This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser redirect

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I live in a share house and we have a comunal laptop to do all things internet on. When i moved in the laptop had a number of viruses on it. I installed Malwarebites and Avast! which both removed a couple of problems. Now when i scan with them they say the computer is clear but…… my browser searches get redirected. when i search for somthing in google i get a list of results, but when i click on any of them it redirects to some random page. the page it redirects to changes depending on the search topic of the original search.

I am stumped.

below is the log i got using OTL:

Log 1:

OTL logfile created on: 6/04/2011 6:45:06 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\fodd\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220.29 Gb Total Space | 41.46 Gb Free Space | 18.82% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.73 Gb Free Space | 57.28% Space Free | Partition Type: NTFS
Drive E: | 2.81 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive G: | 1397.26 Gb Total Space | 770.81 Gb Free Space | 55.17% Space Free | Partition Type: NTFS

Computer Name: HOTH | User Name: fodd | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\fodd\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\fodd\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\AVAST Software\Avast\snxhk.dll (AVAST Software)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (RTL8023xp) – C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (OEM02Dev) – C:\Windows\System32\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (OEM02Vfx) – C:\Windows\System32\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E0 96 BB 6A 5F 7E CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "Google Powered Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms}"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/04/03 20:48:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/23 20:05:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/23 20:05:51 | 000,000,000 | —D | M]

[2010/11/07 19:40:14 | 000,000,000 | -H-D | M] (No name found) – C:\Users\fodd\AppData\Roaming\Mozilla\Extensions
[2011/04/04 20:55:03 | 000,000,000 | —D | M] (No name found) – C:\Users\fodd\AppData\Roaming\Mozilla\Firefox\Profiles\uccirord.default\extensions
[2010/11/08 15:53:03 | 000,000,903 | -H– | M] () – C:\Users\fodd\AppData\Roaming\Mozilla\Firefox\Profiles\uccirord.default\searchplugins\conduit.xml
[2010/11/08 17:24:37 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/11/08 17:24:37 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/11/08 17:24:10 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/03/10 13:10:09 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2011/03/10 13:10:09 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2011/03/10 13:10:09 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2011/03/10 13:10:09 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/04/30 13:56:09 | 000,001,798 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 125.252.224.90
O1 - Hosts: 127.0.0.1 125.252.224.91
O1 - Hosts: 127.0.0.1 hl2rcv.adobe.com
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 07:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{5c863e3e-ee3f-11df-a365-001d0939d3f5}\Shell - "" = AutoRun
O33 - MountPoints2\{5c863e3e-ee3f-11df-a365-001d0939d3f5}\Shell\AutoRun\command - "" = H:\autorun.exe
O33 - MountPoints2\{5c863e3e-ee3f-11df-a365-001d0939d3f5}\Shell\directx\command - "" = H:\DirectX9\dxsetup.exe
O33 - MountPoints2\{5c863e3e-ee3f-11df-a365-001d0939d3f5}\Shell\setup\command - "" = H:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: VIDC.ACDV - ACDV.dll File not found
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()


========== Files/Folders - Created Within 30 Days ==========

[2011/04/06 18:42:39 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\fodd\Desktop\OTL.exe
[2011/04/06 09:38:11 | 000,000,000 | -H-D | C] – C:\Windows\AxInstSV
[2011/04/06 06:24:42 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2011/04/03 20:48:48 | 000,301,528 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2011/04/03 20:48:48 | 000,019,544 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2011/04/03 20:48:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2011/04/03 20:48:44 | 000,025,432 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2011/04/03 20:48:42 | 000,049,240 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2011/04/03 20:48:39 | 000,371,544 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2011/04/03 20:48:31 | 000,053,592 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2011/04/03 20:48:05 | 000,040,648 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2011/04/03 20:48:02 | 000,190,016 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2011/04/03 20:47:56 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2011/04/03 20:47:56 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2011/04/03 20:28:58 | 000,000,000 | —D | C] – C:\Users\fodd\AppData\Roaming\Malwarebytes
[2011/04/03 20:28:54 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/04/03 20:28:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/03 20:28:54 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/04/03 20:28:51 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/03 20:19:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/04/03 20:19:30 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2011/04/03 17:33:57 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2011/03/30 20:36:21 | 000,000,000 | —D | C] – C:\Users\fodd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Repair
[2011/03/30 11:43:02 | 000,000,000 | —D | C] – C:\Users\fodd\Desktop\outfall29mar
[2011/03/23 01:22:20 | 000,000,000 | -H-D | C] – C:\Users\fodd\AppData\Local\{9D80DB5F-BF67-4DED-9F17-A21888A80F65}
[2011/03/22 13:22:07 | 000,000,000 | -H-D | C] – C:\Users\fodd\AppData\Local\{F61A12D9-5FF1-467F-9B3E-ED4FEC9E28D1}
[2011/03/21 18:07:29 | 000,000,000 | —D | C] – C:\Windows\en
[2011/03/21 18:05:49 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2011/03/21 18:04:48 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2011/03/21 18:04:09 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2011/03/21 18:03:13 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_5.dll
[2011/03/21 18:03:13 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_3.dll
[2011/03/21 18:03:11 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_42.dll
[2011/03/21 18:02:44 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_32.dll
[2011/03/21 18:01:52 | 002,983,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbon.dll
[2011/03/21 18:01:52 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbonRes.dll
[2011/03/21 17:53:09 | 000,000,000 | -H-D | C] – C:\Users\fodd\AppData\Local\Windows Live
[2011/03/21 17:53:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2011/03/20 18:17:49 | 000,000,000 | —D | C] – C:\Users\fodd\Desktop\Beacon20mar
[2011/03/19 15:05:06 | 000,000,000 | —D | C] – C:\Users\fodd\Desktop\schanck19mar
[2011/03/16 15:38:45 | 000,000,000 | -H-D | C] – C:\Users\fodd\dwhelper
[2011/03/13 09:52:44 | 000,000,000 | —D | C] – C:\Users\fodd\Desktop\Meanos13mar
[2011/03/09 17:33:51 | 001,074,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/09 17:33:51 | 000,739,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2011/03/09 17:33:45 | 000,850,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/03/09 17:33:45 | 000,642,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CPFilters.dll
[2011/03/09 17:33:45 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/03/09 17:33:45 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2010/11/03 20:33:35 | 000,695,296 | —- | C] (AnjoCaido) – C:\Users\fodd\AppData\Roaming\MinecraftSP.exe

========== Files - Modified Within 30 Days ==========

[2011/04/06 18:46:54 | 000,359,929 | —- | M] () – C:\Users\fodd\Desktop\dds.scr
[2011/04/06 18:43:04 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\fodd\Desktop\OTL.exe
[2011/04/06 10:42:27 | 000,020,576 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/06 10:42:27 | 000,020,576 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/06 06:31:13 | 000,628,460 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/04/06 06:31:13 | 000,110,612 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/06 06:24:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/06 06:24:36 | 1508,376,576 | -HS- | M] () – C:\hiberfil.sys
[2011/04/03 20:48:48 | 000,002,000 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/04/03 20:48:31 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2011/04/03 20:46:05 | 062,623,864 | —- | M] () – C:\Users\fodd\Desktop\setup_av_free.exe
[2011/04/03 20:28:54 | 000,001,073 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/31 16:59:36 | 000,005,120 | —- | M] () – C:\Users\fodd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/30 20:38:35 | 000,000,392 | —- | M] () – C:\ProgramData\31186696
[2011/03/30 20:36:34 | 000,000,136 | —- | M] () – C:\ProgramData\~31186696
[2011/03/30 20:36:33 | 000,000,152 | —- | M] () – C:\ProgramData\~31186696r

========== Files Created - No Company Name ==========

[2011/04/06 18:46:35 | 000,359,929 | —- | C] () – C:\Users\fodd\Desktop\dds.scr
[2011/04/03 20:48:48 | 000,002,000 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/04/03 20:44:53 | 062,623,864 | —- | C] () – C:\Users\fodd\Desktop\setup_av_free.exe
[2011/04/03 20:28:54 | 000,001,073 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/30 20:36:33 | 000,000,152 | —- | C] () – C:\ProgramData\~31186696r
[2011/03/30 20:36:32 | 000,000,136 | —- | C] () – C:\ProgramData\~31186696
[2011/03/30 20:36:20 | 000,000,392 | —- | C] () – C:\ProgramData\31186696
[2011/03/21 18:06:55 | 000,001,253 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2011/03/21 18:06:08 | 000,001,322 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2011/02/13 11:23:43 | 000,005,120 | —- | C] () – C:\Users\fodd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/14 12:10:57 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/11/08 17:47:37 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/11/08 17:13:13 | 000,093,671 | —- | C] () – C:\Users\fodd\AppData\Roaming\Uninstal.exe
[2009/07/14 14:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 14:33:53 | 000,266,808 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 12:05:48 | 000,628,460 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 12:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 12:05:48 | 000,110,612 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 12:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 12:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 12:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 10:19:49 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/07/14 09:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 09:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 09:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/11 07:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2008/12/01 19:46:12 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2008/12/01 19:08:40 | 003,107,788 | —- | C] () – C:\Windows\System32\atiumdva.dat
[2008/10/30 13:45:42 | 000,180,720 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2005/05/06 18:06:00 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll

========== LOP Check ==========

[2011/04/01 08:20:33 | 000,000,000 | —D | M] – C:\Users\fodd\AppData\Roaming\.minecraft
[2010/11/12 18:16:39 | 000,000,000 | -H-D | M] – C:\Users\fodd\AppData\Roaming\ACD Systems
[2011/04/06 15:46:18 | 000,000,000 | —D | M] – C:\Users\fodd\AppData\Roaming\Azureus
[2010/11/12 19:31:40 | 000,000,000 | -H-D | M] – C:\Users\fodd\AppData\Roaming\DAEMON Tools Lite
[2010/11/12 19:46:08 | 000,000,000 | -H-D | M] – C:\Users\fodd\AppData\Roaming\Sony
[2011/02/15 15:57:07 | 000,000,000 | -H-D | M] – C:\Users\fodd\AppData\Roaming\TuneUpMedia
[2009/07/14 14:53:46 | 000,011,932 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/11 07:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/07/14 11:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/11/08 14:01:04 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/11 07:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2008/03/31 21:44:18 | 000,004,483 | RH– | M] () – C:\dell.sdr
[2010/12/12 16:02:37 | 000,203,836 | RHS- | M] () – C:\grldr
[2011/04/06 06:24:36 | 1508,376,576 | -HS- | M] () – C:\hiberfil.sys
[2010/02/13 15:58:19 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/02/13 15:58:19 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/03/17 21:51:46 | 000,000,801 | -H– | M] () – C:\os604495.bin
[2011/04/06 06:24:38 | 2011,172,864 | -HS- | M] () – C:\pagefile.sys
[2010/07/18 10:05:01 | 000,000,072 | —- | M] () – C:\SNDUpgrade.log
[2010/12/12 16:02:38 | 000,000,000 | RHS- | M] () – C:\winx.ld

< %systemroot%\Fonts\*.com >
[2009/07/14 14:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 14:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 14:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 14:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/11 07:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 11:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/14 11:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/02/24 02:04:21 | 000,040,648 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 14:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/11/07 19:37:35 | 000,000,221 | -HS- | M] () – C:\Users\fodd\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/04/06 18:43:04 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\fodd\Desktop\OTL.exe
[2011/04/03 20:46:05 | 062,623,864 | —- | M] () – C:\Users\fodd\Desktop\setup_av_free.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-06 00:39:06

< End of report >

Log 2:

OTL Extras logfile created on: 6/04/2011 6:45:06 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\fodd\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220.29 Gb Total Space | 41.46 Gb Free Space | 18.82% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.73 Gb Free Space | 57.28% Space Free | Partition Type: NTFS
Drive E: | 2.81 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive G: | 1397.26 Gb Total Space | 770.81 Gb Free Space | 55.17% Space Free | Partition Type: NTFS

Computer Name: HOTH | User Name: fodd | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDSee Photo Manager 12.Manage] – "C:\Program Files\ACD Systems\ACDSee\12.0\ACDSeeQV12.exe" "%1" (ACD Systems International Inc.)
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{56415658-366E-4E28-A6BD-68EC63E560E0}" = Vegas Pro 9.0
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A5CBD7C5-CF16-443F-A4F2-3503C9DE311B}" = ACDSee Photo Manager 12
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"conduitEngine" = Conduit Engine
"Creative OEM002" = Laptop Integrated Webcam Driver (1.04.01.1011)
"ffdshow_is1" = ffdshow v1.1.3562 [2010-09-07]
"InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Minecraft 1.2.0_02" = Minecraft 1.2.0_02
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"TuneUpMedia" = TuneUp Companion 1.9.0
"VLC media player" = VLC media player 1.1.4
"Vuze_Remote Toolbar" = Vuze Remote Toolbar
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 20/03/2011 3:52:22 AM | Computer Name = Hoth | Source = Application Error | ID = 1000
Description = Faulting application name: DevDetect.exe, version: 5.1.237.0, time
stamp: 0x4bb54196 Faulting module name: KERNELBASE.dll, version: 6.1.7600.16385,
time stamp: 0x4a5bdaae Exception code: 0xc000008c Fault offset: 0x00009617 Faulting
process id: 0xd90 Faulting application start time: 0x01cbded09cbb32fd Faulting application
path: C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe Faulting module
path: C:\Windows\system32\KERNELBASE.dll Report Id: fc0bac04-52c6-11e0-a562-001d0939d3f5

Error - 21/03/2011 4:02:07 AM | Computer Name = Hoth | Source = Application Hang | ID = 1002
Description = The program wmplayer.exe version 12.0.7600.16667 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 10ec Start
Time: 01cbe79d1dbb2ba1 Termination Time: 12 Application Path: C:\Program Files\Windows
Media Player\wmplayer.exe Report Id: 7d72158e-5391-11e0-a562-001d0939d3f5

Error - 21/03/2011 10:09:40 AM | Computer Name = Hoth | Source = Application Error | ID = 1000
Description = Faulting application name: wmpnetwk.exe, version: 12.0.7600.16385,
time stamp: 0x4a5bccb3 Faulting module name: KERNELBASE.dll, version: 6.1.7600.16385,
time stamp: 0x4a5bdaae Exception code: 0x0000046b Fault offset: 0x00009617 Faulting
process id: 0x980 Faulting application start time: 0x01cbde760c2a245e Faulting application
path: C:\Program Files\Windows Media Player\wmpnetwk.exe Faulting module path: C:\Windows\system32\KERNELBASE.dll
Report
Id: dc1be636-53c4-11e0-a562-001d0939d3f5

Error - 23/03/2011 11:45:18 PM | Computer Name = Hoth | Source = EventSystem | ID = 4621
Description =

Error - 30/03/2011 6:39:59 AM | Computer Name = Hoth | Source = EventSystem | ID = 4621
Description =

Error - 31/03/2011 2:59:41 AM | Computer Name = Hoth | Source = Application Error | ID = 1000
Description = Faulting application name: ACDSee12.exe, version: 12.0.344.0, time
stamp: 0x4bd8b413 Faulting module name: ntdll.dll, version: 6.1.7600.16695, time
stamp: 0x4cc7ab44 Exception code: 0xc0000005 Fault offset: 0x0002fa7b Faulting process
id: 0x91c Faulting application start time: 0x01cbef712ab2fd7d Faulting application
path: C:\Program Files\ACD Systems\ACDSee\12.0\ACDSee12.exe Faulting module path:
C:\Windows\SYSTEM32\ntdll.dll Report Id: 72d3fc67-5b64-11e0-9d36-001d0939d3f5

Error - 31/03/2011 2:59:46 AM | Computer Name = Hoth | Source = Application Error | ID = 1000
Description = Faulting application name: ACDSee12.exe, version: 12.0.344.0, time
stamp: 0x4bd8b413 Faulting module name: ntdll.dll, version: 6.1.7600.16695, time
stamp: 0x4cc7ab44 Exception code: 0xc0150010 Fault offset: 0x000817ff Faulting process
id: 0x91c Faulting application start time: 0x01cbef712ab2fd7d Faulting application
path: C:\Program Files\ACD Systems\ACDSee\12.0\ACDSee12.exe Faulting module path:
C:\Windows\SYSTEM32\ntdll.dll Report Id: 75de3a8c-5b64-11e0-9d36-001d0939d3f5

Error - 3/04/2011 8:14:46 AM | Computer Name = Hoth | Source = EventSystem | ID = 4621
Description =

Error - 4/04/2011 4:37:22 AM | Computer Name = Hoth | Source = Application Error | ID = 1000
Description = Faulting application name: 0.10262949141378142.exe, version: 0.0.0.0,
time stamp: 0x49b02529 Faulting module name: ntdll.dll, version: 6.1.7600.16695,
time stamp: 0x4cc7ab44 Exception code: 0xc0000005 Fault offset: 0x00061b7f Faulting
process id: 0xa7c Faulting application start time: 0x01cbf2a37fb463fc Faulting application
path: C:\Users\fodd\AppData\Local\Temp\0.10262949141378142.exe Faulting module path:
C:\Windows\SYSTEM32\ntdll.dll Report Id: c1f64f43-5e96-11e0-84dd-001d0939d3f5

Error - 5/04/2011 8:00:25 AM | Computer Name = Hoth | Source = Application Hang | ID = 1002
Description = The program Explorer.EXE version 6.1.7600.16450 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: a7c Start
Time: 01cbf34398692a31 Termination Time: 448 Application Path: C:\Windows\Explorer.EXE

Report
Id: fd924228-5f7b-11e0-a769-001d0939d3f5

[ Media Center Events ]
Error - 25/12/2010 5:38:55 AM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 8:38:45 PM - Error connecting to the internet. 8:38:51 PM - Unable
to contact server..

Error - 25/12/2010 6:39:01 AM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 9:39:01 PM - Error connecting to the internet. 9:39:01 PM - Unable
to contact server..

Error - 25/12/2010 6:39:07 AM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 9:39:06 PM - Error connecting to the internet. 9:39:06 PM - Unable
to contact server..

Error - 25/12/2010 7:39:11 AM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 10:39:11 PM - Error connecting to the internet. 10:39:11 PM - Unable
to contact server..

Error - 25/12/2010 7:39:18 AM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 10:39:16 PM - Error connecting to the internet. 10:39:16 PM - Unable
to contact server..

Error - 26/12/2010 7:20:47 PM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 10:20:47 AM - Error connecting to the internet. 10:20:47 AM - Unable
to contact server..

Error - 26/12/2010 7:21:04 PM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 10:20:52 AM - Error connecting to the internet. 10:20:52 AM - Unable
to contact server..

Error - 5/01/2011 3:37:22 PM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 6:37:12 AM - Failed to retrieve MCEClientUX (Error: Unable to connect
to the remote server)

Error - 9/01/2011 3:47:52 PM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 6:47:52 AM - Failed to retrieve Directory (Error: Unable to connect
to the remote server)

Error - 10/01/2011 3:11:57 PM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 6:11:52 AM - Failed to retrieve Broadband (Error: Unable to connect
to the remote server)

[ System Events ]
Error - 5/04/2011 7:51:34 AM | Computer Name = Hoth | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 5/04/2011 7:51:35 AM | Computer Name = Hoth | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 5/04/2011 8:56:57 AM | Computer Name = Hoth | Source = NetBT | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the computer that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.

Error - 5/04/2011 8:57:27 AM | Computer Name = Hoth | Source = NetBT | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the computer that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.

Error - 5/04/2011 4:24:46 PM | Computer Name = Hoth | Source = EventLog | ID = 6008
Description = The previous system shutdown at 1:11:21 AM on ?6/?04/?2011 was unexpected.

Error - 5/04/2011 4:24:47 PM | Computer Name = HOTH | Source = BugCheck | ID = 1001
Description =

Error - 5/04/2011 4:26:05 PM | Computer Name = Hoth | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Media Player Network Sharing Service service to connect.

Error - 5/04/2011 4:26:05 PM | Computer Name = Hoth | Source = Service Control Manager | ID = 7000
Description = The Windows Media Player Network Sharing Service service failed to
start due to the following error: %%1053

Error - 6/04/2011 1:53:28 AM | Computer Name = Hoth | Source = NetBT | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the computer that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.

Error - 6/04/2011 2:07:17 AM | Computer Name = Hoth | Source = NetBT | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the computer that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.


< End of report >


I hope someone can help. It is driving me crazy.

thanks

Joe.
Hi,


Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds file to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop. Post them back to your topic.
Thanks for the reply… Here are the logs as instructed. . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 21:18:47.42 on Thu 07/04/2011 Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.61.1033.18.1918.1025 [GMT 10:00] . AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\Ati2evxx.exe C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\OEM02Mon.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\DllHost.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Common Files\Java\Java Update\jucheck.exe C:\Windows\system32\taskmgr.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\fodd\Desktop\dds.com C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\tbVuze.dll mURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\tbVuze.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\tbVuze.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\tbVuze.dll TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10l_Plugin.exe -update plugin mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\fodd\appdata\roaming\mozilla\firefox\profiles\uccirord.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms} FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} . ============= SERVICES / DRIVERS =============== . R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-4-3 371544] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-4-3 301528] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-4-3 19544] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-4-3 53592] R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-4-3 42184] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-14 207360] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-14 980992] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-14 661504] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-11-9 1343400] . =============== Created Last 30 ================ . 2011-04-06 00:38:43 6792528 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{b1dec377-4df5-4c57-b88f-9f374dc5b6e4}\mpengine.dll 2011-04-05 23:38:11 ——– d–h–w- c:\windows\AxInstSV 2011-04-03 10:48:39 371544 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2011-04-03 10:48:31 53592 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2011-04-03 10:48:05 40648 —-a-w- c:\windows\avastSS.scr 2011-04-03 10:47:56 ——– d—–w- c:\program files\AVAST Software 2011-04-03 10:47:56 ——– d—–w- c:\progra~2\AVAST Software 2011-04-03 10:28:58 ——– d—–w- c:\users\fodd\appdata\roaming\Malwarebytes 2011-04-03 10:28:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-04-03 10:28:54 ——– d—–w- c:\progra~2\Malwarebytes 2011-04-03 10:28:51 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-04-03 10:19:30 ——– d—–w- c:\program files\CCleaner 2011-04-03 07:33:57 ——– d—–w- c:\progra~2\MFAData 2011-03-22 15:22:20 ——– d–h–w- c:\users\fodd\appdata\local\{9D80DB5F-BF67-4DED-9F17-A21888A80F65} 2011-03-22 03:22:07 ——– d–h–w- c:\users\fodd\appdata\local\{F61A12D9-5FF1-467F-9B3E-ED4FEC9E28D1} 2011-03-21 08:07:29 ——– d—–w- c:\windows\en 2011-03-21 08:05:49 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition 2011-03-21 08:04:48 ——– d—–w- c:\windows\PCHEALTH 2011-03-21 08:03:13 69464 —-a-w- c:\windows\system32\XAPOFX1_3.dll 2011-03-21 08:03:13 515416 —-a-w- c:\windows\system32\XAudio2_5.dll 2011-03-21 08:03:11 453456 —-a-w- c:\windows\system32\d3dx10_42.dll 2011-03-21 08:02:44 3426072 —-a-w- c:\windows\system32\d3dx9_32.dll 2011-03-21 08:01:52 2983424 —-a-w- c:\windows\system32\UIRibbon.dll 2011-03-21 08:01:52 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll 2011-03-21 07:56:37 525656 —-a-w- c:\program files\common files\windows live\.cache\7391d8b41cbe79d05\DXSETUP.exe 2011-03-21 07:56:36 1691480 —-a-w- c:\program files\common files\windows live\.cache\7391d8b41cbe79d05\dsetup32.dll 2011-03-21 07:56:35 94040 —-a-w- c:\program files\common files\windows live\.cache\7391d8b41cbe79d05\DSETUP.dll 2011-03-21 07:55:12 525656 —-a-w- c:\program files\common files\windows live\.cache\4156ae9a1cbe79d04\DXSETUP.exe 2011-03-21 07:55:06 1691480 —-a-w- c:\program files\common files\windows live\.cache\4156ae9a1cbe79d04\dsetup32.dll 2011-03-21 07:54:58 94040 —-a-w- c:\program files\common files\windows live\.cache\4156ae9a1cbe79d04\DSETUP.dll 2011-03-21 07:53:09 ——– d–h–w- c:\users\fodd\appdata\local\Windows Live 2011-03-21 07:53:07 ——– d—–w- c:\program files\common files\Windows Live 2011-03-16 05:38:45 ——– d–h–w- c:\users\fodd\dwhelper 2011-03-09 07:33:51 802304 —-a-w- c:\windows\system32\FntCache.dll 2011-03-09 07:33:51 739840 —-a-w- c:\windows\system32\d2d1.dll 2011-03-09 07:33:51 1074176 —-a-w- c:\windows\system32\DWrite.dll 2011-03-09 07:33:45 850432 —-a-w- c:\windows\system32\sbe.dll 2011-03-09 07:33:45 642048 —-a-w- c:\windows\system32\CPFilters.dll 2011-03-09 07:33:45 534528 —-a-w- c:\windows\system32\EncDec.dll 2011-03-09 07:33:45 199680 —-a-w- c:\windows\system32\mpg2splt.ax 2011-03-09 07:33:37 2690560 —-a-w- c:\windows\system32\mstscax.dll 2011-03-09 07:33:37 1034240 —-a-w- c:\windows\system32\mstsc.exe . ==================== Find3M ==================== . 2011-02-02 07:11:20 222080 ——w- c:\windows\system32\MpSigStub.exe . ============= FINISH: 21:20:13.78 ===============

Attachments:

Hi,

Vuze

Above listed ones are P2P file sharing programs. P2P downloads are nowadays one of those things that most likely bring infection into the system. My recommendation is to uninstall these (and other if present) P2P file sharing programs.


1. Download TDSSKiller and extract its contents into a folder in desired location (i.e. c:\tdsskiller).
2. Execute the file TDSSKiller.exe.
3. Click Start Scan. If threats are found, select cure and click Continue (tool may prompt for a reboot).
4. Post back contents of log file in c: drive root (name should be in UtilityName.Version_Date_Time_log.txt format)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI