Louiscypher100
2011-09-03, 20:27
Hello,
The malware on my computer has been giving me run errors since I've been tryhing to remove it.
I thought I could learn to remove it my self but it is beyond me at this point in my education.
Here is the DDS: and the attached "Attach.txt" report.
Any help would be greatly appreciated and sacrifices of choclate will be givein to the Diety of you choice.
Regards, LouisCypher
Your personal Facilitator
:cowboy:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Bobo at 10:30:02 on 2011-09-03
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.993 [GMT -7:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
BHO: AutorunsDisabled - No File
BHO: {16fbc17a-9fb3-4b4d-824e-b965cf45bf3d} - c:\windows\system32\dimsntf.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - No File
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: com\www.msi
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.254 199.185.220.254
TCP: Interfaces\{D9D2E454-23FB-47B9-8D6F-E00E8520D99C} : DhcpNameServer = 192.168.1.254 199.185.220.254
Handler: AutorunsDisabled\grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
.
============= SERVICES / DRIVERS ===============
.
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-8-23 2255464]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 FLASHSYS;FLASHSYS; [x]
S3 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-10 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-10 136176]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; [x]
S3 MSI_DVD_010507;MSI_DVD_010507;c:\progra~1\msi\msiwdev\DVDSYS32_100507.sys [2010-5-10 22328]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\progra~1\msi\msiwdev\msibios32_100507.sys [2010-5-10 25912]
S3 MSI_VGASYS_010507;MSI_VGASYS_010507;c:\progra~1\msi\msiwdev\VGASYS32_100507.sys [2010-5-10 16696]
S3 Vsp;Vsp;c:\windows\system32\drivers\vsp.sys [2010-8-22 3351]
.
=============== Created Last 30 ================
.
2011-09-03 01:43:09 -------- d-----w- c:\windows\system32\NtmsData
2011-09-03 00:59:57 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-09-03 00:59:57 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
2011-09-02 23:54:19 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-09-02 23:51:59 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-09-02 23:51:59 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-09-02 23:51:59 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-09-02 23:51:59 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-09-02 23:51:59 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-09-02 23:51:59 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-09-02 23:51:59 11081728 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-09-02 23:51:58 -------- d-----w- C:\otherrecycler
2011-09-02 23:21:17 2321288 ----a-w- c:\documents and settings\all users\application data\microsoft\windows defender\definition updates\backup\mpengine.dll
2011-09-02 23:21:11 7152464 ----a-w- c:\documents and settings\all users\application data\microsoft\windows defender\definition updates\{2a0b44f2-2835-437b-8b15-9231086176db}\mpengine.dll
2011-09-02 23:21:11 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-09-02 22:47:10 -------- d-sha-r- C:\cmdcons
2011-09-02 22:45:45 256000 ----a-w- c:\windows\PEV.exe
2011-09-02 22:37:04 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-09-02 22:37:01 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-09-02 22:37:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-09-02 22:32:23 -------- d-----w- C:\ERDNT
2011-09-02 22:32:03 1445888 ----a-w- C:\WinsockxpFix.exe
2011-09-02 22:29:42 2560 ----a-w- c:\documents and settings\all users\application data\microsoft\usmt\iconlib.dll
2011-09-02 22:24:45 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-09-02 22:24:45 -------- d-----w- c:\windows\system32\wbem\Repository
2011-09-02 21:58:45 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-09-02 16:56:01 -------- d-sh--w- c:\documents and settings\bobo\IECompatCache
2011-09-02 16:54:53 -------- d-sh--w- c:\documents and settings\bobo\PrivacIE
2011-09-02 16:42:20 -------- d---a-w- C:\cmdcons(2)
2011-09-02 16:03:34 -------- d-----w- c:\windows\system32\CatRoot2
2011-09-02 15:55:44 446464 ----a-w- C:\TFC.exe
2011-09-02 15:43:07 4192529 ----a-w- C:\ComboFix.exe
2011-09-02 15:41:09 139264 ----a-w- C:\RKUnhookerLE.EXE
2011-09-02 15:40:22 50477 ----a-w- C:\Defogger.exe
2011-09-02 13:49:56 98816 ----a-w- c:\windows\sed.exe
2011-09-02 13:49:56 518144 ----a-w- c:\windows\SWREG.exe
2011-09-02 13:49:56 208896 ----a-w- c:\windows\MBR.exe
2011-09-02 04:43:27 29959 ----a-w- c:\windows\system\regsv32a.exe
2011-09-01 09:40:13 4194304 ----a-w- c:\windows\system32\embpmffm.dll
2011-09-01 05:12:15 -------- d-----w- c:\program files\Emsisoft HiJackFree
2011-09-01 05:02:37 709896 ----a-w- c:\program files\mozilla firefox\fakeavremover\tmufeng.dll
2011-09-01 05:02:37 537864 ----a-w- c:\program files\mozilla firefox\fakeavremover\tmfbeng.dll
2011-09-01 05:02:31 2433672 ----a-w- c:\program files\mozilla firefox\fakeavremover\svchost.exe
2011-09-01 05:01:06 15360 ----a-w- c:\windows\system32\ctfmon.exe.backup
2011-08-31 23:29:32 0 ----a-w- c:\windows\virus.bin
2011-08-31 23:28:04 -------- d-----w- c:\program files\Yontoo Layers Runtime
2011-08-31 23:27:41 121856 ----a-w- c:\windows\system32\dimsntf.dll
2011-08-27 23:15:52 69376 ----a-w- c:\windows\system32\drivers\usbhub20.sys
2011-08-27 23:09:18 10264 ----a-w- c:\windows\system32\Viagart.sys
2011-08-27 23:01:49 203776 ----a-w- c:\windows\system32\drivers\vinyl97.sys
2011-08-27 23:01:08 19968 ----a-w- c:\windows\Logi_MwX.Exe
2011-08-27 23:01:07 73576 ----a-w- c:\windows\system32\drivers\LMouFlt2.Sys
2011-08-27 23:01:07 26104 ----a-w- c:\windows\system32\drivers\LHidFlt2.Sys
2011-08-27 22:57:01 -------- d-----w- c:\documents and settings\all users\Uniblue
2011-08-27 22:31:02 73728 ----a-w- c:\windows\system32\fdeploy.dll
2011-08-27 22:31:02 566784 ----a-w- c:\windows\system32\gpedit.dll
2011-08-27 22:31:02 199680 ----a-w- c:\windows\system32\gptext.dll
2011-08-27 22:31:02 124928 ----a-w- c:\windows\system32\fde.dll
2011-08-27 22:31:02 -------- d--h--w- c:\windows\system32\GroupPolicy
2011-08-27 22:28:18 295936 ----a-w- c:\windows\system32\appmgr.dll
2011-08-27 22:28:18 167936 ----a-w- c:\windows\system32\appmgmts.dll
2011-08-23 15:28:48 -------- d-----w- c:\documents and settings\all users\application data\NVIDIA Corporation
2011-08-23 15:28:38 146024 ----a-w- c:\windows\system32\nvsvc32.exe
2011-08-23 15:28:38 145000 ----a-w- c:\windows\system32\nvcolor.exe
2011-08-23 15:28:37 54272 ----a-w- c:\windows\system32\nvwddi.dll
2011-08-23 15:28:37 13892200 ----a-w- c:\windows\system32\nvcpl.dll
2011-08-23 15:28:37 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-08-23 15:28:34 281440 ----a-w- c:\windows\system32\nvdrsdb1.bin
2011-08-23 15:28:34 281440 ----a-w- c:\windows\system32\nvdrsdb0.bin
2011-08-23 15:28:34 1 ----a-w- c:\windows\system32\nvdrssel.bin
2011-08-22 20:37:51 5427200 ----a-w- c:\windows\system32\nvcuda.dll
2011-08-22 20:37:51 2387560 ----a-w- c:\windows\system32\nvcuvid.dll
2011-08-22 20:37:51 2090088 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-08-22 20:37:51 17186816 ----a-w- c:\windows\system32\nvcompiler.dll
2011-08-22 20:37:51 16191488 ----a-w- c:\windows\system32\nvoglnt.dll
2011-08-22 20:31:02 -------- d-----w- c:\program files\SystemRequirementsLab
2011-08-18 16:51:50 -------- d-----w- c:\program files\Eusing Free Registry Cleaner
2011-08-17 17:08:43 -------- d-----r- c:\program files\Skype
2011-08-16 14:20:32 4892320 ----a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
2011-08-11 03:46:13 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-11 03:45:56 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2011-08-10 17:54:35 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-10 17:37:32 -------- d-----w- c:\documents and settings\bobo\local settings\application data\Solid State Networks
2011-08-10 03:11:49 974848 ----a-w- c:\windows\system32\mfc70.dll
2011-08-10 03:11:49 487424 ----a-w- c:\windows\system32\msvcp70.dll
2011-08-10 03:11:49 344064 ----a-w- c:\windows\system32\msvcr70.dll
2011-08-10 03:11:49 -------- d-----w- c:\program files\AML Products
2011-08-10 02:58:13 -------- d-----w- c:\documents and settings\all users\application data\Autorun Eater
2011-08-10 01:39:07 -------- d-----w- c:\program files\InCode Solutions
2011-08-09 02:28:35 -------- d-----w- c:\program files\Everything
2011-08-09 02:22:22 -------- d-----w- c:\windows\SxsCaPendDel
2011-08-07 17:19:36 -------- d-----w- c:\documents and settings\all users\application data\Arovax
.
==================== Find3M ====================
.
2011-09-02 15:00:25 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2011-09-01 05:01:06 24064 ----a-w- c:\windows\system32\ctfmon.exe
2011-08-27 23:14:51 69632 ----a-w- c:\windows\system32\vuins32.dll
2011-08-27 23:14:51 46592 ----a-w- c:\windows\system32\drivers\fetnd5bv.sys
2011-08-27 23:14:51 319456 ----a-w- c:\windows\system32\difxapi.dll
2011-08-27 23:09:11 117248 ----a-w- c:\windows\system32\drivers\viamraid.sys
2011-08-27 23:09:02 13976 ----a-w- c:\windows\system32\drivers\videX32.sys
2011-08-03 11:49:00 61440 ----a-w- c:\windows\system32\OpenCL.dll
2011-08-03 11:49:00 4210816 ----a-w- c:\windows\system32\nv4_disp.dll
2011-08-03 11:49:00 2404864 ----a-w- c:\windows\system32\nvapi.dll
2011-08-03 11:49:00 12542592 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-07-15 13:29:31 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10:36 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36:30 916480 ----a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36:30 43520 ------w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36:30 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05:13 385024 ----a-w- c:\windows\system32\html.iec
2011-06-21 18:18:34 667136 ----a-w- c:\windows\system32\wininet(5).dll
2011-06-21 18:18:34 667136 ----a-w- c:\windows\system32\wininet(4).dll
2011-06-21 18:18:34 633344 ----a-w- c:\windows\system32\urlmon(5).dll
2011-06-21 18:18:34 633344 ----a-w- c:\windows\system32\urlmon(4).dll
2011-06-21 18:18:34 449536 ----a-w- c:\windows\system32\mshtmled(2).dll
2011-06-21 18:18:34 37888 ----a-w- c:\windows\system32\url(3).dll
2011-06-20 17:44:52 293376 ----a-w- c:\windows\system32\winsrv.dll
.
============= FINISH: 10:30:13.57 ===============
The malware on my computer has been giving me run errors since I've been tryhing to remove it.
I thought I could learn to remove it my self but it is beyond me at this point in my education.
Here is the DDS: and the attached "Attach.txt" report.
Any help would be greatly appreciated and sacrifices of choclate will be givein to the Diety of you choice.
Regards, LouisCypher
Your personal Facilitator
:cowboy:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Bobo at 10:30:02 on 2011-09-03
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.993 [GMT -7:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
BHO: AutorunsDisabled - No File
BHO: {16fbc17a-9fb3-4b4d-824e-b965cf45bf3d} - c:\windows\system32\dimsntf.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - No File
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: com\www.msi
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.254 199.185.220.254
TCP: Interfaces\{D9D2E454-23FB-47B9-8D6F-E00E8520D99C} : DhcpNameServer = 192.168.1.254 199.185.220.254
Handler: AutorunsDisabled\grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
.
============= SERVICES / DRIVERS ===============
.
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-8-23 2255464]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 FLASHSYS;FLASHSYS; [x]
S3 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-10 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-10 136176]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; [x]
S3 MSI_DVD_010507;MSI_DVD_010507;c:\progra~1\msi\msiwdev\DVDSYS32_100507.sys [2010-5-10 22328]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\progra~1\msi\msiwdev\msibios32_100507.sys [2010-5-10 25912]
S3 MSI_VGASYS_010507;MSI_VGASYS_010507;c:\progra~1\msi\msiwdev\VGASYS32_100507.sys [2010-5-10 16696]
S3 Vsp;Vsp;c:\windows\system32\drivers\vsp.sys [2010-8-22 3351]
.
=============== Created Last 30 ================
.
2011-09-03 01:43:09 -------- d-----w- c:\windows\system32\NtmsData
2011-09-03 00:59:57 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-09-03 00:59:57 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
2011-09-02 23:54:19 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-09-02 23:51:59 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-09-02 23:51:59 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-09-02 23:51:59 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-09-02 23:51:59 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-09-02 23:51:59 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-09-02 23:51:59 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-09-02 23:51:59 11081728 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-09-02 23:51:58 -------- d-----w- C:\otherrecycler
2011-09-02 23:21:17 2321288 ----a-w- c:\documents and settings\all users\application data\microsoft\windows defender\definition updates\backup\mpengine.dll
2011-09-02 23:21:11 7152464 ----a-w- c:\documents and settings\all users\application data\microsoft\windows defender\definition updates\{2a0b44f2-2835-437b-8b15-9231086176db}\mpengine.dll
2011-09-02 23:21:11 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-09-02 22:47:10 -------- d-sha-r- C:\cmdcons
2011-09-02 22:45:45 256000 ----a-w- c:\windows\PEV.exe
2011-09-02 22:37:04 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-09-02 22:37:01 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-09-02 22:37:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-09-02 22:32:23 -------- d-----w- C:\ERDNT
2011-09-02 22:32:03 1445888 ----a-w- C:\WinsockxpFix.exe
2011-09-02 22:29:42 2560 ----a-w- c:\documents and settings\all users\application data\microsoft\usmt\iconlib.dll
2011-09-02 22:24:45 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-09-02 22:24:45 -------- d-----w- c:\windows\system32\wbem\Repository
2011-09-02 21:58:45 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-09-02 16:56:01 -------- d-sh--w- c:\documents and settings\bobo\IECompatCache
2011-09-02 16:54:53 -------- d-sh--w- c:\documents and settings\bobo\PrivacIE
2011-09-02 16:42:20 -------- d---a-w- C:\cmdcons(2)
2011-09-02 16:03:34 -------- d-----w- c:\windows\system32\CatRoot2
2011-09-02 15:55:44 446464 ----a-w- C:\TFC.exe
2011-09-02 15:43:07 4192529 ----a-w- C:\ComboFix.exe
2011-09-02 15:41:09 139264 ----a-w- C:\RKUnhookerLE.EXE
2011-09-02 15:40:22 50477 ----a-w- C:\Defogger.exe
2011-09-02 13:49:56 98816 ----a-w- c:\windows\sed.exe
2011-09-02 13:49:56 518144 ----a-w- c:\windows\SWREG.exe
2011-09-02 13:49:56 208896 ----a-w- c:\windows\MBR.exe
2011-09-02 04:43:27 29959 ----a-w- c:\windows\system\regsv32a.exe
2011-09-01 09:40:13 4194304 ----a-w- c:\windows\system32\embpmffm.dll
2011-09-01 05:12:15 -------- d-----w- c:\program files\Emsisoft HiJackFree
2011-09-01 05:02:37 709896 ----a-w- c:\program files\mozilla firefox\fakeavremover\tmufeng.dll
2011-09-01 05:02:37 537864 ----a-w- c:\program files\mozilla firefox\fakeavremover\tmfbeng.dll
2011-09-01 05:02:31 2433672 ----a-w- c:\program files\mozilla firefox\fakeavremover\svchost.exe
2011-09-01 05:01:06 15360 ----a-w- c:\windows\system32\ctfmon.exe.backup
2011-08-31 23:29:32 0 ----a-w- c:\windows\virus.bin
2011-08-31 23:28:04 -------- d-----w- c:\program files\Yontoo Layers Runtime
2011-08-31 23:27:41 121856 ----a-w- c:\windows\system32\dimsntf.dll
2011-08-27 23:15:52 69376 ----a-w- c:\windows\system32\drivers\usbhub20.sys
2011-08-27 23:09:18 10264 ----a-w- c:\windows\system32\Viagart.sys
2011-08-27 23:01:49 203776 ----a-w- c:\windows\system32\drivers\vinyl97.sys
2011-08-27 23:01:08 19968 ----a-w- c:\windows\Logi_MwX.Exe
2011-08-27 23:01:07 73576 ----a-w- c:\windows\system32\drivers\LMouFlt2.Sys
2011-08-27 23:01:07 26104 ----a-w- c:\windows\system32\drivers\LHidFlt2.Sys
2011-08-27 22:57:01 -------- d-----w- c:\documents and settings\all users\Uniblue
2011-08-27 22:31:02 73728 ----a-w- c:\windows\system32\fdeploy.dll
2011-08-27 22:31:02 566784 ----a-w- c:\windows\system32\gpedit.dll
2011-08-27 22:31:02 199680 ----a-w- c:\windows\system32\gptext.dll
2011-08-27 22:31:02 124928 ----a-w- c:\windows\system32\fde.dll
2011-08-27 22:31:02 -------- d--h--w- c:\windows\system32\GroupPolicy
2011-08-27 22:28:18 295936 ----a-w- c:\windows\system32\appmgr.dll
2011-08-27 22:28:18 167936 ----a-w- c:\windows\system32\appmgmts.dll
2011-08-23 15:28:48 -------- d-----w- c:\documents and settings\all users\application data\NVIDIA Corporation
2011-08-23 15:28:38 146024 ----a-w- c:\windows\system32\nvsvc32.exe
2011-08-23 15:28:38 145000 ----a-w- c:\windows\system32\nvcolor.exe
2011-08-23 15:28:37 54272 ----a-w- c:\windows\system32\nvwddi.dll
2011-08-23 15:28:37 13892200 ----a-w- c:\windows\system32\nvcpl.dll
2011-08-23 15:28:37 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-08-23 15:28:34 281440 ----a-w- c:\windows\system32\nvdrsdb1.bin
2011-08-23 15:28:34 281440 ----a-w- c:\windows\system32\nvdrsdb0.bin
2011-08-23 15:28:34 1 ----a-w- c:\windows\system32\nvdrssel.bin
2011-08-22 20:37:51 5427200 ----a-w- c:\windows\system32\nvcuda.dll
2011-08-22 20:37:51 2387560 ----a-w- c:\windows\system32\nvcuvid.dll
2011-08-22 20:37:51 2090088 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-08-22 20:37:51 17186816 ----a-w- c:\windows\system32\nvcompiler.dll
2011-08-22 20:37:51 16191488 ----a-w- c:\windows\system32\nvoglnt.dll
2011-08-22 20:31:02 -------- d-----w- c:\program files\SystemRequirementsLab
2011-08-18 16:51:50 -------- d-----w- c:\program files\Eusing Free Registry Cleaner
2011-08-17 17:08:43 -------- d-----r- c:\program files\Skype
2011-08-16 14:20:32 4892320 ----a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
2011-08-11 03:46:13 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-11 03:45:56 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2011-08-10 17:54:35 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-10 17:37:32 -------- d-----w- c:\documents and settings\bobo\local settings\application data\Solid State Networks
2011-08-10 03:11:49 974848 ----a-w- c:\windows\system32\mfc70.dll
2011-08-10 03:11:49 487424 ----a-w- c:\windows\system32\msvcp70.dll
2011-08-10 03:11:49 344064 ----a-w- c:\windows\system32\msvcr70.dll
2011-08-10 03:11:49 -------- d-----w- c:\program files\AML Products
2011-08-10 02:58:13 -------- d-----w- c:\documents and settings\all users\application data\Autorun Eater
2011-08-10 01:39:07 -------- d-----w- c:\program files\InCode Solutions
2011-08-09 02:28:35 -------- d-----w- c:\program files\Everything
2011-08-09 02:22:22 -------- d-----w- c:\windows\SxsCaPendDel
2011-08-07 17:19:36 -------- d-----w- c:\documents and settings\all users\application data\Arovax
.
==================== Find3M ====================
.
2011-09-02 15:00:25 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2011-09-01 05:01:06 24064 ----a-w- c:\windows\system32\ctfmon.exe
2011-08-27 23:14:51 69632 ----a-w- c:\windows\system32\vuins32.dll
2011-08-27 23:14:51 46592 ----a-w- c:\windows\system32\drivers\fetnd5bv.sys
2011-08-27 23:14:51 319456 ----a-w- c:\windows\system32\difxapi.dll
2011-08-27 23:09:11 117248 ----a-w- c:\windows\system32\drivers\viamraid.sys
2011-08-27 23:09:02 13976 ----a-w- c:\windows\system32\drivers\videX32.sys
2011-08-03 11:49:00 61440 ----a-w- c:\windows\system32\OpenCL.dll
2011-08-03 11:49:00 4210816 ----a-w- c:\windows\system32\nv4_disp.dll
2011-08-03 11:49:00 2404864 ----a-w- c:\windows\system32\nvapi.dll
2011-08-03 11:49:00 12542592 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-07-15 13:29:31 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10:36 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36:30 916480 ----a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36:30 43520 ------w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36:30 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05:13 385024 ----a-w- c:\windows\system32\html.iec
2011-06-21 18:18:34 667136 ----a-w- c:\windows\system32\wininet(5).dll
2011-06-21 18:18:34 667136 ----a-w- c:\windows\system32\wininet(4).dll
2011-06-21 18:18:34 633344 ----a-w- c:\windows\system32\urlmon(5).dll
2011-06-21 18:18:34 633344 ----a-w- c:\windows\system32\urlmon(4).dll
2011-06-21 18:18:34 449536 ----a-w- c:\windows\system32\mshtmled(2).dll
2011-06-21 18:18:34 37888 ----a-w- c:\windows\system32\url(3).dll
2011-06-20 17:44:52 293376 ----a-w- c:\windows\system32\winsrv.dll
.
============= FINISH: 10:30:13.57 ===============