Jump to content

Trojan.0Access please help remove


Recommended Posts

Hi, I've just encountered the rootkit Trojan.0Access. I've run malwarebytes and rebooted and it still shows up on the subsequent re-scan. In the past I have successfully removed rootkits with tools like RogueKiller and tdsskiller but I wasn't sure what would be best in this case. I'm not exactly a rookie but I'm no expert either. Please help. Thank you. Here are my logs: *note* I have uTorrent installed but it isn't running nor was it at the time of the scan. If it needs to be uninstalled I am happy to do that. Thank you

DDS (Ver_2012-11-20.01) - NTFS_x86

Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_32

Run by Joy at 7:10:41 on 2013-03-08

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.1976.651 [GMT -6:00]

.

SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

============== Running Processes ================

.

C:\windows\system32\wininit.exe

C:\windows\system32\lsm.exe

C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\STacSV.exe

C:\windows\System32\spoolsv.exe

C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\aestsrv.exe

C:\Program Files\LSI SoftModem\agrsmsvc.exe

C:\Program Files\Clearwire\Connection Manager\clearwireDeviceDiagnosticsService.exe

C:\Program Files\Hawkes Learning Systems\Hawkes Update Service Manager\srvany.exe

C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe

C:\Program Files\Hawkes Learning Systems\Hawkes Update Service Manager\HawkesUpdater.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\Common Files\Motive\McciCMService.exe

C:\Program Files\PDF Complete\pdfsvc.exe

C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe

C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Program Files\Clearwire\Connection Manager\DeviceLaunchSvc.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

C:\windows\system32\taskhost.exe

C:\windows\system32\Dwm.exe

C:\windows\system32\taskhost.exe

C:\windows\Explorer.EXE

C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\IDT\WDM\sttray.exe

C:\Program Files\Nuance\PDF Professional 6\PdfPro6Hook.exe

C:\windows\system32\igfxsrvc.exe

C:\Program Files\Cricket Broadband Connect\AvqAutorun.exe

C:\Program Files\DivX\DivX Update\DivXUpdate.exe

C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

C:\windows\system32\SearchIndexer.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe

C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe

C:\windows\system32\wbem\wmiprvse.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\WhatPulse\WhatPulse.exe

C:\Program Files\Hawkes Learning Systems\Hawkes Update Service Manager\HawkesUpdater.exe

C:\Program Files\MagicDisc\MagicDisc.exe

C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe

C:\Program Files\Skype\Plugin Manager\skypePM.exe

C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe

C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe

C:\Program Files\VideoLAN\VLC\vlc.exe

C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Program Files\Clearwire\Connection Manager\ClearwireCM.exe

C:\Program Files\Clearwire\Connection Manager\RcAppSvc.exe

C:\Program Files\Clearwire\Connection Manager\ConAppsSvc.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Mozilla Firefox\plugin-container.exe

C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_6_602_168.exe

C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_6_602_168.exe

C:\windows\system32\calc.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\windows\notepad.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Joy\AppData\Local\Google\Chrome\Application\chrome.exe

C:\windows\system32\conhost.exe

C:\windows\system32\wbem\wmiprvse.exe

C:\windows\system32\svchost.exe -k DcomLaunch

C:\windows\system32\svchost.exe -k RPCSS

C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\windows\system32\svchost.exe -k netsvcs

C:\windows\system32\svchost.exe -k LocalService

C:\windows\system32\svchost.exe -k NetworkService

C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\windows\System32\svchost.exe -k LocalServiceNoNetwork

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.att.net

BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - c:\program files\divx\divx plus web player\npdivx32.dll

BHO: PlusIEEventHelper Class: {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - c:\program files\nuance\pdf professional 6\bin\PlusIEContextMenu.dll

BHO: DivX HiQ: {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - c:\program files\divx\divx plus web player\npdivx32.dll

BHO: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll

BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll

BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: ZeonIEEventHelper Class: {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: Google Gears Helper: {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll

BHO: Windows Live Toolbar Helper: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - c:\program files\windows live\toolbar\wltcore.dll

BHO: WinAVI YouTube Download: {E8DF67A1-B618-4F3F-9E7D-CBE175ADEF5B} - c:\program files\winavi youtube download\YDTune.dll

TB: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - c:\program files\windows live\toolbar\wltcore.dll

TB: Nuance PDF: {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll

TB: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - c:\program files\windows live\toolbar\wltcore.dll

uRun: [iSUSPM] c:\programdata\flexnet\connect\11\ISUSPM.exe -scheduler

uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden

uRun: [skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized

uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent

uRun: [Google Update] "c:\users\joy\appdata\local\google\update\GoogleUpdate.exe" /c

uRun: [WhatPulse] c:\program files\whatpulse\WhatPulse.exe

mRun: [QLBController] c:\program files\hewlett-packard\hp hotkey support\QLBController.exe /start

mRun: [iAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe

mRun: [PDF Complete] c:\program files\pdf complete\pdfsty.exe

mRun: [synTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe

mRun: [WirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe

mRun: [igfxTray] c:\windows\system32\igfxtray.exe

mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe

mRun: [Persistence] c:\windows\system32\igfxpers.exe

mRun: [sysTrayApp] c:\program files\idt\wdm\sttray.exe

mRun: [PDFHook] c:\program files\nuance\pdf professional 6\pdfpro6hook.exe

mRun: [PDF6 Registry Controller] c:\program files\nuance\pdf professional 6\RegistryController.exe

mRun: [Nuance PDF Reader-reminder] "c:\program files\nuance\pdf reader\ereg\ereg.exe" -r "c:\programdata\nuance\pdf reader\ereg\Ereg.ini"

mRun: [NortonOnlineBackupReminder] "c:\program files\symantec\norton online backup\activation\NOBuActivation.exe" UNATTENDED

mRun: [{F9AA8FE2-E89A-E99B-E8b8-E9AE9B9ABA99}] "c:\program files\cricket broadband connect\avqautorun.exe" "c:\program files\cricket broadband connect\mphonetools.exe" /OnPlug=%s

mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW

mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"

mRun: [EM_EXEC] c:\progra~1\logitech\mousew~1\system\EM_EXEC.EXE

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [Clearwire Connection Manager] "c:\program files\clearwire\connection manager\ClearwireCM.exe" -a

mRunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "c:\programdata\malwarebytes\malwarebytes' anti-malware\cleanup.dll",ProcessCleanupScript

StartupFolder: c:\users\joy\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe

StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hawkes~1.lnk - c:\program files\hawkes learning systems\hawkes update service manager\HawkesUpdater.exe

uPolicies-Explorer: NoDrives = dword:0

uPolicies-Explorer: HideSCAHealth = dword:1

mPolicies-Explorer: NoDrives = dword:0

mPolicies-System: ConsentPromptBehaviorAdmin = dword:0

mPolicies-System: ConsentPromptBehaviorUser = dword:3

mPolicies-System: EnableLUA = dword:0

mPolicies-System: EnableUIADesktopToggle = dword:0

mPolicies-System: PromptOnSecureDesktop = dword:0

IE: Append the content of the link to existing PDF file - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML

IE: Append the content of the selected links to existing PDF file - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML

IE: Append to existing PDF file - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML

IE: Create PDF file - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML

IE: Create PDF file from the content of the link - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML

IE: Create PDF files from the selected links - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML

IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000

IE: Open with Nuance PDF Converter 6.0 - c:\program files\nuance\pdf professional 6\cnvres_eng.dll /100

IE: Open with PDF Professional 6 - c:\program files\nuance\pdf professional 6\bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm

IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

Trusted Zone: //about.htm/

Trusted Zone: //Exclude.htm/

Trusted Zone: //FWEvent.htm/

Trusted Zone: //LanguageSelection.htm/

Trusted Zone: //Message.htm/

Trusted Zone: //MyAgttryCmd.htm/

Trusted Zone: //MyAgttryNag.htm/

Trusted Zone: //MyNotification.htm/

Trusted Zone: //NOCLessUpdate.htm/

Trusted Zone: //quarantine.htm/

Trusted Zone: //ScanNow.htm/

Trusted Zone: //strings.vbs/

Trusted Zone: //Template.htm/

Trusted Zone: //Update.htm/

Trusted Zone: //VirFound.htm/

DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab

DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} - hxxp://www.convergysworkathome.com/AppHardT.CAB

DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab

TCP: NameServer = 66.233.164.12 64.13.115.12

TCP: Interfaces\{AC987FE2-3C83-4A1E-B4B3-0A9C8DF3920E} : DHCPNameServer = 192.168.1.254

TCP: Interfaces\{D329BE76-3F91-4718-9779-0510BBFFEA8A} : DHCPNameServer = 192.168.1.254

TCP: Interfaces\{D329BE76-3F91-4718-9779-0510BBFFEA8A}\442757764756368637 : DHCPNameServer = 75.75.75.75 75.75.76.76

TCP: Interfaces\{D329BE76-3F91-4718-9779-0510BBFFEA8A}\A4F6970284F6D656 : DHCPNameServer = 192.168.1.254

TCP: Interfaces\{D329BE76-3F91-4718-9779-0510BBFFEA8A}\B6565607F65747 : DHCPNameServer = 192.168.0.1

TCP: Interfaces\{F90C3FEB-3D9A-4BB2-BE84-5BB54D92718C} : DHCPNameServer = 66.233.164.12 64.13.115.12

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll

Notify: igfxcui - igfxdev.dll

SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\users\joy\appdata\roaming\mozilla\firefox\profiles\avir56eu.default\

FF - prefs.js: browser.startup.homepage - hxxp://apps.facebook.com/luckygemcasino/?fb_source=canvasbookmark&count=3

FF - component: c:\program files\google\google gears\firefox\lib\ff36\gears.dll

FF - plugin: c:\program files\common files\motive\npMotive.dll

FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll

FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll

FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll

FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll

FF - plugin: c:\program files\google\update\1.3.21.135\npGoogleUpdate3.dll

FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll

FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll

FF - plugin: c:\program files\nuance\pdf professional 6\bin\nppdf.dll

FF - plugin: c:\program files\nuance\pdf reader\bin\nppdf.dll

FF - plugin: c:\program files\nuance\pdf reader\bin\nppdf.dll

FF - plugin: c:\users\joy\appdata\local\google\update\1.3.21.135\npGoogleUpdate3.dll

FF - plugin: c:\users\joy\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll

FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_6_602_168.dll

FF - plugin: c:\windows\system32\npdeployJava1.dll

FF - plugin: c:\windows\system32\npmproxy.dll

.

============= SERVICES / DRIVERS ===============

.

R1 lkbdfltr;Logitech Keyboard Class Filter Driver;c:\windows\system32\drivers\LKBDFLTR.SYS [2011-3-31 4240]

R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\AEstSrv.exe [2010-6-12 81920]

R2 clearwireDeviceDiagnosticsService;Clearwire Device Diagnostics Service;c:\program files\clearwire\connection manager\clearwireDeviceDiagnosticsService.exe [2011-3-29 407552]

R2 HawkesUpdater;Hawkes Unattended Updater;c:\program files\hawkes learning systems\hawkes update service manager\srvany.exe [2011-8-28 8192]

R2 hpHotkeyMonitor;HP Hotkey Monitor;c:\program files\hewlett-packard\hp hotkey support\hpHotkeyMonitor.exe [2010-1-28 265272]

R2 pdfcDispatcher;PDF Document Manager;c:\program files\pdf complete\pdfsvc.exe [2010-3-15 635416]

R2 PDFProFiltSrv;PDFProFiltSrv;c:\program files\nuance\pdf professional 6\PDFProFiltSrv.exe [2009-11-3 134944]

R2 SMSI Device Launch Service;Clearwire Device Launch Service;c:\program files\clearwire\connection manager\DeviceLaunchSvc.exe [2011-11-22 108376]

R3 bcm;WiMAX Network Adapter;c:\windows\system32\drivers\drxvi314.sys [2011-10-17 340992]

R3 bcmbusctr;WiMAX Bus Driver;c:\windows\system32\drivers\BcmBusCtr.sys [2011-10-17 48768]

R3 CACLEARWIRE;Clearwire Con App Svc;c:\program files\clearwire\connection manager\ConAppsSvc.exe [2011-11-22 124760]

R3 CLEARWIRERcAppSvc;Clearwire RcAppSvc;c:\program files\clearwire\connection manager\RcAppSvc.exe [2011-11-22 120664]

R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2011-1-18 122880]

R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-3-15 257568]

R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\drivers\rtl8192se.sys [2010-6-12 1115240]

S1 lmoufltr;Logitech Mouse Class Filter Driver;c:\windows\system32\drivers\LMOUFLTR.SYS [2011-3-31 58592]

S1 lsermous;Logitech Serial Mouse Driver;c:\windows\system32\drivers\LSERMOUS.SYS [2011-3-31 58736]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]

S3 PTUMWBus;PANTECH USB Modem V2 Composite Device Driver;c:\windows\system32\drivers\PTUMWBus.sys [2010-12-20 54544]

S3 PTUMWFLT;PTUMWNET Filter Driver;c:\windows\system32\drivers\PTUMWFLT.sys [2010-12-20 12048]

S3 PTUMWMdm;PANTECH USB Modem V2 Modem Driver;c:\windows\system32\drivers\PTUMWMdm.sys [2010-12-20 160400]

S3 PTUMWNET;PANTECH USB Modem V2 WWAN Driver;c:\windows\system32\drivers\PTUMWNET.sys [2010-12-20 115216]

S3 PTUMWVsp;PANTECH USB Modem V2 Diagnostic Port;c:\windows\system32\drivers\PTUMWVsp.sys [2010-12-20 160400]

S3 RoxMediaDB10;RoxMediaDB10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxMediaDB10.exe [2009-11-23 1120752]

.

=============== Created Last 30 ================

.

2013-03-08 12:40:13 54016 ----a-w- c:\windows\system32\drivers\wfvsi.sys

2013-03-08 09:18:40 -------- d-sh--w- c:\windows\system32\%APPDATA%

2013-03-08 09:14:29 -------- d-----w- c:\programdata\AC8853FB9BF075F40000AC87A7777979

2013-03-05 08:50:37 -------- d-----w- c:\users\joy\appdata\roaming\Nitreal Games

2013-03-04 12:00:29 -------- d-----w- c:\program files\Infogrames

2013-02-24 01:22:08 -------- d-----w- c:\users\joy\cookieart

2013-02-23 09:16:59 -------- d-----w- c:\users\joy\appdata\roaming\WhiteBear

2013-02-21 14:13:12 -------- d-----w- c:\programdata\Ice Cream Tycoon

2013-02-21 14:06:48 -------- d-----w- c:\users\joy\appdata\roaming\InImages

2013-02-21 11:13:56 -------- d-----w- c:\users\joy\appdata\roaming\RunningPillow

2013-02-21 07:44:11 -------- d-----w- c:\users\joy\appdata\local\MLS2

2013-02-17 06:49:19 -------- d-----w- c:\program files\R.G.BestGamer

2013-02-17 04:20:09 -------- d-----w- c:\users\joy\appdata\roaming\PetStorePanic

.

==================== Find3M ====================

.

2013-02-26 02:44:12 691568 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2013-02-26 02:44:11 71024 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2013-01-28 21:59:00 108144 ----a-w- c:\windows\system32\CmdLineExt.dll

2012-12-14 22:49:28 21104 ----a-w- c:\windows\system32\drivers\mbam.sys

.

============= FINISH: 7:11:33.78 ===============

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2012-11-20.01)

.

Microsoft Windows 7 Home Premium

Boot Device: \Device\HarddiskVolume1

Install Date: 12/1/2010 1:38:02 PM

System Uptime: 3/8/2013 3:38:13 AM (4 hours ago)

.

Motherboard: Hewlett-Packard | | 1526

Processor: Genuine Intel® CPU T1600 @ 1.66GHz | Intel® Genuine processor | 1662/166mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 281 GiB total, 3.876 GiB free.

D: is CDROM (CDFS)

E: is CDROM (UDF)

F: is FIXED (FAT32) - 2 GiB total, 1.973 GiB free.

G: is CDROM ()

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

No restore point in system.

.

==== Installed Programs ======================

.

Leawo DVD to FLV Converter version 4.3.0.0

Leawo FLV Converter version 3.1.0.0

µTorrent

2007 Microsoft Office Suite Service Pack 1 (SP1)

2007 Microsoft Office system

A Gnomes Home The Great Crystal Crusade 1.00

ACDSee 5.0 Standard Trial

ACDSee 7.0

ActiveCheck component for HP Active Support Library

Adobe AIR

Adobe Digital Editions 2.0

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Reader X (10.0.1)

Airport Simulator

Alchemy Deluxe 1.00

Amelies Cafe Holiday Spirit 1.00

Amelies Cafe Summer Time 1.00

Ancient Hearts and Spades 1.00

Anno 1602

Anno 1701

AnswerWorks 5.0 English Runtime

Antique Road Trip USA 1.00

Ashtons - Family Resort 1.00

AstroPop 1.00

Atomica 1.00

ATT-PRT22

Balloon Express 1.00

Barn Yarn Collectors 1.00

Baseball Mogul

Big Money 1.00

BLM 2.7.7

Boutique Boulevard 1.00

Burger Bustle 1.00

Burger Bustle Ellies Organics 1.00

Burger Island 2 1.00

Cake Mania 5 Lights Camera Action 1.00

Cake Mania Back to the Bakery 1.00

Cake Mania Main Street 1.00

Cake Mania To the Max 1.00

Cake Shop 3 1.00

Campfire Legends 2 The Babysitter 1.00

CBR Reader

Chocolatier - Decadence by Design 1.00

Chocolatier 1.00

Cisco EAP-FAST Module

Cisco LEAP Module

Cisco PEAP Module

CLEAR Connection Manager

Coby Media Manager

Compatibility Pack for the 2007 Office system

Cooking Academy 3 Recipe for Success 1.00

Cooking Dash 2 DinerTown Studios 1.00

CorsixTH 0.01

Corys Lunch Rush 1.00

Costume Chaos 1.00

Cricket Broadband Connect

Delicious Deluxe 2 Free Trial

Delicious Deluxe Free Trial

Delicious Emilys Childhood Memories PE 1.00

Delicious Emilys True Love Premium Edition 1.00

Depth Hunter

Din's Curse

Din's Curse - Demon War Expansion

Diner Dash 2 - Restaurant Rescue 1.00

DinerTown Tycoon 1.00

Direct Show Ogg Vorbis Filter (remove only)

DirectX 9 Runtime

DivX Setup

Doggie Dash 1.00

Dr. Mal Practice of Horror 1.00

Dream Builder Amusement Park 1.00

ER

Fab Fashion 1.00

Fairway Solitaire 2 Collectors Edition 1.1

Family Guy Back to the Multiverse

Family Restaurant 1.00

Farm Craft 1.00

Farm Frenzy Pizza Party 1.00

Farm Frenzy Viking Heroes 1.00

Farm Girl at the Nile 1.00

Farm Quest 1.00

Farm Tribe 2 1.00

Farm Tribe Updated 1.00

Farm Tribe Updated 1.2

Farm Up 1.00

Farmers Market 1.00

Fashion Fits Free Trial

Fashion Fortune 1.00

Fashion Season 1.00

Fashion Solitaire 1.00

Fill Up! 1.00

Fiona Finch and the Finest Flowers 1.00

FishCo

Fishdom 3 Collectors Edition 1.00

Fishers Family Farm New 1.00

Fishing Craze 1.00

Fix-It-Up Eighties Meet Kates Parents 1.00

focus booster

Fruits Inc 1.00

Gallop for Gold 1.00

GangLand

Garden-Simulator 2010 version 1.0

Garden Dash 1.00

Gardenscapes Mansion Makeover CE 1.00

Ghost Master

GhostMaster

GoldHeartsJuiceB

Google Chrome

Google Gears

Google Update Helper

Gourmania 3 Zoo Zoom 1.00

Happy Chef 1.00

Haunted Legends The Undertaker Collectors 1.00

Hawkes Update Service Manager

Hobby Farm 1.00

Hollywood Tycoon 1.00

Horatio's Travels 1.00

Hot Farm Africa 1.00

Hotel Dash 2 Lost Luxuries 1.00

HP Advisor

HP Customer Experience Enhancements

HP ESU for Microsoft Windows 7

HP HotKey Support

HP Product Detection

HP Setup

HP SoftPaq Download Manager

HP Software Framework

HP Software Setup

HP User Guides 0190

HP Web Camera

HP Webcam

HP Webcam Driver

HP Wireless Assistant

HPAsset component for HP Active Support Library

Ice Cream Craze Natural Hero 1.00

IDT Audio

IGT Slots Cleopatra II

Inquisit 3 Web Edition

Insaniquarium! Deluxe 1.00

Intel® Graphics Media Accelerator Driver

Intel® Matrix Storage Manager

Introductory and Intermediate Algebra (Fall 2011 Student)

Introductory and Intermediate Algebra (Fall 2012 Student)

Jack of All Tribes BFG 1.00

Java Auto Updater

Java 6 Update 32

Jessicas BowWow Bistro 1.00

Jojos Fashion Show World Tour 1.00

Jos Dream Organic Coffee 1.00

Juliettes Fashion Empire 1.00

K-Lite Codec Pack 6.5.0 (Basic)

Katy and Bob Way Back Home 1.00

Kings Smith 1.00

Kitchen Brigade 1.00

Knights and Merchants - The Peasants Rebellion

Kudos 2

Lake House Children of Silence Collectors Edition 1.00

Law and Order - Legacies

LightScribe System Software

Logitech MouseWare 9.10

Lottso! Deluxe 1.00

Lovely Kitchen 1.00

LPL Software 2.7

Lucy's Expedition 1.00

Magic Farm 2 Premium Edition 2.0.3

Magic ISO Maker v5.5 (build 0276)

Magic Sweets 1.00

MagicDisc 2.7.106

Majesty 2: Monster Kingdom

Malwarebytes Anti-Malware version 1.70.0.1100

MeggieSoft Games Gin Rummy

Microsoft .NET Framework 4 Client Profile

Microsoft .NET Framework 4 Extended

Microsoft Choice Guard

Microsoft Office Access MUI (English) 2007

Microsoft Office Access MUI (French) 2007

Microsoft Office Access MUI (Portuguese (Brazil)) 2007

Microsoft Office Access MUI (Spanish) 2007

Microsoft Office Access Setup Metadata MUI (English) 2007

Microsoft Office Enterprise 2007

Microsoft Office Excel MUI (English) 2007

Microsoft Office Excel MUI (French) 2007

Microsoft Office Excel MUI (Portuguese (Brazil)) 2007

Microsoft Office Excel MUI (Spanish) 2007

Microsoft Office Groove MUI (English) 2007

Microsoft Office Groove Setup Metadata MUI (English) 2007

Microsoft Office InfoPath MUI (English) 2007

Microsoft Office OneNote MUI (English) 2007

Microsoft Office Outlook MUI (English) 2007

Microsoft Office Outlook MUI (French) 2007

Microsoft Office Outlook MUI (Portuguese (Brazil)) 2007

Microsoft Office Outlook MUI (Spanish) 2007

Microsoft Office PowerPoint MUI (English) 2007

Microsoft Office PowerPoint MUI (French) 2007

Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2007

Microsoft Office PowerPoint MUI (Spanish) 2007

Microsoft Office Professional Hybrid 2007

Microsoft Office Proof (Arabic) 2007

Microsoft Office Proof (Basque) 2007

Microsoft Office Proof (Catalan) 2007

Microsoft Office Proof (Dutch) 2007

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Galician) 2007

Microsoft Office Proof (German) 2007

Microsoft Office Proof (Portuguese (Brazil)) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Proofing (French) 2007

Microsoft Office Proofing (Portuguese (Brazil)) 2007

Microsoft Office Proofing (Spanish) 2007

Microsoft Office Publisher MUI (English) 2007

Microsoft Office Publisher MUI (French) 2007

Microsoft Office Publisher MUI (Portuguese (Brazil)) 2007

Microsoft Office Publisher MUI (Spanish) 2007

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared MUI (French) 2007

Microsoft Office Shared MUI (Portuguese (Brazil)) 2007

Microsoft Office Shared MUI (Spanish) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office Suite Activation Assistant

Microsoft Office Word MUI (English) 2007

Microsoft Office Word MUI (French) 2007

Microsoft Office Word MUI (Portuguese (Brazil)) 2007

Microsoft Office Word MUI (Spanish) 2007

Microsoft Search Enhancement Pack

Microsoft Silverlight

Microsoft Sync Framework Runtime Native v1.0 (x86)

Microsoft Sync Framework Services Native v1.0 (x86)

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

Microsoft Visual C++ Run Time Lib Setup

Microsoft WSE 3.0 Runtime

Microsoft XNA Framework Redistributable 3.1

Miriels Enchanted Mystery 1.00

Mob Rule

Mobile PhoneTools

Monopoly Tycoon

Mozilla Firefox 12.0 (x86 en-US)

Mozilla Maintenance Service

MSVCRT

My Farm Life 1.00

My Life Story Adventures 1.00

My Vet Practice - Marine Patrol

Neighbours From Hell Compilation

Network Play System (Patching)

Night in the Opera 1.00

Norton Online Backup

Nuance PDF Professional 6

Nuance PDF Reader

NVIDIA PhysX

Oktoberfest Manager

OpenAL

Origin

PANTECH USB Modem V2

Paradise Pet Salon Free Trial

Party Planner 1.00

Path to Success 1.00

PDF Complete Special Edition

PeerGuardian 2.0

Pet Show Craze 1.00

Pet Store Panic 1.00

Pets Fun House 1.00

Pirates of Black Cove

Pizza Connection 2

Port Royale 3 Steam Edition 3.4.2.27374

Posh Shop Free Trial

Pranksterz Off Your Boss 1.00

Project Rescue Africa 1.00

Quicken 2011

Reality Show Fatal Shot Collectors Edition 1.00

Realtek Ethernet Controller All-In-One Windows Driver

REALTEK Wireless LAN Driver

REALTEK Wireless LAN Software

Road to Riches 1.00

Roller Rush Free Trial

RollerCoaster Tycoon Deluxe

Roxio Activation Module

Roxio Creator Audio

Roxio Creator Business

Roxio Creator Business v10

Roxio Creator Copy

Roxio Creator Data

Roxio Creator Tools

Roxio Express Labeler 3

Roxio MyDVD

Sale Frenzy 1.00

Sally's Spa 1.00

Sally's Studio Collector's Edition 1.00

Sallys Quick Clips 1.00

Satisfashion 1.00

Scansoft PDF Professional

Shaman Odyssey Tropic Adventure 1.00

Shiver Vanishing Hitchhiker Collectors Edition 1.00

Shop Spree Shopping Paradise 1.00

Shopmania 1.00

Sibelius Scorch (Firefox, Opera, Netscape only)

Sims2Pack Clean Installer

Skype™ 3.8

Slot Quest Wild West 1.00

Snackjack

Snow Globe Farm World 1.00

Soap Opera Dash 1.00

Solitaire Mystery Stolen Power 1.00

Sonic CinePlayer Decoder Pack

Spooky Mall 1.00

Stand OFood 3 1.00

Stone Age Cafe 1.00

Stronghold

SummerRush 1.00

Sunset Studio Free Trial

Supermarket Management 2 1.00

Supermarket Mania 2 1.00

Supple Episode 2 1.00

Synaptics Pointing Device Driver

System Requirements Lab for Intel

Tasty Turbo Trio 1.00

The Cat Lady

The Game of Life 1.00

The Golden Years Way Out West 1.00

The Island Castaway 2 1.00

The Joy of Farming 1.00

The Movies

The Movies Stunts & Effects

The Nations Gold

The Promised Land 1.00

The Sims™ 2 Deluxe

The Sims™ 3

The Sims™ 3 70s, 80s, & 90s Stuff

The Sims™ 3 Ambitions

The Sims™ 3 Diesel Stuff

The Sims™ 3 Fast Lane Stuff

The Sims™ 3 Generations

The Sims™ 3 High-End Loft Stuff

The Sims™ 3 Katy Perry's Sweet Treats

The Sims™ 3 Late Night

The Sims™ 3 Master Suite Stuff

The Sims™ 3 Outdoor Living Stuff

The Sims™ 3 Pets

The Sims™ 3 Seasons

The Sims™ 3 Showtime

The Sims™ 3 Supernatural

The Sims™ 3 Town Life Stuff

The Sims™ 3 World Adventures

The Walking Dead Episode 3 © TellTale Games version 1

The Walking Dead Game EP 1&2

Theme Hospital

Townopolis Gold 1.00

Trade Mania 1.00

Travel Agency 1.00

Treasure Adventure Game

Trick or Travel 1.00

Tropico Reloaded

TV Farm 1.00

Unity Web Player

Update for Microsoft Office Word 2007 (KB974631)

Vacation Quest The Hawaiian Islands 1.00

Vanilla and Chocolate 1.00

VC80CRTRedist - 8.0.50727.4053

Virtual City 2 Paradise Resort 1.00

Virtual Farm 2 1.00

Virtual Villagers 4 The Tree of Life 1.00

Virtual Villagers New Believers 1.00

VLC media player 2.0.5

Wedding Dash 3 Ready, Aim, Love 1.00

Wedding Salon 1.00

Wendys Wellness 1.00

Westward Kingdoms 1.00

WhatPulse 1.7.1

Wild Tribe 1.00

WinAVI YouTube Download

Windows 7 Default Setting

Windows Driver Package - Broadcom Bluetooth (07/30/2009 6.2.0.9405)

Windows Driver Package - Broadcom Bluetooth (12/16/2009 6.2.0.9414)

Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800)

Windows Live Essentials

Windows Live Sign-in Assistant

Windows Live Toolbar

Windows Live Upload Tool

Windows Media Player Firefox Plugin

WinRAR 4.01 (32-bit)

WinZip 12.0

World Wonderland 1.00

Yahoo! Install Manager

Yard Sale Junkie 1.00

Ye Olde Sandwich Shoppe 1.00

Youda Farmer 2 Save the Village 1.00

Youda Farmer 3 Seasons 1.00

Youda Fisherman 1.00

Youda Jewel Shop 1.00

Zombie Bowl-O-Rama 1.00

.

==== Event Viewer Messages From Past Week ========

.

3/8/2013 4:07:41 AM, Error: Service Control Manager [7023] - The Function Discovery Resource Publication service terminated with the following error: %%-2147024891

3/8/2013 4:07:41 AM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: %%-2147024891

3/8/2013 3:38:40 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: lmoufltr tcpipBM

3/8/2013 3:38:39 AM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

3/8/2013 3:38:39 AM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

3/8/2013 3:38:39 AM, Error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: This driver has been blocked from loading

3/8/2013 3:38:39 AM, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading.

3/8/2013 3:38:38 AM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.

3/5/2013 11:35:09 AM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.

3/4/2013 6:04:41 AM, Error: cdrom [11] - The driver detected a controller error on \Device\CdRom2.

.

==== End Of File ===========================

Link to post
Share on other sites

Welcome to the forum.

Please remove any usb or external drives from the computer before you run this scan!

Please download and run RogueKiller to your desktop.

RogueKiller<---use this one for 64 bit systems

Quit all running programs.

For Windows XP, double-click to start.

For Vista or Windows 7-8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.

Click Scan to scan the system.

When the scan completes > Close out the program > Don't Fix anything!

Don't run any other options, they're not all bad!!!!!!!

Post back the report which should be located on your desktop.

(please don't put logs in code or quotes)

P2P Warning:

If you're using Peer 2 Peer software such as uTorrent, BitTorrent or similar you must either fully uninstall it or completely disable it from running while being assisted here.

Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.

MrC

Note:

Removing malware can be unpredictable
...things can go very wrong!
Backup
any files that cannot be replaced. You can copy them to a CD/DVD, external drive or a pen drive

<+>
Please don't run any other scans, download, install or uninstall any programs while I'm working with you.

<+>The removal of malware isn't instantaneous, please be patient.

<+>
Please stick with me until I give you the "all clear".

------->Your topic will be closed if you haven't replied within 3 days!<--------

(If I don't respond within 24 hours, please send me a PM)

Link to post
Share on other sites

Here we go, thank you :)

RogueKiller V8.5.2 [Feb 23 2013] by Tigzy

mail : tigzyRK<at>gmail<dot>com

Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/

Website : http://tigzy.geekstogo.com/roguekiller.php

Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7600 ) 32 bits version

Started in : Normal mode

User : Joy [Admin rights]

Mode : Scan -- Date : 03/08/2013 07:39:37

| ARK || FAK || MBR |

¤¤¤ Bad processes : 2 ¤¤¤

[Microsoft][HJNAME] notepad.exe -- C:\Windows\System32\notepad.exe [7] ->

KILLED [TermProc]

[Microsoft][HJNAME] notepad.exe -- C:\Windows\System32\notepad.exe [7] ->

KILLED [TermProc]

¤¤¤ Registry Entries : 13 ¤¤¤

[TASK][sUSP PATH] {300A9586-47AD-4979-9DEA-3FA644728265} : C:\Users\Joy

\Desktop\academagia\academagia\Academagia.exe [x] -> FOUND

[TASK][sUSP PATH] {4C936CE3-7D09-4AD2-AD80-ACBB760F25E6} : C:\Users\Joy

\Desktop\academagia\academagia\Academagia.exe [x] -> FOUND

[TASK][sUSP PATH] {55EBC056-D4C8-4F36-AC34-3A78FEBE7CA1} : C:\Users\Joy

\Desktop\academagia\academagia\Academagia.exe [x] -> FOUND

[TASK][sUSP PATH] {9F3700ED-CD5A-4476-9D0B-ED56CA062AAC} : C:\Users\Joy

\Desktop\academagia\academagia\Academagia.exe [x] -> FOUND

[TASK][sUSP PATH] {F1228A15-DBB1-4C99-8F86-521EE7942D98} : C:\Users\Joy

\Desktop\academagia\academagia\Academagia.exe [x] -> FOUND

[TASK][sUSP PATH] {F5AAACA3-F52F-42DB-B611-3F119A90D819} : C:\Users\Joy

\Desktop\academagia\academagia\Academagia.exe [x] -> FOUND

[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer () -> FOUND

[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND

[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND

[HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND

[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND

[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee}

(1) -> FOUND

[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D}

(1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

[ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-18\

$39fa3f49bd9941b5e75d6dd27e0edb3b\@ [-] --> FOUND

[ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-21-169340207-3269167449-

2088699052-1002\$39fa3f49bd9941b5e75d6dd27e0edb3b\@ [-] --> FOUND

[ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-18\

$39fa3f49bd9941b5e75d6dd27e0edb3b\U --> FOUND

[ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-21-169340207-3269167449-

2088699052-1002\$39fa3f49bd9941b5e75d6dd27e0edb3b\U --> FOUND

[ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-18\

$39fa3f49bd9941b5e75d6dd27e0edb3b\L --> FOUND

[ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-21-169340207-3269167449-

2088699052-1002\$39fa3f49bd9941b5e75d6dd27e0edb3b\L --> FOUND

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ Infection : ZeroAccess ¤¤¤

¤¤¤ HOSTS File: ¤¤¤

--> C:\windows\system32\drivers\etc\hosts

127.0.0.1 localhost

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: Hitachi HTS725032A9A364 +++++

--- User ---

[MBR] 11420eda46b8acc607158c6576084454

[bSP] 35913ee709db3ce50c83284c0df9175f : Windows Vista MBR Code

Partition table:

0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 300 Mo

1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 616448 | Size: 287534

Mo

2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 589486080 | Size: 15360

Mo

3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 620943360 | Size:

2043 Mo

User = LL1 ... OK!

User = LL2 ... OK!

Finished : << RKreport[1]_S_03082013_02d0739.txt >>

RKreport[1]_S_03082013_02d0739.txt

Link to post
Share on other sites

Please uncheck Word Wrap in notepad.

--------------------------------------

Run RogueKiller again and click Scan

When the scan completes > click on the Files tab

Put a check next to all of these and uncheck the rest: (if found)

[ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-18\$39fa3f49bd9941b5e75d6dd27e0edb3b\@ [-] --> FOUND

[ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-21-169340207-3269167449-2088699052-1002\$39fa3f49bd9941b5e75d6dd27e0edb3b\@ [-] --> FOUND

[ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-18\$39fa3f49bd9941b5e75d6dd27e0edb3b\U --> FOUND

[ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-21-169340207-3269167449-2088699052-1002\$39fa3f49bd9941b5e75d6dd27e0edb3b\U --> FOUND

[ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-18\$39fa3f49bd9941b5e75d6dd27e0edb3b\L --> FOUND

[ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-21-169340207-3269167449-2088699052-1002\$39fa3f49bd9941b5e75d6dd27e0edb3b\L --> FOUND

Now click Delete on the right hand column under Options

-------------

Please create a new system restore point before running Malwarebytes Anti-Rootkit if you can.

Download Malwarebytes Anti-Rootkit from HERE

  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log.txt and system-log.txt

To attach a log if needed:

Bottom right corner of this page.

more-reply-options.jpg

New window that comes up.

choose-files1.jpg

~~~~~~~~~~~~~~~~~~~~~~~

Note:

If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:

Internet access

Windows Update

Windows Firewall

If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit and reboot.

Verify that your system is now functioning normally.

MrC

Link to post
Share on other sites

I have run the anti-rootkit scan once and done the cleanup...it said no reboot required. Am running it this second time but am certain all will be well. I am just waiting to make certain the threat didn't persist and it's safe to login to my paypal. I'll be chipping in. Thank you ever so much.

Link to post
Share on other sites

Clean as a whistle. I certainly appreciate your assistance. Thank you!

Malwarebytes Anti-Rootkit BETA 1.01.0.1021

www.malwarebytes.org

Database version: v2013.03.08.11

Windows 7 x86 NTFS

Internet Explorer 8.0.7600.16385

Joy :: JOY-HP [administrator]

3/8/2013 9:11:42 AM

mbar-log-2013-03-08 (09-11-42).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P

Scan options disabled:

Objects scanned: 31983

Time elapsed: 18 minute(s), 38 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

---------------------------------------

Malwarebytes Anti-Rootkit BETA 1.01.0.1021

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7600 Windows 7 x86

Account is Administrative

Internet Explorer version: 8.0.7600.16385

Java version: 1.6.0_32

File system is: NTFS

Disk drives: C:\ DRIVE_FIXED, F:\ DRIVE_FIXED

CPU speed: 1.662000 GHz

Memory total: 2072264704, free: 946040832

------------ Kernel report ------------

03/08/2013 08:19:55

------------ Loaded modules -----------

\SystemRoot\system32\ntkrnlpa.exe

\SystemRoot\system32\halmacpi.dll

\SystemRoot\system32\kdcom.dll

\SystemRoot\system32\mcupdate_GenuineIntel.dll

\SystemRoot\system32\PSHED.dll

\SystemRoot\system32\BOOTVID.dll

\SystemRoot\system32\CLFS.SYS

\SystemRoot\system32\CI.dll

\SystemRoot\System32\drivers\wfvsi.sys

\SystemRoot\system32\drivers\Wdf01000.sys

\SystemRoot\system32\drivers\WDFLDR.SYS

\SystemRoot\system32\DRIVERS\ACPI.sys

\SystemRoot\system32\DRIVERS\WMILIB.SYS

\SystemRoot\system32\DRIVERS\msisadrv.sys

\SystemRoot\system32\DRIVERS\pci.sys

\SystemRoot\system32\DRIVERS\vdrvroot.sys

\SystemRoot\System32\drivers\partmgr.sys

\SystemRoot\system32\DRIVERS\compbatt.sys

\SystemRoot\system32\DRIVERS\BATTC.SYS

\SystemRoot\system32\DRIVERS\volmgr.sys

\SystemRoot\System32\drivers\volmgrx.sys

\SystemRoot\System32\drivers\mountmgr.sys

\SystemRoot\system32\DRIVERS\iaStor.sys

\SystemRoot\system32\DRIVERS\amdxata.sys

\SystemRoot\system32\drivers\fltmgr.sys

\SystemRoot\system32\drivers\fileinfo.sys

\SystemRoot\System32\Drivers\PxHelp20.sys

\SystemRoot\System32\Drivers\Ntfs.sys

\SystemRoot\System32\Drivers\msrpc.sys

\SystemRoot\System32\Drivers\ksecdd.sys

\SystemRoot\System32\Drivers\cng.sys

\SystemRoot\System32\drivers\pcw.sys

\SystemRoot\System32\Drivers\Fs_Rec.sys

\SystemRoot\system32\drivers\ndis.sys

\SystemRoot\system32\drivers\NETIO.SYS

\SystemRoot\System32\Drivers\ksecpkg.sys

\SystemRoot\system32\DRIVERS\volsnap.sys

\SystemRoot\System32\Drivers\spldr.sys

\SystemRoot\System32\drivers\rdyboost.sys

\SystemRoot\System32\Drivers\mup.sys

\SystemRoot\System32\drivers\hwpolicy.sys

\SystemRoot\System32\DRIVERS\fvevol.sys

\SystemRoot\system32\DRIVERS\disk.sys

\SystemRoot\system32\DRIVERS\CLASSPNP.SYS

\SystemRoot\system32\drivers\BMLoad.sys

\SystemRoot\system32\DRIVERS\cdrom.sys

\SystemRoot\System32\Drivers\Null.SYS

\SystemRoot\System32\Drivers\Beep.SYS

\SystemRoot\system32\DRIVERS\l8042prt.sys

\SystemRoot\System32\DRIVERS\lkbdfltr.sys

\SystemRoot\System32\drivers\vga.sys

\SystemRoot\System32\drivers\VIDEOPRT.SYS

\SystemRoot\System32\drivers\watchdog.sys

\SystemRoot\System32\DRIVERS\RDPCDD.sys

\SystemRoot\system32\drivers\rdpencdd.sys

\SystemRoot\system32\drivers\rdprefmp.sys

\SystemRoot\System32\Drivers\Msfs.SYS

\SystemRoot\System32\Drivers\Npfs.SYS

\SystemRoot\System32\drivers\tcpip.sys

\SystemRoot\System32\drivers\fwpkclnt.sys

\SystemRoot\system32\DRIVERS\tdx.sys

\SystemRoot\system32\DRIVERS\TDI.SYS

\SystemRoot\System32\DRIVERS\netbt.sys

\SystemRoot\system32\drivers\afd.sys

\SystemRoot\system32\drivers\ws2ifsl.sys

\SystemRoot\system32\DRIVERS\wfplwf.sys

\SystemRoot\system32\DRIVERS\pacer.sys

\SystemRoot\system32\DRIVERS\vwififlt.sys

\SystemRoot\system32\DRIVERS\netbios.sys

\SystemRoot\system32\DRIVERS\wanarp.sys

\SystemRoot\system32\DRIVERS\termdd.sys

\SystemRoot\system32\DRIVERS\rdbss.sys

\SystemRoot\system32\drivers\nsiproxy.sys

\SystemRoot\system32\DRIVERS\mssmbios.sys

\SystemRoot\System32\drivers\discache.sys

\SystemRoot\System32\Drivers\dfsc.sys

\SystemRoot\system32\DRIVERS\blbdrive.sys

\SystemRoot\system32\DRIVERS\tunnel.sys

\SystemRoot\system32\DRIVERS\intelppm.sys

\SystemRoot\system32\DRIVERS\igdkmd32.sys

\SystemRoot\System32\Drivers\fastfat.SYS

\SystemRoot\System32\drivers\dxgkrnl.sys

\SystemRoot\System32\drivers\dxgmms1.sys

\SystemRoot\system32\DRIVERS\usbuhci.sys

\SystemRoot\system32\DRIVERS\USBPORT.SYS

\SystemRoot\system32\DRIVERS\usbehci.sys

\SystemRoot\system32\DRIVERS\HDAudBus.sys

\SystemRoot\system32\DRIVERS\rtl8192se.sys

\SystemRoot\system32\DRIVERS\vwifibus.sys

\SystemRoot\system32\DRIVERS\Rt86win7.sys

\SystemRoot\system32\DRIVERS\CmBatt.sys

\SystemRoot\system32\DRIVERS\wmiacpi.sys

\SystemRoot\system32\DRIVERS\CompositeBus.sys

\SystemRoot\system32\DRIVERS\AgileVpn.sys

\SystemRoot\system32\DRIVERS\rasl2tp.sys

\SystemRoot\system32\DRIVERS\ndistapi.sys

\SystemRoot\system32\DRIVERS\ndiswan.sys

\SystemRoot\system32\DRIVERS\raspppoe.sys

\SystemRoot\system32\DRIVERS\raspptp.sys

\SystemRoot\system32\DRIVERS\rassstp.sys

\SystemRoot\system32\DRIVERS\kbdclass.sys

\SystemRoot\system32\DRIVERS\mouclass.sys

\SystemRoot\system32\DRIVERS\mcdbus.sys

\SystemRoot\system32\DRIVERS\SCSIPORT.SYS

\SystemRoot\system32\DRIVERS\swenum.sys

\SystemRoot\system32\DRIVERS\ks.sys

\SystemRoot\system32\DRIVERS\umbus.sys

\SystemRoot\system32\DRIVERS\usbhub.sys

\SystemRoot\System32\Drivers\NDProxy.SYS

\SystemRoot\system32\DRIVERS\stwrt.sys

\SystemRoot\system32\DRIVERS\portcls.sys

\SystemRoot\system32\DRIVERS\drmk.sys

\SystemRoot\system32\DRIVERS\AGRSM.sys

\SystemRoot\system32\DRIVERS\USBD.SYS

\SystemRoot\system32\drivers\modem.sys

\SystemRoot\system32\drivers\IntcHdmi.sys

\SystemRoot\system32\DRIVERS\cdfs.sys

\SystemRoot\System32\win32k.sys

\SystemRoot\System32\drivers\Dxapi.sys

\SystemRoot\system32\DRIVERS\udfs.sys

\SystemRoot\System32\Drivers\crashdmp.sys

\SystemRoot\System32\Drivers\dump_iaStor.sys

\SystemRoot\System32\Drivers\dump_dumpfve.sys

\SystemRoot\system32\DRIVERS\monitor.sys

\SystemRoot\System32\TSDDD.dll

\SystemRoot\system32\DRIVERS\usbccgp.sys

\SystemRoot\System32\cdd.dll

\SystemRoot\system32\DRIVERS\snp2uvc.sys

\SystemRoot\system32\DRIVERS\STREAM.SYS

\SystemRoot\system32\DRIVERS\sncduvc.SYS

\SystemRoot\system32\DRIVERS\hidusb.sys

\SystemRoot\system32\DRIVERS\HIDCLASS.SYS

\SystemRoot\system32\DRIVERS\HIDPARSE.SYS

\SystemRoot\system32\DRIVERS\kbdhid.sys

\SystemRoot\system32\DRIVERS\mouhid.sys

\SystemRoot\System32\ATMFD.DLL

\SystemRoot\system32\drivers\WudfPf.sys

\SystemRoot\system32\DRIVERS\lltdio.sys

\SystemRoot\system32\DRIVERS\nwifi.sys

\SystemRoot\system32\DRIVERS\ndisuio.sys

\SystemRoot\system32\DRIVERS\rspndr.sys

\SystemRoot\system32\drivers\HTTP.sys

\SystemRoot\System32\DRIVERS\srvnet.sys

\SystemRoot\system32\DRIVERS\bowser.sys

\SystemRoot\system32\DRIVERS\mrxsmb.sys

\SystemRoot\system32\DRIVERS\mrxsmb10.sys

\SystemRoot\system32\DRIVERS\mrxsmb20.sys

\SystemRoot\System32\DRIVERS\srv2.sys

\SystemRoot\System32\DRIVERS\srv.sys

\SystemRoot\system32\DRIVERS\lirsgt.sys

\SystemRoot\system32\drivers\peauth.sys

\SystemRoot\System32\Drivers\secdrv.SYS

\SystemRoot\System32\drivers\tcpipreg.sys

\??\C:\windows\system32\drivers\TrueSight.sys

\SystemRoot\system32\DRIVERS\BcmBusCtr.sys

\SystemRoot\system32\DRIVERS\drxvi314.sys

\??\C:\windows\system32\drivers\mbamchameleon.sys

\??\C:\windows\system32\drivers\mbamswissarmy.sys

\Windows\System32\ntdll.dll

\Windows\System32\smss.exe

\Windows\System32\apisetschema.dll

\Windows\System32\autochk.exe

\Windows\System32\normaliz.dll

\Windows\System32\clbcatq.dll

\Windows\System32\setupapi.dll

\Windows\System32\nsi.dll

\Windows\System32\wininet.dll

\Windows\System32\ws2_32.dll

\Windows\System32\oleaut32.dll

\Windows\System32\comdlg32.dll

\Windows\System32\shell32.dll

\Windows\System32\advapi32.dll

\Windows\System32\rpcrt4.dll

\Windows\System32\msctf.dll

\Windows\System32\user32.dll

\Windows\System32\gdi32.dll

\Windows\System32\iertutil.dll

\Windows\System32\difxapi.dll

\Windows\System32\msvcrt.dll

\Windows\System32\ole32.dll

\Windows\System32\imagehlp.dll

\Windows\System32\psapi.dll

\Windows\System32\Wldap32.dll

\Windows\System32\kernel32.dll

\Windows\System32\lpk.dll

\Windows\System32\urlmon.dll

\Windows\System32\shlwapi.dll

\Windows\System32\sechost.dll

\Windows\System32\usp10.dll

\Windows\System32\imm32.dll

\Windows\System32\KernelBase.dll

\Windows\System32\wintrust.dll

\Windows\System32\comctl32.dll

\Windows\System32\devobj.dll

\Windows\System32\cfgmgr32.dll

\Windows\System32\crypt32.dll

\Windows\System32\msasn1.dll

----------- End -----------

<<<1>>>

Upper Device Name: \Device\Harddisk0\DR0

Upper Device Object: 0xffffffff86539030

Upper Device Driver Name: \Driver\Disk\

Lower Device Name: \Device\Ide\IAAStorageDevice-1\

Lower Device Object: 0xffffffff85b44028

Lower Device Driver Name: \Driver\iaStor\

Driver name found: iaStor

Initialization returned 0x0

Load Function returned 0x0

Downloaded database version: v2013.03.08.11

Initializing...

Done!

<<<2>>>

Device number: 0, partition: 2

Physical Sector Size: 512

Drive: 0, DevicePointer: 0xffffffff86539030, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\

--------- Disk Stack ------

DevicePointer: 0xffffffff865382a8, DeviceName: Unknown, DriverName: \Driver\partmgr\

DevicePointer: 0xffffffff86539030, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\

DevicePointer: 0xffffffff85b92690, DeviceName: Unknown, DriverName: \Driver\ACPI\

DevicePointer: 0xffffffff85b44028, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\

------------ End ----------

Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\

Upper DeviceData: 0xffffffffbf2ff380, 0xffffffff86539030, 0xffffffff852937d0

Lower DeviceData: 0xffffffffbb72e090, 0xffffffff85b44028, 0xffffffff84f5b418

<<<3>>>

Volume: C:

File system type: NTFS

SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes

Scanning directory: C:\windows\system32\drivers...

<<<2>>>

Device number: 0, partition: 2

<<<3>>>

Volume: C:

File system type: NTFS

SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes

Done!

Drive 0

Scanning MBR on drive 0...

Inspecting partition table:

MBR Signature: 55AA

Disk Signature: 63A576A1

Partition information:

Partition 0 type is Primary (0x7)

Partition is ACTIVE.

Partition starts at LBA: 2048 Numsec = 614400

Partition file system is NTFS

Partition is bootable

Partition 1 type is Primary (0x7)

Partition is NOT ACTIVE.

Partition starts at LBA: 616448 Numsec = 588869632

Partition 2 type is Primary (0x7)

Partition is NOT ACTIVE.

Partition starts at LBA: 589486080 Numsec = 31457280

Partition 3 type is Other (0xc)

Partition is NOT ACTIVE.

Partition starts at LBA: 620943360 Numsec = 4184064

Disk Size: 320072933376 bytes

Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-2047-625122448-625142448)...

Done!

Performing system, memory and registry scan...

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\Hawkes Update Service Manager.dat" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\instance.dat" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\{7CD6B202-CDCC-48CF-9B96-268A94BD97FB}.native.bitness.log" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\{7CD6B202-CDCC-48CF-9B96-268A94BD97FB}.native.elements.log" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\{7CD6B202-CDCC-48CF-9B96-268A94BD97FB}.native.weight.log" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\Hawkes Update Service Manager.dat" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\instance.dat" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\{7CD6B202-CDCC-48CF-9B96-268A94BD97FB}.native.bitness.log" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\{7CD6B202-CDCC-48CF-9B96-268A94BD97FB}.native.elements.log" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\{7CD6B202-CDCC-48CF-9B96-268A94BD97FB}.native.weight.log" is compressed (flags = 1)

Infected: HKCU\SOFTWARE\CLASSES\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9} --> [Hijack.Trojan.Siredef.C]

Infected: c:\$RECYCLE.BIN\S-1-5-18\$39fa3f49bd9941b5e75d6dd27e0edb3b --> [Trojan.Siredef.C]

Infected: c:\$RECYCLE.BIN\S-1-5-21-169340207-3269167449-2088699052-1002\$39fa3f49bd9941b5e75d6dd27e0edb3b --> [Trojan.Siredef.C]

Done!

Scan finished

Creating System Restore point...

Scheduling clean up...

<<<2>>>

Device number: 0, partition: 2

<<<3>>>

Volume: C:

File system type: NTFS

SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes

Removal successful. No system shutdown is required.

=======================================

---------------------------------------

Malwarebytes Anti-Rootkit BETA 1.01.0.1021

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7600 Windows 7 x86

Account is Administrative

Internet Explorer version: 8.0.7600.16385

Java version: 1.6.0_32

File system is: NTFS

Disk drives: C:\ DRIVE_FIXED, F:\ DRIVE_FIXED

CPU speed: 1.662000 GHz

Memory total: 2072264704, free: 623271936

------------ Kernel report ------------

03/08/2013 08:51:02

------------ Loaded modules -----------

\SystemRoot\system32\ntkrnlpa.exe

\SystemRoot\system32\halmacpi.dll

\SystemRoot\system32\kdcom.dll

\SystemRoot\system32\mcupdate_GenuineIntel.dll

\SystemRoot\system32\PSHED.dll

\SystemRoot\system32\BOOTVID.dll

\SystemRoot\system32\CLFS.SYS

\SystemRoot\system32\CI.dll

\SystemRoot\System32\drivers\wfvsi.sys

\SystemRoot\system32\drivers\Wdf01000.sys

\SystemRoot\system32\drivers\WDFLDR.SYS

\SystemRoot\system32\DRIVERS\ACPI.sys

\SystemRoot\system32\DRIVERS\WMILIB.SYS

\SystemRoot\system32\DRIVERS\msisadrv.sys

\SystemRoot\system32\DRIVERS\pci.sys

\SystemRoot\system32\DRIVERS\vdrvroot.sys

\SystemRoot\System32\drivers\partmgr.sys

\SystemRoot\system32\DRIVERS\compbatt.sys

\SystemRoot\system32\DRIVERS\BATTC.SYS

\SystemRoot\system32\DRIVERS\volmgr.sys

\SystemRoot\System32\drivers\volmgrx.sys

\SystemRoot\System32\drivers\mountmgr.sys

\SystemRoot\system32\DRIVERS\iaStor.sys

\SystemRoot\system32\DRIVERS\amdxata.sys

\SystemRoot\system32\drivers\fltmgr.sys

\SystemRoot\system32\drivers\fileinfo.sys

\SystemRoot\System32\Drivers\PxHelp20.sys

\SystemRoot\System32\Drivers\Ntfs.sys

\SystemRoot\System32\Drivers\msrpc.sys

\SystemRoot\System32\Drivers\ksecdd.sys

\SystemRoot\System32\Drivers\cng.sys

\SystemRoot\System32\drivers\pcw.sys

\SystemRoot\System32\Drivers\Fs_Rec.sys

\SystemRoot\system32\drivers\ndis.sys

\SystemRoot\system32\drivers\NETIO.SYS

\SystemRoot\System32\Drivers\ksecpkg.sys

\SystemRoot\system32\DRIVERS\volsnap.sys

\SystemRoot\System32\Drivers\spldr.sys

\SystemRoot\System32\drivers\rdyboost.sys

\SystemRoot\System32\Drivers\mup.sys

\SystemRoot\System32\drivers\hwpolicy.sys

\SystemRoot\System32\DRIVERS\fvevol.sys

\SystemRoot\system32\DRIVERS\disk.sys

\SystemRoot\system32\DRIVERS\CLASSPNP.SYS

\SystemRoot\system32\drivers\BMLoad.sys

\SystemRoot\system32\DRIVERS\cdrom.sys

\SystemRoot\System32\Drivers\Null.SYS

\SystemRoot\System32\Drivers\Beep.SYS

\SystemRoot\system32\DRIVERS\l8042prt.sys

\SystemRoot\System32\DRIVERS\lkbdfltr.sys

\SystemRoot\System32\drivers\vga.sys

\SystemRoot\System32\drivers\VIDEOPRT.SYS

\SystemRoot\System32\drivers\watchdog.sys

\SystemRoot\System32\DRIVERS\RDPCDD.sys

\SystemRoot\system32\drivers\rdpencdd.sys

\SystemRoot\system32\drivers\rdprefmp.sys

\SystemRoot\System32\Drivers\Msfs.SYS

\SystemRoot\System32\Drivers\Npfs.SYS

\SystemRoot\System32\drivers\tcpip.sys

\SystemRoot\System32\drivers\fwpkclnt.sys

\SystemRoot\system32\DRIVERS\tdx.sys

\SystemRoot\system32\DRIVERS\TDI.SYS

\SystemRoot\System32\DRIVERS\netbt.sys

\SystemRoot\system32\drivers\afd.sys

\SystemRoot\system32\drivers\ws2ifsl.sys

\SystemRoot\system32\DRIVERS\wfplwf.sys

\SystemRoot\system32\DRIVERS\pacer.sys

\SystemRoot\system32\DRIVERS\vwififlt.sys

\SystemRoot\system32\DRIVERS\netbios.sys

\SystemRoot\system32\DRIVERS\wanarp.sys

\SystemRoot\system32\DRIVERS\termdd.sys

\SystemRoot\system32\DRIVERS\rdbss.sys

\SystemRoot\system32\drivers\nsiproxy.sys

\SystemRoot\system32\DRIVERS\mssmbios.sys

\SystemRoot\System32\drivers\discache.sys

\SystemRoot\System32\Drivers\dfsc.sys

\SystemRoot\system32\DRIVERS\blbdrive.sys

\SystemRoot\system32\DRIVERS\tunnel.sys

\SystemRoot\system32\DRIVERS\intelppm.sys

\SystemRoot\system32\DRIVERS\igdkmd32.sys

\SystemRoot\System32\Drivers\fastfat.SYS

\SystemRoot\System32\drivers\dxgkrnl.sys

\SystemRoot\System32\drivers\dxgmms1.sys

\SystemRoot\system32\DRIVERS\usbuhci.sys

\SystemRoot\system32\DRIVERS\USBPORT.SYS

\SystemRoot\system32\DRIVERS\usbehci.sys

\SystemRoot\system32\DRIVERS\HDAudBus.sys

\SystemRoot\system32\DRIVERS\rtl8192se.sys

\SystemRoot\system32\DRIVERS\vwifibus.sys

\SystemRoot\system32\DRIVERS\Rt86win7.sys

\SystemRoot\system32\DRIVERS\CmBatt.sys

\SystemRoot\system32\DRIVERS\wmiacpi.sys

\SystemRoot\system32\DRIVERS\CompositeBus.sys

\SystemRoot\system32\DRIVERS\AgileVpn.sys

\SystemRoot\system32\DRIVERS\rasl2tp.sys

\SystemRoot\system32\DRIVERS\ndistapi.sys

\SystemRoot\system32\DRIVERS\ndiswan.sys

\SystemRoot\system32\DRIVERS\raspppoe.sys

\SystemRoot\system32\DRIVERS\raspptp.sys

\SystemRoot\system32\DRIVERS\rassstp.sys

\SystemRoot\system32\DRIVERS\kbdclass.sys

\SystemRoot\system32\DRIVERS\mouclass.sys

\SystemRoot\system32\DRIVERS\mcdbus.sys

\SystemRoot\system32\DRIVERS\SCSIPORT.SYS

\SystemRoot\system32\DRIVERS\swenum.sys

\SystemRoot\system32\DRIVERS\ks.sys

\SystemRoot\system32\DRIVERS\umbus.sys

\SystemRoot\system32\DRIVERS\usbhub.sys

\SystemRoot\System32\Drivers\NDProxy.SYS

\SystemRoot\system32\DRIVERS\stwrt.sys

\SystemRoot\system32\DRIVERS\portcls.sys

\SystemRoot\system32\DRIVERS\drmk.sys

\SystemRoot\system32\DRIVERS\AGRSM.sys

\SystemRoot\system32\DRIVERS\USBD.SYS

\SystemRoot\system32\drivers\modem.sys

\SystemRoot\system32\drivers\IntcHdmi.sys

\SystemRoot\system32\DRIVERS\cdfs.sys

\SystemRoot\System32\win32k.sys

\SystemRoot\System32\drivers\Dxapi.sys

\SystemRoot\system32\DRIVERS\udfs.sys

\SystemRoot\System32\Drivers\crashdmp.sys

\SystemRoot\System32\Drivers\dump_iaStor.sys

\SystemRoot\System32\Drivers\dump_dumpfve.sys

\SystemRoot\system32\DRIVERS\monitor.sys

\SystemRoot\System32\TSDDD.dll

\SystemRoot\system32\DRIVERS\usbccgp.sys

\SystemRoot\System32\cdd.dll

\SystemRoot\system32\DRIVERS\snp2uvc.sys

\SystemRoot\system32\DRIVERS\STREAM.SYS

\SystemRoot\system32\DRIVERS\sncduvc.SYS

\SystemRoot\system32\DRIVERS\hidusb.sys

\SystemRoot\system32\DRIVERS\HIDCLASS.SYS

\SystemRoot\system32\DRIVERS\HIDPARSE.SYS

\SystemRoot\system32\DRIVERS\kbdhid.sys

\SystemRoot\system32\DRIVERS\mouhid.sys

\SystemRoot\System32\ATMFD.DLL

\SystemRoot\system32\drivers\WudfPf.sys

\SystemRoot\system32\DRIVERS\lltdio.sys

\SystemRoot\system32\DRIVERS\nwifi.sys

\SystemRoot\system32\DRIVERS\ndisuio.sys

\SystemRoot\system32\DRIVERS\rspndr.sys

\SystemRoot\system32\drivers\HTTP.sys

\SystemRoot\System32\DRIVERS\srvnet.sys

\SystemRoot\system32\DRIVERS\bowser.sys

\SystemRoot\system32\DRIVERS\mrxsmb.sys

\SystemRoot\system32\DRIVERS\mrxsmb10.sys

\SystemRoot\system32\DRIVERS\mrxsmb20.sys

\SystemRoot\System32\DRIVERS\srv2.sys

\SystemRoot\System32\DRIVERS\srv.sys

\SystemRoot\system32\DRIVERS\lirsgt.sys

\SystemRoot\system32\drivers\peauth.sys

\SystemRoot\System32\Drivers\secdrv.SYS

\SystemRoot\System32\drivers\tcpipreg.sys

\??\C:\windows\system32\drivers\TrueSight.sys

\SystemRoot\system32\DRIVERS\BcmBusCtr.sys

\SystemRoot\system32\DRIVERS\drxvi314.sys

\??\C:\windows\system32\drivers\mbamchameleon.sys

\??\C:\windows\system32\drivers\mbamswissarmy.sys

\Windows\System32\ntdll.dll

\Windows\System32\smss.exe

\Windows\System32\apisetschema.dll

\Windows\System32\autochk.exe

\Windows\System32\normaliz.dll

\Windows\System32\clbcatq.dll

\Windows\System32\setupapi.dll

\Windows\System32\nsi.dll

\Windows\System32\wininet.dll

\Windows\System32\ws2_32.dll

\Windows\System32\oleaut32.dll

\Windows\System32\comdlg32.dll

\Windows\System32\shell32.dll

\Windows\System32\advapi32.dll

\Windows\System32\rpcrt4.dll

\Windows\System32\msctf.dll

\Windows\System32\user32.dll

\Windows\System32\gdi32.dll

\Windows\System32\iertutil.dll

\Windows\System32\difxapi.dll

\Windows\System32\msvcrt.dll

\Windows\System32\ole32.dll

\Windows\System32\imagehlp.dll

\Windows\System32\psapi.dll

\Windows\System32\Wldap32.dll

\Windows\System32\kernel32.dll

\Windows\System32\lpk.dll

\Windows\System32\urlmon.dll

\Windows\System32\shlwapi.dll

\Windows\System32\sechost.dll

\Windows\System32\usp10.dll

\Windows\System32\imm32.dll

\Windows\System32\KernelBase.dll

\Windows\System32\wintrust.dll

\Windows\System32\comctl32.dll

\Windows\System32\devobj.dll

\Windows\System32\cfgmgr32.dll

\Windows\System32\crypt32.dll

\Windows\System32\msasn1.dll

----------- End -----------

<<<1>>>

Upper Device Name: \Device\Harddisk0\DR0

Upper Device Object: 0xffffffff86539030

Upper Device Driver Name: \Driver\Disk\

Lower Device Name: \Device\Ide\IAAStorageDevice-1\

Lower Device Object: 0xffffffff85b44028

Lower Device Driver Name: \Driver\iaStor\

Device already Exists: 0xffffffff84f5b418

=======================================

---------------------------------------

Malwarebytes Anti-Rootkit BETA 1.01.0.1021

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7600 Windows 7 x86

Account is Administrative

Internet Explorer version: 8.0.7600.16385

Java version: 1.6.0_32

File system is: NTFS

Disk drives: C:\ DRIVE_FIXED, F:\ DRIVE_FIXED

CPU speed: 1.662000 GHz

Memory total: 2072264704, free: 719425536

------------ Kernel report ------------

03/08/2013 08:52:54

------------ Loaded modules -----------

\SystemRoot\system32\ntkrnlpa.exe

\SystemRoot\system32\halmacpi.dll

\SystemRoot\system32\kdcom.dll

\SystemRoot\system32\mcupdate_GenuineIntel.dll

\SystemRoot\system32\PSHED.dll

\SystemRoot\system32\BOOTVID.dll

\SystemRoot\system32\CLFS.SYS

\SystemRoot\system32\CI.dll

\SystemRoot\System32\drivers\wfvsi.sys

\SystemRoot\system32\drivers\Wdf01000.sys

\SystemRoot\system32\drivers\WDFLDR.SYS

\SystemRoot\system32\DRIVERS\ACPI.sys

\SystemRoot\system32\DRIVERS\WMILIB.SYS

\SystemRoot\system32\DRIVERS\msisadrv.sys

\SystemRoot\system32\DRIVERS\pci.sys

\SystemRoot\system32\DRIVERS\vdrvroot.sys

\SystemRoot\System32\drivers\partmgr.sys

\SystemRoot\system32\DRIVERS\compbatt.sys

\SystemRoot\system32\DRIVERS\BATTC.SYS

\SystemRoot\system32\DRIVERS\volmgr.sys

\SystemRoot\System32\drivers\volmgrx.sys

\SystemRoot\System32\drivers\mountmgr.sys

\SystemRoot\system32\DRIVERS\iaStor.sys

\SystemRoot\system32\DRIVERS\amdxata.sys

\SystemRoot\system32\drivers\fltmgr.sys

\SystemRoot\system32\drivers\fileinfo.sys

\SystemRoot\System32\Drivers\PxHelp20.sys

\SystemRoot\System32\Drivers\Ntfs.sys

\SystemRoot\System32\Drivers\msrpc.sys

\SystemRoot\System32\Drivers\ksecdd.sys

\SystemRoot\System32\Drivers\cng.sys

\SystemRoot\System32\drivers\pcw.sys

\SystemRoot\System32\Drivers\Fs_Rec.sys

\SystemRoot\system32\drivers\ndis.sys

\SystemRoot\system32\drivers\NETIO.SYS

\SystemRoot\System32\Drivers\ksecpkg.sys

\SystemRoot\system32\DRIVERS\volsnap.sys

\SystemRoot\System32\Drivers\spldr.sys

\SystemRoot\System32\drivers\rdyboost.sys

\SystemRoot\System32\Drivers\mup.sys

\SystemRoot\System32\drivers\hwpolicy.sys

\SystemRoot\System32\DRIVERS\fvevol.sys

\SystemRoot\system32\DRIVERS\disk.sys

\SystemRoot\system32\DRIVERS\CLASSPNP.SYS

\SystemRoot\system32\drivers\BMLoad.sys

\SystemRoot\system32\DRIVERS\cdrom.sys

\SystemRoot\System32\Drivers\Null.SYS

\SystemRoot\System32\Drivers\Beep.SYS

\SystemRoot\system32\DRIVERS\l8042prt.sys

\SystemRoot\System32\DRIVERS\lkbdfltr.sys

\SystemRoot\System32\drivers\vga.sys

\SystemRoot\System32\drivers\VIDEOPRT.SYS

\SystemRoot\System32\drivers\watchdog.sys

\SystemRoot\System32\DRIVERS\RDPCDD.sys

\SystemRoot\system32\drivers\rdpencdd.sys

\SystemRoot\system32\drivers\rdprefmp.sys

\SystemRoot\System32\Drivers\Msfs.SYS

\SystemRoot\System32\Drivers\Npfs.SYS

\SystemRoot\System32\drivers\tcpip.sys

\SystemRoot\System32\drivers\fwpkclnt.sys

\SystemRoot\system32\DRIVERS\tdx.sys

\SystemRoot\system32\DRIVERS\TDI.SYS

\SystemRoot\System32\DRIVERS\netbt.sys

\SystemRoot\system32\drivers\afd.sys

\SystemRoot\system32\drivers\ws2ifsl.sys

\SystemRoot\system32\DRIVERS\wfplwf.sys

\SystemRoot\system32\DRIVERS\pacer.sys

\SystemRoot\system32\DRIVERS\vwififlt.sys

\SystemRoot\system32\DRIVERS\netbios.sys

\SystemRoot\system32\DRIVERS\wanarp.sys

\SystemRoot\system32\DRIVERS\termdd.sys

\SystemRoot\system32\DRIVERS\rdbss.sys

\SystemRoot\system32\drivers\nsiproxy.sys

\SystemRoot\system32\DRIVERS\mssmbios.sys

\SystemRoot\System32\drivers\discache.sys

\SystemRoot\System32\Drivers\dfsc.sys

\SystemRoot\system32\DRIVERS\blbdrive.sys

\SystemRoot\system32\DRIVERS\tunnel.sys

\SystemRoot\system32\DRIVERS\intelppm.sys

\SystemRoot\system32\DRIVERS\igdkmd32.sys

\SystemRoot\System32\Drivers\fastfat.SYS

\SystemRoot\System32\drivers\dxgkrnl.sys

\SystemRoot\System32\drivers\dxgmms1.sys

\SystemRoot\system32\DRIVERS\usbuhci.sys

\SystemRoot\system32\DRIVERS\USBPORT.SYS

\SystemRoot\system32\DRIVERS\usbehci.sys

\SystemRoot\system32\DRIVERS\HDAudBus.sys

\SystemRoot\system32\DRIVERS\rtl8192se.sys

\SystemRoot\system32\DRIVERS\vwifibus.sys

\SystemRoot\system32\DRIVERS\Rt86win7.sys

\SystemRoot\system32\DRIVERS\CmBatt.sys

\SystemRoot\system32\DRIVERS\wmiacpi.sys

\SystemRoot\system32\DRIVERS\CompositeBus.sys

\SystemRoot\system32\DRIVERS\AgileVpn.sys

\SystemRoot\system32\DRIVERS\rasl2tp.sys

\SystemRoot\system32\DRIVERS\ndistapi.sys

\SystemRoot\system32\DRIVERS\ndiswan.sys

\SystemRoot\system32\DRIVERS\raspppoe.sys

\SystemRoot\system32\DRIVERS\raspptp.sys

\SystemRoot\system32\DRIVERS\rassstp.sys

\SystemRoot\system32\DRIVERS\kbdclass.sys

\SystemRoot\system32\DRIVERS\mouclass.sys

\SystemRoot\system32\DRIVERS\mcdbus.sys

\SystemRoot\system32\DRIVERS\SCSIPORT.SYS

\SystemRoot\system32\DRIVERS\swenum.sys

\SystemRoot\system32\DRIVERS\ks.sys

\SystemRoot\system32\DRIVERS\umbus.sys

\SystemRoot\system32\DRIVERS\usbhub.sys

\SystemRoot\System32\Drivers\NDProxy.SYS

\SystemRoot\system32\DRIVERS\stwrt.sys

\SystemRoot\system32\DRIVERS\portcls.sys

\SystemRoot\system32\DRIVERS\drmk.sys

\SystemRoot\system32\DRIVERS\AGRSM.sys

\SystemRoot\system32\DRIVERS\USBD.SYS

\SystemRoot\system32\drivers\modem.sys

\SystemRoot\system32\drivers\IntcHdmi.sys

\SystemRoot\system32\DRIVERS\cdfs.sys

\SystemRoot\System32\win32k.sys

\SystemRoot\System32\drivers\Dxapi.sys

\SystemRoot\system32\DRIVERS\udfs.sys

\SystemRoot\System32\Drivers\crashdmp.sys

\SystemRoot\System32\Drivers\dump_iaStor.sys

\SystemRoot\System32\Drivers\dump_dumpfve.sys

\SystemRoot\system32\DRIVERS\monitor.sys

\SystemRoot\System32\TSDDD.dll

\SystemRoot\system32\DRIVERS\usbccgp.sys

\SystemRoot\System32\cdd.dll

\SystemRoot\system32\DRIVERS\snp2uvc.sys

\SystemRoot\system32\DRIVERS\STREAM.SYS

\SystemRoot\system32\DRIVERS\sncduvc.SYS

\SystemRoot\system32\DRIVERS\hidusb.sys

\SystemRoot\system32\DRIVERS\HIDCLASS.SYS

\SystemRoot\system32\DRIVERS\HIDPARSE.SYS

\SystemRoot\system32\DRIVERS\kbdhid.sys

\SystemRoot\system32\DRIVERS\mouhid.sys

\SystemRoot\System32\ATMFD.DLL

\SystemRoot\system32\drivers\WudfPf.sys

\SystemRoot\system32\DRIVERS\lltdio.sys

\SystemRoot\system32\DRIVERS\nwifi.sys

\SystemRoot\system32\DRIVERS\ndisuio.sys

\SystemRoot\system32\DRIVERS\rspndr.sys

\SystemRoot\system32\drivers\HTTP.sys

\SystemRoot\System32\DRIVERS\srvnet.sys

\SystemRoot\system32\DRIVERS\bowser.sys

\SystemRoot\system32\DRIVERS\mrxsmb.sys

\SystemRoot\system32\DRIVERS\mrxsmb10.sys

\SystemRoot\system32\DRIVERS\mrxsmb20.sys

\SystemRoot\System32\DRIVERS\srv2.sys

\SystemRoot\System32\DRIVERS\srv.sys

\SystemRoot\system32\DRIVERS\lirsgt.sys

\SystemRoot\system32\drivers\peauth.sys

\SystemRoot\System32\Drivers\secdrv.SYS

\SystemRoot\System32\drivers\tcpipreg.sys

\SystemRoot\system32\DRIVERS\BcmBusCtr.sys

\SystemRoot\system32\DRIVERS\drxvi314.sys

\??\C:\windows\system32\drivers\mbamchameleon.sys

\??\C:\windows\system32\drivers\mbamswissarmy.sys

\Windows\System32\ntdll.dll

\Windows\System32\smss.exe

\Windows\System32\apisetschema.dll

\Windows\System32\autochk.exe

\Windows\System32\normaliz.dll

\Windows\System32\clbcatq.dll

\Windows\System32\setupapi.dll

\Windows\System32\nsi.dll

\Windows\System32\wininet.dll

\Windows\System32\ws2_32.dll

\Windows\System32\oleaut32.dll

\Windows\System32\comdlg32.dll

\Windows\System32\shell32.dll

\Windows\System32\advapi32.dll

\Windows\System32\rpcrt4.dll

\Windows\System32\msctf.dll

\Windows\System32\user32.dll

\Windows\System32\gdi32.dll

\Windows\System32\iertutil.dll

\Windows\System32\difxapi.dll

\Windows\System32\msvcrt.dll

\Windows\System32\ole32.dll

\Windows\System32\imagehlp.dll

\Windows\System32\psapi.dll

\Windows\System32\Wldap32.dll

\Windows\System32\kernel32.dll

\Windows\System32\lpk.dll

\Windows\System32\urlmon.dll

\Windows\System32\shlwapi.dll

\Windows\System32\sechost.dll

\Windows\System32\usp10.dll

\Windows\System32\imm32.dll

\Windows\System32\KernelBase.dll

\Windows\System32\wintrust.dll

\Windows\System32\comctl32.dll

\Windows\System32\devobj.dll

\Windows\System32\cfgmgr32.dll

\Windows\System32\crypt32.dll

\Windows\System32\msasn1.dll

----------- End -----------

<<<1>>>

Upper Device Name: \Device\Harddisk0\DR0

Upper Device Object: 0xffffffff86539030

Upper Device Driver Name: \Driver\Disk\

Lower Device Name: \Device\Ide\IAAStorageDevice-1\

Lower Device Object: 0xffffffff85b44028

Lower Device Driver Name: \Driver\iaStor\

Device already Exists: 0xffffffff84f5b418

Initializing...

Done!

<<<2>>>

Device number: 0, partition: 2

Physical Sector Size: 512

Drive: 0, DevicePointer: 0xffffffff86539030, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\

--------- Disk Stack ------

DevicePointer: 0xffffffff865382a8, DeviceName: Unknown, DriverName: \Driver\partmgr\

DevicePointer: 0xffffffff86539030, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\

DevicePointer: 0xffffffff85b92690, DeviceName: Unknown, DriverName: \Driver\ACPI\

DevicePointer: 0xffffffff85b44028, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\

------------ End ----------

Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\

Upper DeviceData: 0xffffffffb11745e8, 0xffffffff86539030, 0xffffffff852937d0

Lower DeviceData: 0xffffffffc9b322b0, 0xffffffff85b44028, 0xffffffff84f5b418

<<<3>>>

Volume: C:

File system type: NTFS

SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes

Scanning directory: C:\windows\system32\drivers...

<<<2>>>

Device number: 0, partition: 2

<<<3>>>

Volume: C:

File system type: NTFS

SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes

Done!

Drive 0

Scanning MBR on drive 0...

Inspecting partition table:

MBR Signature: 55AA

Disk Signature: 63A576A1

Partition information:

Partition 0 type is Primary (0x7)

Partition is ACTIVE.

Partition starts at LBA: 2048 Numsec = 614400

Partition file system is NTFS

Partition is bootable

Partition 1 type is Primary (0x7)

Partition is NOT ACTIVE.

Partition starts at LBA: 616448 Numsec = 588869632

Partition 2 type is Primary (0x7)

Partition is NOT ACTIVE.

Partition starts at LBA: 589486080 Numsec = 31457280

Partition 3 type is Other (0xc)

Partition is NOT ACTIVE.

Partition starts at LBA: 620943360 Numsec = 4184064

Disk Size: 320072933376 bytes

Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-2047-625122448-625142448)...

Done!

Performing system, memory and registry scan...

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\Hawkes Update Service Manager.dat" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\instance.dat" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\{7CD6B202-CDCC-48CF-9B96-268A94BD97FB}.native.bitness.log" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\{7CD6B202-CDCC-48CF-9B96-268A94BD97FB}.native.elements.log" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\{7CD6B202-CDCC-48CF-9B96-268A94BD97FB}.native.weight.log" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\Hawkes Update Service Manager.dat" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\instance.dat" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\{7CD6B202-CDCC-48CF-9B96-268A94BD97FB}.native.bitness.log" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\{7CD6B202-CDCC-48CF-9B96-268A94BD97FB}.native.elements.log" is compressed (flags = 1)

Read File: File "c:\ProgramData\{590548D5-2A97-4BA8-9027-807D9222F023}\{7CD6B202-CDCC-48CF-9B96-268A94BD97FB}.native.weight.log" is compressed (flags = 1)

Done!

Scan finished

=======================================

Link to post
Share on other sites

It's important to follow through an d make sure there's no left overs:

Please download and run ComboFix.

The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.

Please visit this webpage for download links, and instructions for running ComboFix

http://www.bleepingc...to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Information on disabling your malware programs can be found Here.

Make sure you run ComboFix from your desktop.

Give it at least 30-45 minutes to finish if needed.

Please include the C:\ComboFix.txt in your next reply for further review.

---------->NOTE<----------

If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix....please reboot the computer, this should resolve the problem. You may have to do this several times if needed.

MrC

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.