Jump to content

Infected I think


Recommended Posts

I have included my DDS.txt and Attach.txt in addition to my hijackthis.log just in case

.

DDS (Ver_2011-08-26.01) - NTFSAMD64

Internet Explorer: 9.0.8112.16421

Run by mitchel at 22:39:02 on 2012-04-01

Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8191.5205 [GMT -5:00]

.

AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}

SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe

C:\Windows\system32\atiesrxx.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\atieclxx.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\SysWOW64\svchost.exe -k Akamai

C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe

C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe

C:\Windows\SysWOW64\ASGT.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe

D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe

C:\Windows\system32\spool\DRIVERS\x64\3\lxebserv.exe

C:\Windows\system32\lxebcoms.exe

C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe

C:\Windows\SysWOW64\PnkBstrA.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe

C:\Windows\SysWOW64\vmnat.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

D:\Program Files (x86)\VMWare Player\vmware-authd.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\SysWOW64\vmnetdhcp.exe

C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\Microsoft Security Client\msseces.exe

C:\Program Files (x86)\Lexmark Pro200-S500 Series\lxebmon.exe

C:\Program Files (x86)\Lexmark Pro200-S500 Series\ezprint.exe

C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

D:\Program Files (x86)\DisplayFusion\DisplayFusion.exe

C:\Users\mitchel\Local Settings\Apps\F.lux\flux.exe

D:\Users\Mitchel\AppData\Local\dplaysvr.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

D:\Program Files (x86)\DisplayFusion\AppHookx86.exe

D:\Program Files\Rainmeter\Rainmeter.exe

D:\Program Files (x86)\Razer\BlackWidow\BlackWidowTray.exe

D:\Program Files (x86)\Razer\Lachesis\razerhid.exe

D:\Program Files (x86)\Razer\Lachesis\OSD.exe

C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe

D:\Program Files (x86)\Razer\Lachesis\razertra.exe

D:\Program Files (x86)\Razer\Lachesis\razerofa.exe

D:\Program Files (x86)\RaidCall\raidcall.exe

D:\Program Files (x86)\Steam\Steam.exe

D:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe

D:\Program Files (x86)\Winamp\winamp.exe

D:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Reader.exe

D:\Program Files (x86)\Last.fm\LastFM.exe

C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe

C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe

C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

D:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe

C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe

C:\Windows\system32\conhost.exe

d:\program files (x86)\steam\steamapps\common\dawn of war ii - retribution\DOW2.exe

D:\Program Files (x86)\Steam\GameOverlayUI.exe

C:\Windows\system32\WUDFHost.exe

C:\Windows\system32\taskhost.exe

C:\Windows\system32\mmc.exe

C:\Windows\system32\wuauclt.exe

C:\Windows\system32\svchost.exe -k SDRSVC

C:\Windows\system32\conhost.exe

D:\Downloads\HijackThis.exe

C:\Windows\SysWOW64\DllHost.exe

C:\Windows\SysWOW64\cmd.exe

C:\Windows\system32\conhost.exe

C:\Windows\SysWOW64\cscript.exe

C:\Windows\system32\wbem\wmiprvse.exe

.

============== Pseudo HJT Report ===============

.

uSearch Bar = Preserve

mWinlogon: Userinit=userinit.exe,

BHO: SteadyVideoBHO Class: {6c680bae-655c-4e3d-8fc4-e6a520c3d928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: LastPass Browser Helper Object: {95d9ecf5-2a4d-4550-be49-70d42f71296e} - C:\Program Files (x86)\LastPass\LPBar.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\5.1\youtubedownloaderToolbarIE.dll

TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPBar.dll

TB: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\5.1\youtubedownloaderToolbarIE.dll

uRun: [Google Update] "D:\Users\Mitchel\AppData\Local\Google\Update\GoogleUpdate.exe" /c

uRun: [DisplayFusion] "D:\Program Files (x86)\DisplayFusion\DisplayFusion.exe"

uRun: [F.lux] "C:\Users\mitchel\Local Settings\Apps\F.lux\flux.exe" /noshow

uRun: [Akamai NetSession Interface] "C:\Users\mitchel\AppData\Local\Akamai\netsession_win.exe"

uRun: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun

uRun: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun

uRun: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"

mRun: [Razer Blackwidow Driver] D:\Program Files (x86)\Razer\BlackWidow\BlackwidowTray.exe

mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin

mRun: [Lachesis] D:\Program Files (x86)\Razer\Lachesis\razerhid.exe

mRun: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

mRun: [LogMeIn Hamachi Ui] "D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start

mRun: [<NO NAME>]

mRun: [searchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"

mRun: [searchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"

dRunOnce: [AOD] D:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe AutoTune

mPolicies-explorer: NoActiveDesktop = 1 (0x1)

mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)

mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableLUA = 0 (0x0)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

mPolicies-system: PromptOnSecureDesktop = 0 (0x0)

IE: Open Client to monitor &1 - C:\Windows\web\AOpenClient.htm

IE: Open Client to monitor &2 - C:\Windows\web\AOpenClient.htm

IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar.dll

LSP: %SystemRoot%\system32\vsocklib.dll

Trusted Zone: clonewarsadventures.com

Trusted Zone: freerealms.com

Trusted Zone: soe.com

Trusted Zone: sony.com

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{0F6BDBFE-AD1E-42C4-A2F7-25869B0B5C28} : DhcpNameServer = 192.168.1.1

TCP: Interfaces\{5243C439-0B24-48CB-8740-01E40B82EBD4} : DhcpNameServer = 192.168.1.1

TCP: Interfaces\{C0EEA7FC-8AC3-467D-A5D8-3E029A3A8540} : DhcpNameServer = 192.168.1.1

TCP: Interfaces\{C5B7118E-E5B9-441F-9B12-FB7A5B4A3343} : DhcpNameServer = 192.168.1.1

TCP: Interfaces\{C5B7118E-E5B9-441F-9B12-FB7A5B4A3343}\C494E4B4232323 : DhcpNameServer = 68.87.72.134 68.87.77.134

Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll

Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

BHO-X64: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll

BHO-X64: AMD SteadyVideo BHO - No File

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: LastPass Browser Helper Object: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar.dll

BHO-X64: LastPass Browser Helper Object - No File

BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO-X64: YouTube Downloader Toolbar: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\5.1\youtubedownloaderToolbarIE.dll

TB-X64: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPBar.dll

TB-X64: YouTube Downloader Toolbar: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\5.1\youtubedownloaderToolbarIE.dll

mRun-x64: [Razer Blackwidow Driver] D:\Program Files (x86)\Razer\BlackWidow\BlackwidowTray.exe

mRun-x64: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin

mRun-x64: [Lachesis] D:\Program Files (x86)\Razer\Lachesis\razerhid.exe

mRun-x64: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

mRun-x64: [LogMeIn Hamachi Ui] "D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start

mRun-x64: [(Default)]

mRun-x64: [searchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\mitchel\AppData\Roaming\Mozilla\Firefox\Profiles\9luvvoip.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://myfav.es/

FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\1.104.0\npesnlaunch.dll

FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\1.116.0\npesnlaunch.dll

FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll

FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrlui.dll

FF - plugin: C:\Program Files (x86)\OnLive\Plugin\npolgdet.dll

FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_228.dll

FF - plugin: D:\Users\Mitchel\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll

.

============= SERVICES / DRIVERS ===============

.

P2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2012-2-16 8704]

R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]

R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]

R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]

R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 20992]

R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]

R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-2-14 361984]

R2 AODDriver4.1;AODDriver4.1;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-1-3 55936]

R2 Application Updater;Application Updater;C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe [2012-3-4 748440]

R2 ASGT;ASGT;C:\Windows\SysWOW64\ASGT.exe [2012-1-17 55296]

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

R2 cpuz135;cpuz135;\??\C:\Windows\system32\drivers\cpuz135_x64.sys --> C:\Windows\system32\drivers\cpuz135_x64.sys [?]

R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-2-7 2343816]

R2 lxeb_device;lxeb_device;C:\Windows\system32\lxebcoms.exe -service --> C:\Windows\system32\lxebcoms.exe -service [?]

R2 lxebCATSCustConnectService;lxebCATSCustConnectService;C:\Windows\System32\spool\DRIVERS\x64\3\lxebserv.exe [2011-9-1 45736]

R2 PassThru Service;Internet Pass-Through Service;C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2011-3-31 80896]

R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-8-29 846448]

R3 amdiox64;AMD IO Driver;C:\Windows\system32\DRIVERS\amdiox64.sys --> C:\Windows\system32\DRIVERS\amdiox64.sys [?]

R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]

R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]

R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]

R3 HTCAND64;HTC Device Driver;C:\Windows\system32\Drivers\ANDROIDUSB.sys --> C:\Windows\system32\Drivers\ANDROIDUSB.sys [?]

R3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]

R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]

R3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver;C:\Windows\system32\DRIVERS\Rtnic64.sys --> C:\Windows\system32\DRIVERS\Rtnic64.sys [?]

R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]

R3 RzSynapse;Razer Driver;C:\Windows\system32\DRIVERS\RzSynapse.sys --> C:\Windows\system32\DRIVERS\RzSynapse.sys [?]

R3 VaneFltr;Lachesis Mouse Driver;C:\Windows\system32\drivers\Lachesis.sys --> C:\Windows\system32\drivers\Lachesis.sys [?]

R3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys --> C:\Windows\system32\DRIVERS\WSDPrint.sys [?]

R4 IOMap;IOMap;\??\C:\Windows\system32\drivers\IOMap64.sys --> C:\Windows\system32\drivers\IOMap64.sys [?]

S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-29 158856]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-1 253600]

S3 htcnprot;HTC NDIS Protocol Driver;C:\Windows\system32\DRIVERS\htcnprot.sys --> C:\Windows\system32\DRIVERS\htcnprot.sys [?]

S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]

S3 netr28ux;RT2870 USB Wireless LAN Card Driver for Vista;C:\Windows\system32\DRIVERS\netr28ux.sys --> C:\Windows\system32\DRIVERS\netr28ux.sys [?]

S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]

.

=============== Created Last 30 ================

.

2012-04-02 03:15:03 8767136 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe

2012-04-02 02:53:15 418464 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2012-04-02 02:50:10 -------- d-----w- C:\Program Files (x86)\AMD AVT

2012-04-02 02:50:08 -------- d-----w- C:\Program Files\AMD

2012-04-02 02:50:08 -------- d-----w- C:\Program Files (x86)\AMD

2012-04-02 02:50:05 -------- d-----w- C:\Program Files (x86)\AMD APP

2012-04-02 02:43:57 11561984 ----a-w- C:\Windows\SysWow64\aticaldd.dll

2012-04-02 00:14:55 -------- d-----w- D:\Users\Mitchel\AppData\Local\The Witcher 2

2012-03-31 22:30:52 -------- d-----r- C:\Program Files (x86)\Skype

2012-03-31 03:05:49 -------- d-----w- C:\TDSSKiller_Quarantine

2012-03-28 20:48:44 8669240 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{FDE7A773-3F20-4334-AFB7-39D459E49F80}\mpengine.dll

2012-03-23 10:40:23 -------- d-----w- C:\Program Files (x86)\VideoLAN

2012-03-20 20:27:01 -------- d-----w- D:\Users\Mitchel\AppData\Local\SKIDROW

2012-03-20 10:51:41 98304 ----a-w- C:\Windows\SysWow64\CmdLineExt.dll

2012-03-19 19:56:22 -------- d-----w- C:\Program Files (x86)\YouTube Downloader Toolbar

2012-03-19 19:56:22 -------- d-----w- C:\Program Files (x86)\Common Files\Spigot

2012-03-19 19:56:22 -------- d-----w- C:\Program Files (x86)\Application Updater

2012-03-18 05:51:14 -------- d-----w- C:\ProgramData\Media Center Programs

2012-03-17 07:09:26 -------- d-----w- D:\Users\Mitchel\AppData\Local\SplitMediaLabs

2012-03-15 13:58:03 23680 ----a-w- C:\Windows\System32\drivers\IOMap64.sys

2012-03-14 22:52:36 -------- d-----w- C:\Windows\Downloaded Installations

2012-03-14 20:22:32 -------- d-----w- C:\Users\mitchel\AppData\Roaming\Raptr

2012-03-14 20:22:32 -------- d-----w- C:\Program Files (x86)\Raptr

2012-03-07 07:30:28 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation

2012-03-07 06:36:31 -------- d-----w- C:\Windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP

2012-03-03 20:02:06 -------- d-----w- D:\Users\Mitchel\AppData\Local\Deployment

2012-03-03 20:02:06 -------- d-----w- D:\Users\Mitchel\AppData\Local\Apps

.

==================== Find3M ====================

.

2012-04-02 03:15:24 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2012-04-02 02:43:57 5954048 ----a-w- C:\Windows\SysWow64\atiumdag.dll

2012-03-21 00:41:20 76888 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe

2012-03-21 00:41:11 282864 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr

2012-03-21 00:41:11 282864 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe

2012-03-21 00:37:32 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0

2012-02-15 03:05:32 69632 ----a-w- C:\Windows\System32\OpenVideo64.dll

2012-02-15 03:05:26 59904 ----a-w- C:\Windows\SysWow64\OpenVideo.dll

2012-02-15 03:05:20 61952 ----a-w- C:\Windows\System32\OVDecode64.dll

2012-02-15 03:05:16 54784 ----a-w- C:\Windows\SysWow64\OVDecode.dll

2012-02-15 03:05:08 16507904 ----a-w- C:\Windows\System32\amdocl64.dll

2012-02-15 03:04:26 13238272 ----a-w- C:\Windows\SysWow64\amdocl.dll

2012-02-15 03:03:44 54272 ----a-w- C:\Windows\System32\OpenCL.dll

2012-02-15 03:03:38 48128 ----a-w- C:\Windows\SysWow64\OpenCL.dll

2012-02-08 16:12:51 3123272 ----a-w- C:\Windows\SysWow64\pbsvc.exe

2012-01-31 11:02:26 21504 ----a-w- C:\Windows\System32\kdbsdk64.dll

2012-01-31 11:00:24 16896 ----a-w- C:\Windows\SysWow64\kdbsdk32.dll

2012-01-17 21:07:34 65536 ----a-w- C:\Windows\IFinst27.exe

2012-01-17 16:24:10 55296 ----a-w- C:\Windows\SysWow64\ASGT.exe

.

============= FINISH: 22:39:24.53 ===============

hijackthis.log

DDS.txt

Attach.txt

Link to post
Share on other sites

post-32477-1261866970.gif

Logs will be closed if you haven't replied within 3 days

Please don't attach the scans / logs for these tools, use "copy/paste".

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.

Please run a new MBAM scan being sure to update before scanning.

Post the scan results

Also please describe how your computer behaves at the moment.

Please don't attach the scans / logs, use "copy/paste".

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.