?]
S3 Neo_PacketiX;VPN Client Device Driver - PacketiX;C:\Windows\system32\DRIVERS\Neo_0116.sys --> C:\Windows\system32\DRIVERS\Neo_0116.sys [?]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\system32\DRIVERS\netaapl64.sys --> C:\Windows\system32\DRIVERS\netaapl64.sys [?]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);C:\Windows\system32\DRIVERS\tap0901t.sys --> C:\Windows\system32\DRIVERS\tap0901t.sys [?]
S3 tapoas;TAP-Win32 Adapter OAS;C:\Windows\system32\DRIVERS\tapoas.sys --> C:\Windows\system32\DRIVERS\tapoas.sys [?]
S3 Update Server;BitDefender Update Server v2;C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [2010-7-16 467248]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 avc3;avc3;C:\Windows\system32\DRIVERS\avc3.sys --> C:\Windows\system32\DRIVERS\avc3.sys [?]
S4 avckf;avckf;C:\Windows\system32\DRIVERS\avckf.sys --> C:\Windows\system32\DRIVERS\avckf.sys [?]
.
=============== Created Last 30 ================
.
2011-08-15 02:21:29 -------- d-----w- C:\Users\Nick\AppData\Local\{769082D1-8D38-4E83-A5E5-BF0A53FD256C}
2011-08-14 14:20:54 -------- d-----w- C:\Users\Nick\AppData\Local\{FDBCF026-0890-4B25-BD6D-7E2061F6FA7F}
2011-08-14 02:20:18 -------- d-----w- C:\Users\Nick\AppData\Local\{6EBFE81B-CF8D-44CC-BEF1-5C074ADEC9F5}
2011-08-13 14:19:43 -------- d-----w- C:\Users\Nick\AppData\Local\{EE85EA67-A62A-4F55-9335-EBCDF12C5B9C}
2011-08-13 02:19:08 -------- d-----w- C:\Users\Nick\AppData\Local\{A5B749B6-DAD9-4713-A7B0-5986802C866F}
2011-08-13 02:18:45 -------- d-----w- C:\Users\Nick\AppData\Local\{498FD2A4-AC87-4B6F-ABAD-68F8BF94A98C}
2011-08-12 14:18:20 -------- d-----w- C:\Users\Nick\AppData\Local\{9B518BE2-94BE-4908-9AA5-AE6A7BB5D7CE}
2011-08-12 14:17:58 -------- d-----w- C:\Users\Nick\AppData\Local\{6A0B5188-A23E-4BB2-A89A-F47B7510D239}
2011-08-12 03:52:40 -------- d-----w- C:\Program Files (x86)\AMD APP
2011-08-12 03:52:28 -------- d-----w- C:\Program Files (x86)\Common Files\ATI Technologies
2011-08-12 03:52:26 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2011-08-12 03:51:59 -------- d-----w- C:\Program Files\Common Files\ATI Technologies
2011-08-12 03:49:06 -------- d-----w- C:\Program Files\ATI
2011-08-12 03:38:57 -------- d-----w- C:\Program Files\CCleaner
2011-08-12 02:17:26 -------- d-----w- C:\Users\Nick\AppData\Local\{07DD887E-8220-4609-B183-3F4F2F16B82A}
2011-08-11 14:16:48 -------- d-----w- C:\Users\Nick\AppData\Local\{6E35367E-A3A7-4B73-A8BC-9E34884F4E8B}
2011-08-11 14:16:24 -------- d-----w- C:\Users\Nick\AppData\Local\{D0C559DA-D696-4DC5-9851-5F7916647DBC}
2011-08-11 09:55:34 388096 ----a-r- C:\Users\Nick\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-08-11 02:15:59 -------- d-----w- C:\Users\Nick\AppData\Local\{D1DBEF8D-80A5-4556-847A-C2F7F3A4E2D5}
2011-08-11 02:15:38 -------- d-----w- C:\Users\Nick\AppData\Local\{321C6430-3FE5-4B7F-A692-1AF3B8B44B88}
2011-08-10 20:12:59 -------- d-----w- C:\Windows\System32\SPReview
2011-08-10 14:15:12 -------- d-----w- C:\Users\Nick\AppData\Local\{027604F2-581F-4AD5-906A-1B86F3706CD7}
2011-08-10 14:14:48 -------- d-----w- C:\Users\Nick\AppData\Local\{30C52B72-CEF6-4EBB-8933-BC47E8D3772C}
2011-08-10 12:36:04 287744 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-08-10 12:35:58 1896832 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-08-10 10:40:49 53248 ----a-r- C:\Users\Nick\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-08-10 10:40:24 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2011-08-10 10:38:00 -------- d-----w- C:\Users\Nick\AppData\Roaming\Logishrd
2011-08-10 02:14:37 -------- d-----w- C:\Users\Nick\AppData\Local\{8081F302-7038-43C7-8AD5-F7337334CB32}
2011-08-10 02:14:15 -------- d-----w- C:\Users\Nick\AppData\Local\{E2103D5E-67FC-40A0-8458-4D09F38C5E24}
2011-08-09 22:03:56 -------- d-----w- C:\ProgramData\bdch
2011-08-09 19:04:50 94208 ----a-w- C:\Program Files (x86)\Common Files\System\Ole DB\msdaosp.dll
2011-08-09 14:13:49 -------- d-----w- C:\Users\Nick\AppData\Local\{21284080-3F13-4974-A422-DAEAF5AE3941}
2011-08-09 14:13:28 -------- d-----w- C:\Users\Nick\AppData\Local\{C669BACA-9273-4EF0-94CB-E98978CC8C68}
2011-08-08 21:18:22 -------- d-----w- C:\Users\Nick\AppData\Local\{8CD2925E-3CA4-4018-8BA8-14E119207836}
2011-08-08 21:17:58 -------- d-----w- C:\Users\Nick\AppData\Local\{26F4E34A-2EF5-4B10-BF3F-7AFDAD3D07B1}
2011-08-08 14:42:09 0 ----a-w- C:\Windows\ativpsrm.bin
2011-08-08 14:39:45 118784 ----a-w- C:\Windows\System32\atibtmon.exe
2011-08-08 09:17:31 -------- d-----w- C:\Users\Nick\AppData\Local\{D5BB7E30-7662-46ED-9BF1-3066AF027D37}
2011-08-08 09:17:18 -------- d-----w- C:\Users\Nick\AppData\Local\{9D9AB5AD-1467-4CCB-8B7C-7F1744B530CA}
2011-08-08 08:05:10 -------- d--h--w- C:\$AVG
2011-08-08 08:00:59 -------- d-----w- C:\ProgramData\IObit
2011-08-08 07:59:32 -------- d-----w- C:\Users\Nick\AppData\Roaming\IObit
2011-08-08 07:42:57 -------- d-----w- C:\Users\Nick\AppData\Roaming\AVG10
2011-08-08 07:41:54 -------- d--h--w- C:\ProgramData\Common Files
2011-08-08 07:41:32 -------- d-----w- C:\Windows\SysWow64\drivers\AVG
2011-08-08 07:40:53 -------- d-----w- C:\Windows\System32\drivers\AVG
2011-08-08 07:40:53 -------- d-----w- C:\ProgramData\AVG10
2011-08-08 07:14:56 60416 ----a-w- C:\Windows\System32\OVDecode64.dll
2011-08-08 07:14:52 53760 ----a-w- C:\Windows\SysWow64\OVDecode.dll
2011-08-08 07:14:24 16552960 ----a-w- C:\Windows\System32\amdocl64.dll
2011-08-08 07:14:14 13555200 ----a-w- C:\Windows\SysWow64\amdocl.dll
2011-08-08 03:31:52 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-07 21:16:43 -------- d-----w- C:\Users\Nick\AppData\Local\{41D1C3FB-6937-46E3-9641-46F1B3DF0D04}
2011-08-07 21:16:30 -------- d-----w- C:\Users\Nick\AppData\Local\{D1EA4680-70CE-4CF3-8B8A-CCEDB79EC663}
2011-08-07 21:02:31 18328 ----a-w- C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-08-07 20:58:40 -------- d-----w- C:\Windows\System32\EventProviders
2011-08-07 20:51:42 -------- d-----w- C:\7e5f84440d0e56b1456e2f8523a7da
2011-08-07 20:32:51 -------- d-----w- C:\Users\Nick\AppData\Roaming\BitDefender
2011-08-07 20:16:29 -------- d-----w- C:\Users\Nick\AppData\Roaming\QuickScan
2011-08-07 20:16:10 -------- d-----w- C:\ProgramData\BitDefender
2011-08-07 20:16:10 -------- d-----w- C:\Program Files\Common Files\BitDefender
2011-08-07 20:16:01 57547 ----a-w- C:\ProgramData\bdinstall.bin
2011-08-07 20:16:01 388168 ----a-w- C:\Windows\System32\drivers\bdfsfltr.sys
2011-08-07 19:58:36 -------- d-----w- C:\ProgramData\MFAData
2011-08-07 19:55:39 -------- d-----w- C:\Users\Nick\AppData\Roaming\Malwarebytes
2011-08-07 19:55:29 -------- d-----w- C:\ProgramData\Malwarebytes
2011-08-07 19:55:26 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-07 04:39:27 -------- d-----w- C:\Users\Nick\AppData\Local\{BF5D2A33-90A9-4D4F-A8BA-595684C0AA82}
2011-08-07 04:39:01 -------- d-----w- C:\Users\Nick\AppData\Local\{DE292556-A8D7-4259-82F6-853D908B82C9}
2011-08-04 16:39:01 -------- d-----w- C:\Users\Nick\AppData\Local\{D71CD9EE-2E98-428A-9733-BA58513CEA48}
2011-08-04 04:42:55 -------- d-----w- C:\Users\Nick\AppData\Local\{EF20107B-49F8-49DB-ABF6-916AF15049E3}
2011-08-03 16:42:32 -------- d-----w- C:\Users\Nick\AppData\Local\{6C269EB0-004C-4579-9883-62706D34CBDB}
2011-08-03 04:42:10 -------- d-----w- C:\Users\Nick\AppData\Local\{B370F7A1-7EFE-4DE4-9B28-730AE25B605F}
2011-08-02 16:41:48 -------- d-----w- C:\Users\Nick\AppData\Local\{627A7307-1663-4A2A-88B7-E01C223F38BA}
2011-08-02 04:41:22 -------- d-----w- C:\Users\Nick\AppData\Local\{60C0164D-6259-4E41-A520-32BE339C7DC0}
2011-08-01 16:41:00 -------- d-----w- C:\Users\Nick\AppData\Local\{501288E7-3FB5-43E9-A758-4F5305E6FC12}
2011-08-01 04:40:38 -------- d-----w- C:\Users\Nick\AppData\Local\{0432DD00-99AB-494B-84F4-C48598A2CE4D}
2011-07-31 20:41:41 8578896 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FFB6EACC-DFE4-4B8D-8F41-975CD46DF893}\mpengine.dll
2011-07-31 16:40:16 -------- d-----w- C:\Users\Nick\AppData\Local\{F661954A-720F-47F1-9D2E-22253F215F1F}
2011-07-31 04:39:54 -------- d-----w- C:\Users\Nick\AppData\Local\{9BD1CCBE-19FA-4122-98DC-179CBCD369F2}
2011-07-30 16:39:32 -------- d-----w- C:\Users\Nick\AppData\Local\{6B66CD89-6C56-4530-A26F-76F7B80AA12D}
2011-07-30 09:08:39 -------- d-----w- C:\Users\Nick\AppData\Local\The Witcher 2
2011-07-30 04:39:11 -------- d-----w- C:\Users\Nick\AppData\Local\{44D32E11-697A-4391-B619-B38679C303DC}
2011-07-29 16:38:44 -------- d-----w- C:\Users\Nick\AppData\Local\{49CC925A-C4E7-4A86-9BC9-1921ECAD2D02}
2011-07-26 16:36:31 -------- d-----w- C:\Users\Nick\AppData\Local\{32423105-183B-441E-A3F9-52A857AF3C34}
2011-07-26 04:35:55 -------- d-----w- C:\Users\Nick\AppData\Local\{BD0897A3-B928-4407-8267-717D3274D764}
2011-07-21 07:54:35 -------- d-----w- C:\Users\Nick\AppData\Local\{61233297-DAE1-498B-8478-F7ECC39ECEBD}
.
==================== Find3M ====================
.
2011-08-08 19:51:42 9978880 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2011-08-08 19:25:28 24501760 ----a-w- C:\Windows\System32\atio6axx.dll
2011-08-08 19:10:38 18688000 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2011-08-08 19:05:52 151552 ----a-w- C:\Windows\System32\atiapfxx.exe
2011-08-08 19:05:42 726528 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2011-08-08 19:04:24 852992 ----a-w- C:\Windows\System32\aticfx64.dll
2011-08-08 19:01:54 462848 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2011-08-08 19:01:48 485376 ----a-w- C:\Windows\System32\atieclxx.exe
2011-08-08 19:01:12 204288 ----a-w- C:\Windows\System32\atiesrxx.exe
2011-08-08 19:00:02 120320 ----a-w- C:\Windows\System32\atitmm64.dll
2011-08-08 18:59:48 423424 ----a-w- C:\Windows\System32\atipdl64.dll
2011-08-08 18:59:40 356352 ----a-w- C:\Windows\SysWow64\atipdlxx.dll
2011-08-08 18:59:30 278528 ----a-w- C:\Windows\SysWow64\Oemdspif.dll
2011-08-08 18:59:24 21504 ----a-w- C:\Windows\System32\atimuixx.dll
2011-08-08 18:59:20 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2011-08-08 18:59:16 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2011-08-08 18:56:16 4178432 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2011-08-08 18:47:14 4921344 ----a-w- C:\Windows\System32\atidxx64.dll
2011-08-08 18:44:18 1113088 ----a-w- C:\Windows\System32\atiumd6v.dll
2011-08-08 18:43:54 1828864 ----a-w- C:\Windows\SysWow64\atiumdmv.dll
2011-08-08 18:43:42 3871744 ----a-w- C:\Windows\System32\atiumd6a.dll
2011-08-08 18:39:32 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
2011-08-08 18:39:30 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2011-08-08 18:39:22 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2011-08-08 18:39:20 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
2011-08-08 18:39:08 8724480 ----a-w- C:\Windows\System32\aticaldd64.dll
2011-08-08 18:37:06 4255232 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2011-08-08 18:36:16 7327232 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2011-08-08 18:34:20 4056064 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2011-08-08 18:31:44 58880 ----a-w- C:\Windows\System32\coinst.dll
2011-08-08 18:31:12 5394432 ----a-w- C:\Windows\System32\atiumd64.dll
2011-08-08 18:24:30 378368 ----a-w- C:\Windows\System32\atiadlxx.dll
2011-08-08 18:24:24 266240 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2011-08-08 18:24:16 15360 ----a-w- C:\Windows\System32\atig6pxx.dll
2011-08-08 18:24:14 13312 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
2011-08-08 18:24:14 13312 ----a-w- C:\Windows\System32\atiglpxx.dll
2011-08-08 18:24:10 39936 ----a-w- C:\Windows\System32\atig6txx.dll
2011-08-08 18:24:02 32768 ----a-w- C:\Windows\SysWow64\atigktxx.dll
2011-08-08 18:23:54 309248 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
2011-08-08 18:23:06 40960 ----a-w- C:\Windows\System32\atiuxp64.dll
2011-08-08 18:23:00 31744 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2011-08-08 18:22:52 38912 ----a-w- C:\Windows\System32\atiu9p64.dll
2011-08-08 18:22:44 29184 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2011-08-08 18:22:08 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2011-08-08 18:20:10 53760 ----a-w- C:\Windows\System32\atimpc64.dll
2011-08-08 18:20:10 53760 ----a-w- C:\Windows\System32\amdpcom64.dll
2011-08-08 18:19:58 52736 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2011-08-08 18:19:58 52736 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2011-07-22 05:42:23 2303488 ----a-w- C:\Windows\System32\jscript9.dll
2011-07-22 05:36:16 1389056 ----a-w- C:\Windows\System32\wininet.dll
2011-07-22 05:32:40 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-07-22 02:54:43 1797632 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-07-22 02:48:26 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-07-22 02:44:36 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-07-16 05:26:54 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-07-16 05:26:53 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-07-16 05:26:53 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-07-16 05:26:18 214528 ----a-w- C:\Windows\System32\winsrv.dll
2011-07-16 05:24:09 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-07-16 05:21:32 422400 ----a-w- C:\Windows\System32\KernelBase.dll
2011-07-16 05:17:46 338432 ----a-w- C:\Windows\System32\conhost.exe
2011-07-16 04:36:09 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-07-16 04:32:14 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-07-16 04:31:50 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-07-16 04:30:29 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-07-16 04:30:27 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-07-16 02:26:12 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-07-16 02:26:11 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-07-16 02:21:47 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:21:47 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:21:47 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:21:47 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-07-12 17:41:27 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-07 15:37:10 51200 ----a-w- C:\Windows\System32\OpenCL.dll
2011-07-07 09:36:56 103784 ----a-w- C:\Users\Nick\GoToAssistDownloadHelper.exe
2011-06-27 08:23:02 43520 ----a-w- C:\Windows\SysWow64\OpenCL.dll
2011-06-23 05:29:39 5507968 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-06-23 04:38:05 3957120 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-06-23 04:38:04 3902336 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-06-15 19:34:06 79872 ----a-w- C:\Windows\SysWow64\SlotMaximizerAg.dll
2011-06-15 19:34:06 2971648 ----a-w- C:\Windows\System32\SlotMaximizerBe.dll
2011-06-15 19:34:06 2117632 ----a-w- C:\Windows\SysWow64\SlotMaximizerBe.dll
2011-06-15 19:34:06 105984 ----a-w- C:\Windows\System32\SlotMaximizerAg.dll
2011-06-15 09:58:31 212992 ----a-w- C:\Windows\System32\odbctrac.dll
2011-06-15 09:58:31 163840 ----a-w- C:\Windows\System32\odbccp32.dll
2011-06-15 09:58:31 106496 ----a-w- C:\Windows\System32\odbccu32.dll
2011-06-15 09:58:31 106496 ----a-w- C:\Windows\System32\odbccr32.dll
2011-06-15 09:04:46 86016 ----a-w- C:\Windows\SysWow64\odbccu32.dll
2011-06-15 09:04:46 81920 ----a-w- C:\Windows\SysWow64\odbccr32.dll
2011-06-15 09:04:46 319488 ----a-w- C:\Windows\SysWow64\odbcjt32.dll
2011-06-15 09:04:46 163840 ----a-w- C:\Windows\SysWow64\odbctrac.dll
2011-06-15 09:04:46 122880 ----a-w- C:\Windows\SysWow64\odbccp32.dll
2011-06-11 02:56:44 3134464 ----a-w- C:\Windows\System32\win32k.sys
2011-06-06 22:07:00 231440 ----a-w- C:\Windows\System32\drivers\AtihdW76.sys
2011-05-24 11:21:59 404992 ----a-w- C:\Windows\System32\umpnpmgr.dll
2011-05-24 10:34:20 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
2011-05-24 10:34:20 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll
2011-05-24 10:34:00 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll
2011-05-24 10:32:46 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe
2010-07-08 02:37:14 101544 ----a-w- C:\Program Files\Common Files\LinkInstaller.exe
.
============= FINISH: 15:38:11.24 ===============

#3 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,760 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:04 PM

Posted 20 August 2011 - 02:35 AM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

Posted Image In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resouce! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/414481 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

Posted Image If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS and GMER log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from one of the following links if you no longer have it available. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE


We also need a new log from the GMER anti-rootkit Scanner.

Please note that if you are running a 64-bit version of Windows you will not be able to run GMER and you may skip this step.

Please first disable any CD emulation programs using the steps found in this topic:

Why we request you disable CD Emulation when receiving Malware Removal Advice


Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here:

How to create a GMER log


As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#4 berlok

berlok
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:04 AM

Posted 20 August 2011 - 07:49 AM

Running on Windows 7 64bits, found out my computer have a lot of bloatware and weird toolbars appearing, tried to self medicate. but just want to make sure it is all clean.

Attached is the DDS Log

Attached Files

  • Attached File  DDS.txt   30.61KB   1 downloads


#5 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:04 PM

Posted 20 August 2011 - 01:19 PM

Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems.

Somethings to remember while we are working together.

  • Do not run any other tool untill instructed to do so!
  • please Do not Attach logs or put in code boxes.
  • Tell me about any problems that have occurred during the fix.
  • Tell me of any other symptoms you may be having as these can help also.
  • Do not run anything while running a fix.
  • Do not run any other tool untill instructed to do so!


Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#6 berlok

berlok
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:04 AM

Posted 21 August 2011 - 02:04 PM

Hi Gringo,

Here is my combofix log

One thing to note is that, i have uninstalled bitdefender from my control panel, but combofix still informs me that I am protected by it. weird.

And for my AVG, when I tried to disable it, it says "an error occured when saving the configuration. Connection is off-line" but I am online.

I went on with the scan as AVG interface says "There are no active components"


ComboFix 11-08-21.01 - Nick 08/22/2011 2:38.1.2 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.4094.2695 [GMT 8:00]
Running from: c:\users\Nick\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
AV: BitDefender Antivirus *Enabled/Updated* {50909708-FF80-02AF-F814-B28405891E92}
FW: BitDefender Firewall *Disabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: BitDefender Antispyware *Enabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Nick\AppData\Local\.#
c:\users\Nick\AppData\Local\.#\MBX@1268@3D19E0.###
c:\users\Nick\AppData\Local\GoalServer2009.exe
c:\users\Nick\AppData\Local\GoalWebServer2009.exe
c:\users\Nick\AppData\Local\libeay32.dll
c:\users\Nick\AppData\Local\libssl32.dll
c:\users\Nick\AppData\Local\stunnel.exe
c:\users\Nick\GoToAssistDownloadHelper.exe
F:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-07-21 to 2011-08-21 )))))))))))))))))))))))))))))))
.
.
2011-08-21 18:46 . 2011-08-21 18:48 -------- d-----w- c:\users\Nick\AppData\Local\temp
2011-08-21 18:46 . 2011-08-21 18:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-17 10:40 . 2011-08-17 10:40 -------- d-----w- c:\users\Nick\AppData\Local\Locktime
2011-08-17 10:39 . 2011-08-17 10:39 -------- d-----w- c:\program files (x86)\Linksys Wireless-G USB Wireless Network Monitor
2011-08-17 10:36 . 2011-08-17 10:36 -------- d-----w- c:\programdata\Locktime
2011-08-17 10:07 . 2011-08-17 10:07 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2011-08-12 03:53 . 2011-08-12 03:53 -------- d-----w- c:\programdata\ATI
2011-08-12 03:52 . 2011-08-12 03:52 -------- d-----w- c:\program files (x86)\AMD APP
2011-08-12 03:52 . 2011-08-12 03:52 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2011-08-12 03:52 . 2011-08-12 03:52 -------- d-----w- c:\program files (x86)\ATI Technologies
2011-08-12 03:51 . 2011-08-12 03:51 -------- d-----w- c:\program files\Common Files\ATI Technologies
2011-08-12 03:49 . 2011-08-12 03:49 -------- d-----w- c:\program files\ATI
2011-08-12 03:38 . 2011-08-12 03:38 -------- d-----w- c:\program files\CCleaner
2011-08-11 09:55 . 2011-08-11 09:55 388096 ----a-r- c:\users\Nick\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-08-10 20:12 . 2011-08-10 20:12 -------- d-----w- c:\windows\system32\SPReview
2011-08-10 12:36 . 2011-07-09 02:44 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-10 12:35 . 2011-06-21 06:27 1896832 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-10 10:40 . 2011-08-10 10:40 53248 ----a-r- c:\users\Nick\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-08-10 10:40 . 2011-08-10 10:40 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd
2011-08-10 10:40 . 2011-08-10 10:40 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-08-10 10:39 . 2011-08-10 10:40 -------- d-----w- c:\programdata\Logishrd
2011-08-10 10:38 . 2011-08-10 10:40 -------- d-----w- c:\program files\Common Files\LogiShrd
2011-08-10 10:38 . 2011-08-10 10:40 -------- d-----w- c:\users\Nick\AppData\Roaming\Logitech
2011-08-10 10:38 . 2011-08-10 10:38 -------- d-----w- c:\users\Nick\AppData\Roaming\Logishrd
2011-08-09 19:04 . 2011-06-15 09:58 212992 ----a-w- c:\windows\system32\odbctrac.dll
2011-08-08 14:42 . 2011-08-08 14:42 0 ----a-w- c:\windows\ativpsrm.bin
2011-08-08 14:39 . 2009-05-11 21:35 118784 ----a-w- c:\windows\system32\atibtmon.exe
2011-08-08 08:05 . 2011-08-08 08:05 -------- d-----w- C:\$AVG
2011-08-08 08:00 . 2011-08-08 08:00 -------- d-----w- c:\programdata\IObit
2011-08-08 07:59 . 2011-08-08 07:59 -------- d-----w- c:\users\Nick\AppData\Roaming\IObit
2011-08-08 07:42 . 2011-08-08 07:42 -------- d-----w- c:\users\Nick\AppData\Roaming\AVG10
2011-08-08 07:41 . 2011-08-08 07:41 -------- d--h--w- c:\programdata\Common Files
2011-08-08 07:41 . 2011-08-08 07:41 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2011-08-08 07:40 . 2011-08-16 10:56 -------- d-----w- c:\windows\system32\drivers\AVG
2011-08-08 07:40 . 2011-08-08 07:42 -------- d-----w- c:\programdata\AVG10
2011-08-08 07:14 . 2011-08-08 07:14 60416 ----a-w- c:\windows\system32\OVDecode64.dll
2011-08-08 07:14 . 2011-08-08 07:14 53760 ----a-w- c:\windows\SysWow64\OVDecode.dll
2011-08-08 07:14 . 2011-08-08 07:14 16552960 ----a-w- c:\windows\system32\amdocl64.dll
2011-08-08 07:14 . 2011-08-08 07:14 13555200 ----a-w- c:\windows\SysWow64\amdocl.dll
2011-08-08 03:31 . 2011-07-06 11:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-07 21:02 . 2011-08-07 21:02 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-08-07 20:58 . 2011-08-07 20:58 -------- d-----w- c:\windows\system32\EventProviders
2011-08-07 20:51 . 2011-08-07 20:51 -------- d-----w- C:\7e5f84440d0e56b1456e2f8523a7da
2011-08-07 20:16 . 2011-08-07 20:16 -------- d-----w- c:\users\Nick\AppData\Roaming\QuickScan
2011-08-07 20:16 . 2011-08-16 21:59 -------- d-----w- c:\program files\Common Files\BitDefender
2011-08-07 20:16 . 2011-08-16 21:56 64534 ----a-w- c:\programdata\bdinstall.bin
2011-08-07 19:58 . 2011-08-08 07:42 -------- d-----w- c:\programdata\MFAData
2011-08-07 19:55 . 2011-08-07 19:55 -------- d-----w- c:\users\Nick\AppData\Roaming\Malwarebytes
2011-08-07 19:55 . 2011-08-07 19:55 -------- d-----w- c:\programdata\Malwarebytes
2011-08-07 19:55 . 2011-07-06 11:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-02 18:31 . 2011-08-02 18:31 -------- d-----w- c:\program files (x86)\Google
2011-07-31 20:41 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FFB6EACC-DFE4-4B8D-8F41-975CD46DF893}\mpengine.dll
2011-07-30 09:08 . 2011-07-30 09:08 -------- d-----w- c:\users\Nick\AppData\Local\The Witcher 2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-08 18:31 . 2010-08-26 01:27 58880 ----a-w- c:\windows\system32\coinst.dll
2011-07-16 04:32 . 2011-08-09 19:04 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-12 17:41 . 2011-05-20 10:16 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-07 15:37 . 2011-07-07 15:37 51200 ----a-w- c:\windows\system32\OpenCL.dll
2011-06-27 08:23 . 2011-06-27 08:23 43520 ----a-w- c:\windows\SysWow64\OpenCL.dll
2011-06-15 19:34 . 2011-06-15 19:34 79872 ----a-w- c:\windows\SysWow64\SlotMaximizerAg.dll
2011-06-15 19:34 . 2011-06-15 19:34 2971648 ----a-w- c:\windows\system32\SlotMaximizerBe.dll
2011-06-15 19:34 . 2011-06-15 19:34 2117632 ----a-w- c:\windows\SysWow64\SlotMaximizerBe.dll
2011-06-15 19:34 . 2011-06-15 19:34 105984 ----a-w- c:\windows\system32\SlotMaximizerAg.dll
2011-06-11 02:56 . 2011-07-13 01:58 3134464 ----a-w- c:\windows\system32\win32k.sys
2011-05-24 11:21 . 2011-06-28 21:55 404992 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-05-24 10:34 . 2011-06-28 21:55 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-05-24 10:34 . 2011-06-28 21:55 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-05-24 10:34 . 2011-06-28 21:55 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-05-24 10:32 . 2011-06-28 21:55 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-20 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[7] 2010-11-19 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2010-04-30 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7600.16385] .. c:\windows\system32\user32.dll
.
[7] 2010-11-20 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[7] 2010-11-19 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[-] 2010-04-30 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7600.16385] .. c:\windows\SysWOW64\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256]
"AtiTrayTools"="d:\program files (x86)\Ray Adams\ATI Tray Tools\atitray.exe" [2011-03-27 929280]
"NetLimiter"="d:\program files\NetLimiter 3\NLClientApp.exe" [2011-03-21 2910208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="d:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-08-08 336384]
"PlusService"="d:\program files (x86)\Yuna Software\Messenger Plus!\PlusService.exe" [2011-05-26 800768]
"AVG_TRAY"="d:\program files (x86)\AVG\AVG10\avgtray.exe" [2011-04-18 2334560]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ d:\progra~1\AVG\AVG10\avgchsva.exe /sync\0d:\progra~1\AVG\AVG10\avgrsa.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R3 AdvancedSystemCareService;Advanced SystemCare Service;d:\program files (x86)\IObit\Advanced SystemCare 4\ASCService.exe [2011-06-02 353168]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x]
R3 BFBackupUtilityService;Backup Utility Service;c:\program files (x86)\BUFFALO\Backup_Utility\BUService.exe [2010-08-20 320888]
R3 BFBackupUtilityVSSService;Backup Utility VSS Service;c:\program files (x86)\BUFFALO\Backup_Utility\BUVSSService64.exe [2010-04-28 359288]
R3 bftpusbx64;BUFFALO TurboPC USB Filter;c:\windows\system32\drivers\bftpusbx64.sys [x]
R3 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-02-23 16776]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-02-23 9096]
R3 GGSAFERDriver;GGSAFER Driver;d:\program files (x86)\Garena\safedrv.sys [x]
R3 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;d:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-08-04 2329480]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys [x]
R3 Neo_PacketiX;VPN Client Device Driver - PacketiX;c:\windows\system32\DRIVERS\Neo_0116.sys [x]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [x]
R3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\DRIVERS\nlndis.sys [x]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [x]
R3 tapoas;TAP-Win32 Adapter OAS;c:\windows\system32\DRIVERS\tapoas.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 vpnclient;PacketiX VPN Client;d:\program files\PacketiX VPN Client 64-bit Edition English\vpnclient_x64.exe [2008-05-15 4601344]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
R4 AVGIDSAgent;AVGIDSAgent;d:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-04-18 7398752]
R4 avgwd;AVG WatchDog;d:\program files (x86)\AVG\AVG10\avgwdsvc.exe [2011-02-07 269520]
R4 TunngleService;TunngleService;d:\program files (x86)\Tunngle\TnglCtrl.exe [2010-07-06 716024]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x]
S0 BFRD4G;BUFFALO RAM Disk Driver;c:\windows\system32\DRIVERS\BFRD4G.sys [x]
S0 bftpdskc64;BUFFALO TurboPC Cache Filter;c:\windows\system32\drivers\bftpdskc64.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x]
S1 nltdi;nltdi;d:\program files\NetLimiter 3\nltdi.sys [2011-03-21 88200]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 NLNdisMP;NLNdisMP;c:\windows\system32\DRIVERS\nlndis.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S4 DRIVER_B;DRIVER_B;c:\windows\system32\Drivers\DRIVER_BIN64 [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4215053619-1285209441-3098757345-1001Core.job
- c:\users\Nick\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-30 18:37]
.
2011-08-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4215053619-1285209441-3098757345-1001UA.job
- c:\users\Nick\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-30 18:37]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184]
"EvtMgr6"="d:\program files\Logitech\SetPointP\SetPoint.exe" [2011-06-23 1744152]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = http=
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\0jvkwx1e.default\
FF - prefs.js: browser.search.selectedEngine - Facemoods Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sg/
FF - prefs.js: network.proxy.http - 89.74.147.143
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - d:\program files (x86)\Hotspot Shield\HssIE\HssIE_64.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-LoL - d:\program files (x86)\Garena Messenger\Apps\LoL\uninst.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\DRIVER_B]
"ImagePath"="\??\c:\windows\system32\Drivers\DRIVER_BIN64"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-4215053619-1285209441-3098757345-1001\Software\G*e*n*i*e*"!\FM Genie Scout 10]
"GameDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2010\\games"
"ShortlistDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2010\\shortlists"
"ScreenshotsDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2010"
"SaveDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2010\\"
"HistoryDir"="c:\\Users\\Nick\\Desktop\\FM Genie Scout 10\\History Points"
"LangDB"="d:\\Program Files (x86)\\Sports Interactive\\Football Manager 2010\\data\\db\\1000\\lang_db.dat"
"LastSaveGame"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2011\\games\\lfc v1.fm"
"Language"="English"
"LoadLangDB"=dword:00000001
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000032
"GraphStep"=dword:00000000
"SkinName"="Steklo Black"
"LastUpdateCheck"=dword:00009e28
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:00000074
"UniqueID"="95-EC80-E32F"
"Currency"=dword:00000056
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""
.
[HKEY_USERS\S-1-5-21-4215053619-1285209441-3098757345-1001\Software\G*e*n*i*e*"!\FM Genie Scout 11]
"GameDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2011\\games"
"ShortlistDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2011\\shortlists"
"FMPath"="d:\\Program Files (x86)\\Sports Interactive\\Football Manager 2011\\"
"ScreenshotsDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2011"
"SaveDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2011\\"
"HistoryDir"="d:\\FM Genie Scout 11\\History Points"
"LangDB"="d:\\Program Files (x86)\\Sports Interactive\\Football Manager 2011\\data\\updates\\update-1120\\db\\1120\\lang_db.dat"
"LastSaveGame"=""
"Language"="English"
"LoadLangDB"=dword:00000001
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000050
"GraphStep"=dword:00000000
"SkinName"="PSV Eindhoven"
"LastUpdateCheck"=dword:00009e80
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:00000080
"UniqueID"="95-EC80-E32F"
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""
"Currency"=dword:00000056
"PlayerSearchFeatureNum"=dword:00000008
"StaffSearchFeatureNum"=dword:00000001
"ClubSearchFeatureNum"=dword:00000000
"FilterByClubFeatureNum"=dword:00000001
"CompareFeatureNum"=dword:00000000
"ShortlistFeatureNum"=dword:00000000
"ExportFeatureNum"=dword:00000000
"HistoryFeatureNum"=dword:00000000
"LanguageDBFeatureNum"=dword:00000008
"HintsFeatureNum"=dword:00000000
"GenieReportFeatureNum"=dword:00000005
"TopFormationFeatureNum"=dword:00000000
"ScreenshotFeatureNum"=dword:00000000
.
[HKEY_USERS\S-1-5-21-4215053619-1285209441-3098757345-1001\Software\G*e*n*i*e*"!\FM Genie Scout 11g]
"PicturesNumber"=dword:00000000
.
[HKEY_USERS\S-1-5-21-4215053619-1285209441-3098757345-1001\Software\SecuROM\License information*]
"datasecu"=hex:f0,0b,40,7f,01,28,89,0e,ce,ca,e0,e2,7b,f6,e9,ee,cd,f5,f7,9b,e2,
31,83,d5,b4,63,91,f2,e0,26,e6,a7,e5,8a,80,dc,e2,91,e3,81,e6,71,9b,10,b1,a7,\
"rkeysecu"=hex:97,a2,9a,da,51,31,f3,fc,a9,3b,ea,1c,77,81,49,ac
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\ProgramData\\ESET\\ESET NOD32 Antivirus\\"
"DataDir"="ESET\\ESET NOD32 Antivirus\\"
"EditionName"=" "
"InstallDir"="d:\\Program Files\\ESET\\ESET NOD32 Antivirus\\"
"LanguageId"=dword:00000409
"PackageTag"=dword:6090e758
"ProductBase"=dword:00000000
"ProductCode"="{DD83A4D4-745F-4B69-94BA-FF1E1CCC03D1}"
"ProductName"="ESET NOD32 Antivirus"
"ProductType"="eav"
"ProductVersion"="4.2.42.0"
"UniqueId"="0BA29B714C57E7DB"
"ScannerBuild"=dword:00001ab4
"ScannerVersionId"=dword:00001377
"ScannerVersion"="Open window for status."
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
d:\program files (x86)\IObit\Advanced SystemCare 4\PMonitor.exe
d:\program files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
.
**************************************************************************
.
Completion time: 2011-08-22 02:53:08 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-21 18:53
.
Pre-Run: 26,645,942,272 bytes free
Post-Run: 26,554,568,704 bytes free
.
- - End Of File - - 8B6745B79FE4F112342522D282631833

Edited by berlok, 21 August 2011 - 02:10 PM.


#7 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:04 PM

Posted 21 August 2011 - 07:56 PM

Greetings

Good That cleaned up some bad guys but I see some other stuff that we need to go after, so I want you to run this custom script for me.

:Run CFScript:

Open Notepad and copy/paste the text in the box into the window:

DDS::
FF - ProfilePath - c:\users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\0jvkwx1e.default\
FF - prefs.js: browser.search.selectedEngine - Facemoods Search


Save it to your desktop as CFScript.txt

Refering to the picture above, drag CFScript.txt into ComboFix.exe
Posted Image
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

"information and logs"

  • In your next post I need the following

  • report from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now after running the script?

Gringo

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#8 berlok

berlok
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:04 AM

Posted 21 August 2011 - 10:50 PM

Hi Gringo, this is the latest Combofix Log. Computer seems to be running fine, but I have a lot of svhost running with some using a lot of memory, if this is normal.


ComboFix 11-08-21.01 - Nick 08/22/2011 11:35:41.2.2 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.4094.2269 [GMT 8:00]
Running from: c:\users\Nick\Downloads\ComboFix.exe
Command switches used :: c:\users\Nick\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2011-07-22 to 2011-08-22 )))))))))))))))))))))))))))))))
.
.
2011-08-22 03:38 . 2011-08-22 03:41 -------- d-----w- c:\users\Nick\AppData\Local\temp
2011-08-22 03:38 . 2011-08-22 03:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-17 10:40 . 2011-08-17 10:40 -------- d-----w- c:\users\Nick\AppData\Local\Locktime
2011-08-17 10:39 . 2011-08-17 10:39 -------- d-----w- c:\program files (x86)\Linksys Wireless-G USB Wireless Network Monitor
2011-08-17 10:36 . 2011-08-17 10:36 -------- d-----w- c:\programdata\Locktime
2011-08-17 10:07 . 2011-08-17 10:07 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2011-08-12 03:53 . 2011-08-12 03:53 -------- d-----w- c:\programdata\ATI
2011-08-12 03:52 . 2011-08-12 03:52 -------- d-----w- c:\program files (x86)\AMD APP
2011-08-12 03:52 . 2011-08-12 03:52 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2011-08-12 03:52 . 2011-08-12 03:52 -------- d-----w- c:\program files (x86)\ATI Technologies
2011-08-12 03:51 . 2011-08-12 03:51 -------- d-----w- c:\program files\Common Files\ATI Technologies
2011-08-12 03:49 . 2011-08-12 03:49 -------- d-----w- c:\program files\ATI
2011-08-12 03:38 . 2011-08-12 03:38 -------- d-----w- c:\program files\CCleaner
2011-08-11 09:55 . 2011-08-11 09:55 388096 ----a-r- c:\users\Nick\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-08-10 20:12 . 2011-08-10 20:12 -------- d-----w- c:\windows\system32\SPReview
2011-08-10 12:36 . 2011-07-09 02:44 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-10 12:35 . 2011-06-21 06:27 1896832 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-10 10:40 . 2011-08-10 10:40 53248 ----a-r- c:\users\Nick\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-08-10 10:40 . 2011-08-10 10:40 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd
2011-08-10 10:40 . 2011-08-10 10:40 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-08-10 10:39 . 2011-08-10 10:40 -------- d-----w- c:\programdata\Logishrd
2011-08-10 10:38 . 2011-08-10 10:40 -------- d-----w- c:\program files\Common Files\LogiShrd
2011-08-10 10:38 . 2011-08-10 10:40 -------- d-----w- c:\users\Nick\AppData\Roaming\Logitech
2011-08-10 10:38 . 2011-08-10 10:38 -------- d-----w- c:\users\Nick\AppData\Roaming\Logishrd
2011-08-09 19:04 . 2011-06-15 09:58 212992 ----a-w- c:\windows\system32\odbctrac.dll
2011-08-08 14:42 . 2011-08-08 14:42 0 ----a-w- c:\windows\ativpsrm.bin
2011-08-08 14:39 . 2009-05-11 21:35 118784 ----a-w- c:\windows\system32\atibtmon.exe
2011-08-08 08:05 . 2011-08-08 08:05 -------- d-----w- C:\$AVG
2011-08-08 08:00 . 2011-08-08 08:00 -------- d-----w- c:\programdata\IObit
2011-08-08 07:59 . 2011-08-08 07:59 -------- d-----w- c:\users\Nick\AppData\Roaming\IObit
2011-08-08 07:42 . 2011-08-08 07:42 -------- d-----w- c:\users\Nick\AppData\Roaming\AVG10
2011-08-08 07:41 . 2011-08-08 07:41 -------- d--h--w- c:\programdata\Common Files
2011-08-08 07:41 . 2011-08-08 07:41 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2011-08-08 07:40 . 2011-08-16 10:56 -------- d-----w- c:\windows\system32\drivers\AVG
2011-08-08 07:40 . 2011-08-08 07:42 -------- d-----w- c:\programdata\AVG10
2011-08-08 07:14 . 2011-08-08 07:14 60416 ----a-w- c:\windows\system32\OVDecode64.dll
2011-08-08 07:14 . 2011-08-08 07:14 53760 ----a-w- c:\windows\SysWow64\OVDecode.dll
2011-08-08 07:14 . 2011-08-08 07:14 16552960 ----a-w- c:\windows\system32\amdocl64.dll
2011-08-08 07:14 . 2011-08-08 07:14 13555200 ----a-w- c:\windows\SysWow64\amdocl.dll
2011-08-08 03:31 . 2011-07-06 11:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-07 21:02 . 2011-08-07 21:02 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-08-07 20:58 . 2011-08-07 20:58 -------- d-----w- c:\windows\system32\EventProviders
2011-08-07 20:51 . 2011-08-07 20:51 -------- d-----w- C:\7e5f84440d0e56b1456e2f8523a7da
2011-08-07 20:16 . 2011-08-07 20:16 -------- d-----w- c:\users\Nick\AppData\Roaming\QuickScan
2011-08-07 20:16 . 2011-08-16 21:59 -------- d-----w- c:\program files\Common Files\BitDefender
2011-08-07 20:16 . 2011-08-16 21:56 64534 ----a-w- c:\programdata\bdinstall.bin
2011-08-07 19:58 . 2011-08-08 07:42 -------- d-----w- c:\programdata\MFAData
2011-08-07 19:55 . 2011-08-07 19:55 -------- d-----w- c:\users\Nick\AppData\Roaming\Malwarebytes
2011-08-07 19:55 . 2011-08-07 19:55 -------- d-----w- c:\programdata\Malwarebytes
2011-08-07 19:55 . 2011-07-06 11:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-02 18:31 . 2011-08-02 18:31 -------- d-----w- c:\program files (x86)\Google
2011-07-31 20:41 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FFB6EACC-DFE4-4B8D-8F41-975CD46DF893}\mpengine.dll
2011-07-30 09:08 . 2011-07-30 09:08 -------- d-----w- c:\users\Nick\AppData\Local\The Witcher 2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-08 18:31 . 2010-08-26 01:27 58880 ----a-w- c:\windows\system32\coinst.dll
2011-07-16 04:32 . 2011-08-09 19:04 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-12 17:41 . 2011-05-20 10:16 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-07 15:37 . 2011-07-07 15:37 51200 ----a-w- c:\windows\system32\OpenCL.dll
2011-06-27 08:23 . 2011-06-27 08:23 43520 ----a-w- c:\windows\SysWow64\OpenCL.dll
2011-06-15 19:34 . 2011-06-15 19:34 79872 ----a-w- c:\windows\SysWow64\SlotMaximizerAg.dll
2011-06-15 19:34 . 2011-06-15 19:34 2971648 ----a-w- c:\windows\system32\SlotMaximizerBe.dll
2011-06-15 19:34 . 2011-06-15 19:34 2117632 ----a-w- c:\windows\SysWow64\SlotMaximizerBe.dll
2011-06-15 19:34 . 2011-06-15 19:34 105984 ----a-w- c:\windows\system32\SlotMaximizerAg.dll
2011-06-11 02:56 . 2011-07-13 01:58 3134464 ----a-w- c:\windows\system32\win32k.sys
2011-05-24 11:21 . 2011-06-28 21:55 404992 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-05-24 10:34 . 2011-06-28 21:55 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-05-24 10:34 . 2011-06-28 21:55 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-05-24 10:34 . 2011-06-28 21:55 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-05-24 10:32 . 2011-06-28 21:55 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-19 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2010-04-30 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7600.16385] .. c:\windows\system32\user32.dll
.
[7] 2010-11-19 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[-] 2010-04-30 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7600.16385] .. c:\windows\SysWOW64\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-08-21_18.48.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-25 16:00 . 2011-08-21 18:50 42640 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-08-21 18:50 34854 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2011-08-21 18:48 . 2011-08-21 18:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-08-22 03:39 . 2011-08-22 03:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-08-22 03:39 . 2011-08-22 03:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-08-21 18:48 . 2011-08-21 18:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:36 . 2011-08-22 03:40 648004 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-08-22 03:40 118180 c:\windows\system32\perfc009.dat
+ 2009-07-14 05:01 . 2011-08-22 03:38 437660 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2011-08-21 18:47 437660 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-10-31 18:30 . 2011-08-22 03:38 37804114 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4215053619-1285209441-3098757345-1001-12288.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256]
"AtiTrayTools"="d:\program files (x86)\Ray Adams\ATI Tray Tools\atitray.exe" [2011-03-27 929280]
"NetLimiter"="d:\program files\NetLimiter 3\NLClientApp.exe" [2011-03-21 2910208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="d:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-08-08 336384]
"PlusService"="d:\program files (x86)\Yuna Software\Messenger Plus!\PlusService.exe" [2011-05-26 800768]
"AVG_TRAY"="d:\program files (x86)\AVG\AVG10\avgtray.exe" [2011-04-18 2334560]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ d:\progra~1\AVG\AVG10\avgchsva.exe /sync\0d:\progra~1\AVG\AVG10\avgrsa.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R3 AdvancedSystemCareService;Advanced SystemCare Service;d:\program files (x86)\IObit\Advanced SystemCare 4\ASCService.exe [2011-06-02 353168]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x]
R3 BFBackupUtilityService;Backup Utility Service;c:\program files (x86)\BUFFALO\Backup_Utility\BUService.exe [2010-08-20 320888]
R3 BFBackupUtilityVSSService;Backup Utility VSS Service;c:\program files (x86)\BUFFALO\Backup_Utility\BUVSSService64.exe [2010-04-28 359288]
R3 bftpusbx64;BUFFALO TurboPC USB Filter;c:\windows\system32\drivers\bftpusbx64.sys [x]
R3 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-02-23 16776]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-02-23 9096]
R3 GGSAFERDriver;GGSAFER Driver;d:\program files (x86)\Garena\safedrv.sys [x]
R3 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;d:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-08-04 2329480]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys [x]
R3 Neo_PacketiX;VPN Client Device Driver - PacketiX;c:\windows\system32\DRIVERS\Neo_0116.sys [x]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [x]
R3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\DRIVERS\nlndis.sys [x]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [x]
R3 tapoas;TAP-Win32 Adapter OAS;c:\windows\system32\DRIVERS\tapoas.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 vpnclient;PacketiX VPN Client;d:\program files\PacketiX VPN Client 64-bit Edition English\vpnclient_x64.exe [2008-05-15 4601344]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
R4 AVGIDSAgent;AVGIDSAgent;d:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-04-18 7398752]
R4 avgwd;AVG WatchDog;d:\program files (x86)\AVG\AVG10\avgwdsvc.exe [2011-02-07 269520]
R4 TunngleService;TunngleService;d:\program files (x86)\Tunngle\TnglCtrl.exe [2010-07-06 716024]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x]
S0 BFRD4G;BUFFALO RAM Disk Driver;c:\windows\system32\DRIVERS\BFRD4G.sys [x]
S0 bftpdskc64;BUFFALO TurboPC Cache Filter;c:\windows\system32\drivers\bftpdskc64.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x]
S1 nltdi;nltdi;d:\program files\NetLimiter 3\nltdi.sys [2011-03-21 88200]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 NLNdisMP;NLNdisMP;c:\windows\system32\DRIVERS\nlndis.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S4 DRIVER_B;DRIVER_B;c:\windows\system32\Drivers\DRIVER_BIN64 [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4215053619-1285209441-3098757345-1001Core.job
- c:\users\Nick\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-30 18:37]
.
2011-08-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4215053619-1285209441-3098757345-1001UA.job
- c:\users\Nick\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-30 18:37]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
d:\program files (x86)\Hotspot Shield\HssIE\HssIE_64.dll [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184]
"EvtMgr6"="d:\program files\Logitech\SetPointP\SetPoint.exe" [2011-06-23 1744152]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = http=
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\0jvkwx1e.default\
FF - prefs.js: browser.search.selectedEngine - Facemoods Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sg/
FF - prefs.js: network.proxy.http - 89.74.147.143
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\DRIVER_B]
"ImagePath"="\??\c:\windows\system32\Drivers\DRIVER_BIN64"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-4215053619-1285209441-3098757345-1001\Software\G*e*n*i*e*"!\FM Genie Scout 10]
"GameDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2010\\games"
"ShortlistDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2010\\shortlists"
"ScreenshotsDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2010"
"SaveDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2010\\"
"HistoryDir"="c:\\Users\\Nick\\Desktop\\FM Genie Scout 10\\History Points"
"LangDB"="d:\\Program Files (x86)\\Sports Interactive\\Football Manager 2010\\data\\db\\1000\\lang_db.dat"
"LastSaveGame"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2011\\games\\lfc v1.fm"
"Language"="English"
"LoadLangDB"=dword:00000001
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000032
"GraphStep"=dword:00000000
"SkinName"="Steklo Black"
"LastUpdateCheck"=dword:00009e28
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:00000074
"UniqueID"="95-EC80-E32F"
"Currency"=dword:00000056
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""
.
[HKEY_USERS\S-1-5-21-4215053619-1285209441-3098757345-1001\Software\G*e*n*i*e*"!\FM Genie Scout 11]
"GameDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2011\\games"
"ShortlistDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2011\\shortlists"
"FMPath"="d:\\Program Files (x86)\\Sports Interactive\\Football Manager 2011\\"
"ScreenshotsDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2011"
"SaveDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2011\\"
"HistoryDir"="d:\\FM Genie Scout 11\\History Points"
"LangDB"="d:\\Program Files (x86)\\Sports Interactive\\Football Manager 2011\\data\\updates\\update-1120\\db\\1120\\lang_db.dat"
"LastSaveGame"=""
"Language"="English"
"LoadLangDB"=dword:00000001
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000050
"GraphStep"=dword:00000000
"SkinName"="PSV Eindhoven"
"LastUpdateCheck"=dword:00009e80
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:00000080
"UniqueID"="95-EC80-E32F"
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""
"Currency"=dword:00000056
"PlayerSearchFeatureNum"=dword:00000008
"StaffSearchFeatureNum"=dword:00000001
"ClubSearchFeatureNum"=dword:00000000
"FilterByClubFeatureNum"=dword:00000001
"CompareFeatureNum"=dword:00000000
"ShortlistFeatureNum"=dword:00000000
"ExportFeatureNum"=dword:00000000
"HistoryFeatureNum"=dword:00000000
"LanguageDBFeatureNum"=dword:00000008
"HintsFeatureNum"=dword:00000000
"GenieReportFeatureNum"=dword:00000005
"TopFormationFeatureNum"=dword:00000000
"ScreenshotFeatureNum"=dword:00000000
.
[HKEY_USERS\S-1-5-21-4215053619-1285209441-3098757345-1001\Software\G*e*n*i*e*"!\FM Genie Scout 11g]
"PicturesNumber"=dword:00000000
.
[HKEY_USERS\S-1-5-21-4215053619-1285209441-3098757345-1001\Software\SecuROM\License information*]
"datasecu"=hex:f0,0b,40,7f,01,28,89,0e,ce,ca,e0,e2,7b,f6,e9,ee,cd,f5,f7,9b,e2,
31,83,d5,b4,63,91,f2,e0,26,e6,a7,e5,8a,80,dc,e2,91,e3,81,e6,71,9b,10,b1,a7,\
"rkeysecu"=hex:97,a2,9a,da,51,31,f3,fc,a9,3b,ea,1c,77,81,49,ac
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\ProgramData\\ESET\\ESET NOD32 Antivirus\\"
"DataDir"="ESET\\ESET NOD32 Antivirus\\"
"EditionName"=" "
"InstallDir"="d:\\Program Files\\ESET\\ESET NOD32 Antivirus\\"
"LanguageId"=dword:00000409
"PackageTag"=dword:6090e758
"ProductBase"=dword:00000000
"ProductCode"="{DD83A4D4-745F-4B69-94BA-FF1E1CCC03D1}"
"ProductName"="ESET NOD32 Antivirus"
"ProductType"="eav"
"ProductVersion"="4.2.42.0"
"UniqueId"="0BA29B714C57E7DB"
"ScannerBuild"=dword:00001ab4
"ScannerVersionId"=dword:00001377
"ScannerVersion"="Open window for status."
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
d:\program files (x86)\IObit\Advanced SystemCare 4\PMonitor.exe
d:\program files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
.
**************************************************************************
.
Completion time: 2011-08-22 11:44:18 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-22 03:44
ComboFix2.txt 2011-08-21 18:53
.
Pre-Run: 28,603,846,656 bytes free
Post-Run: 28,548,063,232 bytes free
.
- - End Of File - - CC488A29A8308F61189F831D75E4C07A

#9 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:04 PM

Posted 24 August 2011 - 05:13 PM

Greetings

Good That cleaned up some bad guys but I see some other stuff that we need to go after, so I want you to run this custom script for me.

:Run CFScript:

Open Notepad and copy/paste the text in the box into the window:

FireFox::
FF - ProfilePath - c:\users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\0jvkwx1e.default\
FF - prefs.js: browser.search.selectedEngine - Facemoods Search
FF - prefs.js: network.proxy.http - 89.74.147.143


Save it to your desktop as CFScript.txt

Refering to the picture above, drag CFScript.txt into ComboFix.exe
Posted Image
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

"information and logs"

  • In your next post I need the following

  • report from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now after running the script?

Gringo

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#10 berlok

berlok
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:04 AM

Posted 24 August 2011 - 05:58 PM

ComboFix 11-08-24.06 - Nick 08/25/2011 7:00.3.2 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.4094.2795 [GMT 8:00]
Running from: c:\users\Nick\Downloads\ComboFix.exe
Command switches used :: c:\users\Nick\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2011-07-24 to 2011-08-24 )))))))))))))))))))))))))))))))
.
.
2011-08-24 23:03 . 2011-08-24 23:05 -------- d-----w- c:\users\Nick\AppData\Local\temp
2011-08-24 23:03 . 2011-08-24 23:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-24 05:39 . 2011-07-09 05:14 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-24 05:39 . 2011-07-09 04:30 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-08-22 03:54 . 2011-08-22 03:54 -------- d-----w- c:\windows\system32\SPReview
2011-08-17 10:40 . 2011-08-17 10:40 -------- d-----w- c:\users\Nick\AppData\Local\Locktime
2011-08-17 10:39 . 2011-08-17 10:39 -------- d-----w- c:\program files (x86)\Linksys Wireless-G USB Wireless Network Monitor
2011-08-17 10:36 . 2011-08-17 10:36 -------- d-----w- c:\programdata\Locktime
2011-08-17 10:07 . 2011-08-17 10:07 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
2011-08-12 03:53 . 2011-08-12 03:53 -------- d-----w- c:\programdata\ATI
2011-08-12 03:52 . 2011-08-12 03:52 -------- d-----w- c:\program files (x86)\AMD APP
2011-08-12 03:52 . 2011-08-12 03:52 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2011-08-12 03:52 . 2011-08-12 03:52 -------- d-----w- c:\program files (x86)\ATI Technologies
2011-08-12 03:51 . 2011-08-12 03:51 -------- d-----w- c:\program files\Common Files\ATI Technologies
2011-08-12 03:49 . 2011-08-12 03:49 -------- d-----w- c:\program files\ATI
2011-08-12 03:38 . 2011-08-12 03:38 -------- d-----w- c:\program files\CCleaner
2011-08-11 09:55 . 2011-08-11 09:55 388096 ----a-r- c:\users\Nick\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-08-10 12:36 . 2011-07-09 02:44 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-10 12:35 . 2011-06-21 06:27 1896832 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-10 10:40 . 2011-08-10 10:40 53248 ----a-r- c:\users\Nick\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-08-10 10:40 . 2011-08-10 10:40 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd
2011-08-10 10:40 . 2011-08-10 10:40 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-08-10 10:39 . 2011-08-10 10:40 -------- d-----w- c:\programdata\Logishrd
2011-08-10 10:38 . 2011-08-10 10:40 -------- d-----w- c:\program files\Common Files\LogiShrd
2011-08-10 10:38 . 2011-08-10 10:40 -------- d-----w- c:\users\Nick\AppData\Roaming\Logitech
2011-08-10 10:38 . 2011-08-10 10:38 -------- d-----w- c:\users\Nick\AppData\Roaming\Logishrd
2011-08-09 19:04 . 2011-06-15 09:58 212992 ----a-w- c:\windows\system32\odbctrac.dll
2011-08-08 14:42 . 2011-08-08 14:42 0 ----a-w- c:\windows\ativpsrm.bin
2011-08-08 14:39 . 2009-05-11 21:35 118784 ----a-w- c:\windows\system32\atibtmon.exe
2011-08-08 08:05 . 2011-08-08 08:05 -------- d-----w- C:\$AVG
2011-08-08 08:00 . 2011-08-08 08:00 -------- d-----w- c:\programdata\IObit
2011-08-08 07:59 . 2011-08-08 07:59 -------- d-----w- c:\users\Nick\AppData\Roaming\IObit
2011-08-08 07:42 . 2011-08-08 07:42 -------- d-----w- c:\users\Nick\AppData\Roaming\AVG10
2011-08-08 07:41 . 2011-08-08 07:41 -------- d--h--w- c:\programdata\Common Files
2011-08-08 07:41 . 2011-08-08 07:41 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2011-08-08 07:40 . 2011-08-16 10:56 -------- d-----w- c:\windows\system32\drivers\AVG
2011-08-08 07:40 . 2011-08-08 07:42 -------- d-----w- c:\programdata\AVG10
2011-08-08 07:14 . 2011-08-08 07:14 60416 ----a-w- c:\windows\system32\OVDecode64.dll
2011-08-08 07:14 . 2011-08-08 07:14 53760 ----a-w- c:\windows\SysWow64\OVDecode.dll
2011-08-08 07:14 . 2011-08-08 07:14 16552960 ----a-w- c:\windows\system32\amdocl64.dll
2011-08-08 07:14 . 2011-08-08 07:14 13555200 ----a-w- c:\windows\SysWow64\amdocl.dll
2011-08-08 03:31 . 2011-07-06 11:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-07 21:02 . 2011-08-07 21:02 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-08-07 20:58 . 2011-08-07 20:58 -------- d-----w- c:\windows\system32\EventProviders
2011-08-07 20:51 . 2011-08-07 20:51 -------- d-----w- C:\7e5f84440d0e56b1456e2f8523a7da
2011-08-07 20:16 . 2011-08-07 20:16 -------- d-----w- c:\users\Nick\AppData\Roaming\QuickScan
2011-08-07 20:16 . 2011-08-16 21:59 -------- d-----w- c:\program files\Common Files\BitDefender
2011-08-07 20:16 . 2011-08-16 21:56 64534 ----a-w- c:\programdata\bdinstall.bin
2011-08-07 19:58 . 2011-08-08 07:42 -------- d-----w- c:\programdata\MFAData
2011-08-07 19:55 . 2011-08-07 19:55 -------- d-----w- c:\users\Nick\AppData\Roaming\Malwarebytes
2011-08-07 19:55 . 2011-08-07 19:55 -------- d-----w- c:\programdata\Malwarebytes
2011-08-07 19:55 . 2011-07-06 11:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-02 18:31 . 2011-08-02 18:31 -------- d-----w- c:\program files (x86)\Google
2011-07-30 09:08 . 2011-07-30 09:08 -------- d-----w- c:\users\Nick\AppData\Local\The Witcher 2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-08 18:31 . 2010-08-26 01:27 58880 ----a-w- c:\windows\system32\coinst.dll
2011-07-16 04:32 . 2011-08-09 19:04 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-13 04:53 . 2011-07-31 20:41 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FFB6EACC-DFE4-4B8D-8F41-975CD46DF893}\mpengine.dll
2011-07-12 17:41 . 2011-05-20 10:16 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-07 15:37 . 2011-07-07 15:37 51200 ----a-w- c:\windows\system32\OpenCL.dll
2011-06-27 08:23 . 2011-06-27 08:23 43520 ----a-w- c:\windows\SysWow64\OpenCL.dll
2011-06-15 19:34 . 2011-06-15 19:34 79872 ----a-w- c:\windows\SysWow64\SlotMaximizerAg.dll
2011-06-15 19:34 . 2011-06-15 19:34 2971648 ----a-w- c:\windows\system32\SlotMaximizerBe.dll
2011-06-15 19:34 . 2011-06-15 19:34 2117632 ----a-w- c:\windows\SysWow64\SlotMaximizerBe.dll
2011-06-15 19:34 . 2011-06-15 19:34 105984 ----a-w- c:\windows\system32\SlotMaximizerAg.dll
2011-06-11 02:56 . 2011-07-13 01:58 3134464 ----a-w- c:\windows\system32\win32k.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-19 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2010-04-30 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7600.16385] .. c:\windows\system32\user32.dll
.
[7] 2010-11-19 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[-] 2010-04-30 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7600.16385] .. c:\windows\SysWOW64\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-08-21_18.48.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-25 16:00 . 2011-08-22 04:06 43196 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-08-22 04:06 34982 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:30 . 2011-08-17 10:36 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2009-07-14 05:30 . 2011-08-22 04:04 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2009-10-26 05:52 . 2011-08-22 22:03 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-26 05:52 . 2011-08-16 13:16 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-26 05:52 . 2011-08-16 13:16 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-10-26 05:52 . 2011-08-22 22:03 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-08-22 22:03 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-08-16 13:16 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-08-24 05:39 . 2011-07-09 05:16 49664 c:\windows\servicing\GC64\tzupd.exe
- 2010-02-24 10:41 . 2010-02-02 08:39 49664 c:\windows\servicing\GC64\tzupd.exe
+ 2009-10-25 15:00 . 2011-08-22 04:06 9068 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4215053619-1285209441-3098757345-1001_UserData.bin
- 2011-08-21 18:48 . 2011-08-21 18:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-08-24 23:05 . 2011-08-24 23:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-08-24 23:05 . 2011-08-24 23:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-08-21 18:48 . 2011-08-21 18:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-08-22 03:54 . 2011-08-22 03:54 263168 c:\windows\system32\SPReview\spwizui.dll
- 2011-08-10 20:12 . 2011-08-10 20:12 263168 c:\windows\system32\SPReview\spwizui.dll
- 2011-08-10 20:12 . 2011-08-10 20:12 301568 c:\windows\system32\SPReview\spreview.exe
+ 2011-08-22 03:54 . 2011-08-22 03:54 301568 c:\windows\system32\SPReview\spreview.exe
+ 2011-08-22 03:54 . 2011-08-22 03:54 238592 c:\windows\system32\SPReview\sperror.dll
- 2011-08-10 20:12 . 2011-08-10 20:12 238592 c:\windows\system32\SPReview\sperror.dll
+ 2009-07-14 02:36 . 2011-08-22 03:40 648004 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-08-22 03:40 118180 c:\windows\system32\perfc009.dat
+ 2009-07-14 05:30 . 2011-08-22 04:04 143360 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2011-08-17 10:36 143360 c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2011-08-22 04:04 143360 c:\windows\system32\DriverStore\infstor.dat
- 2009-07-14 05:30 . 2011-08-17 10:36 143360 c:\windows\system32\DriverStore\infstor.dat
+ 2009-07-14 05:01 . 2011-08-24 23:04 437660 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2011-08-21 18:47 437660 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 02:34 . 2011-08-24 19:10 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat
- 2009-07-14 02:34 . 2011-08-11 10:41 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2009-10-31 18:30 . 2011-08-24 23:04 37860784 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4215053619-1285209441-3098757345-1001-12288.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256]
"AtiTrayTools"="d:\program files (x86)\Ray Adams\ATI Tray Tools\atitray.exe" [2011-03-27 929280]
"NetLimiter"="d:\program files\NetLimiter 3\NLClientApp.exe" [2011-03-21 2910208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="d:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-08-08 336384]
"PlusService"="d:\program files (x86)\Yuna Software\Messenger Plus!\PlusService.exe" [2011-05-26 800768]
"AVG_TRAY"="d:\program files (x86)\AVG\AVG10\avgtray.exe" [2011-04-18 2334560]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ d:\progra~1\AVG\AVG10\avgchsva.exe /sync\0d:\progra~1\AVG\AVG10\avgrsa.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R3 AdvancedSystemCareService;Advanced SystemCare Service;d:\program files (x86)\IObit\Advanced SystemCare 4\ASCService.exe [2011-06-02 353168]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x]
R3 BFBackupUtilityService;Backup Utility Service;c:\program files (x86)\BUFFALO\Backup_Utility\BUService.exe [2010-08-20 320888]
R3 BFBackupUtilityVSSService;Backup Utility VSS Service;c:\program files (x86)\BUFFALO\Backup_Utility\BUVSSService64.exe [2010-04-28 359288]
R3 bftpusbx64;BUFFALO TurboPC USB Filter;c:\windows\system32\drivers\bftpusbx64.sys [x]
R3 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-02-23 16776]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-02-23 9096]
R3 GGSAFERDriver;GGSAFER Driver;d:\program files (x86)\Garena\safedrv.sys [x]
R3 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;d:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-08-04 2329480]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys [x]
R3 Neo_PacketiX;VPN Client Device Driver - PacketiX;c:\windows\system32\DRIVERS\Neo_0116.sys [x]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [x]
R3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\DRIVERS\nlndis.sys [x]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [x]
R3 tapoas;TAP-Win32 Adapter OAS;c:\windows\system32\DRIVERS\tapoas.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 vpnclient;PacketiX VPN Client;d:\program files\PacketiX VPN Client 64-bit Edition English\vpnclient_x64.exe [2008-05-15 4601344]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
R4 AVGIDSAgent;AVGIDSAgent;d:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-04-18 7398752]
R4 avgwd;AVG WatchDog;d:\program files (x86)\AVG\AVG10\avgwdsvc.exe [2011-02-07 269520]
R4 TunngleService;TunngleService;d:\program files (x86)\Tunngle\TnglCtrl.exe [2010-07-06 716024]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x]
S0 BFRD4G;BUFFALO RAM Disk Driver;c:\windows\system32\DRIVERS\BFRD4G.sys [x]
S0 bftpdskc64;BUFFALO TurboPC Cache Filter;c:\windows\system32\drivers\bftpdskc64.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x]
S1 nltdi;nltdi;d:\program files\NetLimiter 3\nltdi.sys [2011-03-21 88200]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 NLNdisMP;NLNdisMP;c:\windows\system32\DRIVERS\nlndis.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S4 DRIVER_B;DRIVER_B;c:\windows\system32\Drivers\DRIVER_BIN64 [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4215053619-1285209441-3098757345-1001Core.job
- c:\users\Nick\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-30 18:37]
.
2011-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4215053619-1285209441-3098757345-1001UA.job
- c:\users\Nick\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-30 18:37]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
d:\program files (x86)\Hotspot Shield\HssIE\HssIE_64.dll [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184]
"EvtMgr6"="d:\program files\Logitech\SetPointP\SetPoint.exe" [2011-06-23 1744152]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = http=
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\0jvkwx1e.default\
FF - prefs.js: browser.search.selectedEngine - Facemoods Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sg/
FF - prefs.js: network.proxy.http - 89.74.147.143
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\DRIVER_B]
"ImagePath"="\??\c:\windows\system32\Drivers\DRIVER_BIN64"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-4215053619-1285209441-3098757345-1001\Software\G*e*n*i*e*"!\FM Genie Scout 10]
"GameDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2010\\games"
"ShortlistDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2010\\shortlists"
"ScreenshotsDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2010"
"SaveDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2010\\"
"HistoryDir"="c:\\Users\\Nick\\Desktop\\FM Genie Scout 10\\History Points"
"LangDB"="d:\\Program Files (x86)\\Sports Interactive\\Football Manager 2010\\data\\db\\1000\\lang_db.dat"
"LastSaveGame"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2011\\games\\lfc v1.fm"
"Language"="English"
"LoadLangDB"=dword:00000001
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000032
"GraphStep"=dword:00000000
"SkinName"="Steklo Black"
"LastUpdateCheck"=dword:00009e28
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:00000074
"UniqueID"="95-EC80-E32F"
"Currency"=dword:00000056
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""
.
[HKEY_USERS\S-1-5-21-4215053619-1285209441-3098757345-1001\Software\G*e*n*i*e*"!\FM Genie Scout 11]
"GameDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2011\\games"
"ShortlistDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2011\\shortlists"
"FMPath"="d:\\Program Files (x86)\\Sports Interactive\\Football Manager 2011\\"
"ScreenshotsDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2011"
"SaveDir"="c:\\Users\\Nick\\Documents\\Sports Interactive\\Football Manager 2011\\"
"HistoryDir"="d:\\FM Genie Scout 11\\History Points"
"LangDB"="d:\\Program Files (x86)\\Sports Interactive\\Football Manager 2011\\data\\updates\\update-1120\\db\\1120\\lang_db.dat"
"LastSaveGame"=""
"Language"="English"
"LoadLangDB"=dword:00000001
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000050
"GraphStep"=dword:00000000
"SkinName"="PSV Eindhoven"
"LastUpdateCheck"=dword:00009e80
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:00000080
"UniqueID"="95-EC80-E32F"
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""
"Currency"=dword:00000056
"PlayerSearchFeatureNum"=dword:00000008
"StaffSearchFeatureNum"=dword:00000001
"ClubSearchFeatureNum"=dword:00000000
"FilterByClubFeatureNum"=dword:00000001
"CompareFeatureNum"=dword:00000000
"ShortlistFeatureNum"=dword:00000000
"ExportFeatureNum"=dword:00000000
"HistoryFeatureNum"=dword:00000000
"LanguageDBFeatureNum"=dword:00000008
"HintsFeatureNum"=dword:00000000
"GenieReportFeatureNum"=dword:00000005
"TopFormationFeatureNum"=dword:00000000
"ScreenshotFeatureNum"=dword:00000000
.
[HKEY_USERS\S-1-5-21-4215053619-1285209441-3098757345-1001\Software\G*e*n*i*e*"!\FM Genie Scout 11g]
"PicturesNumber"=dword:00000000
.
[HKEY_USERS\S-1-5-21-4215053619-1285209441-3098757345-1001\Software\SecuROM\License information*]
"datasecu"=hex:f0,0b,40,7f,01,28,89,0e,ce,ca,e0,e2,7b,f6,e9,ee,cd,f5,f7,9b,e2,
31,83,d5,b4,63,91,f2,e0,26,e6,a7,e5,8a,80,dc,e2,91,e3,81,e6,71,9b,10,b1,a7,\
"rkeysecu"=hex:97,a2,9a,da,51,31,f3,fc,a9,3b,ea,1c,77,81,49,ac
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\ProgramData\\ESET\\ESET NOD32 Antivirus\\"
"DataDir"="ESET\\ESET NOD32 Antivirus\\"
"EditionName"=" "
"InstallDir"="d:\\Program Files\\ESET\\ESET NOD32 Antivirus\\"
"LanguageId"=dword:00000409
"PackageTag"=dword:6090e758
"ProductBase"=dword:00000000
"ProductCode"="{DD83A4D4-745F-4B69-94BA-FF1E1CCC03D1}"
"ProductName"="ESET NOD32 Antivirus"
"ProductType"="eav"
"ProductVersion"="4.2.42.0"
"UniqueId"="0BA29B714C57E7DB"
"ScannerBuild"=dword:00001ab4
"ScannerVersionId"=dword:00001377
"ScannerVersion"="Open window for status."
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
d:\program files (x86)\IObit\Advanced SystemCare 4\PMonitor.exe
d:\program files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
.
**************************************************************************
.
Completion time: 2011-08-25 07:10:07 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-24 23:10
ComboFix2.txt 2011-08-22 03:44
ComboFix3.txt 2011-08-21 18:53
.
Pre-Run: 28,170,326,016 bytes free
Post-Run: 28,120,985,600 bytes free
.
- - End Of File - - 5F82EEE5E22E9D2A9D386D1A6B737F68

Edited by berlok, 24 August 2011 - 06:12 PM.


#11 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:04 PM

Posted 24 August 2011 - 08:14 PM

Hello

I would ike to see a report that combofix makes.

extra combofix report

  • push the "windows key" + "R" (between the "Ctrl" button and "Alt" Button)
  • please copy and past the following into the box
C:\Qoobox\Add-Remove Programs.txt
  • click ok

copy and paste the report into this topic for me to review

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#12 berlok

berlok
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:04 AM

Posted 24 August 2011 - 10:15 PM

Update for Microsoft Office 2007 (KB2508958)
"Nero SoundTrax Help
µTorrent
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X (10.1.0)
Adobe Shockwave Player 11.5
Advanced SystemCare 4
Advertising Center
Apple Application Support
Apple Software Update
Assassin's Creed Brotherhood
Assassin's Creed II
AviSynth 2.5
BUFFALO Backup Utility
BUFFALO BuffaloTools Launcher
BUFFALO TurboCopy
BUFFALO TurboPC for FLASH/HDD
Bulletstorm
calibre
Call of Duty Modern Warfare 2
Call of Duty: Black Ops
Catalyst Control Center
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Combined Community Codec Pack 2010-10-10
D3DX10
DAEMON Tools Toolbar
DivX Setup
DolbyFiles
Dragon Age II
Driver Sweeper version 2.9.0
EASEUS Partition Master 5.5.1 Professional
EOSInfo
eReg
Fable III
ffdshow [rev 1723] [2007-12-24]
FINAL FANTASY XIV
FlashGet(JetCar)
FM Genie Scout 11 version 1.00 beta 2
Football Manager 2011
Foxit Reader
Garena - Heroes of Newerth
Garena - League of Legends
Garena 2010
Garena Messenger
Google Chrome
HiJackThis
HydraVision
ImagXpress
Japanese Fonts Support For Adobe Reader 9
Java Auto Updater
Java™ 6 Update 26
JDownloader 0.9
League of Legends
Linksys Wireless-G USB Network Adapter
Logitech Touch Mouse Server 1.0
LogMeIn Hamachi
LOST PLANET 2
Malwarebytes' Anti-Malware version 1.51.1.1800
Menu Templates - Starter Kit
Messenger Plus! 5
Microsoft .NET Framework 1.1
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Movie Templates - Starter Kit
Mozilla Firefox 4.0b10 (x86 en-US)
Mozilla Firefox 6.0 (x86 en-US)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 9
Nero BurningROM
Nero BurnRights
Nero ControlCenter
Nero CoverDesigner
Nero CoverDesigner Help
Nero Disc Copy Gadget
Nero Disc Copy Gadget Help
Nero DiscSpeed
Nero DriveSpeed
Nero Express
Nero InfoTool
Nero Installer
Nero PhotoSnap
Nero PhotoSnap Help
Nero Recode
Nero Recode Help
Nero Rescue Agent
Nero RescueAgent Help
Nero ShowTime
Nero StartSmart
Nero StartSmart Help
Nero Vision
Nero WaveEditor
Nero WaveEditor Help
NeroBurningROM
NeroExpress
neroxml
Notepad++
NVIDIA PhysX
OpenAL
OpenOffice.org 3.2
Opera 11.10
Picasa 3
PingPlotter Freeware
Pro Evolution Soccer 2010
Pro Evolution Soccer 2011
QuickTime
Rapture3D 2.3.22 Game
Ray Adams ATI Tray Tools
Safari
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2509488)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft Office 2007 System (KB2541012)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2541007)
Security Update for Microsoft Office Groove 2007 (KB2494047)
Security Update for Microsoft Office InfoPath 2007 (KB2510061)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Skype™ 5.3
SoundTrax
Steam
Team Fortress 2
The Witcher 2
Tunngle beta
Ubisoft Game Launcher
Update for 2007 Microsoft Office System (KB2284654)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2509470)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (KB2586924)
VC80CRTRedist - 8.0.50727.4053
Veetle TV 0.9.18
Visual Studio 2008 x64 Redistributables
VLC media player 1.1.9
vShare Plugin
Watson
Winamp
Winamp Detector Plug-in
Windows Live Communications Platform
Windows Live Device Manager
Windows Live Essentials
Windows Live Installer
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Media Player Firefox Plugin

#13 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:04 PM

Posted 24 August 2011 - 11:25 PM

Hello


that looks very good



Clear your Java Cache

  • click on Start-> Control Panel (Classic View)-> Java (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH Checked
      Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.

TFC(Temp File Cleaner):

  • Please download TFC to your desktop,
  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • If prompted, click "Yes" to reboot.
Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds. Only if needed will you be prompted to reboot.

: Malwarebytes' Anti-Malware :

  • I would like you to rerun MBAM
  • Double-click mbam icon
  • go to the update tab at the top
  • click on check for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is Checked (ticked) except items in the C:\System Volume Information folder and click on Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply
  • If you accidently close it, the log file is saved here and will be named like this:
  • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


Download HijackThis

  • Go Here to download HijackThis Installer
  • Save HijackThis Installer to your desktop.
  • Double-click on the HijackThis Installer icon on your desktop. (Vista and Win 7 right click and run as admin)
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed it will launch Hijackthis.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on Edit > Select All then click on Edit > Copy to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT use the AnalyseThis button its findings are dangerous if misinterpreted.
  • DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

If you have problems running Hijackthis.

sometimes we have to run it like this To run HijackThis as an administrator,
rightclick HijackThis.exe (located: C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe)
and select to run as administrator

"information and logs"

  • In your next post I need the following

  • Log From MBAM
  • report from Hijackthis
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#14 berlok

berlok
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:04 AM

Posted 25 August 2011 - 01:15 AM

Malware Log


Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7560

Windows 6.1.7600
Internet Explorer 9.0.8112.16421

8/25/2011 2:12:20 PM
mbam-log-2011-08-25 (14-12-20).txt

Scan type: Full scan (C:\|D:\|F:\|)
Objects scanned: 645658
Time elapsed: 1 hour(s), 2 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

HJT Log


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:13:32 PM, on 8/25/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
D:\Program Files (x86)\Ray Adams\ATI Tray Tools\atitray.exe
D:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe
D:\Program Files (x86)\AVG\AVG10\avgtray.exe
D:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
D:\Program Files (x86)\GarenaHoN\GameData\GarenaMessenger.exe
D:\Program Files (x86)\GarenaHoN\GameData\Apps\HoN\hon.exe
C:\Users\Nick\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
D:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [PlusService] D:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe
O4 - HKLM\..\Run: [AVG_TRAY] D:\Program Files (x86)\AVG\AVG10\avgtray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [AtiTrayTools] "D:\Program Files (x86)\Ray Adams\ATI Tray Tools\atitray.exe"
O4 - HKCU\..\Run: [NetLimiter] D:\Program Files\NetLimiter 3\NLClientApp.exe /tray
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} (IBM Lotus iNotes 8.5 Control) - https://www.sianet.com.sg/,DanaInfo=SINCCBLMSXP02.sq.com.sg,ST=1+/dwa85W.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files (x86)\AVG\AVG10\avgpp.dll
O18 - Protocol: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - D:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: Backup Utility Service (BFBackupUtilityService) - BUFFALO INC. - C:\Program Files (x86)\BUFFALO\Backup_Utility\BUService.exe
O23 - Service: Backup Utility VSS Service (BFBackupUtilityVSSService) - BUFFALO INC. - C:\Program Files (x86)\BUFFALO\Backup_Utility\BUVSSService64.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NetLimiter 3 Service (nlsvc) - Locktime Software - D:\Program Files\NetLimiter 3\nlsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Software Protection (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: PacketiX VPN Client (vpnclient) - SoftEther Corporation - D:\Program Files\PacketiX VPN Client 64-bit Edition English\vpnclient_x64.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 8487 bytes

#15 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:04 PM

Posted 25 August 2011 - 02:09 AM

Greetings

These logs are looking very good, we are almost done!!! Just one more scan to go.

:Remove unneeded startup entries:

This part of the fix is purely optional
These are programs that start up when you turn on your computer but don't need to be, any of these programs you can click on their icons (or start from the control panel) and start the program when you need it. By stopping these programs you will boot up faster and your computer will work faster.

  • Run HijackThis
  • Click on the Scan button
  • Put a check beside all of the items listed below (if present):

    • O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
      O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
      O4 - HKLM\..\Run: [PlusService] D:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [AtiTrayTools] "D:\Program Files (x86)\Ray Adams\ATI Tray Tools\atitray.exe"
      O4 - HKCU\..\Run: [NetLimiter] D:\Program Files\NetLimiter 3\NLClientApp.exe /tray
  • Close all open windows and browsers/email, etc...
  • Click on the "Fix Checked" button
  • When completed, close the application.

    NOTE**You can research each of those lines >here< and see if you want to keep them or not
    just copy the name between the brakets and paste into the search space
    O4 - HKLM\..\Run: [IntelliPoint]



If you have any problems running Hijackthis.

sometimes we have to run it like this To run HijackThis as an administrator,
rightclick HijackThis.exe (located: C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe)
and select to run as administrator


Eset Online Scanner

**Note** You will need to use Internet explorer for this scan - Vista and win 7 right click on IE shortcut and run as admin

Go Eset web page to run an online scannner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • click on the ESET Online Scanner button
  • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
  • When asked, allow the activex control to install
    • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options
    Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Click on copy to clipboard and paste the results here in this topic
  • you may also find here C:\Program Files\Eset\Eset Online Scanner\log.txt
Copy and paste that log as a reply to this topic

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users