Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Very nasty new malware and Trojan Horse


  • This topic is locked This topic is locked
3 replies to this topic

#1 VolleyballWilson

VolleyballWilson

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:47 PM

Posted 28 September 2014 - 05:46 PM

Dear Bleeping Computer,

 

In the past couple of weeks I got Russian adds in my browsers, both FF and Chrome. Adblock didn't remove it and my AV(Avast) said everything was ok. Till last week. Everytime I opened Google or a couple of other websites it starts signalling malwarecausing the Russian adds. Malwarebytes has removed the malware infection but it has left me with a Trojan Horse called HTML:FBListener-A

Avast recognizes it as a Trojan Horse but doesn't give additional info, just that it is a high risk threat. Deleting the file doesn't help because everytime I start up FF it copies itself back into the browser's cache.

HELP!



BC AdBot (Login to Remove)

 


m

#2 VolleyballWilson

VolleyballWilson
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:47 PM

Posted 28 September 2014 - 05:57 PM

Here is my DDS log:

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17280
Run by Cove at 0:55:21 on 2014-09-29
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.1.1033.18.4095.2076 [GMT 2:00]
.
AV: Ad-Aware Antivirus *Disabled/Outdated* {D87B6541-12A1-DAEA-0033-9B8057AAB996}
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Ad-Aware Antivirus *Disabled/Outdated* {631A84A5-349B-D564-3A83-A0F22C2DF32B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: Ad-Aware Firewall *Disabled* {E040E464-58CE-DBB2-2B6C-32B5A979FEED}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareService.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\PROGRA~2\Raptr\raptr.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\PROGRA~2\Raptr\raptr_im.exe
C:\Program Files (x86)\Raptr\raptr_ep64.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uProxyOverride = <local>
mWinlogon: Userinit = userinit.exe
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
uRun: [Raptr] C:\PROGRA~2\Raptr\raptrstub.exe --startup
uRun: [Akamai NetSession Interface] "C:\Users\Cove\AppData\Local\Akamai\netsession_win.exe"
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 37.251.1.100 188.142.0.22
TCP: Interfaces\{0483DE69-B371-4938-8E3B-DA62789012B7} : DHCPNameServer = 37.251.1.100 188.142.0.22
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [MouseDriver] TiltWheelMouse.exe
x64-Run: [CmPCIaudio] C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\CMICNFG3.dll,CMICtrlWnd
x64-Run: [AdAwareTray] "C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareTray.exe"
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Cove\AppData\Roaming\Mozilla\Firefox\Profiles\wmgj85oa.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll
FF - plugin: C:\Users\Cove\AppData\Roaming\ACEStream\player\npace_plugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\drivers\aswRvrt.sys [2014-8-1 65776]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\drivers\aswVmm.sys [2014-8-1 224896]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2014-8-1 1041168]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswsp.sys [2014-8-1 427360]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2014-9-6 283064]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2014-4-18 239616]
R2 aswHwid;avast! HardwareID;C:\Windows\System32\drivers\aswHwid.sys [2014-8-1 29208]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2014-8-1 79184]
R2 aswStm;aswStm;C:\Windows\System32\drivers\aswStm.sys [2014-8-1 92008]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-8-1 50344]
R2 LavasoftAdAwareService11;Ad-Aware Service 11;C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareService.exe [2014-8-27 706864]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;C:\Windows\System32\drivers\l160x64.sys [2009-10-13 61440]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2013-12-19 94720]
R3 t_mouse.sys;HID-compliand device;C:\Windows\System32\drivers\t_mouse.sys [2012-12-19 6144]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-9-10 111616]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2014-8-1 19456]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-8-1 56832]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2014-7-31 1255736]
S3 XSplit_Dummy;XSplit  Stream  Audio  Renderer;C:\Windows\System32\drivers\xspltspk.sys [2014-7-2 26200]
.
=============== Created Last 30 ================
.
2014-09-26 20:21:04    --------    d-----w-    C:\Users\Cove\AppData\Roaming\LavasoftStatistics
2014-09-26 20:20:20    --------    d-----w-    C:\Program Files\Lavasoft
2014-09-26 20:19:45    --------    d-----w-    C:\Program Files\Common Files\Lavasoft
2014-09-26 13:54:51    11578928    ----a-w-    C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DF7237E5-A2AE-4B21-9A3E-84961EA36D5B}\mpengine.dll
2014-09-25 15:09:59    --------    d-----w-    C:\Users\Cove\AppData\Local\Chromium
2014-09-25 15:06:07    --------    d-----w-    C:\Users\Cove\AppData\Local\The Lord of the Rings Online
2014-09-25 14:14:41    --------    d-----w-    C:\Users\Cove\AppData\Local\Akamai
2014-09-25 14:14:28    --------    d-----w-    C:\Users\Cove\AppData\Local\Turbine
2014-09-25 13:05:39    --------    d-----w-    C:\ProgramData\Turbine
2014-09-25 13:05:09    --------    d-----w-    C:\ProgramData\HappyCloud
2014-09-24 12:29:26    2048    ----a-w-    C:\Windows\SysWow64\tzres.dll
2014-09-24 12:29:26    2048    ----a-w-    C:\Windows\System32\tzres.dll
2014-09-22 17:30:34    --------    d-----w-    C:\Users\Cove\AppData\Local\ApplicationHistory
2014-09-22 16:22:26    --------    d-----w-    C:\Windows\SysWow64\URTTEMP
2014-09-22 14:44:14    --------    d-----w-    C:\Program Files (x86)\SEGA
2014-09-21 17:06:40    --------    d-----w-    C:\Users\Cove\AppData\Local\Google
2014-09-18 11:49:06    --------    d-----w-    C:\Windows\System32\appmgmt
2014-09-18 11:33:10    --------    d-sh--w-    C:\Windows\SysWow64\AI_RecycleBin
2014-09-18 11:32:45    --------    d-----w-    C:\ProgramData\SplitMediaLabs
2014-09-18 11:31:07    --------    d-----w-    C:\Users\Cove\AppData\Roaming\SplitmediaLabs
2014-09-16 14:00:58    --------    d-----w-    C:\Users\Cove\AppData\Roaming\The Creative Assembly
2014-09-16 13:21:38    --------    d-----w-    C:\Program Files (x86)\Common Files\Steam
2014-09-16 13:21:37    --------    d-----w-    C:\Program Files (x86)\Steam
2014-09-10 21:48:00    483328    ----a-w-    C:\Program Files\Internet Explorer\ieinstal.exe
2014-09-10 21:48:00    470016    ----a-w-    C:\Program Files (x86)\Internet Explorer\ieinstal.exe
2014-09-10 21:48:00    360448    ----a-w-    C:\Program Files\Internet Explorer\IEShims.dll
2014-09-10 21:48:00    259584    ----a-w-    C:\Program Files (x86)\Internet Explorer\IEShims.dll
2014-09-10 21:48:00    222720    ----a-w-    C:\Program Files\Internet Explorer\ielowutil.exe
2014-09-10 21:48:00    222720    ----a-w-    C:\Program Files (x86)\Internet Explorer\ielowutil.exe
2014-09-10 21:42:30    2777088    ----a-w-    C:\Windows\System32\msmpeg2vdec.dll
2014-09-10 21:42:29    2285056    ----a-w-    C:\Windows\SysWow64\msmpeg2vdec.dll
2014-09-10 19:01:01    793600    ----a-w-    C:\Windows\SysWow64\TSWorkspace.dll
2014-09-10 19:01:01    1031168    ----a-w-    C:\Windows\System32\TSWorkspace.dll
2014-09-10 19:00:54    2565120    ----a-w-    C:\Windows\System32\d3d10warp.dll
2014-09-10 19:00:54    1987584    ----a-w-    C:\Windows\SysWow64\d3d10warp.dll
2014-09-10 19:00:45    96768    ----a-w-    C:\Windows\SysWow64\sspicli.dll
2014-09-10 19:00:45    728064    ----a-w-    C:\Windows\System32\kerberos.dll
2014-09-10 19:00:45    550912    ----a-w-    C:\Windows\SysWow64\kerberos.dll
2014-09-10 19:00:45    22016    ----a-w-    C:\Windows\SysWow64\secur32.dll
2014-09-10 19:00:45    1460736    ----a-w-    C:\Windows\System32\lsasrv.dll
2014-09-10 19:00:40    578048    ----a-w-    C:\Windows\System32\aepdu.dll
2014-09-10 19:00:39    424448    ----a-w-    C:\Windows\System32\aeinv.dll
2014-09-09 13:05:43    253440    ----a-w-    C:\Windows\System32\Spool\prtprocs\x64\hpfpp02t.dll
2014-09-09 13:05:39    138752    ----a-w-    C:\Windows\System32\hpf3l02t.dll
2014-09-07 20:40:40    --------    d--h--w-    C:\_acestream_cache_
2014-09-07 20:40:27    --------    d-----w-    C:\Users\Cove\AppData\Roaming\.ACEStream
2014-09-07 20:39:52    --------    d-----w-    C:\Users\Cove\AppData\Roaming\ACEStream
2014-09-07 09:14:15    --------    d-sh--w-    C:\Users\Cove\AppData\Local\EmieUserList
2014-09-07 09:14:15    --------    d-sh--w-    C:\Users\Cove\AppData\Local\EmieSiteList
2014-09-06 15:22:12    --------    d-----w-    C:\Users\Cove\AppData\Local\ATI
2014-09-06 15:21:32    --------    d-----w-    C:\Users\Cove\AppData\Roaming\library_dir
2014-09-06 15:21:05    --------    d-----w-    C:\Users\Cove\AppData\Roaming\Raptr
2014-09-06 15:21:05    --------    d-----w-    C:\Program Files (x86)\Raptr
2014-09-06 15:21:02    --------    d-----w-    C:\ProgramData\AMD
2014-09-06 15:21:01    --------    d-----w-    C:\Program Files (x86)\AMD AVT
2014-09-06 15:20:59    --------    d-----w-    C:\Program Files (x86)\Common Files\ATI Technologies
2014-09-06 15:19:12    --------    d-----w-    C:\Program Files\AMD
2014-09-06 15:18:16    --------    d-----w-    C:\Program Files\Common Files\ATI Technologies
2014-09-06 15:18:02    --------    d-----w-    C:\Program Files (x86)\ATI Technologies
2014-09-06 15:17:09    --------    d-----w-    C:\Program Files\ATI Technologies
2014-09-06 15:17:08    --------    d-----w-    C:\Program Files\ATI
2014-09-06 15:16:05    --------    d-----w-    C:\AMD
2014-09-06 14:43:08    --------    d-----w-    C:\Program Files (x86)\Origin Games
2014-09-06 14:04:39    --------    d-----w-    C:\Users\Cove\AppData\Roaming\Origin
2014-09-06 14:04:37    --------    d-----w-    C:\Users\Cove\AppData\Local\Origin
2014-09-06 14:03:36    --------    d-----w-    C:\ProgramData\Electronic Arts
2014-09-06 14:03:23    --------    d-----w-    C:\Program Files (x86)\Origin
2014-09-06 14:00:24    --------    d-----w-    C:\ProgramData\Origin
2014-09-06 13:56:45    283064    ----a-w-    C:\Windows\System32\drivers\dtsoftbus01.sys
2014-09-06 13:56:40    --------    d-----w-    C:\Users\Cove\AppData\Roaming\DAEMON Tools Lite
2014-09-06 13:56:38    --------    d-----w-    C:\Program Files (x86)\DAEMON Tools Lite
2014-09-06 13:55:59    --------    d-----w-    C:\ProgramData\DAEMON Tools Lite
2014-09-06 13:55:16    122584    ----a-w-    C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-08-30 19:34:58    --------    d-----w-    C:\Users\Cove\AppData\Roaming\XBMC
2014-08-30 19:32:35    --------    d-----w-    C:\Program Files (x86)\XBMC
.
==================== Find3M  ====================
.
2014-09-15 07:06:02    278152    ------w-    C:\Windows\System32\MpSigStub.exe
2014-09-09 20:31:21    71344    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-09-09 20:31:21    701104    ----a-w-    C:\Windows\SysWow64\FlashPlayerApp.exe
2014-08-23 02:07:00    404480    ----a-w-    C:\Windows\System32\gdi32.dll
2014-08-23 01:45:55    311808    ----a-w-    C:\Windows\SysWow64\gdi32.dll
2014-08-23 00:59:01    3163648    ----a-w-    C:\Windows\System32\win32k.sys
2014-08-18 22:29:49    2724864    ----a-w-    C:\Windows\System32\mshtml.tlb
2014-08-18 22:29:35    4096    ----a-w-    C:\Windows\System32\ieetwcollectorres.dll
2014-08-18 22:19:53    5833728    ----a-w-    C:\Windows\System32\jscript9.dll
2014-08-18 22:15:34    547328    ----a-w-    C:\Windows\System32\vbscript.dll
2014-08-18 22:15:09    66048    ----a-w-    C:\Windows\System32\iesetup.dll
2014-08-18 22:14:38    48640    ----a-w-    C:\Windows\System32\ieetwproxystub.dll
2014-08-18 22:14:10    83968    ----a-w-    C:\Windows\System32\MshtmlDac.dll
2014-08-18 22:08:55    4232704    ----a-w-    C:\Windows\SysWow64\jscript9.dll
2014-08-18 22:03:47    139264    ----a-w-    C:\Windows\System32\ieUnatt.exe
2014-08-18 22:03:37    111616    ----a-w-    C:\Windows\System32\ieetwcollector.exe
2014-08-18 22:03:01    758272    ----a-w-    C:\Windows\System32\jscript9diag.dll
2014-08-18 21:57:44    2724864    ----a-w-    C:\Windows\SysWow64\mshtml.tlb
2014-08-18 21:56:17    940032    ----a-w-    C:\Windows\System32\MsSpellCheckingFacility.exe
2014-08-18 21:46:26    454656    ----a-w-    C:\Windows\SysWow64\vbscript.dll
2014-08-18 21:45:23    61952    ----a-w-    C:\Windows\SysWow64\iesetup.dll
2014-08-18 21:45:12    72704    ----a-w-    C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-08-18 21:44:44    51200    ----a-w-    C:\Windows\SysWow64\ieetwproxystub.dll
2014-08-18 21:44:09    61952    ----a-w-    C:\Windows\SysWow64\MshtmlDac.dll
2014-08-18 21:36:07    112128    ----a-w-    C:\Windows\SysWow64\ieUnatt.exe
2014-08-18 21:35:24    597504    ----a-w-    C:\Windows\SysWow64\jscript9diag.dll
2014-08-18 21:23:17    2104832    ----a-w-    C:\Windows\System32\inetcpl.cpl
2014-08-18 21:23:16    1249280    ----a-w-    C:\Windows\System32\mshtmlmedia.dll
2014-08-18 21:22:48    60416    ----a-w-    C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-08-18 21:15:13    2310656    ----a-w-    C:\Windows\System32\wininet.dll
2014-08-18 21:08:54    2014208    ----a-w-    C:\Windows\SysWow64\inetcpl.cpl
2014-08-18 21:07:44    1068032    ----a-w-    C:\Windows\SysWow64\mshtmlmedia.dll
2014-08-18 20:46:48    1812992    ----a-w-    C:\Windows\SysWow64\wininet.dll
2014-08-01 12:44:31    152576    ----a-w-    C:\Windows\SysWow64\msclmd.dll
2014-08-01 12:44:30    175616    ----a-w-    C:\Windows\System32\msclmd.dll
2014-08-01 09:07:57    92008    ----a-w-    C:\Windows\System32\drivers\aswStm.sys
2014-08-01 09:07:57    224896    ----a-w-    C:\Windows\System32\drivers\aswVmm.sys
2014-08-01 09:07:57    1041168    ----a-w-    C:\Windows\System32\drivers\aswSnx.sys
2014-08-01 09:07:56    93568    ----a-w-    C:\Windows\System32\drivers\aswRdr2.sys
2014-08-01 09:07:56    79184    ----a-w-    C:\Windows\System32\drivers\aswMonFlt.sys
2014-08-01 09:07:56    65776    ----a-w-    C:\Windows\System32\drivers\aswRvrt.sys
2014-08-01 09:07:56    43152    ----a-w-    C:\Windows\avastSS.scr
2014-08-01 09:07:56    29208    ----a-w-    C:\Windows\System32\drivers\aswHwid.sys
2014-07-31 13:55:36    0    ----a-w-    C:\Windows\ativpsrm.bin
2014-07-25 00:35:46    875688    ----a-w-    C:\Windows\SysWow64\msvcr120_clr0400.dll
2014-07-24 21:47:06    869544    ----a-w-    C:\Windows\System32\msvcr120_clr0400.dll
2014-07-14 02:02:45    1216000    ----a-w-    C:\Windows\System32\rpcrt4.dll
2014-07-14 01:40:58    664064    ----a-w-    C:\Windows\SysWow64\rpcrt4.dll
2014-07-10 12:09:30    389240    ----a-w-    C:\Windows\System32\drivers\Trufos.sys
2014-07-09 02:03:23    7168    ----a-w-    C:\Windows\System32\KBDYAK.DLL
2014-07-09 02:03:22    7168    ----a-w-    C:\Windows\System32\KBDBASH.DLL
2014-07-09 01:31:42    7168    ----a-w-    C:\Windows\SysWow64\KBDYAK.DLL
2014-07-09 01:31:41    6656    ----a-w-    C:\Windows\SysWow64\KBDBASH.DLL
2014-07-02 18:49:08    26200    ----a-w-    C:\Windows\System32\drivers\xspltspk.sys
.
============= FINISH:  0:56:06.55 ===============



#3 VolleyballWilson

VolleyballWilson
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:47 PM

Posted 28 September 2014 - 07:10 PM

In advance I did a Farbar recovery scan and attached the FRST.txt and Addition.txt to this reply, hope it helps.

Attached Files



#4 Valinorum

Valinorum

    Shadow Hide The Hunter


  • Malware Response Instructor
  • 1,553 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:04:47 PM

Posted 01 October 2014 - 06:06 AM

Being helped here.

Geek U Graduate

I close my topic(s) with no replies for more than 4 days. PM me or Moderators to reactivate. All helps are provided via forum ergo do not PM me for help.

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users