Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Zero Access Rootkit


  • This topic is locked This topic is locked
3 replies to this topic

#1 BoJangles00

BoJangles00

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:34 AM

Posted 18 November 2011 - 02:32 PM

http://www.bleepingcomputer.com/forums/topic428348.html

.
DDS (Ver_2011-08-26.01) - NTFSAMD64 
Internet Explorer: 8.0.7601.17514  BrowserJavaVersion: 1.6.0_29
Run by DuSchi at 12:42:39 on 2011-11-18
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.4095.2132 [GMT -6:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\Origin\Origin.exe
C:\Windows\System32\spoolsv.exe
C:\Users\DuSchi\Local Settings\Apps\F.lux\flux.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Ray Adams\ATI Tray Tools\atitray.exe
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Orbitdownloader\orbitdm.exe
C:\Users\DuSchi\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Users\DuSchi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Users\DuSchi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\DuSchi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\DuSchi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\DuSchi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\DuSchi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\DuSchi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Users\DuSchi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\DuSchi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\DuSchi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\ping.exe
C:\Windows\system32\conhost.exe
C:\Users\DuSchi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.orbitdownloader.com
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll
BHO: IDM integration (IDMIEHlprObj Class): {0055c089-8582-441b-a0bf-17b458c2a3a8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [ASRockOCTuner] 
uRun: [ASRockIES] 
uRun: [zASRockInstantBoot] 
uRun: [Google Update] "C:\Users\DuSchi\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
uRun: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
uRun: [F.lux] "C:\Users\DuSchi\Local Settings\Apps\F.lux\flux.exe" /noshow
uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
uRun: [AtiTrayTools] "C:\Program Files (x86)\Ray Adams\ATI Tray Tools\atitray.exe"
mRun: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\DuSchi\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\DuSchi\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\DuSchi\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\LOGITE~1.LNK - C:\Program Files\Logitech\SetPoint\SetPoint.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\Orbit.lnk - C:\Program Files (x86)\Orbitdownloader\orbitdm.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/202
IE: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{9C13FCCA-797B-482D-B972-34B002CE12EF} : DhcpNameServer = 192.168.1.254
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2 sxssrv,4
BHO-X64: Octh Class: {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll
BHO-X64:     btorbit.com - No File
BHO-X64: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
BHO-X64:     IDM Helper - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64:     AcroIEHelperStub - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
BHO-X64:     URLRedirectionBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
mRun-x64: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun-x64: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\DuSchi\AppData\Roaming\Mozilla\Firefox\Profiles\6zwf46y1.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - google.com
FF - component: C:\Program Files (x86)\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll
FF - component: C:\Users\DuSchi\AppData\Roaming\Mozilla\Firefox\Profiles\6zwf46y1.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Users\DuSchi\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Users\DuSchi\AppData\Local\HuluDesktop\instances\0.9.14.1\nphdplg.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-7-18 140672]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-9-23 361984]
R2 AODDriver4.01;AODDriver4.01;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2011-6-24 55424]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-9-15 44768]
R2 cpuz135;cpuz135;\??\C:\Windows\system32\drivers\cpuz135_x64.sys --> C:\Windows\system32\drivers\cpuz135_x64.sys [?]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-8-4 2329480]
R2 IDMWFP;IDMWFP;C:\Windows\system32\DRIVERS\idmwfp.sys --> C:\Windows\system32\DRIVERS\idmwfp.sys [?]
R3 amdiox64;AMD IO Driver;C:\Windows\system32\DRIVERS\amdiox64.sys --> C:\Windows\system32\DRIVERS\amdiox64.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\DRIVERS\usbfilter.sys --> C:\Windows\system32\DRIVERS\usbfilter.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AODDriver4.0;AODDriver4.0;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2011-6-24 55424]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2011-2-25 128928]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 31125880]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-11-18 03:13:06	--------	d-----w-	C:\Program Files (x86)\Black_Box
2011-11-18 03:11:50	--------	d--h--w-	C:\Windows\msdownld.tmp
2011-11-11 23:14:16	--------	d-----w-	C:\Users\DuSchi\AppData\Local\Skyrim
2011-11-11 20:57:43	--------	d-----w-	C:\Program Files (x86)\The Elder Scrolls V Skyrim
2011-11-11 19:59:59	886784	----a-w-	C:\Program Files\Common Files\System\wab32.dll
2011-11-11 19:59:59	708608	----a-w-	C:\Program Files (x86)\Common Files\System\wab32.dll
2011-11-11 19:59:57	1923952	----a-w-	C:\Windows\System32\drivers\tcpip.sys
2011-11-11 19:59:55	3144704	----a-w-	C:\Windows\System32\win32k.sys
2011-11-11 19:54:48	--------	d-sh--w-	C:\Users\DuSchi\AppData\Local\8b085dde
2011-11-06 19:33:07	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\jBBBrzzONyx0uS2
2011-11-06 19:33:06	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\PyxxA11uvS2oFp
2011-11-06 19:33:04	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\kddEEL8gRZqYXkV
2011-11-06 19:33:02	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\vaaaQHH6dWKfR9g
2011-11-06 19:33:01	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\j111uvvS2ob3p
2011-11-06 19:31:58	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\wrrzzPNyxA1uS2b
2011-11-06 19:30:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\r666dEEK8fR9
2011-11-06 19:29:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\j4ammH6sW7LgZhC
2011-11-06 19:28:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\zjjYYCeekIrzO
2011-11-06 19:27:53	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\W00yccS1i
2011-11-06 19:26:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\EEELL8gTZqjYwkV
2011-11-06 19:25:57	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\KPP00yccA1vD2n4
2011-11-06 19:24:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\wVeelIBtzPNyc
2011-11-06 19:23:53	2620928	----a-w-	C:\Windows\SysWow64\JfffRLL9h.exe
2011-11-06 19:22:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\h333pmmG5aQ6dK8
2011-11-06 19:21:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\pP00yccA1
2011-11-06 19:20:58	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\IOOONtxxAucSib3
2011-11-06 19:19:57	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\H333onFF4aH5sJd
2011-11-06 19:18:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\QeellOBtzP0yA1v
2011-11-06 19:17:54	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\qNNNtxPP0uS1iDo
2011-11-06 19:16:55	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\XbbFF3pnG5aQ6dK
2011-11-06 19:15:59	2620928	----a-w-	C:\Windows\SysWow64\TonnF44pmH5sJdE.exe
2011-11-06 19:14:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\KS22obbF3pmGaJ6
2011-11-06 19:13:57	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\JppmmH5J7
2011-11-06 19:12:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\nyyccA1ivD2oF4m
2011-11-06 19:11:57	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\uBBrzPPNyxAuv2b
2011-11-06 19:10:57	2620928	----a-w-	C:\Windows\SysWow64\HSS11ibbD3n.exe
2011-11-06 19:09:59	2620928	----a-w-	C:\Windows\SysWow64\SiivvD3onF.exe
2011-11-06 19:08:57	2620928	----a-w-	C:\Windows\SysWow64\FYXwUVlItPyc1vo.exe
2011-11-06 19:07:55	2620928	----a-w-	C:\Windows\SysWow64\wXXXqjjYCekVrON.exe
2011-11-06 19:06:46	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\vwwjjUVVelBtzNc
2011-11-06 19:05:53	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\VzzONNyxA0uv2iF
2011-11-06 19:04:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\UqjjUCCekIBrONx
2011-11-06 19:03:55	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\YsssQJJ7dEKgR9h
2011-11-06 19:02:55	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\t444ammH5WJ7E8g
2011-11-06 19:01:53	2620928	----a-w-	C:\Windows\SysWow64\KYCCwkkIVrlNtP0.exe
2011-11-06 19:00:46	2620928	----a-w-	C:\Windows\SysWow64\hNNNyxxA1.exe
2011-11-06 18:59:33	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\ljjUUVeelBtzPyA
2011-11-06 18:58:57	2620928	----a-w-	C:\Windows\SysWow64\FrrllOBtx.exe
2011-11-06 18:57:58	2620928	----a-w-	C:\Windows\SysWow64\CzzOONtxA0uSib3.exe
2011-11-06 18:56:31	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\buuucSS1ibDon4a
2011-11-06 18:55:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\EllIIBttzPycAuD
2011-11-06 18:54:44	2620928	----a-w-	C:\Windows\SysWow64\YqqhhYCwkUVrOBx.exe
2011-11-06 18:53:48	2620928	----a-w-	C:\Windows\SysWow64\offfRZZ9hTXjUeI.exe
2011-11-06 18:52:57	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\nGG44amH6sWJ7E8
2011-11-06 18:51:57	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\vCCeekIVrzONxAu
2011-11-06 18:50:51	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\zxxPP0ycS1ivDoF
2011-11-06 18:49:54	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\XyyxxA1uvS2ob3m
2011-11-06 18:48:54	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\Z6ssWWK7f
2011-11-06 18:47:55	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\uQQQJ66dWK8RLhT
2011-11-06 18:46:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\zyyccA11uv2ob
2011-11-06 18:45:57	2620928	----a-w-	C:\Windows\SysWow64\qAA1uvS2o.exe
2011-11-06 18:44:59	2620928	----a-w-	C:\Windows\SysWow64\XQHH6dWKfRLgTqj.exe
2011-11-06 18:43:55	2620928	----a-w-	C:\Windows\SysWow64\nFFF3ppmG5aQ6dK.exe
2011-11-06 18:42:58	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\OjjYYCwkkVrlOtP
2011-11-06 18:41:59	2620928	----a-w-	C:\Windows\SysWow64\YKK7ffRL9gTXjYe.exe
2011-11-06 18:02:04	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\RlOBtzP0yAiDoFp
2011-11-06 18:00:58	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\AdddWK8fRLTXjUe
2011-11-06 17:59:59	2620928	----a-w-	C:\Windows\SysWow64\wEEK8ffR9hTwj.exe
2011-11-06 17:58:24	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\PSS11bb3on4aHs
2011-11-06 17:57:57	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\TmG55QQ6d
2011-11-06 17:07:41	2620928	----a-w-	C:\Windows\SysWow64\fcccS22ibD.exe
2011-11-06 17:06:57	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\JQQJJ6dWK8fR9hX
2011-11-06 17:05:58	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\RjUUCeekIBrONx
2011-11-06 17:04:54	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\V55aaQJJ6dK8fLh
2011-11-06 17:03:55	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\sKKK8ggRZ9hXwUV
2011-11-06 17:02:59	2620928	----a-w-	C:\Windows\SysWow64\xGG55aQHHdWKfL9.exe
2011-11-06 17:01:46	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\uQ68qezxvbGHKfL
2011-11-06 17:00:59	2620928	----a-w-	C:\Windows\SysWow64\EssWJ7f8ZYwkU.exe
2011-11-06 16:57:05	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\syyycAA1uvD
2011-11-06 16:57:02	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\T333ppnG5aQHdW7
2011-11-06 16:55:55	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\plllONNtxP0cS1b
2011-11-06 16:54:57	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\QCCCwwkIVrlOtx
2011-11-06 16:53:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\jaaamHH6sWJfE8g
2011-11-06 16:52:58	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\uyyyxAA1uvSob3p
2011-11-06 16:51:58	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\O00yycAA1iD2oF4
2011-11-06 16:50:58	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\upppnnG4aQH6WKf
2011-11-06 16:49:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\kKK77fRRL9TXqY
2011-11-06 16:48:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\fZZZ9hhYXwjVelB
2011-11-06 16:47:58	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\FttxxA00uc2i
2011-11-06 16:46:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\iJJ66dWWK8fL9TX
2011-11-06 16:45:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\LPPP0yycA1iD2nF
2011-11-06 16:44:57	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\xbbbF33pmG5aJ6
2011-11-06 16:43:59	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\RA000uvS2ibF3n5
2011-11-04 01:44:35	--------	d-----w-	C:\Users\DuSchi\AppData\Roaming\atitray
2011-11-04 01:43:14	--------	d-----w-	C:\Program Files (x86)\Ray Adams
2011-10-28 18:17:53	--------	d-----w-	C:\Users\DuSchi\AppData\Local\ESN Sonar
2011-10-28 04:00:02	6144	----a-w-	C:\Program Files\Internet Explorer\iecompat.dll
2011-10-28 04:00:02	6144	----a-w-	C:\Program Files (x86)\Internet Explorer\iecompat.dll
2011-10-22 19:49:28	--------	d-----w-	C:\Program Files (x86)\WinSCP
.
==================== Find3M  ====================
.
2011-11-12 18:25:07	414368	----a-w-	C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-06 22:44:43	280904	----a-w-	C:\Windows\SysWow64\PnkBstrB.xtr
2011-11-06 22:44:43	280904	----a-w-	C:\Windows\SysWow64\PnkBstrB.exe
2011-11-06 22:38:55	280904	----a-w-	C:\Windows\SysWow64\PnkBstrB.ex0
2011-11-06 19:31:57	2620928	----a-w-	C:\Windows\SysWow64\G33oonG4amH6WJf.exe
2011-11-06 19:31:42	2620928	----a-w-	C:\Windows\SysWow64\N00uvvS2ibF3nG.exe
2011-11-06 19:31:42	2620928	----a-w-	C:\Windows\SysWow64\EqqjjYCeeIVrzNx.exe
2011-11-06 19:31:25	2620928	----a-w-	C:\Windows\SysWow64\oEKK8ggRZ9hXwU.exe
2011-11-06 19:31:25	2620928	----a-w-	C:\Windows\SysWow64\bK88ggRZ9hYXjU.exe
2011-11-06 19:31:10	2620928	----a-w-	C:\Windows\SysWow64\mZZqqhYXwkUVlOt.exe
2011-11-06 19:31:09	2620928	----a-w-	C:\Windows\SysWow64\NsssWJJ7fE8gTq.exe
2011-11-06 19:29:58	2620928	----a-w-	C:\Windows\SysWow64\ac2DpG4QHK7EgZj.exe
2011-11-06 19:29:48	2620928	----a-w-	C:\Windows\SysWow64\tuuccS11ib3oG4m.exe
2011-11-06 19:29:48	2620928	----a-w-	C:\Windows\SysWow64\QoonnG4amH6.exe
2011-11-06 19:29:48	2620928	----a-w-	C:\Windows\SysWow64\JnnGG4aamHsW.exe
2011-11-06 19:29:35	2620928	----a-w-	C:\Windows\SysWow64\erllOOBtxP0.exe
2011-11-06 19:29:18	2620928	----a-w-	C:\Windows\SysWow64\m888gRRZ9hXwj.exe
2011-11-06 19:29:17	2620928	----a-w-	C:\Windows\SysWow64\ttttxPP0yc1v3n4.exe
2011-11-06 19:29:17	2620928	----a-w-	C:\Windows\SysWow64\ollOOBttxPycSv.exe
2011-11-06 19:29:17	2620928	----a-w-	C:\Windows\SysWow64\FBttxP00cSvDn4m.exe
2011-11-06 19:28:52	2620928	----a-w-	C:\Windows\SysWow64\jBrzzPNyxA1uS2b.exe
2011-11-06 19:28:51	2620928	----a-w-	C:\Windows\SysWow64\svDD22obF4pm5s.exe
2011-11-06 19:28:51	2620928	----a-w-	C:\Windows\SysWow64\DF44ppmG5sQJdE8.exe
2011-11-06 19:28:34	2620928	----a-w-	C:\Windows\SysWow64\FqqhhYXwkUVe.exe
2011-11-06 19:28:34	2620928	----a-w-	C:\Windows\SysWow64\FqhhYXXwkUVl.exe
2011-11-06 19:27:36	2620928	----a-w-	C:\Windows\SysWow64\QellIBBtzPNyAu.exe
2011-11-06 19:27:26	2620928	----a-w-	C:\Windows\SysWow64\GhTTXwwjUCeIBzP.exe
2011-11-06 19:26:56	2620928	----a-w-	C:\Windows\SysWow64\mJJJ7ddEL8gZqYX.exe
2011-11-06 19:26:56	2620928	----a-w-	C:\Windows\SysWow64\aWWJ77dEL8gRqhX.exe
2011-11-06 19:26:16	2620928	----a-w-	C:\Windows\SysWow64\YLLL9ggTZq.exe
2011-11-06 19:26:10	2620928	----a-w-	C:\Windows\SysWow64\VjjUUCelIBrzNyA.exe
2011-11-06 19:26:10	2620928	----a-w-	C:\Windows\SysWow64\gFF3ppnG5aQHdW7.exe
2011-11-06 19:26:10	2620928	----a-w-	C:\Windows\SysWow64\gFF33pnGGaQH6W7.exe
2011-11-06 19:26:10	2620928	----a-w-	C:\Windows\SysWow64\gF33ppnG5aQHdW7.exe
2011-11-06 19:26:04	2620928	----a-w-	C:\Windows\SysWow64\gFF33pnG5aQHdW7.exe
2011-11-06 19:25:56	2620928	----a-w-	C:\Windows\SysWow64\QJ77ddEK8RZ9YXU.exe
2011-11-06 19:25:56	2620928	----a-w-	C:\Windows\SysWow64\pXXwjUVVe.exe
2011-11-06 19:25:56	2620928	----a-w-	C:\Windows\SysWow64\lgRRZZ9hYXUVlIt.exe
2011-11-06 19:25:55	2620928	----a-w-	C:\Windows\SysWow64\pXXwUUVel.exe
2011-11-06 19:25:55	2620928	----a-w-	C:\Windows\SysWow64\mUUVeelIBt.exe
2011-11-06 19:25:55	2620928	----a-w-	C:\Windows\SysWow64\lggRRZ9hYXjUVlB.exe
2011-11-06 19:25:55	2620928	----a-w-	C:\Windows\SysWow64\aQQJJ7ddE8gRZhX.exe
2011-11-06 19:25:52	2620928	----a-w-	C:\Windows\SysWow64\agRRZqhYXw.exe
2011-11-06 19:25:26	2620928	----a-w-	C:\Windows\SysWow64\nAAA0uucS2iD3nG.exe
2011-11-06 19:24:07	2620928	----a-w-	C:\Windows\SysWow64\X333onGG4a.exe
2011-11-06 19:24:07	2620928	----a-w-	C:\Windows\SysWow64\ERRZqhhYXwkUeOt.exe
2011-11-06 19:23:52	2620928	----a-w-	C:\Windows\SysWow64\fiiivD22on.exe
2011-11-06 19:23:33	2620928	----a-w-	C:\Windows\SysWow64\KvvSS2ibF3pn5aH.exe
2011-11-06 19:23:15	2620928	----a-w-	C:\Windows\SysWow64\qkkUrrlOBtxPyc1.exe
2011-11-06 19:23:14	2620928	----a-w-	C:\Windows\SysWow64\nuccSS2ib.exe
2011-11-06 19:22:19	2620928	----a-w-	C:\Windows\SysWow64\FZZZqhYXkUel.exe
2011-11-06 19:22:06	2620928	----a-w-	C:\Windows\SysWow64\SXqqjYYCekIrzNt.exe
2011-11-06 19:21:49	2620928	----a-w-	C:\Windows\SysWow64\JxA0uSi3n4Q6W7E.exe
2011-11-06 19:21:28	2620928	----a-w-	C:\Windows\SysWow64\uPPNyycA1uvDob4.exe
2011-11-06 19:21:06	2620928	----a-w-	C:\Windows\SysWow64\OKKK8gRZ9h.exe
2011-11-06 19:20:50	2620928	----a-w-	C:\Windows\SysWow64\KzzPNNycA1uv2.exe
2011-11-06 19:20:46	2620928	----a-w-	C:\Windows\SysWow64\N11ivDDon4pm5sJ.exe
2011-11-06 19:20:46	2620928	----a-w-	C:\Windows\SysWow64\byyc1v3n4msJdLg.exe
2011-11-06 19:20:46	2620928	----a-w-	C:\Windows\SysWow64\byc1v3n4HsJdLgZ.exe
2011-11-06 19:20:34	2620928	----a-w-	C:\Windows\SysWow64\nnnGG4aamHsW.exe
2011-11-06 19:19:53	2620928	----a-w-	C:\Windows\SysWow64\KwwwkUUVelOtz0y.exe
2011-11-06 19:19:53	2620928	----a-w-	C:\Windows\SysWow64\g1iivDD3onFam5.exe
2011-11-06 19:19:49	2620928	----a-w-	C:\Windows\SysWow64\B55ssQJJ6d.exe
2011-11-06 19:19:31	2620928	----a-w-	C:\Windows\SysWow64\pmGG5aaQJ6dK.exe
2011-11-06 19:19:31	2620928	----a-w-	C:\Windows\SysWow64\pGGG5aaQJ6dK.exe
2011-11-06 19:17:45	2620928	----a-w-	C:\Windows\SysWow64\ixxxP00ycS1vDon.exe
2011-11-06 19:17:42	2620928	----a-w-	C:\Windows\SysWow64\wRLL99gTXqjYekV.exe
2011-11-06 19:17:42	2620928	----a-w-	C:\Windows\SysWow64\GWKK77fRL9gTq.exe
2011-11-06 19:17:35	2620928	----a-w-	C:\Windows\SysWow64\jLL99gTXqjYCkIr.exe
2011-11-06 19:17:33	2620928	----a-w-	C:\Windows\SysWow64\p6ddWKK7fRL9.exe
2011-11-06 19:17:33	2620928	----a-w-	C:\Windows\SysWow64\mddWWK77fR9gT.exe
2011-11-06 19:17:33	2620928	----a-w-	C:\Windows\SysWow64\mdddWKK7fRLgT.exe
2011-11-06 19:17:17	2620928	----a-w-	C:\Windows\SysWow64\FAA00uvS2ib3pG5.exe
2011-11-06 19:15:31	2620928	----a-w-	C:\Windows\SysWow64\otttzPPNycA.exe
2011-11-06 19:15:05	2620928	----a-w-	C:\Windows\SysWow64\UllIBrrzPNyA1vS.exe
2011-11-06 19:15:00	2620928	----a-w-	C:\Windows\SysWow64\YKKK7fRRL9.exe
2011-11-06 19:15:00	2620928	----a-w-	C:\Windows\SysWow64\w2iibFF3pnG5QHd.exe
2011-11-06 19:15:00	2620928	----a-w-	C:\Windows\SysWow64\w2iibbF3pnG5QHd.exe
2011-11-06 19:14:59	2620928	----a-w-	C:\Windows\SysWow64\UbbFF3pnG5aQ6dK.exe
2011-11-06 19:14:51	2620928	----a-w-	C:\Windows\SysWow64\XqqqjUUCekBrzNx.exe
2011-11-06 19:14:51	2620928	----a-w-	C:\Windows\SysWow64\TTTXXqjjUCkIBzN.exe
2011-11-06 19:14:42	2620928	----a-w-	C:\Windows\SysWow64\hbbbF33pn.exe
2011-11-06 19:14:06	2620928	----a-w-	C:\Windows\SysWow64\HQQJJ7dEK8g.exe
2011-11-06 19:14:04	2620928	----a-w-	C:\Windows\SysWow64\X555sQQJ7d.exe
2011-11-06 19:13:33	2620928	----a-w-	C:\Windows\SysWow64\qA11iivD2onFpm5.exe
2011-11-06 19:13:25	2620928	----a-w-	C:\Windows\SysWow64\QCCCekIIVrONtAu.exe
2011-11-06 19:13:25	2620928	----a-w-	C:\Windows\SysWow64\NTTTXqjjYCkIVzN.exe
2011-11-06 19:13:25	2620928	----a-w-	C:\Windows\SysWow64\FRRRL99gTXqYCkI.exe
2011-11-06 19:13:25	2620928	----a-w-	C:\Windows\SysWow64\aYYCeekIVrzOtx0.exe
2011-11-06 19:13:17	2620928	----a-w-	C:\Windows\SysWow64\Z99hhTXwwUCe.exe
2011-11-06 19:13:17	2620928	----a-w-	C:\Windows\SysWow64\guSi4HWfLgZjwkV.exe
2011-11-06 19:13:16	2620928	----a-w-	C:\Windows\SysWow64\BfRRZZ9hTX.exe
2011-11-06 19:13:16	2620928	----a-w-	C:\Windows\SysWow64\BfffRZZ9hT.exe
2011-11-06 19:11:55	2620928	----a-w-	C:\Windows\SysWow64\gPPP0yycA1iD2n.exe
2011-11-06 19:10:58	2620928	----a-w-	C:\Windows\SysWow64\wddEEKfRZ9hXwUe.exe
2011-11-06 19:10:58	2620928	----a-w-	C:\Windows\SysWow64\V5sQJ6dKfZTXjUI.exe
2011-11-06 19:10:06	2620928	----a-w-	C:\Windows\SysWow64\zLL88gTZqhYCk.exe
2011-11-06 19:08:56	2620928	----a-w-	C:\Windows\SysWow64\zllOOBtzP0yc1.exe
2011-11-06 19:07:34	2620928	----a-w-	C:\Windows\SysWow64\TvvSSoob3mGaJdW.exe
2011-11-06 19:06:34	2620928	----a-w-	C:\Windows\SysWow64\nWWWJ77fEL8TZhY.exe
.
============= FINISH: 12:43:08.72 ===============

Edited by BoJangles00, 18 November 2011 - 02:32 PM.


BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:12:34 PM

Posted 19 November 2011 - 12:50 PM

Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems.

Somethings to remember while we are working together.

  • Do not run any other tool untill instructed to do so!
  • please Do not Attach logs or put in code boxes.
  • Tell me about any problems that have occurred during the fix.
  • Tell me of any other symptoms you may be having as these can help also.
  • Do not run anything while running a fix.
  • Do not run any other tool untill instructed to do so!


Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:12:34 PM

Posted 22 November 2011 - 09:24 PM

Hello

48 Hour bump

It has been more than 48 hours since my last post.

  • do you still need help with this?
  • do you need more time?
  • are you having problems following my instructions?
  • if after 48hrs you have not replied to this thread then it will have to be closed!

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#4 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:12:34 PM

Posted 25 November 2011 - 09:46 PM

Due to the lack of feedback, this topic is now closed.In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users