Hey guys,
Hopefully you guys can help me out with this. I have a 1Tb WD Hdd which I use to backup my photos and videos while I'm in the field working. I make my backup everyday in the field basically just making a folder day1, day 2 and follows. When I got back home I plugged it in my computer and as soon as I opened the drive half the folders were being shown as shortcuts. When i tired to open it avast kicked in gave me a Trojan alert and blocked the file. Avast's Shield log lists its as follows :
FILE NAME: H:\.Trashes\b3fdadef.com - SEVERITY: High - STATUS: Threat: Win32:Kryptik-LQL[Tfj] - ACTION: Move to Chest - RESULT: Action Successful
Now when I try to open a folder it gives the following error: Windows cannot find H:\.Trashes\b3fdadef.com. Make you you typed the name correctly are try again. I can tell that the data is still there by the overall file size on the passport.
The other folders which haven't been infected are working absolutely fine.
I'm on a brand new PC, I just installed Win7 myself everything is working fine my computer isn't or doesn't seem to be infected it self in anyway. Its as far as I can tell restricted to only the portable HDD. My antivirus is up to date, before writing this I scanned everything with Malewarebytes no positives any where.
I would appreciate any help that you can give me, this is very important data for a shoot which cannot be conducted again.
Thanx alot in guys
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16483
Run by [removed] at 17:52:34 on 2013-05-25
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.16275.13348 [GMT 5:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\D-Link\DWA-131 revA\WlanWpsSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\D-Link\DWA-131 revA\wirelesscm.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\explorer.exe
C:\Program Files\TeraCopy\TeraCopy.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [Google Update] "C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [AdobeBridge] <no file>
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\WIRELE~1.LNK - C:\Program Files (x86)\D-Link\DWA-131 revA\wirelesscm.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{7754D541-F12F-4EEE-91EA-80F37D1DB23E} : DHCPNameServer = 192.168.0.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\
FF - prefs.js: browser.startup.homepage - Yahoo.com
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Users\SS\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: C:\Users\SS\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\SS\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Users\SS\AppData\Roaming\Mozilla\plugins\npo1d.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll
FF - ExtSQL: 2013-05-24 19:56; [removed]; C:\Program Files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2013-05-24 20:07; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-05-24 20:30; {dc572301-7619-498c-a57d-39143191b318}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
FF - ExtSQL: 2013-05-24 20:30; {b9db16a4-6edc-47ec-a1f4-b86292ed211d}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - ExtSQL: 2013-05-24 20:30; {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
FF - ExtSQL: 2013-05-24 20:30; {AE93811A-5C9A-4d34-8462-F7B864FC4696}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi
FF - ExtSQL: 2013-05-24 20:31; {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi
FF - ExtSQL: 2013-05-24 20:31; {0FED7D55-65D4-47b6-A6DE-9A4ADB55355F}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{0FED7D55-65D4-47b6-A6DE-9A4ADB55355F}
FF - ExtSQL: 2013-05-24 20:31; {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - ExtSQL: 2013-05-24 20:31; [removed]; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\[removed]
FF - ExtSQL: 2013-05-24 20:31; [removed]; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\[removed]
FF - ExtSQL: 2013-05-24 20:31; [removed]; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\[removed]
FF - ExtSQL: 2013-05-24 20:31; [removed]; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\[removed]
FF - ExtSQL: 2013-05-24 20:43; {1280606b-2510-4fe0-97ef-9b5a22eafe30}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-5-24 65336]
R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-5-24 189936]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2013-5-24 19264]
R1 AppleCharger;AppleCharger;C:\Windows\System32\drivers\AppleCharger.sys [2013-5-24 22680]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-5-24 1025808]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-5-24 378432]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-5-24 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-5-24 80816]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-5-24 46808]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2013-5-24 166720]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-5-25 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-5-25 701512]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-5-24 365376]
R2 WlanWpsSvc;WlanWpsSvc;C:\Program Files (x86)\D-Link\DWA-131 revA\WlanWpsSvc.exe [2013-5-24 167936]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-5-24 160256]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2013-5-24 342528]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2013-5-24 357184]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2013-5-24 789824]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2013-5-24 110744]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-5-25 25928]
R3 RTL8192su;%RTL8192su.DeviceDesc.DispName%;C:\Windows\System32\drivers\RTL8192su.sys [2013-5-24 589312]
R3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-4-19 161384]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2011-4-12 71168]
S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2013-5-24 16776]
S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2013-5-24 9096]
S3 GVTDrv64;GVTDrv64;C:\Windows\GVTDrv64.sys [2013-5-24 30528]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-1-10 19456]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\System32\drivers\Synth3dVsc.sys [2011-4-12 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\System32\drivers\terminpt.sys [2013-1-10 29696]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-1-10 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-1-10 30208]
S3 tsusbhub;tsusbhub;C:\Windows\System32\drivers\tsusbhub.sys [2011-4-12 117248]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-5-24 1255736]
.
=============== Created Last 30 ================
.
2013-05-25 11:29:03 -------- d-----w- C:\Users\SS\AppData\Roaming\Malwarebytes
2013-05-25 11:28:57 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-05-25 11:28:57 -------- d-----w- C:\ProgramData\Malwarebytes
2013-05-25 11:28:57 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-05-25 11:28:44 -------- d-----w- C:\Users\SS\AppData\Local\Programs
2013-05-25 08:06:56 -------- d-----w- C:\Users\SS\AppData\Local\Diagnostics
2013-05-25 07:54:37 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe
2013-05-25 07:44:05 -------- d-----w- C:\Users\SS\AppData\Local\Adobe
2013-05-25 07:16:02 -------- d-----w- C:\Program Files (x86)\Auslogics
2013-05-25 02:30:08 -------- d-----w- C:\Windows\Panther
2013-05-25 02:29:54 -------- d-sh--w- C:\Boot
2013-05-24 19:08:49 -------- d-----w- C:\Users\SS\AppData\Local\Macromedia
2013-05-24 18:53:14 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-05-24 18:53:13 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-24 17:42:36 -------- d-----w- C:\Users\SS\AppData\Local\Microsoft Games
2013-05-24 17:28:38 -------- d-----w- C:\Program Files\WDCSAM
2013-05-24 17:18:11 -------- d-----w- C:\Users\SS\AppData\Local\MediaMonkey
2013-05-24 17:18:10 -------- d-----w- C:\Program Files (x86)\MediaMonkey
2013-05-24 17:17:34 -------- d-----w- C:\Program Files (x86)\Media Monkey
2013-05-24 16:55:33 -------- d-----w- C:\Users\SS\AppData\Roaming\TeraCopy
2013-05-24 16:31:13 9096 ----a-w- C:\Windows\System32\EuGdiDrv.sys
2013-05-24 16:31:13 86408 ----a-w- C:\Windows\SysWow64\setupempdrv03.exe
2013-05-24 16:31:13 8456 ----a-w- C:\Windows\SysWow64\EuGdiDrv.sys
2013-05-24 16:31:13 2209920 ----a-w- C:\Windows\System32\BootMan.exe
2013-05-24 16:31:13 1774720 ----a-w- C:\Windows\SysWow64\BootMan.exe
2013-05-24 16:31:13 16776 ----a-w- C:\Windows\System32\epmntdrv.sys
2013-05-24 16:31:13 14848 ----a-w- C:\Windows\SysWow64\EuEpmGdi.dll
2013-05-24 16:31:13 14216 ----a-w- C:\Windows\SysWow64\epmntdrv.sys
2013-05-24 16:31:13 11264 ----a-w- C:\Windows\System32\EuEpmGdi.dll
2013-05-24 16:31:13 100232 ----a-w- C:\Windows\System32\setupempdrvx64.exe
2013-05-24 16:31:07 -------- d-----w- C:\Program Files (x86)\EASEUS
2013-05-24 16:27:05 -------- d-----w- C:\Windows\SysWow64\Wat
2013-05-24 16:27:05 -------- d-----w- C:\Windows\System32\Wat
2013-05-24 15:58:13 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-05-24 15:58:13 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2013-05-24 15:58:04 8199504 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-05-24 15:58:02 9460464 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2688BBD1-3261-4286-819E-9D23B773EE49}\mpengine.dll
2013-05-24 15:38:03 -------- d-----r- C:\Program Files (x86)\Skype
2013-05-24 15:29:45 70144 ----a-w- C:\Windows\System32\appinfo.dll
2013-05-24 15:29:45 1930752 ----a-w- C:\Windows\System32\authui.dll
2013-05-24 15:29:45 1796096 ----a-w- C:\Windows\SysWow64\authui.dll
2013-05-24 15:29:45 111448 ----a-w- C:\Windows\System32\consent.exe
2013-05-24 15:27:41 223752 ----a-w- C:\Windows\System32\drivers\fvevol.sys
2013-05-24 15:24:29 -------- d-----w- C:\Users\SS\AppData\Roaming\SumatraPDF
2013-05-24 15:24:26 -------- d-----w- C:\Program Files (x86)\SumatraPDF
2013-05-24 15:24:15 -------- d-----w- C:\Program Files\TeraCopy
2013-05-24 15:05:44 -------- d-----w- C:\Users\SS\AppData\Roaming\uTorrent
2013-05-24 15:05:24 -------- d-----w- C:\Program Files (x86)\VideoLAN
2013-05-24 15:01:52 589312 ----a-w- C:\Windows\System32\drivers\RTL8192su.sys
2013-05-24 15:01:52 -------- d-----w- C:\Windows\pcidevice
2013-05-24 15:01:51 -------- d-----w- C:\Program Files (x86)\D-Link
2013-05-24 14:57:29 -------- d-----w- C:\Users\SS\AppData\Local\Google
2013-05-24 14:57:26 72016 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-05-24 14:57:26 1025808 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-05-24 14:57:25 189936 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2013-05-24 14:57:23 65336 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-05-24 14:57:22 80816 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2013-05-24 14:56:51 41664 ----a-w- C:\Windows\avastSS.scr
2013-05-24 14:56:42 -------- d-----w- C:\Program Files\AVAST Software
2013-05-24 14:56:16 -------- d-----w- C:\ProgramData\AVAST Software
2013-05-24 14:49:43 30528 ----a-w- C:\Windows\GVTDrv64.sys
2013-05-24 14:49:30 25640 ----a-w- C:\Windows\gdrv.sys
2013-05-24 14:29:11 -------- d-----w- C:\Program Files (x86)\AMD
2013-05-24 14:10:00 31272 ----a-w- C:\Windows\System32\AppleChargerSrv.exe
2013-05-24 14:10:00 22680 ----a-w- C:\Windows\System32\drivers\AppleCharger.sys
2013-05-24 14:10:00 -------- d-----w- C:\Program Files\GIGABYTE
2013-05-24 14:10:00 -------- d-----w- C:\Program Files (x86)\GIGABYTE
2013-05-24 14:09:53 753664 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2013-05-24 14:09:53 69714 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2013-05-24 14:09:53 63488 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ISBEW64.exe
2013-05-24 14:09:53 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2013-05-24 14:09:53 331908 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2013-05-24 14:09:53 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2013-05-24 14:09:53 200836 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2013-05-24 14:09:53 184320 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2013-05-24 14:09:39 41984 ----a-w- C:\Windows\System32\drivers\USB3Ver.dll
2013-05-24 14:09:18 -------- d-----w- C:\Windows\SysWow64\Atheros_L1e
2013-05-24 14:07:46 53248 ----a-w- C:\Windows\SysWow64\CSVer.dll
2013-05-24 14:07:38 15168 ----a-w- C:\Windows\System32\drivers\IntelMEFWVer.dll
2013-05-24 14:06:56 -------- d-----w- C:\Program Files (x86)\Common Files\postureAgent
2013-05-24 14:06:54 62784 ----a-w- C:\Windows\System32\drivers\HECIx64.sys
2013-05-24 14:06:54 -------- d-----w- C:\Intel
2013-05-24 14:03:15 -------- d-sh--w- C:\Windows\Installer
2013-05-24 14:01:08 207400 ----a-w- C:\Windows\GSetup.exe
2013-05-24 13:59:56 -------- d-----w- C:\Users\SS\AppData\Local\VirtualStore
2013-05-24 13:57:34 142336 ----a-w- C:\Windows\System32\poqexec.exe
2013-05-24 13:57:34 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2013-05-24 13:56:26 -------- d-sh--w- C:\Recovery
2013-05-24 04:20:59 9728 ----a-w- C:\Windows\System32\IGFXDEVLib.dll
2013-05-24 04:16:22 110744 ----a-w- C:\Windows\System32\drivers\L1C62x64.sys
.
==================== Find3M ====================
.
2013-05-01 21:06:08 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2013-04-10 06:01:54 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2013-04-10 06:01:53 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2013-04-10 03:30:50 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-04-05 01:08:44 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2013-04-05 01:00:30 1392128 ----a-w- C:\Windows\System32\wininet.dll
2013-04-05 00:59:24 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2013-04-05 00:56:16 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2013-04-05 00:55:47 599040 ----a-w- C:\Windows\System32\vbscript.dll
2013-04-04 22:11:34 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-04-04 22:02:59 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-04-04 22:02:17 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-04-04 21:58:51 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2013-04-04 21:57:45 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2013-03-19 06:04:06 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-03-19 05:53:58 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll
2013-03-19 05:53:58 230400 ----a-w- C:\Windows\System32\wwansvc.dll
2013-03-19 05:46:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2013-03-19 05:04:13 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-03-19 05:04:10 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-03-19 04:47:50 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll
2013-03-19 03:06:33 112640 ----a-w- C:\Windows\System32\smss.exe
.
============= FINISH: 17:53:00.86 ===============
Hopefully you guys can help me out with this. I have a 1Tb WD Hdd which I use to backup my photos and videos while I'm in the field working. I make my backup everyday in the field basically just making a folder day1, day 2 and follows. When I got back home I plugged it in my computer and as soon as I opened the drive half the folders were being shown as shortcuts. When i tired to open it avast kicked in gave me a Trojan alert and blocked the file. Avast's Shield log lists its as follows :
FILE NAME: H:\.Trashes\b3fdadef.com - SEVERITY: High - STATUS: Threat: Win32:Kryptik-LQL[Tfj] - ACTION: Move to Chest - RESULT: Action Successful
Now when I try to open a folder it gives the following error: Windows cannot find H:\.Trashes\b3fdadef.com. Make you you typed the name correctly are try again. I can tell that the data is still there by the overall file size on the passport.
The other folders which haven't been infected are working absolutely fine.
I'm on a brand new PC, I just installed Win7 myself everything is working fine my computer isn't or doesn't seem to be infected it self in anyway. Its as far as I can tell restricted to only the portable HDD. My antivirus is up to date, before writing this I scanned everything with Malewarebytes no positives any where.
I would appreciate any help that you can give me, this is very important data for a shoot which cannot be conducted again.
Thanx alot in guys
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16483
Run by [removed] at 17:52:34 on 2013-05-25
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.16275.13348 [GMT 5:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\D-Link\DWA-131 revA\WlanWpsSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\D-Link\DWA-131 revA\wirelesscm.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\explorer.exe
C:\Program Files\TeraCopy\TeraCopy.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [Google Update] "C:\Users\SS\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [AdobeBridge] <no file>
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\WIRELE~1.LNK - C:\Program Files (x86)\D-Link\DWA-131 revA\wirelesscm.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{7754D541-F12F-4EEE-91EA-80F37D1DB23E} : DHCPNameServer = 192.168.0.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\
FF - prefs.js: browser.startup.homepage - Yahoo.com
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Users\SS\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: C:\Users\SS\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\SS\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Users\SS\AppData\Roaming\Mozilla\plugins\npo1d.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll
FF - ExtSQL: 2013-05-24 19:56; [removed]; C:\Program Files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2013-05-24 20:07; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-05-24 20:30; {dc572301-7619-498c-a57d-39143191b318}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
FF - ExtSQL: 2013-05-24 20:30; {b9db16a4-6edc-47ec-a1f4-b86292ed211d}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - ExtSQL: 2013-05-24 20:30; {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
FF - ExtSQL: 2013-05-24 20:30; {AE93811A-5C9A-4d34-8462-F7B864FC4696}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi
FF - ExtSQL: 2013-05-24 20:31; {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi
FF - ExtSQL: 2013-05-24 20:31; {0FED7D55-65D4-47b6-A6DE-9A4ADB55355F}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{0FED7D55-65D4-47b6-A6DE-9A4ADB55355F}
FF - ExtSQL: 2013-05-24 20:31; {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - ExtSQL: 2013-05-24 20:31; [removed]; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\[removed]
FF - ExtSQL: 2013-05-24 20:31; [removed]; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\[removed]
FF - ExtSQL: 2013-05-24 20:31; [removed]; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\[removed]
FF - ExtSQL: 2013-05-24 20:31; [removed]; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\[removed]
FF - ExtSQL: 2013-05-24 20:43; {1280606b-2510-4fe0-97ef-9b5a22eafe30}; C:\Users\SS\AppData\Roaming\Mozilla\Firefox\Profiles\64glyqu5.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-5-24 65336]
R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-5-24 189936]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2013-5-24 19264]
R1 AppleCharger;AppleCharger;C:\Windows\System32\drivers\AppleCharger.sys [2013-5-24 22680]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-5-24 1025808]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-5-24 378432]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-5-24 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-5-24 80816]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-5-24 46808]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2013-5-24 166720]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-5-25 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-5-25 701512]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-5-24 365376]
R2 WlanWpsSvc;WlanWpsSvc;C:\Program Files (x86)\D-Link\DWA-131 revA\WlanWpsSvc.exe [2013-5-24 167936]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-5-24 160256]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2013-5-24 342528]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2013-5-24 357184]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2013-5-24 789824]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2013-5-24 110744]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-5-25 25928]
R3 RTL8192su;%RTL8192su.DeviceDesc.DispName%;C:\Windows\System32\drivers\RTL8192su.sys [2013-5-24 589312]
R3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-4-19 161384]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2011-4-12 71168]
S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2013-5-24 16776]
S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2013-5-24 9096]
S3 GVTDrv64;GVTDrv64;C:\Windows\GVTDrv64.sys [2013-5-24 30528]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-1-10 19456]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\System32\drivers\Synth3dVsc.sys [2011-4-12 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\System32\drivers\terminpt.sys [2013-1-10 29696]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-1-10 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-1-10 30208]
S3 tsusbhub;tsusbhub;C:\Windows\System32\drivers\tsusbhub.sys [2011-4-12 117248]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-5-24 1255736]
.
=============== Created Last 30 ================
.
2013-05-25 11:29:03 -------- d-----w- C:\Users\SS\AppData\Roaming\Malwarebytes
2013-05-25 11:28:57 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-05-25 11:28:57 -------- d-----w- C:\ProgramData\Malwarebytes
2013-05-25 11:28:57 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-05-25 11:28:44 -------- d-----w- C:\Users\SS\AppData\Local\Programs
2013-05-25 08:06:56 -------- d-----w- C:\Users\SS\AppData\Local\Diagnostics
2013-05-25 07:54:37 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe
2013-05-25 07:44:05 -------- d-----w- C:\Users\SS\AppData\Local\Adobe
2013-05-25 07:16:02 -------- d-----w- C:\Program Files (x86)\Auslogics
2013-05-25 02:30:08 -------- d-----w- C:\Windows\Panther
2013-05-25 02:29:54 -------- d-sh--w- C:\Boot
2013-05-24 19:08:49 -------- d-----w- C:\Users\SS\AppData\Local\Macromedia
2013-05-24 18:53:14 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-05-24 18:53:13 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-24 17:42:36 -------- d-----w- C:\Users\SS\AppData\Local\Microsoft Games
2013-05-24 17:28:38 -------- d-----w- C:\Program Files\WDCSAM
2013-05-24 17:18:11 -------- d-----w- C:\Users\SS\AppData\Local\MediaMonkey
2013-05-24 17:18:10 -------- d-----w- C:\Program Files (x86)\MediaMonkey
2013-05-24 17:17:34 -------- d-----w- C:\Program Files (x86)\Media Monkey
2013-05-24 16:55:33 -------- d-----w- C:\Users\SS\AppData\Roaming\TeraCopy
2013-05-24 16:31:13 9096 ----a-w- C:\Windows\System32\EuGdiDrv.sys
2013-05-24 16:31:13 86408 ----a-w- C:\Windows\SysWow64\setupempdrv03.exe
2013-05-24 16:31:13 8456 ----a-w- C:\Windows\SysWow64\EuGdiDrv.sys
2013-05-24 16:31:13 2209920 ----a-w- C:\Windows\System32\BootMan.exe
2013-05-24 16:31:13 1774720 ----a-w- C:\Windows\SysWow64\BootMan.exe
2013-05-24 16:31:13 16776 ----a-w- C:\Windows\System32\epmntdrv.sys
2013-05-24 16:31:13 14848 ----a-w- C:\Windows\SysWow64\EuEpmGdi.dll
2013-05-24 16:31:13 14216 ----a-w- C:\Windows\SysWow64\epmntdrv.sys
2013-05-24 16:31:13 11264 ----a-w- C:\Windows\System32\EuEpmGdi.dll
2013-05-24 16:31:13 100232 ----a-w- C:\Windows\System32\setupempdrvx64.exe
2013-05-24 16:31:07 -------- d-----w- C:\Program Files (x86)\EASEUS
2013-05-24 16:27:05 -------- d-----w- C:\Windows\SysWow64\Wat
2013-05-24 16:27:05 -------- d-----w- C:\Windows\System32\Wat
2013-05-24 15:58:13 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-05-24 15:58:13 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2013-05-24 15:58:04 8199504 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-05-24 15:58:02 9460464 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2688BBD1-3261-4286-819E-9D23B773EE49}\mpengine.dll
2013-05-24 15:38:03 -------- d-----r- C:\Program Files (x86)\Skype
2013-05-24 15:29:45 70144 ----a-w- C:\Windows\System32\appinfo.dll
2013-05-24 15:29:45 1930752 ----a-w- C:\Windows\System32\authui.dll
2013-05-24 15:29:45 1796096 ----a-w- C:\Windows\SysWow64\authui.dll
2013-05-24 15:29:45 111448 ----a-w- C:\Windows\System32\consent.exe
2013-05-24 15:27:41 223752 ----a-w- C:\Windows\System32\drivers\fvevol.sys
2013-05-24 15:24:29 -------- d-----w- C:\Users\SS\AppData\Roaming\SumatraPDF
2013-05-24 15:24:26 -------- d-----w- C:\Program Files (x86)\SumatraPDF
2013-05-24 15:24:15 -------- d-----w- C:\Program Files\TeraCopy
2013-05-24 15:05:44 -------- d-----w- C:\Users\SS\AppData\Roaming\uTorrent
2013-05-24 15:05:24 -------- d-----w- C:\Program Files (x86)\VideoLAN
2013-05-24 15:01:52 589312 ----a-w- C:\Windows\System32\drivers\RTL8192su.sys
2013-05-24 15:01:52 -------- d-----w- C:\Windows\pcidevice
2013-05-24 15:01:51 -------- d-----w- C:\Program Files (x86)\D-Link
2013-05-24 14:57:29 -------- d-----w- C:\Users\SS\AppData\Local\Google
2013-05-24 14:57:26 72016 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-05-24 14:57:26 1025808 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-05-24 14:57:25 189936 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2013-05-24 14:57:23 65336 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-05-24 14:57:22 80816 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2013-05-24 14:56:51 41664 ----a-w- C:\Windows\avastSS.scr
2013-05-24 14:56:42 -------- d-----w- C:\Program Files\AVAST Software
2013-05-24 14:56:16 -------- d-----w- C:\ProgramData\AVAST Software
2013-05-24 14:49:43 30528 ----a-w- C:\Windows\GVTDrv64.sys
2013-05-24 14:49:30 25640 ----a-w- C:\Windows\gdrv.sys
2013-05-24 14:29:11 -------- d-----w- C:\Program Files (x86)\AMD
2013-05-24 14:10:00 31272 ----a-w- C:\Windows\System32\AppleChargerSrv.exe
2013-05-24 14:10:00 22680 ----a-w- C:\Windows\System32\drivers\AppleCharger.sys
2013-05-24 14:10:00 -------- d-----w- C:\Program Files\GIGABYTE
2013-05-24 14:10:00 -------- d-----w- C:\Program Files (x86)\GIGABYTE
2013-05-24 14:09:53 753664 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2013-05-24 14:09:53 69714 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2013-05-24 14:09:53 63488 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ISBEW64.exe
2013-05-24 14:09:53 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2013-05-24 14:09:53 331908 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2013-05-24 14:09:53 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2013-05-24 14:09:53 200836 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2013-05-24 14:09:53 184320 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2013-05-24 14:09:39 41984 ----a-w- C:\Windows\System32\drivers\USB3Ver.dll
2013-05-24 14:09:18 -------- d-----w- C:\Windows\SysWow64\Atheros_L1e
2013-05-24 14:07:46 53248 ----a-w- C:\Windows\SysWow64\CSVer.dll
2013-05-24 14:07:38 15168 ----a-w- C:\Windows\System32\drivers\IntelMEFWVer.dll
2013-05-24 14:06:56 -------- d-----w- C:\Program Files (x86)\Common Files\postureAgent
2013-05-24 14:06:54 62784 ----a-w- C:\Windows\System32\drivers\HECIx64.sys
2013-05-24 14:06:54 -------- d-----w- C:\Intel
2013-05-24 14:03:15 -------- d-sh--w- C:\Windows\Installer
2013-05-24 14:01:08 207400 ----a-w- C:\Windows\GSetup.exe
2013-05-24 13:59:56 -------- d-----w- C:\Users\SS\AppData\Local\VirtualStore
2013-05-24 13:57:34 142336 ----a-w- C:\Windows\System32\poqexec.exe
2013-05-24 13:57:34 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2013-05-24 13:56:26 -------- d-sh--w- C:\Recovery
2013-05-24 04:20:59 9728 ----a-w- C:\Windows\System32\IGFXDEVLib.dll
2013-05-24 04:16:22 110744 ----a-w- C:\Windows\System32\drivers\L1C62x64.sys
.
==================== Find3M ====================
.
2013-05-01 21:06:08 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2013-04-10 06:01:54 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2013-04-10 06:01:53 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2013-04-10 03:30:50 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-04-05 01:08:44 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2013-04-05 01:00:30 1392128 ----a-w- C:\Windows\System32\wininet.dll
2013-04-05 00:59:24 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2013-04-05 00:56:16 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2013-04-05 00:55:47 599040 ----a-w- C:\Windows\System32\vbscript.dll
2013-04-04 22:11:34 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-04-04 22:02:59 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-04-04 22:02:17 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-04-04 21:58:51 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2013-04-04 21:57:45 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2013-03-19 06:04:06 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-03-19 05:53:58 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll
2013-03-19 05:53:58 230400 ----a-w- C:\Windows\System32\wwansvc.dll
2013-03-19 05:46:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2013-03-19 05:04:13 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-03-19 05:04:10 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-03-19 04:47:50 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll
2013-03-19 03:06:33 112640 ----a-w- C:\Windows\System32\smss.exe
.
============= FINISH: 17:53:00.86 ===============