Hi WTT folks!
I hope you are well and not to busy, especially since I require some assistance in a particularly scary occurrence.
Today I logged into my facebook only to find that my account was "locked" due to an attempted log-in from a location I have not previously logged into. The location was Japan. I am most certain that there is no good reason that someone in Japan (or possibly elsewhere and spoofing their address) had my facebook password and tried to log-in to my account. I certainly know I haven't shared my password with anyone and I rarely use facebook on any machine but my own (and my work machine, mentioned below).
My hope is that it was not an actual keylogging but just that my roughly 5 year old password (that was also the same for many other sites in my high school years) was leaked from another site. I know, terrible habits. But nonetheless I would like to make absolutely certain my machine is clean. Unfortunately I also have a machine in my office which I do use frequently and could have been the victim. I imagine I should start a separate post for that machine but is it ok to have two ongoing for the same issue? I would assume so given the scenario but I just thought I'd check and see if we couldn't do both machines in the same thread or something to that effect.
But down to business. Since I discovered the unknown log-in, I've obviously changed my facebook password and I have cleared much of my temp data/cache with CCleaner. I am also in the process of running a full Microsoft Security scan. I doubt it will turn up anything and other than running MalwareBytes and SuperAntispyware that is the extent of my malware removing capabilities. I imagine keyloggers are a bit harder to detect than your average virus and I am hoping that those of you experienced with these things will have some strong tools (and eyes) that can actually catch this thing if I am indeed infected with it. I would appreciate being able to browse with my laptop again and feel secure!
Lastly, here is my DDS log.
I do not see how to attach the "Attach.txt" and the basic malware posting instructions don't mention posting it so I am leaving it off unless requested (I have it saved).
Many thanks.
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 22:53:56.14 on Fri 11/09/2012
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.4023.2084 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\PROGRA~2\PHAROS~1\Core\CTskMstr.exe
C:\Windows\System32\svchost.exe -k HPZ12
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
C:\Windows\system32\svchost.exe -k iissvcs
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.123\GoogleCrashHandler.exe
C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.123\GoogleCrashHandler64.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Daniel\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\System32\osk.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [Google Update] "C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\Users\Daniel\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect118.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
mRun-x64: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2012-8-30 228768]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-8-11 140672]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [2009-3-2 89600]
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2011-5-13 30520]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2011-4-27 128456]
R2 TeamViewer7;TeamViewer 7;C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-8-24 2848168]
R2 vpnagent;Cisco AnyConnect Secure Mobility Agent;C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [2012-6-7 478712]
R3 enecir;ENE CIR Receiver;C:\Windows\System32\drivers\enecir.sys [2009-6-28 70656]
R3 JMCR;JMCR;C:\Windows\System32\drivers\jmcr.sys [2009-7-20 140712]
R3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETw5s64.sys [2010-1-13 7675392]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-9-12 368896]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
S3 acsock;acsock;C:\Windows\System32\drivers\acsock64.sys [2012-6-7 107432]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-5 250808]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2011-4-12 71168]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 31125880]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-2 19456]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-3-20 291328]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-11-2 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2012-11-2 30208]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-2-15 52736]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-3-20 1255736]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2009-7-22 61976]
S4 RsFx0105;RsFx0105 Driver;C:\Windows\System32\drivers\RsFx0105.sys [2011-9-22 311144]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-9-22 431464]
.
=============== Created Last 30 ================
.
2012-11-10 03:37:27 69000 —-a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{26F65854-7768-4482-9352-6C3823926384}\offreg.dll
2012-11-10 03:29:46 9291768 —-a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{26F65854-7768-4482-9352-6C3823926384}\mpengine.dll
2012-11-08 04:42:38 9291768 ——w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-07 04:10:00 77656 —-a-w- C:\Windows\System32\XAPOFX1_5.dll
2012-11-07 04:10:00 74072 —-a-w- C:\Windows\SysWow64\XAPOFX1_5.dll
2012-11-07 04:10:00 527192 —-a-w- C:\Windows\SysWow64\XAudio2_7.dll
2012-11-07 04:10:00 518488 —-a-w- C:\Windows\System32\XAudio2_7.dll
2012-11-07 04:10:00 239960 —-a-w- C:\Windows\SysWow64\xactengine3_7.dll
2012-11-07 04:10:00 176984 —-a-w- C:\Windows\System32\xactengine3_7.dll
2012-11-03 02:59:42 458712 —-a-w- C:\Windows\System32\drivers\cng.sys
2012-11-03 02:59:42 340992 —-a-w- C:\Windows\System32\schannel.dll
2012-11-03 02:59:42 307200 —-a-w- C:\Windows\System32\ncrypt.dll
2012-11-03 02:59:42 247808 —-a-w- C:\Windows\SysWow64\schannel.dll
2012-11-03 02:59:41 96768 —-a-w- C:\Windows\SysWow64\sspicli.dll
2012-11-03 02:59:41 220160 —-a-w- C:\Windows\SysWow64\ncrypt.dll
2012-11-03 02:59:41 22016 —-a-w- C:\Windows\SysWow64\secur32.dll
2012-11-03 02:59:41 154480 —-a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-11-03 02:59:41 1448448 —-a-w- C:\Windows\System32\lsasrv.dll
2012-10-27 03:29:49 ——– d—–w- C:\Users\Daniel\51FB15F4AD2743BCAD4BDD0354FB6BBD.TMP
2012-10-27 02:34:57 ——– d—–w- C:\Users\Daniel\AppData\Local\Cisco
2012-10-27 02:34:57 ——– d—–w- C:\Program Files (x86)\Cisco
2012-10-27 02:34:40 ——– d—–w- C:\PROGRA~3\Cisco
2012-10-26 00:19:48 ——– d—–w- C:\Program Files (x86)\SystemRequirementsLab
2012-10-25 03:21:45 ——– d—–w- C:\Users\Daniel\AppData\Local\Ubisoft Game Launcher
2012-10-25 03:12:01 ——– d—–w- C:\Users\Daniel\AppData\Roaming\Ubisoft
2012-10-20 14:33:19 972192 ——w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{1CC11A0E-7FC9-4556-9820-38C1A4400A84}\gapaengine.dll
.
==================== Find3M ====================
.
2012-10-10 03:44:27 73656 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-10 03:44:27 696760 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-09-14 19:19:29 2048 —-a-w- C:\Windows\System32\tzres.dll
2012-09-14 18:28:53 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2012-09-07 21:04:46 25928 —-a-w- C:\Windows\System32\drivers\mbam.sys
2012-09-05 21:13:20 108008 —-a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2012-09-05 21:13:19 1034216 —-a-w- C:\Windows\System32\npDeployJava1.dll
2012-09-05 21:13:18 916456 —-a-w- C:\Windows\System32\deployJava1.dll
2012-08-31 18:19:35 1659760 —-a-w- C:\Windows\System32\drivers\ntfs.sys
2012-08-31 04:03:31 95208 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2012-08-31 04:03:28 821736 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-08-31 04:03:28 746984 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2012-08-31 02:03:48 228768 —-a-w- C:\Windows\System32\drivers\MpFilter.sys
2012-08-31 02:03:48 128456 —-a-w- C:\Windows\System32\drivers\NisDrvWFP.sys
2012-08-30 18:03:45 5559664 —-a-w- C:\Windows\System32\ntoskrnl.exe
2012-08-30 17:12:02 3968880 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:12:02 3914096 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-08-24 18:05:07 220160 —-a-w- C:\Windows\System32\wintrust.dll
2012-08-24 16:57:48 172544 —-a-w- C:\Windows\SysWow64\wintrust.dll
2012-08-24 10:31:32 2312704 —-a-w- C:\Windows\System32\jscript9.dll
2012-08-24 10:21:18 1392128 —-a-w- C:\Windows\System32\wininet.dll
2012-08-24 10:20:11 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl
2012-08-24 10:14:45 173056 —-a-w- C:\Windows\System32\ieUnatt.exe
2012-08-24 10:13:29 599040 —-a-w- C:\Windows\System32\vbscript.dll
2012-08-24 10:09:42 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2012-08-24 06:59:17 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll
2012-08-24 06:51:27 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll
2012-08-24 06:51:02 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-08-24 06:47:26 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-08-24 06:47:12 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll
2012-08-24 06:43:58 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2012-08-23 14:13:11 243200 —-a-w- C:\Windows\System32\rdpudd.dll
2012-08-23 14:10:20 19456 —-a-w- C:\Windows\System32\drivers\rdpvideominiport.sys
2012-08-23 14:08:26 30208 —-a-w- C:\Windows\System32\drivers\TsUsbGD.sys
2012-08-23 14:07:35 57856 —-a-w- C:\Windows\System32\drivers\TsUsbFlt.sys
2012-08-23 13:47:20 46592 —-a-w- C:\Windows\SysWow64\MsRdpWebAccess.dll
2012-08-23 13:46:20 16896 —-a-w- C:\Windows\SysWow64\wksprtPS.dll
2012-08-23 13:41:52 13312 —-a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
2012-08-23 13:40:56 13312 —-a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2012-08-23 13:24:57 15360 —-a-w- C:\Windows\System32\RdpGroupPolicyExtension.dll
2012-08-23 13:20:40 54272 —-a-w- C:\Windows\System32\MsRdpWebAccess.dll
2012-08-23 13:18:14 37376 —-a-w- C:\Windows\SysWow64\tsgqec.dll
2012-08-23 13:17:54 18432 —-a-w- C:\Windows\System32\wksprtPS.dll
2012-08-23 13:06:58 43520 —-a-w- C:\Windows\System32\TsUsbGDCoInstaller.dll
2012-08-23 12:52:53 44032 —-a-w- C:\Windows\System32\tsgqec.dll
2012-08-23 11:20:06 62976 —-a-w- C:\Windows\System32\TSWbPrxy.exe
2012-08-23 11:15:57 269312 —-a-w- C:\Windows\SysWow64\aaclient.dll
2012-08-23 11:14:09 384000 —-a-w- C:\Windows\System32\wksprt.exe
2012-08-23 11:12:17 192000 —-a-w- C:\Windows\SysWow64\rdpendp_winip.dll
2012-08-23 10:54:24 322560 —-a-w- C:\Windows\System32\aaclient.dll
2012-08-23 10:51:14 228864 —-a-w- C:\Windows\System32\rdpendp_winip.dll
2012-08-23 10:39:24 1048064 —-a-w- C:\Windows\SysWow64\mstsc.exe
2012-08-23 10:22:22 1123840 —-a-w- C:\Windows\System32\mstsc.exe
2012-08-23 09:51:57 3174912 —-a-w- C:\Windows\System32\rdpcorets.dll
2012-08-23 08:19:01 4916224 —-a-w- C:\Windows\SysWow64\mstscax.dll
2012-08-23 08:13:07 5773824 —-a-w- C:\Windows\System32\mstscax.dll
2012-08-22 18:12:50 1913200 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2012-08-22 18:12:40 950128 —-a-w- C:\Windows\System32\drivers\ndis.sys
2012-08-22 18:12:40 376688 —-a-w- C:\Windows\System32\drivers\netio.sys
2012-08-22 18:12:33 288624 —-a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2012-08-21 21:01:00 245760 —-a-w- C:\Windows\System32\OxpsConverter.exe
2012-08-20 18:48:44 362496 —-a-w- C:\Windows\System32\wow64win.dll
2012-08-20 18:48:44 243200 —-a-w- C:\Windows\System32\wow64.dll
2012-08-20 18:48:44 13312 —-a-w- C:\Windows\System32\wow64cpu.dll
2012-08-20 18:48:43 215040 —-a-w- C:\Windows\System32\winsrv.dll
2012-08-20 18:48:37 16384 —-a-w- C:\Windows\System32\ntvdm64.dll
2012-08-20 18:48:35 424448 —-a-w- C:\Windows\System32\KernelBase.dll
2012-08-20 18:46:22 338432 —-a-w- C:\Windows\System32\conhost.exe
2012-08-20 17:40:21 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-08-20 17:38:44 44032 —-a-w- C:\Windows\apppatch\acwow64.dll
2012-08-20 17:38:26 25600 —-a-w- C:\Windows\SysWow64\setup16.exe
2012-08-20 17:37:19 5120 —-a-w- C:\Windows\SysWow64\wow32.dll
2012-08-20 17:37:18 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll
2012-08-20 15:38:21 7680 —-a-w- C:\Windows\SysWow64\instnm.exe
2012-08-20 15:38:20 2048 —-a-w- C:\Windows\SysWow64\user.exe
2012-08-20 15:33:28 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-08-20 15:33:28 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-08-20 15:33:28 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-08-20 15:33:28 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
.
============= FINISH: 22:54:50.03 ===============
Hi WTT folks!
I hope you are well and not to busy, especially since I require some assistance in a particularly scary occurrence.
Hi DanielD!
Today I logged into my facebook only to find that my account was "locked" due to an attempted log-in from a location I have not previously logged into. The location was Japan. I am most certain that there is no good reason that someone in Japan (or possibly elsewhere and spoofing their address) had my facebook password and tried to log-in to my account. I certainly know I haven't shared my password with anyone and I rarely use facebook on any machine but my own (and my work machine, mentioned below).
My hope is that it was not an actual keylogging but just that my roughly 5 year old password (that was also the same for many other sites in my high school years) was leaked from another site. I know, terrible habits. But nonetheless I would like to make absolutely certain my machine is clean. Unfortunately I also have a machine in my office which I do use frequently and could have been the victim. I imagine I should start a separate post for that machine but is it ok to have two ongoing for the same issue? I would assume so given the scenario but I just thought I'd check and see if we couldn't do both machines in the same thread or something to that effect.
I would think the latter is the case unless you suspect someone you know with access to your home or office machine has reason to keylog you. I recommend you start another thread for the office machine so that it is easier to keep track of fixes for each.
But down to business. Since I discovered the unknown log-in, I've obviously changed my facebook password and I have cleared much of my temp data/cache with CCleaner. I am also in the process of running a full Microsoft Security scan. I doubt it will turn up anything and other than running MalwareBytes and SuperAntispyware that is the extent of my malware removing capabilities. I imagine keyloggers are a bit harder to detect than your average virus and I am hoping that those of you experienced with these things will have some strong tools (and eyes) that can actually catch this thing if I am indeed infected with it. I would appreciate being able to browse with my laptop again and feel secure!
You've taken good initial steps. We can check for the presence of malware with keylogging and backdoor functionality.
Lastly, here is my DDS log.
I do not see how to attach the "Attach.txt" and the basic malware posting instructions don't mention posting it so I am leaving it off unless requested (I have it saved).
Just cut and paste its contents in the post
Many thanks.
You are very welcome!
Now on to the diagnosis.
Please download aswMBR.exe and save it to your desktop.
Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
Click
Scan
Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet. You will also notice another file created on the desktop named MBR.dat . Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
Since DanielD does not have permission to reply to this thread, a new one was started here:
http://forums.whatthetech.com/index.php?showtopic=124831