This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google redirecting and Spybot (safernet-working.org) is blocked

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Following up from a previous post where I thought my system was clean, I now suspect it is not. Whilst I was able to fix yahoo search results redirecting to advertising sites, I suspect something is still active as I'm unable to install spybotS&D because I can't resolve the server during the update, and trying to go to their URL also gives and error in my browser. The file that seemed to be responsible for the redirecting behaviour in Yahoo also reappeared. I have removed it once again with TDSSKiller , but something still doesn't seem quite right.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:36:57, on 03/09/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
C:\Windows\System32\Ctxfihlp.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Winamp\winampa.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Users\Raymond\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\userinit.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\AVG\AVG9\avgui.exe
C:\Users\Raymond\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk/ig/dell?hl=en&…amp;ibd=3080111
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [SetPoint] C:\Program Files\Logitech\SetPoint\SetPoint.EXE
O4 - HKLM\..\Run: [PMX Daemon] ICO.EXE
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [CCUTRAYICON] "C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe"
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe" /S
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2567757336-1158460955-345887290-1000\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'IUSR_NMPR')
O4 - HKUS\S-1-5-21-2567757336-1158460955-345887290-1000\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User 'IUSR_NMPR')
O4 - HKUS\S-1-5-21-2567757336-1158460955-345887290-1000\..\RunOnce: [CTAutoUpdate] "C:\Program Files\Creative\Shared Files\Software Update\AutoUpdate.exe" /RunFromInstaller (User 'IUSR_NMPR')
O4 - HKUS\S-1-5-18\..\Run: [CtxfiReg] CTXFIREG.exe /FAIL2 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CtxfiReg] CTXFIREG.exe /FAIL2 (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: userinit.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup…15108/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{33413700-EC02-4156-8F0C-F779F23B47EF}: NameServer = 93.188.164.77,93.188.166.227
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 93.188.164.77,93.188.166.227
O17 - HKLM\System\CS1\Services\Tcpip\..\{33413700-EC02-4156-8F0C-F779F23B47EF}: NameServer = 93.188.164.77,93.188.166.227
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.164.77,93.188.166.227
O18 - Protocol: bw+0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: offline-8876480 - {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - AppInit_DLLs: avgrsstx.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Intel® DHTrace Controller (DHTRACE) - Intel® Corporation - C:\Program Files\Common Files\Intel\IntelDH\bin\DHTraceController.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Intel® Viiv™ Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Intel® NMSCore (NMSCore) - Intel® Corporation - C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: Intel® Quality Manager (QualityManager) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe
O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 24099 bytes
Hi TheDoctor46,

:welcome:

My name is NightWizard and I will be your helper. :)

While I go through your log, I would very much appreciate it if you read the following.

  • I aim provide you with the best instructions possible to resolve your issue. However, I ask that you understand that malware is complex and the process usually takes a few attempts before successfully cleaning everything out. In severe cases cleaning may not be possible and a reformat may be our only option.
  • If you are unresponsive to this thread within three days, the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.
  • Please do not make any new threads about this issue here or any other malware removal forum; it wastes other helpers' time and it can be dangerous for your PC.
  • If you don't understand a set of instructions or you are having trouble performing some of the fix, don't panic! Let me know and I will be happy to help in any way I can.
  • Please remember that the absence of symptoms does not mean you are clean. I request that you stick to this log until the very end - I will inform you when your system is clean.
  • Please do not use any tools other than the ones I instruct you to use. Some of the tools available can be dangerous if used incorrectly.

Please be advised that I am still in training at this forum. My posts will be checked by experts before I post in this thread. This is to ensure you get the best possible help available. This may cause delay however I will do my best to limit the time gaps between posts.



Thanks for choosing WhatTheTech and I will be back with a fix shortly! :)


-NightWizard
Hi TheDoctor46,

Please work your way through the following:

Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")




Step One


Download OTL to your Desktop from one of the following links:

LINK 1
LINK 2
LINK 3

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop from HERE.
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click Ok to load a custom scan from a file or Cancel to cancel"
  • Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in this thread.




Step Two


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries




In your next reply please include:
  • The OTL log.
  • The GMER log.
Cheers :thumbup:
OK….

I ran OTL with the settings you gave, it generated the OTL and Extras text files. I then ran GMER which blue-screened my computer halfway through it's scan. Unfortunately I deleted the previous two text files as I was going to let OTL run again as well as GMER.

Anyway, GMER blue-screened the machine for a second time and now when I run OTL I only get the OTL text file and not the extras as well.

Here's the error report upon recovering from the BSOD,

Problem signature:
Problem Event Name: BlueScreen
OS Version: 6.0.6002.2.2.0.768.3
Locale ID: 2057

Additional information about the problem:
BCCode: 1000008e
BCP1: C0000005
BCP2: 82260D95
BCP3: B48F1A54
BCP4: 00000000
OS Version: 6_0_6002
Service Pack: 2_0
Product: 768_1

Files that help describe the problem:
C:\Windows\Minidump\Mini090410-02.dmp
C:\Users\Raymond\AppData\Local\Temp\WER-31028-0.sysdata.xml
C:\Users\Raymond\AppData\Local\Temp\WERC512.tmp.version.txt

Read our privacy statement:
http://go.microsoft.com/fwlink/?linkid=501…mp;clcid=0x0409


and seeing as OTL won't generate Extras.txt anymore all I've got is this.

OTL logfile created on: 04/09/2010 16:09:47 - Run 3
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Raymond\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 58.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 581.12 Gb Total Space | 232.17 Gb Free Space | 39.95% Space Free | Partition Type: NTFS
Drive D: | 7.55 Gb Total Space | 3.17 Gb Free Space | 41.93% Space Free | Partition Type: NTFS
Drive E: | 688.96 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RMWD-PC
Current User Name: Raymond
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Raymond\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Raymond\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\userinit.exe ()
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe (COMODO)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Windows\System32\Ctxfihlp.exe (Creative Technology Ltd)
PRC - C:\Windows\System32\CTxfispi.exe (Creative Technology Ltd)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe ()
PRC - C:\Program Files\AskBarDis\bar\bin\AskService.exe ()
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\QualityManager.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\issm.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe (Intel Corporation)
PRC - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe ()
PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
PRC - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()


========== Modules (SafeList) ==========

MOD - C:\Users\Raymond\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985
d\msvcr80.dll (Microsoft Corporation)
MOD - C:\Windows\System32\WindowsCodecs.dll (Microsoft Corporation)
MOD - C:\Program Files\Logitech\SetPoint\lgscroll.dll (Logitech, Inc.)
MOD - C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll (Microsoft Corporation)
MOD - C:\Windows\System32\networkexplorer.dll (Microsoft Corporation)
MOD - C:\Windows\System32\SLC.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msshsq.dll (Microsoft Corporation)
MOD - C:\Windows\System32\EhStorShell.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cscapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\rsaenh.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\thumbcache.dll (Microsoft Corporation)
MOD - C:\Windows\System32\duser.dll (Microsoft Corporation)
MOD - C:\Windows\System32\actxprxy.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Stereo Service) – C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (CLPSLS) – C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe (COMODO)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (ASKUpgrade) – C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe ()
SRV - (ASKService) – C:\Program Files\AskBarDis\bar\bin\AskService.exe ()
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (AlertService) Intel® – C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
SRV - (QualityManager) Intel® – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe (Intel® Corporation)
SRV - (Remote UI Service) Intel® – C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe (Intel® Corporation)
SRV - (MCLServiceATL) Intel® – C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe (Intel® Corporation)
SRV - (DHTRACE) Intel® – C:\Program Files\Common Files\Intel\IntelDH\bin\DHTraceController.exe (Intel® Corporation)
SRV - (ISSM) Intel® – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe (Intel® Corporation)
SRV - (NMSCore) Intel® – C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe (Intel® Corporation)
SRV - (M1 Server) Intel® Viiv™ – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe ()
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (StarWindServiceAE) – C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
SRV - (DQLWinService) – C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (mcdbus) – C:\Windows\System32\DRIVERS\mcdbus.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (ha20x22k) – C:\Windows\System32\drivers\ha20x22k.sys File not found
DRV - (CTHWIUT.DLL) – C:\Windows\System32\CTHWIUT.DLL File not found
DRV - (CTEXFIFX.DLL) – C:\Windows\System32\CTEXFIFX.DLL File not found
DRV - (CT20XUT.DLL) – C:\Windows\System32\CT20XUT.DLL File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (AvgTdiX) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (taphss) – C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (MotioninJoyXFilter) – C:\Windows\System32\drivers\MijXfilt.sys (MotioninJoy)
DRV - (xusb21) – C:\Windows\System32\drivers\xusb21.sys (Microsoft Corporation)
DRV - (RivaTuner32) – C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner32.sys ()
DRV - (LUsbFilt) – C:\Windows\System32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouFilt) – C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (ha20x2k) – C:\Windows\System32\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\Windows\System32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\Windows\System32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\Windows\System32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\Windows\System32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\Windows\System32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\Windows\System32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTEXFIFX.SYS) – C:\Windows\System32\drivers\CTEXFIFX.SYS (Creative Technology Ltd.)
DRV - (CTEXFIFX) – C:\Windows\System32\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV - (CTHWIUT.SYS) – C:\Windows\System32\drivers\CTHWIUT.SYS (Creative Technology Ltd.)
DRV - (CTHWIUT) – C:\Windows\System32\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV - (CT20XUT.SYS) – C:\Windows\System32\drivers\CT20XUT.SYS (Creative Technology Ltd.)
DRV - (CT20XUT) – C:\Windows\System32\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (StarOpen) – C:\Windows\System32\drivers\StarOpen.sys ()
DRV - (WmXlCore) – C:\Windows\System32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (WmVirHid) – C:\Windows\System32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmHidLo) – C:\Windows\System32\drivers\WmHidLo.sys (Logitech Inc.)
DRV - (WmFilter) – C:\Windows\System32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmBEnum) – C:\Windows\System32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (IntelDH) – C:\Windows\System32\drivers\IntelDH.sys (Intel Corporation)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (iaStor) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (TSHWMDTCP) – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys ()
DRV - (NAL) – C:\Windows\System32\drivers\iqvw32.sys (Intel Corporation )
DRV - (nmsunidr) – C:\Windows\System32\drivers\nmsunidr.sys (Gteko Ltd.)
DRV - (vmm) – C:\Windows\System32\drivers\VMM.sys (Microsoft Corporation)
DRV - (VPCNetS2) – C:\Windows\System32\drivers\VMNetSrv.sys (Microsoft Corporation)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk/ig/dell?hl=en&…amp;ibd=3080111

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.yahoo.com"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.845
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.4
FF - prefs.js..extensions.enabledItems: [removed]:1.5.7
FF - prefs.js..extensions.enabledItems: [removed]:4.60
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/05/12 17:34:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/07/21 09:08:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/22 13:19:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/22 13:19:58 | 000,000,000 | —D | M]

[2009/09/06 11:27:37 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\Mozilla\Extensions
[2010/09/03 18:11:19 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\Mozilla\Firefox\Profiles\8k93p5qj.default\extensions
[2010/07/17 17:31:32 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Raymond\AppData\Roaming\Mozilla\Firefox\Profiles\8k93p5qj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/17 17:31:32 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Raymond\AppData\Roaming\Mozilla\Firefox\Profiles\8k93p5qj.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/09/06 11:28:55 | 000,000,000 | —D | M] (Mouse Gestures Redox) – C:\Users\Raymond\AppData\Roaming\Mozilla\Firefox\Profiles\8k93p5qj.default\extensions\{FFA36170-80B1-4535-B0E3-A4569E497DD0}
[2010/07/17 17:31:32 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\Mozilla\Firefox\Profiles\8k93p5qj.default\extensions\[removed]
[2010/09/03 18:11:19 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/28 10:53:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/27 11:09:41 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2008/07/04 10:03:44 | 000,024,683 | —- | M] (Ask.com) – C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/12 17:33:56 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll

O1 HOSTS File: ([2010/08/05 17:27:19 | 000,416,458 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 14377 more lines…
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe (Intel® Corporation)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [NMSSupport] C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe (Intel Corporation)
O4 - HKLM..\Run: [PMX Daemon] File not found
O4 - HKLM..\Run: [RivaTunerStartupDaemon] C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe ()
O4 - HKLM..\Run: [SetPoint] C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - Startup: C:\Users\Raymond\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\Raymond\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\userinit.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O13 - gopher Prefix: missing
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab (Reg Error: Key error.)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15108/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.164.77,93.188.166.227
O18 - Protocol\Handler\bw+0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw+0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0 {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0s {2e747aea-6998-4fb0-9d97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\offline-8876480 {2E747AEA-6998-4FB0-9D97-684537066257} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img18.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img18.jpg
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2006/09/15 00:08:19 | 000,000,055 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{66391e4a-eead-11dc-a1a8-001d0925b216}\Shell - "" = AutoRun
O33 - MountPoints2\{66391e4a-eead-11dc-a1a8-001d0925b216}\Shell\AutoRun\command - "" = K:\Setup.exe – File not found
O33 - MountPoints2\{66391e4a-eead-11dc-a1a8-001d0925b216}\Shell\setup\command - "" = K:\Setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\System32\lhacm.acm (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\System32\frapsvid.dll (Beepa P/L)
Drivers32: VIDC.IV32 - C:\Windows\System32\ir32_32.dll (Intel® Corporation)
Drivers32: VIDC.IV41 - C:\Windows\System32\IR41_32.DLL (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 90 Days ==========

[2010/09/04 15:10:01 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Raymond\Desktop\OTL.exe
[2010/09/03 22:36:33 | 000,000,000 | —D | C] – C:\Users\Raymond\Documents\888poker
[2010/09/03 12:23:40 | 000,000,000 | —D | C] – C:\Users\Raymond\AppData\Roaming\HPAppData
[2010/09/01 18:19:56 | 000,000,000 | —D | C] – C:\Users\Raymond\Desktop\tdsskiller
[2010/09/01 18:19:14 | 000,000,000 | —D | C] – C:\Users\Raymond\Desktop\GooredFix Backups
[2010/09/01 18:18:40 | 000,071,398 | —- | C] (jpshortstuff) – C:\Users\Raymond\Desktop\GooredFix.exe
[2010/09/01 16:17:50 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Raymond\Desktop\HiJackThis.exe
[2010/09/01 15:07:25 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Users\Raymond\Desktop\spybotsd162.exe
[2010/08/31 12:06:59 | 000,000,000 | —D | C] – C:\Program Files\SquareEnix
[2010/08/31 11:10:57 | 123,225,432 | —- | C] (SQUARE ENIX CO., LTD.) – C:\Users\Raymond\Desktop\ffxivsetup.exe
[2010/08/31 09:25:24 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/08/27 12:09:39 | 000,000,000 | —D | C] – C:\Users\Raymond\Desktop\pink_noise_FLAC
[2010/07/22 22:28:39 | 000,000,000 | —D | C] – C:\Users\Raymond\Desktop\wgens211
[2010/07/17 12:37:10 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/07/17 12:37:08 | 000,243,024 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2010/07/17 12:37:03 | 000,216,400 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/07/17 12:37:01 | 000,029,584 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/07/17 12:37:01 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\Avg
[2010/07/17 12:34:49 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010/07/17 12:34:34 | 000,000,000 | —D | C] – C:\ProgramData\avg9
[2010/07/17 11:13:16 | 000,000,000 | -H-D | C] – C:\VritualRoot
[2010/07/17 11:09:52 | 000,000,000 | —D | C] – C:\ProgramData\COMODO
[2010/07/17 11:06:26 | 000,000,000 | —D | C] – C:\ProgramData\Comodo Downloader
[2010/07/09 18:41:42 | 000,000,000 | —D | C] – C:\Users\Raymond\Desktop\rFactor stuff
[2010/07/09 18:31:36 | 000,000,000 | —D | C] – C:\Users\Raymond\AppData\Roaming\BlackBean
[2010/07/09 18:26:18 | 000,000,000 | —D | C] – C:\Users\Raymond\AppData\Roaming\FreeArc
[2010/07/09 18:26:07 | 000,000,000 | —D | C] – C:\Program Files\FreeArc
[2010/07/09 18:10:36 | 000,000,000 | —D | C] – C:\Users\Raymond\AppData\Roaming\Spotify
[2010/07/09 18:10:36 | 000,000,000 | —D | C] – C:\Users\Raymond\AppData\Local\Spotify
[2010/07/09 18:10:34 | 000,000,000 | —D | C] – C:\Program Files\Spotify
[2010/07/01 12:41:26 | 000,000,000 | —D | C] – C:\Program Files\rFactor
[2010/06/30 21:55:46 | 000,000,000 | —D | C] – C:\Users\Raymond\Desktop\REPLAYFRIDGE
[2010/06/30 20:31:24 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA Corporation
[2010/06/30 20:30:27 | 000,056,936 | —- | C] (Khronos Group) – C:\Windows\System32\OpenCL.dll
[2010/06/30 12:41:53 | 000,000,000 | —D | C] – C:\ProgramData\Trymedia
[2010/06/27 22:29:57 | 000,000,000 | —D | C] – C:\MoTeC
[2010/06/27 22:29:56 | 000,000,000 | —D | C] – C:\Program Files\MoTeC
[2010/06/27 22:15:11 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Thraex Software
[2010/06/26 08:59:41 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2009/06/03 20:21:54 | 000,060,928 | —- | C] ( ) – C:\Windows\System32\a3d.dll
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[16 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/09/04 16:09:59 | 008,388,608 | -HS- | M] () – C:\Users\Raymond\ntuser.dat
[2010/09/04 15:46:35 | 000,759,570 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/09/04 15:46:35 | 000,649,514 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/09/04 15:46:35 | 000,125,552 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/09/04 15:39:51 | 000,070,161 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/09/04 15:39:50 | 000,070,161 | —- | M] () – C:\ProgramData\nvModes.001
[2010/09/04 15:39:42 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/04 15:39:41 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/04 15:39:37 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/04 15:39:35 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/04 15:39:32 | 3219,050,496 | -HS- | M] () – C:\hiberfil.sys
[2010/09/04 15:39:30 | 280,797,222 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/09/04 15:26:42 | 000,293,376 | —- | M] () – C:\Users\Raymond\Desktop\pgtgwv1y.exe
[2010/09/04 15:10:01 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Raymond\Desktop\OTL.exe
[2010/09/04 13:48:51 | 000,055,468 | —- | M] () – C:\Windows\System32\BMXStateBkp-{00000004-00000000-00000004-00001102-00000005-60021102}.rfx
[2010/09/04 13:48:51 | 000,055,468 | —- | M] () – C:\Windows\System32\BMXState-{00000004-00000000-00000004-00001102-00000005-60021102}.rfx
[2010/09/04 13:48:51 | 000,000,788 | —- | M] () – C:\Windows\System32\DVCState-{00000004-00000000-00000004-00001102-00000005-60021102}.rfx
[2010/09/04 10:24:26 | 064,275,422 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/09/04 10:20:17 | 000,000,450 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{93953CBA-97BA-4141-BC3B-ECBC94AD33E9}.job
[2010/09/03 23:42:34 | 000,524,288 | -HS- | M] () – C:\Users\Raymond\ntuser.dat{7707f0fc-92f1-11de-9268-001d0925b216}.TMContainer00000000000000000002.regtrans-ms
[2010/09/03 23:42:34 | 000,065,536 | -HS- | M] () – C:\Users\Raymond\ntuser.dat{7707f0fc-92f1-11de-9268-001d0925b216}.TM.blf
[2010/09/03 23:42:14 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/09/03 23:39:09 | 003,105,804 | -H– | M] () – C:\Users\Raymond\AppData\Local\IconCache.db
[2010/09/03 22:37:21 | 000,001,832 | —- | M] () – C:\Users\Raymond\Application Data\Microsoft\Internet Explorer\Quick Launch\888poker.lnk
[2010/09/02 22:03:10 | 000,000,069 | —- | M] () – C:\Windows\NeroDigital.ini
[2010/09/02 22:02:54 | 000,128,512 | —- | M] () – C:\Users\Raymond\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/01 18:18:40 | 000,071,398 | —- | M] (jpshortstuff) – C:\Users\Raymond\Desktop\GooredFix.exe
[2010/09/01 18:18:28 | 001,142,091 | —- | M] () – C:\Users\Raymond\Desktop\tdsskiller.zip
[2010/09/01 16:17:50 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Raymond\Desktop\HiJackThis.exe
[2010/09/01 15:07:34 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Users\Raymond\Desktop\spybotsd162.exe
[2010/09/01 13:20:55 | 000,001,134 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUser.job
[2010/08/31 12:07:04 | 000,001,922 | —- | M] () – C:\Users\Public\Desktop\FINAL FANTASY XIV Beta Version.lnk
[2010/08/31 11:23:00 | 123,225,432 | —- | M] (SQUARE ENIX CO., LTD.) – C:\Users\Raymond\Desktop\ffxivsetup.exe
[2010/08/31 09:12:28 | 000,000,120 | —- | M] () – C:\Users\Raymond\AppData\Local\Hsomalib.dat
[2010/08/31 09:12:28 | 000,000,000 | —- | M] () – C:\Users\Raymond\AppData\Local\Dlarapes.bin
[2010/08/30 11:33:23 | 000,015,872 | —- | M] () – C:\Users\Raymond\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\userinit.exe
[2010/08/27 12:08:53 | 024,737,934 | —- | M] () – C:\Users\Raymond\Desktop\pink_noise_FLAC.zip
[2010/08/16 12:32:58 | 000,000,740 | —- | M] () – C:\Users\Raymond\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/08/16 12:32:58 | 000,000,716 | —- | M] () – C:\Users\Public\Desktop\Opera.lnk
[2010/08/12 11:39:10 | 000,316,384 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/08/09 14:24:05 | 000,001,385 | —- | M] () – C:\Users\Raymond\Documents\girlznight letter.rtf
[2010/08/05 17:27:19 | 000,416,458 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/07/27 15:19:42 | 000,524,288 | -HS- | M] () – C:\Users\Raymond\ntuser.dat{7707f0fc-92f1-11de-9268-001d0925b216}.TMContainer00000000000000000001.regtrans-ms
[2010/07/27 10:48:42 | 000,415,271 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100805-172719.backup
[2010/07/17 12:37:11 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/07/17 12:37:09 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2010/07/17 12:37:03 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/07/17 12:37:02 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/07/17 12:37:01 | 000,113,461 | —- | M] () – C:\Windows\System32\drivers\Avg\iavichjw.avm
[2010/07/16 21:16:17 | 000,412,671 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100727-104842.backup
[2010/07/09 18:26:14 | 000,000,892 | —- | M] () – C:\Users\Raymond\Application Data\Microsoft\Internet Explorer\Quick Launch\FreeArc.lnk
[2010/07/02 12:22:40 | 000,000,732 | —- | M] () – C:\Users\Raymond\Desktop\rFactor - Shortcut.lnk
[2010/07/01 12:33:33 | 008,126,464 | -HS- | M] () – C:\Users\Raymond\ntuser.dat_previous
[2010/06/27 22:25:24 | 000,224,605 | —- | M] () – C:\Windows\rFactor Data Acquisition Plugin Uninstaller.exe
[2010/06/08 00:57:00 | 000,056,936 | —- | M] (Khronos Group) – C:\Windows\System32\OpenCL.dll
[2010/06/08 00:57:00 | 000,009,633 | —- | M] () – C:\Windows\System32\nvinfo.pb
[2010/06/07 20:51:34 | 000,000,374 | —- | M] () – C:\Users\Raymond\Documents\Pictures - Shortcut.lnk
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[16 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/04 15:34:57 | 280,797,222 | —- | C] () – C:\Windows\MEMORY.DMP
[2010/09/04 15:26:42 | 000,293,376 | —- | C] () – C:\Users\Raymond\Desktop\pgtgwv1y.exe
[2010/09/03 22:37:21 | 000,001,832 | —- | C] () – C:\Users\Raymond\Application Data\Microsoft\Internet Explorer\Quick Launch\888poker.lnk
[2010/09/01 18:18:28 | 001,142,091 | —- | C] () – C:\Users\Raymond\Desktop\tdsskiller.zip
[2010/08/31 12:07:04 | 000,001,922 | —- | C] () – C:\Users\Public\Desktop\FINAL FANTASY XIV Beta Version.lnk
[2010/08/30 11:35:20 | 000,000,000 | —- | C] () – C:\Users\Raymond\AppData\Local\Dlarapes.bin
[2010/08/30 11:35:19 | 000,000,120 | —- | C] () – C:\Users\Raymond\AppData\Local\Hsomalib.dat
[2010/08/30 11:33:24 | 000,015,872 | —- | C] () – C:\Users\Raymond\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\userinit.exe
[2010/08/27 12:08:10 | 024,737,934 | —- | C] () – C:\Users\Raymond\Desktop\pink_noise_FLAC.zip
[2010/08/09 14:24:05 | 000,001,385 | —- | C] () – C:\Users\Raymond\Documents\girlznight letter.rtf
[2010/07/17 12:37:01 | 064,275,422 | —- | C] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/07/17 12:37:01 | 000,113,461 | —- | C] () – C:\Windows\System32\drivers\Avg\iavichjw.avm
[2010/07/17 11:25:09 | 3219,050,496 | -HS- | C] () – C:\hiberfil.sys
[2010/07/09 18:26:14 | 000,000,892 | —- | C] () – C:\Users\Raymond\Application Data\Microsoft\Internet Explorer\Quick Launch\FreeArc.lnk
[2010/07/02 12:22:40 | 000,000,732 | —- | C] () – C:\Users\Raymond\Desktop\rFactor - Shortcut.lnk
[2010/06/30 20:30:27 | 000,009,633 | —- | C] () – C:\Windows\System32\nvinfo.pb
[2010/06/27 22:15:11 | 000,224,605 | —- | C] () – C:\Windows\rFactor Data Acquisition Plugin Uninstaller.exe
[2010/06/07 20:51:34 | 000,000,374 | —- | C] () – C:\Users\Raymond\Documents\Pictures - Shortcut.lnk
[2010/05/11 10:32:13 | 000,070,161 | —- | C] () – C:\ProgramData\nvModes.001
[2010/05/11 10:32:10 | 000,070,161 | —- | C] () – C:\ProgramData\nvModes.dat
[2010/05/11 09:18:03 | 000,000,680 | —- | C] () – C:\Users\Raymond\AppData\Local\d3d9caps.dat
[2010/04/02 17:17:34 | 000,179,091 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2010/02/06 14:55:50 | 000,001,547 | —- | C] () – C:\ProgramData\hpzinstall.log
[2009/11/19 12:29:41 | 000,000,130 | —- | C] () – C:\Windows\cfplogvw.INI
[2009/09/24 09:32:45 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/09/06 11:43:04 | 000,000,760 | —- | C] () – C:\Users\Raymond\AppData\Roaming\setup_ldm.iss
[2009/09/05 19:26:13 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2009/09/05 14:52:35 | 000,031,007 | —- | C] () – C:\Users\Raymond\AppData\Roaming\UserTile.png
[2009/09/05 14:36:59 | 000,000,029 | —- | C] () – C:\Windows\sfbm.INI
[2009/09/02 10:36:08 | 000,138,808 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2009/09/01 21:14:43 | 000,000,095 | —- | C] () – C:\Users\Raymond\AppData\Local\fusioncache.dat
[2009/06/03 21:00:30 | 000,026,928 | —- | C] () – C:\Windows\System32\instwdm.ini
[2009/06/03 21:00:28 | 000,000,054 | —- | C] () – C:\Windows\System32\ctzapxx.ini
[2009/06/03 20:19:42 | 000,002,560 | —- | C] () – C:\Windows\System32\CtxfiRes.dll
[2009/06/03 20:19:42 | 000,002,560 | —- | C] () – C:\Windows\CTXFIRES.DLL
[2009/05/26 04:12:38 | 000,000,297 | —- | C] () – C:\Windows\System32\kill.ini
[2009/04/16 13:28:03 | 000,000,115 | —- | C] () – C:\Windows\GPM2MICP.INI
[2009/03/07 23:48:47 | 000,155,384 | —- | C] () – C:\Windows\System32\guard32.dll1
[2008/10/20 19:18:18 | 000,069,632 | —- | C] () – C:\Windows\System32\xmltok.dll
[2008/10/20 19:18:18 | 000,036,864 | —- | C] () – C:\Windows\System32\xmlparse.dll
[2008/10/20 16:15:05 | 000,022,328 | —- | C] () – C:\Users\Raymond\AppData\Roaming\PnkBstrK.sys
[2008/05/29 11:43:16 | 000,000,000 | —- | C] () – C:\ProgramData\LauncherAccess.dt
[2008/05/29 11:41:51 | 000,005,632 | —- | C] () – C:\Windows\System32\drivers\StarOpen.sys
[2008/03/18 19:58:06 | 000,000,319 | —- | C] () – C:\Windows\game.ini
[2008/03/17 20:33:01 | 000,034,308 | —- | C] () – C:\Windows\System32\BASSMOD.dll
[2008/03/09 17:58:43 | 000,717,296 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2008/02/24 13:53:47 | 000,001,478 | —- | C] () – C:\Users\Raymond\AppData\Roaming\wklnhst.dat
[2008/01/19 14:39:43 | 000,128,512 | —- | C] () – C:\Users\Raymond\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/11 02:22:43 | 000,876,544 | —- | C] () – C:\Windows\System32\TEACico2.dll
[2008/01/10 18:40:00 | 000,164,864 | —- | C] () – C:\Windows\System32\APOMngr.DLL
[2008/01/10 18:40:00 | 000,073,728 | —- | C] () – C:\Windows\System32\CmdRtr.DLL
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/06/23 11:09:34 | 000,019,968 | R— | C] () – C:\Windows\System32\cpuinf32.dll
[1996/04/03 20:33:26 | 000,005,248 | —- | C] () – C:\Windows\System32\giveio.sys

========== LOP Check ==========

[2010/09/02 23:00:48 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\Azureus
[2008/10/18 16:45:12 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\Bioshock
[2010/07/09 18:31:36 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\BlackBean
[2010/07/01 12:28:07 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\DAEMON Tools
[2010/07/09 18:26:18 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\FreeArc
[2008/07/05 16:17:50 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\GetRightToGo
[2008/07/09 20:37:21 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\gnupg
[2008/06/23 20:24:13 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\Ludia
[2010/01/28 13:31:53 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\MotioninJoy
[2009/08/08 14:16:11 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\NoNameScript
[2010/09/03 23:01:28 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\NoNameScript4.22
[2008/01/19 15:01:08 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\Opera
[2010/09/03 22:38:23 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\PacificPoker
[2009/09/05 14:52:35 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\PeerNetworking
[2008/06/23 20:23:50 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\PlayFirst
[2008/05/30 14:45:28 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\Samsung
[2009/12/13 13:03:34 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\ScummVM
[2010/07/09 18:20:36 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\Spotify
[2008/10/24 14:07:31 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\SystemRequirementsLab
[2008/03/18 12:01:31 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\Template
[2009/09/06 14:23:27 | 000,000,000 | —D | M] – C:\Users\Raymond\AppData\Roaming\wsInspector
[2010/09/03 23:42:14 | 000,032,622 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/09/04 10:20:17 | 000,000,450 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{93953CBA-97BA-4141-BC3B-ECBC94AD33E9}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 22:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 07:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/11/10 14:22:24 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 22:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2008/01/11 02:22:56 | 000,004,953 | RH– | M] () – C:\dell.sdr
[2010/09/04 15:39:32 | 3219,050,496 | -HS- | M] () – C:\hiberfil.sys
[2008/07/01 10:34:14 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/07/01 10:34:14 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/09/04 15:39:31 | 3532,881,920 | -HS- | M] () – C:\pagefile.sys
[2010/09/01 18:23:28 | 000,064,588 | —- | M] () – C:\TDSSKiller.2.4.1.4_01.09.2010_18.20.03_log.txt
[2010/09/01 18:30:32 | 000,063,002 | —- | M] () – C:\TDSSKiller.2.4.1.4_01.09.2010_18.29.07_log.txt
[2010/09/03 10:16:54 | 000,063,002 | —- | M] () – C:\TDSSKiller.2.4.1.4_03.09.2010_10.16.15_log.txt
[2010/09/03 18:16:04 | 000,064,588 | —- | M] () – C:\TDSSKiller.2.4.1.4_03.09.2010_18.15.13_log.txt
[2010/09/03 18:22:06 | 000,063,002 | —- | M] () – C:\TDSSKiller.2.4.1.4_03.09.2010_18.21.34_log.txt
[2010/09/03 18:24:30 | 000,063,002 | —- | M] () – C:\TDSSKiller.2.4.1.4_03.09.2010_18.24.03_log.txt
[2010/09/04 10:23:28 | 000,063,002 | —- | M] () – C:\TDSSKiller.2.4.1.4_04.09.2010_10.22.55_log.txt
[2010/09/04 10:59:45 | 000,063,002 | —- | M] () – C:\TDSSKiller.2.4.1.4_04.09.2010_10.59.24_log.txt
[2009/11/30 21:00:38 | 1086,193,664 | —- | M] () – C:\WinLite.iso

< %systemroot%\Fonts\*.com >
[2006/11/02 13:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/09/28 09:53:35 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/04/16 15:08:20 | 000,312,832 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpfpp70v.dll
[2006/11/02 13:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/06/29 18:30:59 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 11:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/06/18 13:13:30 | 000,000,444 | -HS- | M] () – C:\Users\Raymond\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2009/08/06 20:12:44 | 057,398,647 | —- | M] () – C:\Users\Raymond\Desktop\AbsoluteBlue_Setup.exe
[2010/09/01 17:08:12 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Raymond\Desktop\ATF_Cleaner.exe
[2010/08/31 11:23:00 | 123,225,432 | —- | M] (SQUARE ENIX CO., LTD.) – C:\Users\Raymond\Desktop\ffxivsetup.exe
[2010/09/01 18:18:40 | 000,071,398 | —- | M] (jpshortstuff) – C:\Users\Raymond\Desktop\GooredFix.exe
[2010/09/01 16:17:50 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Raymond\Desktop\HiJackThis.exe
[2010/05/13 13:41:14 | 005,585,208 | —- | M] () – C:\Users\Raymond\Desktop\HSS-1.43-install-anchorfree-76-conduit.exe
[2010/09/04 15:10:01 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Raymond\Desktop\OTL.exe
[2010/09/04 15:26:42 | 000,293,376 | —- | M] () – C:\Users\Raymond\Desktop\pgtgwv1y.exe
[2010/09/01 15:07:34 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Users\Raymond\Desktop\spybotsd162.exe
[2009/10/13 19:54:21 | 067,200,131 | —- | M] () – C:\Users\Raymond\Desktop\WorldOfGooSetup.1.30.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >
[2010/07/01 13:30:00 | 000,008,192 | —- | M] () – C:\Windows\security\database\edb.chk
[2010/07/01 13:29:30 | 001,048,576 | —- | M] () – C:\Windows\security\database\edb.log
[2009/08/29 17:08:41 | 001,048,576 | —- | M] () – C:\Windows\security\database\edbres00001.jrs
[2009/08/29 17:08:41 | 001,048,576 | —- | M] () – C:\Windows\security\database\edbres00002.jrs
[2010/07/01 13:29:30 | 001,056,768 | —- | M] () – C:\Windows\security\database\tmp.edb

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2008/01/19 14:32:37 | 000,000,402 | -HS- | M] () – C:\Users\Raymond\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >
[2010/05/12 17:34:29 | 000,001,547 | —- | M] () – C:\ProgramData\hpzinstall.log
[2008/11/12 12:31:48 | 000,000,000 | —- | M] () – C:\ProgramData\LauncherAccess.dt
[2010/09/04 15:39:50 | 000,070,161 | —- | M] () – C:\ProgramData\nvModes.001

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >
rFactor Data Acquisition Plugin Uninstaller.exe

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< %systemroot%\system32\winlog\*.* >

< %systemroot%\system32\Language\*.* >

< %systemroot%\system32\Settings\*.* >

< %systemroot%\system32\*.quo >

< %SYSTEMROOT%\AppPatch\*.exe >

< %SYSTEMROOT%\inf\*.exe >

< %SYSTEMROOT%\Installer\*.exe >

< %USERPROFILE%\Templates\*.* >

< %systemroot%\system32\config\*.bak2 >

< %systemroot%\system32\Computers\*.* >

< %SystemRoot%\system32\Sound\*.* >

< %SystemRoot%\system32\SpecialImg\*.* >

< %SystemRoot%\system32\code\*.* >

< %SystemRoot%\system32\draft\*.* >

< %SystemRoot%\system32\MSSSys\*.* >

< %ProgramFiles%\Javascript\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-12 07:47:51
< End of report >
Hi TheDoctor46,

Sorry for the delay.

Please open OTL.

Copy/Paste the following into the custom scans/fixes box:

C:\Windows\System32\userinit.exe /S
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon|userinit /RS


Then select the "None" radio button next to:
  • Processes
  • Services
  • Standard Registry
  • Modules
  • Drivers
  • Extra Registry
  • Files modified within
  • Files created within

Then click Run Scan. When presented with the OTL log, please copy/paste it here for me to see.
Thanks for the reply.

Log as requested.

OTL logfile created on: 06/09/2010 11:11:01 - Run 5
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Raymond\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 581.12 Gb Total Space | 228.33 Gb Free Space | 39.29% Space Free | Partition Type: NTFS
Drive D: | 7.55 Gb Total Space | 3.17 Gb Free Space | 41.93% Space Free | Partition Type: NTFS
Drive E: | 688.96 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RMWD-PC
Current User Name: Raymond
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Custom Scans ==========


< C:\Windows\System32\userinit.exe /S >
[2008/01/19 08:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) – C:\Windows\System32\userinit.exe
[16 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

< HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon|userinit /RS >
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit: C:\Windows\system32\userinit.exe,
< End of report >
Hi TheDoctor46,

Please work your way through the following steps:

Step 1

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\Users\Raymond\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\userinit.exe ()
    O4 - Startup: C:\Users\Raymond\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\userinit.exe ()
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [PMX Daemon] File not found
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab (Reg Error: Key error.)
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
    O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - Reg Error: Key error. File not found
    O33 - MountPoints2\{66391e4a-eead-11dc-a1a8-001d0925b216}\Shell - "" = AutoRun
    O33 - MountPoints2\{66391e4a-eead-11dc-a1a8-001d0925b216}\Shell\AutoRun\command - "" = K:\Setup.exe – File not found
    O33 - MountPoints2\{66391e4a-eead-11dc-a1a8-001d0925b216}\Shell\setup\command - "" = K:\Setup.exe – File not found
    [2010/08/31 09:12:28 | 000,000,120 | —- | M] () – C:\Users\Raymond\AppData\Local\Hsomalib.dat
    [2010/08/31 09:12:28 | 000,000,000 | —- | M] () – C:\Users\Raymond\AppData\Local\Dlarapes.bin
    [2010/08/30 11:33:23 | 000,015,872 | —- | M] () – C:\Users\Raymond\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\userinit.exe
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • After rebooting, please post the OTL you are presented with on startup.


Step 2

Please download Malwarebytes' AntiMalware.

Double click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Full Scan, then click Scan.
    The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to restart. Restart if it tells you to.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.


In your next reply please include:
  • The log from OTL.
  • The MBAM log.
Cheers :thumbup:
OK OTL completed fine and here's the log.

All processes killed
========== OTL ==========
No active process named userinit.exe was found!
C:\Users\Raymond\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\userinit.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\PMX Daemon deleted successfully.
Starting removal of ActiveX control {39B0684F-D7BF-4743-B050-FDC3F48F7E3B}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{39B0684F-D7BF-4743-B050-FDC3F48F7E3B}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{39B0684F-D7BF-4743-B050-FDC3F48F7E3B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39B0684F-D7BF-4743-B050-FDC3F48F7E3B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{39B0684F-D7BF-4743-B050-FDC3F48F7E3B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39B0684F-D7BF-4743-B050-FDC3F48F7E3B}\ not found.
Starting removal of ActiveX control {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{67A5F8DC-1A4B-4D66-9F24-A704AD929EEE}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{67A5F8DC-1A4B-4D66-9F24-A704AD929EEE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67A5F8DC-1A4B-4D66-9F24-A704AD929EEE}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67A5F8DC-1A4B-4D66-9F24-A704AD929EEE}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67A5F8DC-1A4B-4D66-9F24-A704AD929EEE}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{4F07DA45-8170-4859-9B5F-037EF2970034} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F07DA45-8170-4859-9B5F-037EF2970034}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{66391e4a-eead-11dc-a1a8-001d0925b216}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66391e4a-eead-11dc-a1a8-001d0925b216}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{66391e4a-eead-11dc-a1a8-001d0925b216}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66391e4a-eead-11dc-a1a8-001d0925b216}\ not found.
File K:\Setup.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{66391e4a-eead-11dc-a1a8-001d0925b216}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66391e4a-eead-11dc-a1a8-001d0925b216}\ not found.
File K:\Setup.exe not found.
C:\Users\Raymond\AppData\Local\Hsomalib.dat moved successfully.
C:\Users\Raymond\AppData\Local\Dlarapes.bin moved successfully.
File C:\Users\Raymond\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\userinit.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: IUSR_NMPR
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: Raymond
->Temp folder emptied: 42584753 bytes
->Temporary Internet Files folder emptied: 21023741 bytes
->Java cache emptied: 49712669 bytes
->FireFox cache emptied: 86825116 bytes
->Google Chrome cache emptied: 6702825 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 44217 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 155648 bytes
%systemroot%\System32 .tmp files removed: 5722940 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 305289 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 203.00 mb


[EMPTYFLASH]

User: Default

User: IUSR_NMPR

User: Public

User: Raymond
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.11.0 log created on 09062010_141731

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…


MBAM I had some problems with. Firstly I was unable to download it from any of the mirrors in your link. The browser just point-blank refused. I obtained it from a different site, the same version that you linked. I tried to update it but it gave an error, which I will also mention that Spybot does as well when I try to update that. I can't get onto the official malwarebytes-antimalware site, and nor can I get onto spybot's site either. This is what made me suspicious that something was active on this maachine in the first place.

I did run MBAM without the update and here is the log.

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18943

06/09/2010 16:23:05
mbam-log-2010-09-06 (16-23-05).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 408589
Time elapsed: 1 hour(s), 47 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.164.77,93.188.166.227 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{33413700-ec02-4156-8f0c-f779f23b47ef}\NameServer (Trojan.DNSChanger) -> Data: 93.188.164.77,93.188.166.227 -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Raymond\Documents\Azureus Downloads\Applications\mIRC.v6.34.Incl.KeyGen.and.Server.Patch-F4CG\f4123501\f4cg\keygen.exe (Backdoor.GF) -> Quarantined and deleted successfully.
C:\Users\Raymond\Documents\Azureus Downloads\Applications\mIRC.v6.34.Incl.KeyGen.and.Server.Patch-F4CG\f4123501\f4cg\patch.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully.

The problem with running this fix is that it wipes my DNS server settings and of course makes my internet connection non-functional. I was using OpenDNS servers which are the ones listed in the registry values that MBAM isn't too keen on. I can swap back to my ISP provided DNS servers for now though. Access to updates for spybot and MBAM are still unobtainable with these DNS servers though.

Edit: seemingly I actually can obtain the updates for spybot and MBAM since changing back to my ISP-issued DNS servers and also visit their respective websites as well, so that's progress. I'll double check that those DNS servers that MBAM doesn't like the look of are actually OpenDNS servers or if they've been changed without my permission.

Also If I get time to run MBAM with the update before you log on again, I will provide and updated log for it.

Edit2: According to my info the DNS servers that MBAM flagged-up are NOT the OpenDNS servers that I had originally entered so they've been changed without my permission. I am now using my ISP provided DNS servers for the duration of this case.

Apologies for making this thread a bit muddled, and once again many thanks for your continued support.

MalwareBytes has (coincidentally) just this minute finished running. This is it's log after the most recent update that I have now been able to obtain (reboot pending).

Thanks for your help once again, and I'll stick with this thread until any further tests have been conducted.

Internet Explorer 8.0.6001.18943

06/09/2010 21:15:19
mbam-log-2010-09-06 (21-15-19).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 426982
Time elapsed: 1 hour(s), 53 minute(s), 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Raymond\Desktop\HSS-1.43-install-anchorfree-76-conduit.exe (Adware.Anchorfree) -> Quarantined and deleted successfully.
C:\_OTL\MovedFiles\09062010_141731\C_Users\Raymond\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\userinit.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
Sorry for the short delay,

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ComboFix 10-09-07.01 - Raymond 08/09/2010 11:52:48.1.4 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3069.2218 [GMT 1:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\%appdata% . ((((((((((((((((((((((((( Files Created from 2010-08-08 to 2010-09-08 ))))))))))))))))))))))))))))))) . 2010-09-06 13:28 . 2010-09-06 13:28 ——– d—–w- c:\users\Raymond\AppData\Roaming\Malwarebytes 2010-09-06 13:28 . 2010-09-06 13:28 ——– d—–w- c:\programdata\Malwarebytes 2010-09-06 13:28 . 2010-04-29 14:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-09-06 13:28 . 2010-09-06 13:28 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-09-06 13:28 . 2010-04-29 14:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-09-06 13:17 . 2010-09-06 13:17 ——– d—–w- C:\_OTL 2010-09-03 11:23 . 2010-09-03 21:36 ——– d—–w- c:\users\Raymond\AppData\Roaming\HPAppData 2010-08-31 11:06 . 2010-08-31 11:06 ——– d—–w- c:\program files\SquareEnix 2010-08-11 15:39 . 2010-06-08 17:35 3600768 —-a-w- c:\windows\system32\ntkrnlpa.exe 2010-08-11 15:39 . 2010-06-08 17:35 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe 2010-08-11 15:39 . 2010-06-18 15:04 302080 —-a-w- c:\windows\system32\drivers\srv.sys 2010-08-11 15:39 . 2010-06-18 15:04 144896 —-a-w- c:\windows\system32\drivers\srv2.sys 2010-08-11 15:39 . 2010-06-11 16:15 1248768 —-a-w- c:\windows\system32\msxml3.dll 2010-08-11 15:39 . 2010-06-16 16:04 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-09-08 11:02 . 2008-01-19 18:01 ——– d—–w- c:\programdata\NVIDIA 2010-09-08 11:02 . 2010-05-11 09:32 70161 —-a-w- c:\programdata\nvModes.dat 2010-09-08 11:01 . 2008-01-10 17:36 12 —-a-w- c:\windows\bthservsdp.dat 2010-09-06 16:29 . 2008-07-03 09:00 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2010-09-06 16:28 . 2008-07-03 09:00 ——– d—–w- c:\program files\Spybot - Search & Destroy 2010-09-06 15:28 . 2009-08-08 13:17 ——– d—–w- c:\users\Raymond\AppData\Roaming\NoNameScript4.22 2010-09-06 15:28 . 2008-01-19 15:36 ——– d—–w- c:\program files\mIRC 2010-09-03 21:38 . 2009-11-06 21:51 ——– d—–w- c:\users\Raymond\AppData\Roaming\PacificPoker 2010-09-03 21:37 . 2009-11-06 21:50 ——– d—–w- c:\program files\PacificPoker 2010-09-03 17:18 . 2008-06-06 20:44 16384 —-a-w- c:\windows\system32\drivers\nsiproxy.sys 2010-09-02 22:00 . 2008-03-16 19:43 ——– d—–w- c:\users\Raymond\AppData\Roaming\Azureus 2010-09-02 21:22 . 2010-02-14 20:09 ——– d—–w- c:\users\Raymond\AppData\Roaming\vlc 2010-09-02 20:24 . 2010-09-02 20:24 348160 —-a-w- c:\users\Raymond\AppData\Roaming\Azureus\updates\inst_1\msvcr71.dll 2010-09-02 20:24 . 2010-09-02 20:24 199616 —-a-w- c:\users\Raymond\AppData\Roaming\Azureus\updates\inst_1\AzureusUpdater.exe 2010-09-02 20:24 . 2010-09-02 20:24 78272 —-a-w- c:\users\Raymond\AppData\Roaming\Azureus\updates\inst_1\aereg.dll 2010-09-02 20:24 . 2010-09-02 20:24 227328 —-a-w- c:\users\Raymond\AppData\Roaming\Azureus\updates\inst_1\Azureus.exe 2010-09-01 17:27 . 2008-06-06 20:47 57400 —-a-w- c:\windows\system32\drivers\mountmgr.sys 2010-08-31 16:53 . 2009-07-19 13:26 ——– d—–w- c:\users\Raymond\AppData\Roaming\Winamp 2010-08-31 16:42 . 2008-01-19 15:48 ——– d—–w- c:\program files\Winamp 2010-08-31 16:41 . 2010-05-20 18:43 ——– d—–w- c:\program files\Winamp Detect 2010-08-31 11:06 . 2008-01-10 17:37 ——– d–h–w- c:\program files\InstallShield Installation Information 2010-08-31 09:18 . 2010-07-17 11:34 ——– d—–w- c:\programdata\avg9 2010-08-27 10:10 . 2008-01-10 17:37 ——– d—–w- c:\program files\Common Files\Java 2010-08-27 10:09 . 2008-01-10 17:37 ——– d—–w- c:\program files\Java 2010-08-16 11:32 . 2008-01-19 13:58 ——– d—–w- c:\program files\Opera 2010-08-12 07:44 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail 2010-08-10 20:51 . 2008-03-16 19:42 ——– d—–w- c:\program files\Azureus 2010-07-27 16:16 . 2008-01-27 17:20 ——– d—–w- c:\program files\Steam 2010-07-27 09:48 . 2009-03-13 20:11 ——– d—–w- c:\program files\CCleaner 2010-07-17 11:37 . 2010-07-17 11:37 12536 —-a-w- c:\windows\system32\avgrsstx.dll 2010-07-17 11:37 . 2010-07-17 11:37 243024 —-a-w- c:\windows\system32\drivers\avgtdix.sys 2010-07-17 11:37 . 2010-07-17 11:37 216400 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2010-07-17 11:37 . 2010-07-17 11:37 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys 2010-07-17 11:34 . 2010-07-17 11:34 ——– d—–w- c:\program files\AVG 2010-07-17 10:09 . 2010-07-17 10:09 ——– d—–w- c:\programdata\COMODO 2010-07-17 10:07 . 2008-07-04 09:01 ——– d—–w- c:\program files\COMODO 2010-07-17 10:06 . 2010-07-17 10:06 ——– d—–w- c:\programdata\Comodo Downloader 2010-07-17 04:00 . 2010-04-28 09:53 423656 —-a-w- c:\windows\system32\deployJava1.dll 2010-07-09 17:10 . 2010-07-09 17:10 655360 —-a-w- c:\users\Raymond\AppData\Roaming\Spotify\Gracenote\gnsdk_sdkmanager.dll 2010-07-09 17:10 . 2010-07-09 17:10 282624 —-a-w- c:\users\Raymond\AppData\Roaming\Spotify\Gracenote\gnsdk_musicid_file.dll 2010-07-09 17:10 . 2010-07-09 17:10 208896 —-a-w- c:\users\Raymond\AppData\Roaming\Spotify\Gracenote\gnsdk_dsp.dll 2010-06-27 21:25 . 2010-06-27 21:15 224605 —-a-w- c:\windows\rFactor Data Acquisition Plugin Uninstaller.exe 2010-06-26 06:05 . 2010-08-11 15:40 916480 —-a-w- c:\windows\system32\wininet.dll 2010-06-26 06:02 . 2010-08-11 15:40 71680 —-a-w- c:\windows\system32\iesetup.dll 2010-06-26 06:02 . 2010-08-11 15:40 109056 —-a-w- c:\windows\system32\iesysprep.dll 2010-06-26 04:25 . 2010-08-11 15:40 133632 —-a-w- c:\windows\system32\ieUnatt.exe 2010-06-21 13:37 . 2010-08-11 15:40 2037760 —-a-w- c:\windows\system32\win32k.sys 2010-06-18 17:31 . 2010-08-11 15:40 36864 —-a-w- c:\windows\system32\rtutils.dll 2010-06-11 16:16 . 2010-08-11 15:40 274944 —-a-w- c:\windows\system32\schannel.dll 2008-01-11 01:22 . 2008-01-11 01:13 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}] 2009-04-02 11:47 333192 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "SetPoint"="c:\program files\Logitech\SetPoint\SetPoint.EXE" [2009-07-20 813584] "NMSSupport"="c:\program files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" [2007-06-27 439512] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-26 178712] "CCUTRAYICON"="c:\program files\Intel\IntelDH\CCU\CCU_TrayIcon.exe" [2007-06-27 215256] "RivaTunerStartupDaemon"="c:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe" [2009-08-22 24576] "VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2008-08-06 233576] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824] "CTxfiHlp"="CTXFIHLP.EXE" [2009-06-03 25600] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208] "AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-17 2065760] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-07-12 74752] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CtxfiReg"="CTXFIREG.exe" [2009-06-03 47104] c:\users\Raymond\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768] Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-1-19 450560] Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-3-4 813584] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\avgrsstx.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^Users^Raymond^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk] path=c:\users\Raymond\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk backup=c:\windows\pss\MagicDisc.lnk.Startup backupExtension=.Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2008-01-11 21:16 39792 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount] 2009-03-17 11:21 4608 —-a-w- c:\program files\Alcohol Soft\Alcohol 120\AxCmd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] 2007-08-03 12:51 202024 —-a-w- c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp] 2009-06-03 19:19 25600 —-a-w- c:\windows\System32\Ctxfihlp.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter] 2007-05-25 06:03 17920 —-a-w- c:\dell\E-Center\EULALauncher.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan] 2007-08-08 09:25 1828136 —-a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] 2007-03-01 15:57 153136 —-a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler] 2008-04-04 10:38 88584 —-a-w- c:\program files\Logitech\Gaming Software\LWEMon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] 2009-03-14 18:12 198160 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] 2008-01-19 07:38 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000001 "VistaSp2"=hex(B):c9,b7,8d,88,1b,40,ca,01 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2567757336-1158460955-345887290-1001] "EnableNotificationsRef"=dword:00000001 R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2009-09-05 79360] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-09-05 79360] R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2009-06-03 171032] R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2009-06-03 1324056] R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2009-06-03 72728] R3 DHTRACE;Intel® DHTrace Controller;c:\program files\Common Files\Intel\IntelDH\bin\DHTraceController.exe [2007-06-27 39640] R3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [x] R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys [2010-01-15 48128] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-09-23 3429200] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2008-07-11 717296] S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-07-17 216400] S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-07-17 243024] S2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [2009-04-02 464264] S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [2009-04-02 234888] S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-07-21 921952] S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-07-17 308136] S2 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO livePCsupport\CLPSLS.exe [2010-02-19 148744] S2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2007-02-12 208896] S2 NMSCore;Intel® NMSCore;c:\program files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe [2007-06-27 317656] S2 nmsunidr;UniDriver for NMS;c:\windows\system32\DRIVERS\nmsunidr.sys [2007-02-18 5376] S2 QualityManager;Intel® Quality Manager;c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe [2007-06-27 272600] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-06-07 240232] S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2009-06-03 171032] S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2009-06-03 1324056] S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2009-06-03 72728] S3 IntelDH;IntelDH Driver;c:\windows\system32\Drivers\IntelDH.sys [2008-01-10 5632] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder 2010-09-08 c:\windows\Tasks\User_Feed_Synchronization-{93953CBA-97BA-4141-BC3B-ECBC94AD33E9}.job - c:\windows\system32\msfeedssync.exe [2010-08-11 04:24] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ TCP: {33413700-EC02-4156-8F0C-F779F23B47EF} = 87.194.255.154,87.194.255.155 Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll FF - ProfilePath - c:\users\Raymond\AppData\Roaming\Mozilla\Firefox\Profiles\8k93p5qj.default\ FF - prefs.js: browser.startup.homepage - www.yahoo.com FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll FF - plugin: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ —- FIREFOX POLICIES —- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); . - - - - ORPHANS REMOVED - - - - SafeBoot-klmdb.sys MSConfigStartUp-dscactivate - c:\program files\Dell Support Center\gs_agent\custom\dsca.exe MSConfigStartUp-Google Update - c:\users\Raymond\AppData\Local\Google\Update\GoogleUpdate.exe MSConfigStartUp-igndlm - c:\program files\Download Manager\DLM.exe MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe AddRemove-Octoshape add-in for Adobe Flash Player - c:\users\Raymond\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe ************************************************************************** scanning hidden processes … scanning hidden autostart entries … HKLM\Software\Microsoft\Windows\CurrentVersion\Run CTxfiHlp = CTXFIHLP.EXE? scanning hidden files … scan completed successfully hidden files: ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'Explorer.exe'(5948) c:\program files\Logitech\SetPoint\GameHook.dll c:\program files\Logitech\SetPoint\lgscroll.dll c:\program files\Microsoft Virtual PC\VPCShExH.DLL . ———————— Other Running Processes ———————— . c:\windows\system32\nvvsvc.exe c:\program files\Creative\Shared Files\CTAudSvc.exe c:\windows\system32\nvvsvc.exe c:\windows\system32\WUDFHost.exe c:\program files\Intel\IntelDH\CCU\AlertService.exe c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe c:\program files\AVG\AVG9\avgtray.exe c:\windows\ehome\ehmsas.exe c:\program files\Intel\IntelDH\CCU\CCU_Engine.exe c:\windows\system32\PnkBstrA.exe c:\windows\system32\PnkBstrB.exe c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe c:\windows\system32\WUDFHost.exe c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe c:\program files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe c:\program files\AVG\AVG9\avgnsx.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\program files\AVG\AVG9\avgrsx.exe c:\program files\AVG\AVG9\avgchsvx.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\SYSTEM32\CTXFISPI.EXE c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe c:\program files\HP\Digital Imaging\bin\hpqbam08.exe c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe c:\windows\servicing\TrustedInstaller.exe . ************************************************************************** . Completion time: 2010-09-08 12:11:16 - machine was rebooted ComboFix-quarantined-files.txt 2010-09-08 11:11 Pre-Run: 244,793,577,472 bytes free Post-Run: 246,690,721,792 bytes free - - End Of File - - 623C9311CE2284DED09FEF477E45DCB8
Hi TheDoctor46,

Please work your way through the following:


Step 1

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply


In your next reply please include:
  • The Kaspersky log.
  • How is your PC running?
Cheers :thumbup:
——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Friday, September 10, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Friday, September 10, 2010 00:41:36 Records in database: 4209209 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ Scan statistics: Objects scanned: 291427 Threats found: 5 Infected objects found: 8 Suspicious objects found: 0 Scan duration: 07:22:13 File name / Threat / Threats count winampa.exe\winampa.exe/winampa.exe\winampa.exe Infected: Worm.Win32.Qvod.anx 1 C:\Program Files\mIRC\backups\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 1 C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1 C:\Program Files\mIRC\mirc.exe.BAK Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1 C:\Users\Raymond\Documents\Azureus Downloads\Applications\mIRC.v6.34.Incl.KeyGen.and.Server.Patch-F4CG\f4123501\f4cg\setup.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1 C:\Users\Raymond\Documents\Azureus Downloads\Applications\mIRC.v6.34.Incl.KeyGen.and.Server.Patch-F4CG\f4123501.zip Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1 C:\Users\Raymond\Music\copy over\essentials\daemon4091-x86.exe Infected: not-a-virus:WebToolbar.Win32.WhenU.a 1 C:\Users\Raymond\Music\copy over\essentials\mirc621.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 1 Selected area has been scanned. The computer is running fine. Since the problem with Google links redirecting was fixed, and the DNS servers that had been changed without my authorisation had been set back to what they should have been, I'm not getting any unusual behaviour and don't have any reason to suspect anything malicious of being active on the system anymore.
Hi TheDoctor46,

Just a little left to do:

Step 1

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Files
    C:\Users\Raymond\Documents\Azureus Downloads\Applications\mIRC.v6.34.Incl.KeyGen.and.Server.Patch-F4CG
    c:\winampa.exe /s
    
    :Commands
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the log from OTL presented after to Reboot.
All processes killed ========== FILES ========== C:\Users\Raymond\Documents\Azureus Downloads\Applications\mIRC.v6.34.Incl.KeyGen.and.Server.Patch-F4CG\f4123501\f4cg folder moved successfully. C:\Users\Raymond\Documents\Azureus Downloads\Applications\mIRC.v6.34.Incl.KeyGen.and.Server.Patch-F4CG\f4123501 folder moved successfully. C:\Users\Raymond\Documents\Azureus Downloads\Applications\mIRC.v6.34.Incl.KeyGen.and.Server.Patch-F4CG folder moved successfully. c:\Program Files\Winamp\winampa.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: IUSR_NMPR ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes User: Raymond ->Temp folder emptied: 125146676 bytes ->Temporary Internet Files folder emptied: 1285436 bytes ->Java cache emptied: 3145270 bytes ->FireFox cache emptied: 82263862 bytes ->Google Chrome cache emptied: 0 bytes ->Opera cache emptied: 0 bytes ->Flash cache emptied: 5687 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2354750 bytes Error loading Shell32.dll! Cannot empty RecycleBin. RecycleBin emptied: 1067199 bytes Total Files Cleaned = 205.00 mb OTL by OldTimer - Version 3.2.11.0 log created on 09112010_104231 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Hi TheDoctor46,

Update Adobe Reader
You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Old version goes here first. Be sure to move any PDF documents to another folder first though.


The following procedure will implement some cleanup procedures. It will also reset your System Restore by flushing out previous restore points (which contain the infections) and create a new restore point.

Uninstall ComboFix:

  • push the "windows key" + "R" (between the "Ctrl" button and "Alt" Button)
  • please copy and past the following into the box ComboFix /Uninstall and click OK.
  • Note the space between the X and the /Uninstall, it needs to be there.
  • [external image: Posted Image]


CleanUp with OTL
  • Make sure you have an Internet Connection.
  • Double-click OTL.exe to run it. (Vista users, please right click on OTL.exe and select "Run as an Administrator")
  • Click on the CleanUp! button
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTL to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You should be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


Make your Internet Explorer more secure:

  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialise and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    Next press the Apply button and then the OK to exit the Internet Properties page.

Turn On Automatic Updates:

Turn On Automatic Updates
1. Click Start, click Run, type sysdm.cpl, and then press ENTER.
2. Click the Automatic Updates tab, and then click to select one of the following options. We recommend that you select the Automatic (recommended) Automatically download recommended updates for my computer and install them

If you click this setting, click to select the day and time for scheduled updates to occur. You can schedule Automatic Updates for any time of day. Remember, your computer must be on at the scheduled time for updates to be installed. After you set this option, Windows recognizes when you are online and uses your Internet connection to find updates on the Windows Update Web site or on the Microsoft Update Web site that apply to your computer. Updates are downloaded automatically in the background, and you are not notified or interrupted during this process. An icon appears in the notification area of your taskbar when the updates are being downloaded. You can point to the icon to view the download status. To pause or to resume the download, right-click the icon, and then click Pause or Resume. When the download is completed, another message appears in the notification area so that you can review the updates that are scheduled for installation. If you choose not to install at that time, Windows starts the installation on your set schedule.

or visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Antispyware programs:

I would recommend the download and installation of some or all of the following programs (all free), and the updating of them regularly:

  • WinPatrol As a robust security monitor, WinPatrol will alert you to hijackings, malware attacks and critical changes made to your computer without your permission. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge.
  • Spyware Blaster - By altering your registry, this program stops harmful sites from installing things like ActiveX Controls on your machines.
  • Malwarebytes' Anti-Malware - Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is
    totally free but for real-time protection you will have to pay a small one-time fee. We used this to help clean your computer and recommend keeping it and using often.


Please read this great article by miekiemoes How to prevent Malware
and this great article by Tony Klein So How Did I Get Infected In First Place



Best wishes!

-NightWizard

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI