This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PING.exe [Closed]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Picked up PING.exe last night. Opens itself and runs about every 5 minutes. Malwarebytes was unable to fix this. I read a recent thread here about you guys helping someone else with this problem, and see that you asked the guy for several other utility scan reports. I have run and will include these in my initial post. Thanks in advance for any and all help.

Edit: I see that GMER log is asked for as an attachment. I tried but am being told i may not make attachments of this kind.


OTL report:

OTL logfile created on: 2/6/2012 11:58:39 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Loch\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 1.01 Gb Available Physical Memory | 31.23% Memory free
6.50 Gb Paging File | 4.06 Gb Available in Paging File | 62.48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 29.19 Gb Total Space | 3.86 Gb Free Space | 13.21% Space Free | Partition Type: NTFS
Drive D: | 59.14 Gb Total Space | 11.68 Gb Free Space | 19.76% Space Free | Partition Type: NTFS
Drive E: | 119.85 Gb Total Space | 33.93 Gb Free Space | 28.31% Space Free | Partition Type: NTFS
Drive F: | 89.91 Gb Total Space | 12.87 Gb Free Space | 14.32% Space Free | Partition Type: NTFS

Computer Name: MARS3 | User Name: Loch | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Loch\Desktop\OTL.exe (OldTimer Tools)
PRC - E:\program files\firefox\firefox.exe (Mozilla Corporation)
PRC - E:\program files\firefox\plugin-container.exe (Mozilla Corporation)
PRC - E:\program files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - E:\program files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - E:\program files\winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Windows\SysWOW64\CTxfispi.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Windows\SysWOW64\Ctxfihlp.exe (Creative Technology Ltd)
PRC - E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTSS.exe ()
PRC - E:\program files\evga\EVGA Precision\EVGAPrecision.exe ()
PRC - C:\Windows\SysWOW64\PING.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
PRC - E:\program files\Blaze Media Pro\NMSAccess32.exe ()
PRC - C:\Program Files\Mouse\Amoumain.exe ()
PRC - C:\Program Files (x86)\Creative\MediaSource5\Go\CTCMSGoU.exe (Creative Technology Ltd)


========== Modules (No Company Name) ==========

MOD - E:\program files\firefox\mozjs.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Windows\SysWOW64\CTXFIRES.DLL ()
MOD - E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTSS.exe ()
MOD - E:\program files\evga\EVGA Precision\EVGAPrecision.exe ()
MOD - E:\program files\evga\EVGA Precision\RTHAL.dll ()
MOD - E:\program files\evga\EVGA Precision\RTCore.dll ()
MOD - E:\program files\evga\EVGA Precision\EVGAPrecisionHooks.dll ()
MOD - E:\program files\evga\EVGA Precision\RTUI.dll ()
MOD - E:\program files\evga\EVGA Precision\RTFC.dll ()
MOD - E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTSSHooks.dll ()
MOD - E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTUI.dll ()
MOD - E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTFC.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - \\.\globalroot\systemroot\syswow64\mswsock.dll ()
MOD - C:\Windows\SysWOW64\APOMngr.DLL ()
MOD - C:\Windows\SysWOW64\CmdRtr.DLL ()
MOD - C:\Program Files\Mouse\Amoumain.exe ()
MOD - C:\Program Files\Mouse\Amoures.dll ()
MOD - C:\Windows\SysWOW64\Amhooker.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (O&O Defrag) – C:\Program Files\OO Software\Defrag\oodag.exe (O&O Software GmbH)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (NETw5x32) – C:\Windows\SysNative\PID_08A0.dll (Oak Technology Inc.)
SRV - (MBAMService) – E:\program files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (CTAudSvcService) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (NMSAccess) – E:\program files\Blaze Media Pro\NMSAccess32.exe ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (ha20x2k) – C:\Windows\SysNative\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV:64bit: - (CTEXFIFX.SYS) – C:\Windows\SysNative\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV:64bit: - (CTEXFIFX) – C:\Windows\SysNative\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV:64bit: - (ctaud2k) Creative Audio Driver (WDM) – C:\Windows\SysNative\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctac32k) – C:\Windows\SysNative\drivers\ctac32k.sys (Creative Technology Ltd)
DRV:64bit: - (ctsfm2k) – C:\Windows\SysNative\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV:64bit: - (CT20XUT.SYS) – C:\Windows\SysNative\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV:64bit: - (CT20XUT) – C:\Windows\SysNative\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV:64bit: - (ossrv) – C:\Windows\SysNative\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV:64bit: - (emupia) – C:\Windows\SysNative\drivers\emupia2k.sys (Creative Technology Ltd)
DRV:64bit: - (CTHWIUT.SYS) – C:\Windows\SysNative\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV:64bit: - (CTHWIUT) – C:\Windows\SysNative\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV:64bit: - (ctprxy2k) – C:\Windows\SysNative\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64k.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (Amusbprt) – C:\Windows\SysNative\drivers\Amusbx64.sys (A4Tech Co.,Ltd.)
DRV:64bit: - (Amfilter) – C:\Windows\SysNative\drivers\Amfltx64.sys ((Standard mouse types))
DRV:64bit: - (RTL8187) – C:\Windows\SysNative\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (RtlProt) – C:\Windows\SysNative\drivers\RtlProt.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (RTCore64) – E:\program files\evga\EVGA Precision\RTCore64.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2080295074-847258215-3720127285-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 86 70 2E 03 4A A3 CB 01 [binary data]
IE - HKU\S-1-5-21-2080295074-847258215-3720127285-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6778
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {e2c58150-9d72-11dd-ad8b-0800200c9a66}:1.3.1

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: E:\program files\vlc2\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: E:\program files\firefox\components [2012/02/02 10:24:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: E:\program files\firefox\plugins [2012/01/12 17:54:39 | 000,000,000 | —D | M]

[2010/04/23 00:48:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Loch\AppData\Roaming\Mozilla\Extensions
[2012/01/05 15:48:30 | 000,000,000 | —D | M] (No name found) – C:\Users\Loch\AppData\Roaming\Mozilla\Firefox\Profiles\q0ryv8o3.default\extensions
[2010/04/23 11:42:43 | 000,000,000 | —D | M] (Black Steel) – C:\Users\Loch\AppData\Roaming\Mozilla\Firefox\Profiles\q0ryv8o3.default\extensions\{e2c58150-9d72-11dd-ad8b-0800200c9a66}
() (No name found) – C:\USERS\LOCH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Q0RYV8O3.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI

Hosts file not found
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [WheelMouse] C:\Program Files\Mouse\Amoumain.exe ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AudioDrvEmulator] C:\Program Files (x86)\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\SysWow64\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [EVGAPrecision] E:\program files\evga\EVGA Precision\EVGAPrecisionWrapper.exe ()
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] E:\program files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [WinampAgent] E:\program files\winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2080295074-847258215-3720127285-1001..\Run: [Creative MediaSource Go] C:\Program Files (x86)\Creative\MediaSource5\Go\CTCMSGoU.exe (Creative Technology Ltd)
O4 - HKU\S-1-5-21-2080295074-847258215-3720127285-1001..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - mmswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\wshbth.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {A796D216-2DE1-4EA8-BABB-FE6E7C959098} http://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cab (HPSDDX Class)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{72B389E3-F247-4530-8240-CCE44F13CE2F}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{93A74603-BBFE-4A3B-9214-61BBB91AB219}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{04cb0790-4eac-11df-a39d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{04cb0790-4eac-11df-a39d-806e6f6e6963}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (OODBS)
O34 - HKLM BootExecute: (E BootExecute settings..)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: NETw5x32 - C:\Windows\SysNative\PID_08A0.dll (Oak Technology Inc.)
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FFDS - ff_vfw.dll ()
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\SysWow64\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWow64\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/02/06 11:53:14 | 000,607,260 | —- | C] (Swearware) – C:\Users\Loch\Desktop\dds.scr
[2012/02/06 11:43:36 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Loch\Desktop\HiJackThis.exe
[2012/02/06 11:26:02 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Loch\Desktop\OTL.exe
[2012/02/06 02:25:18 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Roaming\Malwarebytes
[2012/02/06 02:25:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/02/05 23:50:59 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2012/02/05 23:47:38 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Local\BigHugeEngine
[2012/02/05 23:39:37 | 000,000,000 | —D | C] – C:\Windows\system64
[2012/02/03 19:16:30 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Roaming\BigHugeEngine
[2012/01/31 17:57:15 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BOSS
[2012/01/31 17:57:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\BOSS
[2012/01/31 17:35:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager
[2012/01/31 10:23:25 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2012/01/31 10:23:25 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2012/01/31 10:23:25 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2012/01/31 10:23:25 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2012/01/31 10:23:25 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2012/01/31 10:23:25 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2012/01/31 10:23:24 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2012/01/31 10:23:24 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2012/01/29 22:07:26 | 000,000,000 | —D | C] – C:\Users\Loch\Documents\Witcher 2
[2012/01/29 22:07:26 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Local\The Witcher 2
[2012/01/29 22:02:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher 2
[2012/01/16 18:25:31 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA
[2012/01/16 18:23:42 | 006,004,544 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2012/01/16 18:23:42 | 003,028,800 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2012/01/16 18:23:42 | 002,562,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvcr.dll
[2012/01/16 18:23:42 | 000,118,080 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2012/01/16 18:23:42 | 000,063,296 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[2012/01/16 18:23:03 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA Corporation
[2012/01/16 18:22:00 | 025,432,896 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2012/01/16 18:22:00 | 009,622,336 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2012/01/16 18:22:00 | 007,677,248 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2012/01/16 18:21:59 | 019,348,800 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2012/01/16 18:21:58 | 017,483,072 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2012/01/16 18:21:58 | 014,863,680 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2012/01/16 18:21:58 | 001,715,008 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2012/01/16 18:21:58 | 001,454,912 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2012/01/16 18:21:57 | 017,498,432 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2012/01/16 18:21:57 | 007,974,208 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2012/01/16 18:21:57 | 005,868,352 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2012/01/16 18:21:57 | 002,660,160 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2012/01/16 18:21:57 | 002,506,048 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2012/01/16 18:21:57 | 002,374,464 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2012/01/16 18:21:57 | 002,206,016 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2012/01/16 18:21:56 | 025,137,472 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2012/01/16 18:21:56 | 002,403,136 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2012/01/16 18:21:56 | 002,095,424 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2012/01/16 18:21:55 | 000,068,928 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2012/01/16 18:21:55 | 000,061,248 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2012/01/16 18:21:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xtreme-G 290.53 Win7-Vista 64bit
[2012/01/16 18:20:41 | 000,000,000 | —D | C] – C:\NVIDIA
[2012/01/13 14:08:27 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Roaming\vlc
[2012/01/13 14:08:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/01/10 17:40:13 | 000,614,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\COMCTL32.OCX
[2012/01/10 17:40:13 | 000,053,248 | —- | C] (vbAccelerator) – C:\Windows\SysWow64\SSUBTMR6.DLL
[2012/01/10 17:40:13 | 000,010,752 | —- | C] (Almeida & Andrade Ltda) – C:\Windows\SysWow64\aamd532.dll
[2012/01/09 08:46:29 | 000,000,000 | —D | C] – C:\Users\Loch\Documents\Nexus Mod Manager
[2012/01/09 08:46:29 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Local\Black_Tree_Gaming
[2010/07/28 17:31:32 | 000,060,928 | —- | C] ( ) – C:\Windows\SysWow64\a3d.dll
[2010/07/28 17:31:30 | 000,012,800 | —- | C] ( ) – C:\Windows\SysWow64\killapps.exe
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/02/06 11:53:48 | 000,879,683 | —- | M] () – C:\Users\Loch\Desktop\SecurityCheck.exe
[2012/02/06 11:53:26 | 000,302,592 | —- | M] () – C:\Users\Loch\Desktop\pwy6t2ip.exe
[2012/02/06 11:53:14 | 000,607,260 | —- | M] (Swearware) – C:\Users\Loch\Desktop\dds.scr
[2012/02/06 11:43:36 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Loch\Desktop\HiJackThis.exe
[2012/02/06 11:26:02 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Loch\Desktop\OTL.exe
[2012/02/06 11:04:41 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/06 11:04:41 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/06 11:00:30 | 000,000,000 | -HS- | M] () – C:\Windows\SysNative\dds_trash_log.cmd
[2012/02/06 10:59:29 | 000,000,322 | —- | M] () – C:\Windows\tasks\GlaryInitialize.job
[2012/02/06 10:59:29 | 000,000,262 | —- | M] () – C:\Windows\tasks\RtlVistaStart.job
[2012/02/06 10:59:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/02/06 10:59:24 | 2616,549,376 | -HS- | M] () – C:\hiberfil.sys
[2012/02/06 10:59:23 | 000,653,029 | —- | M] () – C:\Windows\SysNative\oodbs.lor
[2012/02/06 04:16:58 | 000,062,644 | —- | M] () – C:\Windows\SysNative\BMXStateBkp-{00000005-00000000-00000002-00001102-00000005-10031102}.rfx
[2012/02/06 04:16:58 | 000,062,644 | —- | M] () – C:\Windows\SysNative\BMXState-{00000005-00000000-00000002-00001102-00000005-10031102}.rfx
[2012/02/06 04:16:58 | 000,000,788 | —- | M] () – C:\Windows\SysNative\DVCState-{00000005-00000000-00000002-00001102-00000005-10031102}.rfx
[2012/02/06 02:31:23 | 000,000,370 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2012/02/06 02:25:14 | 000,000,789 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/05 23:51:02 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/02/05 23:49:49 | 000,000,997 | —- | M] () – C:\Users\Loch\Desktop\Reckoning - Shortcut.lnk
[2012/02/05 00:25:02 | 000,014,336 | —- | M] () – C:\Users\Loch\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/03 22:22:48 | 000,778,150 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/02/03 22:22:48 | 000,659,580 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/02/03 22:22:48 | 000,120,508 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/02/03 19:11:51 | 000,316,691 | LS\x00\x00\x00\x00
Hello lochabar,

Welcome to the Malware Removal Forum. My name is Troy and I will be assisting you with the malware issues on your computer.
Because I am still in training, all the advice I give must first be checked by an instructor, therefore there may be some delays in my replies.

A few things before we get started
  • If you have not already done so Please read these forum rules.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • Any fixes I may post will be specific to your computer and should not be used on other computers.
  • While we work on your computer please don't install any new programs, try any other fixes, or run any tools other than those requested.
  • If at any time my instructions are not clear please ask before proceeding.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.

Step 1
Scan with DDS
  • Please download DDS … by sUBs. Save it to your desktop. Alternate download links here or here.
  • Disable any script blocking software you have running before running DDS.
  • Double click dds.com to run the tool. (File name will be different if alternate download used).
    A black window will open with some instructions/comments…
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
    Caution: The above logs will NOT be saved… you must save them to your desktop.
  • Please post both logs in your next reply.
Thank you for the prompt help. Here are both DDS logs dds log: . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_23 Run by [removed] at 13:14:13 on 2012-02-07 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3327.2125 [GMT -5:00] . AV: Trend Micro Titanium Internet Security 2012 *Disabled/Outdated* {7193B549-236F-55EE-9AEC-F65279E59A92} SP: Trend Micro Titanium Internet Security 2012 *Disabled/Outdated* {CAF254AD-0555-5A60-A05C-CD200262D02F} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation E:\program files\Blaze Media Pro\NMSAccess32.exe C:\Windows\system32\taskhost.exe C:\Program Files\OO Software\Defrag\oodag.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Mouse\Amoumain.exe C:\Program Files\Microsoft IntelliType Pro\itype.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files (x86)\Creative\MediaSource5\Go\CTCMSGoU.exe C:\Program Files\Windows Sidebar\sidebar.exe E:\program files\winamp\winampa.exe C:\Windows\SysWOW64\Ctxfihlp.exe E:\program files\evga\EVGA Precision\EVGAPrecision.exe C:\Windows\SysWOW64\CTXFISPI.EXE E:\program files\Malwarebytes' Anti-Malware\mbamgui.exe E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTSS.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskmgr.exe E:\program files\Core Temp\Core Temp.exe E:\program files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet E:\program files\firefox\firefox.exe C:\Windows\system32\rundll32.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll uRun: [Creative MediaSource Go] "C:\Program Files (x86)\Creative\MediaSource5\Go\CTCMSGoU.exe" /SCB uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun mRun: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe mRun: [EVGAPrecision] "E:\program files\evga\EVGA Precision\EVGAPrecisionWrapper.exe" /s mRun: [WinampAgent] "E:\program files\winamp\winampa.exe" mRun: [VolPanel] "C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r mRun: [AudioDrvEmulator] "C:\Program Files (x86)\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files (x86)\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll" mRun: [CTxfiHlp] CTXFIHLP.EXE mRun: [UpdReg] C:\Windows\UpdReg.EXE mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [Malwarebytes' Anti-Malware] "E:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~4\Office14\ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll LSP: mswsock.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {A796D216-2DE1-4EA8-BABB-FE6E7C959098} - hxxp://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cab DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{72B389E3-F247-4530-8240-CCE44F13CE2F} : DhcpNameServer = [removed] [removed] TCP: Interfaces\{93A74603-BBFE-4A3B-9214-61BBB91AB219} : DhcpNameServer = [removed] [removed] Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2 sxssrv,4 BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL BHO-X64: URLRedirectionBHO - No File BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll mRun-x64: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe mRun-x64: [EVGAPrecision] "E:\program files\evga\EVGA Precision\EVGAPrecisionWrapper.exe" /s mRun-x64: [WinampAgent] "E:\program files\winamp\winampa.exe" mRun-x64: [VolPanel] "C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r mRun-x64: [AudioDrvEmulator] "C:\Program Files (x86)\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files (x86)\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll" mRun-x64: [CTxfiHlp] CTXFIHLP.EXE mRun-x64: [UpdReg] C:\Windows\UpdReg.EXE mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [Malwarebytes' Anti-Malware] "E:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Loch\AppData\Roaming\Mozilla\Firefox\Profiles\q0ryv8o3.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll FF - plugin: E:\program files\firefox\plugins\npdeployJava1.dll FF - plugin: E:\program files\firefox\plugins\npwachk.dll FF - plugin: E:\program files\vlc2\VLC\npvlc.dll . ============= SERVICES / DRIVERS =============== . R1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;C:\Windows\system32\DRIVERS\rtlprot.sys –> C:\Windows\system32\DRIVERS\rtlprot.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 MBAMService;MBAMService;E:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-2-6 652360] R3 CT20XUT.SYS;CT20XUT.SYS;C:\Windows\system32\drivers\CT20XUT.SYS –> C:\Windows\system32\drivers\CT20XUT.SYS [?] R3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\Windows\system32\drivers\CTEXFIFX.SYS –> C:\Windows\system32\drivers\CTEXFIFX.SYS [?] R3 CTHWIUT.SYS;CTHWIUT.SYS;C:\Windows\system32\drivers\CTHWIUT.SYS –> C:\Windows\system32\drivers\CTHWIUT.SYS [?] R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys –> C:\Windows\system32\drivers\mbam.sys [?] R3 RTCore64;RTCore64;E:\program files\evga\EVGA Precision\RTCore64.sys [2010-5-21 14440] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys –> C:\Windows\system32\DRIVERS\yk62x64.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;"C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL1Licensing.exe" –> C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL1Licensing.exe [?] S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-7-28 79360] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-7-28 79360] S3 CT20XUT;CT20XUT;C:\Windows\system32\drivers\CT20XUT.SYS –> C:\Windows\system32\drivers\CT20XUT.SYS [?] S3 CTEXFIFX;CTEXFIFX;C:\Windows\system32\drivers\CTEXFIFX.SYS –> C:\Windows\system32\drivers\CTEXFIFX.SYS [?] S3 CTHWIUT;CTHWIUT;C:\Windows\system32\drivers\CTHWIUT.SYS –> C:\Windows\system32\drivers\CTHWIUT.SYS [?] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-3-25 51456888] S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 RTL8187;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\rtl8187.sys –> C:\Windows\system32\DRIVERS\rtl8187.sys [?] . =============== Created Last 30 ================ . 2012-02-06 07:25:18 ——– d—–w- C:\Users\Loch\AppData\Roaming\Malwarebytes 2012-02-06 04:47:38 ——– d—–w- C:\Users\Loch\AppData\Local\BigHugeEngine 2012-02-06 04:40:44 0 –sha-w- C:\Windows\System32\dds_trash_log.cmd 2012-02-06 04:39:37 ——– d—–we C:\Windows\system64 2012-02-04 00:16:30 ——– d—–w- C:\Users\Loch\AppData\Roaming\BigHugeEngine 2012-01-31 22:57:15 ——– d—–w- C:\Program Files (x86)\Common Files\BOSS 2012-01-31 15:23:25 99176 —-a-w- C:\Windows\SysWow64\PresentationHostProxy.dll 2012-01-31 15:23:25 49472 —-a-w- C:\Windows\SysWow64\netfxperf.dll 2012-01-31 15:23:25 444752 —-a-w- C:\Windows\System32\mscoree.dll 2012-01-31 15:23:25 320352 —-a-w- C:\Windows\System32\PresentationHost.exe 2012-01-31 15:23:25 297808 —-a-w- C:\Windows\SysWow64\mscoree.dll 2012-01-31 15:23:25 295264 —-a-w- C:\Windows\SysWow64\PresentationHost.exe 2012-01-31 15:23:25 1130824 —-a-w- C:\Windows\SysWow64\dfshim.dll 2012-01-31 15:23:25 109912 —-a-w- C:\Windows\System32\PresentationHostProxy.dll 2012-01-31 15:23:24 48960 —-a-w- C:\Windows\System32\netfxperf.dll 2012-01-31 15:23:24 1942856 —-a-w- C:\Windows\System32\dfshim.dll 2012-01-30 03:07:26 ——– d—–w- C:\Users\Loch\AppData\Local\The Witcher 2 2012-01-16 23:23:42 889664 —-a-w- C:\Windows\System32\nvvsvc.exe 2012-01-16 23:23:42 63296 —-a-w- C:\Windows\System32\nvshext.dll 2012-01-16 23:23:42 6004544 —-a-w- C:\Windows\System32\nvcpl.dll 2012-01-16 23:23:42 3028800 —-a-w- C:\Windows\System32\nvsvc64.dll 2012-01-16 23:23:42 2562368 —-a-w- C:\Windows\System32\nvsvcr.dll 2012-01-16 23:23:42 118080 —-a-w- C:\Windows\System32\nvmctray.dll 2012-01-16 23:23:03 ——– d—–w- C:\ProgramData\NVIDIA Corporation 2012-01-16 23:22:00 9622336 —-a-w- C:\Windows\System32\nvwgf2umx.dll 2012-01-16 23:22:00 7677248 —-a-w- C:\Windows\SysWow64\nvwgf2um.dll 2012-01-16 23:22:00 25432896 —-a-w- C:\Windows\System32\nvoglv64.dll 2012-01-16 23:20:41 ——– d—–w- C:\NVIDIA 2012-01-10 22:40:13 614992 —-a-w- C:\Windows\SysWow64\COMCTL32.OCX 2012-01-10 22:40:13 53248 —-a-w- C:\Windows\SysWow64\SSUBTMR6.DLL 2012-01-10 22:40:13 10752 —-a-w- C:\Windows\SysWow64\aamd532.dll 2012-01-09 13:46:29 ——– d—–w- C:\Users\Loch\AppData\Local\Black_Tree_Gaming . ==================== Find3M ==================== . 2012-02-06 04:51:02 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-12-10 20:24:08 23152 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-11-15 19:29:56 270720 ——w- C:\Windows\System32\MpSigStub.exe . ============= FINISH: 13:14:48.15 =============== DDS attach log: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Ultimate Boot Device: \Device\HarddiskVolume3 Install Date: 4/23/2010 3:49:17 AM System Uptime: 2/7/2012 1:01:07 PM (0 hours ago) . Motherboard: ASUSTeK Computer INC. | | P5K Premium Processor: Intel® Core™2 Duo CPU E8400 @ 3.00GHz | LGA775 | 3005/333mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 29 GiB total, 3.574 GiB free. D: is FIXED (NTFS) - 59 GiB total, 11.685 GiB free. E: is FIXED (NTFS) - 120 GiB total, 33.932 GiB free. F: is FIXED (NTFS) - 90 GiB total, 12.875 GiB free. G: is CDROM () H: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e96b-e325-11ce-bfc1-08002be10318} Description: Standard PS/2 Keyboard Device ID: ACPI\PNP0303\4&23F9C1E3&0 Manufacturer: (Standard keyboards) Name: Standard PS/2 Keyboard PNP Device ID: ACPI\PNP0303\4&23F9C1E3&0 Service: i8042prt . ==== System Restore Points =================== . RP392: 2/6/2012 11:59:38 AM - OTL Restore Point - 2/6/2012 11:59:37 AM . ==== Installed Programs ====================== . Sansa Media Converter µTorrent Acrobat.com Adobe AIR Adobe Flash Player 11 Plugin Adobe Reader 9.5.0 Apple Application Support Apple Software Update Ashampoo Burning Studio 10.0.1 Blaze Media Pro BOSS calibre Creative Media Toolbox Creative MediaSource 5 Creative System Information Crysis 2 dBpoweramp DSP Effects dBpoweramp Music Converter Dead Space™ 2 Deus Ex - Human Revolution version 1.0 Deus Ex Human Revolution - The Missing Link EVGA Precision 1.9.4 FLAC 1.2.1b (remove only) FreeSpace 2 Glary Utilities Pro 2.17.0.776 HijackThis 2.0.2 Java Auto Updater Java™ 6 Update 23 JMicron JMB36X Driver jv16 PowerTools 2010 Beta7 K-Lite Mega Codec Pack 7.7.0 Malwarebytes Anti-Malware version 1.60.1.1000 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Monkey's Audio Mozilla Firefox 10.0 (x86 en-US) Mumble and Murmur Neverwinter Nights 2 Adventure Pack: Mysteries of Westgate NVIDIA PhysX OpenAL OpenRPG Python 2.6.2 QuickPar 0.9 QuickTime Sansa Updater Sound Blaster X-Fi The KMPlayer (remove only) The Witcher 2 VC80CRTRedist - 8.0.50727.4053 VLC media player 1.1.11 Winamp Winamp Detector Plug-in wxPython [removed] (unicode) for Python 2.6 XnView 1.98.5 Xtreme-G 285.79 Win7-Vista 64bit Xtreme-G 290.53 Win7-Vista 64bit . ==== Event Viewer Messages From Past Week ======== . 2/7/2012 1:08:20 PM, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file. 2/7/2012 1:08:17 PM, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143. 2/7/2012 1:01:31 PM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed. 2/7/2012 1:01:27 PM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service. 2/7/2012 1:01:27 PM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed. 2/6/2012 4:19:11 AM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 2/6/2012 4:19:11 AM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 2/6/2012 4:18:08 AM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start. 2/6/2012 4:18:08 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 2/6/2012 4:18:08 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 2/6/2012 4:18:06 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89} 2/6/2012 4:18:06 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E} 2/6/2012 4:18:05 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 2/6/2012 4:17:59 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 2/6/2012 4:17:53 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD CSC DfsC discache NetBIOS NetBT nsiproxy Psched rdbss RtlProt spldr sptd tdx vwififlt Wanarpv6 WfpLwf 2/6/2012 4:17:53 AM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 2/6/2012 4:17:53 AM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 2/6/2012 4:17:53 AM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning. 2/6/2012 4:17:53 AM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 2/6/2012 4:17:53 AM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 2/6/2012 4:17:53 AM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning. 2/6/2012 4:17:53 AM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 2/6/2012 4:17:53 AM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning. 2/6/2012 4:17:53 AM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 2/6/2012 4:17:53 AM, Error: Service Control Manager [7001] - The Creative Audio Service service depends on the Windows Audio service which failed to start because of the following error: The dependency service or group failed to start. 2/6/2012 4:17:53 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 2/6/2012 4:17:34 AM, Error: sptd [4] - Driver detected an internal error in its data structures for . 2/5/2012 6:08:28 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000109 (0xa3a039d89b0de57b, 0x0000000000000000, 0x23c1088f42178de8, 0x0000000000000101). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 020512-20701-01. 2/5/2012 1:47:17 PM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. 2/3/2012 10:27:41 PM, Error: VDS Basic Provider [1] - Unexpected failure. Error code: 490@01010004 2/2/2012 1:56:39 AM, Error: Service Control Manager [7023] - The Function Discovery Resource Publication service terminated with the following error: %%-2147014847 2/1/2012 9:21:49 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR3. . ==== End Of File ===========================
Hi lochabar,

Rootkit!
I have reviewed your log and found your computer has been infected with a Rootkit.
A rootkit is a set of software tools intended for concealing running processes, files or system data from the operating system. This allows the attacker to make changes to your system so that they can use it for malicious purposes without your knowledge. They can collect and transmit personal information including usernames, passwords, and personally identifiable information.

You are strongly advised to do the following:
  • Disconnect the computer from the Internet and from any networked computers until it is cleaned.
  • Call all your banks, financial institutions, credit card companies and inform them that you may be a victim of identity theft, put a watch on your accounts, and change all your account numbers.
  • From a clean computer, change all your passwords
    (ISP login password, your email address(es) passwords, financial accounts, PayPal, eBay, Amazon, any online activity you perform, requiring a username and password).
    Do NOT change your passwords from this computer as the attacker will be able to get all the new passwords and transaction records.
  • Back up all your important data except programs. The programs can be reinstalled back from the original disc or from the Net.

Because your computer is infected with a rootkit it is impossible to know all the changes that may have been made to your system. The best course of action would be to re-format and re-install your operating system.
If you would like to try and clean your system I will help, but I would advise against it. In the end, the clean-up procees is likely to take as long or longer than a re-format and re-install, and because we cannot know what changes were made, the computer can never be trusted again untill it has been re-formatted.

Please see the following articles for more information.
How to Reformat and Reinstall your Operating System
When should I re-format and reinstall my OS
What are Remote Access Trojans and why are they dangerous?
Back up and restore: frequently asked questions
Restoring your backups


Registry Cleaners
While analysing your logs, I noticed the following programs installed.

Glary Utilities Pro 2.17.0.776
jv16 PowerTools 2010 Beta7


I don't personally recommend the use of ANY registry cleaners. Here is an excerpt from a discussion on reg cleaners.

Most reg cleaners aren't bad as such, but they aren't perfect and even the best have been known to cause problems. The point we are trying to make is that the risk of using one far outweighs any benefit. If it does work perfectly you will not see any difference. If it doesn't work properly you may end up with an expensive doorstop.

This post by Bill Castner is very informative: WhatTheTech Forum



I think your best option is to Reformat and Reinstall Windows but, if you want to try and clean it start with the following.

Step 1
CKScanner

  • Please download CKScanner from Here
  • Save it to your desktop.
  • Right-click CKScanner.exe > select " Run as administrator " then click Search For Files.
  • After a short time, when it has finished running, click Save List To File.
  • A message box will verify the file saved. Please Run the program only once.
  • Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.

Either way please reply back and let me know how you would like to proceed.

Troy
I'd like to try to clean the system up as well as possible and THEN do a reinstall. That will make it easier to save data from all 4 current partitions without worrying about contaminating a future install. Have run CKScanner, here is the savelog. It didn't have much to say…. CKScanner - Additional Security Risks - These are not necessarily bad scanner sequence 3.RP.11.ENAACR —– EOF —–
Hi lochabar, I think that reformatting is the right decision. If you are going to do a reformat then there's no point in attempting to clean the machine since the reformat will totally remove the infection. Please see the articles from my previous post for more information on backing up your system before reformatting. Troy

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI