darca
Posts: 46 +0
Hi
I'm having problem with this kind of threat. It's attacked services.exe in C:\Windows\System32
I'm running on Win7 Ultimate
malwarebyte dosen't find anything
theres GMER log
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-07-16 15:40:51
Windows 6.1.7601 Service Pack 1
Running: njwg4zun.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a20-9b1a-11d4-9123-0050047759bc}\4
Reg HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a20-9b1a-11d4-9123-0050047759bc}\6
Reg HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a20-9b1a-11d4-9123-0050047759bc}\6@ 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a20-9b1a-11d4-9123-0050047759bc}\7
Reg HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a20-9b1a-11d4-9123-0050047759bc}\7@0000000000001800 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a20-9b1a-11d4-9123-0050047759bc}\7@000000000000f300 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a20-9b1a-11d4-9123-0050047759bc}\7@0000000600000600 0x00 0x00 0x00 0x00 ...
---- EOF - GMER 1.0.15 ----
here DDS
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1
Run by Darca at 15:44:38 on 2012-07-16
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.48.1045.18.8159.6820 [GMT 2:00]
.
AV: ESET NOD32 Antivirus 5.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\ProgramData\DatacardService\DCService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files (x86)\Last.fm\LastFM.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\splwow64.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
uRun: [Steam] "D:\gry\Steam\Steam.exe" -silent
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
StartupFolder: C:\Users\Darca\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\LASTFM~1.LNK - C:\Program Files (x86)\Last.fm\LastFM.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
LSP: mswsock.dll
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{5CC821B3-7C4C-4A27-A03C-4652ACCC592A} : NameServer = 89.108.195.21 89.108.202.21
TCP: Interfaces\{98417DC1-FE25-4800-AB1A-7B7D8B946391} : NameServer = 89.108.195.21 89.108.202.21
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Darca\AppData\Roaming\Mozilla\Firefox\Profiles\jbcktsh5.default\
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
FF - plugin: C:\Users\Darca\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R1 eamonm;eamonm;C:\Windows\system32\DRIVERS\eamonm.sys --> C:\Windows\system32\DRIVERS\eamonm.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 DCService.exe;DCService.exe;C:\ProgramData\DatacardService\DCService.exe [2010-5-8 229376]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2012-3-7 913144]
R2 epfwwfpr;epfwwfpr;C:\Windows\system32\DRIVERS\epfwwfpr.sys --> C:\Windows\system32\DRIVERS\epfwwfpr.sys [?]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-7-10 1262400]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-5-15 382272]
R3 huawei_enumerator;huawei_enumerator;C:\Windows\system32\DRIVERS\ew_jubusenum.sys --> C:\Windows\system32\DRIVERS\ew_jubusenum.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface ;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-7-10 250056]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;C:\Windows\system32\DRIVERS\ew_hwusbdev.sys --> C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [?]
S3 ewusbnet;HUAWEI USB-NDIS miniport;C:\Windows\system32\DRIVERS\ewusbnet.sys --> C:\Windows\system32\DRIVERS\ewusbnet.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-7-10 113120]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\system32\drivers\synth3dvsc.sys --> C:\Windows\system32\drivers\synth3dvsc.sys [?]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys --> C:\Windows\system32\drivers\terminpt.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 tsusbhub;tsusbhub;C:\Windows\system32\drivers\tsusbhub.sys --> C:\Windows\system32\drivers\tsusbhub.sys [?]
.
=============== Created Last 30 ================
.
2012-07-16 12:30:53--------d-----w-C:\Users\Darca\AppData\Roaming\Malwarebytes
2012-07-16 12:30:39--------d-----w-C:\ProgramData\Malwarebytes
2012-07-16 12:30:3824904----a-w-C:\Windows\System32\drivers\mbam.sys
2012-07-16 12:30:38--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-15 19:06:42--------d-sh--w-C:\$RECYCLE.BIN
2012-07-15 13:09:26--------d-----w-C:\Users\Darca\AppData\Local\ESET
2012-07-14 17:45:07--------d-----w-C:\Users\Darca\AppData\Local\Adobe
2012-07-13 17:02:30--------d-----w-C:\Users\Darca\AppData\Local\ElevatedDiagnostics
2012-07-13 17:00:56178800----a-w-C:\Windows\SysWow64\CmdLineExt_x64.dll
2012-07-13 16:57:175632----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2012-07-13 16:53:36749568----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2012-07-13 16:53:3669715----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2012-07-13 16:53:3632768----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2012-07-13 16:53:36323716----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2012-07-13 16:53:36274432----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2012-07-13 16:53:36192644----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2012-07-13 16:53:36180224----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2012-07-13 15:20:41--------d-----w-C:\Users\Darca\AppData\Roaming\Beat Hazard
2012-07-13 06:49:2383456----a-w-C:\Windows\System32\drivers\ew_jubusenum.sys
2012-07-13 06:49:2378848----a-w-C:\Windows\System32\drivers\ew_jucdcacm.sys
2012-07-13 06:49:2354784----a-w-C:\Windows\System32\drivers\ew_jucdcecm.sys
2012-07-13 06:49:2329696----a-w-C:\Windows\System32\drivers\ew_juextctrl.sys
2012-07-13 06:49:23195584----a-w-C:\Windows\System32\drivers\ew_juwwanecm.sys
2012-07-13 06:49:1932768----a-w-C:\Windows\System32\drivers\ewdcsc.sys
2012-07-13 06:49:19252928----a-w-C:\Windows\System32\drivers\ewusbnet.sys
2012-07-13 06:49:1913952----a-w-C:\Windows\System32\drivers\ew_usbenumfilter.sys
2012-07-13 06:49:19120704----a-w-C:\Windows\System32\drivers\ewusbmdm.sys
2012-07-13 06:49:13114560----a-w-C:\Windows\System32\drivers\ew_hwusbdev.sys
2012-07-13 06:18:42--------d-----w-C:\Users\Darca\AppData\Roaming\LolClient
2012-07-12 13:59:16--------d-----w-C:\Users\Darca\AppData\Local\id Software
2012-07-12 13:52:51--------d-sh--w-C:\Windows\ftpcache
2012-07-11 15:28:18--------d-----w-C:\ProgramData\Last.fm
2012-07-11 02:40:22--------d-----w-C:\Users\Darca\AppData\Roaming\NapiProjekt
2012-07-11 02:40:20--------d-----w-C:\Program Files (x86)\NapiProjekt
2012-07-10 19:03:03--------d-----w-C:\Users\Darca\AppData\Local\FalloutNV
2012-07-10 03:39:08--------d-----w-C:\Program Files (x86)\Damian Pasternak
2012-07-10 01:40:35519000----a-w-C:\Windows\System32\d3dx10_40.dll
2012-07-10 01:40:35452440----a-w-C:\Windows\SysWow64\d3dx10_40.dll
2012-07-10 01:40:352605920----a-w-C:\Windows\System32\D3DCompiler_40.dll
2012-07-10 01:40:352036576----a-w-C:\Windows\SysWow64\D3DCompiler_40.dll
2012-07-10 01:40:345631312----a-w-C:\Windows\System32\D3DX9_40.dll
2012-07-10 01:40:344379984----a-w-C:\Windows\SysWow64\D3DX9_40.dll
2012-07-10 01:11:47197912----a-w-C:\Windows\SysWow64\physxcudart_20.dll
2012-07-10 01:11:42197912----a-w-C:\Windows\System32\physxcudart_20.dll
2012-07-10 01:10:35--------d-----w-C:\Users\Darca\AppData\Roaming\NVIDIA
2012-07-10 00:51:05283200----a-w-C:\Windows\System32\drivers\dtsoftbus01.sys
2012-07-10 00:51:03--------d-----w-C:\Users\Darca\AppData\Roaming\DAEMON Tools Lite
2012-07-10 00:51:02--------d-----w-C:\Program Files (x86)\DAEMON Tools Lite
2012-07-10 00:50:29--------d-----w-C:\ProgramData\DAEMON Tools Lite
2012-07-09 23:53:44--------d-----w-C:\Users\Darca\AppData\Roaming\uTorrent
2012-07-09 23:46:32466456----a-w-C:\Windows\System32\wrap_oal.dll
2012-07-09 23:46:32444952----a-w-C:\Windows\SysWow64\wrap_oal.dll
2012-07-09 23:46:32122904----a-w-C:\Windows\System32\OpenAL32.dll
2012-07-09 23:46:32109080----a-w-C:\Windows\SysWow64\OpenAL32.dll
2012-07-09 23:46:32--------d-----w-C:\Program Files (x86)\OpenAL
2012-07-09 23:45:04--------d-----w-C:\Program Files (x86)\Common Files\Steam
2012-07-09 23:42:00--------d-----w-C:\Program Files\ESET
2012-07-09 23:30:595554512----a-w-C:\Windows\System32\d3dcsx_42.dll
2012-07-09 23:23:28--------d-----w-C:\Windows\SysWow64\directx
2012-07-09 23:22:49--------d-----w-C:\Users\Darca\AppData\Local\Macromedia
2012-07-09 23:14:072414360----a-w-C:\Windows\SysWow64\d3dx9_31.dll
2012-07-09 23:14:071892184----a-w-C:\Windows\SysWow64\D3DX9_42.dll
2012-07-09 23:13:37--------d-----w-C:\Program Files (x86)\Common Files\PX Storage Engine
2012-07-09 23:10:4792160----a-w-C:\Windows\System32\ff_vfw.dll
2012-07-09 23:10:47206336----a-w-C:\Windows\System32\unrar.dll
2012-07-09 23:10:46--------d-----w-C:\Program Files\K-Lite Codec Pack x64
2012-07-09 23:09:45650752----a-w-C:\Windows\SysWow64\xvidcore.dll
2012-07-09 23:09:45243200----a-w-C:\Windows\SysWow64\xvidvfw.dll
2012-07-09 23:09:45178688----a-w-C:\Windows\SysWow64\unrar.dll
2012-07-09 23:09:45151552----a-w-C:\Windows\SysWow64\ac3acm.acm
2012-07-09 23:09:4479872----a-w-C:\Windows\SysWow64\ff_vfw.dll
2012-07-09 23:09:43--------d-----w-C:\Program Files (x86)\K-Lite Codec Pack
2012-07-09 23:05:51889664----a-w-C:\Windows\System32\nvvsvc.exe
2012-07-09 23:05:5163296----a-w-C:\Windows\System32\nvshext.dll
2012-07-09 23:05:516151488----a-w-C:\Windows\System32\nvcpl.dll
2012-07-09 23:05:513149632----a-w-C:\Windows\System32\nvsvc64.dll
2012-07-09 23:05:512621723----a-w-C:\Windows\System32\nvcoproc.bin
2012-07-09 23:05:512561856----a-w-C:\Windows\System32\nvsvcr.dll
2012-07-09 23:05:51118080----a-w-C:\Windows\System32\nvmctray.dll
2012-07-09 23:03:33--------d-----w-C:\Users\Darca\AppData\Roaming\foobar2000
2012-07-09 23:03:21--------d-----w-C:\NVIDIA
2012-07-09 22:59:14--------d-----w-C:\Program Files (x86)\foobar2000
2012-07-09 22:47:50--------d-----w-C:\Program Files\Defraggler
2012-07-09 22:47:19--------d-----w-C:\Program Files (x86)\VS Revo Group
2012-07-09 22:44:33--------d-----w-C:\Program Files\CCleaner
2012-07-09 22:43:4470344----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-09 22:43:44426184----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
2012-07-09 22:41:32--------d-----w-C:\Program Files (x86)\Oracle
2012-07-09 22:41:11772504----a-w-C:\Windows\SysWow64\npDeployJava1.dll
2012-07-09 22:41:11687504----a-w-C:\Windows\SysWow64\deployJava1.dll
2012-07-09 22:40:39--------d-sh--w-C:\Windows\Installer
2012-07-09 22:29:29--------d-----w-C:\Program Files (x86)\Audacity
2012-07-09 22:22:56--------d-----w-C:\ProgramData\NVIDIA Corporation
2012-07-09 22:22:55--------d-----w-C:\Program Files\NVIDIA Corporation
2012-07-09 22:22:55--------d-----w-C:\Program Files (x86)\NVIDIA Corporation
2012-07-09 22:21:528199504----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-07-09 22:21:489013136----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B00918FB-8FB1-4730-A484-67C185B86594}\mpengine.dll
2012-07-09 22:18:53--------d-----w-C:\Users\Darca\AppData\Local\Last.fm
2012-07-09 22:18:52--------d-----w-C:\Program Files (x86)\Last.fm
2012-07-09 22:14:50861696----a-w-C:\Windows\System32\oleaut32.dll
2012-07-09 22:14:50571904----a-w-C:\Windows\SysWow64\oleaut32.dll
2012-07-09 22:14:50331776----a-w-C:\Windows\System32\oleacc.dll
2012-07-09 22:14:50233472----a-w-C:\Windows\SysWow64\oleacc.dll
2012-07-09 22:14:43976896----a-w-C:\Windows\System32\inetcomm.dll
2012-07-09 22:14:43741376----a-w-C:\Windows\SysWow64\inetcomm.dll
2012-07-09 22:14:32690688----a-w-C:\Windows\SysWow64\msvcrt.dll
2012-07-09 22:14:32634880----a-w-C:\Windows\System32\msvcrt.dll
2012-07-09 22:13:40936960----a-w-C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2012-07-09 22:13:401732096----a-w-C:\Program Files\Windows Journal\NBDoc.DLL
2012-07-09 22:13:401402880----a-w-C:\Program Files\Windows Journal\JNWDRV.dll
2012-07-09 22:13:401393664----a-w-C:\Program Files\Windows Journal\JNTFiltr.dll
2012-07-09 22:13:401367552----a-w-C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2012-07-09 22:13:372048----a-w-C:\Windows\SysWow64\tzres.dll
2012-07-09 22:13:372048----a-w-C:\Windows\System32\tzres.dll
2012-07-09 22:13:011918320----a-w-C:\Windows\System32\drivers\tcpip.sys
2012-07-09 22:12:47723456----a-w-C:\Windows\System32\EncDec.dll
2012-07-09 22:12:47534528----a-w-C:\Windows\SysWow64\EncDec.dll
2012-07-09 22:12:471731920----a-w-C:\Windows\System32\ntdll.dll
2012-07-09 22:12:471292080----a-w-C:\Windows\SysWow64\ntdll.dll
2012-07-09 22:10:2277312----a-w-C:\Windows\System32\packager.dll
2012-07-09 22:10:2267072----a-w-C:\Windows\SysWow64\packager.dll
2012-07-09 22:03:39--------d-----w-C:\Users\Darca\AppData\Local\Google
2012-07-09 22:03:12--------d-----w-C:\Users\Darca\AppData\Local\Apps
2012-07-09 22:03:11--------d-----w-C:\Users\Darca\AppData\Local\Deployment
2012-07-09 22:02:482622464----a-w-C:\Windows\System32\wucltux.dll
2012-07-09 22:02:3999840----a-w-C:\Windows\System32\wudriver.dll
2012-07-09 22:02:2936864----a-w-C:\Windows\System32\wuapp.exe
2012-07-09 22:02:29186752----a-w-C:\Windows\System32\wuwebv.dll
2012-07-09 21:56:021721576----a-w-C:\Windows\System32\WdfCoInstaller01009.dll
2012-07-09 21:56:021721576----a-w-C:\Windows\System32\drivers\WdfCoInstaller01009.dll
2012-07-09 21:55:49--------d-----w-C:\Program Files (x86)\PLAY ONLINE
2012-07-09 21:54:55--------d-----w-C:\ProgramData\DatacardService
2012-07-09 11:44:30--------d-----w-C:\Windows\Panther
2012-07-09 11:44:16--------d-----w-C:\Boot
.
==================== Find3M ====================
.
2012-05-31 10:25:12279656------w-C:\Windows\System32\MpSigStub.exe
2012-05-18 02:06:482311680----a-w-C:\Windows\System32\jscript9.dll
2012-05-18 01:59:141392128----a-w-C:\Windows\System32\wininet.dll
2012-05-18 01:58:391494528----a-w-C:\Windows\System32\inetcpl.cpl
2012-05-18 01:55:22173056----a-w-C:\Windows\System32\ieUnatt.exe
2012-05-18 01:51:302382848----a-w-C:\Windows\System32\mshtml.tlb
2012-05-17 22:45:371800192----a-w-C:\Windows\SysWow64\jscript9.dll
2012-05-17 22:35:471129472----a-w-C:\Windows\SysWow64\wininet.dll
2012-05-17 22:35:391427968----a-w-C:\Windows\SysWow64\inetcpl.cpl
2012-05-17 22:29:45142848----a-w-C:\Windows\SysWow64\ieUnatt.exe
2012-05-17 22:24:452382848----a-w-C:\Windows\SysWow64\mshtml.tlb
2012-05-15 00:21:50423744----a-w-C:\Windows\SysWow64\nvStreaming.exe
2012-04-18 17:08:0831040----a-w-C:\Windows\System32\nvhdap64.dll
2012-04-18 17:08:03188736----a-w-C:\Windows\System32\drivers\nvhda64v.sys
2012-04-18 17:08:021451840----a-w-C:\Windows\System32\nvhdagenco6420103.dll
.
============= FINISH: 15:44:47,64 ===============
Please help ASAP
I'm having problem with this kind of threat. It's attacked services.exe in C:\Windows\System32
I'm running on Win7 Ultimate
malwarebyte dosen't find anything
theres GMER log
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-07-16 15:40:51
Windows 6.1.7601 Service Pack 1
Running: njwg4zun.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a20-9b1a-11d4-9123-0050047759bc}\4
Reg HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a20-9b1a-11d4-9123-0050047759bc}\6
Reg HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a20-9b1a-11d4-9123-0050047759bc}\6@ 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a20-9b1a-11d4-9123-0050047759bc}\7
Reg HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a20-9b1a-11d4-9123-0050047759bc}\7@0000000000001800 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a20-9b1a-11d4-9123-0050047759bc}\7@000000000000f300 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a20-9b1a-11d4-9123-0050047759bc}\7@0000000600000600 0x00 0x00 0x00 0x00 ...
---- EOF - GMER 1.0.15 ----
here DDS
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1
Run by Darca at 15:44:38 on 2012-07-16
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.48.1045.18.8159.6820 [GMT 2:00]
.
AV: ESET NOD32 Antivirus 5.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\ProgramData\DatacardService\DCService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files (x86)\Last.fm\LastFM.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\splwow64.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
uRun: [Steam] "D:\gry\Steam\Steam.exe" -silent
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
StartupFolder: C:\Users\Darca\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\LASTFM~1.LNK - C:\Program Files (x86)\Last.fm\LastFM.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
LSP: mswsock.dll
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{5CC821B3-7C4C-4A27-A03C-4652ACCC592A} : NameServer = 89.108.195.21 89.108.202.21
TCP: Interfaces\{98417DC1-FE25-4800-AB1A-7B7D8B946391} : NameServer = 89.108.195.21 89.108.202.21
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Darca\AppData\Roaming\Mozilla\Firefox\Profiles\jbcktsh5.default\
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
FF - plugin: C:\Users\Darca\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R1 eamonm;eamonm;C:\Windows\system32\DRIVERS\eamonm.sys --> C:\Windows\system32\DRIVERS\eamonm.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 DCService.exe;DCService.exe;C:\ProgramData\DatacardService\DCService.exe [2010-5-8 229376]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2012-3-7 913144]
R2 epfwwfpr;epfwwfpr;C:\Windows\system32\DRIVERS\epfwwfpr.sys --> C:\Windows\system32\DRIVERS\epfwwfpr.sys [?]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-7-10 1262400]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-5-15 382272]
R3 huawei_enumerator;huawei_enumerator;C:\Windows\system32\DRIVERS\ew_jubusenum.sys --> C:\Windows\system32\DRIVERS\ew_jubusenum.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface ;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-7-10 250056]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;C:\Windows\system32\DRIVERS\ew_hwusbdev.sys --> C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [?]
S3 ewusbnet;HUAWEI USB-NDIS miniport;C:\Windows\system32\DRIVERS\ewusbnet.sys --> C:\Windows\system32\DRIVERS\ewusbnet.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-7-10 113120]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\system32\drivers\synth3dvsc.sys --> C:\Windows\system32\drivers\synth3dvsc.sys [?]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys --> C:\Windows\system32\drivers\terminpt.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 tsusbhub;tsusbhub;C:\Windows\system32\drivers\tsusbhub.sys --> C:\Windows\system32\drivers\tsusbhub.sys [?]
.
=============== Created Last 30 ================
.
2012-07-16 12:30:53--------d-----w-C:\Users\Darca\AppData\Roaming\Malwarebytes
2012-07-16 12:30:39--------d-----w-C:\ProgramData\Malwarebytes
2012-07-16 12:30:3824904----a-w-C:\Windows\System32\drivers\mbam.sys
2012-07-16 12:30:38--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-15 19:06:42--------d-sh--w-C:\$RECYCLE.BIN
2012-07-15 13:09:26--------d-----w-C:\Users\Darca\AppData\Local\ESET
2012-07-14 17:45:07--------d-----w-C:\Users\Darca\AppData\Local\Adobe
2012-07-13 17:02:30--------d-----w-C:\Users\Darca\AppData\Local\ElevatedDiagnostics
2012-07-13 17:00:56178800----a-w-C:\Windows\SysWow64\CmdLineExt_x64.dll
2012-07-13 16:57:175632----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2012-07-13 16:53:36749568----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2012-07-13 16:53:3669715----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2012-07-13 16:53:3632768----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2012-07-13 16:53:36323716----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2012-07-13 16:53:36274432----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2012-07-13 16:53:36192644----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2012-07-13 16:53:36180224----a-w-C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2012-07-13 15:20:41--------d-----w-C:\Users\Darca\AppData\Roaming\Beat Hazard
2012-07-13 06:49:2383456----a-w-C:\Windows\System32\drivers\ew_jubusenum.sys
2012-07-13 06:49:2378848----a-w-C:\Windows\System32\drivers\ew_jucdcacm.sys
2012-07-13 06:49:2354784----a-w-C:\Windows\System32\drivers\ew_jucdcecm.sys
2012-07-13 06:49:2329696----a-w-C:\Windows\System32\drivers\ew_juextctrl.sys
2012-07-13 06:49:23195584----a-w-C:\Windows\System32\drivers\ew_juwwanecm.sys
2012-07-13 06:49:1932768----a-w-C:\Windows\System32\drivers\ewdcsc.sys
2012-07-13 06:49:19252928----a-w-C:\Windows\System32\drivers\ewusbnet.sys
2012-07-13 06:49:1913952----a-w-C:\Windows\System32\drivers\ew_usbenumfilter.sys
2012-07-13 06:49:19120704----a-w-C:\Windows\System32\drivers\ewusbmdm.sys
2012-07-13 06:49:13114560----a-w-C:\Windows\System32\drivers\ew_hwusbdev.sys
2012-07-13 06:18:42--------d-----w-C:\Users\Darca\AppData\Roaming\LolClient
2012-07-12 13:59:16--------d-----w-C:\Users\Darca\AppData\Local\id Software
2012-07-12 13:52:51--------d-sh--w-C:\Windows\ftpcache
2012-07-11 15:28:18--------d-----w-C:\ProgramData\Last.fm
2012-07-11 02:40:22--------d-----w-C:\Users\Darca\AppData\Roaming\NapiProjekt
2012-07-11 02:40:20--------d-----w-C:\Program Files (x86)\NapiProjekt
2012-07-10 19:03:03--------d-----w-C:\Users\Darca\AppData\Local\FalloutNV
2012-07-10 03:39:08--------d-----w-C:\Program Files (x86)\Damian Pasternak
2012-07-10 01:40:35519000----a-w-C:\Windows\System32\d3dx10_40.dll
2012-07-10 01:40:35452440----a-w-C:\Windows\SysWow64\d3dx10_40.dll
2012-07-10 01:40:352605920----a-w-C:\Windows\System32\D3DCompiler_40.dll
2012-07-10 01:40:352036576----a-w-C:\Windows\SysWow64\D3DCompiler_40.dll
2012-07-10 01:40:345631312----a-w-C:\Windows\System32\D3DX9_40.dll
2012-07-10 01:40:344379984----a-w-C:\Windows\SysWow64\D3DX9_40.dll
2012-07-10 01:11:47197912----a-w-C:\Windows\SysWow64\physxcudart_20.dll
2012-07-10 01:11:42197912----a-w-C:\Windows\System32\physxcudart_20.dll
2012-07-10 01:10:35--------d-----w-C:\Users\Darca\AppData\Roaming\NVIDIA
2012-07-10 00:51:05283200----a-w-C:\Windows\System32\drivers\dtsoftbus01.sys
2012-07-10 00:51:03--------d-----w-C:\Users\Darca\AppData\Roaming\DAEMON Tools Lite
2012-07-10 00:51:02--------d-----w-C:\Program Files (x86)\DAEMON Tools Lite
2012-07-10 00:50:29--------d-----w-C:\ProgramData\DAEMON Tools Lite
2012-07-09 23:53:44--------d-----w-C:\Users\Darca\AppData\Roaming\uTorrent
2012-07-09 23:46:32466456----a-w-C:\Windows\System32\wrap_oal.dll
2012-07-09 23:46:32444952----a-w-C:\Windows\SysWow64\wrap_oal.dll
2012-07-09 23:46:32122904----a-w-C:\Windows\System32\OpenAL32.dll
2012-07-09 23:46:32109080----a-w-C:\Windows\SysWow64\OpenAL32.dll
2012-07-09 23:46:32--------d-----w-C:\Program Files (x86)\OpenAL
2012-07-09 23:45:04--------d-----w-C:\Program Files (x86)\Common Files\Steam
2012-07-09 23:42:00--------d-----w-C:\Program Files\ESET
2012-07-09 23:30:595554512----a-w-C:\Windows\System32\d3dcsx_42.dll
2012-07-09 23:23:28--------d-----w-C:\Windows\SysWow64\directx
2012-07-09 23:22:49--------d-----w-C:\Users\Darca\AppData\Local\Macromedia
2012-07-09 23:14:072414360----a-w-C:\Windows\SysWow64\d3dx9_31.dll
2012-07-09 23:14:071892184----a-w-C:\Windows\SysWow64\D3DX9_42.dll
2012-07-09 23:13:37--------d-----w-C:\Program Files (x86)\Common Files\PX Storage Engine
2012-07-09 23:10:4792160----a-w-C:\Windows\System32\ff_vfw.dll
2012-07-09 23:10:47206336----a-w-C:\Windows\System32\unrar.dll
2012-07-09 23:10:46--------d-----w-C:\Program Files\K-Lite Codec Pack x64
2012-07-09 23:09:45650752----a-w-C:\Windows\SysWow64\xvidcore.dll
2012-07-09 23:09:45243200----a-w-C:\Windows\SysWow64\xvidvfw.dll
2012-07-09 23:09:45178688----a-w-C:\Windows\SysWow64\unrar.dll
2012-07-09 23:09:45151552----a-w-C:\Windows\SysWow64\ac3acm.acm
2012-07-09 23:09:4479872----a-w-C:\Windows\SysWow64\ff_vfw.dll
2012-07-09 23:09:43--------d-----w-C:\Program Files (x86)\K-Lite Codec Pack
2012-07-09 23:05:51889664----a-w-C:\Windows\System32\nvvsvc.exe
2012-07-09 23:05:5163296----a-w-C:\Windows\System32\nvshext.dll
2012-07-09 23:05:516151488----a-w-C:\Windows\System32\nvcpl.dll
2012-07-09 23:05:513149632----a-w-C:\Windows\System32\nvsvc64.dll
2012-07-09 23:05:512621723----a-w-C:\Windows\System32\nvcoproc.bin
2012-07-09 23:05:512561856----a-w-C:\Windows\System32\nvsvcr.dll
2012-07-09 23:05:51118080----a-w-C:\Windows\System32\nvmctray.dll
2012-07-09 23:03:33--------d-----w-C:\Users\Darca\AppData\Roaming\foobar2000
2012-07-09 23:03:21--------d-----w-C:\NVIDIA
2012-07-09 22:59:14--------d-----w-C:\Program Files (x86)\foobar2000
2012-07-09 22:47:50--------d-----w-C:\Program Files\Defraggler
2012-07-09 22:47:19--------d-----w-C:\Program Files (x86)\VS Revo Group
2012-07-09 22:44:33--------d-----w-C:\Program Files\CCleaner
2012-07-09 22:43:4470344----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-09 22:43:44426184----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
2012-07-09 22:41:32--------d-----w-C:\Program Files (x86)\Oracle
2012-07-09 22:41:11772504----a-w-C:\Windows\SysWow64\npDeployJava1.dll
2012-07-09 22:41:11687504----a-w-C:\Windows\SysWow64\deployJava1.dll
2012-07-09 22:40:39--------d-sh--w-C:\Windows\Installer
2012-07-09 22:29:29--------d-----w-C:\Program Files (x86)\Audacity
2012-07-09 22:22:56--------d-----w-C:\ProgramData\NVIDIA Corporation
2012-07-09 22:22:55--------d-----w-C:\Program Files\NVIDIA Corporation
2012-07-09 22:22:55--------d-----w-C:\Program Files (x86)\NVIDIA Corporation
2012-07-09 22:21:528199504----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-07-09 22:21:489013136----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B00918FB-8FB1-4730-A484-67C185B86594}\mpengine.dll
2012-07-09 22:18:53--------d-----w-C:\Users\Darca\AppData\Local\Last.fm
2012-07-09 22:18:52--------d-----w-C:\Program Files (x86)\Last.fm
2012-07-09 22:14:50861696----a-w-C:\Windows\System32\oleaut32.dll
2012-07-09 22:14:50571904----a-w-C:\Windows\SysWow64\oleaut32.dll
2012-07-09 22:14:50331776----a-w-C:\Windows\System32\oleacc.dll
2012-07-09 22:14:50233472----a-w-C:\Windows\SysWow64\oleacc.dll
2012-07-09 22:14:43976896----a-w-C:\Windows\System32\inetcomm.dll
2012-07-09 22:14:43741376----a-w-C:\Windows\SysWow64\inetcomm.dll
2012-07-09 22:14:32690688----a-w-C:\Windows\SysWow64\msvcrt.dll
2012-07-09 22:14:32634880----a-w-C:\Windows\System32\msvcrt.dll
2012-07-09 22:13:40936960----a-w-C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2012-07-09 22:13:401732096----a-w-C:\Program Files\Windows Journal\NBDoc.DLL
2012-07-09 22:13:401402880----a-w-C:\Program Files\Windows Journal\JNWDRV.dll
2012-07-09 22:13:401393664----a-w-C:\Program Files\Windows Journal\JNTFiltr.dll
2012-07-09 22:13:401367552----a-w-C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2012-07-09 22:13:372048----a-w-C:\Windows\SysWow64\tzres.dll
2012-07-09 22:13:372048----a-w-C:\Windows\System32\tzres.dll
2012-07-09 22:13:011918320----a-w-C:\Windows\System32\drivers\tcpip.sys
2012-07-09 22:12:47723456----a-w-C:\Windows\System32\EncDec.dll
2012-07-09 22:12:47534528----a-w-C:\Windows\SysWow64\EncDec.dll
2012-07-09 22:12:471731920----a-w-C:\Windows\System32\ntdll.dll
2012-07-09 22:12:471292080----a-w-C:\Windows\SysWow64\ntdll.dll
2012-07-09 22:10:2277312----a-w-C:\Windows\System32\packager.dll
2012-07-09 22:10:2267072----a-w-C:\Windows\SysWow64\packager.dll
2012-07-09 22:03:39--------d-----w-C:\Users\Darca\AppData\Local\Google
2012-07-09 22:03:12--------d-----w-C:\Users\Darca\AppData\Local\Apps
2012-07-09 22:03:11--------d-----w-C:\Users\Darca\AppData\Local\Deployment
2012-07-09 22:02:482622464----a-w-C:\Windows\System32\wucltux.dll
2012-07-09 22:02:3999840----a-w-C:\Windows\System32\wudriver.dll
2012-07-09 22:02:2936864----a-w-C:\Windows\System32\wuapp.exe
2012-07-09 22:02:29186752----a-w-C:\Windows\System32\wuwebv.dll
2012-07-09 21:56:021721576----a-w-C:\Windows\System32\WdfCoInstaller01009.dll
2012-07-09 21:56:021721576----a-w-C:\Windows\System32\drivers\WdfCoInstaller01009.dll
2012-07-09 21:55:49--------d-----w-C:\Program Files (x86)\PLAY ONLINE
2012-07-09 21:54:55--------d-----w-C:\ProgramData\DatacardService
2012-07-09 11:44:30--------d-----w-C:\Windows\Panther
2012-07-09 11:44:16--------d-----w-C:\Boot
.
==================== Find3M ====================
.
2012-05-31 10:25:12279656------w-C:\Windows\System32\MpSigStub.exe
2012-05-18 02:06:482311680----a-w-C:\Windows\System32\jscript9.dll
2012-05-18 01:59:141392128----a-w-C:\Windows\System32\wininet.dll
2012-05-18 01:58:391494528----a-w-C:\Windows\System32\inetcpl.cpl
2012-05-18 01:55:22173056----a-w-C:\Windows\System32\ieUnatt.exe
2012-05-18 01:51:302382848----a-w-C:\Windows\System32\mshtml.tlb
2012-05-17 22:45:371800192----a-w-C:\Windows\SysWow64\jscript9.dll
2012-05-17 22:35:471129472----a-w-C:\Windows\SysWow64\wininet.dll
2012-05-17 22:35:391427968----a-w-C:\Windows\SysWow64\inetcpl.cpl
2012-05-17 22:29:45142848----a-w-C:\Windows\SysWow64\ieUnatt.exe
2012-05-17 22:24:452382848----a-w-C:\Windows\SysWow64\mshtml.tlb
2012-05-15 00:21:50423744----a-w-C:\Windows\SysWow64\nvStreaming.exe
2012-04-18 17:08:0831040----a-w-C:\Windows\System32\nvhdap64.dll
2012-04-18 17:08:03188736----a-w-C:\Windows\System32\drivers\nvhda64v.sys
2012-04-18 17:08:021451840----a-w-C:\Windows\System32\nvhdagenco6420103.dll
.
============= FINISH: 15:44:47,64 ===============
Please help ASAP