This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hijackthis + CFLog

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, my other topic was closed because I thought it was fixed, but today I was keylogged AGAIN after I thought I had got rid of it.
They logged into my World of Warcraft account, and it seems restricted to just that, as I haven't had any other passwords reset or stolen.
In the previous thread the reply was to simply download ATFCleaner and run it, which I've done, and download ComboFix and make a log, which I've done.
Here are the results.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:17:03, on 26/08/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Windows\Explorer.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.skybroadband.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com (file missing)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

–
End of file - 6727 bytes

ComboFix Log:

ComboFix 09-08-25.04 - Hart 26/08/2009 13:55.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3582.2722 [GMT 1:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
PEV Error: CacheFolder

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
c:\windows\system32\config\systemprofile\ntuser.dat{c92be680-c7c0-11dc-8ff1-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms
c:\users\Hart\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms . . . . failed to delete
c:\windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms . . . . failed to delete
c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2009-07-26 to 2009-08-26 )))))))))))))))))))))))))))))))
.

2009-08-26 13:00 . 2009-08-26 13:02 ——– d—–w- c:\users\Hart\AppData\Local\temp
2009-08-26 13:00 . 2009-08-26 13:00 ——– d—–w- c:\users\Default\AppData\Local\temp
2009-08-20 18:16 . 2009-06-24 12:23 660480 —-a-w- c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\pmv304-0906240-0-libOctoshapeClient.dll
2009-08-20 18:16 . 2009-08-20 18:16 120088 —-a-w- c:\users\Hart\AppData\Roaming\Mozilla\Plugins\npoctoshape.dll
2009-08-20 18:16 . 2009-08-20 18:16 ——– d—–w- c:\users\Hart\AppData\Roaming\Octoshape
2009-08-20 18:16 . 2009-06-22 13:37 397824 —-a-w- c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-0906220-0-libOctoshapeClient.dll
2009-08-20 18:16 . 2009-06-22 13:37 124184 —-a-w- c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-0906220-0-apoctoshape.dll
2009-08-20 18:16 . 2009-06-22 13:37 120088 —-a-w- c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-0906220-0-npoctoshape.dll
2009-08-20 18:16 . 2009-01-08 13:44 70936 —-a-w- c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
2009-08-20 01:32 . 2009-08-20 01:32 ——– d—–w- c:\programdata\Blizzard Entertainment
2009-08-18 17:21 . 2009-08-18 17:21 782664 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-08-18 04:22 . 2009-08-18 04:22 ——– d—–w- c:\program files\iPod
2009-08-18 04:22 . 2009-08-18 04:23 ——– d—–w- c:\program files\iTunes
2009-08-17 20:04 . 2009-08-17 20:04 ——– d—–w- c:\programdata\WindowsSearch
2009-08-17 17:01 . 2009-08-17 17:54 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2009-08-17 17:01 . 2009-08-17 17:02 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-17 14:41 . 2009-08-17 14:41 ——– d—–w- c:\program files\Trend Micro
2009-08-17 13:43 . 2009-08-17 16:04 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 13:43 . 2009-08-17 16:04 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 13:43 . 2009-08-17 16:02 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-08-17 13:42 . 2009-08-17 16:05 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 13:42 . 2009-08-17 16:05 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 13:42 . 2009-08-17 16:10 1279456 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-17 13:42 . 2009-08-17 16:05 53328 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-08-17 13:42 . 2003-03-18 19:20 1060864 —-a-w- c:\windows\system32\MFC71.dll
2009-08-17 13:42 . 2009-08-17 13:42 ——– d—–w- c:\program files\Alwil Software
2009-08-13 23:22 . 2009-08-18 00:45 ——– d—–w- c:\program files\Xfire
2009-08-13 19:53 . 2009-08-13 19:53 41872 —-a-w- c:\windows\system32\xfcodec.dll
2009-08-12 23:24 . 2009-06-15 14:54 175104 —-a-w- c:\windows\system32\wdigest.dll
2009-08-12 23:24 . 2009-06-15 14:53 218624 —-a-w- c:\windows\system32\msv1_0.dll
2009-08-12 23:24 . 2009-06-15 14:52 499712 —-a-w- c:\windows\system32\kerberos.dll
2009-08-12 23:24 . 2009-06-15 23:15 439864 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-08-12 23:24 . 2009-06-15 14:53 72704 —-a-w- c:\windows\system32\secur32.dll
2009-08-12 23:24 . 2009-06-15 14:53 270848 —-a-w- c:\windows\system32\schannel.dll
2009-08-12 23:24 . 2009-06-15 14:52 1259008 —-a-w- c:\windows\system32\lsasrv.dll
2009-08-12 23:24 . 2009-06-15 12:48 9728 —-a-w- c:\windows\system32\lsass.exe
2009-08-11 18:51 . 2009-07-17 13:54 71680 —-a-w- c:\windows\system32\atl.dll
2009-08-11 18:51 . 2009-06-10 11:42 160256 —-a-w- c:\windows\system32\wkssvc.dll
2009-08-11 18:51 . 2009-06-04 12:07 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-08-11 18:51 . 2009-06-10 11:38 91136 —-a-w- c:\windows\system32\avifil32.dll
2009-08-11 18:51 . 2009-07-15 12:40 8147456 —-a-w- c:\windows\system32\wmploc.DLL
2009-08-11 18:51 . 2009-07-15 12:39 313344 —-a-w- c:\windows\system32\wmpdxm.dll
2009-08-11 18:51 . 2009-07-15 12:39 4096 —-a-w- c:\windows\system32\dxmasf.dll
2009-08-11 18:51 . 2009-07-15 12:39 7680 —-a-w- c:\windows\system32\spwmp.dll
2009-08-11 02:58 . 2009-08-18 15:47 ——– d—–w- C:\Rise Against - The Sufferer & The Witness [2006] [Punk] [www.file24ever.com]
2009-08-09 16:59 . 2009-08-09 16:59 ——– d—–w- C:\ESCAPE THE FATE - DISCOGRAPHY [CHANNEL NEO]
2009-08-05 19:16 . 2009-08-25 01:18 ——– d—–w- c:\users\Hart\AppData\Local\CurseClient
2009-08-05 19:16 . 2009-08-05 19:16 ——– d—–w- c:\program files\Curse
2009-08-02 01:06 . 2009-08-02 01:08 ——– d—–w- c:\windows\system32\ca-ES
2009-08-02 01:06 . 2009-08-02 01:08 ——– d—–w- c:\windows\system32\eu-ES
2009-08-02 01:06 . 2009-08-02 01:08 ——– d—–w- c:\windows\system32\vi-VN
2009-08-02 00:16 . 2009-08-02 00:16 ——– d—–w- c:\windows\system32\EventProviders
2009-08-01 23:12 . 2009-08-01 23:12 ——– d—–w- c:\users\Hart\AppData\Roaming\skypePM
2009-08-01 23:00 . 2009-08-02 01:49 ——– d—–w- c:\programdata\Skype
2009-07-31 23:37 . 2009-04-11 05:03 12240896 —-a-w- c:\windows\system32\NlsLexicons0007.dll
2009-07-31 23:37 . 2009-04-11 06:28 1081344 —-a-w- c:\windows\system32\SLCExt.dll
2009-07-31 23:37 . 2009-04-11 06:27 3408896 —-a-w- c:\windows\system32\SLsvc.exe
2009-07-31 23:37 . 2009-04-11 06:28 2134528 —-a-w- c:\windows\system32\FunctionDiscoveryFolder.dll
2009-07-31 23:37 . 2009-04-11 06:27 65536 —-a-w- c:\windows\system32\DevicePairingWizard.exe
2009-07-31 23:37 . 2009-04-11 05:03 2644480 —-a-w- c:\windows\system32\NlsLexicons0009.dll
2009-07-31 23:37 . 2009-04-11 06:28 1480704 —-a-w- c:\windows\system32\mssrch.dll
2009-07-31 23:37 . 2009-04-11 02:52 684032 —-a-w- c:\windows\system32\drivers\spsys.sys
2009-07-31 23:37 . 2009-04-11 06:28 1576960 —-a-w- c:\windows\system32\tquery.dll
2009-07-31 23:35 . 2009-04-11 06:28 61440 —-a-w- c:\windows\system32\wscsvc.dll
2009-07-31 23:34 . 2009-04-11 06:28 83968 —-a-w- c:\windows\system32\wbem\wmiutils.dll
2009-07-31 23:34 . 2009-04-11 06:28 744448 —-a-w- c:\windows\system32\wbem\wbemcore.dll
2009-07-31 23:34 . 2009-04-11 06:28 30208 —-a-w- c:\windows\system32\wbem\wbemprox.dll
2009-07-31 23:34 . 2009-04-11 06:28 265728 —-a-w- c:\windows\system32\wbem\repdrvfs.dll
2009-07-31 23:34 . 2009-04-11 06:28 189440 —-a-w- c:\windows\system32\wbem\mofd.dll
2009-07-31 23:34 . 2009-04-11 06:28 614912 —-a-w- c:\windows\system32\wbem\fastprox.dll
2009-07-31 23:34 . 2009-04-11 06:28 265728 —-a-w- c:\windows\system32\wbem\esscli.dll
2009-07-31 23:34 . 2009-04-11 06:28 705536 —-a-w- c:\windows\system32\SmiEngine.dll
2009-07-31 23:34 . 2009-04-11 06:28 218624 —-a-w- c:\windows\system32\wdscore.dll
2009-07-31 23:34 . 2009-04-11 06:27 130560 —-a-w- c:\windows\system32\PkgMgr.exe
2009-07-31 23:34 . 2009-04-11 06:28 247808 —-a-w- c:\windows\system32\drvstore.dll
2009-07-31 01:29 . 2009-07-31 01:48 ——– d—–w- c:\users\Hart\3.0.1.8874 EU PTR Installer
2009-07-29 19:12 . 2009-07-29 19:12 ——– d—–w- c:\users\Hart\AppData\Local\Ares
2009-07-29 19:12 . 2009-07-29 19:12 ——– d—–w- c:\program files\Ares
2009-07-29 02:19 . 2009-08-25 16:34 ——– d—–w- c:\users\Hart\.worldoflogs
2009-07-29 02:17 . 2009-07-25 04:23 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-07-29 02:16 . 2009-08-05 01:49 ——– d—–w- c:\program files\Java
2009-07-29 02:16 . 2009-07-29 02:16 ——– d—–w- c:\programdata\McAfee

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 13:02 . 2009-07-24 11:02 49552 —-a-w- c:\programdata\nvModes.dat
2009-08-26 13:01 . 2009-07-24 10:58 ——– d—–w- c:\programdata\NVIDIA
2009-08-26 06:43 . 2009-07-24 21:00 ——– d—–w- c:\program files\Steam
2009-08-25 01:21 . 2009-08-21 18:37 ——– d—–w- c:\users\Hart\AppData\Roaming\RayV
2009-08-23 16:12 . 2009-07-24 09:50 ——– d—–w- c:\programdata\avg8
2009-08-22 07:02 . 2009-07-25 02:37 ——– d—–w- c:\users\Hart\AppData\Roaming\vlc
2009-08-22 05:03 . 2009-07-24 23:13 ——– d—–w- c:\users\Hart\AppData\Roaming\uTorrent
2009-08-21 15:45 . 2009-07-24 21:00 ——– d—–w- c:\program files\Common Files\Steam
2009-08-20 14:38 . 2009-07-24 15:53 ——– d—–w- c:\users\Hart\AppData\Roaming\Xfire
2009-08-20 13:41 . 2009-07-24 15:53 ——– d—–w- c:\programdata\Xfire
2009-08-19 17:03 . 2009-07-24 10:00 ——– d—–w- c:\programdata\Microsoft Help
2009-08-18 04:22 . 2009-07-24 16:06 ——– d—–w- c:\program files\Common Files\Apple
2009-08-12 07:12 . 2009-07-24 16:54 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2009-08-12 02:01 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Calendar
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Journal
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Collaboration
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Photo Gallery
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Defender
2009-08-02 01:05 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-08-01 23:12 . 2009-08-01 23:12 56 —ha-w- c:\programdata\ezsidmv.dat
2009-07-25 08:58 . 2009-07-25 08:58 ——– d—–w- c:\users\Hart\AppData\Roaming\Samsung
2009-07-25 08:57 . 2009-07-25 08:50 5632 —-a-w- c:\windows\system32\drivers\StarOpen.sys
2009-07-25 08:50 . 2009-07-24 08:32 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-25 08:42 . 2009-07-25 08:42 ——– d—–w- c:\program files\Samsung
2009-07-25 02:00 . 2009-07-25 02:00 ——– d—–w- c:\program files\MSXML 4.0
2009-07-24 23:53 . 2009-07-24 23:53 ——– d—–w- c:\users\Hart\AppData\Roaming\Nero
2009-07-24 23:14 . 2009-07-24 23:14 ——– d—–w- c:\program files\uTorrent
2009-07-24 19:35 . 2009-07-24 19:35 ——– d—–w- c:\program files\My Company Name
2009-07-24 19:34 . 2009-07-24 08:32 ——– d—–w- c:\program files\Common Files\InstallShield
2009-07-24 19:31 . 2009-07-24 19:31 ——– d—–w- c:\program files\VideoLAN
2009-07-24 17:39 . 2009-07-24 17:39 ——– d—–w- c:\programdata\Blizzard
2009-07-24 17:11 . 2009-07-24 16:34 ——– d—–w- c:\users\Hart\AppData\Roaming\Ventrilo
2009-07-24 16:38 . 2009-07-24 16:38 ——– d—–w- c:\program files\Microsoft
2009-07-24 16:38 . 2009-07-24 16:37 ——– d—–w- c:\program files\Windows Live
2009-07-24 16:38 . 2009-07-24 16:38 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-07-24 16:35 . 2009-07-24 16:35 ——– d—–w- c:\program files\Common Files\Windows Live
2009-07-24 16:33 . 2009-07-24 16:33 ——– d—–w- c:\program files\Ventrilo
2009-07-24 16:32 . 2009-07-24 10:57 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-07-24 16:22 . 2009-07-24 16:09 ——– d—–w- c:\users\Hart\AppData\Roaming\Apple Computer
2009-07-24 16:09 . 2009-07-24 16:08 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-24 16:08 . 2009-07-24 16:07 ——– d—–w- c:\programdata\Apple Computer
2009-07-24 16:08 . 2009-07-24 16:08 ——– d—–w- c:\program files\Bonjour
2009-07-24 16:08 . 2009-07-24 16:07 ——– d—–w- c:\program files\QuickTime
2009-07-24 16:07 . 2009-07-24 16:07 ——– d—–w- c:\program files\Apple Software Update
2009-07-24 16:06 . 2009-07-24 16:06 ——– d—–w- c:\programdata\Apple
2009-07-24 15:46 . 2009-07-24 15:46 ——– d—–w- c:\program files\Sky Broadband
2009-07-24 15:41 . 2009-07-24 15:41 ——– d–h–w- c:\programdata\CanonBJ
2009-07-24 10:58 . 2009-07-24 10:58 ——– d—–w- c:\program files\NVIDIA Corporation
2009-07-24 10:57 . 2009-07-24 10:57 ——– d—–w- c:\program files\AGEIA Technologies
2009-07-24 10:37 . 2009-07-24 08:21 1356 —-a-w- c:\users\Hart\AppData\Local\d3d9caps.dat
2009-07-24 10:25 . 2009-07-24 10:25 ——– d—–w- c:\program files\VistaCodecPack
2009-07-24 10:21 . 2009-07-24 10:21 ——– d—–w- c:\programdata\VistaCodecs
2009-07-24 10:20 . 2009-07-24 10:20 ——– d—–w- c:\programdata\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2009-07-24 10:20 . 2009-07-24 10:20 ——– d—–w- c:\program files\Activation Assistant for the 2007 Microsoft Office suites
2009-07-24 10:15 . 2009-07-24 08:21 58896 —-a-w- c:\users\Hart\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-24 10:02 . 2009-07-24 10:02 ——– d—–w- c:\program files\Microsoft Works
2009-07-24 10:02 . 2009-07-24 10:02 ——– d—–w- c:\program files\Microsoft.NET
2009-07-24 09:58 . 2009-07-24 09:58 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-07-24 09:50 . 2009-07-24 09:50 ——– d—–w- c:\program files\AVG
2009-07-24 09:38 . 2009-07-24 09:38 ——– d—–w- c:\program files\NeroInstall.bak
2009-07-24 09:36 . 2009-07-24 09:34 ——– d—–w- c:\program files\Common Files\Nero
2009-07-24 09:34 . 2009-07-24 09:34 ——– d—–w- c:\programdata\Nero
2009-07-24 09:34 . 2009-07-24 09:34 ——– d—–w- c:\program files\Nero
2009-07-24 09:25 . 2009-07-24 08:43 ——– d—–w- c:\programdata\NOS
2009-07-24 09:25 . 2009-07-24 08:43 ——– d—–w- c:\program files\NOS
2009-07-24 08:54 . 2009-07-24 08:54 ——– d—–w- c:\program files\ASUS
2009-07-24 08:52 . 2009-07-24 08:54 24576 —-a-w- c:\windows\system32\AsIO.dll
2009-07-24 08:52 . 2009-07-24 08:54 12400 —-a-w- c:\windows\system32\drivers\AsIO.sys
2009-07-24 08:45 . 2009-07-24 08:45 ——– d—–w- c:\program files\Common Files\Adobe
2009-07-24 08:44 . 2009-07-24 08:44 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-07-24 08:44 . 2009-07-24 08:44 86016 —-a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe
2009-07-24 08:32 . 2009-07-24 08:32 319456 —-a-w- c:\windows\DIFxAPI.dll
2009-07-24 08:32 . 2009-07-24 08:32 ——– d—–w- c:\program files\Realtek
2009-07-24 08:32 . 2009-07-24 08:32 315392 —-a-w- c:\windows\HideWin.exe
2009-07-24 08:24 . 2009-07-24 08:24 ——– d—–w- c:\program files\Intel
2009-07-21 21:52 . 2009-07-29 02:33 915456 —-a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 02:33 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 02:33 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 02:33 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-07-20 15:09 . 2009-07-24 18:24 282624 —-a-w- c:\users\Hart\AppData\Roaming\Mozilla\Firefox\Profiles\7ikh45np.default\extensions\[removed]\Plugins\npDyyno.dll
2009-07-14 12:29 . 2009-07-14 12:29 2505248 —-a-w- c:\windows\system32\nvcpluir.dll
2009-07-13 13:22 . 2009-07-13 13:22 75048 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-10 06:01 . 2009-07-24 10:55 485920 —-a-w- c:\windows\system32\NVUNINST.EXE
2009-06-15 14:53 . 2009-07-24 08:49 156672 —-a-w- c:\windows\system32\t2embed.dll
2009-06-15 14:52 . 2009-07-24 08:49 23552 —-a-w- c:\windows\system32\lpk.dll
2009-06-15 14:52 . 2009-07-24 08:49 72704 —-a-w- c:\windows\system32\fontsub.dll
2009-06-15 14:51 . 2009-07-24 08:49 10240 —-a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:42 . 2009-07-24 08:49 289792 —-a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-08-20_19.17.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-08-24 11:11 36668 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-08-26 09:13 60370 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-24 16:03 . 2009-07-24 16:03 84661 c:\windows\System32\Macromed\Flash\uninstall_plugin.exe
+ 2009-07-24 16:03 . 2009-08-23 16:11 84661 c:\windows\System32\Macromed\Flash\uninstall_plugin.exe
+ 2009-07-24 08:21 . 2009-08-26 13:01 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-24 08:21 . 2009-08-20 18:42 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-24 08:21 . 2009-08-26 13:01 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-24 08:21 . 2009-08-20 18:42 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-24 08:21 . 2009-08-20 18:42 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-24 08:21 . 2009-08-26 13:01 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 07:11 . 2006-11-02 07:11 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6002.18046_none_0de371cfef8dc034\AcRes.dll
+ 2009-07-24 08:51 . 2008-03-08 01:58 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6001.18267_none_0be85e73f276bf22\AcRes.dll
+ 2009-07-24 09:23 . 2009-08-23 16:07 4410 c:\windows\System32\WDI\ERCQueuedResolutions.dat
- 2009-07-24 09:23 . 2009-08-18 22:02 4410 c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2009-07-24 08:23 . 2009-08-26 09:13 6402 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2809076371-2212094262-4108447950-1000_UserData.bin
+ 2009-07-26 09:10 . 2009-08-26 12:41 201934 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2006-11-02 10:33 . 2009-08-26 09:19 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-08-20 14:45 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-08-20 14:45 105448 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-08-26 09:19 105448 c:\windows\System32\perfc009.dat
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\System32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-07-31 23:36 . 2009-04-11 06:28 1696768 c:\windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.18046_none_43c188b4be7e55e2\gameux.dll
+ 2009-07-24 08:51 . 2008-03-08 04:21 1695744 c:\windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.18267_none_41c67558c16754d0\gameux.dll
+ 2006-11-02 10:22 . 2009-08-26 06:33 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2006-11-02 10:22 . 2009-08-13 07:30 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\System32\Macromed\Flash\NPSWF32.dll
+ 2009-07-24 09:28 . 2009-08-26 06:33 128417399 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Octoshape Streaming Services"="c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-08 70936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-07-03 6266880]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2008-06-25 1826816]

c:\users\Hart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):7f,63,b9,96,0e,13,ca,01

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DA5E6BCC-2D98-4D40-8995-CFC28187AC43}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{AE2BF41F-77DD-4D1F-8B0B-0353455ACAB1}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{F022D00D-F6BD-473D-847F-91124814D2B3}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{03E31955-19C4-4476-90D8-46103EF0A811}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{6F0D3C08-A92B-4F01-9F86-526F0E4BAAB6}c:\\users\\hart\\documents\\d drive\\xfire\\xfire.exe"= UDP:c:\users\hart\documents\d drive\xfire\xfire.exe:xfire.exe
"UDP Query User{A680F75D-8FA4-47B4-842D-BFA59869C0E8}c:\\users\\hart\\documents\\d drive\\xfire\\xfire.exe"= TCP:c:\users\hart\documents\d drive\xfire\xfire.exe:xfire.exe
"{A5924FDE-03FF-48ED-81A7-9CFD62740B28}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{61EB6808-EE84-442E-97B7-77F977EA9F93}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{FC55767C-D9E2-4083-B86F-2210CAECDDAD}c:\\d drive\\world of warcraft\\backgrounddownloader.exe"= UDP:c:\d drive\world of warcraft\backgrounddownloader.exe:Blizzard Downloader
"UDP Query User{F80EE7F5-52FF-4A50-8529-602881C5368B}c:\\d drive\\world of warcraft\\backgrounddownloader.exe"= TCP:c:\d drive\world of warcraft\backgrounddownloader.exe:Blizzard Downloader
"{BF83E13B-22BF-43E7-AA63-181335EDBA30}"= UDP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"{1751FE31-7F6C-4182-9F25-2177A3345C63}"= TCP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"TCP Query User{84D54768-0109-4721-A5FF-A05ACB8AB2A6}c:\\users\\hart\\appdata\\locallow\\dyyno receiver\\dppm.exe"= UDP:c:\users\hart\appdata\locallow\dyyno receiver\dppm.exe:dppm.exe
"UDP Query User{EE7823F0-F188-4FC7-BB65-9B57C78D5F29}c:\\users\\hart\\appdata\\locallow\\dyyno receiver\\dppm.exe"= TCP:c:\users\hart\appdata\locallow\dyyno receiver\dppm.exe:dppm.exe
"TCP Query User{52D88A08-C015-4E98-8364-9FB8FB959717}c:\\world of warcraft\\launcher.exe"= UDP:c:\world of warcraft\launcher.exe:Blizzard Launcher
"UDP Query User{721CD836-BD14-4D1E-97FD-C170D4B2B2CB}c:\\world of warcraft\\launcher.exe"= TCP:c:\world of warcraft\launcher.exe:Blizzard Launcher
"{6F288A60-2C34-4F62-90DE-3D854140359B}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-enGB-downloader.exe:Blizzard Downloader
"{10A2DCA4-B37A-45D1-8527-DBC96F87B497}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-enGB-downloader.exe:Blizzard Downloader
"{0BADB25F-2E4D-4D90-A178-FB5EC431B65C}"= UDP:3724:Blizzard Downloader: 3724
"{95A4FA98-575A-46E7-9DA1-FE39C214293E}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{DBFE6EF7-CFD3-456E-92B3-085050F354E1}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{40A93E66-8E2A-438D-8F5D-2970955F1221}c:\\program files\\steam\\steamapps\\the_bigman\\counter-strike source\\hl2.exe"= UDP:c:\program files\steam\steamapps\the_bigman\counter-strike source\hl2.exe:hl2
"UDP Query User{4EFD0858-4335-433D-80EE-A1EC0F81CC99}c:\\program files\\steam\\steamapps\\the_bigman\\counter-strike source\\hl2.exe"= TCP:c:\program files\steam\steamapps\the_bigman\counter-strike source\hl2.exe:hl2
"{6A8E190A-3AE6-4DFF-AA4F-7884B706FD2D}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10048-to-0.2.0.10072-enGB-downloader.exe:Blizzard Downloader
"{9DFB850B-A9DA-4A9D-9B32-BAC3C15FFB3B}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10048-to-0.2.0.10072-enGB-downloader.exe:Blizzard Downloader
"{FB898F2C-471C-4D63-AAC2-107271044862}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10072-to-0.2.0.10083-enGB-downloader.exe:Blizzard Downloader
"{EBBFADEE-3A6C-4A29-96FE-E306E688127D}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10072-to-0.2.0.10083-enGB-downloader.exe:Blizzard Downloader
"{3DBD53F5-D3E5-473D-940F-AB2D62CA3250}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\wow-0.2.0.10083-to-0.2.0.10116-enGB-downloader.exe:Blizzard Downloader
"{BB48A926-994E-4E42-952B-DDCB48D798E7}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\wow-0.2.0.10083-to-0.2.0.10116-enGB-downloader.exe:Blizzard Downloader
"{FE39BEC2-9E53-43E9-A7FA-E9A054DAD123}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10116-to-0.2.0.10128-enGB-downloader.exe:Blizzard Downloader
"{C791A3C2-7BF4-4933-8B94-178F2CCBE428}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10116-to-0.2.0.10128-enGB-downloader.exe:Blizzard Downloader
"{FD13FE4F-8167-4F39-8A39-E9F8CEA7D844}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10128-to-0.2.0.10147-enGB-downloader.exe:Blizzard Downloader
"{F37F4D57-F80B-4A45-9F60-DDD0DC1DD70F}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10128-to-0.2.0.10147-enGB-downloader.exe:Blizzard Downloader
"{20D6BC59-7AFD-4309-9CA6-7D9F4DBAA1B1}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10147-to-0.2.0.10170-enGB-downloader.exe:Blizzard Downloader
"{F387C577-8CA6-4FF3-963D-ADDBABA7BBEA}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10147-to-0.2.0.10170-enGB-downloader.exe:Blizzard Downloader
"{01678A26-0F18-4BAD-B4E1-B43B90A0053D}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10170-to-0.2.0.10179-enGB-downloader.exe:Blizzard Downloader
"{FE512B6A-2914-4C14-B827-E0A9BEB8FB6B}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10170-to-0.2.0.10179-enGB-downloader.exe:Blizzard Downloader
"{8D6D4A7F-59DE-4C4D-9E98-A4B6A18D68E9}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10179-to-0.2.0.10192-enGB-downloader.exe:Blizzard Downloader
"{64A9BC09-18C2-4CCD-AD49-E4B2D4DC1508}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10179-to-0.2.0.10192-enGB-downloader.exe:Blizzard Downloader
"{EFE6E42C-DBC5-4F0B-8E7C-94C5ECD8C91C}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe:Blizzard Downloader
"{9BFF6FD9-DC55-46B0-9B5E-900E78DD287F}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe:Blizzard Downloader
"{AF35F03A-0E84-4786-81DE-E83F15FC4F73}"= UDP:c:\program files\Curse\CurseClient.exe:Curse Client
"{804A03D9-4BA3-4C4A-8569-0C7DF17396B8}"= TCP:c:\program files\Curse\CurseClient.exe:Curse Client
"TCP Query User{277E3B24-D751-4D8B-A444-1563537CD3F1}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{7269B75B-E452-4A75-824F-D0FB8385FC33}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"TCP Query User{9A5FA208-2F9B-486B-A389-19B259B30A5C}c:\\program files\\xfire\\xfire.exe"= UDP:c:\program files\xfire\xfire.exe:Xfire
"UDP Query User{0EC630CC-D154-4FAF-A559-B20682FB9FE7}c:\\program files\\xfire\\xfire.exe"= TCP:c:\program files\xfire\xfire.exe:Xfire
"{0D6039D9-C765-4223-88E6-00CF3A2F28C9}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{544F42B1-C1B9-4D96-B601-7A20307D792E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{1016EA34-8E33-4AB2-AD6D-D452AF57952F}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe:Blizzard Downloader
"{EB0FD12C-95CC-48A4-B79B-1C62EA54F997}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe:Blizzard Downloader
"TCP Query User{9F64B24A-084E-42A1-B7EE-B6A72F20A658}c:\\program files\\rayv\\rayv\\rayv.exe"= UDP:c:\program files\rayv\rayv\rayv.exe:RayV
"UDP Query User{A1C75037-E712-4082-BE77-EEA749DDE75D}c:\\program files\\rayv\\rayv\\rayv.exe"= TCP:c:\program files\rayv\rayv\rayv.exe:RayV

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [17/08/2009 14:42 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [17/08/2009 14:42 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [17/08/2009 14:42 53328]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [14/07/2009 12:28 239648]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\System32\drivers\l160x86.sys [24/07/2009 09:34 46592]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-26 c:\windows\Tasks\User_Feed_Synchronization-{C6F7EF7B-F0D7-4475-8F74-C275E15C8FD8}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.skybroadband.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\users\Hart\AppData\Roaming\Mozilla\Firefox\Profiles\7ikh45np.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF - plugin: c:\users\Hart\AppData\Roaming\Mozilla\Firefox\Profiles\7ikh45np.default\extensions\[removed]\plugins\npDyyno.dll
FF - plugin: c:\users\Hart\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-26 14:01
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
———————— Other Running Processes ————————
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\nvvsvc.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\System32\IoctlSvc.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-08-26 14:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-26 13:05
ComboFix2.txt 2009-08-20 19:18

Pre-Run: 204,761,321,472 bytes free
Post-Run: 204,615,528,448 bytes free

433 — E O F — 2009-08-20 23:32



Any amount of help would be appreciated as this is becoming extremely frustrating, thanks.

Oh, the Malwarebytes' Anti-Walware log:

Malwarebytes' Anti-Malware 1.40
Database version: 2699
Windows 6.0.6002 Service Pack 2

26/08/2009 17:24:48
mbam-log-2009-08-26 (17-24-48).txt

Scan type: Full Scan (C:\|)
Objects scanned: 199943
Time elapsed: 40 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Oops, was supposed to be an edit :/
redemption,

I don't see any sign of a keylogger. What makes you think you had/have one? Just your WOW account getting hacked?

There has been a spate of users complaining of their WOW account being hacked but no sign of infections on their system. WOW servers have been hacked before. I just don't know.

Let's get another scan.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
redemption,

No worries there.

I don't see any malware on your system. I don't know how you got hacked or what is going on but in the last two to three weeks, there have been dozens of complaints like yours. I wish I could be more helpful.

Log looks good :D


You need to create a new Clean restore point:

  • Download SysRestorePoint to your desktop and unzip it to it's own folder.
  • Double click SysRestorePoint.exe so that we can make a new system restore point.
  • A box will pop up after it has made a new point, usually after a few seconds. Close that window and exit the program.
Remove all previous Restore Points
Click Start Menu > Run > copy and paste

cleanmgr

You may be asked to choose drive. Choose C: At top, click on More Options tab. Click Clean up… button in the System Restore box. Click on Yes button. When finished, click on Cancel button to exit.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI