This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe taking up 100%

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm new here, and I already know this has been posted and answered before, but I don't know if the same processes or fixes will apply to me as well and forgive me if my english is not good, English is not my native tongue I've noticed this new process in my process list named 「PING.EXE」, and it is taking up my CPU more than usual, it's always at 100%, and my PC is running slow I already performed a scan with ESET NOD32 antivirus, it detected a few Trojans and cleaned them, but didn't pick up PING.EXE Help please?
Here are the logs from OTL







OTL Extras logfile created on: 2011/09/17 22:48:04 - Run 1
OTL by OldTimer - Version 3.2.28.0 Folder = C:\Users\Zero\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

2.00 Gb Total Physical Memory | 1.12 Gb Available Physical Memory | 56.15% Memory free
4.00 Gb Paging File | 2.68 Gb Available in Paging File | 67.15% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 59.47 Gb Free Space | 19.95% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 397.94 Gb Free Space | 42.72% Space Free | Partition Type: NTFS
Drive E: | 485.44 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: SYNTHESIZE | User Name: Zero | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Users\Zero\AppData\Roaming\x2l2rlgwhwmvlvrhvfdgzveehzeedv3k2\svcnost.exe" = C:\Users\Zero\AppData\Roaming\x2l2rlgwhwmvlvrhvfdgzveehzeedv3k2\svcnost.exe:*:Enabled:ldrsoft


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F31532A-16F1-4812-8B7B-D321A4CE91A6}" = Sony Vegas Pro 8.0
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{232DB76D-4751-41A9-9EC2-CDC0DAC1FAB6}" = WD SmartWare
"{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = Media Player Classic - Home Cinema v1.4.2499.0
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 26
"{296D8550-CB06-48E4-9A8B-E5034FB64715}" = Command & Conquer™ Red Alert™ 3
"{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}" = Adobe CS4 American English Speech Analysis Models
"{2C0E2B08-0991-43DF-9515-77FA4C5A9DD2}" = Adobe Setup
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{45057FCE-5784-48BE-8176-D9D00AF56C3C}" = ザ・シムズ3レイト・ナイト
"{45dfc589-14eb-4894-8342-4945ab4ec2e9}.sdb" = New Database(1)
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4BC14A37-586A-4AB3-A458-874AAE29337C}" = Adobe Setup
"{4C0C4077-46E5-42A7-A507-6998CDF7FA9A}" = DIVINA
"{4E074808-1B86-4230-A9EB-0904942EC4AE}" = LEGO Star Wars II
"{52E9A798-88C7-4EE6-94D4-2D54FEC8EE52}" = Ragnarok Online
"{54B7A3C7-0940-4C16-A509-FC3C3758D22A}_is1" = Amnesia - The Dark Descent
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5A74371F-993C-4AEF-8EA0-B5A8A9472050}" = Command & Conquer™ Red Alert™ 3 Worldbuilder
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.5
"{5EAD5443-7194-46CC-A055-428E6ABB1BAF}" = Adobe Encore CS4
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{678C5508-D657-43EB-AE80-1C73A723F739}" = Emil Chronicle Online
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A0A1B81-BE93-4A66-83D1-1D6B7C1FD06C}" = PoseStudio
"{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}" = Adobe Flash Player 10 ActiveX
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7406DF60-016D-476B-A2C7-55D997592047}" = Adobe OnLocation CS4
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{85C70286-A56F-4834-BD24-B34EB76A93A2}" = ESET NOD32 Antivirus
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D1A9C55-7055-4E6F-92F0-42BFC2CBB13C}" = Command & Conquer™ Red Alert™ 3 Worldbuilder
"{8E5CFA2B-8CC5-4C8D-88CB-C4A1D4AD9790}_is1" = 東方非想天則 Ver1.10アップデート
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = ザ・シムズ3 アンビション
"{929CE49F-1CA7-4CF3-A9A1-6D757443C63F}" = Microsoft Games for Windows - LIVE Redistributable
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{98248D1E-82CB-423C-8E94-E32B74C1BA73}" = 幼なじみは大統領
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A996B6A-846E-4A89-B9C4-17546B7BE49F}" = Burnout™ Paradise The Ultimate Box
"{9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9}" = Steam Platform [removed] i6
"{9EA5CC76-8B4D-407B-87F4-DB052978D8A7}" = Adobe Setup
"{9EB48D00-99FA-48EC-8458-C354B68468C5}" = PoseStudio
"{A0BCF90F-B4E4-435C-A48D-8FAAE10554F9}" = Pixia
"{A1BC7068-C1BA-410F-8B9A-DB807C803DE2}" = Adobe Creative Suite 5 Design Premium
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9307988-3EA8-415E-A91E-0EB1FBF439DA}" = Adobe After Effects CS4 Third Party Content
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.4
"{AD9E5D61-0EBB-4472-8DA9-359560FB6988}}_is1" = グリーフシンドローム
"{AD9E6AC8-27B4-326A-69D1-C8A3549DAC22}" = Bamboo Dock
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 280.26
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 280.26
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 280.26
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 280.19
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.4.28
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B5F8FCE2-1677-4370-A857-4976E5A95209}" = Topaz Vivacity
"{B5FCBF46-D2DA-455C-8AB1-148181AEBA14}" = Adobe After Effects CS4
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}" = The Sims 3 World Adventures
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims・3
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D45B21D2-1ABA-46C4-A226-722DC28EAAC4}" = Premiere Pro CS4 and After Effects CS4, 32-bit support for CS5
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DDE59617-F59A-473B-BC4E-C2B81F6CD38D}" = Command & Conquer™ Red Alert™ 3 Uprising
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E528A747-DC66-4FD4-AB53-110D024561CC}" = Adobe Premiere Pro CS4
"{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}" = ザ・シムズ3 ジェネレーションズ
"{EC317B1E-FC13-403D-BD0D-B22324DDE414}" = Emil chronicle online
"{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}" = The Sims 3 Fast Lane Stuff
"{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F1181364-95F9-4041-AE79-322831D7DFDF}" = LucentHeart
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FF6C1285-C38A-406C-9A92-81F1909FD62A}" = Emil Chronicle Online
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_0b36ff97a89684768f1da4defc9f237" = Adobe Encore CS4 Codecs
"Adobe_15f4da9bfad48542a17f089e7c5e0ab" = Adobe After Effects CS4 Third Party Content
"Adobe_1b5a11fde44351ae0f4c7fd0e4daadc" = Premiere Pro CS4 and After Effects CS4, 32-bit support for CS5
"Advanced RAR Repair v1.2" = Advanced RAR Repair v1.2
"AhnLab Online Security" = AhnLab Online Security
"Akamai" = Akamai NetSession Interface
"Any Video Converter Professional_is1" = Any Video Converter Professional 2.7.6
"Bamboo Dock" = Bamboo Dock 3.3
"Camfrog 6.0" = Camfrog Video Chat 6.0
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Command_And_Conquer_Yuri's_Revenge_1.001_MPI" = Command And Conquer Red Alert 2 Yuri's Revenge 1.001
"DAEMON Tools Lite" = DAEMON Tools Lite
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"DVD Decrypter" = DVD Decrypter (Remove Only)
"EADM" = EA Download Manager
"EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 7.1.1 Home Edition
"facemoods" = Facemoods Toolbar
"Fraps" = Fraps (remove only)
"Garena Classic 2011" = Garena Classic 2011
"Google Chrome" = Google Chrome
"Hamachi" = Hamachi 1.0.3.0
"HDMI" = Intel® Graphics Media Accelerator Driver
"InstallShield_{4E074808-1B86-4230-A9EB-0904942EC4AE}" = LEGO Star Wars II
"JDownloader" = JDownloader
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.5.3 (Full)
"LibUSB-Win32_is1" = LibUSB-Win32-0.1.10.1
"LimitRO Renewal" = LimitRO Renewal v20110322
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox 6.0.2 (x86 en-US)" = Mozilla Firefox 6.0.2 (x86 en-US)
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"ObjectDock" = ObjectDock
"PaintToolSAI" = ペイントツールSAI Ver.1
"PakkISO_is1" = PakkISO 0.4
"Pen Tablet Driver" = Bamboo
"PowerISO" = PowerISO
"PS3Splitter_is1" = PS3Splitter version 1.1.5.1
"RESIDENT EVIL2" = RESIDENT EVIL2
"RESIDENT EVIL2_is1" = Resident Evil 2
"RocketDock_is1" = RocketDock 1.3.5
"s3pe" = Sims3 Package Editor
"Search Toolbar" = Search Toolbar
"StepMania" = StepMania v5.0 Preview 3 (remove only)
"StepMania CVS" = StepMania CVS 4.0 (remove only)
"TmUnited_is1" = TrackMania United 0.2.0.0
"Trillian" = Trillian
"TS3 Install Helper Monkey" = TS3 Install Helper Monkey
"Unlocker" = Unlocker 1.9.1
"uTorrent" = µTorrent
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1" = Bamboo Dock
"Winamp" = Winamp
"WinGimp-2.0_is1" = GIMP 2.6.6
"WinRAR archiver" = WinRAR archiver
"WolfTeam" = WolfTeam
"Xfire" = Xfire (remove only)
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo!Jツールバー" = Yahoo!ツールバー
"Yuri's Revenge" = Command && Conquer Red Alert 2 - Yuri's Revenge
"中出し孕ませ新薬調査_is1" = 中出し孕ませ新薬調査 1.00
"超次元ゲイム ネプテューヌ EVENT CG" = 超次元ゲイム ネプテューヌ EVENT CGスクリーンセーバー

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"515ccaee7a583465" = ocojyo
"beanfun!" = beanfun!
"uTorrent" = µTorrent
"Winamp Detect" = Winamp アプリケーション検出
"ポリンだま" = ポリンだま

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
OTL logfile created on: 2011/09/17 22:48:04 - Run 1
OTL by OldTimer - Version 3.2.28.0 Folder = C:\Users\Zero\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000411 | Country: 日本 | Language: JPN | Date Format: yyyy/MM/dd

2.00 Gb Total Physical Memory | 1.12 Gb Available Physical Memory | 56.15% Memory free
4.00 Gb Paging File | 2.68 Gb Available in Paging File | 67.15% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 59.47 Gb Free Space | 19.95% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 397.94 Gb Free Space | 42.72% Space Free | Partition Type: NTFS
Drive E: | 485.44 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: SYNTHESIZE | User Name: Zero | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Zero\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files\Bamboo Dock\BambooCore.exe ()
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\audiodg.exe (Microsoft Corporation)
PRC - C:\Program Files\Tablet\Pen\Pen_Tablet.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Tablet\Pen\Pen_TouchUser.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Tablet\Pen\Pen_TabletUser.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Tablet\Pen\Pen_TouchService.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Fraps\fraps.exe (Beepa P/L)
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe (Western Digital)
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (WDC)
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
PRC - D:\Documents - Zero\Rainmeter-1.1-32bit\Rainmeter.exe ()
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
PRC - C:\Windows\System32\PING.EXE (Microsoft Corporation)
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe (Memeo)
PRC - C:\Program Files\RocketDock\RocketDock.exe ()
PRC - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
PRC - C:\Windows\System32\libusbd-nt.exe (http://libusb-win32.sourceforge.net)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\20008c75bb41e2febf84d4d4aea5b4e8\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\1e85062785e286cd9eae9c26d2c61f73\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\da5da08245467818759aa44c4eb948e1\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5cae93d923c8378370758489e5535820\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\a81a3835a5415f299c3b790ecbed8d18\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll ()
MOD - C:\Users\Zero\AppData\Local\Apps\2.0\GJAKV8QA.DJ3\G1RDKATG.YP0\ocoj..tion_f492e7df897d44e3_0001.0000_d27804b587028ece\FastLoad.dll ()
MOD - C:\Program Files\Bamboo Dock\BambooCore.exe ()
MOD - C:\Program Files\Bamboo Dock\BambooWinTab.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Program Files\Tablet\Pen\libxml2.dll ()
MOD - D:\Documents - Zero\Rainmeter-1.1-32bit\Plugins\WindowMessagePlugin.dll ()
MOD - D:\Documents - Zero\Rainmeter-1.1-32bit\Plugins\WebParser.dll ()
MOD - D:\Documents - Zero\Rainmeter-1.1-32bit\Plugins\PowerPlugin.dll ()
MOD - D:\Documents - Zero\Rainmeter-1.1-32bit\Rainmeter.exe ()
MOD - D:\Documents - Zero\Rainmeter-1.1-32bit\Rainmeter.dll ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\Memeo.API.dll ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\sqlite3.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\RocketDock\RocketDock.exe ()
MOD - C:\Program Files\RocketDock\RocketDock.dll ()
MOD - C:\Program Files\Stardock\ObjectDock\DockShellHook.dll ()
MOD - C:\Program Files\Stardock\ObjectDock\zlib.dll ()
MOD - C:\Program Files\Stardock\ObjectDock\CrashRpt.dll ()
MOD - C:\Program Files\Common Files\Stardock\ODimg.dll ()
MOD - C:\Program Files\Stardock\ObjectDock\ODimg.dll ()


========== Win32 Services (SafeList) ==========

SRV - (ayoraa7oogoogoen) – File not found
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_2da1ebd.dll ()
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (TabletServicePen) – C:\Program Files\Tablet\Pen\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV - (TouchServicePen) – C:\Program Files\Tablet\Pen\Pen_TouchService.exe (Wacom Technology, Corp.)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (WDDMService) – C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
SRV - (EhttpSrv) – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)
SRV - (ekrn) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WDSmartWareBackgroundService) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe (Memeo)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (libusbd) – C:\Windows\System32\libusbd-nt.exe (http://libusb-win32.sourceforge.net)


========== Driver Services (SafeList) ==========

DRV - (zmeianoc7) – C:\Windows\System32\drivers\zmeianoc7.sys ()
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (hamachi) – C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (dtsoftbus01) – C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (RdpVideoMiniport) – C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (vmbus) – C:\Windows\system32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (tsusbhub) – C:\Windows\System32\drivers\tsusbhub.sys (Microsoft Corporation)
DRV - (Synth3dVsc) – C:\Windows\System32\drivers\Synth3dVsc.sys (Microsoft Corporation)
DRV - (dmvsc) – C:\Windows\system32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbGD) – C:\Windows\system32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (terminpt) – C:\Windows\system32\drivers\terminpt.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (wacmoumonitor) – C:\Windows\System32\drivers\wacmoumonitor.sys (Wacom Technology)
DRV - (wacommousefilter) – C:\Windows\System32\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (wacomvhid) – C:\Windows\System32\drivers\wacomvhid.sys (Wacom Technology)
DRV - (epmntdrv) – C:\Windows\System32\epmntdrv.sys ()
DRV - (EuGdiDrv) – C:\Windows\System32\EuGdiDrv.sys ()
DRV - (SCDEmu) – C:\Windows\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (ivusb) – C:\Windows\System32\drivers\ivusb.sys (Initio Corporation)
DRV - (Mkd2kfNt) – C:\Windows\System32\drivers\Mkd2kfNT.sys (AhnLab, Inc.)
DRV - (epfwwfpr) – C:\Windows\System32\drivers\epfwwfpr.sys (ESET)
DRV - (ehdrv) – C:\Windows\System32\drivers\ehdrv.sys (ESET)
DRV - (eamon) – C:\Windows\System32\drivers\eamon.sys (ESET)
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (Mkd2Nadr) – C:\Windows\System32\drivers\Mkd2Nadr.sys (AhnLab, Inc.)
DRV - (WDC_SAM) – C:\Windows\System32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (irsir) – C:\Windows\System32\drivers\irsir.sys (Microsoft Corporation)
DRV - (libusb0) – C:\Windows\System32\drivers\libusb0.sys ()
DRV - (npkcusb) – D:\Program Files\Level Up Games\Ragnarok Online\npkcusb.sys (INCA Internet Co., Ltd.)
DRV - (npkcrypt) – D:\Program Files\Level Up Games\Ragnarok Online\npkcrypt.sys (INCA Internet Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddr&s;={s…hTerms}&f;=4

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://dn.gamania.co.jp/index.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://jp.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = ja-JP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 77 9A FA A9 1E 75 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:55576

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Facemoods Search"
FF - prefs.js..browser.search.selectedEngine: "Gelbooru"
FF - prefs.js..browser.startup.homepage: "http://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.7
FF - prefs.js..extensions.enabledItems: {6e73f6b7-b9ab-44b8-b744-6393e3c2e351}:1.5
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110323
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.3
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:2.01.110409
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.1.4.0024
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 55576
FF - prefs.js..network.proxy.no_proxies_on: ""
FF - prefs.js..network.proxy.type: 1

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5: C:\Program Files\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKCU\Software\MozillaPlugins\@ahnlab.com/asp/npmkd25aos: C:\Program Files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll (AhnLab, Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/07 17:49:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/14 21:20:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011/09/17 17:51:05 | 000,000,000 | —D | M]

[2011/05/09 16:37:15 | 000,000,000 | —D | M] (No name found) – C:\Users\Zero\AppData\Roaming\Mozilla\Extensions
[2011/09/09 15:54:28 | 000,000,000 | —D | M] (No name found) – C:\Users\Zero\AppData\Roaming\Mozilla\Firefox\Profiles\nntgdydn.default\extensions
[2011/06/20 11:47:33 | 000,000,000 | —D | M] (Rikaichan) – C:\Users\Zero\AppData\Roaming\Mozilla\Firefox\Profiles\nntgdydn.default\extensions\{0AA9101C-D3C1-4129-A9B7-D778C6A17F82}
[2011/07/13 05:07:57 | 000,000,000 | —D | M] (WOT) – C:\Users\Zero\AppData\Roaming\Mozilla\Firefox\Profiles\nntgdydn.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/08/18 20:02:12 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Zero\AppData\Roaming\Mozilla\Firefox\Profiles\nntgdydn.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/05/09 16:37:16 | 000,000,000 | —D | M] ("CS Launcher") – C:\Users\Zero\AppData\Roaming\Mozilla\Firefox\Profiles\nntgdydn.default\extensions\[removed]
[2011/06/02 11:57:49 | 000,000,000 | —D | M] ("DAEMON Tools Toolbar") – C:\Users\Zero\AppData\Roaming\Mozilla\Firefox\Profiles\nntgdydn.default\extensions\[removed]
[2011/05/09 16:37:17 | 000,000,000 | —D | M] (Personas) – C:\Users\Zero\AppData\Roaming\Mozilla\Firefox\Profiles\nntgdydn.default\extensions\[removed]
[2011/06/03 02:21:55 | 000,000,000 | —D | M] (Rikaichan Japanese-English Dictionary File) – C:\Users\Zero\AppData\Roaming\Mozilla\Firefox\Profiles\nntgdydn.default\extensions\[removed]
[2011/03/18 10:16:01 | 000,002,059 | —- | M] () – C:\Users\Zero\AppData\Roaming\Mozilla\Firefox\Profiles\nntgdydn.default\searchplugins\daemon-search.xml
[2011/02/27 22:28:24 | 000,002,331 | —- | M] () – C:\Users\Zero\AppData\Roaming\Mozilla\Firefox\Profiles\nntgdydn.default\searchplugins\gelbooru.xml
[2011/07/04 07:20:17 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/05/09 16:29:32 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/05/09 16:29:32 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/20 18:23:14 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
() (No name found) – C:\USERS\ZERO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NNTGDYDN.DEFAULT\EXTENSIONS\{6E73F6B7-B9AB-44B8-B744-6393E3C2E351}.XPI
() (No name found) – C:\USERS\ZERO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NNTGDYDN.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\ZERO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NNTGDYDN.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
[2011/09/07 17:49:32 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/07/13 08:07:28 | 000,053,912 | —- | M] ( ) – C:\Program Files\mozilla firefox\plugins\npBFPlugin.dll
[2011/05/04 04:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/23 02:38:12 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2011/09/07 17:49:30 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/02/21 17:41:22 | 000,002,046 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fcmdSrchddr.xml

Hosts file not found
O2 - BHO: (Yahoo!ツールバーフィッシング警告) - {1F68E72C-50E5-44B8-8F56-6A54D3AF1DA4} - C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\ypho.dll (Yahoo Japan Corporation. )
O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.4.17.5\bh\facemoods.dll File not found
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll File not found
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (Yahoo!ツールバーヘルパー) - {EEBA90E6-2B14-413F-9BF8-61A8BDF92258} - C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\YahooToolBar.dll (Yahoo! JAPAN)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll File not found
O3 - HKLM\..\Toolbar: (Yahoo!ツールバー) - {AEF44653-C059-42CB-A5B7-41C640DA4A67} - C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\YahooToolBar.dll (Yahoo! JAPAN)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.4.17.5\facemoodsTlbr.dll File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo!ツールバー) - {AEF44653-C059-42CB-A5B7-41C640DA4A67} - C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\YahooToolBar.dll (Yahoo! JAPAN)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BambooCore] C:\Program Files\Bamboo Dock\BambooCore.exe ()
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [Bamboo Dock] C:\Program Files\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe ()
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe (Electronic Arts)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\Zero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe (LogMeIn Inc.)
O4 - Startup: C:\Users\Zero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter - Shortcut.lnk = D:\Documents - Zero\Rainmeter-1.1-32bit\Rainmeter.exe ()
O4 - Startup: C:\Users\Zero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
F3 - HKCU WinNT: Load - (C:\Users\Zero\AppData\Local\Temp\csrss.exe) - File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O13 - gopher Prefix: missing
O16 - DPF: {53F4962A-8E27-4601-8B01-79A82B4D7FC9} https://member.gungho.jp/front/member/webgs/LoadPrgAx.CAB (LoadPrg Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {C8F5F737-2683-40B8-BFB6-47B15AC20A79} https://gash.gamania.co.jp/acxauth/cab/2.0.1/lcjggame.cab (Game Starter Control)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0091257D-FE2F-4F79-B2B1-93BD6B5DBA3A}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\Users\Zero\AppData\Local\Apps\2.0\GJAKV8QA.DJ3\G1RDKATG.YP0\OCOJTI~1.000\FastLoad.dll) -C:\Users\Zero\AppData\Local\Apps\2.0\GJAKV8QA.DJ3\G1RDKATG.YP0\ocoj..tion_f492e7df897d44e3_0001.0000_d27804b587028ece\FastLoad.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (svdhalp.exe) -C:\Windows\System32\svdhalp.exe (Yacht Jokes Clark)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKCU Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Users\Zero\AppData\Roaming\dwm.exe) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2010/10/12 03:17:00 | 000,000,055 | R— | M] () - E:\Autorun.inf – [ CDFS ]
O33 - MountPoints2\{5d9a0908-489d-11e0-81b0-001fe25fcfb1}\Shell - "" = AutoRun
O33 - MountPoints2\{5d9a0908-489d-11e0-81b0-001fe25fcfb1}\Shell\AutoRun\command - "" = "I:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{d1ce0dac-9be0-11e0-860b-001fe25fcfb1}\Shell - "" = AutoRun
O33 - MountPoints2\{d1ce0dac-9be0-11e0-860b-001fe25fcfb1}\Shell\AutoRun\command - "" = H:\setup.exe -INST_WK
O33 - MountPoints2\{d8b4aa54-7a19-11e0-9a59-001fe25fcfb1}\Shell - "" = AutoRun
O33 - MountPoints2\{d8b4aa54-7a19-11e0-9a59-001fe25fcfb1}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{f2dbf77e-7a13-11e0-89fe-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{f2dbf77e-7a13-11e0-89fe-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Install.exe – [2010/10/12 03:17:00 | 000,513,130 | R— | M] (Adobe Systems, Inc.)
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\Windows\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\System32\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.vorbis - C:\Windows\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.FPS1 - C:\Windows\System32\frapsvid.dll (Beepa P/L)
Drivers32: VIDC.HFYU - C:\Windows\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\Windows\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.iv41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\Windows\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\Windows\System32\x264vfw.dll ()
Drivers32: VIDC.XFR1 - C:\Windows\System32\xfcodec.dll ()
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/09/17 22:44:28 | 000,581,632 | —- | C] (OldTimer Tools) – C:\Users\Zero\Desktop\OTL.exe
[2011/09/17 17:51:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2011/09/17 17:51:04 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/09/17 08:44:39 | 000,000,000 | RHSD | C] – C:\RECYCLER
[2011/09/17 08:44:25 | 000,242,176 | —- | C] (Yacht Jokes Clark) – C:\Windows\System32\svdhalp.exe98
[2011/09/17 08:44:25 | 000,242,176 | —- | C] (Yacht Jokes Clark) – C:\Windows\System32\svdhalp.exe.ini713
[2011/09/17 08:44:25 | 000,242,176 | —- | C] (Yacht Jokes Clark) – C:\Windows\System32\svdhalp.exe.ini
[2011/09/17 08:44:25 | 000,242,176 | —- | C] (Yacht Jokes Clark) – C:\Windows\System32\svdhalp.exe
[2011/09/14 21:20:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\beanfun!
[2011/09/14 21:11:56 | 000,000,000 | —D | C] – C:\Users\Zero\Documents\My Beanfun
[2011/09/14 21:07:06 | 000,000,000 | —D | C] – C:\Users\Public\Documents\bf! installer
[2011/09/14 18:26:45 | 000,000,000 | —D | C] – C:\Program Files\Electronic Arts
[2011/09/14 14:38:17 | 000,000,000 | —D | C] – C:\Windows\Super nude patch 3
[2011/09/14 14:23:00 | 000,000,000 | —D | C] – C:\Users\Zero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TS3 Install Helper Monkey
[2011/09/14 14:23:00 | 000,000,000 | —D | C] – C:\Program Files\Mad Scientist Productions
[2011/09/13 19:28:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GungHo
[2011/09/13 17:25:48 | 000,000,000 | —D | C] – C:\Users\Zero\AppData\Roaming\InstallShield
[2011/09/12 23:56:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\softhouse-seal
[2011/09/10 21:10:44 | 000,000,000 | —D | C] – C:\Users\Zero\AppData\Roaming\StepMania 5
[2011/09/10 21:10:44 | 000,000,000 | —D | C] – C:\ProgramData\StepMania 5
[2011/09/10 21:06:36 | 000,000,000 | —D | C] – C:\Users\Zero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StepMania
[2011/09/10 21:06:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StepMania
[2011/09/06 22:13:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\s3pe
[2011/09/03 17:58:29 | 000,000,000 | —D | C] – C:\Users\Zero\Documents\DragonNest
[2011/09/01 09:15:38 | 000,000,000 | —D | C] – C:\Windows\Panther
[2011/09/01 09:12:56 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/09/01 09:12:56 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/09/01 09:12:55 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/09/01 09:12:55 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/09/01 09:12:55 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/09/01 09:12:55 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/09/01 09:12:55 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/09/01 09:12:55 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/09/01 09:12:55 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/09/01 09:12:55 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/09/01 09:12:55 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/09/01 09:12:55 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/09/01 09:12:55 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/09/01 09:12:55 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/09/01 09:12:55 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/09/01 09:12:55 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/09/01 09:12:55 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/09/01 09:12:55 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/09/01 09:12:55 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/09/01 09:12:55 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/09/01 09:12:55 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/09/01 09:12:55 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/09/01 09:12:55 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/09/01 09:12:55 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/09/01 09:12:55 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/09/01 09:12:55 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/09/01 09:12:55 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/09/01 09:12:55 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/09/01 09:12:54 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/09/01 09:12:54 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/09/01 09:12:54 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/09/01 09:12:54 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/09/01 09:12:54 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/09/01 09:12:54 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/09/01 09:12:54 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/09/01 09:12:54 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/09/01 09:12:54 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/09/01 08:23:41 | 003,912,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/09/01 08:23:40 | 003,967,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/09/01 08:23:37 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011/09/01 08:23:28 | 002,334,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/09/01 08:23:27 | 001,549,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tquery.dll
[2011/09/01 08:23:27 | 001,401,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssrch.dll
[2011/09/01 08:23:27 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssph.dll
[2011/09/01 08:23:26 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssvp.dll
[2011/09/01 08:23:26 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssphtb.dll
[2011/09/01 08:23:26 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscntrs.dll
[2011/09/01 08:23:07 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\poqexec.exe
[2011/09/01 08:23:03 | 000,271,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
[2011/09/01 08:23:03 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2011/09/01 08:23:03 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2011/09/01 08:23:03 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2011/09/01 08:23:03 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/09/01 08:23:03 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2011/09/01 08:23:03 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2011/09/01 08:23:03 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2011/09/01 08:23:03 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2011/09/01 08:23:03 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/09/01 08:23:03 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/09/01 08:23:03 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2011/09/01 08:23:03 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/09/01 08:23:03 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2011/09/01 08:23:03 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2011/09/01 08:23:02 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2011/09/01 08:23:02 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2011/09/01 08:23:02 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2011/09/01 08:23:02 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/09/01 08:23:02 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2011/09/01 08:23:02 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2011/09/01 08:23:02 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2011/09/01 08:23:02 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2011/09/01 08:23:02 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2011/09/01 08:23:02 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2011/09/01 08:23:02 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2011/09/01 08:23:02 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/09/01 08:23:02 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2011/09/01 08:23:02 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2011/09/01 08:23:02 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2011/09/01 08:21:55 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbcjt32.dll
[2011/09/01 08:21:55 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbctrac.dll
[2011/09/01 08:21:55 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccp32.dll
[2011/09/01 08:21:55 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccu32.dll
[2011/09/01 08:21:55 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccr32.dll
[2011/08/30 16:49:32 | 000,000,000 | —D | C] – C:\Users\Zero\Documents\punyeta
[2011/08/30 12:04:41 | 000,000,000 | —D | C] – C:\Users\Zero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\エミル・クロニクル・オンライン
[2011/08/28 12:49:37 | 000,000,000 | —D | C] – C:\Users\Zero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxis
[2011/08/28 12:49:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxis
[2011/08/25 22:17:37 | 017,193,576 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcompiler.dll
[2011/08/25 22:17:37 | 016,595,560 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvoglv32.dll
[2011/08/25 22:17:37 | 010,304,104 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvlddmkm.sys
[2011/08/25 22:17:37 | 005,404,776 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcuda.dll
[2011/08/25 22:17:37 | 002,391,656 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcuvid.dll
[2011/08/25 22:17:37 | 002,090,088 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcuvenc.dll
[2011/08/25 22:17:37 | 000,914,024 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvdispco32.dll
[2011/08/25 22:17:37 | 000,875,112 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvgenco32.dll
[2011/08/25 22:17:37 | 000,057,960 | —- | C] (Khronos Group) – C:\Windows\System32\OpenCL.dll
[2011/08/20 10:11:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts
[2011/08/20 10:08:51 | 000,000,000 | —D | C] – C:\Users\Zero\AppData\Roaming\Xfire
[2011/08/20 10:08:49 | 000,000,000 | —D | C] – C:\ProgramData\Xfire
[2011/08/20 10:08:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xfire
[2011/08/20 10:08:48 | 000,000,000 | —D | C] – C:\Program Files\Xfire
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/09/17 22:21:48 | 000,000,674 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/17 22:19:13 | 000,005,872 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/17 22:19:12 | 000,005,872 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/17 20:17:24 | 000,000,670 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/17 20:16:52 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/09/17 20:16:39 | 205,560,497 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/09/17 20:16:39 | 1609,420,800 | -HS- | M] () – C:\hiberfil.sys
[2011/09/17 17:27:49 | 000,003,528 | —- | M] () – C:\Users\Zero\AppData\Roaming\3D0E.38E
[2011/09/17 09:00:46 | 000,081,408 | —- | M] () – C:\ProgramData\sys7l4g6.exe
[2011/09/17 09:00:32 | 000,242,176 | —- | M] (Yacht Jokes Clark) – C:\Windows\System32\svdhalp.exe.ini
[2011/09/17 09:00:32 | 000,242,176 | —- | M] (Yacht Jokes Clark) – C:\Windows\System32\svdhalp.exe
[2011/09/17 08:44:25 | 000,242,176 | —- | M] (Yacht Jokes Clark) – C:\Windows\System32\svdhalp.exe98
[2011/09/17 08:44:25 | 000,242,176 | —- | M] (Yacht Jokes Clark) – C:\Windows\System32\svdhalp.exe.ini713
[2011/09/17 08:44:25 | 000,000,017 | —- | M] () – C:\Windows\syskey2i.drv
[2011/09/15 21:26:19 | 000,000,567 | —- | M] () – C:\Users\Zero\Desktop\Emil Chronicle Online start.lnk
[2011/09/14 21:01:55 | 000,651,450 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/09/14 21:01:55 | 000,120,382 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/09/13 19:17:58 | 000,007,604 | —- | M] () – C:\Users\Zero\AppData\Local\Resmon.ResmonCfg
[2011/09/13 00:17:50 | 000,581,632 | —- | M] (OldTimer Tools) – C:\Users\Zero\Desktop\OTL.exe
[2011/09/11 01:22:34 | 004,089,392 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/09/09 15:39:24 | 000,000,284 | —- | M] () – C:\Users\Zero\Documents\Divina Plugin fix.reg
[2011/09/07 17:52:39 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/09/07 17:49:44 | 000,001,998 | —- | M] () – C:\Users\Zero\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/09/03 01:15:45 | 000,051,078 | —- | M] () – C:\Users\Zero\AppData\Roaming\room_v3.dat
[2011/09/01 09:16:03 | 000,001,407 | —- | M] () – C:\Users\Zero\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/09/01 09:12:56 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/09/01 09:12:56 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/09/01 09:12:55 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/09/01 09:12:55 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/09/01 09:12:55 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/09/01 09:12:55 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/09/01 09:12:55 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/09/01 09:12:55 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/09/01 09:12:55 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/09/01 09:12:55 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/09/01 09:12:55 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/09/01 09:12:55 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/09/01 09:12:55 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/09/01 09:12:55 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/09/01 09:12:55 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/09/01 09:12:55 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/09/01 09:12:55 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/09/01 09:12:55 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/09/01 09:12:55 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/09/01 09:12:55 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/09/01 09:12:55 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/09/01 09:12:55 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/09/01 09:12:55 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/09/01 09:12:55 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/09/01 09:12:55 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/09/01 09:12:55 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/09/01 09:12:55 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/09/01 09:12:55 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/09/01 09:12:55 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/09/01 09:12:54 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/09/01 09:12:54 | 001,797,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/09/01 09:12:54 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/09/01 09:12:54 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/09/01 09:12:54 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/09/01 09:12:54 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/09/01 09:12:54 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/09/01 09:12:54 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/09/01 09:12:54 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/08/31 14:57:15 | 000,001,185 | —- | M] () – C:\Users\Zero\Desktop\コズミックブレイク.lnk
[2011/08/31 13:17:56 | 000,000,132 | —- | M] () – C:\Users\Zero\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/08/30 12:04:41 | 000,001,989 | —- | M] () – C:\Users\Zero\Desktop\エミル・クロニクル・オンライン.lnk
[2011/08/28 13:23:19 | 000,000,055 | —- | M] () – C:\Users\Zero\Documents\computer_gender.vbs
[2011/08/20 10:13:57 | 000,000,035 | —- | M] () – C:\Windows\WorldBuilder.INI
[2011/08/20 10:08:49 | 000,000,945 | —- | M] () – C:\Users\Zero\Application Data\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/09/17 09:00:53 | 000,081,408 | —- | C] () – C:\ProgramData\sys7l4g6.exe
[2011/09/17 08:54:33 | 000,003,528 | —- | C] () – C:\Users\Zero\AppData\Roaming\3D0E.38E
[2011/09/17 08:44:25 | 000,000,017 | —- | C] () – C:\Windows\syskey2i.drv
[2011/09/14 18:26:47 | 000,001,101 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Download Manager.lnk
[2011/09/13 20:07:22 | 000,000,567 | —- | C] () – C:\Users\Zero\Desktop\Emil Chronicle Online start.lnk
[2011/09/13 19:12:32 | 000,007,604 | —- | C] () – C:\Users\Zero\AppData\Local\Resmon.ResmonCfg
[2011/09/09 15:30:48 | 000,000,284 | —- | C] () – C:\Users\Zero\Documents\Divina Plugin fix.reg
[2011/09/01 09:12:55 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/08/31 14:57:15 | 000,001,185 | —- | C] () – C:\Users\Zero\Desktop\コズミックブレイク.lnk
[2011/08/30 12:04:41 | 000,001,989 | —- | C] () – C:\Users\Zero\Desktop\エミル・クロニクル・オンライン.lnk
[2011/08/28 13:23:19 | 000,000,055 | —- | C] () – C:\Users\Zero\Documents\computer_gender.vbs
[2011/08/20 10:13:57 | 000,000,035 | —- | C] () – C:\Windows\WorldBuilder.INI
[2011/08/20 10:08:49 | 000,000,945 | —- | C] () – C:\Users\Zero\Application Data\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk
[2011/08/18 09:18:13 | 000,051,078 | —- | C] () – C:\Users\Zero\AppData\Roaming\room_v3.dat
[2011/08/18 07:21:38 | 000,000,040 | —- | C] () – C:\ProgramData\ra3.ini
[2011/08/03 03:31:54 | 000,311,912 | —- | C] () – C:\Windows\System32\nvStreaming.exe
[2011/07/23 07:13:49 | 000,000,000 | —- | C] () – C:\Users\Zero\AppData\Local\{971C3ED3-720E-436F-857C-A44C30F30804}
[2011/06/25 02:51:18 | 000,036,352 | —- | C] () – C:\Windows\System32\xfcodec.dll
[2011/06/20 17:51:06 | 000,033,792 | —- | C] () – C:\Windows\System32\drivers\libusb0.sys
[2011/05/29 23:42:16 | 000,000,132 | —- | C] () – C:\Users\Zero\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2011/05/29 23:42:00 | 000,001,456 | —- | C] () – C:\Users\Zero\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/05/09 16:44:45 | 000,021,316 | —- | C] () – C:\Windows\System32\emptyregdb.dat
[2011/04/07 08:28:13 | 000,000,000 | —- | C] () – C:\Users\Zero\AppData\Roaming\chrtmp
[2011/03/30 22:42:18 | 000,180,224 | —- | C] () – C:\Windows\Res2_uninst.exe
[2011/03/17 00:04:28 | 000,001,025 | —- | C] () – C:\Windows\System32\sysprs7.dll
[2011/03/17 00:04:28 | 000,001,025 | —- | C] () – C:\Windows\System32\clauth2.dll
[2011/03/17 00:04:28 | 000,001,025 | —- | C] () – C:\Windows\System32\clauth1.dll
[2011/03/17 00:04:28 | 000,000,205 | —- | C] () – C:\Windows\System32\lsprst7.dll
[2011/03/17 00:04:28 | 000,000,073 | —- | C] () – C:\Windows\System32\ssprs.dll
[2011/03/17 00:04:28 | 000,000,021 | —- | C] () – C:\Windows\SurCode.INI
[2011/03/15 19:39:09 | 000,000,132 | —- | C] () – C:\Users\Zero\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/03/07 23:17:49 | 002,336,384 | —- | C] () – C:\Windows\System32\BootMan.exe
[2011/03/07 23:17:49 | 000,086,408 | —- | C] () – C:\Windows\System32\setupempdrv03.exe
[2011/03/07 23:17:49 | 000,014,848 | —- | C] () – C:\Windows\System32\EuEpmGdi.dll
[2011/03/07 23:17:49 | 000,008,456 | —- | C] () – C:\Windows\System32\EuGdiDrv.sys
[2011/03/07 23:17:48 | 000,014,216 | —- | C] () – C:\Windows\System32\epmntdrv.sys
[2011/03/07 17:13:23 | 000,412,598 | —- | C] () – C:\Windows\System32\perfh011.dat
[2011/03/07 17:13:23 | 000,141,988 | —- | C] () – C:\Windows\System32\perfi011.dat
[2011/03/07 17:13:23 | 000,118,564 | —- | C] () – C:\Windows\System32\perfc011.dat
[2011/03/07 17:13:23 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd011.dat
[2011/03/06 17:33:04 | 000,516,692 | —- | C] () – C:\Windows\超次元ゲイム ネプテューヌ EVENT CGUninst.exe
[2011/02/23 17:04:38 | 000,168,448 | —- | C] () – C:\Windows\System32\unrar.dll
[2011/02/23 17:04:37 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2011/02/23 17:04:37 | 002,330,643 | —- | C] () – C:\Windows\System32\x264vfw.dll
[2011/02/23 17:04:37 | 000,795,648 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2011/02/23 17:04:37 | 000,130,048 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2011/02/23 17:04:36 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2011/02/21 17:18:32 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/11/21 05:29:34 | 000,080,896 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2010/11/21 05:29:26 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/12/03 09:27:30 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/07/14 12:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 12:33:53 | 004,089,392 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 10:05:48 | 000,651,450 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 10:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 10:05:48 | 000,120,382 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 10:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 10:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 10:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 07:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 07:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 07:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/11 05:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2007/12/15 14:55:30 | 005,423,104 | —- | C] () – C:\Windows\System32\tlpsplib10.dll
[2007/11/26 21:56:28 | 000,151,415 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2005/12/07 08:34:39 | 000,191,875 | -H– | C] () – C:\Users\Zero\AppData\Roaming\Zerolog.dat

========== LOP Check ==========

[2011/05/09 16:36:54 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\.minecraft
[2011/05/09 16:36:58 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\AnvSoft
[2011/09/12 16:15:53 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\Any Video Converter Professional
[2011/05/09 16:36:59 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\Bioshock
[2011/07/22 07:40:42 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\Camfrog
[2011/09/09 21:26:06 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\CELSYS
[2011/05/09 16:37:00 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\DAEMON Tools Lite
[2011/03/29 09:30:31 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\fltk.org
[2011/05/09 16:37:00 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\gtk-2.0
[2011/03/17 08:51:21 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\Publish Providers
[2011/06/16 01:12:13 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\Rainmeter
[2011/08/20 23:01:48 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\Red Alert 3
[2011/05/09 16:37:19 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\Red Alert 3 Uprising
[2011/05/09 16:37:20 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\Sony
[2011/05/09 16:37:20 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/09/10 21:10:44 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\StepMania 5
[2011/05/09 16:37:20 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\Synthesia
[2011/07/23 00:33:08 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\SYSTEMAX Software Development
[2011/05/09 16:37:20 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\Trillian
[2011/09/17 20:18:55 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\uTorrent
[2011/05/09 16:37:21 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\VitySoft
[2011/07/20 17:37:05 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\Wacom
[2011/07/20 17:37:07 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
[2011/05/09 16:37:21 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\Western Digital
[2011/05/09 16:37:21 | 000,000,000 | —D | M] – C:\Users\Zero\AppData\Roaming\Xilisoft
[2011/09/17 17:12:39 | 000,032,556 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/11 05:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/07/14 09:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2011/02/22 07:26:01 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2010/10/04 16:36:10 | 010,526,416 | —- | M] () – C:\ComgenieAwesomeFilemanager.pkg
[2010/09/24 04:23:08 | 000,028,672 | —- | M] (Comgenie) – C:\ComgenieAwesomeFilesplitter.exe
[2009/06/11 05:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/04/15 11:41:34 | 000,319,488 | —- | M] () – C:\DEFAULT
[2010/10/13 17:38:38 | 000,001,044 | —- | M] () – C:\default.opl
[2007/08/23 01:22:57 | 000,042,877 | —- | M] () – C:\fatal_frame_ii.cbs
[2011/09/17 20:16:39 | 1609,420,800 | -HS- | M] () – C:\hiberfil.sys
[2010/12/05 09:56:00 | 000,921,658 | —- | M] () – C:\Image.bmp
[2011/03/22 12:13:25 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/06/15 17:33:10 | 000,000,000 | —- | M] () – C:\log.htm
[2010/12/01 15:33:09 | 004,004,962 | —- | M] () – C:\Mga posibleng gagamitin.rar
[2011/03/22 12:13:25 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/09/17 20:16:40 | 2145,898,496 | -HS- | M] () – C:\pagefile.sys
[2010/07/17 20:17:24 | 123,002,880 | —- | M] () – C:\Photoshop Temp1176571192
[2010/10/04 17:19:08 | 000,003,544 | —- | M] () – C:\ReadMe.txt
[2011/04/15 11:41:34 | 000,028,672 | —- | M] () – C:\SAM
[2011/04/15 11:41:13 | 000,024,576 | —- | M] () – C:\SECURITY
[2011/04/15 11:41:27 | 036,761,600 | —- | M] () – C:\SOFTWARE
[2011/05/06 11:15:44 | 000,177,485 | —- | M] () – C:\TrollFace.png
[2003/03/25 13:05:10 | 000,005,127 | —- | M] () – C:\updateE.txt
[2010/04/15 20:16:52 | 731,066,368 | —- | M] () – C:\Zombieland (2009).avi
[1 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >
[2009/07/14 12:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 12:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 12:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 12:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/11 05:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 09:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2010/11/21 05:29:21 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/03/06 17:33:04 | 001,884,938 | —- | M] () – C:\Windows\超次元ゲイム ネプテューヌ EVENT CG.scr
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 12:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/02/21 22:58:17 | 000,000,221 | -HS- | M] () – C:\Users\Zero\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2011/09/01 09:16:03 | 000,000,221 | -HS- | M] () – C:\Users\Zero\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/09/13 00:17:50 | 000,581,632 | —- | M] (OldTimer Tools) – C:\Users\Zero\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >
[2011/06/25 23:21:42 | 000,000,584 | —- | M] () – C:\Windows\AppPatch\Custom\{45dfc589-14eb-4894-8342-4945ab4ec2e9}.sdb

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-09-01 01:01:59

< >

< >

< >

< >

========== Files - Unicode (All) ==========
[2011/05/09 16:37:28 | 000,000,000 | —D | M](C:\Users\Zero\Documents\IllustStudio Ver1 ?Y’e) – C:\Users\Zero\Documents\IllustStudio Ver1 Ý’è
[2011/03/11 17:43:31 | 000,000,000 | —D | C](C:\Users\Zero\Documents\IllustStudio Ver1 ?Y’e) – C:\Users\Zero\Documents\IllustStudio Ver1 Ý’è

========== Alternate Data Streams ==========

@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:7724E4AA
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:888AFB86

< End of report >
Hi YukiYuki,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

µTorrent
You have µTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005…cles/art053.htm


I would recommend that you uninstall µTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop



**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi Tomk I managed to successfully run it on safe mode, but then after it reboots to normal boot mode While making a log, my whole system stopped responding. I waited for it for a few minutes, but to no avail, so I hit the restart button And here's the ComboFix Log, I found it in my C:\ComboFix\Combofix.txt, is this the one? ComboFix 11-09-19.01 - Zero 2011/09/19 23:23:34.1.2 - x86 NETWORK Microsoft Windows 7 Ultimate 6.1.7601.1.932.81.1033.18.2046.1113 [GMT 8:00] Running from: C:\Users\[removed]\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5} SP: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\Program Files\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe C:\Program Files\Search Toolbar C:\Program Files\Search Toolbar\icon.ico C:\Program Files\Search Toolbar\SearchToolbarUninstall.exe C:\Program Files\Search Toolbar\SearchToolbarUpdater.exe C:\Program Files\Yahoo!J C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\Config.xml C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\def_bland20.dll C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\def_comment20.dll C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\def_customize20.dll C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\def_search20.dll C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\LocalPlugin.dll C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\Update.xml C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\YahooToolBar.dll C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\yjem.dll C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\yjgh.dll C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\YJImage.dll C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\YJImageToCom.dll C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\yjop.exe C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\YJTools.dll C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\yphb.exe C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\Modules\ypho.dll C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\uninst.exe C:\Program Files\Yahoo!J\Toolbar\7_3_0_14\uninstall.exe C:\Program Files\Yahoo!J\Toolbar\data\ytcnt.ini C:\Program Files\Yahoo!J\Toolbar\ytcnt.exe C:\ProgramData\sys7l4g6.exe C:\readme.txt C:\Users\Zero\AppData\Roaming\3D0E.38E C:\Users\Zero\AppData\Roaming\chrtmp C:\Users\Zero\AppData\Roaming\Zerolog.dat C:\Windows\iun6002.exe C:\Windows\syskey2i.drv C:\Windows\system32\nvdispco3220140.dll C:\Windows\system32\nvdispco3220150.dll C:\Windows\system32\svdhalp.exe.ini C:\Windows\system32\svdhalp.exe.ini713 C:\Windows\system32\svdhalp.exe98 C:\Windows\system32\u1lovehfu0larqnn.dll C:\Windows\system32\windows Infected copy of C:\Windows\System32\slui.exe was found and disinfected Restored copy from - C:\Windows\winsxs\x86_microsoft-windows-security-spp-ux_31bf3856ad364e35_6.1.7601.17514_none_5dc908a6fd144a83\slui.exe Infected copy of C:\Windows\System32\winver.exe was found and disinfected Restored copy from - C:\Windows\winsxs\x86_microsoft-windows-winver_31bf3856ad364e35_6.1.7600.16385_none_b627d45ffdcc6f00\winver.exe ((((((((((((((((((((((((( Files Created from 2011-08-19 to 2011-09-19 ))))))))))))))))))))))))))))))) 2011-09-19 15:32:36 . 2011-09-19 15:35:42 ——– d—–w- C:\Users\Zero\AppData\Local\temp 2011-09-19 15:32:36 . 2011-09-19 15:32:36 ——– d—–w- C:\Users\UpdatusUser\AppData\Local\temp 2011-09-19 15:32:36 . 2011-09-19 15:32:36 ——– d—–w- C:\Users\UpdatusUser.SYNTHESiZE\AppData\Local\temp 2011-09-19 15:32:36 . 2011-09-19 15:32:36 ——– d—–w- C:\Users\Default\AppData\Local\temp 2011-09-17 09:51:04 . 2011-09-17 09:51:04 ——– d—–w- C:\Program Files\ESET 2011-09-14 13:20:32 . 2011-07-13 00:07:28 53912 —-a-w- C:\Program Files\Mozilla Firefox\plugins\npBFPlugin.dll 2011-09-14 10:26:45 . 2011-09-14 10:26:45 ——– d—–w- C:\Program Files\Electronic Arts 2011-09-14 06:38:17 . 2011-09-14 06:38:17 ——– d—–w- C:\Windows\Super nude patch 3 2011-09-14 06:23:00 . 2011-09-14 06:23:00 ——– d—–w- C:\Program Files\Mad Scientist Productions 2011-09-13 09:25:48 . 2011-09-13 09:25:48 ——– d—–w- C:\Users\Zero\AppData\Roaming\InstallShield 2011-09-10 13:10:44 . 2011-09-10 13:10:44 ——– d—–w- C:\Users\Zero\AppData\Roaming\StepMania 5 2011-09-10 13:10:44 . 2011-09-10 13:10:44 ——– d—–w- C:\ProgramData\StepMania 5 2011-09-01 01:15:38 . 2011-09-17 09:46:14 ——– d—–w- C:\Windows\Panther 2011-09-01 00:47:37 . 2011-08-16 00:48:52 7152464 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DC638D04-DFD9-459B-9710-6299D76E6732}\mpengine.dll 2011-09-01 00:24:15 . 2011-06-21 05:34:23 1290624 —-a-w- C:\Windows\system32\drivers\tcpip.sys 2011-09-01 00:22:19 . 2011-07-09 02:30:00 223744 —-a-w- C:\Windows\system32\drivers\mrxsmb10.sys 2011-09-01 00:22:19 . 2011-04-27 02:17:28 96768 —-a-w- C:\Windows\system32\drivers\mrxsmb20.sys 2011-09-01 00:22:19 . 2011-04-27 02:17:22 123904 —-a-w- C:\Windows\system32\drivers\mrxsmb.sys 2011-09-01 00:21:55 . 2011-06-15 08:55:19 86016 —-a-w- C:\Windows\system32\odbccu32.dll 2011-09-01 00:21:55 . 2011-06-15 08:55:19 81920 —-a-w- C:\Windows\system32\odbccr32.dll 2011-09-01 00:21:55 . 2011-06-15 08:55:19 319488 —-a-w- C:\Windows\system32\odbcjt32.dll 2011-09-01 00:21:55 . 2011-06-15 08:55:19 163840 —-a-w- C:\Windows\system32\odbctrac.dll 2011-09-01 00:21:55 . 2011-06-15 08:55:19 122880 —-a-w- C:\Windows\system32\odbccp32.dll 2011-09-01 00:21:55 . 2011-06-15 08:54:35 94208 —-a-w- C:\Program Files\Common Files\System\Ole DB\msdaosp.dll 2011-08-30 04:04:40 . 2011-08-30 04:04:40 45056 —-a-r- C:\Users\Zero\AppData\Roaming\Microsoft\Installer\{EC317B1E-FC13-403D-BD0D-B22324DDE414}\NewShortcut3_EC317B1EFC13403DBD0DB22324DDE414_1.exe 2011-08-30 04:04:40 . 2011-08-30 04:04:40 45056 —-a-r- C:\Users\Zero\AppData\Roaming\Microsoft\Installer\{EC317B1E-FC13-403D-BD0D-B22324DDE414}\NewShortcut1_EC317B1EFC13403DBD0DB22324DDE414_2.exe 2011-08-25 14:17:37 . 2011-08-03 11:50:00 914024 —-a-w- C:\Windows\system32\nvdispco32.dll 2011-08-25 14:17:37 . 2011-08-03 11:50:00 875112 —-a-w- C:\Windows\system32\nvgenco32.dll 2011-08-25 14:17:37 . 2011-08-03 11:50:00 57960 —-a-w- C:\Windows\system32\OpenCL.dll 2011-08-25 14:17:37 . 2011-08-03 11:50:00 5404776 —-a-w- C:\Windows\system32\nvcuda.dll 2011-08-25 14:17:37 . 2011-08-03 11:50:00 2391656 —-a-w- C:\Windows\system32\nvcuvid.dll 2011-08-25 14:17:37 . 2011-08-03 11:50:00 2090088 —-a-w- C:\Windows\system32\nvcuvenc.dll 2011-08-25 14:17:37 . 2011-08-03 11:50:00 17193576 —-a-w- C:\Windows\system32\nvcompiler.dll 2011-08-25 14:17:37 . 2011-08-03 11:50:00 16595560 —-a-w- C:\Windows\system32\nvoglv32.dll 2011-08-25 14:17:37 . 2011-08-03 11:50:00 10304104 —-a-w- C:\Windows\system32\drivers\nvlddmkm.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2011-09-07 09:52:39 . 2011-06-15 01:14:32 404640 —-a-w- C:\Windows\system32\FlashPlayerCPLApp.cpl 2011-08-03 11:50:00 . 2011-06-17 04:27:23 12636776 —-a-w- C:\Windows\system32\nvd3dum.dll 2011-08-03 11:50:00 . 2011-04-07 14:45:08 600680 —-a-w- C:\Windows\system32\easyUpdatusAPIU.dll 2011-08-03 11:50:00 . 2011-04-07 14:45:06 599144 —-a-w- C:\Windows\system32\nvvsvc.exe 2011-08-03 11:50:00 . 2011-04-07 14:45:06 111208 —-a-w- C:\Windows\system32\nvmctray.dll 2011-08-03 11:50:00 . 2011-04-07 14:44:58 3730024 —-a-w- C:\Windows\system32\nvcpl.dll 2011-08-03 11:50:00 . 2011-04-07 14:44:48 2558568 —-a-w- C:\Windows\system32\nvsvc.dll 2011-08-03 11:50:00 . 2011-02-21 09:13:14 2412136 —-a-w- C:\Windows\system32\nvapi.dll 2011-08-03 11:50:00 . 2011-01-07 13:06:02 66664 —-a-w- C:\Windows\system32\nvshext.dll 2011-08-03 11:50:00 . 2009-07-13 22:09:18 6613096 —-a-w- C:\Windows\system32\nvwgf2um.dll 2011-08-02 19:31:54 . 2011-08-02 19:31:54 311912 —-a-w- C:\Windows\system32\nvStreaming.exe 2011-07-31 16:14:48 . 2011-07-31 16:14:48 25280 —-a-w- C:\Windows\system32\drivers\hamachi.sys 2011-06-24 18:51:18 . 2011-06-24 18:51:18 36352 —-a-w- C:\Windows\system32\xfcodec.dll 2011-06-24 02:53:03 . 2011-03-15 00:49:20 107888 —-a-w- C:\Windows\system32\CmdLineExt.dll 2011-09-07 09:49:32 . 2011-06-01 05:42:31 134104 —-a-w- C:\Program Files\mozilla firefox\components\browsercomps.dll
Hi Tomk, When I ran it on Normal Mode, it asked me to update, so I clicked yes and it updated Here's the new log ComboFix 11-09-19.04 - Zero 2011/09/20 9:14.2.2 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.932.81.1033.18.2046.768 [GMT 8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5} SP: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . —- Previous Run ——- . c:\program files\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe c:\program files\Search Toolbar\icon.ico c:\program files\Search Toolbar\SearchToolbarUninstall.exe c:\program files\Search Toolbar\SearchToolbarUpdater.exe c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\Config.xml c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\def_bland20.dll c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\def_comment20.dll c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\def_customize20.dll c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\def_search20.dll c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\LocalPlugin.dll c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\Update.xml c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\YahooToolBar.dll c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\yjem.dll c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\yjgh.dll c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\YJImage.dll c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\YJImageToCom.dll c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\yjop.exe c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\YJTools.dll c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\yphb.exe c:\program files\Yahoo!J\Toolbar\7_3_0_14\Modules\ypho.dll c:\program files\Yahoo!J\Toolbar\7_3_0_14\uninst.exe c:\program files\Yahoo!J\Toolbar\7_3_0_14\uninstall.exe c:\program files\Yahoo!J\Toolbar\data\ytcnt.ini c:\program files\Yahoo!J\Toolbar\ytcnt.exe c:\programdata\sys7l4g6.exe C:\readme.txt c:\users\Zero\AppData\Roaming\3D0E.38E c:\users\Zero\AppData\Roaming\chrtmp c:\users\Zero\AppData\Roaming\Zerolog.dat c:\windows\iun6002.exe c:\windows\syskey2i.drv c:\windows\system32\nvdispco3220140.dll c:\windows\system32\nvdispco3220150.dll c:\windows\system32\svdhalp.exe.ini c:\windows\system32\svdhalp.exe.ini713 c:\windows\system32\svdhalp.exe98 c:\windows\system32\u1lovehfu0larqnn.dll . – Previous Run – . Infected copy of c:\windows\System32\slui.exe was found and disinfected Restored copy from - c:\windows\winsxs\x86_microsoft-windows-security-spp-ux_31bf3856ad364e35_6.1.7601.17514_none_5dc908a6fd144a83\slui.exe . Infected copy of c:\windows\System32\slui.exe was found and disinfected Restored copy from - c:\windows\winsxs\x86_microsoft-windows-security-spp-ux_31bf3856ad364e35_6.1.7601.17514_none_5dc908a6fd144a83\slui.exe . Infected copy of c:\windows\System32\winver.exe was found and disinfected Restored copy from - c:\windows\winsxs\x86_microsoft-windows-winver_31bf3856ad364e35_6.1.7600.16385_none_b627d45ffdcc6f00\winver.exe . ——– . . ((((((((((((((((((((((((( Files Created from 2011-08-20 to 2011-09-20 ))))))))))))))))))))))))))))))) . . 2011-09-20 01:22 . 2011-09-20 01:22 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2011-09-20 01:22 . 2011-09-20 01:22 ——– d—–w- c:\users\UpdatusUser.SYNTHESiZE\AppData\Local\temp 2011-09-20 01:22 . 2011-09-20 01:22 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-09-19 15:32 . 2011-09-20 01:22 ——– d—–w- c:\users\Zero\AppData\Local\temp 2011-09-17 09:51 . 2011-09-17 09:51 ——– d—–w- c:\program files\ESET 2011-09-14 13:20 . 2011-07-13 00:07 53912 —-a-w- c:\program files\Mozilla Firefox\plugins\npBFPlugin.dll 2011-09-14 10:26 . 2011-09-14 10:26 ——– d—–w- c:\program files\Electronic Arts 2011-09-14 06:38 . 2011-09-14 06:38 ——– d—–w- c:\windows\Super nude patch 3 2011-09-14 06:23 . 2011-09-14 06:23 ——– d—–w- c:\program files\Mad Scientist Productions 2011-09-13 09:25 . 2011-09-13 09:25 ——– d—–w- c:\users\Zero\AppData\Roaming\InstallShield 2011-09-10 13:10 . 2011-09-10 13:10 ——– d—–w- c:\users\Zero\AppData\Roaming\StepMania 5 2011-09-10 13:10 . 2011-09-10 13:10 ——– d—–w- c:\programdata\StepMania 5 2011-09-01 01:15 . 2011-09-17 09:46 ——– d—–w- c:\windows\Panther 2011-09-01 00:47 . 2011-08-16 00:48 7152464 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DC638D04-DFD9-459B-9710-6299D76E6732}\mpengine.dll 2011-09-01 00:24 . 2011-06-21 05:34 1290624 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-09-01 00:22 . 2011-07-09 02:30 223744 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-09-01 00:22 . 2011-04-27 02:17 96768 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-09-01 00:22 . 2011-04-27 02:17 123904 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-09-01 00:21 . 2011-06-15 08:55 86016 —-a-w- c:\windows\system32\odbccu32.dll 2011-09-01 00:21 . 2011-06-15 08:55 81920 —-a-w- c:\windows\system32\odbccr32.dll 2011-09-01 00:21 . 2011-06-15 08:55 319488 —-a-w- c:\windows\system32\odbcjt32.dll 2011-09-01 00:21 . 2011-06-15 08:55 163840 —-a-w- c:\windows\system32\odbctrac.dll 2011-09-01 00:21 . 2011-06-15 08:55 122880 —-a-w- c:\windows\system32\odbccp32.dll 2011-09-01 00:21 . 2011-06-15 08:54 94208 —-a-w- c:\program files\Common Files\System\Ole DB\msdaosp.dll 2011-08-30 04:04 . 2011-08-30 04:04 45056 —-a-r- c:\users\Zero\AppData\Roaming\Microsoft\Installer\{EC317B1E-FC13-403D-BD0D-B22324DDE414}\NewShortcut3_EC317B1EFC13403DBD0DB22324DDE414_1.exe 2011-08-30 04:04 . 2011-08-30 04:04 45056 —-a-r- c:\users\Zero\AppData\Roaming\Microsoft\Installer\{EC317B1E-FC13-403D-BD0D-B22324DDE414}\NewShortcut1_EC317B1EFC13403DBD0DB22324DDE414_2.exe 2011-08-25 14:17 . 2011-08-03 11:50 914024 —-a-w- c:\windows\system32\nvdispco32.dll 2011-08-25 14:17 . 2011-08-03 11:50 875112 —-a-w- c:\windows\system32\nvgenco32.dll 2011-08-25 14:17 . 2011-08-03 11:50 57960 —-a-w- c:\windows\system32\OpenCL.dll 2011-08-25 14:17 . 2011-08-03 11:50 5404776 —-a-w- c:\windows\system32\nvcuda.dll 2011-08-25 14:17 . 2011-08-03 11:50 2391656 —-a-w- c:\windows\system32\nvcuvid.dll 2011-08-25 14:17 . 2011-08-03 11:50 2090088 —-a-w- c:\windows\system32\nvcuvenc.dll 2011-08-25 14:17 . 2011-08-03 11:50 17193576 —-a-w- c:\windows\system32\nvcompiler.dll 2011-08-25 14:17 . 2011-08-03 11:50 16595560 —-a-w- c:\windows\system32\nvoglv32.dll 2011-08-25 14:17 . 2011-08-03 11:50 10304104 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-09-07 09:52 . 2011-06-15 01:14 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-08-03 11:50 . 2011-06-17 04:27 12636776 —-a-w- c:\windows\system32\nvd3dum.dll 2011-08-03 11:50 . 2011-04-07 14:45 600680 —-a-w- c:\windows\system32\easyUpdatusAPIU.dll 2011-08-03 11:50 . 2011-04-07 14:45 599144 —-a-w- c:\windows\system32\nvvsvc.exe 2011-08-03 11:50 . 2011-04-07 14:45 111208 —-a-w- c:\windows\system32\nvmctray.dll 2011-08-03 11:50 . 2011-04-07 14:44 3730024 —-a-w- c:\windows\system32\nvcpl.dll 2011-08-03 11:50 . 2011-04-07 14:44 2558568 —-a-w- c:\windows\system32\nvsvc.dll 2011-08-03 11:50 . 2011-02-21 09:13 2412136 —-a-w- c:\windows\system32\nvapi.dll 2011-08-03 11:50 . 2011-01-07 13:06 66664 —-a-w- c:\windows\system32\nvshext.dll 2011-08-03 11:50 . 2009-07-13 22:09 6613096 —-a-w- c:\windows\system32\nvwgf2um.dll 2011-08-02 19:31 . 2011-08-02 19:31 311912 —-a-w- c:\windows\system32\nvStreaming.exe 2011-07-31 16:14 . 2011-07-31 16:14 25280 —-a-w- c:\windows\system32\drivers\hamachi.sys 2011-06-24 18:51 . 2011-06-24 18:51 36352 —-a-w- c:\windows\system32\xfcodec.dll 2011-06-24 02:53 . 2011-03-15 00:49 107888 —-a-w- c:\windows\system32\CmdLineExt.dll 2011-09-07 09:49 . 2011-06-01 05:42 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ——- Sigcheck ——- Note: Unsigned files aren't necessarily malware. . [7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll [-] 2010-11-20 . BE8C64439F1E2AF088063218C16EB9FE . 811520 . . [6.1.7601.17514] . . c:\windows\System32\user32.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2009-11-18 10:40 1196936 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408] "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408] "RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616] "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-02-24 395640] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296] "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-05 500208] "AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-21 406992] "PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2010-04-12 180224] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-03-22 74752] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552] "BambooCore"="c:\program files\Bamboo Dock\BambooCore.exe" [2011-07-20 629848] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-09-29 2054360] . c:\users\Zero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2011-8-1 625952] Rainmeter - Shortcut.lnk - d:\documents - zero\Rainmeter-1.1-32bit\Rainmeter.exe [2010-2-19 119296] Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2011-3-13 3450608] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-11-13 2057536] WDSmartWare.lnk - c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-11-13 9117504] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "ConsentPromptBehaviorAdmin"= 0 (0x0) "EnableLUA"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R2 ayoraa7oogoogoen;Winferno Subscription Service;c:\users\Zero\AppData\Roaming\Microsoft\fipoowou.exe [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google アップデート サービス (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47 136176] R3 1394hub;1394 Enabled Hub;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464] R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x] R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-07-15 14216] R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-07-15 8456] R3 GGSAFERDriver;GGSAFER Driver;c:\program files\Garena Classic\safedrv.sys [x] R3 gupdatem;Google Update サービス (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47 136176] R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys [2010-03-10 25112] R3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNt.sys [2009-10-13 133632] R3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2009-07-13 79360] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2011-06-19 4122968] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-20 77184] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-20 25600] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-20 112640] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2010-10-11 16240] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2008-05-06 11520] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-05-09 218688] S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-09-29 108792] S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992] S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-09-29 735960] S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2009-09-29 95896] S2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;c:\windows\system32\libusbd-nt.exe [2005-03-09 18944] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-08-02 379496] S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2010-10-26 4869488] S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2010-10-26 416112] S2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-11-13 110592] S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480] S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2005-03-09 33792] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-06-23 275048] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai . Contents of the 'Scheduled Tasks' folder . 2011-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47] . 2011-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47] . . ——- Supplementary Scan ——- . uStart Page = hxxp://dn.gamania.co.jp/index.aspx uInternet Settings,ProxyServer = http=127.0.0.1:55576 TCP: DhcpNameServer = [removed] [removed] DPF: {53F4962A-8E27-4601-8B01-79A82B4D7FC9} - hxxps://member.gungho.jp/front/member/webgs/LoadPrgAx.CAB DPF: {C8F5F737-2683-40B8-BFB6-47B15AC20A79} - hxxps://gash.gamania.co.jp/acxauth/cab/2.0.1/lcjggame.cab FF - ProfilePath - c:\users\Zero\AppData\Roaming\Mozilla\Firefox\Profiles\nntgdydn.default\ FF - prefs.js: browser.search.selectedEngine - Gelbooru FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 55576 FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) HKCU-Run-Bamboo Dock - c:\program files\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe HKU-Default-Explorer_Run-explorer - c:\programdata\sys7l4g6.exe MSConfigStartUp-aslgkb - c:\recycler\S-1-5-21-3757766361-7165949638-472004661-1047\dsuzsn.exe MSConfigStartUp-cd Tools updater - c:\users\Zero\AppData\Local\Temp\ikstun.exe MSConfigStartUp-conhost - c:\users\Zero\AppData\Roaming\Microsoft\conhost.exe MSConfigStartUp-default drivers checker - c:\users\Zero\AppData\Local\Temp\rhgpv.exe MSConfigStartUp-explorer - c:\windows\Temp\explorer.exe MSConfigStartUp-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodssrv.exe MSConfigStartUp-foovukub - c:\users\Zero\AppData\Roaming\Microsoft\fipoowou.exe MSConfigStartUp-iqrgoq - c:\recycler\S-1-5-21-3158636405-6882042932-712087407-8324\wouhiyamx.exe MSConfigStartUp-msi system tune - c:\users\Zero\AppData\Local\Temp\gnstvn.exe MSConfigStartUp-mssend - c:\users\Zero\AppData\Roaming\x2l2rlgwhwmvlvrhvfdgzveehzeedv3k2\svcnost.exe MSConfigStartUp-raawlfvw - c:\recycler\S-1-5-21-2035773267-8033905806-801417897-3543\gqtkrzasbc.exe MSConfigStartUp-sbiyyjkn - c:\recycler\S-1-5-21-4803985723-8889411458-020163396-9365\oaqqlvadvd.exe AddRemove-Command_And_Conquer_Yuri's_Revenge_1.001_MPI - c:\windows\iun6002.exe AddRemove-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.5\uninstall.exe AddRemove-LimitRO Renewal - d:\limitro ata\Ragnarok Online\uninst.exe AddRemove-Search Toolbar - c:\program files\Search Toolbar\SearchToolbarUninstall.exe AddRemove-Yahoo!Jツールバー - c:\program files\Yahoo!J\Toolbar\7_3_0_14\uninst.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "?慴"=hex:b6,6e,f8,0f,8f,5b,8e,86,00,74,cc,31,d2,a9,6c,25,00,2d,b3,45,e3,fb,f0, 73,ae,21,19,51,34,d2,d0,97,5a,cf,33,09,d8,86,6a,2f,a1,18,4b,9d,a4,07,4d,c0,\ "?祥"=hex:a3,b8,1c,b6,88,5e,66,62,23,f3,bc,61,67,a6,61,76 . [HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1001\Software\SecuROM\License information*] "datasecu"=hex:e3,18,d6,36,b4,01,b1,41,3c,0b,3b,07,82,c0,1a,18,b2,fc,da,8e,3f, bc,9d,af,af,a4,d4,99,32,49,6d,b1,d7,90,c1,97,00,84,c7,c5,b6,07,ab,66,f5,f0,\ "rkeysecu"=hex:0d,a3,f0,50,09,3e,af,a0,af,d0,b8,8e,0f,70,d0,94 . [HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1001\Software\ウ0ケ0ラ0・ォU6・Z0\ン0・・`0~0*0ェ0・・、0・] @Class="Path" "Path"="d:\\コスプレ喫茶娘々\\ポリンだま オンライン\\" "Update"="0" . [HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1005\Software\ウ0ケ0ラ0・ォU6・Z0\ン0・・`0~0*0ェ0・・、0・] "Path"="d:\\コスプレ喫茶娘々\\ポリンだま オンライン\\" "Update"="0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(3764) c:\program files\Stardock\ObjectDock\DockShellHook.dll . Completion time: 2011-09-20 09:26:28 ComboFix-quarantined-files.txt 2011-09-20 01:26 . Pre-Run: 65,906,753,536 bytes free Post-Run: 65,811,103,744 bytes free . - - End Of File - - 468CA89BA55FEB575C694D6783C03B82
YukiYuki,

Your computer appears to have been infected by a backdoor trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.


COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    c:\users\Zero\AppData\Roaming\Microsoft\fipoowou.exe
    
    Driver::
    ayoraa7oogoogoen
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Hi Tomk, Like my previous attempt at running ComboFix, my system crashed again Should I do the latest step while in Safe Mode? And I do not wish to reformat my system
Hi Tomk, It managed to extract successfully (the part where my system always crash) while in Normal Mode after an update for ComboFix But after sometime around Stage 6 of scanning, my system crashed again What is happening?
Hi Tomk, Here are the logs ComboFix 11-09-19.05 - Zero 2011/09/20 14:14:47.4.2 - x86 NETWORK Microsoft Windows 7 Ultimate 6.1.7601.1.932.81.1033.18.2046.1108 [GMT 8:00] Running from: c:\users\[removed]\Desktop\ComboFix-1.exe Command switches used :: c:\users\Zero\Desktop\CFScript.txt AV: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5} SP: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . FILE :: "c:\users\Zero\AppData\Roaming\Microsoft\fipoowou.exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_ayoraa7oogoogoen . . ((((((((((((((((((((((((( Files Created from 2011-08-20 to 2011-09-20 ))))))))))))))))))))))))))))))) . . 2011-09-20 06:23 . 2011-09-20 06:23 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2011-09-20 06:23 . 2011-09-20 06:23 ——– d—–w- c:\users\UpdatusUser.SYNTHESiZE\AppData\Local\temp 2011-09-17 09:51 . 2011-09-17 09:51 ——– d—–w- c:\program files\ESET 2011-09-14 13:20 . 2011-07-13 00:07 53912 —-a-w- c:\program files\Mozilla Firefox\plugins\npBFPlugin.dll 2011-09-14 10:26 . 2011-09-14 10:26 ——– d—–w- c:\program files\Electronic Arts 2011-09-14 06:38 . 2011-09-14 06:38 ——– d—–w- c:\windows\Super nude patch 3 2011-09-14 06:23 . 2011-09-14 06:23 ——– d—–w- c:\program files\Mad Scientist Productions 2011-09-13 09:25 . 2011-09-13 09:25 ——– d—–w- c:\users\Zero\AppData\Roaming\InstallShield 2011-09-10 13:10 . 2011-09-10 13:10 ——– d—–w- c:\users\Zero\AppData\Roaming\StepMania 5 2011-09-10 13:10 . 2011-09-10 13:10 ——– d—–w- c:\programdata\StepMania 5 2011-09-01 01:15 . 2011-09-17 09:46 ——– d—–w- c:\windows\Panther 2011-09-01 00:47 . 2011-08-16 00:48 7152464 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DC638D04-DFD9-459B-9710-6299D76E6732}\mpengine.dll 2011-09-01 00:24 . 2011-06-21 05:34 1290624 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-09-01 00:22 . 2011-07-09 02:30 223744 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-09-01 00:22 . 2011-04-27 02:17 96768 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-09-01 00:22 . 2011-04-27 02:17 123904 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-09-01 00:21 . 2011-06-15 08:55 86016 —-a-w- c:\windows\system32\odbccu32.dll 2011-09-01 00:21 . 2011-06-15 08:55 81920 —-a-w- c:\windows\system32\odbccr32.dll 2011-09-01 00:21 . 2011-06-15 08:55 319488 —-a-w- c:\windows\system32\odbcjt32.dll 2011-09-01 00:21 . 2011-06-15 08:55 163840 —-a-w- c:\windows\system32\odbctrac.dll 2011-09-01 00:21 . 2011-06-15 08:55 122880 —-a-w- c:\windows\system32\odbccp32.dll 2011-09-01 00:21 . 2011-06-15 08:54 94208 —-a-w- c:\program files\Common Files\System\Ole DB\msdaosp.dll 2011-08-30 04:04 . 2011-08-30 04:04 45056 —-a-r- c:\users\Zero\AppData\Roaming\Microsoft\Installer\{EC317B1E-FC13-403D-BD0D-B22324DDE414}\NewShortcut3_EC317B1EFC13403DBD0DB22324DDE414_1.exe 2011-08-30 04:04 . 2011-08-30 04:04 45056 —-a-r- c:\users\Zero\AppData\Roaming\Microsoft\Installer\{EC317B1E-FC13-403D-BD0D-B22324DDE414}\NewShortcut1_EC317B1EFC13403DBD0DB22324DDE414_2.exe 2011-08-25 14:17 . 2011-08-03 11:50 914024 —-a-w- c:\windows\system32\nvdispco32.dll 2011-08-25 14:17 . 2011-08-03 11:50 875112 —-a-w- c:\windows\system32\nvgenco32.dll 2011-08-25 14:17 . 2011-08-03 11:50 57960 —-a-w- c:\windows\system32\OpenCL.dll 2011-08-25 14:17 . 2011-08-03 11:50 5404776 —-a-w- c:\windows\system32\nvcuda.dll 2011-08-25 14:17 . 2011-08-03 11:50 2391656 —-a-w- c:\windows\system32\nvcuvid.dll 2011-08-25 14:17 . 2011-08-03 11:50 2090088 —-a-w- c:\windows\system32\nvcuvenc.dll 2011-08-25 14:17 . 2011-08-03 11:50 17193576 —-a-w- c:\windows\system32\nvcompiler.dll 2011-08-25 14:17 . 2011-08-03 11:50 16595560 —-a-w- c:\windows\system32\nvoglv32.dll 2011-08-25 14:17 . 2011-08-03 11:50 10304104 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-09-07 09:52 . 2011-06-15 01:14 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-08-03 11:50 . 2011-06-17 04:27 12636776 —-a-w- c:\windows\system32\nvd3dum.dll 2011-08-03 11:50 . 2011-04-07 14:45 600680 —-a-w- c:\windows\system32\easyUpdatusAPIU.dll 2011-08-03 11:50 . 2011-04-07 14:45 599144 —-a-w- c:\windows\system32\nvvsvc.exe 2011-08-03 11:50 . 2011-04-07 14:45 111208 —-a-w- c:\windows\system32\nvmctray.dll 2011-08-03 11:50 . 2011-04-07 14:44 3730024 —-a-w- c:\windows\system32\nvcpl.dll 2011-08-03 11:50 . 2011-04-07 14:44 2558568 —-a-w- c:\windows\system32\nvsvc.dll 2011-08-03 11:50 . 2011-02-21 09:13 2412136 —-a-w- c:\windows\system32\nvapi.dll 2011-08-03 11:50 . 2011-01-07 13:06 66664 —-a-w- c:\windows\system32\nvshext.dll 2011-08-03 11:50 . 2009-07-13 22:09 6613096 —-a-w- c:\windows\system32\nvwgf2um.dll 2011-08-02 19:31 . 2011-08-02 19:31 311912 —-a-w- c:\windows\system32\nvStreaming.exe 2011-07-31 16:14 . 2011-07-31 16:14 25280 —-a-w- c:\windows\system32\drivers\hamachi.sys 2011-06-24 18:51 . 2011-06-24 18:51 36352 —-a-w- c:\windows\system32\xfcodec.dll 2011-06-24 02:53 . 2011-03-15 00:49 107888 —-a-w- c:\windows\system32\CmdLineExt.dll 2011-09-07 09:49 . 2011-06-01 05:42 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ——- Sigcheck ——- Note: Unsigned files aren't necessarily malware. . [7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll [-] 2010-11-20 . BE8C64439F1E2AF088063218C16EB9FE . 811520 . . [6.1.7601.17514] . . c:\windows\System32\user32.dll . ((((((((((((((((((((((((((((( SnapShot@2011-09-20_01.22.58 ))))))))))))))))))))))))))))))))))))))))) . + 2010-11-20 21:20 . 2011-09-20 06:27 35698 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 04:55 . 2011-09-20 06:27 47394 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-05-09 09:09 . 2011-09-20 06:27 11588 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4208408748-883319235-2440751903-1001_UserData.bin - 2011-05-09 08:15 . 2011-09-20 01:07 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-05-09 08:15 . 2011-09-20 06:10 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-05-09 08:15 . 2011-09-20 01:07 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2011-05-09 08:15 . 2011-09-20 06:10 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:41 . 2011-09-20 01:07 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:41 . 2011-09-20 06:10 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:34 . 2011-09-20 01:08 92416 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat + 2009-07-14 04:34 . 2011-09-20 06:26 92416 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat + 2011-09-20 06:10 . 2011-09-20 06:25 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-09-19 21:29 . 2011-09-20 01:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-09-19 21:29 . 2011-09-20 01:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-09-20 06:10 . 2011-09-20 06:25 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2009-07-14 04:47 . 2011-09-20 06:09 399064 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 04:47 . 2011-09-19 17:18 399064 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 04:34 . 2011-09-20 06:26 7083571 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat - 2009-07-14 04:34 . 2011-09-20 01:08 7083571 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat - 2011-03-17 19:50 . 2011-09-19 17:18 64320255 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4208408748-883319235-2440751903-1001-12288.dat + 2011-03-17 19:50 . 2011-09-20 06:09 64320255 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4208408748-883319235-2440751903-1001-12288.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2009-11-18 10:40 1196936 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408] "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408] "RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616] "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-02-24 395640] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296] "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-05 500208] "AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-21 406992] "PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2010-04-12 180224] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-03-22 74752] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552] "BambooCore"="c:\program files\Bamboo Dock\BambooCore.exe" [2011-07-20 629848] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-09-29 2054360] . c:\users\Zero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2011-8-1 625952] Rainmeter - Shortcut.lnk - d:\documents - zero\Rainmeter-1.1-32bit\Rainmeter.exe [2010-2-19 119296] Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2011-3-13 3450608] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-11-13 2057536] WDSmartWare.lnk - c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-11-13 9117504] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "ConsentPromptBehaviorAdmin"= 0 (0x0) "EnableLUA"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google アップデート サービス (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47 136176] R3 1394hub;1394 Enabled Hub;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464] R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x] R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-07-15 14216] R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-07-15 8456] R3 GGSAFERDriver;GGSAFER Driver;c:\program files\Garena Classic\safedrv.sys [x] R3 gupdatem;Google Update サービス (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47 136176] R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys [2010-03-10 25112] R3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNt.sys [2009-10-13 133632] R3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2009-07-13 79360] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2011-06-19 4122968] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-20 77184] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-20 25600] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-20 112640] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2010-10-11 16240] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2008-05-06 11520] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-05-09 218688] S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-09-29 108792] S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992] S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-09-29 735960] S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2009-09-29 95896] S2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;c:\windows\system32\libusbd-nt.exe [2005-03-09 18944] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-08-02 379496] S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2010-10-26 4869488] S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2010-10-26 416112] S2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-11-13 110592] S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480] S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2005-03-09 33792] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-06-23 275048] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai . Contents of the 'Scheduled Tasks' folder . 2011-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47] . 2011-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-07-02 21:47] . . ——- Supplementary Scan ——- . uStart Page = hxxp://dn.gamania.co.jp/index.aspx uInternet Settings,ProxyServer = http=127.0.0.1:55576 TCP: DhcpNameServer = [removed] [removed] DPF: {53F4962A-8E27-4601-8B01-79A82B4D7FC9} - hxxps://member.gungho.jp/front/member/webgs/LoadPrgAx.CAB DPF: {C8F5F737-2683-40B8-BFB6-47B15AC20A79} - hxxps://gash.gamania.co.jp/acxauth/cab/2.0.1/lcjggame.cab FF - ProfilePath - c:\users\Zero\AppData\Roaming\Mozilla\Firefox\Profiles\nntgdydn.default\ FF - prefs.js: browser.search.selectedEngine - Gelbooru FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 55576 FF - prefs.js: network.proxy.type - 0 . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "?慴"=hex:b6,6e,f8,0f,8f,5b,8e,86,00,74,cc,31,d2,a9,6c,25,00,2d,b3,45,e3,fb,f0, 73,ae,21,19,51,34,d2,d0,97,5a,cf,33,09,d8,86,6a,2f,a1,18,4b,9d,a4,07,4d,c0,\ "?祥"=hex:a3,b8,1c,b6,88,5e,66,62,23,f3,bc,61,67,a6,61,76 . [HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1001\Software\SecuROM\License information*] "datasecu"=hex:e3,18,d6,36,b4,01,b1,41,3c,0b,3b,07,82,c0,1a,18,b2,fc,da,8e,3f, bc,9d,af,af,a4,d4,99,32,49,6d,b1,d7,90,c1,97,00,84,c7,c5,b6,07,ab,66,f5,f0,\ "rkeysecu"=hex:0d,a3,f0,50,09,3e,af,a0,af,d0,b8,8e,0f,70,d0,94 . [HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1001\Software\ウ0ケ0ラ0・ォU6・Z0\ン0・・`0~0*0ェ0・・、0・] @Class="Path" "Path"="d:\\コスプレ喫茶娘々\\ポリンだま オンライン\\" "Update"="0" . [HKEY_USERS\S-1-5-21-4208408748-883319235-2440751903-1005\Software\ウ0ケ0ラ0・ォU6・Z0\ン0・・`0~0*0ェ0・・、0・] "Path"="d:\\コスプレ喫茶娘々\\ポリンだま オンライン\\" "Update"="0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(5016) c:\program files\RocketDock\RocketDock.dll c:\program files\Stardock\ObjectDock\DockShellHook.dll . ———————— Other Running Processes ———————— . c:\windows\system32\nvvsvc.exe c:\windows\system32\AUDIODG.EXE c:\program files\NVIDIA Corporation\Display\nvxdsync.exe c:\windows\system32\nvvsvc.exe c:\windows\SYSTEM32\WISPTIS.EXE c:\windows\system32\taskhost.exe c:\windows\SYSTEM32\WISPTIS.EXE c:\program files\Tablet\Pen\Pen_TouchUser.exe c:\program files\Common Files\microsoft shared\ink\TabTip.exe c:\program files\Tablet\Pen\Pen_TabletUser.exe c:\windows\system32\conhost.exe c:\windows\servicing\TrustedInstaller.exe c:\windows\system32\sppsvc.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe c:\windows\System32\ping.exe c:\windows\system32\conhost.exe . ************************************************************************** . Completion time: 2011-09-20 14:31:29 - machine was rebooted ComboFix-quarantined-files.txt 2011-09-20 06:31 ComboFix2.txt 2011-09-20 01:26 . Pre-Run: 65,708,343,296 bytes free Post-Run: 65,556,336,640 bytes free . - - End Of File - - C2D3C1694EE6011B1C69275372DEF501
Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI