This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] GAMEVANCE

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I keep getting these high-lighted word in green on any website im on and when i scroll my mouse over it, a little pop up from gamevance show up. It really annoying and i cant seem to get rid of it. Any assitance would be greatly appreciated.
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 5 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
•Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
•This may cause a delay in response time, but I will do my best to keep it as short as possible.
•I will reply back shortly with instructions.
Hello esseff,please do the following.

Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

If GMER will not run in normal windows, please run it in safe mode.



In your next reply please post the following
MBAM log
Both OTL logs
GMER log
Here is the MBAM log: Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 3930 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 4/20/2010 4:23:31 PM mbam-log-2010-04-20 (16-23-31).txt Scan type: Quick scan Objects scanned: 102993 Time elapsed: 5 minute(s), 3 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk (Rogue.InternetSecurity2010) -> Quarantined and deleted successfully. C:\WINDOWS\system32\config\systemprofile\Start Menu\Internet Security 2010.lnk (Rogue.InternetSecurity2010) -> Quarantined and deleted successfully.
Here is OTL Part 1:
OTL logfile created on: 4/20/2010 4:28:44 PM - Run 1
OTL by OldTimer - Version 3.2.1.3 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 573.00 Mb Available Physical Memory | 56.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.50 Gb Total Space | 101.67 Gb Free Space | 70.85% Space Free | Partition Type: NTFS
Drive D: | 5.53 Gb Total Space | 1.92 Gb Free Space | 34.65% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: B-PLEASE
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe (Stardock Systems, Inc)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll (Stardock.Net, Inc)
MOD - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll (Stardock.Net, Inc)
MOD - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)


========== Win32 Services (SafeList) ==========

SRV - (npggsvc) – C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (GameConsoleService) – C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe (WildTangent, Inc.)


========== Driver Services (SafeList) ==========

DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura Ltd)
DRV - (fasttx2k) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (viaagp1) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation )
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "Playdom Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2464976&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://newsarama.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:9.0.0.736
FF - prefs.js..extensions.enabledItems: [removed]:1.5.3
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.5.6.0
FF - prefs.js..extensions.enabledItems: [removed]:0.6.20100314

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/02 14:29:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/02 14:29:22 | 000,000,000 | —D | M]

[2009/11/05 21:41:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/04/20 14:00:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\avsqrjul.default\extensions
[2009/11/06 19:10:52 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\avsqrjul.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/25 18:32:31 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\avsqrjul.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2009/11/05 22:03:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\avsqrjul.default\extensions\[removed]
[2010/03/16 16:46:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\avsqrjul.default\extensions\[removed]
[2010/04/13 06:05:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\avsqrjul.default\extensions\[removed]
[2010/04/20 14:00:42 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/11/09 11:47:34 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2010/01/19 11:35:52 | 000,238,776 | —- | M] (Pando Networks) – C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll

O1 HOSTS File: ([2010/01/31 23:34:48 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {ae2786e8-100f-4a07-9c0d-5bd8e3157782} - File not found
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\wbsys.dll) - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\WB: DllName - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll - C:\Program Files\Stardock\Object Desktop\WindowBlinds\fastload.dll (Stardock)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/05/12 18:46:51 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 05:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/11/05 20:22:09 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (74885954556395520)

========== Files/Folders - Created Within 30 Days ==========

[2010/04/20 06:48:09 | 000,562,176 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/04/14 18:48:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Unity
[2010/04/14 18:45:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Unity
[2010/04/14 18:45:19 | 000,000,000 | —D | C] – C:\Program Files\Unity
[2010/04/14 18:44:36 | 003,391,612 | —- | C] (Unity Technologies ApS) – C:\Documents and Settings\Owner\Desktop\UnityWebPlayer.exe
[2010/04/08 18:51:17 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_5.dll
[2010/04/08 18:51:16 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_42.dll
[2010/04/08 18:51:16 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_5.dll
[2010/04/08 18:51:15 | 005,501,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dcsx_42.dll
[2010/04/08 18:51:15 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx11_42.dll
[2010/04/08 18:51:14 | 001,892,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_42.dll
[2010/04/08 18:51:14 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_42.dll
[2010/04/08 18:51:13 | 004,178,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_41.dll
[2010/04/08 18:51:13 | 001,846,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_41.dll
[2010/04/08 18:51:13 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_41.dll
[2010/04/08 18:51:12 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_4.dll
[2010/04/08 18:51:12 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_4.dll
[2010/04/08 18:51:12 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_3.dll
[2010/04/08 18:51:11 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_6.dll
[2010/04/08 18:51:10 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_40.dll
[2010/04/08 18:51:10 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_40.dll
[2010/04/08 18:51:09 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_40.dll
[2010/04/08 18:51:09 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_3.dll
[2010/04/08 18:51:09 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_2.dll
[2010/04/08 18:51:08 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_3.dll
[2010/04/08 18:51:08 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_5.dll
[2010/04/08 18:51:07 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_2.dll
[2010/04/08 18:51:07 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_2.dll
[2010/04/08 18:51:07 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_1.dll
[2010/04/08 18:51:06 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_39.dll
[2010/04/08 18:51:06 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_39.dll
[2010/04/08 18:51:06 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_39.dll
[2010/04/08 18:51:05 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_1.dll
[2010/04/08 18:51:05 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_0.dll
[2010/04/08 18:51:04 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_1.dll
[2010/04/08 18:51:04 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_4.dll
[2010/04/08 18:51:03 | 003,850,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_38.dll
[2010/04/08 18:51:03 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_38.dll
[2010/04/08 18:51:03 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_38.dll
[2010/04/08 18:51:02 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_0.dll
[2010/04/08 18:51:01 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_0.dll
[2010/04/08 18:51:01 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_3.dll
[2010/04/08 18:51:00 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_37.dll
[2010/04/08 18:51:00 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_37.dll
[2010/04/08 18:51:00 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_37.dll
[2010/04/08 18:50:59 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_10.dll
[2010/04/08 18:50:58 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_36.dll
[2010/04/08 18:50:58 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_36.dll
[2010/04/08 18:50:58 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_36.dll
[2010/04/08 18:50:57 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_35.dll
[2010/04/08 18:50:57 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_35.dll
[2010/04/08 18:50:57 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_9.dll
[2010/04/08 18:50:56 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_35.dll
[2010/04/08 18:50:56 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_8.dll
[2010/04/08 18:50:56 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_2.dll
[2010/04/08 18:50:55 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_34.dll
[2010/04/08 18:50:55 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_34.dll
[2010/04/08 18:50:55 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_34.dll
[2010/04/08 18:50:54 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_3.dll
[2010/04/08 18:50:51 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_7.dll
[2010/04/08 18:50:49 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_33.dll
[2010/04/08 18:50:49 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_33.dll
[2010/04/08 18:50:46 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_33.dll
[2010/04/08 18:50:46 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_6.dll
[2010/04/08 18:50:46 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_5.dll
[2010/04/08 18:50:45 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2010/04/08 18:50:45 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_31.dll
[2010/04/08 18:50:45 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_4.dll
[2010/04/08 18:50:45 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_3.dll
[2010/04/08 18:50:45 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_1.dll
[2010/04/08 18:50:44 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_2.dll
[2010/04/08 18:50:44 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_2.dll
[2010/04/08 18:50:44 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_1.dll
[2010/04/08 18:50:43 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_1.dll
[2010/04/08 18:50:35 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_30.dll
[2010/04/08 18:50:35 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_0.dll
[2010/04/08 18:50:35 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_0.dll
[2010/04/08 18:50:34 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_29.dll
[2010/04/08 18:50:34 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_28.dll
[2010/04/08 18:50:33 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_26.dll
[2010/04/08 18:50:33 | 000,061,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput9_1_0.dll
[2010/04/08 18:50:32 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_25.dll
[2010/04/08 18:50:29 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_24.dll
[2010/04/08 18:49:43 | 000,000,000 | —D | C] – C:\WINDOWS\Logs
[2010/04/08 18:49:35 | 000,000,000 | —D | C] – C:\Program Files\Cryptic Studios
[2010/04/01 19:00:48 | 000,032,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2010/03/29 07:48:17 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/03/29 07:48:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/03/28 18:42:27 | 000,000,000 | —D | C] – C:\Program Files\Eusing Free Registry Cleaner
[2010/03/28 18:42:15 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/03/28 18:38:30 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2009/11/05 23:17:04 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2004/05/12 18:49:30 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2004/05/12 18:49:29 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2004/05/12 18:49:29 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/04/20 16:25:13 | 000,186,097 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/04/20 16:25:07 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/20 16:25:06 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/04/20 16:24:24 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/04/20 16:24:23 | 002,359,296 | -H– | M] () – C:\Documents and Settings\Owner\NTUSER.DAT
[2010/04/20 16:00:00 | 000,000,262 | -H– | M] () – C:\WINDOWS\tasks\AC98B9B197AF2B69.job
[2010/04/20 06:48:36 | 000,284,915 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010/04/20 06:48:09 | 000,562,176 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/04/19 14:25:56 | 358,018,489 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HoNClient-0.3.3.exe
[2010/04/14 18:44:39 | 003,391,612 | —- | M] (Unity Technologies ApS) – C:\Documents and Settings\Owner\Desktop\UnityWebPlayer.exe
[2010/04/14 16:04:29 | 004,814,268 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2010/04/14 16:01:11 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/04/03 14:29:11 | 001,063,104 | —- | M] () – C:\Documents and Settings\Owner\Application Data\8d51356f4bb435f1b6f84a242a76b34c-i686.cache-2
[2010/03/30 16:44:25 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/29 07:48:23 | 000,000,941 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2010/03/28 18:37:07 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/03/28 18:31:07 | 003,905,353 | R— | M] () – C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2010/03/26 16:50:03 | 000,528,020 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/26 16:50:03 | 000,445,370 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/03/26 16:50:03 | 000,072,576 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/03/22 11:53:04 | 000,045,467 | —- | M] () – C:\Documents and Settings\Owner\Desktop\MARK.BMP.rar
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/04/20 06:48:36 | 000,284,915 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010/04/19 13:54:37 | 358,018,489 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HoNClient-0.3.3.exe
[2010/03/29 07:48:23 | 000,000,941 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2010/03/22 11:53:04 | 000,045,467 | —- | C] () – C:\Documents and Settings\Owner\Desktop\MARK.BMP.rar
[2010/01/29 15:13:30 | 000,012,288 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/24 17:15:59 | 000,002,352 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/12/10 21:25:38 | 000,000,082 | —- | C] () – C:\WINDOWS\wb.ini
[2009/11/19 16:09:14 | 000,020,152 | —- | C] () – C:\Documents and Settings\Owner\Application Data\c03a1910ab4c98b8fe52989672e7ed28-i686.cache-2
[2009/11/19 16:09:13 | 001,063,104 | —- | C] () – C:\Documents and Settings\Owner\Application Data\8d51356f4bb435f1b6f84a242a76b34c-i686.cache-2
[2009/11/05 21:32:31 | 000,262,144 | —- | C] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2009/11/05 21:32:31 | 000,001,024 | -H– | C] () – C:\Documents and Settings\All Users\NTUSER.DAT.LOG
[2009/11/05 21:30:37 | 001,486,848 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2009/11/05 21:30:37 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008/05/16 15:01:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/05/16 15:01:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2004/05/15 04:32:12 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/05/12 22:01:17 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
[2004/05/12 22:00:51 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/05/12 22:00:51 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2004/05/12 21:59:23 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2004/05/12 21:57:44 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2004/05/12 21:42:17 | 000,027,756 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2004/05/12 21:41:38 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2004/05/12 20:50:40 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/05/12 20:42:12 | 000,000,889 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2004/05/12 20:02:46 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/05/12 19:54:22 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2004/05/12 19:30:08 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/05/12 19:21:01 | 000,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2004/05/12 19:21:01 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2004/05/12 19:20:43 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/05/12 19:20:00 | 000,015,318 | —- | C] () – C:\Documents and Settings\Owner\ml2.srt
[2004/05/12 19:20:00 | 000,015,318 | —- | C] () – C:\Documents and Settings\Owner\ml1.srt
[2004/05/12 19:20:00 | 000,000,071 | —- | C] () – C:\Documents and Settings\Owner\tempdiff.txt
[2004/05/12 18:51:31 | 000,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/05/12 18:50:53 | 000,001,024 | -H– | C] () – C:\Documents and Settings\Owner\ntuser.dat.LOG
[2004/05/12 18:50:53 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Owner\ntuser.ini
[2004/05/12 18:50:52 | 002,359,296 | -H– | C] () – C:\Documents and Settings\Owner\NTUSER.DAT
[2004/05/12 18:36:11 | 000,000,553 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini

========== LOP Check ==========

[2010/01/11 23:45:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fugazo
[2009/12/27 17:44:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2009/12/27 18:47:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2010/01/19 11:36:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/01/29 14:54:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2009/12/27 17:43:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/01/20 16:12:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Flag16Book
[2010/01/20 16:48:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2009/12/27 18:47:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PlayFirst
[2010/01/29 15:35:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Publish Providers
[2004/05/12 22:19:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2010/01/29 15:45:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sony
[2009/11/23 09:46:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SystemRequirementsLab
[2010/04/14 18:48:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Unity
[2010/03/06 17:05:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\uTorrent
[2009/12/27 16:32:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WildTangent
[2010/04/20 16:00:00 | 000,000,262 | -H– | M] () – C:\WINDOWS\Tasks\AC98B9B197AF2B69.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/11/05 23:06:59 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/11/06 00:20:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/11/05 23:06:59 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2009/11/06 00:20:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 11:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 11:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 11:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 23:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/04/03 04:55:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2009/11/05 23:06:59 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/11/06 00:20:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/04/02 21:55:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\I386\sp1.cab:atapi.sys
[2009/11/05 23:06:59 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2009/11/06 00:20:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2004/04/02 21:10:00 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\$NtUninstallQ331958$\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 17:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 17:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 17:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 00:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 17:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 17:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 17:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 00:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 00:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2004/05/12 11:39:01 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/05/12 11:39:01 | 000,602,112 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/05/12 11:39:01 | 000,393,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< End of report >
Part 2:
OTL Extras logfile created on: 4/20/2010 4:28:44 PM - Run 1
OTL by OldTimer - Version 3.2.1.3 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 573.00 Mb Available Physical Memory | 56.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.50 Gb Total Space | 101.67 Gb Free Space | 70.85% Space Free | Partition Type: NTFS
Drive D: | 5.53 Gb Total Space | 1.92 Gb Free Space | 34.65% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: B-PLEASE
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"56993:TCP" = 56993:TCP:*:Enabled:Pando Media Booster
"56993:UDP" = 56993:UDP:*:Enabled:Pando Media Booster
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\WINDOWS\Temp\alg.exe" = C:\WINDOWS\Temp\alg.exe:*:Enabled:Application Layer Gateway Service – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\softnyx\GunboundWC\GunBound.gme" = C:\Program Files\softnyx\GunboundWC\GunBound.gme:*:Enabled:GunBound – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{1D643CD7-4DD6-11D7-A4E0-000874180BB3}" = Microsoft Money 2004
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{624A3DDD-F7F0-427C-993E-611EFC36EAE1}" = Rose Online Pegasus Test [removed]
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" =
"{8C64E145-54BA-11D6-91B1-00500462BE80}" = Microsoft Money 2004 System Pack
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{95470515-4CF7-44F6-871F-60EAFF98C6F9}" = AruaROSE v834
"{97E038E1-41AD-4C93-BCDC-6A2394AEE352}" = Vegas Movie Studio Platinum 9.0
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD Player
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}" = Wizard101
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}" = Microsoft Plus! Digital Media Edition
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
"COH" = City of Villains/City of Heroes (remove only)
"Compaq Instant Support" = Compaq Instant Support
"Cooking Academy" = Cooking Academy (remove only)
"Disney Toontown Online" = Disney Toontown Online
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.9)" = Mozilla Firefox (3.5.9)
"NVIDIA Display Driver" = NVIDIA Display Driver
"NVIDIA Drivers" = NVIDIA Drivers
"PROR" = Microsoft Office Professional 2007 Trial
"PS2" = PS2
"Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
"Python 2.2.1" = Python 2.2.1
"RoseNA" = Rose Online
"Rundll Errors Fix Wizard_is1" = Rundll Errors Fix Wizard
"SystemRequirementsLab" = System Requirements Lab
"The Suffering" = The Suffering (remove only)
"Theme Manager" = Theme Manager
"UnityWebPlayer" = Unity Web Player
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.0.0
"WildTangent wildgames Master Uninstall" = WildTangent Games
"WindowBlinds" = WindowBlinds
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{373B1718-8CC5-4567-8EE2-9033AD08A680}" = Roblox for Owner
"dumbmeowdefy" = CiD Help

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/17/2009 1:45:22 AM | Computer Name = B-PLEASE | Source = Application Error | ID = 1000
Description = Faulting application trose.exe, version 1.1.5.385, faulting module
znzin.dll, version 3.4.3.940, fault address 0x000312c0.

Error - 12/17/2009 2:21:04 PM | Computer Name = B-PLEASE | Source = Application Error | ID = 1000
Description = Faulting application trose.exe, version 1.1.5.385, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x00010a19.

Error - 12/17/2009 4:10:23 PM | Computer Name = B-PLEASE | Source = Application Error | ID = 1000
Description = Faulting application trose.exe, version 1.1.5.385, faulting module
unknown, version 0.0.0.0, fault address 0x1d8f36bd.

Error - 12/18/2009 3:43:50 PM | Computer Name = B-PLEASE | Source = Application Error | ID = 1000
Description = Faulting application trose.exe, version 1.1.5.385, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x00010a19.

Error - 12/20/2009 3:42:36 PM | Computer Name = B-PLEASE | Source = Application Hang | ID = 1002
Description = Hanging application RobloxApp.exe, version 0.21.0.23, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/20/2009 11:31:53 PM | Computer Name = B-PLEASE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module dirapix.dll, version 10.4.1.27, fault address 0x00037a3d.

Error - 12/21/2009 2:16:18 AM | Computer Name = B-PLEASE | Source = Application Error | ID = 1000
Description = Faulting application trose.exe, version 1.1.5.385, faulting module
znzin.dll, version 3.4.3.940, fault address 0x000316b9.

Error - 12/22/2009 1:03:01 AM | Computer Name = B-PLEASE | Source = Application Error | ID = 1000
Description = Faulting application trose.exe, version 1.1.5.385, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x00010a19.

Error - 12/22/2009 4:57:25 PM | Computer Name = B-PLEASE | Source = Application Error | ID = 1000
Description = Faulting application fearmp.exe, version 1.8.282.0, faulting module
gam19a.tmp, version 1.8.282.0, fault address 0x00166cf1.

Error - 12/23/2009 8:41:28 PM | Computer Name = B-PLEASE | Source = Application Error | ID = 1000
Description = Faulting application trose.exe, version 1.3.0.1, faulting module znzin.dll,
version 3.4.3.940, fault address 0x000322dc.

[ System Events ]
Error - 4/14/2010 7:06:53 PM | Computer Name = B-PLEASE | Source = Service Control Manager | ID = 7034
Description = The Print Spooler service terminated unexpectedly. It has done this
1 time(s).

Error - 4/14/2010 7:06:55 PM | Computer Name = B-PLEASE | Source = Service Control Manager | ID = 7034
Description = The Application Layer Gateway Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 4/14/2010 7:07:07 PM | Computer Name = B-PLEASE | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).

Error - 4/14/2010 7:07:09 PM | Computer Name = B-PLEASE | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 4/15/2010 10:37:43 PM | Computer Name = B-PLEASE | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 4/15/2010 10:37:45 PM | Computer Name = B-PLEASE | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).

Error - 4/15/2010 10:37:50 PM | Computer Name = B-PLEASE | Source = Service Control Manager | ID = 7034
Description = The Application Layer Gateway Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 4/15/2010 10:37:52 PM | Computer Name = B-PLEASE | Source = Service Control Manager | ID = 7034
Description = The Print Spooler service terminated unexpectedly. It has done this
1 time(s).

Error - 4/20/2010 7:25:20 PM | Computer Name = B-PLEASE | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.

Error - 4/20/2010 7:25:20 PM | Computer Name = B-PLEASE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
fasttx2k IntelIde viaagp1 ViaIde


< End of report >



Waiting for GMER to finish….first time my it locked up my system
GMER kept locking up so i ran it in safe mode. Here is the log:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-20 20:08:30
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\kxtyqpod.sys


—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR

—- EOF - GMER 1.0.15 —-
Hello esseff

Peer-to-Peer Programs Warning
Your log shows that you are using so called peer-to-peer or file-sharing programs. These programs allow to share files between users as the name(s) suggest. In today's world cyber crime has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.

It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care.

It is also important to note that sharing entertainment files and proprietary software infringes the copyright laws in many countries over the world and you are putting yourself at risk of being indicted through organizations watching over the rights of the authors of such files (i.e. the RIAA for music files, or the MPAA for movie files in the USA) or the authors of the files themselves.

It is your decision whether or not you wish to keep your program(s). However, please refrain from using them until your computer has been declared clean


Please do the following.


SPYBOT TEATIMER
  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Uncheck the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done and reboot your computer.
    (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    FF - prefs.js..extensions.enabledItems: [removed]:1.0.0
    O2 - BHO: (no name) - {ae2786e8-100f-4a07-9c0d-5bd8e3157782} - File not found
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

Your Malwarebytes log shows you are using an old database.Please update and run a new scan.Post the log.

It seems you have run ComboFix.Can you please post the log it produced.

In your next reply please post the following.

  • OTLlog
  • Updated MBAM log
  • Combofix log
I did update MBAM prior to running it, but i will update again and post a new MBAM log. I havent ran combofix in a while. Did you want the last log or a new log?
OTL log: All processes killed ========== OTL ========== Prefs.js: [removed]:1.0.0 removed from extensions.enabledItems Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ae2786e8-100f-4a07-9c0d-5bd8e3157782}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ae2786e8-100f-4a07-9c0d-5bd8e3157782}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: LocalService ->Temp folder emptied: 65748 bytes ->Temporary Internet Files folder emptied: 16786 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Owner ->Temp folder emptied: 134991244 bytes ->Temporary Internet Files folder emptied: 16085736 bytes ->Java cache emptied: 16762594 bytes ->FireFox cache emptied: 37858799 bytes ->Flash cache emptied: 275994 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 39097 bytes %systemroot%\System32 .tmp files removed: 8456209 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 32768 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 294871 bytes RecycleBin emptied: 110103 bytes Total Files Cleaned = 205.00 mb OTL by OldTimer - Version 3.2.1.3 log created on 04212010_061924 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
MBAM log: Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 4014 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 4/21/2010 6:27:28 AM mbam-log-2010-04-21 (06-27-28).txt Scan type: Quick scan Objects scanned: 103641 Time elapsed: 3 minute(s), 52 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Old combofix log:
ComboFix 10-03-28.01 - Owner 03/28/2010 18:32:31.9.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.755 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\eSellerateEngine.dll

.
((((((((((((((((((((((((( Files Created from 2010-02-28 to 2010-03-29 )))))))))))))))))))))))))))))))
.

2010-03-13 04:01 . 2010-03-13 04:01 119808 —-a-w- c:\documents and settings\Owner\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\FFTextLinks.dll
2010-03-12 05:36 . 2010-03-12 05:36 ——– d—–w- c:\program files\softnyx
2010-03-10 04:48 . 2009-10-23 15:28 3558912 -c—-w- c:\windows\system32\dllcache\moviemk.exe
2010-03-01 23:44 . 2010-03-01 23:44 ——– d—–w- c:\program files\Maxis

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-21 17:50 . 2010-01-22 22:49 ——– d—–w- c:\program files\City of Heroes
2010-03-10 11:00 . 2010-01-20 23:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-07 00:29 . 2009-11-19 23:08 ——– d—–w- c:\documents and settings\Owner\Application Data\vlc
2010-03-07 00:05 . 2009-11-06 04:43 ——– d—–w- c:\documents and settings\Owner\Application Data\uTorrent
2010-02-14 23:07 . 2010-02-14 23:07 ——– d—–w- c:\program files\Common Files\Stardock
2010-02-08 17:01 . 2009-11-06 04:52 78240 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-08 03:57 . 2009-12-28 00:25 1670136 —-a-w- c:\documents and settings\All Users\Application Data\WildTangent\Game Console - WildGames\Downloads\en-us\Installers\SetupGamesClient.exe
2010-02-05 18:21 . 2009-12-04 02:22 ——– d—–w- c:\program files\AruaROSE
2010-02-03 20:59 . 2010-02-03 20:59 ——– d—–w- c:\program files\Rundll Errors Fix Wizard
2010-02-01 06:51 . 2009-12-28 05:05 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-29 22:45 . 2010-01-29 22:33 ——– d—–w- c:\documents and settings\Owner\Application Data\Sony
2010-01-29 22:35 . 2010-01-29 22:35 ——– d—–w- c:\documents and settings\Owner\Application Data\Publish Providers
2010-01-29 21:54 . 2010-01-29 21:54 ——– d—–w- c:\program files\Vstplugins
2010-01-29 21:54 . 2010-01-29 21:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Sony
2010-01-29 21:54 . 2010-01-29 21:54 ——– d—–w- c:\program files\Sony
2010-01-29 21:53 . 2010-01-29 21:53 ——– d—–w- c:\program files\Sony Setup
2010-01-29 21:14 . 2010-01-29 21:14 ——– d—–w- c:\program files\Disney
2010-01-20 23:12 . 2010-01-20 23:12 294912 —-a-w- c:\documents and settings\Owner\Application Data\Flag16Book\regsfirstinfo.exe
2010-01-20 23:12 . 2010-01-20 23:12 712704 —-a-w- c:\documents and settings\Owner\Application Data\Flag16Book\ksxatwsb.exe
2010-01-20 23:12 . 2010-01-20 23:12 483328 —-a-w- c:\documents and settings\Owner\Application Data\Flag16Book\Morebashfive.exe
2010-01-20 20:13 . 2010-01-26 01:32 52224 —-a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\avsqrjul.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
2010-01-20 20:13 . 2010-01-26 01:32 101376 —-a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\avsqrjul.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
2010-01-13 04:10 . 2009-12-25 00:15 2352 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-01-08 00:07 . 2010-02-01 06:51 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-08 00:07 . 2010-02-01 06:51 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-31 16:50 . 2004-05-13 01:35 353792 —-a-w- c:\windows\system32\drivers\srv.sys
.

((((((((((((((((((((((((((((( SnapShot_2010-02-21_19.40.00 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-11-06 07:17 . 2009-10-28 15:07 46080 c:\windows\system32\tzchange.exe
+ 2009-11-06 07:17 . 2010-01-23 08:11 46080 c:\windows\system32\tzchange.exe
+ 2004-05-13 01:35 . 2010-03-26 23:50 72576 c:\windows\system32\perfc009.dat
- 2004-05-13 01:35 . 2010-01-27 03:05 72576 c:\windows\system32\perfc009.dat
+ 2009-11-06 04:54 . 2010-03-14 18:42 84507 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
- 2009-11-06 04:54 . 2010-01-16 00:50 84507 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-11-14 01:22 . 2010-03-26 23:49 87716 c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
- 2009-10-29 05:27 . 2009-10-29 05:27 94208 c:\windows\system32\Adobe\Shockwave 11\SwMenu.dll
+ 2010-01-12 06:26 . 2010-01-12 06:26 94208 c:\windows\system32\Adobe\Shockwave 11\SwMenu.dll
+ 2010-01-12 05:54 . 2010-01-12 05:54 79488 c:\windows\system32\Adobe\Shockwave 11\gtapi.dll
- 2009-10-29 04:55 . 2009-10-29 04:55 79488 c:\windows\system32\Adobe\Shockwave 11\gtapi.dll
+ 2010-01-12 06:41 . 2010-01-12 06:41 65816 c:\windows\system32\Adobe\Director\SWDNLD.EXE
- 2010-01-20 23:56 . 2010-02-10 11:01 35088 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
+ 2010-01-20 23:56 . 2010-03-10 11:00 35088 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
+ 2010-01-20 23:56 . 2010-03-10 11:00 18704 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
- 2010-01-20 23:56 . 2010-02-10 11:01 18704 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
- 2010-01-20 23:56 . 2010-02-10 11:01 20240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
+ 2010-01-20 23:56 . 2010-03-10 11:00 20240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
+ 2010-02-24 11:00 . 2009-10-28 15:07 46080 c:\windows\$NtUninstallKB979306$\tzchange.exe
+ 2010-02-24 11:00 . 2010-01-23 10:40 16896 c:\windows\$NtUninstallKB979306$\spuninst\tzchange.dll
+ 2010-02-24 11:00 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB976662-IE8\update\spcustom.dll
+ 2010-02-24 11:00 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB976662-IE8\spmsg.dll
+ 2010-01-12 06:28 . 2010-01-12 06:28 9216 c:\windows\system32\Adobe\Shockwave 11\DynaPlayer.dll
- 2009-10-29 05:29 . 2009-10-29 05:29 9216 c:\windows\system32\Adobe\Shockwave 11\DynaPlayer.dll
+ 2004-05-13 01:35 . 2010-03-26 23:50 445370 c:\windows\system32\perfh009.dat
- 2004-05-13 01:35 . 2010-01-27 03:05 445370 c:\windows\system32\perfh009.dat
+ 2010-01-27 00:58 . 2010-01-27 00:58 256280 c:\windows\system32\Macromed\Flash\FlashUtil10e.exe
+ 2003-01-14 04:57 . 2009-12-09 05:53 726528 c:\windows\system32\jscript.dll
- 2003-01-14 04:57 . 2009-06-22 06:44 726528 c:\windows\system32\jscript.dll
+ 2009-03-08 12:33 . 2009-12-09 05:53 726528 c:\windows\system32\dllcache\jscript.dll
- 2009-03-08 12:33 . 2009-06-22 06:44 726528 c:\windows\system32\dllcache\jscript.dll
+ 2010-01-12 05:54 . 2010-01-12 05:54 136568 c:\windows\system32\Adobe\Shockwave 11\SYMCCHECKER.DLL
- 2009-10-29 05:27 . 2009-10-29 05:27 114688 c:\windows\system32\Adobe\Shockwave 11\SwInit.exe
+ 2010-01-12 06:26 . 2010-01-12 06:26 114688 c:\windows\system32\Adobe\Shockwave 11\SwInit.exe
+ 2010-01-12 06:39 . 2010-01-12 06:39 459032 c:\windows\system32\Adobe\Shockwave 11\SwHelper_1156606.exe
- 2009-10-29 05:29 . 2009-10-29 05:29 446464 c:\windows\system32\Adobe\Shockwave 11\Proj.dll
+ 2010-01-12 06:29 . 2010-01-12 06:29 446464 c:\windows\system32\Adobe\Shockwave 11\Proj.dll
+ 2010-01-12 06:27 . 2010-01-12 06:27 372736 c:\windows\system32\Adobe\Shockwave 11\Plugin.dll
- 2009-10-29 05:28 . 2009-10-29 05:28 372736 c:\windows\system32\Adobe\Shockwave 11\Plugin.dll
+ 2010-01-12 05:54 . 2010-01-12 05:54 753152 c:\windows\system32\Adobe\Shockwave 11\gi.dll
- 2009-10-29 05:26 . 2009-10-29 05:26 503808 c:\windows\system32\Adobe\Shockwave 11\Control.dll
+ 2010-01-12 06:26 . 2010-01-12 06:26 503808 c:\windows\system32\Adobe\Shockwave 11\Control.dll
+ 2010-01-12 06:40 . 2010-01-12 06:40 213272 c:\windows\system32\Adobe\Director\SwDir.dll
+ 2010-01-12 06:28 . 2010-01-12 06:28 135168 c:\windows\system32\Adobe\Director\np32dsw.dll
- 2010-01-20 23:56 . 2010-02-10 11:01 888080 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
+ 2010-01-20 23:56 . 2010-03-10 11:00 888080 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
+ 2010-01-20 23:56 . 2010-03-10 11:00 272648 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
- 2010-01-20 23:56 . 2010-02-10 11:01 272648 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
- 2010-01-20 23:56 . 2010-02-10 11:01 922384 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
+ 2010-01-20 23:56 . 2010-03-10 11:00 922384 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
+ 2010-01-20 23:56 . 2010-03-10 11:00 845584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
- 2010-01-20 23:56 . 2010-02-10 11:01 845584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
+ 2010-01-20 23:56 . 2010-03-10 11:00 217864 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
- 2010-01-20 23:56 . 2010-02-10 11:01 217864 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
+ 2010-02-24 11:00 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB976662-IE8\spuninst\updspapi.dll
+ 2010-02-24 11:00 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB976662-IE8\spuninst\spuninst.exe
+ 2010-02-24 11:00 . 2009-06-22 06:44 726528 c:\windows\ie8updates\KB976662-IE8\jscript.dll
+ 2010-02-24 11:00 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB979306$\spuninst\updspapi.dll
+ 2010-02-24 11:00 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB979306$\spuninst\spuninst.exe
+ 2010-02-24 11:00 . 2008-07-08 13:02 382840 c:\windows\$hf_mig$\KB976662-IE8\update\updspapi.dll
+ 2010-02-24 11:00 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB976662-IE8\update\update.exe
+ 2010-02-24 11:00 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB976662-IE8\spuninst.exe
+ 2010-02-24 10:20 . 2009-12-09 05:51 726528 c:\windows\$hf_mig$\KB976662-IE8\SP3QFE\jscript.dll
+ 2010-01-12 06:01 . 2010-01-12 06:01 1011712 c:\windows\system32\Adobe\Shockwave 11\iml32.dll
- 2009-10-29 05:01 . 2009-10-29 05:01 1011712 c:\windows\system32\Adobe\Shockwave 11\iml32.dll
+ 2010-01-12 05:54 . 2010-01-12 05:54 1975408 c:\windows\system32\Adobe\Shockwave 11\gt.exe
- 2009-10-29 05:05 . 2009-10-29 05:05 1798144 c:\windows\system32\Adobe\Shockwave 11\dirapi.dll
+ 2010-01-12 06:05 . 2010-01-12 06:05 1798144 c:\windows\system32\Adobe\Shockwave 11\dirapi.dll
+ 2010-02-04 08:59 . 2010-02-04 08:59 5031936 c:\windows\Installer\74f56c0.msp
- 2010-01-20 23:56 . 2010-02-10 11:01 1172240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
+ 2010-01-20 23:56 . 2010-03-10 11:00 1172240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
+ 2010-01-20 23:56 . 2010-03-10 11:00 1165584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
- 2010-01-20 23:56 . 2010-02-10 11:01 1165584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
+ 2010-02-10 11:01 . 2010-03-02 05:30 31648712 c:\windows\system32\MRT.exe
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ae2786e8-100f-4a07-9c0d-5bd8e3157782}]
kabunabo.dll [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 06:34 24576 —-a-w- c:\progra~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Compaq Organize.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Compaq Organize.lnk
backup=c:\windows\pss\Compaq Organize.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^IMStart.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\IMStart.lnk
backup=c:\windows\pss\IMStart.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2004-06-29 17:06 88363 —-a-w- c:\windows\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
2004-09-07 21:47 57344 —-a-w- c:\windows\ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ——w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dalenurb]
2010-01-20 23:12 483328 —-a-w- c:\docume~1\Owner\APPLIC~1\FLAG16~1\Morebashfive.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
2004-03-18 05:10 61952 —-a-w- c:\windows\system32\Hdaudpropshortcut.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
1998-05-07 23:04 52736 —-a-w- c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IcoSet]
1999-11-07 14:11 27136 —-a-w- c:\hp\bin\cloaker.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2003-02-12 02:02 61440 —-a-w- c:\hp\KBD\kbd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-05-16 22:01 13529088 —-a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-05-16 22:01 86016 —-a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-05-16 22:01 1630208 —-a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
2010-01-19 18:35 2937528 —-a-w- c:\program files\Pando Networks\Media Booster\PMB.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
2003-09-13 02:13 98304 —-a-w- c:\windows\system32\ps2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2004-04-14 20:43 233472 —-a-w- c:\windows\SMINST\Recguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
2003-12-18 06:31 118784 —-a-w- c:\windows\CREATOR\Remind_XP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-11-06 04:36 149280 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\taskmgr.exe"=
"c:\\Program Files\\softnyx\\GunboundWC\\GunBound.gme"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56993:TCP"= 56993:TCP:Pando Media Booster
"56993:UDP"= 56993:UDP:Pando Media Booster

S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
.
Contents of the 'Scheduled Tasks' folder

2010-03-29 c:\windows\Tasks\AC98B9B197AF2B69.job
- c:\docume~1\owner\applic~1\flag16~1\regsfirstinfo.exe [2010-01-20 23:12]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=Q304&bd;=presario&pf;=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q304&bd;=presario&pf;=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q304&bd;=presario&pf;=desktop
uInternet Settings,ProxyOverride = localhost
IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\avsqrjul.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2464976&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://newsarama.com/
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\FFTextLinks.dll
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\avsqrjul.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\avsqrjul.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\KavLinkFilter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-28 18:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(544)
c:\progra~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
.
Completion time: 2010-03-28 18:38:28
ComboFix-quarantined-files.txt 2010-03-29 01:38
ComboFix2.txt 2010-03-06 02:00
ComboFix3.txt 2010-02-21 19:41
ComboFix4.txt 2010-02-01 06:38
ComboFix5.txt 2010-03-29 01:31

Pre-Run: 109,857,492,992 bytes free
Post-Run: 110,317,289,472 bytes free

- - End Of File - - 30BB86B83092EAC2465EA0B72D8AD838
Hello esseff,please do the following.

I'd like for you to run this next online scan to check for remnants or anything that might be hidden.
The below scan can take up to an hour or longer, please be patient.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.



Please do a scan with Kaspersky Online Scanner
Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
  • Then, click: Save
  • Please post the Kaspersky Online Scanner Report in your reply.

Animated tutorial
http://i275.photobucket.com/albums/jj285/B…ng/KAS/KAS9.gif

(Note.. for Internet Explorer 7 users:
If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%
.)
Or use Firefox with IE-Tab plugin
https://addons.mozilla.org/en-US/firefox/addon/1419

In your next reply post:
  • Kaspersky log
  • A description of how your computer is running now
Here is the Kaspersky log: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Thursday, April 22, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, April 21, 2010 20:27:33 Records in database: 3962586 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ Scan statistics: Objects scanned: 92920 Threats found: 15 Infected objects found: 34 Suspicious objects found: 0 Scan duration: 02:23:46 File name / Threat / Threats count C:\Documents and Settings\Owner\Application Data\Flag16Book\ksxatwsb.exe Infected: Trojan.Win32.Swizzor.d 1 C:\Documents and Settings\Owner\Application Data\Flag16Book\Morebashfive.exe Infected: Trojan-Downloader.Win32.Obfuscated.wqs 1 C:\Documents and Settings\Owner\Application Data\Flag16Book\regsfirstinfo.exe Infected: Trojan.Win32.Swizzor.d 1 C:\hp\recovery\wizard\fscommand\AppRecoveryLink_ret.exe Infected: Trojan-Spy.Win32.Agent.bdrd 1 C:\hp\recovery\wizard\fscommand\CDLogic_ret.exe Infected: Trojan-Spy.Win32.Agent.bdrd 1 C:\hp\recovery\wizard\fscommand\CreatorLink_ret.exe Infected: Trojan-Spy.Win32.Agent.bdrd 1 C:\hp\recovery\wizard\fscommand\RestoreLink_ret.exe Infected: Trojan-Spy.Win32.Agent.bdrd 1 C:\hp\recovery\wizard\fscommand\RTCDLink_ret.exe Infected: Trojan-Spy.Win32.Agent.bdrd 1 C:\hp\recovery\wizard\fscommand\RunLink_ret.exe Infected: Trojan-Spy.Win32.Agent.bdrd 1 C:\hp\recovery\wizard\fscommand\SysRecoveryLink_ret.exe Infected: Trojan-Spy.Win32.Agent.bdrd 1 C:\hp\recovery\wizard\fscommand\WizardLink_ret.exe Infected: Trojan-Spy.Win32.Agent.bdrd 1 C:\Qoobox\Quarantine\C\Program Files\InternetSecurity2010\IS2010.exe.vir Infected: not-a-virus:FraudTool.Win32.InternetSecurity2010 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\birakuze.dll.vir Infected: Trojan.Win32.Monder.ddts 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\critical_warning.html.vir Infected: Trojan.JS.Hoax.b 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\fisojoho.dll.vir Infected: Trojan.Win32.Stuh.amet 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\gonihuha.dll.vir Infected: Packed.Win32.TDSS.aa 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\helper32.dll.vir Infected: Trojan-Ransom.Win32.Agent.jm 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\kabunabo.dll.vir Infected: Packed.Win32.TDSS.aa 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\mivivohe.dll.vir Infected: Packed.Win32.TDSS.aa 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\nipugahi.dll.vir Infected: Packed.Win32.TDSS.aa 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\ruvigesa.dll.vir Infected: Packed.Win32.TDSS.aa 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\sivuvaje.dll.vir Infected: Packed.Win32.TDSS.aa 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\smss32.exe.vir Infected: Trojan-Downloader.Win32.FraudLoad.gkc 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\vasezanu.dll.vir Infected: Packed.Win32.TDSS.aa 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\warning.html.vir Infected: Trojan.JS.Fraud.w 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\winhelper86.dll.vir Infected: Trojan-Ransom.Win32.Agent.il 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\winlogon32.exe.vir Infected: Trojan-Downloader.Win32.FraudLoad.gkc 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\winlogon86.exe.vir Infected: Trojan-Downloader.Win32.FraudLoad.wwxj 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\winupdate86.exe.vir Infected: Trojan-Downloader.Win32.FraudLoad.wwxj 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\wisebiga.dll.vir Infected: Trojan.Win32.Stuh.amet 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\yakegihu.dll.vir Infected: Packed.Win32.TDSS.aa 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\_logon_.exe.zip Infected: Trojan.Win32.Vilsel.pqd 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\_logon_.exe.zip Infected: Trojan-Downloader.Win32.Agent.dcgt 1 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Desktop.htt Infected: Trojan.JS.Fraud.w 1 Selected area has been scanned.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI