This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help, My pc Is running Extremly Slow!

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok here is my Kaspersky Log File


——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, January 13, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Wednesday, January 13, 2010 02:42:01
Records in database: 3301893
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan statistics:
Objects scanned: 148185
Threats found: 3
Infected objects found: 3
Suspicious objects found: 0
Scan duration: 03:59:49


File name / Threat / Threats count
C:\Documents and Settings\Jeff Matthews\Application Data\Sun\Java\Deployment\cache\6.0\12\16c3138c-53f905dc Infected: Trojan-Downloader.Java.OpenStream.ad 1
C:\Documents and Settings\Jeff Matthews\My Documents\Documents and Settings\Game Directory\Emulators\games\NDS\Lunar Dragon Song USA (Nintendo DS)\Lunar Dragon Song USA (Nintendo DS)\WinZix-2.3.0.0-setup.exe Infected: Trojan.Win32.C4DLMedia.b 1
C:\Documents and Settings\Jeff Matthews\My Documents\Documents and Settings\Game Directory\Encoding\UltraVNC_105_Setup_W32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ab 1

Selected area has been scanned.

I also installed Avira as my anti virus program.
Sorry for the double post. But i also wanted to add that programs that require graphics or video like mostly video games and what not. They are running at around 90% CPU and under "memory Usage" It says 780k That is an absurd amount of physical memory being used. Do you think this has to do with the viruses and maleware on my machine. I hope to solve this problem as well. I can't play any games or do anything on my computer that requires graphics or high video. My specs for my computer are definitely strong enough to run most games, but yet i still have this problem. Also i think this may be the cause of my BSOD crashes as well. I have certain BSOD crashes and they only seem to happen when im playing video games on the computer. They will do one of two things, either go "non responsive" and just shut down, or it will cause a BSOD crash. This is something that i REALLY want to solve. I been asking around at other various tech forums for the answers to see if any one knows anything. People always tell me its related to RAM. But i have changed my RAM twice in the last few months so i know that has to be impossible. One of my friends says it could be video codecs thats causing the problem. Anyway if you have any knowledge on this and might know whats going on or maybe you can give me some diagnoses to run on my pc to try and figure out this problem, i would appreciate it alot, thanks!
jeff,

MBAM took care of the crack/keygen. The point I was trying to make with you is that P2P and cracks/keygens are a major source of malware. Since you have or had both, you are at very high risk for continued problems. I don't think it's a coincidence that you have had multiple infections and other issues with your computer.

🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::


File::
C:\Documents and Settings\Jeff Matthews\Application Data\Sun\Java\Deployment\cache\6.0\12\16c3138c-53f905dc
C:\Documents and Settings\Jeff Matthews\My Documents\Documents and Settings\Game Directory\Emulators\games\NDS\Lunar Dragon Song USA (Nintendo DS)\Lunar Dragon Song USA (Nintendo DS)\WinZix-2.3.0.0-setup.exe

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new DDS log.

🖼Click to load external image (Posted Image) Download Security Check from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Your next post should include:
  • ComboFix log
  • Security Check log
  • Fresh DDS log
Here is my DDS log



DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 11:01:36.68 on Wed 01/13/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2332 [GMT -8:00]


============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jeff Matthews\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - No File
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [CurseClient] c:\program files\curse\CurseClient.exe -silent
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: &AOL Toolbar Search
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll/206
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F}
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1243547212812
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jeffma~1\applic~1\mozilla\firefox\profiles\t00b4ems.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\mpcstar\codecs\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\mpcstar\codecs\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-11-11 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-11-11 74480]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-8-1 24652]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-11-11 7408]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2010-1-11 25832]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2009-11-26 95568]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\vboxnetflt.sys –> c:\windows\system32\drivers\VBoxNetFlt.sys [?]

=============== Created Last 30 ================

2010-01-13 18:48:48 0 d—–w- C:\ComboFix
2010-01-12 17:02:41 0 d—–w- C:\Rooter$
2010-01-12 05:14:19 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-12 05:14:18 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-12 05:14:18 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-12 01:22:32 0 d—–w- c:\docume~1\alluse~1\applic~1\BioWare
2010-01-12 00:55:26 0 d—–w- c:\program files\Dragon Age
2010-01-11 16:33:08 0 d-sha-r- C:\cmdcons
2010-01-11 16:31:50 98816 —-a-w- c:\windows\sed.exe
2010-01-11 16:31:50 77312 —-a-w- c:\windows\MBR.exe
2010-01-11 16:31:50 261632 —-a-w- c:\windows\PEV.exe
2010-01-11 16:31:50 161792 —-a-w- c:\windows\SWREG.exe
2010-01-06 14:38:30 0 d—–w- c:\program files\common files\BioWare
2010-01-06 14:36:25 0 d—–w- c:\program files\Dragon Age Origins Character Creator
2010-01-04 11:30:25 87 —-a-w- c:\windows\MrSetup.ini
2010-01-04 11:30:24 327680 ——w- c:\windows\MrSetup.exe
2010-01-04 11:30:14 0 d—–w- c:\program files\Studio-74

==================== Find3M ====================

2009-12-11 10:41:37 4876 —-a-w- c:\documents and settings\jeff matthews\FilterData.dat
2009-11-27 23:44:10 18440 -c–a-w- c:\docume~1\jeffma~1\applic~1\GDIPFONTCACHEV1.DAT
2009-10-29 07:45:38 916480 ——w- c:\windows\system32\wininet.dll
2009-10-25 07:40:54 47360 —-a-w- c:\docume~1\jeffma~1\applic~1\pcouffin.sys
2009-10-21 05:38:36 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 —-a-w- c:\windows\system32\httpapi.dll

============= FINISH: 11:01:47.04 ===============


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 5/28/2009 9:23:27 AM
System Uptime: 1/13/2010 5:56:44 AM (6 hours ago)

Motherboard: ASUSTeK Computer INC. | | M2N-E SLI
Processor: AMD Athlon™ 64 X2 Dual Core Processor 6400+ | Socket AM2 | 3216/200mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 149 GiB total, 53.733 GiB free.
D: is FIXED (NTFS) - 39 GiB total, 12.508 GiB free.
E: is FIXED (NTFS) - 35 GiB total, 15.497 GiB free.
F: is CDROM (CDFS)
G: is FIXED (NTFS) - 149 GiB total, 77.365 GiB free.
H: is CDROM ()
I: is FIXED (NTFS) - 932 GiB total, 676.024 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: ACPI\ATK0110\1010110
Manufacturer:
Name:
PNP Device ID: ACPI\ATK0110\1010110
Service:

==== System Restore Points ===================

RP169: 10/16/2009 5:21:21 AM - System Checkpoint
RP170: 10/17/2009 5:26:02 AM - System Checkpoint
RP171: 10/18/2009 6:20:46 AM - System Checkpoint
RP172: 10/19/2009 6:40:58 AM - System Checkpoint
RP173: 10/20/2009 3:07:23 PM - System Checkpoint
RP174: 10/21/2009 4:25:45 PM - System Checkpoint
RP175: 10/22/2009 6:55:30 PM - System Checkpoint
RP176: 10/24/2009 1:46:24 AM - System Checkpoint
RP177: 10/24/2009 11:26:25 PM - Restore Operation
RP178: 10/24/2009 11:31:28 PM - Software Distribution Service 3.0
RP179: 10/24/2009 11:46:55 PM - Removed Apple Application Support
RP180: 10/25/2009 12:08:03 AM - Removed OTB
RP181: 10/25/2009 4:42:53 PM - Installed WinZip 12.0
RP182: 10/26/2009 5:30:03 PM - System Checkpoint
RP183: 10/27/2009 10:09:24 PM - System Checkpoint
RP184: 10/29/2009 1:40:18 AM - System Checkpoint
RP185: 10/30/2009 6:04:14 AM - System Checkpoint
RP186: 10/31/2009 6:14:38 AM - System Checkpoint
RP187: 11/1/2009 7:23:48 AM - System Checkpoint
RP188: 11/1/2009 3:05:41 PM - Removed Microsoft Silverlight
RP189: 11/1/2009 3:06:48 PM - Removed WinZip 12.0
RP190: 11/2/2009 3:47:32 PM - System Checkpoint
RP191: 11/3/2009 4:14:30 PM - System Checkpoint
RP192: 11/4/2009 4:58:37 PM - System Checkpoint
RP193: 11/5/2009 5:48:19 PM - System Checkpoint
RP194: 11/6/2009 6:02:50 PM - System Checkpoint
RP195: 11/7/2009 6:21:53 PM - System Checkpoint
RP196: 11/8/2009 5:22:59 PM - System Checkpoint
RP197: 11/9/2009 6:32:57 PM - System Checkpoint
RP198: 11/10/2009 5:51:48 PM - Installed Windows XP KB954708.
RP199: 11/10/2009 5:52:01 PM - Installed DirectX
RP200: 11/11/2009 7:05:12 PM - System Checkpoint
RP201: 11/11/2009 9:19:33 PM - Software Distribution Service 3.0
RP202: 11/12/2009 11:36:23 PM - System Checkpoint
RP203: 11/13/2009 1:02:20 PM - Installed SUPERAntiSpyware Free Edition
RP204: 11/14/2009 3:50:45 AM - Installed RPGXP
RP205: 11/14/2009 3:51:15 AM - Installed RGSS-RTP Standard
RP206: 11/15/2009 4:16:59 AM - System Checkpoint
RP207: 11/16/2009 5:05:53 AM - System Checkpoint
RP208: 11/17/2009 6:05:53 AM - System Checkpoint
RP209: 11/18/2009 7:19:53 AM - System Checkpoint
RP210: 11/19/2009 8:06:01 AM - System Checkpoint
RP211: 11/20/2009 2:53:44 PM - System Checkpoint
RP212: 11/21/2009 4:03:29 PM - System Checkpoint
RP213: 11/22/2009 5:39:35 PM - System Checkpoint
RP214: 11/23/2009 7:38:25 PM - System Checkpoint
RP215: 11/24/2009 7:58:57 PM - System Checkpoint
RP216: 11/25/2009 3:00:12 AM - Software Distribution Service 3.0
RP217: 11/26/2009 3:02:00 AM - System Checkpoint
RP218: 11/26/2009 4:08:59 PM - Installed Sun VirtualBox
RP219: 11/27/2009 5:54:44 PM - System Checkpoint
RP220: 11/28/2009 2:33:01 PM - Restore Operation
RP221: 11/29/2009 2:39:37 PM - System Checkpoint
RP222: 11/30/2009 3:06:38 PM - System Checkpoint
RP223: 12/1/2009 4:26:49 PM - System Checkpoint
RP224: 12/2/2009 6:12:44 PM - System Checkpoint
RP225: 12/3/2009 8:05:12 PM - System Checkpoint
RP226: 12/5/2009 12:36:31 AM - System Checkpoint
RP227: 12/6/2009 12:39:40 AM - System Checkpoint
RP228: 12/7/2009 12:49:07 AM - System Checkpoint
RP229: 12/8/2009 1:22:31 AM - System Checkpoint
RP230: 12/9/2009 1:26:47 AM - System Checkpoint
RP231: 12/10/2009 2:22:30 AM - System Checkpoint
RP232: 12/10/2009 3:00:13 AM - Software Distribution Service 3.0
RP233: 12/11/2009 2:13:19 PM - System Checkpoint
RP234: 12/12/2009 2:23:00 PM - System Checkpoint
RP235: 12/13/2009 9:44:13 PM - System Checkpoint
RP236: 12/14/2009 9:56:23 PM - System Checkpoint
RP237: 12/15/2009 10:52:59 PM - System Checkpoint
RP238: 12/17/2009 1:10:43 AM - System Checkpoint
RP239: 12/18/2009 2:05:40 AM - System Checkpoint
RP240: 12/19/2009 3:55:40 PM - System Checkpoint
RP241: 12/20/2009 6:54:46 PM - System Checkpoint
RP242: 12/21/2009 7:42:23 PM - System Checkpoint
RP243: 12/22/2009 8:17:40 PM - System Checkpoint
RP244: 12/23/2009 8:25:59 PM - System Checkpoint
RP245: 12/24/2009 9:24:10 PM - System Checkpoint
RP246: 12/25/2009 10:13:57 PM - System Checkpoint
RP247: 12/26/2009 11:12:07 PM - System Checkpoint
RP248: 12/27/2009 12:26:18 PM - Removed Aion
RP249: 12/27/2009 12:28:03 PM - Removed RPGXP
RP250: 12/27/2009 12:28:17 PM - Removed RGSS-RTP Standard
RP251: 12/27/2009 12:28:41 PM - Removed Sun VirtualBox
RP252: 12/28/2009 1:12:07 PM - System Checkpoint
RP253: 12/29/2009 1:58:45 PM - System Checkpoint
RP254: 12/30/2009 10:28:57 PM - System Checkpoint
RP255: 1/1/2010 5:10:07 AM - System Checkpoint
RP256: 1/2/2010 5:07:58 PM - System Checkpoint
RP257: 1/3/2010 5:35:17 PM - System Checkpoint
RP258: 1/4/2010 5:50:10 PM - System Checkpoint
RP259: 1/5/2010 8:22:38 PM - System Checkpoint
RP260: 1/6/2010 6:37:20 AM - Removed Microsoft Visual C++ 2005 Redistributable
RP261: 1/6/2010 6:37:37 AM - Installed Microsoft Visual C++ 2005 Redistributable
RP262: 1/6/2010 6:37:45 AM - Installed DirectX
RP263: 1/7/2010 6:58:53 AM - System Checkpoint
RP264: 1/8/2010 2:40:43 AM - Installed Java™ 6 Update 17
RP265: 1/9/2010 2:43:17 AM - System Checkpoint
RP266: 1/10/2010 2:57:03 AM - System Checkpoint
RP267: 1/10/2010 3:21:55 AM - Removed NCsoft Launcher
RP268: 1/11/2010 6:02:22 AM - System Checkpoint
RP269: 1/12/2010 10:23:14 AM - System Checkpoint

==== Installed Programs ======================

7-Zip 4.42
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.2
AMD Processor Driver
Any Video Converter 2.7.3
Apple Application Support
Apple Software Update
Avidemux 2.5
AVS Update Manager 1.0
AVS Video Converter 6
AVS Video Recorder 2.4
AVS Video ReMaker [removed]
AVS4YOU Software Navigator 1.3
BitComet 1.06
Broadcom 802.11 Driver
ConvertXtoDVD 3.8.0.193j
Critical Update for Windows Media Player 11 (KB959772)
Curse Client
Dragon Age: Origins
Dragon Age: Origins Character Creator
DVD Decrypter (Remove Only)
DVD Shrink 3.2
EVEREST Ultimate Edition v4.60
ffdshow [rev 2527] [2008-12-19]
Fraps (remove only)
GOM Player
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HTSK
InterActual Player
Java™ 6 Update 17
Junk Mail filter update
K-Lite Codec Pack 4.8.5 (Full)
Malwarebytes' Anti-Malware
MapleStory
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Office Live Add-in 1.3
Microsoft Office XP Professional with FrontPage
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft VC9 runtime libraries
Microsoft Virtual PC 2007
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
MIDI Converter Studio 6.1
MKVtoolnix 2.9.8
MobMap 3.33
Mozilla Firefox (3.5.7)
MpcStar 4.1
MSVCRT
MSXML 6.0 Parser (KB927977)
Nero 6 Ultra Edition
NVIDIA Drivers
NVIDIA PhysX
OGA Notifier 2.0.0048.0
PFPortChecker 1.0.31
PowerDVD
PowerISO
Project64 1.6
QuickTime
RealPlayer
REALTEK GbE & FE Ethernet PCI NIC Driver
REALTEK Gigabit and Fast Ethernet NIC Driver
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Segoe UI
SpeedFan (remove only)
Spybot - Search & Destroy
SUPERAntiSpyware Free Edition
The File Splitter 1.31
Total Video Converter 3.50
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB971180)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Ventrilo Client
VideoLAN VLC media player 0.8.6c
Viewpoint Media Player
Vim 7.2 (self-installing)
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
WinRAR archiver
Wireless Home Network Setup
World of Warcraft
XML Paper Specification Shared Components Pack 1.0
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Search Protection
Yahoo! Software Update

==== Event Viewer Messages From Past Week ========

1/9/2010 3:01:23 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
1/12/2010 8:58:42 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/11/2010 8:48:14 PM, error: PlugPlayManager [11] - The device Root\LEGACY_XDVA279\0000 disappeared from the system without first being prepared for removal.
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The Yahoo! Updater service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The Viewpoint Manager Service service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 6:38:09 PM, error: System Error [1003] - Error code 1000008e, parameter1 c0000005, parameter2 805803f8, parameter3 a3065c14, parameter4 00000000.
1/11/2010 3:01:03 AM, error: System Error [1003] - Error code 1000000a, parameter1 96f8c67d, parameter2 000000ff, parameter3 00000001, parameter4 806e4ea5.
1/11/2010 3:00:43 AM, error: System Error [1003] - Error code 1000000a, parameter1 00000000, parameter2 000000ff, parameter3 00000000, parameter4 806e4ea0.

==== End Of File ===========================




Security Check Log


Results of screen317's Security Check version 0.99.1
Windows XP Service Pack 3
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
WMIC entry does not exist for antivirus; attempting automatic update.
``````````````````````````````
Anti-malware/Other Utilities Check:

Spybot - Search & Destroy
SUPERAntiSpyware Free Edition
HijackThis 2.0.2
Java™ 6 Update 17
Adobe Flash Player 10
Adobe Reader 9.2
``````````````````````````````
Process Check:
objlist.exe by Laurent

``````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````



Combo Fix Log




ComboFix 10-01-13.04 - Jeff Matthews 01/13/2010 10:49:59.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2458 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jeff Matthews\Desktop\CFScript.txt

FILE ::
"c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\cache\6.0\12\16c3138c-53f905dc"
"c:\documents and settings\Jeff Matthews\My Documents\Documents and Settings\Game Directory\Emulators\games\NDS\Lunar Dragon Song USA (Nintendo DS)\Lunar Dragon Song USA (Nintendo DS)\WinZix-2.3.0.0-setup.exe"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\cache\6.0\12\16c3138c-53f905dc
c:\documents and settings\Jeff Matthews\My Documents\Documents and Settings\Game Directory\Emulators\games\NDS\Lunar Dragon Song USA (Nintendo DS)\Lunar Dragon Song USA (Nintendo DS)\WinZix-2.3.0.0-setup.exe

.
((((((((((((((((((((((((( Files Created from 2009-12-13 to 2010-01-13 )))))))))))))))))))))))))))))))
.

2010-01-12 17:02 . 2010-01-12 17:03 ——– d—–w- C:\Rooter$
2010-01-12 05:14 . 2010-01-08 00:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-12 05:14 . 2010-01-12 05:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-12 05:14 . 2010-01-08 00:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-08 10:40 . 2010-01-08 10:40 152576 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-06 14:38 . 2010-01-12 01:17 ——– d—–w- c:\program files\Common Files\BioWare
2010-01-06 14:36 . 2010-01-06 14:37 ——– d—–w- c:\program files\Dragon Age Origins Character Creator
2010-01-04 11:30 . 2005-05-09 08:47 327680 ——w- c:\windows\MrSetup.exe
2010-01-04 11:30 . 2010-01-04 11:30 ——– d—–w- c:\program files\Studio-74
2009-12-24 04:56 . 2009-12-24 04:56 ——– d—–w- c:\program files\Common Files\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-12 12:08 . 2010-01-12 00:55 ——– d—–w- c:\program files\Dragon Age
2010-01-12 01:22 . 2010-01-12 01:22 ——– d—–w- c:\documents and settings\All Users\Application Data\BioWare
2010-01-11 15:19 . 2009-05-29 02:03 ——– d—–w- c:\program files\BitComet
2010-01-08 10:40 . 2009-05-29 00:58 ——– d—–w- c:\program files\Java
2010-01-08 10:39 . 2009-11-25 09:00 79488 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-02 11:29 . 2009-05-29 00:59 ——– d—–w- c:\program files\MpcStar
2009-12-31 01:26 . 2009-11-11 06:19 ——– d—–w- c:\program files\Avidemux 2.5
2009-12-29 03:54 . 2009-05-29 01:40 ——– d—–w- c:\program files\Yahoo!
2009-12-27 20:26 . 2009-07-21 06:43 ——– d—–w- c:\program files\NCSoft
2009-12-27 20:26 . 2009-05-28 17:14 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-24 08:27 . 2009-10-25 00:36 ——– d—–w- c:\documents and settings\Jeff Matthews\Application Data\Vso
2009-12-24 04:56 . 2009-10-02 02:02 ——– d—–w- c:\program files\QuickTime
2009-12-24 04:55 . 2009-05-29 00:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-20 04:34 . 2009-05-29 00:54 ——– d—–w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-12-15 10:25 . 2009-11-04 00:52 ——– d—–w- c:\documents and settings\Jeff Matthews\Application Data\HTSK
2009-12-11 10:41 . 2009-10-21 09:01 4876 —-a-w- c:\documents and settings\Jeff Matthews\FilterData.dat
2009-12-10 11:18 . 2009-10-11 16:45 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-07 20:18 . 2009-11-13 21:02 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-12-06 23:39 . 2009-10-01 02:59 165232 —ha-w- c:\documents and settings\Jeff Matthews\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll
2009-12-01 22:09 . 2009-12-01 22:09 ——– d—–w- c:\program files\Vim
2009-11-22 08:06 . 2009-05-28 17:18 18440 -c–a-w- c:\documents and settings\Jeff Matthews\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-22 03:45 . 2009-11-22 03:44 ——– d—–w- c:\program files\Total Video Converter
2009-11-17 02:20 . 2009-11-17 02:20 ——– d—–w- c:\program files\MIDI Converter Studio
2009-11-14 11:52 . 2009-11-14 11:52 56 –sh–r- c:\windows\system32\BE6684D741.sys
2009-11-14 11:52 . 2009-11-14 11:52 952 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-11-13 21:03 . 2009-11-13 21:03 117760 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-11-10 22:54 . 2009-11-27 00:09 95568 —-a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2009-11-10 22:54 . 2009-11-27 00:09 116560 —-a-w- c:\windows\system32\drivers\VBoxDrv.sys
2009-11-10 22:53 . 2009-11-27 00:09 41424 —-a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2009-11-04 00:52 . 2009-11-04 00:52 695688 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\HTSK\unins000.exe
2009-10-29 07:45 . 2008-04-14 12:00 916480 ——w- c:\windows\system32\wininet.dll
2009-10-25 07:40 . 2009-10-25 07:40 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-10-25 07:40 . 2009-10-25 07:40 47360 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\pcouffin.sys
2009-10-25 07:40 . 2009-10-25 07:40 47360 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\pcouffin.sys
2009-10-21 05:38 . 2008-04-14 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2008-04-14 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2008-04-14 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
.

((((((((((((((((((((((((((((( SnapShot@2010-01-11_16.39.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-13 13:57 . 2010-01-13 13:57 16384 c:\windows\temp\Perflib_Perfdata_504.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-27 3883856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"CurseClient"="c:\program files\Curse\CurseClient.exe" [2009-07-31 1935360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-07 2001648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2009-05-01 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-05-01 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-01 13750272]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-03-14 233472]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"d:\\World of Warcraft\\Launcher.exe"=
"d:\\World of Warcraft\\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"d:\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Dragon Age Origins Character Creator\\bin_ship\\DAOCharacterCreator.exe"=
"c:\\Program Files\\Dragon Age Origins Character Creator\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"64583:TCP"= 64583:TCP:BitComet 64583 TCP
"64583:UDP"= 64583:UDP:BitComet 64583 UDP
"23424:TCP"= 23424:TCP:BitComet 23424 TCP
"23424:UDP"= 23424:UDP:BitComet 23424 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [11/11/2009 10:44 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/11/2009 10:44 AM 74480]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [8/1/2009 2:54 PM 24652]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [11/11/2009 10:44 AM 7408]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [1/11/2010 5:06 PM 25832]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [11/26/2009 4:09 PM 95568]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys –> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-01-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-01-13 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 22:07]

2010-01-13 c:\windows\Tasks\User_Feed_Synchronization-{8818D99A-01C3-44EA-8B71-4878400CC76A}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &AOL Toolbar Search
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - ProfilePath - c:\documents and settings\Jeff Matthews\Application Data\Mozilla\Firefox\Profiles\t00b4ems.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-13 10:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(916)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
.
Completion time: 2010-01-13 10:58:17
ComboFix-quarantined-files.txt 2010-01-13 18:58
ComboFix2.txt 2010-01-12 05:02
ComboFix3.txt 2010-01-11 16:42

Pre-Run: 57,578,287,104 bytes free
Post-Run: 57,649,115,136 bytes free

- - End Of File - - ADDF5B8ECBE28C39290FDBE86B698AA1




Is that Java Deployment thing have anyting to do with opening up browsers that require java. I noticed before i was having major issues opening up browser windows that needed java support plugin and they just woulnd't open. Maybe that was the culprit.

Anyways the computer still seems some what slow. Mostly the internet, pages are not loading as fast, it takes a min or so before it starts loading up. Also when i still try to load certain programs, the CPU jumps up to like 90% and under "memory Usage" it still says like 500k is being used and it keeps going up to like 800k or so.
jeff,

🖼Click to load external image (Posted Image) Install an anti-virus program. I don't see any anti-virus software running on your computer. Choose one, (but no more) reputable AV program. If you need help chosing one, this site has good information. Avast, AVG, Avira and Microsoft all offer free AV products.

🖼Click to load external image (Posted Image) JavaRa …by: Paul McLain and Fred de Vries

Please download JavaRa (Copyright © 2008 RaProducts.org) and unzip it to your desktop.
***Please close any instances of Internet Explorer before continuing!***
Print these instructions…you won't have Internet access during this particular phase!
  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.
  • Copy and paste the contents of the JavaRa log, in your next reply.
🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above Registry::

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]  
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"=-

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

🖼Click to load external image (Posted Image) Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
🖼Click to load external image (Posted Image) You have Viewpoint software installed on your system. While this is not malware, it can be installed without your knowledge. See this thread for more information and removal instructions for Viewpoint.

In your next post include:
  • comboFix log
  • Fresh DDS log
ok here is my logs




Java Ra Log




JavaRa 1.15 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Thu Jan 14 07:47:59 2010

Found and removed: C:\Documents and Settings\Jeff Matthews\Application Data\Sun\Java\jre1.6.0_13

Found and removed: C:\Documents and Settings\Jeff Matthews\Application Data\Sun\Java\jre1.6.0_15

Found and removed: C:\Documents and Settings\Jeff Matthews\Application Data\Sun\Java\jre1.6.0_17

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

————————————

Finished reporting.



JavaRa 1.15 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Thu Jan 14 07:48:42 2010

————————————

Finished reporting.



JavaRa 1.15 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Thu Jan 14 07:49:07 2010

————————————

Finished reporting.




ComboFix Log



ComboFix 10-01-13.0C - Jeff Matthews 01/14/2010 7:54.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2786 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jeff Matthews\Desktop\CFScript.txt
.

((((((((((((((((((((((((( Files Created from 2009-12-14 to 2010-01-14 )))))))))))))))))))))))))))))))
.

2010-01-13 20:16 . 2010-01-13 20:16 348160 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-6b53d370-n\msvcr71.dll
2010-01-13 20:16 . 2010-01-13 20:16 61440 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-6b53d370-n\decora-sse.dll
2010-01-13 20:16 . 2010-01-13 20:16 503808 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-6b53d370-n\msvcp71.dll
2010-01-13 20:16 . 2010-01-13 20:16 499712 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-6b53d370-n\jmc.dll
2010-01-13 20:16 . 2010-01-13 20:16 12800 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-6b53d370-n\decora-d3d.dll
2010-01-13 20:16 . 2010-01-13 20:16 ——– d—–w- c:\program files\Common Files\Java
2010-01-13 20:16 . 2010-01-13 20:16 315392 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-5a8c6bfb-n\jogl.dll
2010-01-13 20:16 . 2010-01-13 20:16 20480 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-5a8c6bfb-n\jogl_awt.dll
2010-01-13 20:16 . 2010-01-13 20:16 114688 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-5a8c6bfb-n\jogl_cg.dll
2010-01-13 20:16 . 2010-01-13 20:16 20480 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\45\4f710eed-744b1afe-n\gluegen-rt.dll
2010-01-12 17:02 . 2010-01-12 17:03 ——– d—–w- C:\Rooter$
2010-01-12 05:14 . 2010-01-08 00:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-12 05:14 . 2010-01-12 05:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-12 05:14 . 2010-01-08 00:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 14:38 . 2010-01-12 01:17 ——– d—–w- c:\program files\Common Files\BioWare
2010-01-06 14:36 . 2010-01-06 14:37 ——– d—–w- c:\program files\Dragon Age Origins Character Creator
2010-01-04 11:30 . 2005-05-09 08:47 327680 ——w- c:\windows\MrSetup.exe
2010-01-04 11:30 . 2010-01-04 11:30 ——– d—–w- c:\program files\Studio-74
2009-12-24 04:56 . 2009-12-24 04:56 ——– d—–w- c:\program files\Common Files\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-14 05:28 . 2009-05-28 21:11 ——– d—–w- c:\program files\Lavalys
2010-01-14 03:13 . 2010-01-12 00:55 ——– d—–w- c:\program files\Dragon Age
2010-01-13 20:15 . 2009-05-29 00:58 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-01-13 20:14 . 2009-12-01 22:09 ——– d—–w- c:\program files\Vim
2010-01-13 20:14 . 2009-11-13 21:02 ——– d—–w- c:\documents and settings\Jeff Matthews\Application Data\SUPERAntiSpyware.com
2010-01-13 20:13 . 2009-11-13 21:02 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-01-13 20:13 . 2009-05-28 23:41 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-01-12 01:22 . 2010-01-12 01:22 ——– d—–w- c:\documents and settings\All Users\Application Data\BioWare
2010-01-11 15:19 . 2009-05-29 02:03 ——– d—–w- c:\program files\BitComet
2010-01-08 10:40 . 2009-05-29 00:58 ——– d—–w- c:\program files\Java
2010-01-02 11:29 . 2009-05-29 00:59 ——– d—–w- c:\program files\MpcStar
2009-12-31 01:26 . 2009-11-11 06:19 ——– d—–w- c:\program files\Avidemux 2.5
2009-12-29 03:54 . 2009-05-29 01:40 ——– d—–w- c:\program files\Yahoo!
2009-12-27 20:26 . 2009-07-21 06:43 ——– d—–w- c:\program files\NCSoft
2009-12-27 20:26 . 2009-05-28 17:14 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-24 08:27 . 2009-10-25 00:36 ——– d—–w- c:\documents and settings\Jeff Matthews\Application Data\Vso
2009-12-24 04:56 . 2009-10-02 02:02 ——– d—–w- c:\program files\QuickTime
2009-12-24 04:55 . 2009-05-29 00:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-20 04:34 . 2009-05-29 00:54 ——– d—–w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-12-15 10:25 . 2009-11-04 00:52 ——– d—–w- c:\documents and settings\Jeff Matthews\Application Data\HTSK
2009-12-11 10:41 . 2009-10-21 09:01 4876 —-a-w- c:\documents and settings\Jeff Matthews\FilterData.dat
2009-12-10 11:18 . 2009-10-11 16:45 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-06 23:39 . 2009-10-01 02:59 165232 —ha-w- c:\documents and settings\Jeff Matthews\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll
2009-11-22 08:06 . 2009-05-28 17:18 18440 -c–a-w- c:\documents and settings\Jeff Matthews\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-22 03:45 . 2009-11-22 03:44 ——– d—–w- c:\program files\Total Video Converter
2009-11-21 15:51 . 2008-04-14 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-17 02:20 . 2009-11-17 02:20 ——– d—–w- c:\program files\MIDI Converter Studio
2009-11-14 11:52 . 2009-11-14 11:52 56 –sh–r- c:\windows\system32\BE6684D741.sys
2009-11-14 11:52 . 2009-11-14 11:52 952 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-11-10 22:54 . 2009-11-27 00:09 95568 —-a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2009-11-10 22:54 . 2009-11-27 00:09 116560 —-a-w- c:\windows\system32\drivers\VBoxDrv.sys
2009-11-10 22:53 . 2009-11-27 00:09 41424 —-a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2009-11-04 00:52 . 2009-11-04 00:52 695688 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\HTSK\unins000.exe
2009-10-29 07:45 . 2008-04-14 12:00 916480 ——w- c:\windows\system32\wininet.dll
2009-10-25 07:40 . 2009-10-25 07:40 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-10-25 07:40 . 2009-10-25 07:40 47360 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\pcouffin.sys
2009-10-25 07:40 . 2009-10-25 07:40 47360 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\pcouffin.sys
2009-10-21 05:38 . 2008-04-14 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2008-04-14 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2008-04-14 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
.

((((((((((((((((((((((((((((( SnapShot@2010-01-11_16.39.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-14 06:35 . 2010-01-14 06:35 16384 c:\windows\temp\Perflib_Perfdata_5a4.dat
- 2008-04-14 12:00 . 2009-06-16 14:36 81920 c:\windows\system32\fontsub.dll
+ 2008-04-14 12:00 . 2009-10-15 16:28 81920 c:\windows\system32\fontsub.dll
+ 2008-04-14 12:00 . 2009-10-15 16:28 81920 c:\windows\system32\dllcache\fontsub.dll
- 2008-04-14 12:00 . 2009-06-16 14:36 81920 c:\windows\system32\dllcache\fontsub.dll
+ 2008-04-14 12:00 . 2009-10-15 16:28 119808 c:\windows\system32\t2embed.dll
- 2008-04-14 12:00 . 2009-06-16 14:36 119808 c:\windows\system32\t2embed.dll
+ 2010-01-13 20:15 . 2010-01-13 20:15 153376 c:\windows\system32\javaws.exe
- 2010-01-08 10:41 . 2009-10-11 12:17 145184 c:\windows\system32\javaw.exe
+ 2010-01-13 20:15 . 2010-01-13 20:15 145184 c:\windows\system32\javaw.exe
- 2010-01-08 10:41 . 2009-10-11 12:17 145184 c:\windows\system32\java.exe
+ 2010-01-13 20:15 . 2010-01-13 20:15 145184 c:\windows\system32\java.exe
- 2008-04-14 12:00 . 2009-06-16 14:36 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2008-04-14 12:00 . 2009-10-15 16:28 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2008-04-14 12:00 . 2009-11-21 15:51 471552 c:\windows\system32\dllcache\aclayers.dll
+ 2010-01-13 20:16 . 2010-01-13 20:16 178176 c:\windows\Installer\157f23a.msi
+ 2010-01-13 20:15 . 2010-01-13 20:15 577536 c:\windows\Installer\157f231.msi
+ 2009-05-28 22:37 . 2010-01-05 00:17 29634504 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-27 3883856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"CurseClient"="c:\program files\Curse\CurseClient.exe" [2009-07-31 1935360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2009-05-01 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-05-01 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-01 13750272]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-03-14 233472]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"d:\\World of Warcraft\\Launcher.exe"=
"d:\\World of Warcraft\\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"d:\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Dragon Age Origins Character Creator\\bin_ship\\DAOCharacterCreator.exe"=
"c:\\Program Files\\Dragon Age Origins Character Creator\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"64583:TCP"= 64583:TCP:BitComet 64583 TCP
"64583:UDP"= 64583:UDP:BitComet 64583 UDP
"23424:TCP"= 23424:TCP:BitComet 23424 TCP
"23424:UDP"= 23424:UDP:BitComet 23424 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [8/1/2009 2:54 PM 24652]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [1/11/2010 5:06 PM 25832]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [11/26/2009 4:09 PM 95568]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys –> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-01-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-01-14 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 22:07]

2010-01-14 c:\windows\Tasks\User_Feed_Synchronization-{8818D99A-01C3-44EA-8B71-4878400CC76A}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &AOL Toolbar Search
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - ProfilePath - c:\documents and settings\Jeff Matthews\Application Data\Mozilla\Firefox\Profiles\t00b4ems.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-14 08:00
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(1500)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-01-14 08:03:19
ComboFix-quarantined-files.txt 2010-01-14 16:03
ComboFix2.txt 2010-01-13 18:58
ComboFix3.txt 2010-01-12 05:02
ComboFix4.txt 2010-01-11 16:42

Pre-Run: 58,740,142,080 bytes free
Post-Run: 58,748,116,992 bytes free

- - End Of File - - 2FA0F8322C96E3DD9C470C0B676514B7


DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 8:24:55.21 on Thu 01/14/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2812 [GMT -8:00]


============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Jeff Matthews\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - No File
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [CurseClient] c:\program files\curse\CurseClient.exe -silent
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: &AOL Toolbar Search
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll/206
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F}
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1243547212812
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jeffma~1\applic~1\mozilla\firefox\profiles\t00b4ems.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\mpcstar\codecs\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\mpcstar\codecs\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2010-1-14 138680]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2010-1-14 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2010-1-14 352920]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2010-1-11 25832]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2009-11-26 95568]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\vboxnetflt.sys –> c:\windows\system32\drivers\VBoxNetFlt.sys [?]

=============== Created Last 30 ================

2010-01-14 16:21:57 1060864 —-a-w- c:\windows\system32\MFC71.dll
2010-01-14 15:53:16 0 d—–w- C:\ComboFix
2010-01-13 20:15:55 73728 —-a-w- c:\windows\system32\javacpl.cpl
2010-01-12 17:02:41 0 d—–w- C:\Rooter$
2010-01-12 05:14:19 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-12 05:14:18 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-12 05:14:18 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-12 01:22:32 0 d—–w- c:\docume~1\alluse~1\applic~1\BioWare
2010-01-12 00:55:26 0 d—–w- c:\program files\Dragon Age
2010-01-11 16:33:08 0 d-sha-r- C:\cmdcons
2010-01-11 16:31:50 98816 —-a-w- c:\windows\sed.exe
2010-01-11 16:31:50 77312 —-a-w- c:\windows\MBR.exe
2010-01-11 16:31:50 261632 —-a-w- c:\windows\PEV.exe
2010-01-11 16:31:50 161792 —-a-w- c:\windows\SWREG.exe
2010-01-06 14:38:30 0 d—–w- c:\program files\common files\BioWare
2010-01-06 14:36:25 0 d—–w- c:\program files\Dragon Age Origins Character Creator
2010-01-04 11:30:25 87 —-a-w- c:\windows\MrSetup.ini
2010-01-04 11:30:24 327680 ——w- c:\windows\MrSetup.exe
2010-01-04 11:30:14 0 d—–w- c:\program files\Studio-74

==================== Find3M ====================

2010-01-13 20:15:45 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-11 10:41:37 4876 —-a-w- c:\documents and settings\jeff matthews\FilterData.dat
2009-11-27 23:44:10 18440 -c–a-w- c:\docume~1\jeffma~1\applic~1\GDIPFONTCACHEV1.DAT
2009-10-29 07:45:38 916480 ——w- c:\windows\system32\wininet.dll
2009-10-25 07:40:54 47360 —-a-w- c:\docume~1\jeffma~1\applic~1\pcouffin.sys
2009-10-21 05:38:36 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 —-a-w- c:\windows\system32\httpapi.dll

============= FINISH: 8:25:16.26 ===============

Attach DDS Log



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 5/28/2009 9:23:27 AM
System Uptime: 1/14/2010 8:07:18 AM (0 hours ago)

Motherboard: ASUSTeK Computer INC. | | M2N-E SLI
Processor: AMD Athlon™ 64 X2 Dual Core Processor 6400+ | Socket AM2 | 3216/200mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 149 GiB total, 54.768 GiB free.
D: is FIXED (NTFS) - 39 GiB total, 12.508 GiB free.
E: is FIXED (NTFS) - 35 GiB total, 15.497 GiB free.
F: is CDROM (CDFS)
G: is CDROM ()
H: is FIXED (NTFS) - 149 GiB total, 77.365 GiB free.
I: is FIXED (NTFS) - 932 GiB total, 676.024 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: ACPI\ATK0110\1010110
Manufacturer:
Name:
PNP Device ID: ACPI\ATK0110\1010110
Service:

==== System Restore Points ===================

RP170: 10/17/2009 5:26:02 AM - System Checkpoint
RP171: 10/18/2009 6:20:46 AM - System Checkpoint
RP172: 10/19/2009 6:40:58 AM - System Checkpoint
RP173: 10/20/2009 3:07:23 PM - System Checkpoint
RP174: 10/21/2009 4:25:45 PM - System Checkpoint
RP175: 10/22/2009 6:55:30 PM - System Checkpoint
RP176: 10/24/2009 1:46:24 AM - System Checkpoint
RP177: 10/24/2009 11:26:25 PM - Restore Operation
RP178: 10/24/2009 11:31:28 PM - Software Distribution Service 3.0
RP179: 10/24/2009 11:46:55 PM - Removed Apple Application Support
RP180: 10/25/2009 12:08:03 AM - Removed OTB
RP181: 10/25/2009 4:42:53 PM - Installed WinZip 12.0
RP182: 10/26/2009 5:30:03 PM - System Checkpoint
RP183: 10/27/2009 10:09:24 PM - System Checkpoint
RP184: 10/29/2009 1:40:18 AM - System Checkpoint
RP185: 10/30/2009 6:04:14 AM - System Checkpoint
RP186: 10/31/2009 6:14:38 AM - System Checkpoint
RP187: 11/1/2009 7:23:48 AM - System Checkpoint
RP188: 11/1/2009 3:05:41 PM - Removed Microsoft Silverlight
RP189: 11/1/2009 3:06:48 PM - Removed WinZip 12.0
RP190: 11/2/2009 3:47:32 PM - System Checkpoint
RP191: 11/3/2009 4:14:30 PM - System Checkpoint
RP192: 11/4/2009 4:58:37 PM - System Checkpoint
RP193: 11/5/2009 5:48:19 PM - System Checkpoint
RP194: 11/6/2009 6:02:50 PM - System Checkpoint
RP195: 11/7/2009 6:21:53 PM - System Checkpoint
RP196: 11/8/2009 5:22:59 PM - System Checkpoint
RP197: 11/9/2009 6:32:57 PM - System Checkpoint
RP198: 11/10/2009 5:51:48 PM - Installed Windows XP KB954708.
RP199: 11/10/2009 5:52:01 PM - Installed DirectX
RP200: 11/11/2009 7:05:12 PM - System Checkpoint
RP201: 11/11/2009 9:19:33 PM - Software Distribution Service 3.0
RP202: 11/12/2009 11:36:23 PM - System Checkpoint
RP203: 11/13/2009 1:02:20 PM - Installed SUPERAntiSpyware Free Edition
RP204: 11/14/2009 3:50:45 AM - Installed RPGXP
RP205: 11/14/2009 3:51:15 AM - Installed RGSS-RTP Standard
RP206: 11/15/2009 4:16:59 AM - System Checkpoint
RP207: 11/16/2009 5:05:53 AM - System Checkpoint
RP208: 11/17/2009 6:05:53 AM - System Checkpoint
RP209: 11/18/2009 7:19:53 AM - System Checkpoint
RP210: 11/19/2009 8:06:01 AM - System Checkpoint
RP211: 11/20/2009 2:53:44 PM - System Checkpoint
RP212: 11/21/2009 4:03:29 PM - System Checkpoint
RP213: 11/22/2009 5:39:35 PM - System Checkpoint
RP214: 11/23/2009 7:38:25 PM - System Checkpoint
RP215: 11/24/2009 7:58:57 PM - System Checkpoint
RP216: 11/25/2009 3:00:12 AM - Software Distribution Service 3.0
RP217: 11/26/2009 3:02:00 AM - System Checkpoint
RP218: 11/26/2009 4:08:59 PM - Installed Sun VirtualBox
RP219: 11/27/2009 5:54:44 PM - System Checkpoint
RP220: 11/28/2009 2:33:01 PM - Restore Operation
RP221: 11/29/2009 2:39:37 PM - System Checkpoint
RP222: 11/30/2009 3:06:38 PM - System Checkpoint
RP223: 12/1/2009 4:26:49 PM - System Checkpoint
RP224: 12/2/2009 6:12:44 PM - System Checkpoint
RP225: 12/3/2009 8:05:12 PM - System Checkpoint
RP226: 12/5/2009 12:36:31 AM - System Checkpoint
RP227: 12/6/2009 12:39:40 AM - System Checkpoint
RP228: 12/7/2009 12:49:07 AM - System Checkpoint
RP229: 12/8/2009 1:22:31 AM - System Checkpoint
RP230: 12/9/2009 1:26:47 AM - System Checkpoint
RP231: 12/10/2009 2:22:30 AM - System Checkpoint
RP232: 12/10/2009 3:00:13 AM - Software Distribution Service 3.0
RP233: 12/11/2009 2:13:19 PM - System Checkpoint
RP234: 12/12/2009 2:23:00 PM - System Checkpoint
RP235: 12/13/2009 9:44:13 PM - System Checkpoint
RP236: 12/14/2009 9:56:23 PM - System Checkpoint
RP237: 12/15/2009 10:52:59 PM - System Checkpoint
RP238: 12/17/2009 1:10:43 AM - System Checkpoint
RP239: 12/18/2009 2:05:40 AM - System Checkpoint
RP240: 12/19/2009 3:55:40 PM - System Checkpoint
RP241: 12/20/2009 6:54:46 PM - System Checkpoint
RP242: 12/21/2009 7:42:23 PM - System Checkpoint
RP243: 12/22/2009 8:17:40 PM - System Checkpoint
RP244: 12/23/2009 8:25:59 PM - System Checkpoint
RP245: 12/24/2009 9:24:10 PM - System Checkpoint
RP246: 12/25/2009 10:13:57 PM - System Checkpoint
RP247: 12/26/2009 11:12:07 PM - System Checkpoint
RP248: 12/27/2009 12:26:18 PM - Removed Aion
RP249: 12/27/2009 12:28:03 PM - Removed RPGXP
RP250: 12/27/2009 12:28:17 PM - Removed RGSS-RTP Standard
RP251: 12/27/2009 12:28:41 PM - Removed Sun VirtualBox
RP252: 12/28/2009 1:12:07 PM - System Checkpoint
RP253: 12/29/2009 1:58:45 PM - System Checkpoint
RP254: 12/30/2009 10:28:57 PM - System Checkpoint
RP255: 1/1/2010 5:10:07 AM - System Checkpoint
RP256: 1/2/2010 5:07:58 PM - System Checkpoint
RP257: 1/3/2010 5:35:17 PM - System Checkpoint
RP258: 1/4/2010 5:50:10 PM - System Checkpoint
RP259: 1/5/2010 8:22:38 PM - System Checkpoint
RP260: 1/6/2010 6:37:20 AM - Removed Microsoft Visual C++ 2005 Redistributable
RP261: 1/6/2010 6:37:37 AM - Installed Microsoft Visual C++ 2005 Redistributable
RP262: 1/6/2010 6:37:45 AM - Installed DirectX
RP263: 1/7/2010 6:58:53 AM - System Checkpoint
RP264: 1/8/2010 2:40:43 AM - Installed Java™ 6 Update 17
RP265: 1/9/2010 2:43:17 AM - System Checkpoint
RP266: 1/10/2010 2:57:03 AM - System Checkpoint
RP267: 1/10/2010 3:21:55 AM - Removed NCsoft Launcher
RP268: 1/11/2010 6:02:22 AM - System Checkpoint
RP269: 1/12/2010 10:23:14 AM - System Checkpoint
RP270: 1/13/2010 12:12:27 PM - Removed Java™ 6 Update 10
RP271: 1/13/2010 12:12:50 PM - Removed MapleStory.
RP272: 1/13/2010 12:13:11 PM - Removed Microsoft Virtual PC 2007
RP273: 1/13/2010 12:13:54 PM - Removed SUPERAntiSpyware Free Edition
RP274: 1/13/2010 12:15:42 PM - Installed Java™ 6 Update 18
RP275: 1/13/2010 10:06:57 PM - Software Distribution Service 3.0

==== Installed Programs ======================

7-Zip 4.42
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.2
AMD Processor Driver
Any Video Converter 2.7.3
Apple Application Support
Apple Software Update
avast! Antivirus
Avidemux 2.5
AVS Update Manager 1.0
AVS Video Converter 6
AVS Video Recorder 2.4
AVS Video ReMaker [removed]
AVS4YOU Software Navigator 1.3
BitComet 1.06
Broadcom 802.11 Driver
ConvertXtoDVD 3.8.0.193j
Critical Update for Windows Media Player 11 (KB959772)
Curse Client
Dragon Age: Origins
Dragon Age: Origins Character Creator
DVD Decrypter (Remove Only)
DVD Shrink 3.2
EVEREST Home Edition v2.20
EVEREST Ultimate Edition v4.60
ffdshow [rev 2527] [2008-12-19]
Fraps (remove only)
GOM Player
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HTSK
InterActual Player
Java Auto Updater
Java™ 6 Update 18
Junk Mail filter update
K-Lite Codec Pack 4.8.5 (Full)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Office Live Add-in 1.3
Microsoft Office XP Professional with FrontPage
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
MIDI Converter Studio 6.1
MKVtoolnix 2.9.8
MobMap 3.33
Mozilla Firefox (3.5.7)
MpcStar 4.1
MSVCRT
MSXML 6.0 Parser (KB927977)
Nero 6 Ultra Edition
NVIDIA Drivers
NVIDIA PhysX
OGA Notifier 2.0.0048.0
PFPortChecker 1.0.31
PowerDVD
PowerISO
Project64 1.6
QuickTime
RealPlayer
REALTEK GbE & FE Ethernet PCI NIC Driver
REALTEK Gigabit and Fast Ethernet NIC Driver
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Segoe UI
SpeedFan (remove only)
Spybot - Search & Destroy
The File Splitter 1.31
Total Video Converter 3.50
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB971180)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Ventrilo Client
VideoLAN VLC media player 0.8.6c
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
WinRAR archiver
Wireless Home Network Setup
World of Warcraft
XML Paper Specification Shared Components Pack 1.0
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Search Protection
Yahoo! Software Update

==== Event Viewer Messages From Past Week ========

1/12/2010 8:58:42 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/11/2010 8:48:14 PM, error: PlugPlayManager [11] - The device Root\LEGACY_XDVA279\0000 disappeared from the system without first being prepared for removal.
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The Yahoo! Updater service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The Viewpoint Manager Service service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 6:38:09 PM, error: System Error [1003] - Error code 1000008e, parameter1 c0000005, parameter2 805803f8, parameter3 a3065c14, parameter4 00000000.
1/11/2010 3:01:03 AM, error: System Error [1003] - Error code 1000000a, parameter1 96f8c67d, parameter2 000000ff, parameter3 00000001, parameter4 806e4ea5.
1/11/2010 3:00:43 AM, error: System Error [1003] - Error code 1000000a, parameter1 00000000, parameter2 000000ff, parameter3 00000000, parameter4 806e4ea0.
1/11/2010 2:59:35 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

==== End Of File ===========================

Ok i have a question now. Do you by any chance know what this is. MSXML 6.0 Parser That file was found in my programs when i was deleting the Viewpoint software from my machine. It says used rarely. I hope thats not some kind of automated tracker, spyware or something.

Also when i run my Processes in the Task Manager i notice ALOT of files that says SVschost. When i go to certain weg pages, those file's run up alot of CPU. I am not sure what that means though if its good or bad. I am just trying to pinpoint some things to better help you in solving my problem here.

Also i want to make sure i delete every possible remnant of any crack/keygen, or seriel codes that are on my computer. I notice alot of my viruses happend to be coming from my "game Directory" folder in which i did download alot of emulation, which is legal if you own the system. But i noticed everytime i clean my machine that seems to be were the source is coming from.
I just wanted to add that i notice a vast improvement in my programs running now. I haven't received any "non responsive" crashes in any of my software that i load. Lets hope this fixed my BSOD crashes as well, i hope! Before i could open a program and it would crash almost with in a min or two. Now i have had this software running for around 2 hrs and it hasn't crashed. So thats a very good thing indeed. I wonder what actually caused this. Also i wanted to add that i do have the K lite Codec pack on my computer. Do you think that could be interfering with anything or perhaps should i uninstall it? Thanks again!
Sorry for the triple post. I am just updating you on information. I guess my internet is still pretty bogged down. Its almost like it has a very slow response time. i did a speed test and my download speed comes to around 1.4 mb which is accurate for my 1.5 connection. How ever my upload speed is only around .60 which is not even 100k upload. That could be a contributing factor. I tried to check and see if its my router, i did a factory reset. Still does the same thing. The internet is just VERYYY slow! It takes around 5 min to buffer a video online. To load pages i have to wait about 39 seconds and it will kind of stay there in that "freezing" state and then finally load the page. As i said slow response times. I am not sure what is causing this. As for my crashes, i havn't recieved any as of yet so thats a good thing. Maybe we did fix that part of the problem, but my internet still has some major issues.

This computer hasn't been updated that much so that also could be a part of the problem, need to make sure i have all updated drivers, and windows is up to date. I won't do anything though unless you give me the go ahead.
jeff,

I'm glad your computer seems to be running better. Your latest logs appear to be clean! I'll do my best to answer your questions here:

Do you by any chance know what this is. MSXML 6.0 Parser

That is a legit entry.

Also when i run my Processes in the Task Manager i notice ALOT of files that says SVschost. When i go to certain weg pages, those file's run up alot of CPU. I am not sure what that means though if its good or bad.

Svchost or Svschost? Svchost is legit; a good explanation can be found HERE

Also i want to make sure i delete every possible remnant of any crack/keygen, or seriel codes that are on my computer.

We removed one of the cracks with MBAM. You can delete the other; it should be here:
C:\DOCUME~1\JEFFMA~1\My Documents\Documents and Settings\Game Directory\Encoding\cracksearcher.rar

I notice alot of my viruses happend to be coming from my "game Directory" folder in which i did download alot of emulation, which is legal if you own the system. But i noticed everytime i clean my machine that seems to be were the source is coming from.

I can only speculate here, but I'm thinking at least some of the content of your game directory was downloaded from P2P. I understand that there are legitimate and legal uses for P2P, but I also know for a fact that it is a breeding ground for malware.

Also i wanted to add that i do have the K lite Codec pack on my computer. Do you think that could be interfering with anything or perhaps should i uninstall it?

As far as I know the K Lite codecs should be fine. If you are concerned about them, you may want to start a new topic in our Microsoft Windows forum.

….my internet still has some major issues

Many things can cause your internet connection to be slower than advertised. Your logs don't show any remaining malware though. I suggest that you contact your ISP or open a new thread in our Browsers, Internet and email section if you continue to experience problems.

Now we have some important housekeeping and clean up items you need to complete:

🖼Click to load external image (Posted Image) Your Adbobe reader needs to be updated. Please visit Adobe's site and grab the newest version.

Go HERE to scan for any other out of date and/or vulnerable applications on your computer and follow the instructions given for updating them.

🖼Click to load external image (Posted Image) Now, let’s update your operating system:
  • Click Start -> All Programs -> Windows Update
  • In the left pane, click on Check for Updates
  • Download and install all updates labeled Critical, Important or Recommended.
  • Repeat these steps until no more Critical, Important or Recommended updates appear.
  • In the left pane, click on Change Settings. Choose Install updates automatically and pick a time that works for you. Also check the box in the Recommended updates section.
🖼Click to load external image (Posted Image) Uninstall ComboFix
  • Press the Windows key + R on your keyboard or click Start -> Run. Copy and past the following text into the run box that opens:
    Combofix /Uninstall
🖼Click to load external image (Posted Image)

🖼Click to load external image (Posted Image) Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.
🖼Click to load external image (Posted Image) Finally, I'd like to make a couple of suggestions to help you stay clean in the future:
  • Restart any anti-malware programs that we disabled while we were cleaning your machine.
  • Keep your antivirus application current and updated. Also, hang on to MBAM. Scan with them at least weekly.
  • Avoid using P2P programs, cracks and keygens! Refer back to my earlier post for more information.
  • Consider running in a limited user account. See this post for more information.
  • Please carefully review the information in our Security - Best Practices and Prevention forum located HERE
Please post once more so I know you are all set and I can close this thread. Good luck and stay safe!
ok thank you so much. My computer is running faster now and i notice far less problems. I think part of the other problems relating to why my internet is slow is probably due to either my router or my ISP. I will have to check back with them and find out. I am going to also Defrage, i haven't done that in a while and clean temp files from the C drive as well. Hopefully that gets rid of alot of the clusters in the hard drive. Anyways thanks again for your excellent support in helping me remove the maleware. I also have another issue that im going to try and ask for support. Some one else is helping me in another part of the forums. for this issue. The issue is related to updating drivers, testing ram or hardware in my computer to see if there is any errors. I am pretty sure my pc is just way out of date with drivers and that might also be some parts of my problem and why video's aren't loading fast and what not. So i am going to ask bout that as well and hopefully i can get the same excellent support as you gave me. He is just waiting for this thread to be solved. Well It has a been a pleasure, i will definitely look back on this site for any information if the need arises to remove any other male ware problems i have, thanks again!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI