dimanche 10 novembre 2013

MSE Disabled - Zeroaccess Rootkit

Sent here from this introductory post / topic:


http://www.bleepingcomputer.com/forums/t/513488/mse-disabled-zeroaccess-rootkit/


dds.txt


DDS (Ver_2012-11-20.01) - NTFS_AMD64


Internet Explorer: 10.0.9200.16720 BrowserJavaVersion: 10.13.2


Run by Owner at 13:59:00 on 2013-11-09


Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.4044.2474 [GMT -7:00]


.


AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}


SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}


SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


.


============== Running Processes ===============


.


C:\Windows\system32\lsm.exe


C:\Windows\system32\svchost.exe -k DcomLaunch


C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe


C:\Windows\system32\svchost.exe -k RPCSS


C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted


C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted


C:\Windows\system32\svchost.exe -k LocalService


C:\Windows\system32\svchost.exe -k netsvcs


C:\Program Files\IDT\WDM\STacSV64.exe


C:\Windows\system32\svchost.exe -k GPSvcGroup


C:\Windows\system32\svchost.exe -k NetworkService


C:\Windows\System32\spoolsv.exe


C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe


C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe


C:\Program Files\Bonjour\mDNSResponder.exe


C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork


C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe


C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe


C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe


C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe


C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe


C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe


C:\Windows\SysWOW64\IoctlSvc.exe


C:\Windows\system32\svchost.exe -k imgsvc


C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE


C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe


C:\Windows\system32\taskhost.exe


C:\Windows\system32\Dwm.exe


C:\Windows\Explorer.EXE


C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe


C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe


C:\Windows\system32\wbem\wmiprvse.exe


C:\Windows\system32\wbem\unsecapp.exe


C:\Windows\System32\hkcmd.exe


C:\Windows\System32\igfxpers.exe


C:\Program Files\IDT\WDM\sttray64.exe


C:\Program Files\Microsoft IntelliPoint\ipoint.exe


C:\Program Files\Synaptics\SynTP\SynTPEnh.exe


C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe


C:\Users\Owner\AppData\Local\TheWeatherNetwork\WeatherEye\WeatherEye.exe


C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe


C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE


C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe


C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe


C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe


C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe


C:\Program Files (x86)\iTunes\iTunesHelper.exe


"c:\windows\syswow64\svchost.exe"


C:\Program Files\iPod\bin\iPodService.exe


"c:\windows\syswow64\svchost.exe"


C:\Windows\system32\SearchIndexer.exe


C:\Program Files\Windows Media Player\wmpnetwk.exe


C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation


C:\Windows\system32\taskeng.exe


C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe


C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe


C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe


C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe


C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe


C:\Program Files\Internet Explorer\iexplore.exe


C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE


C:\Program Files (x86)\Windows Media Player\wmplayer.exe


C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE


C:\Windows\system32\wbem\wmiprvse.exe


C:\Windows\System32\cscript.exe


.


============== Pseudo HJT Report ===============


.


uStart Page = hxxp://expectingrain.com/


mSearchAssistant = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4


mWinlogon: Userinit = userinit.exe,


BHO: CescrtHlpr Object: {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll


BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll


BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll


BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll


BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL


BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll


BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll


TB: facemoods Toolbar: {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll


uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020


uRun: [WeatherEye] C:\Users\Owner\AppData\Local\TheWeatherNetwork\WeatherEye\WeatherEye.exe


uRun: [VideoCard] C:\Users\Owner\AppData\Roaming\VideoCard.exe


mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe


mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"


mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"


mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe


mRun: [NeroFilterCheck] C:\Windows\System32\NeroCheck.exe


mRun: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I


mRun: [MaxMenuMgr] "C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"


mRun: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"


mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"


mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"


mPolicies-Explorer: NoActiveDesktop = dword:1


mPolicies-System: ConsentPromptBehaviorAdmin = dword:5


mPolicies-System: ConsentPromptBehaviorUser = dword:3


mPolicies-System: EnableUIADesktopToggle = dword:0


IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000


IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105


IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll


IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe


IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll


IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll


LSP: mswsock.dll


TCP: NameServer = 64.59.184.13 64.59.190.242


TCP: Interfaces\{30FDC84B-B236-486B-A698-9142C2DAFF25} : DHCPNameServer = 173.243.32.50 8.8.8.8


TCP: Interfaces\{5BB7E7B0-2813-4655-8584-5471CB140AFF} : DHCPNameServer = 209.91.107.11 209.121.225.11


TCP: Interfaces\{EE0F1C56-A1DC-4079-9FBF-25FCC73468B3} : DHCPNameServer = 64.59.184.13 64.59.190.242


TCP: Interfaces\{EE0F1C56-A1DC-4079-9FBF-25FCC73468B3}\34F6163747027457563747 : DHCPNameServer = 173.243.32.50 8.8.8.8


Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL


Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll


SSODL: WebCheck - <orphaned>


x64-BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll


x64-BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll


x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll


x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL


x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll


x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe


x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe


x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe


x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe


x64-Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"


x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe


x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\Antimalware\mssecex.exe" -hide -runkey


x64-RunOnce: [NCPluginUpdater] "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update


x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll


x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll


x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab


x64-DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab


x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab


x64-DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab


x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL


x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>


x64-Notify: igfxcui - igfxdev.dll


x64-SSODL: WebCheck - <orphaned>


.


================= FIREFOX ===================


.


FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\a7waq9e0.default\


FF - prefs.js: browser.startup.homepage - hxxp://pretendersarchives.com/MainMenu.html


FF - prefs.js: network.proxy.type - 0


FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL


FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL


FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll


FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll


.


============= SERVICES / DRIVERS ===============


.


R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2011-4-18 189440]


R2 FPLService;TrueSuiteService;C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2011-5-5 263496]


R2 FreeAgentGoNext Service;Seagate Service;C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-9-25 189736]


R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-9-27 86528]


R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]


R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-8-10 197536]


R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-9-23 13592]


R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-9-23 2372096]


R2 jhi_service;Intel® Identity Protection Technology Host Interface Service;C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-2-24 212944]


R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-9-23 2656280]


R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys [2010-7-28 31088]


R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-5-10 317440]


R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\drivers\netr28x.sys [2011-9-23 1807424]


R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-1-14 565352]


S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]


S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]


S3 HPAuto;HP Auto;C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-2-16 682040]


S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\System32\drivers\MpNWMon.sys [2011-4-18 40832]


S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\drivers\netaapl64.sys [2011-8-2 22528]


S3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2011-4-27 84864]


S3 NisSrv;NisSrv;"c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe" --> c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [?]


S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-2-27 19456]


S3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2011-9-23 335464]


S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]


S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]


S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]


S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-2-27 57856]


S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-2-27 30208]


S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]


S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-12-24 1255736]


S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]


.


=============== File Associations ===============


.


FileExt: .txt: textfile="C:\Program Files (x86)\Windows NT\Accessories\WORDPAD.EXE" "%1" [UserChoice]


.


=============== Created Last 30 ================


.


2013-11-09 06:22:22 -------- d-----w- C:\TDSSKiller_Quarantine


2013-11-03 17:50:21 10280728 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B156D0C5-3F21-4C67-9A43-D10C687361F1}\mpengine.dll


2013-10-18 00:49:34 10280728 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll


2013-10-16 06:20:57 972264 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5882ECB3-1221-4ADA-873E-D7F179A71C96}\gapaengine.dll


2013-10-16 06:19:28 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client


2013-10-16 06:19:25 -------- d-----w- C:\Program Files\Microsoft Security Client


2013-10-16 06:15:12 9694160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{969E2FA4-DC09-4D5D-9149-C88381558336}\mpengine.dll


2013-10-14 03:01:20 143360 ----a-w- C:\Users\Owner\AppData\Roaming\VideoCard.exe


2013-10-14 03:01:10 -------- d-----w- C:\Users\Owner\AppData\Local\Google


2013-10-11 04:12:57 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll


.


==================== Find3M ====================


.


2013-09-27 03:21:22 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl


2013-09-27 03:21:22 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe


2013-09-22 23:28:06 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll


2013-09-22 23:27:49 2876928 ----a-w- C:\Windows\SysWow64\jscript9.dll


2013-09-22 23:27:48 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll


2013-09-22 23:27:48 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll


2013-09-22 22:55:10 2241024 ----a-w- C:\Windows\System32\wininet.dll


2013-09-22 22:54:51 3959296 ----a-w- C:\Windows\System32\jscript9.dll


2013-09-22 22:54:50 67072 ----a-w- C:\Windows\System32\iesetup.dll


2013-09-22 22:54:50 136704 ----a-w- C:\Windows\System32\iesysprep.dll


2013-09-21 03:38:39 2706432 ----a-w- C:\Windows\System32\mshtml.tlb


2013-09-21 03:30:24 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb


2013-09-21 02:48:36 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe


2013-09-21 02:39:47 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe


2013-09-14 01:10:19 497152 ----a-w- C:\Windows\System32\drivers\afd.sys


2013-09-08 02:30:37 1903552 ----a-w- C:\Windows\System32\drivers\tcpip.sys


2013-09-08 02:27:14 327168 ----a-w- C:\Windows\System32\mswsock.dll


2013-09-08 02:03:58 231424 ----a-w- C:\Windows\SysWow64\mswsock.dll


2013-09-03 20:35:10 278800 ------w- C:\Windows\System32\MpSigStub.exe


2013-08-29 02:17:48 5549504 ----a-w- C:\Windows\System32\ntoskrnl.exe


2013-08-29 02:16:35 1732032 ----a-w- C:\Windows\System32\ntdll.dll


2013-08-29 02:16:28 243712 ----a-w- C:\Windows\System32\wow64.dll


2013-08-29 02:16:14 859648 ----a-w- C:\Windows\System32\tdh.dll


2013-08-29 02:13:28 878080 ----a-w- C:\Windows\System32\advapi32.dll


2013-08-29 01:51:45 3969472 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe


2013-08-29 01:51:45 3914176 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe


2013-08-29 01:50:31 5120 ----a-w- C:\Windows\SysWow64\wow32.dll


2013-08-29 01:50:30 1292192 ----a-w- C:\Windows\SysWow64\ntdll.dll


2013-08-29 01:50:16 619520 ----a-w- C:\Windows\SysWow64\tdh.dll


2013-08-29 01:48:17 640512 ----a-w- C:\Windows\SysWow64\advapi32.dll


2013-08-29 01:48:15 44032 ----a-w- C:\Windows\apppatch\acwow64.dll


2013-08-29 00:49:53 25600 ----a-w- C:\Windows\SysWow64\setup16.exe


2013-08-29 00:49:52 7680 ----a-w- C:\Windows\SysWow64\instnm.exe


2013-08-29 00:49:52 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll


2013-08-29 00:49:49 2048 ----a-w- C:\Windows\SysWow64\user.exe


2013-08-28 01:21:06 3155968 ----a-w- C:\Windows\System32\win32k.sys


2013-08-28 01:12:33 461312 ----a-w- C:\Windows\System32\scavengeui.dll


.


============= FINISH: 13:59:38.21 ===============


attach.txt








via Bleeping Computer Last 20 Posts http://www.bleepingcomputer.com/forums/t/513530/mse-disabled-zeroaccess-rootkit/

Aucun commentaire:

Enregistrer un commentaire