Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Multiple PUP's, Freeze.com, Conduit Malware


  • This topic is locked This topic is locked
2 replies to this topic

#1 oom

oom

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:11:05 AM

Posted 20 September 2014 - 12:27 PM

Hello I was having issues with my computer running slow and my wireless has been sluggish. I was able to remove some malware with mwb, hitmanpro, awdcleaner. Some files were found by the tdsskill program also. Here is a DDS scan log of my computer after it was removed.

 

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 11.0.9600.17280  BrowserJavaVersion: 10.60.2
Run by Jonathan at 13:20:33 on 2014-09-20
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.3959.665 [GMT -4:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
C:\Windows\system32\mfevtps.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Secunia\PSI\PSIA.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\McAfee\MSC\McAPExe.exe
C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files (x86)\Razer\Naga Epic\NagaEpicSysTray.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\WUDFHost.exe
C:\PROGRA~2\Raptr\raptr.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\PROGRA~2\Raptr\raptr_im.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Raptr\raptr_ep64.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\HitmanPro\hmpsched.exe
C:\Users\Jonathan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jonathan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jonathan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jonathan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jonathan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jonathan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\System32\cleanmgr.exe
C:\Users\Jonathan\AppData\Local\Temp\1B57EB2B-BD15-4165-8CF3-32A623729DA2\dismhost.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files (x86)\Secunia\PSI\psi.exe
C:\Program Files\HitmanPro\HitmanPro.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Secunia\PSI\sua.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files (x86)\PrivaZer\PrivaZer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\msiexec.exe
C:\Users\Jonathan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jonathan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mStart Page = about:blank
uProxyOverride = localhost;127.0.0.1:9421;<local>;*.local
mWinlogon: Userinit = userinit.exe
uRun: [Google Update] "C:\Users\Jonathan\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
uRun: [EPSON NX420 Series] C:\Windows\System32\spool\DRIVERS\x64\3\E_IATIGCA.EXE /FU "C:\Windows\TEMP\E_SA227.tmp" /EF "HKCU"
uRun: [Raptr] C:\PROGRA~2\Raptr\raptrstub.exe --startup
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [Razer Naga Driver] C:\Program Files (x86)\Razer\Naga Epic\NagaEpicSysTray.exe
mRun: [mcpltui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\LOGITE~1.LNK - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SECUNI~1.LNK - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: &Download All with FlashGet - C:\Program Files (x86)\FlashGet\jc_all.htm
IE: &Download with FlashGet - C:\Program Files (x86)\FlashGet\jc_link.htm
IE: Download all with Free Download Manager - C:\Program Files (x86)\Download Manager\dlall.htm
IE: Download selected with Free Download Manager - C:\Program Files (x86)\Download Manager\dlselected.htm
IE: Download video with Free Download Manager - C:\Program Files (x86)\Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - C:\Program Files (x86)\Download Manager\dllink.htm
Trusted Zone: aeriagames.com
Trusted Zone: aeriagames.com
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {5C1B293E-DA77-4AFF-8B52-63DEF8C8A071} - hxxp://download.netmarble.net/ActiveX/NMAutoUpdateX/NMAutoUpdateX_1.0.1.1_20091109.cab
DPF: {89F434A7-4A49-4394-AC02-007480331AE2} - hxxp://download.netmarble.net/ActiveX/NMAutoUpdateX/SystemIDInfo/NMSystemIDInfo_1.0.0.1.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{61F6180F-1370-468A-A646-D1429B88340A} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{AA0AC9E6-B673-45A7-B7A3-5172CC9CFBE6} : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{AA0AC9E6-B673-45A7-B7A3-5172CC9CFBE6} : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{AA0AC9E6-B673-45A7-B7A3-5172CC9CFBE6}\348494E4F5E45445 : DHCPNameServer = 192.168.1.1
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
x64-mStart Page = about:blank
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - <orphaned>
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
Hosts: 255.255.255.255 bolscripts.net
Hosts: 255.255.255.255 www.bolscripts.net
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\System32\drivers\mfehidk.sys [2011-1-3 786296]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\System32\drivers\mfewfpk.sys [2011-1-3 348552]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2013-12-19 94720]
R3 cfwids;McAfee Inc. cfwids;C:\Windows\System32\drivers\cfwids.sys [2011-1-3 72128]
R3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-1-18 56344]
R3 hitmanpro37;HitmanPro 3.7 Support Driver;C:\Windows\System32\drivers\hitmanpro37.sys [2014-9-20 32512]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2014-9-20 25816]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\drivers\MBAMSwissArmy.sys [2014-9-20 122584]
R3 MBAMWebAccessControl;MBAMWebAccessControl;C:\Windows\System32\drivers\mwac.sys [2014-9-20 63704]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\System32\drivers\mfeavfk.sys [2011-1-3 313544]
R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\System32\drivers\mfefirek.sys [2011-1-3 523792]
R3 mfencbdc;McAfee Inc. mfencbdc;C:\Windows\System32\drivers\mfencbdc.sys [2014-7-24 444720]
R3 PSI;PSI;C:\Windows\System32\drivers\psi_mf_amd64.sys [2013-12-6 18456]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;C:\Windows\System32\drivers\RTL8192su.sys [2010-9-29 695400]
R3 rzendpt;rzendpt;C:\Windows\System32\drivers\rzendpt.sys [2013-7-10 39096]
R3 rzudd;Razer Mouse Driver;C:\Windows\System32\drivers\rzudd.sys [2013-7-10 137400]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2013-6-26 767144]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2013-6-26 273576]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2013-6-26 28840]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2013-6-26 23208]
S3 BRDriver64;BRDriver64;C:\ProgramData\BitRaider\BRDriver64.sys [2013-6-13 75048]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2010-12-6 48488]
S3 HipShieldK;McAfee Inc. HipShieldK;C:\Windows\System32\drivers\HipShieldK.sys [2014-4-16 197704]
S3 mfencrk;McAfee Inc. mfencrk;C:\Windows\System32\drivers\mfencrk.sys [2014-7-24 96592]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;C:\Windows\System32\drivers\MijXfilt.sys [2014-7-10 115272]
S3 PCAMp50a64;PCAMp50a64 NDIS Protocol Driver;C:\Windows\System32\drivers\PCAMp50a64.sys [2010-12-3 43328]
S3 PCASp50a64;PCASp50a64 NDIS Protocol Driver;C:\Windows\System32\drivers\PCASp50a64.sys [2010-12-3 41280]
S3 Revoflt;Revoflt;C:\Windows\System32\drivers\revoflt.sys [2014-9-20 31800]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-8-27 325664]
S3 RzSynapse;Razer Driver;C:\Windows\System32\drivers\RzSynapse.sys [2010-12-16 126464]
S3 ScreamBAudioSvc;ScreamBee Audio;C:\Windows\System32\drivers\ScreamingBAudio64.sys [2010-7-1 38992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-5-2 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 WinRing0_1_2_0;WinRing0_1_2_0;C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [2012-11-13 14544]
.
=============== File Associations ===============
.
FileExt: .reg: regfile="regedit.exe" "%1"
ShellExec: QSync.exe: Open="C:\Program Files (x86)\Logitech\Video\QSync.exe"
.
=============== Created Last 30 ================
.
2014-09-20 17:03:49 -------- d-----w- C:\Users\Jonathan\AppData\Local\PrivaZer
2014-09-20 17:03:49 -------- d-----w- C:\ProgramData\privazer
2014-09-20 17:03:49 -------- d-----w- C:\Program Files (x86)\PrivaZer
2014-09-20 16:56:10 -------- d-----w- C:\Users\Jonathan\AppData\Local\Secunia PSI
2014-09-20 16:44:37 32512 ----a-w- C:\Windows\System32\drivers\hitmanpro37.sys
2014-09-20 16:44:22 -------- d-----w- C:\TDSSKiller_Quarantine
2014-09-20 16:24:26 -------- d-----w- C:\Users\Jonathan\AppData\Local\VS Revo Group
2014-09-20 16:23:19 31800 ----a-w- C:\Windows\System32\drivers\revoflt.sys
2014-09-20 16:23:19 -------- d-----w- C:\ProgramData\VS Revo Group
2014-09-20 16:23:15 -------- d-----w- C:\Program Files\VS Revo Group
2014-09-20 16:21:40 -------- d-----w- C:\Program Files (x86)\Secunia
2014-09-20 16:18:27 536576 ----a-w- C:\Windows\SysWow64\sqlite3.dll
2014-09-20 16:15:28 -------- d-----w- C:\AdwCleaner
2014-09-20 16:02:39 -------- d-----w- C:\Users\Jonathan\AppData\Local\AntiLogger Free
2014-09-20 16:00:28 122584 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-09-20 15:59:55 91352 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-09-20 15:59:55 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys
2014-09-20 15:59:55 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-09-20 15:59:54 -------- d-----w- C:\ProgramData\Malwarebytes
2014-09-20 15:59:54 -------- d-----w- C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-20 15:49:34 -------- d-----w- C:\Windows\pss
2014-09-20 15:44:57 -------- d-----w- C:\Program Files\HitmanPro
2014-09-20 15:41:27 -------- d-----w- C:\ProgramData\HitmanPro
2014-09-20 02:03:25 -------- d-----w- C:\Users\Jonathan\AppData\Local\Glyph
2014-09-20 02:03:25 -------- d-----w- C:\ProgramData\Glyph
2014-09-20 02:03:22 -------- d-----w- C:\Program Files (x86)\Glyph
2014-09-12 03:31:59 977408 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
2014-09-12 03:10:55 2777088 ----a-w- C:\Windows\System32\msmpeg2vdec.dll
2014-09-12 03:10:55 2285056 ----a-w- C:\Windows\SysWow64\msmpeg2vdec.dll
2014-09-11 23:22:49 793600 ----a-w- C:\Windows\SysWow64\TSWorkspace.dll
2014-09-11 23:22:49 1031168 ----a-w- C:\Windows\System32\TSWorkspace.dll
2014-09-11 23:22:25 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2014-09-11 23:22:25 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2014-09-11 23:22:11 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2014-09-11 23:22:11 728064 ----a-w- C:\Windows\System32\kerberos.dll
2014-09-11 23:22:11 550912 ----a-w- C:\Windows\SysWow64\kerberos.dll
2014-09-11 23:22:11 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2014-09-11 23:22:11 1460736 ----a-w- C:\Windows\System32\lsasrv.dll
2014-09-11 23:22:05 578048 ----a-w- C:\Windows\System32\aepdu.dll
2014-09-11 23:22:04 424448 ----a-w- C:\Windows\System32\aeinv.dll
2014-09-10 02:45:12 10036224 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2014-09-07 18:07:35 -------- d-----w- C:\Users\Jonathan\AppData\Roaming\library_dir
2014-09-07 18:07:04 -------- d-----w- C:\Users\Jonathan\AppData\Roaming\Raptr
2014-09-07 18:07:04 -------- d-----w- C:\Program Files (x86)\Raptr
2014-09-07 18:07:00 -------- d-----w- C:\ProgramData\AMD
2014-09-07 18:06:59 -------- d-----w- C:\Program Files (x86)\AMD AVT
2014-09-07 18:06:56 -------- d-----w- C:\Program Files (x86)\Common Files\ATI Technologies
2014-09-07 18:03:53 -------- d-----w- C:\Program Files\AMD
2014-09-07 18:03:01 -------- d-----w- C:\Program Files\Common Files\ATI Technologies
2014-09-07 18:01:36 -------- d-----w- C:\Program Files\ATI Technologies
2014-09-07 18:01:34 -------- d-----w- C:\Program Files\ATI
2014-09-07 17:58:37 -------- d-----w- C:\AMD
2014-09-05 20:49:20 -------- d-----w- C:\Program Files (x86)\LogMeIn Hamachi
2014-08-31 04:06:24 -------- d-----w- C:\Users\Jonathan\AppData\Local\Cockatrice
2014-08-31 04:04:59 -------- d-----w- C:\Program Files (x86)\Cockatrice
2014-08-28 00:50:19 3163648 ----a-w- C:\Windows\System32\win32k.sys
2014-08-28 00:50:18 404480 ----a-w- C:\Windows\System32\gdi32.dll
2014-08-28 00:50:17 311808 ----a-w- C:\Windows\SysWow64\gdi32.dll
2014-08-24 06:00:00 -------- d-----w- C:\Users\Jonathan\AppData\Local\Adobe
2014-08-24 04:34:28 -------- d-----w- C:\Users\Jonathan\AppData\Roaming\BoL
.
==================== Find3M  ====================
.
2014-09-20 17:21:57 12872 ----a-w- C:\Windows\System32\bootdelete.exe
2014-09-20 15:32:05 2778377 ----a-w- C:\Users\Jonathan\AppData\Roaming\LeagueBotSetup_12_20_t1.exe
2014-09-10 02:45:19 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-09-10 02:45:19 701104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-08-18 22:29:49 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-08-18 22:29:35 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-08-18 22:19:53 5833728 ----a-w- C:\Windows\System32\jscript9.dll
2014-08-18 22:15:34 547328 ----a-w- C:\Windows\System32\vbscript.dll
2014-08-18 22:15:09 66048 ----a-w- C:\Windows\System32\iesetup.dll
2014-08-18 22:14:38 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-08-18 22:14:10 83968 ----a-w- C:\Windows\System32\MshtmlDac.dll
2014-08-18 22:08:55 4232704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-08-18 22:03:47 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-08-18 22:03:37 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-08-18 22:03:01 758272 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-08-18 21:57:44 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-08-18 21:56:17 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-08-18 21:46:26 454656 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-08-18 21:45:23 61952 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-08-18 21:45:12 72704 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-08-18 21:44:44 51200 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-08-18 21:44:09 61952 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2014-08-18 21:36:07 112128 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-08-18 21:35:24 597504 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-08-18 21:23:17 2104832 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-08-18 21:23:16 1249280 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2014-08-18 21:22:48 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-08-18 21:15:13 2310656 ----a-w- C:\Windows\System32\wininet.dll
2014-08-18 21:08:54 2014208 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-08-18 21:07:44 1068032 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2014-08-18 20:46:48 1812992 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-08-17 23:22:18 2048 ----a-w- C:\Users\Jonathan\AppData\Roaming\LeagueBotSetup_12_20_t.exe
2014-07-25 06:35:46 875688 ----a-w- C:\Windows\SysWow64\msvcr120_clr0400.dll
2014-07-25 03:47:06 869544 ----a-w- C:\Windows\System32\msvcr120_clr0400.dll
2014-07-24 18:33:10 11336 ----a-w- C:\Windows\System32\drivers\mfeclnrk.sys
2014-07-24 18:32:30 96592 ----a-w- C:\Windows\System32\drivers\mfencrk.sys
2014-07-24 18:31:56 444720 ----a-w- C:\Windows\System32\drivers\mfencbdc.sys
2014-07-16 03:23:41 2048 ----a-w- C:\Windows\System32\tzres.dll
2014-07-16 02:46:02 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2014-07-14 02:02:45 1216000 ----a-w- C:\Windows\System32\rpcrt4.dll
2014-07-14 01:40:58 664064 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2014-07-09 02:03:23 7168 ----a-w- C:\Windows\System32\KBDYAK.DLL
2014-07-09 02:03:22 7168 ----a-w- C:\Windows\System32\KBDBASH.DLL
2014-07-09 01:31:42 7168 ----a-w- C:\Windows\SysWow64\KBDYAK.DLL
2014-07-09 01:31:41 6656 ----a-w- C:\Windows\SysWow64\KBDBASH.DLL
2014-06-30 22:24:50 8856 ----a-w- C:\Windows\System32\icardres.dll
2014-06-30 22:14:53 8856 ----a-w- C:\Windows\SysWow64\icardres.dll
2011-06-25 04:19:57 9832704 ----a-w- C:\Program Files (x86)\setup.exe
.
============= FINISH: 13:22:56.26 ===============
 


BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 39,551 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:05 AM

Posted 25 September 2014 - 10:23 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Nothing suspicious was found on your DDS log.

Download the version of this tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
===

Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
p.s.
If the SecurityCheck program fails to run for any reason, run it as an Administrator.

If the site is busy or not available use this mirror site:
http://www.bleepingcomputer.com/download/securitycheck/

Please paste the logs in your next reply DO NOT ATTACH THEM unless specified.
To attach a file select the "More Reply Option" and follow the instructions.

Wait for further instructions.

#3 nasdaq

nasdaq

  • Malware Response Team
  • 39,551 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:05 AM

Posted 30 September 2014 - 06:25 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users