This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible infection [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I have try a VPN for a first time and I installed many programs and firefox add-ons about privacy, which I found in different Internet sites. I am not sure when exactly, but my computer started to act strange. Sometimes I cannot close a programs, some program windows disappeared and then appeared again, the CPU is on 100 % (cmdagent.exe) and so on. I am sure, that something is wrong. When I shut down the PC, Comodo opens a window that dw20.exe is doing something (no time to read it). I have run a full virus scan, but it has not found anything. But yesterday Comodo blocked for only one day about 20000 intrusions. I thought, maybe it is happened because of VPN connection. Today I have disconnected from VPN and after that there are no more intrusions. Today I started Hijackthis and after I click on "Analyze" it told me, that no Internet connection was found, which obviously was not true. I made this earlier today, before I saw on your post, that I schuldn´t have to do this.
Now when I start OTL with your instructions, it stops responding on "Checking Firefox settings". That is why I post the log file from hijackthis.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:56:32, on 04.03.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16446)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Launcher.exe
C:\Program Files (x86)\Winamp\winamp.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 93.123.45.23:8008
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: DVDVideoSoftTB - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O2 - BHO: FreeOnlineRadioPlayerRecorder - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll
O3 - Toolbar: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll
O3 - Toolbar: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll
O3 - Toolbar: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [VPNCheck] C:\Program Files (x86)\VPNCheck\startVPNCheck.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2670363844-3478454606-541885934-1005\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-2670363844-3478454606-541885934-1005\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Launcher.lnk = C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Launcher.exe
O4 - Global Startup: Winamp.lnk = C:\Program Files (x86)\Winamp\winamp.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5D75C6C1-9FDB-4F70-B978-B1919A0F075E}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CS1\Services\Tcpip\..\{5D75C6C1-9FDB-4F70-B978-B1919A0F075E}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CS2\Services\Tcpip\..\{5D75C6C1-9FDB-4F70-B978-B1919A0F075E}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CS3\Services\Tcpip\..\{5D75C6C1-9FDB-4F70-B978-B1919A0F075E}: NameServer = 8.26.56.26,156.154.70.22
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
O23 - Service: ALDITALKVerbindungsassistent_Service - Unknown owner - C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Brother BRAdminPro Scheduler (BRA_Scheduler) - Unknown owner - C:\Program Files (x86)\Brother\BRAdmin Professional 3\bratimer.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\Windows\SysWOW64\brsvc01a.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Netlsabeghep - Unknown owner - (no file)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11545 bytes
Hello ovcharovpcz and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested


I am looking at your log and will reply with instructions shortly.

Satchfan
Hello again ovcharovpcz

The “intrusions” don't necessarily mean that someone is trying to hack into your computer: It could be simple internet browsing where cookies are used.

Is this a mobile or cell phone that you were using to establish a VPN?


Let’s try running the scans in Safe Mode:
  • restart your computer.
  • when the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with the Windows Advanced Boot Options menu
  • select the option for Safe Mode using the arrow keys
  • then press Enter on your keyboard to boot into Safe Mode.
You should then be presented with the Windows Login screen. Log in to Windows.

===================================================

Run OTL

I assume you have already downloaded OTL from what you said. If you no longer have it you can download it to your desktop from here
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • click Scan all users.
  • under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply. Note - do NOT attempt any Fix yet.
Logs to include with next post:

OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan
Hello Satchfan, Thank you for your reply! I am using the VPN connection on my Desktop-PC. The “intrusions”, that my Comodo Firewall blocks almost every second are even there, when no programs are started, even Internet browser. They cannot come because of cookies when no browser is started. Unfortunately I was unable to finish the scans with OTL and I think the also the second scan with aswMBR.exe. In Safe Mode, exectely as in Normal Mode, OTL stops responding on "Scanning FireFox Settings…", so I had to kill the process every time after I tried to make the scan. The scan finished exately the same way, as I tried to start a Quick Scan. I started aswMBR.exe and downloaded the new defintions (as offered) in Safe Mode with Networking. I clicked on "Scan" and it took a while. The process stoped on "Checking C:\Users\…\SilverlightPlayer…". I waited about 10 Minutes and after that I saved the log without waiting for it to finisch. Do I need to uninstall the Silverlight Player in Order to finish the scan? Thanks! —————————————————————————————————————————————– aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2013-03-10 12:04:18 —————————– 12:04:18.562 OS Version: Windows x64 6.1.7601 Service Pack 1 12:04:18.562 Number of processors: 2 586 0xF06 12:04:18.562 ComputerName: IKO7 UserName: Iko 12:04:20.312 Initialize success 12:05:25.125 AVAST engine defs: 13031000 12:12:13.922 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4 12:12:13.922 Disk 0 Vendor: WDC_WD20EARS-00S8B1 80.00A80 Size: 1907729MB BusType: 11 12:12:13.922 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-5 12:12:13.938 Disk 1 Vendor: WDC_WD20EARS-00MVWB0 50.0AB50 Size: 1907729MB BusType: 11 12:12:13.938 Disk 0 MBR read successfully 12:12:13.954 Disk 0 MBR scan 12:12:13.954 Disk 0 Windows 7 default MBR code 12:12:13.969 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 190771 MB offset 63 12:12:13.969 Disk 0 Partition - 00 0F Extended LBA 1716954 MB offset 390700800 12:12:13.985 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 1716954 MB offset 390700863 12:12:14.032 Disk 0 scanning C:\Windows\system32\drivers 12:12:25.594 Service scanning 12:12:50.985 Modules scanning 12:12:50.985 Disk 0 trace - called modules: 12:12:51.000 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys 12:12:51.000 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004402060] 12:12:51.016 3 CLASSPNP.SYS[fffff88001b2e43f] -> nt!IofCallDriver -> [0xfffffa8004273090] 12:12:51.016 5 ACPI.sys[fffff880010b17a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-4[0xfffffa800427e060] 12:12:52.532 AVAST engine scan C:\Windows 12:12:55.032 AVAST engine scan C:\Windows\system32 12:15:14.969 AVAST engine scan C:\Windows\system32\drivers 12:15:28.297 AVAST engine scan C:\Users\Iko 12:21:20.782 Disk 0 MBR has been saved successfully to "D:\check\MBR.dat" 12:21:20.797 The log file has been saved successfully to "D:\check\aswMBR.txt" —————————————————————————————————————————————–
Let's see if will run a different scan.

Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!

Close all running programs.


Download RogueKiller to your desktop.
  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the pre-scan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad
If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.

Please post the contents of the RKreport.txt in your next reply.

Satchfan
RogueKiller V8.5.2 _x64_ [Mar 9 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Iko [Admin rights]
Mode : Scan – Date : 03/10/2013 15:37:43
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 15 ¤¤¤
[PROXY IE] HKCU\[…]\Internet Settings : ProxyServer ([removed]:8008) -> FOUND
[DNS] HKLM\[…]\ControlSet001\Services\Tcpip\Interfaces\{5D75C6C1-9FDB-4F70-B978-B1919A0F075E} : NameServer (8.26.56.26,156.154.70.22) -> FOUND
[DNS] HKLM\[…]\ControlSet002\Services\Tcpip\Interfaces\{5D75C6C1-9FDB-4F70-B978-B1919A0F075E} : NameServer (8.26.56.26,156.154.70.22) -> FOUND
[DNS] HKLM\[…]\ControlSet003\Services\Tcpip\Interfaces\{5D75C6C1-9FDB-4F70-B978-B1919A0F075E} : NameServer (8.26.56.26,156.154.70.22) -> FOUND
[HJ] HKLM\[…]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ] HKLM\[…]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ] HKLM\[…]\System : EnableLUA (0) -> FOUND
[HJ] HKLM\[…]\Wow6432Node\System : EnableLUA (0) -> FOUND
[HJ SMENU] HKCU\[…]\Advanced : Start_ShowRecentDocs (0) -> FOUND
[HJ SMENU] HKCU\[…]\Advanced : Start_ShowMyGames (0) -> FOUND
[HJ SMENU] HKCU\[…]\Advanced : Start_ShowDownloads (0) -> FOUND
[HJ SMENU] HKCU\[…]\Advanced : Start_ShowVideos (0) -> FOUND
[HJ SMENU] HKCU\[…]\Advanced : Start_ShowRun (0) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 102.112.2o7.net


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD20EARS-00S8B1 ATA Device +++++
— User —
[MBR] 8a42d3d95e9a3d8a7422d59d9e04f4bd
[BSP] 06ee12b86889943e2cacad0a03d14604 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 190771 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 390700800 | Size: 1716954 Mo
User = LL1 … OK!
User = LL2 … OK!

+++++ PhysicalDrive1: WDC WD20EARS-00MVWB0 ATA Device +++++
— User —
[MBR] 0b25f3fc2a7b31d3fd4661c9bdb37ebd
[BSP] 4c201df24e6f54fbf9003c0c6c583dd3 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 190771 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 390700800 | Size: 1716954 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[3]_S_03102013_02d1537.txt >>
RKreport[1]_S_03102013_02d1530.txt ; RKreport[2]_S_03102013_02d1533.txt ; RKreport[3]_S_03102013_02d1537.txt
That didn’t show anything nasty either so we’ll have a different look.

Run DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.pif
DDS.com

  • disable any script blocking protection (How to Disable your Security Programs)
  • double click DDS icon to run the tool (may take up to 3 minutes to run)
  • when done, DDS.txt will open.
  • after a few moments, attach.txt will open in a second window.
  • save both reports to your desktop.
  • Post the contents of the DDS.txt and Attach.txt reports in your next reply
Satchfan
DDS.txt: DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 9.0.8112.16464 BrowserJavaVersion: 1.6.0_35 Run by [removed] at 18:13:54 on 2013-03-10 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1033.18.4095.2366 [GMT 2:00] . AV: COMODO Antivirus *Disabled/Updated* {458BB331-2324-0753-3D5F-1472EB102AC0} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: COMODO Defense+ *Disabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D} FW: COMODO Firewall *Disabled* {7DB03214-694B-060B-1600-BD4715C36DBB} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\AUDIODG.EXE C:\Windows\system32\svchost.exe -k LocalService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\COMODO\COMODO Internet Security\cfp.exe C:\Program Files (x86)\Skype\Phone\Skype.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Launcher.exe C:\Program Files (x86)\Winamp\winamp.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe C:\Windows\System32\WUDFHost.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\wuauclt.exe C:\Program Files (x86)\Attractel\Zoiper\Zoiper.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uSearch Bar = Preserve uProxyServer = 93.123.45.23:8008 mURLSearchHooks: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll mURLSearchHooks: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll TB: DVDVideoSoftTB Toolbar: {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll TB: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll TB: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - uRun: [AdobeBridge] mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s StartupFolder: C:\Users\Iko\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\Winamp.lnk - C:\Program Files (x86)\Winamp\winamp.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 uPolicies-Explorer: TaskbarNoNotification = dword:1 uPolicies-Explorer: QuickLaunchEnabled = dword:1 uPolicies-Explorer: TaskbarNoThumbnail = dword:0 mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:0 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableLUA = dword:0 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: PromptOnSecureDesktop = dword:0 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: NameServer = 192.168.178.1 TCP: Interfaces\{5D75C6C1-9FDB-4F70-B978-B1919A0F075E} : NameServer = 8.26.56.26,156.154.70.22 TCP: Interfaces\{5D75C6C1-9FDB-4F70-B978-B1919A0F075E} : DHCPNameServer = 192.168.178.1 TCP: Interfaces\{A5C17969-81DA-405C-9AED-F27399947E08} : DHCPNameServer = 192.168.178.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll AppInit_DLLs= C:\Windows\SysWOW64\guard32.dll SSODL: WebCheck - SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.152\Installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome x64-BHO: Windows Live Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL x64-BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll x64-Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - x64-SSODL: WebCheck - x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Iko\AppData\Roaming\Mozilla\Firefox\Profiles\skszjri4.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.de FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties FF - prefs.js: network.proxy.http - 93.123.45.23 FF - prefs.js: network.proxy.http_port - 8008 FF - prefs.js: network.proxy.ssl - 93.123.45.23 FF - prefs.js: network.proxy.ssl_port - 8008 FF - prefs.js: network.proxy.type - 0 FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll FF - plugin: C:\Windows\SysWOW64\npmproxy.dll FF - ExtSQL: 2013-03-09 19:25; {73a6fe31-595d-460b-a920-fcc0f8843232}; C:\Users\Iko\AppData\Roaming\Mozilla\Firefox\Profiles\skszjri4.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF - ExtSQL: 2013-03-09 23:22; [removed]; C:\Users\Iko\AppData\Roaming\Mozilla\Firefox\Profiles\skszjri4.default\extensions\[removed] FF - ExtSQL: 2013-03-09 23:23; [removed]; C:\Users\Iko\AppData\Roaming\Mozilla\Firefox\Profiles\skszjri4.default\extensions\[removed] . ============= SERVICES / DRIVERS =============== . R0 DRVECDB;DRVECDB;C:\Windows\System32\drivers\DRVECDB.SYS [2010-10-8 122776] R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-10-8 52664] R1 ArcSec;ArcSec;C:\Windows\System32\drivers\ArcSec.sys [2011-6-19 312184] R1 cmderd;COMODO Internet Security Eradication Driver;C:\Windows\System32\drivers\cmderd.sys [2010-9-10 22736] R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\System32\drivers\cmdGuard.sys [2010-9-10 584056] R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\System32\drivers\cmdhlp.sys [2010-9-10 38144] R1 DLACDBHE;DLACDBHE;C:\Windows\System32\drivers\DLACDBHE.SYS [2010-10-8 15864] R1 DLARTL_E;DLARTL_E;C:\Windows\System32\drivers\DLARTL_E.SYS [2010-10-8 39160] R2 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648] R2 DLABMFSE;DLABMFSE;C:\Windows\System32\DLA\DLABMFSE.SYS [2010-10-8 43888] R2 DLABOIOE;DLABOIOE;C:\Windows\System32\DLA\DLABOIOE.SYS [2010-10-8 41712] R2 DLADResE;DLADResE;C:\Windows\System32\DLA\DLADResE.SYS [2010-10-8 10096] R2 DLAIFS_E;DLAIFS_E;C:\Windows\System32\DLA\DLAIFS_E.SYS [2010-10-8 141296] R2 DLAOPIOE;DLAOPIOE;C:\Windows\System32\DLA\DLAOPIOE.SYS [2010-10-8 33904] R2 DLAPoolE;DLAPoolE;C:\Windows\System32\DLA\DLAPoolE.SYS [2010-10-8 17776] R2 DLAUDF_E;DLAUDF_E;C:\Windows\System32\DLA\DLAUDF_E.SYS [2010-10-8 142832] R2 DLAUDFAE;DLAUDFAE;C:\Windows\System32\DLA\DLAUDFAE.SYS [2010-10-8 136816] R2 DRVEDDM;DRVEDDM;C:\Windows\System32\drivers\DRVEDDM.SYS [2010-10-8 63608] R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-1-31 3289208] R2 SSPORT;SSPORT;C:\Windows\System32\drivers\SSPORT.SYS [2011-4-26 11576] R3 LVUSBS64;Logitech USB Monitor Filter;C:\Windows\System32\drivers\LVUSBS64.sys [2007-10-12 50072] R3 Ph3xIB64;Philips 713x Inbox PCI TV Card;C:\Windows\System32\drivers\Ph3xIB64.sys [2009-6-10 1627520] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-3-2 187392] R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\System32\drivers\viahduaa.sys [2010-10-3 1250816] S1 HCW88AUD;Hauppauge WinTV 88x Audio Capture;C:\Windows\System32\drivers\hcw88aud.sys [2009-8-6 16128] S2 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;C:\Windows\System32\drivers\ew_hwusbdev.sys [2013-1-8 117248] S3 ewusbnet;HUAWEI USB-NDIS miniport;C:\Windows\System32\drivers\ewusbnet.sys [2013-1-8 138752] S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2012-12-14 61288] S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-4-28 704872] S3 HCW88BDA;Hauppauge WinTV 88x DVB Tuner/Demod;C:\Windows\System32\drivers\hcw88bda.sys [2009-8-6 257664] S3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture;C:\Windows\System32\drivers\hcw88tse.sys [2009-8-6 339840] S3 HCW88TUNE;Hauppauge WinTV 88x Tuner;C:\Windows\System32\drivers\hcw88tun.sys [2009-8-6 110080] S3 hcw88vid;Hauppauge WinTV 88x Video;C:\Windows\System32\drivers\hcw88vid.sys [2009-8-6 440064] S3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;C:\Windows\System32\drivers\hcw88bar.sys [2009-8-6 21632] S3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\System32\drivers\lvrs64.sys [2010-11-10 341856] S3 LVUVC64;Logitech QuickCam 3000(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2010-11-10 4162784] S3 RTL2832U_IRHID;HID Infrared Remote Receiver;C:\Windows\System32\drivers\RTL2832U_IRHID.sys [2009-10-5 44320] S3 RTL2832UBDA;REALTEK 2832U BDA Driver;C:\Windows\System32\drivers\RTL2832UBDA.sys [2010-7-1 224488] S3 RTL2832UUSB;REALTEK 2832U USB Driver;C:\Windows\System32\drivers\RTL2832UUSB.sys [2010-7-1 39016] S3 SIVDriver;SIV Kernel Driver;C:\Windows\System32\drivers\SIVX64.sys [2013-3-4 119064] S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-3-19 59392] S4 ALDITALKVerbindungsassistent_Service;ALDITALKVerbindungsassistent_Service;C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [2013-1-8 358528] S4 BRA_Scheduler;Brother BRAdminPro Scheduler;C:\Program Files (x86)\Brother\BRAdmin Professional 3\bratimer.exe [2011-1-9 65536] S4 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-10-12 1038088] S4 Futuremark SystemInfo Service;Futuremark SystemInfo Service;C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2011-11-17 128928] S4 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-1-8 161536] S4 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-1-16 3467768] . =============== File Associations =============== . FileExt: .vbe: VBEFile=C:\Windows\SysWow64\CScript.exe "%1" %* FileExt: .vbs: VBSFile=C:\Windows\SysWow64\CScript.exe "%1" %* FileExt: .js: JSFile=C:\Windows\SysWow64\CScript.exe "%1" %* FileExt: .jse: JSEFile=C:\Windows\SysWow64\CScript.exe "%1" %* FileExt: .wsf: WSFFile=C:\Windows\SysWow64\CScript.exe "%1" %* . =============== Created Last 30 ================ . 2013-03-10 12:59:57 ——– d—–w- C:\Program Files (x86)\Attractel 2013-03-10 12:20:39 ——– d—–w- C:\Users\Iko\AppData\Local\CrashDumps 2013-03-10 11:56:57 ——– d—–w- C:\Program Files (x86)\Phoner 2013-03-10 11:56:30 76232 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DFE5BFA4-488F-4B78-92B4-E31902882574}\offreg.dll 2013-03-09 13:20:55 963488 —-a-w- C:\Windows\System32\deployJava1.dll 2013-03-09 13:20:55 1085344 —-a-w- C:\Windows\System32\npDeployJava1.dll 2013-03-09 13:20:33 108448 —-a-w- C:\Windows\System32\WindowsAccessBridge-64.dll 2013-03-05 10:19:02 ——– d—–r- C:\Users\Iko\Virtual Machines 2013-03-05 09:00:08 996352 —-a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll 2013-03-05 09:00:08 768000 —-a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll 2013-03-05 08:36:22 46080 —-a-w- C:\Windows\System32\atmlib.dll 2013-03-05 08:36:22 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2013-03-05 08:36:21 367616 —-a-w- C:\Windows\System32\atmfd.dll 2013-03-05 08:36:21 295424 —-a-w- C:\Windows\SysWow64\atmfd.dll 2013-03-05 08:34:19 87040 —-a-w- C:\Windows\System32\drivers\WUDFPf.sys 2013-03-05 08:34:19 84992 —-a-w- C:\Windows\System32\WUDFSvc.dll 2013-03-05 08:34:19 198656 —-a-w- C:\Windows\System32\drivers\WUDFRd.sys 2013-03-05 08:34:18 194048 —-a-w- C:\Windows\System32\WUDFPlatform.dll 2013-03-05 08:34:17 744448 —-a-w- C:\Windows\System32\WUDFx.dll 2013-03-05 08:34:17 45056 —-a-w- C:\Windows\System32\WUDFCoinstaller.dll 2013-03-05 08:34:17 229888 —-a-w- C:\Windows\System32\WUDFHost.exe 2013-03-05 08:33:58 9162192 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DFE5BFA4-488F-4B78-92B4-E31902882574}\mpengine.dll 2013-03-05 08:01:57 68608 —-a-w- C:\Windows\System32\taskhost.exe 2013-03-05 08:01:38 750592 —-a-w- C:\Windows\System32\win32spl.dll 2013-03-05 08:01:38 492032 —-a-w- C:\Windows\SysWow64\win32spl.dll 2013-03-05 08:01:29 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2013-03-05 08:01:29 2048 —-a-w- C:\Windows\System32\tzres.dll 2013-03-05 07:54:53 59392 —-a-w- C:\Windows\System32\browcli.dll 2013-03-05 07:54:53 41984 —-a-w- C:\Windows\SysWow64\browcli.dll 2013-03-05 07:54:53 136704 —-a-w- C:\Windows\System32\browser.dll 2013-03-05 07:52:48 503808 —-a-w- C:\Windows\System32\srcore.dll 2013-03-05 07:48:00 424448 —-a-w- C:\Windows\System32\KernelBase.dll 2013-03-05 07:48:00 338432 —-a-w- C:\Windows\System32\conhost.exe 2013-03-05 07:48:00 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll 2013-03-04 21:28:54 950128 —-a-w- C:\Windows\System32\drivers\ndis.sys 2013-03-04 21:28:54 41472 —-a-w- C:\Windows\System32\drivers\RNDISMP.sys 2013-03-04 21:27:00 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2013-03-04 21:19:22 1464320 —-a-w- C:\Windows\System32\crypt32.dll 2013-03-04 21:19:21 184320 —-a-w- C:\Windows\System32\cryptsvc.dll 2013-03-04 21:19:21 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll 2013-03-04 21:19:21 140288 —-a-w- C:\Windows\System32\cryptnet.dll 2013-03-04 21:19:21 1159680 —-a-w- C:\Windows\SysWow64\crypt32.dll 2013-03-04 21:19:21 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll 2013-03-04 11:42:55 119064 —-a-w- C:\Windows\System32\drivers\SIVX64.sys 2013-03-01 21:57:42 ——– d—–w- C:\Users\Iko\AppData\Local\Guavi 2013-03-01 21:56:07 ——– d—–w- C:\Program Files (x86)\VPNCheck 2013-02-28 21:52:23 ——– d—–w- C:\Program Files (x86)\FVPN Connect 2013-02-28 21:28:26 ——– d—–w- C:\Users\Iko\AppData\Local\FVPN 2013-02-23 22:03:41 2560 —-a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui 2013-02-23 22:03:40 9728 —-a-w- C:\Windows\System32\Wdfres.dll 2013-02-23 22:03:40 785512 —-a-w- C:\Windows\System32\drivers\Wdf01000.sys 2013-02-23 22:03:40 54376 —-a-w- C:\Windows\System32\drivers\WdfLdr.sys . ==================== Find3M ==================== . 2013-03-10 10:44:29 151552 —-a-w- C:\Windows\KMSEmulator.exe 2013-03-09 14:25:25 71024 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-03-09 14:25:25 691568 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-02-07 10:42:52 333856 —-a-w- C:\Windows\System32\RaCoInstx.dll 2013-02-07 10:42:52 2201120 —-a-w- C:\Windows\System32\drivers\netr28ux.sys 2013-02-03 14:46:19 999936 —-a-w- C:\Windows\SysWow64\drivers\mod7700.sys 2013-02-03 14:46:19 1490656 —-a-w- C:\Windows\SysWow64\WdfCoInstaller01007.dll 2013-02-03 14:46:19 1490656 —-a-w- C:\Windows\SysWow64\drivers\WdfCoInstaller01007.dll 2013-02-03 14:46:19 13952 —-a-w- C:\Windows\SysWow64\drivers\ew_usbenumfilter.sys 2013-02-03 14:46:18 91136 —-a-w- C:\Windows\SysWow64\drivers\ew_jucdcacm.sys 2013-02-03 14:46:18 85504 —-a-w- C:\Windows\SysWow64\drivers\ew_jubusenum.sys 2013-02-03 14:46:18 55296 —-a-w- C:\Windows\SysWow64\drivers\ew_jucdcecm.sys 2013-02-03 14:46:18 29696 —-a-w- C:\Windows\SysWow64\drivers\ewdcsc.sys 2013-02-03 14:46:18 29184 —-a-w- C:\Windows\SysWow64\drivers\ew_juextctrl.sys 2013-02-03 14:46:18 138752 —-a-w- C:\Windows\SysWow64\drivers\ewusbnet.sys 2013-02-03 14:46:18 121600 —-a-w- C:\Windows\SysWow64\drivers\ewusbmdm.sys 2013-02-03 14:46:18 117248 —-a-w- C:\Windows\SysWow64\drivers\ew_hwusbdev.sys 2013-01-24 09:32:08 2177648 —-a-w- C:\Windows\System32\coin93.dll 2013-01-16 23:28:58 273840 ——w- C:\Windows\System32\MpSigStub.exe 2013-01-09 01:19:09 2312704 —-a-w- C:\Windows\System32\jscript9.dll 2013-01-09 01:12:03 1392128 —-a-w- C:\Windows\System32\wininet.dll 2013-01-09 01:11:06 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl 2013-01-09 01:07:51 173056 —-a-w- C:\Windows\System32\ieUnatt.exe 2013-01-09 01:07:47 599040 —-a-w- C:\Windows\System32\vbscript.dll 2013-01-08 22:11:21 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll 2013-01-08 22:03:20 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll 2013-01-08 22:03:12 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2013-01-08 21:59:02 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2013-01-08 21:58:29 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll 2013-01-08 21:56:23 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2013-01-08 19:27:40 138752 —-a-w- C:\Windows\System32\drivers\ewusbnet.sys 2013-01-08 19:27:40 121600 —-a-w- C:\Windows\System32\drivers\ewusbmdm.sys 2013-01-08 19:27:40 117248 —-a-w- C:\Windows\System32\drivers\ew_hwusbdev.sys 2013-01-05 05:53:43 5553512 —-a-w- C:\Windows\System32\ntoskrnl.exe 2013-01-05 05:00:15 3967848 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2013-01-05 05:00:11 3913064 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2013-01-04 05:46:09 215040 —-a-w- C:\Windows\System32\winsrv.dll 2013-01-04 04:51:16 5120 —-a-w- C:\Windows\SysWow64\wow32.dll 2013-01-04 04:43:21 44032 —-a-w- C:\Windows\apppatch\acwow64.dll 2013-01-04 03:26:48 3153408 —-a-w- C:\Windows\System32\win32k.sys 2013-01-04 02:47:35 25600 —-a-w- C:\Windows\SysWow64\setup16.exe 2013-01-04 02:47:34 7680 —-a-w- C:\Windows\SysWow64\instnm.exe 2013-01-04 02:47:34 2048 —-a-w- C:\Windows\SysWow64\user.exe 2013-01-04 02:47:33 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll 2013-01-03 06:00:54 1913192 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2013-01-03 06:00:42 288088 —-a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS . ============= FINISH: 18:14:55,07 ===============
Attach.txt: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 7 Professional Boot Device: \Device\HarddiskVolume1 Install Date: 03.10.2010 01:33:06 System Uptime: 10.03.2013 12:43:49 (6 hours ago) . Motherboard: ASRock | | P43DE Processor: Intel® Core™2 CPU 6600 @ 2.40GHz | CPUSocket | 2400/267mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 186 GiB total, 107,776 GiB free. D: is FIXED (NTFS) - 1677 GiB total, 276,308 GiB free. E: is FIXED (NTFS) - 186 GiB total, 182,207 GiB free. F: is FIXED (NTFS) - 1677 GiB total, 597,084 GiB free. G: is CDROM () H: is CDROM () I: is CDROM () J: is CDROM () K: is CDROM () L: is Removable M: is Removable N: is Removable O: is Removable X: is CDROM () Y: is CDROM () Z: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP732: 05.03.2013 12:34:06 - Windows Update RP733: 07.03.2013 23:53:02 - Windows Update RP734: 09.03.2013 15:19:40 - Installed Java 7 Update 17 (64-bit) RP735: 10.03.2013 14:18:37 - Installed X-Lite RP736: 10.03.2013 14:30:40 - Removed X-Lite . ==== Installed Programs ====================== . 100% Free Chess 7.42 64 Bit HP CIO Components Installer Adobe AIR Adobe Anchor Service CS4 Adobe Anchor Service x64 CS4 Adobe Bridge CS4 Adobe CMaps CS4 Adobe CMaps x64 CS4 Adobe Color - Photoshop Specific CS4 Adobe Color EU Extra Settings CS4 Adobe Color JA Extra Settings CS4 Adobe Color NA Recommended Settings CS4 Adobe Color Video Profiles CS CS4 Adobe CSI CS4 Adobe CSI CS4 x64 Adobe Default Language CS4 Adobe Device Central CS4 Adobe Drive CS4 Adobe Drive CS4 x64 Adobe ExtendScript Toolkit CS4 Adobe Extension Manager CS4 Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Fonts All Adobe Fonts All x64 Adobe Illustrator CS Adobe Linguistics CS4 Adobe Linguistics CS4 x64 Adobe Media Player Adobe Output Module Adobe PDF Library Files CS4 Adobe PDF Library Files x64 CS4 Adobe Photoshop CS4 Adobe Photoshop CS4 (64 Bit) Adobe Photoshop CS4 Support Adobe Reader 9.4.6 - Deutsch Adobe Reader X (10.1.1) - Deutsch Adobe Search for Help Adobe Service Manager Extension Adobe Setup Adobe SVG Viewer 3.0 Adobe Type Support CS4 Adobe Type Support x64 CS4 Adobe Update Manager CS4 Adobe WinSoft Linguistics Plugin Adobe WinSoft Linguistics Plugin x64 Adobe XMP Panels CS4 AdobeColorCommonSetCMYK ALDI TALK Verbindungsassistent Apple Application Support Apple Software Update ArcSoft TotalMedia 3 ArcSoft TotalMedia 3.5 ArcSoft TotalMedia Theatre 5 µTorrent AviSplit Classic Version 1.43 Bing Bar BitTorrent BlazeDTV 6.0 BRAdmin Professional 3 BSR Screen Recorder 4 COMODO Internet Security Conduit Engine Connect Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition DesignPro 5 DVDVideoSoftTB Toolbar Elite Proxy Switcher 1.19 ERUNT 1.1j Folder Size 1.4.0.0 Free AVI MPEG WMV MP4 FLV Video Joiner 4.1.5 Free Video Joiner 1.1 Free YouTube Download version 2.10.30 FreeOnlineRadioPlayerRecorder Toolbar Futuremark SystemInfo FVPN Connect Gaberoff Koral German Dictionary 1.01 GIMP 2.6.8 GOM Player Google Chrome Google Update Helper HiJackThis Internet-TV für Windows Media Center Java 7 Update 17 (64-bit) Java Auto Updater Java™ 6 Update 35 Junk Mail filter update K-Lite Codec Pack 8.6.0 (Standard) kuler Malwarebytes' Anti-Malware Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Office 2010 Proofing Tools Kit Service Pack 1 (SP1) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office File Validation Add-In Microsoft Office Groove MUI (English) 2010 Microsoft Office IME (Chinese (Simplified)) 2010 Microsoft Office IME (Chinese (Traditional)) 2010 Microsoft Office IME (Japanese) 2010 Microsoft Office IME (Korean) 2010 Microsoft Office InfoPath MUI (English) 2010 Microsoft Office Office 64-bit Components 2010 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office Professional Plus 2010 Microsoft Office Proof (Arabic) 2010 Microsoft Office Proof (Basque) 2010 Microsoft Office Proof (Bulgarian) 2010 Microsoft Office Proof (Catalan) 2010 Microsoft Office Proof (Chinese (Simplified)) 2010 Microsoft Office Proof (Chinese (Traditional)) 2010 Microsoft Office Proof (Croatian) 2010 Microsoft Office Proof (Czech) 2010 Microsoft Office Proof (Danish) 2010 Microsoft Office Proof (Dutch) 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (Estonian) 2010 Microsoft Office Proof (Finnish) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Galician) 2010 Microsoft Office Proof (German) 2010 Microsoft Office Proof (Greek) 2010 Microsoft Office Proof (Gujarati) 2010 Microsoft Office Proof (Hebrew) 2010 Microsoft Office Proof (Hindi) 2010 Microsoft Office Proof (Hungarian) 2010 Microsoft Office Proof (Italian) 2010 Microsoft Office Proof (Japanese) 2010 Microsoft Office Proof (Kannada) 2010 Microsoft Office Proof (Kazakh) 2010 Microsoft Office Proof (Korean) 2010 Microsoft Office Proof (Latvian) 2010 Microsoft Office Proof (Lithuanian) 2010 Microsoft Office Proof (Marathi) 2010 Microsoft Office Proof (Norwegian (Bokmål)) 2010 Microsoft Office Proof (Norwegian (Nynorsk)) 2010 Microsoft Office Proof (Polish) 2010 Microsoft Office Proof (Portuguese (Brazil)) 2010 Microsoft Office Proof (Portuguese (Portugal)) 2010 Microsoft Office Proof (Punjabi) 2010 Microsoft Office Proof (Romanian) 2010 Microsoft Office Proof (Russian) 2010 Microsoft Office Proof (Serbian (Latin)) 2010 Microsoft Office Proof (Slovak) 2010 Microsoft Office Proof (Slovenian) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proof (Swedish) 2010 Microsoft Office Proof (Tamil) 2010 Microsoft Office Proof (Telugu) 2010 Microsoft Office Proof (Thai) 2010 Microsoft Office Proof (Turkish) 2010 Microsoft Office Proof (Ukrainian) 2010 Microsoft Office Proof (Urdu) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Proofing Kit 2010 Microsoft Office Proofing Tools Kit Compilation 2010 Microsoft Office ProofMUI (English) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared 64-bit MUI (English) 2010 Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office Word MUI (English) 2010 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 MixPad Audio Mixer Mobile Partner Monopoly Mozilla Firefox 19.0 (x86 en-US) Mozilla Maintenance Service MPEG2 Codec(libmpeg2/mad) MSVC80_x64_v2 MSVC80_x86_v2 MSVC90_x64 MSVC90_x86 MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) nLite 1.4.9.1 Nokia Connectivity Cable Driver Nokia Ovi Suite NTFS Undelete 3.0.2.406 NVIDIA 3D Vision Controller Driver 306.97 NVIDIA Control Panel 306.97 NVIDIA Graphics Driver 306.97 NVIDIA HD Audio Driver 1.3.18.0 NVIDIA Install Application NVIDIA PhysX NVIDIA Update Components OpenAL Opera 11.51 Ovi Desktop Sync Engine PC Connectivity Solution PC Inspector File Recovery PC Inspector smart recovery PDF Settings CS4 PDFCreator Phoner 2.80 Photoshop Camera Raw Photoshop Camera Raw_x64 Platform PlayReady PC Runtime amd64 QuickTime Roxio Creator Audio Roxio Creator Basic v9 Roxio Creator Copy Roxio Creator Data Roxio Creator Tools Roxio Drag-to-Disc Roxio Express Labeler 3 Roxio MyDVD Basic v9 Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2687436) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553091) Security Update for Microsoft Office 2010 (KB2553096) Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition Security Update for Microsoft Visio 2010 (KB2687508) 32-Bit Edition Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition Skype Click to Call Skype™ 5.5 Skype™ 6.1 SoftwareClub Video Cutter Max [removed] SolveigMM AVI Trimmer Sonic Activation Module SopCast 3.5.0 Suite Shared Configuration CS4 TeamViewer 8 TOGGO PC-Spielebox 1 UltraISO Premium V9.36 Uninstall 1.0.0.1 Unlocker 1.9.0-x64 Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596963) 32-Bit Edition Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2598241) 32-Bit Edition Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2687277) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition VIA Plattform-Geräte-Manager VirtualCloneDrive VLC media player 2.0.1 VPNCheck 1.5 WavePad Sound Editor Winamp Winamp Detector Plug-in Windows 7 USB/DVD Download Tool Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0) Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live Mail Windows Live Messenger Windows Live Movie Maker Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Upload Tool Windows Live Writer Windows Media Center Add-in for Silverlight Windows Updates Downloader WinRAR archiver WinToFlash Suggestor WMP11 Slipstreamer [removed] XnView 1.97.8 Zoiper . ==== Event Viewer Messages From Past Week ======== . 10.03.2013 13:53:22, Error: Schannel [36888] - The following fatal alert was generated: 10. The internal error state is 10. 10.03.2013 12:45:32, Error: Server [2505] - The server could not bind to the transport \Device\NetBT_Tcpip_{BA3B9000-17AB-4D0D-8128-7FC0D8AAAD2C} because another computer on the network has the same name. The server could not start. 10.03.2013 12:44:17, Error: Service Control Manager [7000] - The DgiVecp service failed to start due to the following error: The system cannot find the device specified. 10.03.2013 12:43:56, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 10.03.2013 12:04:07, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F} 10.03.2013 12:04:07, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF} 10.03.2013 12:03:06, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 10.03.2013 12:02:56, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start. 10.03.2013 12:02:55, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 10.03.2013 12:02:55, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 10.03.2013 12:02:51, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 10.03.2013 12:02:44, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 10.03.2013 12:02:36, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: ArcSec cmdGuard discache ElbyCDIO spldr sptd vpcvmm Wanarpv6 10.03.2013 12:02:12, Error: sptd [4] - Driver detected an internal error in its data structures for . 10.03.2013 11:51:26, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start. 10.03.2013 11:35:31, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89} 10.03.2013 11:35:31, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E} 10.03.2013 11:35:10, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD ArcSec cmdGuard cmdHlp CSC DfsC discache ElbyCDIO inspect NetBIOS NetBT nsiproxy Psched rdbss spldr sptd tdx vpcnfltr vpcvmm vwififlt Wanarpv6 WfpLwf 10.03.2013 11:35:10, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 10.03.2013 11:35:10, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 10.03.2013 11:35:10, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning. 10.03.2013 11:35:10, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 10.03.2013 11:35:10, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 10.03.2013 11:35:10, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning. 10.03.2013 11:35:10, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 10.03.2013 11:35:10, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 10.03.2013 11:35:10, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning. 10.03.2013 11:35:10, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 08.03.2013 00:40:32, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 4 on XP, Server 2003, Vista, Windows 7, Server 2008, Server 2008 R2 for x64 (KB2742595). 08.03.2013 00:28:49, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows Server 2008 R2 for x64-based Systems (KB2468871). 08.03.2013 00:15:47, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 4 on XP, Server 2003, Vista, Windows 7, Server 2008, Server 2008 R2 for x64 (KB2656351). 08.03.2013 00:06:58, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows Server 2008 R2 for x64-based Systems (KB2533523). 08.03.2013 00:06:17, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Microsoft .NET Framework 4 on XP, Server 2003, Vista, Windows 7, Server 2008, Server 2008 R2 for x64 (KB2600217). 04.03.2013 23:28:57, Error: Service Control Manager [7043] - The Windows Update service did not shut down properly after receiving a preshutdown control. . ==== End Of File ===========================
Hi

Disable Windows Defender

You have Windows Defender running. Apart from the fact that it is useless, it will conflict with your antivirus, (AV), as they will be both looking for the same things.

To disable Windows Defender:
  • open Windows Defender
  • click on Tools, General Settings
  • scroll down and uncheck Turn on real-time protection (recommended)
  • after you uncheck this, click on the Save button and close Windows Defender.
===================================================

Run RogueKiller

I missed an entry in RogueKiller.
  • close all programs
  • double-click RogueKiller.exe - Windows 7: right-click the program and select Run as Administrator'
  • after it has completed it's prescan click on the “Proxy” tab
  • make sure the entries there are checked, then click on Fix Proxy button
===================================================

Run CKScanner

Download CKScanner by askey127 from here & save it to your Desktop.
  • doubleclick CKScanner.exe then click Search For Files
  • when the cursor hourglass disappears, click Save List To File
  • a message box will verify the file saved
  • double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
Satchfan
Hello Satchfan,

Thank you again for your answer. These are the files, that you want me to post:

——————————————————————————————————————————-

RogueKiller V8.5.2 _x64_ [Mar 9 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Iko [Admin rights]
Mode : Scan – Date : 03/11/2013 11:52:27
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 15 ¤¤¤
[PROXY IE] HKCU\[…]\Internet Settings : ProxyServer ([removed]:8008) -> FOUND
[DNS] HKLM\[…]\ControlSet001\Services\Tcpip\Interfaces\{5D75C6C1-9FDB-4F70-B978-B1919A0F075E} : NameServer (8.26.56.26,156.154.70.22) -> FOUND
[DNS] HKLM\[…]\ControlSet002\Services\Tcpip\Interfaces\{5D75C6C1-9FDB-4F70-B978-B1919A0F075E} : NameServer (8.26.56.26,156.154.70.22) -> FOUND
[DNS] HKLM\[…]\ControlSet003\Services\Tcpip\Interfaces\{5D75C6C1-9FDB-4F70-B978-B1919A0F075E} : NameServer (8.26.56.26,156.154.70.22) -> FOUND
[HJ] HKLM\[…]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ] HKLM\[…]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ] HKLM\[…]\System : EnableLUA (0) -> FOUND
[HJ] HKLM\[…]\Wow6432Node\System : EnableLUA (0) -> FOUND
[HJ SMENU] HKCU\[…]\Advanced : Start_ShowRecentDocs (0) -> FOUND
[HJ SMENU] HKCU\[…]\Advanced : Start_ShowMyGames (0) -> FOUND
[HJ SMENU] HKCU\[…]\Advanced : Start_ShowDownloads (0) -> FOUND
[HJ SMENU] HKCU\[…]\Advanced : Start_ShowVideos (0) -> FOUND
[HJ SMENU] HKCU\[…]\Advanced : Start_ShowRun (0) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 102.112.2o7.net


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD20EARS-00S8B1 ATA Device +++++
— User —
[MBR] 8a42d3d95e9a3d8a7422d59d9e04f4bd
[BSP] 06ee12b86889943e2cacad0a03d14604 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 190771 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 390700800 | Size: 1716954 Mo
User = LL1 … OK!
User = LL2 … OK!

+++++ PhysicalDrive1: WDC WD20EARS-00MVWB0 ATA Device +++++
— User —
[MBR] 0b25f3fc2a7b31d3fd4661c9bdb37ebd
[BSP] 4c201df24e6f54fbf9003c0c6c583dd3 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 190771 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 390700800 | Size: 1716954 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[1]_S_03112013_02d1152.txt >>
RKreport[1]_S_03112013_02d1152.txt

——————————————————————————————————————————-

CKScanner 2.1 - Additional Security Risks - These are not necessarily bad
c:\program files\gimp-2.0\share\gimp\2.0\patterns\cracked.pat
scanner sequence 3.NA.11.JMAPEL
—– EOF —–

——————————————————————————————————————————-
Hello ovcharovpcz

You have a illegal software on your system, which is probably how your computer became infected. Besides being illegal, cracks/keygens are the most certain means of infecting your system, as ALL illegal software contains some form of malicious code.

This forum, as well as all the other malware removal forums, does not condone the use of illegal software and does not offer support unless it is for the removal of it.

Continuing to help you could be viewed as supporting/condoning this therefore. If you require further help I need you to uninstall all the illegal software that you have downloaded and installed. When you have done thus, run CKScanner again and post a new log. If I don’t hear back from you in 24 hours this thread will be closed and no more help will be offered.

Satchfan
Hello Satchfan, Thank you for your answer. No, I do not have any illegal software on my computer. If you think, that "c:\program files\gimp-2.0\share\gimp\2.0\patterns\cracked.pat" is illegal, then you are wrong. I rather think, that something happened when I started to use vpn. I installed some programs as "VPNCheck" and add-ons to Firefox, which of course, all are free to use. But because I experience the problems only when I use the VPN and without it everything looks OK, I think to find another, better VPN-provider, which I can trust. Maybe everything comes from the VPN. Or as you said, maybe it is nothing, I am just getting paranoid. Regards, ovcharovpcz

If you think, that "c:\program files\gimp-2.0\share\gimp\2.0\patterns\cracked.pat" is illegal, then you are wrong.

No, I realise now that it is legit and running CKScanner again won't show anything but this is what I'm more concerned with:

C:\Windows\KMSEmulator.exe

Do you know what it is?

===============

With reference to the VPN problem, it may worth starting a thread in our Networking forum here.

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI