This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected, but by what?

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My system is not acting right, there are freezes and programs being unable to load. My hotmail account is set to not stay open but it does half the time. Internet broadband losing half its speed at night and I have had Astound out to check my lines but all is okay. There is no excessive usage of the service during those hours. I'm running Online armor Pro beta ver. 52. One of the bugs is Mbam cannot complete a scan, it stops and freezes at the same point every time and I have to do a forced shut down and restart. Every scan I run with any tools comes up clean, except for Super AntiSpyware which detects several adware hits but nothing out of the ordinary. I can't put my finger on it but the computer is just not acting correctly. I have deleted OA Pro and gone with the Windows Firewall and Avast free. Still the system is acting weird. I wish I had never gotten this 64bit system. Here is a new HJT log if it helps.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:47:41 AM, on 6/26/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Tall Emu\Online Armor\oaui.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\Windows\System32\oem\SetEvent.exe
C:\Program Files (x86)\Tall Emu\Online Armor\OAhlp.exe
C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Secunia\PSI\psi.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Users\Bryan\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…28v1j5w45j1t539
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…28v1j5w45j1t539
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…28v1j5w45j1t539
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [OpenDNS Updater] "C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe" /autostart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - (no file)
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - (no file)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://oas.support.microsoft.com/ActiveX/MSDcode.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/…can8/oscan8.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://www.battlefieldheroes.com/static/up…er_4.0.53.0.cab
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} (PCMaticVer Class) - http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll
O20 - AppInit_DLLs: C:\PROGRA~2\Google\GOOGLE~3\GO36F4~1.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: CSIScanner - Unknown owner - C:\Users\Bryan\prevx.exe (file missing)
O23 - Service: Encrypting File System (EFS) (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Online Armor Helper Service (OAcat) - Unknown owner - C:\Program Files (x86)\Tall Emu\Online Armor\OAcat.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Unknown owner - C:\Program Files (x86)\Tall Emu\Online Armor\oasrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 14283 bytes
Hi Bryan A,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Let's get some different scans that do better with 64 bit machines.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Copy and paste the following bold text in to the window Under the Custom Scan box

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • GMER log
  • both OTL logs
Hi Tomk, There are some problems. first Gmer ran and when done popped up a notice saying that there were no changes made to the system, or something to that effect but after I checked OK it did not produce a log. Second when I started OTL it popped up an error message. That the script engine couldn't make the langauge conversion. This is at the point when it gets to making a restore point but it never does, it just stops there and goes no further. Please advise me what you want me to do.
Bryan A,

Well then… let's try getting a log from a different tool.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Here are the logs. One thng first though. When the scan finished this error message popped up.: Can't find script engine "VBSCRIPT" for script "C:\users\Bryan\app data\local\temp\MSGE.pif" DDS (Ver_10-03-17.01) - NTFSX64 Run by [removed] at 10:04:31.06 on Wed 06/30/2010 Internet Explorer: 8.0.7600.16385 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3839.2640 [GMT -7:00] SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\nvvsvc.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Acer\Registration\GregHSRW.exe C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe C:\Windows\SysWOW64\PnkBstrA.exe C:\Program Files\Sandboxie\SbieSvc.exe C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Acer\Acer Updater\UpdaterService.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Windows\System32\StikyNot.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe c:\Windows\System32\oem\SetEvent.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Alwil Software\Avast5\AvastUI.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\taskeng.exe C:\Program Files (x86)\Secunia\PSI\psi.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\SysWOW64\ctfmon.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Bryan\Desktop\dds.scr C:\Windows\system32\conhost.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_x1301&r=17360510s707p0428v1j5w45j1t539 uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uDefault_Search_URL = hxxp://www.google.com/ie mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_x1301&r=17360510s707p0428v1j5w45j1t539 mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_x1301&r=17360510s707p0428v1j5w45j1t539 mLocal Page = c:\windows\syswow64\blank.htm uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files (x86)\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files (x86)\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files (x86)\google\googletoolbarnotifier\5.5.5126.1836\swg.dll BHO: {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - No File BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files (x86)\wot\WOT.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files (x86)\windows live\toolbar\wltcore.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files (x86)\windows live\toolbar\wltcore.dll TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files (x86)\wot\WOT.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files (x86)\google\google toolbar\GoogleToolbar_32.dll uRun: [RESTART_STICKY_NOTES] c:\windows\system32\StikyNot.exe uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [OpenDNS Updater] "c:\program files (x86)\opendns updater\OpenDNSUpdater.exe" /autostart uRun: [swg] "c:\program files (x86)\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [msnmsgr] "c:\program files (x86)\windows live\messenger\msnmsgr.exe" /background mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0) mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~2\micros~1\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files (x86)\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files (x86)\pokerstars\PokerStarsUpdate.exe IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} LSP: %SYSTEMROOT%\system32\nvLsp.dll Trusted Zone: google.com\www DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://oas.support.microsoft.com/ActiveX/MSDcode.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.53.0.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: {473F86ED-FB55-42E5-8A1F-9FC700C929D6} = 208.67.222.222,208.67.220.220 Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files (x86)\belarc\advisor\system\BAVoilaX.dll Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files (x86)\wot\WOT.dll AppInit_DLLs: c:\progra~2\google\google~3\GO36F4~1.DLL BHO-X64: Windows Live Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - c:\program files\windows live\family safety\fssbho.dll BHO-X64: Windows Live Family Safety Browser Helper - No File BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files (x86)\google\google toolbar\GoogleToolbar_64.dll BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg64.dll TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files (x86)\google\google toolbar\GoogleToolbar_64.dll TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File TB-X64: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File mRun-x64: [RtHDVCpl] c:\program files\realtek\audio\hda\RAVCpl64.exe -s mRun-x64: [PLD_FrameworkRun] c:\windows\system32\oem\_NowIntoDT.vbs ============= SERVICES / DRIVERS =============== R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys [2010-5-3 37392] R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2010-6-17 34696] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-6-17 121936] R1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\drivers\mwlPSDFilter.sys [2009-6-2 22576] R1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\drivers\mwlPSDNserv.sys [2009-6-2 20016] R1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\drivers\mwlPSDVDisk.sys [2009-6-2 60464] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv64.sys [2010-2-17 14920] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\saskutil64.sys [2010-2-17 12360] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore64.exe [2010-6-7 125440] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-6-17 20048] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-6-17 61008] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-29 40384] R2 Greg_Service;GRegService;c:\program files (x86)\acer\registration\GregHSRW.exe [2009-8-28 1150496] R2 MWLService;MyWinLocker Service;c:\program files (x86)\egistec\mywinlocker 3\x86\MWLService.exe [2009-9-10 305448] R2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\newtech infosystems\acer backup manager\IScheduleSvc.exe [2009-8-12 62208] R2 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2010-6-17 55808] R2 Updater Service;Updater Service;c:\program files\acer\acer updater\UpdaterService.exe [2009-10-27 240160] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2009-10-27 83488] R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-5-28 17456] R3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2010-4-17 134760] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 CSIScanner;CSIScanner;"c:\users\bryan\prevx.exe" /service –> c:\users\bryan\prevx.exe [?] S2 gupdate;Google Update Service (gupdate);c:\program files (x86)\google\update\GoogleUpdate.exe [2010-5-3 136176] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-29 40384] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-29 40384] S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-5-17 61288] S3 fsssvc;Windows Live Family Safety Service;c:\program files (x86)\windows live\family safety\fsssvc.exe [2010-4-28 704872] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files (x86)\google\google desktop search\GoogleDesktop.exe [2010-5-3 30192] S3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\91D5.tmp [2010-6-28 6144] S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2010-5-12 19936] S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2010-5-12 13280] S3 SaiKF622;SaiKF622;c:\windows\system32\drivers\SaiKF622.sys [2009-6-2 140800] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-5-3 1255736] =============== Created Last 30 ================ 2010-06-30 08:59:10 0 d—–w- c:\programdata\Tracker Software 2010-06-29 17:56:01 38848 —-a-w- c:\windows\avastSS.scr 2010-06-28 17:05:41 6144 ——w- c:\windows\system32\91D5.tmp 2010-06-28 17:05:01 6144 ——w- c:\windows\system32\F576.tmp 2010-06-28 16:17:09 0 d—–w- c:\program files\MPC HomeCinema (x64) 2010-06-28 15:25:20 0 d—–w- c:\programdata\NVIDIA Corporation 2010-06-28 15:23:09 65128 —-a-w- c:\windows\system32\OpenCL.dll 2010-06-28 15:23:09 56936 —-a-w- c:\windows\syswow64\OpenCL.dll 2010-06-28 15:23:08 6824040 —-a-w- c:\windows\system32\nvwgf2umx.dll 2010-06-28 15:23:07 4967528 —-a-w- c:\windows\syswow64\nvwgf2um.dll 2010-06-28 15:23:06 21662312 —-a-w- c:\windows\system32\nvoglv64.dll 2010-06-28 15:23:04 15764072 —-a-w- c:\windows\syswow64\nvoglv32.dll 2010-06-28 15:23:03 13039336 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys 2010-06-28 15:23:02 2890856 —-a-w- c:\windows\syswow64\nvencodemft.dll 2010-06-28 15:23:01 3184744 —-a-w- c:\windows\system32\nvencodemft.dll 2010-06-28 15:23:00 405608 —-a-w- c:\windows\system32\nvdecodemft.dll 2010-06-28 15:23:00 332392 —-a-w- c:\windows\syswow64\nvdecodemft.dll 2010-06-28 15:23:00 12338280 —-a-w- c:\windows\system32\nvd3dumx.dll 2010-06-28 07:50:18 5979 —-a-w- c:\windows\system32\nvnrm.nvu 2010-06-28 07:50:18 541216 —-a-w- c:\windows\system32\nvunrm.exe 2010-06-28 07:50:17 899584 —-a-w- c:\windows\system32\fdco2.dll 2010-06-28 07:50:17 339744 —-a-w- c:\windows\system32\drivers\nvmf6264.sys 2010-06-28 00:05:35 0 d—–w- c:\programdata\Yahoo! 2010-06-28 00:05:31 0 d—a-w- c:\programdata\TEMP 2010-06-28 00:05:23 0 d—–w- c:\programdata\Oberon Media 2010-06-28 00:04:37 0 d—–w- c:\program files (x86)\Oberon Media 2010-06-25 05:24:28 0 d—–w- c:\users\bryan\appdata\roaming\X-Setup Pro 2010-06-25 05:24:28 0 d—–w- c:\programdata\X-Setup Pro 2010-06-24 09:15:17 99176 —-a-w- c:\windows\syswow64\PresentationHostProxy.dll 2010-06-24 09:15:17 49472 —-a-w- c:\windows\syswow64\netfxperf.dll 2010-06-24 09:15:17 48960 —-a-w- c:\windows\system32\netfxperf.dll 2010-06-24 09:15:17 444752 —-a-w- c:\windows\system32\mscoree.dll 2010-06-24 09:15:17 320352 —-a-w- c:\windows\system32\PresentationHost.exe 2010-06-24 09:15:17 297808 —-a-w- c:\windows\syswow64\mscoree.dll 2010-06-24 09:15:17 295264 —-a-w- c:\windows\syswow64\PresentationHost.exe 2010-06-24 09:15:17 1942856 —-a-w- c:\windows\system32\dfshim.dll 2010-06-24 09:15:17 1130824 —-a-w- c:\windows\syswow64\dfshim.dll 2010-06-24 09:15:17 109912 —-a-w- c:\windows\system32\PresentationHostProxy.dll 2010-06-23 21:57:28 0 d—–w- c:\program files\7-Zip 2010-06-23 21:06:45 0 d—–w- c:\users\bryan\.bh_gui 2010-06-23 06:44:14 1736608 —-a-w- c:\windows\system32\ntdll.dll 2010-06-23 06:44:14 1289528 —-a-w- c:\windows\syswow64\ntdll.dll 2010-06-23 06:44:09 961024 —-a-w- c:\windows\system32\CPFilters.dll 2010-06-23 06:44:09 641536 —-a-w- c:\windows\syswow64\CPFilters.dll 2010-06-23 06:44:08 288256 —-a-w- c:\windows\system32\MSNP.ax 2010-06-23 06:44:08 258560 —-a-w- c:\windows\system32\mpg2splt.ax 2010-06-23 06:44:08 204288 —-a-w- c:\windows\syswow64\MSNP.ax 2010-06-23 06:44:08 199680 —-a-w- c:\windows\syswow64\mpg2splt.ax 2010-06-21 01:39:25 0 d—–w- c:\programdata\Ubisoft 2010-06-21 00:22:05 0 d—–w- c:\programdata\NOS 2010-06-20 03:24:47 0 d—–w- c:\program files (x86)\common files\Steam 2010-06-20 03:24:44 0 d—–w- c:\program files (x86)\Steam 2010-06-20 03:23:58 73544 —-a-w- c:\windows\system32\XAPOFX1_3.dll 2010-06-19 02:15:51 19016 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys 2010-06-19 02:15:33 0 d—–w- c:\programdata\Hitman Pro 2010-06-19 02:15:25 0 d—–w- c:\program files\Hitman Pro 3.5 2010-06-18 05:52:14 61008 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2010-06-18 05:51:52 165032 —-a-w- c:\windows\syswow64\aswBoot.exe 2010-06-18 04:39:19 62464 —-a-w- c:\windows\syswow64\PxSecure.dll 2010-06-18 04:39:19 34696 —-a-w- c:\windows\system32\drivers\pxscan.sys 2010-06-18 04:39:09 55808 —-a-w- c:\windows\system32\drivers\pxrts.sys 2010-06-18 04:39:09 22336 —-a-w- c:\windows\system32\drivers\pxkbf.sys 2010-06-17 17:27:53 0 d—–w- c:\users\bryan\appdata\roaming\OnlineArmor 2010-06-16 06:22:22 50 —-a-w- c:\windows\wininit.ini 2010-06-12 05:37:55 0 d–h–w- C:\VritualRoot 2010-06-11 17:36:42 0 d—–w- c:\program files\Tracker Software 2010-06-11 09:38:43 0 d—–w- c:\program files (x86)\Conduit 2010-06-11 03:55:55 0 d—–w- c:\users\bryan\appdata\roaming\SUPERAntiSpyware.com 2010-06-11 03:55:55 0 d—–w- c:\programdata\SUPERAntiSpyware.com 2010-06-11 03:55:30 0 d—–w- c:\programdata\!SASCORE 2010-06-11 03:55:26 0 d—–w- c:\program files\SUPERAntiSpyware 2010-06-10 16:58:30 0 d—–w- c:\program files (x86)\PokerStars 2010-06-08 00:21:00 15282280 —-a-w- c:\windows\system32\nvcpl.dll 2010-06-08 00:21:00 116328 —-a-w- c:\windows\system32\nvmctray.dll 2010-06-08 00:20:58 159336 —-a-w- c:\windows\system32\nvvsvc.exe 2010-06-08 00:20:58 1448040 —-a-w- c:\windows\system32\nvsvc64.dll 2010-06-05 22:40:42 65536 –sha-w- c:\users\bryan\ntuser.dat{faea86da-70f0-11df-8bf9-00262d289fc4}.TM.blf 2010-06-05 22:40:42 524288 –sha-w- c:\users\bryan\ntuser.dat{faea86da-70f0-11df-8bf9-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms 2010-06-05 22:40:42 524288 –sha-w- c:\users\bryan\ntuser.dat{faea86da-70f0-11df-8bf9-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms 2010-06-05 00:38:22 0 d—–w- c:\users\bryan\DoctorWeb 2010-06-03 02:41:44 3600384 —-a-w- c:\windows\syswow64\GPhotos.scr 2010-06-01 18:28:38 0 d—–w- c:\program files (x86)\Full Tilt Poker ==================== Find3M ==================== 2010-06-26 04:54:59 219128 —-a-w- c:\windows\syswow64\PnkBstrB.exe 2010-05-28 22:42:20 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_SaiKF622_01005.Wdf 2010-05-28 11:04:52 17456 —-a-w- c:\windows\system32\drivers\psi_mf.sys 2010-05-27 07:24:13 34304 —-a-w- c:\windows\syswow64\atmlib.dll 2010-05-27 06:34:09 46080 —-a-w- c:\windows\system32\atmlib.dll 2010-05-27 04:11:32 366080 —-a-w- c:\windows\system32\atmfd.dll 2010-05-27 03:49:37 293888 —-a-w- c:\windows\syswow64\atmfd.dll 2010-05-24 00:29:25 75064 —-a-w- c:\windows\syswow64\PnkBstrA.exe 2010-05-24 00:29:25 2427248 —-a-w- c:\windows\syswow64\pbsvc_heroes.exe 2010-05-21 21:14:28 270208 ——w- c:\windows\system32\MpSigStub.exe 2010-05-21 05:52:30 1192960 —-a-w- c:\windows\system32\wininet.dll 2010-05-21 05:18:06 977920 —-a-w- c:\windows\syswow64\wininet.dll 2010-05-21 05:14:50 48128 —-a-w- c:\windows\syswow64\jsproxy.dll 2010-05-15 22:10:16 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2010-05-06 12:42:05 1225216 —-a-w- c:\windows\syswow64\urlmon.dll 2010-05-06 12:41:55 606208 —-a-w- c:\windows\syswow64\mstime.dll 2010-05-06 12:41:53 64512 —-a-w- c:\windows\syswow64\msfeedsbs.dll 2010-05-06 12:41:53 5970944 —-a-w- c:\windows\syswow64\mshtml.dll 2010-05-06 12:41:49 381440 —-a-w- c:\windows\syswow64\iedkcs32.dll 2010-05-06 12:41:49 10984448 —-a-w- c:\windows\syswow64\ieframe.dll 2010-05-02 22:10:31 153376 —-a-w- c:\windows\syswow64\javaws.exe 2010-05-02 22:10:31 145184 —-a-w- c:\windows\syswow64\javaw.exe 2010-05-02 22:10:31 145184 —-a-w- c:\windows\syswow64\java.exe 2010-05-02 22:10:30 411368 —-a-w- c:\windows\syswow64\deployJava1.dll 2010-05-02 21:44:28 0 —-a-w- c:\users\bryan\appdata\roaming\wklnhst.dat 2010-05-01 15:07:05 3122176 —-a-w- c:\windows\system32\win32k.sys 2010-04-23 07:13:36 2048 —-a-w- c:\windows\syswow64\tzres.dll 2010-04-23 07:11:58 2048 —-a-w- c:\windows\system32\tzres.dll 2010-04-17 07:04:40 306032 —-a-w- c:\windows\WLXPGSS.SCR 2010-04-17 05:12:18 48464 —-a-w- c:\windows\syswow64\sirenacm.dll 2010-04-09 20:17:04 19936 ——w- c:\windows\system32\pwdrvio.sys 2010-04-09 20:16:58 13280 ——w- c:\windows\system32\pwdspio.sys 2010-04-09 20:16:54 611400 —-a-w- c:\windows\system32\pwNative.exe 2010-04-07 00:59:58 332320 —-a-w- c:\windows\system32\RtlCPAPI64.dll 2010-04-07 00:59:58 1943584 —-a-w- c:\windows\system32\RtPgEx64.dll 2010-04-07 00:59:52 1660960 —-a-w- c:\windows\system32\RtkAPO64.dll 2010-04-07 00:59:52 149536 —-a-w- c:\windows\system32\RtkCfg64.dll 2010-04-07 00:59:46 69664 —-a-w- c:\windows\system32\RCoInst64.dll 2010-04-07 00:59:46 476192 —-a-w- c:\windows\system32\RtkApi64.dll 2010-04-07 00:59:46 1210912 —-a-w- c:\windows\system32\RTCOM64.dll 2010-04-04 05:55:32 254056 —-a-w- c:\windows\system32\nvcod1914.dll 2009-07-14 05:37:38 31548 —-a-w- c:\windows\inf\perflib\0409\perfd.dat 2009-07-14 05:37:38 31548 —-a-w- c:\windows\inf\perflib\0409\perfc.dat 2009-07-14 05:37:38 291294 —-a-w- c:\windows\inf\perflib\0409\perfi.dat 2009-07-14 05:37:38 291294 —-a-w- c:\windows\inf\perflib\0409\perfh.dat 2009-07-14 04:54:24 174 –sha-w- c:\program files\desktop.ini 2009-07-14 04:54:24 174 –sha-w- c:\program files (x86)\desktop.ini 2009-07-14 01:00:34 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat 2009-07-14 01:00:34 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat 2009-07-14 01:00:32 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat 2009-07-14 01:00:32 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat 2009-06-10 20:44:08 9633792 –sha-r- c:\windows\fonts\StaticCache.dat 2009-07-14 01:39:53 398848 –sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe 2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe ============= FINISH: 10:04:41.81 =============== ==== Installed Programs ====================== Acer Assist Acer Backup Manager Acer eRecovery Management Acer Games Acer Registration Acer ScreenSaver Acer Updater Acrobat.com Adobe AIR Adobe Download Manager Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.3.2 Advertising Center Auslogics Disk Defrag avast! Free Antivirus Backup Manager Advance Battlefield Heroes Belarc Advisor 8.1 Call of Duty® 4 - Modern Warfare™ Call of Duty: Modern Warfare 2 Call of Duty: Modern Warfare 2 - Multiplayer CCleaner Combat Arms Compatibility Pack for the 2007 Office system Counter-Strike: Source DriverMax 5 ESET Online Scanner v3 eSobi v2 FileHippo.com Update Checker GamersFirst LIVE! Google Chrome Google Desktop Google Earth Google Toolbar for Internet Explorer Google Update Helper HostsMan 3.2.73 Hotkey Utility Identity Card ImagXpress ImgBurn Java Auto Updater Java™ 6 Update 20 Junk Mail filter update Malwarebytes' Anti-Malware Masque IGT Slots Little Green Men Microsoft Choice Guard Microsoft Office Live Add-in 1.5 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Suite Activation Assistant Microsoft Search Enhancement Pack Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Works Mozilla Thunderbird (3.1) MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MyWinLocker Nero 9 Essentials Nero ControlCenter Nero DiscSpeed Nero DiscSpeed Help Nero DriveSpeed Nero DriveSpeed Help Nero Express Help Nero InfoTool Nero InfoTool Help Nero Installer Nero Online Upgrade Nero StartSmart Nero StartSmart Help Nero StartSmart OEM NeroExpress neroxml NVIDIA ForceWare Network Access Manager OpenDNS Updater 2.2 Pando Media Booster Partition Wizard Home Edition 5.0 Picasa 3 PokerStars PunkBuster Services Realtek High Definition Audio Driver Revo Uninstaller 1.89 Secunia PSI Sophos Anti-Rootkit 1.5.4 Steam System Requirements Lab Tom Clancy's Splinter Cell Conviction Ubisoft Game Launcher Ubuntu Welcome Center Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Mail Windows Live Messenger Windows Live Movie Maker Windows Live Photo Gallery Windows Live Sync Windows Live Toolbar Windows Live Upload Tool Windows Live Writer WOT for Internet Explorer ==== End Of File ===========================
Bryan A,

Can't find script engine "VBSCRIPT" for script "C:\users\Bryan\app data\local\temp\MSGE.pif"

It is not likely that VBSCRIPT is actually missing - which means that your computer is having trouble locating it.

Please press the Windows logo key on your key board and press R at the same time. A small window should open that says RUN in the upper left corner. In the Open: box - please type - regsvr32 VBScript and then click on OK. You should get a message DllRegisterServer in VBScript succeded

Then…

I'm not seeing anything wrong with your log. Let's get an Online Scan, but first lets clean up some Temp files so the scan will go faster (It will still take a long time).

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Ok the VSCript engine was enabled, I have gone through this before and something keeps turning it off. But for now it is enabled. As far as Kaspersky goes the scan took 1.5 hours and came back clean. There was no report that would save even after I changed it to txt file, I guess this was because nothing was detected. The last time I came here for help nothing could be found in the way of malware then either. But what could not be found was why the computer was freezing at times and causing files to be disabled (VBSCRIPT for one) I am no longer running Onlne Armor beta because I know it still had bugs that were responsible for some of my problems but not all. Is there any way to determine where the errors in the registry are? Or is there a scan that can pinpoint problems not related to malware? Also, what should I do with all the tools saved to my desktop, should I just wait until we're finished before doing something about them?
Bryan A,

Unfortunately, because I can't find any malware…. my usefulness to you is pretty much non-existant. The OTL scan you did shows me some of the registry where the majority of malware problems are found. It doesn't show everything, obviously, and there is much about Windows that I don't know. However, we are very fortunate here at WTT to have some excellent members of the Tech Team. I suggest that you post a new topic in the Windows forum . There is a good chance that the Tech Team will have some useful advise. It wouldn't hurt to post a link there back to this thread so that they can see the information that you provided to me.

But first… let's clean up the mess we made on your destop.

  • Double click on OTL to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.

That should have removed the majority of what we put on your computer. If anything is left on your desktop…. please delete it.

Sorry that I couldn't be more helpful. Any questions?
No questions as of now, I do want to thank you for the time and effort you put into helping me. I wish I knew more about this 64bit system so I could understand more of it.
Bryan A,

I wish I knew more about this 64bit system so I could understand more of it.

I think alot of us share that wish. :) Nobody knows it all. That's what makes forums like WTT so awesome because there are so many knowledgeable people gathered together that it is fairly rare that someone doesn't at least have a theory.

I'm going to go ahead and close this thread. If something should arise that is malware related while you are working with the Tech Team, just PM me and I'll reopen this topic.

Good Luck and Be Well. :wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI