This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

pup.casino infection

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been getting notices of my e-mail account sending out messages to all of my contacts. Twice I've run malwarebytes and had it clean out the pup.casino virus but it keeps re-establishing itself. I also cannot access the internet through I.E, I have to use google chrome to get access.
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.


Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleanerยป
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Next:


Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step

Next:

Note: if the Cure option is not there, please select 'Skip'.

Please read carefully and follow these steps.




Also please describe how your computer behaves at the moment.
I did as you asked, the tds skiller didn't detect anything and it also didn't produce a log. Neither program requested a reboot. Here is the log from Goored Fix GooredFix by jpshortstuff (03.07.10.1) Log created at 16:44 on 01/03/2011 (Bryan) Firefox version 3.6.13 (en-US) ========== GooredScan ========== ========== GooredLog ========== C:\Program Files (x86)\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [05:37 14/12/2010] {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [00:51 23/02/2011] C:\Users\Bryan\Application Data\Mozilla\Firefox\Profiles\qci6f7wd.default\extensions\ {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} [05:04 24/08/2010] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] (Key not found) -=E.O.F=- I will go ahead and do a reboot and check to see if the infections still come up on the scan from Online Armor++. Is there another scanning tool that might find the same things as Online Armor did? I don't know how to capture the screen shot of the scan results from Online Arm or++. If you need to see the results of the scan I will have to do it again, but please tell me how to post that scan result to this thread.
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have XP SP3, use the XP SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you โ€“ please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
I don't know whats going on here. I ran combofix but when it got to the finish and rebooted it didn't produce a log. When the computer did reboot and the command prompt came back up it showed unable to access three times then went off and didn't make a log. Before the tool finished though an error box came up that said "Unable to enable VBScript". One good thing is that I can now enable and use Internet Explorer once again. Please let me know what I should do next. Thank You for all your help.
I don't know whats going on here. I ran combofix but when it got to the finish and rebooted it didn't produce a log. When the computer did reboot and the command prompt came back up it showed unable to access three times then went off and didn't make a log. Before the tool finished though an error box came up that said "Unable to enable VBScript". One good thing is that I can now enable and use Internet Explorer once again. Please let me know what I should do next. Thank You for all your help.
If you still get this error: "Unable to enable VBScript".

If you're using Vista or Win7


Open an elevated Command Prompt to register the module vbscript.dll. To open an elevated Command Prompt, click Start, click All Programs, click Accessories, right-click Command Prompt, and then click Run as administrator.

Type the following in the Command Prompt window:

regsvr32 vbscript.dll

Press ENTER

If XP:

Open Command Prompt to register the module vbscript.dll. To open a Command Prompt, click Start, Run, type in CMD and Press ENTER

Type the following in the Command Prompt window:

regsvr32 vbscript.dll <โ€“Note any spaces

Press ENTER
Alright, I ran Combofix once again, even though it took an exceptionally long time to run and I kept getting prompts to approve certain programs related to combofix to run even after the reboot it finally produced a log. Yes it still showed denied access and the vbscript error. I have done as you asked and enabled the vbscripting engine. Heres the log file: ComboFix 11-02-28.07 - Bryan 03/01/2011 18:27:24.2.2 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3839.2323 [GMT -8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} AV: Online Armor ++ *Disabled/Updated* {607A6E45-BE50-AFD5-4F70-7EAAEC5B715D} AV: Returnil System Safe 2011 *Disabled/Updated* {B1F99400-BE58-E5B3-88CF-FB21D431A392} FW: Online Armor Firewall *Disabled* {5841EF60-F43F-AE8D-642F-D79F12883626} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Online Armor ++ *Disabled/Updated* {DB1B8FA1-986A-A05B-75C0-45D897DC3BE0} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . โ€”- Previous Run โ€”โ€”- . c:\users\Ashanthe\Desktop\Internet Explorer.lnk c:\windows\system32\drivers\etc\lmhosts . ((((((((((((((((((((((((( Files Created from 2011-02-02 to 2011-03-02 ))))))))))))))))))))))))))))))) . 2011-03-02 02:35 . 2011-03-02 02:35 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Zanthia\AppData\Local\temp 2011-03-02 02:35 . 2011-03-02 02:35 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Zanthia.Family\AppData\Local\temp 2011-03-02 02:35 . 2011-03-02 02:35 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Default\AppData\Local\temp 2011-03-02 02:35 . 2011-03-02 02:35 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Daniel\AppData\Local\temp 2011-03-02 02:35 . 2011-03-02 02:35 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Daniel.Family\AppData\Local\temp 2011-03-02 02:35 . 2011-03-02 02:35 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Betty\AppData\Local\temp 2011-03-02 02:35 . 2011-03-02 02:35 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Ashanthe\AppData\Local\temp 2011-03-02 01:56 . 2011-02-11 07:30 7947600 โ€”-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{44879CA6-8641-46E2-A631-B9D1B4DBBC44}\mpengine.dll 2011-03-02 00:48 . 2011-03-02 00:48 92248 โ€”-a-w- c:\windows\system32\drivers\klmd.sys 2011-03-01 19:20 . 2011-03-01 19:20 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Zanthia.Family\AppData\Local\Mozilla 2011-02-25 22:21 . 2011-02-25 22:21 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\launcher 2011-02-25 22:04 . 2011-01-21 22:52 37456 โ€”-a-w- c:\windows\system32\drivers\hotcore3.sys 2011-02-25 01:43 . 2011-02-25 01:45 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\MasqueGames 2011-02-24 20:06 . 2011-01-17 06:12 320512 โ€”-a-w- c:\windows\system32\d3d10_1core.dll 2011-02-24 20:06 . 2011-01-17 06:12 197120 โ€”-a-w- c:\windows\system32\d3d10_1.dll 2011-02-24 20:06 . 2011-01-17 05:30 218624 โ€”-a-w- c:\windows\SysWow64\d3d10_1core.dll 2011-02-24 20:06 . 2011-01-17 05:30 161792 โ€”-a-w- c:\windows\SysWow64\d3d10_1.dll 2011-02-24 03:59 . 2011-02-24 03:59 388096 โ€”-a-r- c:\users\Bryan\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-02-24 02:34 . 2011-02-24 02:34 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Prevx 2011-02-24 02:32 . 2011-02-24 02:37 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\PrevxCSI 2011-02-24 01:05 . 2010-05-26 18:39 6144 โ€”โ€”w- c:\windows\system32\7114.tmp 2011-02-24 01:04 . 2010-05-26 18:39 6144 โ€”โ€”w- c:\windows\system32\8178.tmp 2011-02-23 22:58 . 2011-02-23 22:58 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Bryan\AppData\Roaming\SUPERAntiSpyware.com 2011-02-23 22:58 . 2011-02-23 22:58 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\!SASCORE 2011-02-23 00:51 . 2011-02-23 00:51 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Common Files\Java 2011-02-23 00:51 . 2011-02-23 00:51 472808 โ€”-a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll 2011-02-23 00:51 . 2011-02-23 00:51 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Java 2011-02-23 00:47 . 2011-02-23 00:47 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Java 2011-02-21 06:56 . 2011-02-21 06:56 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Zanthia.Family\AppData\Local\JollyBear 2011-02-21 06:56 . 2011-02-21 06:56 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\JollyBear 2011-02-21 05:18 . 2011-02-21 05:35 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Zanthia.Family\AppData\Roaming\Flood Light Games 2011-02-21 05:18 . 2011-02-21 05:35 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Flood Light Games 2011-02-21 04:21 . 2011-02-21 04:22 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Zanthia.Family\AppData\Roaming\Mystery of Mortlake Mansion 2011-02-17 21:14 . 2010-12-21 06:13 2003968 โ€”-a-w- c:\windows\system32\msxml6.dll 2011-02-12 20:52 . 2011-02-12 20:52 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Common Files\CA Shared 2011-02-12 01:09 . 2010-12-21 06:16 214016 โ€”-a-w- c:\windows\system32\winsrv.dll 2011-02-12 01:09 . 2011-01-26 06:53 982912 โ€”-a-w- c:\windows\system32\drivers\dxgkrnl.sys 2011-02-12 01:09 . 2011-01-26 06:53 265088 โ€”-a-w- c:\windows\system32\drivers\dxgmms1.sys 2011-02-12 01:09 . 2011-01-26 06:31 144384 โ€”-a-w- c:\windows\system32\cdd.dll 2011-02-12 01:09 . 2010-12-18 06:11 714752 โ€”-a-w- c:\windows\system32\kerberos.dll 2011-02-12 01:09 . 2010-12-18 05:29 541184 โ€”-a-w- c:\windows\SysWow64\kerberos.dll 2011-02-12 01:09 . 2011-01-05 04:00 3127808 โ€”-a-w- c:\windows\system32\win32k.sys 2011-02-12 01:08 . 2010-10-27 05:18 5510528 โ€”-a-w- c:\windows\system32\ntoskrnl.exe 2011-02-12 01:08 . 2010-10-27 05:16 1739176 โ€”-a-w- c:\windows\system32\ntdll.dll 2011-02-12 01:08 . 2010-10-27 04:43 3901824 โ€”-a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-02-12 01:08 . 2010-10-27 04:43 3957120 โ€”-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-02-12 01:08 . 2010-10-27 04:40 1293120 โ€”-a-w- c:\windows\SysWow64\ntdll.dll 2011-02-12 01:08 . 2011-01-07 08:06 46080 โ€”-a-w- c:\windows\system32\atmlib.dll 2011-02-12 01:08 . 2011-01-07 07:27 34304 โ€”-a-w- c:\windows\SysWow64\atmlib.dll 2011-02-12 01:08 . 2011-01-07 05:49 366080 โ€”-a-w- c:\windows\system32\atmfd.dll 2011-02-12 01:08 . 2011-01-07 05:33 294400 โ€”-a-w- c:\windows\SysWow64\atmfd.dll 2011-02-10 10:28 . 2011-02-10 10:28 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\GameHouse 2011-02-10 10:26 . 2011-02-10 10:26 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Trymedia 2011-02-10 10:26 . 2011-02-10 10:26 โ€”โ€”โ€“ dโ€”โ€“w- C:\GameHouse Games 2011-02-10 10:26 . 2011-02-10 10:26 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Zylom 2011-02-10 10:24 . 2011-02-10 10:24 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\RealArcade 2011-02-01 08:59 . 2011-02-22 06:59 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Bryan\AppData\Roaming\Absolute Poker 2011-02-01 08:58 . 2011-02-01 08:59 โ€”โ€”โ€“ dโ€”โ€“w- C:\Poker Application . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-02-24 02:34 . 2010-06-18 04:39 62976 โ€”-a-w- c:\windows\SysWow64\PxSecure.dll 2011-02-24 02:34 . 2010-06-18 04:39 36384 โ€”-a-w- c:\windows\system32\drivers\pxscan.sys 2011-02-24 02:34 . 2010-06-18 04:39 65736 โ€”-a-w- c:\windows\system32\drivers\pxrts.sys 2011-02-24 02:34 . 2010-06-18 04:39 24024 โ€”-a-w- c:\windows\system32\drivers\pxkbf.sys 2011-02-23 00:51 . 2010-05-02 22:10 472808 โ€”-a-w- c:\windows\SysWow64\deployJava1.dll 2011-02-23 00:47 . 2010-07-26 21:02 521448 โ€”-a-w- c:\windows\system32\deployJava1.dll 2011-02-11 07:30 . 2010-09-12 02:02 7947600 โ€”-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-01-21 22:52 . 2011-01-21 22:52 249936 โ€”-a-w- c:\windows\SysWow64\prgiso.dll 2011-01-21 22:52 . 2011-01-21 22:52 53840 โ€”-a-w- c:\windows\system32\drivers\uimx64.sys 2011-01-21 22:52 . 2011-01-21 22:52 528464 โ€”-a-w- c:\windows\system32\drivers\Uim_IMx64.sys 2011-01-21 22:52 . 2011-01-21 22:52 404048 โ€”-a-w- c:\windows\system32\drivers\UimFIO.sys 2011-01-03 14:19 . 2011-01-03 14:20 601424 โ€”โ€”w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EFE444C6-3F7A-4D27-8AB5-D53B758E61FE}\gapaengine.dll 2010-12-25 21:18 . 2010-12-25 21:18 61072 โ€”-a-w- c:\windows\system32\drivers\rvsystem.sys 2010-12-21 02:09 . 2010-05-09 20:26 38224 โ€”-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2010-12-21 02:08 . 2010-05-09 20:26 24152 โ€”-a-w- c:\windows\system32\drivers\mbam.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{fe337d7b-1447-4780-9a52-48bdac438235}"= "c:\program files (x86)\Maps_Bar\tbMaps.dll" [2010-11-29 3908192] [HKEY_CLASSES_ROOT\clsid\{fe337d7b-1447-4780-9a52-48bdac438235}] [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{fe337d7b-1447-4780-9a52-48bdac438235}] 2010-11-29 23:26 3908192 โ€”-a-w- c:\program files (x86)\Maps_Bar\tbMaps.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{fe337d7b-1447-4780-9a52-48bdac438235}"= "c:\program files (x86)\Maps_Bar\tbMaps.dll" [2010-11-29 3908192] [HKEY_CLASSES_ROOT\clsid\{fe337d7b-1447-4780-9a52-48bdac438235}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072] "RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2010-05-07 0] "OpenDNS Updater"="c:\program files (x86)\OpenDNS Updater\OpenDNSUpdater.exe" [2010-06-16 839680] "HostsServer"="c:\program files (x86)\HostsMan\hostssrv.exe" [2010-02-06 1930240] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-09-15 39408] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Google Desktop Search"="c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" [2010-05-28 30192] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2010-12-21 291896] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~2\Google\GOOGLE~3\GoogleDesktopNetwork3.dll [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 CSIScanner;CSIScanner;c:\users\Bryan\prevx.exe [x] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 136176] R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [2010-05-28 30192] R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\7114.tmp [2010-05-26 6144] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 40832] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 72064] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616] R3 nosGetPlusHelper;getPlusยฎ Helper 3004;c:\windows\System32\svchost.exe [2009-07-14 27136] R3 PCGenFam;PCGenFam;c:\windows\system32\DRIVERS\PCGenFAM.sys [2010-11-02 198088] R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2010-04-09 19936] R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2010-04-09 13280] R3 SaiKF622;SaiKF622;c:\windows\system32\DRIVERS\SaiKF622.sys [2009-06-02 140800] R3 VaneFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2007-08-17 30336] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-03 1255736] R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080] S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [2011-01-21 37456] S0 pxscan;pxscan;c:\windows\System32\drivers\pxscan.sys [2011-02-24 36384] S0 RVSystem;RVSystem;c:\windows\system32\Drivers\RVSystem.sys [2010-12-25 61072] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464] S1 OADevice;OADriver;c:\windows\SysWow64\Drivers\OADriver.sys [2010-10-27 54864] S1 oahlpXX;Online Armor helper driver;c:\windows\syswow64\drivers\oahlp64.sys [2010-11-22 54896] S1 OAmon;OAmon;c:\windows\SysWOW64\Drivers\OAmon.sys [2010-11-22 37872] S1 rvsmon;rvsmon;c:\windows\system32\DRIVERS\rvsmon.sys [2010-10-18 165664] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752] S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-08-12 62208] S2 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2011-02-24 65736] S2 RVSMONBL;Returnil System Safe Core Service;c:\program files (x86)\Returnil\RVS3\rvsmon.exe [2010-10-23 1714696] S2 rvsmonf;rvsmonf;c:\windows\system32\DRIVERS\rvsmonf.sys [2010-10-18 1436136] S2 rvsmonn;rvsmonn;c:\windows\system32\DRIVERS\rvsmonn2.sys [2010-10-18 21920] S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2010-12-21 987704] S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2010-12-21 399416] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2009-06-26 83488] S3 OAnet;OnlineArmor Service;c:\windows\system32\DRIVERS\oanet.sys [2010-11-22 32728] S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 17976] S3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [2011-02-24 24024] [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper . Contents of the 'Scheduled Tasks' folder 2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28] 2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28] . โ€”โ€”โ€” x86-64 โ€”โ€”โ€”โ€“ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-07 10144288] "PLD_FrameworkRun"="c:\windows\system32\oem\_NowIntoDT.vbs" [2009-10-11 490] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-22 2327952] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 1436224] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 . โ€”โ€”- Supplementary Scan โ€”โ€”- . uStart Page = hxxp://www.google.com/ uLocal Page = c:\windows\system32\blank.htm uDefault_Search_URL = hxxp://www.google.com/ie mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_x1301&r=17360510s707p0428v1j5w45j1t539 mLocal Page = c:\windows\SysWOW64\blank.htm uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Google Sidewikiโ€ฆ - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html LSP: %SYSTEMROOT%\system32\nvLsp.dll Trusted Zone: absolutebanking.com Trusted Zone: absolutepoker.com\www Trusted Zone: google.com\mail Trusted Zone: google.com\www TCP: {473F86ED-FB55-42E5-8A1F-9FC700C929D6} = 208.67.222.222,208.67.220.220 DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab FF - ProfilePath - c:\users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\qci6f7wd.default\ FF - prefs.js: network.proxy.type - 0 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: CoolPreviews : {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} - %profile%\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} . - - - - ORPHANS REMOVED - - - - ShellIconOverlayIdentifiers-{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} - (no file) SafeBoot-mcmscsvc SafeBoot-MCODS SafeBoot-SolutoService ShellIconOverlayIdentifiers-{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} - (no file) AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_heroes.exe [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MEMSWEEP2] "ImagePath"="\??\c:\windows\system32\7114.tmp" . โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€” [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx" "ThreadingModel"="Apartment" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx" "ThreadingModel"="Apartment" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€” Other Running Processes โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€” . c:\program files (x86)\Online Armor\OAcat.exe c:\program files (x86)\Online Armor\oasrv.exe c:\program files (x86)\Online Armor\a2\AVGate.exe c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files (x86)\Online Armor\oaui.exe c:\program files (x86)\Online Armor\OAhlp.exe . ************************************************************************** . Completion time: 2011-03-01 18:56:02 - machine was rebooted ComboFix-quarantined-files.txt 2011-03-02 02:56 Pre-Run: 645,347,987,456 bytes free Post-Run: 644,964,769,792 bytes free - - End Of File - - 3CEE775B12E0E7B049BC9DA86EA357CA
The first issue you have is having 3 anti-virus programs active:

AV: Microsoft Security Essentials *Disabled/Updated*
AV: Online Armor ++ *Disabled/Updated*
AV: Returnil System Safe 2011 *Disabled/Updated*

Never install more than one Antivirus and Firewall! Rather than giving you extra protection, it will decrease the reliability of it seriously!
The reason for this is that if both products have their automatic (Real-Time) protection switched on, your system may lock up due to both software products attempting to access the same file at the same time.
Also because more than one Antivirus and Firewall installed are not compatible with each other, it can cause system performance problems and a serious system slowdown.

Please do not delete anything unless instructed to.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove 2 of the 3:


Reboot:




After the above:


Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

KillAll::

File::
c:\windows\system32\7114.tmp
c:\windows\system32\8178.tmp

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fe337d7b-1447-4780-9a52-48bdac438235}"=-  
[-HKEY_CLASSES_ROOT\clsid\{fe337d7b-1447-4780-9a52-48bdac438235}]
[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{fe337d7b-1447-4780-9a52-48bdac438235}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{fe337d7b-1447-4780-9a52-48bdac438235}"=- 
[-HKEY_CLASSES_ROOT\clsid\{fe337d7b-1447-4780-9a52-48bdac438235}]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save Asโ€ฆ Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save โ€ฆ


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
Even though I got the VBScript enabled just as you showed me when the combofix ran it still came up with the same error about vbscript being unavailable. Everything else went fine and heres the log you wanted to see. ComboFix 11-02-28.07 - Bryan 03/02/2011 9:26.3.2 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3839.2599 [GMT -8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Bryan\Desktop\CFScript.txt AV: Online Armor ++ *Enabled/Updated* {607A6E45-BE50-AFD5-4F70-7EAAEC5B715D} FW: Online Armor Firewall *Enabled* {5841EF60-F43F-AE8D-642F-D79F12883626} SP: Online Armor ++ *Enabled/Updated* {DB1B8FA1-986A-A05B-75C0-45D897DC3BE0} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FILE :: "c:\windows\system32\7114.tmp" "c:\windows\system32\8178.tmp" . ((((((((((((((((((((((((( Files Created from 2011-02-02 to 2011-03-02 ))))))))))))))))))))))))))))))) . 2011-03-02 17:31 . 2011-03-02 17:31 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Zanthia\AppData\Local\temp 2011-03-02 17:31 . 2011-03-02 17:31 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Zanthia.Family\AppData\Local\temp 2011-03-02 17:31 . 2011-03-02 17:31 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Default\AppData\Local\temp 2011-03-02 17:31 . 2011-03-02 17:31 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Daniel\AppData\Local\temp 2011-03-02 17:31 . 2011-03-02 17:31 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Daniel.Family\AppData\Local\temp 2011-03-02 17:31 . 2011-03-02 17:31 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Betty\AppData\Local\temp 2011-03-02 17:31 . 2011-03-02 17:31 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Ashanthe\AppData\Local\temp 2011-03-02 17:31 . 2011-03-02 17:31 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Administrator\AppData\Local\temp 2011-03-02 03:11 . 2010-09-14 06:45 367104 โ€”-a-w- c:\windows\system32\wcncsvc.dll 2011-03-02 03:11 . 2010-09-14 06:07 276992 โ€”-a-w- c:\windows\SysWow64\wcncsvc.dll 2011-03-02 03:10 . 2011-01-07 08:07 662528 โ€”-a-w- c:\windows\system32\XpsPrint.dll 2011-03-02 03:10 . 2011-01-07 08:07 475648 โ€”-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-03-02 03:10 . 2011-01-07 07:31 442880 โ€”-a-w- c:\windows\SysWow64\XpsPrint.dll 2011-03-02 03:10 . 2011-01-07 07:31 288256 โ€”-a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2011-03-02 02:56 . 2011-03-02 18:18 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Bryan\AppData\Local\temp 2011-03-02 00:48 . 2011-03-02 00:48 92248 โ€”-a-w- c:\windows\system32\drivers\klmd.sys 2011-03-01 19:20 . 2011-03-01 19:20 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Zanthia.Family\AppData\Local\Mozilla 2011-02-25 22:21 . 2011-02-25 22:21 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\launcher 2011-02-25 22:04 . 2011-01-21 22:52 37456 โ€”-a-w- c:\windows\system32\drivers\hotcore3.sys 2011-02-25 01:43 . 2011-02-25 01:45 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\MasqueGames 2011-02-24 20:06 . 2011-01-17 06:12 320512 โ€”-a-w- c:\windows\system32\d3d10_1core.dll 2011-02-24 20:06 . 2011-01-17 06:12 197120 โ€”-a-w- c:\windows\system32\d3d10_1.dll 2011-02-24 20:06 . 2011-01-17 05:30 218624 โ€”-a-w- c:\windows\SysWow64\d3d10_1core.dll 2011-02-24 20:06 . 2011-01-17 05:30 161792 โ€”-a-w- c:\windows\SysWow64\d3d10_1.dll 2011-02-24 03:59 . 2011-02-24 03:59 388096 โ€”-a-r- c:\users\Bryan\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-02-24 02:34 . 2011-02-24 02:34 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Prevx 2011-02-24 02:32 . 2011-02-24 02:37 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\PrevxCSI 2011-02-24 01:05 . 2010-05-26 18:39 6144 โ€”โ€”w- c:\windows\system32\7114.tmp 2011-02-24 01:04 . 2010-05-26 18:39 6144 โ€”โ€”w- c:\windows\system32\8178.tmp 2011-02-23 22:58 . 2011-02-23 22:58 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Bryan\AppData\Roaming\SUPERAntiSpyware.com 2011-02-23 22:58 . 2011-02-23 22:58 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\!SASCORE 2011-02-23 00:51 . 2011-02-23 00:51 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Common Files\Java 2011-02-23 00:51 . 2011-02-23 00:51 472808 โ€”-a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll 2011-02-23 00:51 . 2011-02-23 00:51 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Java 2011-02-23 00:47 . 2011-02-23 00:47 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Java 2011-02-21 06:56 . 2011-02-21 06:56 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Zanthia.Family\AppData\Local\JollyBear 2011-02-21 06:56 . 2011-02-21 06:56 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\JollyBear 2011-02-21 05:18 . 2011-02-21 05:35 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Zanthia.Family\AppData\Roaming\Flood Light Games 2011-02-21 05:18 . 2011-02-21 05:35 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Flood Light Games 2011-02-21 04:21 . 2011-02-21 04:22 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Zanthia.Family\AppData\Roaming\Mystery of Mortlake Mansion 2011-02-17 21:14 . 2010-12-21 06:13 2003968 โ€”-a-w- c:\windows\system32\msxml6.dll 2011-02-12 20:52 . 2011-02-12 20:52 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Common Files\CA Shared 2011-02-12 01:09 . 2010-12-21 06:16 214016 โ€”-a-w- c:\windows\system32\winsrv.dll 2011-02-12 01:09 . 2011-01-26 06:53 982912 โ€”-a-w- c:\windows\system32\drivers\dxgkrnl.sys 2011-02-12 01:09 . 2011-01-26 06:53 265088 โ€”-a-w- c:\windows\system32\drivers\dxgmms1.sys 2011-02-12 01:09 . 2011-01-26 06:31 144384 โ€”-a-w- c:\windows\system32\cdd.dll 2011-02-12 01:09 . 2010-12-18 06:11 714752 โ€”-a-w- c:\windows\system32\kerberos.dll 2011-02-12 01:09 . 2010-12-18 05:29 541184 โ€”-a-w- c:\windows\SysWow64\kerberos.dll 2011-02-12 01:09 . 2011-01-05 04:00 3127808 โ€”-a-w- c:\windows\system32\win32k.sys 2011-02-12 01:08 . 2010-10-27 05:18 5510528 โ€”-a-w- c:\windows\system32\ntoskrnl.exe 2011-02-12 01:08 . 2010-10-27 05:16 1739176 โ€”-a-w- c:\windows\system32\ntdll.dll 2011-02-12 01:08 . 2010-10-27 04:43 3901824 โ€”-a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-02-12 01:08 . 2010-10-27 04:43 3957120 โ€”-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-02-12 01:08 . 2010-10-27 04:40 1293120 โ€”-a-w- c:\windows\SysWow64\ntdll.dll 2011-02-12 01:08 . 2011-01-07 08:06 46080 โ€”-a-w- c:\windows\system32\atmlib.dll 2011-02-12 01:08 . 2011-01-07 07:27 34304 โ€”-a-w- c:\windows\SysWow64\atmlib.dll 2011-02-12 01:08 . 2011-01-07 05:49 366080 โ€”-a-w- c:\windows\system32\atmfd.dll 2011-02-12 01:08 . 2011-01-07 05:33 294400 โ€”-a-w- c:\windows\SysWow64\atmfd.dll 2011-02-10 10:28 . 2011-02-10 10:28 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\GameHouse 2011-02-10 10:26 . 2011-02-10 10:26 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Trymedia 2011-02-10 10:26 . 2011-02-10 10:26 โ€”โ€”โ€“ dโ€”โ€“w- C:\GameHouse Games 2011-02-10 10:26 . 2011-02-10 10:26 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Zylom 2011-02-10 10:24 . 2011-02-10 10:24 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\RealArcade 2011-02-01 08:59 . 2011-02-22 06:59 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Bryan\AppData\Roaming\Absolute Poker 2011-02-01 08:58 . 2011-02-01 08:59 โ€”โ€”โ€“ dโ€”โ€“w- C:\Poker Application . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-02-24 02:34 . 2010-06-18 04:39 62976 โ€”-a-w- c:\windows\SysWow64\PxSecure.dll 2011-02-24 02:34 . 2010-06-18 04:39 36384 โ€”-a-w- c:\windows\system32\drivers\pxscan.sys 2011-02-24 02:34 . 2010-06-18 04:39 65736 โ€”-a-w- c:\windows\system32\drivers\pxrts.sys 2011-02-24 02:34 . 2010-06-18 04:39 24024 โ€”-a-w- c:\windows\system32\drivers\pxkbf.sys 2011-02-23 00:51 . 2010-05-02 22:10 472808 โ€”-a-w- c:\windows\SysWow64\deployJava1.dll 2011-02-23 00:47 . 2010-07-26 21:02 521448 โ€”-a-w- c:\windows\system32\deployJava1.dll 2011-01-21 22:52 . 2011-01-21 22:52 249936 โ€”-a-w- c:\windows\SysWow64\prgiso.dll 2011-01-21 22:52 . 2011-01-21 22:52 53840 โ€”-a-w- c:\windows\system32\drivers\uimx64.sys 2011-01-21 22:52 . 2011-01-21 22:52 528464 โ€”-a-w- c:\windows\system32\drivers\Uim_IMx64.sys 2011-01-21 22:52 . 2011-01-21 22:52 404048 โ€”-a-w- c:\windows\system32\drivers\UimFIO.sys 2010-12-21 02:09 . 2010-05-09 20:26 38224 โ€”-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2010-12-21 02:08 . 2010-05-09 20:26 24152 โ€”-a-w- c:\windows\system32\drivers\mbam.sys . ((((((((((((((((((((((((((((( SnapShot@2011-03-02_02.38.20 ))))))))))))))))))))))))))))))))))))))))) . - 2009-07-14 04:54 . 2011-03-02 02:36 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2011-03-02 17:33 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2011-03-02 02:36 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-03-02 17:33 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2011-03-02 02:36 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2011-03-02 17:33 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-10-28 05:40 . 2011-03-02 17:23 81112 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin - 2009-07-14 05:10 . 2011-03-02 02:38 56616 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2011-03-02 17:23 56616 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin - 2010-05-02 05:52 . 2011-03-02 02:38 21620 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3488347447-2488368954-518346416-1000_UserData.bin + 2010-05-02 05:52 . 2011-03-02 17:23 21620 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3488347447-2488368954-518346416-1000_UserData.bin - 2006-10-11 03:00 . 2011-03-02 02:38 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2006-10-11 03:00 . 2011-03-02 17:35 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-11-10 23:56 . 2011-03-02 02:38 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2010-11-10 23:56 . 2011-03-02 17:35 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2011-03-02 02:38 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2011-03-02 17:35 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:46 . 2011-03-02 17:20 71344 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat - 2010-05-02 05:34 . 2011-03-02 02:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2010-05-02 05:34 . 2011-03-02 17:33 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-03-02 17:32 . 2011-03-02 17:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-03-02 02:36 . 2011-03-02 02:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-03-02 02:36 . 2011-03-02 02:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-03-02 17:32 . 2011-03-02 17:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2010-05-02 18:13 . 2011-03-02 18:17 365986 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin + 2009-07-14 02:36 . 2011-03-02 17:11 623940 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2011-03-02 17:11 106316 c:\windows\system32\perfc009.dat + 2009-07-14 05:01 . 2011-03-02 17:31 305844 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01 . 2011-03-02 02:35 305844 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 04:45 . 2011-02-25 22:53 3801083 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat + 2009-07-14 04:45 . 2011-03-02 17:01 3801083 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat - 2010-05-03 10:38 . 2011-03-02 02:35 2776444 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3488347447-2488368954-518346416-1000-8192.dat + 2010-05-03 10:38 . 2011-03-02 17:31 2776444 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3488347447-2488368954-518346416-1000-8192.dat - 2010-05-03 10:38 . 2011-03-02 01:07 3267396 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3488347447-2488368954-518346416-1000-12288.dat + 2010-05-03 10:38 . 2011-03-02 17:12 3267396 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3488347447-2488368954-518346416-1000-12288.dat - 2009-07-14 02:34 . 2011-03-02 01:53 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat + 2009-07-14 02:34 . 2011-03-02 17:46 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat + 2010-09-28 22:59 . 2011-03-02 17:20 17280574 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3488347447-2488368954-518346416-1000-4096.dat - 2010-09-28 22:59 . 2011-03-02 02:35 17280574 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3488347447-2488368954-518346416-1000-4096.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072] "RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2010-05-07 0] "OpenDNS Updater"="c:\program files (x86)\OpenDNS Updater\OpenDNSUpdater.exe" [2010-06-16 839680] "HostsServer"="c:\program files (x86)\HostsMan\hostssrv.exe" [2010-02-06 1930240] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-09-15 39408] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Google Desktop Search"="c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" [2010-05-28 30192] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2010-12-21 291896] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~2\Google\GOOGLE~3\GoogleDesktopNetwork3.dll [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 CSIScanner;CSIScanner;c:\users\Bryan\prevx.exe [x] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 136176] R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [2010-05-28 30192] R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\7114.tmp [2010-05-26 6144] R3 nosGetPlusHelper;getPlusยฎ Helper 3004;c:\windows\System32\svchost.exe [2009-07-14 27136] R3 PCGenFam;PCGenFam;c:\windows\system32\DRIVERS\PCGenFAM.sys [2010-11-02 198088] R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2010-04-09 19936] R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2010-04-09 13280] R3 SaiKF622;SaiKF622;c:\windows\system32\DRIVERS\SaiKF622.sys [2009-06-02 140800] R3 VaneFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2007-08-17 30336] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-03 1255736] R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080] S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [2011-01-21 37456] S0 pxscan;pxscan;c:\windows\System32\drivers\pxscan.sys [2011-02-24 36384] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464] S1 OADevice;OADriver;c:\windows\SysWow64\Drivers\OADriver.sys [2010-10-27 54864] S1 oahlpXX;Online Armor helper driver;c:\windows\syswow64\drivers\oahlp64.sys [2010-11-22 54896] S1 OAmon;OAmon;c:\windows\SysWOW64\Drivers\OAmon.sys [2010-11-22 37872] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752] S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-08-12 62208] S2 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2011-02-24 65736] S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2010-12-21 987704] S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2010-12-21 399416] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2009-06-26 83488] S3 OAnet;OnlineArmor Service;c:\windows\system32\DRIVERS\oanet.sys [2010-11-22 32728] S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 17976] S3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [2011-02-24 24024] [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper . Contents of the 'Scheduled Tasks' folder 2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28] 2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28] . โ€”โ€”โ€” x86-64 โ€”โ€”โ€”โ€“ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-07 10144288] "PLD_FrameworkRun"="c:\windows\system32\oem\_NowIntoDT.vbs" [2009-10-11 490] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-22 2327952] . โ€”โ€”- Supplementary Scan โ€”โ€”- . uStart Page = hxxp://www.google.com/ uLocal Page = c:\windows\system32\blank.htm uDefault_Search_URL = hxxp://www.google.com/ie mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_x1301&r=17360510s707p0428v1j5w45j1t539 mLocal Page = c:\windows\SysWOW64\blank.htm uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Google Sidewikiโ€ฆ - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html LSP: %SYSTEMROOT%\system32\nvLsp.dll Trusted Zone: absolutebanking.com Trusted Zone: absolutepoker.com\www Trusted Zone: google.com\mail Trusted Zone: google.com\www TCP: {473F86ED-FB55-42E5-8A1F-9FC700C929D6} = 208.67.222.222,208.67.220.220 DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab FF - ProfilePath - c:\users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\qci6f7wd.default\ FF - prefs.js: network.proxy.type - 0 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: CoolPreviews : {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} - %profile%\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} . - - - - ORPHANS REMOVED - - - - ShellIconOverlayIdentifiers-{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} - (no file) [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MEMSWEEP2] "ImagePath"="\??\c:\windows\system32\7114.tmp" . โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€” [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx" "ThreadingModel"="Apartment" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx" "ThreadingModel"="Apartment" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€” Other Running Processes โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€” . c:\program files (x86)\Online Armor\OAcat.exe c:\program files (x86)\Online Armor\oasrv.exe c:\program files (x86)\Online Armor\a2\AVGate.exe c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files (x86)\Online Armor\oaui.exe c:\program files (x86)\Online Armor\OAhlp.exe . ************************************************************************** . Completion time: 2011-03-02 10:25:48 - machine was rebooted ComboFix-quarantined-files.txt 2011-03-02 18:25 ComboFix2.txt 2011-03-02 02:56 Pre-Run: 644,640,186,368 bytes free Post-Run: 644,588,093,440 bytes free - - End Of File - - CFC03CA21D640282B687D501F22E242F
Hey, I just got back from running some errands. I can't give an assessment just yet but I can now access I.E. and it looks like things are moving quicker than before. If any problems or glitches come up I'll send a request in. I just want to thank you very much for all your help.
I just checked my mail again and it is still showing that my e-mail is still sending out messages. This last one has the time as 3:20pm pst. Which is after we completed running the combofix tool. What else do you need from me to help with this?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI