Hello There, Guest!
View New Posts  |  View Today's Posts
Big Problem

  • 0 Vote(s) - 0 Average


07-18-2012, 01:55 PM #1
Predator
Staff
*****
Moderators
Posts: 2,488 Threads:427 Joined: Jun 2011 Reputation: 11

Big Problem
Somethings gotta be wrong with my desktop. It's constantly switching to the basic theme, then I look at my data usage, and in 18 days there has been over 200gb used. My net speed has been 200kb/s opposed to 600 - 800 normally. Something is definitely wrong. Maybe i'm on a botnet or something? I have no idea :((

The only abnormal thing I see is a svchost.exe running at nearly 150k.
This post was last modified: 07-18-2012, 01:57 PM by Predator.


07-18-2012, 02:00 PM #2
AceInfinity
Developer
*******
Administrators
Posts: 9,733 Threads:1,026 Joined: Jun 2011 Reputation: 76

RE: Big Problem
Do you run Windows 7? What does your Event Viewer say? Check for warnings/errors with your desktop windows manager (dwm).


Microsoft MVP .NET Programming - (2012 - Present)
®Crestron DMC-T Certified Automation Programmer

Development Site: aceinfinity.net

 ▲
 ▲ ▲

07-18-2012, 02:07 PM #3
Predator
Staff
*****
Moderators
Posts: 2,488 Threads:427 Joined: Jun 2011 Reputation: 11

RE: Big Problem
"Event log service is unavailable"


07-18-2012, 02:07 PM #4
RDCA
Senior Member
***
Posts: 278 Threads:10 Joined: Jun 2011 Reputation: 9

RE: Big Problem
If you want, I can assist you if you think it is malware related.

07-18-2012, 02:11 PM #5
Predator
Staff
*****
Moderators
Posts: 2,488 Threads:427 Joined: Jun 2011 Reputation: 11

RE: Big Problem
(07-18-2012, 02:07 PM)RDCA Wrote:  If you want, I can assist you if you think it is malware related.
Could be. The fact that my theme keeps reverting back to basic, along with the fact that my home connection has hit 200gb within 18 days...


07-18-2012, 02:13 PM #6
RDCA
Senior Member
***
Posts: 278 Threads:10 Joined: Jun 2011 Reputation: 9

RE: Big Problem
(07-18-2012, 02:11 PM)Predator Wrote:  
(07-18-2012, 02:07 PM)RDCA Wrote:  If you want, I can assist you if you think it is malware related.
Could be. The fact that my theme keeps reverting back to basic, along with the fact that my home connection has hit 200gb within 18 days...
Well, lets just get an OTL scan for now. No harm in checking.

Please download OTL from one of the following links
  • LINK 1
  • LINK 2
    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Under the Custom Scan box paste this in;




      Quote:netsvcs
      %SYSTEMDRIVE%\*.*
      %systemroot%\*. /mp /s
      CREATERESTOREPOINT
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles
      %systemroot%\System32\config\*.sav
      %systemroot%\system32\drivers\*.sys /180




    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them if you need to start a new topic.

07-18-2012, 02:33 PM #7
Predator
Staff
*****
Moderators
Posts: 2,488 Threads:427 Joined: Jun 2011 Reputation: 11

RE: Big Problem



It's still (5 minutes later) on the "uninstall list"


http://i.upme.us/JHGeY.png

(with the error in that picture)
This post was last modified: 07-18-2012, 02:36 PM by Predator.


07-18-2012, 03:52 PM #8
Shintaro
Member
**
Posts: 248 Threads:58 Joined: Jan 2012 Reputation: 8

RE: Big Problem
Mate,

I hope that RDCA can help, I am interested in the problem and the fix as well.

If all else fails you could just do a offline scan:
Kaspersky
http://support.kaspersky.com/viruses/rescuedisk/

Microsoft Defender
http://windows.microsoft.com/en-US/w...fender-offline
This post was last modified: 07-18-2012, 03:53 PM by Shintaro.
Thoughts create realities.


To be old and wise,
You must first be young and stupid.

Try to live an ordinary life,
in a non-ordinary way.

07-18-2012, 03:59 PM #9
RDCA
Senior Member
***
Posts: 278 Threads:10 Joined: Jun 2011 Reputation: 9

RE: Big Problem
Alright, lets try something a bit more powerful.


Step 1
  • Please download Combofix from one of the following locations:

    LINK 1
    LINK 2

    **IMPORTANT! Save Combofix to your Desktop
    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link --> http://www.hackforums.net/showthread.php?tid=198032

    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

    Notes:
    1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
    3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
    4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
    5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Step 2
  • Please download Malwarebytes' AntiMalware.

    Double click mbam-setup.exe to install the application.
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform Full Scan, then click Scan.
      The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart. Restart if it tells you to.
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the entire report in your next reply.

07-18-2012, 06:33 PM #10
Predator
Staff
*****
Moderators
Posts: 2,488 Threads:427 Joined: Jun 2011 Reputation: 11

RE: Big Problem
Code:
ComboFix 12-07-18.04 - Brandon 07/18/2012  18:09:35.1.2 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.1.1033.18.3070.1492 [GMT -5:00]
Running from: c:\users\Brandon\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}
SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\program files (x86)\RelevantKnowledge
c:\program files (x86)\RelevantKnowledge\chrome.manifest
c:\program files (x86)\RelevantKnowledge\components\rlxg.dll
c:\program files (x86)\RelevantKnowledge\components\rlxh.dll
c:\program files (x86)\RelevantKnowledge\components\rlxi.dll
c:\program files (x86)\RelevantKnowledge\components\rlxj.dll
c:\program files (x86)\RelevantKnowledge\components\rlxk.dll
c:\program files (x86)\RelevantKnowledge\install.rdf
c:\program files (x86)\RelevantKnowledge\nscf.dat
c:\program files (x86)\RelevantKnowledge\rlcm.crx
c:\program files (x86)\RelevantKnowledge\rlcm.txt
c:\program files (x86)\RelevantKnowledge\rlls.dll
c:\program files (x86)\RelevantKnowledge\rlls64.dll
c:\program files (x86)\RelevantKnowledge\rloci.bin
c:\program files (x86)\RelevantKnowledge\rlph.dll
c:\program files (x86)\RelevantKnowledge\rlservice.exe
c:\program files (x86)\RelevantKnowledge\rlvknlg.exe
c:\program files (x86)\RelevantKnowledge\rlvknlg64.exe
c:\program files (x86)\RelevantKnowledge\rlxf.dll
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\About RelevantKnowledge.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Privacy Policy and User License Agreement.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Support.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Uninstall Instructions.lnk
c:\users\Brandon\AppData\Local\assembly\tmp
c:\users\Brandon\AppData\Local\Microsoft\Windows\Temporary Internet Files\{395D2142-FADF-4608-A93B-8D070477D7C3}.xps
c:\users\Brandon\AppData\Roaming\Love
c:\users\Brandon\AppData\Roaming\Love\mari0\options.txt
c:\windows\SysWow64\windir
.
Infected copy of c:\windows\system32\Services.exe was found and disinfected
Restored copy from - c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
.
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_RelevantKnowledge
.
.
(((((((((((((((((((((((((   Files Created from 2012-06-18 to 2012-07-18  )))))))))))))))))))))))))))))))
.
.
2012-07-18 23:21 . 2012-07-18 23:21    --------    d-----w-    c:\programdata\AutoKMS
2012-07-18 23:18 . 2012-07-18 23:18    --------    d-----w-    c:\users\Default\AppData\Local\temp
2012-07-17 15:30 . 2012-06-29 10:04    9133488    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{493047D9-2032-4D65-828A-496DB14CE454}\mpengine.dll
2012-07-15 06:24 . 2007-06-21 22:51    215808    ----a-w-    c:\windows\system32\drivers\emDevice64.sys
2012-07-15 06:24 . 2007-06-21 22:51    6400    ----a-w-    c:\windows\system32\drivers\emFilter64.sys
2012-07-15 06:24 . 2007-06-21 22:51    6144    ----a-w-    c:\windows\system32\drivers\emScan64.sys
2012-07-15 06:24 . 2007-06-21 21:21    13824    ----a-w-    c:\windows\system32\emUSD64.dll
2012-07-15 06:24 . 2007-03-05 21:36    70656    ----a-w-    c:\windows\system32\PCLECoInst64.dll
2012-07-15 06:24 . 2006-07-19 23:12    57344    ----a-w-    c:\windows\SysWow64\emVFW.dll
2012-07-15 06:24 . 2006-07-19 23:12    32768    ----a-w-    c:\windows\SysWow64\emProp.ax
2012-07-15 06:24 . 2004-09-15 00:25    17808    ----a-w-    c:\windows\SysWow64\emYUV.dll
2012-07-15 06:24 . 2007-08-31 19:15    79872    ----a-w-    c:\windows\system32\drivers\emAudio64.sys
2012-07-15 06:24 . 2012-07-15 06:24    --------    d-----w-    c:\program files (x86)\Common Files\Pinnacle
2012-07-15 06:23 . 2012-07-15 06:23    --------    d-----w-    c:\users\Brandon\AppData\Local\Downloaded Installations
2012-07-15 06:23 . 2012-07-15 06:23    --------    d-----w-    c:\users\Brandon\AppData\Local\Pinnacle
2012-07-15 06:22 . 2012-07-15 06:22    --------    d-----w-    c:\programdata\Pinnacle Studio Ultimate Collection
2012-07-15 06:18 . 2012-07-15 06:18    --------    d-----w-    c:\program files (x86)\Common Files\Yahoo!
2012-07-15 06:18 . 2012-07-15 06:18    --------    d-----w-    c:\program files (x86)\Common Files\Pegasus Imaging
2012-07-15 06:18 . 2012-07-15 06:18    --------    d-----w-    c:\programdata\Studio 15
2012-07-15 06:18 . 2012-07-15 06:18    --------    d-----w-    c:\programdata\Pinnacle Studio Plus
2012-07-15 06:15 . 2012-07-15 06:22    --------    d-----w-    c:\programdata\Pinnacle
2012-07-15 06:15 . 2012-07-15 06:18    --------    d-----w-    c:\program files (x86)\Pinnacle
2012-07-12 21:01 . 2012-07-12 21:02    --------    d-----w-    c:\program files (x86)\Tag
2012-07-12 06:25 . 2012-06-12 03:08    3148800    ----a-w-    c:\windows\system32\win32k.sys
2012-07-11 17:23 . 2012-07-15 01:58    298016    ----a-w-    c:\windows\SysWow64\PnkBstrB.xtr
2012-07-11 17:23 . 2012-07-11 17:23    --------    d-----w-    c:\users\Brandon\AppData\Local\PunkBuster
2012-07-11 16:30 . 2010-02-04 15:01    238936    ----a-w-    c:\windows\SysWow64\xactengine3_6.dll
2012-07-11 16:29 . 2008-05-30 19:11    4991496    ----a-w-    c:\windows\system32\D3DX9_38.dll
2012-07-11 16:28 . 2012-07-11 16:28    --------    d-----w-    c:\program files (x86)\NVIDIA Corporation
2012-07-11 16:27 . 2012-07-11 16:27    --------    d-----w-    c:\program files (x86)\Common Files\Wise Installation Wizard
2012-07-11 16:26 . 2012-07-15 01:58    298016    ----a-w-    c:\windows\SysWow64\PnkBstrB.exe
2012-07-11 16:26 . 2012-07-15 01:54    298016    ----a-w-    c:\windows\SysWow64\PnkBstrB.ex0
2012-07-11 16:26 . 2012-07-11 17:23    76888    ----a-w-    c:\windows\SysWow64\PnkBstrA.exe
2012-07-11 16:26 . 2011-12-19 22:16    3130440    ----a-w-    c:\windows\SysWow64\pbsvc_blr.exe
2012-07-11 16:26 . 2012-07-11 16:26    --------    d-----w-    C:\Perfect World Entertainment
2012-07-11 10:51 . 2012-06-06 06:05    466944    ----a-w-    c:\program files\Common Files\System\ado\msadomd.dll
2012-07-11 10:51 . 2012-06-06 06:05    1499136    ----a-w-    c:\program files\Common Files\System\ado\msado15.dll
2012-07-11 10:51 . 2012-06-06 05:05    1019904    ----a-w-    c:\program files (x86)\Common Files\System\ado\msado15.dll
2012-07-11 10:51 . 2012-06-06 06:05    495616    ----a-w-    c:\program files\Common Files\System\ado\msadox.dll
2012-07-11 10:51 . 2012-06-06 06:05    61440    ----a-w-    c:\program files\Common Files\System\ado\msador15.dll
2012-07-11 10:51 . 2012-06-06 06:05    258048    ----a-w-    c:\program files\Common Files\System\msadc\msadco.dll
2012-07-11 10:51 . 2012-06-06 06:02    1133568    ----a-w-    c:\windows\system32\cdosys.dll
2012-07-11 10:51 . 2012-06-06 05:05    143360    ----a-w-    c:\program files (x86)\Common Files\System\ado\msjro.dll
2012-07-11 10:51 . 2012-06-06 05:05    372736    ----a-w-    c:\program files (x86)\Common Files\System\ado\msadox.dll
2012-07-11 10:51 . 2012-06-06 05:05    57344    ----a-w-    c:\program files (x86)\Common Files\System\ado\msador15.dll
2012-07-11 10:51 . 2012-06-06 05:05    352256    ----a-w-    c:\program files (x86)\Common Files\System\ado\msadomd.dll
2012-07-11 10:51 . 2012-06-06 05:05    212992    ----a-w-    c:\program files (x86)\Common Files\System\msadc\msadco.dll
2012-07-11 10:51 . 2012-06-06 05:03    805376    ----a-w-    c:\windows\SysWow64\cdosys.dll
2012-07-11 03:05 . 2012-07-12 06:21    --------    d-----w-    c:\users\Brandon\AppData\Local\PMB Files
2012-07-11 03:05 . 2012-07-11 03:06    --------    d-----w-    c:\programdata\PMB Files
2012-07-11 03:05 . 2012-07-11 03:05    --------    d-----w-    c:\program files (x86)\Pando Networks
2012-07-10 01:06 . 2012-07-10 01:57    --------    d-----w-    c:\program files (x86)\LiveUSB Creator
2012-06-28 02:15 . 2012-06-28 02:19    --------    d-----w-    c:\program files (x86)\MKV Player
2012-06-25 02:16 . 2012-06-25 07:53    --------    d-----w-    c:\users\Brandon\Games
2012-06-21 15:48 . 2012-06-02 22:19    57880    ----a-w-    c:\windows\system32\wuauclt.exe
2012-06-21 15:48 . 2012-06-02 22:19    44056    ----a-w-    c:\windows\system32\wups2.dll
2012-06-21 15:48 . 2012-06-02 22:19    2428952    ----a-w-    c:\windows\system32\wuaueng.dll
2012-06-21 15:48 . 2012-06-02 22:15    2622464    ----a-w-    c:\windows\system32\wucltux.dll
2012-06-21 15:48 . 2012-06-02 22:19    38424    ----a-w-    c:\windows\system32\wups.dll
2012-06-21 15:48 . 2012-06-02 22:19    701976    ----a-w-    c:\windows\system32\wuapi.dll
2012-06-21 15:48 . 2012-06-02 22:15    99840    ----a-w-    c:\windows\system32\wudriver.dll
2012-06-21 15:47 . 2012-06-02 20:19    186752    ----a-w-    c:\windows\system32\wuwebv.dll
2012-06-21 15:47 . 2012-06-02 20:15    36864    ----a-w-    c:\windows\system32\wuapp.exe
2012-06-21 02:39 . 2012-06-21 02:39    --------    d-----w-    c:\program files (x86)\VirtualDJ
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-31 17:25 . 2010-11-21 03:27    279656    ------w-    c:\windows\system32\MpSigStub.exe
2012-05-23 08:04 . 2012-05-13 00:19    2478272    ----a-w-    c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2012-05-04 11:06 . 2012-06-14 00:32    5559664    ----a-w-    c:\windows\system32\ntoskrnl.exe
2012-05-04 10:03 . 2012-06-14 00:32    3968368    ----a-w-    c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03 . 2012-06-14 00:32    3913072    ----a-w-    c:\windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40 . 2012-06-14 00:32    209920    ----a-w-    c:\windows\system32\profsvc.dll
2012-04-28 05:32 . 2012-06-14 00:32    1112064    ----a-w-    c:\windows\system32\rdpcorets.dll
2012-04-28 03:55 . 2012-06-14 00:32    210944    ----a-w-    c:\windows\system32\drivers\rdpwd.sys
2012-04-26 05:41 . 2012-06-14 00:32    77312    ----a-w-    c:\windows\system32\rdpwsx.dll
2012-04-26 05:41 . 2012-06-14 00:32    149504    ----a-w-    c:\windows\system32\rdpcorekmts.dll
2012-04-26 05:34 . 2012-06-14 00:32    9216    ----a-w-    c:\windows\system32\rdrmemptylst.exe
2012-04-24 05:37 . 2012-06-14 00:32    184320    ----a-w-    c:\windows\system32\cryptsvc.dll
2012-04-24 05:37 . 2012-06-14 00:32    140288    ----a-w-    c:\windows\system32\cryptnet.dll
2012-04-24 05:37 . 2012-06-14 00:32    1462272    ----a-w-    c:\windows\system32\crypt32.dll
2012-04-24 04:36 . 2012-06-14 00:32    140288    ----a-w-    c:\windows\SysWow64\cryptsvc.dll
2012-04-24 04:36 . 2012-06-14 00:32    1158656    ----a-w-    c:\windows\SysWow64\crypt32.dll
2012-04-24 04:36 . 2012-06-14 00:32    103936    ----a-w-    c:\windows\SysWow64\cryptnet.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[-] 2012-02-25 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
[-] 2012-02-25 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spotify"="c:\users\Brandon\AppData\Roaming\Spotify\spotify.exe" [2012-07-11 7609560]
"Spotify Web Helper"="c:\users\Brandon\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-07-11 1192664]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2011-04-25 202296]
.
c:\users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Blockify Service.lnk - c:\users\Brandon\Downloads\BlockifyService.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages    REG_MULTI_SZ       kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
"SwitchBoard"=c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-08 160944]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-17 113120]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-21 20992]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-21 88960]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 34816]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-03-18 68440]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-02-25 1255736]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2008-05-06 14464]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2011-03-04 11864]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2011-03-11 29488]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-12-06 235520]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-03-19 2666880]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-12-06 10720256]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-12-06 327168]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-03 22544]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt    REG_MULTI_SZ       hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2441664883-2334920327-4159254501-1001Core.job
- c:\users\Brandon\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-19 17:22]
.
2012-07-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2441664883-2334920327-4159254501-1001UA.job
- c:\users\Brandon\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-19 17:22]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF16968.3XE" [2010-11-21 345088]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{F791A188-699D-4FD4-955A-EB59E89B1907}"= "\Program Files\Theme Resource Changer\ThemeResourceChanger.dll" [2010-10-07 103936]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Add to Anti-Banner - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Brandon\AppData\Roaming\Mozilla\Firefox\Profiles\tn1lp2rj.default\
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_blr.exe
AddRemove-{d08d9f98-1c78-4704-87e6-368b0023d831} - c:\program files (x86)\RelevantKnowledge\rlvknlg.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2441664883-2334920327-4159254501-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B60B8BC7-6636-D68B-CF51-C1B88EF82C27}*]
"bbenmpkohimenajdcdkognnkeofodmalheeo"=hex:61,62,62,64,6c,70,63,67,67,68,6d,6a,
   6a,67,65,6e,67,64,6b,6d,64,67,69,6c,6a,6d,65,6d,6c,6d,6a,61,62,6b,00,76
"abenmpkohimenajdcdhfbndgpjebopgjjl"=hex:61,62,67,63,66,70,62,62,6e,6f,68,70,
   6d,65,62,64,61,6d,66,6b,64,6a,70,69,66,6b,64,6d,6e,66,64,68,65,6f,00,76
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:62,9c,7f,d2,61,2b,01,fc,7a,f0,21,2f,8c,7c,97,8b,4e,ba,ab,26,c5,
   02,ed,ff,da,96,8c,89,46,7f,14,0d,70,40,ed,7b,87,c1,2b,15,6d,e9,4b,40,c5,b6,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:62,9c,7f,d2,61,2b,01,fc,7a,f0,21,2f,8c,7c,97,8b,4e,ba,ab,26,c5,
   02,ed,ff,da,96,8c,89,46,7f,14,0d,70,40,ed,7b,87,c1,2b,15,6d,e9,4b,40,c5,b6,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
"Key"="ActionsPane3"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\AutoKMS.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\TeamViewer\Version7\TeamViewer.exe
c:\program files (x86)\TeamViewer\Version7\tv_w32.exe
.
**************************************************************************
.
Completion time: 2012-07-18  18:31:00 - machine was rebooted
ComboFix-quarantined-files.txt  2012-07-18 23:30
.
Pre-Run: 280,644,952,064 bytes free
Post-Run: 294,397,444,096 bytes free
.
- - End Of File - - 2DDAE0A37956F55967D6B5B6CFF9711F





Forum Jump:


Possibly Related Threads...
Thread Author Replies Views Last Post
  Interesting Visual Studio Problem KoBE 0 902 01-24-2013, 11:56 PM
Last Post: KoBE


Users browsing this thread: 1 Guest(s)