I am sorry for bothering you with my problem once again.
Even I was surprised to see the issue cropping up again after I performed a quick scan with Malwarebytes yesterday (22-Mar-2012). It shows 2 Registry Data Items which were promptly quarantined. I wish to know how this is happening and how to get rid of these registry entries.
Here is the MBAM scan log:Malwarebytes Anti-Malware (PRO) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.03.22.03
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Om Deva :: OMDEVA-PC [administrator]
Protection: Enabled
22-Mar-12 21:03:58
mbam-log-2012-03-22 (21-03-58).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 183891
Time elapsed: 16 minute(s), 10 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 2
HKCR\scrfile\shell\open\command| (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and repaired successfully.
HKCR\regfile\shell\open\command| (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and repaired successfully.
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
This is the DDS log:.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31
Run by Om Deva at 14:22:24 on 2012-03-23
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2038.813 [GMT 5.5:30]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\aestsrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\FsUsbExService.Exe
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Perfios\perfios_winsvc.exe
C:\Program Files\Airtel NetXpert\bin\sprtsvc.exe
C:\Program Files\Airtel NetXpert\bin\sprtcmd.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\Airtel NetXpert\bin\tgsrvc.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Authentium\AntiVirus5\vsedsps.exe
C:\Program Files\Common Files\Authentium\AntiVirus5\vseamps.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Hide My IP\HideMyIP.exe
C:\Program Files\TeamViewer\Version7\TeamViewer.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\iolo\System Mechanic Professional\SystemGuardAlerter.exe
C:\Program Files\Common Files\Apple\Internet Services\ubd.exe
C:\Program Files\iolo\System Mechanic Professional\System Shield\ioloSSTray.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Hide My IP\HideMyIpSrv.exe
C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\WUDFHost.exe
C:\Program Files\TeamViewer\Version7\tv_w32.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Foxit Software\Foxit Reader\Foxit Reader.exe
C:\Windows\System32\taskmgr.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uWindow Title = Internet Explorer, optimized for Bing and MSN
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [HideMyIP] c:\program files\hide my ip\HideMyIP.exe
uRun: [Google Update] "c:\users\om deva\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [AutoStartNPSAgent] c:\program files\samsung\samsung new pc studio\NPSAgent.exe
uRun: [MobileDocuments] c:\program files\common files\apple\internet services\ubd.exe
uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray
uRun: [DriverMax] "c:\program files\innovative solutions\drivermax\drivermax.exe" -agent
uRun: [DriverMax_RESTART] "c:\program files\innovative solutions\drivermax\drivermax.exe" -RESTART
mRun: [iolo Startup] "c:\program files\iolo\common\lib\ioloLManager.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [Mouse Suite 98 Daemon] ico.EXE
mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [AcronisTimounterMonitor] c:\program files\acronis\trueimagehome\TimounterMonitor.exe
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
mRun: [NPSStartup]
mRun: [netxpert] "c:\program files\airtel netxpert\bin\sprtcmd.exe" /P netxpert
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Fellowes Proxy] c:\windows\system32\r3proxy.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRunOnce: [SMRequiresRestart]
StartupFolder: c:\users\omdeva~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\users\omdeva~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\google~1.lnk - c:\program files\google\google calendar sync\GoogleCalendarSync.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\windows\system32\HMIPCore.dll
LSP: c:\windows\system32\iavlsp.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{7A511D57-6A8D-448B-8D3F-419488EC3A50} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{C6B1B7EA-81F1-40B7-9D7C-4CDD9A2BB155} : DhcpNameServer = 192.168.1.1
Notify: igfxcui - igfxdev.dll
LSA: Authentication Packages = msv1_0 relog_ap
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\om deva\appdata\roaming\mozilla\firefox\profiles\0jmy17v4.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/
FF - plugin: c:\program files\foxit software\foxit reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\users\om deva\appdata\local\google\update\1.3.21.111\npGoogleUpdate3.dll
.
============= SERVICES / DRIVERS ===============
.
R2 AMP;Active Malware Protection Minifilter Driver;c:\windows\system32\drivers\amp.sys [2011-9-28 138048]
R2 AMPSE;Active Malware Protection Support Driver;c:\windows\system32\drivers\ampse.sys [2012-2-9 1189184]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2012-2-9 361000]
.
=============== File Associations ===============
.
JSEFile=NOTEPAD.EXE %1
regfile=NOTEPAD.EXE %1
scrfile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
=============== Created Last 30 ================
.
2012-03-23 08:40:57 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-03-23 06:52:56 56200 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{9c823277-8e22-4e6e-9f94-55268eea3b00}\offreg.dll
2012-03-23 06:52:56 29904 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{9c823277-8e22-4e6e-9f94-55268eea3b00}\MpKslb6b96e65.sys
2012-03-23 06:50:24 6582328 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{9c823277-8e22-4e6e-9f94-55268eea3b00}\mpengine.dll
2012-03-21 06:59:46 25088 ----a-w- c:\windows\system32\drivers\teamviewervpn.sys
2012-03-21 06:59:29 -------- d-----w- c:\program files\TeamViewer
2012-03-20 09:57:17 -------- d-----w- c:\program files\common files\PCSuite
2012-03-20 09:56:44 -------- d-----w- c:\program files\common files\Nokia
2012-03-20 09:56:29 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2012-03-20 09:55:59 -------- d-----w- c:\program files\PC Connectivity Solution
2012-03-20 09:54:55 75264 ----a-w- c:\windows\system32\nmwcdcls.dll
2012-03-20 09:54:52 -------- d-----w- c:\program files\Nokia
2012-03-19 08:28:09 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-03-19 08:27:54 129976 ----a-w- c:\program files\mozilla firefox\maintenanceservice.exe
2012-03-19 08:27:53 145960 ----a-w- c:\program files\mozilla firefox\maintenanceservice_installer.exe
2012-03-18 07:57:06 -------- d-----w- c:\program files\MagicISO
2012-03-16 03:02:43 -------- d-----w- c:\program files\iPod
2012-03-16 02:48:45 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2012-03-16 02:48:44 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2012-03-16 02:48:44 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2012-03-16 02:48:43 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2012-03-16 02:48:42 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2012-03-16 02:48:41 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2012-03-16 02:48:41 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2012-03-16 02:46:04 -------- d-----w- c:\users\om deva\appdata\local\Diagnostics
2012-03-15 00:20:47 3968368 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-03-15 00:20:45 3913584 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-14 23:55:53 2343424 ----a-w- c:\windows\system32\win32k.sys
2012-03-14 23:55:51 1077248 ----a-w- c:\windows\system32\DWrite.dll
2012-03-14 03:17:06 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-03-14 03:17:06 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-03-14 03:17:05 58880 ----a-w- c:\windows\system32\rdpwsx.dll
2012-03-14 03:17:03 919040 ----a-w- c:\windows\system32\rdpcorets.dll
2012-03-14 03:17:03 826880 ----a-w- c:\windows\system32\rdpcore.dll
2012-03-14 03:17:02 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-03-14 03:17:02 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-13 12:10:46 -------- d-----w- c:\program files\IDT
2012-03-13 12:09:07 915968 ----a-w- c:\windows\system32\stapo.dll
2012-03-13 12:09:07 495104 ----a-w- c:\windows\system32\stapi32.dll
2012-03-13 12:09:07 328704 ----a-w- c:\windows\system32\stcplx.dll
2012-03-13 12:09:05 176128 ----a-w- c:\windows\system32\st326233.dll
2012-03-13 12:07:14 98304 ----a-w- c:\windows\system32\r3proxy.exe
2012-03-13 12:07:14 2387968 ----a-w- c:\windows\system32\FEzPtCPL.dll
2012-03-13 12:07:14 12672 ----a-w- c:\windows\system32\drivers\FeMouWDM.sys
2012-03-13 12:07:13 131072 ----a-w- c:\windows\system32\language.dll
2012-03-13 12:06:50 90112 ----a-w- c:\windows\system32\femouse.dll
2012-03-13 11:55:21 140288 ----a-w- c:\windows\system32\igfxtvcx.dll
2012-03-13 11:30:36 985472 ----a-w- c:\windows\system32\drivers\HSF_DP.sys
2012-03-13 11:30:36 210688 ----a-w- c:\windows\system32\drivers\HSF_HWAZL.sys
2012-03-13 11:30:35 738360 ----a-w- c:\windows\system32\drivers\HSF_CNXT.sys
2012-03-13 11:29:47 38400 ----a-w- c:\windows\system32\drivers\rixdptsk.sys
2012-03-13 11:28:56 48128 ----a-w- c:\windows\system32\drivers\rimmptsk.sys
2012-03-13 11:27:31 44544 ----a-w- c:\windows\system32\drivers\rimsptsk.sys
2012-03-13 11:22:55 108544 ----a-w- c:\windows\system32\drivers\MxEFUF32.sys
2012-03-13 11:20:28 4703232 ----a-w- c:\windows\system32\drivers\BCMWL63.SYS
2012-03-13 11:16:13 -------- d-----w- C:\Intel
2012-03-13 11:12:47 81920 ----a-w- c:\windows\system32\igfxCoIn_v2226.dll
2012-03-13 11:12:45 208896 ----a-w- c:\windows\system32\iglhsip32.dll
2012-03-13 11:12:44 147456 ----a-w- c:\windows\system32\iglhcp32.dll
2012-03-13 11:12:43 874048 ----a-w- c:\windows\system32\igkrng575.bin
2012-03-13 11:12:39 86528 ----a-w- c:\windows\system32\igfxresn.lrc
2012-03-13 11:12:37 4096 ----a-w- c:\windows\system32\IGFXDEVLib.dll
2012-03-13 11:12:36 104796 ----a-w- c:\windows\system32\igfcg575m.bin
2012-03-13 11:12:30 127868 ----a-w- c:\windows\system32\igcompkrng575.bin
2012-03-13 11:12:25 3157784 ----a-w- c:\windows\system32\GfxUI.exe
2012-03-13 11:12:25 120320 ----a-w- c:\windows\system32\gfxSrvc.dll
2012-03-13 11:12:24 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2012-03-12 14:52:31 -------- d-----w- c:\program files\common files\xing shared
2012-03-09 06:34:01 -------- d-----w- c:\users\om deva\appdata\local\Jaksta_Technologies_Pty_L
2012-03-09 06:30:25 -------- d-----w- c:\program files\Applian Technologies
2012-03-09 06:29:15 -------- d-----w- c:\programdata\Applian
2012-03-08 04:24:42 -------- d-----w- c:\program files\common files\SupportSoft
2012-03-08 04:22:56 -------- d-----w- c:\users\om deva\appdata\local\SupportSoft
2012-03-08 04:22:55 -------- d-----w- c:\program files\Airtel NetXpert
2012-03-08 03:06:49 20392 ----a-w- c:\windows\system32\drivers\ElRawDsk.sys
2012-03-08 03:05:33 -------- d-----w- c:\program files\MSXML 4.0
2012-03-07 13:36:47 -------- d-----w- c:\program files\Perfios
2012-03-06 17:37:39 12416 ----a-w- c:\windows\system32\drivers\ssm_whnt.sys
2012-03-06 17:37:39 12416 ----a-w- c:\windows\system32\drivers\ssm_wh.sys
2012-03-06 17:37:38 14848 ----a-w- c:\windows\system32\drivers\ssm_mdfl.sys
2012-03-06 17:37:38 132608 ----a-w- c:\windows\system32\drivers\ssm_mdm.sys
2012-03-06 17:37:38 12544 ----a-w- c:\windows\system32\drivers\ssm_cmnt.sys
2012-03-06 17:37:38 12544 ----a-w- c:\windows\system32\drivers\ssm_cm.sys
2012-03-06 17:37:38 104448 ----a-w- c:\windows\system32\drivers\ssm_bus.sys
2012-03-06 17:33:03 36608 ----a-w- c:\windows\system32\FsUsbExDisk.Sys
2012-03-06 17:33:03 238952 ----a-w- c:\windows\system32\FsUsbExService.Exe
2012-03-06 17:33:02 110592 ----a-w- c:\windows\system32\FsUsbExDevice.Dll
2012-03-06 17:31:54 -------- d-----w- c:\users\om deva\appdata\roaming\Samsung
2012-03-06 17:29:35 -------- d-----w- c:\program files\MarkAny
2012-03-06 17:26:45 -------- d-----w- c:\program files\Samsung
2012-03-06 17:24:23 -------- d-----w- c:\programdata\Samsung
2012-03-06 17:23:01 -------- d-----w- c:\users\om deva\appdata\local\Downloaded Installations
2012-03-06 13:10:23 86016 ------w- c:\windows\unvise32.exe
2012-03-06 13:10:11 -------- d-----w- c:\program files\Bandwidth Monitor Pro
2012-03-06 12:43:36 737280 ----a-w- c:\windows\iun6002.exe
2012-03-05 13:29:37 30512 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
2012-03-05 13:29:36 29552 ----a-w- c:\windows\system32\mdimon.dll
2012-02-28 08:26:48 -------- d-----w- c:\users\om deva\appdata\roaming\Foxit Software
2012-02-22 10:15:26 73728 ----a-w- c:\windows\system32\AEstSrv.exe
2012-02-22 10:15:23 647168 ----a-w- c:\windows\system32\aestecap.dll
2012-02-22 10:15:22 53248 ----a-w- c:\windows\system32\aestaren.dll
2012-02-22 10:15:22 131072 ----a-w- c:\windows\system32\aestacap.dll
2012-02-22 10:15:21 1601536 ----a-w- c:\windows\system32\stlang.dll
2012-02-22 10:15:21 102400 ----a-w- c:\windows\system32\stacsv.exe
2012-02-22 10:15:20 4947968 ----a-w- c:\windows\system32\stacgui.cpl
2012-02-22 10:08:42 330240 ----a-w- c:\windows\system32\drivers\stwrt.sys
2012-02-22 10:08:34 146944 ----a-w- c:\windows\system32\st325614.dll
2012-02-22 10:08:33 45568 ----a-w- c:\windows\system32\ctppld.dll
2012-02-22 10:08:32 492544 ----a-w- c:\windows\system32\ctapo32.dll
2012-02-22 10:08:23 -------- d-----w- c:\program files\SigmaTel
2012-02-22 09:45:59 -------- d-----w- c:\users\om deva\My Installables
.
==================== Find3M ====================
.
2012-03-12 17:01:56 1608 ----a-w- c:\windows\fonts\JayHo.ttf
2012-03-06 17:35:06 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-22 12:08:10 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-02-15 05:31:50 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll
2012-02-15 05:31:50 43520 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2012-02-11 06:41:28 44384 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2012-02-11 06:41:28 441760 ----a-w- c:\windows\system32\drivers\timntr.sys
2012-02-11 06:41:24 132224 ----a-w- c:\windows\system32\drivers\snapman.sys
2012-02-11 06:41:16 368480 ----a-w- c:\windows\system32\drivers\tdrpman.sys
2012-02-11 06:06:32 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-02-11 06:06:31 499712 ----a-w- c:\windows\system32\msvcp71.dll
2012-02-10 05:21:53 152576 ----a-w- c:\windows\system32\msclmd.dll
2012-02-09 07:11:36 74703 ----a-w- c:\windows\system32\mfc45.dll
2012-01-31 12:44:05 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-01-12 00:19:16 4448256 ----a-w- c:\windows\system32\GPhotos.scr
2012-01-06 06:21:24 29696 ----a-w- c:\windows\system32\iolobtdfg.exe
2012-01-06 06:21:16 11776 ----a-w- c:\windows\system32\smrgdf.exe
2012-01-06 05:59:06 2083464 ----a-w- c:\windows\system32\Incinerator32.dll
2012-01-04 08:58:41 442880 ----a-w- c:\windows\system32\ntshrui.dll
2011-12-30 05:27:56 478720 ----a-w- c:\windows\system32\timedate.cpl
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.netWindows 6.1.7601 Disk: ST932032 rev.SD03 -> Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: >>UNKNOWN [0x82C1C000]<< >>UNKNOWN [0x833C0000]<< >>UNKNOWN [0x88DE4000]<< >>UNKNOWN [0x88C00000]<< >>UNKNOWN [0x8302E000]<<
_asm { DEC EBP; POP EDX; NOP ; ADD [EBX], AL; ADD [EAX], AL; ADD [EAX+EAX], AL; ADD [EAX], AL; }
1 ntkrnlpa!IofCallDriver[0x82C5355A] -> \Device\Harddisk0\DR0[0x8726F5A8]
\Driver\Disk[0x8726EB78] -> IRP_MJ_CREATE -> 0x833C439F
3 [0x833C459E] -> ntkrnlpa!IofCallDriver[0x82C5355A] -> \Device\Ide\IAAStorageDevice-0[0x8580F028]
\Driver\iaStor[0x8578FB48] -> IRP_MJ_CREATE -> 0x88C230F8
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 14:24:32.69 ===============
This is the Attack.txt file:.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 09-Feb-12 12:13:14
System Uptime: 23-Mar-12 07:54:15 (7 hours ago)
.
Motherboard: Dell Inc. | | 0TT347
Processor: Intel® Core2 Duo CPU T5270 @ 1.40GHz | Microprocessor | 1386/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 298 GiB total, 162.718 GiB free.
D: is CDROM ()
F: is CDROM (UDF)
G: is FIXED (NTFS) - 466 GiB total, 254.548 GiB free.
H: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP138: 23-Mar-12 12:28:23 - Scheduled Checkpoint
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
7-Zip 4.62
Acronis Disk Director Suite
Acronis True Image Home
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Advanced Task Manager for Windows Vista & Windows XP
Advanced Uninstaller PRO - Version 9
Airtel NetXpert 3.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AVSDK5
Beyond Compare Version 3.3.4
Bonjour
CanSecure-Retail
Carbon Folder
Conexant HDA D330 MDC V.92 Modem
Daily Planner Journal 5.6
DriverMax 6
EssentialPIM
eWallet 7.2
Foxit Reader 5.1
Google Calendar Sync
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Hide My IP 5.3
iCloud
Innovative System Optimizer - version 4
Intel® Graphics Media Accelerator Driver
Intel® TV Wizard
iolo technologies' System Mechanic Professional
iTunes
Java Auto Updater
Java 6 Update 31
Kensington SlimBlade Driver
Magic ISO Maker v5.5 (build 0273)
MagicDisc 2.7.106
Malwarebytes Anti-Malware version 1.60.1.1000
MediaFire Express (beta)
Microsoft .NET Framework 4 Client Profile
Microsoft Antimalware
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mobile Partner
Mozilla Firefox 12.0 (x86 en-US)
Mozilla Maintenance Service
MSVC90_x86
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nokia Connectivity Cable Driver
Nokia PC Suite
OpenOffice.org 3.3
PC Connectivity Solution
Perfios SmartUpdate
Picasa 3
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
RICOH Media Driver ver.2.07.01.04
RICOH R5U8xx Media Driver ver.3.62.02
RoboTask Lite 3.0
Safari
Samsung New PC Studio
SAMSUNG USB Driver for Mobile Phones
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
SigmaTel Audio
StarToken
TeamViewer 7
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2597970) 32-Bit Edition
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VLC media player 2.0.1
Windows Driver Package - Nokia Modem (02/25/2011 4.7)
Windows Driver Package - Nokia Modem (02/25/2011 7.01.0.9)
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Mobile Device Center
Windows Mobile Device Center Driver Update
.
==== Event Viewer Messages From Past Week ========
.
23-Mar-12 11:55:03, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
23-Mar-12 07:55:43, Error: Service Control Manager [7023] - The iPod Service service terminated with the following error: %%-2147417831
23-Mar-12 07:55:27, Error: Service Control Manager [7034] - The SigmaTel Audio Service service terminated unexpectedly. It has done this 1 time(s).
23-Mar-12 07:55:27, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: eairwnet FileDisk
22-Mar-12 20:50:40, Error: BTHUSB [17] - The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.
22-Mar-12 12:13:09, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume I:.
22-Mar-12 11:55:38, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
22-Mar-12 11:55:38, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-2147218173.
.
==== End Of File ===========================