ok here is my logs
Java Ra Log
JavaRa 1.15 Removal Log.
Report follows after line.
————————————
The JavaRa removal process was started on Thu Jan 14 07:47:59 2010
Found and removed: C:\Documents and Settings\Jeff Matthews\Application Data\Sun\Java\jre1.6.0_13
Found and removed: C:\Documents and Settings\Jeff Matthews\Application Data\Sun\Java\jre1.6.0_15
Found and removed: C:\Documents and Settings\Jeff Matthews\Application Data\Sun\Java\jre1.6.0_17
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
————————————
Finished reporting.
JavaRa 1.15 Removal Log.
Report follows after line.
————————————
The JavaRa removal process was started on Thu Jan 14 07:48:42 2010
————————————
Finished reporting.
JavaRa 1.15 Removal Log.
Report follows after line.
————————————
The JavaRa removal process was started on Thu Jan 14 07:49:07 2010
————————————
Finished reporting.
ComboFix Log
ComboFix 10-01-13.0C - Jeff Matthews 01/14/2010 7:54.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2786 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jeff Matthews\Desktop\CFScript.txt
.
((((((((((((((((((((((((( Files Created from 2009-12-14 to 2010-01-14 )))))))))))))))))))))))))))))))
.
2010-01-13 20:16 . 2010-01-13 20:16 348160 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-6b53d370-n\msvcr71.dll
2010-01-13 20:16 . 2010-01-13 20:16 61440 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-6b53d370-n\decora-sse.dll
2010-01-13 20:16 . 2010-01-13 20:16 503808 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-6b53d370-n\msvcp71.dll
2010-01-13 20:16 . 2010-01-13 20:16 499712 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-6b53d370-n\jmc.dll
2010-01-13 20:16 . 2010-01-13 20:16 12800 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-6b53d370-n\decora-d3d.dll
2010-01-13 20:16 . 2010-01-13 20:16 ——– d—–w- c:\program files\Common Files\Java
2010-01-13 20:16 . 2010-01-13 20:16 315392 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-5a8c6bfb-n\jogl.dll
2010-01-13 20:16 . 2010-01-13 20:16 20480 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-5a8c6bfb-n\jogl_awt.dll
2010-01-13 20:16 . 2010-01-13 20:16 114688 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-5a8c6bfb-n\jogl_cg.dll
2010-01-13 20:16 . 2010-01-13 20:16 20480 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\Sun\Java\Deployment\SystemCache\6.0\45\4f710eed-744b1afe-n\gluegen-rt.dll
2010-01-12 17:02 . 2010-01-12 17:03 ——– d—–w- C:\Rooter$
2010-01-12 05:14 . 2010-01-08 00:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-12 05:14 . 2010-01-12 05:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-12 05:14 . 2010-01-08 00:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 14:38 . 2010-01-12 01:17 ——– d—–w- c:\program files\Common Files\BioWare
2010-01-06 14:36 . 2010-01-06 14:37 ——– d—–w- c:\program files\Dragon Age Origins Character Creator
2010-01-04 11:30 . 2005-05-09 08:47 327680 ——w- c:\windows\MrSetup.exe
2010-01-04 11:30 . 2010-01-04 11:30 ——– d—–w- c:\program files\Studio-74
2009-12-24 04:56 . 2009-12-24 04:56 ——– d—–w- c:\program files\Common Files\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-14 05:28 . 2009-05-28 21:11 ——– d—–w- c:\program files\Lavalys
2010-01-14 03:13 . 2010-01-12 00:55 ——– d—–w- c:\program files\Dragon Age
2010-01-13 20:15 . 2009-05-29 00:58 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-01-13 20:14 . 2009-12-01 22:09 ——– d—–w- c:\program files\Vim
2010-01-13 20:14 . 2009-11-13 21:02 ——– d—–w- c:\documents and settings\Jeff Matthews\Application Data\SUPERAntiSpyware.com
2010-01-13 20:13 . 2009-11-13 21:02 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-01-13 20:13 . 2009-05-28 23:41 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-01-12 01:22 . 2010-01-12 01:22 ——– d—–w- c:\documents and settings\All Users\Application Data\BioWare
2010-01-11 15:19 . 2009-05-29 02:03 ——– d—–w- c:\program files\BitComet
2010-01-08 10:40 . 2009-05-29 00:58 ——– d—–w- c:\program files\Java
2010-01-02 11:29 . 2009-05-29 00:59 ——– d—–w- c:\program files\MpcStar
2009-12-31 01:26 . 2009-11-11 06:19 ——– d—–w- c:\program files\Avidemux 2.5
2009-12-29 03:54 . 2009-05-29 01:40 ——– d—–w- c:\program files\Yahoo!
2009-12-27 20:26 . 2009-07-21 06:43 ——– d—–w- c:\program files\NCSoft
2009-12-27 20:26 . 2009-05-28 17:14 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-24 08:27 . 2009-10-25 00:36 ——– d—–w- c:\documents and settings\Jeff Matthews\Application Data\Vso
2009-12-24 04:56 . 2009-10-02 02:02 ——– d—–w- c:\program files\QuickTime
2009-12-24 04:55 . 2009-05-29 00:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-20 04:34 . 2009-05-29 00:54 ——– d—–w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-12-15 10:25 . 2009-11-04 00:52 ——– d—–w- c:\documents and settings\Jeff Matthews\Application Data\HTSK
2009-12-11 10:41 . 2009-10-21 09:01 4876 —-a-w- c:\documents and settings\Jeff Matthews\FilterData.dat
2009-12-10 11:18 . 2009-10-11 16:45 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-06 23:39 . 2009-10-01 02:59 165232 —ha-w- c:\documents and settings\Jeff Matthews\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll
2009-11-22 08:06 . 2009-05-28 17:18 18440 -c–a-w- c:\documents and settings\Jeff Matthews\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-22 03:45 . 2009-11-22 03:44 ——– d—–w- c:\program files\Total Video Converter
2009-11-21 15:51 . 2008-04-14 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-17 02:20 . 2009-11-17 02:20 ——– d—–w- c:\program files\MIDI Converter Studio
2009-11-14 11:52 . 2009-11-14 11:52 56 –sh–r- c:\windows\system32\BE6684D741.sys
2009-11-14 11:52 . 2009-11-14 11:52 952 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-11-10 22:54 . 2009-11-27 00:09 95568 —-a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2009-11-10 22:54 . 2009-11-27 00:09 116560 —-a-w- c:\windows\system32\drivers\VBoxDrv.sys
2009-11-10 22:53 . 2009-11-27 00:09 41424 —-a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2009-11-04 00:52 . 2009-11-04 00:52 695688 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\HTSK\unins000.exe
2009-10-29 07:45 . 2008-04-14 12:00 916480 ——w- c:\windows\system32\wininet.dll
2009-10-25 07:40 . 2009-10-25 07:40 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-10-25 07:40 . 2009-10-25 07:40 47360 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\pcouffin.sys
2009-10-25 07:40 . 2009-10-25 07:40 47360 —-a-w- c:\documents and settings\Jeff Matthews\Application Data\pcouffin.sys
2009-10-21 05:38 . 2008-04-14 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2008-04-14 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2008-04-14 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-01-11_16.39.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-14 06:35 . 2010-01-14 06:35 16384 c:\windows\temp\Perflib_Perfdata_5a4.dat
- 2008-04-14 12:00 . 2009-06-16 14:36 81920 c:\windows\system32\fontsub.dll
+ 2008-04-14 12:00 . 2009-10-15 16:28 81920 c:\windows\system32\fontsub.dll
+ 2008-04-14 12:00 . 2009-10-15 16:28 81920 c:\windows\system32\dllcache\fontsub.dll
- 2008-04-14 12:00 . 2009-06-16 14:36 81920 c:\windows\system32\dllcache\fontsub.dll
+ 2008-04-14 12:00 . 2009-10-15 16:28 119808 c:\windows\system32\t2embed.dll
- 2008-04-14 12:00 . 2009-06-16 14:36 119808 c:\windows\system32\t2embed.dll
+ 2010-01-13 20:15 . 2010-01-13 20:15 153376 c:\windows\system32\javaws.exe
- 2010-01-08 10:41 . 2009-10-11 12:17 145184 c:\windows\system32\javaw.exe
+ 2010-01-13 20:15 . 2010-01-13 20:15 145184 c:\windows\system32\javaw.exe
- 2010-01-08 10:41 . 2009-10-11 12:17 145184 c:\windows\system32\java.exe
+ 2010-01-13 20:15 . 2010-01-13 20:15 145184 c:\windows\system32\java.exe
- 2008-04-14 12:00 . 2009-06-16 14:36 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2008-04-14 12:00 . 2009-10-15 16:28 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2008-04-14 12:00 . 2009-11-21 15:51 471552 c:\windows\system32\dllcache\aclayers.dll
+ 2010-01-13 20:16 . 2010-01-13 20:16 178176 c:\windows\Installer\157f23a.msi
+ 2010-01-13 20:15 . 2010-01-13 20:15 577536 c:\windows\Installer\157f231.msi
+ 2009-05-28 22:37 . 2010-01-05 00:17 29634504 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-27 3883856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"CurseClient"="c:\program files\Curse\CurseClient.exe" [2009-07-31 1935360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2009-05-01 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-05-01 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-01 13750272]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-03-14 233472]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"d:\\World of Warcraft\\Launcher.exe"=
"d:\\World of Warcraft\\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"d:\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Dragon Age Origins Character Creator\\bin_ship\\DAOCharacterCreator.exe"=
"c:\\Program Files\\Dragon Age Origins Character Creator\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"64583:TCP"= 64583:TCP:BitComet 64583 TCP
"64583:UDP"= 64583:UDP:BitComet 64583 UDP
"23424:TCP"= 23424:TCP:BitComet 23424 TCP
"23424:UDP"= 23424:UDP:BitComet 23424 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [8/1/2009 2:54 PM 24652]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [1/11/2010 5:06 PM 25832]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [11/26/2009 4:09 PM 95568]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys –> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-01-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2010-01-14 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 22:07]
2010-01-14 c:\windows\Tasks\User_Feed_Synchronization-{8818D99A-01C3-44EA-8B71-4878400CC76A}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &AOL Toolbar Search
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - ProfilePath - c:\documents and settings\Jeff Matthews\Application Data\Mozilla\Firefox\Profiles\t00b4ems.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-14 08:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(1500)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-01-14 08:03:19
ComboFix-quarantined-files.txt 2010-01-14 16:03
ComboFix2.txt 2010-01-13 18:58
ComboFix3.txt 2010-01-12 05:02
ComboFix4.txt 2010-01-11 16:42
Pre-Run: 58,740,142,080 bytes free
Post-Run: 58,748,116,992 bytes free
- - End Of File - - 2FA0F8322C96E3DD9C470C0B676514B7
DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 8:24:55.21 on Thu 01/14/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2812 [GMT -8:00]
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Jeff Matthews\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - No File
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [CurseClient] c:\program files\curse\CurseClient.exe -silent
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: &AOL Toolbar Search
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll/206
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F}
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1243547212812
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\jeffma~1\applic~1\mozilla\firefox\profiles\t00b4ems.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\mpcstar\codecs\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\mpcstar\codecs\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2010-1-14 138680]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2010-1-14 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2010-1-14 352920]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2010-1-11 25832]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2009-11-26 95568]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\vboxnetflt.sys –> c:\windows\system32\drivers\VBoxNetFlt.sys [?]
=============== Created Last 30 ================
2010-01-14 16:21:57 1060864 —-a-w- c:\windows\system32\MFC71.dll
2010-01-14 15:53:16 0 d—–w- C:\ComboFix
2010-01-13 20:15:55 73728 —-a-w- c:\windows\system32\javacpl.cpl
2010-01-12 17:02:41 0 d—–w- C:\Rooter$
2010-01-12 05:14:19 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-12 05:14:18 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-12 05:14:18 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-12 01:22:32 0 d—–w- c:\docume~1\alluse~1\applic~1\BioWare
2010-01-12 00:55:26 0 d—–w- c:\program files\Dragon Age
2010-01-11 16:33:08 0 d-sha-r- C:\cmdcons
2010-01-11 16:31:50 98816 —-a-w- c:\windows\sed.exe
2010-01-11 16:31:50 77312 —-a-w- c:\windows\MBR.exe
2010-01-11 16:31:50 261632 —-a-w- c:\windows\PEV.exe
2010-01-11 16:31:50 161792 —-a-w- c:\windows\SWREG.exe
2010-01-06 14:38:30 0 d—–w- c:\program files\common files\BioWare
2010-01-06 14:36:25 0 d—–w- c:\program files\Dragon Age Origins Character Creator
2010-01-04 11:30:25 87 —-a-w- c:\windows\MrSetup.ini
2010-01-04 11:30:24 327680 ——w- c:\windows\MrSetup.exe
2010-01-04 11:30:14 0 d—–w- c:\program files\Studio-74
==================== Find3M ====================
2010-01-13 20:15:45 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-11 10:41:37 4876 —-a-w- c:\documents and settings\jeff matthews\FilterData.dat
2009-11-27 23:44:10 18440 -c–a-w- c:\docume~1\jeffma~1\applic~1\GDIPFONTCACHEV1.DAT
2009-10-29 07:45:38 916480 ——w- c:\windows\system32\wininet.dll
2009-10-25 07:40:54 47360 —-a-w- c:\docume~1\jeffma~1\applic~1\pcouffin.sys
2009-10-21 05:38:36 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 —-a-w- c:\windows\system32\httpapi.dll
============= FINISH: 8:25:16.26 ===============
Attach DDS Log
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-12-01.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 5/28/2009 9:23:27 AM
System Uptime: 1/14/2010 8:07:18 AM (0 hours ago)
Motherboard: ASUSTeK Computer INC. | | M2N-E SLI
Processor: AMD Athlon™ 64 X2 Dual Core Processor 6400+ | Socket AM2 | 3216/200mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 149 GiB total, 54.768 GiB free.
D: is FIXED (NTFS) - 39 GiB total, 12.508 GiB free.
E: is FIXED (NTFS) - 35 GiB total, 15.497 GiB free.
F: is CDROM (CDFS)
G: is CDROM ()
H: is FIXED (NTFS) - 149 GiB total, 77.365 GiB free.
I: is FIXED (NTFS) - 932 GiB total, 676.024 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: ACPI\ATK0110\1010110
Manufacturer:
Name:
PNP Device ID: ACPI\ATK0110\1010110
Service:
==== System Restore Points ===================
RP170: 10/17/2009 5:26:02 AM - System Checkpoint
RP171: 10/18/2009 6:20:46 AM - System Checkpoint
RP172: 10/19/2009 6:40:58 AM - System Checkpoint
RP173: 10/20/2009 3:07:23 PM - System Checkpoint
RP174: 10/21/2009 4:25:45 PM - System Checkpoint
RP175: 10/22/2009 6:55:30 PM - System Checkpoint
RP176: 10/24/2009 1:46:24 AM - System Checkpoint
RP177: 10/24/2009 11:26:25 PM - Restore Operation
RP178: 10/24/2009 11:31:28 PM - Software Distribution Service 3.0
RP179: 10/24/2009 11:46:55 PM - Removed Apple Application Support
RP180: 10/25/2009 12:08:03 AM - Removed OTB
RP181: 10/25/2009 4:42:53 PM - Installed WinZip 12.0
RP182: 10/26/2009 5:30:03 PM - System Checkpoint
RP183: 10/27/2009 10:09:24 PM - System Checkpoint
RP184: 10/29/2009 1:40:18 AM - System Checkpoint
RP185: 10/30/2009 6:04:14 AM - System Checkpoint
RP186: 10/31/2009 6:14:38 AM - System Checkpoint
RP187: 11/1/2009 7:23:48 AM - System Checkpoint
RP188: 11/1/2009 3:05:41 PM - Removed Microsoft Silverlight
RP189: 11/1/2009 3:06:48 PM - Removed WinZip 12.0
RP190: 11/2/2009 3:47:32 PM - System Checkpoint
RP191: 11/3/2009 4:14:30 PM - System Checkpoint
RP192: 11/4/2009 4:58:37 PM - System Checkpoint
RP193: 11/5/2009 5:48:19 PM - System Checkpoint
RP194: 11/6/2009 6:02:50 PM - System Checkpoint
RP195: 11/7/2009 6:21:53 PM - System Checkpoint
RP196: 11/8/2009 5:22:59 PM - System Checkpoint
RP197: 11/9/2009 6:32:57 PM - System Checkpoint
RP198: 11/10/2009 5:51:48 PM - Installed Windows XP KB954708.
RP199: 11/10/2009 5:52:01 PM - Installed DirectX
RP200: 11/11/2009 7:05:12 PM - System Checkpoint
RP201: 11/11/2009 9:19:33 PM - Software Distribution Service 3.0
RP202: 11/12/2009 11:36:23 PM - System Checkpoint
RP203: 11/13/2009 1:02:20 PM - Installed SUPERAntiSpyware Free Edition
RP204: 11/14/2009 3:50:45 AM - Installed RPGXP
RP205: 11/14/2009 3:51:15 AM - Installed RGSS-RTP Standard
RP206: 11/15/2009 4:16:59 AM - System Checkpoint
RP207: 11/16/2009 5:05:53 AM - System Checkpoint
RP208: 11/17/2009 6:05:53 AM - System Checkpoint
RP209: 11/18/2009 7:19:53 AM - System Checkpoint
RP210: 11/19/2009 8:06:01 AM - System Checkpoint
RP211: 11/20/2009 2:53:44 PM - System Checkpoint
RP212: 11/21/2009 4:03:29 PM - System Checkpoint
RP213: 11/22/2009 5:39:35 PM - System Checkpoint
RP214: 11/23/2009 7:38:25 PM - System Checkpoint
RP215: 11/24/2009 7:58:57 PM - System Checkpoint
RP216: 11/25/2009 3:00:12 AM - Software Distribution Service 3.0
RP217: 11/26/2009 3:02:00 AM - System Checkpoint
RP218: 11/26/2009 4:08:59 PM - Installed Sun VirtualBox
RP219: 11/27/2009 5:54:44 PM - System Checkpoint
RP220: 11/28/2009 2:33:01 PM - Restore Operation
RP221: 11/29/2009 2:39:37 PM - System Checkpoint
RP222: 11/30/2009 3:06:38 PM - System Checkpoint
RP223: 12/1/2009 4:26:49 PM - System Checkpoint
RP224: 12/2/2009 6:12:44 PM - System Checkpoint
RP225: 12/3/2009 8:05:12 PM - System Checkpoint
RP226: 12/5/2009 12:36:31 AM - System Checkpoint
RP227: 12/6/2009 12:39:40 AM - System Checkpoint
RP228: 12/7/2009 12:49:07 AM - System Checkpoint
RP229: 12/8/2009 1:22:31 AM - System Checkpoint
RP230: 12/9/2009 1:26:47 AM - System Checkpoint
RP231: 12/10/2009 2:22:30 AM - System Checkpoint
RP232: 12/10/2009 3:00:13 AM - Software Distribution Service 3.0
RP233: 12/11/2009 2:13:19 PM - System Checkpoint
RP234: 12/12/2009 2:23:00 PM - System Checkpoint
RP235: 12/13/2009 9:44:13 PM - System Checkpoint
RP236: 12/14/2009 9:56:23 PM - System Checkpoint
RP237: 12/15/2009 10:52:59 PM - System Checkpoint
RP238: 12/17/2009 1:10:43 AM - System Checkpoint
RP239: 12/18/2009 2:05:40 AM - System Checkpoint
RP240: 12/19/2009 3:55:40 PM - System Checkpoint
RP241: 12/20/2009 6:54:46 PM - System Checkpoint
RP242: 12/21/2009 7:42:23 PM - System Checkpoint
RP243: 12/22/2009 8:17:40 PM - System Checkpoint
RP244: 12/23/2009 8:25:59 PM - System Checkpoint
RP245: 12/24/2009 9:24:10 PM - System Checkpoint
RP246: 12/25/2009 10:13:57 PM - System Checkpoint
RP247: 12/26/2009 11:12:07 PM - System Checkpoint
RP248: 12/27/2009 12:26:18 PM - Removed Aion
RP249: 12/27/2009 12:28:03 PM - Removed RPGXP
RP250: 12/27/2009 12:28:17 PM - Removed RGSS-RTP Standard
RP251: 12/27/2009 12:28:41 PM - Removed Sun VirtualBox
RP252: 12/28/2009 1:12:07 PM - System Checkpoint
RP253: 12/29/2009 1:58:45 PM - System Checkpoint
RP254: 12/30/2009 10:28:57 PM - System Checkpoint
RP255: 1/1/2010 5:10:07 AM - System Checkpoint
RP256: 1/2/2010 5:07:58 PM - System Checkpoint
RP257: 1/3/2010 5:35:17 PM - System Checkpoint
RP258: 1/4/2010 5:50:10 PM - System Checkpoint
RP259: 1/5/2010 8:22:38 PM - System Checkpoint
RP260: 1/6/2010 6:37:20 AM - Removed Microsoft Visual C++ 2005 Redistributable
RP261: 1/6/2010 6:37:37 AM - Installed Microsoft Visual C++ 2005 Redistributable
RP262: 1/6/2010 6:37:45 AM - Installed DirectX
RP263: 1/7/2010 6:58:53 AM - System Checkpoint
RP264: 1/8/2010 2:40:43 AM - Installed Java™ 6 Update 17
RP265: 1/9/2010 2:43:17 AM - System Checkpoint
RP266: 1/10/2010 2:57:03 AM - System Checkpoint
RP267: 1/10/2010 3:21:55 AM - Removed NCsoft Launcher
RP268: 1/11/2010 6:02:22 AM - System Checkpoint
RP269: 1/12/2010 10:23:14 AM - System Checkpoint
RP270: 1/13/2010 12:12:27 PM - Removed Java™ 6 Update 10
RP271: 1/13/2010 12:12:50 PM - Removed MapleStory.
RP272: 1/13/2010 12:13:11 PM - Removed Microsoft Virtual PC 2007
RP273: 1/13/2010 12:13:54 PM - Removed SUPERAntiSpyware Free Edition
RP274: 1/13/2010 12:15:42 PM - Installed Java™ 6 Update 18
RP275: 1/13/2010 10:06:57 PM - Software Distribution Service 3.0
==== Installed Programs ======================
7-Zip 4.42
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.2
AMD Processor Driver
Any Video Converter 2.7.3
Apple Application Support
Apple Software Update
avast! Antivirus
Avidemux 2.5
AVS Update Manager 1.0
AVS Video Converter 6
AVS Video Recorder 2.4
AVS Video ReMaker [removed]
AVS4YOU Software Navigator 1.3
BitComet 1.06
Broadcom 802.11 Driver
ConvertXtoDVD 3.8.0.193j
Critical Update for Windows Media Player 11 (KB959772)
Curse Client
Dragon Age: Origins
Dragon Age: Origins Character Creator
DVD Decrypter (Remove Only)
DVD Shrink 3.2
EVEREST Home Edition v2.20
EVEREST Ultimate Edition v4.60
ffdshow [rev 2527] [2008-12-19]
Fraps (remove only)
GOM Player
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HTSK
InterActual Player
Java Auto Updater
Java™ 6 Update 18
Junk Mail filter update
K-Lite Codec Pack 4.8.5 (Full)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Office Live Add-in 1.3
Microsoft Office XP Professional with FrontPage
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
MIDI Converter Studio 6.1
MKVtoolnix 2.9.8
MobMap 3.33
Mozilla Firefox (3.5.7)
MpcStar 4.1
MSVCRT
MSXML 6.0 Parser (KB927977)
Nero 6 Ultra Edition
NVIDIA Drivers
NVIDIA PhysX
OGA Notifier 2.0.0048.0
PFPortChecker 1.0.31
PowerDVD
PowerISO
Project64 1.6
QuickTime
RealPlayer
REALTEK GbE & FE Ethernet PCI NIC Driver
REALTEK Gigabit and Fast Ethernet NIC Driver
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Segoe UI
SpeedFan (remove only)
Spybot - Search & Destroy
The File Splitter 1.31
Total Video Converter 3.50
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB971180)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Ventrilo Client
VideoLAN VLC media player 0.8.6c
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
WinRAR archiver
Wireless Home Network Setup
World of Warcraft
XML Paper Specification Shared Components Pack 1.0
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Search Protection
Yahoo! Software Update
==== Event Viewer Messages From Past Week ========
1/12/2010 8:58:42 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/11/2010 8:48:14 PM, error: PlugPlayManager [11] - The device Root\LEGACY_XDVA279\0000 disappeared from the system without first being prepared for removal.
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The Yahoo! Updater service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The Viewpoint Manager Service service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 8:42:25 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
1/11/2010 6:38:09 PM, error: System Error [1003] - Error code 1000008e, parameter1 c0000005, parameter2 805803f8, parameter3 a3065c14, parameter4 00000000.
1/11/2010 3:01:03 AM, error: System Error [1003] - Error code 1000000a, parameter1 96f8c67d, parameter2 000000ff, parameter3 00000001, parameter4 806e4ea5.
1/11/2010 3:00:43 AM, error: System Error [1003] - Error code 1000000a, parameter1 00000000, parameter2 000000ff, parameter3 00000000, parameter4 806e4ea0.
1/11/2010 2:59:35 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
==== End Of File ===========================
Ok i have a question now. Do you by any chance know what this is. MSXML 6.0 Parser That file was found in my programs when i was deleting the Viewpoint software from my machine. It says used rarely. I hope thats not some kind of automated tracker, spyware or something.
Also when i run my Processes in the Task Manager i notice ALOT of files that says SVschost. When i go to certain weg pages, those file's run up alot of CPU. I am not sure what that means though if its good or bad. I am just trying to pinpoint some things to better help you in solving my problem here.
Also i want to make sure i delete every possible remnant of any crack/keygen, or seriel codes that are on my computer. I notice alot of my viruses happend to be coming from my "game Directory" folder in which i did download alot of emulation, which is legal if you own the system. But i noticed everytime i clean my machine that seems to be were the source is coming from.