This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] WOW Account Family Hacked

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My Bro In-law and I play WOW and he was hacked of his account. The forum says to check your account for key loggers. I have not been hacked yet but want to make sure I don't have any Key-loggers or anything that looks weird…………. Thanks, Frontrunner

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:44:10 PM, on 4/25/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Belkin\Nostromo\nost_LM.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [meperebavu] Rundll32.exe "C:\WINDOWS\System32\nitokima.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [meperebavu] Rundll32.exe "C:\WINDOWS\System32\nitokima.dll",s (User 'NETWORK SERVICE')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1238350673968
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

–
End of file - 6868 bytes
Hello Frontrunner and :welcome:

My name is JonTom.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.
Hello Frontrunner

Thank you for the log.

want to make sure I don't have any Key-loggers or anything that looks weird

I can see evidence of Malware on your system. Before we do any cleaning, I would like to take a closer look at your system. Please work your way through the following steps. If you encounter any difficulties come back and let me know.


  • Download and run OTL by Oldtimer


    • Please download OTL by Oldtimer by clicking here and save the file (called OTL.exe) to your desktop.
    • Close all open windows on your computer then Double click on the OTL.exe icon to run the program.
    • When OTL opens, underneath "Output" (at the top) select "Minimal Output".
    • Check the boxes beside "LOP Check" and "Purity Check".
    • Under Custom Scan paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
    CREATERESTOREPOINT


    • Click the "Run Scan" button. Do not change any settings unless specifically told to do so. The scan will not take long.

    • When the scan completes, it will open two notepad windows: OTL.Txt and Extras.Txt.
    • Note: These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
    • Please Copy and Paste the contents of both files in your next reply. You may need two posts to fit them both in.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

      [external image: Posted Image]
      Click the image to enlarge it
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please provide the OTL logs and the GMER log in your next reply.
OTL Scan Results

OTL logfile created on: 4/27/2010 4:33:35 PM - Run 1
OTL by OldTimer - Version 3.2.3.0 Folder = C:\Documents and Settings\Corey Malone\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 58.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 3070 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 121.67 Gb Free Space | 40.82% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SOUTHERN-T9IVW0
Current User Name: Corey Malone
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Corey Malone\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe (Logitech Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Belkin\Nostromo\nost_LM.exe ()
PRC - C:\WINDOWS\system32\BRSS01A.EXE (brother Industries Ltd)
PRC - C:\WINDOWS\system32\BRSVC01A.EXE (brother Industries Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Corey Malone\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\nvwddi.dll (NVIDIA Corporation)
MOD - C:\Program Files\NVIDIA Corporation\nView\nView.dll ()
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Belkin\Nostromo\nost_FSH.dll (eTEK Labs)


========== Win32 Services (SafeList) ==========

SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (Brother XP spl Service) – C:\WINDOWS\system32\BRSVC01A.EXE (brother Industries Ltd)


========== Driver Services (SafeList) ==========

DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (PnkBstrK) – C:\WINDOWS\system32\drivers\PnkBstrK.sys ()
DRV - (aswMon2) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswTdi) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (UsbserFilt) – C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (nmwcdc) – C:\WINDOWS\system32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia)
DRV - (upperdev) – C:\WINDOWS\system32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (xusb21) – C:\WINDOWS\system32\drivers\xusb21.sys (Microsoft Corporation)
DRV - (CamDrL) Logitech QuickCam Pro 3000(CamDrl) – C:\WINDOWS\system32\drivers\Camdrl.sys (Logitech Inc.)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (samhid) – C:\WINDOWS\system32\drivers\Samhid.sys ()
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (bcgame) – C:\WINDOWS\system32\drivers\bcgame.sys (Belkin Corporation)
DRV - (PhilCam8116) Logitech QuickCam Pro 3000(PID_08B0) – C:\WINDOWS\system32\drivers\CamDrL21.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (BrPar) – C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;*.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "iPhone OS 3 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2436531&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-msgr"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-msgr"
FF - prefs.js..browser.search.selectedEngine: "iPhone OS 3 Customized Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:[removed]
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:3.3.20
FF - prefs.js..extensions.enabledItems: {74714d77-1695-4e73-a98e-25cb374f46b4}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.723
FF - prefs.js..extensions.enabledItems: {55ce2530-61df-4ddc-b287-feae64e70575}:0.7
FF - prefs.js..extensions.enabledItems: [removed]:3.5.1
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p="


FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009/11/24 20:17:49 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2010/01/30 11:28:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/24 07:49:49 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/24 09:07:08 | 000,000,000 | —D | M]

[2008/10/01 23:52:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Corey Malone\Application Data\Mozilla\Extensions
[2010/04/25 16:51:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Corey Malone\Application Data\Mozilla\Firefox\Profiles\pb1x8v89.default\extensions
[2010/01/17 12:30:26 | 000,000,000 | —D | M] (Flagfox) – C:\Documents and Settings\Corey Malone\Application Data\Mozilla\Firefox\Profiles\pb1x8v89.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2009/09/20 20:35:15 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Corey Malone\Application Data\Mozilla\Firefox\Profiles\pb1x8v89.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/17 12:30:25 | 000,000,000 | —D | M] (RefreshBlocker) – C:\Documents and Settings\Corey Malone\Application Data\Mozilla\Firefox\Profiles\pb1x8v89.default\extensions\{55ce2530-61df-4ddc-b287-feae64e70575}
[2010/04/24 07:49:55 | 000,000,000 | —D | M] (iPhone OS 3 Toolbar) – C:\Documents and Settings\Corey Malone\Application Data\Mozilla\Firefox\Profiles\pb1x8v89.default\extensions\{74714d77-1695-4e73-a98e-25cb374f46b4}
[2010/02/16 20:10:18 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Documents and Settings\Corey Malone\Application Data\Mozilla\Firefox\Profiles\pb1x8v89.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010/01/17 12:30:25 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Corey Malone\Application Data\Mozilla\Firefox\Profiles\pb1x8v89.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/02/09 12:41:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Corey Malone\Application Data\Mozilla\Firefox\Profiles\pb1x8v89.default\extensions\[removed]
[2009/08/28 15:38:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Corey Malone\Application Data\Mozilla\Firefox\Profiles\pb1x8v89.default\extensions\[removed]
[2009/03/22 21:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Corey Malone\Application Data\Mozilla\Firefox\Profiles\pb1x8v89.default\extensions\[removed]
[2010/04/21 12:07:24 | 000,000,925 | —- | M] () – C:\Documents and Settings\Corey Malone\Application Data\Mozilla\Firefox\Profiles\pb1x8v89.default\searchplugins\conduit.xml
[2010/04/25 16:51:41 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2002/08/29 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - Startup: C:\Documents and Settings\Corey Malone\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1238350673968 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Corey Malone\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Corey Malone\Application Data\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/10/01 01:02:26 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008/09/30 17:51:08 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54338225421942784)

========== Files/Folders - Created Within 30 Days ==========

[2010/04/27 16:30:23 | 000,563,712 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Corey Malone\Desktop\OTL.exe
[2010/04/25 21:56:53 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Corey Malone\Recent
[2010/04/25 21:48:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\Desktop\Unknown
[2010/04/25 21:47:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\Desktop\Softball
[2010/04/25 21:47:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\Desktop\Ipod
[2010/04/25 21:46:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\Desktop\Virus Tools
[2010/04/25 21:46:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\Desktop\BORDERLANDS
[2010/04/25 21:45:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\Desktop\WOW
[2010/04/25 21:42:38 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/04/25 21:42:09 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/04/25 21:39:50 | 000,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\Corey Malone\Desktop\SysRestorePoint.exe
[2010/04/25 21:26:08 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/04/24 09:07:33 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2010/04/24 09:07:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/04/24 09:07:28 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/04/24 09:07:08 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2010/04/24 09:07:08 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/04/24 09:07:08 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/04/24 09:07:08 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/04/24 09:07:08 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/04/24 09:06:55 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/04/24 09:06:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\Application Data\Sun
[2010/04/09 19:02:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\Desktop\Mustang Edit
[2010/04/09 19:00:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\My Documents\My PSP8 Files
[2010/04/09 19:00:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\Application Data\Jasc Software Inc
[2010/04/09 19:00:23 | 000,000,000 | —D | C] – C:\Program Files\Jasc Software Inc
[2010/04/09 18:59:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\Desktop\Paintshop Pro
[2010/04/09 18:29:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\Desktop\Mustang Bad
[2010/04/09 18:25:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\Desktop\Me Bike
[2010/04/09 18:25:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\Desktop\Mustang Orig
[2010/04/04 08:10:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\Desktop\Back rest
[2010/04/04 07:49:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Corey Malone\My Documents\Flickr
[2002/04/11 03:41:06 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/04/27 16:30:23 | 000,563,712 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Corey Malone\Desktop\OTL.exe
[2010/04/25 21:43:54 | 000,002,461 | —- | M] () – C:\Documents and Settings\Corey Malone\Desktop\HiJackThis.lnk
[2010/04/25 21:42:17 | 000,000,767 | —- | M] () – C:\Documents and Settings\Corey Malone\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/04/25 21:42:10 | 000,000,592 | —- | M] () – C:\Documents and Settings\Corey Malone\Desktop\ERUNT.lnk
[2010/04/25 21:39:50 | 000,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\Corey Malone\Desktop\SysRestorePoint.exe
[2010/04/25 16:39:35 | 000,248,910 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2010/04/25 16:39:34 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/04/25 16:38:57 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/25 16:38:52 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/04/25 13:21:21 | 005,242,880 | -H– | M] () – C:\Documents and Settings\Corey Malone\NTUSER.DAT
[2010/04/24 09:06:59 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/04/24 09:06:59 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/04/24 09:06:59 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/04/24 09:06:59 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/04/24 09:06:58 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2010/04/24 07:11:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/04/21 17:27:13 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/04/15 21:39:23 | 000,000,799 | —- | M] () – C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2010/04/11 20:15:18 | 000,000,068 | —- | M] () – C:\WINDOWS\brmx2001.ini
[2010/04/11 20:07:33 | 000,002,519 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Jasc Paint Shop Pro 8.lnk
[2010/04/09 18:55:15 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Corey Malone\ntuser.ini
[2010/04/09 18:51:07 | 000,034,304 | —- | M] () – C:\Documents and Settings\Corey Malone\Desktop\Accounts And Pass.xls
[2010/04/02 09:06:59 | 000,120,320 | —- | M] () – C:\Documents and Settings\Corey Malone\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/01 16:05:14 | 000,017,920 | —- | M] () – C:\Documents and Settings\Corey Malone\Application Data\GDIPFONTCACHEV1.DAT
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2099/01/01 12:00:00 | 000,011,168 | -H– | C] () – C:\WINDOWS\System32\giwawezo
[2010/04/25 21:42:17 | 000,000,767 | —- | C] () – C:\Documents and Settings\Corey Malone\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/04/25 21:42:10 | 000,000,592 | —- | C] () – C:\Documents and Settings\Corey Malone\Desktop\ERUNT.lnk
[2010/04/25 21:26:08 | 000,002,461 | —- | C] () – C:\Documents and Settings\Corey Malone\Desktop\HiJackThis.lnk
[2010/04/09 19:01:44 | 000,002,519 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Jasc Paint Shop Pro 8.lnk
[2010/04/02 09:41:41 | 000,034,304 | —- | C] () – C:\Documents and Settings\Corey Malone\Desktop\Accounts And Pass.xls
[2010/01/28 17:38:23 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2010/01/28 17:34:24 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\BROSNMP.DLL
[2010/01/28 17:34:24 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\BRVPDNTA.DLL
[2010/01/28 17:34:24 | 000,026,624 | —- | C] () – C:\WINDOWS\System32\BRGSRC32.DLL
[2010/01/28 17:34:23 | 000,011,568 | —- | C] () – C:\WINDOWS\HL-1440.INI
[2010/01/28 17:34:23 | 000,004,608 | —- | C] () – C:\WINDOWS\System32\BRGSRC16.DLL
[2010/01/28 17:18:00 | 000,000,068 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2010/01/28 17:18:00 | 000,000,040 | —- | C] () – C:\WINDOWS\opt_1440.ini
[2010/01/28 17:18:00 | 000,000,037 | —- | C] () – C:\WINDOWS\Brwmark.ini
[2010/01/28 17:18:00 | 000,000,000 | —- | C] () – C:\WINDOWS\Brohl144.ini
[2010/01/28 17:17:27 | 000,000,312 | —- | C] () – C:\WINDOWS\BRDIAG.INI
[2010/01/28 17:17:27 | 000,000,145 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2010/01/28 17:17:27 | 000,000,026 | —- | C] () – C:\WINDOWS\brpp2ka.ini
[2010/01/28 17:17:27 | 000,000,023 | —- | C] () – C:\WINDOWS\Brownie.ini
[2009/12/11 23:31:28 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\Ffpage.dll
[2009/12/11 23:31:28 | 000,005,036 | —- | C] () – C:\WINDOWS\System32\drivers\Samhid.sys
[2009/12/06 21:32:10 | 000,000,707 | —- | C] () – C:\WINDOWS\client.config.ini
[2009/06/21 09:09:51 | 000,137,544 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/03/29 13:24:43 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2009/02/28 19:48:01 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/10/16 16:07:34 | 000,000,241 | —- | C] () – C:\WINDOWS\QSync.INI
[2008/10/16 16:07:15 | 000,011,653 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/10/16 16:06:29 | 000,000,816 | —- | C] () – C:\WINDOWS\_delis32.ini
[2008/10/16 16:06:08 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\MimicICM.dll
[2008/10/07 10:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/10/01 21:19:13 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008/02/17 13:22:26 | 000,212,992 | —- | C] () – C:\WINDOWS\System32\ACPC.dll
[2007/10/28 01:38:50 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\ACPHELP.dll
[2005/05/03 13:38:42 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\P17.dll
[2003/10/02 12:48:18 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
[1999/01/27 14:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll

========== LOP Check ==========

[2010/01/28 18:18:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2009/11/13 23:50:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Funcom
[2009/11/24 20:16:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2009/10/18 07:37:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nokia
[2010/01/30 11:23:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OviInstallerCache
[2010/01/30 11:36:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/01/11 23:47:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/02/01 21:19:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/11/14 15:23:42 | 000,000,000 | -HSD | M] – C:\Documents and Settings\Corey Malone\Application Data\.#
[2009/12/06 10:52:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Corey Malone\Application Data\FOG Downloader
[2008/10/16 16:06:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Corey Malone\Application Data\FotoWire
[2009/03/21 08:30:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Corey Malone\Application Data\Leadertech
[2009/09/11 18:57:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Corey Malone\Application Data\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
[2010/01/30 11:40:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Corey Malone\Application Data\Nokia
[2010/01/30 11:40:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Corey Malone\Application Data\Nokia Ovi Suite
[2009/10/18 07:28:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Corey Malone\Application Data\PC Suite

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/03/29 14:23:18 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/03/29 14:23:18 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2004/08/04 01:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2004/08/04 01:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2002/08/29 07:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2009/03/29 14:23:18 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/03/29 14:23:18 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2002/08/29 07:00:00 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 00:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2004/08/04 00:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2004/08/04 02:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2004/08/04 02:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\eventlog.dll
[2002/08/29 07:00:00 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2002/08/29 07:00:00 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2009/02/06 13:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2004/08/04 02:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2004/08/04 02:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\netlogon.dll

< MD5 for: NVGTS.SYS >
[2008/08/18 20:54:00 | 000,145,952 | —- | M] (NVIDIA Corporation) MD5=37954CD1D0AFC11BECD149F7C3EC88C2 – C:\NVIDIA\nForceWin2k\15.23\IS\IDE\WinXP\sataraid\nvgts.sys
[2008/08/18 20:54:00 | 000,145,952 | —- | M] (NVIDIA Corporation) MD5=EA98BFE4931BD13D747D647C1859796E – C:\NVIDIA\nForceWin2k\15.23\IS\IDE\WinXP\sata_ide\nvgts.sys

< MD5 for: NVRD32.SYS >
[2008/08/18 20:54:00 | 000,133,152 | —- | M] (NVIDIA Corporation) MD5=BEF704AA9E17D176A46DDF77C6A52194 – C:\NVIDIA\nForceWin2k\15.23\IS\IDE\WinXP\sataraid\nvrd32.sys

< MD5 for: SCECLI.DLL >
[2004/08/04 02:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2004/08/04 02:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\scecli.dll
[2002/08/29 07:00:00 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2008/09/30 17:52:42 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008/09/30 17:52:42 | 000,626,688 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008/09/30 17:52:42 | 000,430,080 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >
< End of report >
OTL Extras

OTL Extras logfile created on: 4/27/2010 4:33:35 PM - Run 1
OTL by OldTimer - Version 3.2.3.0 Folder = C:\Documents and Settings\Corey Malone\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 58.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 3070 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 121.67 Gb Free Space | 40.82% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SOUTHERN-T9IVW0
Current User Name: Corey Malone
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"8370:TCP" = 8370:TCP:*:Enabled:League of Legends Launcher
"8370:UDP" = 8370:UDP:*:Enabled:League of Legends Launcher
"8372:TCP" = 8372:TCP:*:Enabled:League of Legends Launcher
"8372:UDP" = 8372:UDP:*:Enabled:League of Legends Launcher
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Curse\CurseClient.exe" = C:\Program Files\Curse\CurseClient.exe:*:Enabled:CurseClient – File not found
"C:\Program Files\Atari\ArmA Demo\ArmADemo.exe" = C:\Program Files\Atari\ArmA Demo\ArmADemo.exe:*:Enabled:ArmA Demo – (Bohemia Interactive)
"C:\Riot Games\League of Legends\air\LolClient.exe" = C:\Riot Games\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby – ()
"C:\Riot Games\League of Legends\game\League of Legends.exe" = C:\Riot Games\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client – ()
"C:\Program Files\Steam\steamapps\common\america's army 3\Binaries\AA3Game.exe" = C:\Program Files\Steam\steamapps\common\america's army 3\Binaries\AA3Game.exe:*:Enabled:America's Army 3 – ()
"C:\Program Files\Steam\steamapps\common\left 4 dead 2\left4dead2.exe" = C:\Program Files\Steam\steamapps\common\left 4 dead 2\left4dead2.exe:*:Enabled:Left 4 Dead 2 – ()
"C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe" = C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process – (Nokia Corporation)
"C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" = C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe:*:Enabled:Nokia Ovi Suite 2 – (Nokia)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Documents and Settings\Corey Malone\Local Settings\Apps\2.0\19XN19EG.KPC\7TAPVRE7.J96\curs..tion_eee711038731a406_0004.0000_152ef8e82e8f5a48\CurseClient.exe" = C:\Documents and Settings\Corey Malone\Local Settings\Apps\2.0\19XN19EG.KPC\7TAPVRE7.J96\curs..tion_eee711038731a406_0004.0000_152ef8e82e8f5a48\CurseClient.exe:*:Enabled:Curse Client 4.0 – (Curse)
"C:\Program Files\StarCraft II Beta\StarCraft II.exe" = C:\Program Files\StarCraft II Beta\StarCraft II.exe:*:Enabled:Blizzard Launcher – (Blizzard Entertainment)
"C:\Program Files\StarCraft II Beta\Versions\Base14593\SC2.exe" = C:\Program Files\StarCraft II Beta\Versions\Base14593\SC2.exe:*:Enabled:StarCraft II – (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\BackgroundDownloader.exe" = C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0C28E0CC-223E-4F45-B97F-3AEBDE2CBF30}" = Delta Force Black Hawk Down Team Sabre
"{0F3A1C5A-DA6A-4536-A058-CBB857CAC20C}" = Nostromo Array Programming Software
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{254AA551-D855-41A7-9E19-6DBB50D1EB03}" = Delta Force 2
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{2A539C9F-1F8F-4746-BCA6-217B06440EF0}" = Delta Force Land Warrior
"{307C42FF-4C61-4F7A-B872-6756B236285A}" = Delta Force Task Force Dagger
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}" = Nokia Software Updater
"{4CE6B3C4-D8E2-4A5D-BEF5-5B69AF843B0C}" = PC Connectivity Solution
"{52B65911-1559-4ED5-9461-46957FDD48CD}" = Borderlands
"{564B16F4-6B5B-47B0-9AB6-FF2E943947F7}" = Nokia Ovi Suite Software Updater
"{5A24DD7E-7B01-41AC-ADA8-F1776177A3BA}" = Logitech ImageStudio
"{66F0AC35-4805-44BC-A3D4-347D4196F9B3}" = Microsoft Xbox 360 Accessories 1.1
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{74D0A269-49C8-4EFA-AB53-BD4A80251906}" = Aion
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{868EC22E-7E82-4760-9265-3F2E705BF24B}" = League of Legends
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D100E0C-1A5A-43AD-93EF-76F94AE61C30}" = OviMPlatform
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}" = Nokia PC Suite
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{948BE614-F37B-4A73-AD43-0245F23C110D}" = Logitech GamePanel Software 2.00
"{961C4925-5B53-4127-969D-1CACF2426C05}" = Delta Force: Xtreme
"{984F10FD-11FD-4BED-8163-92DB81E6A825}" = Logitech IM Video Companion
"{99A4F599-7227-40DB-9CFA-147EB029F504}" = Delta Force
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2F166A0-F031-4E27-A057-C69733219434}_is1" = Runes of Magic
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A59BB15D-51B7-F12B-4548-8C0368243441}" = EA Download Manager UI
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.1
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}" = Nokia Ovi Suite
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C22E50B4-B9D0-4a07-B1F3-12362514FEA7}" = The Sims™ 2 Double Deluxe
"{C50EF365-2898-489A-B6C7-30DAA466E9A2}" = Nokia Connectivity Cable Driver
"{C9FB868B-2086-4EE2-BD4F-BFBA36B131F4}" = NCsoft Launcher
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D56B0E27-4A3E-46C9-B5C1-D93D580C099C}" = NVIDIA PhysX v8.10.29
"{E760F3F6-426D-48EC-8CDB-D7559C575A7A}" = Delta Force Black Hawk Down
"{F1C3541D-5B93-4131-B440-692FBA3DD250}" = Ovi Desktop Sync Engine
"{F439D7AF-03F3-4F8E-AEC4-571BFE977C61}" = iTunes
"05B59228C7E1C21DFBE89260F879BD95880548D8" = Windows Driver Package - Nokia Modem (10/05/2009 4.2)
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"8CDCFB95BB84DD9C0F88F22266A0CA86035E55BA" = Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.4)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Age of Conan_is1" = Age of Conan - Hyborian Adventures
"ArmA Demo" = ArmA Demo Uninstall
"avast!" = avast! Antivirus
"Brother 1440" = Brother 1440
"BROWNIE" = Brownie
"com.ea.Vault.919CACB699904AC5D41B606703500DD39747C02D.1" = EA Download Manager UI
"Download Manager" = Download Manager 2.3.9
"EA Download Manager" = EA Download Manager
"ERUNT_is1" = ERUNT 1.1j
"Free iPod Video Converter_is1" = Free iPod Video Converter 1.34
"Guild Wars" = Guild Wars
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Logitech Print Service" = Logitech Print Service
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.9)" = Mozilla Firefox (3.5.9)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Nokia Ovi Suite" = Nokia Ovi Suite
"Nokia PC Suite" = Nokia PC Suite
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"NYKO AirFlo Controller v0.1" = NYKO AirFlo Controller v0.1
"OpenAL" = OpenAL
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 6.0" = RealPlayer 7 Basic
"StarCraft II Beta" = StarCraft II Beta
"Steam App 13140" = America's Army 3
"Steam App 550" = Left 4 Dead 2
"SystemRequirementsLab" = System Requirements Lab
"Warhammer Online - Age of Reckoning" = Warhammer Online - Age of Reckoning
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"World of Warcraft" = World of Warcraft
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"NCsoft-GuildWars" = Guild Wars

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 11/8/2009 10:35:18 AM | Computer Name = SOUTHERN-T9IVW0 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://w186.slashkey.com/facebook/farm/aja…ig_locale=en_US
failed, 0000A413.

[ Application Events ]
Error - 2/14/2010 3:13:19 PM | Computer Name = SOUTHERN-T9IVW0 | Source = Application Error | ID = 1000
Description = Faulting application lcdmedia.exe, version 2.0.171.0, faulting module
lcdmedia.exe, version 2.0.171.0, fault address 0x000151c0.

Error - 2/16/2010 6:57:23 PM | Computer Name = SOUTHERN-T9IVW0 | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 3/5/2010 8:26:51 PM | Computer Name = SOUTHERN-T9IVW0 | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 4/23/2010 4:38:37 PM | Computer Name = SOUTHERN-T9IVW0 | Source = Application Error | ID = 1000
Description = Faulting application lcdmedia.exe, version 2.0.171.0, faulting module
lcdmedia.exe, version 2.0.171.0, fault address 0x000151c0.

Error - 4/27/2010 5:33:07 PM | Computer Name = SOUTHERN-T9IVW0 | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.3.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 9/7/2009 11:29:48 AM | Computer Name = SOUTHERN-T9IVW0 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 9/7/2009 11:34:03 AM | Computer Name = SOUTHERN-T9IVW0 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 9/7/2009 11:44:01 AM | Computer Name = SOUTHERN-T9IVW0 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 9/7/2009 11:48:56 AM | Computer Name = SOUTHERN-T9IVW0 | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 9/7/2009 11:50:27 AM | Computer Name = SOUTHERN-T9IVW0 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 9/7/2009 11:57:17 AM | Computer Name = SOUTHERN-T9IVW0 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 9/7/2009 12:21:37 PM | Computer Name = SOUTHERN-T9IVW0 | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 9/7/2009 12:29:49 PM | Computer Name = SOUTHERN-T9IVW0 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 9/7/2009 12:50:52 PM | Computer Name = SOUTHERN-T9IVW0 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft .NET Framework, Version 1.1
Service Pack 1 (KB928366).

Error - 9/7/2009 1:20:01 PM | Computer Name = SOUTHERN-T9IVW0 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747


< End of report >
Every time I try to run ……………(Please scan your system with GMER) (gmer.exe)………………. I follow your instructions and as soon as its done with the scan I hit save it locks my computer up to the point I have to do a soft boot. Im not sure if you want to know or not but before coming here I did run Avast (Runs In Background as well), Mbam, Search and destroy and super antivirus. I run these quit often as this is my Gaming unit. The scans found minimal adware and no viruses. Thanks for the help, Corey
Hello Frontrunner

Thank you for the logs.

  • DeFogger


    • Please download DeFogger to your desktop.
    • Double click DeFogger to run the tool.
    • The application window will appear
    • Click the Disable button to disable your CD Emulation drivers
    • Click Yes to continue
    • A 'Finished!' message will appear
    • Click OK
    • DeFogger will now ask to reboot the machine - click OK
    IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

    Do not re-enable these drivers until otherwise instructed.


  • GMER


    • If you are having trouble getting GMER to complete a scan, please run it again, but this time uncheck everything EXCEPT "Sections" and "C:\".
    • If GMER does not produce a log please try running it from Safe Mode.
    • If GMER in safe mode does not work, please try RootRepeal:

  • RootRepeal


    • Please download RootRepeal to your desktop
    • Physically disconnect your machine from the internet as your system will be unprotected.
    • Unzip it to it's own folder, close all other programs especially your security programs (anti-spyware, anti-virus, and firewall) and run RootRepeal.exe
    • Click the Report tab at the bottom and then the Scan button.
    • A box will pop up, check the boxes beside Drivers, Files, Processes SSDT and click OK.
    • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
    • The scan will take a little while to run, so let it go unhindered.
    • Once it is done, click the "Save Report" button, call it RepealScan and save the log to your desktop.
    • Reconnect to the internet.

    Please provide the GMER/Rootrepeal log in your next reply. If you are still having trouble, come back and let me know.
I ran Defogger the way you said and I did get GMER to run and save a file. I figured out what I was doing wrong and was able to run it with the settings from your first post. Here is the log and thanks.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-28 18:51:30
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\COREYM~1\LOCALS~1\Temp\afacrpod.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB47C16B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB47C1574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB47C1A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB47C114C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB47C164E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB47C108C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB47C10F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB47C176E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB47C172E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB47C18AE]

—- Kernel code sections - GMER 1.0.15 —-

.text C:\WINDOWS\System32\DRIVERS\nv4_mini.sys section is writeable [0xB6D57360, 0x3E57A5, 0xE8000020]

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

—- EOF - GMER 1.0.15 —-
Hello Frontrunner

Thank you for the logs.

Before we go any further I would like to take a closer look at some files and folders on your system. Please work your way through the following steps:

  • Please make all files and folders VISIBLE:


    • Click "Start" Go to My Computer-> Tools-> Folder Options-> View tab:
    • Choose to "Show hidden files and folders."
    • Uncheck the "Hide protected operating system files" and the "Hide extensions for know file types" boxes.
    • Close the window with "OK".

  • Please scan the following files


    • Please visit Virus Total by clicking here.
    • Click the Browse button and search for the following file: C:\Documents and Settings\Corey Malone\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    • Click Open.
    • Then click Send File.
    • Please be patient while the file is scanned.
    • If Virus Total tells you that the file has already been scanned, click "reanalyse now".

    • Once the scan results appear, copy and paste them into Notepad and repeat the procedure for the following file(s):

    C:\WINDOWS\_delis32.ini

    C:\WINDOWS\System32\ACPHELP.dll


    • Please provide the results from the scans in your next reply.

  • Please download SystemLook by JPShortstuff


    • Please download SystemLook by JPShortstuff by clicking here or here and save the file (called SystemLook.exe) to your desktop.
    • Double click SystemLook.exe to run the program.
    • Copy the content of the following codebox into the main textfield:

    :dir 
    C:\Documents and Settings\Corey Malone\Application Data\.#
    C:\Documents and Settings\Corey Malone\Application Data\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1

    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    • Note: The log can also be found on your Desktop entitled SystemLook.txt

    Please provide the VT scan logs and the SystemLook scan data in your next reply.

    Please note - you may need more than one post to fit all of the required information in.
Virus Total Scan Results File DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3 received on 2010.04.29 17:40:41 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/41 (0%) Loading server information… Your file is queued in position: 1. Estimated start time is between 42 and 60 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Compact Print results Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.5.0.50 2010.04.29 - AhnLab-V3 2010.04.29.05 2010.04.29 - AntiVir 8.2.1.224 2010.04.29 - Antiy-AVL 2.0.3.7 2010.04.29 - Authentium 5.2.0.5 2010.04.29 - Avast 4.8.1351.0 2010.04.29 - Avast5 5.0.332.0 2010.04.29 - AVG 9.0.0.787 2010.04.29 - BitDefender 7.2 2010.04.29 - CAT-QuickHeal 10.00 2010.04.29 - ClamAV 0.96.0.3-git 2010.04.29 - Comodo 4711 2010.04.29 - DrWeb 5.0.2.03300 2010.04.29 - eSafe 7.0.17.0 2010.04.29 - eTrust-Vet 35.2.7457 2010.04.29 - F-Prot 4.5.1.85 2010.04.29 - F-Secure 9.0.15370.0 2010.04.29 - Fortinet 4.0.14.0 2010.04.27 - GData 21 2010.04.29 - Ikarus T3.1.1.80.0 2010.04.29 - Jiangmin 13.0.900 2010.04.29 - Kaspersky 7.0.0.125 2010.04.29 - McAfee 5.400.0.1158 2010.04.29 - McAfee-GW-Edition 6.8.5 2010.04.29 - Microsoft 1.5703 2010.04.29 - NOD32 5072 2010.04.29 - Norman 6.04.12 2010.04.29 - nProtect 2010-04-29.01 2010.04.29 - Panda 10.0.2.7 2010.04.29 - PCTools 7.0.3.5 2010.04.29 - Prevx 3.0 2010.04.29 - Rising 22.45.03.03 2010.04.29 - Sophos 4.53.0 2010.04.29 - Sunbelt 6235 2010.04.28 - Symantec 20091.2.0.41 2010.04.29 - TheHacker 6.5.2.0.273 2010.04.29 - TrendMicro 9.120.0.1004 2010.04.29 - TrendMicro-HouseCall 9.120.0.1004 2010.04.29 - VBA32 3.12.12.4 2010.04.29 - ViRobot 2010.4.27.2295 2010.04.28 - VirusBuster 5.0.27.0 2010.04.29 - Additional information File size: 120320 bytes MD5…: 315b4e6e69d105fad2660a30f3698d43 SHA1..: 28628abcf45ca38777934f7e31e59db68920be5a SHA256: 7d7aa37e0a416476a6efbe121ba11b8b7f791f1be08586ee44d160578520d222 ssdeep: 1536:cGFSl2p+ED/wZEK6hHO3cipy/9klayf4bC5FACA1IqAwryCIwP+:n17aw PEiD..: - PEInfo: - RDS…: NSRL Reference Data Set - pdfid.: - trid..: Generic OLE2 / Multistream Compound File (100.0%) sigcheck: publisher….: n/a copyright….: n/a product……: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments…..: n/a signers……: - signing date.: - verified…..: Unsigned File _delis32.ini received on 2010.04.29 17:44:14 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/41 (0%) Loading server information… Your file is queued in position: 1. Estimated start time is between 42 and 60 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Compact Print results Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.5.0.50 2010.04.29 - AhnLab-V3 2010.04.29.05 2010.04.29 - AntiVir 8.2.1.224 2010.04.29 - Antiy-AVL 2.0.3.7 2010.04.29 - Authentium 5.2.0.5 2010.04.29 - Avast 4.8.1351.0 2010.04.29 - Avast5 5.0.332.0 2010.04.29 - AVG 9.0.0.787 2010.04.29 - BitDefender 7.2 2010.04.29 - CAT-QuickHeal 10.00 2010.04.29 - ClamAV 0.96.0.3-git 2010.04.29 - Comodo 4711 2010.04.29 - DrWeb 5.0.2.03300 2010.04.29 - eSafe 7.0.17.0 2010.04.29 - eTrust-Vet 35.2.7457 2010.04.29 - F-Prot 4.5.1.85 2010.04.29 - F-Secure 9.0.15370.0 2010.04.29 - Fortinet 4.0.14.0 2010.04.27 - GData 21 2010.04.29 - Ikarus T3.1.1.80.0 2010.04.29 - Jiangmin 13.0.900 2010.04.29 - Kaspersky 7.0.0.125 2010.04.29 - McAfee 5.400.0.1158 2010.04.29 - McAfee-GW-Edition 6.8.5 2010.04.29 - Microsoft 1.5703 2010.04.29 - NOD32 5072 2010.04.29 - Norman 6.04.12 2010.04.29 - nProtect 2010-04-29.01 2010.04.29 - Panda 10.0.2.7 2010.04.29 - PCTools 7.0.3.5 2010.04.29 - Prevx 3.0 2010.04.29 - Rising 22.45.03.03 2010.04.29 - Sophos 4.53.0 2010.04.29 - Sunbelt 6235 2010.04.28 - Symantec 20091.2.0.41 2010.04.29 - TheHacker 6.5.2.0.273 2010.04.29 - TrendMicro 9.120.0.1004 2010.04.29 - TrendMicro-HouseCall 9.120.0.1004 2010.04.29 - VBA32 3.12.12.4 2010.04.29 - ViRobot 2010.4.27.2295 2010.04.28 - VirusBuster 5.0.27.0 2010.04.29 - Additional information File size: 816 bytes MD5…: c8a321d3a19ca12e12c465d26b2ee1cb SHA1..: bc19359219a87aa5f26027478149b9b9cc1a0ada SHA256: 7d0390bbdea21cd729cd0b4437e06e19c6c4d4abe2f549adb7deb86e72c16588 ssdeep: 12:DnQ2kA2k5dY2kq0w2ksKhQ2k12kOdY2kD0w2kXK5kQ2kMR2kMqdY2kMP0w2kM DKM:/i0izlW157zWM+jgjmjMzjDx PEiD..: - PEInfo: - RDS…: NSRL Reference Data Set - pdfid.: - trid..: Generic INI configuration (100.0%) sigcheck: publisher….: n/a copyright….: n/a product……: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments…..: n/a signers……: - signing date.: - verified…..: Unsigned File ACPHELP.dll received on 2010.04.29 17:47:19 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 1/41 (2.44%) Loading server information… Your file is queued in position: 2. Estimated start time is between 49 and 70 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Compact Print results Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.5.0.50 2010.04.29 - AhnLab-V3 2010.04.29.05 2010.04.29 - AntiVir 8.2.1.224 2010.04.29 - Antiy-AVL 2.0.3.7 2010.04.29 - Authentium 5.2.0.5 2010.04.29 - Avast 4.8.1351.0 2010.04.29 - Avast5 5.0.332.0 2010.04.29 - AVG 9.0.0.787 2010.04.29 - BitDefender 7.2 2010.04.29 - CAT-QuickHeal 10.00 2010.04.29 - ClamAV 0.96.0.3-git 2010.04.29 - Comodo 4711 2010.04.29 - DrWeb 5.0.2.03300 2010.04.29 - eSafe 7.0.17.0 2010.04.29 - eTrust-Vet 35.2.7457 2010.04.29 - F-Prot 4.5.1.85 2010.04.29 - F-Secure 9.0.15370.0 2010.04.29 - Fortinet 4.0.14.0 2010.04.27 - GData 21 2010.04.29 - Ikarus T3.1.1.80.0 2010.04.29 - Jiangmin 13.0.900 2010.04.29 - Kaspersky 7.0.0.125 2010.04.29 - McAfee 5.400.0.1158 2010.04.29 - McAfee-GW-Edition 6.8.5 2010.04.29 Heuristic.BehavesLike.Win32.Trojan.L Microsoft 1.5703 2010.04.29 - NOD32 5072 2010.04.29 - Norman 6.04.12 2010.04.29 - nProtect 2010-04-29.01 2010.04.29 - Panda 10.0.2.7 2010.04.29 - PCTools 7.0.3.5 2010.04.29 - Prevx 3.0 2010.04.29 - Rising 22.45.03.03 2010.04.29 - Sophos 4.53.0 2010.04.29 - Sunbelt 6235 2010.04.28 - Symantec 20091.2.0.41 2010.04.29 - TheHacker 6.5.2.0.273 2010.04.29 - TrendMicro 9.120.0.1004 2010.04.29 - TrendMicro-HouseCall 9.120.0.1004 2010.04.29 - VBA32 3.12.12.4 2010.04.29 - ViRobot 2010.4.27.2295 2010.04.28 - VirusBuster 5.0.27.0 2010.04.29 - Additional information File size: 69632 bytes MD5…: aa94f942369550dbf6cf46045b904be3 SHA1..: 19ce6ed06f87224a05c698113e3f3fe67a809dba SHA256: aa440556c33e8392ac23b7e5e47a3ddbc79c501add6a5d653e382fad389be713 ssdeep: 1536:Mf5/DD5RyCr1QxESNbTnDvoUx5oxD1i5m:s/P572ESxx5ovi5m PEiD..: - PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x400c timedatestamp…..: 0x47242e7b (Sun Oct 28 06:38:51 2007) machinetype…….: 0x14c (I386) ( 4 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x8c5a 0x9000 6.58 2cbf7c898226e7a8cb7c19642c6db5dd .rdata 0xa000 0x18c1 0x2000 4.45 b1577a835dc1506c32bafac4c2b9901e .data 0xc000 0x3344 0x3000 0.93 e139b516b4f2aeba0d904a7b7d32ebef .reloc 0x10000 0x1582 0x2000 3.04 cde779f4f3e0dbcb7edf45f1477a9c2f ( 2 imports ) > KERNEL32.dll: FlushInstructionCache, GetCurrentProcess, VirtualProtect, GetProcAddress, GetModuleHandleA, CloseHandle, Process32Next, Process32First, CreateToolhelp32Snapshot, HeapAlloc, GetTimeZoneInformation, GetSystemTime, GetLocalTime, RtlUnwind, RaiseException, GetCommandLineA, GetVersion, HeapFree, ExitProcess, TerminateProcess, HeapReAlloc, HeapSize, GetModuleFileNameA, GetEnvironmentVariableA, GetVersionExA, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, IsBadWritePtr, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, WideCharToMultiByte, GetCurrentThreadId, TlsSetValue, TlsAlloc, TlsFree, SetLastError, TlsGetValue, GetLastError, SetUnhandledExceptionFilter, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, FreeEnvironmentStringsW, GetEnvironmentStrings, GetEnvironmentStringsW, WriteFile, IsBadReadPtr, IsBadCodePtr, GetCPInfo, GetACP, GetOEMCP, LoadLibraryA, InterlockedDecrement, InterlockedIncrement, MultiByteToWideChar, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, CompareStringA, CompareStringW, SetEnvironmentVariableA > USER32.dll: CharUpperBuffA ( 65 exports ) __0CACPHELP@@QAE@XZ, __4CACPHELP@@QAEAAV0@ABV0@@Z, _GHT10@@YAXXZ, _GHT11@@YAXXZ, _GHT12@@YAXXZ, _GHT13@@YAXXZ, _GHT14@@YAXXZ, _GHT15@@YAXXZ, _GHT16@@YAXXZ, _GHT17@@YAXXZ, _GHT18@@YAXXZ, _GHT19@@YAXXZ, _GHT20@@YAXXZ, _GHT21@@YAXXZ, _GHT22@@YAXXZ, _GHT23@@YAXXZ, _GHT24@@YAXXZ, _GHT25@@YAXXZ, _GHT26@@YAXXZ, _GHT27@@YAXXZ, _GHT28@@YAXXZ, _GHT29@@YAXXZ, _GHT30@@YAXXZ, _GHT31@@YAXXZ, _GHT32@@YAXXZ, _GHT33@@YAXXZ, _GHT34@@YAXXZ, _GHT35@@YAXXZ, _GHT36@@YAXXZ, _GHT37@@YAXXZ, _GHT38@@YAXXZ, _GHT39@@YAXXZ, _GHT40@@YAXXZ, _GHT41@@YAXXZ, _GHT42@@YAXXZ, _GHT43@@YAXXZ, _GHT44@@YAXXZ, _GHT45@@YAXXZ, _GHT46@@YAXXZ, _GHT47@@YAXXZ, _GHT48@@YAXXZ, _GHT49@@YAXXZ, _GHT50@@YAXXZ, _GHT51@@YAXXZ, _GHT52@@YAXXZ, _GHT53@@YAXXZ, _GHT54@@YAXXZ, _GHT55@@YAXXZ, _GHT56@@YAXXZ, _GHT57@@YAXXZ, _GHT58@@YAXXZ, _GHT59@@YAXXZ, _GHT60@@YAXXZ, _GHT61@@YGHPAX0PBXKPAK@Z, _GHT62@@YGHPAXPBX0KPAK@Z, _GHT63@@YGPAXKHK@Z, _GHT64@@YAXXZ, _GHT65@@YAHK@Z, _GHT66@@YA_NK@Z, _GHT67@@YA_NPAD@Z, _GHT68@@YA_NPAD@Z, _GHT69@@YA_NXZ, _GHT70@@YAKK@Z, _GHT71@@YAXKPAD@Z, _GHT72@@YAXPADH@Z RDS…: NSRL Reference Data Set - pdfid.: - trid..: Win32 Executable MS Visual C++ (generic) (65.2%) Win32 Executable Generic (14.7%) Win32 Dynamic Link Library (generic) (13.1%) Generic Win/DOS Executable (3.4%) DOS Executable Generic (3.4%) sigcheck: publisher….: n/a copyright….: n/a product……: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments…..: n/a signers……: - signing date.: - verified…..: Unsigned
System Look Report…………………… Thanks SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 12:52 on 29/04/2010 by Corey Malone (Administrator - Elevation successful) ========== dir ========== C:\Documents and Settings\Corey Malone\Application Data\.# - Parameters: "(none)" —Files— None found. —Folders— None found. C:\Documents and Settings\Corey Malone\Application Data\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1 - Parameters: "(none)" —Files— None found. —Folders— Local Store d—– [23:57 11/09/2009] -=End Of File=-
Hello Frontrunner

Thank you for the scan results.

One of the files you scanned came back as infected, whilst the other two failed sigcheck. We will take care of these in the steps below:

  • Please open OTL


    • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

      :OTL
      PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
      O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
      O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
      O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
      
      :Files
      C:\WINDOWS\System32\giwawezo
      C:\Documents and Settings\Corey Malone\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
      C:\WINDOWS\_delis32.ini
      C:\WINDOWS\System32\ACPHELP.dll
      
      :Commands
      [purity]
      [emptytemp]
      [start explorer]
      [Reboot]
    • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
    • Allow the program to run unhindered.
    • Your machine will re-start itself. This is normal.
    • A log will be created after your machine reboots. Please post the contents of the log in your next reply.

  • Please perform the following scan:


    • Please download MalwareBytes AntiMalware by clicking here and save the file (called mbam-setup.exe) to your desktop.

    • Double click on the mbam-setup.exe icon to install the program.
    • Follow the prompts during installation and have the Installation Wizzard create a desktop icon.
    • Once installed, double click on the MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform full scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

  • Please update your Java


    • You currently have Java™ 6 Update 18 installed. Update 20 is the latest version.
    • To update your Java, Click on "Start" then on "Control Panel" and then on the Java icon (looks like a coffee cup).
    • In the window that opens, click on the "Update" tab, and then on "Update Now".
    • Your Java should begin to update. Please follow any prompts that you receive.

  • Please perform the following scan:


    • This is a very deep scan that can take many hours. In some instances you may need to let it run overnight. Please be patient.


    • It is recommended that you disable your onboard antivirus program and antispyware programs while performing scans to eliminate software conflicts and to speed up scan time.
    • DO NOT surf the net while your resident protection is disabled!
    • Once the scan is finished remember to re-enable your resident antivirus protection along with whatever antispyware applications you use.


    • Please perform a Kaspersky Online Scan of your computer by clicking here or here.


    • Click on the Accept button and install any components it needs.
    • The program will install and then begin downloading the latest definition files.
    • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
    • This will start the program and scan your system.
    • The scan will take a while, so be patient and let it run (at times it may appear to stall).
    • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.

    • Once the scan is complete, click on View scan report. To obtain the report:
    • Click on: Save Report As
    • Next, in the Save as prompt, Save in area, select: Desktop
    • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:Text file [*.txt]
    • Then, click: Save
    • Please post the Kaspersky Online Scanner Report in your reply.
    • If you need help performing the above steps, an animated tutorial can be found here.

    Please provide the OTL log, the MBAM log and the Kaspersky Online Scan log in your next reply.

    Also, please let me know how your machine is behaving now. Are you still experiencing problems?
Here they are JonTom and my system is running fine. I actually know enough to be dangerous….lol….I keep it pretty clean for gaming and try not to surf the net much on this one. I have 2 others to do that with. I was really worried I could have a key logger I couldn't find. I'm learning alot with this too so thanks so much for your help on this.

OTL Log

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found.
File Animation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab not found.
Starting removal of ActiveX control DirectAnimation Java Classes
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\DirectAnimation Java Classes\ not found.
File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found.
Starting removal of ActiveX control Microsoft XML Parser for Java
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
========== FILES ==========
C:\WINDOWS\System32\giwawezo moved successfully.
C:\Documents and Settings\Corey Malone\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
C:\WINDOWS\_delis32.ini moved successfully.
C:\WINDOWS\System32\ACPHELP.dll moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Corey Malone
->Temp folder emptied: 537470461 bytes
->Temporary Internet Files folder emptied: 302256356 bytes
->Java cache emptied: 930319 bytes
->FireFox cache emptied: 44490384 bytes
->Flash cache emptied: 106078 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41620 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 60805 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 800143 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1119318 bytes
%systemroot%\System32 .tmp files removed: 2832913 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 243270810 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33728 bytes
RecycleBin emptied: 1066319302 bytes

Total Files Cleaned = 2,098.00 mb


OTL by OldTimer - Version 3.2.3.0 log created on 04292010_190116

Files\Folders moved on Reboot…
C:\WINDOWS\temp\Perflib_Perfdata_69c.dat moved successfully.

Registry entries deleted on Reboot…
_______________________________________________________

Malware Log

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13

4/29/2010 7:58:41 PM
mbam-log-2010-04-29 (19-58-41).txt

Scan type: Full scan (C:\|)
Objects scanned: 229657
Time elapsed: 49 minute(s), 18 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
____________________________________________

KASPERSKY Log
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, April 29, 2010
Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, April 29, 2010 21:23:06
Records in database: 4004514
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Objects scanned: 117327
Threats found: 0
Infected objects found: 0
Suspicious objects found: 0
Scan duration: 02:52:19

No threats found. Scanned area is clean.

Selected area has been scanned.
Hello Frontrunner

Your logs appear to be clean. Good job :thumbup:

I was really worried I could have a key logger I couldn't find

You did have evidence of an infection on your system (not a keylogger) but we took care of it.

Please work your way through the following steps:

  • You can now re-conceal all of the files that ought to be hidden on your system.


    • Click "Start" Go to My Computer-> Tools-> Folder Options-> View tab:
    • Under the Hidden files and folders heading:
    • Select "Do not show hidden files and folders".
    • Place a checkmark next to "Hide protected operating system files (recommended)" option.
    • Also, make sure there is a checkmark beside "Hide file extensions for known file types".
    • Click "OK/Apply"

  • Re-enable your drivers


    • To re-enable your Emulation drivers, double click on DeFogger to run the tool.
    • The application window will appear.
    • Click the Re-enable button to re-enable your CD Emulation drivers.
    • Click Yes to continue
    • A 'Finished!' message will appear.
    • Click OK
    • DeFogger will now ask to reboot the machine - click OK
    IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.
    Your Emulation drivers are now re-enabled.

  • Please perform the following cleanup procedure


    • Double click on the OTL.exe icon on your desktop to run the program. (Note: If you are running Vista, right-click on the file and choose Run As Administrator).
    • Once OTL has opened, click on the "CleanUp!" button.
    • Follow any prompts that you receive.

  • Removal of Tools


    • You no longer need Defogger, SytemLook or RootRepeal (if you downloaded it). Please delete these tools from your system.

  • Malwarebytes' Anti-Malware


    • MBAM is your to keep. Keep it updated and scan your system regularly.

  • Please create a new System Restore point


    • Click on "Start" > "All Programs" > "Accessories" > "System tools" > "System Restore".
    • In the dialogue box that appears select "Create a Restore Point".
    • Click "Next".
    • Enter a name
    • e.g. Clean.
    • Click "Create".

  • Please purge the old System Restore points from your system


    • Malware can sometimes hide in the old System Restore points saved on your computer.
    • Follow the steps below to flush the old Restore Points from your system.
    • Click on "Start" > "All Programs" > "Accessories" > "System tools" > "Disk Cleanup".
    • In the drop down box that appears, select your main drive e.g. "C".
    • Click on "OK".
    • Your system will perform a quick calculation and then display a dialogue box containing various tabs.
    • Select the "More Options" tab.
    • At the bottom of this tab, there will be a system restore box with a "Cleanup" button.
    • click on the "Cleanup" button, accept the warning and select "OK".

  • Please install XP Service Pack 3


    • XP Service Pack 3 contains many more security features that are not present in Service Pack 2.
    • You can download XP Service Pack 3 from here.

  • Your Internet Explorer is out of date


    • A newer version of Internet Explorer is available from here.
    • Alternatively, you can use Firefox (I will provide the link later).

    thanks so much for your help on this

    You are Very Welcome :)


    Once you have completed the above steps you should be good to go! If you have any further questions, please feel free to ask.

  • Finally, please take the time to read through the information provided below:

    Enhance your System Security

    • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.

    • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system. When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
    • Once complete, remember to re-engage your resident security before going online.

    Web Browsers and Browser Security

    Firefox
    • Firefox is generally considered to have greater browsing security in comparison to other popular programs. You can download Firefox 3.0 from here.

    No-Script
    • If you use Firefox as your default browser, No-Script can provide additional security by preventing malicious scripts from being executed on your system.
    • You can download No-Script by clicking here.

    Internet Explorer
    • The newest version of Internet Explorer is available from here.

    SpywareBlaster
    • If you use Internet Explorer as your default browser, SpywareBlaster would be a valuable addition to your online security.
    • SpywareBlaster prevents malicious ActiveX objects from being downloaded onto your system.
    • You can download SpywareBlaster by clicking here.

    Web of Trust
    • When using search engines, Web of Trust provides you with an easy way of telling the good sites from the bad and is compatible with both Firefox and Internet Explorer.
    • Coloured symbols are displayed next to search results, giving you more confidence in the links you choose to click on: Green (To go), Yellow (Caution) and Red (Stop).
    • You can download Web of Trust by clicking here.

    Keep your Software Updated
    • Outdated software can sometimes have vulnerabilities that are exploitable by malware.
    • Check if there are available updates for your installed software with Secunia's Online Software Inspector by clicking here.

    Passwords
    • Learn how to create strong passwords by clicking here and test the strength of the passwords you already use by clicking here.

    General Reading

    Learn How To Combat Malware
    • Would you like to learn how to fight back against malware and help others? Enroll at the What The Tech (Formerly Tom Coyotes) Malware Classroom by clicking here.
Thank you very much for your help. The system is cleaned of all the files as you mentioned above. I do have a few questions. If I don't use IE at all should I still update it? I use FF 3.0 with no scrip already as my primary. I tried a while back downloading Service Pack 3 and ran into a ton of problems with my video card since this is my gaming unit. I re-installed windows and have been reluctant to try it again. Have they fixed all the compatibility problems with it? I use Malewarebytes on all my machines on a regular basis and have Avast on them as an anti virus protector. I use windows xp firewall since I haven't found one that works well with gaming but keep in mind I rarely use this system to surf the internet. Am I covered good enough? Thanks, Frontrunner

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI