This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

baseline [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Merged 3 post



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:44:07 AM, on 4/20/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:Windowssystem32taskhost.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program FilesCommon FilesJavaJava Updatejusched.exe
C:Program FilesRealtekAudioHDARtHDVCpl.exe
C:UsersbizAppDataRoamingGoogleGoogle Talkgoogletalk.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesSynapticsSynTPSynTPHelper.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesMozilla Firefoxplugin-container.exe
C:Windowssystem32SearchFilterHost.exe
D:DOWNLOADHiJackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:Program FilesuTorrentBarprxtbuTor.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - (no file)
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll
O2 - BHO: uTorrentBar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:Program FilesuTorrentBarprxtbuTor.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre6binjp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - (no file)
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:Program FilesuTorrentBarprxtbuTor.dll
O4 - HKLM..Run: [SynTPEnh] C:Program FilesSynapticsSynTPSynTPEnh.exe
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesCommon FilesJavaJava Updatejusched.exe"
O4 - HKLM..Run: [RTHDVCPL] C:Program FilesRealtekAudioHDARtHDVCpl.exe -s
O4 - HKLM..Run: [Adobe ARM] "C:Program FilesCommon FilesAdobeARM1.0AdobeARM.exe"
O4 - HKCU..Run: [googletalk] C:UsersbizAppDataRoamingGoogleGoogle Talkgoogletalk.exe /autostart
O4 - HKCU..Run: [Google Update] "C:UsersbizAppDataLocalGoogleUpdateGoogleUpdate.exe" /c
O4 - HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /minimized /regrun
O4 - HKUSS-1-5-21-624239619-2511677762-1314868306-1003..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUSS-1-5-21-624239619-2511677762-1314868306-1003..RunOnce: [mctadmin] C:WindowsSystem32mctadmin.exe (User 'UpdatusUser')
O4 - HKUSS-1-5-18..Run: [PC Health Status] C:Windowssystem32configsystemprofileAppDataRoamingtqmoqdpr.exe (User 'SYSTEM')
O4 - HKUS.DEFAULT..Run: [PC Health Status] C:Windowssystem32configsystemprofileAppDataRoamingtqmoqdpr.exe (User 'Default user')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20614.www2.hp.com/ediags/gmd/Insta…hpdetect118.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:Program FilesCommon FilesAdobeARM1.0armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:Windowssystem32MacromedFlashFlashPlayerUpdateService.exe
O23 - Service: ESET Service (ekrn) - Unknown owner - C:Program FilesESETESET Smart Securityekrn.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:Windowssystem32nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:Program FilesNVIDIA CorporationNVIDIA Updatusdaemonu.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:Program FilesSkypeUpdaterUpdater.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:Program FilesTeamViewerVersion7TeamViewer_Service.exe

–
End of file - 6047 bytes

StartupList report, 4/20/2012, 11:46:44 AM
StartupList version: 1.52.2
Started from : D:DOWNLOADHiJackThis.EXE
Detected: Windows 7 SP1 (WinNT 6.00.3505)
Detected: Internet Explorer v9.00 (9.00.8112.16421)
* Using default options
==================================================

Running processes:

C:Windowssystem32taskhost.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program FilesCommon FilesJavaJava Updatejusched.exe
C:Program FilesRealtekAudioHDARtHDVCpl.exe
C:UsersbizAppDataRoamingGoogleGoogle Talkgoogletalk.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesSynapticsSynTPSynTPHelper.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesMozilla Firefoxplugin-container.exe
D:DOWNLOADHiJackThis.exe
C:Windowssystem32NOTEPAD.EXE
C:Windowssystem32SearchFilterHost.exe

————————————————–

Checking Windows NT UserInit:

[HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogon]
UserInit = C:Windowssystem32userinit.exe,

————————————————–

Autorun entries from Registry:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun

SynTPEnh = C:Program FilesSynapticsSynTPSynTPEnh.exe
(Default) =
SunJavaUpdateSched = "C:Program FilesCommon FilesJavaJava Updatejusched.exe"
RTHDVCPL = C:Program FilesRealtekAudioHDARtHDVCpl.exe -s
Adobe ARM = "C:Program FilesCommon FilesAdobeARM1.0AdobeARM.exe"

————————————————–

Autorun entries from Registry:
HKCUSoftwareMicrosoftWindowsCurrentVersionRun

googletalk = C:UsersbizAppDataRoamingGoogleGoogle Talkgoogletalk.exe /autostart
Google Update = "C:UsersbizAppDataLocalGoogleUpdateGoogleUpdate.exe" /c
Skype = "C:Program FilesSkypePhoneSkype.exe" /minimized /regrun

————————————————–

Shell & screensaver key from C:WindowsSYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=explorer.exe
SCRNSAVE.EXE=C:Windowssystem32scrnsave.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU..Policies: Shell=*Registry value not found*
HKLM..Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

AcroIEHelperStub - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
IEVkbdBHO - (no file) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}
SkypeIEPluginBHO - C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
uTorrentBar - C:Program FilesuTorrentBarprxtbuTor.dll - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
(no name) - C:Program FilesJavajre6binjp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}
link filter bho - (no file) - {E33CF602-D945-461A-83F0-819F76A199F8}

————————————————–

Enumerating Task Scheduler jobs:

Adobe Flash Player Updater.job
GoogleUpdateTaskUserS-1-5-21-624239619-2511677762-1314868306-1001Core.job
GoogleUpdateTaskUserS-1-5-21-624239619-2511677762-1314868306-1001UA.job

————————————————–

Enumerating Download Program Files:

[GMNRev Class]
InProcServer32 = C:Program FilesHPCommonHPGMNRev.dll
CODEBASE = http://h20614.www2.hp.com/ediags/gmd/Insta…hpdetect118.cab

[Shockwave Flash Object]
InProcServer32 = C:Windowssystem32MacromedFlashFlash32_11_2_202_233.ocx
CODEBASE = http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab

————————————————–

Enumerating Winsock LSP files:

NameSpace #2: C:Windowssystem32napinsp.dll
NameSpace #3: C:Windowssystem32pnrpnsp.dll
NameSpace #4: C:Windowssystem32pnrpnsp.dll
NameSpace #5: C:Windowssystem32wshbth.dll

————————————————–

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:ProgramDataMalwarebytesMalwarebytes' Anti-Malwarecleanup.old


————————————————–

Enumerating ShellServiceObjectDelayLoad items:

WebCheck: *Registry key not found*

————————————————–
End of report, 5,298 bytes
Report generated in 0.015 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Run by [removed] at 11:58:53 on 2012-04-20
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3070.1571 [GMT -7:00]
.
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:Windowssystem32wininit.exe
C:Windowssystem32lsm.exe
C:Windowssystem32svchost.exe -k DcomLaunch
C:Windowssystem32nvvsvc.exe
C:Windowssystem32svchost.exe -k RPCSS
C:WindowsSystem32svchost.exe -k LocalServiceNetworkRestricted
C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted
C:Windowssystem32svchost.exe -k netsvcs
C:Windowssystem32svchost.exe -k LocalService
C:Windowssystem32svchost.exe -k NetworkService
C:WindowsSystem32spoolsv.exe
C:Program FilesCommon FilesAdobeARM1.0armsvc.exe
C:Windowssystem32svchost.exe -k apphost
C:WindowsSystem32svchost.exe -k LocalServiceNoNetwork
C:Windowssystem32svchost.exe -k LocalServiceAndNoImpersonation
C:Program FilesTeamViewerVersion7TeamViewer_Service.exe
C:Windowssystem32svchost.exe -k iissvcs
C:WindowsSystem32svchost.exe -k secsvcs
C:Windowssystem32svchost.exe -k bthsvcs
C:Program FilesNVIDIA CorporationNVIDIA Updatusdaemonu.exe
C:Program FilesWindows Media Playerwmpnetwk.exe
C:Windowssystem32SearchIndexer.exe
C:Windowssystem32SearchProtocolHost.exe
C:Windowssystem32taskhost.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program FilesCommon FilesJavaJava Updatejusched.exe
C:Program FilesRealtekAudioHDARtHDVCpl.exe
C:UsersbizAppDataRoamingGoogleGoogle Talkgoogletalk.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesSynapticsSynTPSynTPHelper.exe
C:WindowsSystem32svchost.exe -k LocalServicePeerNet
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesMozilla Firefoxplugin-container.exe
D:DOWNLOADHiJackThis.exe
C:Windowssystem32NOTEPAD.EXE
C:WindowsSystem32notepad.exe
C:Windowsexplorer.exe
C:Windowssystem32taskmgr.exe
D:DOWNLOADOTL step1 of malwarecheck.exe
C:Windowssystem32wbemwmiprvse.exe
C:Windowssystem32vssvc.exe
C:WindowsSystem32svchost.exe -k swprv
C:Windowssystem32SearchFilterHost.exe
C:Windowssystem32conhost.exe
.
============== Pseudo HJT Report ===============
.
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:program filesutorrentbarprxtbuTor.dll
mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:program filesutorrentbarprxtbuTor.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll
BHO: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - No File
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dll
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:program filesutorrentbarprxtbuTor.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:program filesjavajre6binjp2ssv.dll
BHO: {E33CF602-D945-461A-83F0-819F76A199F8} - No File
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:program filesutorrentbarprxtbuTor.dll
uRun: [googletalk] c:usersbizappdataroaminggooglegoogle talkgoogletalk.exe /autostart
uRun: [Google Update] "c:usersbizappdatalocalgoogleupdateGoogleUpdate.exe" /c
uRun: [Skype] "c:program filesskypephoneSkype.exe" /minimized /regrun
mRun: [SynTPEnh] c:program filessynapticssyntpSynTPEnh.exe
mRun: []
mRun: [SunJavaUpdateSched] "c:program filescommon filesjavajava updatejusched.exe"
mRun: [RTHDVCPL] c:program filesrealtekaudiohdaRtHDVCpl.exe -s
mRun: [Adobe ARM] "c:program filescommon filesadobearm1.0AdobeARM.exe"
dRun: [PC Health Status] c:windowssystem32configsystemprofileappdataroamingtqmoqdpr.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:progra~1micros~2office11EXCEL.EXE/3000
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:progra~1micros~2office11REFIEBAR.DLL
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect118.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces{C0A5B743-1DAE-40FB-8EB5-65295A7A55F6} : DhcpNameServer = 192.168.0.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:progra~1common~1skypeSKYPE4~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:usersbizappdataroamingmozillafirefoxprofilesjy6mjvhh.bizlaptop
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource;=2&q;=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:program filesadobereader 10.0readerairnppdf32.dll
FF - plugin: c:program filesjavajre6binnew_pluginnpdeployJava1.dll
FF - plugin: c:usersbizappdatalocalgoogleupdate1.3.21.111npGoogleUpdate3.dll
FF - plugin: c:usersbizappdataroamingmozillapluginsnpgoogletalk.dll
FF - plugin: c:usersbizappdataroamingmozillapluginsnpgtpo3dautoplugin.dll
FF - plugin: c:windowssystem32macromedflashNPSWF32_11_2_202_233.dll
.
============= SERVICES / DRIVERS ===============
.
R2 AdobeARMservice;Adobe Acrobat Update Service;c:program filescommon filesadobearm1.0armsvc.exe [2012-1-3 63928]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:program filesnvidia corporationnvidia updatusdaemonu.exe [2011-12-2 2253120]
R2 TeamViewer7;TeamViewer 7;c:program filesteamviewerversion7TeamViewer_Service.exe [2012-4-2 2666880]
R3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:windowssystem32driversnetw5v32.sys [2009-6-10 4231168]
R3 RTL8167;Realtek 8167 NT Driver;c:windowssystem32driversRt86win7.sys [2009-3-2 139776]
S2 ekrn;ESET Service;"c:program fileseseteset smart securityekrn.exe" –> c:program fileseseteset smart securityekrn.exe [?]
S2 SkypeUpdate;Skype Updater;c:program filesskypeupdaterUpdater.exe [2012-4-5 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:windowssystem32macromedflashFlashPlayerUpdateService.exe [2012-4-2 253088]
S3 ATSwpWDF;AuthenTec TruePrint USB WBF WDF Driver;c:windowssystem32driversATSwpWDF.sys [2009-12-3 625224]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:windowssystem32driversb57nd60x.sys [2009-7-13 229888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:windowssystem32driversrdpvideominiport.sys [2011-12-2 15872]
S3 TsUsbFlt;TsUsbFlt;c:windowssystem32driversTsUsbFlt.sys [2011-12-2 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:windowssystem32watWatAdminSvc.exe [2011-12-4 1343400]
.
=============== Created Last 30 ================
.
2012-04-20 18:36:10 ——– d—–w- c:programdataboost_interprocess
2012-04-20 17:46:05 ——– d—–w- c:usersbizappdataroamingMalwarebytes
2012-04-20 17:46:03 ——– d—–w- c:programdataMalwarebytes
2012-04-20 05:10:21 56200 —-a-w- c:programdatamicrosoftwindows defenderdefinition updates{0730dad9-ebe7-4d5e-be93-221ac68af987}offreg.dll
2012-04-20 04:12:28 42720 —-a-w- c:windowssystem32epfwdata.bin
2012-04-19 08:26:49 ——– d—–w- c:program filesESET
2012-04-19 07:59:33 ——– d—–w- c:windowssystem32BestPractices
2012-04-19 07:59:22 ——– d—–w- C:inetpub
2012-04-19 07:42:39 98816 —-a-w- c:windowssed.exe
2012-04-19 07:42:39 518144 —-a-w- c:windowsSWREG.exe
2012-04-19 07:42:39 256000 —-a-w- c:windowsPEV.exe
2012-04-19 07:42:39 208896 —-a-w- c:windowsMBR.exe
2012-04-19 07:42:20 ——– d-s—w- C:ComboFix
2012-04-17 08:46:59 19824 —-a-w- c:windowssystem32driversfs_rec.sys
2012-04-17 08:46:58 5120 —-a-w- c:windowssystem32wmi.dll
2012-04-17 08:46:58 172544 —-a-w- c:windowssystem32wintrust.dll
2012-04-17 08:46:58 159232 —-a-w- c:windowssystem32imagehlp.dll
2012-04-09 18:22:30 4916384 —-a-w- c:program filesmozilla firefoxextensions{82af8dca-6de9-405d-bd5e-43525bdad38a}componentsSkypeFfComponent.dll
2012-04-03 02:39:38 ——– d—–w- c:program filesTeamViewer
2012-04-03 02:35:42 ——– d—–w- c:usersbizappdataroamingTeamViewer
2012-04-03 00:40:39 418464 —-a-w- c:windowssystem32FlashPlayerApp.exe
2012-03-30 17:19:18 592824 —-a-w- c:program filesmozilla firefoxgkmedias.dll
2012-03-30 17:19:18 44472 —-a-w- c:program filesmozilla firefoxmozglue.dll
2012-03-30 17:12:33 ——– d—–w- c:usersbizappdataroamingMetaQuotes
2012-03-30 08:33:34 0 –sha-w- c:windowssystem32dds_trash_log.cmd
2012-03-29 06:19:22 6582328 —-a-w- c:programdatamicrosoftwindows defenderdefinition updates{0730dad9-ebe7-4d5e-be93-221ac68af987}mpengine.dll
2012-03-25 06:59:35 ——– d—–w- c:usersbizappdataroamingKeePass
.
==================== Find3M ====================
.
2012-04-20 06:57:56 187904 —-a-w- c:windowssystem32driversnetbt.sys
2012-04-17 08:43:56 70304 —-a-w- c:windowssystem32FlashPlayerCPLApp.cpl
2012-02-28 01:18:55 1799168 —-a-w- c:windowssystem32jscript9.dll
2012-02-28 01:11:21 1427456 —-a-w- c:windowssystem32inetcpl.cpl
2012-02-28 01:11:07 1127424 —-a-w- c:windowssystem32wininet.dll
2012-02-28 01:03:16 2382848 —-a-w- c:windowssystem32mshtml.tlb
2012-02-23 16:18:36 237072 ——w- c:windowssystem32MpSigStub.exe
2012-02-17 05:34:22 919040 —-a-w- c:windowssystem32rdpcorets.dll
2012-02-17 05:34:22 826880 —-a-w- c:windowssystem32rdpcore.dll
2012-02-17 04:14:08 183808 —-a-w- c:windowssystem32driversrdpwd.sys
2012-02-17 04:13:22 24576 —-a-w- c:windowssystem32driverstdtcp.sys
2012-02-10 05:38:43 1077248 —-a-w- c:windowssystem32DWrite.dll
2012-02-03 03:54:27 2343424 —-a-w- c:windowssystem32win32k.sys
2012-01-25 05:32:35 58880 —-a-w- c:windowssystem32rdpwsx.dll
2012-01-25 05:32:34 129536 —-a-w- c:windowssystem32rdpcorekmts.dll
2012-01-25 05:27:51 8192 —-a-w- c:windowssystem32rdrmemptylst.exe
.
============= FINISH: 11:59:51.11 ===============

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI