Jump to content

PERVASIVE RESISTANT MALWARE PROBLEM PLEASE HELP!


Recommended Posts

DDS (Ver_2012-11-20.01) - NTFS_x86 NETWORK
Internet Explorer: 9.0.8112.16526
Run by Krissi at 0:42:17 on 2014-01-27
#Option Extended Search is enabled.
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.2938.2025 [GMT -8:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.

uURLSearchHooks: <No Name>: {97ef77e6-97be-4204-a890-2485903c5624} -
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common

files\adobe\acrobat\activex\AcroIEHelperShim.dll
mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe

/install /silent
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program

files\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} -

842756A66467/MicrosoftDownloadManager.cab
TCP: NameServer = 68.105.28.12 68.105.29.12 68.105.28.11
TCP: Interfaces\{E00780F9-06A8-4D7E-B8D5-6A3D0C1989F1} : DHCPNameServer = 68.105.28.12 68.105.29.12

68.105.28.11
Notify: igfxcui - igfxdev.dll
LSA: Security Packages =  kerberos msv1_0 schannel wdigest tspkg
.
============= SERVICES / DRIVERS ===============
.
R3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [2013-12-31 9344]
S0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2013-9-27

214696]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN

v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k

LocalServiceAndNoImpersonation [2014-1-7 21504]
S2 iprip;RIP Listener;c:\windows\system32\svchost.exe -k ipripsvc [2014-1-7 21504]
S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2013-9-27

104768]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2013

-10-23 280288]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache

4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2013-9-11 770168]
S4 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2014-1-27 107224]
S4 SampleCollector;Intel® Sample Collector;c:\program files\sony\vaio care\collsvc.exe [2014-1-21

122880]
.
=============== Created Last 60 ================
.
2014-01-27 08:22:03 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-01-27 08:21:51 107224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2014-01-27 08:21:46 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-01-27 06:32:12 -------- d-sh--w- C:\$RECYCLE.BIN
2014-01-27 06:25:39 7760024 ----a-w- c:\programdata\microsoft\microsoft

antimalware\definition updates\{12d87139-3a10-49f4-b154-5103b77f5ef7}\mpengine.dll
2014-01-27 04:22:00 -------- dc----w- c:\program files\Malwarebytes' Anti-Malware
2014-01-27 00:33:20 7760024 ----a-w- c:\programdata\microsoft\microsoft

antimalware\definition updates\backup\mpengine.dll
2014-01-26 19:37:11 -------- dc----w- 

c:\users\krissi\appdata\roaming\Malwarebytes
2014-01-26 13:58:05 -------- dc----w- c:\windows\Downloaded Program Files
2014-01-26 10:45:24 -------- dc----w- c:\programdata\Application Data(201)
2014-01-25 16:29:43 -------- dc----w- c:\users\krissi\appdata\local\Microsoft

Games
2014-01-24 05:19:31 859720 -c--a-w- c:\program files\69Uninstall PackageTracer.dll
2014-01-24 05:19:31 189832 -c--a-w- c:\program files\69res.dll
2014-01-24 03:23:46 -------- dc--a-w- c:\program files\PackageTracer_69EI
2014-01-23 07:08:24 719224 ------w- c:\programdata\microsoft\microsoft

antimalware\definition updates\{bd88331e-f2dd-403f-bf1c-4ac89adda7ee}\gapaengine.dll
2014-01-23 06:20:09 -------- dc----w- c:\programdata\Malwarebytes' Anti-Malware

(portable)
2014-01-23 06:14:55 -------- dc----w- c:\program files\FileASSASSIN
2014-01-23 05:46:49 719224 ------w- c:\programdata\microsoft\microsoft

antimalware\definition updates\nisbackup\gapaengine.dll
2014-01-21 21:40:40 -------- dc----w- c:\program files\BSPlayer
2014-01-21 11:02:25 -------- d-----w- c:\windows\CheckSur
2014-01-20 08:30:46 -------- dc----w- C:\Program Files (x86)
2014-01-20 08:28:45 749568 -c--a-w- c:\program files\common

files\installshield\professional\runtime\10\50\intel32\iKernel.dll
2014-01-20 08:28:45 69715 -c--a-w- c:\program files\common

files\installshield\professional\runtime\10\50\intel32\ctor.dll
2014-01-20 08:28:45 5632 -c--a-w- c:\program files\common

files\installshield\professional\runtime\10\50\intel32\DotNetInstaller.exe
2014-01-20 08:28:45 32768 -c--a-w- c:\program files\common

files\installshield\professional\runtime\Objectps.dll
2014-01-20 08:28:45 274432 -c--a-w- c:\program files\common

files\installshield\professional\runtime\10\50\intel32\iscript.dll
2014-01-20 08:28:45 180224 -c--a-w- c:\program files\common

files\installshield\professional\runtime\10\50\intel32\iuser.dll
2014-01-20 08:28:44 323716 -c--a-w- c:\program files\common

files\installshield\professional\runtime\10\50\intel32\setup.dll
2014-01-20 08:28:44 192644 -c--a-w- c:\program files\common

files\installshield\professional\runtime\10\50\intel32\iGdi.dll
2014-01-20 08:07:49 -------- dc----w- c:\program files\Sony
2014-01-20 08:04:13 46592 ----a-w- c:\windows\system32\drivers\risdptsk.sys
2014-01-18 09:33:37 2345 -c--a-w- c:\users\krissi\reset.cmd
2014-01-18 09:27:22 379392 -c--a-w- c:\users\krissi\subinacl.msi
2014-01-18 09:08:19 -------- dc----w- c:\program files\Windows Resource Kits
2014-01-18 09:07:44 1302 ----a-w- c:\windows\system32\reset.cmd
2014-01-18 07:24:57 -------- dc----w- c:\users\krissi\appdata\local\Adobe
2014-01-18 06:39:33 -------- dc----w- 

c:\users\krissi\appdata\local\ElevatedDiagnostics
2014-01-15 09:58:29 -------- d-----w- c:\windows\system32\catroot2
2014-01-15 08:56:27 650936 -c--a-w- 

c:\programdata\microsoft\ehome\packages\sportstemplate\sportstemplatecore\Microsoft.MediaCenter.Spo

rts.UI.dll
2014-01-15 08:56:09 677136 -c--a-w- 

c:\programdata\microsoft\ehome\packages\mcespotlight\mcespotlight\SpotlightResources.dll
2014-01-15 08:55:53 416128 -c--a-w- 

c:\programdata\microsoft\ehome\packages\nettv\browse\NetTVResources.dll
2014-01-13 23:23:04 -------- d-----w- c:\windows\PCHEALTH
2014-01-13 20:13:47 33104 ----a-w- c:\windows\system32\spool\prtprocs\w32x86

\msonpppr.dll
2014-01-13 20:13:47 31640 ----a-w- c:\windows\system32\msonpmon.dll
2014-01-13 20:09:24 -------- d-----w- c:\windows\SHELLNEW
2014-01-13 20:08:52 -------- dc----w- c:\users\krissi\appdata\local\Microsoft

Help
2014-01-12 11:23:32 -------- d--h--w- c:\windows\msdownld.tmp
2014-01-12 11:13:49 -------- d-----w- c:\program files\Microsoft Security Client
2014-01-12 11:13:15 221568 ----a-w- c:\windows\system32\drivers\netio.sys
2014-01-12 10:57:36 62576 ----a-w- c:\programdata\microsoft\windows

defender\definition updates\{6edffe36-b8a5-4ed4-9460-7d66fbdfaaa5}\offreg.dll
2014-01-12 10:47:08 7760024 ----a-w- c:\programdata\microsoft\windows

defender\definition updates\{6edffe36-b8a5-4ed4-9460-7d66fbdfaaa5}\mpengine.dll
2014-01-12 10:22:02 -------- d-----w- c:\windows\system32\NtmsData
2014-01-12 09:55:26 -------- dc----w- c:\users\krissi\appdata\local\VirtualStore
2014-01-12 07:58:03 -------- dc----w- C:\perflogs
2014-01-11 00:37:05 -------- dc----w- 

c:\users\krissi\appdata\local\IsolatedStorage
2014-01-10 20:08:41 -------- dc----w- c:\program files\common files\Intuit
2014-01-10 20:06:29 -------- dc----w- c:\program files\TurboTax
2014-01-10 20:06:06 -------- dc----w- c:\programdata\Intuit
2014-01-10 11:50:44 -------- dc----w- c:\program files\common files\Advanced Win

Utilities Free - Registry Cleanup
2014-01-10 08:56:24 -------- d-----w- c:\windows\system32\catroot2.bak
2014-01-10 08:56:24 -------- d-----w- c:\windows\system32\catroot2(12).bak
2014-01-10 08:37:55 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2014-01-10 08:37:55 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2014-01-10 08:37:55 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2014-01-10 08:32:16 15712 -c--a-w- c:\program files\common files\windows

live\.cache\77e545741cf0dde20\MeshBetaRemover.exe
2014-01-10 08:32:01 94040 -c--a-w- c:\program files\common files\windows

live\.cache\6e837a141cf0dde1a\DSETUP.dll
2014-01-10 08:32:01 525656 -c--a-w- c:\program files\common files\windows

live\.cache\6e837a141cf0dde1a\DXSETUP.exe
2014-01-10 08:32:01 1691480 -c--a-w- c:\program files\common files\windows

live\.cache\6e837a141cf0dde1a\dsetup32.dll
2014-01-10 08:31:48 94040 -c--a-w- c:\program files\common files\windows

live\.cache\666c8dd41cf0dde17\DSETUP.dll
2014-01-10 08:31:48 525656 -c--a-w- c:\program files\common files\windows

live\.cache\666c8dd41cf0dde17\DXSETUP.exe
2014-01-10 08:31:48 1691480 -c--a-w- c:\program files\common files\windows

live\.cache\666c8dd41cf0dde17\dsetup32.dll
2014-01-10 08:25:05 -------- d-----w- c:\windows\Migration
2014-01-09 12:29:34 -------- dc----w- c:\program files\Windows Portable Devices
2014-01-09 11:54:24 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2014-01-09 11:54:23 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2014-01-09 11:54:23 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2014-01-09 11:16:06 9728 ----a-w- c:\windows\system32\Wdfres.dll
2014-01-09 11:15:55 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-01-09 11:15:55 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-01-09 11:15:54 16896 ----a-w- c:\windows\system32\winusb.dll
2014-01-09 11:15:53 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-01-09 11:15:53 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-01-09 11:15:52 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2014-01-09 11:15:49 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-01-09 11:15:49 34944 ----a-w- c:\windows\system32\drivers\winusb.sys
2014-01-09 11:15:48 613888 ----a-w- c:\windows\system32\WUDFx.dll
2014-01-09 11:15:48 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2014-01-08 22:16:33 812544 ----a-w- c:\windows\system32\certutil.exe
2014-01-08 22:16:33 41984 ----a-w- c:\windows\system32\certenc.dll
2014-01-08 22:16:23 993792 ----a-w- c:\windows\system32\crypt32.dll
2014-01-08 22:16:14 563712 ----a-w- c:\windows\system32\oleaut32.dll
2014-01-08 22:16:14 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2014-01-08 22:16:14 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2014-01-08 22:16:14 238080 ----a-w- c:\windows\system32\oleacc.dll
2014-01-08 22:16:03 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2014-01-08 22:13:55 75776 ----a-w- c:\windows\system32\synceng.dll
2014-01-08 22:13:51 914880 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-01-08 22:13:51 31232 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2014-01-08 22:13:34 429056 ----a-w- c:\windows\system32\EncDec.dll
2014-01-08 22:12:59 2048 ----a-w- c:\windows\system32\tzres.dll
2014-01-08 22:12:29 335360 ----a-w- c:\windows\system32\SysFxUI.dll
2014-01-08 22:12:29 167936 ----a-w- c:\windows\system32\drivers\portcls.sys
2014-01-08 22:12:28 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2014-01-08 22:12:28 130048 ----a-w- c:\windows\system32\drivers\drmk.sys
2014-01-08 22:12:26 376320 ----a-w- c:\windows\system32\dpnet.dll
2014-01-08 22:12:26 23040 ----a-w- c:\windows\system32\dpnsvr.exe
2014-01-08 22:12:25 783360 ----a-w- c:\windows\system32\rpcrt4.dll
2014-01-08 22:12:24 224640 ----a-w- c:\windows\system32\drivers\volsnap.sys
2014-01-08 22:12:18 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2014-01-08 22:11:55 66560 ----a-w- c:\windows\system32\packager.dll
2014-01-08 22:09:58 1314816 ----a-w- c:\windows\system32\quartz.dll
2014-01-08 22:09:57 1548288 ----a-w- c:\windows\system32\WMVDECOD.DLL
2014-01-08 22:09:56 443904 ----a-w- c:\windows\system32\win32spl.dll
2014-01-08 22:09:55 37376 ----a-w- c:\windows\system32\printcom.dll
2014-01-08 22:09:54 297984 ----a-w- c:\windows\system32\gdi32.dll
2014-01-08 22:09:01 1400832 ----a-w- c:\windows\system32\msxml6.dll
2014-01-08 22:07:35 505344 ----a-w- c:\windows\system32\qedit.dll
2014-01-08 22:07:32 1248768 ----a-w- c:\windows\system32\msxml3.dll
2014-01-08 22:06:33 2067968 ----a-w- c:\windows\system32\mstscax.dll
2014-01-08 22:06:27 532480 ----a-w- c:\windows\system32\comctl32.dll
2014-01-08 22:06:25 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2014-01-08 22:06:22 376320 ----a-w- c:\windows\system32\winsrv.dll
2014-01-08 22:05:41 35328 ----a-w- c:\windows\system32\drivers\usbscan.sys
2014-01-08 22:05:41 25472 ----a-w- c:\windows\system32\drivers\hidparse.sys
2014-01-08 21:54:54 707584 -c--a-w- c:\program files\common files\system\wab32.dll
2014-01-08 21:53:47 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2014-01-08 21:53:46 9728 ----a-w- c:\windows\system32\lsass.exe
2014-01-08 21:53:46 72704 ----a-w- c:\windows\system32\secur32.dll
2014-01-08 21:53:46 278528 ----a-w- c:\windows\system32\schannel.dll
2014-01-08 21:53:46 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2014-01-08 21:53:42 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2014-01-08 21:53:38 1404928 -c--a-w- c:\program files\common files\microsoft

shared\ink\InkObj.dll
2014-01-08 21:53:37 936960 -c--a-w- c:\program files\common files\microsoft

shared\ink\journal.dll
2014-01-08 20:58:45 172544 ----a-w- c:\windows\system32\wintrust.dll
2014-01-08 20:58:44 98304 ----a-w- c:\windows\system32\cryptnet.dll
2014-01-08 20:58:44 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2014-01-08 19:51:51 613376 ----a-w- c:\windows\system32\rdpencom.dll
2014-01-08 19:35:38 2422272 ----a-w- c:\windows\system32\wucltux.dll
2014-01-08 19:35:11 88576 ----a-w- c:\windows\system32\wudriver.dll
2014-01-08 19:34:58 171904 ----a-w- c:\windows\system32\wuwebv.dll
2014-01-08 19:34:57 33792 ----a-w- c:\windows\system32\wuapp.exe
2014-01-08 05:41:46 98816 ----a-w- c:\windows\system32\mfps.dll
2014-01-08 05:39:18 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-01-08 05:39:18 519680 ----a-w- c:\windows\system32\d3d11.dll
2014-01-08 05:39:18 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2014-01-08 05:39:18 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2014-01-08 05:39:18 252928 ----a-w- c:\windows\system32\dxdiag.exe
2014-01-08 05:39:18 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2014-01-08 05:39:18 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2014-01-08 03:50:56 -------- d-----w- c:\windows\system32\vi-VN
2014-01-08 03:50:56 -------- d-----w- c:\windows\system32\eu-ES
2014-01-08 03:50:56 -------- d-----w- c:\windows\system32\ca-ES
2014-01-08 02:30:59 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2014-01-08 01:37:56 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2014-01-08 00:58:08 -------- dc----w- c:\program files\common files\Windows Live
2014-01-08 00:41:28 18904 ----a-w- c:\windows\system32

\StructuredQuerySchemaTrivial.bin
2014-01-08 00:31:40 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2014-01-08 00:31:40 49472 ----a-w- c:\windows\system32\netfxperf.dll
2014-01-08 00:31:40 297808 ----a-w- c:\windows\system32\mscoree.dll
2014-01-08 00:31:40 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2014-01-08 00:31:40 1130824 ----a-w- c:\windows\system32\dfshim.dll
2014-01-08 00:28:13 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2014-01-08 00:00:49 168960 -c--a-w- c:\program files\windows media player\wmplayer.exe
2014-01-08 00:00:48 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2014-01-08 00:00:37 677888 ----a-w- c:\windows\system32\mstsc.exe
2014-01-08 00:00:36 63488 ----a-w- c:\windows\system32\tscupgrd.exe
2014-01-08 00:00:32 125952 ----a-w- c:\windows\system32\srvsvc.dll
2014-01-08 00:00:31 17920 ----a-w- c:\windows\system32\netevent.dll
2014-01-08 00:00:20 502272 ----a-w- c:\windows\system32\usp10.dll
2014-01-07 23:55:32 601600 ----a-w- c:\windows\system32\schedsvc.dll
2014-01-07 23:55:32 352768 ----a-w- c:\windows\system32\taskschd.dll
2014-01-07 23:55:31 345600 ----a-w- c:\windows\system32\wmicmiplugin.dll
2014-01-07 23:55:30 270336 ----a-w- c:\windows\system32\taskcomp.dll
2014-01-07 23:55:30 171520 ----a-w- c:\windows\system32\taskeng.exe
2014-01-07 23:55:28 739328 ----a-w- c:\windows\system32\inetcomm.dll
2014-01-07 23:55:26 81920 ----a-w- c:\windows\system32\consent.exe
2014-01-07 21:05:40 193024 ----a-w- c:\windows\system32\recdisc.exe
2014-01-07 21:05:36 6656 ----a-w- c:\windows\system32\sdspres.dll
2014-01-07 21:04:43 28160 ----a-w- c:\windows\system32\sxproxy.dll
2014-01-07 21:02:59 84992 ----a-w- c:\windows\system32\SessEnv.dll
2014-01-07 21:01:59 487936 ----a-w- c:\windows\system32\catsrvut.dll
2014-01-07 21:00:58 80896 ----a-w- c:\windows\system32\tasklist.exe
2014-01-04 06:09:14 -------- dc----w- c:\program files\Traction Software
2014-01-04 06:09:02 77824 -c--a-w- c:\program files\common

files\installshield\engine\6\intel 32\ctor.dll
2014-01-04 06:09:02 32768 -c----w- c:\program files\common

files\installshield\engine\6\intel 32\objectps.dll
2014-01-04 06:09:02 225280 -c----w- c:\program files\common

files\installshield\iscript\IScript.dll
2014-01-04 06:09:02 212992 -c--a-w- c:\program files\common

files\installshield\engine\6\intel 32\ILog.dll
2014-01-04 06:09:02 176128 -c----w- c:\program files\common

files\installshield\engine\6\intel 32\iuser.dll
2014-01-04 06:09:01 614532 -c--a-w- c:\program files\common

files\installshield\engine\6\intel 32\IKernel.exe
2014-01-04 06:04:33 -------- dc----w- c:\program files\Fotosizer
2014-01-03 04:01:03 2048 -c--a-w- c:\program files\internet explorer\iecompat.dll
2014-01-03 04:00:56 265720 -c--a-w- c:\program files\internet explorer\msdbg2.dll
2014-01-03 04:00:55 355832 -c--a-w- c:\program files\internet explorer\pdm.dll
2014-01-02 14:15:44 -------- dc----w- c:\program files\MSECache
2014-01-02 13:55:26 -------- dc----w- c:\program files\Microsoft Download Manager
2014-01-02 00:20:59 -------- d-----w- c:\windows\system32\EventProviders
2014-01-01 22:33:17 8704 ----a-w- c:\windows\system32\hccoin.dll
2014-01-01 22:33:17 15872 ----a-w- c:\windows\system32\hcrstco.dll
2014-01-01 21:22:26 23552 ----a-w- c:\windows\system32\lpk.dll
2014-01-01 21:22:25 10240 ----a-w- c:\windows\system32\dciman32.dll
2014-01-01 21:19:42 61440 ----a-w- c:\windows\system32\winipsec.dll
2014-01-01 21:19:41 272896 ----a-w- c:\windows\system32\polstore.dll
2014-01-01 21:16:26 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2014-01-01 21:16:26 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2014-01-01 21:16:26 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2014-01-01 21:16:26 19968 ----a-w- c:\windows\system32\ARP.EXE
2014-01-01 21:16:26 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2014-01-01 21:16:26 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2014-01-01 21:16:26 105984 ----a-w- c:\windows\system32\netiohlp.dll
2014-01-01 21:16:26 10240 ----a-w- c:\windows\system32\finger.exe
2014-01-01 21:13:51 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2014-01-01 21:13:50 68096 ----a-w- c:\windows\system32\wlanhlp.dll
2014-01-01 21:13:50 65024 ----a-w- c:\windows\system32\wlanapi.dll
2014-01-01 21:13:49 513536 ----a-w- c:\windows\system32\wlansvc.dll
2014-01-01 21:13:49 302592 ----a-w- c:\windows\system32\wlansec.dll
2014-01-01 21:13:49 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2014-01-01 21:13:44 15181 ----a-w- c:\windows\system32\gatherWirelessInfo.vbs
2014-01-01 21:12:55 2048 ----a-w- c:\windows\system32\msxml3r.dll
2014-01-01 21:12:53 2048 ----a-w- c:\windows\system32\msxml6r.dll
2014-01-01 21:12:09 218624 ----a-w- c:\windows\system32\msv1_0.dll
2014-01-01 21:10:17 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2014-01-01 21:10:17 2048 ----a-w- c:\windows\system32\mferror.dll
2014-01-01 21:10:16 24576 ----a-w- c:\windows\system32\mfpmp.exe
2014-01-01 21:06:31 71680 ----a-w- c:\windows\system32\atl.dll
2014-01-01 21:03:06 160256 ----a-w- c:\windows\system32\wkssvc.dll
2014-01-01 21:02:24 53248 ----a-w- c:\windows\system32\tsgqec.dll
2014-01-01 21:02:24 136192 ----a-w- c:\windows\system32\aaclient.dll
2014-01-01 20:59:56 714240 ----a-w- c:\windows\system32\timedate.cpl
2014-01-01 20:57:13 23040 -c--a-w- c:\program files\movie maker\WMM2EXT.dll
2014-01-01 20:57:13 195072 -c--a-w- c:\program files\movie maker\WMM2AE.dll
2014-01-01 20:48:36 62464 ----a-w- c:\windows\system32\l3codeca.acm
2014-01-01 20:48:36 220672 ----a-w- c:\windows\system32\l3codecp.acm
2014-01-01 20:47:32 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2014-01-01 20:47:32 200704 ----a-w- c:\windows\system32\iphlpsvc.dll
2014-01-01 20:47:31 15360 ----a-w- c:\windows\system32\drivers\TUNMP.SYS
2014-01-01 20:43:06 14848 ----a-w- c:\windows\system32\wshrm.dll
2014-01-01 20:42:32 43520 ----a-w- c:\windows\system32\msdxm.tlb
2014-01-01 20:42:32 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2014-01-01 20:42:32 18432 ----a-w- c:\windows\system32\amcompat.tlb
2014-01-01 20:42:28 7680 ----a-w- c:\windows\system32\spwmp.dll
2014-01-01 20:42:27 4096 ----a-w- c:\windows\system32\dxmasf.dll
2014-01-01 20:42:27 107520 -c--a-w- c:\program files\windows media player\wmpshare.exe
2014-01-01 20:42:26 4096 ----a-w- c:\windows\system32\msdxm.ocx
2014-01-01 20:42:26 107520 -c--a-w- c:\program files\windows media player\wmpconfig.exe
2014-01-01 20:41:34 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2014-01-01 20:41:34 332288 ----a-w- c:\windows\system32\msdrm.dll
2014-01-01 20:41:34 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2014-01-01 20:41:33 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2014-01-01 20:41:33 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2014-01-01 20:41:32 518144 ----a-w- c:\windows\system32\RMActivate.exe
2014-01-01 20:41:32 471552 ----a-w- c:\windows\system32\secproc.dll
2014-01-01 20:41:31 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2014-01-01 20:41:31 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2014-01-01 20:37:33 243712 ----a-w- c:\windows\system32\rastls.dll
2014-01-01 18:38:25 499712 ----a-w- c:\windows\system32\kerberos.dll
2014-01-01 18:38:25 175104 ----a-w- c:\windows\system32\wdigest.dll
2014-01-01 18:31:29 6656 ----a-w- c:\windows\system32\kbd106n.dll
2014-01-01 18:12:01 -------- d-----w- c:\windows\system32\MRT
2014-01-01 17:46:11 84480 ----a-w- c:\windows\system32\INETRES.dll
2014-01-01 17:45:53 60928 ----a-w- c:\windows\system32\msasn1.dll
2014-01-01 17:44:19 355328 ----a-w- c:\windows\system32\WSDApi.dll
2014-01-01 13:31:14 91136 ----a-w- c:\windows\system32\avifil32.dll
2014-01-01 13:31:14 82944 ----a-w- c:\windows\system32\mciavi32.dll
2014-01-01 13:31:14 65024 ----a-w- c:\windows\system32\avicap32.dll
2014-01-01 13:31:14 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2014-01-01 13:31:14 31744 ----a-w- c:\windows\system32\msvidc32.dll
2014-01-01 13:31:14 22528 ----a-w- c:\windows\system32\msyuv.dll
2014-01-01 13:31:14 13312 ----a-w- c:\windows\system32\msrle32.dll
2014-01-01 13:31:14 123904 ----a-w- c:\windows\system32\msvfw32.dll
2014-01-01 13:31:14 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2014-01-01 13:25:07 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2014-01-01 11:07:00 310784 ----a-w- c:\windows\system32\unregmp2.exe
2014-01-01 11:07:00 1418752 -c--a-w- c:\program files\windows media player\setup_wm.exe
2014-01-01 11:03:36 -------- dc----w- c:\users\krissi\appdata\local\WindowsUpdate
2014-01-01 10:59:31 -------- dc----w- c:\programdata\Malwarebytes
2014-01-01 10:58:32 743248 ----a-w- c:\windows\system32\msvcp100d.dll
2014-01-01 10:58:32 1498960 ----a-w- c:\windows\system32\msvcr100d.dll
2014-01-01 06:20:43 98304 ----a-w- c:\windows\system32\cabview.dll
2014-01-01 06:19:53 51712 ----a-w- c:\windows\system32\admwprox.dll
2014-01-01 06:19:53 153600 ----a-w- c:\windows\system32\iisRtl.dll
2014-01-01 06:19:52 27136 ----a-w- c:\windows\system32\ahadmin.dll
2014-01-01 06:19:52 14848 ----a-w- c:\windows\system32\iisreset.exe
2014-01-01 06:19:52 10752 ----a-w- c:\windows\system32\wamregps.dll
2014-01-01 06:19:51 8192 ----a-w- c:\windows\system32\iisrstap.dll
2014-01-01 06:19:48 411648 ----a-w- c:\windows\system32\drivers\http.sys
2014-01-01 06:19:48 30720 ----a-w- c:\windows\system32\httpapi.dll
2014-01-01 06:19:48 24064 ----a-w- c:\windows\system32\nshhttp.dll
2014-01-01 05:17:39 69120 ----a-w- c:\windows\system32\drivers\rimsptsk.sys
2014-01-01 05:17:39 626688 ----a-w- c:\windows\snymsico.dll
2014-01-01 05:13:25 9344 ----a-w- c:\windows\system32\drivers\SFEP.sys
2014-01-01 03:00:32 2565432 ----a-w- c:\programdata\microsoft\windows

defender\definition updates\backup\mpengine.dll
2014-01-01 03:00:18 231584 ------w- c:\windows\system32\MpSigStub.exe
2013-12-31 23:52:44 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-12-31 23:52:44 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-12-31 23:10:36 85504 ----a-w- c:\windows\system32\spool\prtprocs\w32x86

\CNMPPB8.DLL
2013-12-31 23:10:36 29184 ----a-w- c:\windows\system32\spool\prtprocs\w32x86

\CNMPDB8.DLL
2013-12-31 23:09:23 314880 ----a-w- c:\windows\system32\CNMLMB8.DLL
2013-12-31 23:04:34 96768 ----a-w- c:\windows\system32\CNC_B8I.dll
2013-12-31 23:04:34 320000 ----a-w- c:\windows\system32\CNC_B8L.dll
2013-12-31 23:04:34 266752 ----a-w- c:\windows\system32\CNC_B8C.dll
2013-12-31 23:04:34 15872 ----a-w- c:\windows\system32\CNHMCA.dll
2013-12-31 20:57:09 1249792 ----a-w- c:\windows\system32\drivers\athr.sys
2013-12-31 20:48:26 319456 ----a-w- c:\windows\system32\difxapi.dll
2013-12-31 20:47:08 9036800 ----a-w- c:\windows\system32\drivers\igdkmd32.sys
2013-12-31 20:47:01 81920 ----a-w- c:\windows\system32\igfxCoIn_v2302.dll
2013-12-31 20:47:01 57856 ----a-w- c:\windows\system32\igfxsrvc.dll
2013-12-31 20:47:01 261632 ----a-w- c:\windows\system32\igfxTMM.dll
2013-12-31 20:47:01 208896 ----a-w- c:\windows\system32\iglhsip32.dll
2013-12-31 20:47:01 147456 ----a-w- c:\windows\system32\iglhcp32.dll
2013-12-31 20:45:58 982240 ----a-w- c:\windows\system32\igkrng500.bin
2013-12-31 20:45:58 92356 ----a-w- c:\windows\system32\igfcg500m.bin
2013-12-31 20:45:58 439308 ----a-w- c:\windows\system32\igcompkrng500.bin
2013-12-31 20:45:19 90112 ----a-w- c:\windows\system32\snymsico.dll
2013-12-30 23:33:41 -------- d-sh--w- c:\windows\Installer
2013-12-30 02:12:55 -------- d-----w- c:\windows\Panther
2013-12-30 01:13:33 -------- dcsh--w- C:\Boot
.
==================== Find6M  ====================
.
2014-01-08 05:41:46 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2014-01-08 05:39:19 4096 ----a-w- c:\windows\system32\drivers\en-us\dxgkrnl.sys.mui
2014-01-07 21:31:07 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2014-01-07 21:31:04 82432 ----a-w- c:\windows\system32\axaltocm.dll
2014-01-01 22:30:16 36864 ----a-w- c:\windows\system32\drivers\en-us\http.sys.mui
2014-01-01 20:39:49 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2013-10-30 02:13:01 1304064 ----a-w- c:\windows\system32\WMALFXGFXDSP.dll
2013-10-30 00:35:24 2050560 ----a-w- c:\windows\system32\win32k.sys
2013-10-22 07:19:59 158208 ----a-w- c:\windows\system32\imagehlp.dll
2013-10-11 02:08:55 36864 ----a-w- c:\windows\system32\wshcon.dll
2013-10-11 02:08:55 131072 ----a-w- c:\windows\system32\wshom.ocx
2013-10-11 02:08:35 172032 ----a-w- c:\windows\system32\scrrun.dll
2013-10-11 02:08:02 444928 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-10-11 02:07:57 596480 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2013-10-11 00:35:42 135168 ----a-w- c:\windows\system32\cscript.exe
2013-10-11 00:35:41 155648 ----a-w- c:\windows\system32\wscript.exe
2013-09-27 17:53:06 214696 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2013-09-27 17:53:06 104768 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2013-09-12 05:21:54 863344 ----a-w- c:\windows\system32\msvcr110_clr0400.dll
2013-09-12 05:21:54 501872 ----a-w- c:\windows\system32\msvcp110_clr0400.dll
2013-09-12 05:21:54 28776 ----a-w- c:\windows\system32\aspnet_counters.dll
2013-09-12 05:21:54 18000 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
2013-08-27 02:47:50 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-08-27 02:47:50 189952 ----a-w- c:\windows\system32\d3d10core.dll
2013-08-27 02:47:50 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2013-08-27 02:47:50 1029120 ----a-w- c:\windows\system32\d3d10.dll
2013-08-27 01:52:08 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2013-08-27 01:50:40 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2013-08-27 01:32:20 683008 ----a-w- c:\windows\system32\d2d1.dll
2013-08-27 01:28:36 1069056 ----a-w- c:\windows\system32\DWrite.dll
2013-08-27 01:28:35 798208 ----a-w- c:\windows\system32\FntCache.dll
2013-08-01 03:16:32 638400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-08-01 02:49:15 37376 ----a-w- c:\windows\system32\cdd.dll
.
============= FINISH:  0:43:53.92 ===============

 

 

***************************************************************************************************

***************************************************************************************************

***************************************************************************************************

***************************************************************************************************

***************************************************************************************************

***************************************************************************************************

 

 

(((((((((((((((((((((((((((ATTACH.TXT BEGINS NOW)))))))))))))))))))))))))))))))))))))))))))))))))))

 

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 12/29/2013 6:26:03 PM
System Uptime: 1/27/2014 12:18:40 AM (0 hours ago)
.
Motherboard: Sony Corporation |  | VAIO
Processor: Intel® Pentium® Dual  CPU  T3200  @ 2.00GHz | N/A | 1994/166mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 233 GiB total, 172.427 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
Description: USB Human Interface Device
Device ID: USB\VID_046D&PID_C018\5&410800B&0&2
Manufacturer: (Standard system devices)
Name: USB Human Interface Device
PNP Device ID: USB\VID_046D&PID_C018\5&410800B&0&2
Service: HidUsb
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 9.5.5
BS.Player FREE
Compatibility Pack for the 2007 Office system
FileASSASSIN
Fotosizer 2.07
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Intel® Graphics Media Accelerator Driver
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4.5.1
Microsoft Application Error Reporting
Microsoft Download Manager
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Security Client
Microsoft Security Essentials
Screen Grab Pro
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2861697)
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760415) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2817641) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2827326) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2837615) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2850022) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2827324) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2837617) 32-Bit Edition
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VAIO Care
VAIO Care Update
Windows Live Sync
Windows Resource Kit Tools - SubInAcl.exe
.
==== End Of File ===========================

Link to post
Share on other sites

Hello and post-32477-1261866970.gif

P2P/Piracy Warning:

    
If you're using Peer 2 Peer software such as uTorrent, BitTorrent or similar you must either fully uninstall them or completely disable them from running while being assisted here.
Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.
If you have illegal/cracked software, cracks, keygens etc. on the system, please remove or uninstall them now and read the policy on Piracy.

 

Download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.


 

Kevin...

Link to post
Share on other sites

  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.