This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Mor.exe has stopped working [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there. After doing a quick google search I was directed to these forums and I registered with the hopes that someone might be able to help. I've ran the ESET online scanner which came up with 14 threats that it has claimed to have cleaned. I restarted my computer and ran TDSS and OTL but as far as I know both seem to have found nothing. I am going to post the log from ESET so maybe I can get some insight as to what's wrong.

C:\Users\Mike\AppData\Local\Temp\1uiu12gug1s44u2gy3.exe a variant of Win32/Kryptik.AHRW trojan cleaned by deleting - quarantined
C:\Users\Mike\AppData\Local\Temp\nsrexg.dll a variant of Win32/Medfos.AD trojan cleaned by deleting (after the next restart) - quarantined
C:\Users\Mike\AppData\Local\Temp\whuid.dll Win32/Medfos.T trojan cleaned by deleting (after the next restart) - quarantined
C:\Users\Mike\AppData\Local\{5aff48e4-4589-eed1-dcb5-0d23c1cbdb72}\n Win64/Sirefef.W trojan cleaned by deleting (after the next restart) - quarantined
C:\Users\Mike\AppData\Local\{BB7AC108-9E2D-11E1-826F-B8AC6F996F26}\chrome\content\browser.xul JS/Redirector.NIQ trojan cleaned by deleting - quarantined
C:\Users\Mike\Downloads\21_Jump_Street[2012]BRRip_XviD-ETRG.exe Win32/Adware.1ClickDownload.E application cleaned by deleting - quarantined
C:\Users\Mike\Downloads\YouTubeDownloaderSetup35.exe Win32/Toolbar.Widgi application cleaned by deleting - quarantined
C:\Users\Mike\Downloads\Elcomsoft Password Recovery Bundle 2007\AIMPR v3.50\aimpr.exe probably a variant of Win32/Agent.NQTKWMV trojan cleaned by deleting - quarantined
C:\Windows\KMService.exe Win32/HackKMS.A application cleaned by deleting (after the next restart) - quarantined
C:\Windows\Installer\{5aff48e4-4589-eed1-dcb5-0d23c1cbdb72}\n Win64/Sirefef.W trojan cleaned by deleting - quarantined
C:\Windows\Installer\{5aff48e4-4589-eed1-dcb5-0d23c1cbdb72}\U\80000000.@ Win64/Sirefef.AL trojan cleaned by deleting - quarantined
G:\Users\Mike\Downloads\YouTubeDownloaderSetup35.exe Win32/Toolbar.Widgi application cleaned by deleting - quarantined
G:\Users\Mike\Downloads\Elcomsoft Password Recovery Bundle 2007\AIMPR v3.50\aimpr.exe probably a variant of Win32/Agent.NQTKWMV trojan cleaned by deleting - quarantined
G:\Windows\KMService.exe Win32/HackKMS.A application cleaned by deleting - quarantined

That was from ESET and I'll also post the OTL log.

OTL logfile created on: 28/07/2012 5:40:00 PM - Run 1
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\Mike\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

5.99 Gb Total Physical Memory | 4.35 Gb Available Physical Memory | 72.58% Memory free
11.98 Gb Paging File | 10.10 Gb Available in Paging File | 84.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.67 Gb Total Space | 45.26 Gb Free Space | 9.72% Space Free | Partition Type: NTFS
Drive G: | 465.76 Gb Total Space | 148.57 Gb Free Space | 31.90% Space Free | Partition Type: NTFS

Computer Name: MIKE-PC | User Name: Mike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mike\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001 (Macrovision Europe Ltd.)
PRC - C:\Users\Mike\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Overwolf\Overwolf.exe (Overwolf)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe (Creative Labs)
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Logitech\G35\G35.exe (Logitech©)
PRC - C:\Program Files (x86)\InstallShield Installation Information\{3A94E148-9C8B-4FE9-99DD-93072F99BE20}\AMBSPISyncService.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe (Creative Technology Ltd)


========== Modules (No Company Name) ==========

MOD - C:\Users\Mike\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0235\~de6248.tmp ()
MOD - C:\Users\Mike\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0235\~df394b.tmp ()
MOD - C:\Program Files (x86)\Overwolf\OWServer.dll ()
MOD - C:\Program Files (x86)\Overwolf\OWService.dll ()
MOD - C:\Program Files (x86)\Overwolf\OverWolf.BL.Interfaces.dll ()
MOD - C:\Program Files (x86)\Overwolf\BrowserWindow.dll ()
MOD - C:\Program Files (x86)\Overwolf\OWInjector.dll ()
MOD - C:\Program Files (x86)\Overwolf\OverWolf.Client.Core.dll ()
MOD - C:\Program Files (x86)\Overwolf\OWExplorer-1066.dll ()
MOD - C:\Program Files (x86)\Overwolf\CoreAudioApi.dll ()
MOD - C:\Program Files (x86)\Overwolf\OWLog.dll ()
MOD - C:\Program Files (x86)\Overwolf\ODK.AddIns.V1.HostView.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\SysWOW64\APOMngr.DLL ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Windows\SysWOW64\CmdRtr.DLL ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\de8525cc2e6327337e1c6917352bfe16\WindowsFormsIntegration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\89deefc2bee804776ba425a42814ae3b\System.AddIn.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\4b1607fbccd7ac11f43121d5d027a2c7\System.AddIn.Contract.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\1762137638019a091020b3baf52f6de3\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\39f5a71b5185d267b0f55cd4cea26d6b\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\68e5eeb3c6ef18ba2dc1ad70eb74aeee\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e71959f4ec6eb386889050ac139835c7\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7b459c5815af8123e4bf30d4e05bba65\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\c2f9dd7db911053edcaaadf5fefc500a\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b1350e31ff09cc583b34854816d8036\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (LBTServ) – C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (AEADIFilters) – C:\Windows\SysNative\AEADISRV.EXE (Andrea Electronics Corporation)
SRV - (xsherlock) – C:\Windows\SysWOW64\xsherlock.xem (Wellbia.com Co., Ltd.)
SRV - (OverwolfUpdaterService) – C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe (Overwolf Ltd)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (npggsvc) – C:\Windows\SysWOW64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (Futuremark SystemInfo Service) – C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe (Futuremark Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Sound Blaster X-Fi MB Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe (Creative Labs)
SRV - (CTAudSvcService) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (jswpsapi) – C:\Program Files (x86)\D-Link\DWA-552 revA\jswpsapi.exe (Atheros Communications, Inc.)
SRV - (KMService) – C:\Windows\SysWOW64\srvany.exe ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (ivusb) – C:\Windows\SysNative\drivers\ivusb.sys (Initio Corporation)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (ElbyCDIO) – C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (LGVirHid) – C:\Windows\SysNative\drivers\LGVirHid.sys (Logitech Inc.)
DRV:64bit: - (LGBusEnum) – C:\Windows\SysNative\drivers\LGBusEnum.sys (Logitech Inc.)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (VClone) – C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (XENfiltv) – C:\Windows\SysNative\drivers\XENfiltv.sys (Creative Technology Ltd.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (LADF_SBVM) – C:\Windows\SysNative\drivers\ladfSBVMamd64.sys (Logitech)
DRV:64bit: - (LADF_DHP2) – C:\Windows\SysNative\drivers\ladfDHP2amd64.sys (Logitech)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (WmXlCore) – C:\Windows\SysNative\drivers\WmXlCore.sys (Logitech Inc.)
DRV:64bit: - (WmVirHid) – C:\Windows\SysNative\drivers\WmVirHid.sys (Logitech Inc.)
DRV:64bit: - (WmHidLo) – C:\Windows\SysNative\drivers\WmHidLo.sys (Logitech Inc.)
DRV:64bit: - (WmFilter) – C:\Windows\SysNative\drivers\WmFilter.sys (Logitech Inc.)
DRV:64bit: - (WmBEnum) – C:\Windows\SysNative\drivers\WmBEnum.sys (Logitech Inc.)
DRV:64bit: - (RimVSerPort) – C:\Windows\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:64bit: - (JSWPSLWF) – C:\Windows\SysNative\drivers\jswpslwfx.sys (Atheros Communications, Inc.)
DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV:64bit: - (ADIHdAudAddService) – C:\Windows\SysNative\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (Gun) – C:\Game\SoftnyxGame\GunboundIS\Gun64.sys ()
DRV - (RTCore64) – C:\Program Files (x86)\EVGA Precision\RTCore64.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (JSWPSLWF) – C:\Windows\SysWOW64\drivers\jswpslwfx.sys (Atheros Communications, Inc.)
DRV - (NPPTNT2) – C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?lang=en-ca&OCID=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-CA
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B6 F8 B8 CE 23 6B CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {6D5D296B-F4C9-4A6A-87C8-D3024BCDF1B8}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6D5D296B-F4C9-4A6A-87C8-D3024BCDF1B8}: "URL" = http://www.google.com/search?q={searchTerm…utputEncoding?}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar: C:\Program Files (x86)\BF3 Alpha Trial Web Plugins\Sonar\npesnsonar.dll (ESN AB)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.0: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch: C:\Program Files (x86)\BF3 Alpha Trial Web Plugins\npesnlaunch.dll (ESN AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.104.0: C:\Program Files (x86)\Battlelog Web Plugins\1.104.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.96.0: C:\Program Files (x86)\Battlelog Web Plugins\1.96.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Mike\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Mike\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Mike\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\components [2012/06/26 15:56:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\plugins [2012/04/24 08:12:40 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{BB7AC108-9E2D-11E1-826F-B8AC6F996F26}: C:\Users\Mike\AppData\Local\{BB7AC108-9E2D-11E1-826F-B8AC6F996F26}\ [2012/05/14 21:31:46 | 000,000,000 | —D | M]

[2010/07/08 11:46:16 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Extensions
[2012/05/14 21:31:46 | 000,000,000 | —D | M] (Mozilla Safe Browsing) – C:\USERS\MIKE\APPDATA\LOCAL\{BB7AC108-9E2D-11E1-826F-B8AC6F996F26}

========== Chrome ==========

CHR - homepage: http://www.msn.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.msn.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Mike\AppData\Local\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Mike\AppData\Local\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Mike\AppData\Local\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Mike\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\plugins\np-mswmp.dll
CHR - plugin: ijji Auto Install Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\plugins\npijjiautoinstallpluginff.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL
CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\BF3 Alpha Trial Web Plugins\Sonar\npesnsonar.dll
CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\BF3 Alpha Trial Web Plugins\npesnlaunch.dll
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\1.104.0\npesnlaunch.dll
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\1.96.0\npesnlaunch.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Mike\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Mike\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - Extension: Angry Birds = C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: Realm of the Mad God = C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjfmaldpppkmjjgkmadddbanpabfflp\1.0.0.3_0\
CHR - Extension: Realm of the Mad God = C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhjfmaldpppkmjjgkmadddbanpabfflp\1.0.0.3_0\~
CHR - Extension: Classic Blue Theme = C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilkecpolncpdeefgdlnhmmdghkmonfkk\1.2_0\

O1 HOSTS File: ([2010/06/17 17:45:32 | 000,000,854 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [nsrexg] rundll32.exe "C:\Users\Mike\AppData\Local\Temp\nsrexg.dll",CreateCubeTextureFromFileA File not found
O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [whuid] rundll32.exe "C:\Users\Mike\AppData\Local\Temp\whuid.dll",SteamClient File not found
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CTSyncService] C:\Program Files (x86)\InstallShield Installation Information\{3A94E148-9C8B-4FE9-99DD-93072F99BE20}\AMBSPISyncService.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Logitech G35] C:\Program Files (x86)\Logitech\G35\G35.exe (Logitech©)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [Overwolf] C:\Program Files (x86)\Overwolf\Overwolf.exe (Overwolf)
O4 - HKCU..\Run: [PlayNC Launcher] File not found
O4 - HKCU..\Run: [Tmuquj] C:\Users\Mike\AppData\Roaming\Tmuquj.exe File not found
O4 - HKCU..\Run: [WINSXS32] C:\Users\Mike\AppData\Roaming\BE9D.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} http://messenger.zone.msn.com/MessengerGam…S.cab109791.cab ()
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/up…er_1.0.26.2.cab (Battlefield Play4Free Updater)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7BC5C6F1-D03F-4735-96BF-E1C6B3A7C99C}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Overwolf\SKYPE4~2.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{146b6d64-804a-11df-89a7-002354edf496}\Shell - "" = AutoRun
O33 - MountPoints2\{146b6d64-804a-11df-89a7-002354edf496}\Shell\AutoRun\command - "" = E:\runidx.exe
O33 - MountPoints2\{46ef821e-aa60-11df-8c0f-002354edf496}\Shell - "" = AutoRun
O33 - MountPoints2\{46ef821e-aa60-11df-8c0f-002354edf496}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{5e14081c-7939-11df-84b7-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{5e14081c-7939-11df-84b7-806e6f6e6963}\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/28 12:45:32 | 000,597,504 | —- | C] (OldTimer Tools) – C:\Users\Mike\Desktop\OTL.exe
[2012/07/28 11:18:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012/07/23 23:42:39 | 000,654,944 | —- | C] (Wellbia.com Co., Ltd.) – C:\Windows\SysWow64\xsherlock.xem
[2012/07/23 23:42:24 | 000,000,000 | —D | C] – C:\Users\Mike\Documents\C9
[2012/07/23 23:39:03 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Webzen Hub
[2012/07/23 23:38:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Overwolf
[2012/07/23 23:38:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Overwolf
[2012/07/23 23:38:08 | 000,000,000 | —D | C] – C:\Users\Mike\Desktop\C9
[2012/07/23 23:37:19 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Local\Overwolf
[2012/07/23 23:36:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\C9
[2012/07/23 23:27:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\WEBZEN
[2012/07/23 22:40:51 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DiskInternals
[2012/07/23 22:40:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DiskInternals
[2012/07/23 22:40:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\DiskInternals
[2012/07/15 19:28:20 | 000,000,000 | —D | C] – C:\Users\Mike\Desktop\Android Stuff
[2012/07/15 12:34:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftnyxGame
[2012/07/15 12:33:59 | 000,000,000 | —D | C] – C:\Game
[2012/07/13 23:22:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012/07/13 23:22:38 | 000,000,000 | —D | C] – C:\Program Files\7-Zip
[2012/07/13 23:13:16 | 001,721,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WdfCoInstaller01009.dll
[2012/07/13 23:13:16 | 001,002,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WinUSBCoInstaller2.dll
[2012/07/07 21:51:02 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Local\Creative
[2012/07/07 21:45:57 | 000,873,472 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\XENAPO64.dll
[2012/07/07 21:45:57 | 000,733,184 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysWow64\XENAPO32.dll
[2012/07/07 21:45:57 | 000,285,696 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\XENCFX64.dll
[2012/07/07 21:45:57 | 000,235,520 | —- | C] (Creative Technology Limited) – C:\Windows\SysNative\XENcInst.dll
[2012/07/07 21:45:57 | 000,219,136 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysWow64\XENCFX32.dll
[2012/07/07 21:45:57 | 000,057,856 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\XENpld64.dll
[2012/07/07 21:45:57 | 000,042,496 | —- | C] (Creative Technology Ltd.) – C:\Windows\AddCat.exe
[2012/07/07 21:45:57 | 000,025,600 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\drivers\XENfiltv.sys
[2012/07/07 21:45:57 | 000,010,752 | —- | C] (Creative Technology Ltd.) – C:\Windows\XENDefE.exe
[2012/07/07 21:36:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2012/06/28 19:27:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\1ClickDownload
[7 C:\*.tmp files -> C:\*.tmp -> ]
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Users\Mike\Documents\*.tmp files -> C:\Users\Mike\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/28 17:36:38 | 000,010,208 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/28 17:36:38 | 000,010,208 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/28 17:32:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2362873391-3827102734-1216569792-1001UA.job
[2012/07/28 17:31:22 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/07/28 17:31:18 | 529,858,559 | -HS- | M] () – C:\hiberfil.sys
[2012/07/28 12:45:32 | 000,597,504 | —- | M] (OldTimer Tools) – C:\Users\Mike\Desktop\OTL.exe
[2012/07/25 21:21:32 | 000,654,944 | —- | M] (Wellbia.com Co., Ltd.) – C:\Windows\SysWow64\xsherlock.xem
[2012/07/23 23:39:03 | 000,001,979 | —- | M] () – C:\Users\Public\Desktop\Webzen Hub.lnk
[2012/07/23 23:36:29 | 000,001,956 | —- | M] () – C:\Users\Mike\Desktop\C9.lnk
[2012/07/23 23:02:40 | 715,642,730 | —- | M] () – C:\Users\Mike\Desktop\Global_C9_Full_Setup.zip
[2012/07/22 19:36:44 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2362873391-3827102734-1216569792-1001Core.job
[2012/07/20 20:08:10 | 000,000,221 | —- | M] () – C:\Users\Mike\Desktop\Nexuiz.url
[2012/07/15 12:34:42 | 000,000,824 | —- | M] () – C:\Users\Mike\Desktop\GunboundIS.lnk
[2012/07/13 23:43:54 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01009.Wdf
[2012/07/12 07:32:33 | 000,002,395 | —- | M] () – C:\Users\Mike\Desktop\Google Chrome.lnk
[2012/07/07 21:46:02 | 000,000,376 | RH– | M] () – C:\Windows\ctfile.rfc
[2012/07/07 21:45:53 | 000,466,520 | —- | M] (Creative Labs) – C:\Windows\SysNative\wrap_oal.dll
[2012/07/07 21:45:53 | 000,445,016 | —- | M] (Creative Labs) – C:\Windows\SysWow64\wrap_oal.dll
[2012/07/07 21:45:53 | 000,123,480 | —- | M] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\Windows\SysNative\OpenAL32.dll
[2012/07/07 21:45:53 | 000,109,144 | —- | M] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\Windows\SysWow64\OpenAL32.dll
[7 C:\*.tmp files -> C:\*.tmp -> ]
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Users\Mike\Documents\*.tmp files -> C:\Users\Mike\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/28 12:47:24 | 000,016,896 | —- | C] () – C:\Windows\Installer\{5aff48e4-4589-eed1-dcb5-0d23c1cbdb72}\U\80000000.@
[2012/07/23 23:39:03 | 000,001,979 | —- | C] () – C:\Users\Public\Desktop\Webzen Hub.lnk
[2012/07/23 23:36:29 | 000,001,956 | —- | C] () – C:\Users\Mike\Desktop\C9.lnk
[2012/07/23 23:19:16 | 715,642,730 | —- | C] () – C:\Users\Mike\Desktop\Global_C9_Full_Setup.zip
[2012/07/20 20:08:10 | 000,000,221 | —- | C] () – C:\Users\Mike\Desktop\Nexuiz.url
[2012/07/15 12:34:42 | 000,000,824 | —- | C] () – C:\Users\Mike\Desktop\GunboundIS.lnk
[2012/07/13 23:43:54 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01009.Wdf
[2012/07/07 21:46:02 | 000,032,434 | —- | C] () – C:\Windows\SysNative\xfiXen.ini
[2012/07/07 21:45:57 | 000,011,084 | —- | C] () – C:\Windows\XENAPO64.ssc
[2012/07/07 21:45:57 | 000,006,737 | —- | C] () – C:\Windows\XENCFX64.ssc
[2012/07/07 21:45:57 | 000,002,169 | —- | C] () – C:\Windows\XENcfg.ini
[2012/07/07 21:45:57 | 000,000,388 | —- | C] () – C:\Windows\XENMCcfg.ini
[2012/07/07 21:45:39 | 000,007,062 | —- | C] () – C:\Windows\SysWow64\audiopid.vxd
[2012/06/13 19:02:10 | 000,023,040 | —- | C] () – C:\Windows\Installer\{5aff48e4-4589-eed1-dcb5-0d23c1cbdb72}\U\800000cb.@
[2012/06/13 19:02:10 | 000,001,712 | —- | C] () – C:\Windows\Installer\{5aff48e4-4589-eed1-dcb5-0d23c1cbdb72}\U\00000001.@
[2012/05/03 14:40:35 | 000,040,960 | —- | C] () – C:\Windows\SysWow64\psfind.dll
[2012/05/02 22:54:46 | 000,042,392 | —- | C] () – C:\Windows\SysWow64\xfcodec.dll
[2012/01/29 20:42:14 | 000,003,232 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp m4a Codec.dat
[2011/11/15 08:53:21 | 000,021,504 | —- | C] () – C:\Windows\jestertb.dll
[2011/10/15 01:54:52 | 000,321,856 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2011/09/28 21:44:47 | 000,000,786 | —- | C] () – C:\Windows\AAPR2.INI
[2011/04/09 18:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/02/21 17:12:07 | 000,010,105 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2011/02/21 17:12:04 | 000,014,645 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2011/01/21 01:02:26 | 000,850,152 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2011/01/12 18:08:12 | 000,056,927 | —- | C] () – C:\Windows\SysWow64\wbers.dat.dmp
[2010/12/15 19:43:20 | 000,280,904 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2010/12/15 19:43:19 | 000,075,136 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2010/12/15 19:43:18 | 000,669,184 | —- | C] () – C:\Windows\SysWow64\pbsvc.exe
[2010/12/10 09:42:21 | 000,001,057 | —- | C] () – C:\Users\Mike\AppData\Roaming\vso_ts_preview.xml
[2010/08/16 08:25:46 | 000,038,912 | —- | C] () – C:\Users\Mike\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/17 17:50:43 | 000,000,132 | —- | C] () – C:\Users\Mike\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2009/07/13 19:22:13 | 000,002,048 | -HS- | C] () – C:\Windows\Installer\{5aff48e4-4589-eed1-dcb5-0d23c1cbdb72}\@
[2009/07/13 19:22:13 | 000,002,048 | -HS- | C] () – C:\Users\Mike\AppData\Local\{5aff48e4-4589-eed1-dcb5-0d23c1cbdb72}\@

========== LOP Check ==========

[2010/06/26 12:28:44 | 000,000,000 | -HSD | M] – C:\Users\Mike\AppData\Roaming\.#
[2012/01/29 21:36:50 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\Apowersoft
[2012/03/24 16:46:06 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\com.cipherprime.auditorium
[2011/06/27 15:24:55 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\dBpoweramp
[2010/08/23 23:16:31 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\DMCache
[2011/03/06 20:53:56 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\DVDVideoSoft
[2011/02/02 00:20:46 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\Hi-Rez Studios
[2011/01/22 19:55:11 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\ijjigame
[2010/11/20 13:16:01 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\IrfanView
[2010/06/16 07:33:00 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\Leadertech
[2010/06/17 13:00:33 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\LolClient
[2012/05/31 12:37:32 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\LolClient2
[2010/06/18 22:53:36 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\MotionDSP
[2010/06/29 07:25:00 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\OpenCandy
[2011/10/25 22:19:15 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\Origin
[2011/01/14 22:48:35 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\Research In Motion
[2012/07/01 22:12:27 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\uTorrent
[2012/03/03 00:04:32 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\Vso
[2011/05/11 20:20:58 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\wargaming.net
[2012/03/03 00:17:05 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\Xilisoft
[2012/07/06 07:32:21 | 000,032,574 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\SysWOW64\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 21:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2009/07/13 21:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\SysWOW64\userinit.exe
[2009/07/13 21:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 21:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\SysNative\userinit.exe
[2009/07/13 21:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/07/13 21:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\SysNative\winlogon.exe
[2009/07/13 21:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:890CC2F3

< End of report >

Thanks for any help!
:welcome:

A couple of the files ESET removed and other markers in your OTL log show that your infected with the ZeroAccess rootkit, this is a nasty piece of malware that can leave damage on your system, with an infection like this most times you would be better off doing a format of your hard drive and a clean install of windows

How is your computer behaving, what are you experiencing ?

Lets see if anything else is underfoot

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
Ah that doesn't sound too good. Thanks for the reply though! My computer is behaving pretty normal actually. Aside from after running OTL my icons start up at large view as opposed to small view and at every start up I get an error message saying whuid.dll has failed and some other .dll has failed. Next time I reboot I'll get exactly what it is for you. However, here is my aswMBR log. aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-07-29 08:35:50 —————————– 08:35:50.285 OS Version: Windows x64 6.1.7600 08:35:50.285 Number of processors: 4 586 0x1A04 08:35:50.285 ComputerName: MIKE-PC UserName: Mike 08:35:51.395 Initialize success 08:36:16.394 AVAST engine defs: 12072900 08:36:18.124 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 08:36:18.124 Disk 0 Vendor: Intel___ 1.0. Size: 476945MB BusType: 8 08:36:18.124 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-0 08:36:18.124 Disk 1 Vendor: ST350032 SD1A Size: 476940MB BusType: 8 08:36:18.134 Disk 0 MBR read successfully 08:36:18.134 Disk 0 MBR scan 08:36:18.134 Disk 0 Windows 7 default MBR code 08:36:18.134 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 08:36:18.144 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 476843 MB offset 206848 08:36:18.184 Disk 0 scanning C:\Windows\system32\drivers 08:36:43.295 Service scanning 08:37:11.378 Modules scanning 08:37:11.378 Disk 0 trace - called modules: 08:37:11.398 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStorV.sys hal.dll 08:37:11.408 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80065f1060] 08:37:11.408 3 CLASSPNP.SYS[fffff8800120143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8006338050] 08:37:13.838 AVAST engine scan C:\Windows 08:37:15.918 AVAST engine scan C:\Windows\system32 08:39:59.940 AVAST engine scan C:\Windows\system32\drivers 08:40:35.020 AVAST engine scan C:\Users\Mike 08:59:29.186 AVAST engine scan C:\ProgramData 09:11:24.821 Scan finished successfully 09:48:30.623 Disk 0 MBR has been saved successfully to "C:\Users\Mike\Desktop\MBR.dat" 09:48:30.625 The log file has been saved successfully to "C:\Users\Mike\Desktop\aswMBR.txt"
Hi,

Lets see what this finds

Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please
Alright so I ran Malwarebytes. Here is the log. Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.29.09 Windows 7 x64 NTFS Internet Explorer 9.0.8112.16421 Mike :: MIKE-PC [administrator] 29/07/2012 3:12:48 PM mbam-log-2012-07-29 (15-12-48).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 222395 Time elapsed: 4 minute(s), 51 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WINSXS32 (Trojan.Agent) -> Data: C:\Users\Mike\AppData\Roaming\BE9D.exe -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 2 C:\Users\Mike\Downloads\RemoveWAT.exe (HackTool.Wpakill) -> No action taken. C:\Users\Mike\AppData\Local\Temp\mor.exe (Spyware.Zeus) -> Quarantined and deleted successfully. (end) Also, the errors that are reported upon start up are "There was a problem starting C:\Users\Mike\Appdata\Local\Temp\whuid.dll The specified module could not be found." and There was a problem starting C:\Users\Mike\Appdata\Local\Temp\nsrexg.dll The specified module could not be found." On top of that the icons keep reseting to large and going into alphabetical order as apposed to the order I put them in before restart. That however starting happening after I ran OTL. Is it possible OTL did something to the desktop portion? netsvcs %SYSTEMDRIVE%\*.exe /md5start explorer.exe winlogon.exe Userinit.exe svchost.exe /md5stop C:\Windows\assembly\tmp\U\*.* /s CREATERESTOREPOINT I had pasted that into the custom scan part as per what I read on another forum. Thanks!
Download CKScanner by askey127 from Here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Please Run this program only once
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
CKScanner - Additional Security Risks - These are not necessarily bad c:\program files (x86)\gamersfirst\apb reloaded\apbgame\content\release\packages\symboleditor\primitives_splatscracks.upk c:\program files (x86)\steam\steamapps\common\audiosurf\engine\crypt.dll c:\program files (x86)\steam\steamapps\common\audiosurf\engine\channels\crypt.dll c:\program files (x86)\steam\steamapps\common\call of duty black ops\zone\common\mp_cracked.ff c:\program files (x86)\steam\steamapps\common\call of duty black ops\zone\english\en_mp_cracked.ff c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota\particles\particle_snapshots\good_ancient_destruction\goodancient_ground_crackglow_1.psf c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota\particles\particle_snapshots\good_ancient_destruction\goodancient_ground_crackglow_1b.psf c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota\particles\particle_snapshots\good_ancient_destruction\goodancient_ground_crackglow_2.psf c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota\particles\particle_snapshots\good_ancient_destruction\goodancient_ground_crackglow_2b.psf c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota\particles\particle_snapshots\good_ancient_destruction\goodancient_ground_crackglow_3.psf c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota\particles\particle_snapshots\good_ancient_destruction\goodancient_ground_crackglow_4.psf c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota\particles\particle_snapshots\good_ancient_destruction\goodancient_ground_crackglow_5.psf c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota\particles\particle_snapshots\good_ancient_destruction\goodancient_ground_crackglow_6.psf c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota\particles\particle_snapshots\good_ancient_destruction\goodancient_ground_crackglow_7.psf c:\program files (x86)\steam\steamapps\common\magicka\content\levels\textures\surface\nature\ground\dirt01_cracked_0.xnb c:\program files (x86)\steam\steamapps\common\magicka\content\levels\textures\surface\nature\ground\dirt01_cracked_nrm_0.xnb c:\program files (x86)\steam\steamapps\common\magicka\content\levels\textures\surface\structure\stone\pillar_cracked00_0.xnb c:\program files (x86)\steam\steamapps\common\magicka\content\levels\textures\surface\structure\stone\pillar_cracked00_nrm02_0.xnb c:\program files (x86)\steam\steamapps\common\magicka\content\levels\textures\surface\structure\stone\wall_cracked00_0.xnb c:\program files (x86)\steam\steamapps\common\magicka\content\levels\textures\surface\structure\stone\wall_cracked01_0.xnb c:\program files (x86)\steam\steamapps\common\magicka\content\levels\textures\surface\structure\stone\wall_cracked_nrm_0.xnb c:\program files (x86)\steam\steamapps\[removed]\counter-strike source\cstrike\maps\cs_crackhouse.bsp c:\program files (x86)\steam\steamapps\[removed]\counter-strike source\cstrike\maps\cs_crackhouse.nav c:\program files (x86)\steam\steamapps\[removed]\counter-strike source\cstrike\maps\cs_crackhouse2.bsp c:\program files (x86)\steam\steamapps\[removed]\counter-strike source\cstrike\maps\soundcache\cs_crackhouse.cache c:\program files (x86)\steam\steamapps\[removed]\counter-strike source\cstrike\maps\soundcache\cs_crackhouse2.cache c:\users\mike\documents\rosetta stone v3\rosetta stone v3.3.5 for windows\rosetta stone v3.3.5 for windows\crack\rosettastoneversion3.exe c:\users\mike\downloads\removewat.exe c:\users\mike\downloads\removewat.rar c:\users\mike\downloads\xilisoft.video.converter.7.1.0.20120222.ultimate.crack.&.fix-supergenius.rar c:\users\mike\downloads\[]demonoid.me[]-plants_vs_zombies_full_precracked_fishbone_games_7292166.0528.torrent c:\users\mike\downloads\adobe photoshop cs5 extended v12 keygen only-works\adobe.photoshop.cs5.extended.v12.keygen.only-works.rar c:\users\mike\downloads\adobe photoshop cs5 extended v12 keygen only-works\torrent downloaded from demonoid.com.txt c:\users\mike\downloads\adobe photoshop cs5 extended v12 keygen only-works\adobe.photoshop.cs5.extended.v12.keygen.only.embrace-deantjah\deantjah.nfo c:\users\mike\downloads\adobe photoshop cs5 extended v12 keygen only-works\adobe.photoshop.cs5.extended.v12.keygen.only.embrace-deantjah\keygen\embrace.nfo c:\users\mike\downloads\adobe photoshop cs5 extended v12 keygen only-works\adobe.photoshop.cs5.extended.v12.keygen.only.embrace-deantjah\keygen\file_id.diz c:\users\mike\downloads\adobe photoshop cs5 extended v12 keygen only-works\adobe.photoshop.cs5.extended.v12.keygen.only.embrace-deantjah\keygen\keygen.exe c:\users\mike\downloads\adobe photoshop cs5 extended [32bit+64bit]\keygen.exe c:\users\mike\downloads\elcomsoft password recovery bundle 2007\aefsdr v3.2\!crack\aefsdr.exe c:\users\mike\downloads\elcomsoft password recovery bundle 2007\art v2.11\!crack\brd.nfo c:\users\mike\downloads\elcomsoft password recovery bundle 2007\avpr v1.63\!crack\avpr.exe c:\users\mike\downloads\elcomsoft password recovery bundle 2007\avpr v1.63\!crack\avpr.reg c:\users\mike\downloads\elcomsoft password recovery bundle 2007\awopr v1.30\!crack\awopr.exe c:\users\mike\downloads\plants vs. zombies - full precracked\plants vs. zombies - full precracked.exe c:\users\mike\downloads\reset.windows.password.v1.70.incl.keymaker-core\keygen.exe c:\users\mike\downloads\skyrim mods\high res textures\textures\architecture\windhelm\wholdcrackedbrick.dds c:\users\mike\downloads\skyrim mods\high res textures\textures\architecture\windhelm\wholdcrackedbrick2.dds c:\users\mike\downloads\vsocxtdvd4.1.7.343\convertxtodvd_4_keygen.exe hosts 127.0.0.1 activate.adobe.com scanner sequence 3.ZZ.11.QHNAGO —– EOF —–
Let me explain where we are at. When I looked at your ESET log I saw entries for ZeroAccess Rootkit, I also saw some entries that might have been from illegal software but at that point I gave you the benefit of the doubt. Malwarebytes found C:\Users\Mike\Downloads\RemoveWAT.exe (HackTool.Wpakill) -> No action taken, and you decided not to remove it because your copy of windows is most likely illegal. When we ran CKScanner, it found many illegal programs that where downloaded via the torrents.

We do not offer help for illegal operating systems and programs, what I would suggest you do is to contact Microsoft and purchase a legit keycode for your system. If you keep downloading this illegal stuff your just going to constantly infect your system and with the threats going around today , thats not good..

If I was to continue helping you it could be construed in the eyes of the law as aiding and abetting a crime.

So this thread will now be closed

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI