Hi again Tomk,
Sorry for the very late reply, I had things to take care of at work
I don't know or think I have a spyware either, but I better be safe than sorry
Here are the logs from DDS, following would be the attachment of "Attach.txt"
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by [removed] at 12:45:04 on 2011-10-08
Microsoft Windows 7 Ultimate 6.1.7600.1.932.81.1033.18.2046.862 [GMT 8:00]
.
AV: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Tablet\Pen\Pen_TouchService.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k Akamai
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\libusbd-nt.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Fraps\fraps.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Bamboo Dock\BambooCore.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
D:\Documents - Zero\Rainmeter-1.1-32bit\Rainmeter.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\AUDIODG.EXE
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://dn.gamania.co.jp/index.aspx
uInternet Settings,ProxyServer = http=127.0.0.1:55576
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Yahoo!ツールバーフィッシング警告: {1f68e72c-50e5-44b8-8f56-6a54d3af1da4} - c:\program files\yahoo!j\toolbar\7_3_0_14\modules\ypho.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Yahoo!ツールバーヘルパー: {eeba90e6-2b14-413f-9bf8-61a8bdf92258} - c:\program files\yahoo!j\toolbar\7_3_0_14\modules\YahooToolBar.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
TB: Yahoo!ツールバー: {aef44653-c059-42cb-a5b7-41c640da4a67} - c:\program files\yahoo!j\toolbar\7_3_0_14\modules\YahooToolBar.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [BambooCore] c:\program files\bamboo dock\BambooCore.exe
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
StartupFolder: c:\users\zero\appdata\roaming\micros~1\windows\startm~1\programs\startup\rainme~1.lnk - d:\documents - zero\rainmeter-1.1-32bit\Rainmeter.exe
StartupFolder: c:\users\zero\appdata\roaming\micros~1\windows\startm~1\programs\startup\stardo~1.lnk - c:\program files\stardock\objectdock\ObjectDock.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\wddmst~1.lnk - c:\program files\western digital\wd smartware\wd drive manager\WDDMStatus.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\wdsmar~1.lnk - c:\program files\western digital\wd smartware\front parlor\WDSmartWare.exe
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
DPF: {53F4962A-8E27-4601-8B01-79A82B4D7FC9} - hxxps://member.gungho.jp/front/member/webgs/LoadPrgAx.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {C8F5F737-2683-40B8-BFB6-47B15AC20A79} - hxxps://gash.gamania.co.jp/acxauth/cab/2.0.1/lcjggame.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{0091257D-FE2F-4F79-B2B1-93BD6B5DBA3A} : DhcpNameServer = [removed] [removed]
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\zero\appdata\roaming\mozilla\firefox\profiles\nntgdydn.default\
FF - prefs.js: browser.search.selectedEngine - Gelbooru
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 55576
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\ahnlab\asp\mykeydefense 2.5\npmkd25aos.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npBFPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\tabletplugins\npwacom.dll
.
============= SERVICES / DRIVERS ===============
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-5-9 218688]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2009-7-14 20992]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-9-29 735960]
R2 epfwwfpr;epfwwfpr;c:\windows\system32\drivers\epfwwfpr.sys [2009-9-29 95896]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe –> system32\libusbd-nt.exe [?]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-4-19 2255464]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2011-8-3 379496]
R2 TabletServicePen;TabletServicePen;c:\program files\tablet\pen\Pen_Tablet.exe [2011-7-20 4869488]
R2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\tablet\pen\Pen_TouchService.exe [2011-7-20 416112]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\western digital\wd smartware\wd drive manager\WDDMService.exe [2009-11-13 110592]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\western digital\wd smartware\front parlor\WDSmartWareBackgroundService.exe [2009-6-16 20480]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2011-6-20 33792]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-6-23 275048]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google アップデート サービス (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-7-3 136176]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 62464]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011-3-7 14216]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011-3-7 8456]
S3 gupdatem;Google Update サービス (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-7-3 136176]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [2010-3-10 25112]
S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [2011-6-15 133632]
S3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2011-6-15 79360]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-21 15872]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\Synth3dVsc.sys [2010-11-21 77184]
S3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 25600]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-21 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 27264]
S3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 112640]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2011-7-20 16240]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
.
=============== Created Last 30 ================
.
2011-10-08 02:16:40 56200 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{1e2838f4-e69d-4dc0-b3af-49c9ba1d538a}\offreg.dll
2011-10-07 02:57:04 ——– d—–w- C:\Games
2011-09-30 10:31:28 7269712 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{1e2838f4-e69d-4dc0-b3af-49c9ba1d538a}\mpengine.dll
2011-09-30 10:16:49 75776 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2011-09-30 10:16:49 5888 —-a-w- c:\windows\system32\drivers\usbd.sys
2011-09-30 10:16:49 43008 —-a-w- c:\windows\system32\drivers\usbehci.sys
2011-09-30 10:16:49 284672 —-a-w- c:\windows\system32\drivers\usbport.sys
2011-09-30 10:16:49 258560 —-a-w- c:\windows\system32\drivers\usbhub.sys
2011-09-30 10:16:49 24064 —-a-w- c:\windows\system32\drivers\usbuhci.sys
2011-09-30 10:16:49 20480 —-a-w- c:\windows\system32\drivers\usbohci.sys
2011-09-20 22:58:09 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-09-20 22:58:09 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-09-20 06:26:01 ——– d—–w- C:\$RECYCLE.BIN
2011-09-19 15:32:36 ——– d—–w- c:\users\zero\appdata\local\temp
2011-09-17 09:51:04 ——– d—–w- c:\program files\ESET
2011-09-14 13:20:32 53912 —-a-w- c:\program files\mozilla firefox\plugins\npBFPlugin.dll
2011-09-14 06:23:00 ——– d—–w- c:\program files\Mad Scientist Productions
2011-09-10 13:10:44 ——– d—–w- c:\users\zero\appdata\roaming\StepMania 5
2011-09-10 13:10:44 ——– d—–w- c:\programdata\StepMania 5
.
==================== Find3M ====================
.
2011-09-27 12:40:54 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-20 08:32:51 73 —-a-w- c:\windows\system32\ssprs.dll
2011-09-20 08:32:51 205 —-a-w- c:\windows\system32\lsprst7.dll
2011-08-03 11:50:00 914024 —-a-w- c:\windows\system32\nvdispco32.dll
2011-08-02 19:31:54 311912 —-a-w- c:\windows\system32\nvStreaming.exe
2011-07-31 16:14:48 25280 —-a-w- c:\windows\system32\drivers\hamachi.sys
2011-07-16 04:27:30 290816 —-a-w- c:\windows\system32\KernelBase.dll
2011-07-16 02:17:19 6144 —ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:17:19 4608 —ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:17:19 3584 —ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:17:19 3072 —ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
.
============= FINISH: 12:45:54.15 ===============
YukiYuki,
Download ComboFix from one of these locations:
Link 1
Link 2
Link 3
* IMPORTANT !!! Save ComboFix.exe to your Desktop
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html
Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the
C:\ComboFix.txt in your next reply.
Notes:
1.
Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2.
Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of
ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely , the connection can be manually restored by restarting your machine.
Hi Tomk,
It's been 2 weeks since my last reply, and I'm really really sorry for that. Things haven't been going smoothly back at work, so I haven't had the time to check on this lately
Again, I'm really really sorry for the very late reply
Here's the Log from Combofix, which I did a few days ago during my very little spare time
and also, since I'm already here. I'd also like to inquire about another problem, which would be explained in the next post
ComboFix 11-10-24.02 - Zero 2011/10/24 21:41:06.5.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.1.932.81.1033.18.2046.1357 [GMT 8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\drivers\etc\hosts.txt
c:\windows\system32\lsprst7.dll
c:\windows\system32\ssprs.dll
.
Infected copy of c:\windows\System32\slui.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-security-spp-ux_31bf3856ad364e35_6.1.7601.17514_none_5dc908a6fd144a83\slui.exe
.
Infected copy of c:\windows\System32\winver.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-winver_31bf3856ad364e35_6.1.7600.16385_none_b627d45ffdcc6f00\winver.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-09-24 to 2011-10-24 )))))))))))))))))))))))))))))))
.
.
2011-10-24 13:49 . 2011-10-24 13:49 ——– d—–w- c:\users\Zero\AppData\Local\temp
2011-10-24 13:49 . 2011-10-24 13:49 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp
2011-10-24 13:49 . 2011-10-24 13:49 ——– d—–w- c:\users\UpdatusUser.SYNTHESiZE\AppData\Local\temp
2011-10-24 13:49 . 2011-10-24 13:49 ——– d—–w- c:\users\Public\AppData\Local\temp
2011-10-24 13:49 . 2011-10-24 13:49 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-10-24 09:13 . 2011-10-24 09:13 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DA6EBF5A-0141-4B72-AEBC-8033FDA4F36B}\offreg.dll
2011-10-23 08:19 . 2011-03-02 10:43 175616 —-a-w- c:\windows\system32\unrar.dll
2011-10-23 08:19 . 2011-10-04 08:00 74752 —-a-w- c:\windows\system32\ff_vfw.dll
2011-10-23 08:19 . 2011-07-16 14:17 151552 —-a-w- c:\windows\system32\ac3acm.acm
2011-10-23 08:19 . 2011-06-24 14:44 243200 —-a-w- c:\windows\system32\xvidvfw.dll
2011-10-23 08:19 . 2011-06-24 14:28 650752 —-a-w- c:\windows\system32\xvidcore.dll
2011-10-23 08:19 . 2008-09-24 18:41 839680 —-a-w- c:\windows\system32\lameACM.acm
2011-10-23 06:59 . 2011-09-08 09:48 1152888 —-a-w- c:\windows\system32\WacomMT.dll
2011-10-22 15:07 . 2011-10-07 03:48 6668624 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DA6EBF5A-0141-4B72-AEBC-8033FDA4F36B}\mpengine.dll
2011-10-22 14:58 . 2011-08-27 04:26 571904 —-a-w- c:\windows\system32\oleaut32.dll
2011-10-22 14:58 . 2011-08-27 04:26 233472 —-a-w- c:\windows\system32\oleacc.dll
2011-10-22 14:58 . 2011-08-17 04:24 465408 —-a-w- c:\windows\system32\psisdecd.dll
2011-10-22 14:58 . 2011-08-17 04:19 75776 —-a-w- c:\windows\system32\psisrndr.ax
2011-10-22 14:58 . 2011-09-06 02:28 2334720 —-a-w- c:\windows\system32\win32k.sys
2011-10-19 23:15 . 2011-10-19 23:15 ——– d—–w- c:\program files\Common Files\Java
2011-10-11 11:12 . 2011-10-11 11:12 ——– d—–w- c:\program files\7-Zip
2011-10-11 11:07 . 2011-10-11 12:37 ——– d—–w- c:\users\Zero\AppData\Roaming\DJ Hackers
2011-10-11 11:05 . 2011-10-11 11:09 ——– d—–w- c:\users\Zero\AppData\Roaming\com.zipeg
2011-10-11 11:04 . 2011-10-11 11:04 ——– d—–w- c:\program files\Zipeg
2011-10-08 23:33 . 2011-10-09 21:03 ——– d—–w- c:\users\TEMP
2011-10-07 02:57 . 2011-10-15 00:14 ——– d—–w- C:\Games
2011-09-30 10:16 . 2011-03-25 02:58 258560 —-a-w- c:\windows\system32\drivers\usbhub.sys
2011-09-30 10:16 . 2011-03-25 02:58 284672 —-a-w- c:\windows\system32\drivers\usbport.sys
2011-09-30 10:16 . 2011-03-25 02:58 75776 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2011-09-30 10:16 . 2011-03-25 02:57 43008 —-a-w- c:\windows\system32\drivers\usbehci.sys
2011-09-30 10:16 . 2011-03-25 02:57 20480 —-a-w- c:\windows\system32\drivers\usbohci.sys
2011-09-30 10:16 . 2011-03-25 02:57 24064 —-a-w- c:\windows\system32\drivers\usbuhci.sys
2011-09-30 10:16 . 2011-03-25 02:57 5888 —-a-w- c:\windows\system32\drivers\usbd.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-02 21:06 . 2011-02-21 09:43 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-09-27 12:40 . 2011-06-15 01:14 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-08 09:48 . 2011-07-20 09:34 1156472 —-a-w- c:\windows\system32\Wintab32.dll
2011-09-08 09:48 . 2011-07-20 09:35 1107832 —-a-w- c:\windows\system32\Pen_Touch_Tablet.dll
2011-09-08 09:48 . 2011-07-20 09:34 1369464 —-a-w- c:\windows\system32\Pen_Tablet.dll
2011-09-01 01:12 . 2011-09-01 01:12 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-09-01 01:12 . 2011-09-01 01:12 161792 —-a-w- c:\windows\system32\msls31.dll
2011-09-01 01:12 . 2011-09-01 01:12 86528 —-a-w- c:\windows\system32\iesysprep.dll
2011-09-01 01:12 . 2011-09-01 01:12 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-09-01 01:12 . 2011-09-01 01:12 74752 —-a-w- c:\windows\system32\iesetup.dll
2011-09-01 01:12 . 2011-09-01 01:12 63488 —-a-w- c:\windows\system32\tdc.ocx
2011-09-01 01:12 . 2011-09-01 01:12 48640 —-a-w- c:\windows\system32\mshtmler.dll
2011-09-01 01:12 . 2011-09-01 01:12 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-09-01 01:12 . 2011-09-01 01:12 367104 —-a-w- c:\windows\system32\html.iec
2011-09-01 01:12 . 2011-09-01 01:12 23552 —-a-w- c:\windows\system32\licmgr10.dll
2011-09-01 01:12 . 2011-09-01 01:12 152064 —-a-w- c:\windows\system32\wextract.exe
2011-09-01 01:12 . 2011-09-01 01:12 150528 —-a-w- c:\windows\system32\iexpress.exe
2011-09-01 01:12 . 2011-09-01 01:12 1427456 —-a-w- c:\windows\system32\inetcpl.cpl
2011-09-01 01:12 . 2011-09-01 01:12 110592 —-a-w- c:\windows\system32\IEAdvpack.dll
2011-09-01 01:12 . 2011-09-01 01:12 35840 —-a-w- c:\windows\system32\imgutil.dll
2011-09-01 01:12 . 2011-09-01 01:12 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2011-09-01 01:12 . 2011-09-01 01:12 11776 —-a-w- c:\windows\system32\mshta.exe
2011-09-01 01:12 . 2011-09-01 01:12 101888 —-a-w- c:\windows\system32\admparse.dll
2011-08-31 09:00 . 2011-09-20 22:58 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-08-30 04:04 . 2011-08-30 04:04 45056 —-a-r- c:\users\Zero\AppData\Roaming\Microsoft\Installer\{EC317B1E-FC13-403D-BD0D-B22324DDE414}\NewShortcut3_EC317B1EFC13403DBD0DB22324DDE414_1.exe
2011-08-30 04:04 . 2011-08-30 04:04 45056 —-a-r- c:\users\Zero\AppData\Roaming\Microsoft\Installer\{EC317B1E-FC13-403D-BD0D-B22324DDE414}\NewShortcut1_EC317B1EFC13403DBD0DB22324DDE414_2.exe
2011-08-03 11:50 . 2011-08-25 14:17 914024 —-a-w- c:\windows\system32\nvdispco32.dll
2011-08-03 11:50 . 2011-08-25 14:17 875112 —-a-w- c:\windows\system32\nvgenco32.dll
2011-08-03 11:50 . 2011-08-25 14:17 57960 —-a-w- c:\windows\system32\OpenCL.dll
2011-08-03 11:50 . 2011-08-25 14:17 5404776 —-a-w- c:\windows\system32\nvcuda.dll
2011-08-03 11:50 . 2011-08-25 14:17 2391656 —-a-w- c:\windows\system32\nvcuvid.dll
2011-08-03 11:50 . 2011-08-25 14:17 2090088 —-a-w- c:\windows\system32\nvcuvenc.dll
2011-08-03 11:50 . 2011-08-25 14:17 17193576 —-a-w- c:\windows\system32\nvcompiler.dll
2011-08-03 11:50 . 2011-08-25 14:17 16595560 —-a-w- c:\windows\system32\nvoglv32.dll
2011-08-03 11:50 . 2011-08-25 14:17 10304104 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-08-03 11:50 . 2011-06-17 04:27 12636776 —-a-w- c:\windows\system32\nvd3dum.dll
2011-08-03 11:50 . 2011-04-07 14:45 600680 —-a-w- c:\windows\system32\easyUpdatusAPIU.dll
2011-08-03 11:50 . 2011-04-07 14:45 599144 —-a-w- c:\windows\system32\nvvsvc.exe
2011-08-03 11:50 . 2011-04-07 14:45 111208 —-a-w- c:\windows\system32\nvmctray.dll
2011-08-03 11:50 . 2011-04-07 14:44 3730024 —-a-w- c:\windows\system32\nvcpl.dll
2011-08-03 11:50 . 2011-04-07 14:44 2558568 —-a-w- c:\windows\system32\nvsvc.dll
2011-08-03 11:50 . 2011-02-21 09:13 2412136 —-a-w- c:\windows\system32\nvapi.dll
2011-08-03 11:50 . 2011-01-07 13:06 66664 —-a-w- c:\windows\system32\nvshext.dll
2011-08-03 11:50 . 2009-07-13 22:09 6613096 —-a-w- c:\windows\system32\nvwgf2um.dll
2011-08-02 19:31 . 2011-08-02 19:31 311912 —-a-w- c:\windows\system32\nvStreaming.exe
2011-07-31 16:14 . 2011-07-31 16:14 25280 —-a-w- c:\windows\system32\drivers\hamachi.sys
2011-09-30 13:31 . 2011-06-01 05:42 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
[-] 2010-11-20 . BE8C64439F1E2AF088063218C16EB9FE . 811520 . . [6.1.7601.17514] . . c:\windows\System32\user32.dll
.
[7] 2011-06-23 . 3624D782F8B061B6FBA3A35E2FE53CFD . 3967872 . . [6.1.7601.21755] . . c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21755_none_6e972ad72ba2517f\ntkrnlpa.exe
[7] 2011-06-23 . A4A8EF2ACE5FA5863AA0B04C9BBFECA7 . 3967872 . . [6.1.7601.17640] . . c:\windows\ERDNT\cache\ntkrnlpa.exe
[7] 2011-06-23 . A4A8EF2ACE5FA5863AA0B04C9BBFECA7 . 3967872 . . [6.1.7601.17640] . . c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17640_none_6e135c8612811711\ntkrnlpa.exe
[7] 2011-04-09 . 102A6182087B18C795664BCD22EB52E9 . 3967872 . . [6.1.7601.17592] . . c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17592_none_6ddf4b9812a7d84d\ntkrnlpa.exe
[7] 2011-04-09 . 9CF7F5D025183FA10E130445BC071B70 . 3967872 . . [6.1.7601.21701] . . c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21701_none_6ec9394b2b7d606e\ntkrnlpa.exe
[7] 2010-11-20 . 144BD78C6103C8616DE047B3532142DB . 3966848 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17514_none_6e37cb8c12652b73\ntkrnlpa.exe
[-] 2010-11-20 . 6BB5D70720DB62A363404836140C97E6 . 3958792 . . [6.1.7600.20738] . . c:\windows\System32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-11-18 10:40 1196936 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Steam"="d:\program files\Steam\Steam.exe" [2011-10-23 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-05 500208]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-21 406992]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-03-22 74752]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"BambooCore"="c:\program files\Bamboo Dock\BambooCore.exe" [2011-07-20 629848]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
c:\users\Zero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Rainmeter - Shortcut.lnk - d:\documents - zero\Rainmeter-1.1-32bit\Rainmeter.exe [2010-2-19 119296]
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2011-3-13 3450608]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-11-13 2057536]
WDSmartWare.lnk - c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-11-13 9117504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^Users^Zero^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^hamachi.lnk]
path=c:\users\Zero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hamachi.lnk
backup=c:\windows\pss\hamachi.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-10-23 13:23 1242448 —-a-w- d:\program files\Steam\Steam.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google アップデート サービス (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47 136176]
R3 1394hub;1394 Enabled Hub;c:\windows\System32\svchost.exe [2009-07-14 20992]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-07-15 14216]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-07-15 8456]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files\Garena Classic\safedrv.sys [x]
R3 gupdatem;Google Update サービス (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47 136176]
R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys [2010-03-10 25112]
R3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNt.sys [2009-10-13 133632]
R3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2009-07-13 79360]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2011-06-19 4122968]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-20 77184]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-20 25600]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-20 112640]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2010-10-11 16240]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2008-05-06 11520]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-05-09 218688]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;c:\windows\system32\libusbd-nt.exe [2005-03-09 18944]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-08-02 379496]
S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2011-09-08 5554552]
S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2011-09-08 451960]
S2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-11-13 110592]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2005-03-09 33792]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-06-23 275048]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47]
.
2011-10-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://dn.gamania.co.jp/index.aspx
uInternet Settings,ProxyServer = http=127.0.0.1:55576
TCP: DhcpNameServer = [removed] [removed]
DPF: {53F4962A-8E27-4601-8B01-79A82B4D7FC9} - hxxps://member.gungho.jp/front/member/webgs/LoadPrgAx.CAB
DPF: {C8F5F737-2683-40B8-BFB6-47B15AC20A79} - hxxps://gash.gamania.co.jp/acxauth/cab/2.0.1/lcjggame.cab
FF - ProfilePath - c:\users\Zero\AppData\Roaming\Mozilla\Firefox\Profiles\nntgdydn.default\
FF - prefs.js: browser.search.selectedEngine - Gelbooru
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: network.proxy.ftp - 127.0.0.1
FF - prefs.js: network.proxy.ftp_port - 55576
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 55576
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 55576
FF - prefs.js: network.proxy.ssl - 127.0.0.1
FF - prefs.js: network.proxy.ssl_port - 55576
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Super_nude_patch_II_1.0 - c:\windows\Super nude patch 3\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"?慴"=hex:b6,6e,f8,0f,8f,5b,8e,86,00,74,cc,31,d2,a9,6c,25,00,2d,b3,45,e3,fb,f0,
73,ae,21,19,51,34,d2,d0,97,5a,cf,33,09,d8,86,6a,2f,a1,18,4b,9d,a4,07,4d,c0,\
"?祥"=hex:a3,b8,1c,b6,88,5e,66,62,23,f3,bc,61,67,a6,61,76
.
[HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1001\Software\SecuROM\License information*]
"datasecu"=hex:e3,18,d6,36,b4,01,b1,41,3c,0b,3b,07,82,c0,1a,18,b2,fc,da,8e,3f,
bc,9d,af,af,a4,d4,99,32,49,6d,b1,d7,90,c1,97,00,84,c7,c5,b6,07,ab,66,f5,f0,\
"rkeysecu"=hex:0d,a3,f0,50,09,3e,af,a0,af,d0,b8,8e,0f,70,d0,94
.
[HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1001\Software\ウ0ケ0ラ0・ォU6・Z0\ン0・・`0~0*0ェ0・・、0・]
@Class="Path"
"Path"="d:\\コスプレ喫茶娘々\\ポリンだま オンライン\\"
"Update"="0"
.
[HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1005\Software\ウ0ケ0ラ0・ォU6・Z0\ン0・・`0~0*0ェ0・・、0・]
"Path"="d:\\コスプレ喫茶娘々\\ポリンだま オンライン\\"
"Update"="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:c4,f1,41,28,bf,88,fa,fe,f2,3b,f5,b3,aa,14,b9,f4,6d,6f,2b,96,1c,
21,79,28,3f,58,f8,07,15,8d,25,82,07,ca,cf,73,e3,d9,cf,c8,1e,f2,13,5f,bc,dc,\
.
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:c4,f1,41,28,bf,88,fa,fe,f2,3b,f5,b3,aa,14,b9,f4,6d,6f,2b,96,1c,
21,79,28,3f,58,f8,07,15,8d,25,82,07,ca,cf,73,e3,d9,cf,c8,1e,f2,13,5f,bc,dc,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(1412)
c:\program files\Stardock\ObjectDock\DockShellHook.dll
c:\program files\RocketDock\RocketDock.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\AUDIODG.EXE
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\windows\SYSTEM32\WISPTIS.EXE
c:\program files\Common Files\microsoft shared\ink\TabTip.exe
c:\program files\Tablet\Pen\Pen_TouchUser.exe
c:\windows\system32\taskhost.exe
c:\program files\Tablet\Pen\Pen_TabletUser.exe
c:\fraps\fraps.exe
c:\windows\system32\conhost.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
c:\program files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
.
**************************************************************************
.
Completion time: 2011-10-24 21:56:05 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-24 13:56
.
Pre-Run: 83,662,188,544 bytes free
Post-Run: 83,876,868,096 bytes free
.
- - End Of File - - EB203A4ABCC007FBF447BD4BCB3A0E2B
Hi Tomk,
Lately, my system's been freezing a lot lately. It'll freeze for a few seconds or minutes, you can also hear the sounds freezing, and then it resumes normal proccess
I already tried updating my Windows and some drivers, but the problem still persists
Then there's also the mysterious file in my C:\Windows\system32\drivers\
Before my trial version of NOD32 expired, it reported something about a zmeianoc7.sys, inside the said directory, and it can't do anything about it
I do not know if the said file is related to the my aforementioned freezing issues, but I'm really worried as to what this file might be, NOD32 kept reporting it as a threat
I tried running a HiJackThis scan, to see if it could help
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:37:59, on 2011/10/26
Platform: Windows 7 SP1 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Fraps\fraps.exe
C:\Windows\Explorer.EXE
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Bamboo Dock\BambooCore.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
D:\Documents - Zero\Rainmeter-1.1-32bit\Rainmeter.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\taskhost.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Yahoo!ツールバーフィッシング警告 - {1F68E72C-50E5-44B8-8F56-6A54D3AF1DA4} - C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\ypho.dll (file missing)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Yahoo!ツールバーヘルパー - {EEBA90E6-2B14-413F-9BF8-61A8BDF92258} - C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\YahooToolBar.dll (file missing)
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Yahoo!ツールバー - {AEF44653-C059-42CB-A5B7-41C640DA4A67} - C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\YahooToolBar.dll (file missing)
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [BambooCore] C:\Program Files\Bamboo Dock\BambooCore.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Steam] "D:\Program Files\Steam\Steam.exe" -silent
O4 - HKUS\S-1-5-21-4208408748-883319235-2440751903-1005\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4208408748-883319235-2440751903-1005\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: Rainmeter - Shortcut.lnk = D:\Documents - Zero\Rainmeter-1.1-32bit\Rainmeter.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
O4 - Global Startup: WDSmartWare.lnk = C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {53F4962A-8E27-4601-8B01-79A82B4D7FC9} (LoadPrg Class) -
https://member.gungho.jp/front/member/webgs/LoadPrgAx.CAB
O16 - DPF: {C8F5F737-2683-40B8-BFB6-47B15AC20A79} (Game Starter Control) -
https://gash.gamania.co.jp/acxauth/cab/2.0.1/lcjggame.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google アップデート サービス (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update サービス (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - http://libusb-win32.sourceforge.net - C:\Windows\system32\libusbd-nt.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Program Files\Tablet\Pen\Pen_Tablet.exe
O23 - Service: Wacom Consumer Touch Service (TouchServicePen) - Wacom Technology, Corp. - C:\Program Files\Tablet\Pen\Pen_TouchService.exe
O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
–
End of file - 7316 bytes
YukiYuki,
Is the behavior that you have described still manifesting since running ComboFix?
Hi Tomk,
The weird IP address seemed to have died off the past weeks
and yes, it's still freezing even after running ComboFix
Let's get an online scan:
ESET Online Scanner:
Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read
here .
Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select
Run as Administrator from the context menu.
Please go here then click on: [external image: Posted Image]
Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image] When prompted allow the Add-On/Active X to install. Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked. Now click on Advanced Settings and select the following:
Scan for potentially unwanted applications Scan for potentially unsafe applications Enable Anti-Stealth Technology Now click on: [external image: Posted Image] The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection. When completed the Online Scan will begin automatically. Do no t touch either the Mouse or keyboard during the scan otherwise it may stall.When completed select Uninstall application on close if you so wish, make sure you copy the logfile first! Now click on: [external image: Posted Image] Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt . Copy and paste that log as a reply to this topic.
Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
Hi Tomk,
I did a scan using ESET Online Scanner
and the Logs are unexpectedly short?
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=2e9704ec8d5aba43a358b385d1763b0c
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-10-28 04:05:56
# local_time=2011-10-29 12:05:56 (+0800, Malay Peninsula Standard Time)
# country="Japan"
# lang=1033
# osver=6.1.7600 NT Service Pack 1
# compatibility_mode=512 16777215 100 0 176383 176383 0 0
# compatibility_mode=5893 16776573 100 94 52015 71442387 0 0
# compatibility_mode=8192 67108863 100 0 2113 2113 0 0
# scanned=246877
# found=5
# cleaned=0
# scan_time=6760
C:\Documents - Bran Flakes\SoftonicDownloader_for_xpadder.exe a variant of Win32/SoftonicDownloader.A application (unable to clean) 00000000000000000000000000000000 I
C:\Documents - Bran Flakes\TDU2 Trainer 1+ v.1027.rar a variant of Win32/HackTool.CheatEngine.AB application (unable to clean) 00000000000000000000000000000000 I
C:\Documents - Bran Flakes\RA3\CommandAndConquerRedAlert3v1.12PLUS12Trainer.rar a variant of Win32/GameHack.O application (unable to clean) 00000000000000000000000000000000 I
C:\Documents - Bran Flakes\RA3\CommandAndConquerRedAlert3v1.12Trainer.zip a variant of Win32/GameHack.F application (unable to clean) 00000000000000000000000000000000 I
C:\Users\Zero\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\551154de-6568a8fc Java/TrojanDownloader.OpenStream.NCM trojan (unable to clean) 00000000000000000000000000000000 I
The log looks correct. It should be pretty short.
Clean out the Java cache:
Go into the Control Panel and double-click the Java Icon.
[external image: Posted Image]
Under Temporary Internet Files, click the Settings… button click the Delete Files button. There are two options in the window to clear the cache - Leave both Checked
Applications and Applets
Trace and Log Files Click OK on Delete Temporary Files Window
Note: This deletes ALL the Downloaded Applications and Applets from the CACHE. Click OK to leave the Temporary Files Settings Click OK to leave the Java Control Panel.
COMBOFIX-Script
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Hi Tomk,
Here are the logs from ComboFix
ComboFix 11-10-29.01 - Zero 2011/10/29 15:32:22.6.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.1.932.81.1033.18.2046.1439 [GMT 8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Zero\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
FILE ::
"c:\documents - bran flakes\SoftonicDownloader_for_xpadder.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents - bran flakes\SoftonicDownloader_for_xpadder.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-09-28 to 2011-10-29 )))))))))))))))))))))))))))))))
.
.
2011-10-29 07:39 . 2011-10-29 07:40 ——– d—–w- c:\users\Zero\AppData\Local\temp
2011-10-29 07:39 . 2011-10-29 07:39 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp
2011-10-29 07:39 . 2011-10-29 07:39 ——– d—–w- c:\users\UpdatusUser.SYNTHESiZE\AppData\Local\temp
2011-10-29 07:39 . 2011-10-29 07:39 ——– d—–w- c:\users\Public\AppData\Local\temp
2011-10-29 07:39 . 2011-10-29 07:39 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-10-27 23:46 . 2011-10-29 00:13 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DA6EBF5A-0141-4B72-AEBC-8033FDA4F36B}\offreg.dll
2011-10-26 15:42 . 1999-03-23 01:12 304128 —-a-w- c:\windows\unin040c.exe
2011-10-26 13:39 . 2011-10-26 13:39 ——– d—–w- c:\program files\Intel
2011-10-26 13:39 . 2008-02-22 12:26 53248 —-a-w- c:\windows\system32\CSVer.dll
2011-10-26 13:39 . 2011-10-26 13:39 ——– d—–w- C:\Intel
2011-10-26 13:36 . 2011-10-26 13:36 388096 —-a-r- c:\users\Zero\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-10-26 13:13 . 2011-10-26 13:13 ——– d—–w- c:\program files\Trend Micro
2011-10-25 18:24 . 2009-03-18 09:35 26176 —ha-w- c:\windows\system32\hamachi.sys
2011-10-25 18:23 . 2011-10-25 18:36 ——– d—–w- c:\users\Zero\AppData\Local\LogMeIn Hamachi
2011-10-25 16:30 . 2011-10-25 16:30 ——– d—–w- c:\users\Zero\AppData\Local\Xenocode
2011-10-25 16:30 . 2011-10-25 16:30 ——– d—–w- c:\program files\Xenocode
2011-10-23 08:19 . 2011-03-02 10:43 175616 —-a-w- c:\windows\system32\unrar.dll
2011-10-23 08:19 . 2011-10-04 08:00 74752 —-a-w- c:\windows\system32\ff_vfw.dll
2011-10-23 08:19 . 2011-07-16 14:17 151552 —-a-w- c:\windows\system32\ac3acm.acm
2011-10-23 08:19 . 2011-06-24 14:44 243200 —-a-w- c:\windows\system32\xvidvfw.dll
2011-10-23 08:19 . 2011-06-24 14:28 650752 —-a-w- c:\windows\system32\xvidcore.dll
2011-10-23 08:19 . 2008-09-24 18:41 839680 —-a-w- c:\windows\system32\lameACM.acm
2011-10-23 06:59 . 2011-09-08 09:48 1152888 —-a-w- c:\windows\system32\WacomMT.dll
2011-10-22 15:07 . 2011-10-07 03:48 6668624 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DA6EBF5A-0141-4B72-AEBC-8033FDA4F36B}\mpengine.dll
2011-10-22 14:58 . 2011-08-27 04:26 571904 —-a-w- c:\windows\system32\oleaut32.dll
2011-10-22 14:58 . 2011-08-27 04:26 233472 —-a-w- c:\windows\system32\oleacc.dll
2011-10-22 14:58 . 2011-08-17 04:24 465408 —-a-w- c:\windows\system32\psisdecd.dll
2011-10-22 14:58 . 2011-08-17 04:19 75776 —-a-w- c:\windows\system32\psisrndr.ax
2011-10-22 14:58 . 2011-09-06 02:28 2334720 —-a-w- c:\windows\system32\win32k.sys
2011-10-19 23:15 . 2011-10-19 23:15 ——– d—–w- c:\program files\Common Files\Java
2011-10-11 11:12 . 2011-10-11 11:12 ——– d—–w- c:\program files\7-Zip
2011-10-11 11:07 . 2011-10-11 12:37 ——– d—–w- c:\users\Zero\AppData\Roaming\DJ Hackers
2011-10-11 11:05 . 2011-10-11 11:09 ——– d—–w- c:\users\Zero\AppData\Roaming\com.zipeg
2011-10-11 11:04 . 2011-10-11 11:04 ——– d—–w- c:\program files\Zipeg
2011-10-08 23:33 . 2011-10-09 21:03 ——– d—–w- c:\users\TEMP
2011-10-07 02:57 . 2011-10-15 00:14 ——– d—–w- C:\Games
2011-09-30 10:16 . 2011-03-25 02:58 258560 —-a-w- c:\windows\system32\drivers\usbhub.sys
2011-09-30 10:16 . 2011-03-25 02:58 284672 —-a-w- c:\windows\system32\drivers\usbport.sys
2011-09-30 10:16 . 2011-03-25 02:58 75776 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2011-09-30 10:16 . 2011-03-25 02:57 43008 —-a-w- c:\windows\system32\drivers\usbehci.sys
2011-09-30 10:16 . 2011-03-25 02:57 20480 —-a-w- c:\windows\system32\drivers\usbohci.sys
2011-09-30 10:16 . 2011-03-25 02:57 24064 —-a-w- c:\windows\system32\drivers\usbuhci.sys
2011-09-30 10:16 . 2011-03-25 02:57 5888 —-a-w- c:\windows\system32\drivers\usbd.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-29 05:06 . 2011-03-18 02:15 428088 —-a-w- c:\windows\system32\drivers\sptd.sys
2011-10-02 21:06 . 2011-02-21 09:43 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-09-27 12:40 . 2011-06-15 01:14 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-08 09:49 . 2011-07-20 09:34 10752 —-a-w- c:\windows\system32\drivers\wacmoumonitor.sys
2011-09-08 09:48 . 2011-07-20 09:34 1156472 —-a-w- c:\windows\system32\Wintab32.dll
2011-09-01 01:12 . 2011-09-01 01:12 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-09-01 01:12 . 2011-09-01 01:12 161792 —-a-w- c:\windows\system32\msls31.dll
2011-09-01 01:12 . 2011-09-01 01:12 86528 —-a-w- c:\windows\system32\iesysprep.dll
2011-09-01 01:12 . 2011-09-01 01:12 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-09-01 01:12 . 2011-09-01 01:12 74752 —-a-w- c:\windows\system32\iesetup.dll
2011-09-01 01:12 . 2011-09-01 01:12 63488 —-a-w- c:\windows\system32\tdc.ocx
2011-09-01 01:12 . 2011-09-01 01:12 48640 —-a-w- c:\windows\system32\mshtmler.dll
2011-09-01 01:12 . 2011-09-01 01:12 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-09-01 01:12 . 2011-09-01 01:12 367104 —-a-w- c:\windows\system32\html.iec
2011-09-01 01:12 . 2011-09-01 01:12 23552 —-a-w- c:\windows\system32\licmgr10.dll
2011-09-01 01:12 . 2011-09-01 01:12 152064 —-a-w- c:\windows\system32\wextract.exe
2011-09-01 01:12 . 2011-09-01 01:12 150528 —-a-w- c:\windows\system32\iexpress.exe
2011-09-01 01:12 . 2011-09-01 01:12 1427456 —-a-w- c:\windows\system32\inetcpl.cpl
2011-09-01 01:12 . 2011-09-01 01:12 110592 —-a-w- c:\windows\system32\IEAdvpack.dll
2011-09-01 01:12 . 2011-09-01 01:12 35840 —-a-w- c:\windows\system32\imgutil.dll
2011-09-01 01:12 . 2011-09-01 01:12 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2011-09-01 01:12 . 2011-09-01 01:12 11776 —-a-w- c:\windows\system32\mshta.exe
2011-09-01 01:12 . 2011-09-01 01:12 101888 —-a-w- c:\windows\system32\admparse.dll
2011-08-31 09:00 . 2011-09-20 22:58 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-08-30 04:04 . 2011-08-30 04:04 45056 —-a-r- c:\users\Zero\AppData\Roaming\Microsoft\Installer\{EC317B1E-FC13-403D-BD0D-B22324DDE414}\NewShortcut3_EC317B1EFC13403DBD0DB22324DDE414_1.exe
2011-08-30 04:04 . 2011-08-30 04:04 45056 —-a-r- c:\users\Zero\AppData\Roaming\Microsoft\Installer\{EC317B1E-FC13-403D-BD0D-B22324DDE414}\NewShortcut1_EC317B1EFC13403DBD0DB22324DDE414_2.exe
2011-08-03 11:50 . 2011-08-25 14:17 914024 —-a-w- c:\windows\system32\nvdispco32.dll
2011-08-03 11:50 . 2011-08-25 14:17 875112 —-a-w- c:\windows\system32\nvgenco32.dll
2011-08-03 11:50 . 2011-08-25 14:17 57960 —-a-w- c:\windows\system32\OpenCL.dll
2011-08-03 11:50 . 2011-08-25 14:17 5404776 —-a-w- c:\windows\system32\nvcuda.dll
2011-08-03 11:50 . 2011-08-25 14:17 2391656 —-a-w- c:\windows\system32\nvcuvid.dll
2011-08-03 11:50 . 2011-08-25 14:17 2090088 —-a-w- c:\windows\system32\nvcuvenc.dll
2011-08-03 11:50 . 2011-08-25 14:17 17193576 —-a-w- c:\windows\system32\nvcompiler.dll
2011-08-03 11:50 . 2011-08-25 14:17 16595560 —-a-w- c:\windows\system32\nvoglv32.dll
2011-08-03 11:50 . 2011-08-25 14:17 10304104 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-08-03 11:50 . 2011-06-17 04:27 12636776 —-a-w- c:\windows\system32\nvd3dum.dll
2011-08-03 11:50 . 2011-04-07 14:45 600680 —-a-w- c:\windows\system32\easyUpdatusAPIU.dll
2011-08-03 11:50 . 2011-04-07 14:45 599144 —-a-w- c:\windows\system32\nvvsvc.exe
2011-08-03 11:50 . 2011-04-07 14:45 111208 —-a-w- c:\windows\system32\nvmctray.dll
2011-08-03 11:50 . 2011-04-07 14:44 3730024 —-a-w- c:\windows\system32\nvcpl.dll
2011-08-03 11:50 . 2011-04-07 14:44 2558568 —-a-w- c:\windows\system32\nvsvc.dll
2011-08-03 11:50 . 2011-02-21 09:13 2412136 —-a-w- c:\windows\system32\nvapi.dll
2011-08-03 11:50 . 2011-01-07 13:06 66664 —-a-w- c:\windows\system32\nvshext.dll
2011-08-03 11:50 . 2009-07-13 22:09 6613096 —-a-w- c:\windows\system32\nvwgf2um.dll
2011-08-02 19:31 . 2011-08-02 19:31 311912 —-a-w- c:\windows\system32\nvStreaming.exe
2011-09-30 13:31 . 2011-06-01 05:42 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
[-] 2010-11-20 . BE8C64439F1E2AF088063218C16EB9FE . 811520 . . [6.1.7601.17514] . . c:\windows\System32\user32.dll
.
[7] 2011-06-23 . 3624D782F8B061B6FBA3A35E2FE53CFD . 3967872 . . [6.1.7601.21755] . . c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21755_none_6e972ad72ba2517f\ntkrnlpa.exe
[7] 2011-06-23 . A4A8EF2ACE5FA5863AA0B04C9BBFECA7 . 3967872 . . [6.1.7601.17640] . . c:\windows\ERDNT\cache\ntkrnlpa.exe
[7] 2011-06-23 . A4A8EF2ACE5FA5863AA0B04C9BBFECA7 . 3967872 . . [6.1.7601.17640] . . c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17640_none_6e135c8612811711\ntkrnlpa.exe
[7] 2011-04-09 . 102A6182087B18C795664BCD22EB52E9 . 3967872 . . [6.1.7601.17592] . . c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17592_none_6ddf4b9812a7d84d\ntkrnlpa.exe
[7] 2011-04-09 . 9CF7F5D025183FA10E130445BC071B70 . 3967872 . . [6.1.7601.21701] . . c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21701_none_6ec9394b2b7d606e\ntkrnlpa.exe
[7] 2010-11-20 . 144BD78C6103C8616DE047B3532142DB . 3966848 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17514_none_6e37cb8c12652b73\ntkrnlpa.exe
[-] 2010-11-20 . 6BB5D70720DB62A363404836140C97E6 . 3958792 . . [6.1.7600.20738] . . c:\windows\System32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-11-18 10:40 1196936 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-02-24 395640]
"Steam"="d:\program files\Steam\Steam.exe" [2011-10-26 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-05 500208]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-21 406992]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-03-22 74752]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"BambooCore"="c:\program files\Bamboo Dock\BambooCore.exe" [2011-07-20 629848]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
c:\users\Zero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Rainmeter - Shortcut.lnk - d:\documents - zero\Rainmeter-1.1-32bit\Rainmeter.exe [2010-2-19 119296]
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2011-3-13 3450608]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-11-13 2057536]
WDSmartWare.lnk - c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-11-13 9117504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^Users^Zero^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^hamachi.lnk]
path=c:\users\Zero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hamachi.lnk
backup=c:\windows\pss\hamachi.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-10-26 02:10 1242448 —-a-w- d:\program files\Steam\Steam.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google アップデート サービス (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47 136176]
R3 1394hub;1394 Enabled Hub;c:\windows\System32\svchost.exe [2009-07-14 20992]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-07-15 14216]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-07-15 8456]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files\Garena Classic\safedrv.sys [x]
R3 gupdatem;Google Update サービス (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47 136176]
R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys [2010-03-10 25112]
R3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNt.sys [2009-10-13 133632]
R3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2009-07-13 79360]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2011-06-19 4122968]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-20 77184]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-20 25600]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-20 112640]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2011-09-08 10752]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2008-05-06 11520]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-05-09 218688]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;c:\windows\system32\libusbd-nt.exe [2005-03-09 18944]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-08-02 379496]
S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2010-10-26 4869488]
S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2010-10-26 416112]
S2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-11-13 110592]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2005-03-09 33792]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-06-23 275048]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47]
.
2011-10-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://dn.gamania.co.jp/index.aspx
uInternet Settings,ProxyServer = http=127.0.0.1:55576
TCP: DhcpNameServer = [removed] [removed]
DPF: {53F4962A-8E27-4601-8B01-79A82B4D7FC9} - hxxps://member.gungho.jp/front/member/webgs/LoadPrgAx.CAB
DPF: {C8F5F737-2683-40B8-BFB6-47B15AC20A79} - hxxps://gash.gamania.co.jp/acxauth/cab/2.0.1/lcjggame.cab
FF - ProfilePath - c:\users\Zero\AppData\Roaming\Mozilla\Firefox\Profiles\nntgdydn.default\
FF - prefs.js: browser.search.selectedEngine - Gelbooru
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: network.proxy.ftp - 127.0.0.1
FF - prefs.js: network.proxy.ftp_port - 55576
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 55576
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 55576
FF - prefs.js: network.proxy.ssl - 127.0.0.1
FF - prefs.js: network.proxy.ssl_port - 55576
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Counter-Strike - d:\program files\Counter-Strike\Uninstall Counter-Strike.exe
AddRemove-Half-Life Primary Server 4.1.1.1 - d:\progra~1\Valve\hlds\UNWISE.EXE
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"?慴"=hex:b6,6e,f8,0f,8f,5b,8e,86,00,74,cc,31,d2,a9,6c,25,00,2d,b3,45,e3,fb,f0,
73,ae,21,19,51,34,d2,d0,97,5a,cf,33,09,d8,86,6a,2f,a1,18,4b,9d,a4,07,4d,c0,\
"?祥"=hex:a3,b8,1c,b6,88,5e,66,62,23,f3,bc,61,67,a6,61,76
.
[HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1001\Software\SecuROM\License information*]
"datasecu"=hex:e3,18,d6,36,b4,01,b1,41,3c,0b,3b,07,82,c0,1a,18,b2,fc,da,8e,3f,
bc,9d,af,af,a4,d4,99,32,49,6d,b1,d7,90,c1,97,00,84,c7,c5,b6,07,ab,66,f5,f0,\
"rkeysecu"=hex:0d,a3,f0,50,09,3e,af,a0,af,d0,b8,8e,0f,70,d0,94
.
[HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1001\Software\ウ0ケ0ラ0・ォU6・Z0\ン0・・`0~0*0ェ0・・、0・]
@Class="Path"
"Path"="d:\\コスプレ喫茶娘々\\ポリンだま オンライン\\"
"Update"="0"
.
[HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1005\Software\ウ0ケ0ラ0・ォU6・Z0\ン0・・`0~0*0ェ0・・、0・]
"Path"="d:\\コスプレ喫茶娘々\\ポリンだま オンライン\\"
"Update"="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:c4,f1,41,28,bf,88,fa,fe,f2,3b,f5,b3,aa,14,b9,f4,6d,6f,2b,96,1c,
21,79,28,3f,58,f8,07,15,8d,25,82,07,ca,cf,73,e3,d9,cf,c8,1e,f2,13,5f,bc,dc,\
.
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:c4,f1,41,28,bf,88,fa,fe,f2,3b,f5,b3,aa,14,b9,f4,6d,6f,2b,96,1c,
21,79,28,3f,58,f8,07,15,8d,25,82,07,ca,cf,73,e3,d9,cf,c8,1e,f2,13,5f,bc,dc,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-10-29 15:43:01
ComboFix-quarantined-files.txt 2011-10-29 07:43
ComboFix2.txt 2011-10-24 13:56
.
Pre-Run: 103,605,481,472 bytes free
Post-Run: 103,713,427,456 bytes free
.
- - End Of File - - 428B324602DA3F62DFF2580B10323E84
Hi Tomk,
Malwarebyte's Anti Malware didn't detect any malicious items
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8041
Windows 6.1.7600 Service Pack 1
Internet Explorer 9.0.8112.16421
2011/10/29 23:59:37
mbam-log-2011-10-29 (23-59-36).txt
Scan type: Quick scan
Objects scanned: 211673
Time elapsed: 3 minute(s), 49 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)