Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Stop c000135 error


  • This topic is locked This topic is locked
14 replies to this topic

#1 DigitalKirin

DigitalKirin

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:36 PM

Posted 13 November 2011 - 02:55 AM

Hello,

First time poster here. I saw that several people on this forum have had the same stop error and almost the exact same scenario, so I am hopeful that I will find help here.

I am assisting a friend with a Windows 7 box. He was constantly being redirected in his browsers. After running TDSSKiller from Kaspersky and then installing Avira and running that as well, I noticed several updates waiting to be installed, one of which seems to have been SP1.

After the install, it rebooted, however, I am now getting BSOD with the error: STOP c0000135 The program can't start because %hs is missing from your computer. Try reinstalling the program to fix the problem.

---
I am about to run the Farbar Recovery Scan Tool that seems to be recommended by one of the Malware Response Team. I will post the txt file in the hopes that it will help expedite the process.

BC AdBot (Login to Remove)

 


#2 DigitalKirin

DigitalKirin
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:36 PM

Posted 13 November 2011 - 03:04 AM

Also, thank you in advance to whoever is able to help me! :)


Scan result of Farbars's Recovery Tool (FRST written by farbar) Version 2.2.7
Ran by SYSTEM at 2011-11-12 19:02:04
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry (Whitelisted) =============

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11464296 2010-09-03] (Realtek Semiconductor)
HKLM\...\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun [825184 2009-09-30] (Microsoft Corporation)
HKLM-x32\...\Run: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start [81920 2005-02-17] (InstallShield Software Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [35736 2011-01-30] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [932288 2010-11-10] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [D-Link D-Link DWA-125] C:\Program Files (x86)\D-Link\DWA-125 revA\AirGCFG.exe [995328 2009-10-19] (D-Link Corp.)
HKLM-x32\...\Run: [WZCSLDR2] C:\Program Files (x86)\D-Link\DWA-125 revA\WZCSLDR2.exe [122880 2009-10-19] (Wireless Service)
HKLM-x32\...\Run: [AmazonGSDownloaderTray] C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe [326144 2009-10-23] (Amazon.com)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [248552 2010-05-14] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [258512 2011-10-05] (Avira Operations GmbH & Co. KG)
HKU\Matthew Zounes\...\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup [221184 2005-02-17] (InstallShield Software Corporation)
HKU\Matthew Zounes\...\Run: [Google Update] "C:\Users\Matthew Zounes\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-04-13] (Google Inc.)
HKU\Matthew Zounes\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized [15146376 2011-04-18] (Skype Technologies S.A.)
HKU\Matthew Zounes\...\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent [1242448 2011-08-11] (Valve Corporation)
HKU\Matthew Zounes\...\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5495680 2011-11-11] (SUPERAntiSpyware.com)
HKLM\...\RunOnce: [RPMKickstart] C:\Program Files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe [2552320 2010-08-23] (Gigabyte Technology CO., LTD.)
HKLM\...\RunOnce: [*Restore] C:\Windows\system32\rstrui.exe /RUNONCE [296960 2009-07-13] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.1.1
SubSystems: [Windows] ==> ZeroAccess

==================== Services (Whitelisted) ======

2 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE" [140672 2011-08-11] (SUPERAntiSpyware.com)
2 Amazon Download Agent; C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [401920 2009-10-23] (Amazon.com)
2 AntiVirSchedulerService; "C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe" [86224 2011-10-05] (Avira Operations GmbH & Co. KG)
2 AntiVirService; "C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe" [110032 2011-10-05] (Avira Operations GmbH & Co. KG)
3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
2 D_Link_DWA-125; C:\Program Files (x86)\D-Link\DWA-125 revA\ANIWZCSdS.exe [126976 2009-08-21] (Wireless Service)
2 D_Link_DWA-125_WPS; C:\Program Files (x86)\D-Link\DWA-125 revA\ANIWConnService.exe [40960 2009-07-07] ()
3 IDriverT; "C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" [69632 2005-04-03] (Macrovision Corporation)
2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.)

========================== Drivers (Whitelisted) =============

1 anodlwf; C:\Windows\System32\DRIVERS\anodlwfx.sys [15872 2009-03-06] ()
1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21544 2010-04-27] ()
2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [97312 2011-09-15] (Avira GmbH)
1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130760 2011-09-18] (Avira GmbH)
1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [27760 2011-09-15] (Avira GmbH)
3 gdrv; \??\C:\Windows\gdrv.sys [25640 2011-11-11] (Windows ® Server 2003 DDK provider)
3 GVTDrv64; \??\C:\Windows\GVTDrv64.sys [30528 2011-04-13] ()
3 netr28ux; C:\Windows\System32\DRIVERS\Dnetr28ux.sys [1061888 2009-09-15] (Ralink Technology Corp.)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
3 V0520Vid; C:\Windows\System32\DRIVERS\V0520Vid.sys [283648 2010-09-15] (Creative Technology Ltd.)

========================== NetSvcs (Whitelisted) ===========

============ One Month Created Files and Folders ==============

2011-11-12 16:37 - 2011-11-12 16:56 - 0000000 ____D C:\Users\All Users\Recovery
2011-11-12 16:37 - 2011-11-12 16:56 - 0000000 ____D C:\ProgramData\Recovery
2011-11-11 22:31 - 2011-11-12 03:35 - 0000000 ____D C:\5ae30d54baaa1570f0ba87
2011-11-11 22:31 - 2011-11-11 22:31 - 0000000 ____D C:\Windows\System32\EventProviders
2011-11-11 22:29 - 2011-10-27 23:05 - 52174280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2011-11-11 22:27 - 2011-11-11 22:28 - 0074178 ____A C:\TDSSKiller.2.6.18.0_11.11.2011_22.27.38_log.txt
2011-11-11 22:25 - 2011-11-11 22:27 - 2562040 ____A (Symantec Corporation) C:\Users\Matthew Zounes\Downloads\NPE.exe
2011-11-11 22:01 - 2011-11-12 16:56 - 0389944 ____A C:\Windows\ntbtlog.txt
2011-11-11 21:36 - 2011-11-11 21:36 - 0000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2011-11-11 21:36 - 2011-11-11 21:36 - 0000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2011-11-11 21:26 - 2011-11-11 21:27 - 0002070 ____A C:\Users\Public\Desktop\Avira Control Center.lnk
2011-11-11 21:25 - 2011-09-18 08:39 - 0130760 ____A (Avira GmbH) C:\Windows\System32\Drivers\avipbb.sys
2011-11-11 21:25 - 2011-09-15 23:55 - 0097312 ____A (Avira GmbH) C:\Windows\System32\Drivers\avgntflt.sys
2011-11-11 21:25 - 2011-09-15 23:55 - 0027760 ____A (Avira GmbH) C:\Windows\System32\Drivers\avkmgr.sys
2011-11-11 18:56 - 2011-11-11 18:56 - 0000766 ____A C:\Users\Matthew Zounes\AppData\Roaming\SMRBackup210.dat
2011-11-11 18:52 - 2011-11-11 18:53 - 0074930 ____A C:\TDSSKiller.2.6.18.0_11.11.2011_18.52.08_log.txt
2011-11-11 16:26 - 2011-09-30 21:24 - 9326080 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2011-11-11 16:26 - 2011-09-30 20:42 - 5990912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2011-11-11 16:26 - 2011-09-30 19:21 - 1638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2011-11-11 16:26 - 2011-09-30 18:59 - 1638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2011-11-11 16:26 - 2011-08-19 21:45 - 1197568 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2011-11-11 16:26 - 2011-08-19 21:44 - 1501184 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2011-11-11 16:26 - 2011-08-19 21:44 - 0134144 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2011-11-11 16:26 - 2011-08-19 21:42 - 1026560 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
2011-11-11 16:26 - 2011-08-19 21:41 - 0703488 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2011-11-11 16:26 - 2011-08-19 21:41 - 0097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2011-11-11 16:26 - 2011-08-19 21:41 - 0082944 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2011-11-11 16:26 - 2011-08-19 21:41 - 0064512 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2011-11-11 16:26 - 2011-08-19 21:41 - 0057856 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2011-11-11 16:26 - 2011-08-19 21:40 - 2458624 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2011-11-11 16:26 - 2011-08-19 21:40 - 12370944 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2011-11-11 16:26 - 2011-08-19 21:40 - 0445952 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2011-11-11 16:26 - 2011-08-19 21:40 - 0256000 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2011-11-11 16:26 - 2011-08-19 21:40 - 0256000 ____A (Microsoft Corporation) C:\Windows\System32\iepeers(1544).dll
2011-11-11 16:26 - 2011-08-19 21:40 - 0247808 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2011-11-11 16:26 - 2011-08-19 21:37 - 0012288 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2011-11-11 16:26 - 2011-08-19 20:38 - 1230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2011-11-11 16:26 - 2011-08-19 20:38 - 0981504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2011-11-11 16:26 - 2011-08-19 20:38 - 0132096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2011-11-11 16:26 - 2011-08-19 20:36 - 0606208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll
2011-11-11 16:26 - 2011-08-19 20:35 - 2072576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2011-11-11 16:26 - 2011-08-19 20:35 - 10990080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2011-11-11 16:26 - 2011-08-19 20:35 - 0599552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2011-11-11 16:26 - 2011-08-19 20:35 - 0185856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2011-11-11 16:26 - 2011-08-19 20:35 - 0176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2011-11-11 16:26 - 2011-08-19 20:35 - 0067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2011-11-11 16:26 - 2011-08-19 20:35 - 0064512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2011-11-11 16:26 - 2011-08-19 20:35 - 0048128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2011-11-11 16:26 - 2011-08-19 20:35 - 0044544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2011-11-11 16:26 - 2011-08-19 20:34 - 0381440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2011-11-11 16:26 - 2011-08-19 20:32 - 0012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2011-11-11 16:25 - 2011-08-26 21:40 - 0331776 ____A (Microsoft Corporation) C:\Windows\System32\oleacc.dll
2011-11-11 16:25 - 2011-08-26 20:43 - 0571904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2011-11-11 16:25 - 2011-08-26 20:43 - 0233472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2011-11-11 16:25 - 2011-08-16 21:32 - 0613888 ____A (Microsoft Corporation) C:\Windows\System32\psisdecd.dll
2011-11-11 16:25 - 2011-08-16 21:27 - 0288256 ____A (Microsoft Corporation) C:\Windows\System32\MSNP.ax
2011-11-11 16:25 - 2011-08-16 21:27 - 0108032 ____A (Microsoft Corporation) C:\Windows\System32\psisrndr.ax
2011-11-11 16:25 - 2011-08-16 21:27 - 0104960 ____A (Microsoft Corporation) C:\Windows\System32\Mpeg2Data.ax
2011-11-11 16:25 - 2011-08-16 21:27 - 0075776 ____A (Microsoft Corporation) C:\Windows\System32\MSDvbNP.ax
2011-11-11 16:25 - 2011-08-16 20:26 - 0465408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2011-11-11 16:25 - 2011-08-16 20:22 - 0204288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSNP.ax
2011-11-11 16:25 - 2011-08-16 20:22 - 0075776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2011-11-11 16:25 - 2011-08-16 20:22 - 0072704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Mpeg2Data.ax
2011-11-11 16:25 - 2011-08-16 20:22 - 0059904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSDvbNP.ax
2011-11-11 16:24 - 2011-11-11 16:24 - 0000316 ____A C:\Users\Matthew Zounes\Downloads\TmRCMScanDebug20111111_00.log
2011-11-11 16:13 - 2011-11-11 22:15 - 0000000 ____D C:\Users\All Users\Norton
2011-11-11 16:13 - 2011-11-11 22:15 - 0000000 ____D C:\ProgramData\Norton
2011-11-11 16:13 - 2011-11-11 18:55 - 0000000 ____D C:\Users\Matthew Zounes\AppData\Local\NPE
2011-11-11 15:48 - 2011-11-11 22:27 - 1564976 ____A (Kaspersky Lab ZAO) C:\Users\Matthew Zounes\Downloads\TDSSKiller.exe
2011-11-11 11:52 - 2011-11-11 11:52 - 0000000 ____D C:\Users\Matthew Zounes\AppData\Roaming\Avira
2011-11-11 11:51 - 2011-11-11 21:52 - 0000000 ____D C:\Program Files (x86)\Avira
2011-11-11 11:51 - 2011-11-11 11:51 - 0000000 ____D C:\Users\All Users\Avira
2011-11-11 11:51 - 2011-11-11 11:51 - 0000000 ____D C:\ProgramData\Avira
2011-11-11 11:41 - 2011-11-11 11:41 - 0074952 ____A C:\TDSSKiller.2.6.18.0_11.11.2011_11.41.06_log.txt
2011-11-11 11:36 - 2011-11-11 11:37 - 0075640 ____A C:\TDSSKiller.2.6.18.0_11.11.2011_11.36.46_log.txt
2011-10-19 15:12 - 2011-10-19 15:12 - 0000000 ____D C:\Users\Matthew Zounes\AppData\Roaming\Wilei
2011-10-13 22:03 - 2011-10-13 22:03 - 0013617 ____A C:\Users\Matthew Zounes\Documents\wod 2.docx
2011-10-13 21:49 - 2011-10-13 21:49 - 0000162 ___AH C:\Users\Matthew Zounes\Documents\~$rgianrevised2.docx
2011-10-13 18:21 - 2011-10-13 21:53 - 0027038 ____A C:\Users\Matthew Zounes\Documents\bargianrevised2.docx
2011-10-13 16:24 - 2011-10-13 16:24 - 0026164 ____A C:\Users\Matthew Zounes\Downloads\bargianrevised2.docx
2011-10-13 10:36 - 2011-11-11 19:13 - 0000000 __SHD C:\Windows\SysWOW64\%APPDATA%


============ 3 Months Modified Files and Folders =============

2011-11-12 19:02 - 2011-11-12 19:01 - 0000000 ____D C:\FRST
2011-11-12 16:56 - 2011-11-12 16:37 - 0000000 ____D C:\Users\All Users\Recovery
2011-11-12 16:56 - 2011-11-12 16:37 - 0000000 ____D C:\ProgramData\Recovery
2011-11-12 16:56 - 2011-11-11 22:01 - 0389944 ____A C:\Windows\ntbtlog.txt
2011-11-12 16:56 - 2011-04-14 05:27 - 3208241152 __ASH C:\hiberfil.sys
2011-11-12 15:47 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files (x86)\Windows Portable Devices
2011-11-12 15:45 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files\Windows Portable Devices
2011-11-12 03:38 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\config\TxR
2011-11-12 03:36 - 2011-04-13 02:38 - 0000000 ___HD C:\users\Matthew Zounes
2011-11-12 03:36 - 2009-07-13 23:45 - 0000000 ____D C:\Program Files\Windows Journal
2011-11-12 03:36 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files\Windows Sidebar
2011-11-12 03:36 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files\Windows Photo Viewer
2011-11-12 03:36 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files\Windows Defender
2011-11-12 03:36 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files\DVD Maker
2011-11-12 03:36 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files (x86)\Windows Sidebar
2011-11-12 03:36 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 __RSD C:\Windows\Media
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\sppui
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\Setup
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\oobe
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\migwiz
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\manifeststore
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\es-ES
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\Dism
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\da-DK
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\cs-CZ
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\AdvancedInstallers
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\sppui
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\Setup
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\oobe
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\migwiz
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\manifeststore
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\es-ES
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\Dism
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\da-DK
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\cs-CZ
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\AdvancedInstallers
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\servicing
2011-11-12 03:36 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\PolicyDefinitions
2011-11-12 03:35 - 2011-11-11 22:31 - 0000000 ____D C:\5ae30d54baaa1570f0ba87
2011-11-12 03:35 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\Speech
2011-11-12 03:35 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\MUI
2011-11-12 03:35 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\sysprep
2011-11-12 03:35 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\spp
2011-11-12 03:35 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\Speech
2011-11-12 03:35 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\MUI
2011-11-12 03:35 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\registration
2011-11-12 03:35 - 2009-07-13 19:20 - 0000000 ____D C:\Program Files\Common Files\Microsoft Shared
2011-11-12 03:32 - 2011-04-27 14:39 - 0000000 ___HD C:\Users\Matthew Zounes\AppData\Roaming\Skype
2011-11-11 22:31 - 2011-11-11 22:31 - 0000000 ____D C:\Windows\System32\EventProviders
2011-11-11 22:31 - 2011-04-13 02:38 - 1343354 ____A C:\Windows\WindowsUpdate.log
2011-11-11 22:29 - 2011-05-29 07:34 - 0000000 ____D C:\Users\All Users\Easybits GO
2011-11-11 22:29 - 2011-05-29 07:34 - 0000000 ____D C:\ProgramData\Easybits GO
2011-11-11 22:28 - 2011-11-11 22:27 - 0074178 ____A C:\TDSSKiller.2.6.18.0_11.11.2011_22.27.38_log.txt
2011-11-11 22:27 - 2011-11-11 22:25 - 2562040 ____A (Symantec Corporation) C:\Users\Matthew Zounes\Downloads\NPE.exe
2011-11-11 22:27 - 2011-11-11 15:48 - 1564976 ____A (Kaspersky Lab ZAO) C:\Users\Matthew Zounes\Downloads\TDSSKiller.exe
2011-11-11 22:16 - 2011-10-05 16:06 - 0000000 ____D C:\Program Files (x86)\QuickTime
2011-11-11 22:16 - 2011-09-23 19:47 - 0000000 ____D C:\Windows\Minidump
2011-11-11 22:16 - 2011-05-01 18:20 - 0000000 ____D C:\Users\All Users\Microsoft Games
2011-11-11 22:16 - 2011-05-01 18:20 - 0000000 ____D C:\ProgramData\Microsoft Games
2011-11-11 22:16 - 2011-05-01 14:53 - 0000000 ____D C:\Program Files\Microsoft Xbox 360 Accessories
2011-11-11 22:16 - 2011-05-01 07:35 - 0000000 ____D C:\Users\All Users\Media Center Programs
2011-11-11 22:16 - 2011-05-01 07:35 - 0000000 ____D C:\ProgramData\Media Center Programs
2011-11-11 22:16 - 2011-04-27 14:38 - 0000000 ___RD C:\Program Files (x86)\Skype
2011-11-11 22:16 - 2011-04-27 14:38 - 0000000 ____D C:\Users\All Users\Skype
2011-11-11 22:16 - 2011-04-27 14:38 - 0000000 ____D C:\ProgramData\Skype
2011-11-11 22:16 - 2011-04-21 07:56 - 0000000 ____D C:\Program Files (x86)\Mozilla Firefox
2011-11-11 22:16 - 2011-04-13 03:26 - 0000000 ____D C:\Users\All Users\MFAData
2011-11-11 22:16 - 2011-04-13 03:26 - 0000000 ____D C:\ProgramData\MFAData
2011-11-11 22:16 - 2011-04-13 03:00 - 0000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2011-11-11 22:16 - 2011-04-13 02:58 - 0000000 ____D C:\Program Files\NVIDIA Corporation
2011-11-11 22:16 - 2011-04-13 02:48 - 0000000 ____D C:\Program Files\Realtek
2011-11-11 22:16 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files\Microsoft Games
2011-11-11 22:16 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\AppCompat
2011-11-11 22:16 - 2009-07-13 19:20 - 0000000 ____D C:\Program Files\Common Files\System
2011-11-11 22:15 - 2011-11-11 16:13 - 0000000 ____D C:\Users\All Users\Norton
2011-11-11 22:15 - 2011-11-11 16:13 - 0000000 ____D C:\ProgramData\Norton
2011-11-11 22:15 - 2011-05-08 13:18 - 0000000 ____D C:\Program Files (x86)\GameSpy Arcade
2011-11-11 22:15 - 2011-05-05 20:16 - 0000000 ____D C:\Program Files (x86)\Armagetron Advanced
2011-11-11 22:11 - 2011-04-21 08:00 - 0000000 ____D C:\Windows\SysWOW64\Macromed
2011-11-11 22:08 - 2011-09-18 19:27 - 0000000 ___HD C:\Users\Matthew Zounes\AppData\Roaming\SUPERAntiSpyware.com
2011-11-11 22:08 - 2011-09-03 18:22 - 0000000 ___HD C:\Users\Matthew Zounes\Desktop\Eddie's Games
2011-11-11 22:08 - 2011-05-05 20:16 - 0000000 ___HD C:\Users\Matthew Zounes\AppData\Roaming\Armagetron
2011-11-11 22:08 - 2011-05-01 14:42 - 0000000 ____D C:\Users\All Users\PC Drivers HeadQuarters
2011-11-11 22:08 - 2011-05-01 14:42 - 0000000 ____D C:\ProgramData\PC Drivers HeadQuarters
2011-11-11 22:08 - 2011-04-21 07:56 - 0000000 ___HD C:\Users\Matthew Zounes\AppData\Roaming\Mozilla
2011-11-11 22:08 - 2011-04-20 02:08 - 0000000 ___HD C:\Users\Matthew Zounes\AppData\Local\Microsoft Games
2011-11-11 22:07 - 2011-05-01 07:08 - 0000000 ____D C:\Program Files (x86)\Ubisoft
2011-11-11 22:07 - 2011-04-13 04:08 - 0000000 ____D C:\Program Files\Microsoft Office
2011-11-11 22:07 - 2011-04-13 04:00 - 0000000 ____D C:\Users\All Users\Adobe
2011-11-11 22:07 - 2011-04-13 04:00 - 0000000 ____D C:\ProgramData\Adobe
2011-11-11 22:07 - 2011-04-13 02:49 - 0000000 ____D C:\Users\All Users\InstallShield
2011-11-11 22:07 - 2011-04-13 02:49 - 0000000 ____D C:\ProgramData\InstallShield
2011-11-11 22:07 - 2011-04-13 02:49 - 0000000 ____D C:\Program Files\GIGABYTE
2011-11-11 22:07 - 2011-04-13 02:47 - 0000000 ____D C:\Program Files (x86)\Realtek
2011-11-11 22:07 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files\Reference Assemblies
2011-11-11 22:07 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files\MSBuild
2011-11-11 22:07 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files (x86)\Windows Defender
2011-11-11 22:07 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files (x86)\Reference Assemblies
2011-11-11 22:07 - 2009-07-13 21:32 - 0000000 ____D C:\Program Files (x86)\MSBuild
2011-11-11 22:07 - 2009-07-13 19:20 - 0000000 ____D C:\Program Files\Windows NT
2011-11-11 22:07 - 2009-07-13 19:20 - 0000000 ____D C:\Program Files\Common Files\SpeechEngines
2011-11-11 22:07 - 2009-07-13 19:20 - 0000000 ____D C:\Program Files (x86)\Windows NT
2011-11-11 22:06 - 2011-06-01 19:33 - 0000000 ____D C:\Program Files (x86)\Java
2011-11-11 22:06 - 2011-05-04 21:10 - 0000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2011-11-11 22:06 - 2011-05-01 18:20 - 0000000 ____D C:\Program Files (x86)\Microsoft Games
2011-11-11 22:06 - 2011-04-20 07:54 - 0000000 ____D C:\Program Files (x86)\D-Link
2011-11-11 22:06 - 2011-04-13 04:08 - 0000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2011-11-11 22:06 - 2011-04-13 04:07 - 0000000 ____D C:\Program Files (x86)\Microsoft Office
2011-11-11 22:06 - 2011-04-13 02:49 - 0000000 ____D C:\Program Files (x86)\GIGABYTE
2011-11-11 22:06 - 2011-04-13 02:47 - 0000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2011-11-11 22:06 - 2011-04-13 02:47 - 0000000 ____D C:\Program Files (x86)\Intel
2011-11-11 22:05 - 2011-06-23 10:04 - 0000000 ____D C:\.jagex_cache_32
2011-11-11 22:05 - 2011-04-30 21:39 - 0000000 ____D C:\Program Files (x86)\Amazon
2011-11-11 22:05 - 2011-04-13 04:00 - 0000000 ____D C:\Program Files (x86)\Adobe
2011-11-11 22:05 - 2011-04-13 03:45 - 0000000 ____D C:\Program Files (x86)\garbage
2011-11-11 21:52 - 2011-11-11 11:51 - 0000000 ____D C:\Program Files (x86)\Avira
2011-11-11 21:49 - 2011-04-27 14:39 - 0000000 ____D C:\Users\All Users\Skype Extras
2011-11-11 21:49 - 2011-04-27 14:39 - 0000000 ____D C:\ProgramData\Skype Extras
2011-11-11 21:46 - 2009-07-13 20:45 - 0015696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2011-11-11 21:46 - 2009-07-13 20:45 - 0015696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2011-11-11 21:45 - 2011-04-13 03:14 - 0000944 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2576670710-1449445552-3589073893-1000UA.job
2011-11-11 21:44 - 2009-07-13 21:13 - 0726316 ____A C:\Windows\System32\PerfStringBackup.INI
2011-11-11 21:42 - 2011-08-11 16:26 - 0000000 ____D C:\Program Files (x86)\Steam
2011-11-11 21:39 - 2011-04-20 08:09 - 0000007 ____A C:\Windows\SysWOW64\ANIWZCSUSERNAME
2011-11-11 21:38 - 2011-04-18 00:30 - 0025640 ____A (Windows ® Server 2003 DDK provider) C:\Windows\gdrv.sys
2011-11-11 21:38 - 2011-04-13 04:18 - 0266976 ____A C:\Windows\PFRO.log
2011-11-11 21:38 - 2011-04-13 03:00 - 0000000 ____D C:\Users\All Users\NVIDIA
2011-11-11 21:38 - 2011-04-13 03:00 - 0000000 ____D C:\ProgramData\NVIDIA
2011-11-11 21:38 - 2009-07-13 21:08 - 0000006 ___AH C:\Windows\Tasks\SA.DAT
2011-11-11 21:38 - 2009-07-13 20:51 - 0028509 ____A C:\Windows\setupact.log
2011-11-11 21:36 - 2011-11-11 21:36 - 0000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2011-11-11 21:36 - 2011-11-11 21:36 - 0000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2011-11-11 21:36 - 2011-04-13 04:07 - 0000000 ____D C:\Users\All Users\Microsoft Help
2011-11-11 21:36 - 2011-04-13 04:07 - 0000000 ____D C:\ProgramData\Microsoft Help
2011-11-11 21:27 - 2011-11-11 21:26 - 0002070 ____A C:\Users\Public\Desktop\Avira Control Center.lnk
2011-11-11 21:25 - 2011-09-18 19:27 - 0000000 ____D C:\Program Files\SUPERAntiSpyware
2011-11-11 21:23 - 2011-04-13 03:46 - 0000000 ____D C:\Users\All Users\AVG10
2011-11-11 21:23 - 2011-04-13 03:46 - 0000000 ____D C:\ProgramData\AVG10
2011-11-11 21:22 - 2011-04-13 03:46 - 0000000 ____D C:\Windows\System32\Drivers\AVG
2011-11-11 19:13 - 2011-10-13 10:36 - 0000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2011-11-11 18:56 - 2011-11-11 18:56 - 0000766 ____A C:\Users\Matthew Zounes\AppData\Roaming\SMRBackup210.dat
2011-11-11 18:55 - 2011-11-11 16:13 - 0000000 ____D C:\Users\Matthew Zounes\AppData\Local\NPE
2011-11-11 18:53 - 2011-11-11 18:52 - 0074930 ____A C:\TDSSKiller.2.6.18.0_11.11.2011_18.52.08_log.txt
2011-11-11 16:24 - 2011-11-11 16:24 - 0000316 ____A C:\Users\Matthew Zounes\Downloads\TmRCMScanDebug20111111_00.log
2011-11-11 16:00 - 2011-05-29 07:34 - 0000000 ___HD C:\Users\Matthew Zounes\AppData\Roaming\go
2011-11-11 11:52 - 2011-11-11 11:52 - 0000000 ____D C:\Users\Matthew Zounes\AppData\Roaming\Avira
2011-11-11 11:51 - 2011-11-11 11:51 - 0000000 ____D C:\Users\All Users\Avira
2011-11-11 11:51 - 2011-11-11 11:51 - 0000000 ____D C:\ProgramData\Avira
2011-11-11 11:41 - 2011-11-11 11:41 - 0074952 ____A C:\TDSSKiller.2.6.18.0_11.11.2011_11.41.06_log.txt
2011-11-11 11:37 - 2011-11-11 11:36 - 0075640 ____A C:\TDSSKiller.2.6.18.0_11.11.2011_11.36.46_log.txt
2011-11-11 11:26 - 2011-04-14 06:27 - 0000000 ____D C:\Windows\Panther
2011-10-27 23:05 - 2011-11-11 22:29 - 52174280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2011-10-20 19:05 - 2011-04-20 07:55 - 0000007 ____A C:\Windows\SysWOW64\ANIWZCSUSERNAME{D5E2FB2E-4AF1-4016-B220-8AE7EB96D14F}
2011-10-20 16:30 - 2011-04-13 04:07 - 0000000 __RHD C:\MSOCache
2011-10-19 15:12 - 2011-10-19 15:12 - 0000000 ____D C:\Users\Matthew Zounes\AppData\Roaming\Wilei
2011-10-13 22:03 - 2011-10-13 22:03 - 0013617 ____A C:\Users\Matthew Zounes\Documents\wod 2.docx
2011-10-13 21:53 - 2011-10-13 18:21 - 0027038 ____A C:\Users\Matthew Zounes\Documents\bargianrevised2.docx
2011-10-13 21:49 - 2011-10-13 21:49 - 0000162 ___AH C:\Users\Matthew Zounes\Documents\~$rgianrevised2.docx
2011-10-13 16:24 - 2011-10-13 16:24 - 0026164 ____A C:\Users\Matthew Zounes\Downloads\bargianrevised2.docx
2011-10-12 19:45 - 2011-04-13 03:14 - 0000892 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2576670710-1449445552-3589073893-1000Core.job
2011-10-12 14:40 - 2009-07-13 21:08 - 0032588 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2011-10-08 07:47 - 2011-04-13 03:17 - 0002451 ___AH C:\Users\Matthew Zounes\Desktop\Google Chrome.lnk
2011-10-07 19:22 - 2011-10-07 18:53 - 83477336 ____A C:\Users\Matthew Zounes\Downloads\avira_free_antivirus_en.exe
2011-10-06 18:34 - 2011-10-04 18:00 - 0014786 ____A C:\Users\Matthew Zounes\Documents\bargian.docx
2011-10-06 17:53 - 2011-10-06 17:52 - 0230889 ____A C:\Users\Matthew Zounes\Documents\Intro.docx
2011-10-05 16:06 - 2009-07-13 21:32 - 0000000 ____D C:\Windows\Downloaded Program Files
2011-10-04 19:08 - 2011-05-28 05:55 - 0407622 ___AH C:\Users\Matthew Zounes\Documents\Airsoft.docx
2011-10-04 17:43 - 2011-10-04 17:43 - 0016040 ____A C:\Users\Matthew Zounes\Documents\wod oct 3.docx
2011-10-02 12:39 - 2011-06-23 10:05 - 0000035 ___AH C:\Users\Matthew Zounes\jagex_runescape_preferences.dat
2011-10-02 11:40 - 2011-04-20 08:07 - 0003284 ___AH C:\Windows\SysWOW64\ANIWZCS{D5E2FB2E-4AF1-4016-B220-8AE7EB96D14F}
2011-10-02 11:40 - 2011-04-20 08:07 - 0003284 ___AH C:\Users\Matthew Zounes\AppData\Roaming\ANIWZCS{D5E2FB2E-4AF1-4016-B220-8AE7EB96D14F}
2011-10-01 07:18 - 2011-10-01 06:41 - 0000000 ___HD C:\Users\Matthew Zounes\AppData\Roaming\Exce
2011-10-01 06:41 - 2011-10-01 06:41 - 0000000 ___HD C:\Users\Matthew Zounes\AppData\Roaming\Yfok
2011-10-01 06:41 - 2011-10-01 06:38 - 0000000 ___HD C:\Users\Matthew Zounes\AppData\Roaming\Ovvo
2011-10-01 06:38 - 2011-10-01 06:38 - 0000174 ___SH C:\Users\Default\Start Menu\Programs\Startup\desktop.ini
2011-10-01 06:38 - 2011-10-01 06:38 - 0000174 ___SH C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
2011-10-01 06:38 - 2011-10-01 06:38 - 0000174 ___SH C:\Users\Default User\Start Menu\Programs\Startup\desktop.ini
2011-10-01 06:38 - 2011-10-01 06:38 - 0000174 ___SH C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
2011-10-01 06:38 - 2011-10-01 06:38 - 0000000 ___HD C:\Users\Matthew Zounes\AppData\Roaming\Jyvob
2011-10-01 06:38 - 2011-10-01 06:38 - 0000000 ____D C:\Windows\Sun
2011-10-01 06:12 - 2011-10-01 06:12 - 0000000 ____D C:\Windows\system64
2011-10-01 06:12 - 2009-07-13 21:37 - 0000000 ____D C:\Windows\SysWOW64\sysprep
2011-09-30 21:24 - 2011-11-11 16:26 - 9326080 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2011-09-30 20:42 - 2011-11-11 16:26 - 5990912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2011-09-30 19:21 - 2011-11-11 16:26 - 1638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2011-09-30 18:59 - 2011-11-11 16:26 - 1638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2011-09-29 18:07 - 2011-09-29 18:07 - 0000000 ____D C:\Windows\SysWOW64\GLOBALROOT
2011-09-23 19:47 - 2011-09-23 19:47 - 269841708 ____A C:\Windows\MEMORY.DMP
2011-09-23 19:47 - 2011-09-23 19:47 - 0349488 ____A C:\Windows\Minidump\092311-24460-01.dmp
2011-09-23 19:45 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\LiveKernelReports
2011-09-22 15:37 - 2011-09-22 15:10 - 0022609 ___AH C:\Users\Matthew Zounes\Documents\research song of the trees missp depressin.docx
2011-09-18 19:27 - 2011-09-18 19:27 - 0001808 ___AH C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2011-09-18 19:27 - 2011-09-18 19:27 - 0000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2011-09-18 19:27 - 2011-09-18 19:27 - 0000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2011-09-18 19:26 - 2011-09-18 19:26 - 12581512 ___AH (SUPERAntiSpyware.com) C:\Users\Matthew Zounes\Downloads\SUPERAntiSpyware.exe
2011-09-18 18:58 - 2011-09-18 18:57 - 5052966 ___AH C:\Users\Matthew Zounes\Downloads\TheFewTheProudTheZounesJPEG.jpg
2011-09-18 18:57 - 2011-09-18 18:57 - 0121853 ___AH C:\Users\Matthew Zounes\Downloads\2.jpg
2011-09-18 18:57 - 2011-09-18 18:52 - 0121853 ___AH C:\Users\Matthew Zounes\Downloads\MissionImplausibleJPEG.jpg
2011-09-18 08:39 - 2011-11-11 21:25 - 0130760 ____A (Avira GmbH) C:\Windows\System32\Drivers\avipbb.sys
2011-09-15 23:55 - 2011-11-11 21:25 - 0097312 ____A (Avira GmbH) C:\Windows\System32\Drivers\avgntflt.sys
2011-09-15 23:55 - 2011-11-11 21:25 - 0027760 ____A (Avira GmbH) C:\Windows\System32\Drivers\avkmgr.sys
2011-09-03 18:22 - 2011-09-03 18:22 - 0000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2011-09-01 17:02 - 2011-09-01 17:02 - 0417729 ___AH C:\Users\Matthew Zounes\Documents\hughes poem annotation.pdf
2011-09-01 17:01 - 2011-09-01 17:01 - 0067680 ___AH C:\Users\Matthew Zounes\Documents\FoulShotPoem (1).pdf
2011-08-26 21:40 - 2011-11-11 16:25 - 0331776 ____A (Microsoft Corporation) C:\Windows\System32\oleacc.dll
2011-08-26 21:40 - 2011-10-12 15:12 - 0861184 ____A (Microsoft Corporation) C:\Windows\System32\oleaut32.dll
2011-08-26 20:43 - 2011-11-11 16:25 - 0571904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2011-08-26 20:43 - 2011-11-11 16:25 - 0233472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2011-08-26 08:11 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\rescache
2011-08-24 19:48 - 2011-08-24 19:48 - 0000219 ___AH C:\Users\Matthew Zounes\Desktop\Team Fortress 2.url
2011-08-21 08:25 - 2011-08-21 08:25 - 0013151 ___AH C:\Users\Matthew Zounes\Documents\ummmmmm.docx
2011-08-19 21:45 - 2011-11-11 16:26 - 1197568 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2011-08-19 21:44 - 2011-11-11 16:26 - 1501184 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2011-08-19 21:44 - 2011-11-11 16:26 - 0134144 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2011-08-19 21:42 - 2011-11-11 16:26 - 1026560 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
2011-08-19 21:41 - 2011-11-11 16:26 - 0703488 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2011-08-19 21:41 - 2011-11-11 16:26 - 0097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2011-08-19 21:41 - 2011-11-11 16:26 - 0082944 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2011-08-19 21:41 - 2011-11-11 16:26 - 0064512 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2011-08-19 21:41 - 2011-11-11 16:26 - 0057856 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2011-08-19 21:40 - 2011-11-11 16:26 - 2458624 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2011-08-19 21:40 - 2011-11-11 16:26 - 12370944 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2011-08-19 21:40 - 2011-11-11 16:26 - 0445952 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2011-08-19 21:40 - 2011-11-11 16:26 - 0256000 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2011-08-19 21:40 - 2011-11-11 16:26 - 0256000 ____A (Microsoft Corporation) C:\Windows\System32\iepeers(1544).dll
2011-08-19 21:40 - 2011-11-11 16:26 - 0247808 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2011-08-19 21:37 - 2011-11-11 16:26 - 0012288 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2011-08-19 20:38 - 2011-11-11 16:26 - 1230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2011-08-19 20:38 - 2011-11-11 16:26 - 0981504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2011-08-19 20:38 - 2011-11-11 16:26 - 0132096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2011-08-19 20:36 - 2011-11-11 16:26 - 0606208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll
2011-08-19 20:35 - 2011-11-11 16:26 - 2072576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2011-08-19 20:35 - 2011-11-11 16:26 - 10990080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2011-08-19 20:35 - 2011-11-11 16:26 - 0599552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2011-08-19 20:35 - 2011-11-11 16:26 - 0185856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2011-08-19 20:35 - 2011-11-11 16:26 - 0176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2011-08-19 20:35 - 2011-11-11 16:26 - 0067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2011-08-19 20:35 - 2011-11-11 16:26 - 0064512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2011-08-19 20:35 - 2011-11-11 16:26 - 0048128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2011-08-19 20:35 - 2011-11-11 16:26 - 0044544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2011-08-19 20:34 - 2011-11-11 16:26 - 0381440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2011-08-19 20:32 - 2011-11-11 16:26 - 0012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2011-08-19 20:20 - 2011-10-12 15:26 - 0482816 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2011-08-19 19:26 - 2011-10-12 15:26 - 0386048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2011-08-16 21:32 - 2011-11-11 16:25 - 0613888 ____A (Microsoft Corporation) C:\Windows\System32\psisdecd.dll
2011-08-16 21:27 - 2011-11-11 16:25 - 0288256 ____A (Microsoft Corporation) C:\Windows\System32\MSNP.ax
2011-08-16 21:27 - 2011-11-11 16:25 - 0108032 ____A (Microsoft Corporation) C:\Windows\System32\psisrndr.ax
2011-08-16 21:27 - 2011-11-11 16:25 - 0104960 ____A (Microsoft Corporation) C:\Windows\System32\Mpeg2Data.ax
2011-08-16 21:27 - 2011-11-11 16:25 - 0075776 ____A (Microsoft Corporation) C:\Windows\System32\MSDvbNP.ax
2011-08-16 20:26 - 2011-11-11 16:25 - 0465408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2011-08-16 20:22 - 2011-11-11 16:25 - 0204288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSNP.ax
2011-08-16 20:22 - 2011-11-11 16:25 - 0075776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2011-08-16 20:22 - 2011-11-11 16:25 - 0072704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Mpeg2Data.ax
2011-08-16 20:22 - 2011-11-11 16:25 - 0059904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSDvbNP.ax

========================= Known DLLs (Whitelisted) ============


========================= Bamital & volsnap Check ============

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

========================= Memory info ======================

Percentage of memory in use: 14%
Total physical RAM: 4079.49 MB
Available physical RAM: 3493.83 MB
Total Pagefile: 4077.64 MB
Available Pagefile: 3476.48 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB

======================= Partitions =========================

1 Drive c: () (Fixed) (Total:931.41 GB) (Free:852.91 GB) NTFS
2 Drive e: (Repair disc Windows 7 64-bit) (CDROM) (Total:0.16 GB) (Free:0 GB) UDF
3 Drive f: () (Removable) (Total:3.76 GB) (Free:0.04 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS

==========================================================

Last Boot: 2011-11-11 16:56

======================= End Of Log ==========================

#3 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,316 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:04:36 AM

Posted 13 November 2011 - 04:11 AM

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flashdrive as fixlist.txt

SubSystems: [Windows] ==> ZeroAccess

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Now please enter System Recovery Options.
Run FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply. Let me also know if the computer will now boot up correctly.

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#4 DigitalKirin

DigitalKirin
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:36 PM

Posted 13 November 2011 - 10:34 AM

The system will now boot up, thank you very much Elise025!

Here are the contents of Fixlog.txt:

Fix result of Farbars's Recovery Tool (FRST written by farbar Version 2.2.7)
Ran by SYSTEM at 2011-11-13 02:30:46 R:1
Running from F:\

==============================================

HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Session Manager\SubSystems\\Windows Value was restored.

==== End of Fixlog ====

#5 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,316 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:04:36 AM

Posted 13 November 2011 - 11:07 AM

Glad to hear that! :)
Now lets see what else needs a bit more attention.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#6 DigitalKirin

DigitalKirin
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:36 PM

Posted 13 November 2011 - 05:00 PM

Thank you for the follow up. Here is the requested information:

.
DDS (Ver_2011-06-23.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22
Run by Matthew Zounes at 13:56:42 on 2011-11-13
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4079.2098 [GMT -8:00]
.
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\D-Link\DWA-125 revA\ANIWConnService.exe
C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\GIGABYTE\SMART6\Recovery\RPMDaemon.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\D-Link\DWA-125 revA\AirGCFG.exe
C:\Program Files (x86)\D-Link\DWA-125 revA\WZCSLDR2.exe
C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\AlarmClock.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\explorer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
uRun: [Google Update] "C:\Users\Matthew Zounes\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [D-Link D-Link DWA-125] C:\Program Files (x86)\D-Link\DWA-125 revA\AirGCFG.exe
mRun: [WZCSLDR2] C:\Program Files (x86)\D-Link\DWA-125 revA\WZCSLDR2.exe
mRun: [AmazonGSDownloaderTray] C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
dRun: [JavaSoft Update] rundll32 "C:\Windows\system32\config\systemprofile\AppData\Local\Programs\ProgramsUpdate\Programsupdt32.DLL",DllRegisterServer
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 10.0.1.1
TCP: Interfaces\{64FDADC6-0801-4D0A-B986-9E9CFD13CCD8} : DhcpNameServer = 10.0.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype Plug-In: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [D-Link D-Link DWA-125] C:\Program Files (x86)\D-Link\DWA-125 revA\AirGCFG.exe
mRun-x64: [WZCSLDR2] C:\Program Files (x86)\D-Link\DWA-125 revA\WZCSLDR2.exe
mRun-x64: [AmazonGSDownloaderTray] C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Matthew Zounes\AppData\Roaming\Mozilla\Firefox\Profiles\9ppt4fuw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Users\Matthew Zounes\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Users\Matthew Zounes\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Matthew Zounes\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
.
R1 anodlwf;ANOD Network Security Filter driver;C:\Windows\system32\DRIVERS\anodlwfx.sys --> C:\Windows\system32\DRIVERS\anodlwfx.sys [?]
R1 AppleCharger;AppleCharger;C:\Windows\system32\DRIVERS\AppleCharger.sys --> C:\Windows\system32\DRIVERS\AppleCharger.sys [?]
R1 avkmgr;avkmgr;C:\Windows\system32\DRIVERS\avkmgr.sys --> C:\Windows\system32\DRIVERS\avkmgr.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 Amazon Download Agent;Amazon Download Agent;C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2011-4-30 401920]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-11-11 86224]
R2 AntiVirService;Avira Realtime Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-11-11 110032]
R2 avgntflt;avgntflt;C:\Windows\system32\DRIVERS\avgntflt.sys --> C:\Windows\system32\DRIVERS\avgntflt.sys [?]
R2 D_Link_DWA-125_WPS;D_Link_DWA-125_WPS Service;C:\Program Files (x86)\D-Link\DWA-125 revA\ANIWConnService.exe [2011-4-20 40960]
R2 Smart TimeLock;Smart TimeLock Service;C:\Program Files (x86)\GIGABYTE\smart6\timelock\TimeMgmtDaemon.exe [2011-4-13 114688]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-19 369256]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-4-13 2655768]
R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 D_Link_DWA-125;D_Link_DWA-125 Service;C:\Program Files (x86)\D-Link\DWA-125 revA\ANIWZCSdS.exe [2011-4-20 126976]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 GVTDrv64;GVTDrv64;C:\Windows\GVTDrv64.sys [2011-4-13 30528]
S3 netr28ux;D-Link dnetr28u USB Extensible Wireless LAN Card Driver;C:\Windows\system32\DRIVERS\Dnetr28ux.sys --> C:\Windows\system32\DRIVERS\Dnetr28ux.sys [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 V0520Vid;Creative Camera VF0520 Driver;C:\Windows\system32\DRIVERS\V0520Vid.sys --> C:\Windows\system32\DRIVERS\V0520Vid.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-11-13 03:01:46 -------- d-----w- C:\FRST
2011-11-13 00:37:24 -------- d-----w- C:\ProgramData\Recovery
2011-11-12 06:31:04 -------- d-----w- C:\Windows\System32\EventProviders
2011-11-12 06:31:03 -------- d-----w- C:\5ae30d54baaa1570f0ba87
2011-11-12 05:42:28 6144 ----a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll
2011-11-12 05:42:27 6144 ----a-w- C:\Program Files\Internet Explorer\iecompat.dll
2011-11-12 05:41:58 8424784 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-11-12 05:41:54 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1002EC1E-0F56-4CE6-84F6-C60506C98591}\offreg.dll
2011-11-12 05:41:52 8570192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1002EC1E-0F56-4CE6-84F6-C60506C98591}\mpengine.dll
2011-11-12 05:25:55 97312 ----a-w- C:\Windows\System32\drivers\avgntflt.sys
2011-11-12 05:25:55 27760 ----a-w- C:\Windows\System32\drivers\avkmgr.sys
2011-11-12 00:25:10 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2011-11-12 00:25:10 75776 ----a-w- C:\Windows\System32\MSDvbNP.ax
2011-11-12 00:25:10 72704 ----a-w- C:\Windows\SysWow64\Mpeg2Data.ax
2011-11-12 00:25:10 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2011-11-12 00:25:10 59904 ----a-w- C:\Windows\SysWow64\MSDvbNP.ax
2011-11-12 00:25:10 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2011-11-12 00:25:10 288256 ----a-w- C:\Windows\System32\MSNP.ax
2011-11-12 00:25:10 204288 ----a-w- C:\Windows\SysWow64\MSNP.ax
2011-11-12 00:25:10 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2011-11-12 00:25:10 104960 ----a-w- C:\Windows\System32\Mpeg2Data.ax
2011-11-12 00:25:08 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-11-12 00:25:08 331776 ----a-w- C:\Windows\System32\oleacc.dll
2011-11-12 00:25:08 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-11-12 00:13:14 -------- d-----w- C:\Users\Matthew Zounes\AppData\Local\NPE
2011-11-12 00:13:14 -------- d-----w- C:\ProgramData\Norton
2011-11-11 19:52:04 -------- d-----w- C:\Users\Matthew Zounes\AppData\Roaming\Avira
2011-11-11 19:51:56 -------- d-----w- C:\ProgramData\Avira
2011-11-11 19:51:56 -------- d-----w- C:\Program Files (x86)\Avira
2011-10-19 23:12:14 -------- d-----w- C:\Users\Matthew Zounes\AppData\Roaming\Wilei
2011-10-17 02:55:32 18139008 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
.
==================== Find3M ====================
.
2011-11-13 10:33:02 25640 ----a-w- C:\Windows\gdrv.sys
2011-10-01 03:21:20 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-10-01 02:59:14 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-08-27 05:40:28 861184 ----a-w- C:\Windows\System32\oleaut32.dll
2011-08-20 05:45:20 1197568 ----a-w- C:\Windows\System32\wininet.dll
2011-08-20 05:41:16 57856 ----a-w- C:\Windows\System32\licmgr10.dll
2011-08-20 05:40:50 256000 ----a-w- C:\Windows\System32\iepeers(1544).dll
2011-08-20 04:38:10 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-08-20 04:35:20 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
2011-08-20 04:20:23 482816 ----a-w- C:\Windows\System32\html.iec
2011-08-20 03:26:38 386048 ----a-w- C:\Windows\SysWow64\html.iec
.
============= FINISH: 13:56:56.43 ===============

Attached Files



#7 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,316 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:04:36 AM

Posted 14 November 2011 - 01:36 AM

Hi again,

COMBOFIX
---------------
Please download ComboFix from one of these locations:
Bleepingcomputer
ForoSpyware
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on Combofix.exe and follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, or if you are running Vista, ComboFix will continue it's malware removal procedures.

Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\Combofix.txt in your next reply.

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#8 DigitalKirin

DigitalKirin
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:36 PM

Posted 14 November 2011 - 05:50 AM

Hello again, I appreciate the time you are spending to help out!

Here is the log produced and combofix.txt attachment:

ComboFix 11-11-14.01 - Matthew Zounes 11/14/2011 2:37.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4079.2053 [GMT -8:00]
Running from: c:\users\Matthew Zounes\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Internet Explorer\2FD6.tmp
C:\Recycle.Bin
c:\recycle.bin\10B1FF359539EE5
c:\users\Matthew Zounes\AppData\Roaming\Wilei
c:\users\Matthew Zounes\AppData\Roaming\Wilei\cyvir.miy
c:\users\Matthew Zounes\AppData\Roaming\Yfok
c:\users\Matthew Zounes\AppData\Roaming\Yfok\xojie.evi
c:\windows\assembly\tmp\U
c:\windows\assembly\tmp\U\00000001.@
c:\windows\assembly\tmp\U\00000002.@
c:\windows\assembly\tmp\U\00000004.@
c:\windows\assembly\tmp\U\000000c0.@
c:\windows\assembly\tmp\U\000000cb.@
c:\windows\assembly\tmp\U\000000cf.@
c:\windows\assembly\tmp\U\80000000.@
c:\windows\assembly\tmp\U\80000004.@
c:\windows\assembly\tmp\U\80000032.@
c:\windows\assembly\tmp\U\80000064.@
c:\windows\assembly\tmp\U\800000c0.@
c:\windows\assembly\tmp\U\800000cb.@
c:\windows\assembly\tmp\U\800000cf.@
c:\windows\svchost.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-10-14 to 2011-11-14 )))))))))))))))))))))))))))))))
.
.
2011-11-14 10:40 . 2011-11-14 10:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-11-13 03:01 . 2011-11-13 03:02 -------- d-----w- C:\FRST
2011-11-13 00:37 . 2011-11-13 00:56 -------- d-----w- c:\programdata\Recovery
2011-11-12 06:31 . 2011-11-12 06:31 -------- d-----w- c:\windows\system32\EventProviders
2011-11-12 06:31 . 2011-11-12 11:35 -------- d-----w- C:\5ae30d54baaa1570f0ba87
2011-11-12 05:42 . 2011-08-15 04:25 6144 ----a-w- c:\program files (x86)\Internet Explorer\iecompat.dll
2011-11-12 05:42 . 2011-08-15 05:08 6144 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2011-11-12 05:41 . 2011-10-18 09:27 8570192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1002EC1E-0F56-4CE6-84F6-C60506C98591}\mpengine.dll
2011-11-12 05:36 . 2011-11-12 05:36 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2011-11-12 05:25 . 2011-09-18 16:39 130760 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-11-12 05:25 . 2011-09-16 07:55 97312 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-11-12 05:25 . 2011-09-16 07:55 27760 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2011-11-12 00:25 . 2011-08-17 05:32 613888 ----a-w- c:\windows\system32\psisdecd.dll
2011-11-12 00:25 . 2011-08-17 05:27 75776 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-11-12 00:25 . 2011-08-17 05:27 288256 ----a-w- c:\windows\system32\MSNP.ax
2011-11-12 00:25 . 2011-08-17 05:27 108032 ----a-w- c:\windows\system32\psisrndr.ax
2011-11-12 00:25 . 2011-08-17 05:27 104960 ----a-w- c:\windows\system32\Mpeg2Data.ax
2011-11-12 00:25 . 2011-08-17 04:26 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2011-11-12 00:25 . 2011-08-17 04:22 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2011-11-12 00:25 . 2011-08-17 04:22 72704 ----a-w- c:\windows\SysWow64\Mpeg2Data.ax
2011-11-12 00:25 . 2011-08-17 04:22 59904 ----a-w- c:\windows\SysWow64\MSDvbNP.ax
2011-11-12 00:25 . 2011-08-17 04:22 204288 ----a-w- c:\windows\SysWow64\MSNP.ax
2011-11-12 00:25 . 2011-08-27 05:40 331776 ----a-w- c:\windows\system32\oleacc.dll
2011-11-12 00:25 . 2011-08-27 04:43 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-11-12 00:25 . 2011-08-27 04:43 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
2011-11-12 00:13 . 2011-11-12 06:15 -------- d-----w- c:\programdata\Norton
2011-11-12 00:13 . 2011-11-12 02:55 -------- d-----w- c:\users\Matthew Zounes\AppData\Local\NPE
2011-11-11 19:52 . 2011-11-11 19:52 -------- d-----w- c:\users\Matthew Zounes\AppData\Roaming\Avira
2011-11-11 19:51 . 2011-11-12 05:52 -------- d-----w- c:\program files (x86)\Avira
2011-11-11 19:51 . 2011-11-11 19:51 -------- d-----w- c:\programdata\Avira
2011-10-17 02:55 . 2011-10-17 02:55 18139008 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-14 10:41 . 2011-04-18 08:30 25640 ----a-w- c:\windows\gdrv.sys
2011-08-27 05:40 . 2011-10-12 23:12 861184 ----a-w- c:\windows\system32\oleaut32.dll
2011-08-20 04:20 . 2011-10-12 23:26 482816 ----a-w- c:\windows\system32\html.iec
2011-08-20 03:26 . 2011-10-12 23:26 386048 ----a-w- c:\windows\SysWow64\html.iec
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-17 221184]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-04-19 15146376]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-12 1242448]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-11-12 5495680]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"="c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"D-Link D-Link DWA-125"="c:\program files (x86)\D-Link\DWA-125 revA\AirGCFG.exe" [2009-10-20 995328]
"WZCSLDR2"="c:\program files (x86)\D-Link\DWA-125 revA\WZCSLDR2.exe" [2009-10-20 122880]
"AmazonGSDownloaderTray"="c:\program files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [2009-10-23 326144]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-10-05 258512]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 D_Link_DWA-125;D_Link_DWA-125 Service;c:\program files (x86)\D-Link\DWA-125 revA\ANIWZCSdS.exe [2009-08-21 126976]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2011-04-13 30528]
R3 netr28ux;D-Link dnetr28u USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\Dnetr28ux.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 V0520Vid;Creative Camera VF0520 Driver;c:\windows\system32\DRIVERS\V0520Vid.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S1 anodlwf;ANOD Network Security Filter driver;c:\windows\system32\DRIVERS\anodlwfx.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672]
S2 Amazon Download Agent;Amazon Download Agent;c:\program files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2009-10-23 401920]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-05 86224]
S2 D_Link_DWA-125_WPS;D_Link_DWA-125_WPS Service;c:\program files (x86)\D-Link\DWA-125 revA\ANIWConnService.exe [2009-07-08 40960]
S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [2009-10-13 114688]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-19 369256]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-06 2655768]
S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2576670710-1449445552-3589073893-1000Core.job
- c:\users\Matthew Zounes\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-13 11:14]
.
2011-11-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2576670710-1449445552-3589073893-1000UA.job
- c:\users\Matthew Zounes\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-13 11:14]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45d30484-7ded-43d9-957a-d2fd1f046511}]
2009-11-25 19:47 444752 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1d09c093-f71e-43c3-b948-19316cbd695e}"= "mscoree.dll" [2009-11-25 444752]
.
[HKEY_CLASSES_ROOT\CLSID\{1d09c093-f71e-43c3-b948-19316cbd695e}]
[HKEY_CLASSES_ROOT\tGBandObj.tGBandObjClass]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-09-03 11464296]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-10-01 825184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"RPMKickstart"="c:\program files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe" [2010-08-24 2552320]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 10.0.1.1
FF - ProfilePath - c:\users\Matthew Zounes\AppData\Roaming\Mozilla\Firefox\Profiles\9ppt4fuw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKU-Default-Run-JavaSoft Update - c:\windows\system32\config\systemprofile\AppData\Local\Programs\ProgramsUpdate\Programsupdt32.DLL
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\GIGABYTE\Smart6\Timelock\AlarmClock.exe
c:\program files (x86)\Skype\Plugin Manager\skypePM.exe
c:\program files (x86)\Common Files\Steam\SteamService.exe
c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Completion time: 2011-11-14 02:47:27 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-14 10:47
.
Pre-Run: 911,338,426,368 bytes free
Post-Run: 910,737,207,296 bytes free
.
- - End Of File - - A2FEB8DA70B1B0F438AE35057BB8F998

Attached Files



#9 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,316 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:04:36 AM

Posted 14 November 2011 - 06:12 AM

Hi, do you have any problem left at this point?

Your version of Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system.
  • Download the latest version of Java Runtime Environment (JRE) Version 7u1.
  • Look for "JDK 7u1 (JDK or JRE).
  • Click the "Download JRE" button at the right.
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
    • Select "Windows x86 Offline" and click on jre-7-windows-i586.exe
  • Save it to your desktop
  • Close any programs you may have running - especially your web browser.
  • Uninstall all older versions of Java (any item with Java Runtime Environment, JRE or J2SE in the name).
  • Reboot your computer once all Java components are removed.
  • Install the newest version by double clicking (run as Administrator for Windows Vista/Seven) the downloaded file.


MALWAREBYTES ANTIMALWARE
-------------------------------------------
Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2

MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Full Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#10 DigitalKirin

DigitalKirin
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:36 PM

Posted 14 November 2011 - 03:05 PM

Here are the results of the log:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8162

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

11/14/2011 11:29:19 AM
mbam-log-2011-11-14 (11-29-19).txt

Scan type: Full scan (C:\|)
Objects scanned: 365642
Time elapsed: 22 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

#11 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,316 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:04:36 AM

Posted 14 November 2011 - 03:41 PM

That looks good! Any problem left?

ESET ONLINE SCANNER
----------------------------
I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image
      icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#12 DigitalKirin

DigitalKirin
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:36 PM

Posted 15 November 2011 - 05:36 AM

Looks like ESET managed to find another threat, aside from that, operation seems to be going well for the computer.

C:\Users\Matthew Zounes\Downloads\SoftonicDownloader_for_tom-clancys-h-a-w-x.exe a variant of Win32/SoftonicDownloader.A application cleaned by deleting - quarantined

Attached Files



#13 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,316 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:04:36 AM

Posted 15 November 2011 - 06:13 AM

Don't worry, thats just a questionable installer, not actual malware. :)

ALL CLEAN
--------------
Your machine appears to be clean, please take the time to read below on how to secure the machine and take the necessary steps to keep it clean :)

Please do the following to remove the remaining programs from your PC:
  • Delete the tools used during the disinfection:
  • Click start > run and type combofix /uninstall, press enter. This will remove Combofix from your computer.
Please read these advices, in order to prevent reinfecting your PC:
  • Install and update the following programs regularly:
    • an outbound firewall. If you are connected to the internet through a router, you are already behind a hardware firewall and as such you do not need an extra software firewall.
      A comprehensive tutorial and a list of possible firewalls can be found here.
    • an AntiVirus Software
      It is imperative that you update your AntiVirus Software on regular basis.If you do not update your AntiVirus Software then it will not be able to catch the latest threats.
    • an Anti-Spyware program
      Malware Byte's Anti Malware is an excellent Anti-Spyware scanner. It's scan times are usually under ten minutes, and has excellent detection and removal rates.
      SUPERAntiSpyware is another good scanner with high detection and removal rates.
      Both programs are free for non commercial home use but provide a resident and do not nag if you purchase the paid versions.
    • Spyware Blaster
      A tutorial for Spywareblaster can be found here. If you wish, the commercial version provides automatic updating.
  • Keep Windows (and your other Microsoft software) up to date!
    I cannot stress how important this is enough. Often holes are found in Internet Explorer or Windows itself that require patching. Sometimes these holes will allow an attacker unrestricted access to your computer.
    Therefore, please, visit the Microsoft Update Website and follow the on screen instructions to setup Microsoft Update. Also follow the instructions to update your system. Please REBOOT and repeat this process until there are no more updates to install!!
  • Keep your other software up to date as well
    Software does not need to be made by Microsoft to be insecure. You can use the Secunia Online Software occasionally to help you check for out of date software on yourmachine.
  • Stay up to date!
    The MOST IMPORTANT part of any security setup is keeping the software up to date. Malware writers release new variants every single day. If your software updates don't keep up, then the malware will always be one step ahead. Not a good thing.
Some more links you might find of interest:
Please reply to this topic if you have read the above information. If your computer is working fine, this topic will be closed afterwards.

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#14 DigitalKirin

DigitalKirin
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:36 PM

Posted 15 November 2011 - 03:51 PM

Thank you again for all your help, I've got their computer all up to date with Avira and Windows updates - he already had SUPERAntiSpyware on his computer.

#15 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,316 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:04:36 AM

Posted 15 November 2011 - 04:04 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users