View Full Version : Can't run DDS, Spybot or CCleaner or avgmfapx message
Hi,
i noticed that every so often over the past 1 or 2 days avgmfapx would close. My internet has been very sluggish all of a sudden. I tried to search for a problem and found that i can't run:
Spybot
Ccleaner
DDs
It's always a "Windows cannot find" message
I've got an updated AVG and so far it has found nothing
However i finally did manage to get Spybot running via one of the scr files and this is what i got on running a scan:
Opachki.ru - removed it.
Here's the log:
Hint of the Day: Click the bar at the right of this to see more information! ()
Opachki.ru: [SBI $9E90BA5A] Autorun settings (Registry value, nothing done)
HKEY_USERS\S-1-5-21-488920656-923882004-2919504125-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
--- Spybot - Search & Destroy version: 1.6.0 (build: 20080729) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2010-11-16 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2008-10-22 Tools.dll (2.1.6.8)
2009-01-16 UninsSrv.dll (1.0.0.0)
2011-03-18 Includes\Adware.sbi (*)
2011-03-22 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2011-03-08 Includes\DialerC.sbi (*)
2011-02-24 Includes\HeavyDuty.sbi (*)
2011-03-29 Includes\Hijackers.sbi (*)
2011-03-29 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2011-03-08 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2011-03-29 Includes\Malware.sbi (*)
2011-03-29 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2011-03-15 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2011-03-08 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2011-02-24 Includes\Spyware.sbi (*)
2011-03-15 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-12-28 Includes\Trojans.sbi (*)
2011-03-25 Includes\TrojansC-02.sbi (*)
2011-03-29 Includes\TrojansC-03.sbi (*)
2011-03-08 Includes\TrojansC-04.sbi (*)
2011-03-29 Includes\TrojansC-05.sbi (*)
2011-03-08 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
Thanks,
A
Sorry i forgot to mention that my OS is Win 7 Ultimate, SP1 64-bit
Also, AVG returned nothing on scans
Hi,
Download DDS and save it to your desktop from here (http://download.bleepingcomputer.com/sUBs/dds.com). Rename the file to merlin.com and see if you're able to run it. If successful, post back dds.txt & attach.txt logs.
Renamed the file to merlin.com and it says the same thing it does for everything else"
"Windows cannot find 'C:\Users\Arafat\Desktop\Merlin.com' Make sure you typed the name correctly, and then try again "
I then ran it from Safemode. Infact I can run everything from Safemode without any messages
Here's the DDS log and I've attached the Attach.txt file:
.
DDS (Ver_11-05-19.01) - NTFSx86 MINIMAL
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Run by Arafat at 18:41:29 on 2011-05-25
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4094.3366 [GMT 3:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\userinit.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Users\Arafat\Desktop\Merlin.com
C:\Windows\SysWOW64\WSCRIPT.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - D:\SPYBOT~1\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Google Update] "C:\Users\Arafat\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
uRun: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\TeaTimer.exe
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
mRun: [TurboV EVO] "C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe" -b
mRun: [Adobe Reader Speed Launcher] "D:\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - D:\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - D:\MICROS~1\Office14\ONBttnIE.dll/105
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
mRun-x64: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
mRun-x64: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
Hosts: 102.54.94.97 rhino.acme.com # source server
Hosts: 38.25.63.10 x.acme.com # x client host
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Arafat\AppData\Roaming\Mozilla\Firefox\Profiles\brjkibx7.default\
FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox\components\avgssff.dll
FF - component: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\components\FirefoxExtension.dll
FF - component: D:\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Arafat\AppData\Local\Google\Update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: C:\Users\Arafat\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - plugin: D:\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
FF - plugin: D:\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: D:\Mozilla Firefox\plugins\NPDFusionWebFirefox.dll
FF - plugin: D:\VideoLAN\VLC\npvlc.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
S1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
S1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
S2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-14 20992]
S2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
S2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.05\AsSysCtrlService.exe [2010-11-14 109056]
S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-1-6 6128720]
S2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-10-22 265400]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;D:\LogMeIn Hamachi\hamachi-2.exe [2011-3-28 2111368]
S2 KMService;KMService;C:\Windows\System32\srvany.exe [2011-1-6 8192]
S3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
S3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
S3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
S3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-1-21 30963576]
S3 nmwcdcx64;Nokia USB Generic;C:\Windows\system32\drivers\ccdcmbox64.sys --> C:\Windows\system32\drivers\ccdcmbox64.sys [?]
S3 nmwcdnsucx64;Nokia USB Flashing Generic;C:\Windows\system32\drivers\nmwcdnsucx64.sys --> C:\Windows\system32\drivers\nmwcdnsucx64.sys [?]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent;C:\Windows\system32\drivers\nmwcdnsux64.sys --> C:\Windows\system32\drivers\nmwcdnsux64.sys [?]
S3 nmwcdx64;Nokia USB Phone Parent;C:\Windows\system32\drivers\ccdcmbx64.sys --> C:\Windows\system32\drivers\ccdcmbx64.sys [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-05-24 17:20:29 -------- d-----w- C:\Users\Arafat\AppData\Local\{F89D2A5B-1CEC-45DC-98CD-3B8C27C55EEE}
2011-05-23 17:20:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{4DE85A21-2AE4-47ED-BC23-4F1B47C9B7B2}
2011-05-22 14:50:15 -------- d-----w- C:\Users\Arafat\AppData\Local\{53869421-6B45-47B0-BAAE-AC1408A79C47}
2011-05-21 19:33:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{28E7D7E8-526F-4ADB-8181-667D33A61DFC}
2011-05-20 11:15:55 -------- d-----w- C:\Users\Arafat\AppData\Local\{56890F7F-2472-4A8F-A825-0DA532617CE6}
2011-05-19 19:36:48 -------- d-----w- C:\Users\Arafat\AppData\Local\{8C0B880F-FE73-42DE-9E92-B6446DDFEED8}
2011-05-19 07:22:39 -------- d-----w- C:\Users\Arafat\AppData\Local\{B9C6FE17-3E5D-445E-81FC-B36AC7E71BFD}
2011-05-17 17:00:55 -------- d-----w- C:\Users\Arafat\AppData\Local\{722E076A-2A84-4677-817F-9B07F571FAF7}
2011-05-16 19:38:31 -------- d-----w- C:\Windows\CheckSur
2011-05-16 13:33:11 -------- d-----w- C:\Users\Arafat\AppData\Local\{BDF4F900-0721-419A-8ED0-6523DC1EAE5B}
2011-05-15 19:35:45 -------- d-----w- C:\Users\Arafat\AppData\Local\{030EF9CD-9022-4E12-9DBB-B84C85271380}
2011-05-14 10:01:26 -------- d-----w- C:\Users\Arafat\AppData\Local\{45440B02-B680-4F0C-8383-77335D4A364D}
2011-05-13 12:22:47 -------- d-----w- C:\Users\Arafat\AppData\Local\{F1CA829F-9FBD-4126-B743-964971EFE397}
2011-05-13 00:22:01 -------- d-----w- C:\Users\Arafat\AppData\Local\{DBF4DA55-5321-4C54-BC10-064FB4195B9A}
2011-05-12 16:23:19 142336 ----a-w- C:\Windows\System32\poqexec.exe
2011-05-12 16:23:19 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2011-05-12 16:23:18 5562240 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-05-12 16:23:17 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-05-12 16:23:17 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-05-12 16:23:08 52736 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2011-05-12 16:23:07 98816 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2011-05-12 16:23:07 7936 ----a-w- C:\Windows\System32\drivers\usbd.sys
2011-05-12 16:23:07 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2011-05-12 16:23:07 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2011-05-12 16:23:07 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2011-05-12 16:23:07 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2011-05-12 12:21:26 -------- d-----w- C:\Users\Arafat\AppData\Local\{F406B812-45E2-4230-BA50-E83EF04489A8}
2011-05-11 12:00:13 -------- d-----w- C:\Users\Arafat\AppData\Local\{28908B83-A866-4881-A0DF-9D4B9725212C}
2011-05-10 19:56:05 -------- d-----w- C:\Users\Arafat\AppData\Local\{734B2427-E039-4411-8F79-E012EEBC64E2}
2011-05-10 14:40:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{35249393-6A33-453D-953B-FABE876212B1}
2011-05-09 10:50:09 -------- d-----w- C:\Users\Arafat\AppData\Local\{75B41FDB-2E3E-4CFC-8BD1-317E811B15EE}
2011-05-08 14:05:17 -------- d-----w- C:\Users\Arafat\AppData\Local\{1634022F-82E0-4C38-89D3-F73F04AC2E67}
2011-05-07 23:03:35 -------- d-----w- C:\Users\Arafat\AppData\Local\{46675658-ABF9-40D2-9B55-95A46081EE73}
2011-05-07 11:03:01 -------- d-----w- C:\Users\Arafat\AppData\Local\{C674A4FC-A059-48FE-A0EC-3CBF6BE88701}
2011-05-06 22:25:11 -------- d-----w- C:\Users\Arafat\AppData\Local\{373DC4A2-95CD-4835-96E2-7EFEF26C78DD}
2011-05-05 00:10:00 -------- d-----w- C:\Users\Arafat\AppData\Local\{FD4D9AE6-5699-4411-AFCD-F33C725CD855}
2011-05-04 12:09:24 -------- d-----w- C:\Users\Arafat\AppData\Local\{A1534F8F-DF95-4875-9AE8-C5B9B3CB7EB5}
2011-05-03 18:09:09 -------- d-----w- C:\Users\Arafat\AppData\Local\{B8A096B0-ABB0-46A5-A046-6702D317EB29}
2011-04-29 18:49:19 -------- d-----w- C:\Users\Arafat\AppData\Roaming\Adobe Mini Bridge CS5
2011-04-29 18:49:18 -------- d-----w- C:\Users\Arafat\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-04-28 17:33:32 -------- d-----w- C:\Users\Arafat\AppData\Local\LogMeIn Hamachi
2011-04-27 19:32:54 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2011-04-27 19:32:54 31232 ----a-w- C:\Windows\System32\prevhost.exe
2011-04-26 03:55:55 -------- d-----w- C:\Users\Arafat\AppData\Local\{8D1EDC76-8B80-469A-B1C7-3BA58AE0635D}
.
==================== Find3M ====================
.
2011-04-05 17:52:57 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-04-05 17:52:56 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-03-25 19:47:02 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2011-03-19 11:43:50 103736 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-03-12 12:08:49 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-03-12 11:23:45 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-03-11 06:41:37 189824 ----a-w- C:\Windows\System32\drivers\storport.sys
2011-03-11 06:41:34 166272 ----a-w- C:\Windows\System32\drivers\nvstor.sys
2011-03-11 06:41:34 1659776 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2011-03-11 06:41:34 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys
2011-03-11 06:41:26 410496 ----a-w- C:\Windows\System32\drivers\iaStorV.sys
2011-03-11 06:41:12 27008 ----a-w- C:\Windows\System32\drivers\amdxata.sys
2011-03-11 06:41:12 107904 ----a-w- C:\Windows\System32\drivers\amdsata.sys
2011-03-11 06:34:51 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2011-03-11 06:34:50 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2011-03-11 06:33:29 2565632 ----a-w- C:\Windows\System32\esent.dll
2011-03-11 06:30:28 96768 ----a-w- C:\Windows\System32\fsutil.exe
2011-03-11 05:33:59 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-03-11 05:33:59 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
2011-03-11 05:33:09 1699328 ----a-w- C:\Windows\SysWow64\esent.dll
2011-03-11 05:31:07 74240 ----a-w- C:\Windows\SysWow64\fsutil.exe
2011-03-10 12:02:41 66872 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-03-08 06:29:32 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-03-08 05:28:29 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-03-07 06:31:44 1188864 ----a-w- C:\Windows\System32\wininet.dll_old0
2011-03-07 06:31:43 1491456 ----a-w- C:\Windows\System32\urlmon.dll_old0
2011-03-07 05:33:13 981504 ----a-w- C:\Windows\SysWow64\wininet.dll_old0
2011-03-07 05:33:10 1230336 ----a-w- C:\Windows\SysWow64\urlmon.dll_old0
2011-03-04 06:19:28 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2011-03-04 06:19:27 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2011-03-03 06:24:16 183296 ----a-w- C:\Windows\System32\dnsrslvr.dll
2011-03-03 06:21:57 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
2011-03-03 05:36:16 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
2011-03-03 03:52:08 3135488 ----a-w- C:\Windows\System32\win32k.sys
2011-02-25 06:19:30 2871808 ----a-w- C:\Windows\explorer.exe
2011-02-25 05:30:54 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
.
============= FINISH: 18:42:32.02 ===============
Hi,
IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.
Vuze
I'd like you to read this thread (http://forums.spybot.info/showthread.php?t=282).
Uninstall the programs listed above (in red). When done, post fresh dds logs.
Removed Vuze
Here's the DDS log:
.
DDS (Ver_11-05-19.01) - NTFSx86 MINIMAL
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Run by Arafat at 19:34:03 on 2011-05-25
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4094.2946 [GMT 3:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Windows\helppane.exe
C:\Windows\system32\DllHost.exe
C:\Users\Arafat\Desktop\New folder\Fixing\Merlin.com
C:\Windows\SysWOW64\WSCRIPT.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - D:\SPYBOT~1\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Google Update] "C:\Users\Arafat\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
uRun: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\TeaTimer.exe
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
mRun: [TurboV EVO] "C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe" -b
mRun: [Adobe Reader Speed Launcher] "D:\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - D:\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - D:\MICROS~1\Office14\ONBttnIE.dll/105
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
mRun-x64: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
mRun-x64: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
Hosts: 102.54.94.97 rhino.acme.com # source server
Hosts: 38.25.63.10 x.acme.com # x client host
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Arafat\AppData\Roaming\Mozilla\Firefox\Profiles\brjkibx7.default\
FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox\components\avgssff.dll
FF - component: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\components\FirefoxExtension.dll
FF - component: D:\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Arafat\AppData\Local\Google\Update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: C:\Users\Arafat\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - plugin: D:\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
FF - plugin: D:\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: D:\Mozilla Firefox\plugins\NPDFusionWebFirefox.dll
FF - plugin: D:\VideoLAN\VLC\npvlc.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
S1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
S1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
S2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-14 20992]
S2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
S2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.05\AsSysCtrlService.exe [2010-11-14 109056]
S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-1-6 6128720]
S2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-10-22 265400]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;D:\LogMeIn Hamachi\hamachi-2.exe [2011-3-28 2111368]
S2 KMService;KMService;C:\Windows\System32\srvany.exe [2011-1-6 8192]
S3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
S3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
S3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
S3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-1-21 30963576]
S3 nmwcdcx64;Nokia USB Generic;C:\Windows\system32\drivers\ccdcmbox64.sys --> C:\Windows\system32\drivers\ccdcmbox64.sys [?]
S3 nmwcdnsucx64;Nokia USB Flashing Generic;C:\Windows\system32\drivers\nmwcdnsucx64.sys --> C:\Windows\system32\drivers\nmwcdnsucx64.sys [?]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent;C:\Windows\system32\drivers\nmwcdnsux64.sys --> C:\Windows\system32\drivers\nmwcdnsux64.sys [?]
S3 nmwcdx64;Nokia USB Phone Parent;C:\Windows\system32\drivers\ccdcmbx64.sys --> C:\Windows\system32\drivers\ccdcmbx64.sys [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-05-24 17:20:29 -------- d-----w- C:\Users\Arafat\AppData\Local\{F89D2A5B-1CEC-45DC-98CD-3B8C27C55EEE}
2011-05-23 17:20:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{4DE85A21-2AE4-47ED-BC23-4F1B47C9B7B2}
2011-05-22 14:50:15 -------- d-----w- C:\Users\Arafat\AppData\Local\{53869421-6B45-47B0-BAAE-AC1408A79C47}
2011-05-21 19:33:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{28E7D7E8-526F-4ADB-8181-667D33A61DFC}
2011-05-20 11:15:55 -------- d-----w- C:\Users\Arafat\AppData\Local\{56890F7F-2472-4A8F-A825-0DA532617CE6}
2011-05-19 19:36:48 -------- d-----w- C:\Users\Arafat\AppData\Local\{8C0B880F-FE73-42DE-9E92-B6446DDFEED8}
2011-05-19 07:22:39 -------- d-----w- C:\Users\Arafat\AppData\Local\{B9C6FE17-3E5D-445E-81FC-B36AC7E71BFD}
2011-05-17 17:00:55 -------- d-----w- C:\Users\Arafat\AppData\Local\{722E076A-2A84-4677-817F-9B07F571FAF7}
2011-05-16 19:38:31 -------- d-----w- C:\Windows\CheckSur
2011-05-16 13:33:11 -------- d-----w- C:\Users\Arafat\AppData\Local\{BDF4F900-0721-419A-8ED0-6523DC1EAE5B}
2011-05-15 19:35:45 -------- d-----w- C:\Users\Arafat\AppData\Local\{030EF9CD-9022-4E12-9DBB-B84C85271380}
2011-05-14 10:01:26 -------- d-----w- C:\Users\Arafat\AppData\Local\{45440B02-B680-4F0C-8383-77335D4A364D}
2011-05-13 12:22:47 -------- d-----w- C:\Users\Arafat\AppData\Local\{F1CA829F-9FBD-4126-B743-964971EFE397}
2011-05-13 00:22:01 -------- d-----w- C:\Users\Arafat\AppData\Local\{DBF4DA55-5321-4C54-BC10-064FB4195B9A}
2011-05-12 16:23:19 142336 ----a-w- C:\Windows\System32\poqexec.exe
2011-05-12 16:23:19 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2011-05-12 16:23:18 5562240 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-05-12 16:23:17 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-05-12 16:23:17 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-05-12 16:23:08 52736 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2011-05-12 16:23:07 98816 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2011-05-12 16:23:07 7936 ----a-w- C:\Windows\System32\drivers\usbd.sys
2011-05-12 16:23:07 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2011-05-12 16:23:07 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2011-05-12 16:23:07 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2011-05-12 16:23:07 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2011-05-12 12:21:26 -------- d-----w- C:\Users\Arafat\AppData\Local\{F406B812-45E2-4230-BA50-E83EF04489A8}
2011-05-11 12:00:13 -------- d-----w- C:\Users\Arafat\AppData\Local\{28908B83-A866-4881-A0DF-9D4B9725212C}
2011-05-10 19:56:05 -------- d-----w- C:\Users\Arafat\AppData\Local\{734B2427-E039-4411-8F79-E012EEBC64E2}
2011-05-10 14:40:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{35249393-6A33-453D-953B-FABE876212B1}
2011-05-09 10:50:09 -------- d-----w- C:\Users\Arafat\AppData\Local\{75B41FDB-2E3E-4CFC-8BD1-317E811B15EE}
2011-05-08 14:05:17 -------- d-----w- C:\Users\Arafat\AppData\Local\{1634022F-82E0-4C38-89D3-F73F04AC2E67}
2011-05-07 23:03:35 -------- d-----w- C:\Users\Arafat\AppData\Local\{46675658-ABF9-40D2-9B55-95A46081EE73}
2011-05-07 11:03:01 -------- d-----w- C:\Users\Arafat\AppData\Local\{C674A4FC-A059-48FE-A0EC-3CBF6BE88701}
2011-05-06 22:25:11 -------- d-----w- C:\Users\Arafat\AppData\Local\{373DC4A2-95CD-4835-96E2-7EFEF26C78DD}
2011-05-05 00:10:00 -------- d-----w- C:\Users\Arafat\AppData\Local\{FD4D9AE6-5699-4411-AFCD-F33C725CD855}
2011-05-04 12:09:24 -------- d-----w- C:\Users\Arafat\AppData\Local\{A1534F8F-DF95-4875-9AE8-C5B9B3CB7EB5}
2011-05-03 18:09:09 -------- d-----w- C:\Users\Arafat\AppData\Local\{B8A096B0-ABB0-46A5-A046-6702D317EB29}
2011-04-29 18:49:19 -------- d-----w- C:\Users\Arafat\AppData\Roaming\Adobe Mini Bridge CS5
2011-04-29 18:49:18 -------- d-----w- C:\Users\Arafat\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-04-28 17:33:32 -------- d-----w- C:\Users\Arafat\AppData\Local\LogMeIn Hamachi
2011-04-27 19:32:54 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2011-04-27 19:32:54 31232 ----a-w- C:\Windows\System32\prevhost.exe
2011-04-26 03:55:55 -------- d-----w- C:\Users\Arafat\AppData\Local\{8D1EDC76-8B80-469A-B1C7-3BA58AE0635D}
.
==================== Find3M ====================
.
2011-04-05 17:52:57 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-04-05 17:52:56 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-03-25 19:47:02 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2011-03-19 11:43:50 103736 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-03-12 12:08:49 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-03-12 11:23:45 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-03-11 06:41:37 189824 ----a-w- C:\Windows\System32\drivers\storport.sys
2011-03-11 06:41:34 166272 ----a-w- C:\Windows\System32\drivers\nvstor.sys
2011-03-11 06:41:34 1659776 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2011-03-11 06:41:34 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys
2011-03-11 06:41:26 410496 ----a-w- C:\Windows\System32\drivers\iaStorV.sys
2011-03-11 06:41:12 27008 ----a-w- C:\Windows\System32\drivers\amdxata.sys
2011-03-11 06:41:12 107904 ----a-w- C:\Windows\System32\drivers\amdsata.sys
2011-03-11 06:34:51 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2011-03-11 06:34:50 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2011-03-11 06:33:29 2565632 ----a-w- C:\Windows\System32\esent.dll
2011-03-11 06:30:28 96768 ----a-w- C:\Windows\System32\fsutil.exe
2011-03-11 05:33:59 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-03-11 05:33:59 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
2011-03-11 05:33:09 1699328 ----a-w- C:\Windows\SysWow64\esent.dll
2011-03-11 05:31:07 74240 ----a-w- C:\Windows\SysWow64\fsutil.exe
2011-03-10 12:02:41 66872 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-03-08 06:29:32 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-03-08 05:28:29 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-03-07 06:31:44 1188864 ----a-w- C:\Windows\System32\wininet.dll_old0
2011-03-07 06:31:43 1491456 ----a-w- C:\Windows\System32\urlmon.dll_old0
2011-03-07 05:33:13 981504 ----a-w- C:\Windows\SysWow64\wininet.dll_old0
2011-03-07 05:33:10 1230336 ----a-w- C:\Windows\SysWow64\urlmon.dll_old0
2011-03-04 06:19:28 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2011-03-04 06:19:27 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2011-03-03 06:24:16 183296 ----a-w- C:\Windows\System32\dnsrslvr.dll
2011-03-03 06:21:57 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
2011-03-03 05:36:16 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
2011-03-03 03:52:08 3135488 ----a-w- C:\Windows\System32\win32k.sys
2011-02-25 06:19:30 2871808 ----a-w- C:\Windows\explorer.exe
2011-02-25 05:30:54 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
.
============= FINISH: 19:34:54.64 ===============
Post attach.txt part too, please.
Here's the Attach.zip file
Hi
Please visit this webpage for download links, and instructions for running ComboFix tool:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Please ensure you read this guide carefully first.
Please continue as follows:
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.
Click Yes to allow ComboFix to continue scanning for malware.
When the tool is finished, it will produce a report for you.
Please include the following reports for further review, and so we may continue cleansing the system:
C:\ComboFix.txt
New dds log.
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
Sorry it took me a while too figure out how to remove all traces of AVG as otherwise Combofix won't run.
I am without an antivirus protection for the moment, just Spybot
here are the Combofix and DDS logs
Combofix:
ComboFix 11-05-25.01 - Arafat 05/26/2011 9:10.1.4 - x64 MINIMAL
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4094.2964 [GMT 3:00]
Running from: c:\users\Arafat\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\WINDOWS_7_LOADER_EXTREME_EDITION_3006.EXE
c:\windows_7_loader_extreme_edition_3006.exe\WINDOWS_7_LOADER_EXTREME_EDITION_3006.EXE
D:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-04-26 to 2011-05-26 )))))))))))))))))))))))))))))))
.
.
2011-05-26 06:15 . 2011-05-26 06:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-05-24 17:20 . 2011-05-24 17:20 -------- d-----w- c:\users\Arafat\AppData\Local\{F89D2A5B-1CEC-45DC-98CD-3B8C27C55EEE}
2011-05-23 17:20 . 2011-05-23 17:21 -------- d-----w- c:\users\Arafat\AppData\Local\{4DE85A21-2AE4-47ED-BC23-4F1B47C9B7B2}
2011-05-22 14:50 . 2011-05-22 14:50 -------- d-----w- c:\users\Arafat\AppData\Local\{53869421-6B45-47B0-BAAE-AC1408A79C47}
2011-05-21 19:33 . 2011-05-21 19:34 -------- d-----w- c:\users\Arafat\AppData\Local\{28E7D7E8-526F-4ADB-8181-667D33A61DFC}
2011-05-20 11:15 . 2011-05-20 11:16 -------- d-----w- c:\users\Arafat\AppData\Local\{56890F7F-2472-4A8F-A825-0DA532617CE6}
2011-05-19 19:36 . 2011-05-19 19:36 -------- d-----w- c:\users\Arafat\AppData\Local\{8C0B880F-FE73-42DE-9E92-B6446DDFEED8}
2011-05-19 07:22 . 2011-05-19 07:22 -------- d-----w- c:\users\Arafat\AppData\Local\{B9C6FE17-3E5D-445E-81FC-B36AC7E71BFD}
2011-05-17 17:00 . 2011-05-17 17:01 -------- d-----w- c:\users\Arafat\AppData\Local\{722E076A-2A84-4677-817F-9B07F571FAF7}
2011-05-16 19:38 . 2011-05-16 19:38 -------- d-----w- c:\windows\CheckSur
2011-05-16 13:33 . 2011-05-16 13:33 -------- d-----w- c:\users\Arafat\AppData\Local\{BDF4F900-0721-419A-8ED0-6523DC1EAE5B}
2011-05-15 19:35 . 2011-05-15 19:35 -------- d-----w- c:\users\Arafat\AppData\Local\{030EF9CD-9022-4E12-9DBB-B84C85271380}
2011-05-14 10:01 . 2011-05-14 10:01 -------- d-----w- c:\users\Arafat\AppData\Local\{45440B02-B680-4F0C-8383-77335D4A364D}
2011-05-13 12:22 . 2011-05-13 12:23 -------- d-----w- c:\users\Arafat\AppData\Local\{F1CA829F-9FBD-4126-B743-964971EFE397}
2011-05-13 00:22 . 2011-05-13 00:22 -------- d-----w- c:\users\Arafat\AppData\Local\{DBF4DA55-5321-4C54-BC10-064FB4195B9A}
2011-05-12 16:23 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe
2011-05-12 16:23 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
2011-05-12 16:23 . 2011-04-09 07:02 5562240 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-05-12 16:23 . 2011-04-09 06:02 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-05-12 16:23 . 2011-04-09 06:02 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-05-12 16:23 . 2011-03-25 03:29 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2011-05-12 16:23 . 2011-03-25 03:29 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2011-05-12 16:23 . 2011-03-25 03:29 98816 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-05-12 16:23 . 2011-03-25 03:29 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2011-05-12 16:23 . 2011-03-25 03:29 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2011-05-12 16:23 . 2011-03-25 03:29 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2011-05-12 16:23 . 2011-03-25 03:28 7936 ----a-w- c:\windows\system32\drivers\usbd.sys
2011-05-12 12:21 . 2011-05-12 12:21 -------- d-----w- c:\users\Arafat\AppData\Local\{F406B812-45E2-4230-BA50-E83EF04489A8}
2011-05-11 12:00 . 2011-05-11 12:00 -------- d-----w- c:\users\Arafat\AppData\Local\{28908B83-A866-4881-A0DF-9D4B9725212C}
2011-05-10 19:56 . 2011-05-10 19:56 -------- d-----w- c:\users\Arafat\AppData\Local\{734B2427-E039-4411-8F79-E012EEBC64E2}
2011-05-10 14:40 . 2011-05-10 14:41 -------- d-----w- c:\users\Arafat\AppData\Local\{35249393-6A33-453D-953B-FABE876212B1}
2011-05-09 10:50 . 2011-05-09 10:50 -------- d-----w- c:\users\Arafat\AppData\Local\{75B41FDB-2E3E-4CFC-8BD1-317E811B15EE}
2011-05-08 14:05 . 2011-05-08 14:05 -------- d-----w- c:\users\Arafat\AppData\Local\{1634022F-82E0-4C38-89D3-F73F04AC2E67}
2011-05-07 23:03 . 2011-05-07 23:03 -------- d-----w- c:\users\Arafat\AppData\Local\{46675658-ABF9-40D2-9B55-95A46081EE73}
2011-05-07 11:03 . 2011-05-07 11:03 -------- d-----w- c:\users\Arafat\AppData\Local\{C674A4FC-A059-48FE-A0EC-3CBF6BE88701}
2011-05-06 22:25 . 2011-05-06 22:25 -------- d-----w- c:\users\Arafat\AppData\Local\{373DC4A2-95CD-4835-96E2-7EFEF26C78DD}
2011-05-05 00:10 . 2011-05-05 00:10 -------- d-----w- c:\users\Arafat\AppData\Local\{FD4D9AE6-5699-4411-AFCD-F33C725CD855}
2011-05-04 12:09 . 2011-05-04 12:09 -------- d-----w- c:\users\Arafat\AppData\Local\{A1534F8F-DF95-4875-9AE8-C5B9B3CB7EB5}
2011-05-03 18:09 . 2011-05-03 18:09 -------- d-----w- c:\users\Arafat\AppData\Local\{B8A096B0-ABB0-46A5-A046-6702D317EB29}
2011-04-30 17:17 . 2011-04-30 17:17 -------- d-----w- c:\users\Public\Recorded TV
2011-04-29 18:49 . 2011-04-29 18:49 -------- d-----w- c:\users\Arafat\AppData\Roaming\Adobe Mini Bridge CS5
2011-04-29 18:49 . 2011-04-29 18:49 -------- d-----w- c:\users\Arafat\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-04-28 17:33 . 2011-05-22 04:40 -------- d-----w- c:\users\Arafat\AppData\Local\LogMeIn Hamachi
2011-04-27 19:32 . 2011-02-18 10:51 31232 ----a-w- c:\windows\system32\prevhost.exe
2011-04-27 19:32 . 2011-02-18 05:39 31232 ----a-w- c:\windows\SysWow64\prevhost.exe
2011-04-26 18:02 . 2011-04-26 18:02 -------- d-----w- c:\program files (x86)\7-Zip
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-23 09:22 . 2011-04-23 09:22 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-04-23 09:22 . 2011-04-23 09:22 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-04-23 09:22 . 2011-04-23 09:22 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-04-23 09:22 . 2011-04-23 09:22 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-04-23 09:22 . 2011-04-23 09:22 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-04-23 09:22 . 2011-04-23 09:22 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-04-23 09:22 . 2011-04-23 09:22 1797632 ----a-w- c:\windows\SysWow64\jscript9.dll
2011-04-23 09:22 . 2011-04-23 09:22 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-04-23 09:22 . 2011-04-23 09:22 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-04-23 09:22 . 2011-04-23 09:22 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-04-23 09:22 . 2011-04-23 09:22 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-04-23 09:22 . 2011-04-23 09:22 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-04-23 09:22 . 2011-04-23 09:22 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-04-23 09:22 . 2011-04-23 09:22 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-04-23 09:22 . 2011-04-23 09:22 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-04-23 09:22 . 2011-04-23 09:22 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-04-23 09:22 . 2011-04-23 09:22 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-04-23 09:22 . 2011-04-23 09:22 448512 ----a-w- c:\windows\system32\html.iec
2011-04-23 09:22 . 2011-04-23 09:22 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-04-23 09:22 . 2011-04-23 09:22 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-04-23 09:22 . 2011-04-23 09:22 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-23 09:22 . 2011-04-23 09:22 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-04-23 09:22 . 2011-04-23 09:22 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-04-23 09:22 . 2011-04-23 09:22 2303488 ----a-w- c:\windows\system32\jscript9.dll
2011-04-23 09:22 . 2011-04-23 09:22 222208 ----a-w- c:\windows\system32\msls31.dll
2011-04-23 09:22 . 2011-04-23 09:22 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-04-23 09:22 . 2011-04-23 09:22 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-04-23 09:22 . 2011-04-23 09:22 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-04-23 09:22 . 2011-04-23 09:22 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-23 09:22 . 2011-04-23 09:22 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-04-23 09:22 . 2011-04-23 09:22 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-04-23 09:22 . 2011-04-23 09:22 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-04-23 09:22 . 2011-04-23 09:22 12288 ----a-w- c:\windows\system32\mshta.exe
2011-04-23 09:22 . 2011-04-23 09:22 114176 ----a-w- c:\windows\system32\admparse.dll
2011-04-23 09:22 . 2011-04-23 09:22 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-04-23 09:22 . 2011-04-23 09:22 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-04-23 09:22 . 2011-04-23 09:22 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-04-23 09:22 . 2011-04-23 09:22 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-04-23 09:22 . 2011-04-23 09:22 160256 ----a-w- c:\windows\system32\wextract.exe
2011-04-05 17:52 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-04-05 17:52 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-03-25 19:47 . 2011-03-25 19:47 53248 ----a-r- c:\users\Arafat\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-03-25 19:47 . 2011-03-25 19:47 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-03-19 11:43 . 2011-03-08 18:25 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-03-11 06:34 . 2011-04-19 23:31 1359872 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-11 06:34 . 2011-04-19 23:31 1395712 ----a-w- c:\windows\system32\mfc42.dll
2011-03-11 05:33 . 2011-04-19 23:31 1164288 ----a-w- c:\windows\SysWow64\mfc42u.dll
2011-03-11 05:33 . 2011-04-19 23:31 1137664 ----a-w- c:\windows\SysWow64\mfc42.dll
2011-03-10 12:02 . 2011-03-08 18:25 66872 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-03-09 12:26 . 2010-06-24 08:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-08 06:29 . 2011-04-19 23:31 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-08 05:28 . 2011-04-19 23:31 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-03-07 06:31 . 2011-04-19 23:31 1188864 ----a-w- c:\windows\system32\wininet.dll_old0
2011-03-07 06:31 . 2011-04-19 23:31 1491456 ----a-w- c:\windows\system32\urlmon.dll_old0
2011-03-07 05:33 . 2011-04-19 23:31 981504 ----a-w- c:\windows\SysWow64\wininet.dll_old0
2011-03-07 05:33 . 2011-04-19 23:31 1230336 ----a-w- c:\windows\SysWow64\urlmon.dll_old0
2011-03-04 06:19 . 2011-04-27 19:33 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2011-03-04 06:19 . 2011-04-27 19:33 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2011-03-03 06:24 . 2011-04-19 23:31 183296 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-03-03 06:21 . 2011-04-19 23:31 30208 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-03-03 05:36 . 2011-04-19 23:31 28672 ----a-w- c:\windows\SysWow64\dnscacheugc.exe
2011-03-03 03:52 . 2011-04-19 23:31 3135488 ----a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
"SpybotSD TeaTimer"="d:\spybot - search & destroy\TeaTimer.exe" [2009-03-05 2260480]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]
"TurboV EVO"="c:\program files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe" [2010-07-07 9936000]
"Adobe Reader Speed Launcher"="d:\adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-26 336384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
R2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.05\AsSysCtrlService.exe [2010-06-24 109056]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;d:\logmein hamachi\hamachi-2.exe [2011-03-28 2111368]
R3 ALSysIO;ALSysIO;c:\users\Arafat\AppData\Local\Temp\ALSysIO64.sys [x]
R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\ccdcmbox64.sys [x]
R3 nmwcdnsucx64;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsucx64.sys [x]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-488920656-923882004-2919504125-1000Core.job
- c:\users\Arafat\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-14 21:18]
.
2011-05-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-488920656-923882004-2919504125-1000UA.job
- c:\users\Arafat\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-14 21:18]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-21 2327952]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1680976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - d:\micros~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - d:\micros~1\Office14\ONBttnIE.dll/105
FF - ProfilePath - c:\users\Arafat\AppData\Roaming\Mozilla\Firefox\Profiles\brjkibx7.default\
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-488920656-923882004-2919504125-1000\Software\SecuROM\License information*]
"datasecu"=hex:2d,54,ca,c7,67,e8,33,51,78,d5,b0,38,26,50,f9,81,5f,37,b8,f5,db,
f8,16,e6,4d,54,55,67,77,e9,6a,a4,d3,8f,ba,2b,bf,e7,75,b8,e7,be,de,ed,0d,20,\
"rkeysecu"=hex:2f,39,a8,68,ed,3f,13,ee,4c,92,12,48,6f,d3,8e,54
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-05-26 09:16:49
ComboFix-quarantined-files.txt 2011-05-26 06:16
.
Pre-Run: 32,714,440,704 bytes free
Post-Run: 32,311,721,984 bytes free
.
- - End Of File - - 047DE59756FD341738CE003E763F4DC1
DDS log:
.
DDS (Ver_11-05-19.01) - NTFSx86 MINIMAL
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Run by Arafat at 9:30:17 on 2011-05-26
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4094.3138 [GMT 3:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Users\Arafat\Desktop\New folder\Fixing\Merlin.com
C:\Windows\SysWOW64\WSCRIPT.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - D:\SPYBOT~1\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
uRun: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\TeaTimer.exe
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [TurboV EVO] "C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe" -b
mRun: [Adobe Reader Speed Launcher] "D:\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - D:\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - D:\MICROS~1\Office14\ONBttnIE.dll/105
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO-X64: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
mRun-x64: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
mRun-x64: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Arafat\AppData\Roaming\Mozilla\Firefox\Profiles\brjkibx7.default\
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Arafat\AppData\Local\Google\Update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: C:\Users\Arafat\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - plugin: D:\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
FF - plugin: D:\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: D:\Mozilla Firefox\plugins\NPDFusionWebFirefox.dll
FF - plugin: D:\VideoLAN\VLC\npvlc.dll
.
============= SERVICES / DRIVERS ===============
.
S2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-14 20992]
S2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
S2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.05\AsSysCtrlService.exe [2010-11-14 109056]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;D:\LogMeIn Hamachi\hamachi-2.exe [2011-3-28 2111368]
S2 KMService;KMService;C:\Windows\System32\srvany.exe [2011-1-6 8192]
S3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
S3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-1-21 30963576]
S3 nmwcdcx64;Nokia USB Generic;C:\Windows\system32\drivers\ccdcmbox64.sys --> C:\Windows\system32\drivers\ccdcmbox64.sys [?]
S3 nmwcdnsucx64;Nokia USB Flashing Generic;C:\Windows\system32\drivers\nmwcdnsucx64.sys --> C:\Windows\system32\drivers\nmwcdnsucx64.sys [?]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent;C:\Windows\system32\drivers\nmwcdnsux64.sys --> C:\Windows\system32\drivers\nmwcdnsux64.sys [?]
S3 nmwcdx64;Nokia USB Phone Parent;C:\Windows\system32\drivers\ccdcmbx64.sys --> C:\Windows\system32\drivers\ccdcmbx64.sys [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-05-26 06:26:27 8006480 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-05-26 06:26:23 8718160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6D451A7-2481-418B-905A-A68AEEA9E36C}\mpengine.dll
2011-05-26 06:19:46 -------- d-sh--w- C:\$RECYCLE.BIN
2011-05-26 01:41:29 98816 ----a-w- C:\Windows\sed.exe
2011-05-26 01:41:29 89088 ----a-w- C:\Windows\MBR.exe
2011-05-26 01:41:29 256512 ----a-w- C:\Windows\PEV.exe
2011-05-26 01:41:29 161792 ----a-w- C:\Windows\SWREG.exe
2011-05-24 17:20:29 -------- d-----w- C:\Users\Arafat\AppData\Local\{F89D2A5B-1CEC-45DC-98CD-3B8C27C55EEE}
2011-05-23 17:20:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{4DE85A21-2AE4-47ED-BC23-4F1B47C9B7B2}
2011-05-22 14:50:15 -------- d-----w- C:\Users\Arafat\AppData\Local\{53869421-6B45-47B0-BAAE-AC1408A79C47}
2011-05-21 19:33:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{28E7D7E8-526F-4ADB-8181-667D33A61DFC}
2011-05-20 11:15:55 -------- d-----w- C:\Users\Arafat\AppData\Local\{56890F7F-2472-4A8F-A825-0DA532617CE6}
2011-05-19 19:36:48 -------- d-----w- C:\Users\Arafat\AppData\Local\{8C0B880F-FE73-42DE-9E92-B6446DDFEED8}
2011-05-19 07:22:39 -------- d-----w- C:\Users\Arafat\AppData\Local\{B9C6FE17-3E5D-445E-81FC-B36AC7E71BFD}
2011-05-17 17:00:55 -------- d-----w- C:\Users\Arafat\AppData\Local\{722E076A-2A84-4677-817F-9B07F571FAF7}
2011-05-16 19:38:31 -------- d-----w- C:\Windows\CheckSur
2011-05-16 13:33:11 -------- d-----w- C:\Users\Arafat\AppData\Local\{BDF4F900-0721-419A-8ED0-6523DC1EAE5B}
2011-05-15 19:35:45 -------- d-----w- C:\Users\Arafat\AppData\Local\{030EF9CD-9022-4E12-9DBB-B84C85271380}
2011-05-14 10:01:26 -------- d-----w- C:\Users\Arafat\AppData\Local\{45440B02-B680-4F0C-8383-77335D4A364D}
2011-05-13 12:22:47 -------- d-----w- C:\Users\Arafat\AppData\Local\{F1CA829F-9FBD-4126-B743-964971EFE397}
2011-05-13 00:22:01 -------- d-----w- C:\Users\Arafat\AppData\Local\{DBF4DA55-5321-4C54-BC10-064FB4195B9A}
2011-05-12 16:23:19 142336 ----a-w- C:\Windows\System32\poqexec.exe
2011-05-12 16:23:19 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2011-05-12 16:23:18 5562240 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-05-12 16:23:17 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-05-12 16:23:17 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-05-12 16:23:08 52736 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2011-05-12 16:23:07 98816 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2011-05-12 16:23:07 7936 ----a-w- C:\Windows\System32\drivers\usbd.sys
2011-05-12 16:23:07 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2011-05-12 16:23:07 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2011-05-12 16:23:07 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2011-05-12 16:23:07 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2011-05-12 12:21:26 -------- d-----w- C:\Users\Arafat\AppData\Local\{F406B812-45E2-4230-BA50-E83EF04489A8}
2011-05-11 12:00:13 -------- d-----w- C:\Users\Arafat\AppData\Local\{28908B83-A866-4881-A0DF-9D4B9725212C}
2011-05-10 19:56:05 -------- d-----w- C:\Users\Arafat\AppData\Local\{734B2427-E039-4411-8F79-E012EEBC64E2}
2011-05-10 14:40:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{35249393-6A33-453D-953B-FABE876212B1}
2011-05-09 10:50:09 -------- d-----w- C:\Users\Arafat\AppData\Local\{75B41FDB-2E3E-4CFC-8BD1-317E811B15EE}
2011-05-08 14:05:17 -------- d-----w- C:\Users\Arafat\AppData\Local\{1634022F-82E0-4C38-89D3-F73F04AC2E67}
2011-05-07 23:03:35 -------- d-----w- C:\Users\Arafat\AppData\Local\{46675658-ABF9-40D2-9B55-95A46081EE73}
2011-05-07 11:03:01 -------- d-----w- C:\Users\Arafat\AppData\Local\{C674A4FC-A059-48FE-A0EC-3CBF6BE88701}
2011-05-06 22:25:11 -------- d-----w- C:\Users\Arafat\AppData\Local\{373DC4A2-95CD-4835-96E2-7EFEF26C78DD}
2011-05-05 00:10:00 -------- d-----w- C:\Users\Arafat\AppData\Local\{FD4D9AE6-5699-4411-AFCD-F33C725CD855}
2011-05-04 12:09:24 -------- d-----w- C:\Users\Arafat\AppData\Local\{A1534F8F-DF95-4875-9AE8-C5B9B3CB7EB5}
2011-05-03 18:09:09 -------- d-----w- C:\Users\Arafat\AppData\Local\{B8A096B0-ABB0-46A5-A046-6702D317EB29}
2011-04-29 18:49:19 -------- d-----w- C:\Users\Arafat\AppData\Roaming\Adobe Mini Bridge CS5
2011-04-29 18:49:18 -------- d-----w- C:\Users\Arafat\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-04-28 17:33:32 -------- d-----w- C:\Users\Arafat\AppData\Local\LogMeIn Hamachi
2011-04-27 19:32:54 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2011-04-27 19:32:54 31232 ----a-w- C:\Windows\System32\prevhost.exe
.
==================== Find3M ====================
.
2011-04-05 17:52:57 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-04-05 17:52:56 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-03-25 19:47:02 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2011-03-19 11:43:50 103736 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-03-12 12:08:49 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-03-12 11:23:45 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-03-11 06:41:37 189824 ----a-w- C:\Windows\System32\drivers\storport.sys
2011-03-11 06:41:34 166272 ----a-w- C:\Windows\System32\drivers\nvstor.sys
2011-03-11 06:41:34 1659776 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2011-03-11 06:41:34 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys
2011-03-11 06:41:26 410496 ----a-w- C:\Windows\System32\drivers\iaStorV.sys
2011-03-11 06:41:12 27008 ----a-w- C:\Windows\System32\drivers\amdxata.sys
2011-03-11 06:41:12 107904 ----a-w- C:\Windows\System32\drivers\amdsata.sys
2011-03-11 06:34:51 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2011-03-11 06:34:50 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2011-03-11 06:33:29 2565632 ----a-w- C:\Windows\System32\esent.dll
2011-03-11 06:30:28 96768 ----a-w- C:\Windows\System32\fsutil.exe
2011-03-11 05:33:59 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-03-11 05:33:59 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
2011-03-11 05:33:09 1699328 ----a-w- C:\Windows\SysWow64\esent.dll
2011-03-11 05:31:07 74240 ----a-w- C:\Windows\SysWow64\fsutil.exe
2011-03-10 12:02:41 66872 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-03-08 06:29:32 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-03-08 05:28:29 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-03-07 06:31:44 1188864 ----a-w- C:\Windows\System32\wininet.dll_old0
2011-03-07 06:31:43 1491456 ----a-w- C:\Windows\System32\urlmon.dll_old0
2011-03-07 05:33:13 981504 ----a-w- C:\Windows\SysWow64\wininet.dll_old0
2011-03-07 05:33:10 1230336 ----a-w- C:\Windows\SysWow64\urlmon.dll_old0
2011-03-04 06:19:28 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2011-03-04 06:19:27 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2011-03-03 06:24:16 183296 ----a-w- C:\Windows\System32\dnsrslvr.dll
2011-03-03 06:21:57 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
2011-03-03 05:36:16 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
2011-03-03 03:52:08 3135488 ----a-w- C:\Windows\System32\win32k.sys
.
============= FINISH: 9:31:16.28 ===============
Sorry it took me a while too figure out how to remove all traces of AVG as otherwise Combofix won't run.
I am without an antivirus protection for the moment, just Spybot
However, the issue still remains. I still cannot run ccleaner, Spybot, DDS or even get to regedit in normal mode. I've been doing everything from Safemode.
here are the Combofix and DDS logs
Combofix:
ComboFix 11-05-25.01 - Arafat 05/26/2011 9:10.1.4 - x64 MINIMAL
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4094.2964 [GMT 3:00]
Running from: c:\users\Arafat\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\WINDOWS_7_LOADER_EXTREME_EDITION_3006.EXE
c:\windows_7_loader_extreme_edition_3006.exe\WINDOWS_7_LOADER_EXTREME_EDITION_3006.EXE
D:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-04-26 to 2011-05-26 )))))))))))))))))))))))))))))))
.
.
2011-05-26 06:15 . 2011-05-26 06:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-05-24 17:20 . 2011-05-24 17:20 -------- d-----w- c:\users\Arafat\AppData\Local\{F89D2A5B-1CEC-45DC-98CD-3B8C27C55EEE}
2011-05-23 17:20 . 2011-05-23 17:21 -------- d-----w- c:\users\Arafat\AppData\Local\{4DE85A21-2AE4-47ED-BC23-4F1B47C9B7B2}
2011-05-22 14:50 . 2011-05-22 14:50 -------- d-----w- c:\users\Arafat\AppData\Local\{53869421-6B45-47B0-BAAE-AC1408A79C47}
2011-05-21 19:33 . 2011-05-21 19:34 -------- d-----w- c:\users\Arafat\AppData\Local\{28E7D7E8-526F-4ADB-8181-667D33A61DFC}
2011-05-20 11:15 . 2011-05-20 11:16 -------- d-----w- c:\users\Arafat\AppData\Local\{56890F7F-2472-4A8F-A825-0DA532617CE6}
2011-05-19 19:36 . 2011-05-19 19:36 -------- d-----w- c:\users\Arafat\AppData\Local\{8C0B880F-FE73-42DE-9E92-B6446DDFEED8}
2011-05-19 07:22 . 2011-05-19 07:22 -------- d-----w- c:\users\Arafat\AppData\Local\{B9C6FE17-3E5D-445E-81FC-B36AC7E71BFD}
2011-05-17 17:00 . 2011-05-17 17:01 -------- d-----w- c:\users\Arafat\AppData\Local\{722E076A-2A84-4677-817F-9B07F571FAF7}
2011-05-16 19:38 . 2011-05-16 19:38 -------- d-----w- c:\windows\CheckSur
2011-05-16 13:33 . 2011-05-16 13:33 -------- d-----w- c:\users\Arafat\AppData\Local\{BDF4F900-0721-419A-8ED0-6523DC1EAE5B}
2011-05-15 19:35 . 2011-05-15 19:35 -------- d-----w- c:\users\Arafat\AppData\Local\{030EF9CD-9022-4E12-9DBB-B84C85271380}
2011-05-14 10:01 . 2011-05-14 10:01 -------- d-----w- c:\users\Arafat\AppData\Local\{45440B02-B680-4F0C-8383-77335D4A364D}
2011-05-13 12:22 . 2011-05-13 12:23 -------- d-----w- c:\users\Arafat\AppData\Local\{F1CA829F-9FBD-4126-B743-964971EFE397}
2011-05-13 00:22 . 2011-05-13 00:22 -------- d-----w- c:\users\Arafat\AppData\Local\{DBF4DA55-5321-4C54-BC10-064FB4195B9A}
2011-05-12 16:23 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe
2011-05-12 16:23 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
2011-05-12 16:23 . 2011-04-09 07:02 5562240 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-05-12 16:23 . 2011-04-09 06:02 3967872 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-05-12 16:23 . 2011-04-09 06:02 3912576 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-05-12 16:23 . 2011-03-25 03:29 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2011-05-12 16:23 . 2011-03-25 03:29 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2011-05-12 16:23 . 2011-03-25 03:29 98816 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-05-12 16:23 . 2011-03-25 03:29 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2011-05-12 16:23 . 2011-03-25 03:29 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2011-05-12 16:23 . 2011-03-25 03:29 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2011-05-12 16:23 . 2011-03-25 03:28 7936 ----a-w- c:\windows\system32\drivers\usbd.sys
2011-05-12 12:21 . 2011-05-12 12:21 -------- d-----w- c:\users\Arafat\AppData\Local\{F406B812-45E2-4230-BA50-E83EF04489A8}
2011-05-11 12:00 . 2011-05-11 12:00 -------- d-----w- c:\users\Arafat\AppData\Local\{28908B83-A866-4881-A0DF-9D4B9725212C}
2011-05-10 19:56 . 2011-05-10 19:56 -------- d-----w- c:\users\Arafat\AppData\Local\{734B2427-E039-4411-8F79-E012EEBC64E2}
2011-05-10 14:40 . 2011-05-10 14:41 -------- d-----w- c:\users\Arafat\AppData\Local\{35249393-6A33-453D-953B-FABE876212B1}
2011-05-09 10:50 . 2011-05-09 10:50 -------- d-----w- c:\users\Arafat\AppData\Local\{75B41FDB-2E3E-4CFC-8BD1-317E811B15EE}
2011-05-08 14:05 . 2011-05-08 14:05 -------- d-----w- c:\users\Arafat\AppData\Local\{1634022F-82E0-4C38-89D3-F73F04AC2E67}
2011-05-07 23:03 . 2011-05-07 23:03 -------- d-----w- c:\users\Arafat\AppData\Local\{46675658-ABF9-40D2-9B55-95A46081EE73}
2011-05-07 11:03 . 2011-05-07 11:03 -------- d-----w- c:\users\Arafat\AppData\Local\{C674A4FC-A059-48FE-A0EC-3CBF6BE88701}
2011-05-06 22:25 . 2011-05-06 22:25 -------- d-----w- c:\users\Arafat\AppData\Local\{373DC4A2-95CD-4835-96E2-7EFEF26C78DD}
2011-05-05 00:10 . 2011-05-05 00:10 -------- d-----w- c:\users\Arafat\AppData\Local\{FD4D9AE6-5699-4411-AFCD-F33C725CD855}
2011-05-04 12:09 . 2011-05-04 12:09 -------- d-----w- c:\users\Arafat\AppData\Local\{A1534F8F-DF95-4875-9AE8-C5B9B3CB7EB5}
2011-05-03 18:09 . 2011-05-03 18:09 -------- d-----w- c:\users\Arafat\AppData\Local\{B8A096B0-ABB0-46A5-A046-6702D317EB29}
2011-04-30 17:17 . 2011-04-30 17:17 -------- d-----w- c:\users\Public\Recorded TV
2011-04-29 18:49 . 2011-04-29 18:49 -------- d-----w- c:\users\Arafat\AppData\Roaming\Adobe Mini Bridge CS5
2011-04-29 18:49 . 2011-04-29 18:49 -------- d-----w- c:\users\Arafat\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-04-28 17:33 . 2011-05-22 04:40 -------- d-----w- c:\users\Arafat\AppData\Local\LogMeIn Hamachi
2011-04-27 19:32 . 2011-02-18 10:51 31232 ----a-w- c:\windows\system32\prevhost.exe
2011-04-27 19:32 . 2011-02-18 05:39 31232 ----a-w- c:\windows\SysWow64\prevhost.exe
2011-04-26 18:02 . 2011-04-26 18:02 -------- d-----w- c:\program files (x86)\7-Zip
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-23 09:22 . 2011-04-23 09:22 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-04-23 09:22 . 2011-04-23 09:22 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-04-23 09:22 . 2011-04-23 09:22 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-04-23 09:22 . 2011-04-23 09:22 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-04-23 09:22 . 2011-04-23 09:22 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-04-23 09:22 . 2011-04-23 09:22 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-04-23 09:22 . 2011-04-23 09:22 1797632 ----a-w- c:\windows\SysWow64\jscript9.dll
2011-04-23 09:22 . 2011-04-23 09:22 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-04-23 09:22 . 2011-04-23 09:22 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-04-23 09:22 . 2011-04-23 09:22 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-04-23 09:22 . 2011-04-23 09:22 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-04-23 09:22 . 2011-04-23 09:22 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-04-23 09:22 . 2011-04-23 09:22 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-04-23 09:22 . 2011-04-23 09:22 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-04-23 09:22 . 2011-04-23 09:22 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-04-23 09:22 . 2011-04-23 09:22 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-04-23 09:22 . 2011-04-23 09:22 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-04-23 09:22 . 2011-04-23 09:22 448512 ----a-w- c:\windows\system32\html.iec
2011-04-23 09:22 . 2011-04-23 09:22 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-04-23 09:22 . 2011-04-23 09:22 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-04-23 09:22 . 2011-04-23 09:22 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-23 09:22 . 2011-04-23 09:22 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-04-23 09:22 . 2011-04-23 09:22 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-04-23 09:22 . 2011-04-23 09:22 2303488 ----a-w- c:\windows\system32\jscript9.dll
2011-04-23 09:22 . 2011-04-23 09:22 222208 ----a-w- c:\windows\system32\msls31.dll
2011-04-23 09:22 . 2011-04-23 09:22 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-04-23 09:22 . 2011-04-23 09:22 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-04-23 09:22 . 2011-04-23 09:22 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-04-23 09:22 . 2011-04-23 09:22 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-23 09:22 . 2011-04-23 09:22 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-04-23 09:22 . 2011-04-23 09:22 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-04-23 09:22 . 2011-04-23 09:22 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-04-23 09:22 . 2011-04-23 09:22 12288 ----a-w- c:\windows\system32\mshta.exe
2011-04-23 09:22 . 2011-04-23 09:22 114176 ----a-w- c:\windows\system32\admparse.dll
2011-04-23 09:22 . 2011-04-23 09:22 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-04-23 09:22 . 2011-04-23 09:22 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-04-23 09:22 . 2011-04-23 09:22 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-04-23 09:22 . 2011-04-23 09:22 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-04-23 09:22 . 2011-04-23 09:22 160256 ----a-w- c:\windows\system32\wextract.exe
2011-04-05 17:52 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-04-05 17:52 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-03-25 19:47 . 2011-03-25 19:47 53248 ----a-r- c:\users\Arafat\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-03-25 19:47 . 2011-03-25 19:47 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-03-19 11:43 . 2011-03-08 18:25 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-03-11 06:34 . 2011-04-19 23:31 1359872 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-11 06:34 . 2011-04-19 23:31 1395712 ----a-w- c:\windows\system32\mfc42.dll
2011-03-11 05:33 . 2011-04-19 23:31 1164288 ----a-w- c:\windows\SysWow64\mfc42u.dll
2011-03-11 05:33 . 2011-04-19 23:31 1137664 ----a-w- c:\windows\SysWow64\mfc42.dll
2011-03-10 12:02 . 2011-03-08 18:25 66872 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-03-09 12:26 . 2010-06-24 08:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-08 06:29 . 2011-04-19 23:31 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-08 05:28 . 2011-04-19 23:31 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-03-07 06:31 . 2011-04-19 23:31 1188864 ----a-w- c:\windows\system32\wininet.dll_old0
2011-03-07 06:31 . 2011-04-19 23:31 1491456 ----a-w- c:\windows\system32\urlmon.dll_old0
2011-03-07 05:33 . 2011-04-19 23:31 981504 ----a-w- c:\windows\SysWow64\wininet.dll_old0
2011-03-07 05:33 . 2011-04-19 23:31 1230336 ----a-w- c:\windows\SysWow64\urlmon.dll_old0
2011-03-04 06:19 . 2011-04-27 19:33 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2011-03-04 06:19 . 2011-04-27 19:33 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2011-03-03 06:24 . 2011-04-19 23:31 183296 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-03-03 06:21 . 2011-04-19 23:31 30208 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-03-03 05:36 . 2011-04-19 23:31 28672 ----a-w- c:\windows\SysWow64\dnscacheugc.exe
2011-03-03 03:52 . 2011-04-19 23:31 3135488 ----a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
"SpybotSD TeaTimer"="d:\spybot - search & destroy\TeaTimer.exe" [2009-03-05 2260480]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]
"TurboV EVO"="c:\program files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe" [2010-07-07 9936000]
"Adobe Reader Speed Launcher"="d:\adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-26 336384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
R2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.05\AsSysCtrlService.exe [2010-06-24 109056]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;d:\logmein hamachi\hamachi-2.exe [2011-03-28 2111368]
R3 ALSysIO;ALSysIO;c:\users\Arafat\AppData\Local\Temp\ALSysIO64.sys [x]
R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\ccdcmbox64.sys [x]
R3 nmwcdnsucx64;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsucx64.sys [x]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-488920656-923882004-2919504125-1000Core.job
- c:\users\Arafat\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-14 21:18]
.
2011-05-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-488920656-923882004-2919504125-1000UA.job
- c:\users\Arafat\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-14 21:18]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-21 2327952]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1680976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - d:\micros~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - d:\micros~1\Office14\ONBttnIE.dll/105
FF - ProfilePath - c:\users\Arafat\AppData\Roaming\Mozilla\Firefox\Profiles\brjkibx7.default\
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-488920656-923882004-2919504125-1000\Software\SecuROM\License information*]
"datasecu"=hex:2d,54,ca,c7,67,e8,33,51,78,d5,b0,38,26,50,f9,81,5f,37,b8,f5,db,
f8,16,e6,4d,54,55,67,77,e9,6a,a4,d3,8f,ba,2b,bf,e7,75,b8,e7,be,de,ed,0d,20,\
"rkeysecu"=hex:2f,39,a8,68,ed,3f,13,ee,4c,92,12,48,6f,d3,8e,54
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-05-26 09:16:49
ComboFix-quarantined-files.txt 2011-05-26 06:16
.
Pre-Run: 32,714,440,704 bytes free
Post-Run: 32,311,721,984 bytes free
.
- - End Of File - - 047DE59756FD341738CE003E763F4DC1
DDS log:
.
DDS (Ver_11-05-19.01) - NTFSx86 MINIMAL
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Run by Arafat at 9:30:17 on 2011-05-26
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4094.3138 [GMT 3:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Users\Arafat\Desktop\New folder\Fixing\Merlin.com
C:\Windows\SysWOW64\WSCRIPT.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - D:\SPYBOT~1\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
uRun: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\TeaTimer.exe
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [TurboV EVO] "C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe" -b
mRun: [Adobe Reader Speed Launcher] "D:\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - D:\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - D:\MICROS~1\Office14\ONBttnIE.dll/105
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO-X64: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
mRun-x64: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
mRun-x64: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Arafat\AppData\Roaming\Mozilla\Firefox\Profiles\brjkibx7.default\
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Arafat\AppData\Local\Google\Update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: C:\Users\Arafat\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - plugin: D:\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
FF - plugin: D:\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: D:\Mozilla Firefox\plugins\NPDFusionWebFirefox.dll
FF - plugin: D:\VideoLAN\VLC\npvlc.dll
.
============= SERVICES / DRIVERS ===============
.
S2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-14 20992]
S2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
S2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.05\AsSysCtrlService.exe [2010-11-14 109056]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;D:\LogMeIn Hamachi\hamachi-2.exe [2011-3-28 2111368]
S2 KMService;KMService;C:\Windows\System32\srvany.exe [2011-1-6 8192]
S3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
S3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-1-21 30963576]
S3 nmwcdcx64;Nokia USB Generic;C:\Windows\system32\drivers\ccdcmbox64.sys --> C:\Windows\system32\drivers\ccdcmbox64.sys [?]
S3 nmwcdnsucx64;Nokia USB Flashing Generic;C:\Windows\system32\drivers\nmwcdnsucx64.sys --> C:\Windows\system32\drivers\nmwcdnsucx64.sys [?]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent;C:\Windows\system32\drivers\nmwcdnsux64.sys --> C:\Windows\system32\drivers\nmwcdnsux64.sys [?]
S3 nmwcdx64;Nokia USB Phone Parent;C:\Windows\system32\drivers\ccdcmbx64.sys --> C:\Windows\system32\drivers\ccdcmbx64.sys [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-05-26 06:26:27 8006480 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-05-26 06:26:23 8718160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6D451A7-2481-418B-905A-A68AEEA9E36C}\mpengine.dll
2011-05-26 06:19:46 -------- d-sh--w- C:\$RECYCLE.BIN
2011-05-26 01:41:29 98816 ----a-w- C:\Windows\sed.exe
2011-05-26 01:41:29 89088 ----a-w- C:\Windows\MBR.exe
2011-05-26 01:41:29 256512 ----a-w- C:\Windows\PEV.exe
2011-05-26 01:41:29 161792 ----a-w- C:\Windows\SWREG.exe
2011-05-24 17:20:29 -------- d-----w- C:\Users\Arafat\AppData\Local\{F89D2A5B-1CEC-45DC-98CD-3B8C27C55EEE}
2011-05-23 17:20:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{4DE85A21-2AE4-47ED-BC23-4F1B47C9B7B2}
2011-05-22 14:50:15 -------- d-----w- C:\Users\Arafat\AppData\Local\{53869421-6B45-47B0-BAAE-AC1408A79C47}
2011-05-21 19:33:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{28E7D7E8-526F-4ADB-8181-667D33A61DFC}
2011-05-20 11:15:55 -------- d-----w- C:\Users\Arafat\AppData\Local\{56890F7F-2472-4A8F-A825-0DA532617CE6}
2011-05-19 19:36:48 -------- d-----w- C:\Users\Arafat\AppData\Local\{8C0B880F-FE73-42DE-9E92-B6446DDFEED8}
2011-05-19 07:22:39 -------- d-----w- C:\Users\Arafat\AppData\Local\{B9C6FE17-3E5D-445E-81FC-B36AC7E71BFD}
2011-05-17 17:00:55 -------- d-----w- C:\Users\Arafat\AppData\Local\{722E076A-2A84-4677-817F-9B07F571FAF7}
2011-05-16 19:38:31 -------- d-----w- C:\Windows\CheckSur
2011-05-16 13:33:11 -------- d-----w- C:\Users\Arafat\AppData\Local\{BDF4F900-0721-419A-8ED0-6523DC1EAE5B}
2011-05-15 19:35:45 -------- d-----w- C:\Users\Arafat\AppData\Local\{030EF9CD-9022-4E12-9DBB-B84C85271380}
2011-05-14 10:01:26 -------- d-----w- C:\Users\Arafat\AppData\Local\{45440B02-B680-4F0C-8383-77335D4A364D}
2011-05-13 12:22:47 -------- d-----w- C:\Users\Arafat\AppData\Local\{F1CA829F-9FBD-4126-B743-964971EFE397}
2011-05-13 00:22:01 -------- d-----w- C:\Users\Arafat\AppData\Local\{DBF4DA55-5321-4C54-BC10-064FB4195B9A}
2011-05-12 16:23:19 142336 ----a-w- C:\Windows\System32\poqexec.exe
2011-05-12 16:23:19 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2011-05-12 16:23:18 5562240 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-05-12 16:23:17 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-05-12 16:23:17 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-05-12 16:23:08 52736 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2011-05-12 16:23:07 98816 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2011-05-12 16:23:07 7936 ----a-w- C:\Windows\System32\drivers\usbd.sys
2011-05-12 16:23:07 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2011-05-12 16:23:07 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2011-05-12 16:23:07 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2011-05-12 16:23:07 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2011-05-12 12:21:26 -------- d-----w- C:\Users\Arafat\AppData\Local\{F406B812-45E2-4230-BA50-E83EF04489A8}
2011-05-11 12:00:13 -------- d-----w- C:\Users\Arafat\AppData\Local\{28908B83-A866-4881-A0DF-9D4B9725212C}
2011-05-10 19:56:05 -------- d-----w- C:\Users\Arafat\AppData\Local\{734B2427-E039-4411-8F79-E012EEBC64E2}
2011-05-10 14:40:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{35249393-6A33-453D-953B-FABE876212B1}
2011-05-09 10:50:09 -------- d-----w- C:\Users\Arafat\AppData\Local\{75B41FDB-2E3E-4CFC-8BD1-317E811B15EE}
2011-05-08 14:05:17 -------- d-----w- C:\Users\Arafat\AppData\Local\{1634022F-82E0-4C38-89D3-F73F04AC2E67}
2011-05-07 23:03:35 -------- d-----w- C:\Users\Arafat\AppData\Local\{46675658-ABF9-40D2-9B55-95A46081EE73}
2011-05-07 11:03:01 -------- d-----w- C:\Users\Arafat\AppData\Local\{C674A4FC-A059-48FE-A0EC-3CBF6BE88701}
2011-05-06 22:25:11 -------- d-----w- C:\Users\Arafat\AppData\Local\{373DC4A2-95CD-4835-96E2-7EFEF26C78DD}
2011-05-05 00:10:00 -------- d-----w- C:\Users\Arafat\AppData\Local\{FD4D9AE6-5699-4411-AFCD-F33C725CD855}
2011-05-04 12:09:24 -------- d-----w- C:\Users\Arafat\AppData\Local\{A1534F8F-DF95-4875-9AE8-C5B9B3CB7EB5}
2011-05-03 18:09:09 -------- d-----w- C:\Users\Arafat\AppData\Local\{B8A096B0-ABB0-46A5-A046-6702D317EB29}
2011-04-29 18:49:19 -------- d-----w- C:\Users\Arafat\AppData\Roaming\Adobe Mini Bridge CS5
2011-04-29 18:49:18 -------- d-----w- C:\Users\Arafat\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-04-28 17:33:32 -------- d-----w- C:\Users\Arafat\AppData\Local\LogMeIn Hamachi
2011-04-27 19:32:54 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2011-04-27 19:32:54 31232 ----a-w- C:\Windows\System32\prevhost.exe
.
==================== Find3M ====================
.
2011-04-05 17:52:57 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-04-05 17:52:56 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-03-25 19:47:02 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2011-03-19 11:43:50 103736 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-03-12 12:08:49 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-03-12 11:23:45 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-03-11 06:41:37 189824 ----a-w- C:\Windows\System32\drivers\storport.sys
2011-03-11 06:41:34 166272 ----a-w- C:\Windows\System32\drivers\nvstor.sys
2011-03-11 06:41:34 1659776 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2011-03-11 06:41:34 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys
2011-03-11 06:41:26 410496 ----a-w- C:\Windows\System32\drivers\iaStorV.sys
2011-03-11 06:41:12 27008 ----a-w- C:\Windows\System32\drivers\amdxata.sys
2011-03-11 06:41:12 107904 ----a-w- C:\Windows\System32\drivers\amdsata.sys
2011-03-11 06:34:51 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2011-03-11 06:34:50 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2011-03-11 06:33:29 2565632 ----a-w- C:\Windows\System32\esent.dll
2011-03-11 06:30:28 96768 ----a-w- C:\Windows\System32\fsutil.exe
2011-03-11 05:33:59 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-03-11 05:33:59 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
2011-03-11 05:33:09 1699328 ----a-w- C:\Windows\SysWow64\esent.dll
2011-03-11 05:31:07 74240 ----a-w- C:\Windows\SysWow64\fsutil.exe
2011-03-10 12:02:41 66872 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-03-08 06:29:32 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-03-08 05:28:29 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-03-07 06:31:44 1188864 ----a-w- C:\Windows\System32\wininet.dll_old0
2011-03-07 06:31:43 1491456 ----a-w- C:\Windows\System32\urlmon.dll_old0
2011-03-07 05:33:13 981504 ----a-w- C:\Windows\SysWow64\wininet.dll_old0
2011-03-07 05:33:10 1230336 ----a-w- C:\Windows\SysWow64\urlmon.dll_old0
2011-03-04 06:19:28 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2011-03-04 06:19:27 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2011-03-03 06:24:16 183296 ----a-w- C:\Windows\System32\dnsrslvr.dll
2011-03-03 06:21:57 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
2011-03-03 05:36:16 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
2011-03-03 03:52:08 3135488 ----a-w- C:\Windows\System32\win32k.sys
.
============= FINISH: 9:31:16.28 ===============
Hi,
Could you try to run ComboFix in normal mode, please?
I tried, didn't work i got the message:
"Windows cannot find 'C:\Users\Arafat\Desktop\Combofix.exe' Make sure you typed the name correctly, and then try again "
just tried again, no luck
Download GMER (http://www.gmer.net) here by clicking download exe -button and then saving it your desktop:
Double-click .exe that you downloaded
Click rootkit-tab, uncheck files option and then click scan.
Don't check
Show All
box while scanning in progress!
When scanning is ready, click Copy.
This copies log to clipboard
Post log (if the log is long, archive it into a zip file and attach instead of posting) in your reply.
I've been trying to run it in normal mode, it's the same message as the others.
Shall i run it in safe mode?
GMER 1.0.15.15627 - http://www.gmer.net
Rootkit scan 2011-05-26 22:41:30
Windows 6.1.7601 Service Pack 1
Running: km3i0lf4.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 D:\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x5A 0x6B 0x2F 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD3 0x79 0x67 0x4F ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x03 0x39 0x59 0xBE ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x66 0x1A 0xE6 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 D:\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x5A 0x6B 0x2F 0x80 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD3 0x79 0x67 0x4F ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x03 0x39 0x59 0xBE ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x66 0x1A 0xE6 0x02 ...
---- EOF - GMER 1.0.15 ----
* Go here (http://www.eset.eu/online-scanner) to run an online scanner from ESET.
Note: You will need to use Internet explorer for this scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activex control to install
Click Start
Make sure that the option Remove found threats is UNchecked.
Click Scan
Wait for the scan to finish.
Can't get Internet Explorer to run
Would it work if I used the ESET Smart Installer?
Hi,
Rename ComboFix.exe file -> anything.exe and see if you're able to run it in normal mode.
Can't get Internet Explorer to run
Any details how it failed (error message)?
Nope, no message what so ever. I wasn't sure if my internet explorer works at all since i'm a Chrome/Firefox user so i tried to see if it ran in Safemode. It didn't.
Renaming Combofix.exe to anything.exe doesn't work either. Same message a before
So, does Firefox work? If it does try to run ESET online scanner with it.
For any browser other than IE requires that i use the ESET Smart Installer. Should I use that?
No luck. The installer won't run in normal mode.
I can't run it in Safemode either as it requires that i be online so that it can download components to install on my computer.
Ugh, sorry I just realised I can get internet access in Safemode with Networking. Trying that now
C:\Users\Arafat\Desktop\Backup\New folder\autorun.inf INF/Autorun virus
Thats it... however that folder is really old. Hasn't been touched in months. It's a backup of a flash drive. Wouldn't it have shown up earlier?
Thats it... however that folder is really old. Hasn't been touched in months. It's a backup of a flash drive. Wouldn't it have shown up earlier?
Depends if the location was checked by other scanners (and if those had detection for it). Delete the folder and copy-paste fresh dds.txt & attach.txt contents.
.
DDS (Ver_11-05-19.01) - NTFSx86 MINIMAL
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Run by Arafat at 17:12:03 on 2011-05-31
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4094.3153 [GMT 3:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\DllHost.exe
C:\Users\Arafat\Desktop\New folder\Fixing\Merlin.com
C:\Windows\SysWOW64\WSCRIPT.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - D:\SPYBOT~1\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\TeaTimer.exe
uRun: [Google Update] "C:\Users\Arafat\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [TurboV EVO] "C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe" -b
mRun: [Adobe Reader Speed Launcher] "D:\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - D:\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - D:\MICROS~1\Office14\ONBttnIE.dll/105
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO-X64: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
mRun-x64: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
mRun-x64: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Arafat\AppData\Roaming\Mozilla\Firefox\Profiles\brjkibx7.default\
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Arafat\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: C:\Users\Arafat\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - plugin: D:\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
FF - plugin: D:\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: D:\Mozilla Firefox\plugins\NPDFusionWebFirefox.dll
FF - plugin: D:\VideoLAN\VLC\npvlc.dll
.
============= SERVICES / DRIVERS ===============
.
S2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-14 20992]
S2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
S2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.05\AsSysCtrlService.exe [2010-11-14 109056]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;D:\LogMeIn Hamachi\hamachi-2.exe [2011-3-28 2111368]
S2 KMService;KMService;C:\Windows\System32\srvany.exe [2011-1-6 8192]
S3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
S3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-1-21 30963576]
S3 nmwcdcx64;Nokia USB Generic;C:\Windows\system32\drivers\ccdcmbox64.sys --> C:\Windows\system32\drivers\ccdcmbox64.sys [?]
S3 nmwcdnsucx64;Nokia USB Flashing Generic;C:\Windows\system32\drivers\nmwcdnsucx64.sys --> C:\Windows\system32\drivers\nmwcdnsucx64.sys [?]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent;C:\Windows\system32\drivers\nmwcdnsux64.sys --> C:\Windows\system32\drivers\nmwcdnsux64.sys [?]
S3 nmwcdx64;Nokia USB Phone Parent;C:\Windows\system32\drivers\ccdcmbx64.sys --> C:\Windows\system32\drivers\ccdcmbx64.sys [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-05-28 21:32:27 8718160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EC413245-2ECA-44F6-9A48-6CC7820E687D}\mpengine.dll
2011-05-28 21:32:15 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2011-05-28 20:47:07 -------- d-----w- C:\Program Files (x86)\ESET
2011-05-28 18:42:48 -------- d-----w- C:\Users\Arafat\AppData\Roaming\go
2011-05-28 18:42:48 -------- d-----w- C:\ProgramData\Easybits GO
2011-05-28 12:48:28 -------- d-----w- C:\Users\Arafat\AppData\Local\{485CE004-7526-4F8A-AE0B-C876FC84B813}
2011-05-27 16:21:48 -------- d-----w- C:\Users\Arafat\AppData\Local\{AEBFA540-FC6F-4C10-80FE-84B5CFF5EF62}
2011-05-27 03:23:13 -------- d-----w- C:\Users\Arafat\AppData\Local\{4E47630D-DB24-40DC-93B0-C191FB825008}
2011-05-26 10:48:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{A98E9AAB-1B30-42EC-8938-AA77FB17DD03}
2011-05-26 06:26:27 8718160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-05-26 06:19:46 -------- d-sh--w- C:\$RECYCLE.BIN
2011-05-26 01:41:29 98816 ----a-w- C:\Windows\sed.exe
2011-05-26 01:41:29 89088 ----a-w- C:\Windows\MBR.exe
2011-05-26 01:41:29 256512 ----a-w- C:\Windows\PEV.exe
2011-05-26 01:41:29 161792 ----a-w- C:\Windows\SWREG.exe
2011-05-24 17:20:29 -------- d-----w- C:\Users\Arafat\AppData\Local\{F89D2A5B-1CEC-45DC-98CD-3B8C27C55EEE}
2011-05-23 17:20:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{4DE85A21-2AE4-47ED-BC23-4F1B47C9B7B2}
2011-05-22 14:50:15 -------- d-----w- C:\Users\Arafat\AppData\Local\{53869421-6B45-47B0-BAAE-AC1408A79C47}
2011-05-21 19:33:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{28E7D7E8-526F-4ADB-8181-667D33A61DFC}
2011-05-20 11:15:55 -------- d-----w- C:\Users\Arafat\AppData\Local\{56890F7F-2472-4A8F-A825-0DA532617CE6}
2011-05-19 19:36:48 -------- d-----w- C:\Users\Arafat\AppData\Local\{8C0B880F-FE73-42DE-9E92-B6446DDFEED8}
2011-05-19 07:22:39 -------- d-----w- C:\Users\Arafat\AppData\Local\{B9C6FE17-3E5D-445E-81FC-B36AC7E71BFD}
2011-05-17 17:00:55 -------- d-----w- C:\Users\Arafat\AppData\Local\{722E076A-2A84-4677-817F-9B07F571FAF7}
2011-05-16 19:38:31 -------- d-----w- C:\Windows\CheckSur
2011-05-16 13:33:11 -------- d-----w- C:\Users\Arafat\AppData\Local\{BDF4F900-0721-419A-8ED0-6523DC1EAE5B}
2011-05-15 19:35:45 -------- d-----w- C:\Users\Arafat\AppData\Local\{030EF9CD-9022-4E12-9DBB-B84C85271380}
2011-05-14 10:01:26 -------- d-----w- C:\Users\Arafat\AppData\Local\{45440B02-B680-4F0C-8383-77335D4A364D}
2011-05-13 12:22:47 -------- d-----w- C:\Users\Arafat\AppData\Local\{F1CA829F-9FBD-4126-B743-964971EFE397}
2011-05-13 00:22:01 -------- d-----w- C:\Users\Arafat\AppData\Local\{DBF4DA55-5321-4C54-BC10-064FB4195B9A}
2011-05-12 16:23:19 142336 ----a-w- C:\Windows\System32\poqexec.exe
2011-05-12 16:23:19 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2011-05-12 16:23:18 5562240 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-05-12 16:23:17 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-05-12 16:23:17 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-05-12 16:23:08 52736 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2011-05-12 16:23:07 98816 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2011-05-12 16:23:07 7936 ----a-w- C:\Windows\System32\drivers\usbd.sys
2011-05-12 16:23:07 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2011-05-12 16:23:07 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2011-05-12 16:23:07 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2011-05-12 16:23:07 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2011-05-12 12:21:26 -------- d-----w- C:\Users\Arafat\AppData\Local\{F406B812-45E2-4230-BA50-E83EF04489A8}
2011-05-11 12:00:13 -------- d-----w- C:\Users\Arafat\AppData\Local\{28908B83-A866-4881-A0DF-9D4B9725212C}
2011-05-10 19:56:05 -------- d-----w- C:\Users\Arafat\AppData\Local\{734B2427-E039-4411-8F79-E012EEBC64E2}
2011-05-10 14:40:59 -------- d-----w- C:\Users\Arafat\AppData\Local\{35249393-6A33-453D-953B-FABE876212B1}
2011-05-09 10:50:09 -------- d-----w- C:\Users\Arafat\AppData\Local\{75B41FDB-2E3E-4CFC-8BD1-317E811B15EE}
2011-05-08 14:05:17 -------- d-----w- C:\Users\Arafat\AppData\Local\{1634022F-82E0-4C38-89D3-F73F04AC2E67}
2011-05-07 23:03:35 -------- d-----w- C:\Users\Arafat\AppData\Local\{46675658-ABF9-40D2-9B55-95A46081EE73}
2011-05-07 11:03:01 -------- d-----w- C:\Users\Arafat\AppData\Local\{C674A4FC-A059-48FE-A0EC-3CBF6BE88701}
2011-05-06 22:25:11 -------- d-----w- C:\Users\Arafat\AppData\Local\{373DC4A2-95CD-4835-96E2-7EFEF26C78DD}
2011-05-05 00:10:00 -------- d-----w- C:\Users\Arafat\AppData\Local\{FD4D9AE6-5699-4411-AFCD-F33C725CD855}
2011-05-04 12:09:24 -------- d-----w- C:\Users\Arafat\AppData\Local\{A1534F8F-DF95-4875-9AE8-C5B9B3CB7EB5}
2011-05-03 18:09:09 -------- d-----w- C:\Users\Arafat\AppData\Local\{B8A096B0-ABB0-46A5-A046-6702D317EB29}
.
==================== Find3M ====================
.
2011-04-05 17:52:57 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-04-05 17:52:56 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-03-25 19:47:02 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2011-03-19 11:43:50 103736 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-03-12 12:08:49 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-03-12 11:23:45 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-03-11 06:41:37 189824 ----a-w- C:\Windows\System32\drivers\storport.sys
2011-03-11 06:41:34 166272 ----a-w- C:\Windows\System32\drivers\nvstor.sys
2011-03-11 06:41:34 1659776 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2011-03-11 06:41:34 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys
2011-03-11 06:41:26 410496 ----a-w- C:\Windows\System32\drivers\iaStorV.sys
2011-03-11 06:41:12 27008 ----a-w- C:\Windows\System32\drivers\amdxata.sys
2011-03-11 06:41:12 107904 ----a-w- C:\Windows\System32\drivers\amdsata.sys
2011-03-11 06:34:51 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2011-03-11 06:34:50 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2011-03-11 06:33:29 2565632 ----a-w- C:\Windows\System32\esent.dll
2011-03-11 06:30:28 96768 ----a-w- C:\Windows\System32\fsutil.exe
2011-03-11 05:33:59 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-03-11 05:33:59 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
2011-03-11 05:33:09 1699328 ----a-w- C:\Windows\SysWow64\esent.dll
2011-03-11 05:31:07 74240 ----a-w- C:\Windows\SysWow64\fsutil.exe
2011-03-10 12:02:41 66872 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-03-08 06:29:32 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-03-08 05:28:29 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-03-07 06:31:44 1188864 ----a-w- C:\Windows\System32\wininet.dll_old0
2011-03-07 06:31:43 1491456 ----a-w- C:\Windows\System32\urlmon.dll_old0
2011-03-07 05:33:13 981504 ----a-w- C:\Windows\SysWow64\wininet.dll_old0
2011-03-07 05:33:10 1230336 ----a-w- C:\Windows\SysWow64\urlmon.dll_old0
2011-03-04 06:19:28 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2011-03-04 06:19:27 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2011-03-03 06:24:16 183296 ----a-w- C:\Windows\System32\dnsrslvr.dll
2011-03-03 06:21:57 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
2011-03-03 05:36:16 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
2011-03-03 03:52:08 3135488 ----a-w- C:\Windows\System32\win32k.sys
.
============= FINISH: 17:12:59.30 ===============
Hi,
You probably have to do the following in safe mode.
Open notepad and then copy and paste the codebox lines below into it. Go to File > save as and name the file fixes.bat, change the Save as type to all files and save it to your desktop.
@ECHO OFF
regedit /e "%userprofile%\desktop\exported.txt" "HKEY_LOCAL_MACHINE\Software\CLASSES\exefile\shell\open\command"
del %0
Double-click on fixes.bat file to execute it. exported.txt file should appear to your desktop. Attach it to your post, please.
Ran it in safemode, didn't work in normal mode. Here's the exported.txt file
Sorry the replies have been a bit late. I've had midterms all week and finals in 2
Nevertheless i appreciate your efforts.
Hi,
1. Download TDSSKiller (http://support.kaspersky.com/downloads/utils/tdsskiller.zip) and extract its contents into a folder in desired location (i.e. c:\tdsskiller).
2. Execute the file TDSSKiller.exe and wait for the process to finish.
3. Post back contents of log file in c: drive root (name should be in UtilityName.Version_Date_Time_log.txt format)
2011/06/02 18:41:26.0698 1048 TDSS rootkit removing tool 2.5.3.0 May 25 2011 07:09:24
2011/06/02 18:41:27.0072 1048 ================================================================================
2011/06/02 18:41:27.0072 1048 SystemInfo:
2011/06/02 18:41:27.0072 1048
2011/06/02 18:41:27.0072 1048 OS Version: 6.1.7601 ServicePack: 1.0
2011/06/02 18:41:27.0072 1048 Product type: Workstation
2011/06/02 18:41:27.0072 1048 ComputerName: ALTAIR
2011/06/02 18:41:27.0072 1048 UserName: Arafat
2011/06/02 18:41:27.0072 1048 Windows directory: C:\Windows
2011/06/02 18:41:27.0072 1048 System windows directory: C:\Windows
2011/06/02 18:41:27.0072 1048 Running under WOW64
2011/06/02 18:41:27.0072 1048 Processor architecture: Intel x64
2011/06/02 18:41:27.0072 1048 Number of processors: 4
2011/06/02 18:41:27.0072 1048 Page size: 0x1000
2011/06/02 18:41:27.0072 1048 Boot type: Safe boot with network
2011/06/02 18:41:27.0072 1048 ================================================================================
2011/06/02 18:41:29.0240 1048 Initialize success
2011/06/02 18:41:56.0926 2248 ================================================================================
2011/06/02 18:41:56.0926 2248 Scan started
2011/06/02 18:41:56.0926 2248 Mode: Manual;
2011/06/02 18:41:56.0926 2248 ================================================================================
2011/06/02 18:41:59.0857 2248 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
2011/06/02 18:41:59.0896 2248 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
2011/06/02 18:41:59.0948 2248 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
2011/06/02 18:41:59.0989 2248 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/06/02 18:42:00.0026 2248 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
2011/06/02 18:42:00.0053 2248 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
2011/06/02 18:42:00.0123 2248 AFD (d31dc7a16dea4a9baf179f3d6fbdb38c) C:\Windows\system32\drivers\afd.sys
2011/06/02 18:42:00.0159 2248 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
2011/06/02 18:42:00.0211 2248 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
2011/06/02 18:42:00.0376 2248 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
2011/06/02 18:42:00.0397 2248 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
2011/06/02 18:42:00.0555 2248 amdkmdag (dcc8177244fe79c61c4e73c65e63922a) C:\Windows\system32\DRIVERS\atikmdag.sys
2011/06/02 18:42:00.0697 2248 amdkmdap (7fe67d107329dc2cf89136a8e19bceb7) C:\Windows\system32\DRIVERS\atikmpag.sys
2011/06/02 18:42:00.0708 2248 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
2011/06/02 18:42:00.0744 2248 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
2011/06/02 18:42:00.0775 2248 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/06/02 18:42:00.0921 2248 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
2011/06/02 18:42:00.0966 2248 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
2011/06/02 18:42:01.0000 2248 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
2011/06/02 18:42:01.0011 2248 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
2011/06/02 18:42:01.0090 2248 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/06/02 18:42:01.0104 2248 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
2011/06/02 18:42:01.0170 2248 AtiHDAudioService (4bf5bca6e2608cd8a00bc4a6673a9f47) C:\Windows\system32\drivers\AtihdW76.sys
2011/06/02 18:42:01.0201 2248 AtiHdmiService (7e2f5a758f63f80f8b03f889b4e6b19f) C:\Windows\system32\drivers\AtiHdmi.sys
2011/06/02 18:42:01.0240 2248 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
2011/06/02 18:42:01.0274 2248 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
2011/06/02 18:42:01.0297 2248 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
2011/06/02 18:42:01.0345 2248 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/06/02 18:42:01.0387 2248 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
2011/06/02 18:42:01.0409 2248 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/06/02 18:42:01.0418 2248 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/06/02 18:42:01.0446 2248 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
2011/06/02 18:42:01.0457 2248 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/06/02 18:42:01.0468 2248 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/06/02 18:42:01.0479 2248 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/06/02 18:42:01.0500 2248 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/06/02 18:42:01.0558 2248 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/06/02 18:42:01.0596 2248 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
2011/06/02 18:42:01.0609 2248 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
2011/06/02 18:42:01.0651 2248 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
2011/06/02 18:42:01.0687 2248 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/06/02 18:42:01.0707 2248 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
2011/06/02 18:42:01.0749 2248 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
2011/06/02 18:42:01.0774 2248 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
2011/06/02 18:42:01.0819 2248 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
2011/06/02 18:42:01.0842 2248 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/06/02 18:42:01.0889 2248 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys
2011/06/02 18:42:01.0992 2248 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
2011/06/02 18:42:02.0012 2248 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
2011/06/02 18:42:02.0117 2248 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
2011/06/02 18:42:02.0198 2248 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
2011/06/02 18:42:02.0244 2248 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
2011/06/02 18:42:02.0308 2248 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
2011/06/02 18:42:02.0394 2248 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
2011/06/02 18:42:02.0415 2248 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
2011/06/02 18:42:02.0447 2248 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
2011/06/02 18:42:02.0466 2248 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
2011/06/02 18:42:02.0501 2248 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
2011/06/02 18:42:02.0557 2248 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
2011/06/02 18:42:02.0578 2248 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
2011/06/02 18:42:02.0587 2248 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/06/02 18:42:02.0652 2248 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
2011/06/02 18:42:02.0681 2248 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
2011/06/02 18:42:02.0708 2248 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
2011/06/02 18:42:02.0761 2248 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
2011/06/02 18:42:02.0787 2248 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/06/02 18:42:02.0822 2248 hamachi (1e6438d4ea6e1174a3b3b1edc4de660b) C:\Windows\system32\DRIVERS\hamachi.sys
2011/06/02 18:42:02.0834 2248 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
2011/06/02 18:42:02.0891 2248 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
2011/06/02 18:42:02.0913 2248 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
2011/06/02 18:42:02.0934 2248 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/06/02 18:42:02.0946 2248 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
2011/06/02 18:42:02.0957 2248 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
2011/06/02 18:42:02.0994 2248 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
2011/06/02 18:42:03.0027 2248 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
2011/06/02 18:42:03.0081 2248 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
2011/06/02 18:42:03.0121 2248 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
2011/06/02 18:42:03.0143 2248 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
2011/06/02 18:42:03.0184 2248 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
2011/06/02 18:42:03.0206 2248 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
2011/06/02 18:42:03.0253 2248 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
2011/06/02 18:42:03.0270 2248 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
2011/06/02 18:42:03.0312 2248 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/06/02 18:42:03.0332 2248 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
2011/06/02 18:42:03.0353 2248 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
2011/06/02 18:42:03.0373 2248 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
2011/06/02 18:42:03.0399 2248 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
2011/06/02 18:42:03.0421 2248 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
2011/06/02 18:42:03.0470 2248 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
2011/06/02 18:42:03.0484 2248 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
2011/06/02 18:42:03.0557 2248 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
2011/06/02 18:42:03.0595 2248 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
2011/06/02 18:42:03.0627 2248 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
2011/06/02 18:42:03.0700 2248 LHidFilt (24e09882ba51b9830ae029888a3aaf18) C:\Windows\system32\DRIVERS\LHidFilt.Sys
2011/06/02 18:42:03.0714 2248 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
2011/06/02 18:42:03.0761 2248 LMouFilt (2f94325d8c10e2b715f3d753c2422aac) C:\Windows\system32\DRIVERS\LMouFilt.Sys
2011/06/02 18:42:03.0786 2248 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/06/02 18:42:03.0825 2248 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/06/02 18:42:03.0839 2248 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/06/02 18:42:03.0863 2248 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/06/02 18:42:03.0888 2248 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
2011/06/02 18:42:03.0923 2248 LUsbFilt (b8be35421b9e8dc1ab4b0cb7b9b0328b) C:\Windows\system32\Drivers\LUsbFilt.Sys
2011/06/02 18:42:03.0957 2248 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
2011/06/02 18:42:03.0979 2248 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/06/02 18:42:04.0031 2248 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
2011/06/02 18:42:04.0074 2248 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
2011/06/02 18:42:04.0093 2248 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\drivers\mouclass.sys
2011/06/02 18:42:04.0112 2248 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
2011/06/02 18:42:04.0152 2248 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
2011/06/02 18:42:04.0194 2248 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
2011/06/02 18:42:04.0220 2248 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
2011/06/02 18:42:04.0257 2248 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
2011/06/02 18:42:04.0293 2248 mrxsmb (c2b4651001a867ff3f8865863b592991) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/06/02 18:42:04.0346 2248 mrxsmb10 (7e79946afc5f799ab62982282be5ac13) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/06/02 18:42:04.0387 2248 mrxsmb20 (5fb954100cea2bfec6446fbbecaa3f79) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/06/02 18:42:04.0436 2248 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
2011/06/02 18:42:04.0479 2248 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
2011/06/02 18:42:04.0770 2248 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
2011/06/02 18:42:04.0788 2248 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
2011/06/02 18:42:04.0818 2248 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
2011/06/02 18:42:04.0852 2248 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
2011/06/02 18:42:04.0882 2248 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/06/02 18:42:04.0972 2248 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
2011/06/02 18:42:05.0017 2248 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
2011/06/02 18:42:05.0046 2248 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
2011/06/02 18:42:05.0072 2248 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
2011/06/02 18:42:05.0092 2248 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/06/02 18:42:05.0127 2248 MTsensor (19b006b181e3875fd254f7b67acf1e7c) C:\Windows\system32\DRIVERS\ASACPI.sys
2011/06/02 18:42:05.0149 2248 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
2011/06/02 18:42:05.0348 2248 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
2011/06/02 18:42:05.0508 2248 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
2011/06/02 18:42:05.0541 2248 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/06/02 18:42:05.0611 2248 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/06/02 18:42:05.0649 2248 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/06/02 18:42:05.0679 2248 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/06/02 18:42:05.0707 2248 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
2011/06/02 18:42:05.0739 2248 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
2011/06/02 18:42:05.0764 2248 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
2011/06/02 18:42:05.0829 2248 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/06/02 18:42:05.0886 2248 nmwcdcx64 (2c761cc067acf0fb4ea13930b09bfeea) C:\Windows\system32\drivers\ccdcmbox64.sys
2011/06/02 18:42:05.0917 2248 nmwcdnsucx64 (ce90d1dd60db810a45e13fccea47e890) C:\Windows\system32\drivers\nmwcdnsucx64.sys
2011/06/02 18:42:05.0950 2248 nmwcdnsux64 (f5a8219ea8a6b67280308fae169b65c0) C:\Windows\system32\drivers\nmwcdnsux64.sys
2011/06/02 18:42:05.0976 2248 nmwcdx64 (63051819d5cac0fa49c425fc5e1a2b5c) C:\Windows\system32\drivers\ccdcmbx64.sys
2011/06/02 18:42:06.0016 2248 NPF (351533acc2a069b94e80bbfc177e8fdf) C:\Windows\system32\drivers\npf.sys
2011/06/02 18:42:06.0040 2248 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
2011/06/02 18:42:06.0076 2248 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
2011/06/02 18:42:06.0130 2248 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
2011/06/02 18:42:06.0177 2248 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
2011/06/02 18:42:06.0218 2248 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
2011/06/02 18:42:06.0250 2248 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
2011/06/02 18:42:06.0281 2248 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
2011/06/02 18:42:06.0318 2248 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
2011/06/02 18:42:06.0354 2248 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
2011/06/02 18:42:06.0396 2248 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
2011/06/02 18:42:06.0446 2248 pccsmcfd (bc0018c2d29f655188a0ed3fa94fdb24) C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
2011/06/02 18:42:06.0480 2248 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
2011/06/02 18:42:06.0506 2248 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
2011/06/02 18:42:06.0517 2248 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/06/02 18:42:06.0577 2248 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
2011/06/02 18:42:06.0606 2248 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
2011/06/02 18:42:06.0759 2248 Point64 (b8d8ec78b0f9ed8e220506181274f3d3) C:\Windows\system32\DRIVERS\point64.sys
2011/06/02 18:42:06.0819 2248 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
2011/06/02 18:42:06.0829 2248 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
2011/06/02 18:42:06.0877 2248 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
2011/06/02 18:42:06.0918 2248 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
2011/06/02 18:42:06.0957 2248 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/06/02 18:42:06.0979 2248 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
2011/06/02 18:42:07.0013 2248 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
2011/06/02 18:42:07.0031 2248 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/06/02 18:42:07.0074 2248 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/06/02 18:42:07.0092 2248 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/06/02 18:42:07.0102 2248 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
2011/06/02 18:42:07.0157 2248 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
2011/06/02 18:42:07.0187 2248 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/06/02 18:42:07.0198 2248 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/06/02 18:42:07.0237 2248 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys
2011/06/02 18:42:07.0262 2248 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
2011/06/02 18:42:07.0276 2248 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
2011/06/02 18:42:07.0331 2248 RdpVideoMiniport (70cba1a0c98600a2aa1863479b35cb90) C:\Windows\system32\drivers\rdpvideominiport.sys
2011/06/02 18:42:07.0357 2248 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
2011/06/02 18:42:07.0392 2248 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
2011/06/02 18:42:07.0458 2248 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
2011/06/02 18:42:07.0510 2248 RTL8167 (4fe1cef69d36e913738234303986fbb3) C:\Windows\system32\DRIVERS\Rt64win7.sys
2011/06/02 18:42:07.0547 2248 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys
2011/06/02 18:42:07.0591 2248 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
2011/06/02 18:42:07.0655 2248 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
2011/06/02 18:42:07.0708 2248 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2011/06/02 18:42:07.0729 2248 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
2011/06/02 18:42:07.0756 2248 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
2011/06/02 18:42:07.0795 2248 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
2011/06/02 18:42:07.0877 2248 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
2011/06/02 18:42:07.0892 2248 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
2011/06/02 18:42:07.0909 2248 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
2011/06/02 18:42:07.0933 2248 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/06/02 18:42:07.0962 2248 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/06/02 18:42:07.0983 2248 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/06/02 18:42:08.0012 2248 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
2011/06/02 18:42:08.0031 2248 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
2011/06/02 18:42:08.0112 2248 sptd (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys
2011/06/02 18:42:08.0152 2248 srv (65bbf4920148c2ee279055da7228fc7b) C:\Windows\system32\DRIVERS\srv.sys
2011/06/02 18:42:08.0172 2248 srv2 (da939f762a1ccc2d77428621ddbd40a7) C:\Windows\system32\DRIVERS\srv2.sys
2011/06/02 18:42:08.0193 2248 srvnet (3f847c9dc87299516f7dc82fb6572865) C:\Windows\system32\DRIVERS\srvnet.sys
2011/06/02 18:42:08.0215 2248 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
2011/06/02 18:42:08.0256 2248 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys
2011/06/02 18:42:08.0294 2248 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys
2011/06/02 18:42:08.0341 2248 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
2011/06/02 18:42:08.0434 2248 Tcpip (509383e505c973ed7534a06b3d19688d) C:\Windows\system32\drivers\tcpip.sys
2011/06/02 18:42:08.0491 2248 TCPIP6 (509383e505c973ed7534a06b3d19688d) C:\Windows\system32\DRIVERS\tcpip.sys
2011/06/02 18:42:08.0533 2248 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
2011/06/02 18:42:08.0562 2248 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
2011/06/02 18:42:08.0581 2248 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
2011/06/02 18:42:08.0618 2248 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
2011/06/02 18:42:08.0632 2248 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
2011/06/02 18:42:08.0676 2248 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/06/02 18:42:08.0694 2248 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
2011/06/02 18:42:08.0760 2248 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
2011/06/02 18:42:08.0777 2248 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
2011/06/02 18:42:08.0805 2248 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
2011/06/02 18:42:08.0849 2248 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
2011/06/02 18:42:08.0871 2248 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
2011/06/02 18:42:08.0883 2248 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
2011/06/02 18:42:08.0943 2248 upperdev (bcd611d240604ceee7f90805361fab50) C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
2011/06/02 18:42:08.0979 2248 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/06/02 18:42:09.0026 2248 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
2011/06/02 18:42:09.0036 2248 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
2011/06/02 18:42:09.0090 2248 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
2011/06/02 18:42:09.0124 2248 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
2011/06/02 18:42:09.0148 2248 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
2011/06/02 18:42:09.0204 2248 usbser (4acee387fa8fd39f83564fcd2fc234f2) C:\Windows\system32\drivers\usbser.sys
2011/06/02 18:42:09.0252 2248 UsbserFilt (d91be2644b18b4e3c69982fe0e1e97d6) C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys
2011/06/02 18:42:09.0287 2248 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/06/02 18:42:09.0333 2248 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
2011/06/02 18:42:09.0369 2248 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
2011/06/02 18:42:09.0397 2248 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
2011/06/02 18:42:09.0415 2248 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/06/02 18:42:09.0441 2248 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
2011/06/02 18:42:09.0520 2248 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
2011/06/02 18:42:09.0538 2248 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
2011/06/02 18:42:09.0591 2248 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys
2011/06/02 18:42:09.0624 2248 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys
2011/06/02 18:42:09.0643 2248 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
2011/06/02 18:42:09.0674 2248 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
2011/06/02 18:42:09.0720 2248 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
2011/06/02 18:42:09.0760 2248 vpcbus (f004aeb456cd886dfdb123b6297d89c9) C:\Windows\system32\DRIVERS\vpchbus.sys
2011/06/02 18:42:09.0782 2248 vpcnfltr (a7fae0a70e7a6d7a9469a2bf0a1cac5f) C:\Windows\system32\DRIVERS\vpcnfltr.sys
2011/06/02 18:42:09.0812 2248 vpcusb (4cdf15ceaf71f068bd26b9841d4e3e2b) C:\Windows\system32\DRIVERS\vpcusb.sys
2011/06/02 18:42:09.0833 2248 vpcvmm (e7ea9e3fbf1b0f517584e03638511e86) C:\Windows\system32\drivers\vpcvmm.sys
2011/06/02 18:42:09.0851 2248 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/06/02 18:42:09.0878 2248 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
2011/06/02 18:42:09.0906 2248 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
2011/06/02 18:42:09.0933 2248 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
2011/06/02 18:42:09.0941 2248 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
2011/06/02 18:42:09.0978 2248 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
2011/06/02 18:42:10.0011 2248 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
2011/06/02 18:42:10.0069 2248 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/06/02 18:42:10.0091 2248 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
2011/06/02 18:42:10.0186 2248 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
2011/06/02 18:42:10.0222 2248 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
2011/06/02 18:42:10.0282 2248 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
2011/06/02 18:42:10.0311 2248 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/06/02 18:42:10.0377 2248 xnacc (4a5ce13408945e525503b5f73d29b9c5) C:\Windows\system32\DRIVERS\xnacc.sys
2011/06/02 18:42:10.0419 2248 xusb21 (2ee48cfce7ca8e0db4c44c7476c0943b) C:\Windows\system32\DRIVERS\xusb21.sys
2011/06/02 18:42:10.0457 2248 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
2011/06/02 18:42:10.0466 2248 ================================================================================
2011/06/02 18:42:10.0466 2248 Scan finished
2011/06/02 18:42:10.0466 2248 ================================================================================
2011/06/02 18:42:10.0485 2240 Detected object count: 0
2011/06/02 18:42:10.0485 2240 Actual detected object count: 0
Hi,
Rename ComboFix.exe file -> exPLorer.exe and see if you're able to run it in normal mode.
Hi,
Could you create a new user account to see if programs can be run in normal mode with it?
Open notepad and then copy and paste the codebox lines below into it. Go to File > save as and name the file fixes.bat, change the Save as type to all files and save it to your desktop.
@ECHO OFF
regedit /e "%userprofile%\desktop\exported.txt" "HKEY_CLASSES_ROOT\exefile\shell\open\command"
del %0
Double-click on fixes.bat file to execute it. exported.txt file should appear to your desktop. Attach it to your post, please.
Hi,
Let's see if you have available a restore point for a date before problems popped up first time.
1. Click start.
2. In the search box, type System Restore, and then, in the list of results, click System Restore. If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
3. Follow the steps in the wizard to choose a restore point (date before problems appeared) and restore your computer.
I don't seem to have any restore points before the 26th of May 2011.
I started this thread on the 18th of May
Hi,
Reboot the system, press F8 and select "Repair your computer" option there. On the System Recovery Options menu, click "Startup Repair".
Will i lose all data? documents project files etc?
Tried it.
Says that no errors were found. Tried doing a startup repair three times. Nothing
Then I see no other option than recommend to backup your important data and reformat. Nothing in those logs gave any sign of infection.
Hmm, I've already prepped for that. I'll just have to format one partition. All my files and installed software are on the others.
Thank you for all your efforts. I appreciate it