frequencyyy
New member
Alright so, on October 28, 2010, was the first time I have ever had a trojan on my computer, and on that date SpyBot detected 73 entries ( I have a screen shot and Malware Bytes log if needed)
Since 10/28, occasionally, when I use firefox, something would create a new tab by it's self, and it would re-direct me to a "site" that says "Problem in your registry, press this to fix" or something along those lines, of course I quickly exit out of it.
Alright so yesterday, I went out to buy a 32" TV to serve as my monitor. I hook everything up, and change the resolution and stuff and restart my computer. When I boot up my computer, my task bar is gone (the one with the start button on it) and I have a lot of weird tasks in task manager, and I recognize most of them from a month ago, when I had 73 Malwares/Trojans/Viruses detected in SpyBot.
So I turned my computer on with Safe mode, ran a malware bytes scan , and Spy Bot, I quarantined/fixed with both but my task bar is still not there and some programs that I do not recognize are still showing up.
In addition to that, there manystart up services that are related to the problems, in my msconfig, that are still there, but just disabled.
Also, yesterday SpyBot detected KillSec, and when I looked it up, KillSec collects my personal data...
Today:
Alright, so today, I come home and turned on computer, my task bar is still gone, and I run MalWare Bytes and SpyBot and again, trojan assistant detected by MalWare, and only 2 browser entries from Spybot. But I knew there was still a problem, random thing kept crashing (Anti virus, and some programs I have never even heard of).
So I decided to come to the forums for help, and when I ran DDS (my first time) I was watching my task manager, and things like SED.DAT, other DAT things, "Find String Query" or something like that, and something that had to do with registry started running, but they VERY QUICKLY disappeared (Are these things from DDS?..)
So yeah, this is a many parted question
- Are the troians/malware and such all gone?.... since it won't detect anything..
- Is it possible to check if any of my programs/ external hard drive is infected?
- How do I get rid of the things that are in msconfig
-How do I prevent them from coming back?
- Where is my task bar?
I checked and the task bar is not hiding, resolution is correct, I tried hovering mouse over it, CTRL+ESC Yes, explorer is running but nothings working..
- Is it possible to check KillSec had collected any information..?
If anything else is needed, just request and I'll do my best to get them!
DDS (Ver_10-11-10.01) - NTFS_AMD64
Run by James at 15:56:50.23 on Wed 11/17/2010
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.5117.2869 [GMT -5:00]
SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\lcdmon.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe
C:\Windows\system32\AERTSr64.exe
C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe
C:\Program Files\Windows Media Player\WMPSideShowGadget.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
c:\PROGRA~2\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe
C:\Program Files (x86)\McAfee\MSK\MskSrver.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\PROGRA~2\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~2\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~2\mcafee\msc\mcuimgr.exe
C:\Program Files (x86)\Ventrilo\Ventrilo.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\SysWOW64\svchost.exe -k netsvcs
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\explorer.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\James\Downloads\dds.scr
============== Pseudo HJT Report ===============
uWindow Title = Internet Explorer provided by Dell
uStart Page = www.ijji.com
uURLSearchHooks: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll
mURLSearchHooks: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll
BHO: McAfee Phishing Filter: {377c180e-6f0e-4d4c-980f-f45bd3d40cf4} - c:\PROGRA~2\mcafee\msk\mcapbho.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll
BHO: C:\Windows\SysWow64\xsl3g.dll: {b1ba20c1-a503-59bd-f412-03b53a2c8951} - C:\Windows\SysWow64\xsl3g.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
uRun: [AdobeBridge]
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
mRun: [mcagent_exe] C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe /runkey
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [SwitchBoard] "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
mRun: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
mRun: [ATICustomerCare] "c:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
dRun: [MqmPeQ] C:\Windows\TEMP\dju8q5m.exe
dRun: [uPc+kt0Nfv_aXms] rundll32.exe C:\Windows\system32\o9xjmpu72g.dll, SystemServer
dRun: [MqmPsd] C:\Windows\TEMP\taskmgr.exe
dRun: [lSKRCmGJix.exe] C:\Windows\TEMP\lSKRCmGJix.exe
dRun: [MqmPZP] C:\Windows\TEMP\gdi32.exe
dRun: [MqmPrc] C:\Windows\TEMP\winamp.exe
dRun: [MqmP0Z] C:\Windows\TEMP\system.exe
dRun: [MqmPxc] C:\Windows\TEMP\smss.exe
dRun: [uPc+kt0NrzLCxl] rundll32.exe C:\Windows\system32\ksr02670.dll, SystemServer
dRun: [MqmPtg] C:\Windows\TEMP\wininst.exe
dRun: [MqqZ] C:\Windows\cmd.exe
dRun: [MqmPWuc] C:\Windows\TEMP\r88yjlqt.exe
dRun: [Mqrta] C:\Windows\install.exe
dRun: [uPc+kt0NcAaGuo] rundll32.exe C:\Windows\system32\y0nb773.dll, SystemServer
dRun: [MqmPsf] C:\Windows\TEMP\lsass.exe
dRunOnce: [kKjIc02097] C:\ProgramData\kKjIc02097\kKjIc02097.exe
dRunOnce: [9C30] "C:\Windows\system32\config\systemprofile\AppData\Local\790575.exe" 0 41
dRunOnce: [790575] "C:\Windows\system32\config\systemprofile\AppData\Local\52139209.exe" 0 48
StartupFolder: C:\Users\James\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
LSP: C:\Windows\system32\lsp5E7E.dll
DPF: {4944924A-64E4-49C1-AC97-ABA3927262FE} - hxxp://channel.dontblynk.com/Launcher/StWbUsa.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
STS: C:\Windows\SysWow64\xsl3g.dll: {b1ba20c1-a503-59bd-f412-03b53a2c8951} - C:\Windows\SysWow64\xsl3g.dll
BHO-X64: McAfee Phishing Filter: {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~2\mcafee\msk\MCAPBH~1.DLL
BHO-X64: McAntiPhishingBHO - No File
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
BHO-X64: scriptproxy - No File
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB-X64: {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - No File
TB-X64: Winamp Toolbar: {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} -
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
mRun-x64: [Launch LgDeviceAgent] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"
mRun-x64: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
mRun-x64: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
================= FIREFOX ===================
FF - ProfilePath - C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://element.searchpluswin.com/?cmd=home
FF - prefs.js: keyword.URL - hxxp://yandex.ru/yandsearch?clid=123045&text=
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\FFExternalAlert.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\RadioWMPCore.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{74714d77-1695-4e73-a98e-25cb374f46b4}\components\FFExternalAlert.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{74714d77-1695-4e73-a98e-25cb374f46b4}\components\RadioWMPCore.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{e9ddc636-f9b4-43db-9795-fba05b2d0e22}\components\FFExternalAlert.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{e9ddc636-f9b4-43db-9795-fba05b2d0e22}\components\RadioWMPCore.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\engine@conduit.com\components\FFExternalAlert.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\engine@conduit.com\components\RadioWMPCore.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npicaN.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\id Software\QuakeLive\npquakezero.dll
FF - plugin: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
FF - plugin: C:\Users\James\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Users\James\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
C:\Program Files (x86)\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.search-clsid", "{DC3C5E53-6283-4714-B415-10FF48DCA680}");
============= SERVICES / DRIVERS ===============
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2009-3-13 55024]
R1 ctxusbm;Citrix USB Monitor Driver;C:\Windows\System32\drivers\ctxusbm.sys [2009-10-5 87600]
R1 ElRawDisk;ElRawDisk;C:\Windows\System32\drivers\dddskx64.sys [2010-1-16 26024]
R1 mfehidk;McAfee Inc. mfehidk;C:\Windows\System32\drivers\mfehidk.sys [2009-3-13 293192]
R2 AERTFilters;Andrea RT Filters Service;C:\Windows\System32\AERTSr64.exe [2009-3-13 86016]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-11-13 203264]
R2 Apache2.2;Remote Access Media Server;C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe [2007-9-21 15872]
R2 cpuz132;cpuz132;C:\Windows\System32\drivers\cpuz132_x64.sys [2009-12-9 19432]
R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2008-9-23 155648]
R2 McProxy;McAfee Proxy Service;C:\PROGRA~2\COMMON~1\mcafee\mcproxy\mcproxy.exe [2009-3-13 358224]
R2 McShield;McAfee Real-time Scanner;C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2009-3-13 153408]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-10-28 1153368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-9-27 240232]
R2 TeamViewer5;TeamViewer 5;C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-3-18 172328]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2010-11-13 7883264]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2010-11-13 285696]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdLH6.sys [2010-11-13 114704]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;C:\Windows\System32\drivers\LGBusEnum.sys [2009-11-23 22408]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;C:\Windows\System32\drivers\LGVirHid.sys [2009-11-23 16008]
R3 LVUVC64;Logitech Webcam 500(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2009-10-7 6379288]
R3 McSysmon;McAfee SystemGuards;C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe [2009-3-13 695624]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\System32\drivers\mfeavfk.sys [2009-3-13 101960]
R3 mfesmfk;McAfee Inc. mfesmfk;C:\Windows\System32\drivers\mfesmfk.sys [2009-3-13 49480]
R3 ScreamBAudioSvc;ScreamBee Audio;C:\Windows\System32\drivers\ScreamingBAudio64.sys [2009-3-27 27160]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 dsl-db;Remote Access DB;C:\ProgramData\SingleClick Systems\MySQL\bin\mysqld.exe [2007-9-14 5730304]
S2 dsl-fs-sync;Remote Access File Sync Service;C:\ProgramData\SingleClick Systems\Remote Access File Sync Service\dsl_fs_sync.exe [2008-9-30 173296]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-9-6 136176]
S2 MSPnPService;MS PnP Service;C:\Windows\system32\mspnp297f.exe --> C:\Windows\system32\mspnp297f.exe [?]
S3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;C:\Windows\System32\drivers\BVRPMPR5a64.SYS [2010-6-25 35840]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);C:\Windows\System32\drivers\vrtaucbl.sys [2010-2-10 49664]
S3 mferkdk;McAfee Inc. mferkdk;C:\Windows\System32\drivers\mferkdk.sys [2009-3-13 40392]
S3 netr7364;RT73 USB Wireless LAN Card Driver for Vista;C:\Windows\System32\drivers\netr7364.sys [2009-5-24 626176]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2009-8-28 49152]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-3-18 93184]
=============== Created Last 30 ================
2010-11-17 20:25:28 53248 ----a-w- C:\Windows\SysWow64\FastUv32.dll
2010-11-16 21:12:46 36356 ---h--w- C:\Windows\drweb.exe
2010-11-16 21:12:33 220672 ----a-w- C:\Windows\SysWow64\mspnp2a3f.exe
2010-11-16 21:12:29 36356 ---h--w- C:\Windows\winamp.exe
2010-11-16 21:12:17 30000 ----a-w- C:\Windows\SysWow64\uznec0.dll
2010-11-16 21:12:09 220672 ---ha-w- C:\Windows\SysWow64\mspnpd7f.exe
2010-11-16 21:11:56 30000 ----a-w- C:\Windows\SysWow64\k0134b1yc.dll
2010-11-16 21:11:49 220672 ---ha-w- C:\Windows\SysWow64\mspnpd8f.exe
2010-11-16 21:11:41 220672 ----a-w- C:\Windows\SysWow64\mspnp297f.exe
2010-11-16 21:11:33 -------- d-----w- C:\PROGRA~3\WSTB
2010-11-16 21:11:31 30000 ----a-w- C:\Windows\SysWow64\xsl3g.dll
2010-11-15 23:53:37 -------- d-----w- C:\Users\James\AppData\Local\Logitech
2010-11-14 16:42:26 -------- d-----w- C:\PROGRA~3\kKjIc02097
2010-11-14 16:42:00 47490 ----a-w- C:\Windows\SysWow64\lsp5E7E.dll
2010-11-14 16:42:00 0 ----a-w- C:\Windows\SysWow64\lsp5E7E.tmp
2010-11-13 06:51:45 -------- d-----w- C:\Program Files (x86)\ATI
2010-11-13 06:46:00 51200 ----a-w- C:\Windows\System32\ATIODCLI.exe
2010-11-13 06:46:00 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2010-11-13 06:46:00 118784 ----a-w- C:\Windows\System32\atibtmon.exe
2010-11-10 22:02:43 2409784 ----a-w- C:\Program Files\Windows Mail\OESpamFilter.dat
2010-11-10 22:02:43 2409784 ----a-w- C:\Program Files (x86)\Windows Mail\OESpamFilter.dat
2010-11-09 21:12:08 -------- d-----w- C:\Users\James\AppData\Local\Activision
2010-11-09 20:53:09 77656 ----a-w- C:\Windows\System32\XAPOFX1_5.dll
2010-11-09 20:53:09 74072 ----a-w- C:\Windows\SysWow64\XAPOFX1_5.dll
2010-11-09 20:53:09 527192 ----a-w- C:\Windows\SysWow64\XAudio2_7.dll
2010-11-09 20:53:09 518488 ----a-w- C:\Windows\System32\XAudio2_7.dll
2010-11-09 20:53:07 239960 ----a-w- C:\Windows\SysWow64\xactengine3_7.dll
2010-11-09 20:53:07 176984 ----a-w- C:\Windows\System32\xactengine3_7.dll
2010-11-09 20:53:06 2526056 ----a-w- C:\Windows\System32\D3DCompiler_43.dll
2010-11-09 20:53:06 2106216 ----a-w- C:\Windows\SysWow64\D3DCompiler_43.dll
2010-11-09 20:53:02 1907552 ----a-w- C:\Windows\System32\d3dcsx_43.dll
2010-11-09 20:53:02 1868128 ----a-w- C:\Windows\SysWow64\d3dcsx_43.dll
2010-11-09 20:53:00 276832 ----a-w- C:\Windows\System32\d3dx11_43.dll
2010-11-09 20:53:00 248672 ----a-w- C:\Windows\SysWow64\d3dx11_43.dll
2010-11-09 20:51:57 540688 ----a-w- C:\Windows\System32\d3dx10_39.dll
2010-11-09 20:50:54 5073256 ----a-w- C:\Windows\System32\d3dx9_35.dll
2010-11-08 22:19:07 -------- d-----w- C:\Users\James\AE CS5 Plugins Collection v1
2010-11-07 21:16:42 90112 ----a-w- C:\Windows\unvise32.exe
2010-11-04 07:13:57 -------- d-----w- C:\Program Files (x86)\SystemRequirementsLab
2010-10-28 23:41:23 32256 ----a-w- C:\Windows\System32\Apphlpdm.dll
2010-10-28 23:41:23 28672 ----a-w- C:\Windows\SysWow64\Apphlpdm.dll
2010-10-28 23:41:20 4240384 ----a-w- C:\Windows\SysWow64\GameUXLegacyGDFs.dll
2010-10-28 23:41:20 4240384 ----a-w- C:\Windows\System32\GameUXLegacyGDFs.dll
2010-10-28 23:33:52 -------- d-----w- C:\Users\James\AppData\Roaming\Malwarebytes
2010-10-28 23:33:24 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2010-10-28 23:33:22 -------- d-----w- C:\PROGRA~3\Malwarebytes
2010-10-28 23:33:21 24664 ----a-w- C:\Windows\System32\drivers\mbam.sys
2010-10-28 23:33:21 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2010-10-28 20:49:23 -------- d-----w- C:\PROGRA~3\Alwil Software
2010-10-28 20:02:36 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2010-10-28 20:02:36 -------- d-----w- C:\PROGRA~3\Spybot - Search & Destroy
2010-10-28 19:40:17 -------- d-----w- C:\Users\James\AppData\Local\{42987DD0-7F6F-453F-B76A-BD72071959E2}
2010-10-28 19:37:20 -------- d-----w- C:\Program Files (x86)\Flash
2010-10-23 22:08:30 -------- d-----w- C:\Twixtor5AEManual
2010-10-23 22:08:15 -------- d-----w- C:\Twixtor5AE
==================== Find3M ====================
2010-09-20 12:14:32 316416 ----a-w- C:\Windows\System32\msshsq.dll
2010-09-20 09:25:01 231936 ----a-w- C:\Windows\SysWow64\msshsq.dll
2010-09-10 16:37:06 8147456 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2010-09-10 15:52:05 8147968 ----a-w- C:\Windows\System32\wmploc.DLL
2010-09-08 17:26:59 833024 ----a-w- C:\Windows\SysWow64\wininet.dll
2010-09-08 17:23:42 78336 ----a-w- C:\Windows\SysWow64\ieencode.dll
2010-09-08 16:46:38 1032704 ----a-w- C:\Windows\System32\wininet.dll
2010-09-08 16:43:11 86528 ----a-w- C:\Windows\System32\ieencode.dll
2010-09-08 15:53:07 389632 ----a-w- C:\Windows\SysWow64\html.iec
2010-09-08 15:28:29 1383424 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2010-09-08 15:26:20 485376 ----a-w- C:\Windows\System32\html.iec
2010-09-08 15:00:33 1383424 ----a-w- C:\Windows\System32\mshtml.tlb
2010-09-06 16:24:40 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2010-09-06 16:23:14 17920 ----a-w- C:\Windows\SysWow64\netevent.dll
2010-09-06 15:59:19 179712 ----a-w- C:\Windows\System32\srvsvc.dll
2010-09-06 15:59:19 12288 ----a-w- C:\Windows\System32\sscore.dll
2010-09-06 15:57:48 17920 ----a-w- C:\Windows\System32\netevent.dll
2010-09-06 13:44:39 461824 ----a-w- C:\Windows\System32\drivers\srv.sys
2010-09-06 13:44:17 144896 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2010-09-06 13:44:14 175104 ----a-w- C:\Windows\System32\drivers\srv2.sys
2010-08-31 15:41:42 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
2010-08-31 15:41:42 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
2010-08-31 15:40:26 531968 ----a-w- C:\Windows\SysWow64\comctl32.dll
2010-08-31 15:21:34 633856 ----a-w- C:\Windows\System32\comctl32.dll
2010-08-31 13:18:42 2751488 ----a-w- C:\Windows\System32\win32k.sys
2010-08-27 22:19:35 111928 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2010-08-27 22:19:30 75064 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2010-08-27 22:19:30 2373712 ----a-w- C:\Windows\SysWow64\pbsvc.exe
2010-08-26 16:27:46 189952 ----a-w- C:\Windows\System32\t2embed.dll
2010-08-26 16:21:44 331776 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2010-08-26 16:21:44 100352 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2010-08-26 16:21:43 281600 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2010-08-26 16:07:25 157184 ----a-w- C:\Windows\SysWow64\t2embed.dll
2010-08-26 16:01:35 173056 ----a-w- C:\Windows\apppatch\AcXtrnal.dll
2010-08-26 16:01:33 459776 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2010-08-26 16:01:32 541696 ----a-w- C:\Windows\apppatch\AcLayers.dll
2010-08-26 16:01:32 2153984 ----a-w- C:\Windows\apppatch\AcGenral.dll
2010-08-20 15:56:01 1090048 ----a-w- C:\Windows\System32\wmpmde.dll
2010-08-20 15:21:02 866816 ----a-w- C:\Windows\SysWow64\wmpmde.dll
2009-12-22 04:44:16 348952 ----a-w- C:\Program Files (x86)\Uninstal.exe
============= FINISH: 15:57:33.08 ===============
Please and Thank you!
http://forums.spybot.info/showthread.php?t=60435
Update: Did a Full system Malware Bytes scan, and found 40 new things, but it crashed mid way through quarantining.
Please help! I'm really worried that the KillSec thing might have taken some information or something..
I have had past problems before
Details in this thread
http://forums.spybot.info/showthread.php?t=60463
And I thought I fixed it, (I quarantined and such, and then deleted the registry keys that were connect to the viruses)
but today, when I woke up I boot up my computer, and tried to go on the Internet, how ever, nothing will load, when I try to type in a website, it just refreshes the page, no error page comes up, and it does not load. And when I try to connect to a VOiP server, it says "Contacting server" indicating that theres no internet connection, how ever, on my bottom right, it says that I am connected to the internet!
I have tried re-booting, tried multiple websites, and re booting my router, how ever it still does not work.
I have scanned with malware bytes and spy bot a lot of times.
Spybot- nothing.
malware bytes- a new file/registry key/program gets infected every time i scan.
And avast blocked this thing ( i did not get enough time to read) that said insertipaddresshere.exe
there was actually an ip address though by the way, just don't remember it.
And it was in one of my Windows folder..
So yeah, now I don't have connection to the internet, and I'm afraid that the virus just tried connecting itself to another server to steal information or something.
I'm posting on another computer on the same network by the way so it's only that infected one that is not working.
(Ipod, 2 other desktops and 1 laptop relying on same connection, IS working.)
I cannot post the log.. well since I'm on a different computer then the one that is actually infected..
PLEASE HELP!!
============================
The Waiting Room "If you have waited four days or longer for assistance, please start a topic in this sub-forum and post with a link back to your topic in the Malware forum, so that we know who you are"
Since 10/28, occasionally, when I use firefox, something would create a new tab by it's self, and it would re-direct me to a "site" that says "Problem in your registry, press this to fix" or something along those lines, of course I quickly exit out of it.
Alright so yesterday, I went out to buy a 32" TV to serve as my monitor. I hook everything up, and change the resolution and stuff and restart my computer. When I boot up my computer, my task bar is gone (the one with the start button on it) and I have a lot of weird tasks in task manager, and I recognize most of them from a month ago, when I had 73 Malwares/Trojans/Viruses detected in SpyBot.
So I turned my computer on with Safe mode, ran a malware bytes scan , and Spy Bot, I quarantined/fixed with both but my task bar is still not there and some programs that I do not recognize are still showing up.
In addition to that, there manystart up services that are related to the problems, in my msconfig, that are still there, but just disabled.
Also, yesterday SpyBot detected KillSec, and when I looked it up, KillSec collects my personal data...
Today:
Alright, so today, I come home and turned on computer, my task bar is still gone, and I run MalWare Bytes and SpyBot and again, trojan assistant detected by MalWare, and only 2 browser entries from Spybot. But I knew there was still a problem, random thing kept crashing (Anti virus, and some programs I have never even heard of).
So I decided to come to the forums for help, and when I ran DDS (my first time) I was watching my task manager, and things like SED.DAT, other DAT things, "Find String Query" or something like that, and something that had to do with registry started running, but they VERY QUICKLY disappeared (Are these things from DDS?..)
So yeah, this is a many parted question
- Are the troians/malware and such all gone?.... since it won't detect anything..
- Is it possible to check if any of my programs/ external hard drive is infected?
- How do I get rid of the things that are in msconfig
-How do I prevent them from coming back?
- Where is my task bar?
I checked and the task bar is not hiding, resolution is correct, I tried hovering mouse over it, CTRL+ESC Yes, explorer is running but nothings working..
- Is it possible to check KillSec had collected any information..?
If anything else is needed, just request and I'll do my best to get them!
DDS (Ver_10-11-10.01) - NTFS_AMD64
Run by James at 15:56:50.23 on Wed 11/17/2010
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.5117.2869 [GMT -5:00]
SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\lcdmon.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe
C:\Windows\system32\AERTSr64.exe
C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe
C:\Program Files\Windows Media Player\WMPSideShowGadget.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
c:\PROGRA~2\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe
C:\Program Files (x86)\McAfee\MSK\MskSrver.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\PROGRA~2\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~2\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~2\mcafee\msc\mcuimgr.exe
C:\Program Files (x86)\Ventrilo\Ventrilo.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\SysWOW64\svchost.exe -k netsvcs
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\explorer.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\James\Downloads\dds.scr
============== Pseudo HJT Report ===============
uWindow Title = Internet Explorer provided by Dell
uStart Page = www.ijji.com
uURLSearchHooks: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll
mURLSearchHooks: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll
BHO: McAfee Phishing Filter: {377c180e-6f0e-4d4c-980f-f45bd3d40cf4} - c:\PROGRA~2\mcafee\msk\mcapbho.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll
BHO: C:\Windows\SysWow64\xsl3g.dll: {b1ba20c1-a503-59bd-f412-03b53a2c8951} - C:\Windows\SysWow64\xsl3g.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
uRun: [AdobeBridge]
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
mRun: [mcagent_exe] C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe /runkey
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [SwitchBoard] "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
mRun: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
mRun: [ATICustomerCare] "c:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
dRun: [MqmPeQ] C:\Windows\TEMP\dju8q5m.exe
dRun: [uPc+kt0Nfv_aXms] rundll32.exe C:\Windows\system32\o9xjmpu72g.dll, SystemServer
dRun: [MqmPsd] C:\Windows\TEMP\taskmgr.exe
dRun: [lSKRCmGJix.exe] C:\Windows\TEMP\lSKRCmGJix.exe
dRun: [MqmPZP] C:\Windows\TEMP\gdi32.exe
dRun: [MqmPrc] C:\Windows\TEMP\winamp.exe
dRun: [MqmP0Z] C:\Windows\TEMP\system.exe
dRun: [MqmPxc] C:\Windows\TEMP\smss.exe
dRun: [uPc+kt0NrzLCxl] rundll32.exe C:\Windows\system32\ksr02670.dll, SystemServer
dRun: [MqmPtg] C:\Windows\TEMP\wininst.exe
dRun: [MqqZ] C:\Windows\cmd.exe
dRun: [MqmPWuc] C:\Windows\TEMP\r88yjlqt.exe
dRun: [Mqrta] C:\Windows\install.exe
dRun: [uPc+kt0NcAaGuo] rundll32.exe C:\Windows\system32\y0nb773.dll, SystemServer
dRun: [MqmPsf] C:\Windows\TEMP\lsass.exe
dRunOnce: [kKjIc02097] C:\ProgramData\kKjIc02097\kKjIc02097.exe
dRunOnce: [9C30] "C:\Windows\system32\config\systemprofile\AppData\Local\790575.exe" 0 41
dRunOnce: [790575] "C:\Windows\system32\config\systemprofile\AppData\Local\52139209.exe" 0 48
StartupFolder: C:\Users\James\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
LSP: C:\Windows\system32\lsp5E7E.dll
DPF: {4944924A-64E4-49C1-AC97-ABA3927262FE} - hxxp://channel.dontblynk.com/Launcher/StWbUsa.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
STS: C:\Windows\SysWow64\xsl3g.dll: {b1ba20c1-a503-59bd-f412-03b53a2c8951} - C:\Windows\SysWow64\xsl3g.dll
BHO-X64: McAfee Phishing Filter: {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~2\mcafee\msk\MCAPBH~1.DLL
BHO-X64: McAntiPhishingBHO - No File
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
BHO-X64: scriptproxy - No File
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB-X64: {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - No File
TB-X64: Winamp Toolbar: {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} -
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
mRun-x64: [Launch LgDeviceAgent] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"
mRun-x64: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
mRun-x64: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
================= FIREFOX ===================
FF - ProfilePath - C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://element.searchpluswin.com/?cmd=home
FF - prefs.js: keyword.URL - hxxp://yandex.ru/yandsearch?clid=123045&text=
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\FFExternalAlert.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\RadioWMPCore.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{74714d77-1695-4e73-a98e-25cb374f46b4}\components\FFExternalAlert.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{74714d77-1695-4e73-a98e-25cb374f46b4}\components\RadioWMPCore.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{e9ddc636-f9b4-43db-9795-fba05b2d0e22}\components\FFExternalAlert.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{e9ddc636-f9b4-43db-9795-fba05b2d0e22}\components\RadioWMPCore.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\engine@conduit.com\components\FFExternalAlert.dll
FF - component: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\engine@conduit.com\components\RadioWMPCore.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npicaN.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\id Software\QuakeLive\npquakezero.dll
FF - plugin: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
FF - plugin: C:\Users\James\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Users\James\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\nr9r54fv.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
C:\Program Files (x86)\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.search-clsid", "{DC3C5E53-6283-4714-B415-10FF48DCA680}");
============= SERVICES / DRIVERS ===============
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2009-3-13 55024]
R1 ctxusbm;Citrix USB Monitor Driver;C:\Windows\System32\drivers\ctxusbm.sys [2009-10-5 87600]
R1 ElRawDisk;ElRawDisk;C:\Windows\System32\drivers\dddskx64.sys [2010-1-16 26024]
R1 mfehidk;McAfee Inc. mfehidk;C:\Windows\System32\drivers\mfehidk.sys [2009-3-13 293192]
R2 AERTFilters;Andrea RT Filters Service;C:\Windows\System32\AERTSr64.exe [2009-3-13 86016]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-11-13 203264]
R2 Apache2.2;Remote Access Media Server;C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe [2007-9-21 15872]
R2 cpuz132;cpuz132;C:\Windows\System32\drivers\cpuz132_x64.sys [2009-12-9 19432]
R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2008-9-23 155648]
R2 McProxy;McAfee Proxy Service;C:\PROGRA~2\COMMON~1\mcafee\mcproxy\mcproxy.exe [2009-3-13 358224]
R2 McShield;McAfee Real-time Scanner;C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2009-3-13 153408]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-10-28 1153368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-9-27 240232]
R2 TeamViewer5;TeamViewer 5;C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-3-18 172328]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2010-11-13 7883264]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2010-11-13 285696]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdLH6.sys [2010-11-13 114704]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;C:\Windows\System32\drivers\LGBusEnum.sys [2009-11-23 22408]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;C:\Windows\System32\drivers\LGVirHid.sys [2009-11-23 16008]
R3 LVUVC64;Logitech Webcam 500(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2009-10-7 6379288]
R3 McSysmon;McAfee SystemGuards;C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe [2009-3-13 695624]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\System32\drivers\mfeavfk.sys [2009-3-13 101960]
R3 mfesmfk;McAfee Inc. mfesmfk;C:\Windows\System32\drivers\mfesmfk.sys [2009-3-13 49480]
R3 ScreamBAudioSvc;ScreamBee Audio;C:\Windows\System32\drivers\ScreamingBAudio64.sys [2009-3-27 27160]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 dsl-db;Remote Access DB;C:\ProgramData\SingleClick Systems\MySQL\bin\mysqld.exe [2007-9-14 5730304]
S2 dsl-fs-sync;Remote Access File Sync Service;C:\ProgramData\SingleClick Systems\Remote Access File Sync Service\dsl_fs_sync.exe [2008-9-30 173296]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-9-6 136176]
S2 MSPnPService;MS PnP Service;C:\Windows\system32\mspnp297f.exe --> C:\Windows\system32\mspnp297f.exe [?]
S3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;C:\Windows\System32\drivers\BVRPMPR5a64.SYS [2010-6-25 35840]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);C:\Windows\System32\drivers\vrtaucbl.sys [2010-2-10 49664]
S3 mferkdk;McAfee Inc. mferkdk;C:\Windows\System32\drivers\mferkdk.sys [2009-3-13 40392]
S3 netr7364;RT73 USB Wireless LAN Card Driver for Vista;C:\Windows\System32\drivers\netr7364.sys [2009-5-24 626176]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2009-8-28 49152]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-3-18 93184]
=============== Created Last 30 ================
2010-11-17 20:25:28 53248 ----a-w- C:\Windows\SysWow64\FastUv32.dll
2010-11-16 21:12:46 36356 ---h--w- C:\Windows\drweb.exe
2010-11-16 21:12:33 220672 ----a-w- C:\Windows\SysWow64\mspnp2a3f.exe
2010-11-16 21:12:29 36356 ---h--w- C:\Windows\winamp.exe
2010-11-16 21:12:17 30000 ----a-w- C:\Windows\SysWow64\uznec0.dll
2010-11-16 21:12:09 220672 ---ha-w- C:\Windows\SysWow64\mspnpd7f.exe
2010-11-16 21:11:56 30000 ----a-w- C:\Windows\SysWow64\k0134b1yc.dll
2010-11-16 21:11:49 220672 ---ha-w- C:\Windows\SysWow64\mspnpd8f.exe
2010-11-16 21:11:41 220672 ----a-w- C:\Windows\SysWow64\mspnp297f.exe
2010-11-16 21:11:33 -------- d-----w- C:\PROGRA~3\WSTB
2010-11-16 21:11:31 30000 ----a-w- C:\Windows\SysWow64\xsl3g.dll
2010-11-15 23:53:37 -------- d-----w- C:\Users\James\AppData\Local\Logitech
2010-11-14 16:42:26 -------- d-----w- C:\PROGRA~3\kKjIc02097
2010-11-14 16:42:00 47490 ----a-w- C:\Windows\SysWow64\lsp5E7E.dll
2010-11-14 16:42:00 0 ----a-w- C:\Windows\SysWow64\lsp5E7E.tmp
2010-11-13 06:51:45 -------- d-----w- C:\Program Files (x86)\ATI
2010-11-13 06:46:00 51200 ----a-w- C:\Windows\System32\ATIODCLI.exe
2010-11-13 06:46:00 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2010-11-13 06:46:00 118784 ----a-w- C:\Windows\System32\atibtmon.exe
2010-11-10 22:02:43 2409784 ----a-w- C:\Program Files\Windows Mail\OESpamFilter.dat
2010-11-10 22:02:43 2409784 ----a-w- C:\Program Files (x86)\Windows Mail\OESpamFilter.dat
2010-11-09 21:12:08 -------- d-----w- C:\Users\James\AppData\Local\Activision
2010-11-09 20:53:09 77656 ----a-w- C:\Windows\System32\XAPOFX1_5.dll
2010-11-09 20:53:09 74072 ----a-w- C:\Windows\SysWow64\XAPOFX1_5.dll
2010-11-09 20:53:09 527192 ----a-w- C:\Windows\SysWow64\XAudio2_7.dll
2010-11-09 20:53:09 518488 ----a-w- C:\Windows\System32\XAudio2_7.dll
2010-11-09 20:53:07 239960 ----a-w- C:\Windows\SysWow64\xactengine3_7.dll
2010-11-09 20:53:07 176984 ----a-w- C:\Windows\System32\xactengine3_7.dll
2010-11-09 20:53:06 2526056 ----a-w- C:\Windows\System32\D3DCompiler_43.dll
2010-11-09 20:53:06 2106216 ----a-w- C:\Windows\SysWow64\D3DCompiler_43.dll
2010-11-09 20:53:02 1907552 ----a-w- C:\Windows\System32\d3dcsx_43.dll
2010-11-09 20:53:02 1868128 ----a-w- C:\Windows\SysWow64\d3dcsx_43.dll
2010-11-09 20:53:00 276832 ----a-w- C:\Windows\System32\d3dx11_43.dll
2010-11-09 20:53:00 248672 ----a-w- C:\Windows\SysWow64\d3dx11_43.dll
2010-11-09 20:51:57 540688 ----a-w- C:\Windows\System32\d3dx10_39.dll
2010-11-09 20:50:54 5073256 ----a-w- C:\Windows\System32\d3dx9_35.dll
2010-11-08 22:19:07 -------- d-----w- C:\Users\James\AE CS5 Plugins Collection v1
2010-11-07 21:16:42 90112 ----a-w- C:\Windows\unvise32.exe
2010-11-04 07:13:57 -------- d-----w- C:\Program Files (x86)\SystemRequirementsLab
2010-10-28 23:41:23 32256 ----a-w- C:\Windows\System32\Apphlpdm.dll
2010-10-28 23:41:23 28672 ----a-w- C:\Windows\SysWow64\Apphlpdm.dll
2010-10-28 23:41:20 4240384 ----a-w- C:\Windows\SysWow64\GameUXLegacyGDFs.dll
2010-10-28 23:41:20 4240384 ----a-w- C:\Windows\System32\GameUXLegacyGDFs.dll
2010-10-28 23:33:52 -------- d-----w- C:\Users\James\AppData\Roaming\Malwarebytes
2010-10-28 23:33:24 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2010-10-28 23:33:22 -------- d-----w- C:\PROGRA~3\Malwarebytes
2010-10-28 23:33:21 24664 ----a-w- C:\Windows\System32\drivers\mbam.sys
2010-10-28 23:33:21 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2010-10-28 20:49:23 -------- d-----w- C:\PROGRA~3\Alwil Software
2010-10-28 20:02:36 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2010-10-28 20:02:36 -------- d-----w- C:\PROGRA~3\Spybot - Search & Destroy
2010-10-28 19:40:17 -------- d-----w- C:\Users\James\AppData\Local\{42987DD0-7F6F-453F-B76A-BD72071959E2}
2010-10-28 19:37:20 -------- d-----w- C:\Program Files (x86)\Flash
2010-10-23 22:08:30 -------- d-----w- C:\Twixtor5AEManual
2010-10-23 22:08:15 -------- d-----w- C:\Twixtor5AE
==================== Find3M ====================
2010-09-20 12:14:32 316416 ----a-w- C:\Windows\System32\msshsq.dll
2010-09-20 09:25:01 231936 ----a-w- C:\Windows\SysWow64\msshsq.dll
2010-09-10 16:37:06 8147456 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2010-09-10 15:52:05 8147968 ----a-w- C:\Windows\System32\wmploc.DLL
2010-09-08 17:26:59 833024 ----a-w- C:\Windows\SysWow64\wininet.dll
2010-09-08 17:23:42 78336 ----a-w- C:\Windows\SysWow64\ieencode.dll
2010-09-08 16:46:38 1032704 ----a-w- C:\Windows\System32\wininet.dll
2010-09-08 16:43:11 86528 ----a-w- C:\Windows\System32\ieencode.dll
2010-09-08 15:53:07 389632 ----a-w- C:\Windows\SysWow64\html.iec
2010-09-08 15:28:29 1383424 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2010-09-08 15:26:20 485376 ----a-w- C:\Windows\System32\html.iec
2010-09-08 15:00:33 1383424 ----a-w- C:\Windows\System32\mshtml.tlb
2010-09-06 16:24:40 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2010-09-06 16:23:14 17920 ----a-w- C:\Windows\SysWow64\netevent.dll
2010-09-06 15:59:19 179712 ----a-w- C:\Windows\System32\srvsvc.dll
2010-09-06 15:59:19 12288 ----a-w- C:\Windows\System32\sscore.dll
2010-09-06 15:57:48 17920 ----a-w- C:\Windows\System32\netevent.dll
2010-09-06 13:44:39 461824 ----a-w- C:\Windows\System32\drivers\srv.sys
2010-09-06 13:44:17 144896 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2010-09-06 13:44:14 175104 ----a-w- C:\Windows\System32\drivers\srv2.sys
2010-08-31 15:41:42 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
2010-08-31 15:41:42 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
2010-08-31 15:40:26 531968 ----a-w- C:\Windows\SysWow64\comctl32.dll
2010-08-31 15:21:34 633856 ----a-w- C:\Windows\System32\comctl32.dll
2010-08-31 13:18:42 2751488 ----a-w- C:\Windows\System32\win32k.sys
2010-08-27 22:19:35 111928 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2010-08-27 22:19:30 75064 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2010-08-27 22:19:30 2373712 ----a-w- C:\Windows\SysWow64\pbsvc.exe
2010-08-26 16:27:46 189952 ----a-w- C:\Windows\System32\t2embed.dll
2010-08-26 16:21:44 331776 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2010-08-26 16:21:44 100352 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2010-08-26 16:21:43 281600 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2010-08-26 16:07:25 157184 ----a-w- C:\Windows\SysWow64\t2embed.dll
2010-08-26 16:01:35 173056 ----a-w- C:\Windows\apppatch\AcXtrnal.dll
2010-08-26 16:01:33 459776 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2010-08-26 16:01:32 541696 ----a-w- C:\Windows\apppatch\AcLayers.dll
2010-08-26 16:01:32 2153984 ----a-w- C:\Windows\apppatch\AcGenral.dll
2010-08-20 15:56:01 1090048 ----a-w- C:\Windows\System32\wmpmde.dll
2010-08-20 15:21:02 866816 ----a-w- C:\Windows\SysWow64\wmpmde.dll
2009-12-22 04:44:16 348952 ----a-w- C:\Program Files (x86)\Uninstal.exe
============= FINISH: 15:57:33.08 ===============
Please and Thank you!
http://forums.spybot.info/showthread.php?t=60435
Update: Did a Full system Malware Bytes scan, and found 40 new things, but it crashed mid way through quarantining.
Please help! I'm really worried that the KillSec thing might have taken some information or something..
I have had past problems before
Details in this thread
http://forums.spybot.info/showthread.php?t=60463
And I thought I fixed it, (I quarantined and such, and then deleted the registry keys that were connect to the viruses)
but today, when I woke up I boot up my computer, and tried to go on the Internet, how ever, nothing will load, when I try to type in a website, it just refreshes the page, no error page comes up, and it does not load. And when I try to connect to a VOiP server, it says "Contacting server" indicating that theres no internet connection, how ever, on my bottom right, it says that I am connected to the internet!
I have tried re-booting, tried multiple websites, and re booting my router, how ever it still does not work.
I have scanned with malware bytes and spy bot a lot of times.
Spybot- nothing.
malware bytes- a new file/registry key/program gets infected every time i scan.
And avast blocked this thing ( i did not get enough time to read) that said insertipaddresshere.exe
there was actually an ip address though by the way, just don't remember it.
And it was in one of my Windows folder..
So yeah, now I don't have connection to the internet, and I'm afraid that the virus just tried connecting itself to another server to steal information or something.
I'm posting on another computer on the same network by the way so it's only that infected one that is not working.
(Ipod, 2 other desktops and 1 laptop relying on same connection, IS working.)
I cannot post the log.. well since I'm on a different computer then the one that is actually infected..
PLEASE HELP!!
============================
The Waiting Room "If you have waited four days or longer for assistance, please start a topic in this sub-forum and post with a link back to your topic in the Malware forum, so that we know who you are"
Last edited by a moderator: