Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Search Redirection Problem


  • This topic is locked This topic is locked
9 replies to this topic

#1 vegetalordofall

vegetalordofall

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:01:36 AM

Posted 22 March 2012 - 06:28 AM

I have a problem when using search engines through the address bar in both Chrome and Internet Explorer, when it loads up the search page after entering criteria in the address bar and clicking on any link it will be redirected to random sites. This only happens when accessing the search engine through the address bars however, using google directly (as it is my homepage) does not produce redirects at all. I have tried a few different anti-malware programs and anti-viral solutions to no avail and have been pointed to this forum for help.

Here is my HijackThis log, please let me know if I can provide anymore info:



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:17:26, on 22/03/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Steam\steamapps\common\stronghold kingdoms\1.21.1.46\StrongholdKingdoms.exe
C:\Program Files (x86)\Steam\GameOverlayUI.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Genya\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3433945081-1426626829-1563182973-1011\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3433945081-1426626829-1563182973-1011\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Desura Install Service - Desura Pty Ltd - C:\Program Files (x86)\Common Files\Desura\desura_service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Intel® PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8783 bytes

BC AdBot (Login to Remove)

 


#2 ratman

ratman

    Bleepin' gnawing at it!


  • Malware Response Team
  • 1,799 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Scotland
  • Local time:07:36 AM

Posted 27 March 2012 - 11:07 AM

Hello vegetalordofall,

My name is ratman and and I will be helping you with your computer problems.

Before we begin, I would like to make a few things clear so that we can fix your problem as efficiently as possible:

  • Be sure to follow all my instructions carefully! If there is anything you don't understand, don't hesitate to ask.
  • Please do not do anything or perform other steps unless I have asked you to do so.
  • Please make sure you post all logs I ask you to, and make sure that the entire log gets posted.

====================================================================================

Please take note:
  • If you have since resolved the original problem you were having, I would appreciate you letting me know.
  • If you are unable to create a log because your computer cannot start up successfully please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
  • If you are unsure about any of these characteristics just post what you can and I will guide you.


Please tell me if you have your original Windows CD/DVD available.
<li>If you are unable to perform the steps I have recommended please try one more time and if unsuccessful alert us of such and I will design an alternate means of obtaining the necessary information.
<li>If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.
<li>Upon completing the steps below I will review your topic an do my best to resolve your issues.
<li>If you have already posted a DDS log, please do so again, as your situation may have changed.
<li>Use the 'Add Reply' and add the new log to this thread.


I need to see some up to date information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links if you no longer have it available. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.

Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE


I also need a new log from the GMER anti-rootkit Scanner.

Please first disable any CD emulation programs using the steps found in this topic:

Why we request you disable CD Emulation when receiving Malware Removal Advice


Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here:

How to create a GMER log




In your next reply, please copy/paste the contents of the following:
  • DDS.txt
  • Attach.txt
  • GMER.Log

regards, ratman

a proud member of:
Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM

If I have helped and you would like to show your appreciation you may Posted Image to the cause.



#3 vegetalordofall

vegetalordofall
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:01:36 AM

Posted 29 March 2012 - 06:39 PM

Thank you for your reply,

Unfortunatly GMER isnt allowing me to specify the required check boxes, apparently because it is not compatible with 64bit systems? Please let me know if you still require its log etc.

DDS:

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Genya at 0:29:10 on 2012-03-30
Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.8098.5038 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Windows\system32\IProsetMonitor.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Steam\steamapps\common\stronghold kingdoms\1.21.1.61\StrongholdKingdoms.exe
C:\Program Files (x86)\Steam\GameOverlayUI.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = https://www.google.co.uk/
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
uRun: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
uRun: [Google Update] "C:\Users\Genya\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [PlayNC Launcher]
uRunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe -update activex
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{7E19D7B8-1442-4D07-9E50-B309E4E7A9B1} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{ED56CB2A-71CF-46D6-A335-FF09C1A0DC78} : DhcpNameServer = 8.8.8.8
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO-X64: Increase performance and video formats for your HTML5 <video> - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun-x64: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 mv91xx;mv91xx;C:\Windows\system32\DRIVERS\mv91xx.sys --> C:\Windows\system32\DRIVERS\mv91xx.sys [?]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-2-28 2343816]
R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;C:\Windows\system32\IProsetMonitor.exe --> C:\Windows\system32\IProsetMonitor.exe [?]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-3-13 2348352]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-2-29 382272]
R3 e1cexpress;Intel® PRO/1000 PCI Express Network Connection Driver C;C:\Windows\system32\DRIVERS\e1c62x64.sys --> C:\Windows\system32\DRIVERS\e1c62x64.sys [?]
R3 e1qexpress;Intel® PRO/1000 PCI Express Network Connection Driver Q;C:\Windows\system32\DRIVERS\e1q62x64.sys --> C:\Windows\system32\DRIVERS\e1q62x64.sys [?]
R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 Desura Install Service;Desura Install Service;C:\Program Files (x86)\Common Files\Desura\desura_service.exe [2012-2-24 131912]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files (x86)\Microsoft SQL Server\100\Shared\sqladhlp.exe [2008-7-10 47128]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-7-10 369688]
.
=============== Created Last 30 ================
.
2012-03-29 23:09:41 8669240 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-03-29 23:09:35 8669240 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{73F898DE-0E4A-403E-86DE-F86EDBABB428}\mpengine.dll
2012-03-29 22:56:32 -------- d-----w- C:\Users\Genya\AppData\Local\{FA4DC6D7-F8C4-409F-B795-E35AC01D17E8}
2012-03-22 11:49:59 -------- d-----w- C:\Users\Genya\AppData\Local\{13244952-091F-46B9-8CEF-E964EEEE2454}
2012-03-22 11:49:37 -------- d-----w- C:\Users\Genya\AppData\Local\{AEA625C7-E488-4840-9893-8F4135DD48D0}
2012-03-22 11:17:08 388096 ----a-r- C:\Users\Genya\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-03-22 11:17:08 -------- d-----w- C:\Program Files (x86)\Trend Micro
2012-03-22 10:54:57 -------- d-----w- C:\Users\Genya\AppData\Roaming\Malwarebytes
2012-03-22 10:54:47 -------- d-----w- C:\ProgramData\Malwarebytes
2012-03-22 10:16:07 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2012-03-22 10:16:07 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2012-03-21 23:49:13 -------- d-----w- C:\Users\Genya\AppData\Local\{60B9E13A-F70D-417E-BCCA-63B1D02A439B}
2012-03-21 12:12:13 927800 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{93447081-8247-48DD-80B3-12B5061F086E}\gapaengine.dll
2012-03-21 12:10:34 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2012-03-21 12:10:33 -------- d-----w- C:\Program Files\Microsoft Security Client
2012-03-21 11:50:15 8643640 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1885FBE0-EE42-4613-B837-2586A756DA42}\mpengine.dll
2012-03-21 11:48:39 -------- d-----w- C:\Users\Genya\AppData\Local\{C09CA107-615D-4135-9545-776ACFB4637C}
2012-03-21 11:48:28 -------- d-----w- C:\Users\Genya\AppData\Local\{BFA25176-24FF-43E0-A523-2206421CEC6B}
2012-03-21 11:09:27 -------- d-----w- C:\Users\Genya\AppData\Local\{ACD5FC81-91C5-4472-8011-AE9EF05FB5EE}
2012-03-21 11:09:05 -------- d-----w- C:\Users\Genya\AppData\Local\{A441145C-3DA3-47DF-9742-EF52EEDE1DD4}
2012-03-20 23:08:41 -------- d-----w- C:\Users\Genya\AppData\Local\{3163A077-11FE-422F-BBA3-FFC1B1343789}
2012-03-20 23:08:19 -------- d-----w- C:\Users\Genya\AppData\Local\{2642B4E7-E7CD-41DC-9C56-CE029B89ACA3}
2012-03-20 11:08:07 -------- d-----w- C:\Users\Genya\AppData\Local\{4743C8A8-56D8-4529-8FE2-0D683D413F0C}
2012-03-20 11:07:45 -------- d-----w- C:\Users\Genya\AppData\Local\{10E5D914-725F-4C27-AF62-00A70138B01A}
2012-03-19 23:07:21 -------- d-----w- C:\Users\Genya\AppData\Local\{7A2C85B7-F2FC-48A8-B5DC-9BFD56FA4713}
2012-03-19 23:06:59 -------- d-----w- C:\Users\Genya\AppData\Local\{63322CBD-1016-4DC5-8688-35E6ADE763AB}
2012-03-19 11:06:47 -------- d-----w- C:\Users\Genya\AppData\Local\{681937F5-1E28-4A1D-A247-852A79E60F66}
2012-03-19 11:06:25 -------- d-----w- C:\Users\Genya\AppData\Local\{ED1D8E3B-8D5D-4BF0-9C60-321E69A7C686}
2012-03-18 23:06:02 -------- d-----w- C:\Users\Genya\AppData\Local\{58632B96-374E-4D72-B43D-FE049715E30C}
2012-03-18 23:05:40 -------- d-----w- C:\Users\Genya\AppData\Local\{304F36E5-B1E7-4CB6-98CF-60201F231EC0}
2012-03-18 11:05:28 -------- d-----w- C:\Users\Genya\AppData\Local\{A144D7F9-453B-4D7D-8E7F-1C9DA844897D}
2012-03-18 11:05:14 -------- d-----w- C:\Users\Genya\AppData\Local\{EA5377F4-F168-4C0C-874F-6B63DB160AA2}
2012-03-17 22:32:55 -------- d-----w- C:\Users\Genya\AppData\Local\{77D566DC-0739-4EEE-81EE-B14B6FCE8AC9}
2012-03-17 22:32:34 -------- d-----w- C:\Users\Genya\AppData\Local\{A03DACD5-B221-415F-9C72-7137DA18F0CA}
2012-03-17 10:32:22 -------- d-----w- C:\Users\Genya\AppData\Local\{F330D0E3-A960-4EAD-9239-9D26E1F7F332}
2012-03-17 10:32:11 -------- d-----w- C:\Users\Genya\AppData\Local\{930ABFE6-999F-403D-BBD1-5CF5D9A32508}
2012-03-16 22:17:46 -------- d-----w- C:\Users\Genya\AppData\Local\{ACF877D0-872C-4E84-9D42-634F4D6AF6BF}
2012-03-16 22:17:25 -------- d-----w- C:\Users\Genya\AppData\Local\{9641F72F-AA10-4A45-8BEB-824B0841EB14}
2012-03-16 10:43:10 -------- d-----w- C:\Users\Genya\AppData\Local\Geckofx
2012-03-16 10:38:22 -------- d-----w- C:\Users\Genya\AppData\Roaming\Firefly Studios
2012-03-16 10:17:13 -------- d-----w- C:\Users\Genya\AppData\Local\{706D2FDC-29D5-4C34-9180-21EF7CF39D90}
2012-03-16 10:16:51 -------- d-----w- C:\Users\Genya\AppData\Local\{A31C6CE2-6DB4-4C0D-B918-8F3FB9F06810}
2012-03-15 22:16:27 -------- d-----w- C:\Users\Genya\AppData\Local\{24708E28-ADB0-4149-A568-D564D24127C2}
2012-03-15 22:16:16 -------- d-----w- C:\Users\Genya\AppData\Local\{AB511285-72FF-4DDB-B0F8-9F859376AC79}
2012-03-15 10:16:03 -------- d-----w- C:\Users\Genya\AppData\Local\{357D51B4-5326-4776-9524-FD13EFED7526}
2012-03-15 10:15:39 -------- d-----w- C:\Users\Genya\AppData\Local\{0F7C5FFE-3361-4687-9C14-66F891A1C5FD}
2012-03-15 00:56:21 5559152 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-03-15 00:56:21 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-03-15 00:56:21 3913584 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-03-14 22:15:15 -------- d-----w- C:\Users\Genya\AppData\Local\{152F186B-FEEA-4792-A212-25732F29BA89}
2012-03-14 22:14:53 -------- d-----w- C:\Users\Genya\AppData\Local\{626EF7F6-C088-4B4C-B284-134221AEF9AC}
2012-03-14 17:26:02 3145728 ----a-w- C:\Windows\System32\win32k.sys
2012-03-14 17:24:10 1544192 ----a-w- C:\Windows\System32\DWrite.dll
2012-03-14 17:24:10 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
2012-03-14 10:15:01 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-03-14 10:15:01 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2012-03-14 10:15:01 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-03-14 10:15:01 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-03-14 10:15:01 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-03-14 10:15:01 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-03-14 10:15:01 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2012-03-14 10:14:41 -------- d-----w- C:\Users\Genya\AppData\Local\{90AF4437-EF6F-46EB-91A6-96D2BFE54DCC}
2012-03-14 10:14:29 -------- d-----w- C:\Users\Genya\AppData\Local\{E5EB5CAB-90C3-40A7-9AF6-E7C1C7F44789}
2012-03-13 22:03:55 -------- d-----w- C:\Users\Genya\AppData\Local\{B4989306-E997-4D08-BEC9-FFF637F2F3AA}
2012-03-13 22:03:33 -------- d-----w- C:\Users\Genya\AppData\Local\{5A7D84D6-EF22-451E-99F2-9DFE2A3A012B}
2012-03-13 16:36:08 -------- d-----w- C:\Program Files (x86)\Diablo II
2012-03-13 15:35:23 -------- d-----w- C:\Users\Genya\D2-1.12A-enGB
2012-03-13 15:34:30 -------- d-----w- C:\Users\Genya\D2LOD-1.12A-enGB
2012-03-13 15:34:26 -------- d-----w- C:\Program Files (x86)\Common Files\Blizzard Entertainment
2012-03-13 10:03:21 -------- d-----w- C:\Users\Genya\AppData\Local\{D63E18E9-F946-4417-B27E-4E7AAB590704}
2012-03-13 10:02:59 -------- d-----w- C:\Users\Genya\AppData\Local\{79488088-CF8D-4F8A-AE1D-BF24B1C4ACDD}
2012-03-12 22:02:35 -------- d-----w- C:\Users\Genya\AppData\Local\{B48047FC-76E2-4296-B5BA-E6F799290B9E}
2012-03-12 22:02:13 -------- d-----w- C:\Users\Genya\AppData\Local\{183E2F51-0D31-42BC-A190-7F36EA34CDFB}
2012-03-12 10:02:01 -------- d-----w- C:\Users\Genya\AppData\Local\{34C2D654-8B4E-43C4-8733-9C8A3726A218}
2012-03-12 10:01:39 -------- d-----w- C:\Users\Genya\AppData\Local\{9494B7BD-EB51-426D-B1FD-AAF8824C88B7}
2012-03-11 22:01:15 -------- d-----w- C:\Users\Genya\AppData\Local\{40FD835F-DBC6-4B24-8A3C-1808E5B6C3C7}
2012-03-11 10:00:30 -------- d-----w- C:\Users\Genya\AppData\Local\{950270BD-9E7F-4DEB-AA45-C7BAC6CE65EE}
2012-03-11 10:00:18 -------- d-----w- C:\Users\Genya\AppData\Local\{2FDC559D-069D-44A0-A4E0-2AD8DAEA0DCA}
2012-03-10 21:50:22 -------- d-----w- C:\Users\Genya\AppData\Local\{822D6A75-C475-4040-8BA2-D2FA8B44F5ED}
2012-03-10 21:50:00 -------- d-----w- C:\Users\Genya\AppData\Local\{5CF3E50F-B160-4B95-9BD8-3D69A832D7B2}
2012-03-10 09:49:48 -------- d-----w- C:\Users\Genya\AppData\Local\{0ACD77B7-7C7E-4008-A127-7A65CFF818B4}
2012-03-10 09:49:26 -------- d-----w- C:\Users\Genya\AppData\Local\{A576FAB4-F174-492D-A350-8039EE3B0212}
2012-03-09 21:49:02 -------- d-----w- C:\Users\Genya\AppData\Local\{7F585A08-A329-4F2D-B040-AC53A3FBCDA1}
2012-03-09 21:48:51 -------- d-----w- C:\Users\Genya\AppData\Local\{FE58BA73-9311-4AB4-8184-A070090F36ED}
2012-03-09 09:48:27 -------- d-----w- C:\Users\Genya\AppData\Local\{2510CC83-5766-4A54-AFF1-EBCA844BFB33}
2012-03-09 09:48:16 -------- d-----w- C:\Users\Genya\AppData\Local\{ABCF40F3-0C2A-4E8E-B6BB-E937F7C9D74A}
2012-03-08 21:46:44 -------- d-----w- C:\Users\Genya\AppData\Local\{38D00E04-9FD9-46F6-91E9-25155EE07DE0}
2012-03-08 21:46:33 -------- d-----w- C:\Users\Genya\AppData\Local\{D00EDC9A-C061-49D3-B646-BD2A80FA865A}
2012-03-08 09:46:22 -------- d-----w- C:\Users\Genya\AppData\Local\{561FC138-1AB5-49E9-BED3-BA482C4EB9CC}
2012-03-08 09:46:00 -------- d-----w- C:\Users\Genya\AppData\Local\{13C48BE3-8537-4DCA-A5B4-AC8507E7F569}
2012-03-07 21:45:36 -------- d-----w- C:\Users\Genya\AppData\Local\{E2D0663A-FA9E-4A81-BE54-1A14ED08BD6A}
2012-03-07 21:45:14 -------- d-----w- C:\Users\Genya\AppData\Local\{01EB7D35-7CA0-4489-BA94-7339B42EBD0A}
2012-03-07 09:45:02 -------- d-----w- C:\Users\Genya\AppData\Local\{E259BF7D-1B82-4847-9689-FE73B9F94C29}
2012-03-07 09:44:51 -------- d-----w- C:\Users\Genya\AppData\Local\{322CFD47-B0EA-47EE-B0B3-E5E1C593B934}
2012-03-06 20:50:28 -------- d-----w- C:\Users\Genya\AppData\Local\{A925BDA4-523D-40AE-8D83-21852F2502FD}
2012-03-06 08:49:55 -------- d-----w- C:\Users\Genya\AppData\Local\{E79E9D48-3A4E-49B3-8E4E-3B716D7B7F1F}
2012-03-06 08:49:44 -------- d-----w- C:\Users\Genya\AppData\Local\{3539F57B-0BA0-41C9-8B7F-DFD23BE98FAA}
2012-03-05 20:21:38 -------- d-----w- C:\Users\Genya\AppData\Local\{C214F34E-4605-4D47-8E73-516A155B8499}
2012-03-05 20:21:15 -------- d-----w- C:\Users\Genya\AppData\Local\{D277B47C-789F-4B16-8E64-2A52826F5700}
2012-03-05 20:00:18 -------- d-----w- C:\ProgramData\EA Core
2012-03-05 19:58:59 -------- d-----w- C:\Users\Genya\AppData\Roaming\OverPlay.net, LP
2012-03-05 19:57:42 -------- d-----w- C:\Program Files (x86)\Tap0901
2012-03-05 08:20:51 -------- d-----w- C:\Users\Genya\AppData\Local\{4547EE21-23B0-41D1-933A-D983906BD324}
2012-03-05 08:20:30 -------- d-----w- C:\Users\Genya\AppData\Local\{E5C57A74-A71E-40C6-AEEA-057C8BBDB6C7}
2012-03-04 20:20:05 -------- d-----w- C:\Users\Genya\AppData\Local\{371E7027-980A-422D-BC73-B42233D21DFB}
2012-03-04 20:19:54 -------- d-----w- C:\Users\Genya\AppData\Local\{A505DB31-8EA6-46C1-9960-A5D0218E1164}
2012-03-04 08:19:43 -------- d-----w- C:\Users\Genya\AppData\Local\{2AA54973-CBCD-41F8-B19E-92FEACE1E2EE}
2012-03-04 08:19:21 -------- d-----w- C:\Users\Genya\AppData\Local\{E7B8BC79-0E8B-4771-A832-00703D4B2E05}
2012-03-03 19:20:45 -------- d-----w- C:\Users\Genya\AppData\Local\{6E73ABDA-C374-4324-8ECC-F11BE9CE1559}
2012-03-03 19:20:23 -------- d-----w- C:\Users\Genya\AppData\Local\{B0926FF1-0C33-4852-9FCD-DB9F009899A3}
2012-03-03 07:48:45 -------- d-----w- C:\Users\Genya\AppData\Local\Temporary Projects
2012-03-03 07:20:11 -------- d-----w- C:\Users\Genya\AppData\Local\{6FF94D11-9DC1-4BE6-BFFA-8C284AE2A12D}
2012-03-03 07:20:00 -------- d-----w- C:\Users\Genya\AppData\Local\{FB1B3EB2-BB27-400E-8EBA-AB1137028AF1}
2012-03-02 19:03:05 -------- d-----w- C:\Users\Genya\AppData\Local\{465639F6-53E0-449F-9FC2-8ADE9E2CDBE7}
2012-03-02 19:02:43 -------- d-----w- C:\Users\Genya\AppData\Local\{8F2D78E0-9467-44B2-AFA3-8B83C57FC9A3}
2012-03-02 11:56:51 50200 ----a-w- C:\Windows\SysWow64\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.0.1600.22.dll
2012-03-02 11:56:48 79896 ----a-w- C:\Windows\SysWow64\perf-MSSQL$SQLEXPRESS-sqlctr10.0.1600.22.dll
2012-03-02 11:56:28 -------- d-----w- C:\Windows\SysWow64\1033
2012-03-02 11:56:28 -------- d-----w- C:\Windows\System32\1033
2012-03-02 11:56:28 -------- d-----w- C:\Program Files\Microsoft SQL Server
2012-03-02 11:55:47 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server
2012-03-02 11:55:44 -------- d-----w- C:\Program Files (x86)\Microsoft Synchronization Services
2012-03-02 11:55:33 -------- d-----w- C:\Users\Genya\AppData\Local\Microsoft Help
2012-03-02 07:02:31 -------- d-----w- C:\Users\Genya\AppData\Local\{B902FE03-AAEA-47B2-A002-7BC079222EF4}
2012-03-02 07:02:09 -------- d-----w- C:\Users\Genya\AppData\Local\{A5F8622B-6636-4D76-8E20-52045C56AA54}
2012-03-01 19:01:45 -------- d-----w- C:\Users\Genya\AppData\Local\{75622E7F-B51B-41F5-9319-21F7B73C19A9}
2012-03-01 10:14:31 -------- d-----w- C:\Users\Genya\AppData\Roaming\fltk.org
2012-03-01 10:14:31 -------- d-----w- C:\ProgramData\fltk.org
2012-03-01 07:01:11 -------- d-----w- C:\Users\Genya\AppData\Local\{CE62EE4C-E485-4667-A651-3BFE7EC75BE0}
2012-03-01 07:01:00 -------- d-----w- C:\Users\Genya\AppData\Local\{C21EB542-CCE5-4405-B962-D51CCF5D8502}
2012-03-01 06:55:33 -------- d-----w- C:\Program Files (x86)\LogMeIn Hamachi
2012-02-29 16:45:19 -------- d-----w- C:\Users\Genya\AppData\Local\{2FD251D0-6A71-4F05-8BAB-E1CEB291F346}
2012-02-29 13:26:56 416064 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2012-02-29 04:44:45 -------- d-----w- C:\Users\Genya\AppData\Local\{B71E0C7B-C55F-47D2-9323-921CA274CBC5}
2012-02-29 04:44:34 -------- d-----w- C:\Users\Genya\AppData\Local\{A12A8DE3-9FDA-4865-83BC-D3BBEA165CE3}
.
==================== Find3M ====================
.
2012-02-29 21:00:22 3089728 ----a-w- C:\Windows\System32\nvsvc64.dll
2012-02-29 21:00:09 6074176 ----a-w- C:\Windows\System32\nvcpl.dll
2012-02-29 20:59:47 889664 ----a-w- C:\Windows\System32\nvvsvc.exe
2012-02-29 20:59:47 63296 ----a-w- C:\Windows\System32\nvshext.dll
2012-02-29 20:59:47 118080 ----a-w- C:\Windows\System32\nvmctray.dll
2012-02-29 20:59:29 2515790 ----a-w- C:\Windows\System32\nvcoproc.bin
2012-02-17 10:48:24 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-15 18:04:48 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-01-31 12:44:20 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-01-17 12:46:01 31040 ----a-w- C:\Windows\System32\nvhdap64.dll
2012-01-17 12:45:56 188224 ----a-w- C:\Windows\System32\drivers\nvhda64v.sys
2012-01-17 12:45:55 1451840 ----a-w- C:\Windows\System32\nvhdagenco6420103.dll
2012-01-04 10:44:20 509952 ----a-w- C:\Windows\System32\ntshrui.dll
2012-01-04 08:58:41 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
2012-01-04 00:48:42 354176 ----a-w- C:\Windows\SysWow64\DivXControlPanelApplet.cpl
.
============= FINISH: 0:36:03.55 ===============

Attached Files



#4 ratman

ratman

    Bleepin' gnawing at it!


  • Malware Response Team
  • 1,799 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Scotland
  • Local time:07:36 AM

Posted 29 March 2012 - 06:53 PM

Hello vegetalordofall,

Please download ComboFix from here:

Link


* IMPORTANT !!! Save ComboFix.exe to your Desktop.

  • Disable your AntiVirus and AntiSpyware applications including Firewalls, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
  • Right click on ComboFix icon %20http://www.bleepstatic.com/combofix/en/cf-icon.jpg%20 and run as admin then follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

====================================================================================

I'd like you to run a scan with aswMBR
Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

====================================================================================

In your next reply, please copy/paste the contents of the following:
  • C:\Combofix.txt
  • aswMBR Log
How is your machine running now?

regards, ratman

a proud member of:
Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM

If I have helped and you would like to show your appreciation you may Posted Image to the cause.



#5 vegetalordofall

vegetalordofall
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:01:36 AM

Posted 29 March 2012 - 08:50 PM

aswMBR does not appear to run at all when executed.

Using address bar searches still results in redirection upon clicking search engine links.

Here is the combofix log:

ComboFix 12-03-29.02 - Genya 30/03/2012 1:36.1.8 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.8098.5996 [GMT 1:00]
Running from: c:\users\Genya\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\~BtbrJWiKqFdC3a
c:\programdata\~BtbrJWiKqFdC3ar
c:\programdata\BtbrJWiKqFdC3a
c:\users\Genya\217e332b441ea87d7d53baf1a1253781b8fa5512_full.jpg
c:\users\Genya\AppData\Local\assembly\tmp
c:\users\Genya\Minecraft.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-02-28 to 2012-03-30 )))))))))))))))))))))))))))))))
.
.
2012-03-30 01:19 . 2012-03-30 01:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-03-29 23:09 . 2012-03-13 20:27 8669240 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-03-29 23:09 . 2012-03-13 20:27 8669240 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{73F898DE-0E4A-403E-86DE-F86EDBABB428}\mpengine.dll
2012-03-22 11:17 . 2012-03-22 11:17 388096 ----a-r- c:\users\Genya\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-03-22 11:17 . 2012-03-22 11:17 -------- d-----w- c:\program files (x86)\Trend Micro
2012-03-22 10:54 . 2012-03-22 10:54 -------- d-----w- c:\users\Genya\AppData\Roaming\Malwarebytes
2012-03-22 10:54 . 2012-03-22 10:54 -------- d-----w- c:\programdata\Malwarebytes
2012-03-22 10:16 . 2012-03-22 10:35 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2012-03-22 10:16 . 2012-03-22 10:35 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-03-21 12:12 . 2012-03-21 12:12 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{93447081-8247-48DD-80B3-12B5061F086E}\gapaengine.dll
2012-03-21 12:10 . 2012-03-21 12:10 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-03-21 12:10 . 2012-03-21 12:10 -------- d-----w- c:\program files\Microsoft Security Client
2012-03-21 11:50 . 2012-02-08 07:13 8643640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1885FBE0-EE42-4613-B837-2586A756DA42}\mpengine.dll
2012-03-16 10:43 . 2012-03-21 11:43 -------- d-----w- c:\users\Genya\AppData\Local\Geckofx
2012-03-16 10:38 . 2012-03-16 10:38 -------- d-----w- c:\users\Genya\AppData\Roaming\Firefly Studios
2012-03-15 00:56 . 2011-11-19 15:20 5559152 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-15 00:56 . 2011-11-19 14:50 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-03-15 00:56 . 2011-11-19 14:50 3913584 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-03-14 17:26 . 2012-02-03 04:34 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-03-14 17:24 . 2012-02-10 06:36 1544192 ----a-w- c:\windows\system32\DWrite.dll
2012-03-14 17:24 . 2012-02-10 05:38 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-03-14 10:15 . 2012-02-17 06:38 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-03-14 10:15 . 2012-02-17 05:34 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-03-14 10:15 . 2012-02-17 04:58 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-14 10:15 . 2012-02-17 04:57 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-03-14 10:15 . 2012-01-25 06:38 77312 ----a-w- c:\windows\system32\rdpwsx.dll
2012-03-14 10:15 . 2012-01-25 06:38 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-03-14 10:15 . 2012-01-25 06:33 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-03-13 16:46 . 2012-03-21 11:50 -------- d-----w- c:\users\UpdatusUser
2012-03-13 16:36 . 2012-03-21 20:37 -------- d-----w- c:\program files (x86)\Diablo II
2012-03-13 15:35 . 2012-03-21 11:46 -------- d-----w- c:\users\Genya\D2-1.12A-enGB
2012-03-13 15:34 . 2012-03-21 11:46 -------- d-----w- c:\users\Genya\D2LOD-1.12A-enGB
2012-03-13 15:34 . 2012-03-21 11:46 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
2012-03-05 20:00 . 2012-03-05 20:00 -------- d-----w- c:\programdata\EA Core
2012-03-05 19:58 . 2012-03-21 11:46 -------- d-----w- c:\users\Genya\AppData\Roaming\OverPlay.net, LP
2012-03-05 19:57 . 2012-03-21 11:46 -------- d-----w- c:\program files (x86)\Tap0901
2012-03-03 07:48 . 2012-03-03 08:22 -------- d-----w- c:\users\Genya\AppData\Local\Temporary Projects
2012-03-03 01:21 . 2012-03-03 01:21 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2012-03-02 11:56 . 2008-07-10 16:33 50200 ----a-w- c:\windows\SysWow64\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.0.1600.22.dll
2012-03-02 11:56 . 2008-07-10 16:33 79896 ----a-w- c:\windows\SysWow64\perf-MSSQL$SQLEXPRESS-sqlctr10.0.1600.22.dll
2012-03-02 11:56 . 2012-03-21 11:46 -------- d-----w- c:\windows\SysWow64\1033
2012-03-02 11:56 . 2012-03-21 11:46 -------- d-----w- c:\program files\Microsoft SQL Server
2012-03-02 11:56 . 2012-03-02 11:56 -------- d-----w- c:\windows\system32\1033
2012-03-02 11:55 . 2012-03-21 11:46 -------- d-----w- c:\program files (x86)\Microsoft SQL Server
2012-03-02 11:55 . 2012-03-21 11:41 -------- d-----w- c:\program files (x86)\Microsoft Synchronization Services
2012-03-02 11:55 . 2012-03-02 11:55 -------- d-----w- c:\users\Genya\AppData\Local\Microsoft Help
2012-03-02 11:55 . 2012-03-21 11:46 -------- d-----w- c:\programdata\Microsoft Help
2012-03-02 11:55 . 2012-03-21 11:46 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 9.0
2012-03-02 11:55 . 2012-03-21 11:41 -------- d-----w- c:\program files (x86)\Microsoft SDKs
2012-03-02 11:55 . 2012-03-21 11:43 -------- d-----w- c:\program files\Microsoft SDKs
2012-03-02 11:54 . 2012-03-21 11:43 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2012-03-01 10:14 . 2012-03-01 10:14 -------- d-----w- c:\users\Genya\AppData\Roaming\fltk.org
2012-03-01 10:14 . 2012-03-01 10:14 -------- d-----w- c:\programdata\fltk.org
2012-03-01 06:55 . 2012-03-21 11:46 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2012-02-29 13:26 . 2012-02-29 13:26 416064 ----a-w- c:\windows\SysWow64\nvStreaming.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-01 00:02 . 2011-11-03 01:46 9717568 ----a-w- c:\windows\system32\nvwgf2umx.dll
2012-03-01 00:02 . 2011-11-03 01:46 7713088 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2012-03-01 00:02 . 2011-11-03 01:46 17642816 ----a-w- c:\windows\system32\nvd3dumx.dll
2012-03-01 00:02 . 2011-08-29 19:07 1737536 ----a-w- c:\windows\system32\nvdispco64.dll
2012-03-01 00:02 . 2011-08-29 19:07 1466176 ----a-w- c:\windows\system32\nvgenco64.dll
2012-03-01 00:02 . 2011-07-26 12:22 2660160 ----a-w- c:\windows\system32\nvapi64.dll
2012-03-01 00:02 . 2011-07-26 12:22 15009600 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2012-02-29 21:00 . 2011-07-26 12:22 3089728 ----a-w- c:\windows\system32\nvsvc64.dll
2012-02-29 21:00 . 2011-07-26 12:22 6074176 ----a-w- c:\windows\system32\nvcpl.dll
2012-02-29 20:59 . 2011-07-26 12:22 889664 ----a-w- c:\windows\system32\nvvsvc.exe
2012-02-29 20:59 . 2011-07-26 12:22 63296 ----a-w- c:\windows\system32\nvshext.dll
2012-02-29 20:59 . 2011-07-26 12:22 118080 ----a-w- c:\windows\system32\nvmctray.dll
2012-02-17 10:48 . 2011-07-28 12:21 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-15 18:04 . 2011-07-29 08:13 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-01-31 12:44 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-01-04 10:44 . 2012-02-15 08:46 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-01-04 08:58 . 2012-02-15 08:46 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-01-04 00:48 . 2012-01-04 00:48 354176 ----a-w- c:\windows\SysWow64\DivXControlPanelApplet.cpl
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-09-25 1242448]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2011-07-28 3077528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-02-28 1987976]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Desura Install Service;Desura Install Service;c:\program files (x86)\Common Files\Desura\desura_service.exe [2012-02-24 131912]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\users\admin\Desktop\2NVIDIA\REALTEMP\WinRing0x64.sys [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 47128]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-10 369688]
S0 mv91xx;mv91xx;c:\windows\system32\DRIVERS\mv91xx.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-02-28 2343816]
S2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe [x]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-03-01 2348352]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-29 382272]
S3 e1cexpress;Intel® PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\DRIVERS\e1c62x64.sys [x]
S3 e1qexpress;Intel® PRO/1000 PCI Express Network Connection Driver Q;c:\windows\system32\DRIVERS\e1q62x64.sys [x]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3433945081-1426626829-1563182973-1003Core.job
- c:\users\Genya\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-29 07:26]
.
2012-03-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3433945081-1426626829-1563182973-1003UA.job
- c:\users\Genya\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-29 07:26]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-05-03 11842152]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-31 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-31 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-31 416024]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = https://www.google.co.uk/
mLocal Page = c:\windows\SysWOW64\blank.htm
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-PlayNC Launcher - (no file)
AddRemove-{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB} - c:\program files (x86)\Common Files\BioWare\Uninstall Mass Effect 2.exe
AddRemove-UnityWebPlayer - c:\users\Genya\AppData\Local\Unity\WebPlayer\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3433945081-1426626829-1563182973-1003\Software\SecuROM\License information*]
"datasecu"=hex:0b,ee,8f,3b,81,5b,c3,f0,56,8d,70,e0,c4,62,ba,ab,87,6c,e6,b3,4d,
14,3b,3a,17,80,a6,64,a9,4f,dd,17,ec,96,51,10,78,d4,17,74,84,2d,a7,80,d7,52,\
"rkeysecu"=hex:b7,b6,25,85,91,58,ef,5a,b9,2b,d9,ae,c1,44,36,dd
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
.
**************************************************************************
.
Completion time: 2012-03-30 02:42:29 - machine was rebooted
ComboFix-quarantined-files.txt 2012-03-30 01:42
.
Pre-Run: 197,212,430,336 bytes free
Post-Run: 196,660,113,408 bytes free
.
- - End Of File - - AD04CF4D002137156739A950C0ACE090

Edited by vegetalordofall, 30 March 2012 - 02:28 AM.


#6 ratman

ratman

    Bleepin' gnawing at it!


  • Malware Response Team
  • 1,799 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Scotland
  • Local time:07:36 AM

Posted 30 March 2012 - 05:07 AM

Hello vegetalordofall,

I want you to run TDSSKiller:

Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!
Be sure to download TDSSKiller.exe from Kaspersky's website and not TDSSKiller.zip.
  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.

===================================================================================



In your next reply, please copy/paste the contents of the following:
  • TDSSKiller Log


How is your machine running now?
regards, ratman

a proud member of:
Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM

If I have helped and you would like to show your appreciation you may Posted Image to the cause.



#7 vegetalordofall

vegetalordofall
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:01:36 AM

Posted 30 March 2012 - 06:00 AM

TDSS does not seem to run regardless of changing its filetype and name.

#8 ratman

ratman

    Bleepin' gnawing at it!


  • Malware Response Team
  • 1,799 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Scotland
  • Local time:07:36 AM

Posted 30 March 2012 - 06:49 AM

Hello vegetalordofall,

I would like you to run Farbar's Recovery Scan Tool.

For this you will need a USB flash drive.

Download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select English as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select English as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
[*]Select Command Prompt[*]In the command window type in notepad and press Enter.[*]The notepad opens. Under File menu select Open.[*]Select "Computer" and find your flash drive letter and close the notepad.[*]In the command window type e:\frst64 and press Enter
Note: Replace letter e with the drive letter of your flash drive.[*]The tool will start to run.[*]When the tool opens click Yes to disclaimer.[*]Press Scan button.[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.[/list]
In your next reply, please copy/paste the contents of the following:
  • FRST.txt

regards, ratman

a proud member of:
Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM

If I have helped and you would like to show your appreciation you may Posted Image to the cause.



#9 ratman

ratman

    Bleepin' gnawing at it!


  • Malware Response Team
  • 1,799 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Scotland
  • Local time:07:36 AM

Posted 05 April 2012 - 10:40 AM

Hello vegetalordofall,

I have not had a reply from you for more than 5 days. Can you please tell me if you still need help with your computer as I am unable to help other members with their problems while I have your topic still open. The time taken between posts can also change the situation with your PC making it more difficult to help you.
regards, ratman

a proud member of:
Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM

If I have helped and you would like to show your appreciation you may Posted Image to the cause.



#10 ratman

ratman

    Bleepin' gnawing at it!


  • Malware Response Team
  • 1,799 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Scotland
  • Local time:07:36 AM

Posted 09 April 2012 - 09:49 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.
regards, ratman

a proud member of:
Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM

If I have helped and you would like to show your appreciation you may Posted Image to the cause.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users