TechSpot

Pretty sure I have Rootkit.ZeroAccess on my computer

Solved
By Syreynna
Jun 25, 2012
  1. Broni

    Broni Malware Annihilator Posts: 46,865   +254

    LOL
     
  2. Syreynna

    Syreynna TS Rookie Topic Starter Posts: 74

    Bsod when trying to run normally(posting from ipad). Do you want me to run the ubcd and post the fix log?
     
  3. Broni

    Broni Malware Annihilator Posts: 46,865   +254

    Yes please.
     
  4. Syreynna

    Syreynna TS Rookie Topic Starter Posts: 74

    Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 20-06-2012 01
    Ran by SYSTEM at 2012-06-26 22:35:41 Run:1
    Running from D:\
    ==============================================
    HKEY_LOCAL_MACHINE\System\ControlSet002\Control\Session Manager\SubSystems\\Windows Value was restored successfully .
    C:\Windows\System32\consrv.dll not found.
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32\\Default value was restored successfully .
    C:\Windows\$NtUninstallKB56711$ moved successfully.
    ==== End of Fixlog ====
     
  5. Broni

    Broni Malware Annihilator Posts: 46,865   +254

    See if you can boot to safe mode.
     
  6. Syreynna

    Syreynna TS Rookie Topic Starter Posts: 74

    A very sad blue screen!
     
  7. Broni

    Broni Malware Annihilator Posts: 46,865   +254

    Delete current "fixlist.txt" file from your USB flash drive.

    Then....

    Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    On Vista or Windows 7: Now please enter System Recovery Options.
    On Windows XP: Now please boot into the UBCD.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.
     

    Attached Files:

  8. Syreynna

    Syreynna TS Rookie Topic Starter Posts: 74

    Is it fine if I just copy it and paste it while I'm in ubcd mode or write it in manually? Or would youlike me to wait until I can download on a clean computer? I don't have access to another computer witha usb drive currently since I was using my neighbors computer and they are now sleeping!
     
  9. Broni

    Broni Malware Annihilator Posts: 46,865   +254

    That's fine.
     
  10. Syreynna

    Syreynna TS Rookie Topic Starter Posts: 74

    Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 20-06-2012 01
    Ran by SYSTEM at 2012-06-26 23:57:20 Run:2
    Running from D:\
    ==============================================

    ========= fixmbr =========
    'fixmbr' is not recognized as an internal or external command,
    operable program or batch file.
    ========= End of CMD: =========

    ========= fixboot =========
    'fixboot' is not recognized as an internal or external command,
    operable program or batch file.
    ========= End of CMD: =========

    ==== End of Fixlog ====
     
  11. Broni

    Broni Malware Annihilator Posts: 46,865   +254

    We need to use the Recovery Console to try to fix your issue.

    • You'll need to find your Windows XP installation disk.
    • Insert the Windows XP CD into the CD-ROM drive, then restart your computer.
    • If prompted, click any options that are required to start the computer from the CD-ROM drive.
    • When the Welcome to Setup screen appears, press R to start the Recovery Console.
    • The Recovery Console will start and ask you which Windows installation you would like to log on to.
      • If you have multiple Windows installations, it will list each one, and you would enter the number associated with the installation you would like to work on and press enter. If you have just one Windows installation, type 1 and press Enter.
    • It will then prompt you for the Administrator's password. If there is no password, simply press enter.
    • You will now be presented with a C:\Windows> prompt
    • Type with an Enter after each line:

    • fixmbr

      fixboot

      exit
    • Restart computer.

    ************************

    If you don't have Windows CD...
    Download Windows Recovery Console: http://www.thecomputerparamedic.com/files/rc.iso
    Download, and install free Imgburn: http://www.imgburn.com/index.php?act=download
    Using Imgburn, burn rc.iso to a CD.
    Boot to the CD...let it finish loading.
    When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
     
     
  12. Syreynna

    Syreynna TS Rookie Topic Starter Posts: 74

    It's not asking me which windows installations or for the admin password. It just came up with its thing about how rc provides system repair and recovery functionality and then thecommand prompt c:\> after I hit R. Should I still proceed as instructed? :)
     
  13. Broni

    Broni Malware Annihilator Posts: 46,865   +254

    Go ahead.
     
  14. Syreynna

    Syreynna TS Rookie Topic Starter Posts: 74

    It's asking if I am sure I want to write a new boot sector for the c drive? I am assuming yes since mine won't even work anyways.
     
  15. Broni

    Broni Malware Annihilator Posts: 46,865   +254

  16. Syreynna

    Syreynna TS Rookie Topic Starter Posts: 74

    Ok, now what? I tried running it in safe mode and normally and no dice. Sorry for asking so many questions. :x
     
  17. Broni

    Broni Malware Annihilator Posts: 46,865   +254

    Still bluescreeining?

    If so what does BSOD say?
     
  18. Syreynna

    Syreynna TS Rookie Topic Starter Posts: 74

    It says: "a problem has been detected and windows has been shut down to prevent damage to your computer. If this is the first time you've seen this error screen restart your computer. If this screen appears again, follow these steps: check for viruses on your computer. Remove any newly installed hard drives or hard drive controllers. Check your hard drive to make sure it is properly configured and terminated. Run chkdsk /f to check for hard drive corruption, and then restart your computer. Technical information: *** STOP: 0X0000007B (0XB84C3524 , 0XC0000034 , 0X00000000 , 0X00000000"
     
  19. Syreynna

    Syreynna TS Rookie Topic Starter Posts: 74

    Also when I'm selecting safe mode it scrolls though a whole bunch of text really fast then just stops and errors with that bsod error. If I select normal start then it goes to the windows loading screen and loads a little bit then bsod. I don't know if that is important or not but might as well add it.
     
  20. Broni

    Broni Malware Annihilator Posts: 46,865   +254

    Please give me new FRST log.
    Same instructions as in my reply #12.
     
  21. Syreynna

    Syreynna TS Rookie Topic Starter Posts: 74

    While its scanning it gives lots of corrupt file popups and they are all different at first I thought they were the same one that wouldn't go away. They stay there even after the scan is done and closed. Do you need to know what they say?

    Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 20-06-2012 01
    Ran by SYSTEM at 27-06-2012 12:13:41
    Running from D:\
    Microsoft Windows XP Service Pack 2 (X86) OS Language: Georgian
    The current controlset is ControlSet002
    ========================== Registry (Whitelisted) =============
    HKLM\...\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [53248 2005-02-23] (CyberLink Corp.)
    HKLM\...\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe" [425984 2005-07-22] (Dell)
    HKLM\...\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16 [69632 2005-06-07] ()
    HKLM\...\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
    HKLM\...\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe" [135536 2010-12-13] (Microsoft Corporation)
    HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [15504192 2012-05-15] (NVIDIA Corporation)
    HKLM\...\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login [x]
    HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
    HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-21] (Apple Inc.)
    HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
    HKLM\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462408 2012-04-04] (Malwarebytes Corporation)
    HKLM\...\Run: [combofix] "C:\ComboFix\CF3657.3XE" /c "C:\ComboFix\C.bat" [63909 2012-06-24] ()
    HKU\Admin1\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [15360 2008-04-14] (Microsoft Corporation)
    HKU\Administrator\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [15360 2008-04-14] (Microsoft Corporation)
    HKU\Default User\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [15360 2008-04-14] (Microsoft Corporation)
    HKU\GJNA&T\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [15360 2008-04-14] (Microsoft Corporation)
    HKU\GJNA&T\...\Run: [Aim6] [x]
    HKU\GJNA&T\...\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R [x]
    HKU\GJNA&T\...\Run: [A-ToolBar] C:\Program Files\A-ToolBar\AToolBar.exe s [x]
    HKU\GJNA&T\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
    HKU\GJNA&T\...\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [x]
    HKU\GJNA&T\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x]
    HKU\GJNA&T\...\Run: [Google Update] "C:\Documents and Settings\GJNA&T\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c [136176 2010-12-19] (Google Inc.)
    HKU\UpdatusUser\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [15360 2008-04-14] (Microsoft Corporation)
    HKLM\...\RunOnce: [ComboFix_Pre] C:\ComboFix\Res.bat [399 2012-06-26] ()
    HKLM\...\RunOnce: [agp440] C:\WINDOWS\Regedit.exe /s "C:\ComboFix\SW_agp440.reg" [2562 2012-06-26] ()
    HKLM\...\RunOnce: [combofix] "C:\ComboFix\CF3657.3XE" /c "C:\ComboFix\C.bat" [63909 2012-06-24] ()
    HKLM\...\runonceex: [flags] 8 [x]
    Winlogon\Notify\WgaLogon: WgaLogon.dll (Microsoft Corporation)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
    HKLM\...\InprocServer32: [Default-shell32] %SystemRoot%\system32\shdocvw.dll ATTENTION! ====> ZeroAccess
    ================================ Services (Whitelisted) ==================
    4 Autodesk Content Service; "C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe" [18656 2011-02-02] ()
    3 dlcc_device; C:\WINDOWS\system32\dlcccoms.exe -service [491520 2005-06-21] ()
    2 ehRecvr; C:\WINDOWS\eHome\ehRecvr.exe [237568 2006-10-09] (Microsoft Corporation)
    2 ehSched; C:\WINDOWS\eHome\ehSched.exe [102912 2005-08-05] (Microsoft Corporation)
    2 ELService; "C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe" [180224 2005-12-12] (Intel Corporation)
    2 Eventlog; C:\Windows\System32\services.exe [110592 2009-02-06] (Microsoft Corporation)
    3 FLEXnet Licensing Service; "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" [1044816 2012-02-28] (Flexera Software, Inc.)
    2 helpsvc; C:\Windows\System32\svchost.exe -k netsvcs [14336 2008-04-14] (Microsoft Corporation)
    2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
    2 McrdSvc; C:\WINDOWS\ehome\mcrdsvc.exe [99328 2005-08-05] (Microsoft Corporation)
    2 MDM; "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" [322120 2003-06-20] (Microsoft Corporation)
    2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [11552 2012-03-26] (Microsoft Corporation)
    3 NetSvc; C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe [147456 2004-11-19] (Intel(R) Corporation)
    4 NetTcpPortSharing; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [124240 2010-03-18] (Microsoft Corporation)
    3 NtmsSvc; C:\Windows\System32\ntmssvc.dll [435200 2008-04-14] (Microsoft Corporation)
    2 nvUpdatusService; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [1262400 2012-05-15] (NVIDIA Corporation)
    4 Skype C2C Service; "C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe" [3048136 2012-05-30] (Skype Technologies S.A.)
    2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [160944 2012-06-05] (Skype Technologies)
    3 SwitchBoard; "C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [517096 2010-02-19] (Adobe Systems Incorporated)
    2 TuneUp.UtilitiesSvc; "C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe" [1527104 2011-12-08] (TuneUp Software)
    2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [29504 2011-12-08] (TuneUp Software)
    2 Viewpoint Service; "C:\Program Files\Viewpoint\Common\ViewpointService.exe" [30152 2008-04-04] (Viewpoint Corporation)
    3 FontCache3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [x]
    2 JavaQuickStarterService; "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" [x]
    ========================== Drivers (Whitelisted) =============
    4 abp480n5; C:\Windows\system32\DRIVERS\ABP480N5.SYS [23552 2001-08-17] ()
    4 agp440; C:\Windows\System32\Drivers\agp440.svs [42368 2008-04-13] (Microsoft Corporation)
    4 AliIde; C:\Windows\system32\DRIVERS\aliide.sys [5248 2001-08-17] ()
    4 alim1541; C:\Windows\system32\DRIVERS\alim1541.sys [42752 2008-04-13] ()
    4 amdagp; C:\Windows\system32\DRIVERS\amdagp.sys [43008 2008-04-13] ()
    4 amsint; C:\Windows\system32\DRIVERS\amsint.sys [12032 2001-08-17] ()
    4 asc; C:\Windows\system32\DRIVERS\asc.sys [26496 2001-08-17] ()
    4 asc3350p; C:\Windows\system32\DRIVERS\asc3350p.sys [22400 2001-08-17] ()
    4 asc3550; C:\Windows\system32\DRIVERS\asc3550.sys [14848 2001-08-17] ()
    3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
    4 CmdIde; C:\Windows\system32\DRIVERS\cmdide.sys [6656 2001-08-17] ()
    3 cpudrv; \??\C:\Program Files\SystemRequirementsLab\cpudrv.sys [11336 2009-12-18] ()
    4 dac2w2k; C:\Windows\system32\DRIVERS\dac2w2k.sys [179584 2001-08-17] ()
    4 dac960nt; C:\Windows\system32\DRIVERS\dac960nt.sys [14720 2001-08-17] ()
    2 drvnddm; C:\Windows\System32\drivers\drvnddm.sys [40480 2004-11-23] (Sonic Solutions)
    3 e1express; C:\Windows\System32\DRIVERS\e1e5132.sys [176128 2005-08-26] (Intel Corporation)
    3 ELacpi; C:\Windows\System32\DRIVERS\ELacpi.sys [7808 2005-12-12] (Intel Corporation)
    1 ELhid; C:\Windows\System32\DRIVERS\ELhid.sys [10112 2005-12-12] (Intel Corporation)
    1 ELkbd; C:\Windows\System32\DRIVERS\ELkbd.sys [6912 2005-12-12] (Intel Corporation)
    1 ELmon; C:\Windows\System32\DRIVERS\ELmon.sys [7040 2005-12-12] (Intel Corporation)
    1 ELmou; C:\Windows\System32\DRIVERS\ELmou.sys [6400 2005-12-12] (Intel Corporation)
    3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows (R) Server 2003 DDK provider)
    3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49920 2009-05-18] (HP)
    3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2009-05-18] (HP)
    3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2009-05-18] (HP)
    0 iastor; C:\Windows\System32\drivers\iastor.sys [872064 2005-06-17] ()
    4 ini910u; C:\Windows\system32\DRIVERS\ini910u.sys [16000 2001-08-17] ()
    3 LHidFilt; C:\Windows\System32\DRIVERS\LHidFilt.Sys [34576 2007-01-23] (Logitech, Inc.)
    3 LHidUsbK; C:\Windows\System32\Drivers\LHidUsbK.Sys [36736 2006-05-10] (Logitech, Inc.)
    3 LMouFilt; C:\Windows\System32\DRIVERS\LMouFilt.Sys [33296 2007-01-23] (Logitech, Inc.)
    3 MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [22344 2012-04-04] (Malwarebytes Corporation)
    3 MHNDRV; C:\Windows\System32\DRIVERS\mhndrv.sys [11008 2004-08-10] ()
    0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-21] (Microsoft Corporation)
    4 mraid35x; C:\Windows\system32\DRIVERS\mraid35x.sys [17280 2001-08-17] ()
    3 MSHUSBVideo; C:\Windows\System32\Drivers\nx6000.sys [30576 2010-12-13] (Microsoft Corporation)
    3 NABTSFEC; C:\Windows\System32\DRIVERS\NABTSFEC.sys [85248 2008-04-13] (Microsoft Corporation)
    3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
    3 NVHDA; C:\Windows\System32\drivers\nvhda32.sys [123840 2012-04-18] (NVIDIA Corporation)
    3 PSched; C:\Windows\System32\DRIVERS\psched.sys [69120 2008-04-13] (Microsoft Corporation)
    3 Ptilink; C:\Windows\System32\DRIVERS\ptilink.sys [17792 2004-08-10] (Parallel Technologies, Inc.)
    3 pwdrvio; \??\C:\WINDOWS\system32\pwdrvio.sys [16472 2010-08-16] ()
    3 pwdspio; \??\C:\WINDOWS\system32\pwdspio.sys [11104 2010-08-16] ()
    4 ql1080; C:\Windows\system32\DRIVERS\ql1080.sys [40320 2001-08-17] ()
    4 Ql10wnt; C:\Windows\system32\DRIVERS\ql10wnt.sys [33152 2001-08-17] ()
    4 ql12160; C:\Windows\system32\DRIVERS\ql12160.sys [45312 2001-08-17] ()
    4 ql1240; C:\Windows\system32\DRIVERS\ql1240.sys [40448 2001-08-17] ()
    3 SLIP; C:\Windows\System32\DRIVERS\SLIP.sys [11136 2008-04-13] (Microsoft Corporation)
    4 Sparrow; C:\Windows\system32\DRIVERS\sparrow.sys [19072 2001-08-17] (Adaptec, Inc.)
    1 sscdbhk5; C:\Windows\System32\drivers\sscdbhk5.sys [5627 2004-07-14] (Sonic Solutions)
    1 ssrtln; C:\Windows\System32\drivers\ssrtln.sys [23545 2004-07-14] (Sonic Solutions)
    3 STHDA; C:\Windows\System32\drivers\sthda.sys [180864 2005-06-15] (SigmaTel, Inc.)
    3 streamip; C:\Windows\System32\DRIVERS\StreamIP.sys [15232 2008-04-13] (Microsoft Corporation)
    4 symc810; C:\Windows\system32\DRIVERS\symc810.sys [16256 2001-08-17] (Symbios Logic Inc.)
    4 symc8xx; C:\Windows\system32\DRIVERS\symc8xx.sys [32640 2001-08-17] ()
    4 sym_hi; C:\Windows\system32\DRIVERS\sym_hi.sys [28384 2001-08-17] ()
    4 sym_u3; C:\Windows\system32\DRIVERS\sym_u3.sys [30688 2001-08-17] ()
    2 tfsnboio; C:\Windows\System32\dla\tfsnboio.sys [25883 2004-12-06] (Sonic Solutions)
    2 tfsncofs; C:\Windows\System32\dla\tfsncofs.sys [34843 2004-12-06] (Sonic Solutions)
    2 tfsndrct; C:\Windows\System32\dla\tfsndrct.sys [4123 2004-12-06] (Sonic Solutions)
    2 tfsndres; C:\Windows\System32\dla\tfsndres.sys [2239 2004-12-06] (Sonic Solutions)
    2 tfsnifs; C:\Windows\System32\dla\tfsnifs.sys [86586 2004-12-06] (Sonic Solutions)
    2 tfsnopio; C:\Windows\System32\dla\tfsnopio.sys [15227 2004-12-06] (Sonic Solutions)
    2 tfsnpool; C:\Windows\System32\dla\tfsnpool.sys [6363 2004-12-06] (Sonic Solutions)
    2 tfsnudf; C:\Windows\System32\dla\tfsnudf.sys [98714 2004-12-06] (Sonic Solutions)
    2 tfsnudfa; C:\Windows\System32\dla\tfsnudfa.sys [100603 2004-12-06] (Sonic Solutions)
    2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2010-12-19] (Acronis)
    0 timounter; C:\Windows\System32\DRIVERS\timntr.sys [441760 2010-12-19] (Acronis)
    4 TosIde; C:\Windows\system32\DRIVERS\toside.sys [4992 2001-08-17] ()
    3 TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [10064 2011-07-07] (TuneUp Software)
    4 ultra; C:\Windows\system32\DRIVERS\ultra.sys [36736 2001-08-17] ()
    3 usb_rndisx; C:\Windows\System32\DRIVERS\usb8023x.sys [12800 2008-04-13] (Microsoft Corporation)
    0 vkquwexg; C:\Windows\System32\drivers\Combo-Fix.sys [60416 2012-06-26] ()
    3 wceusbsh; C:\Windows\System32\DRIVERS\wceusbsh.sys [28672 2006-11-06] (Microsoft Corporation)
    3 WSTCODEC; C:\Windows\System32\DRIVERS\WSTCODEC.SYS [19200 2008-04-13] (Microsoft Corporation)
    4 Abiosdsk; [x]
    4 Atdisk; [x]
    3 catchme; \??\C:\DOCUME~1\Admin1\LOCALS~1\Temp\catchme.sys [x]
    1 Changer; [x]
    3 EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys [x]
    3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [x]
    1 lbrtfdc; [x]
    3 LMouKE; C:\Windows\System32\DRIVERS\LMouKE.Sys [x]
    1 MpKsl1cb3245a; \??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A4A6C516-9C8E-4F0D-80C2-3FE03BF91FDB}\MpKsl1cb3245a.sys [x]
    1 PCIDump; [x]
    3 PDCOMP; [x]
    3 PDFRAME; [x]
    3 PDRELI; [x]
    3 PDRFRAME; [x]
    4 Simbad; [x]
    3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [x]
    3 WDICA; [x]
    2 zumbus; C:\Windows\System32\DRIVERS\zumbus.sys [x]
     
  22. Syreynna

    Syreynna TS Rookie Topic Starter Posts: 74

    ========================== NetSvcs (Whitelisted) ===========
    NETSVC: UxTuneUp -> C:\Windows\System32\uxtuneup.dll (TuneUp Software)
    ============ One Month Created Files and Folders ==============
    2012-06-26 21:38 - 2012-06-27 12:11 - 00000000 ____D C:\FRST
    2012-06-26 03:43 - 2012-06-26 03:43 - 00008192 ___AH C:\Windows\System32\config\SECURITY.tmp.LOG
    2012-06-26 03:43 - 2012-06-26 03:43 - 00000000 ___AH C:\Windows\System32\config\SYSTEM.tmp.LOG
    2012-06-26 03:43 - 2012-06-26 03:43 - 00000000 ___AH C:\Windows\System32\config\SOFTWARE.tmp.LOG
    2012-06-26 03:43 - 2012-06-26 03:43 - 00000000 ___AH C:\Windows\System32\config\SAM.tmp.LOG
    2012-06-26 03:43 - 2012-06-26 03:43 - 00000000 ___AH C:\Windows\System32\config\DEFAULT.tmp.LOG
    2012-06-26 03:42 - 2012-06-26 03:42 - 00060416 ____A C:\Windows\System32\Drivers\Combo-Fix.sys
    2012-06-26 03:42 - 2008-04-13 18:36 - 00042368 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\agp440.svs
    2012-06-26 03:40 - 2012-06-26 03:43 - 00000000 ___SD C:\ComboFix
    2012-06-26 03:38 - 2012-06-26 03:38 - 04569239 ____R (Swearware) C:\Documents and Settings\Admin1\Desktop\ComboFix.exe
    2012-06-26 03:30 - 2012-06-26 03:30 - 02109806 ____A C:\Documents and Settings\Admin1\Desktop\tdsskiller.zip
    2012-06-26 03:30 - 2012-06-21 01:11 - 02128472 ____A (Kaspersky Lab ZAO) C:\Documents and Settings\Admin1\Desktop\TDSSKiller.exe
    2012-06-26 03:30 - 2011-01-01 05:14 - 00002254 ___RA C:\Documents and Settings\Admin1\Desktop\eula.txt
    2012-06-26 02:58 - 2012-06-26 02:58 - 04731392 ____A (AVAST Software) C:\Documents and Settings\Admin1\Desktop\aswMBR.exe
    2012-06-26 02:58 - 2012-06-26 02:58 - 00000755 ____A C:\Documents and Settings\Admin1\Desktop\bootcleaner.txt
    2012-06-26 02:55 - 2012-06-26 02:54 - 00044607 ____A C:\Documents and Settings\Admin1\Desktop\bootkit_remover.zip
    2012-06-26 02:55 - 2011-09-21 22:11 - 00003641 ____A C:\Documents and Settings\Admin1\Desktop\readme_ru.txt
    2012-06-26 02:55 - 2011-09-21 22:11 - 00003114 ____A C:\Documents and Settings\Admin1\Desktop\readme_en.txt
    2012-06-26 02:55 - 2011-09-20 07:02 - 00083968 ____A (Esage Lab) C:\Documents and Settings\Admin1\Desktop\boot_cleaner.exe
    2012-06-25 23:43 - 2012-06-25 23:43 - 00028169 ____A C:\Documents and Settings\Admin1\Desktop\gmer.log
    2012-06-25 20:22 - 2012-06-25 20:21 - 00302592 ____A C:\Documents and Settings\Admin1\Desktop\d4c1iup5.exe
    2012-06-25 20:17 - 2012-06-25 20:17 - 00000794 ____A C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
    2012-06-25 20:16 - 2012-06-25 20:17 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
    2012-06-25 20:16 - 2012-04-04 19:56 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-06-25 20:15 - 2012-06-24 07:01 - 10063000 ____A (Malwarebytes Corporation ) C:\Documents and Settings\Admin1\Desktop\mbam-setup-1.61.0.1400.exe
    2012-06-25 07:28 - 2012-06-25 23:44 - 00002727 ____A C:\Windows\setupapi.log
    2012-06-25 07:28 - 2004-08-10 11:00 - 00169984 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\iisui.dll
    2012-06-25 07:28 - 2004-08-10 11:00 - 00094720 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\certmap.ocx
    2012-06-25 07:28 - 2004-08-10 11:00 - 00019968 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\inetsloc.dll
    2012-06-25 07:28 - 2004-08-10 11:00 - 00014336 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\iisreset.exe
    2012-06-25 07:28 - 2004-08-10 11:00 - 00007680 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\inetmgr.exe
    2012-06-25 07:28 - 2004-08-10 11:00 - 00007168 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\wamregps.dll
    2012-06-25 07:28 - 2004-08-10 11:00 - 00006144 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\ftpsapi2.dll
    2012-06-25 07:28 - 2004-08-10 11:00 - 00005632 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\iisrstap.dll
    2012-06-25 07:28 - 2001-08-17 18:56 - 00066048 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\s3legacy.dll
    2012-06-25 03:04 - 2012-06-25 03:04 - 00000000 ____D C:\Documents and Settings\Admin1\Application Data\SunRay Games
    2012-06-25 02:50 - 2012-06-25 02:50 - 00000000 ____D C:\Windows\Mystic Diary 3 - Missing Pages With Guide
    2012-06-25 01:05 - 2012-06-25 01:05 - 00098992 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\60941195.sys
    2012-06-25 00:03 - 2012-06-25 00:03 - 00000000 RASHD C:\cmdcons
    2012-06-25 00:03 - 2010-12-19 19:12 - 00000209 ____A C:\Boot.bak
    2012-06-25 00:03 - 2004-08-04 03:00 - 00260272 _RASH C:\cmldr
    2012-06-25 00:00 - 2011-06-26 06:45 - 00256000 ____A C:\Windows\PEV.exe
    2012-06-25 00:00 - 2010-11-07 17:20 - 00208896 ____A C:\Windows\MBR.exe
    2012-06-25 00:00 - 2009-04-20 04:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
    2012-06-25 00:00 - 2000-08-31 00:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
    2012-06-25 00:00 - 2000-08-31 00:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
    2012-06-25 00:00 - 2000-08-31 00:00 - 00212480 ____A (SteelWerX) C:\Windows\SWXCACLS.exe
    2012-06-25 00:00 - 2000-08-31 00:00 - 00098816 ____A C:\Windows\sed.exe
    2012-06-25 00:00 - 2000-08-31 00:00 - 00080412 ____A C:\Windows\grep.exe
    2012-06-25 00:00 - 2000-08-31 00:00 - 00068096 ____A C:\Windows\zip.exe
    2012-06-24 23:27 - 2012-06-24 23:27 - 00000000 ____D C:\TDSSKiller_Quarantine
    2012-06-24 23:20 - 2012-06-26 03:42 - 00000000 ____D C:\Windows\erdnt
    2012-06-24 23:20 - 2012-06-25 09:05 - 00000000 ____D C:\Qoobox
    2012-06-24 23:02 - 2012-06-24 23:02 - 00000218 ____A C:\Documents and Settings\Admin1\.recently-used.xbel
    2012-06-24 06:15 - 2012-06-26 02:54 - 00000366 ___AH C:\Windows\Tasks\MpIdleTask.job
    2012-06-24 06:15 - 2012-06-26 00:21 - 00000384 ___AH C:\Windows\Tasks\Microsoft Antimalware Scheduled Scan.job
    2012-06-24 06:05 - 2012-06-24 06:05 - 00000000 ____D C:\Program Files\Microsoft Security Client
    2012-06-24 06:02 - 2012-06-24 06:02 - 00000000 ____D C:\Documents and Settings\UpdatusUser\Application Data\Macromedia
    2012-06-24 06:02 - 2012-06-24 06:02 - 00000000 ____D C:\Documents and Settings\UpdatusUser\Application Data\Adobe
    2012-06-24 05:11 - 2012-06-24 05:11 - 00000000 ____D C:\Documents and Settings\LocalService\Application Data\Macromedia
    2012-06-24 05:11 - 2012-06-24 05:11 - 00000000 ____D C:\Documents and Settings\LocalService\Application Data\Adobe
    2012-06-16 14:04 - 2012-06-16 14:04 - 00476936 ____A (Sun Microsystems, Inc.) C:\Windows\System32\npdeployJava1.dll
    2012-06-16 14:04 - 2012-06-16 14:04 - 00157448 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
    2012-06-16 14:04 - 2012-06-16 14:04 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
    2012-06-16 14:04 - 2012-06-16 14:04 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
    2012-06-15 16:09 - 2012-06-15 16:09 - 00000000 ____D C:\Documents and Settings\GJNA&T\Application Data\TuneUp Software
    2012-06-14 15:20 - 2012-06-26 03:43 - 00065536 ____A C:\Windows\System32\config\TuneUp.evt
    2012-06-14 15:20 - 2011-12-08 21:38 - 00031552 ____A (TuneUp Software) C:\Windows\System32\TURegOpt.exe
    2012-06-14 15:20 - 2011-12-08 21:31 - 00029504 ____A (TuneUp Software) C:\Windows\System32\uxtuneup.dll
    2012-06-14 15:19 - 2012-06-16 19:51 - 00000000 ____D C:\Program Files\TuneUp Utilities 2011
    2012-06-14 15:19 - 2012-06-14 15:20 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\TuneUp Software
    2012-06-14 15:19 - 2012-06-14 15:19 - 00000000 ____D C:\Documents and Settings\Admin1\Application Data\TuneUp Software
    2012-06-14 15:18 - 2012-06-14 15:18 - 00000000 __SHD C:\Documents and Settings\All Users\Application Data\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
    2012-06-13 09:04 - 2012-06-22 07:16 - 00000000 __HDC C:\Windows\$NtUninstallKB2709162$
    2012-06-13 06:28 - 2012-05-11 14:42 - 00521728 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\jsdbgui.dll
    ============ 3 Months Modified Files and Folders ===============
    2012-06-27 12:11 - 2012-06-26 21:38 - 00000000 ____D C:\FRST
    2012-06-26 03:43 - 2012-06-26 03:43 - 00008192 ___AH C:\Windows\System32\config\SECURITY.tmp.LOG
    2012-06-26 03:43 - 2012-06-26 03:43 - 00000000 ___AH C:\Windows\System32\config\SYSTEM.tmp.LOG
    2012-06-26 03:43 - 2012-06-26 03:43 - 00000000 ___AH C:\Windows\System32\config\SOFTWARE.tmp.LOG
    2012-06-26 03:43 - 2012-06-26 03:43 - 00000000 ___AH C:\Windows\System32\config\SAM.tmp.LOG
    2012-06-26 03:43 - 2012-06-26 03:43 - 00000000 ___AH C:\Windows\System32\config\DEFAULT.tmp.LOG
    2012-06-26 03:43 - 2012-06-26 03:40 - 00000000 ___SD C:\ComboFix
    2012-06-26 03:43 - 2012-06-14 15:20 - 00065536 ____A C:\Windows\System32\config\TuneUp.evt
    2012-06-26 03:43 - 2006-02-13 00:40 - 00000278 __ASH C:\Documents and Settings\Admin1\ntuser.ini
    2012-06-26 03:43 - 2006-02-06 21:04 - 47972352 ____A C:\Windows\System32\config\SOFTWARE.bak
    2012-06-26 03:43 - 2006-02-06 21:04 - 13369344 ____A C:\Windows\System32\config\SYSTEM.bak
    2012-06-26 03:43 - 2006-02-06 15:20 - 00196608 ____A C:\Windows\System32\config\IntelDH.evt
    2012-06-26 03:43 - 2005-08-16 10:40 - 01514793 ____A C:\Windows\WindowsUpdate.log
    2012-06-26 03:43 - 2005-08-16 10:35 - 00000275 ____A C:\Windows\wiadebug.log
    2012-06-26 03:43 - 2005-08-16 10:35 - 00000049 ____A C:\Windows\wiaservc.log
    2012-06-26 03:43 - 2005-08-16 04:27 - 05242880 ____A C:\Windows\System32\config\DEFAULT.bak
    2012-06-26 03:43 - 2005-08-16 04:27 - 00262144 ____A C:\Windows\System32\config\SECURITY.bak
    2012-06-26 03:43 - 2005-08-16 04:27 - 00028672 ____A C:\Windows\System32\config\SAM.bak
    2012-06-26 03:42 - 2012-06-26 03:42 - 00060416 ____A C:\Windows\System32\Drivers\Combo-Fix.sys
    2012-06-26 03:42 - 2012-06-24 23:20 - 00000000 ____D C:\Windows\erdnt
    2012-06-26 03:40 - 2005-08-16 10:49 - 00032308 ____A C:\Windows\SchedLgU.Txt
    2012-06-26 03:40 - 2005-08-16 10:49 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-06-26 03:38 - 2012-06-26 03:38 - 04569239 ____R (Swearware) C:\Documents and Settings\Admin1\Desktop\ComboFix.exe
    2012-06-26 03:30 - 2012-06-26 03:30 - 02109806 ____A C:\Documents and Settings\Admin1\Desktop\tdsskiller.zip
    2012-06-26 03:25 - 2010-12-19 04:45 - 00000982 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-762019420-644879084-276493692-1007UA.job
    2012-06-26 02:58 - 2012-06-26 02:58 - 04731392 ____A (AVAST Software) C:\Documents and Settings\Admin1\Desktop\aswMBR.exe
    2012-06-26 02:58 - 2012-06-26 02:58 - 00000755 ____A C:\Documents and Settings\Admin1\Desktop\bootcleaner.txt
    2012-06-26 02:57 - 2012-04-03 17:48 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-06-26 02:57 - 2010-12-19 01:12 - 00000982 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-762019420-644879084-276493692-1006UA.job
    2012-06-26 02:54 - 2012-06-26 02:55 - 00044607 ____A C:\Documents and Settings\Admin1\Desktop\bootkit_remover.zip
    2012-06-26 02:54 - 2012-06-24 06:15 - 00000366 ___AH C:\Windows\Tasks\MpIdleTask.job
    2012-06-26 02:12 - 2010-08-03 22:54 - 00000000 ____D C:\Documents and Settings\Admin1\Application Data\Skype
    2012-06-26 01:33 - 2012-01-08 04:13 - 00002265 ____A C:\Documents and Settings\All Users\Desktop\Skype.lnk
    2012-06-26 00:21 - 2012-06-24 06:15 - 00000384 ___AH C:\Windows\Tasks\Microsoft Antimalware Scheduled Scan.job
    2012-06-26 00:14 - 2006-02-22 22:01 - 00103607 ____A C:\dlccscan.log
    2012-06-26 00:14 - 2006-02-13 00:40 - 00000062 __ASH C:\Documents and Settings\Admin1\Local Settings\desktop.ini
    2012-06-26 00:14 - 2005-08-16 10:18 - 00002206 ____A C:\Windows\System32\wpa.dbl
    2012-06-26 00:11 - 2012-02-21 21:18 - 00000062 __ASH C:\Documents and Settings\UpdatusUser\Local Settings\desktop.ini
    2012-06-26 00:11 - 2005-08-16 10:38 - 00000000 ____D C:\Windows\Registration
    2012-06-26 00:10 - 2005-08-16 10:49 - 00000062 __ASH C:\Documents and Settings\NetworkService\Local Settings\desktop.ini
    2012-06-26 00:10 - 2005-08-16 10:49 - 00000062 __ASH C:\Documents and Settings\LocalService\Local Settings\desktop.ini
    2012-06-25 23:44 - 2012-06-25 07:28 - 00002727 ____A C:\Windows\setupapi.log
    2012-06-25 23:43 - 2012-06-25 23:43 - 00028169 ____A C:\Documents and Settings\Admin1\Desktop\gmer.log
    2012-06-25 22:25 - 2010-12-19 04:45 - 00000930 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-762019420-644879084-276493692-1007Core.job
    2012-06-25 20:21 - 2012-06-25 20:22 - 00302592 ____A C:\Documents and Settings\Admin1\Desktop\d4c1iup5.exe
    2012-06-25 20:17 - 2012-06-25 20:17 - 00000794 ____A C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
    2012-06-25 20:17 - 2012-06-25 20:16 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
    2012-06-25 09:05 - 2012-06-24 23:20 - 00000000 ____D C:\Qoobox
    2012-06-25 08:58 - 2005-08-16 10:18 - 00000227 ____A C:\Windows\system.ini
    2012-06-25 06:54 - 2011-11-14 21:05 - 00000000 ____D C:\Documents and Settings\Admin1\Application Data\.purple
    2012-06-25 03:04 - 2012-06-25 03:04 - 00000000 ____D C:\Documents and Settings\Admin1\Application Data\SunRay Games
    2012-06-25 02:50 - 2012-06-25 02:50 - 00000000 ____D C:\Windows\Mystic Diary 3 - Missing Pages With Guide
    2012-06-25 02:47 - 2011-11-17 15:59 - 00000000 ____D C:\Documents and Settings\Admin1\Application Data\uTorrent
    2012-06-25 01:05 - 2012-06-25 01:05 - 00098992 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\60941195.sys
    2012-06-25 00:42 - 2010-12-19 04:56 - 00001917 ____A C:\Windows\epplauncher.mif
    2012-06-25 00:33 - 2005-08-16 10:18 - 00000027 ____A C:\Windows\System32\Drivers\etc\hosts.bak
    2012-06-25 00:31 - 2006-02-18 08:02 - 00000000 ____D C:\Documents and Settings\Admin1\Application Data\Adobe
    2012-06-25 00:03 - 2012-06-25 00:03 - 00000000 RASHD C:\cmdcons
    2012-06-25 00:03 - 2006-02-06 15:04 - 00000325 _RASH C:\boot.ini
    2012-06-24 23:35 - 2005-08-16 10:18 - 00075264 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ipsec.sys
    2012-06-24 23:35 - 2005-08-16 10:18 - 00075264 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\ipsec.sys
    2012-06-24 23:27 - 2012-06-24 23:27 - 00000000 ____D C:\TDSSKiller_Quarantine
    2012-06-24 23:02 - 2012-06-24 23:02 - 00000218 ____A C:\Documents and Settings\Admin1\.recently-used.xbel
    2012-06-24 23:00 - 2011-11-17 17:21 - 00000000 ____D C:\Documents and Settings\Admin1\Application Data\vlc
    2012-06-24 20:13 - 2011-11-26 05:05 - 00000000 ____D C:\Documents and Settings\Admin1\Application Data\gtk-2.0
    2012-06-24 07:17 - 2008-08-28 04:05 - 00002644 ____A C:\Windows\System32\d3d9caps.dat
    2012-06-24 07:01 - 2012-06-25 20:15 - 10063000 ____A (Malwarebytes Corporation ) C:\Documents and Settings\Admin1\Desktop\mbam-setup-1.61.0.1400.exe
    2012-06-24 06:46 - 2005-08-16 10:22 - 00000000 ____D C:\Windows\security
    2012-06-24 06:05 - 2012-06-24 06:05 - 00000000 ____D C:\Program Files\Microsoft Security Client
    2012-06-24 06:02 - 2012-06-24 06:02 - 00000000 ____D C:\Documents and Settings\UpdatusUser\Application Data\Macromedia
    2012-06-24 06:02 - 2012-06-24 06:02 - 00000000 ____D C:\Documents and Settings\UpdatusUser\Application Data\Adobe
    2012-06-24 05:11 - 2012-06-24 05:11 - 00000000 ____D C:\Documents and Settings\LocalService\Application Data\Macromedia
    2012-06-24 05:11 - 2012-06-24 05:11 - 00000000 ____D C:\Documents and Settings\LocalService\Application Data\Adobe
    2012-06-24 00:13 - 2012-04-03 17:48 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
    2012-06-24 00:13 - 2011-05-26 14:52 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
    2012-06-23 18:57 - 2010-12-19 01:12 - 00000930 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-762019420-644879084-276493692-1006Core.job
    2012-06-22 20:03 - 2009-03-18 18:16 - 00000000 ____D C:\Program Files\Common Files\Blizzard Entertainment
    2012-06-22 20:02 - 2006-02-13 00:49 - 00000278 __ASH C:\Documents and Settings\GJNA&T\ntuser.ini
    2012-06-22 15:28 - 2006-02-13 00:49 - 00000062 __ASH C:\Documents and Settings\GJNA&T\Local Settings\desktop.ini
    2012-06-22 07:27 - 2012-02-21 21:18 - 00000178 ___SH C:\Documents and Settings\UpdatusUser\ntuser.ini
    2012-06-22 07:17 - 2011-07-12 19:00 - 00000000 __HDC C:\Windows\$NtUninstallKB2555917$
    2012-06-22 07:17 - 2011-04-17 19:16 - 00000000 __HDC C:\Windows\$NtUninstallKB2506223$
    2012-06-22 07:17 - 2011-04-17 19:15 - 00000000 __HDC C:\Windows\$NtUninstallKB2412687$
    2012-06-22 07:17 - 2011-04-17 19:05 - 00000000 __HDC C:\Windows\$NtUninstallKB2508429$
    2012-06-22 07:17 - 2011-03-24 03:39 - 00000000 __HDC C:\Windows\$NtUninstallKB2524375$
    2012-06-22 07:17 - 2011-02-09 07:49 - 00000000 __HDC C:\Windows\$NtUninstallKB2479628$
    2012-06-22 07:17 - 2010-12-16 06:55 - 00000000 __HDC C:\Windows\$NtUninstallKB2436673$
    2012-06-22 07:17 - 2010-12-16 06:54 - 00000000 __HDC C:\Windows\$NtUninstallKB2467659$
    2012-06-22 07:17 - 2010-12-16 06:49 - 00000000 __HDC C:\Windows\$NtUninstallKB2423089$
    2012-06-22 07:17 - 2010-10-14 06:03 - 00000000 __HDC C:\Windows\$NtUninstallKB2345886$
    2012-06-22 07:17 - 2010-10-14 06:02 - 00000000 __HDC C:\Windows\$NtUninstallKB2378111_WM9$
    2012-06-22 07:17 - 2010-09-15 08:43 - 00000000 __HDC C:\Windows\$NtUninstallKB2121546$
    2012-06-22 07:17 - 2010-08-12 04:18 - 00000000 __HDC C:\Windows\$NtUninstallKB2160329$
    2012-06-22 07:17 - 2006-12-18 18:12 - 00000000 __HDC C:\Windows\$NtServicePackUninstallIDNMitigationAPIs$
    2012-06-22 07:17 - 2006-12-18 18:11 - 00000000 __HDC C:\Windows\$NtServicePackUninstallNLSDownlevelMapping$
    2012-06-22 07:17 - 2005-08-17 03:04 - 00000000 ___HD C:\Windows\$NtUninstallEmeraldQFE2$
    2012-06-22 07:16 - 2012-06-13 09:04 - 00000000 __HDC C:\Windows\$NtUninstallKB2709162$
    2012-06-22 07:16 - 2012-05-10 19:01 - 00000000 __HDC C:\Windows\$NtUninstallKB2659262$
    2012-06-22 07:16 - 2012-05-10 18:51 - 00000000 __HDC C:\Windows\$NtUninstallKB2686509$
    2012-06-22 07:16 - 2012-04-12 04:26 - 00000000 __HDC C:\Windows\$NtUninstallKB2656378$
    2012-06-22 07:16 - 2012-03-14 19:07 - 00000000 __HDC C:\Windows\$NtUninstallKB2641653$
    2012-06-22 07:16 - 2012-02-16 20:09 - 00000000 __HDC C:\Windows\$NtUninstallKB2660465$
    2012-06-22 07:16 - 2012-02-16 20:00 - 00000000 __HDC C:\Windows\$NtUninstallKB2661637$
    2012-06-22 07:16 - 2012-01-18 16:16 - 00000000 __HDC C:\Windows\$NtUninstallKB2646524$
    2012-06-22 07:16 - 2011-12-14 20:03 - 00000000 __HDC C:\Windows\$NtUninstallKB2639417$
    2012-06-22 07:16 - 2011-10-14 08:04 - 00000000 __HDC C:\Windows\$NtUninstallKB2567053$
    2012-06-22 07:16 - 2011-08-12 04:47 - 00000000 __HDC C:\Windows\$NtUninstallKB973442_WM11$
    2012-06-22 07:16 - 2011-08-11 05:19 - 00000000 __HDC C:\Windows\$NtUninstallKB2567680$
    2012-06-22 07:16 - 2010-10-14 06:02 - 00000000 __HDC C:\Windows\$NtUninstallKB982132$
    2012-06-22 07:16 - 2010-10-14 04:52 - 00000000 __HDC C:\Windows\$NtUninstallKB981957$
    2012-06-22 07:16 - 2010-09-15 08:42 - 00000000 __HDC C:\Windows\$NtUninstallKB981322$
    2012-06-22 07:16 - 2010-08-12 04:25 - 00000000 __HDC C:\Windows\$NtUninstallKB982214$
    2012-06-22 07:16 - 2010-06-13 19:15 - 00000000 __HDC C:\Windows\$NtUninstallKB979904$
    2012-06-22 07:16 - 2010-06-13 19:12 - 00000000 __HDC C:\Windows\$NtUninstallKB979559$
    2012-06-22 07:16 - 2010-06-13 19:08 - 00000000 __HDC C:\Windows\$NtUninstallKB978695_WM9$
    2012-06-22 07:16 - 2010-04-18 10:05 - 00000000 __HDC C:\Windows\$NtUninstallKB978601$
    2012-06-22 07:16 - 2010-02-11 01:20 - 00000000 __HDC C:\Windows\$NtUninstallKB971468$
    2012-06-22 07:16 - 2009-12-10 01:04 - 00000000 __HDC C:\Windows\$NtUninstallKB971737$
    2012-06-22 07:16 - 2009-11-13 10:28 - 00000000 __HDC C:\Windows\$NtUninstallKB969947$
    2012-06-22 07:16 - 2009-10-17 10:13 - 00000000 __HDC C:\Windows\$NtUninstallKB958869$
    2012-06-22 07:16 - 2009-10-17 10:10 - 00000000 __HDC C:\Windows\$NtUninstallKB974112$
    2012-06-22 07:16 - 2009-10-17 10:10 - 00000000 __HDC C:\Windows\$NtUninstallKB954155_WM9$
    2012-06-22 07:16 - 2009-09-25 19:32 - 00000000 __HDC C:\Windows\$NtUninstallWdf01009$
    2012-06-22 07:16 - 2009-09-12 15:28 - 00000000 __HDC C:\Windows\$NtUninstallKB968816_WM9$
    2012-06-22 07:16 - 2009-09-12 15:27 - 00000000 __HDC C:\Windows\$NtUninstallKB956844$
    2012-06-22 07:16 - 2009-09-05 06:22 - 00000000 __HDC C:\Windows\$NtUninstallwinusb0100$
    2012-06-22 07:16 - 2009-09-05 06:20 - 00000000 __HDC C:\Windows\$NtUninstallWdf01007$
    2012-06-22 07:16 - 2009-08-14 02:24 - 00000000 __HDC C:\Windows\$NtUninstallKB960859$
    2012-06-22 07:16 - 2009-08-14 02:23 - 00000000 __HDC C:\Windows\$NtUninstallKB971657$
    2012-06-22 07:16 - 2009-08-14 02:22 - 00000000 __HDC C:\Windows\$NtUninstallKB973540_WM9$
    2012-06-22 07:16 - 2009-06-14 07:28 - 00000000 __HDC C:\Windows\$NtUninstallKB968537$
    2012-06-22 07:16 - 2009-04-19 19:02 - 00000000 __HDC C:\Windows\$NtUninstallKB960803$
    2012-06-22 07:16 - 2009-03-13 12:26 - 00000000 __HDC C:\Windows\$NtUninstallKB958690$
    2012-06-22 07:16 - 2009-03-13 12:25 - 00000000 __HDC C:\Windows\$NtUninstallKB959772_WM11$
    2012-06-22 07:16 - 2009-01-15 18:11 - 00000000 __HDC C:\Windows\$NtUninstallKB958687$
    2012-06-22 07:16 - 2008-12-15 05:37 - 00000000 __HDC C:\Windows\$NtUninstallKB955839$
    2012-06-22 07:16 - 2008-12-15 05:33 - 00000000 __HDC C:\Windows\$NtUninstallKB954600$
    2012-06-22 07:16 - 2008-11-05 15:29 - 00000000 __HDC C:\Windows\$NtUninstallKB957095$
    2012-06-22 07:16 - 2008-11-05 15:27 - 00000000 __HDC C:\Windows\$NtUninstallKB954211$
    2012-06-22 07:16 - 2008-09-10 01:18 - 00000000 __HDC C:\Windows\$NtUninstallKB954154_WM11$
    2012-06-22 07:16 - 2008-09-10 01:18 - 00000000 __HDC C:\Windows\$NtUninstallKB938464$
    2012-06-22 07:16 - 2008-08-17 15:57 - 00000000 __HDC C:\Windows\$NtUninstallKB951072-v2$
    2012-06-22 07:16 - 2008-04-13 18:46 - 00000000 __HDC C:\Windows\$NtUninstallKB941693$
    2012-06-22 07:16 - 2008-01-15 04:34 - 00000000 __HDC C:\Windows\$NtUninstallKB941644$
    2012-06-22 07:16 - 2007-12-16 18:27 - 00000000 __HDC C:\Windows\$NtUninstallKB942763$
    2012-06-22 07:16 - 2007-12-16 18:27 - 00000000 __HDC C:\Windows\$NtUninstallKB941569$
    2012-06-22 07:16 - 2007-11-17 13:58 - 00000000 __HDC C:\Windows\$NtUninstallKB939683$
    2012-06-22 07:16 - 2007-11-12 19:11 - 00000000 __HDC C:\Windows\$NtUninstallMSCompPackV1$
    2012-06-22 07:16 - 2007-11-12 19:10 - 00000000 __HDC C:\Windows\$NtUninstallWudf01000$
    2012-06-22 07:16 - 2007-08-29 17:15 - 00000000 __HDC C:\Windows\$NtUninstallKB933360$
    2012-06-22 07:16 - 2007-08-18 16:23 - 00000000 __HDC C:\Windows\$NtUninstallKB936782_WMP10$
    2012-06-22 07:16 - 2007-07-17 00:44 - 00000000 __HDC C:\Windows\$NtUninstallKB936357$
    2012-06-22 07:16 - 2007-04-12 21:01 - 00000000 __HDC C:\Windows\$NtUninstallKB931261$
    2012-06-22 07:16 - 2007-04-12 21:00 - 00000000 __HDC C:\Windows\$NtUninstallKB930178$
    2012-06-22 07:16 - 2007-04-07 21:24 - 00000000 __HDC C:\Windows\$NtUninstallWdf01005$
    2012-06-22 07:16 - 2007-02-22 00:50 - 00000000 __HDC C:\Windows\$NtUninstallKB927802$
    2012-06-22 07:16 - 2007-02-22 00:49 - 00000000 __HDC C:\Windows\$NtUninstallKB931836$
    2012-06-22 07:16 - 2006-12-18 18:11 - 00000000 __HDC C:\Windows\$NtUninstallKB915865$
    2012-06-22 07:16 - 2006-12-18 18:10 - 00000000 __HDC C:\Windows\$NtUninstallKB914440$
    2012-06-22 07:16 - 2006-12-18 18:10 - 00000000 __HDC C:\Windows\$NtUninstallKB904942$
    2012-06-22 07:16 - 2006-12-15 16:51 - 00000000 __HDC C:\Windows\$NtUninstallKB923689$
    2012-06-22 07:16 - 2006-12-15 16:50 - 00000000 __HDC C:\Windows\$NtUninstallKB926255$
    2012-06-22 07:16 - 2006-10-14 18:27 - 00000000 __HDC C:\Windows\$NtUninstallKB923414$
    2012-06-22 07:16 - 2006-09-26 18:10 - 00000000 __HDC C:\Windows\$NtUninstallKB925486$
    2012-06-22 07:16 - 2006-07-13 01:09 - 00000000 __HDC C:\Windows\$NtUninstallKB917159$
    2012-06-22 07:16 - 2006-06-17 06:40 - 00000000 __HDC C:\Windows\$NtUninstallKB917734_WMP10$
    2012-06-22 07:16 - 2006-06-17 06:38 - 00000000 __HDC C:\Windows\$NtUninstallKB917953$
    2012-06-22 07:16 - 2006-02-18 08:03 - 00000000 __HDC C:\Windows\$NtUninstallKB911927$
    2012-06-22 07:16 - 2006-02-18 08:03 - 00000000 __HDC C:\Windows\$NtUninstallKB911565$
    2012-06-22 07:16 - 2006-02-18 08:02 - 00000000 __HDC C:\Windows\$NtUninstallKB913446$
    2012-06-22 07:16 - 2006-02-13 01:56 - 00000000 __HDC C:\Windows\$NtUninstallKB910393$
    2012-06-22 07:16 - 2006-02-13 01:56 - 00000000 __HDC C:\Windows\$NtUninstallKB896424$
    2012-06-22 07:16 - 2006-02-13 01:55 - 00000000 __HDC C:\Windows\$NtUninstallKB887998$
    2012-06-22 07:16 - 2006-02-13 01:54 - 00000000 __HDC C:\Windows\$NtUninstallKB893066$
    2012-06-22 07:16 - 2006-02-13 01:53 - 00000000 __HDC C:\Windows\$NtUninstallKB888302$
    2012-06-22 07:16 - 2006-02-13 01:52 - 00000000 __HDC C:\Windows\$NtUninstallKB905749$
    2012-06-22 07:16 - 2006-02-13 01:52 - 00000000 __HDC C:\Windows\$NtUninstallKB896428$
    2012-06-22 07:16 - 2006-02-13 01:22 - 00000000 __HDC C:\Windows\$NtUninstallKB898461$
    2012-06-22 07:16 - 2006-02-06 15:18 - 00000000 __HDC C:\Windows\$NtUninstallKB835221WXP$
    2012-06-22 07:16 - 2005-08-17 03:07 - 00000000 ___HD C:\Windows\$NtUninstallKB902841$
    2012-06-22 07:16 - 2005-08-17 03:06 - 00000000 ___HD C:\Windows\$NtUninstallKB903157$
    2012-06-22 07:16 - 2005-08-17 03:06 - 00000000 ___HD C:\Windows\$NtUninstallKB899510$
    2012-06-22 07:16 - 2005-08-17 03:06 - 00000000 ___HD C:\Windows\$NtUninstallKB895961$
    2012-06-22 07:01 - 2006-10-20 22:54 - 00000000 ____D C:\Windows\Minidump
    2012-06-22 06:50 - 2009-04-21 20:13 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Google
    2012-06-22 06:50 - 2006-02-13 00:40 - 00000000 ____D C:\Documents and Settings\Admin1\Local Settings\Application Data\Google
    2012-06-22 06:50 - 2006-02-06 15:32 - 00000000 ____D C:\Program Files\Google
    2012-06-21 16:02 - 2005-08-16 10:22 - 00000000 ____D C:\Windows\Help
    2012-06-21 01:11 - 2012-06-26 03:30 - 02128472 ____A (Kaspersky Lab ZAO) C:\Documents and Settings\Admin1\Desktop\TDSSKiller.exe
    2012-06-20 22:35 - 2012-05-15 18:20 - 00000000 ____D C:\Documents and Settings\Admin1\My Documents\Diablo III
    2012-06-20 16:36 - 2006-02-15 02:08 - 00000000 ____D C:\Program Files\Dl_cats
    2012-06-19 00:54 - 2006-12-15 21:42 - 00052736 ___AC C:\Documents and Settings\Admin1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2012-06-17 07:05 - 2005-08-16 10:33 - 00609122 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-06-17 07:05 - 2005-08-16 10:22 - 00000000 ____D C:\Windows\System32\inetsrv
    2012-06-16 19:51 - 2012-06-14 15:19 - 00000000 ____D C:\Program Files\TuneUp Utilities 2011
    2012-06-16 14:04 - 2012-06-16 14:04 - 00476936 ____A (Sun Microsystems, Inc.) C:\Windows\System32\npdeployJava1.dll
    2012-06-16 14:04 - 2012-06-16 14:04 - 00157448 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe
    2012-06-16 14:04 - 2012-06-16 14:04 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe
    2012-06-16 14:04 - 2012-06-16 14:04 - 00149256 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe
    2012-06-16 14:04 - 2011-05-07 01:55 - 00472840 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll
    2012-06-16 14:04 - 2008-08-08 17:11 - 00073728 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javacpl.cpl
    2012-06-15 16:09 - 2012-06-15 16:09 - 00000000 ____D C:\Documents and Settings\GJNA&T\Application Data\TuneUp Software
    2012-06-15 08:01 - 2012-01-08 04:13 - 00000000 ___RD C:\Program Files\Skype
    2012-06-15 08:01 - 2010-08-03 22:53 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Skype
    2012-06-14 15:20 - 2012-06-14 15:19 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\TuneUp Software
    2012-06-14 15:19 - 2012-06-14 15:19 - 00000000 ____D C:\Documents and Settings\Admin1\Application Data\TuneUp Software
    2012-06-14 15:18 - 2012-06-14 15:18 - 00000000 __SHD C:\Documents and Settings\All Users\Application Data\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
    2012-06-14 07:07 - 2006-02-18 08:02 - 00000000 ____D C:\Documents and Settings\Admin1\Local Settings\Application Data\Adobe
    2012-06-13 18:28 - 2010-12-19 04:46 - 00002303 ____A C:\Documents and Settings\GJNA&T\Desktop\Google Chrome.lnk
    2012-06-13 17:28 - 2005-08-16 10:38 - 00000000 ____D C:\Windows\Microsoft.NET
    2012-06-13 17:19 - 2005-08-16 10:27 - 03534552 ____A C:\Windows\System32\FNTCACHE.DAT
    2012-06-13 09:12 - 2006-02-13 01:57 - 56731752 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2012-06-13 09:09 - 2006-02-06 15:14 - 00000000 ___HD C:\Windows\$hf_mig$
    2012-06-12 04:02 - 2010-12-19 01:12 - 00002303 ____A C:\Documents and Settings\Admin1\Desktop\Google Chrome.lnk
    2012-06-04 16:19 - 2008-09-02 20:12 - 00002644 ___AC C:\Documents and Settings\GJNA&T\Local Settings\Application Data\d3d9caps.tmp
    2012-06-04 13:39 - 2012-01-05 19:51 - 00000000 ____D C:\Documents and Settings\GJNA&T\Application Data\vlc
    2012-06-02 19:19 - 2007-06-20 23:22 - 00022040 ____A (Microsoft Corporation) C:\Windows\System32\wucltui.dll.mui
    2012-06-02 19:19 - 2007-06-20 23:22 - 00017944 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll.mui
    2012-06-02 19:19 - 2007-06-20 23:22 - 00015384 ____A (Microsoft Corporation) C:\Windows\System32\wuaucpl.cpl.mui
    2012-06-02 19:19 - 2007-06-20 23:22 - 00015384 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll.mui
    2012-06-02 19:19 - 2005-08-16 10:40 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2012-06-02 19:19 - 2005-08-16 10:40 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\wuaueng.dll
    2012-06-02 19:19 - 2005-08-16 10:40 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
    2012-06-02 19:19 - 2005-08-16 10:40 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\wuapi.dll
    2012-06-02 19:19 - 2005-08-16 10:40 - 00329240 ____A (Microsoft Corporation) C:\Windows\System32\wucltui.dll
    2012-06-02 19:19 - 2005-08-16 10:40 - 00329240 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\wucltui.dll
    2012-06-02 19:19 - 2005-08-16 10:40 - 00219160 ____A (Microsoft Corporation) C:\Windows\System32\wuaucpl.cpl
    2012-06-02 19:19 - 2005-08-16 10:40 - 00219160 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\wuaucpl.cpl
    2012-06-02 19:19 - 2005-08-16 10:40 - 00210968 ____A (Microsoft Corporation) C:\Windows\System32\wuweb.dll
    2012-06-02 19:19 - 2005-08-16 10:40 - 00210968 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\wuweb.dll
    2012-06-02 19:19 - 2005-08-16 10:40 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2012-06-02 19:19 - 2005-08-16 10:40 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\wuauclt.exe
    2012-06-02 19:19 - 2005-08-16 10:40 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
    2012-06-02 19:19 - 2005-08-16 10:40 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\wups.dll
    2012-06-02 19:19 - 2005-08-16 10:18 - 00097304 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\cdm.dll
    2012-06-02 19:19 - 2005-08-16 10:18 - 00097304 ____A (Microsoft Corporation) C:\Windows\System32\cdm.dll
    2012-06-02 19:19 - 2005-05-26 09:16 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2012-06-02 19:18 - 2007-06-21 21:23 - 00017136 ____A (Microsoft Corporation) C:\Windows\System32\mucltui.dll.mui
    2012-06-02 19:18 - 2006-12-19 07:36 - 00275696 ____A (Microsoft Corporation) C:\Windows\System32\mucltui.dll
    2012-06-02 19:18 - 2005-05-26 09:19 - 00214256 ____A (Microsoft Corporation) C:\Windows\System32\muweb.dll
    2012-06-02 07:09 - 2006-02-15 13:29 - 00118708 ____A C:\dlcc.log
    2012-05-31 13:22 - 2005-08-16 10:18 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\crypt32.dll
    2012-05-31 13:22 - 2005-08-16 10:18 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
    2012-05-27 19:31 - 2006-02-06 15:06 - 00000000 ____D C:\Windows\System32\ReinstallBackups
    2012-05-27 19:30 - 2011-09-16 19:09 - 01075248 ____A C:\Windows\System32\nvdrsdb1.bin
    2012-05-27 19:30 - 2011-09-16 19:09 - 01075248 ____A C:\Windows\System32\nvdrsdb0.bin
    2012-05-27 19:30 - 2011-09-16 19:09 - 00000001 ____A C:\Windows\System32\nvdrssel.bin
    2012-05-27 19:30 - 2010-01-10 00:25 - 00000000 ____D C:\Program Files\NVIDIA Corporation
    2012-05-16 15:08 - 2005-08-16 10:18 - 00916992 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-05-16 15:08 - 2005-08-16 10:18 - 00916992 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\wininet.dll
    2012-05-15 18:05 - 2012-05-15 17:10 - 00000678 ____A C:\Documents and Settings\All Users\Desktop\Diablo III.lnk
    2012-05-15 17:06 - 2012-05-15 17:06 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Battle.net
    2012-05-15 13:20 - 2008-11-03 07:58 - 01863168 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\win32k.sys
    2012-05-15 13:20 - 2005-08-16 10:18 - 01863168 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-05-15 10:18 - 2012-04-19 19:58 - 00010264 ____A C:\Windows\System32\nvinfo.pb
    2012-05-15 10:18 - 2011-09-16 19:22 - 01000768 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco32.dll
    2012-05-15 10:18 - 2011-09-16 19:22 - 00883008 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco32.dll
    2012-05-15 10:18 - 2011-07-02 08:46 - 02807708 ____A C:\Windows\System32\nvdata.data
    2012-05-15 10:18 - 2010-07-31 14:47 - 18771968 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglnt.dll
    2012-05-15 10:18 - 2010-07-31 14:47 - 17543168 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
    2012-05-15 10:18 - 2010-07-31 14:47 - 06012928 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
    2012-05-15 10:18 - 2010-07-31 14:47 - 02530624 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
    2012-05-15 10:18 - 2010-07-31 14:47 - 02445120 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
    2012-05-15 10:18 - 2010-07-31 14:47 - 02359808 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi.dll
    2012-05-15 10:18 - 2010-07-31 14:47 - 00065536 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
    2012-05-15 10:18 - 2005-08-16 10:35 - 14014656 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nv4_mini.sys
    2012-05-15 10:18 - 2005-08-16 10:35 - 14014656 ____A (NVIDIA Corporation) C:\Windows\System32\dllcache\nv4_mini.sys
    2012-05-15 10:18 - 2005-08-16 10:35 - 04373248 ____A (NVIDIA Corporation) C:\Windows\System32\nv4_disp.dll
    2012-05-15 09:40 - 2011-09-16 19:23 - 15504192 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
    2012-05-15 09:40 - 2011-09-16 19:23 - 00164160 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc32.exe
    2012-05-15 09:40 - 2011-09-16 19:23 - 00143680 ____A (NVIDIA Corporation) C:\Windows\System32\nvcolor.exe
    2012-05-15 09:40 - 2011-09-16 19:23 - 00108352 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
    2012-05-15 09:40 - 2011-09-16 19:23 - 00054272 ____A (NVIDIA Corporation) C:\Windows\System32\nvwddi.dll
    2012-05-14 19:33 - 2008-12-05 20:48 - 00000000 ____D C:\Program Files\Microsoft Silverlight
    2012-05-12 23:14 - 2012-05-12 23:14 - 00001366 ____A C:\Documents and Settings\All Users\Desktop\iTunes.lnk
    2012-05-12 23:13 - 2012-05-12 23:13 - 00000000 ____D C:\Program Files\iPod
    2012-05-12 23:13 - 2012-03-27 23:55 - 00000000 ____D C:\Program Files\Common Files\Apple
    2012-05-12 18:12 - 2012-04-09 15:16 - 00000000 ____D C:\Documents and Settings\GJNA&T\Application Data\Skype
    2012-05-12 00:12 - 2007-05-11 14:34 - 11111424 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\ieframe.dll
    2012-05-12 00:12 - 2006-11-08 02:03 - 11111424 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-05-11 14:42 - 2012-06-13 06:28 - 00521728 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\jsdbgui.dll
    2012-05-11 14:42 - 2010-06-10 02:22 - 00743424 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\iedvtool.dll
    2012-05-11 14:42 - 2009-07-05 05:00 - 00247808 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\ieproxy.dll
    2012-05-11 14:42 - 2009-07-05 05:00 - 00012800 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\xpshims.dll
    2012-05-11 14:42 - 2007-05-11 14:34 - 02000384 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\iertutil.dll
    2012-05-11 14:42 - 2007-05-11 14:34 - 00629760 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\msfeeds.dll
    2012-05-11 14:42 - 2007-05-11 14:34 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\msfeedsbs.dll
    2012-05-11 14:42 - 2006-11-08 02:03 - 00629760 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
    2012-05-11 14:42 - 2006-11-08 02:03 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
    2012-05-11 14:42 - 2006-11-07 08:27 - 00387584 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\iedkcs32.dll
    2012-05-11 14:42 - 2006-10-17 17:05 - 01469440 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\inetcpl.cpl
    2012-05-11 14:42 - 2006-10-17 17:05 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\licmgr10.dll
    2012-05-11 14:42 - 2006-10-17 17:04 - 00206848 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\occache.dll
    2012-05-11 14:42 - 2006-10-17 16:57 - 02000384 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-05-11 14:42 - 2006-05-19 15:06 - 06007808 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\mshtml.dll
    2012-05-11 14:42 - 2006-05-10 05:25 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\iepeers.dll
    2012-05-11 14:42 - 2006-05-10 05:25 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\mshtmled.dll
    2012-05-11 14:42 - 2005-08-16 10:18 - 06007808 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-05-11 14:42 - 2005-08-16 10:18 - 01469440 ____N (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-05-11 14:42 - 2005-08-16 10:18 - 01212416 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-05-11 14:42 - 2005-08-16 10:18 - 01212416 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\urlmon.dll
    2012-05-11 14:42 - 2005-08-16 10:18 - 00611840 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
    2012-05-11 14:42 - 2005-08-16 10:18 - 00611840 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\mstime.dll
    2012-05-11 14:42 - 2005-08-16 10:18 - 00387584 ____N (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
    2012-05-11 14:42 - 2005-08-16 10:18 - 00206848 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
    2012-05-11 14:42 - 2005-08-16 10:18 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
    2012-05-11 14:42 - 2005-08-16 10:18 - 00105984 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-05-11 14:42 - 2005-08-16 10:18 - 00105984 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\url.dll
    2012-05-11 14:42 - 2005-08-16 10:18 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-05-11 14:42 - 2005-08-16 10:18 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
    2012-05-11 14:42 - 2005-08-16 10:18 - 00025600 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-05-11 14:42 - 2005-08-16 10:18 - 00025600 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\jsproxy.dll
    2012-05-11 11:38 - 2006-11-07 08:26 - 00174080 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\ie4uinit.exe
    2012-05-11 11:38 - 2005-08-16 10:18 - 00385024 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
    2012-05-11 11:38 - 2005-08-16 10:18 - 00174080 ____N (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
    2012-05-10 18:50 - 2005-08-16 10:18 - 00000687 ____A C:\Windows\win.ini
    2012-05-04 20:40 - 2012-05-04 20:40 - 00000000 ____D C:\Documents and Settings\Admin1\My Documents\Almost Human
    2012-05-04 20:40 - 2005-08-16 10:40 - 00000000 ____D C:\Windows\System32\DirectX
    2012-05-04 13:16 - 2005-08-16 10:18 - 02148352 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
    2012-05-04 13:16 - 2005-08-16 10:18 - 02148352 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\ntkrnlmp.exe
    2012-05-04 13:12 - 2008-11-03 07:57 - 02192640 ____A (Microsoft Corporation) C:\Windows\System32\dllcache\ntoskrnl.exe
    2012-05-04 12:32 - 2008-11-03 07:57 - 02069120 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\ntkrnlpa.exe
    2012-05-04 12:32 - 2008-11-03 07:57 - 02026496 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\ntkrpamp.exe
    2012-05-04 12:32 - 2004-08-04 04:59 - 02026496 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe
    2012-05-02 13:46 - 2011-08-11 03:33 - 00139656 ____N (Microsoft Corporation) C:\Windows\System32\dllcache\rdpwd.sys
    2012-05-02 13:46 - 2005-08-16 10:37 - 00139656 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
    2012-04-23 18:08 - 2012-04-23 18:08 - 00020480 ____A C:\Documents and Settings\Admin1\My Documents\rpc5.xls
    2012-04-19 21:00 - 2012-04-12 21:12 - 00000000 ____D C:\Documents and Settings\Admin1\Local Settings\Application Data\TERA-Diagnostic
    2012-04-19 20:29 - 2005-08-16 10:38 - 00065536 ____A C:\Windows\System32\config\Media Ce.evt
    2012-04-19 19:59 - 2010-12-03 23:54 - 00000000 ____D C:\NVIDIA
    2012-04-18 17:08 - 2012-02-21 21:15 - 00876864 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdagenco3220103.dll
    2012-04-18 17:08 - 2011-09-16 19:11 - 00123840 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda32.sys
    2012-04-18 17:08 - 2011-09-16 19:11 - 00027968 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap32.dll
    2012-04-16 19:06 - 2012-04-16 19:06 - 00000000 ____D C:\Program Files\Common Files\Skype
    2012-04-12 21:31 - 2007-11-08 19:48 - 00000000 ____D C:\Program Files\DivX
    2012-04-12 21:19 - 2010-03-29 14:34 - 00000000 ____D C:\Documents and Settings\Admin1\Desktop\Unused Desktop Shortcuts
    2012-04-11 20:46 - 2012-04-11 20:46 - 00000000 ____D C:\Program Files\NCsoft
    2012-04-11 20:46 - 2012-04-11 20:46 - 00000000 ____D C:\Program Files\Common Files\Stardock
    2012-04-11 20:20 - 2011-11-17 03:14 - 00000000 ____D C:\Documents and Settings\Admin1\My Documents\My Games
    2012-04-11 04:47 - 2012-04-11 04:39 - 00000000 ____D C:\Documents and Settings\Admin1\Application Data\Stardock
    2012-04-11 04:39 - 2012-04-11 04:39 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Gibraltar
    2012-04-11 04:38 - 2012-04-11 04:38 - 00000588 ____A C:\Documents and Settings\All Users\Desktop\GameStop.lnk
    2012-04-11 04:38 - 2012-04-11 04:38 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Stardock
    2012-04-11 04:38 - 2012-04-11 04:37 - 00000000 __HDC C:\Documents and Settings\All Users\Application Data\{EB424B13-2E57-4A45-936F-A4DFB6DB1688}
    2012-04-11 04:35 - 2012-04-11 04:35 - 00000000 ____D C:\Documents and Settings\Admin1\Local Settings\Application Data\PackageAware
    2012-04-08 23:33 - 2012-04-08 23:33 - 00000000 ____D C:\Documents and Settings\Admin1\My Documents\Electronic Arts
    2012-04-07 00:28 - 2012-04-07 00:28 - 00000000 ____D C:\Documents and Settings\Admin1\Local Settings\Application Data\TERA
    2012-04-06 19:01 - 2010-07-25 08:32 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Electronic Arts
    2012-04-06 18:14 - 2012-04-06 18:14 - 00000794 ____A C:\Documents and Settings\All Users\Desktop\EA Download Manager.lnk
    2012-04-06 17:47 - 2012-04-06 17:47 - 00001723 ____A C:\Documents and Settings\All Users\Desktop\The Sims™ 3.lnk
    2012-04-06 17:30 - 2010-07-25 07:56 - 00000000 ____D C:\Program Files\Electronic Arts
    2012-04-06 17:30 - 2006-02-06 15:20 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
    2012-04-04 19:56 - 2012-06-25 20:16 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-04-03 17:59 - 2012-04-03 17:53 - 00000000 ____D C:\Documents and Settings\Admin1\My Documents\RCT3
    2012-04-03 17:57 - 2012-04-03 17:53 - 00043520 ____A C:\Windows\System32\CmdLineExt03.dll
    2012-04-03 17:53 - 2012-04-03 17:53 - 00000000 ____D C:\Documents and Settings\Admin1\Application Data\Atari
    2012-04-02 15:12 - 2012-04-01 15:17 - 00000000 ____D C:\Documents and Settings\GJNA&T\My Documents\RCT3
    2012-04-01 15:17 - 2012-04-01 15:17 - 00000000 ____D C:\Documents and Settings\GJNA&T\Application Data\Atari
    2012-03-30 18:47 - 2012-03-30 18:47 - 00000460 ____A C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
    2012-03-30 18:47 - 2012-03-30 18:46 - 00000000 ____D C:\VLC
     
  23. Syreynna

    Syreynna TS Rookie Topic Starter Posts: 74

    ========================= Known DLLs (Whitelisted) ============

    ========================= Bamital & volsnap Check ============
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
    ==================== EXE ASSOCIATION =====================
    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK
    ==================== Restore Points (XP) =====================
    RP: -> 2012-06-25 02:08 - 028672 _restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP2786
    RP: -> 2012-06-24 06:08 - 028672 _restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP2785
    RP: -> 2012-06-23 20:15 - 028672 _restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP2784

    ========================= Memory info ======================
    Percentage of memory in use: 24%
    Total physical RAM: 3070.09 MB
    Available physical RAM: 2311.74 MB
    Total Pagefile: 2894.75 MB
    Available Pagefile: 2361.9 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 2001.55 MB
    ======================= Partitions =========================
    1 Drive b: (RAMDisk) (Fixed) (Total:0.5 GB) (Free:0.5 GB) FAT
    2 Drive c: (Local Disk) (Fixed) (Total:69.79 GB) (Free:29.03 GB) NTFS ==>[Drive with boot components (Windows XP)]
    3 Drive d: () (Removable) (Total:3.8 GB) (Free:3.79 GB) FAT32
    5 Drive f: (New Volume) (Fixed) (Total:465.76 GB) (Free:341.46 GB) NTFS
    6 Drive x: (UBCD4Windows) (CDROM) (Total:0.63 GB) (Free:0 GB) CDFS
    Disk ### Status Size Free Dyn Gpt
    -------- ---------- ------- ------- --- ---
    Disk 0 Online 74 GB 0 B
    Disk 1 Online 466 GB 0 B *
    Partitions of Disk 0:
    ===============
    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 OEM 55 MB 32 KB
    Partition 2 Primary 70 GB 55 MB
    Partition 3 Unknown 4754 MB 70 GB
    ======================================================================================================
    Disk: 0
    Partition 1
    Type : DE
    Hidden: Yes
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 FAT Partition 55 MB Healthy
    ======================================================================================================
    Disk: 0
    Partition 2
    Type : 07
    Hidden: No
    Active: Yes
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 4 C Local Disk NTFS Partition 70 GB Healthy
    ======================================================================================================
    Disk: 0
    Partition 3
    Type : DB
    Hidden: Yes
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 5 FAT32 Partition 4754 MB Healthy
    ======================================================================================================
    Partitions of Disk 1:
    ===============
    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Dynamic Data 466 GB 32 KB
    ======================================================================================================
    Disk: 1
    Partition 1
    Type : 42
    Hidden: Yes
    Active: No
    There is no volume associated with this partition.
    ======================================================================================================
    ======================= End Of Log ==========================
     
  24. Broni

    Broni Malware Annihilator Posts: 46,865   +254

    The rootkit is still there.

    Delete existing "fixlist.txt" from your flash drive.

    Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    On Vista or Windows 7: Now please enter System Recovery Options.
    On Windows XP: Now please boot into the UBCD.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

    See if you can boot normally.
     

    Attached Files:

  25. Syreynna

    Syreynna TS Rookie Topic Starter Posts: 74

    Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 20-06-2012 01
    Ran by SYSTEM at 2012-06-27 13:32:04 Run:3
    Running from D:\
    ==============================================
    HKEY_LOCAL_MACHINE\System\ControlSet002\Control\Session Manager\SubSystems\\Windows Value was restored successfully .
    C:\Windows\System32\consrv.dll not found.
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32\\Default value was restored successfully .
    MpKsl1cb3245a service deleted successfully.
    ==== End of Fixlog ====

    restarting to see if it runs normal now.
     


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.