kuuunaal
2012-01-22, 03:34
Brief sequence of events:
I start my comp. chkdsk runs (never happened before on its own)
Bad sectors found, fixed.
I run Microsoft security essentials, no infections
I run Malwarebytes, no infections
I run spybot, find iedefender and virtumonde. I try to clean and SS&D crashes.
I was going to wipe my drive, but then I found these forums, any and all help is appreciated in advance.
==============================
I have backed up my registry with ERUNT
==============================
:fear::fear:
==============================
Check Disk Log
Level Date and Time Source Event ID Task Category
Information 1/18/2012 8:13:20 PM Microsoft-Windows-Wininit 1001 None "
Checking file system on C:
The type of the file system is NTFS.
One of your disks needs to be checked for consistency. You
may cancel the disk check, but it is strongly recommended
that you continue.
Windows will now check the disk.
CHKDSK is verifying files (stage 1 of 3)...
148992 file records processed.
File verification completed.
414 large file records processed.
0 bad file records processed.
0 EA records processed.
76 reparse records processed.
CHKDSK is verifying indexes (stage 2 of 3)...
Read failure with status 0xc000009c at offset 0x4a2000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4a0000 for 0xc000 bytes.
Read failure with status 0xc000009c at offset 0x4a2000 for 0x1000 bytes.
The USA check value, 0x36, at block 0x1 is incorrect.
The expected value is 0x3.
The multi-sector header signature for VCN 0x2 of index $I30
in file 0x1c9 is incorrect.
42 41 41 44 28 00 09 00 44 3c 1c 6d 06 00 00 00 BAAD(...D<.m....
09 00 00 00 00 00 00 00 28 00 00 00 60 09 00 00 ........(...`...
Correcting error in index $I30 for file 457.
The index bitmap $I30 in file 0x1c9 is incorrect.
Correcting error in index $I30 for file 457.
The down pointer of current index entry with length 0xf0 is invalid.
d4 eb 00 00 00 00 53 01 f0 00 d8 00 01 00 00 00 ......S.........
c9 01 00 00 00 00 01 00 3a 70 11 02 ba 8b ca 01 ........:p......
e8 4f e6 0b a3 8c ca 01 e8 4f e6 0b a3 8c ca 01 .O.......O......
e8 4f e6 0b a3 8c ca 01 00 00 00 00 00 00 00 00 .O..............
00 00 00 00 00 00 00 00 00 08 00 10 00 00 00 00 ................
4b 01 4e 00 6f 00 6e 00 43 00 72 00 69 00 74 00 K.N.o.n.C.r.i.t.
69 00 63 00 61 00 6c 00 5f 00 37 00 2e 00 33 00 i.c.a.l._.7...3.
2e 00 37 00 36 00 30 00 30 00 2e 00 31 00 36 00 ..7.6.0.0...1.6.
33 00 38 00 35 00 5f 00 35 00 39 00 36 00 39 00 3.8.5._.5.9.6.9.
64 00 37 00 64 00 65 00 30 00 36 00 39 00 32 00 d.7.d.e.0.6.9.2.
31 00 63 00 61 00 65 00 35 00 36 00 64 00 32 00 1.c.a.e.5.6.d.2.
39 00 37 00 66 00 31 00 61 00 63 00 63 00 35 00 9.7.f.1.a.c.c.5.
34 00 38 00 61 00 32 00 61 00 39 00 33 00 64 00 4.8.a.2.a.9.3.d.
61 00 37 00 63 00 5f 00 30 00 39 00 66 00 38 00 a.7.c._.0.9.f.8.
65 00 63 00 62 00 65 00 ff ff ff ff ff ff ff ff e.c.b.e.........
47 fe 00 00 00 00 fb 01 f0 00 d8 00 01 00 00 00 G...............
Sorting index $I30 in file 457.
194854 index entries processed.
Index verification completed.
CHKDSK is scanning unindexed files for reconnect to their original directory.
Recovering orphaned file NonCritical_7.3.7600.16385_4e53b15dbd94b5b3d8dee38b9eecee6668288e_0b6bf1bd (1280) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_4e53b15dbd94b5b3d8dee38b9eecee6668288e_06f74a58 (57450) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_4e53b15dbd94b5b3d8dee38b9eecee6668288e_072f7879 (57460) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_4e53b15dbd94b5b3d8dee38b9eecee6668288e_05b79819 (57823) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_5969d7de06921cae56d297f1acc548a2a93da7c_0944e696 (58755) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_4e53b15dbd94b5b3d8dee38b9eecee6668288e_0b199ebe (60246) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_4342e9b3dad534fc31627821d4ce0a74eb3a78_0f229d6e (65740) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_4c87385a24c54d696db0bee0365e63d875b63_0cc6ca18 (67460) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_4f79352d175c57a0b24c8f1a729c6d59b7d2ed8_0e4bff35 (70919) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_5969d7de06921cae56d297f1acc548a2a93da7c_08a9fd61 (70946) into directory file 457.
11 unindexed files scanned.
Recovering orphaned file NonCritical_7.3.7600.16385_55161be8486687ade9e3e673cd536b6bb9f473a4_0d64f2f5 (82250) into directory file 457.
0 unindexed files recovered.
CHKDSK is verifying security descriptors (stage 3 of 3)...
148992 file SDs/SIDs processed.
Cleaning up 11 unused index entries from index $SII of file 0x9.
Cleaning up 11 unused index entries from index $SDH of file 0x9.
Cleaning up 11 unused security descriptors.
Security descriptor verification completed.
22932 data files processed.
CHKDSK is verifying Usn Journal...
37237952 USN bytes processed.
Usn Journal verification completed.
Adding 1 bad clusters to the Bad Clusters File.
Correcting errors in the Volume Bitmap.
Windows has made corrections to the file system.
312426495 KB total disk space.
60636760 KB in 81495 files.
57168 KB in 22933 indexes.
16 KB in bad sectors.
262747 KB in use by the system.
65536 KB occupied by the log file.
251469804 KB available on disk.
4096 bytes in each allocation unit.
78106623 total allocation units on disk.
62867451 allocation units available on disk.
Internal Info:
00 46 02 00 f7 97 01 00 0b 1e 03 00 00 00 00 00 .F..............
32 05 00 00 4c 00 00 00 00 00 00 00 00 00 00 00 2...L...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
Windows has finished checking your disk.
Please wait while your computer restarts.
"
==============================
:fear::fear:
==============================
SS&D log
--- Report generated: 2012-01-21 19:23 ---
IEDefender: [SBI $48D96110] Library (File, nothing done)
C:\Windows\System32\gptext.dll
Properties.size=18944
Virtumonde: [SBI $85BCD1C6] Library (File, nothing done)
C:\Windows\System32\mssprxy.dll
Properties.size=35328
==============================
:fear::fear:
==============================
DDS
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Run by oo7 at 18:40:15 on 2012-01-21
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4094.3061 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskmgr.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit=userinit.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: DhcpNameServer = 208.67.220.220 208.67.222.222 97.81.22.195 71.92.29.130 24.217.201.6 192.168.1.1
TCP: Interfaces\{B27D4C3C-24C2-48A5-99A4-39A7E3D3145C} : DhcpNameServer = 208.67.220.220 208.67.222.222 97.81.22.195 71.92.29.130 24.217.201.6 192.168.1.1
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\oo7\AppData\Roaming\Mozilla\Firefox\Profiles\wbzj7k9y.default\
FF - prefs.js: browser.startup.homepage - yahoo.com
FF - plugin: C:\PROGRA~2\Palm\PACKAG~1\NPInstal.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-3-6 135664]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-3-6 135664]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2012-01-18 00:29:05 8602168 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{98460BED-6D2C-4BB7-BA03-A1A4E63CDDF6}\mpengine.dll
2012-01-03 22:15:44 626688 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcr80.dll
2012-01-03 22:15:44 548864 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcp80.dll
2012-01-03 22:15:44 479232 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcm80.dll
2012-01-03 22:15:44 43992 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozutils.dll
2012-01-03 13:10:44 182672 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2012-01-03 13:10:44 182672 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll
.
==================== Find3M ====================
.
2011-11-28 20:51:12 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-24 04:52:09 3145216 ----a-w- C:\Windows\System32\win32k.sys
2011-11-19 14:58:00 77312 ----a-w- C:\Windows\System32\packager.dll
2011-11-19 14:01:00 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2011-11-17 06:49:14 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2011-11-17 06:49:14 152432 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2011-11-17 06:44:43 459232 ----a-w- C:\Windows\System32\drivers\cng.sys
2011-11-17 06:41:18 1731920 ----a-w- C:\Windows\System32\ntdll.dll
2011-11-17 06:35:28 395776 ----a-w- C:\Windows\System32\webio.dll
2011-11-17 06:35:26 29184 ----a-w- C:\Windows\System32\sspisrv.dll
2011-11-17 06:35:26 136192 ----a-w- C:\Windows\System32\sspicli.dll
2011-11-17 06:35:25 340992 ----a-w- C:\Windows\System32\schannel.dll
2011-11-17 06:35:25 28160 ----a-w- C:\Windows\System32\secur32.dll
2011-11-17 06:35:19 1447936 ----a-w- C:\Windows\System32\lsasrv.dll
2011-11-17 06:33:55 31232 ----a-w- C:\Windows\System32\lsass.exe
2011-11-17 05:38:39 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
2011-11-17 05:35:02 314880 ----a-w- C:\Windows\SysWow64\webio.dll
2011-11-17 05:34:52 224768 ----a-w- C:\Windows\SysWow64\schannel.dll
2011-11-17 05:34:52 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2011-11-17 05:28:48 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2011-11-10 21:10:30 525544 ----a-w- C:\Windows\System32\deployJava1.dll
2011-11-05 05:32:50 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-11-05 04:26:03 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-11-04 01:53:39 2309120 ----a-w- C:\Windows\System32\jscript9.dll
2011-11-04 01:44:47 1390080 ----a-w- C:\Windows\System32\wininet.dll
2011-11-04 01:44:21 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl
2011-11-04 01:34:43 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-11-03 22:47:42 1798144 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-11-03 22:40:21 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2011-11-03 22:39:47 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-11-03 22:31:57 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-10-26 05:25:16 1572864 ----a-w- C:\Windows\System32\quartz.dll
2011-10-26 05:25:15 366592 ----a-w- C:\Windows\System32\qdvd.dll
2011-10-26 05:21:20 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2011-10-26 04:32:11 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2011-10-26 04:32:11 1328128 ----a-w- C:\Windows\SysWow64\quartz.dll
2011-10-24 19:29:02 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2011-10-24 19:29:02 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
.
============= FINISH: 18:41:01.15 ===============
I start my comp. chkdsk runs (never happened before on its own)
Bad sectors found, fixed.
I run Microsoft security essentials, no infections
I run Malwarebytes, no infections
I run spybot, find iedefender and virtumonde. I try to clean and SS&D crashes.
I was going to wipe my drive, but then I found these forums, any and all help is appreciated in advance.
==============================
I have backed up my registry with ERUNT
==============================
:fear::fear:
==============================
Check Disk Log
Level Date and Time Source Event ID Task Category
Information 1/18/2012 8:13:20 PM Microsoft-Windows-Wininit 1001 None "
Checking file system on C:
The type of the file system is NTFS.
One of your disks needs to be checked for consistency. You
may cancel the disk check, but it is strongly recommended
that you continue.
Windows will now check the disk.
CHKDSK is verifying files (stage 1 of 3)...
148992 file records processed.
File verification completed.
414 large file records processed.
0 bad file records processed.
0 EA records processed.
76 reparse records processed.
CHKDSK is verifying indexes (stage 2 of 3)...
Read failure with status 0xc000009c at offset 0x4a2000 for 0x1000 bytes.
Read failure with status 0xc000009c at offset 0x4a0000 for 0xc000 bytes.
Read failure with status 0xc000009c at offset 0x4a2000 for 0x1000 bytes.
The USA check value, 0x36, at block 0x1 is incorrect.
The expected value is 0x3.
The multi-sector header signature for VCN 0x2 of index $I30
in file 0x1c9 is incorrect.
42 41 41 44 28 00 09 00 44 3c 1c 6d 06 00 00 00 BAAD(...D<.m....
09 00 00 00 00 00 00 00 28 00 00 00 60 09 00 00 ........(...`...
Correcting error in index $I30 for file 457.
The index bitmap $I30 in file 0x1c9 is incorrect.
Correcting error in index $I30 for file 457.
The down pointer of current index entry with length 0xf0 is invalid.
d4 eb 00 00 00 00 53 01 f0 00 d8 00 01 00 00 00 ......S.........
c9 01 00 00 00 00 01 00 3a 70 11 02 ba 8b ca 01 ........:p......
e8 4f e6 0b a3 8c ca 01 e8 4f e6 0b a3 8c ca 01 .O.......O......
e8 4f e6 0b a3 8c ca 01 00 00 00 00 00 00 00 00 .O..............
00 00 00 00 00 00 00 00 00 08 00 10 00 00 00 00 ................
4b 01 4e 00 6f 00 6e 00 43 00 72 00 69 00 74 00 K.N.o.n.C.r.i.t.
69 00 63 00 61 00 6c 00 5f 00 37 00 2e 00 33 00 i.c.a.l._.7...3.
2e 00 37 00 36 00 30 00 30 00 2e 00 31 00 36 00 ..7.6.0.0...1.6.
33 00 38 00 35 00 5f 00 35 00 39 00 36 00 39 00 3.8.5._.5.9.6.9.
64 00 37 00 64 00 65 00 30 00 36 00 39 00 32 00 d.7.d.e.0.6.9.2.
31 00 63 00 61 00 65 00 35 00 36 00 64 00 32 00 1.c.a.e.5.6.d.2.
39 00 37 00 66 00 31 00 61 00 63 00 63 00 35 00 9.7.f.1.a.c.c.5.
34 00 38 00 61 00 32 00 61 00 39 00 33 00 64 00 4.8.a.2.a.9.3.d.
61 00 37 00 63 00 5f 00 30 00 39 00 66 00 38 00 a.7.c._.0.9.f.8.
65 00 63 00 62 00 65 00 ff ff ff ff ff ff ff ff e.c.b.e.........
47 fe 00 00 00 00 fb 01 f0 00 d8 00 01 00 00 00 G...............
Sorting index $I30 in file 457.
194854 index entries processed.
Index verification completed.
CHKDSK is scanning unindexed files for reconnect to their original directory.
Recovering orphaned file NonCritical_7.3.7600.16385_4e53b15dbd94b5b3d8dee38b9eecee6668288e_0b6bf1bd (1280) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_4e53b15dbd94b5b3d8dee38b9eecee6668288e_06f74a58 (57450) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_4e53b15dbd94b5b3d8dee38b9eecee6668288e_072f7879 (57460) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_4e53b15dbd94b5b3d8dee38b9eecee6668288e_05b79819 (57823) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_5969d7de06921cae56d297f1acc548a2a93da7c_0944e696 (58755) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_4e53b15dbd94b5b3d8dee38b9eecee6668288e_0b199ebe (60246) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_4342e9b3dad534fc31627821d4ce0a74eb3a78_0f229d6e (65740) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_4c87385a24c54d696db0bee0365e63d875b63_0cc6ca18 (67460) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_4f79352d175c57a0b24c8f1a729c6d59b7d2ed8_0e4bff35 (70919) into directory file 457.
Recovering orphaned file NonCritical_7.3.7600.16385_5969d7de06921cae56d297f1acc548a2a93da7c_08a9fd61 (70946) into directory file 457.
11 unindexed files scanned.
Recovering orphaned file NonCritical_7.3.7600.16385_55161be8486687ade9e3e673cd536b6bb9f473a4_0d64f2f5 (82250) into directory file 457.
0 unindexed files recovered.
CHKDSK is verifying security descriptors (stage 3 of 3)...
148992 file SDs/SIDs processed.
Cleaning up 11 unused index entries from index $SII of file 0x9.
Cleaning up 11 unused index entries from index $SDH of file 0x9.
Cleaning up 11 unused security descriptors.
Security descriptor verification completed.
22932 data files processed.
CHKDSK is verifying Usn Journal...
37237952 USN bytes processed.
Usn Journal verification completed.
Adding 1 bad clusters to the Bad Clusters File.
Correcting errors in the Volume Bitmap.
Windows has made corrections to the file system.
312426495 KB total disk space.
60636760 KB in 81495 files.
57168 KB in 22933 indexes.
16 KB in bad sectors.
262747 KB in use by the system.
65536 KB occupied by the log file.
251469804 KB available on disk.
4096 bytes in each allocation unit.
78106623 total allocation units on disk.
62867451 allocation units available on disk.
Internal Info:
00 46 02 00 f7 97 01 00 0b 1e 03 00 00 00 00 00 .F..............
32 05 00 00 4c 00 00 00 00 00 00 00 00 00 00 00 2...L...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
Windows has finished checking your disk.
Please wait while your computer restarts.
"
==============================
:fear::fear:
==============================
SS&D log
--- Report generated: 2012-01-21 19:23 ---
IEDefender: [SBI $48D96110] Library (File, nothing done)
C:\Windows\System32\gptext.dll
Properties.size=18944
Virtumonde: [SBI $85BCD1C6] Library (File, nothing done)
C:\Windows\System32\mssprxy.dll
Properties.size=35328
==============================
:fear::fear:
==============================
DDS
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Run by oo7 at 18:40:15 on 2012-01-21
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4094.3061 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskmgr.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit=userinit.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: DhcpNameServer = 208.67.220.220 208.67.222.222 97.81.22.195 71.92.29.130 24.217.201.6 192.168.1.1
TCP: Interfaces\{B27D4C3C-24C2-48A5-99A4-39A7E3D3145C} : DhcpNameServer = 208.67.220.220 208.67.222.222 97.81.22.195 71.92.29.130 24.217.201.6 192.168.1.1
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\oo7\AppData\Roaming\Mozilla\Firefox\Profiles\wbzj7k9y.default\
FF - prefs.js: browser.startup.homepage - yahoo.com
FF - plugin: C:\PROGRA~2\Palm\PACKAG~1\NPInstal.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-3-6 135664]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-3-6 135664]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2012-01-18 00:29:05 8602168 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{98460BED-6D2C-4BB7-BA03-A1A4E63CDDF6}\mpengine.dll
2012-01-03 22:15:44 626688 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcr80.dll
2012-01-03 22:15:44 548864 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcp80.dll
2012-01-03 22:15:44 479232 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcm80.dll
2012-01-03 22:15:44 43992 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozutils.dll
2012-01-03 13:10:44 182672 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2012-01-03 13:10:44 182672 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll
.
==================== Find3M ====================
.
2011-11-28 20:51:12 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-24 04:52:09 3145216 ----a-w- C:\Windows\System32\win32k.sys
2011-11-19 14:58:00 77312 ----a-w- C:\Windows\System32\packager.dll
2011-11-19 14:01:00 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2011-11-17 06:49:14 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2011-11-17 06:49:14 152432 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2011-11-17 06:44:43 459232 ----a-w- C:\Windows\System32\drivers\cng.sys
2011-11-17 06:41:18 1731920 ----a-w- C:\Windows\System32\ntdll.dll
2011-11-17 06:35:28 395776 ----a-w- C:\Windows\System32\webio.dll
2011-11-17 06:35:26 29184 ----a-w- C:\Windows\System32\sspisrv.dll
2011-11-17 06:35:26 136192 ----a-w- C:\Windows\System32\sspicli.dll
2011-11-17 06:35:25 340992 ----a-w- C:\Windows\System32\schannel.dll
2011-11-17 06:35:25 28160 ----a-w- C:\Windows\System32\secur32.dll
2011-11-17 06:35:19 1447936 ----a-w- C:\Windows\System32\lsasrv.dll
2011-11-17 06:33:55 31232 ----a-w- C:\Windows\System32\lsass.exe
2011-11-17 05:38:39 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
2011-11-17 05:35:02 314880 ----a-w- C:\Windows\SysWow64\webio.dll
2011-11-17 05:34:52 224768 ----a-w- C:\Windows\SysWow64\schannel.dll
2011-11-17 05:34:52 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2011-11-17 05:28:48 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2011-11-10 21:10:30 525544 ----a-w- C:\Windows\System32\deployJava1.dll
2011-11-05 05:32:50 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-11-05 04:26:03 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-11-04 01:53:39 2309120 ----a-w- C:\Windows\System32\jscript9.dll
2011-11-04 01:44:47 1390080 ----a-w- C:\Windows\System32\wininet.dll
2011-11-04 01:44:21 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl
2011-11-04 01:34:43 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-11-03 22:47:42 1798144 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-11-03 22:40:21 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2011-11-03 22:39:47 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-11-03 22:31:57 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-10-26 05:25:16 1572864 ----a-w- C:\Windows\System32\quartz.dll
2011-10-26 05:25:15 366592 ----a-w- C:\Windows\System32\qdvd.dll
2011-10-26 05:21:20 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2011-10-26 04:32:11 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2011-10-26 04:32:11 1328128 ----a-w- C:\Windows\SysWow64\quartz.dll
2011-10-24 19:29:02 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2011-10-24 19:29:02 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
.
============= FINISH: 18:41:01.15 ===============