Jump to content

Infected with sound virus?


Recommended Posts

My computer has become infected with something that causes it to play random sound clips, such as pieces of songs or audio from internet news programs. Sometimes it causes Internet Explorer to crash as well.

Please help me fix this! Thank you!

.

DDS (Ver_2011-08-26.01) - NTFSAMD64

Internet Explorer: 9.0.8112.16421

Run by Mason at 9:24:47 on 2011-11-08

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6143.3457 [GMT -6:00]

.

AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}

SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\nvvsvc.exe

C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\system32\atiesrxx.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\system32\atieclxx.exe

C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe

C:\Windows\system32\nvvsvc.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe

C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe

C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe

C:\Program Files (x86)\Steam\Steam.exe

c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe

C:\Program Files (x86)\PDF Complete\pdfsvc.exe

C:\Program Files\NVIDIA Corporation\Display\nvtray.exe

C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe

C:\Program Files (x86)\Winamp\winampa.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe

C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe

C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe

C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE

C:\Windows\system32\SearchIndexer.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\system32\WUDFHost.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Program Files (x86)\Common Files\Steam\SteamService.exe

C:\Windows\System32\svchost.exe -k LocalServicePeerNet

C:\Windows\system32\DllHost.exe

c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe

C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

C:\Windows\System32\svchost.exe -k secsvcs

C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe

C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe

C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe

C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe

C:\Windows\system32\conhost.exe

C:\Program Files (x86)\Winamp\winamp.exe

C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe

C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\DllHost.exe

C:\Windows\system32\DllHost.exe

C:\Windows\system32\REGSVR32.exe

C:\Windows\SysWOW64\cmd.exe

C:\Windows\system32\conhost.exe

C:\Windows\SysWOW64\cscript.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.google.com/

uSearch Bar = Preserve

mWinlogon: Userinit=userinit.exe,

BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File

uRun: [steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent

uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background

uRun: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

mRun: [startCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

mRun: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe

mRun: [<NO NAME>]

mRun: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe

mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SNAPFI~1.LNK - C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe

mPolicies-explorer: NoActiveDesktop = 1 (0x1)

mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

Trusted Zone: freerealms.com

Trusted Zone: soe.com

Trusted Zone: sony.com

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab

TCP: DhcpNameServer = 24.220.0.10 24.220.0.11

TCP: Interfaces\{85A8D237-F6E2-46AF-AC8D-616AB0A06793} : DhcpNameServer = 24.220.0.10 24.220.0.11

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File

mRun-x64: [startCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

mRun-x64: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe

mRun-x64: [(Default)]

mRun-x64: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe

mRun-x64: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"

mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun-x64: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min

Hosts: 127.0.0.1 www.spywareinfo.com

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Mason\AppData\Roaming\Mozilla\Firefox\Profiles\zihxrr7p.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - prefs.js: network.proxy.type - 0

FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll

FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll

FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

FF - plugin: C:\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\nphdplg.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

.

---- FIREFOX POLICIES ----

FF - user.js: general.useragent.extra.brc -

.

============= SERVICES / DRIVERS ===============

.

R0 amd_sata;amd_sata;C:\Windows\system32\DRIVERS\amd_sata.sys --> C:\Windows\system32\DRIVERS\amd_sata.sys [?]

R0 amd_xata;amd_xata;C:\Windows\system32\DRIVERS\amd_xata.sys --> C:\Windows\system32\DRIVERS\amd_xata.sys [?]

R1 avkmgr;avkmgr;C:\Windows\system32\DRIVERS\avkmgr.sys --> C:\Windows\system32\DRIVERS\avkmgr.sys [?]

R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]

R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]

R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]

R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]

R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-11-8 86224]

R2 AntiVirService;Avira Realtime Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-11-8 110032]

R2 avgntflt;avgntflt;C:\Windows\system32\DRIVERS\avgntflt.sys --> C:\Windows\system32\DRIVERS\avgntflt.sys [?]

R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]

R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-6-21 85560]

R2 HPAuto;HP Auto;C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2010-8-5 681528]

R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-8-5 291896]

R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-3-28 94264]

R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-9-22 2255464]

R2 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2010-12-10 1119768]

R2 RoxioNow Service;RoxioNow Service;C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-9-11 399344]

R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-9-22 1153368]

R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-9-14 508264]

R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-8-3 379496]

R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\system32\DRIVERS\netr28x.sys --> C:\Windows\system32\DRIVERS\netr28x.sys [?]

R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]

R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]

R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --> C:\Windows\system32\DRIVERS\Sftfslh.sys [?]

R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?]

R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]

R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --> C:\Windows\system32\DRIVERS\Sftvollh.sys [?]

R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-9-14 219496]

R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\DRIVERS\usbfilter.sys --> C:\Windows\system32\DRIVERS\usbfilter.sys [?]

S1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-11-7 366152]

S3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]

S3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]

S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]

S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]

.

=============== Created Last 30 ================

.

2011-11-08 15:10:39 -------- d-----w- C:\Program Files\CCleaner

2011-11-08 15:02:52 -------- d-----w- C:\Users\Mason\AppData\Roaming\SUPERAntiSpyware.com

2011-11-08 15:01:11 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com

2011-11-08 15:01:11 -------- d-----w- C:\Program Files\SUPERAntiSpyware

2011-11-08 14:56:37 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys

2011-11-08 14:33:25 -------- d-----w- C:\Users\Mason\AppData\Roaming\Avira

2011-11-08 14:32:51 97312 ----a-w- C:\Windows\System32\drivers\avgntflt.sys

2011-11-08 14:32:51 27760 ----a-w- C:\Windows\System32\drivers\avkmgr.sys

2011-11-08 14:32:51 -------- d-----w- C:\ProgramData\Avira

2011-11-08 14:32:51 -------- d-----w- C:\Program Files (x86)\Avira

2011-11-08 14:29:58 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{55C4998F-AE67-4F37-B496-9DE535C64EA6}\offreg.dll

2011-11-08 14:18:41 8862544 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll

2011-11-08 14:18:36 8570192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{55C4998F-AE67-4F37-B496-9DE535C64EA6}\mpengine.dll

2011-11-08 05:17:49 388096 ----a-r- C:\Users\Mason\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-11-08 05:17:48 -------- d-----w- C:\Program Files (x86)\Trend Micro

2011-11-08 04:53:36 -------- d-----w- C:\Users\Mason\AppData\Local\{B5295AB8-0DFF-42C6-A5C6-EE8258928A1E}

2011-11-08 04:53:14 -------- d-----w- C:\Users\Mason\AppData\Local\{4FF5A263-367F-4BC2-9654-289F54FE4FEE}

2011-11-08 03:33:18 -------- d-----w- C:\Users\Mason\AppData\Local\{5C0F508E-05BD-4750-B5B8-3092B0471CB3}

2011-11-08 00:30:45 -------- d-----w- C:\Users\Mason\AppData\Roaming\Malwarebytes

2011-11-08 00:30:35 -------- d-----w- C:\ProgramData\Malwarebytes

2011-11-08 00:30:31 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2011-11-07 16:48:43 -------- d-----w- C:\Users\Mason\AppData\Local\{A4EC2733-A143-486A-9D76-970879A86570}

2011-11-07 04:48:11 -------- d-----w- C:\Users\Mason\AppData\Local\{629A3D07-E8D0-497C-8697-1A17897AF715}

2011-11-06 16:47:39 -------- d-----w- C:\Users\Mason\AppData\Local\{33927208-8503-4C5C-8B1E-80CC0DD4A339}

2011-11-06 04:47:06 -------- d-----w- C:\Users\Mason\AppData\Local\{E7AAA189-7052-412B-B7EF-C682B58076D0}

2011-11-05 16:46:34 -------- d-----w- C:\Users\Mason\AppData\Local\{CABCD2A0-D24D-4E2C-8D0B-985EE9E218C7}

2011-11-05 16:46:13 -------- d-----w- C:\Users\Mason\AppData\Local\{3490B544-4DCD-4788-ADFB-DFFFA60F817C}

2011-11-05 04:45:49 -------- d-----w- C:\Users\Mason\AppData\Local\{F23F8862-455F-48E0-A98D-A493B9051A98}

2011-11-04 16:42:23 -------- d-----w- C:\Users\Mason\AppData\Local\{2AC55A87-68E9-4D20-A725-2A971CBAF6D0}

2011-11-04 04:41:51 -------- d-----w- C:\Users\Mason\AppData\Local\{1289915E-79B9-4339-8401-EB5B47E95F28}

2011-11-03 16:41:17 -------- d-----w- C:\Users\Mason\AppData\Local\{4A5FF95D-06B4-4960-8C49-07EF9C898D47}

2011-11-03 16:40:55 -------- d-----w- C:\Users\Mason\AppData\Local\{C4971516-226E-40B8-8750-2C2646E0B1EE}

2011-11-03 13:41:49 -------- d-----w- C:\Users\Mason\AppData\Local\SCE

2011-11-03 04:40:31 -------- d-----w- C:\Users\Mason\AppData\Local\{73AAB10A-7DE2-4127-8C52-DBDE44572BCE}

2011-11-03 04:40:10 -------- d-----w- C:\Users\Mason\AppData\Local\{5E2F5CE5-855E-466D-9280-E84604D14A6E}

2011-11-02 16:39:58 -------- d-----w- C:\Users\Mason\AppData\Local\{577D0D66-702B-4C36-8B45-A5B7CDD78FEE}

2011-11-02 16:39:37 -------- d-----w- C:\Users\Mason\AppData\Local\{6E728774-6A60-4A35-A80E-EC7A5DF1EB62}

2011-11-02 04:39:26 -------- d-----w- C:\Users\Mason\AppData\Local\{B5035977-8811-4FC6-8A31-12BFA890C60F}

2011-11-02 04:39:04 -------- d-----w- C:\Users\Mason\AppData\Local\{92D8A58A-D713-4CE5-9D8F-7573C3336335}

2011-11-01 16:38:53 -------- d-----w- C:\Users\Mason\AppData\Local\{2D47772C-C462-4C82-B2BF-11B1BB2DE478}

2011-11-01 16:38:31 -------- d-----w- C:\Users\Mason\AppData\Local\{513B5F42-E548-4BC2-8C7B-405D37B53F3B}

2011-11-01 04:38:20 -------- d-----w- C:\Users\Mason\AppData\Local\{533B55FD-8B0A-4696-850D-97C2964DB8D4}

2011-11-01 04:37:59 -------- d-----w- C:\Users\Mason\AppData\Local\{36F38B76-8149-4AC3-AEAB-0778953DA6FD}

2011-10-31 16:37:47 -------- d-----w- C:\Users\Mason\AppData\Local\{319B7596-7615-450E-821F-0F68DB0203EA}

2011-10-31 16:37:25 -------- d-----w- C:\Users\Mason\AppData\Local\{D1904932-0E5A-4CE2-9DFC-CF33E5B4A3B5}

2011-10-31 04:37:14 -------- d-----w- C:\Users\Mason\AppData\Local\{18B6EC2E-E14A-4147-B16B-93B5A58E8DA4}

2011-10-31 04:36:53 -------- d-----w- C:\Users\Mason\AppData\Local\{66060221-90A2-4920-96DC-263FD301E8DF}

2011-10-30 16:36:41 -------- d-----w- C:\Users\Mason\AppData\Local\{41A4148D-C674-4971-A7E2-E250AC046718}

2011-10-30 16:36:19 -------- d-----w- C:\Users\Mason\AppData\Local\{C2BAB46C-F48A-45B8-A4E8-AACFBFBC5E58}

2011-10-30 04:36:08 -------- d-----w- C:\Users\Mason\AppData\Local\{3FC812E9-7C8A-45E6-A646-A58658A2ED3B}

2011-10-30 04:35:47 -------- d-----w- C:\Users\Mason\AppData\Local\{C19EB3C9-CED5-4BFE-A37D-4B5ED8ABB27B}

2011-10-29 16:35:35 -------- d-----w- C:\Users\Mason\AppData\Local\{E3E2F3C0-E0E3-4B1E-8222-80BAAF939838}

2011-10-29 16:35:15 -------- d-----w- C:\Users\Mason\AppData\Local\{1EEAFAC5-342C-49CF-BA6A-E370E7A47145}

2011-10-29 04:30:55 -------- d-----w- C:\Users\Mason\AppData\Local\{D256EFC8-8CAD-4A11-9E9D-B8EA2C9555AE}

2011-10-29 04:30:34 -------- d-----w- C:\Users\Mason\AppData\Local\{A98E2D0B-5030-4C00-A891-9E06928D4E16}

2011-10-28 16:30:22 -------- d-----w- C:\Users\Mason\AppData\Local\{2B3396C3-D3D6-4803-83ED-8A76F579162A}

2011-10-28 16:30:01 -------- d-----w- C:\Users\Mason\AppData\Local\{818EF603-D215-4554-B4B1-91EC0A56B320}

2011-10-28 08:00:33 -------- d-sh--w- C:\Windows\System32\%APPDATA%

2011-10-28 04:20:04 -------- d-----w- C:\Users\Mason\AppData\Local\{021DAB38-092C-4F85-BE5A-EA02C1206983}

2011-10-28 04:19:43 -------- d-----w- C:\Users\Mason\AppData\Local\{11FBE27E-4D01-4870-BE11-E8C6A8649F7D}

2011-10-27 16:19:31 -------- d-----w- C:\Users\Mason\AppData\Local\{E73D0A0F-DED0-4CB3-A55D-48EFE9D68DBB}

2011-10-27 16:19:11 -------- d-----w- C:\Users\Mason\AppData\Local\{15275314-7293-48DA-82BC-EC492C821B4F}

2011-10-27 04:00:14 -------- d-----w- C:\Users\Mason\AppData\Local\{3076D157-4276-415B-B45A-6794E8B2CD41}

2011-10-27 03:59:52 -------- d-----w- C:\Users\Mason\AppData\Local\{9A5B2691-5383-47BF-B82A-789B0C30660D}

2011-10-26 15:59:40 -------- d-----w- C:\Users\Mason\AppData\Local\{172B9250-6A75-499B-ABC4-CB75B3101D5E}

2011-10-26 15:59:29 -------- d-----w- C:\Users\Mason\AppData\Local\{D11469DD-094B-454D-8819-0D3C79F19018}

2011-10-26 03:57:43 -------- d-----w- C:\Users\Mason\AppData\Local\{10FC16C7-1230-4355-999B-E4D48FE094BD}

2011-10-26 03:57:22 -------- d-----w- C:\Users\Mason\AppData\Local\{E2218276-651B-40A6-A770-CBC282FA4808}

2011-10-25 15:57:11 -------- d-----w- C:\Users\Mason\AppData\Local\{919C2E38-55A3-4CAE-B2C7-8DA4D8D74D15}

2011-10-25 03:50:24 -------- d-----w- C:\Users\Mason\AppData\Local\{0503F123-9B5B-4D1F-9B22-592BF1B57F4C}

2011-10-24 15:49:51 -------- d-----w- C:\Users\Mason\AppData\Local\{002621B0-CA3E-4F78-B870-ED10E7FD5136}

2011-10-24 03:48:40 -------- d-----w- C:\Users\Mason\AppData\Local\{3DDE3AB0-E017-4B63-AC12-B808FB88ACBA}

2011-10-23 15:48:07 -------- d-----w- C:\Users\Mason\AppData\Local\{C46037DA-F282-45AC-A570-04AB4F6968C2}

2011-10-23 03:43:21 -------- d-----w- C:\Users\Mason\AppData\Local\{509B0E36-4D67-4183-AC93-4818E8E4B26D}

2011-10-23 03:43:00 -------- d-----w- C:\Users\Mason\AppData\Local\{2E6F0B2F-BDA5-4735-80BE-4AA494649DEC}

2011-10-22 15:42:36 -------- d-----w- C:\Users\Mason\AppData\Local\{FE3BC055-6F55-4CC9-8B9B-AAF99E09730C}

2011-10-22 03:42:03 -------- d-----w- C:\Users\Mason\AppData\Local\{8BC76BA0-E447-4DEC-BAE7-4ADC82EA992D}

2011-10-21 15:41:30 -------- d-----w- C:\Users\Mason\AppData\Local\{960FEF2F-2558-47D1-B67B-D70F53CAE6F2}

2011-10-21 03:40:58 -------- d-----w- C:\Users\Mason\AppData\Local\{6888823D-CA52-4DE1-934B-9AC197EE428A}

2011-10-20 15:40:25 -------- d-----w- C:\Users\Mason\AppData\Local\{FB08E7D5-5A88-4A84-AC66-AE5CA2400303}

2011-10-20 03:39:53 -------- d-----w- C:\Users\Mason\AppData\Local\{15AE2A67-4B9B-4D87-B8C8-003912591265}

2011-10-19 15:39:20 -------- d-----w- C:\Users\Mason\AppData\Local\{5072351C-2563-4A51-86F4-8B646C64CCF3}

2011-10-19 03:38:48 -------- d-----w- C:\Users\Mason\AppData\Local\{27D63F81-2524-426C-ADEA-80D8F1A8F05D}

2011-10-18 15:38:16 -------- d-----w- C:\Users\Mason\AppData\Local\{A723E88B-5064-44A1-B07B-305B3BE79AE8}

2011-10-18 03:37:43 -------- d-----w- C:\Users\Mason\AppData\Local\{EA84E28E-5C01-4B51-B2D3-B50D4EAEAE61}

2011-10-17 15:37:10 -------- d-----w- C:\Users\Mason\AppData\Local\{54B097D3-E5C9-490E-9BEF-5943FA3DC89D}

2011-10-17 03:36:38 -------- d-----w- C:\Users\Mason\AppData\Local\{7D936B4F-0C3A-4F47-BE0F-8DFFE0956C7F}

2011-10-16 18:27:58 21840 ----a-w- C:\Windows\SysWow64\SIntfNT.dll

2011-10-16 18:27:58 17212 ----a-w- C:\Windows\SysWow64\SIntf32.dll

2011-10-16 18:27:58 12067 ----a-w- C:\Windows\SysWow64\SIntf16.dll

2011-10-16 18:27:43 5120 ----a-r- C:\Users\Mason\AppData\Roaming\Microsoft\Installer\{08E9C35A-A0AE-43FA-AEA1-E4F58A87FBD1}\Icon52758A77.exe

2011-10-16 18:27:43 18944 ----a-r- C:\Users\Mason\AppData\Roaming\Microsoft\Installer\{08E9C35A-A0AE-43FA-AEA1-E4F58A87FBD1}\Icon7BD916931.exe

2011-10-16 18:27:43 11264 ----a-r- C:\Users\Mason\AppData\Roaming\Microsoft\Installer\{08E9C35A-A0AE-43FA-AEA1-E4F58A87FBD1}\Icon7BD91693.exe

2011-10-16 18:22:21 -------- d-----w- C:\Sierra

2011-10-16 15:36:05 -------- d-----w- C:\Users\Mason\AppData\Local\{DE7DCEF4-D78C-4400-9189-549E981E48AE}

2011-10-16 03:35:33 -------- d-----w- C:\Users\Mason\AppData\Local\{993C2FD1-707F-4451-938D-90838B0DF378}

2011-10-16 03:35:11 -------- d-----w- C:\Users\Mason\AppData\Local\{55A866CD-C236-4A39-8979-F527CA505207}

2011-10-15 15:34:47 -------- d-----w- C:\Users\Mason\AppData\Local\{09293777-0F0A-4AAE-94D9-B3A9F6CC8110}

2011-10-15 03:34:15 -------- d-----w- C:\Users\Mason\AppData\Local\{F8A5A58F-ABA1-4C51-BF97-6D440632AF1A}

2011-10-14 15:33:42 -------- d-----w- C:\Users\Mason\AppData\Local\{744A14D2-CC48-4211-8C12-EBB938CC08B8}

2011-10-14 03:33:10 -------- d-----w- C:\Users\Mason\AppData\Local\{6BC3E87F-86B7-4AD8-A589-B51E59F85A6D}

2011-10-13 15:32:48 -------- d-----w- C:\Users\Mason\AppData\Local\{5530E77A-AB2D-42AF-ADC2-E12ABEF1D957}

2011-10-13 15:32:38 -------- d-----w- C:\Users\Mason\AppData\Local\{0E1462CD-22AF-4BEC-98B5-840D1D9C60D4}

2011-10-13 08:02:26 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%

2011-10-13 03:28:48 3138048 ----a-w- C:\Windows\System32\win32k.sys

2011-10-13 03:28:45 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax

2011-10-13 03:28:45 613888 ----a-w- C:\Windows\System32\psisdecd.dll

2011-10-13 03:28:45 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll

2011-10-13 03:28:45 108032 ----a-w- C:\Windows\System32\psisrndr.ax

2011-10-13 03:28:39 861696 ----a-w- C:\Windows\System32\oleaut32.dll

2011-10-13 03:28:39 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll

2011-10-13 03:28:39 331776 ----a-w- C:\Windows\System32\oleacc.dll

2011-10-13 03:28:39 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll

2011-10-13 03:01:23 -------- d-----w- C:\Users\Mason\AppData\Local\{67FF4762-7CFA-490B-97AA-161704A2A097}

2011-10-12 14:53:00 -------- d-----w- C:\Users\Mason\AppData\Local\{A6BB3D92-CA54-47E8-8AA5-F8CA0D0EB68F}

2011-10-12 02:46:57 -------- d-----w- C:\Users\Mason\AppData\Local\{D3122793-4059-44DA-AA56-4BDFECEA0676}

2011-10-12 02:46:35 -------- d-----w- C:\Users\Mason\AppData\Local\{8D3C1531-192E-42F2-BEE9-3B10FB5DBF3A}

2011-10-11 14:46:12 -------- d-----w- C:\Users\Mason\AppData\Local\{146E2432-B6C5-430F-A28C-6F3C67AD7E33}

2011-10-11 02:42:56 -------- d-----w- C:\Users\Mason\AppData\Local\{8B0F404D-CE8F-4F39-A7C2-6C0567D04CAE}

2011-10-10 14:40:16 -------- d-----w- C:\Users\Mason\AppData\Local\{3AE916AF-76EA-4C43-8BC3-15D262D55448}

2011-10-10 14:40:07 -------- d-----w- C:\Users\Mason\AppData\Local\{9F9733B1-F7ED-4359-8E91-4572FFDE9586}

2011-10-10 02:27:32 -------- d-----w- C:\Users\Mason\AppData\Local\{E9582433-B29E-429F-953A-0F094CECBBC6}

.

==================== Find3M ====================

.

2011-10-09 12:27:17 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2011-09-24 19:58:16 175616 ----a-w- C:\Windows\System32\msclmd.dll

2011-09-24 19:58:16 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll

2011-09-22 12:41:16 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2011-09-01 05:24:07 2309120 ----a-w- C:\Windows\System32\jscript9.dll

2011-09-01 05:17:57 1389056 ----a-w- C:\Windows\System32\wininet.dll

2011-09-01 05:12:04 2382848 ----a-w- C:\Windows\System32\mshtml.tlb

2011-09-01 02:35:59 1798144 ----a-w- C:\Windows\SysWow64\jscript9.dll

2011-09-01 02:28:15 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll

2011-09-01 02:22:54 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb

.

============= FINISH: 9:32:47.11 ===============

DDS.txt

Attach.txt

Link to post
Share on other sites

post-32477-1261866970.gif

Logs will be closed if you haven't replied within 3 days

Please don't attach the scans / logs for these tools, use "copy/paste".

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.

Please run a new MBAM scan being sure to update before scanning.

Post the scan results

Also please describe how your computer behaves at the moment.

Please don't attach the scans / logs, use "copy/paste".

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.