Help!

Google results hijacked and programs not updating

 
  

Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> HijackThis Logs RSS
Next:  More fun than MickeyMouse Land  
Author Message
elrechazao



Joined: Apr 04, 2009
Posts: 8



PostPosted: Sat Apr 04, 2009 10:12 pm    Post subject: Google results hijacked and programs not updating

So I'm getting the info-seek google browser results sending me to all sorts of random spammy pages. Ad aware, spybot, panda, avg, none of these will update or even install correctly. They all abort at some point in the installation process. I've read through other posts with similar problems here and the largest problem I have is that these AV and anti spyware programs won't run, won't install, won't update, and often the pages won't even open. Very frustrating.

My hijack this log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:10:53 PM, on 4/4/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\USER\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: (no name) - {4F2D5EBD-15E3-4311-82FC-C86E6EF95B03} - C:\Windows\system32\autopla.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [XboxStat] "c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - http://play.battlefield-heroes.com/static/updater/BFHUpdater_4.0.9.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3C73603-045C-4658-A3A7-0942DA1D57D0}: NameServer = 85.255.112.148,85.255.112.108
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.148,85.255.112.108
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.148,85.255.112.108
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.148,85.255.112.108
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

--
End of file - 6435 bytes


Last edited by elrechazao on Sat Apr 04, 2009 10:38 pm; edited 1 time in total
Back to top
elrechazao



Joined: Apr 04, 2009
Posts: 8



PostPosted: Sat Apr 04, 2009 10:36 pm    Post subject:

For more info I ran this scan after reading some other threads


OTListIt logfile created on: 4/4/2009 10:37:30 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.11.0 Folder = C:\Users\USER\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.14 Gb Available Physical Memory | 56.82% Memory free
4.00 Gb Paging File | 3.38 Gb Available in Paging File | 84.46% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 63.80 Gb Free Space | 27.40% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: USER-PC
Current User Name: USER
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2008/05/02 22:46:00 | 00,118,784 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvvsvc.exe
PRC - [2008/10/29 02:29:41 | 02,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Explorer.EXE
PRC - [2008/01/19 03:38:38 | 01,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007/08/24 08:00:48 | 00,033,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2007/03/14 19:05:48 | 00,257,088 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2008/12/19 09:12:34 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2007/09/26 19:05:58 | 00,734,264 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
PRC - [2008/12/12 12:41:06 | 00,157,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Zune\ZuneLauncher.exe
PRC - [2008/01/19 03:33:09 | 00,125,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehtray.exe
PRC - [2008/01/19 03:33:39 | 00,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2008/01/19 03:33:09 | 00,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehmsas.exe
PRC - [2007/04/04 14:20:16 | 00,126,976 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
PRC - [2007/05/15 21:25:19 | 00,063,040 | ---- | M] () -- C:\Windows\system32\PnkBstrA.exe
PRC - [2008/01/19 03:33:15 | 00,095,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mobsync.exe
PRC - [2008/01/19 03:33:39 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe
PRC - [2007/03/14 19:05:42 | 00,500,800 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/03/28 08:04:35 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/04/04 22:36:47 | 00,499,200 | ---- | M] (OldTimer Tools) -- C:\Users\USER\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/07/27 14:03:13 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/01/19 03:33:09 | 00,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehRecvr.exe -- (ehRecvr [On_Demand | Stopped])
SRV - [2006/11/02 08:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 08:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart [Auto | Stopped])
SRV - [2008/06/19 21:14:44 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2008/06/19 21:14:31 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2007/03/14 19:05:42 | 00,500,800 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2007/08/24 07:59:20 | 00,068,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
SRV - [2006/11/08 16:35:36 | 00,043,520 | ---- | M] (Hewlett-Packard) -- C:\Windows\system32\HPZinw12.dll -- (Net Driver HPZ12 [Auto | Running])
SRV - [2008/06/19 21:14:31 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007/04/04 14:20:16 | 00,126,976 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe -- (nTuneService [Auto | Running])
SRV - [2008/05/02 22:46:00 | 00,118,784 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\nvvsvc.exe -- (nvsvc [Auto | Running])
SRV - [2007/08/24 04:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2006/11/08 16:35:38 | 00,053,248 | ---- | M] (Hewlett-Packard) -- C:\Windows\system32\HPZipm12.dll -- (Pml Driver HPZ12 [Auto | Running])
SRV - [2007/05/15 21:25:19 | 00,063,040 | ---- | M] () -- C:\Windows\system32\PnkBstrA.exe -- (PnkBstrA [Auto | Running])
SRV - [2007/03/28 22:07:10 | 12,798,152 | RHS- | M] (Microsoft Corporation) -- C:\Program Files\NetMeeting\comp.exe -- (RPCER [Auto | Stopped])
SRV - [2008/01/19 03:38:24 | 00,272,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Running])
SRV - [2008/01/19 03:33:39 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [Auto | Running])
SRV - [2008/12/12 12:41:18 | 05,117,568 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Zune\ZuneNss.exe -- (ZuneNetworkSvc [On_Demand | Stopped])
SRV - [2008/12/12 12:41:08 | 00,243,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2006/11/02 05:51:38 | 00,420,968 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx [Disabled | Stopped])
DRV - [2006/11/02 05:51:32 | 00,297,576 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci [Disabled | Stopped])
DRV - [2006/11/02 05:50:35 | 00,098,408 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m [Disabled | Stopped])
DRV - [2006/11/02 05:51:00 | 00,147,048 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320 [Disabled | Stopped])
DRV - [2006/11/02 05:50:11 | 00,071,272 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx [Disabled | Stopped])
DRV - [2006/11/02 05:49:20 | 00,014,952 | ---- | M] (Acer Laboratories Inc.) -- C:\Windows\system32\drivers\aliide.sys -- (aliide [Disabled | Stopped])
DRV - [2008/12/01 12:52:14 | 00,103,360 | ---- | M] (SlySoft, Inc.) -- C:\Windows\System32\Drivers\AnyDVD.sys -- (AnyDVD [On_Demand | Running])
DRV - [2006/11/02 05:50:09 | 00,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\arc.sys -- (arc [Disabled | Stopped])
DRV - [2006/11/02 05:50:10 | 00,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas [Disabled | Stopped])
DRV - [2008/05/25 16:39:48 | 00,278,984 | ---- | M] () -- C:\Windows\system32\DRIVERS\atksgt.sys -- (atksgt [Auto | Running])
DRV - [2006/11/02 04:24:45 | 00,013,568 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo [On_Demand | Stopped])
DRV - [2006/11/02 04:24:46 | 00,005,248 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp [On_Demand | Stopped])
DRV - [2006/11/02 04:25:24 | 00,071,808 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brserid.sys -- (Brserid [Disabled | Stopped])
DRV - [2006/11/02 04:24:44 | 00,062,336 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm [Disabled | Stopped])
DRV - [2006/11/02 04:24:44 | 00,012,160 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm [Disabled | Stopped])
DRV - [2006/11/02 04:24:47 | 00,011,904 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer [On_Demand | Stopped])
DRV - [2006/11/02 05:49:28 | 00,016,488 | ---- | M] (CMD Technology, Inc.) -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide [Disabled | Stopped])
DRV - [2006/11/02 03:30:54 | 00,117,760 | ---- | M] (Intel Corporation) -- C:\Windows\system32\DRIVERS\E1G60I32.sys -- (E1G60 [On_Demand | Stopped])
DRV - [2008/07/21 08:11:58 | 00,024,392 | ---- | M] (Elaborate Bytes AG) -- C:\Windows\System32\Drivers\ElbyCDIO.sys -- (ElbyCDIO [System | Running])
DRV - [2006/11/02 05:51:34 | 00,316,520 | ---- | M] (Emulex) -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor [Disabled | Stopped])
DRV - [2004/10/25 20:02:58 | 00,021,664 | ---- | M] (EnTech Taiwan) -- C:\Windows\system32\DRIVERS\ENTECH.sys -- (ENTECH [On_Demand | Stopped])
DRV - [2006/09/19 14:44:04 | 00,015,664 | ---- | M] (GEAR Software Inc.) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
DRV - [2007/05/02 19:58:55 | 00,026,056 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\system32\DRIVERS\hamachi.sys -- (hamachi [On_Demand | Stopped])
DRV - [2006/11/02 05:50:10 | 00,037,480 | ---- | M] (Hewlett-Packard Company) -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs [Disabled | Stopped])
DRV - [2006/11/02 05:51:25 | 00,232,040 | ---- | M] (Intel Corporation) -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV [Disabled | Stopped])
DRV - [2006/11/02 05:50:17 | 00,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp [Disabled | Stopped])
DRV - [2006/11/02 05:50:07 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi [Disabled | Stopped])
DRV - [2006/11/02 05:50:09 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid [Disabled | Stopped])
DRV - [2008/05/25 16:39:48 | 00,025,416 | ---- | M] () -- C:\Windows\system32\DRIVERS\lirsgt.sys -- (lirsgt [Auto | Running])
DRV - [2006/11/02 05:50:04 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC [Disabled | Stopped])
DRV - [2006/11/02 05:50:05 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS [Disabled | Stopped])
DRV - [2006/11/02 05:50:10 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI [Disabled | Stopped])
DRV - [2006/11/02 05:49:53 | 00,028,776 | ---- | M] (LSI Logic Corporation) -- C:\Windows\system32\drivers\megasas.sys -- (megasas [Disabled | Stopped])
DRV - [2006/11/02 05:49:59 | 00,033,384 | ---- | M] (LSI Logic Corporation) -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x [Disabled | Stopped])
DRV - [2006/11/02 05:50:19 | 00,045,160 | ---- | M] (IBM Corporation) -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960 [Disabled | Stopped])
DRV - [2006/11/02 03:36:50 | 00,020,608 | ---- | M] (N-trig Innovative Technologies) -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi [Disabled | Stopped])
DRV - [2007/01/15 05:35:18 | 01,032,104 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\DRIVERS\nvmfdx32.sys -- (NVENETFD [On_Demand | Running])
DRV - [2008/05/02 22:46:00 | 07,460,320 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\DRIVERS\nvlddmkm.sys -- (nvlddmkm [On_Demand | Running])
DRV - [2007/04/04 14:21:00 | 00,006,912 | ---- | M] (NVidia Corp.) -- C:\Windows\nvoclock.sys -- (NVR0Dev [On_Demand | Running])
DRV - [2006/11/02 05:50:24 | 00,088,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid [Disabled | Stopped])
DRV - [2007/01/05 21:59:42 | 00,035,920 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor [Boot | Running])
DRV - [2006/12/22 08:28:56 | 00,100,648 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\DRIVERS\nvstor32.sys -- (nvstor32 [Boot | Running])
DRV - [2007/06/05 20:12:54 | 00,047,360 | ---- | M] (VSO Software) -- C:\Windows\System32\Drivers\pcouffin.sys -- (pcouffin [On_Demand | Stopped])
DRV - [2008/04/07 19:16:45 | 00,043,872 | ---- | M] (Sonic Solutions) -- C:\Windows\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2006/11/02 05:51:45 | 00,900,712 | ---- | M] (QLogic Corporation) -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300 [Disabled | Stopped])
DRV - [2006/11/02 05:50:35 | 00,106,088 | ---- | M] (QLogic Corporation) -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx [Disabled | Stopped])
DRV - [2006/11/02 02:37:21 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\Windows\System32\drivers\secdrv.sys -- (secdrv [Auto | Running])
DRV - [2006/11/02 05:50:10 | 00,038,504 | ---- | M] (Silicon Integrated Systems Corp.) -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2 [Disabled | Stopped])
DRV - [2006/11/02 05:50:16 | 00,071,784 | ---- | M] (Silicon Integrated Systems) -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4 [Disabled | Stopped])
DRV - [2008/05/25 16:22:49 | 00,685,816 | ---- | M] () -- C:\Windows\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2006/11/02 05:50:05 | 00,035,944 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx [Disabled | Stopped])
DRV - [2006/11/02 05:49:56 | 00,031,848 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi [Disabled | Stopped])
DRV - [2006/11/02 05:50:03 | 00,034,920 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3 [Disabled | Stopped])
DRV - [2006/11/02 05:51:25 | 00,235,112 | ---- | M] (ULi Electronics Inc.) -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci [Disabled | Stopped])
DRV - [2006/11/02 05:50:35 | 00,098,408 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata [Disabled | Stopped])
DRV - [2006/11/02 05:50:45 | 00,115,816 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2 [Disabled | Stopped])
DRV - [2008/01/19 01:53:39 | 00,007,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\DRIVERS\umpass.sys -- (UMPass [On_Demand | Stopped])
DRV - [2008/01/19 01:53:23 | 00,073,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\drivers\usbaudio.sys -- (usbaudio [On_Demand | Stopped])
DRV - [2006/11/02 05:49:30 | 00,017,512 | ---- | M] (VIA Technologies, Inc.) -- C:\Windows\system32\drivers\viaide.sys -- (viaide [Disabled | Stopped])
DRV - [2006/11/02 05:50:41 | 00,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid [Disabled | Stopped])
DRV - [2008/01/19 01:53:22 | 00,031,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\DRIVERS\WinUSB.sys -- (WinUSB [On_Demand | Stopped])
DRV - [2007/02/26 21:15:21 | 00,061,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\DRIVERS\xusb21.sys -- (xusb21 [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "instapundit.com"
FF - prefs.js..extensions.enabledItems: battlefieldheroespatcher.DeleteThis@ea.com:4.0.9.0
FF - prefs.js..extensions.enabledItems: {0C7E3F01-99E9-4095-9BDC-F84724960B57}:5.0.0.4
FF - prefs.js..extensions.enabledItems: max.DeleteThis@subfighter.com:1.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.1.6
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8


FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/02/11 17:59:47 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/28 08:04:42 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/28 08:04:42 | 00,000,000 | ---D | M]

[2008/06/17 21:45:20 | 00,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Extensions
[2008/06/17 21:45:20 | 00,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/04 21:52:57 | 00,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\yyxwbuve.default\extensions
[2009/03/23 23:05:02 | 00,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\yyxwbuve.default\extensions\{0C7E3F01-99E9-4095-9BDC-F84724960B57}
[2009/04/04 21:52:55 | 00,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\yyxwbuve.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2008/04/25 21:53:15 | 00,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\yyxwbuve.default\extensions\{BA979AD0-A3C5-4b32-A47E-4550BF00ECC7}
[2009/02/21 13:59:10 | 00,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\yyxwbuve.default\extensions\battlefieldheroespatcher@ea.com
[2008/09/26 18:42:42 | 00,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\yyxwbuve.default\extensions\max@subfighter.com
[2007/09/18 20:21:41 | 00,000,000 | ---D | M] -- C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\yyxwbuve.default\extensions\videodowloader@videodownloader.net
[2009/04/04 21:52:57 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/03/28 08:04:42 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/04/29 00:00:20 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
[2007/09/04 17:02:50 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2008/02/16 04:27:44 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/08/09 08:17:39 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2008/12/19 09:12:48 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/03/28 08:04:35 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/28 08:04:35 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/02/06 01:55:03 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/02/06 01:55:03 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/02/06 01:55:03 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/02/06 01:55:03 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/02/06 01:55:03 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/02/06 01:55:03 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/02/06 01:55:03 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (227703 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 7989 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (no name) - {4F2D5EBD-15E3-4311-82FC-C86E6EF95B03} - C:\Windows\system32\autopla.dll (Alcohol Soft Development Team)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [NWEReboot] File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation)
O4 - HKLM..\Run: [XboxStat] "c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun (Microsoft Corporation)
O4 - HKLM..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe" (Microsoft Corporation)
O4 - HKCU..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" (SlySoft, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" (DT Soft Ltd.)
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear (NVIDIA)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Domains: 32 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 32 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} http://play.battlefield-heroes.com/static/updater/BFHUpdater_4.0.9.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.148,85.255.112.108
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{D3C73603-045C-4658-A3A7-0942DA1D57D0}\\NameServer = 85.255.112.148,85.255.112.108
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll File not found
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009/04/04 15:56:01 | 00,000,429 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/04/04 22:36:46 | 00,499,200 | ---- | C] (OldTimer Tools) -- C:\Users\USER\Desktop\OTListIt2.exe
[2009/04/04 22:10:32 | 00,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Users\USER\Desktop\HijackThis.exe
[2009/04/04 22:08:28 | 00,028,544 | ---- | C] (Panda Security, S.L.) -- C:\Windows\System32\drivers\pavboot.sys
[2009/04/04 22:08:27 | 00,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2009/04/04 22:03:11 | 00,000,000 | ---D | C] -- C:\ProgramData\avg8
[2009/04/04 21:39:39 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Users\USER\Desktop\spybotsd162.exe
[2009/04/04 19:02:16 | 06,575,752 | ---- | C] (Symantec Corp.) -- C:\Users\USER\Desktop\Setup.exe
[2009/04/04 18:52:33 | 00,000,472 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/04/04 18:52:24 | 00,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2009/04/04 18:51:38 | 00,000,000 | -H-D | C] -- C:\ProgramData\~0
[2009/04/04 18:48:23 | 37,452,296 | ---- | C] (Lavasoft ) -- C:\Users\USER\Desktop\Ad-AwareAE.exe
[2009/04/04 18:05:56 | 00,132,158 | ---- | C] () -- C:\Users\USER\Desktop\David_Eddings_AudioBook_s_Collection_18_books.3986875.TPB.torrent
[2009/04/04 17:45:15 | 00,000,000 | ---D | C] -- C:\Users\USER\Desktop\DL
[2009/04/04 17:40:20 | 00,000,000 | ---D | C] -- C:\Users\USER\Desktop\Video convert
[2009/04/04 17:26:58 | 00,000,000 | ---D | C] -- C:\Users\USER\AppData\Roaming\Pegasys Inc
[2009/04/04 17:26:58 | 00,000,000 | ---D | C] -- C:\Program Files\Pegasys Inc
[2009/04/04 15:56:25 | 00,133,120 | ---- | C] (Microsoft Corporation) -- C:\Users\USER\AppData\Local\svcsv.exe
[2009/04/04 15:56:01 | 00,000,429 | RHS- | C] () -- C:\autorun.inf
[2009/04/04 15:56:01 | 00,000,000 | ---D | C] -- C:\RECYCLER
[2009/04/04 15:55:44 | 00,097,792 | ---- | C] (Alcohol Soft Development Team) -- C:\Windows\System32\autopla.dll
[2009/04/04 15:55:41 | 00,125,440 | ---- | C] () -- C:\Users\USER\AppData\Local\CheckForUpdates.exe
[2009/04/04 15:55:39 | 00,105,372 | ---- | C] () -- C:\Users\USER\AppData\Local\Codec_Setup_1240.exe
[2009/04/04 15:55:31 | 00,024,576 | ---- | C] () -- C:\Users\USER\AppData\Local\codecsetup262.exe
[2009/04/04 14:11:45 | 00,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_ZuneDriver_01_07_00.Wdf
[2009/04/04 14:11:45 | 00,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_WinUSB_01007.Wdf
[2009/04/04 14:10:39 | 00,000,838 | ---- | C] () -- C:\Users\Public\Desktop\Zune.lnk
[2009/04/04 14:10:31 | 00,000,000 | ---D | C] -- C:\Program Files\Zune
[2009/03/30 18:06:31 | 00,099,634 | ---- | C] () -- C:\Users\USER\Desktop\Eminem_-_full_discography_[1995-2008].4465275.TPB.torrent
[2009/03/29 20:14:47 | 00,000,000 | ---D | C] -- C:\Users\USER\Desktop\For Zune
[2009/03/21 11:03:15 | 00,000,000 | ---- | C] () -- C:\Users\USER\Desktop\New Microsoft Office Word Document.docx
[2009/03/16 15:27:37 | 00,000,000 | ---D | C] -- C:\Program Files\Coupons
[2009/03/16 15:12:20 | 00,000,000 | ---D | C] -- C:\Program Files\HP
[2009/03/16 15:12:11 | 00,000,000 | -H-D | C] -- C:\Config.Msi
[2009/03/16 15:10:03 | 00,157,032 | ---- | C] () -- C:\Windows\hphins25.dat
[2009/03/16 15:09:36 | 00,000,000 | ---D | C] -- C:\ProgramData\Hewlett-Packard
[2009/03/16 15:06:35 | 00,309,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\difxapi.dll
[2009/03/16 15:04:53 | 00,000,000 | ---D | C] -- C:\ProgramData\HP
[2009/03/10 23:56:01 | 10,622,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmp.dll
[2009/03/10 23:55:59 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwmp.dll
[2009/03/10 23:55:58 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdxm.ocx
[2009/03/10 23:55:58 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxmasf.dll
[2009/03/10 23:55:57 | 08,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL
[2009/03/10 23:55:52 | 00,268,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\schannel.dll
[2009/03/10 23:55:50 | 02,033,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2008/10/28 18:40:48 | 00,173,552 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2008/08/31 13:51:47 | 00,000,032 | ---- | C] () -- C:\Windows\CD_Start.INI
[2008/06/07 22:06:25 | 00,000,026 | ---- | C] () -- C:\Windows\dvdSanta.INI
[2008/06/07 21:53:40 | 01,216,512 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2008/06/07 21:53:40 | 00,921,600 | ---- | C] () -- C:\Windows\System32\vorbisenc.dll
[2008/06/07 21:53:40 | 00,237,568 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2008/06/07 21:53:40 | 00,237,568 | ---- | C] () -- C:\Windows\System32\OggDS.dll
[2008/06/07 21:53:40 | 00,188,416 | ---- | C] () -- C:\Windows\System32\vorbis.dll
[2008/06/07 21:53:40 | 00,045,056 | ---- | C] () -- C:\Windows\System32\ogg.dll
[2008/06/05 15:37:42 | 00,000,321 | ---- | C] () -- C:\Windows\game.ini
[2008/06/01 00:43:48 | 00,060,124 | ---- | C] () -- C:\Windows\System32\tcpmon.ini
[2008/06/01 00:42:53 | 00,368,640 | ---- | C] () -- C:\Windows\System32\msjetoledb40.dll
[2008/05/25 16:39:48 | 00,278,984 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2008/05/25 16:39:48 | 00,025,416 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2007/07/23 09:03:32 | 00,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2007/07/23 09:03:32 | 00,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2007/07/23 09:03:32 | 00,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2007/07/23 09:03:30 | 00,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2007/07/23 09:03:30 | 00,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2007/07/23 09:03:30 | 00,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2007/07/23 09:03:30 | 00,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2007/07/23 09:03:30 | 00,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2007/07/23 09:03:30 | 00,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2007/06/17 22:57:36 | 00,000,033 | ---- | C] () -- C:\Windows\GunzLauncher.INI
[2007/06/05 20:13:54 | 00,000,014 | ---- | C] () -- C:\Windows\System32\systeminfo3.dll
[2007/04/30 18:48:11 | 00,022,584 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2007/04/28 11:13:20 | 00,685,816 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2007/04/23 20:46:55 | 00,003,972 | ---- | C] () -- C:\Windows\System32\drivers\PciBus.sys
[2007/03/27 03:55:48 | 03,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2007/03/12 12:01:30 | 00,217,088 | ---- | C] () -- C:\Windows\NVGfxOgl.dll
[2006/12/12 12:24:42 | 00,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll
[2006/11/02 08:56:07 | 00,000,082 | -HS- | C] () -- C:\Windows\System32\desktop.ini
[2006/11/02 08:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 00,707,452 | ---- | C] () -- C:\Windows\System32\PerfStringBackup.INI
[2006/11/02 06:24:31 | 00,001,405 | ---- | C] () -- C:\Windows\msdfmap.ini
[2006/11/02 06:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\win.ini
[2006/11/02 06:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
[2006/11/02 03:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 03:09:45 | 00,027,097 | ---- | C] () -- C:\Windows\System32\country.sys
[2006/11/02 03:09:44 | 00,042,809 | ---- | C] () -- C:\Windows\System32\KEY01.SYS
[2006/11/02 03:09:44 | 00,042,537 | ---- | C] () -- C:\Windows\System32\KEYBOARD.SYS
[2006/11/02 03:09:42 | 00,009,029 | ---- | C] () -- C:\Windows\System32\ANSI.SYS
[2006/11/02 03:09:41 | 00,004,768 | ---- | C] () -- C:\Windows\System32\HIMEM.SYS
[2006/11/02 03:09:40 | 00,029,274 | ---- | C] () -- C:\Windows\System32\NTDOS412.SYS
[2006/11/02 03:09:38 | 00,029,370 | ---- | C] () -- C:\Windows\System32\NTDOS411.SYS
[2006/11/02 03:09:35 | 00,029,146 | ---- | C] () -- C:\Windows\System32\NTDOS404.SYS
[2006/11/02 03:09:31 | 00,029,146 | ---- | C] () -- C:\Windows\System32\NTDOS804.SYS
[2006/11/02 03:09:29 | 00,027,866 | ---- | C] () -- C:\Windows\System32\NTDOS.SYS
[2006/11/02 03:09:26 | 00,035,536 | ---- | C] () -- C:\Windows\System32\NTIO412.SYS
[2006/11/02 03:09:24 | 00,035,776 | ---- | C] () -- C:\Windows\System32\NTIO411.SYS
[2006/11/02 03:09:23 | 00,034,672 | ---- | C] () -- C:\Windows\System32\NTIO404.SYS
[2006/11/02 03:09:22 | 00,034,672 | ---- | C] () -- C:\Windows\System32\NTIO804.SYS
[2006/11/02 03:09:20 | 00,033,952 | ---- | C] () -- C:\Windows\System32\NTIO.SYS
[2006/11/02 02:25:08 | 00,013,312 | ---- | C] () -- C:\Windows\System32\win87em.dll

========== Files - Modified Within 30 Days ==========

[2009/04/04 22:36:47 | 00,499,200 | ---- | M] (OldTimer Tools) -- C:\Users\USER\Desktop\OTListIt2.exe
[2009/04/04 22:10:33 | 00,401,720 | ---- | M] (Trend Micro Inc.) -- C:\Users\USER\Desktop\HijackThis.exe
[2009/04/04 21:40:19 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Users\USER\Desktop\spybotsd162.exe
[2009/04/04 21:38:42 | 00,707,452 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/04/04 21:38:42 | 00,606,678 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/04/04 21:38:42 | 00,105,678 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/04/04 21:33:18 | 00,000,040 | -HS- | M] () -- C:\ProgramData\.zreglib
[2009/04/04 21:32:57 | 00,003,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/04/04 21:32:57 | 00,003,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/04/04 21:32:55 | 00,000,472 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/04/04 21:32:55 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/04/04 21:32:51 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/04/04 21:31:47 | 03,848,432 | -H-- | M] () -- C:\Users\USER\AppData\Local\IconCache.db
[2009/04/04 19:02:40 | 06,575,752 | ---- | M] (Symantec Corp.) -- C:\Users\USER\Desktop\Setup.exe
[2009/04/04 18:49:26 | 37,452,296 | ---- | M] (Lavasoft ) -- C:\Users\USER\Desktop\Ad-AwareAE.exe
[2009/04/04 18:05:58 | 00,132,158 | ---- | M] () -- C:\Users\USER\Desktop\David_Eddings_AudioBook_s_Collection_18_books.3986875.TPB.torrent
[2009/04/04 15:56:27 | 00,133,120 | ---- | M] (Microsoft Corporation) -- C:\Users\USER\AppData\Local\svcsv.exe
[2009/04/04 15:56:01 | 00,000,429 | RHS- | M] () -- C:\autorun.inf
[2009/04/04 15:55:43 | 00,125,440 | ---- | M] () -- C:\Users\USER\AppData\Local\CheckForUpdates.exe
[2009/04/04 15:55:40 | 00,105,372 | ---- | M] () -- C:\Users\USER\AppData\Local\Codec_Setup_1240.exe
[2009/04/04 15:55:35 | 00,024,576 | ---- | M] () -- C:\Users\USER\AppData\Local\codecsetup262.exe
[2009/04/04 15:51:00 | 00,206,336 | ---- | M] () -- C:\Users\USER\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/04 14:11:45 | 00,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_ZuneDriver_01_07_00.Wdf
[2009/04/04 14:11:45 | 00,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_WinUSB_01007.Wdf
[2009/04/04 14:10:39 | 00,000,838 | ---- | M] () -- C:\Users\Public\Desktop\Zune.lnk
[2009/03/30 18:06:33 | 00,099,634 | ---- | M] () -- C:\Users\USER\Desktop\Eminem_-_full_discography_[1995-2008].4465275.TPB.torrent
[2009/03/21 11:03:15 | 00,000,000 | ---- | M] () -- C:\Users\USER\Desktop\New Microsoft Office Word Document.docx
[2009/03/20 21:34:39 | 00,000,026 | ---- | M] () -- C:\Windows\dvdSanta.INI
[2009/03/16 15:12:07 | 00,157,032 | ---- | M] () -- C:\Windows\hphins25.dat
[2009/03/11 03:08:43 | 00,356,424 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
< End of report >


Last edited by elrechazao on Sat Apr 04, 2009 10:43 pm; edited 1 time in total
Back to top
elrechazao



Joined: Apr 04, 2009
Posts: 8



PostPosted: Sat Apr 04, 2009 10:37 pm    Post subject:

OTListIt Extras logfile created on: 4/4/2009 10:37:30 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.11.0 Folder = C:\Users\USER\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.14 Gb Available Physical Memory | 56.82% Memory free
4.00 Gb Paging File | 3.38 Gb Available in Paging File | 84.46% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 63.80 Gb Free Space | 27.40% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: USER-PC
Current User Name: USER
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" =
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications" = 0
"EnableFirewall" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR)
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java(TM) SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth
"{4AA3D64E-9EC3-4B0F-AB91-5885AC55641F}" = Microsoft Games for Windows - LIVE
"{5E863175-E85D-44A6-8968-82507D34AE7F}" = QuickTime
"{66F0AC35-4805-44BC-A3D4-347D4196F9B3}" = Microsoft Xbox 360 Accessories 1.1
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B2C675E-8040-431B-99C4-137DF4FBF75A}" = Thermal Analysis Tool
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"{7EF15AAF-42AC-4CF6-B4B4-C4F0D1D92122}" = Far Cry (Patch 1.4)
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}" = AGEIA PhysX v7.11.13
"{AB90749C-7422-4580-8A7A-66CC5E9E5F98}" = iTunes
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.1
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BB3194B5-9D1D-47bd-9A84-5DA711AD85AF}" = Battlefield Heroes
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{EE4ACABF-531E-419A-9225-B8E0FA4955AF}" = Zune Language Pack (ES)
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FD052FB9-FE90-4438-B355-15EDC89D8FB1}" = Microsoft Games for Windows - LIVE Redistributable
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FF70513F-E3A7-402F-84FB-B7810A064BE2}" = Zune
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Age Of Empires 2 & The Conquerors Expansion - Full Game" = Age Of Empires 2 & The Conquerors Expansion - Full Game
"AnyDVD" = AnyDVD
"BitTornado" = BitTornado 0.3.17
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Crayon Physics Deluxe_is1" = Crayon Physics Deluxe - release 51
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"dvdSanta 4.50 - Make your own DVD movies!_is1" = dvdSanta 4.50
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FLVPlayer" = FLV Player 1.3.3
"HijackThis" = HijackThis 2.0.2
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.Cool" = Mozilla Firefox (3.0.Cool
"NVIDIA Drivers" = NVIDIA Drivers
"RealAlt_is1" = Real Alternative 1.8.0
"VLC media player" = VideoLAN VLC media player 0.8.6f
"WinRAR archiver" = WinRAR archiver
"Zune" = Zune

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Back to top
ctran



Joined: Apr 04, 2009
Posts: 1



PostPosted: Sat Apr 04, 2009 10:50 pm    Post subject:

well, heres one: a weird program living in system32:
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
AND
your host file is hijacked.

O1 HOSTS File: (227703 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 7989 more lines...

Go to Run > notepad C:\Windows\System32\drivers\etc\Hosts

you will get a list of these inputs of above. delete all of them.
Back to top
elrechazao



Joined: Apr 04, 2009
Posts: 8



PostPosted: Sat Apr 04, 2009 11:00 pm    Post subject:

Thanks for the response. The host file won't save with the changes since it reports as read only. Any tips on how to work that out? I'm guessing the other program is punkbuster, which is an anti cheat program for various online games. I'd love to get rid of it, since I don't play them anymore.
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Mon Apr 06, 2009 8:44 pm    Post subject:

That O23 service is legitimate and is from PunkBuster. We can remove that part later on as it's not crucial at this point.

The hosts file is not hijacked as far as I can see. It looks like you might be using a customized hosts file to block out bad sites. If you are unsure if you added this yourself, you can always delete it and add a new one back from MVPS.

Run a scan in HijackThis. Check each of the following if they still exist and hit 'Fix Checked' after you checked the last one:

O17 - HKLM\System\CCS\Services\Tcpip\..\{D3C73603-045C-4658-A3A7-0942DA1D57D0}: NameServer = 85.255.112.148,85.255.112.108
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.148,85.255.112.108
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.148,85.255.112.108
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.148,85.255.112.108


See if you can get the following and run them:

Download Malwarebytes ' Anti-Malware at http://www.besttechie.net/tools/mbam-setup.exe or http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html Double-click on mbam-setup.exe to install the application.

* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform Full Scan, then click Scan.
* The scan may take some time to finish, so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to restart (see Extra Note below).
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy & paste the entire report into your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

Go to http://www.bleepingcomputer.com/combofix/how-to-use-combofix and follow the instructions on how to install the Recovery Console and run ComboFix. Go through all the steps until posting the log part. Post the combofix log here.
Back to top
AIM Address Yahoo Messenger
elrechazao



Joined: Apr 04, 2009
Posts: 8



PostPosted: Mon Apr 06, 2009 10:36 pm    Post subject:

Malwarebytes' Anti-Malware 1.36
Database version: 1945
Windows 6.0.6001 Service Pack 1

4/6/2009 10:02:09 PM
mbam-log-2009-04-06 (22-02-09).txt

Scan type: Full Scan (C:\|)
Objects scanned: 196852
Time elapsed: 28 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 4
Registry Data Items Infected: 6
Folders Infected: 2
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4f2d5ebd-15e3-4311-82fc-c86e6ef95b03} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4f2d5ebd-15e3-4311-82fc-c86e6ef95b03} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f2d5ebd-15e3-4311-82fc-c86e6ef95b03} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Convert2PlaySoft (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.148,85.255.112.108 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{d3c73603-045c-4658-a3a7-0942da1d57d0}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.148,85.255.112.108 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.148,85.255.112.108 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{d3c73603-045c-4658-a3a7-0942da1d57d0}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.148,85.255.112.108 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.148,85.255.112.108 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{d3c73603-045c-4658-a3a7-0942da1d57d0}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.148,85.255.112.108 -> Quarantined and deleted successfully.

Folders Infected:
C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Convert2Play (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Convert2Play (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Files Infected:
C:\Users\USER\AppData\Local\Codec_Setup_1240.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1U3RZMLR\CodecSetup_ver1.1[1].exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Windows\System32\autopla.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Convert2Play\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\autorun.inf (Trojan.Agent) -> Quarantined and deleted successfully.
C:\RECYCLER\S-9-7-34-100007086-100017646-100020061-6207.com (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\gaopdxcounter (Trojan.Agent) -> Quarantined and deleted successfully.
Back to top
elrechazao



Joined: Apr 04, 2009
Posts: 8



PostPosted: Mon Apr 06, 2009 10:49 pm    Post subject:

I ran it and it found a file, but I ran it a second time and the log from that first run was overwritten by this one from the second run.



ComboFix 09-04-04.01 - USER-2009-04-06 22:46:27.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2047.1308 [GMT -4:00]
Running from: c:\users\USER\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2009-03-07 to 2009-04-07 )))))))))))))))))))))))))))))))
.

2009-04-06 22:37 . 2009-04-06 22:37 <DIR> d-------- c:\program files\Trend Micro
2009-04-06 21:29 . 2009-04-06 21:29 <DIR> d-------- c:\users\USER\AppData\Roaming\Malwarebytes
2009-04-06 21:29 . 2009-04-06 21:29 <DIR> d-------- c:\users\All Users\Malwarebytes
2009-04-06 21:29 . 2009-04-06 21:29 <DIR> d-------- c:\programdata\Malwarebytes
2009-04-06 21:29 . 2009-04-06 21:29 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-04-06 21:29 . 2009-04-06 15:32 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-04-06 21:29 . 2009-04-06 15:32 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-04-05 11:52 . 2009-04-05 11:52 <DIR> d-------- c:\users\USER\AppData\Roaming\Move Networks
2009-04-04 22:08 . 2009-04-04 22:08 <DIR> d-------- c:\program files\Panda Security
2009-04-04 22:08 . 2008-06-19 16:24 28,544 --a------ c:\windows\System32\drivers\pavboot.sys
2009-04-04 22:03 . 2009-04-04 22:03 <DIR> d-------- c:\users\All Users\avg8
2009-04-04 22:03 . 2009-04-04 22:03 <DIR> d-------- c:\programdata\avg8
2009-04-04 18:52 . 2009-04-04 21:37 <DIR> d----c--- c:\windows\System32\DRVSTORE
2009-04-04 17:26 . 2009-04-04 17:26 <DIR> d-------- c:\users\USER\AppData\Roaming\Pegasys Inc
2009-04-04 17:26 . 2009-04-04 17:26 <DIR> d-------- c:\program files\Pegasys Inc
2009-04-04 14:11 . 2009-04-04 14:11 0 --ah----- c:\windows\System32\drivers\Msft_User_ZuneDriver_01_07_00.Wdf
2009-04-04 14:11 . 2009-04-04 14:11 0 --ah----- c:\windows\System32\drivers\Msft_Kernel_WinUSB_01007.Wdf
2009-04-04 14:10 . 2009-04-04 14:12 <DIR> d-------- c:\program files\Zune
2009-03-16 15:27 . 2009-03-16 15:27 <DIR> d-------- c:\program files\Coupons
2009-03-16 15:12 . 2009-03-16 15:12 <DIR> d-------- c:\program files\HP
2009-03-16 15:10 . 2009-03-16 15:12 157,032 --a------ c:\windows\hphins25.dat
2009-03-16 15:09 . 2009-03-16 15:09 <DIR> d-------- c:\users\All Users\Hewlett-Packard
2009-03-16 15:09 . 2009-03-16 15:09 <DIR> d-------- c:\programdata\Hewlett-Packard
2009-03-16 15:08 . 2007-11-08 11:02 271,704 --a------ c:\windows\System32\hpzids01.dll
2009-03-16 15:08 . 2007-10-20 18:25 118,272 --a------ c:\windows\System32\hpz3l5mu.dll
2009-03-16 15:06 . 2007-10-30 05:25 372,736 --a------ c:\windows\System32\hppldcoi.dll
2009-03-16 15:06 . 2007-10-30 05:25 309,760 --a------ c:\windows\System32\difxapi.dll
2009-03-16 15:04 . 2009-03-16 15:04 <DIR> d-------- c:\users\All Users\HP
2009-03-16 15:04 . 2009-03-16 15:04 <DIR> d-------- c:\programdata\HP
2009-03-11 19:23 . 2006-11-02 06:23 <DIR> dr------- c:\users\Mcx3\Videos
2009-03-11 19:23 . 2006-11-02 06:23 <DIR> d-------- c:\users\Mcx3\Saved Games
2009-03-11 19:23 . 2006-11-02 06:23 <DIR> dr------- c:\users\Mcx3\Pictures
2009-03-11 19:23 . 2006-11-02 06:23 <DIR> dr------- c:\users\Mcx3\Music
2009-03-11 19:23 . 2006-11-02 06:23 <DIR> dr------- c:\users\Mcx3\Links
2009-03-11 19:23 . 2006-11-02 06:23 <DIR> dr------- c:\users\Mcx3\Downloads
2009-03-11 19:23 . 2009-03-11 19:24 <DIR> dr------- c:\users\Mcx3\Documents
2009-03-11 19:23 . 2009-03-11 19:24 <DIR> d--h----- c:\users\Mcx3\AppData
2009-03-11 19:23 . 2009-03-11 19:24 <DIR> d-------- c:\users\Mcx3
2009-03-10 23:55 . 2008-12-15 23:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-10 23:55 . 2009-02-08 23:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-10 23:55 . 2008-11-27 00:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-10 23:55 . 2008-12-16 01:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-10 23:55 . 2008-12-16 01:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-10 23:55 . 2008-12-16 01:31 4,096 --a------ c:\windows\System32\dxmasf.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-05 19:52 --------- d-----w c:\programdata\DVD Shrink
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Tue Apr 07, 2009 7:12 pm    Post subject:

Did ComboFix give you problems? Why did you run it a second time? The log is cutoff, please post the latest log from ComboFix. It's located at C:\ComboFix\.
Back to top
AIM Address Yahoo Messenger
elrechazao



Joined: Apr 04, 2009
Posts: 8



PostPosted: Wed Apr 08, 2009 10:54 pm    Post subject:

This is actually the entire file. I ran it twice out of habit. I tend to run every AV or anti spyware/malware program a few times in a row to verify that the fixes actually fixed things.



ComboFix 09-04-04.01 - Tyler 2009-04-06 22:46:27.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2047.1308 [GMT -4:00]
Running from: c:\users\Tyler\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2009-03-07 to 2009-04-07 )))))))))))))))))))))))))))))))
.

2009-04-06 22:37 . 2009-04-06 22:37 <DIR> d-------- c:\program files\Trend Micro
2009-04-06 21:29 . 2009-04-06 21:29 <DIR> d-------- c:\users\Tyler\AppData\Roaming\Malwarebytes
2009-04-06 21:29 . 2009-04-06 21:29 <DIR> d-------- c:\users\All Users\Malwarebytes
2009-04-06 21:29 . 2009-04-06 21:29 <DIR> d-------- c:\programdata\Malwarebytes
2009-04-06 21:29 . 2009-04-06 21:29 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-04-06 21:29 . 2009-04-06 15:32 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-04-06 21:29 . 2009-04-06 15:32 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-04-05 11:52 . 2009-04-05 11:52 <DIR> d-------- c:\users\Tyler\AppData\Roaming\Move Networks
2009-04-04 22:08 . 2009-04-04 22:08 <DIR> d-------- c:\program files\Panda Security
2009-04-04 22:08 . 2008-06-19 16:24 28,544 --a------ c:\windows\System32\drivers\pavboot.sys
2009-04-04 22:03 . 2009-04-04 22:03 <DIR> d-------- c:\users\All Users\avg8
2009-04-04 22:03 . 2009-04-04 22:03 <DIR> d-------- c:\programdata\avg8
2009-04-04 18:52 . 2009-04-04 21:37 <DIR> d----c--- c:\windows\System32\DRVSTORE
2009-04-04 17:26 . 2009-04-04 17:26 <DIR> d-------- c:\users\Tyler\AppData\Roaming\Pegasys Inc
2009-04-04 17:26 . 2009-04-04 17:26 <DIR> d-------- c:\program files\Pegasys Inc
2009-04-04 14:11 . 2009-04-04 14:11 0 --ah----- c:\windows\System32\drivers\Msft_User_ZuneDriver_01_07_00.Wdf
2009-04-04 14:11 . 2009-04-04 14:11 0 --ah----- c:\windows\System32\drivers\Msft_Kernel_WinUSB_01007.Wdf
2009-04-04 14:10 . 2009-04-04 14:12 <DIR> d-------- c:\program files\Zune
2009-03-16 15:27 . 2009-03-16 15:27 <DIR> d-------- c:\program files\Coupons
2009-03-16 15:12 . 2009-03-16 15:12 <DIR> d-------- c:\program files\HP
2009-03-16 15:10 . 2009-03-16 15:12 157,032 --a------ c:\windows\hphins25.dat
2009-03-16 15:09 . 2009-03-16 15:09 <DIR> d-------- c:\users\All Users\Hewlett-Packard
2009-03-16 15:09 . 2009-03-16 15:09 <DIR> d-------- c:\programdata\Hewlett-Packard
2009-03-16 15:08 . 2007-11-08 11:02 271,704 --a------ c:\windows\System32\hpzids01.dll
2009-03-16 15:08 . 2007-10-20 18:25 118,272 --a------ c:\windows\System32\hpz3l5mu.dll
2009-03-16 15:06 . 2007-10-30 05:25 372,736 --a------ c:\windows\System32\hppldcoi.dll
2009-03-16 15:06 . 2007-10-30 05:25 309,760 --a------ c:\windows\System32\difxapi.dll
2009-03-16 15:04 . 2009-03-16 15:04 <DIR> d-------- c:\users\All Users\HP
2009-03-16 15:04 . 2009-03-16 15:04 <DIR> d-------- c:\programdata\HP
2009-03-11 19:23 . 2006-11-02 06:23 <DIR> dr------- c:\users\Mcx3\Videos
2009-03-11 19:23 . 2006-11-02 06:23 <DIR> d-------- c:\users\Mcx3\Saved Games
2009-03-11 19:23 . 2006-11-02 06:23 <DIR> dr------- c:\users\Mcx3\Pictures
2009-03-11 19:23 . 2006-11-02 06:23 <DIR> dr------- c:\users\Mcx3\Music
2009-03-11 19:23 . 2006-11-02 06:23 <DIR> dr------- c:\users\Mcx3\Links
2009-03-11 19:23 . 2006-11-02 06:23 <DIR> dr------- c:\users\Mcx3\Downloads
2009-03-11 19:23 . 2009-03-11 19:24 <DIR> dr------- c:\users\Mcx3\Documents
2009-03-11 19:23 . 2009-03-11 19:24 <DIR> d--h----- c:\users\Mcx3\AppData
2009-03-11 19:23 . 2009-03-11 19:24 <DIR> d-------- c:\users\Mcx3
2009-03-10 23:55 . 2008-12-15 23:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-10 23:55 . 2009-02-08 23:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-10 23:55 . 2008-11-27 00:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-10 23:55 . 2008-12-16 01:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-10 23:55 . 2008-12-16 01:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-10 23:55 . 2008-12-16 01:31 4,096 --a------ c:\windows\System32\dxmasf.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-05 19:52 --------- d-----w c:\programdata\DVD Shrink
2009-04-05 02:02 --------- d-----w c:\programdata\Avg7
2009-04-05 01:37 --------- d-----w c:\programdata\Lavasoft
2009-04-03 20:51 --------- d-----w c:\program files\Common Files\Blizzard Entertainment
2009-03-22 00:43 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-21 20:47 --------- d-----w c:\program files\Crayon Physics Deluxe
2009-03-21 01:24 --------- d-----w c:\program files\dvdSanta
2009-03-20 01:06 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-20 00:22 --------- d-----w c:\program files\Steam
2009-03-19 23:45 --------- d-----w c:\program files\Common Files\Steam
2009-03-11 07:06 --------- d-----w c:\program files\Windows Mail
2009-03-11 07:00 --------- d-----w c:\programdata\Microsoft Help
2009-02-26 00:30 --------- d-----w c:\programdata\Blizzard
2009-02-25 01:31 --------- d-----w c:\program files\SlySoft
2009-02-21 17:59 --------- d-----w c:\program files\EA Games
2009-02-14 22:06 --------- d-----w c:\users\Tyler\AppData\Roaming\dvdcss
2009-01-15 06:11 827,392 ----a-w c:\windows\System32\wininet.dll
2008-06-01 07:19 174 --sha-w c:\program files\desktop.ini
2007-06-18 03:08 81,920 ----a-w c:\users\Tyler\AppData\Roaming\ezpinst.exe
2007-06-18 03:08 47,360 ----a-w c:\users\Tyler\AppData\Roaming\pcouffin.sys
2006-04-20 22:58 3,874,871 ----a-w c:\users\Tyler\ORTHOS.exe
.

((((((((((((((((((((((((((((( SnapShot.TakeThisOut@2009-04-06_22.33.32.27 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-07 02:41:48 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-04-07 02:41:48 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-04-07 02:17:47 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-04-07 02:42:47 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2009-04-07 02:17:41 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-04-07 02:48:03 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2009-04-07 02:08:01 105,300 ----a-w c:\windows\System32\perfc009.dat
+ 2009-04-07 02:47:42 105,678 ----a-w c:\windows\System32\perfc009.dat
- 2009-04-07 02:08:01 605,930 ----a-w c:\windows\System32\perfh009.dat
+ 2009-04-07 02:47:42 606,678 ----a-w c:\windows\System32\perfh009.dat
- 2009-04-07 01:28:26 13,176 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3648916112-1847584433-1383843039-1000_UserData.bin
+ 2009-04-07 02:43:41 13,368 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3648916112-1847584433-1383843039-1000_UserData.bin
- 2009-04-07 01:28:26 66,660 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-04-07 02:43:41 66,730 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-04-07 01:28:25 39,100 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-04-07 02:43:40 39,466 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-04-04 81920]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVD.exe" [2008-12-01 89024]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-16 282624]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-03-14 257088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-19 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-02 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-02 92704]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-26 734264]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-12-12 157312]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{14A5681C-2346-4421-BAEA-EDA543FB2C91}"= UDP:c:\program files\Grisoft\AVG7\avginet.exe:avginet.exe
"{E6C0A417-9CEF-4796-9752-77EFFC8589F3}"= TCP:c:\program files\Grisoft\AVG7\avginet.exe:avginet.exe
"{3174302C-8E7B-4D8A-91D8-F527CE2929C6}"= UDP:c:\program files\Grisoft\AVG7\avgamsvr.exe:avgamsvr.exe
"{3A0242E5-DCCC-4A70-9AE4-DBF5121E8F53}"= TCP:c:\program files\Grisoft\AVG7\avgamsvr.exe:avgamsvr.exe
"{A271388D-DDE2-4F13-8E4A-C58979E9751D}"= UDP:c:\program files\Grisoft\AVG7\avgcc.exe:avgcc.exe
"{ADA9EB4D-F347-429D-A187-7933406AC3FE}"= TCP:c:\program files\Grisoft\AVG7\avgcc.exe:avgcc.exe
"{831FB6F9-B5EE-445E-9AE1-8E6CD7D119C7}"= UDP:c:\program files\Grisoft\AVG7\avgemc.exe:avgemc.exe
"{AD87B2B8-FC1B-446E-ADC1-EF45B09D5723}"= TCP:c:\program files\Grisoft\AVG7\avgemc.exe:avgemc.exe
"TCP Query User{58B7DED5-3FE8-4B1C-9E8A-361E110BC672}c:\\program files\\abc\\abc.exe"= UDP:c:\program files\abc\abc.exe:abc
"UDP Query User{47D5F137-1E2E-40AB-A686-1893729E4C4A}c:\\program files\\abc\\abc.exe"= TCP:c:\program files\abc\abc.exe:abc
"{19573E3A-6014-43CA-8DBB-F2B163E26F9C}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{CAA34149-0CF8-4FAE-9C99-C97E39EF71DE}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{BCB8D4B1-A0E5-483D-AC2C-60141CDECF4D}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{F6C480AC-BA73-4982-B17C-B74C28C08AB1}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{09C6A2B6-B326-40CC-8B98-E892945DF3B1}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{31F164C2-119C-409D-B911-DC8C3FFC75CF}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{ECBD7651-5F62-4280-A6FA-C0F94A22CF02}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{E197103A-5DA1-4A08-8CAE-ACBCF856F3CD}"= UDP:c:\program files\Electronic Arts\Battlefield 2142 Demo\BF2142.exe:Battlefield 2
"{C2F38D24-B2E4-4A15-8E1F-B41FBD6B390F}"= TCP:c:\program files\Electronic Arts\Battlefield 2142 Demo\BF2142.exe:Battlefield 2
"{A205D9C6-E212-4706-8DF7-89BFAEFF91CA}"= UDP:c:\program files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)
"{76DA78B7-D18F-4D12-85C7-64815182FF0E}"= TCP:c:\program files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)
"{6865B50A-2621-4339-8725-E7E8CDBDEE7B}"= UDP:c:\program files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)
"{11D9F8B0-38D8-4611-B668-292FB193DAB4}"= TCP:c:\program files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)
"TCP Query User{FAA141D9-779C-47B2-8C4B-D579D2B0E664}c:\\program files\\thq\\titan quest immortal throne\\tqit.exe"= UDP:c:\program files\thq\titan quest immortal throne\tqit.exe:Tqit
"UDP Query User{C2CE437D-9F6E-40FF-998B-93E884C5A1AA}c:\\program files\\thq\\titan quest immortal throne\\tqit.exe"= TCP:c:\program files\thq\titan quest immortal throne\tqit.exe:Tqit
"TCP Query User{3D3C3E77-73F8-40CA-A206-748A8727609C}c:\\program files\\abc\\abc.exe"= UDP:c:\program files\abc\abc.exe:abc
"UDP Query User{8F7F260B-C42D-4805-85EA-19ACCBDCC726}c:\\program files\\abc\\abc.exe"= TCP:c:\program files\abc\abc.exe:abc
"TCP Query User{3244728A-1538-463F-AC27-A2FB744CDE7B}c:\\program files\\itunes\\itunes.exe"= UDP:c:\program files\itunes\itunes.exe:iTunes
"UDP Query User{DED519B1-8707-4CA2-9FF1-0AC41DDE6C58}c:\\program files\\itunes\\itunes.exe"= TCP:c:\program files\itunes\itunes.exe:iTunes
"TCP Query User{65903F4C-8687-4B1C-A6C5-70090A05A341}c:\\program files\\capcom\\lost_planet_trial_dx10\\lostplanetdx10.exe"= UDP:c:\program files\capcom\lost_planet_trial_dx10\lostplanetdx10.exe:LostPlanetDX10
"UDP Query User{5F1CB7D8-F7DE-474D-AA2F-5BC33BECF679}c:\\program files\\capcom\\lost_planet_trial_dx10\\lostplanetdx10.exe"= TCP:c:\program files\capcom\lost_planet_trial_dx10\lostplanetdx10.exe:LostPlanetDX10
"TCP Query User{7273C9EC-9397-45FC-8F13-55BB33403054}c:\\unrealtournament\\system\\unrealtournament.exe"= UDP:c:\unrealtournament\system\unrealtournament.exe:UnrealTournament
"UDP Query User{1FD1A524-B8AB-49C6-BAB8-253AAF99F4D5}c:\\unrealtournament\\system\\unrealtournament.exe"= TCP:c:\unrealtournament\system\unrealtournament.exe:UnrealTournament
"TCP Query User{C77B50A0-EC5B-4B08-BF78-F25474814D74}c:\\ijji\\english\\gunz\\gunz.exe"= UDP:c:\ijji\english\gunz\gunz.exe:Gunz
"UDP Query User{EE5887B8-9F41-4DAB-9488-56E305845E8B}c:\\ijji\\english\\gunz\\gunz.exe"= TCP:c:\ijji\english\gunz\gunz.exe:Gunz
"{0FE0F373-FF0F-40F8-B847-AD7566583BA7}"= UDP:9420:Red Swoosh
"{A3503452-7561-416B-AD8D-1A177AADB94A}"= TCP:5000:Red Swoosh
"TCP Query User{F05C63D1-2728-4DA4-B326-78492E1880D0}c:\\program files\\bittornado\\btdownloadgui.exe"= UDP:c:\program files\bittornado\btdownloadgui.exe:btdownloadgui
"UDP Query User{367956C5-E55B-431A-82DD-30F1C880CD69}c:\\program files\\bittornado\\btdownloadgui.exe"= TCP:c:\program files\bittornado\btdownloadgui.exe:btdownloadgui
"{F2C6FEBA-4462-4E3F-BB88-75490072AA38}"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent
"{AA9AF490-BA70-47D5-80E8-2429611A59B7}"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent
"TCP Query User{E5B010AB-B928-48A9-B0F4-D773DDD70782}c:\\program files\\bittornado\\btdownloadgui.exe"= UDP:c:\program files\bittornado\btdownloadgui.exe:btdownloadgui
"UDP Query User{EDC412FD-1FFD-4BCC-8D24-293AFCB8A8BB}c:\\program files\\bittornado\\btdownloadgui.exe"= TCP:c:\program files\bittornado\btdownloadgui.exe:btdownloadgui
"TCP Query User{1AD4AE7B-8BF4-4C7F-A3A9-B454FBEA4AE4}c:\\program files\\world of warcraft\\wow-1.12.0-enus-downloader.exe"= UDP:c:\program files\world of warcraft\wow-1.12.0-enus-downloader.exe:Blizzard Downloader
"UDP Query User{F5576510-C2A0-4AEA-8C1E-335E19593E63}c:\\program files\\world of warcraft\\wow-1.12.0-enus-downloader.exe"= TCP:c:\program files\world of warcraft\wow-1.12.0-enus-downloader.exe:Blizzard Downloader
"TCP Query User{E1ABC44C-B05E-4E92-84F4-8BEE5EA2C72E}c:\\program files\\world of warcraft\\wow-1.12.x-to-2.0.1-enus-patch-downloader.exe"= UDP:c:\program files\world of warcraft\wow-1.12.x-to-2.0.1-enus-patch-downloader.exe:Blizzard Downloader
"UDP Query User{5F5F11D2-737E-4518-8462-15E5A06EB8BE}c:\\program files\\world of warcraft\\wow-1.12.x-to-2.0.1-enus-patch-downloader.exe"= TCP:c:\program files\world of warcraft\wow-1.12.x-to-2.0.1-enus-patch-downloader.exe:Blizzard Downloader
"TCP Query User{3AAC3CC6-C6BA-4DCD-AC83-1F35251EEFA6}c:\\program files\\turbine\\the lord of the rings online\\lotroclient.exe"= UDP:c:\program files\turbine\the lord of the rings online\lotroclient.exe:lotroclient.exe
"UDP Query User{CD080360-A5E5-4A12-BDDD-EC482E763371}c:\\program files\\turbine\\the lord of the rings online\\lotroclient.exe"= TCP:c:\program files\turbine\the lord of the rings online\lotroclient.exe:lotroclient.exe
"{219288FE-8767-401E-8028-46A4DF379370}"= UDP:c:\program files\Unreal Tournament 3 Demo\Binaries\UT3Demo.exe:Unreal Tournament 3 Demo
"{C137B1A1-BBF6-4BE3-940A-A7289B2C017D}"= TCP:c:\program files\Unreal Tournament 3 Demo\Binaries\UT3Demo.exe:Unreal Tournament 3 Demo
"{16E6CCE7-F18B-4016-BCB8-ABF29782BF6A}"= UDP:c:\program files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"{D6242C07-997C-486C-800A-FD21605CCB3E}"= TCP:c:\program files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"TCP Query User{D9E97BE8-51B8-4BAE-900C-C6146DD770F2}c:\\windows\\system32\\msiexec.exe"= UDP:c:\windows\system32\msiexec.exe:Windows® installer
"UDP Query User{6048F5E3-E3D9-486B-9FC6-CB904346E82D}c:\\windows\\system32\\msiexec.exe"= TCP:c:\windows\system32\msiexec.exe:Windows® installer
"TCP Query User{67B361A0-F840-4E54-A063-C3E1E035B775}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{2278C907-422A-42F7-A0DA-45126D48B24D}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{1B7B4DB0-C4AF-483D-A763-26363CCC9B6E}c:\\program files\\nbc direct\\storefrontplayer.exe"= UDP:c:\program files\nbc direct\storefrontplayer.exe:NBC Direct Beta
"UDP Query User{0E36FFE5-C1A2-4ED7-98FD-C8D3A05D4775}c:\\program files\\nbc direct\\storefrontplayer.exe"= TCP:c:\program files\nbc direct\storefrontplayer.exe:NBC Direct Beta
"TCP Query User{A9A19393-292A-41A9-B9F4-7BDEBF76711E}c:\\users\\tyler\\desktop\\new folder\\the witcher\\system\\witcher.exe"= UDP:c:\users\tyler\desktop\new folder\the witcher\system\witcher.exe:witcher.exe
"UDP Query User{25631C7D-95E4-47D9-A6CD-EDB718886523}c:\\users\\tyler\\desktop\\new folder\\the witcher\\system\\witcher.exe"= TCP:c:\users\tyler\desktop\new folder\the witcher\system\witcher.exe:witcher.exe
"TCP Query User{A18E776E-B3DF-4E78-8345-6935A05FD18E}c:\\program files\\steam\\steamapps\\shamrior\\team fortress 2\\hl2.exe"= UDP:c:\program files\steam\steamapps\shamrior\team fortress 2\hl2.exe:hl2
"UDP Query User{0E8F7505-A117-4B8C-8B5C-BBA46589C4B0}c:\\program files\\steam\\steamapps\\shamrior\\team fortress 2\\hl2.exe"= TCP:c:\program files\steam\steamapps\shamrior\team fortress 2\hl2.exe:hl2
"TCP Query User{5280D51B-9426-469C-9F91-36E819BD1F70}c:\\program files\\steam\\steamapps\\shamrior\\half-life 2 deathmatch\\hl2.exe"= UDP:c:\program files\steam\steamapps\shamrior\half-life 2 deathmatch\hl2.exe:hl2
"UDP Query User{C2CD351F-08C9-4B51-B71D-2EBF76F03DAE}c:\\program files\\steam\\steamapps\\shamrior\\half-life 2 deathmatch\\hl2.exe"= TCP:c:\program files\steam\steamapps\shamrior\half-life 2 deathmatch\hl2.exe:hl2
"{2E9549D1-9953-4C03-9058-550118DCC311}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main
"{7D9AB1B8-DAF1-4D06-B62F-AFEBC53B3FC3}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main
"{EF0F77D1-126E-4002-9533-46BE0A40BD71}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD
"{9A0AC75D-FB8C-454A-B0F3-2E51D554EC02}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD
"{59702E93-032C-418A-ADD3-F12C5F198CF7}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{092DB82A-A684-44CB-9A7C-49507DB37F73}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{9A884C7D-1577-4D72-8872-A4377C2F6A39}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"{D7066280-CBEA-43E1-85EE-994FAFE314BA}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"TCP Query User{9D5D3DF1-C8F1-4D2C-8C82-66F13454341D}c:\\program files\\steam\\steamapps\\shamrior\\day of defeat source\\hl2.exe"= UDP:c:\program files\steam\steamapps\shamrior\day of defeat source\hl2.exe:hl2
"UDP Query User{A80DA99A-5C99-4323-9A35-1CC2BB45C5D2}c:\\program files\\steam\\steamapps\\shamrior\\day of defeat source\\hl2.exe"= TCP:c:\program files\steam\steamapps\shamrior\day of defeat source\hl2.exe:hl2
"TCP Query User{242BB1A9-0997-44BD-A966-22D3D0D67AD4}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{F8B8C127-A130-4EBE-851E-2D8B7F4E369E}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{9D736FEE-F3A9-4B6B-8621-2F57392E926B}c:\\program files\\steam\\steamapps\\common\\left 4 dead demo\\left4dead.exe"= UDP:c:\program files\steam\steamapps\common\left 4 dead demo\left4dead.exe:left4dead
"UDP Query User{171C8EB7-5138-4283-BF29-7501AA189C05}c:\\program files\\steam\\steamapps\\common\\left 4 dead demo\\left4dead.exe"= TCP:c:\program files\steam\steamapps\common\left 4 dead demo\left4dead.exe:left4dead
"{7E9EA8CD-2F57-4D77-9688-F9CEA77130F9}"= TCP:67:DHCP Discovery Service
"{44558A1D-5F64-4018-AB1D-36F5C90AB3EF}"= TCP:67:DHCP Discovery Service
"TCP Query User{80AE99F0-FAF3-40C8-9B18-9A699F2A4DF9}c:\\program files\\savage 2 - a tortured soul\\savage2.exe"= UDP:c:\program files\savage 2 - a tortured soul\savage2.exe:savage2
"UDP Query User{F34C5EBD-F1DA-4D70-8CAD-DB7F8F33A4F3}c:\\program files\\savage 2 - a tortured soul\\savage2.exe"= TCP:c:\program files\savage 2 - a tortured soul\savage2.exe:savage2
"TCP Query User{C0DC8E9D-DC3A-4DF2-895F-55761B34A2C7}c:\\program files\\age of empires 2 & the conquerors expansion - full game\\age2_x1.exe"= UDP:c:\program files\age of empires 2 & the conquerors expansion - full game\age2_x1.exe:Age of Empires II Expansion
"UDP Query User{D01C95FB-7542-4D12-8ABF-49AD4572A35A}c:\\program files\\age of empires 2 & the conquerors expansion - full game\\age2_x1.exe"= TCP:c:\program files\age of empires 2 & the conquerors expansion - full game\age2_x1.exe:Age of Empires II Expansion
"TCP Query User{42988BA5-A70D-401D-8A06-2A7017A930E1}c:\\program files\\age of empires 2 & the conquerors expansion - full game\\empires2.exe"= UDP:c:\program files\age of empires 2 & the conquerors expansion - full game\empires2.exe:Age of Empires II
"UDP Query User{293DD7A5-6CFE-4328-8249-C8A21775484E}c:\\program files\\age of empires 2 & the conquerors expansion - full game\\empires2.exe"= TCP:c:\program files\age of empires 2 & the conquerors expansion - full game\empires2.exe:Age of Empires II
"{83E271C2-5DFD-4EED-BBF1-3B3E5FFBF840}"= UDP:c:\program files\Steam\steamapps\common\left 4 dead demo\left4dead.exe:Left 4 Dead Demo
"{E5874E8A-EA43-4F31-82FE-8D51ABEBFDA6}"= TCP:c:\program files\Steam\steamapps\common\left 4 dead demo\left4dead.exe:Left 4 Dead Demo
"{946482E2-8B00-4E7B-B03F-29BA1FE034E5}"= UDP:c:\program files\Steam\steamapps\common\peggle extreme\PeggleExtreme.exe:Peggle Extreme
"{D068E7D3-1E8D-450D-8F18-571A7BF1C50D}"= TCP:c:\program files\Steam\steamapps\common\peggle extreme\PeggleExtreme.exe:Peggle Extreme
"TCP Query User{68483B13-E5A8-4D31-887E-2E257E76FAFB}c:\\users\\public\\games\\world of warcraft\\launcher.exe"= UDP:c:\users\public\games\world of warcraft\launcher.exe:Blizzard Launcher
"UDP Query User{5C8FC1A2-E99F-4B74-8C7E-E0ABA335E1D0}c:\\users\\public\\games\\world of warcraft\\launcher.exe"= TCP:c:\users\public\games\world of warcraft\launcher.exe:Blizzard Launcher
"{645C8D40-B064-4D4D-B373-3C4D5191FFBE}"= UDP:c:\users\Public\Games\World of Warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{0EB8FEA0-71CB-4C74-86BD-BC9D9CF2D405}"= TCP:c:\users\Public\Games\World of Warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{32F14AD2-4938-4D59-9DA2-213657AC11AB}"= UDP:3724:Blizzard Downloader: 3724
"{7CE6B212-E11A-451E-AC15-C8C46DC98A6D}"= UDP:c:\program files\Pure Networks\Network Magic\nmsrvc.exe:Pure Networks Network Magic Service
"{64BC9E3F-F35A-45F8-8AE3-8E4C50ADDDEE}"= TCP:c:\program files\Pure Networks\Network Magic\nmsrvc.exe:Pure Networks Network Magic Service
"TCP Query User{CA88B7B4-9BB0-4B71-830B-1B277E8DF8C6}c:\\world of warcraft\\launcher.exe"= UDP:c:\world of warcraft\launcher.exe:Blizzard Launcher
"UDP Query User{7633FBF6-68E0-4E5C-B301-AFD5C6713940}c:\\world of warcraft\\launcher.exe"= TCP:c:\world of warcraft\launcher.exe:Blizzard Launcher

R0 pavboot;pavboot;c:\windows\System32\drivers\pavboot.sys [2009-04-04 28544]
S2 RPCER;Remote Procedure Call (HNM);c:\program files\NetMeeting\comp.exe [2007-03-28 12798152]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder

2009-04-06 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxp://play.battlefield-heroes.com/static/updater/BFHUpdater_4.0.9.0.cab
FF - ProfilePath - c:\users\Tyler\AppData\Roaming\Mozilla\Firefox\Profiles\yyxwbuve.default\
FF - prefs.js: browser.startup.homepage - instapundit.com
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\users\Tyler\AppData\Roaming\Mozilla\Firefox\Profiles\yyxwbuve.default\extensions\{0C7E3F01-99E9-4095-9BDC-F84724960B57}\plugins\NPCpnMgr.dll
FF - plugin: c:\users\Tyler\AppData\Roaming\Mozilla\Firefox\Profiles\yyxwbuve.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-06 22:48:02
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-04-06 22:50:17
ComboFix-quarantined-files.txt 2009-04-07 02:50:14
ComboFix2.txt 2009-04-07 02:35:17

Pre-Run: 58,469,908,480 bytes free
Post-Run: 58,433,585,152 bytes free

257 --- E O F --- 2009-04-03 03:36:03
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Thu Apr 09, 2009 7:34 pm    Post subject:

Good job. Your log is clean.

To help prevent future spyware infections, read the Anti-Spyware Tutorial and use the tools provided.

Are there any problems now? If none, go to Start->Run, copy/paste in combofix /u and hit OK to remove it. You should be set to go.
Back to top
AIM Address Yahoo Messenger
elrechazao



Joined: Apr 04, 2009
Posts: 8



PostPosted: Thu Apr 09, 2009 10:24 pm    Post subject:

A thousand thanks to you sir.
Back to top
Display posts from previous:   
Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> HijackThis Logs All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum