Solved Got a virus trying to run unkillable IE windows in background

SystemLook 30.07.11 by jpshortstuff
Log created at 17:49 on 23/06/2012 by Skilz
Administrator - Elevation successful

========== filefind ==========

Searching for "user32.dll"
C:\FRST\Quarantine\user32.dll--a---- 857600 bytes[02:02 21/06/2012][12:08 20/11/2010] BA6EE9B4E38B720A537A3EF48BD5903B
C:\Windows\erdnt\cache64\user32.dll--a---- 1008128 bytes[01:06 23/06/2012][13:27 20/11/2010] FE70103391A64039A921DBFFF9C7AB1B
C:\Windows\System32\user32.dll--a---- 1008128 bytes[02:02 21/06/2012][13:27 20/11/2010] FE70103391A64039A921DBFFF9C7AB1B
C:\Windows\SysWOW64\user32.dll--a---- 833024 bytes[02:02 21/06/2012][12:08 20/11/2010] 5E0DB2D8B2750543CD2EBB9EA8E6CDD3
C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll--a---- 1008640 bytes[23:38 13/07/2009][01:41 14/07/2009] 72D7B3EA16946E8F0CF7458150031CC6
C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll--a---- 1008128 bytes[02:02 21/06/2012][13:27 20/11/2010] FE70103391A64039A921DBFFF9C7AB1B
C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll--a---- 833024 bytes[23:24 13/07/2009][01:11 14/07/2009] E8B0FFC209E504CB7E79FC24E6C085F0
C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll------- 833024 bytes[02:02 21/06/2012][12:08 20/11/2010] 5E0DB2D8B2750543CD2EBB9EA8E6CDD3

-= EOF =-
 
ComboFix 12-06-23.05 - Skilz 06/23/2012 18:00:46.6.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.16345.13868 [GMT -7:00]
Running from: c:\users\Skilz\Downloads\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\bwfwcaa.tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-05-24 to 2012-06-24 )))))))))))))))))))))))))))))))
.
.
2012-06-24 01:04 . 2012-06-24 01:04--------d-----w-c:\users\Default\AppData\Local\temp
2012-06-23 06:47 . 2012-06-24 01:02--------d-----w-C:\FRST
2012-06-23 06:37 . 2012-06-23 06:37--------d-----w-c:\windows\system32\Macromed
2012-06-23 01:39 . 2012-06-23 01:39--------d-----w-C:\_OTL
2012-06-23 01:35 . 2012-06-23 01:44--------d-----w-c:\program files\Rainmeter
2012-06-23 00:02 . 2012-06-23 00:02--------d-----w-c:\program files (x86)\Malwarebytes' Anti-Malware
2012-06-23 00:02 . 2012-06-23 00:02--------d-----w-c:\programdata\Malwarebytes
2012-06-23 00:02 . 2012-04-04 22:5624904----a-w-c:\windows\system32\drivers\mbam.sys
2012-06-22 23:58 . 2012-06-22 23:58--------d-----w-c:\program files (x86)\Foxit Software
2012-06-22 23:40 . 2012-06-22 23:40--------d-----w-c:\program files (x86)\Common Files\Symantec Shared
2012-06-22 23:40 . 2012-06-23 02:20175736----a-w-c:\windows\system32\drivers\SYMEVENT64x86.SYS
2012-06-22 23:40 . 2012-06-23 02:20--------d-----w-c:\program files\Symantec
2012-06-22 23:40 . 2012-06-22 23:40--------d-----w-c:\users\Public\Symantec
2012-06-22 23:40 . 2012-06-22 23:40--------d-----w-c:\program files\Common Files\Symantec Shared
2012-06-22 23:40 . 2012-06-22 23:40--------d-----w-c:\program files (x86)\SymSilent
2012-06-22 23:40 . 2012-06-23 02:21--------d-----w-c:\windows\system32\drivers\NISx64
2012-06-22 23:40 . 2012-06-22 23:40--------d-----w-c:\programdata\Norton
2012-06-22 23:40 . 2012-06-22 23:40--------d-----w-c:\program files (x86)\Norton Internet Security
2012-06-22 23:40 . 2012-06-22 23:40--------d-----w-c:\program files (x86)\NortonInstaller
2012-06-22 21:41 . 2012-06-18 10:129013136----a-w-c:\programdata\Microsoft\Windows Defender\Definition Updates\{F4FCF840-2E30-48EE-9EF4-550C0C991BFF}\mpengine.dll
2012-06-22 21:37 . 2012-06-22 21:37--------d-----w-c:\windows\Sun
2012-06-22 21:25 . 2009-07-27 02:5490544----a-w-c:\windows\system32\drivers\scdemu.sys
2012-06-22 21:19 . 2012-06-22 21:19--------d-----w-c:\windows\system32\wbem\Framework
2012-06-22 21:19 . 2012-06-22 21:22--------d-----w-C:\CPU Monitor
2012-06-22 21:14 . 2012-06-22 21:14--------d-----w-c:\program files (x86)\Vertus Fluid Mask 3
2012-06-22 21:11 . 2012-06-22 21:11--------d-----w-c:\programdata\VertusTech
2012-06-22 20:57 . 2012-06-22 20:57--------d-----w-c:\programdata\GlobalSCAPE
2012-06-22 20:56 . 2012-06-22 20:56--------d-----w-c:\program files (x86)\GlobalSCAPE
2012-06-22 05:32 . 2012-06-22 05:32--------d-----w-c:\programdata\ALM
2012-06-22 05:31 . 2012-06-22 05:32--------d-----w-c:\program files\Common Files\Adobe
2012-06-22 05:30 . 2012-06-22 05:30--------d-----w-c:\program files (x86)\Adobe Media Player
2012-06-22 05:29 . 2012-06-22 05:29--------d-----w-c:\program files (x86)\Common Files\Adobe AIR
2012-06-22 04:56 . 2012-06-22 04:56--------d-----w-c:\programdata\EA Core
2012-06-22 04:55 . 2012-06-22 05:24--------d-----w-c:\programdata\EA Logs
2012-06-22 04:22 . 2012-06-22 04:22--------d-----w-c:\program files\BitComet
2012-06-22 04:17 . 2012-06-22 04:17--------d-----w-C:\Downloads
2012-06-22 03:31 . 2012-05-04 11:00366592----a-w-c:\windows\system32\qdvd.dll
2012-06-22 03:31 . 2012-05-04 09:59514560----a-w-c:\windows\SysWow64\qdvd.dll
2012-06-22 03:19 . 2012-06-22 03:20--------d-----w-C:\Temp
2012-06-22 03:18 . 2012-06-22 03:2016384----a-w-c:\windows\SysWow64\lgfwunis.exe
2012-06-22 03:18 . 2001-08-30 04:0059904----a-w-c:\windows\SysWow64\wbemdisp.tlb
2012-06-22 03:18 . 1998-07-22 07:00102912----a-w-c:\windows\SysWow64\Vb6stkit.dll
2012-06-22 03:18 . 1998-07-22 07:00102160----a-w-c:\windows\SysWow64\VB6KO.DLL
2012-06-22 03:18 . 1998-06-24 07:00115016----a-w-c:\windows\SysWow64\MSINET.OCX
2012-06-22 03:18 . 2012-06-24 00:47--------d-----w-c:\program files (x86)\lg_fwupdate
2012-06-22 03:16 . 2012-06-22 03:19--------d-----w-c:\program files (x86)\CyberLink
2012-06-22 03:16 . 2012-06-22 03:18--------d-----w-c:\programdata\CyberLink
2012-06-22 03:15 . 2012-06-02 22:192428952----a-w-c:\windows\system32\wuaueng.dll
2012-06-22 03:15 . 2012-06-02 22:1957880----a-w-c:\windows\system32\wuauclt.exe
2012-06-22 03:15 . 2012-06-02 22:1944056----a-w-c:\windows\system32\wups2.dll
2012-06-22 03:15 . 2012-06-02 22:152622464----a-w-c:\windows\system32\wucltux.dll
2012-06-22 03:15 . 2012-06-02 22:1938424----a-w-c:\windows\system32\wups.dll
2012-06-22 03:15 . 2012-06-02 22:19186752----a-w-c:\windows\system32\wuwebv.dll
2012-06-22 03:15 . 2012-06-02 22:19701976----a-w-c:\windows\system32\wuapi.dll
2012-06-22 03:15 . 2012-06-02 22:1536864----a-w-c:\windows\system32\wuapp.exe
2012-06-22 03:15 . 2012-06-02 22:1599840----a-w-c:\windows\system32\wudriver.dll
2012-06-21 07:17 . 2012-06-21 07:17--------d-----w-c:\program files (x86)\Mozilla Maintenance Service
2012-06-21 07:11 . 2012-06-21 07:11--------d-----w-C:\aws
2012-06-21 07:11 . 2012-06-21 07:11--------d-----w-C:\Asus WebStorage
2012-06-21 07:06 . 2012-06-21 07:06--------d-----w-c:\program files (x86)\Git
2012-06-21 07:06 . 2012-06-21 07:06--------dc----w-c:\windows\system32\DRVSTORE
2012-06-21 07:05 . 2012-06-21 07:05--------d-----w-c:\programdata\Apple
2012-06-21 07:04 . 2012-06-21 07:04--------d-----w-c:\programdata\ASUS WebStorage
2012-06-21 07:04 . 2012-06-21 07:04--------d-----w-c:\program files (x86)\ASUS
2012-06-21 06:58 . 2012-06-22 04:25--------d-----w-c:\program files (x86)\Diablo III
2012-06-21 06:58 . 2012-06-21 07:12--------d-----w-c:\programdata\Blizzard Entertainment
2012-06-21 06:58 . 2012-06-21 07:12--------d-----w-c:\program files (x86)\Common Files\Blizzard Entertainment
2012-06-21 06:57 . 2012-06-21 06:58--------d-----w-c:\programdata\Battle.net
2012-06-21 06:51 . 2012-06-21 06:51--------d--h--w-c:\program files (x86)\Common Files\EAInstaller
2012-06-21 06:37 . 2012-06-21 06:37--------d-----w-c:\program files (x86)\Notepad++
2012-06-21 06:31 . 2012-06-21 06:32--------d-----w-c:\program files (x86)\Origin Games
2012-06-21 06:30 . 2012-06-22 04:56--------d-----w-c:\programdata\Electronic Arts
2012-06-21 06:30 . 2012-06-22 04:56--------d-----w-c:\programdata\Origin
2012-06-21 06:30 . 2012-06-21 06:31--------d-----w-c:\program files (x86)\Origin
2012-06-21 06:29 . 2012-06-24 01:04--------d-----w-c:\program files (x86)\Steam
2012-06-21 06:29 . 2012-06-21 06:29--------d-----w-c:\program files (x86)\Common Files\Steam
2012-06-21 06:00 . 2012-06-21 06:00--------d-----w-c:\program files (x86)\Common Files\Java
2012-06-21 06:00 . 2012-06-21 06:00--------d-----w-c:\program files (x86)\Oracle
2012-06-21 02:07 . 2012-06-21 02:07--------d-----w-c:\windows\system32\SPReview
2012-06-21 02:07 . 2012-06-21 02:07--------d-----w-c:\windows\system32\EventProviders
2012-06-21 02:02 . 2010-11-20 13:33273792----a-w-c:\windows\system32\drivers\msiscsi.sys
2012-06-21 01:56 . 2011-03-25 03:29343040----a-w-c:\windows\system32\drivers\usbhub.sys
2012-06-20 08:53 . 2012-06-20 08:53--------d-----w-c:\program files\Microsoft IntelliPoint
2012-06-20 08:53 . 2012-06-20 08:53--------d-----w-c:\windows\PCHEALTH
2012-06-20 08:52 . 2011-02-19 12:051139200----a-w-c:\windows\system32\FntCache.dll
2012-06-20 08:52 . 2011-02-19 12:04902656----a-w-c:\windows\system32\d2d1.dll
2012-06-20 08:52 . 2011-02-19 06:30739840----a-w-c:\windows\SysWow64\d2d1.dll
2012-06-20 08:51 . 2012-06-20 08:51--------d-----w-c:\program files (x86)\Microsoft.NET
2012-06-20 08:47 . 2012-06-20 07:53--------d-----w-c:\windows\Panther
2012-06-20 08:43 . 2012-06-20 08:43--------d-----w-c:\program files (x86)\Common Files\Intel Corporation
2012-06-20 08:38 . 2012-06-21 00:5630528----a-w-c:\windows\GVTDrv64.sys
2012-06-20 08:37 . 2012-06-20 08:37--------d-----w-c:\windows\SysWow64\Wat
2012-06-20 08:37 . 2012-06-20 08:37--------d-----w-c:\windows\system32\Wat
2012-06-20 08:34 . 2012-06-23 06:3770344----a-w-c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-20 08:34 . 2012-06-23 06:37426184----a-w-c:\windows\SysWow64\FlashPlayerApp.exe
2012-06-20 08:33 . 2012-06-20 08:33--------d-----w-c:\windows\SysWow64\Macromed
2012-06-20 08:31 . 2012-06-20 08:31--------d-----w-c:\program files (x86)\Opera
2012-06-20 08:11 . 2012-03-01 06:4623408----a-w-c:\windows\system32\drivers\fs_rec.sys
2012-06-20 08:11 . 2012-03-01 06:38220672----a-w-c:\windows\system32\wintrust.dll
2012-06-20 08:11 . 2012-03-01 06:3381408----a-w-c:\windows\system32\imagehlp.dll
2012-06-20 08:11 . 2012-03-01 06:285120----a-w-c:\windows\system32\wmi.dll
2012-06-20 08:11 . 2012-03-01 05:37172544----a-w-c:\windows\SysWow64\wintrust.dll
2012-06-20 08:11 . 2012-03-01 05:33159232----a-w-c:\windows\SysWow64\imagehlp.dll
2012-06-20 08:11 . 2012-03-01 05:295120----a-w-c:\windows\SysWow64\wmi.dll
2012-06-20 08:09 . 2011-03-12 12:081465344----a-w-c:\windows\system32\XpsPrint.dll
2012-06-20 08:08 . 2012-05-04 11:065559664----a-w-c:\windows\system32\ntoskrnl.exe
2012-06-20 08:07 . 2011-05-24 11:42404480----a-w-c:\windows\system32\umpnpmgr.dll
2012-06-20 08:06 . 2012-06-20 08:06--------d-----w-c:\programdata\Downloaded Installations
2012-06-20 08:05 . 2012-06-20 08:05--------d-----w-c:\programdata\WinZip
2012-06-20 08:05 . 2012-01-13 01:3766336----a-w-c:\windows\system32\drivers\VirtuWDDM.sys
2012-06-20 08:05 . 2012-06-20 08:05--------d-----w-c:\program files\Lucidlogix Technologies
2012-06-20 08:05 . 2012-01-13 01:36475424----a-w-c:\windows\system32\appinit_dll.dll
2012-06-20 08:05 . 2012-01-13 01:35429856----a-w-c:\windows\SysWow64\appinit_dll.dll
2012-06-20 08:04 . 2012-06-20 08:04--------d-----w-c:\program files (x86)\Atheros ASAV
2012-06-20 08:04 . 2012-06-22 05:31--------d-----w-c:\program files (x86)\Common Files\Adobe
2012-06-20 08:04 . 2011-02-08 23:0266160----a-w-c:\windows\system32\drivers\VirtDiskBus64.sys
2012-06-20 08:04 . 2012-06-20 08:04--------d-----w-c:\program files (x86)\My Company Name
2012-06-20 08:03 . 2012-02-23 17:18279656------w-c:\windows\system32\MpSigStub.exe
2012-06-20 08:01 . 2012-06-20 08:01--------d-----w-c:\program files (x86)\Evernote
2012-06-20 07:58 . 2011-08-11 22:54104560----a-w-c:\windows\system32\drivers\L1C62x64.sys
2012-06-20 07:57 . 2012-06-22 03:18--------d-----w-c:\program files (x86)\Common Files\InstallShield
2012-06-20 07:56 . 2012-06-20 08:38--------d-----w-c:\programdata\Intel
2012-06-20 07:56 . 2012-06-20 07:56--------d-----w-c:\program files\Intel
2012-06-20 07:56 . 2011-12-06 23:5553248----a-r-c:\windows\SysWow64\CSVer.dll
2012-06-20 07:56 . 2012-06-20 07:56--------d-----w-c:\program files (x86)\Common Files\postureAgent
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-21 02:21 . 2009-07-14 02:36175616----a-w-c:\windows\system32\msclmd.dll
2012-06-21 02:21 . 2009-07-14 02:36152576----a-w-c:\windows\SysWow64\msclmd.dll
2012-05-15 09:21 . 2012-05-15 09:21423744----a-w-c:\windows\SysWow64\nvStreaming.exe
2012-04-25 19:11 . 2012-04-25 19:1152736----a-w-c:\windows\system32\drivers\usbaapl64.sys
2012-04-25 19:11 . 2012-04-25 19:114547944----a-w-c:\windows\system32\usbaaplrc.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2012-06-23_19.52.45 )))))))))))))))))))))))))))))))))))))))))
.
- 2012-06-22 23:11 . 2012-06-23 19:4116384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2012-06-22 23:11 . 2012-06-24 00:2816384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2012-06-22 23:12 . 2012-06-24 00:2816384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\index.dat
- 2012-06-22 23:12 . 2012-06-23 19:4116384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\index.dat
+ 2012-06-22 23:39 . 2012-06-24 00:1732768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat
- 2012-06-22 23:39 . 2012-06-22 23:4232768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat
+ 2012-06-23 19:39 . 2012-06-24 00:2898304 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012012062320120624\index.dat
+ 2012-06-24 00:28 . 2012-06-24 00:2830720 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\{8D1349E6-BD93-11E1-94E8-902B343164A9}.dat
+ 2012-06-24 00:17 . 2012-06-24 00:1768096 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{F834C418-BD91-11E1-94E8-902B343164A9}.dat
+ 2012-06-20 08:43 . 2012-06-24 00:4942602 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-06-24 00:4931628 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2012-06-23 19:41 . 2012-06-23 19:413584 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\RecoveryStore.{73DCD4DA-BD6B-11E1-8D7D-902B343164A9}.dat
+ 2012-06-23 19:41 . 2012-06-24 00:283584 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\RecoveryStore.{73DCD4DA-BD6B-11E1-8D7D-902B343164A9}.dat
+ 2012-06-24 00:17 . 2012-06-24 00:174608 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{F834C417-BD91-11E1-94E8-902B343164A9}.dat
+ 2012-06-24 00:00 . 2012-06-24 00:004608 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{A47F4950-BD8F-11E1-AB7D-902B343164A9}.dat
+ 2012-06-24 00:20 . 2012-06-24 00:245120 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{629E0258-BD92-11E1-94E8-902B343164A9}.dat
+ 2012-06-24 00:17 . 2012-06-24 00:176144 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{F834C419-BD91-11E1-94E8-902B343164A9}.dat
+ 2012-06-24 00:00 . 2012-06-24 00:004096 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{A47F4951-BD8F-11E1-AB7D-902B343164A9}.dat
+ 2012-06-20 08:43 . 2012-06-24 00:495338 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-901204113-2561923739-3919432305-1000_UserData.bin
+ 2012-06-24 01:04 . 2012-06-24 01:042048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-06-23 19:52 . 2012-06-23 19:522048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-06-21 02:02 . 2010-11-20 12:08833024 c:\windows\SysWOW64\user32.dll
+ 2009-07-14 04:54 . 2012-06-24 00:28147456 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-06-24 00:20 . 2012-06-24 00:24185856 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{629E0259-BD92-11E1-94E8-902B343164A9}.dat
- 2009-07-14 02:36 . 2012-06-23 06:10623940 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-06-24 00:53623940 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2012-06-23 06:10106316 c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2012-06-24 00:53106316 c:\windows\system32\perfc009.dat
- 2009-07-14 05:01 . 2012-06-23 19:52316832 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-06-24 01:04316832 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-06-22 23:11 . 2012-06-24 00:281146880 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat
- 2009-07-14 04:54 . 2012-06-23 19:411458176 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-06-24 00:281458176 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-06-24 00:282146304 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-06-21 06:00 . 2012-06-24 01:041964838 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-901204113-2561923739-3919432305-1000-12288.dat
+ 2012-06-22 23:27 . 2012-06-24 00:283428264 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-18-16384.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0F3DC9E0-C459-4a40-BCF8-747BD9322E10}"= "c:\program files (x86)\Splashtop\Splashtop Connect IE\AddressBarSearch.dll" [2011-08-29 165776]
.
[HKEY_CLASSES_ROOT\clsid\{0f3dc9e0-c459-4a40-bcf8-747bd9322e10}]
[HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{4E8E0178-00EF-413d-9324-E7B3E31572E3}]
[HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-06-21 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ZyngaGamesAgent"="c:\program files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" [2010-11-15 841544]
"STCAgent"="c:\program files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe" [2011-08-29 771968]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2012-01-12 5028464]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-11-30 284440]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-01-27 291608]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"ASUSWebStorage"="c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\AsusWSPanel.exe" [2012-05-17 3417984]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2009-12-15 103720]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UCam_Menu"="c:\program files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2009-02-18 218408]
"LGODDFU"="c:\program files (x86)\lg_fwupdate\fwupdate.exe" [2012-06-22 557056]
"UpdatePSTShortCut"="c:\program files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2010-04-20 222504]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"PWRISOVM.EXE"="g:\program files (x86)\PowerISO\PWRISOVM.EXE" [2009-07-27 180224]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
c:\users\Skilz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2012-6-13 1014112]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2012-1-8 107720]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\appinit_dll.dll
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-11-30 13592]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-12-16 363800]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-23 250056]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;c:\program files\BitComet\tools\BitCometService.exe [2010-12-28 1296728]
R3 cphs;Intel(R) Content Protection HECI Service;c:\windows\SysWow64\IntelCpHeciSvc.exe [2012-01-12 274200]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2012-06-21 30528]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2011-08-30 160256]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-14 113120]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1307010.005\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1307010.005\SYMEFA64.SYS [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120619.001\BHDrvx64.sys [2012-06-19 1161376]
S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1307010.005\ccSetx64.sys [x]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120622.001\IDSvia64.sys [2012-06-22 509088]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1307010.005\Ironx64.SYS [x]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1307010.005\SYMNETS.SYS [x]
S1 VirtDiskBus;3TB+ Unlock;c:\windows\system32\DRIVERS\VirtDiskBus64.sys [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2011-12-08 607456]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2011-12-16 161560]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\19.7.1.5\ccSvcHst.exe [2012-03-27 138232]
S2 SCBackService;Splashtop Connect Service;c:\program files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000]
S2 SplashtopRemoteService;Splashtop® Remote Service;c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe [2012-02-21 531328]
S2 SSUService;Splashtop Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe [2012-03-15 370504]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-05-15 382272]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-06-23 138912]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x]
S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
S3 VirtuWDDM;VirtuWDDM;c:\windows\system32\DRIVERS\VirtuWDDM.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-20 06:37]
.
2012-06-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-901204113-2561923739-3919432305-1000Core.job
- c:\users\Skilz\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-20 08:25]
.
2012-06-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-901204113-2561923739-3919432305-1000UA.job
- c:\users\Skilz\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-20 08:25]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2012-03-13 09:231500672----a-w-c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2012-03-13 09:231500672----a-w-c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_U]
@="{1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D}"
[HKEY_CLASSES_ROOT\CLSID\{1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D}]
2012-03-13 09:231500672----a-w-c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-01-12 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-01-12 398104]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-01-12 440600]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\appinit_dll.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Skilz\AppData\Roaming\Mozilla\Firefox\Profiles\ex5f8rp2.TonyGotSkilz-home\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://insite.bridgepoint.local/dept/bts/Applications/Engineering%20Dashboard.aspx
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?q=
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.7.1.5\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\19.7.1.5\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{0E5680D1-BF44-4929-94AF-FD30D784AD1D}"=hex:51,66,7a,6c,4c,1d,38,12,bf,83,45,
0a,76,f1,47,0c,eb,b9,be,70,d2,da,e9,09
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}"=hex:51,66,7a,6c,4c,1d,38,12,0c,e0,e4,
3d,b8,cc,34,0e,c3,b9,18,39,ba,81,ae,74
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:2d,4c,9d,4a,cc,50,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,dc,3e,10,8d,e5,39,1d,40,bf,f8,c9,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,dc,3e,10,8d,e5,39,1d,40,bf,f8,c9,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Program Files (x86)\\GIGABYTE\\ET6\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Program Files (x86)\\GIGABYTE\\ET6\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Program Files (x86)\\GIGABYTE\\ET6\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Program Files (x86)\\GIGABYTE\\ET6\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\SysWOW64\nlssrv32.exe
c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRSOOBE.exe
.
**************************************************************************
.
Completion time: 2012-06-23 18:05:41 - machine was rebooted
ComboFix-quarantined-files.txt 2012-06-24 01:05
ComboFix2.txt 2012-06-23 23:21
ComboFix3.txt 2012-06-23 20:21
ComboFix4.txt 2012-06-23 19:54
ComboFix5.txt 2012-06-24 01:00
.
Pre-Run: 130,420,887,552 bytes free
Post-Run: 130,289,336,320 bytes free
.
- - End Of File - - 8F63E37F3B7AA3A5C185FEF17C390E63
 
Excellent!!

Last scans....

1. Download Security Check from HERE, and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

    NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.

2. Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


3. Download Temp File Cleaner (TFC)
  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.


4. Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click on List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • NOTE. If Eset won't find any threats, it won't produce any log.
 
Results of screen317's Security Check version 0.99.24
Windows 7 x64 (UAC is disabled!)
Internet Explorer 9
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
Norton Internet Security
[size=1]WMI entry may not exist for antivirus; attempting automatic update.[/size]
```````````````````````````````
Anti-malware/Other Utilities Check:

JavaFX 2.1.1
Java(TM) 7 Update 5
Out of date Java installed!
Adobe Flash Player11.3.300.262
````````````````````````````````
Process Check:
objlist.exe by Laurent

Norton ccSvcHst.exe
Malwarebytes' Anti-Malware mbamservice.exe
``````````End of Log````````````
 
Farbar Service Scanner Version: 23-06-2012
Ran by Skilz (administrator) on 23-06-2012 at 18:19:14
Running from "C:\Users\Skilz\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is OK.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.
Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log ****
 
C:\FRST\Quarantine\user32.dllWin32/Patched.NBG.Gen trojancleaned - quarantined
C:\Qoobox\Quarantine\C\Windows\SysWOW64\user32.dll.virWin32/Patched.NBG.Gen trojancleaned - quarantined
G:\Storage\Cracked & backups\ms office 2k3\Office2003.isoprobably a variant of Win32/Agent.CNVAOQK trojandeleted - quarantined
G:\Storage\Movies\android\Porn\sys32\aircrack-ng-win-0.9.1\bin\airodump-ng.exeprobably a variant of Win32/Agent.HCTERPB trojancleaned by deleting - quarantined
 
Uninstall JavaFX 2.1.1.

===================================================

Your computer is clean

1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following:

Code:
:OTL
:Commands
[purity]
[emptytemp]
[EMPTYFLASH]
[emptyjava]
[CLEARALLRESTOREPOINTS]
[Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Post resulting log.

2. Now, we'll remove all tools, we used during our cleaning process

Clean up with OTL:

  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

3. Make sure, Windows Updates are current.

4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

7. Run Temporary File Cleaner (TFC) weekly.

8. Download and install Secunia Personal Software Inspector (PSI): https://www.techspot.com/downloads/4898-secunia-personal-software-inspector-psi.html. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

10. (Windows XP only) Run defrag at your convenience.

11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

13. Please, let me know, how your computer is doing.
 
All processes killed
========== OTL ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: Skilz
->Temp folder emptied: 25859 bytes
->Temporary Internet Files folder emptied: 11621764 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 161991561 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 1992 bytes

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 608 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 166.00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: Skilz
->Flash cache emptied: 0 bytes

User: UpdatusUser

Total Flash Files Cleaned = 0.00 mb


[EMPTYJAVA]

User: All Users

User: Default

User: Default User

User: Public

User: Skilz
->Java cache emptied: 0 bytes

User: UpdatusUser

Total Java Files Cleaned = 0.00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.53.0 log created on 06232012_211815

Files\Folders moved on Reboot...
C:\Users\Skilz\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...
File C:\Users\Skilz\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!

Registry entries deleted on Reboot...
 
Thanks for all your help. Everything seems to be running well now. I guess its time to systematically change all my passwords everywhere. This should be fun, haha.
 
Way to go!!
p4193510.gif

Good luck and stay safe :)
 
Back