Hello there,
Some 6 days ago, I found that the windows media player was not starting at all.Tried to start it in every way, but failed...then googled about the problem and found Microsoft Fixit for WMP and it stated that the registry entry was corrupted and fixed all the problems. After that,while I was checking my computer, I saw that the firewall was turned off,defender is also turned off, updates not starting and action center not working at all with the security center turned off.I tried to start all the functions and encountered the above mentioned error code.I had the Avira free antivirus installed then,but it did not found any infections.....so uninstalled it and installed AVG antivirus and MBAM.
After updating and running both, I found my pc is infected with the above mentioned virus. Followed all the instructions and deleted the infected files and did some googling again to remove the virus from my pc.Came through a lot of topics with various methods, but didn't apply anything.But I did make one mistake....I did read in another forum about combofix and did end up running the tool in my PC.Didn't realise it was wrong to do without supervision !!!
Combofix ran well and generated a message about C:\windows\system32\services.exe being corrupted and attempting to patch it and then created a log about the files being patched and new files created...but at that time there was a freak powercut in my area and the log file was erased. So, I did run combofix one more time and the log file is pasted here......
After running combofix, my machine was working great...all services were back to normal,but,today morning again found the rootkit virus message popping up from MBAM and all the services have stopped again. After lot of search found your forum.....was really amazed to see how you people volunteered to help others.Did the 5 steps mentioned...and is pasting all the logs below one after other.......
Thanks in advance for your help...
---------------------------------------------------------------------------------------------------------------------------
ComboFix 12-08-13.01 - Desktop 14-Aug-12 17:44:03.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3893.2773 [GMT 5.5:30]
Running from: c:\users\Desktop\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Desktop\AppData\Local\TempDIR
c:\users\Desktop\AppData\Roaming\110ab52f
c:\users\Desktop\AppData\Roaming\118494bb
c:\users\Desktop\AppData\Roaming\1247491f
c:\users\Desktop\AppData\Roaming\145bcc7
c:\users\Desktop\AppData\Roaming\14b1c720
c:\users\Desktop\AppData\Roaming\14d8b220
c:\users\Desktop\AppData\Roaming\1506a031
c:\users\Desktop\AppData\Roaming\15be8edf
c:\users\Desktop\AppData\Roaming\15ecacfa
c:\users\Desktop\AppData\Roaming\15efa89e
c:\users\Desktop\AppData\Roaming\161af501
c:\users\Desktop\AppData\Roaming\16c656f7
c:\users\Desktop\AppData\Roaming\18057ff9
c:\users\Desktop\AppData\Roaming\1816b214
c:\users\Desktop\AppData\Roaming\1856daa
c:\users\Desktop\AppData\Roaming\1896ebc8
c:\users\Desktop\AppData\Roaming\191b9c54
c:\users\Desktop\AppData\Roaming\1965f68
c:\users\Desktop\AppData\Roaming\19ea700b
c:\users\Desktop\AppData\Roaming\1afb2a27
c:\users\Desktop\AppData\Roaming\1b158729
c:\users\Desktop\AppData\Roaming\1bf5152a
c:\users\Desktop\AppData\Roaming\1c3a3b2d
c:\users\Desktop\AppData\Roaming\1cbbd0ee
c:\users\Desktop\AppData\Roaming\1d6cde3e
c:\users\Desktop\AppData\Roaming\1eae1606
c:\users\Desktop\AppData\Roaming\1f5927d5
c:\users\Desktop\AppData\Roaming\2478fd99
c:\users\Desktop\AppData\Roaming\253b74
c:\users\Desktop\AppData\Roaming\260c4d9e
c:\users\Desktop\AppData\Roaming\270f0f9e
c:\users\Desktop\AppData\Roaming\27f355c4
c:\users\Desktop\AppData\Roaming\284d4587
c:\users\Desktop\AppData\Roaming\28f69cec
c:\users\Desktop\AppData\Roaming\298c3c6c
c:\users\Desktop\AppData\Roaming\29a72cc8
c:\users\Desktop\AppData\Roaming\2a6063cf
c:\users\Desktop\AppData\Roaming\2a655a8
c:\users\Desktop\AppData\Roaming\2a92b305
c:\users\Desktop\AppData\Roaming\2b13b33
c:\users\Desktop\AppData\Roaming\2c2233
c:\users\Desktop\AppData\Roaming\2f96b0ae
c:\users\Desktop\AppData\Roaming\2faa25c
c:\users\Desktop\AppData\Roaming\30a36d49
c:\users\Desktop\AppData\Roaming\325ea1bd
c:\users\Desktop\AppData\Roaming\335d658
c:\users\Desktop\AppData\Roaming\3458b729
c:\users\Desktop\AppData\Roaming\3560bc01
c:\users\Desktop\AppData\Roaming\3650d68d
c:\users\Desktop\AppData\Roaming\37691bc9
c:\users\Desktop\AppData\Roaming\386bbb3d
c:\users\Desktop\AppData\Roaming\39cde08
c:\users\Desktop\AppData\Roaming\3a597b3
c:\users\Desktop\AppData\Roaming\3d4eee1c
c:\users\Desktop\AppData\Roaming\3e2072a1
c:\users\Desktop\AppData\Roaming\3eea7afb
c:\users\Desktop\AppData\Roaming\3f37fdb1
c:\users\Desktop\AppData\Roaming\3f3b128
c:\users\Desktop\AppData\Roaming\411a0827
c:\users\Desktop\AppData\Roaming\41c1789f
c:\users\Desktop\AppData\Roaming\4232ea67
c:\users\Desktop\AppData\Roaming\440e8180
c:\users\Desktop\AppData\Roaming\47128dc6
c:\users\Desktop\AppData\Roaming\471a2a79
c:\users\Desktop\AppData\Roaming\48a4eed2
c:\users\Desktop\AppData\Roaming\49c02ee3
c:\users\Desktop\AppData\Roaming\4a0b6b7
c:\users\Desktop\AppData\Roaming\4b380798
c:\users\Desktop\AppData\Roaming\4b53d497
c:\users\Desktop\AppData\Roaming\4b61b6d9
c:\users\Desktop\AppData\Roaming\4b64601
c:\users\Desktop\AppData\Roaming\4c7ab50b
c:\users\Desktop\AppData\Roaming\4cfc1060
c:\users\Desktop\AppData\Roaming\4e6ce37
c:\users\Desktop\AppData\Roaming\596a25b
c:\users\Desktop\AppData\Roaming\5e08a60
c:\users\Desktop\AppData\Roaming\5e310e45
c:\users\Desktop\AppData\Roaming\5f697a27
c:\users\Desktop\AppData\Roaming\607286e0
c:\users\Desktop\AppData\Roaming\620ef67d
c:\users\Desktop\AppData\Roaming\62c5bb1d
c:\users\Desktop\AppData\Roaming\6332c5b9
c:\users\Desktop\AppData\Roaming\6c4f6882
c:\users\Desktop\AppData\Roaming\6df71825
c:\users\Desktop\AppData\Roaming\6e3ba91
c:\users\Desktop\AppData\Roaming\75669402
c:\users\Desktop\AppData\Roaming\7dec157
c:\users\Desktop\AppData\Roaming\85e36a01
c:\users\Desktop\AppData\Roaming\867f4207
c:\users\Desktop\AppData\Roaming\880d790d
c:\users\Desktop\AppData\Roaming\884bb93b
c:\users\Desktop\AppData\Roaming\9564557d
c:\users\Desktop\AppData\Roaming\97ce75d8
c:\users\Desktop\AppData\Roaming\97d4f8a3
c:\users\Desktop\AppData\Roaming\990e24e1
c:\users\Desktop\AppData\Roaming\995ab09b
c:\users\Desktop\AppData\Roaming\9bc577df
c:\users\Desktop\AppData\Roaming\9e2d83e8
c:\users\Desktop\AppData\Roaming\a12d5826
c:\users\Desktop\AppData\Roaming\a25cdf5f
c:\users\Desktop\AppData\Roaming\a3e19362
c:\users\Desktop\AppData\Roaming\a5677138
c:\users\Desktop\AppData\Roaming\af1c832
c:\users\Desktop\AppData\Roaming\b254f00e
c:\users\Desktop\AppData\Roaming\b2f81783
c:\users\Desktop\AppData\Roaming\b4e61bea
c:\users\Desktop\AppData\Roaming\b592600b
c:\users\Desktop\AppData\Roaming\b7e81e7
c:\users\Desktop\AppData\Roaming\b848f6d8
c:\users\Desktop\AppData\Roaming\b8530f2d
c:\users\Desktop\AppData\Roaming\b9b5fd42
c:\users\Desktop\AppData\Roaming\bbddf538
c:\users\Desktop\AppData\Roaming\bbf4c325
c:\users\Desktop\AppData\Roaming\bd647d71
c:\users\Desktop\AppData\Roaming\bf3c1566
c:\users\Desktop\AppData\Roaming\c0541eb6
c:\users\Desktop\AppData\Roaming\c24630e0
c:\users\Desktop\AppData\Roaming\c35a034c
c:\users\Desktop\AppData\Roaming\c46d6b13
c:\users\Desktop\AppData\Roaming\c5640c5c
c:\users\Desktop\AppData\Roaming\c8feae72
c:\users\Desktop\AppData\Roaming\c92752a
c:\users\Desktop\AppData\Roaming\c958a10
c:\users\Desktop\AppData\Roaming\ca2d1445
c:\users\Desktop\AppData\Roaming\ca625864
c:\users\Desktop\AppData\Roaming\cb24aa75
c:\users\Desktop\AppData\Roaming\cb6d7bee
c:\users\Desktop\AppData\Roaming\cd09cb25
c:\users\Desktop\AppData\Roaming\cd8000d0
c:\users\Desktop\AppData\Roaming\cde151b9
c:\users\Desktop\AppData\Roaming\ce33e2c1
c:\users\Desktop\AppData\Roaming\cf2c3336
c:\users\Desktop\AppData\Roaming\cf72c69c
c:\users\Desktop\AppData\Roaming\cf7d6a37
c:\users\Desktop\AppData\Roaming\chrtmp
c:\users\Desktop\AppData\Roaming\d0969c44
c:\users\Desktop\AppData\Roaming\d09f4e7f
c:\users\Desktop\AppData\Roaming\d19030c3
c:\users\Desktop\AppData\Roaming\d28a6067
c:\users\Desktop\AppData\Roaming\d2c6d69a
c:\users\Desktop\AppData\Roaming\d2eb6fb4
c:\users\Desktop\AppData\Roaming\d3a4b93a
c:\users\Desktop\AppData\Roaming\d4493a08
c:\users\Desktop\AppData\Roaming\d5c47c93
c:\users\Desktop\AppData\Roaming\d635c736
c:\users\Desktop\AppData\Roaming\d6f27a63
c:\users\Desktop\AppData\Roaming\d8cae6ad
c:\users\Desktop\AppData\Roaming\daee34a7
c:\users\Desktop\AppData\Roaming\dc359bdf
c:\users\Desktop\AppData\Roaming\dce30b55
c:\users\Desktop\AppData\Roaming\dd54e89b
c:\users\Desktop\AppData\Roaming\de0b0e37
c:\users\Desktop\AppData\Roaming\df13d14f
c:\users\Desktop\AppData\Roaming\dfa321f7
c:\users\Desktop\AppData\Roaming\e092892b
c:\users\Desktop\AppData\Roaming\e0b963b3
c:\users\Desktop\AppData\Roaming\e196ec7
c:\users\Desktop\AppData\Roaming\e1dae2f7
c:\users\Desktop\AppData\Roaming\e2dec85f
c:\users\Desktop\AppData\Roaming\e66269f
c:\users\Desktop\AppData\Roaming\e780c75a
c:\users\Desktop\AppData\Roaming\e7d8073b
c:\users\Desktop\AppData\Roaming\e8915c65
c:\users\Desktop\AppData\Roaming\e8adb1c4
c:\users\Desktop\AppData\Roaming\e8fc5c12
c:\users\Desktop\AppData\Roaming\e928d42e
c:\users\Desktop\AppData\Roaming\e9c6b7fc
c:\users\Desktop\AppData\Roaming\ea3cb8a2
c:\users\Desktop\AppData\Roaming\eab870dc
c:\users\Desktop\AppData\Roaming\eadb7c2f
c:\users\Desktop\AppData\Roaming\eb3d40ee
c:\users\Desktop\AppData\Roaming\ec44c5ca
c:\users\Desktop\AppData\Roaming\ed02fb4b
c:\users\Desktop\AppData\Roaming\ed43c43a
c:\users\Desktop\AppData\Roaming\ee2000cb
c:\users\Desktop\AppData\Roaming\ee9ffdce
c:\users\Desktop\AppData\Roaming\ef316c03
c:\users\Desktop\AppData\Roaming\efbdf0a5
c:\users\Desktop\AppData\Roaming\f04e30cb
c:\users\Desktop\AppData\Roaming\f15ff377
c:\users\Desktop\AppData\Roaming\f1adf267
c:\users\Desktop\AppData\Roaming\f25929ab
c:\users\Desktop\AppData\Roaming\f2d34aad
c:\users\Desktop\AppData\Roaming\f2e2a803
c:\users\Desktop\AppData\Roaming\f40d9b1f
c:\users\Desktop\AppData\Roaming\f439e845
c:\users\Desktop\AppData\Roaming\f44d901b
c:\users\Desktop\AppData\Roaming\f568b92c
c:\users\Desktop\AppData\Roaming\f62a3dd9
c:\users\Desktop\AppData\Roaming\f70b7ca4
c:\users\Desktop\AppData\Roaming\f809a603
c:\users\Desktop\AppData\Roaming\f819a2b9
c:\users\Desktop\AppData\Roaming\f84a50a
c:\users\Desktop\AppData\Roaming\f921bfb0
c:\users\Desktop\AppData\Roaming\f9632998
c:\users\Desktop\AppData\Roaming\fa142e2f
c:\users\Desktop\AppData\Roaming\fbb65c86
c:\users\Desktop\AppData\Roaming\fd30b46e
c:\users\Desktop\AppData\Roaming\fd66a206
c:\users\Desktop\AppData\Roaming\feb5582e
c:\users\Desktop\AppData\Roaming\fecb4a58
c:\users\Desktop\AppData\Roaming\msthnv.dll
c:\users\Desktop\AppData\Roaming\nhcaps.dll
c:\users\Desktop\AppData\Roaming\qmcts.dll
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\@
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\L\00000004.@
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\U\00000004.@
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\U\00000008.@
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\U\000000cb.@
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\U\80000000.@
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\U\80000032.@
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\U\80000064.@
c:\windows\SysWow64\1065\inf1065.dat
c:\windows\SysWow64\1077
c:\windows\SysWow64\1077\inf1077.dat
c:\windows\SysWow64\1079\inf1079.dat
.
----- File Replicators -----
.
c:\windows\System32\usser.exe
c:\windows\System32\ussser.exe
c:\windows\System32\usssser.exe
c:\windows\System32\ussssser.exe
c:\windows\System32\usssssser.exe
c:\windows\System32\ussssssser.exe
c:\windows\System32\usssssssser.exe
c:\windows\System32\ussssssssser.exe
c:\windows\System32\usssssssssser.exe
c:\windows\System32\ussssssssssser.exe
c:\windows\System32\usssssssssssser.exe
c:\windows\System32\ussssssssssssser.exe
c:\windows\System32\usssssssssssssser.exe
c:\windows\System32\ussssssssssssssser.exe
c:\windows\System32\usssssssssssssssser.exe
c:\windows\System32\ussssssssssssssssser.exe
c:\windows\System32\usssssssssssssssssser.exe
c:\windows\System32\ussssssssssssssssssser.exe
c:\windows\System32\usssssssssssssssssssser.exe
c:\windows\System32\ussssssssssssssssssssser.exe
c:\windows\System32\usssssssssssssssssssssser.exe
c:\windows\System32\ussssssssssssssssssssssser.exe
c:\windows\System32\usssssssssssssssssssssssser.exe
c:\windows\System32\ussssssssssssssssssssssssser.exe
c:\windows\System32\usssssssssssssssssssssssssser.exe
c:\windows\System32\ussssssssssssssssssssssssssser.exe
c:\windows\SysWOW64\usser.exe
c:\windows\SysWOW64\ussser.exe
c:\windows\SysWOW64\usssser.exe
c:\windows\SysWOW64\ussssser.exe
c:\windows\SysWOW64\usssssser.exe
c:\windows\SysWOW64\ussssssser.exe
c:\windows\SysWOW64\usssssssser.exe
c:\windows\SysWOW64\ussssssssser.exe
c:\windows\SysWOW64\usssssssssser.exe
c:\windows\SysWOW64\ussssssssssser.exe
c:\windows\SysWOW64\usssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssser.exe
c:\windows\SysWOW64\usssssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssssser.exe
c:\windows\SysWOW64\usssssssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssssssser.exe
c:\windows\SysWOW64\usssssssssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssssssssser.exe
c:\windows\SysWOW64\usssssssssssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssssssssssser.exe
c:\windows\SysWOW64\usssssssssssssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssssssssssssser.exe
c:\windows\SysWOW64\usssssssssssssssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssssssssssssssser.exe
c:\windows\SysWOW64\usssssssssssssssssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssssssssssssssssser.exe
.
Infected copy of c:\windows\system32\services.exe was found and disinfected
Restored copy from - c:\32788r22fwjfw\HarddiskVolumeShadowCopy2_!Windows!System32!services.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-07-14 to 2012-08-14 )))))))))))))))))))))))))))))))
.
.
2012-08-14 12:18 . 2012-08-14 12:18--------d-----w-c:\users\Default\AppData\Local\temp
2012-08-14 10:11 . 2012-08-14 10:20--------d-----w-c:\users\Desktop\AppData\Roaming\Wise Registry Cleaner
2012-08-11 13:29 . 2012-08-11 13:29--------d-----w-c:\users\Desktop\AppData\Local\SymbolSourceSymbols
2012-08-11 13:29 . 2012-08-11 13:29--------d-----w-c:\users\Desktop\AppData\Local\RefSrcSymbols
2012-08-11 13:29 . 2012-08-11 13:29--------d-----w-c:\users\Desktop\AppData\Local\JetBrains
2012-08-11 13:29 . 2012-08-11 13:29--------d-----w-c:\users\Desktop\AppData\Roaming\JetBrains
2012-08-11 13:00 . 2012-08-11 13:00--------d-----w-c:\windows\SysWow64\1082
2012-08-11 13:00 . 2012-08-11 13:00679936----a-w-c:\windows\system32\Rede1389.scr
2012-08-11 13:00 . 2012-08-11 13:00679936------w-c:\windows\SysWow64\Rede1389.scr
2012-08-11 13:00 . 2012-08-11 13:00--------d-----w-c:\programdata\Screentime
2012-08-11 13:00 . 2012-08-11 13:00--------d-----w-c:\users\Desktop\AppData\Local\Screentime
2012-08-11 12:57 . 2012-08-11 12:57--------d-----w-c:\windows\SysWow64\1081
2012-08-11 12:41 . 2012-08-11 12:47--------d-----w-c:\program files (x86)\Free Registry Cleaner For Seven
2012-08-11 09:39 . 2012-08-11 09:39--------d-----w-c:\windows\SysWow64\1080
2012-08-11 08:46 . 2012-08-14 12:17--------d-----w-c:\windows\SysWow64\1079
2012-08-11 08:33 . 2012-08-11 08:41--------d-----w-c:\users\Desktop\AppData\Roaming\Error Fix
2012-08-11 08:10 . 2012-08-11 08:10--------d-----w-c:\windows\ehome
2012-08-11 08:10 . 2012-08-11 08:10--------d-----w-c:\users\Default\AppData\Roaming\Media Center Programs
2012-08-11 08:01 . 2012-08-11 08:01--------d-----w-c:\windows\SysWow64\1078
2012-08-11 07:52 . 2012-08-11 07:52--------d-----w-c:\windows\SysWow64\1076
2012-08-10 09:47 . 2012-08-10 09:47--------d-----w-c:\windows\SysWow64\1075
2012-08-10 09:33 . 2012-08-10 09:33--------d-----w-c:\windows\SysWow64\1074
2012-08-10 09:08 . 2012-08-10 09:08--------d-----w-c:\windows\SysWow64\1073
2012-08-10 09:05 . 2012-08-10 09:05--------d-----w-c:\windows\SysWow64\1072
2012-08-10 08:53 . 2012-08-10 08:53--------d-----w-c:\windows\SysWow64\1071
2012-08-10 08:34 . 2012-08-10 08:34--------d-----w-c:\windows\SysWow64\1070
2012-08-10 08:32 . 2012-08-10 08:32--------d-----w-c:\users\Desktop\AppData\Roaming\flashInstall
2012-08-10 07:08 . 2012-08-10 07:09--------d-----w-c:\users\Desktop\AppData\Roaming\PE Explorer
2012-08-10 06:38 . 2012-08-10 06:38--------d-----w-c:\windows\SysWow64\1069
2012-08-10 06:30 . 2012-08-10 06:30--------d-----w-c:\windows\SysWow64\1068
2012-08-10 06:19 . 2012-08-10 06:19--------d-----w-c:\windows\SysWow64\1067
2012-08-10 06:18 . 2012-08-10 06:18--------d-----w-c:\windows\SysWow64\1066
2012-08-10 06:15 . 2012-08-14 12:17--------d-----w-c:\windows\SysWow64\1065
2012-08-09 11:26 . 2012-08-09 11:26--------d-----w-c:\windows\SysWow64\1064
2012-08-09 10:24 . 2012-08-09 10:24--------d-----w-c:\windows\SysWow64\1063
2012-08-09 10:24 . 2012-08-09 10:24--------d-----w-c:\windows\SysWow64\1062
2012-08-09 10:10 . 2012-08-09 10:10--------d-----w-c:\windows\SysWow64\1061
2012-08-09 10:09 . 2012-08-09 10:09--------d-----w-c:\windows\SysWow64\1060
2012-08-09 10:01 . 2012-08-09 10:01--------d-----w-c:\windows\SysWow64\1059
2012-08-09 10:00 . 2012-08-09 10:00--------d-----w-c:\windows\SysWow64\1058
2012-08-09 09:59 . 2012-08-09 09:59--------d-----w-c:\windows\SysWow64\1057
2012-08-06 10:56 . 2011-11-09 12:08189608----a-w-c:\windows\system32\IPROSetMonitor.exe
2012-08-06 10:56 . 2012-08-06 10:56--------d-----w-c:\program files\Intel
2012-08-06 10:54 . 2012-02-01 21:13509104----a-w-c:\windows\system32\drivers\e1k62x64.sys
2012-08-06 10:54 . 2012-01-19 21:1199520----a-w-c:\windows\system32\NicInstK.dll
2012-08-06 10:54 . 2012-01-18 21:0768264----a-w-c:\windows\system32\e1kmsg.dll
2012-08-02 14:33 . 2012-06-18 08:0419032------w-c:\windows\system32\pwdrvio.sys
2012-08-02 14:33 . 2012-06-18 08:042966720----a-w-c:\windows\system32\pwNative.exe
2012-08-02 14:33 . 2012-06-18 08:0412384------w-c:\windows\system32\pwdspio.sys
2012-08-01 13:20 . 2012-08-03 02:56--------d-----w-c:\users\Desktop\.android
2012-08-01 13:12 . 2012-08-01 13:12--------d-----w-c:\program files\Oracle
2012-08-01 13:12 . 2012-08-01 13:11268784----a-w-c:\windows\system32\javaws.exe
2012-08-01 13:12 . 2012-08-01 13:11189424----a-w-c:\windows\system32\javaw.exe
2012-08-01 13:12 . 2012-08-01 13:11188912----a-w-c:\windows\system32\java.exe
2012-08-01 13:10 . 2012-08-01 13:11--------d-----w-c:\program files\Java
2012-08-01 13:10 . 2012-08-02 14:04--------d-----w-c:\users\Desktop\jdk1.7.0_05_combo
2012-07-27 13:39 . 2012-08-02 18:03--------d-----w-c:\programdata\LGMOBILEAX
2012-07-26 11:49 . 2012-07-26 11:55--------d-----w-c:\program files (x86)\YourFileDownloader
2012-07-26 11:49 . 2012-07-26 11:49--------d-----w-c:\users\Desktop\AppData\Roaming\YourFileDownloader
2012-07-26 11:21 . 2012-07-26 11:21--------d-----w-c:\program files (x86)\uTorrent
2012-07-25 15:15 . 2012-07-25 15:15--------d-----w-c:\program files (x86)\LG Electronics
2012-07-25 14:31 . 2012-08-02 18:33--------d-----w-c:\users\Desktop\AppData\Roaming\LG Electronics
2012-07-25 14:30 . 2012-07-25 14:30--------d-----w-c:\users\Desktop\AppData\Local\LG Electronics
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-13 10:36 . 2012-04-04 06:17426184----a-w-c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-13 10:36 . 2011-06-02 02:3970344----a-w-c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-09 06:36 . 2009-07-13 23:19328704----a-w-c:\windows\system32\services.exe
2012-07-03 08:16 . 2011-06-14 07:2924904----a-w-c:\windows\system32\drivers\mbam.sys
2012-06-06 04:06 . 2012-06-06 04:062174976----a-w-c:\program files (x86)\Common Files\atimpenc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0BC6E3FA-78EF-4886-842C-5A1258C4455A}"= "mscoree.dll" [2010-11-05 297808]
.
[HKEY_CLASSES_ROOT\clsid\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
[HKEY_CLASSES_ROOT\agihelper.AGUtils]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
2010-11-05 01:58297808----a-w-c:\windows\System32\mscoree.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"Smart File Advisor"="c:\program files (x86)\Smart File Advisor\sfa.exe" [2011-04-04 280824]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatchTray13.exe" [2010-07-16 307184]
"CPMonitor"="c:\program files (x86)\Roxio 2011\5.0\CPMonitor.exe" [2010-07-13 84464]
"Desktop Disc Tool"="c:\program files (x86)\Roxio 2011\Roxio Burn\RoxioBurnLauncher.exe" [2010-06-30 477680]
"Malwarebytes' Anti-Malware"="d:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\users\Desktop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files (x86)\Webshots\3.1.5.7619\Launcher.exe [2011-9-12 157088]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 MBAMService;MBAMService;d:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatch13.exe [2010-07-16 354288]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-12-09 2320920]
R3 andnetadb;ADB Interface DriverNet;c:\windows\system32\Drivers\lgandnetadb.sys [2012-03-06 31744]
R3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\DRIVERS\lgandnetdiag64.sys [2012-03-06 29184]
R3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\DRIVERS\lgandnetmodem64.sys [2012-03-06 36352]
R3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter;c:\windows\system32\DRIVERS\lgandnetndis64.sys [2012-03-06 93184]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-08 129976]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2012-06-18 19032]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2012-06-18 12384]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
R3 RoxMediaDB13;RoxMediaDB13;c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxMediaDB13.exe [2010-07-16 1099248]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc; [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 tsusbhub;tsusbhub; [x]
R3 VGPU;VGPU; [x]
R3 vpcuxd;USB Virtualization Stub Service;c:\windows\system32\DRIVERS\vpcuxd.sys [2010-11-20 16384]
R3 vvftav303;vvftav303;c:\windows\system32\drivers\vvftav303.sys [2007-03-18 301824]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-12-05 1255736]
R3 ZSMC0303;INTEX Game Camera;c:\windows\system32\Drivers\usbVM303.sys [2007-03-25 1494656]
R4 Ireniceaesse;Ireniceaesse; [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-18 55856]
S0 Sahdad64;HDD Filter Driver;c:\windows\System32\Drivers\Sahdad64.sys [2009-06-01 27120]
S0 Saibad64;Volume Filter Driver;c:\windows\System32\Drivers\Saibad64.sys [2009-06-01 19952]
S1 SaibVdAd64;Virtual Disk Driver;c:\windows\system32\Drivers\SaibVdAd64.sys [2009-06-01 27632]
S2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [2009-06-02 457200]
S2 AGCoreService;AG Core Services;c:\program files (x86)\AGI\core\4.2.0.10754\AGCoreService.exe [2010-06-29 20480]
S2 BOT4Service;BOT4Service;c:\program files (x86)\Roxio\BackOnTrack\App\BService.exe [2010-07-13 32240]
S2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe [2011-11-09 189608]
S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys [2012-02-01 509104]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-02-03 271872]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-30 c:\windows\Tasks\SidebarExecute.job
- c:\program files\Windows Sidebar\sidebar.exe [2011-04-09 13:25]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 162328]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 417304]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-07-07 12558440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.co.in/
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{C3D5A4FB-98D0-46EC-8865-32390EE39FB8}: NameServer = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\users\Desktop\AppData\Roaming\Mozilla\Firefox\Profiles\zpqxsszw.default\
FF - prefs.js: browser.startup.homepage - www.google.co.in
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-whtpd - (no file)
Wow6432Node-HKCU-Run-nhcaps - (no file)
Wow6432Node-HKCU-Run-qmcts - (no file)
Wow6432Node-HKCU-Run-msthnv - (no file)
Wow6432Node-HKCU-Run-wladmg - (no file)
WebBrowser-{7B13EC3E-999A-4B70-B9CB-2617B8323822} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-msthnv - (no file)
HKLM-Run-wladmg - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_268_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_268_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\software\Network Associates]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Completion time: 2012-08-14 17:52:30 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-14 12:22
.
Pre-Run: 64,696,188,928 bytes free
Post-Run: 64,522,870,784 bytes free
.
- - End Of File - - DBDDD338056EA51EA6BCCAF12E7952E9
Some 6 days ago, I found that the windows media player was not starting at all.Tried to start it in every way, but failed...then googled about the problem and found Microsoft Fixit for WMP and it stated that the registry entry was corrupted and fixed all the problems. After that,while I was checking my computer, I saw that the firewall was turned off,defender is also turned off, updates not starting and action center not working at all with the security center turned off.I tried to start all the functions and encountered the above mentioned error code.I had the Avira free antivirus installed then,but it did not found any infections.....so uninstalled it and installed AVG antivirus and MBAM.
After updating and running both, I found my pc is infected with the above mentioned virus. Followed all the instructions and deleted the infected files and did some googling again to remove the virus from my pc.Came through a lot of topics with various methods, but didn't apply anything.But I did make one mistake....I did read in another forum about combofix and did end up running the tool in my PC.Didn't realise it was wrong to do without supervision !!!
Combofix ran well and generated a message about C:\windows\system32\services.exe being corrupted and attempting to patch it and then created a log about the files being patched and new files created...but at that time there was a freak powercut in my area and the log file was erased. So, I did run combofix one more time and the log file is pasted here......
After running combofix, my machine was working great...all services were back to normal,but,today morning again found the rootkit virus message popping up from MBAM and all the services have stopped again. After lot of search found your forum.....was really amazed to see how you people volunteered to help others.Did the 5 steps mentioned...and is pasting all the logs below one after other.......
Thanks in advance for your help...
---------------------------------------------------------------------------------------------------------------------------
ComboFix 12-08-13.01 - Desktop 14-Aug-12 17:44:03.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3893.2773 [GMT 5.5:30]
Running from: c:\users\Desktop\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Desktop\AppData\Local\TempDIR
c:\users\Desktop\AppData\Roaming\110ab52f
c:\users\Desktop\AppData\Roaming\118494bb
c:\users\Desktop\AppData\Roaming\1247491f
c:\users\Desktop\AppData\Roaming\145bcc7
c:\users\Desktop\AppData\Roaming\14b1c720
c:\users\Desktop\AppData\Roaming\14d8b220
c:\users\Desktop\AppData\Roaming\1506a031
c:\users\Desktop\AppData\Roaming\15be8edf
c:\users\Desktop\AppData\Roaming\15ecacfa
c:\users\Desktop\AppData\Roaming\15efa89e
c:\users\Desktop\AppData\Roaming\161af501
c:\users\Desktop\AppData\Roaming\16c656f7
c:\users\Desktop\AppData\Roaming\18057ff9
c:\users\Desktop\AppData\Roaming\1816b214
c:\users\Desktop\AppData\Roaming\1856daa
c:\users\Desktop\AppData\Roaming\1896ebc8
c:\users\Desktop\AppData\Roaming\191b9c54
c:\users\Desktop\AppData\Roaming\1965f68
c:\users\Desktop\AppData\Roaming\19ea700b
c:\users\Desktop\AppData\Roaming\1afb2a27
c:\users\Desktop\AppData\Roaming\1b158729
c:\users\Desktop\AppData\Roaming\1bf5152a
c:\users\Desktop\AppData\Roaming\1c3a3b2d
c:\users\Desktop\AppData\Roaming\1cbbd0ee
c:\users\Desktop\AppData\Roaming\1d6cde3e
c:\users\Desktop\AppData\Roaming\1eae1606
c:\users\Desktop\AppData\Roaming\1f5927d5
c:\users\Desktop\AppData\Roaming\2478fd99
c:\users\Desktop\AppData\Roaming\253b74
c:\users\Desktop\AppData\Roaming\260c4d9e
c:\users\Desktop\AppData\Roaming\270f0f9e
c:\users\Desktop\AppData\Roaming\27f355c4
c:\users\Desktop\AppData\Roaming\284d4587
c:\users\Desktop\AppData\Roaming\28f69cec
c:\users\Desktop\AppData\Roaming\298c3c6c
c:\users\Desktop\AppData\Roaming\29a72cc8
c:\users\Desktop\AppData\Roaming\2a6063cf
c:\users\Desktop\AppData\Roaming\2a655a8
c:\users\Desktop\AppData\Roaming\2a92b305
c:\users\Desktop\AppData\Roaming\2b13b33
c:\users\Desktop\AppData\Roaming\2c2233
c:\users\Desktop\AppData\Roaming\2f96b0ae
c:\users\Desktop\AppData\Roaming\2faa25c
c:\users\Desktop\AppData\Roaming\30a36d49
c:\users\Desktop\AppData\Roaming\325ea1bd
c:\users\Desktop\AppData\Roaming\335d658
c:\users\Desktop\AppData\Roaming\3458b729
c:\users\Desktop\AppData\Roaming\3560bc01
c:\users\Desktop\AppData\Roaming\3650d68d
c:\users\Desktop\AppData\Roaming\37691bc9
c:\users\Desktop\AppData\Roaming\386bbb3d
c:\users\Desktop\AppData\Roaming\39cde08
c:\users\Desktop\AppData\Roaming\3a597b3
c:\users\Desktop\AppData\Roaming\3d4eee1c
c:\users\Desktop\AppData\Roaming\3e2072a1
c:\users\Desktop\AppData\Roaming\3eea7afb
c:\users\Desktop\AppData\Roaming\3f37fdb1
c:\users\Desktop\AppData\Roaming\3f3b128
c:\users\Desktop\AppData\Roaming\411a0827
c:\users\Desktop\AppData\Roaming\41c1789f
c:\users\Desktop\AppData\Roaming\4232ea67
c:\users\Desktop\AppData\Roaming\440e8180
c:\users\Desktop\AppData\Roaming\47128dc6
c:\users\Desktop\AppData\Roaming\471a2a79
c:\users\Desktop\AppData\Roaming\48a4eed2
c:\users\Desktop\AppData\Roaming\49c02ee3
c:\users\Desktop\AppData\Roaming\4a0b6b7
c:\users\Desktop\AppData\Roaming\4b380798
c:\users\Desktop\AppData\Roaming\4b53d497
c:\users\Desktop\AppData\Roaming\4b61b6d9
c:\users\Desktop\AppData\Roaming\4b64601
c:\users\Desktop\AppData\Roaming\4c7ab50b
c:\users\Desktop\AppData\Roaming\4cfc1060
c:\users\Desktop\AppData\Roaming\4e6ce37
c:\users\Desktop\AppData\Roaming\596a25b
c:\users\Desktop\AppData\Roaming\5e08a60
c:\users\Desktop\AppData\Roaming\5e310e45
c:\users\Desktop\AppData\Roaming\5f697a27
c:\users\Desktop\AppData\Roaming\607286e0
c:\users\Desktop\AppData\Roaming\620ef67d
c:\users\Desktop\AppData\Roaming\62c5bb1d
c:\users\Desktop\AppData\Roaming\6332c5b9
c:\users\Desktop\AppData\Roaming\6c4f6882
c:\users\Desktop\AppData\Roaming\6df71825
c:\users\Desktop\AppData\Roaming\6e3ba91
c:\users\Desktop\AppData\Roaming\75669402
c:\users\Desktop\AppData\Roaming\7dec157
c:\users\Desktop\AppData\Roaming\85e36a01
c:\users\Desktop\AppData\Roaming\867f4207
c:\users\Desktop\AppData\Roaming\880d790d
c:\users\Desktop\AppData\Roaming\884bb93b
c:\users\Desktop\AppData\Roaming\9564557d
c:\users\Desktop\AppData\Roaming\97ce75d8
c:\users\Desktop\AppData\Roaming\97d4f8a3
c:\users\Desktop\AppData\Roaming\990e24e1
c:\users\Desktop\AppData\Roaming\995ab09b
c:\users\Desktop\AppData\Roaming\9bc577df
c:\users\Desktop\AppData\Roaming\9e2d83e8
c:\users\Desktop\AppData\Roaming\a12d5826
c:\users\Desktop\AppData\Roaming\a25cdf5f
c:\users\Desktop\AppData\Roaming\a3e19362
c:\users\Desktop\AppData\Roaming\a5677138
c:\users\Desktop\AppData\Roaming\af1c832
c:\users\Desktop\AppData\Roaming\b254f00e
c:\users\Desktop\AppData\Roaming\b2f81783
c:\users\Desktop\AppData\Roaming\b4e61bea
c:\users\Desktop\AppData\Roaming\b592600b
c:\users\Desktop\AppData\Roaming\b7e81e7
c:\users\Desktop\AppData\Roaming\b848f6d8
c:\users\Desktop\AppData\Roaming\b8530f2d
c:\users\Desktop\AppData\Roaming\b9b5fd42
c:\users\Desktop\AppData\Roaming\bbddf538
c:\users\Desktop\AppData\Roaming\bbf4c325
c:\users\Desktop\AppData\Roaming\bd647d71
c:\users\Desktop\AppData\Roaming\bf3c1566
c:\users\Desktop\AppData\Roaming\c0541eb6
c:\users\Desktop\AppData\Roaming\c24630e0
c:\users\Desktop\AppData\Roaming\c35a034c
c:\users\Desktop\AppData\Roaming\c46d6b13
c:\users\Desktop\AppData\Roaming\c5640c5c
c:\users\Desktop\AppData\Roaming\c8feae72
c:\users\Desktop\AppData\Roaming\c92752a
c:\users\Desktop\AppData\Roaming\c958a10
c:\users\Desktop\AppData\Roaming\ca2d1445
c:\users\Desktop\AppData\Roaming\ca625864
c:\users\Desktop\AppData\Roaming\cb24aa75
c:\users\Desktop\AppData\Roaming\cb6d7bee
c:\users\Desktop\AppData\Roaming\cd09cb25
c:\users\Desktop\AppData\Roaming\cd8000d0
c:\users\Desktop\AppData\Roaming\cde151b9
c:\users\Desktop\AppData\Roaming\ce33e2c1
c:\users\Desktop\AppData\Roaming\cf2c3336
c:\users\Desktop\AppData\Roaming\cf72c69c
c:\users\Desktop\AppData\Roaming\cf7d6a37
c:\users\Desktop\AppData\Roaming\chrtmp
c:\users\Desktop\AppData\Roaming\d0969c44
c:\users\Desktop\AppData\Roaming\d09f4e7f
c:\users\Desktop\AppData\Roaming\d19030c3
c:\users\Desktop\AppData\Roaming\d28a6067
c:\users\Desktop\AppData\Roaming\d2c6d69a
c:\users\Desktop\AppData\Roaming\d2eb6fb4
c:\users\Desktop\AppData\Roaming\d3a4b93a
c:\users\Desktop\AppData\Roaming\d4493a08
c:\users\Desktop\AppData\Roaming\d5c47c93
c:\users\Desktop\AppData\Roaming\d635c736
c:\users\Desktop\AppData\Roaming\d6f27a63
c:\users\Desktop\AppData\Roaming\d8cae6ad
c:\users\Desktop\AppData\Roaming\daee34a7
c:\users\Desktop\AppData\Roaming\dc359bdf
c:\users\Desktop\AppData\Roaming\dce30b55
c:\users\Desktop\AppData\Roaming\dd54e89b
c:\users\Desktop\AppData\Roaming\de0b0e37
c:\users\Desktop\AppData\Roaming\df13d14f
c:\users\Desktop\AppData\Roaming\dfa321f7
c:\users\Desktop\AppData\Roaming\e092892b
c:\users\Desktop\AppData\Roaming\e0b963b3
c:\users\Desktop\AppData\Roaming\e196ec7
c:\users\Desktop\AppData\Roaming\e1dae2f7
c:\users\Desktop\AppData\Roaming\e2dec85f
c:\users\Desktop\AppData\Roaming\e66269f
c:\users\Desktop\AppData\Roaming\e780c75a
c:\users\Desktop\AppData\Roaming\e7d8073b
c:\users\Desktop\AppData\Roaming\e8915c65
c:\users\Desktop\AppData\Roaming\e8adb1c4
c:\users\Desktop\AppData\Roaming\e8fc5c12
c:\users\Desktop\AppData\Roaming\e928d42e
c:\users\Desktop\AppData\Roaming\e9c6b7fc
c:\users\Desktop\AppData\Roaming\ea3cb8a2
c:\users\Desktop\AppData\Roaming\eab870dc
c:\users\Desktop\AppData\Roaming\eadb7c2f
c:\users\Desktop\AppData\Roaming\eb3d40ee
c:\users\Desktop\AppData\Roaming\ec44c5ca
c:\users\Desktop\AppData\Roaming\ed02fb4b
c:\users\Desktop\AppData\Roaming\ed43c43a
c:\users\Desktop\AppData\Roaming\ee2000cb
c:\users\Desktop\AppData\Roaming\ee9ffdce
c:\users\Desktop\AppData\Roaming\ef316c03
c:\users\Desktop\AppData\Roaming\efbdf0a5
c:\users\Desktop\AppData\Roaming\f04e30cb
c:\users\Desktop\AppData\Roaming\f15ff377
c:\users\Desktop\AppData\Roaming\f1adf267
c:\users\Desktop\AppData\Roaming\f25929ab
c:\users\Desktop\AppData\Roaming\f2d34aad
c:\users\Desktop\AppData\Roaming\f2e2a803
c:\users\Desktop\AppData\Roaming\f40d9b1f
c:\users\Desktop\AppData\Roaming\f439e845
c:\users\Desktop\AppData\Roaming\f44d901b
c:\users\Desktop\AppData\Roaming\f568b92c
c:\users\Desktop\AppData\Roaming\f62a3dd9
c:\users\Desktop\AppData\Roaming\f70b7ca4
c:\users\Desktop\AppData\Roaming\f809a603
c:\users\Desktop\AppData\Roaming\f819a2b9
c:\users\Desktop\AppData\Roaming\f84a50a
c:\users\Desktop\AppData\Roaming\f921bfb0
c:\users\Desktop\AppData\Roaming\f9632998
c:\users\Desktop\AppData\Roaming\fa142e2f
c:\users\Desktop\AppData\Roaming\fbb65c86
c:\users\Desktop\AppData\Roaming\fd30b46e
c:\users\Desktop\AppData\Roaming\fd66a206
c:\users\Desktop\AppData\Roaming\feb5582e
c:\users\Desktop\AppData\Roaming\fecb4a58
c:\users\Desktop\AppData\Roaming\msthnv.dll
c:\users\Desktop\AppData\Roaming\nhcaps.dll
c:\users\Desktop\AppData\Roaming\qmcts.dll
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\@
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\L\00000004.@
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\U\00000004.@
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\U\00000008.@
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\U\000000cb.@
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\U\80000000.@
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\U\80000032.@
c:\windows\Installer\{589e96b4-2f37-e487-882e-05eb34b2f5bb}\U\80000064.@
c:\windows\SysWow64\1065\inf1065.dat
c:\windows\SysWow64\1077
c:\windows\SysWow64\1077\inf1077.dat
c:\windows\SysWow64\1079\inf1079.dat
.
----- File Replicators -----
.
c:\windows\System32\usser.exe
c:\windows\System32\ussser.exe
c:\windows\System32\usssser.exe
c:\windows\System32\ussssser.exe
c:\windows\System32\usssssser.exe
c:\windows\System32\ussssssser.exe
c:\windows\System32\usssssssser.exe
c:\windows\System32\ussssssssser.exe
c:\windows\System32\usssssssssser.exe
c:\windows\System32\ussssssssssser.exe
c:\windows\System32\usssssssssssser.exe
c:\windows\System32\ussssssssssssser.exe
c:\windows\System32\usssssssssssssser.exe
c:\windows\System32\ussssssssssssssser.exe
c:\windows\System32\usssssssssssssssser.exe
c:\windows\System32\ussssssssssssssssser.exe
c:\windows\System32\usssssssssssssssssser.exe
c:\windows\System32\ussssssssssssssssssser.exe
c:\windows\System32\usssssssssssssssssssser.exe
c:\windows\System32\ussssssssssssssssssssser.exe
c:\windows\System32\usssssssssssssssssssssser.exe
c:\windows\System32\ussssssssssssssssssssssser.exe
c:\windows\System32\usssssssssssssssssssssssser.exe
c:\windows\System32\ussssssssssssssssssssssssser.exe
c:\windows\System32\usssssssssssssssssssssssssser.exe
c:\windows\System32\ussssssssssssssssssssssssssser.exe
c:\windows\SysWOW64\usser.exe
c:\windows\SysWOW64\ussser.exe
c:\windows\SysWOW64\usssser.exe
c:\windows\SysWOW64\ussssser.exe
c:\windows\SysWOW64\usssssser.exe
c:\windows\SysWOW64\ussssssser.exe
c:\windows\SysWOW64\usssssssser.exe
c:\windows\SysWOW64\ussssssssser.exe
c:\windows\SysWOW64\usssssssssser.exe
c:\windows\SysWOW64\ussssssssssser.exe
c:\windows\SysWOW64\usssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssser.exe
c:\windows\SysWOW64\usssssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssssser.exe
c:\windows\SysWOW64\usssssssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssssssser.exe
c:\windows\SysWOW64\usssssssssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssssssssser.exe
c:\windows\SysWOW64\usssssssssssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssssssssssser.exe
c:\windows\SysWOW64\usssssssssssssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssssssssssssser.exe
c:\windows\SysWOW64\usssssssssssssssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssssssssssssssser.exe
c:\windows\SysWOW64\usssssssssssssssssssssssssser.exe
c:\windows\SysWOW64\ussssssssssssssssssssssssssser.exe
.
Infected copy of c:\windows\system32\services.exe was found and disinfected
Restored copy from - c:\32788r22fwjfw\HarddiskVolumeShadowCopy2_!Windows!System32!services.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-07-14 to 2012-08-14 )))))))))))))))))))))))))))))))
.
.
2012-08-14 12:18 . 2012-08-14 12:18--------d-----w-c:\users\Default\AppData\Local\temp
2012-08-14 10:11 . 2012-08-14 10:20--------d-----w-c:\users\Desktop\AppData\Roaming\Wise Registry Cleaner
2012-08-11 13:29 . 2012-08-11 13:29--------d-----w-c:\users\Desktop\AppData\Local\SymbolSourceSymbols
2012-08-11 13:29 . 2012-08-11 13:29--------d-----w-c:\users\Desktop\AppData\Local\RefSrcSymbols
2012-08-11 13:29 . 2012-08-11 13:29--------d-----w-c:\users\Desktop\AppData\Local\JetBrains
2012-08-11 13:29 . 2012-08-11 13:29--------d-----w-c:\users\Desktop\AppData\Roaming\JetBrains
2012-08-11 13:00 . 2012-08-11 13:00--------d-----w-c:\windows\SysWow64\1082
2012-08-11 13:00 . 2012-08-11 13:00679936----a-w-c:\windows\system32\Rede1389.scr
2012-08-11 13:00 . 2012-08-11 13:00679936------w-c:\windows\SysWow64\Rede1389.scr
2012-08-11 13:00 . 2012-08-11 13:00--------d-----w-c:\programdata\Screentime
2012-08-11 13:00 . 2012-08-11 13:00--------d-----w-c:\users\Desktop\AppData\Local\Screentime
2012-08-11 12:57 . 2012-08-11 12:57--------d-----w-c:\windows\SysWow64\1081
2012-08-11 12:41 . 2012-08-11 12:47--------d-----w-c:\program files (x86)\Free Registry Cleaner For Seven
2012-08-11 09:39 . 2012-08-11 09:39--------d-----w-c:\windows\SysWow64\1080
2012-08-11 08:46 . 2012-08-14 12:17--------d-----w-c:\windows\SysWow64\1079
2012-08-11 08:33 . 2012-08-11 08:41--------d-----w-c:\users\Desktop\AppData\Roaming\Error Fix
2012-08-11 08:10 . 2012-08-11 08:10--------d-----w-c:\windows\ehome
2012-08-11 08:10 . 2012-08-11 08:10--------d-----w-c:\users\Default\AppData\Roaming\Media Center Programs
2012-08-11 08:01 . 2012-08-11 08:01--------d-----w-c:\windows\SysWow64\1078
2012-08-11 07:52 . 2012-08-11 07:52--------d-----w-c:\windows\SysWow64\1076
2012-08-10 09:47 . 2012-08-10 09:47--------d-----w-c:\windows\SysWow64\1075
2012-08-10 09:33 . 2012-08-10 09:33--------d-----w-c:\windows\SysWow64\1074
2012-08-10 09:08 . 2012-08-10 09:08--------d-----w-c:\windows\SysWow64\1073
2012-08-10 09:05 . 2012-08-10 09:05--------d-----w-c:\windows\SysWow64\1072
2012-08-10 08:53 . 2012-08-10 08:53--------d-----w-c:\windows\SysWow64\1071
2012-08-10 08:34 . 2012-08-10 08:34--------d-----w-c:\windows\SysWow64\1070
2012-08-10 08:32 . 2012-08-10 08:32--------d-----w-c:\users\Desktop\AppData\Roaming\flashInstall
2012-08-10 07:08 . 2012-08-10 07:09--------d-----w-c:\users\Desktop\AppData\Roaming\PE Explorer
2012-08-10 06:38 . 2012-08-10 06:38--------d-----w-c:\windows\SysWow64\1069
2012-08-10 06:30 . 2012-08-10 06:30--------d-----w-c:\windows\SysWow64\1068
2012-08-10 06:19 . 2012-08-10 06:19--------d-----w-c:\windows\SysWow64\1067
2012-08-10 06:18 . 2012-08-10 06:18--------d-----w-c:\windows\SysWow64\1066
2012-08-10 06:15 . 2012-08-14 12:17--------d-----w-c:\windows\SysWow64\1065
2012-08-09 11:26 . 2012-08-09 11:26--------d-----w-c:\windows\SysWow64\1064
2012-08-09 10:24 . 2012-08-09 10:24--------d-----w-c:\windows\SysWow64\1063
2012-08-09 10:24 . 2012-08-09 10:24--------d-----w-c:\windows\SysWow64\1062
2012-08-09 10:10 . 2012-08-09 10:10--------d-----w-c:\windows\SysWow64\1061
2012-08-09 10:09 . 2012-08-09 10:09--------d-----w-c:\windows\SysWow64\1060
2012-08-09 10:01 . 2012-08-09 10:01--------d-----w-c:\windows\SysWow64\1059
2012-08-09 10:00 . 2012-08-09 10:00--------d-----w-c:\windows\SysWow64\1058
2012-08-09 09:59 . 2012-08-09 09:59--------d-----w-c:\windows\SysWow64\1057
2012-08-06 10:56 . 2011-11-09 12:08189608----a-w-c:\windows\system32\IPROSetMonitor.exe
2012-08-06 10:56 . 2012-08-06 10:56--------d-----w-c:\program files\Intel
2012-08-06 10:54 . 2012-02-01 21:13509104----a-w-c:\windows\system32\drivers\e1k62x64.sys
2012-08-06 10:54 . 2012-01-19 21:1199520----a-w-c:\windows\system32\NicInstK.dll
2012-08-06 10:54 . 2012-01-18 21:0768264----a-w-c:\windows\system32\e1kmsg.dll
2012-08-02 14:33 . 2012-06-18 08:0419032------w-c:\windows\system32\pwdrvio.sys
2012-08-02 14:33 . 2012-06-18 08:042966720----a-w-c:\windows\system32\pwNative.exe
2012-08-02 14:33 . 2012-06-18 08:0412384------w-c:\windows\system32\pwdspio.sys
2012-08-01 13:20 . 2012-08-03 02:56--------d-----w-c:\users\Desktop\.android
2012-08-01 13:12 . 2012-08-01 13:12--------d-----w-c:\program files\Oracle
2012-08-01 13:12 . 2012-08-01 13:11268784----a-w-c:\windows\system32\javaws.exe
2012-08-01 13:12 . 2012-08-01 13:11189424----a-w-c:\windows\system32\javaw.exe
2012-08-01 13:12 . 2012-08-01 13:11188912----a-w-c:\windows\system32\java.exe
2012-08-01 13:10 . 2012-08-01 13:11--------d-----w-c:\program files\Java
2012-08-01 13:10 . 2012-08-02 14:04--------d-----w-c:\users\Desktop\jdk1.7.0_05_combo
2012-07-27 13:39 . 2012-08-02 18:03--------d-----w-c:\programdata\LGMOBILEAX
2012-07-26 11:49 . 2012-07-26 11:55--------d-----w-c:\program files (x86)\YourFileDownloader
2012-07-26 11:49 . 2012-07-26 11:49--------d-----w-c:\users\Desktop\AppData\Roaming\YourFileDownloader
2012-07-26 11:21 . 2012-07-26 11:21--------d-----w-c:\program files (x86)\uTorrent
2012-07-25 15:15 . 2012-07-25 15:15--------d-----w-c:\program files (x86)\LG Electronics
2012-07-25 14:31 . 2012-08-02 18:33--------d-----w-c:\users\Desktop\AppData\Roaming\LG Electronics
2012-07-25 14:30 . 2012-07-25 14:30--------d-----w-c:\users\Desktop\AppData\Local\LG Electronics
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-13 10:36 . 2012-04-04 06:17426184----a-w-c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-13 10:36 . 2011-06-02 02:3970344----a-w-c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-09 06:36 . 2009-07-13 23:19328704----a-w-c:\windows\system32\services.exe
2012-07-03 08:16 . 2011-06-14 07:2924904----a-w-c:\windows\system32\drivers\mbam.sys
2012-06-06 04:06 . 2012-06-06 04:062174976----a-w-c:\program files (x86)\Common Files\atimpenc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0BC6E3FA-78EF-4886-842C-5A1258C4455A}"= "mscoree.dll" [2010-11-05 297808]
.
[HKEY_CLASSES_ROOT\clsid\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
[HKEY_CLASSES_ROOT\agihelper.AGUtils]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
2010-11-05 01:58297808----a-w-c:\windows\System32\mscoree.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"Smart File Advisor"="c:\program files (x86)\Smart File Advisor\sfa.exe" [2011-04-04 280824]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatchTray13.exe" [2010-07-16 307184]
"CPMonitor"="c:\program files (x86)\Roxio 2011\5.0\CPMonitor.exe" [2010-07-13 84464]
"Desktop Disc Tool"="c:\program files (x86)\Roxio 2011\Roxio Burn\RoxioBurnLauncher.exe" [2010-06-30 477680]
"Malwarebytes' Anti-Malware"="d:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\users\Desktop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files (x86)\Webshots\3.1.5.7619\Launcher.exe [2011-9-12 157088]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 MBAMService;MBAMService;d:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatch13.exe [2010-07-16 354288]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-12-09 2320920]
R3 andnetadb;ADB Interface DriverNet;c:\windows\system32\Drivers\lgandnetadb.sys [2012-03-06 31744]
R3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\DRIVERS\lgandnetdiag64.sys [2012-03-06 29184]
R3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\DRIVERS\lgandnetmodem64.sys [2012-03-06 36352]
R3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter;c:\windows\system32\DRIVERS\lgandnetndis64.sys [2012-03-06 93184]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-08 129976]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2012-06-18 19032]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2012-06-18 12384]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
R3 RoxMediaDB13;RoxMediaDB13;c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxMediaDB13.exe [2010-07-16 1099248]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc; [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 tsusbhub;tsusbhub; [x]
R3 VGPU;VGPU; [x]
R3 vpcuxd;USB Virtualization Stub Service;c:\windows\system32\DRIVERS\vpcuxd.sys [2010-11-20 16384]
R3 vvftav303;vvftav303;c:\windows\system32\drivers\vvftav303.sys [2007-03-18 301824]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-12-05 1255736]
R3 ZSMC0303;INTEX Game Camera;c:\windows\system32\Drivers\usbVM303.sys [2007-03-25 1494656]
R4 Ireniceaesse;Ireniceaesse; [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-18 55856]
S0 Sahdad64;HDD Filter Driver;c:\windows\System32\Drivers\Sahdad64.sys [2009-06-01 27120]
S0 Saibad64;Volume Filter Driver;c:\windows\System32\Drivers\Saibad64.sys [2009-06-01 19952]
S1 SaibVdAd64;Virtual Disk Driver;c:\windows\system32\Drivers\SaibVdAd64.sys [2009-06-01 27632]
S2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [2009-06-02 457200]
S2 AGCoreService;AG Core Services;c:\program files (x86)\AGI\core\4.2.0.10754\AGCoreService.exe [2010-06-29 20480]
S2 BOT4Service;BOT4Service;c:\program files (x86)\Roxio\BackOnTrack\App\BService.exe [2010-07-13 32240]
S2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe [2011-11-09 189608]
S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys [2012-02-01 509104]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-02-03 271872]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-30 c:\windows\Tasks\SidebarExecute.job
- c:\program files\Windows Sidebar\sidebar.exe [2011-04-09 13:25]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 162328]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 417304]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-07-07 12558440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.co.in/
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{C3D5A4FB-98D0-46EC-8865-32390EE39FB8}: NameServer = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\users\Desktop\AppData\Roaming\Mozilla\Firefox\Profiles\zpqxsszw.default\
FF - prefs.js: browser.startup.homepage - www.google.co.in
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-whtpd - (no file)
Wow6432Node-HKCU-Run-nhcaps - (no file)
Wow6432Node-HKCU-Run-qmcts - (no file)
Wow6432Node-HKCU-Run-msthnv - (no file)
Wow6432Node-HKCU-Run-wladmg - (no file)
WebBrowser-{7B13EC3E-999A-4B70-B9CB-2617B8323822} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-msthnv - (no file)
HKLM-Run-wladmg - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_268_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_268_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_268.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\software\Network Associates]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Completion time: 2012-08-14 17:52:30 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-14 12:22
.
Pre-Run: 64,696,188,928 bytes free
Post-Run: 64,522,870,784 bytes free
.
- - End Of File - - DBDDD338056EA51EA6BCCAF12E7952E9