PDA

View Full Version : NEW topic: Fraud.WindowsProtectionSuite, amongst others



allseeingeye
2011-01-09, 07:39
Hi.
Last week or so I got tricked into thinking I was updating Firefox and this "Windows Protection Suite" .exe started running, with no option to cancel the installation. Ever since, search engines like Yahoo and Google have been acting completely haywire, redirecting me to other sites.

I have followed the directions given to me int he FAQ thread, and post #2 in this thread contains the DDS log.

DDS (Ver_10-12-12.02) - NTFSx86
Run by Troy at 0:30:46.98 on Sun 01/09/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_23
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1245 [GMT -6:00]

AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Personal Internet Security 2011 *Enabled/Updated* {31144D42-F3E1-4D39-89F3-88F67CB62FA2}
FW: Personal Internet Security 2011 *Enabled*

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\SteelSeries\World of Warcraft Cataclysm MMO Gaming Mouse\WoWMHID2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
svchost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Documents and Settings\Troy\Local Settings\Apps\2.0\M6VKE4CO.QNE\4WOQEQ0E.VNE\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\CurseClient.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\SteelSeries\World of Warcraft Cataclysm MMO Gaming Mouse\WoWMTray2.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\Troy\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.facebook.com/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [RIMDeviceManager] "c:\program files\common files\research in motion\rimdevicemanager\RIMDeviceManager.exe" -RunServer
uRun: [LogitechSoftwareUpdate] "c:\program files\logitech\video\ManifestEngine.exe" boot
uRun: [Google Update] "c:\documents and settings\troy\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EPSON Stylus C120 Series] c:\windows\system32\spool\drivers\w32x86\3\e_faticca.exe /fu "c:\windows\temp\E_S197.tmp" /EF "HKCU"
uRun: [JP595IR86O] c:\docume~1\troy\locals~1\temp\Lpl.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SW20] c:\windows\system32\sw20.exe
mRun: [SW24] c:\windows\system32\sw24.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [vptray] c:\program files\navnt\vptray.exe
mRun: [WinSys2] c:\windows\system32\winsys2.exe
mRun: [<NO NAME>]
mRun: [Launch LGDCore] "c:\program files\logitech\g-series software\LGDCore.exe" /SHOWHIDE
mRun: [Launch LCDMon] "c:\program files\logitech\g-series software\LCDMon.exe"
mRun: [FixCamera] c:\windows\FixCamera.exe
mRun: [RivaTunerStartupDaemon] "c:\program files\rivatuner v2.24 msi master overclocking arena 2009 edition\RivaTuner.exe" /S
mRun: [LVCOMSX] c:\windows\system32\LVCOMSX.EXE
mRun: [LogitechVideoRepair] c:\program files\logitech\video\ISStart.exe
mRun: [LogitechVideoTray] c:\program files\logitech\video\LogiTray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SteelSeries World of Warcraft Cataclysm MMO Gaming Mouse] "c:\program files\steelseries\world of warcraft cataclysm mmo gaming mouse\WoWMHID2.exe"
StartupFolder: c:\documents and settings\troy\start menu\programs\startup\CurseClientStartup.ccip
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
IFEO: image file execution options - svchost.exe
IFEO: a.exe - svchost.exe
IFEO: aAvgApi.exe - svchost.exe
IFEO: AAWTray.exe - svchost.exe
IFEO: About.exe - svchost.exe

Note: multiple IFEO entries found. Please refer to Attach.txt
Hosts: 74.125.45.100 4-open-davinci.com
Hosts: 74.125.45.100 securitysoftwarepayments.com
Hosts: 74.125.45.100 privatesecuredpayments.com
Hosts: 74.125.45.100 secure.privatesecuredpayments.com
Hosts: 74.125.45.100 getantivirusplusnow.com

Note: multiple HOSTS entries found. Please refer to Attach.txt

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\troy\applic~1\mozilla\firefox\profiles\ah5v1emr.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2117678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.wowhead.com/
FF - plugin: c:\documents and settings\troy\application data\mozilla\firefox\profiles\ah5v1emr.default\extensions\{000f1ea4-5e08-4564-a29b-29076f63a37a}\plugins\npsoe.dll
FF - plugin: c:\documents and settings\troy\application data\mozilla\firefox\profiles\ah5v1emr.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\documents and settings\troy\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\troy\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\troy\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - Ext: Move Media Player: http://forums.spybot.info/misc.php?do=email_dev&email=bW92ZXBsYXllckBtb3ZlbmV0d29ya3MuY29t - %profile%\extensions\moveplayer@movenetworks.com
FF - Ext: AIM Toolbar: {c2f863cd-0429-48c7-bb54-db756a951760} - %profile%\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
FF - Ext: SOE Web Installer: {000F1EA4-5E08-4564-A29B-29076F63A37A} - %profile%\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: http://forums.spybot.info/misc.php?do=email_dev&email=anFzQHN1bi5jb20= - c:\program files\java\jre6\lib\deploy\jqs\ff

---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-1-2 64288]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-12-3 1389400]
R2 NAVAPEL;NAVAPEL;c:\program files\navnt\Navapel.sys [2001-10-29 9296]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-12-3 15264]
R3 SSMO3v2Filter;MMO3v2 Mouse;c:\windows\system32\drivers\MO3v2Driver.sys [2011-1-1 17408]
S2 Norton AntiVirus Server;Norton AntiVirus Client;c:\program files\navnt\rtvscan.exe [2001-10-29 466944]
S3 danewFltr;NewDeathAdder Mouse;c:\windows\system32\drivers\danew.sys [2010-12-30 11136]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2009-11-30 36608]
S3 NAVAP;NAVAP;c:\program files\navnt\navap.sys [2001-10-29 178304]
S3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20101013.002\NAVENG.sys [2010-10-15 86064]
S3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20101013.002\NAVEX15.sys [2010-10-15 1371184]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
S3 SNP325;USB PC Camera (SNPSTD325);c:\windows\system32\drivers\snp325.sys --> c:\windows\system32\drivers\snp325.sys [?]
S3 vHidDev;Razer Gaming Device;c:\windows\system32\drivers\vHidDev.sys [2010-12-30 5760]

=============== Created Last 30 ================

2011-01-09 01:55:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-01-09 01:55:25 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2011-01-03 00:46:33 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-01-03 00:46:30 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-01-03 00:37:41 -------- d-----w- c:\docume~1\troy\locals~1\applic~1\Sunbelt Software
2011-01-03 00:36:41 -------- dc-h--w- c:\docume~1\alluse~1\applic~1\{2162CCC0-3A5F-4887-B51F-CE5F195B3620}
2011-01-02 20:38:03 223232 ----a-w- c:\windows\Lremob.exe
2011-01-02 20:33:20 -------- d-sh--w- c:\docume~1\alluse~1\applic~1\PICCS
2011-01-02 20:31:21 -------- d-sh--w- c:\docume~1\alluse~1\applic~1\ad514e
2011-01-02 20:23:07 76800 --sha-r- c:\windows\system32\catsrvr.dll
2011-01-02 20:18:51 223232 ----a-w- c:\windows\Lremoa.exe
2011-01-01 17:30:58 17408 ----a-w- c:\windows\system32\drivers\MO3v2Driver.sys
2011-01-01 17:30:58 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2011-01-01 17:30:38 -------- d-----w- c:\program files\SteelSeries
2010-12-30 20:11:05 -------- d-----w- c:\docume~1\troy\locals~1\applic~1\NCH
2010-12-30 20:05:19 -------- d-----w- c:\docume~1\troy\applic~1\Razer
2010-12-30 20:03:32 11136 ----a-w- c:\windows\system32\drivers\danew.sys
2010-12-30 20:03:19 5760 ----a-w- c:\windows\system32\drivers\vHidDev.sys
2010-12-30 02:15:39 -------- d-----w- c:\docume~1\troy\applic~1\SteelSeries
2010-12-30 02:15:14 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2010-12-23 23:42:41 -------- d-----w- c:\program files\Ventrilo
2010-12-23 23:42:08 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2010-12-16 06:05:14 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2010-12-16 06:04:09 45568 -c----w- c:\windows\system32\dllcache\wab.exe

==================== Find3M ====================

2011-01-03 22:32:38 60416 -c--a-w- c:\windows\ALCFDRTM.VER
2010-12-28 13:46:33 53 -c--a-w- c:\windows\sfshell.tmp
2010-11-18 18:12:44 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-13 00:53:06 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-12 22:34:10 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-11-06 00:26:58 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26:58 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26:58 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25:54 385024 ----a-w- c:\windows\system32\html.iec
2010-10-28 13:13:22 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25:00 1853312 ----a-w- c:\windows\system32\win32k.sys

============= FINISH: 0:31:56.34 ===============

Forgot to attach the attach.txt file. Here it is.

Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
4-open-davinci.com=74.125.45.100

Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
securitysoftwarepayments.com=74.125.45.100

Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
privatesecuredpayments.com=74.125.45.100

Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
secure.privatesecuredpayments.com=74.125.45.100

Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
getantivirusplusnow.com=74.125.45.100

Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
secure-plus-payments.com=74.125.45.100

Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
www.getantivirusplusnow.com=74.125.45.100 (http://www.getantivirusplusnow.com=74.125.45.100)

Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
www.secure-plus-payments.com=74.125.45.100 (http://www.secure-plus-payments.com=74.125.45.100)

Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
www.getavplusnow.com=74.125.45.100 (http://www.getavplusnow.com=74.125.45.100)

Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
safebrowsing-cache.google.com=74.125.45.100

Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
www.securesoftwarebill.com=74.125.45.100 (http://www.securesoftwarebill.com=74.125.45.100)

Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
secure.paysecuresystem.com=74.125.45.100

Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
paysoftbillsolution.com=74.125.45.100

Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
protected.maxisoftwaremart.com=74.125.45.100

Microsoft.WindowsSecurityCenter_disabled: [SBI $2E20C9A9] Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Start

Microsoft.Windows.RedirectedHosts: [SBI $B89FBA81] Redirected host (Redirected host, nothing done)
www.securesoftwarebill.com=74.125.45.100 (http://www.securesoftwarebill.com=74.125.45.100)

Microsoft.Windows.RedirectedHosts: [SBI $19781685] Redirected host (Redirected host, nothing done)
secure.paysecuresystem.com=74.125.45.100

Microsoft.Windows.RedirectedHosts: [SBI $CEFF52BA] Redirected host (Redirected host, nothing done)
paysoftbillsolution.com=74.125.45.100

DoubleClick: Tracking cookie (Internet Explorer: Troy) (Cookie, nothing done)


FastClick: Tracking cookie (Internet Explorer: Troy) (Cookie, nothing done)



--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2011-01-08 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2010-10-05 Includes\Adware.sbi (*)
2010-11-30 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2010-12-14 Includes\DialerC.sbi (*)
2010-01-25 Includes\HeavyDuty.sbi (*)
2010-11-30 Includes\Hijackers.sbi (*)
2010-11-30 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2010-12-14 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2010-12-14 Includes\Malware.sbi (*)
2011-01-04 Includes\MalwareC.sbi (*)
2010-05-18 Includes\PUPS.sbi (*)
2010-12-14 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2010-12-14 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2010-12-28 Includes\Spyware.sbi (*)
2010-12-28 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-12-28 Includes\Trojans.sbi (*)
2010-12-17 Includes\TrojansC-02.sbi (*)
2010-12-16 Includes\TrojansC-03.sbi (*)
2010-12-16 Includes\TrojansC-04.sbi (*)
2011-01-04 Includes\TrojansC-05.sbi (*)
2010-12-28 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

ken545
2011-01-12, 00:42
:snwelcome:


Please read Before You Post (http://forums.spybot.info/showthread.php?t=288)
While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.

Until we deem your system clean I am going to ask you not to install or uninstall any software or hardware except for the programs we may run.



Please stay with this topic and do not start any new ones, I will be notified by email when you reply.


You have a bit of mess going on, lets do this.


Please download Malwarebytes from Here (http://www.malwarebytes.org/mbam-download.php) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)


Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
http://i24.photobucket.com/albums/c30/ken545/MBAMCapture.jpg
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please




OTL by OldTimer

Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Check the boxes beside LOP Check and Purity Check.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

allseeingeye
2011-01-13, 01:26
I want to post the log, but vBulletin says it's too long. I will instead compress the file and attach it to this post.

It is prompting me to restart my computer and says that everything selected was removed successfully. I am rebooting as soon as I submit this post.

allseeingeye
2011-01-13, 01:48
OTL logfile created on: 1/12/2011 6:40:24 PM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\Troy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 26.12 Gb Free Space | 17.52% Space Free | Partition Type: NTFS
Drive E: | 111.78 Gb Total Space | 82.47 Gb Free Space | 73.78% Space Free | Partition Type: NTFS

Computer Name: FOR-THE-HORDE | User Name: Troy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Troy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SteelSeries\World of Warcraft Cataclysm MMO Gaming Mouse\WoWMTray2.exe (SteelSeries)
PRC - C:\Program Files\SteelSeries\World of Warcraft Cataclysm MMO Gaming Mouse\WoWMHID2.exe (SteelSeries)
PRC - C:\Documents and Settings\Troy\Local Settings\Apps\2.0\M6VKE4CO.QNE\4WOQEQ0E.VNE\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\CurseClient.exe (Curse)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\FixCamera.exe ()
PRC - C:\Program Files\Logitech\G-series Software\LGDCore.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\LCDMon.exe (Logitech Inc.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
PRC - C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\Video\FxSvr2.exe (Logitech Inc.)
PRC - C:\Program Files\NavNT\vptray.exe (Symantec Corporation)
PRC - C:\Program Files\NavNT\rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\NavNT\defwatch.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\MSGSYS.EXE (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Troy\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (Dot3svc) -- C:\WINDOWS\system32\dot3svc.dll ()
SRV - (Norton AntiVirus Server) -- C:\Program Files\NavNT\rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) -- C:\Program Files\NavNT\defwatch.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (ZSMC303) VIMICRO USB PC Camera (VC0303) -- C:\WINDOWS\System32\Drivers\usbVM303.sys File not found
DRV - (SNP325) USB PC Camera (SNPSTD325) -- C:\WINDOWS\System32\DRIVERS\snp325.sys File not found
DRV - (SetupNTGLM7X) -- D:\NTGLM7X.sys File not found
DRV - (RimUsb) -- C:\WINDOWS\System32\Drivers\RimUsb.sys File not found
DRV - (pccsmcfd) -- C:\WINDOWS\System32\DRIVERS\pccsmcfd.sys File not found
DRV - (NTACCESS) -- D:\NTACCESS.sys File not found
DRV - (MSICPL) -- D:\install4\MSICPL.sys File not found
DRV - (GMSIPCI) -- D:\INSTALL\GMSIPCI.SYS File not found
DRV - (ASInsHelp) -- C:\WINDOWS\System32\drivers\AsInsHelp32.sys File not found
DRV - (Lbd) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (SSMO3v2Filter) -- C:\WINDOWS\system32\drivers\MO3v2Driver.sys (Sagatek Co. Ltd.)
DRV - (NAVEX15) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20101013.002\navex15.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20101013.002\naveng.sys (Symantec Corporation)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (vHidDev) -- C:\WINDOWS\system32\drivers\vHidDev.sys (Windows (R) Win 7 DDK provider)
DRV - (RivaTuner32) -- C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner32.sys ()
DRV - (danewFltr) -- C:\WINDOWS\system32\drivers\danew.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (FsUsbExDisk) -- C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (nvata) -- C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvnetbus) -- C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) -- C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (LVUSBSta) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (yukonwxp) -- C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (AsIO) -- C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (CamDrL) Logitech QuickCam Pro 3000(CamDrl) -- C:\WINDOWS\system32\drivers\Camdrl.sys (Logitech Inc.)
DRV - (MTsensor) -- C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (SymEvent) -- C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVAPEL) -- C:\Program Files\NavNT\Navapel.sys ()
DRV - (NAVAP) -- C:\Program Files\NavNT\navap.sys ()
DRV - (ms_mpu401) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaultthis.engineName: "NCH Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2117678&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.wowhead.com/"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000006
FF - prefs.js..extensions.enabledItems: {c2f863cd-0429-48c7-bb54-db756a951760}:5.96.10.5331
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {000F1EA4-5E08-4564-A29B-29076F63A37A}:1.0.3.126
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/20 14:23:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/02 18:28:02 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/12/14 09:10:50 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2010/07/26 14:32:35 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Extensions
[2010/07/26 14:32:35 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/01/12 05:39:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\extensions
[2010/09/17 05:59:47 | 000,000,000 | ---D | M] () -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
[2010/05/03 07:04:52 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/23 23:03:49 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/05/03 07:04:52 | 000,000,000 | ---D | M] (NoScript) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/04/21 19:41:54 | 000,000,000 | ---D | M] (AIM Toolbar) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
[2009/03/30 20:16:24 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\extensions\moveplayer@movenetworks.com
[2010/04/21 19:45:55 | 000,002,267 | ---- | M] () -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\searchplugins\aim-search.xml
[2010/10/08 23:14:11 | 000,000,909 | ---- | M] () -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\searchplugins\conduit.xml
[2011/01/12 05:39:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/08/14 08:33:17 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/01/02 14:22:22 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2009/04/06 13:10:48 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/11/12 18:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2011/01/02 14:35:03 | 000,002,611 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 74.125.45.100 4-open-davinci.com
O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getavplusnow.com
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 93.174.89.10 www.google.com
O1 - Hosts: 93.174.89.10 google.com
O1 - Hosts: 93.174.89.10 google.com.au
O1 - Hosts: 93.174.89.10 www.google.com.au
O1 - Hosts: 93.174.89.10 google.be
O1 - Hosts: 93.174.89.10 www.google.be
O1 - Hosts: 93.174.89.10 google.com.br
O1 - Hosts: 93.174.89.10 www.google.com.br
O1 - Hosts: 93.174.89.10 google.ca
O1 - Hosts: 93.174.89.10 www.google.ca
O1 - Hosts: 37 more lines...
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll File not found
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe ()
O4 - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\G-series Software\LCDMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\G-series Software\LGDCore.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
O4 - HKLM..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [RivaTunerStartupDaemon] C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SteelSeries World of Warcraft Cataclysm MMO Gaming Mouse] C:\Program Files\SteelSeries\World of Warcraft Cataclysm MMO Gaming Mouse\WoWMHID2.exe (SteelSeries)
O4 - HKLM..\Run: [SW20] C:\WINDOWS\system32\sw20.exe ()
O4 - HKLM..\Run: [SW24] C:\WINDOWS\system32\sw24.exe ()
O4 - HKLM..\Run: [vptray] C:\Program Files\NavNT\vptray.exe (Symantec Corporation)
O4 - HKLM..\Run: [WinSys2] C:\WINDOWS\system32\WinSys2.exe ()
O4 - HKCU..\Run: [EPSON Stylus C120 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICCA.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [LogitechSoftwareUpdate] C:\Program Files\Logitech\Video\ManifestEngine.exe (Logitech Inc.)
O4 - HKCU..\Run: [MsnMsgr] C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe File not found
O4 - HKCU..\Run: [RIMDeviceManager] C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Troy\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 71.92.29.130 97.81.22.195 68.113.206.10
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL File not found
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - CLSID or File not found.
O24 - Desktop WallPaper: C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Desktop Background.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/11 11:22:47 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{5cf0a96c-c86b-11dc-a9dc-0018f3292f0d}\Shell - "" = AutoRun
O33 - MountPoints2\{5cf0a96c-c86b-11dc-a9dc-0018f3292f0d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5cf0a96c-c86b-11dc-a9dc-0018f3292f0d}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O33 - MountPoints2\{b7c945c7-e348-11dc-a9e5-0018f3292f0d}\Shell - "" = AutoRun
O33 - MountPoints2\{b7c945c7-e348-11dc-a9e5-0018f3292f0d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b7c945c7-e348-11dc-a9e5-0018f3292f0d}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/12 18:33:21 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Troy\Desktop\OTL.exe
[2011/01/12 18:11:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Troy\Application Data\Malwarebytes
[2011/01/12 18:11:40 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/01/12 18:11:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/01/12 18:11:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/01/12 18:11:37 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/01/12 18:11:36 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/01/12 18:09:32 | 007,734,240 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Troy\Desktop\mbam-setup.exe
[2011/01/11 11:19:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Troy\Desktop\New Folder
[2011/01/09 00:26:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/01/09 00:25:29 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2011/01/09 00:25:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2011/01/09 00:23:40 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Troy\Desktop\erunt-setup.exe
[2011/01/08 22:57:55 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Documents and Settings\Troy\Desktop\ATF-Cleaner.exe
[2011/01/08 19:55:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2011/01/08 19:55:25 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2011/01/08 19:55:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2011/01/02 18:46:33 | 000,064,288 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2011/01/02 18:46:30 | 000,098,392 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2011/01/02 18:37:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Troy\Local Settings\Application Data\Sunbelt Software
[2011/01/02 18:36:41 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{2162CCC0-3A5F-4887-B51F-CE5F195B3620}
[2011/01/02 18:36:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Lavasoft
[2011/01/02 17:54:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Google
[2011/01/02 14:33:20 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\PICCS
[2011/01/02 14:31:21 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\ad514e
[2011/01/02 14:22:21 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2011/01/02 14:22:21 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2011/01/02 14:22:21 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2011/01/01 11:31:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SteelSeries
[2011/01/01 11:30:58 | 001,112,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WdfCoInstaller01007.dll
[2011/01/01 11:30:58 | 000,017,408 | ---- | C] (Sagatek Co. Ltd.) -- C:\WINDOWS\System32\drivers\MO3v2Driver.sys
[2011/01/01 11:30:38 | 000,000,000 | ---D | C] -- C:\Program Files\SteelSeries
[2010/12/30 14:11:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Troy\Local Settings\Application Data\NCH
[2010/12/30 14:05:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Troy\Application Data\Razer
[2010/12/30 14:03:32 | 000,011,136 | ---- | C] (Razer (Asia-Pacific) Pte Ltd) -- C:\WINDOWS\System32\drivers\danew.sys
[2010/12/30 14:03:19 | 000,005,760 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\WINDOWS\System32\drivers\vHidDev.sys
[2010/12/29 20:15:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Troy\Application Data\SteelSeries
[2010/12/29 20:15:14 | 000,014,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsgXP_2k3.dll
[2010/12/23 17:42:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Ventrilo
[2010/12/23 17:42:41 | 000,000,000 | ---D | C] -- C:\Program Files\Ventrilo
[2010/12/23 17:42:08 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2010/12/20 20:02:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Troy\Start Menu\Programs\Curse
[2010/12/16 00:05:14 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndproxy.sys
[2010/12/16 00:04:09 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab.exe
[2010/12/15 10:37:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\World of Warcraft
[2009/02/08 01:59:23 | 000,057,344 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnp325.dll
[2009/02/08 01:59:23 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp325.dll
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[15 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/12 18:46:00 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/01/12 18:33:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Troy\Desktop\OTL.exe
[2011/01/12 18:29:07 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2011/01/12 18:28:51 | 000,000,053 | ---- | M] () -- C:\biosinfo
[2011/01/12 18:28:35 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2011/01/12 18:28:31 | 000,000,310 | -HS- | M] () -- C:\WINDOWS\tasks\Fpxbqzorrl.job
[2011/01/12 18:28:27 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/01/12 18:25:02 | 000,005,554 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\mbam-log-2011-01-12 (18-20-08).zip
[2011/01/12 18:11:41 | 000,000,793 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/12 18:10:24 | 007,734,240 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Troy\Desktop\mbam-setup.exe
[2011/01/12 17:52:00 | 000,000,974 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-1454471165-725345543-1003UA.job
[2011/01/12 16:12:24 | 000,000,628 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2011/01/12 04:52:00 | 000,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-1454471165-725345543-1003Core.job
[2011/01/11 12:14:54 | 000,884,068 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\Untitled-27 copy.jpg
[2011/01/11 12:14:20 | 000,233,984 | ---- | M] () -- C:\Documents and Settings\Troy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/11 09:02:42 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/01/09 01:09:32 | 000,173,080 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/09 00:42:59 | 000,007,525 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\Attach.zip
[2011/01/09 00:30:14 | 000,624,128 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\dds.scr
[2011/01/09 00:25:29 | 000,000,601 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\ERUNT.lnk
[2011/01/09 00:23:42 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Troy\Desktop\erunt-setup.exe
[2011/01/08 22:57:55 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Documents and Settings\Troy\Desktop\ATF-Cleaner.exe
[2011/01/08 20:37:09 | 000,000,095 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2011/01/08 19:55:30 | 000,000,942 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\Spybot - Search & Destroy.lnk
[2011/01/08 12:11:03 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/03 16:32:38 | 000,060,416 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\ALCFDRTM.VER
[2011/01/02 18:46:30 | 000,098,392 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2011/01/02 18:36:41 | 000,000,894 | ---- | M] () -- C:\Documents and Settings\Troy\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2011/01/02 18:36:41 | 000,000,876 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2011/01/02 18:27:00 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-225457.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-225456.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-225455.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-225454.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-225217.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-224319.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-224318.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-224317.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-224316.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-224315.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-224314.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-224057.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220908.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220907.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220906.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220905.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220904.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220903.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220857.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220734.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220733.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220732.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220728.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220725.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220722.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220720.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220719.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220717.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220711.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203706.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203705.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203704.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203703.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203702.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203701.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203700.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203659.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203658.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203657.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203653.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/12/29 20:15:31 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_MO3v2Driver_01007.Wdf
[2010/12/29 20:15:22 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/12/29 20:15:22 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/12/23 17:42:43 | 000,000,262 | ---- | M] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/12/23 17:42:42 | 000,000,639 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ventrilo.lnk
[2010/12/20 20:02:40 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Troy\Start Menu\Programs\Startup\CurseClientStartup.ccip
[2010/12/20 20:02:09 | 000,000,312 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\Curse Client.appref-ms
[2010/12/20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/19 08:56:30 | 000,103,208 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\boxerforums.org logo.jpg
[2010/12/19 08:55:44 | 000,000,636 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\Shortcut to i_view32.exe.lnk
[2010/12/19 08:47:33 | 000,194,274 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\1_BoxerForumsBannerPNG.png
[2010/12/19 07:34:27 | 000,370,559 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\WoWScrnShot_121910_072931.jpg
[2010/12/14 16:39:16 | 000,142,473 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo2copy.gif
[2010/12/14 16:39:02 | 001,732,549 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo1.psd
[2010/12/14 16:37:23 | 000,141,277 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo1_copy.gif
[2010/12/14 15:08:47 | 000,141,627 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo copy.gif
[2010/12/14 15:08:20 | 001,756,769 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo.psd
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[15 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/12 18:25:02 | 000,005,554 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\mbam-log-2011-01-12 (18-20-08).zip
[2011/01/12 18:11:41 | 000,000,793 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/11 12:14:49 | 000,884,068 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\Untitled-27 copy.jpg
[2011/01/09 00:42:59 | 000,007,525 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\Attach.zip
[2011/01/09 00:30:14 | 000,624,128 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\dds.scr
[2011/01/09 00:25:29 | 000,000,601 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\ERUNT.lnk
[2011/01/08 20:37:09 | 000,000,095 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2011/01/08 19:55:30 | 000,000,942 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\Spybot - Search & Destroy.lnk
[2011/01/02 18:36:41 | 000,000,894 | ---- | C] () -- C:\Documents and Settings\Troy\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2011/01/02 18:36:41 | 000,000,876 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2011/01/02 14:23:07 | 000,000,310 | -HS- | C] () -- C:\WINDOWS\tasks\Fpxbqzorrl.job
[2010/12/29 20:15:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_MO3v2Driver_01007.Wdf
[2010/12/29 20:15:22 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/12/29 18:56:30 | 000,210,968 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/12/23 17:42:42 | 000,000,639 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ventrilo.lnk
[2010/12/23 17:42:40 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/12/20 20:02:40 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Troy\Start Menu\Programs\Startup\CurseClientStartup.ccip
[2010/12/20 20:02:09 | 000,000,312 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\Curse Client.appref-ms
[2010/12/19 08:56:30 | 000,103,208 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\boxerforums.org logo.jpg
[2010/12/19 08:55:44 | 000,000,636 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\Shortcut to i_view32.exe.lnk
[2010/12/19 08:47:32 | 000,194,274 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\1_BoxerForumsBannerPNG.png
[2010/12/19 07:34:26 | 000,370,559 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\WoWScrnShot_121910_072931.jpg
[2010/12/15 10:37:11 | 000,000,628 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2010/12/14 16:39:13 | 000,142,473 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo2copy.gif
[2010/12/14 16:37:19 | 000,141,277 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo1_copy.gif
[2010/12/14 16:36:17 | 001,732,549 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo1.psd
[2010/12/14 15:08:46 | 000,141,627 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo copy.gif
[2010/12/14 12:46:20 | 001,756,769 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo.psd
[2010/04/20 08:43:46 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Troy\Local Settings\Application Data\fusioncache.dat
[2009/11/30 15:56:46 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2009/11/30 15:56:46 | 000,036,608 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2009/09/20 15:24:11 | 000,006,812 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/13 12:51:01 | 000,000,256 | ---- | C] () -- C:\WINDOWS\_delis32.ini
[2009/03/02 19:56:19 | 000,076,407 | ---- | C] () -- C:\Documents and Settings\Troy\Application Data\Smiley.ico
[2008/09/03 23:06:33 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\kbdpash.dll
[2008/09/03 23:06:33 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\kbdnepr.dll
[2008/09/03 23:06:16 | 000,132,096 | ---- | C] () -- C:\WINDOWS\System32\dot3svc.dll
[2008/05/02 21:46:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/03/18 15:50:27 | 000,002,508 | ---- | C] () -- C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2008/01/12 15:31:49 | 000,487,424 | ---- | C] () -- C:\WINDOWS\System32\msvcp70.dll
[2008/01/05 13:42:11 | 000,487,424 | ---- | C] () -- C:\WINDOWS\System32\DLLAV32.dll
[2008/01/05 13:41:01 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
[2008/01/05 13:40:47 | 000,005,937 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2008/01/02 18:07:22 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2007/12/14 15:22:27 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/10/25 17:26:10 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/09/01 09:29:02 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Troy\Application Data\$_hpcst$.hpc
[2007/08/17 07:38:43 | 245,526,269 | ---- | C] () -- C:\Program Files\Photoshop 7.zip
[2007/08/11 19:20:44 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2007/08/11 13:28:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
[2007/08/11 13:19:03 | 000,000,592 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/08/11 13:12:31 | 000,233,984 | ---- | C] () -- C:\Documents and Settings\Troy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/08/11 13:02:38 | 000,024,576 | R--- | C] () -- C:\WINDOWS\System32\AsIO.dll
[2007/08/11 13:02:38 | 000,004,962 | R--- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys
[2007/08/11 13:00:37 | 000,000,164 | R--- | C] () -- C:\WINDOWS\avrack.ini
[2007/08/11 13:00:31 | 000,156,672 | R--- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2007/08/11 12:56:51 | 000,000,266 | R--- | C] () -- C:\WINDOWS\System32\raidmgmt.ini
[2007/08/11 12:56:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\msicpl.ini
[2007/08/11 12:56:39 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2007/08/11 12:56:37 | 000,026,850 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2007/08/11 12:56:30 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/08/11 12:54:16 | 000,009,728 | ---- | C] () -- C:\WINDOWS\System32\sysinfoX64.sys
[2007/08/11 12:54:16 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\sysinfo.sys
[2007/07/25 15:55:24 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\HookMAp.dll
[2007/07/25 15:54:30 | 000,266,240 | ---- | C] () -- C:\WINDOWS\System32\HookShield.dll
[2006/10/18 20:47:22 | 001,574,912 | ---- | C] () -- C:\WINDOWS\System32\WMVENCOD.dll
[2006/08/14 10:31:06 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\Auxiliary.dll
[2006/07/13 04:00:04 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\smdll.dll
[2005/10/09 20:33:54 | 000,137,216 | ---- | C] () -- C:\WINDOWS\System32\secdel.dll
[2004/08/03 23:57:02 | 000,414,720 | ---- | C] () -- C:\WINDOWS\System32\msscp.dll
[2004/08/03 23:56:12 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\kbdsmsfi.dll
[2004/08/03 23:56:12 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\kbdmlt48.dll
[2004/08/03 23:56:12 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\kbdmlt47.dll
[2004/08/03 23:56:12 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\kbdmaori.dll
[2001/10/29 12:51:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll
[2000/11/22 00:59:12 | 000,002,550 | ---- | C] () -- C:\Program Files\SoundPad.txt
[2000/11/22 00:51:48 | 000,008,628 | -H-- | C] () -- C:\Program Files\SOUNDPAD.GID
[2000/09/18 16:12:40 | 000,023,040 | ---- | C] () -- C:\WINDOWS\System32\CSSMS_IN.DLL

========== LOP Check ==========

[2009/03/03 19:56:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\1A186
[2011/01/02 14:36:05 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\ad514e
[2010/08/31 14:59:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2008/01/05 13:43:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MAGIX
[2011/01/02 18:27:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/11/30 15:58:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2011/01/02 14:33:20 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\PICCS
[2008/08/05 08:55:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\scar5
[2007/08/15 21:50:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/15 18:30:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2011/01/02 18:57:01 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{2162CCC0-3A5F-4887-B51F-CE5F195B3620}
[2010/04/03 18:50:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/12 10:21:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/25 11:23:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/11/11 17:45:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\Acreon
[2008/10/08 19:46:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\Blackberry Desktop
[2011/01/02 18:27:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\NCH Swift Sound
[2009/04/02 17:58:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\OpenOffice.org
[2009/10/19 20:23:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\Opera
[2009/11/30 15:58:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\PC Suite
[2010/12/30 14:05:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\Razer
[2008/01/12 18:53:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\Recordpad
[2008/10/08 17:45:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\Research In Motion
[2010/02/26 23:48:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\Samsung
[2008/08/05 08:55:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\scar5
[2011/01/01 11:31:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\SteelSeries
[2010/08/14 06:29:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\SystemRequirementsLab
[2010/07/26 14:32:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\Thunderbird
[2010/04/20 08:44:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\Turbine
[2009/09/14 15:15:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Troy\Application Data\W Photo Studio Viewer
[2011/01/12 18:46:00 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/01/12 18:28:31 | 000,000,310 | -HS- | M] () -- C:\WINDOWS\Tasks\Fpxbqzorrl.job
[2011/01/12 18:28:35 | 000,000,236 | ---- | M] () -- C:\WINDOWS\Tasks\OGALogon.job
[2011/01/12 18:29:07 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job

========== Purity Check ==========



< End of report >

allseeingeye
2011-01-13, 01:49
OTL Extras logfile created on: 1/12/2011 6:40:24 PM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\Troy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 26.12 Gb Free Space | 17.52% Space Free | Partition Type: NTFS
Drive E: | 111.78 Gb Total Space | 82.47 Gb Free Space | 73.78% Space Free | Partition Type: NTFS

Computer Name: FOR-THE-HORDE | User Name: Troy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- File not found
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Soulseek\slsk.exe" = C:\Program Files\Soulseek\slsk.exe:*:Enabled:SoulSeek -- ()
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- File not found
"E:\Program Files\World of Warcraft\BackgroundDownloader.exe" = E:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"E:\Program Files\SmartFTP Client 2.0\SmartFTP.exe" = E:\Program Files\SmartFTP Client 2.0\SmartFTP.exe:*:Enabled:SmartFTP Client 2.0 -- File not found
"C:\Program Files\SmartFTP Client 2.0\SmartFTP.exe" = C:\Program Files\SmartFTP Client 2.0\SmartFTP.exe:*:Enabled:SmartFTP Client 2.0 -- (SmartSoft Ltd.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server -- File not found
"C:\Program Files\BearShare Applications\BearShare\BearShare.exe" = C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare -- File not found
"C:\Program Files\Curse\CurseClient.exe" = C:\Program Files\Curse\CurseClient.exe:*:Enabled:Curse Client -- File not found
"C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- File not found
"C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- File not found
"C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- File not found
"C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- File not found
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe" = C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server -- File not found
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe" = C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server -- File not found
"C:\Program Files\World of Warcraft\WoW-3.2.2.10505-to-3.3.0.10958-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.2.10505-to-3.3.0.10958-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- File not found
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- File not found
"C:\World of Warcraft\WoW-3.2.0-enUS-downloader.exe" = C:\World of Warcraft\WoW-3.2.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\World of Warcraft\Launcher.exe" = C:\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher -- (Blizzard Entertainment)
"C:\Program Files\Turbine\The Lord of the Rings Online\lotroclient.exe" = C:\Program Files\Turbine\The Lord of the Rings Online\lotroclient.exe:*:Disabled:lotroclient -- File not found
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM -- File not found
"C:\Program Files\StarCraft II\StarCraft II.exe" = C:\Program Files\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher -- (Blizzard Entertainment)
"C:\Program Files\StarCraft II\Versions\Base15405\SC2.exe" = C:\Program Files\StarCraft II\Versions\Base15405\SC2.exe:*:Enabled:StarCraft II -- (Blizzard Entertainment, Inc.)
"C:\Program Files\StarCraft II\Versions\Base16605\SC2.exe" = C:\Program Files\StarCraft II\Versions\Base16605\SC2.exe:*:Enabled:StarCraft II -- (Blizzard Entertainment, Inc.)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\Program Files\StarCraft II\Versions\Base16755\SC2.exe" = C:\Program Files\StarCraft II\Versions\Base16755\SC2.exe:*:Enabled:StarCraft II -- (Blizzard Entertainment, Inc.)
"C:\World of Warcraft\Launcher.patch.exe" = C:\World of Warcraft\Launcher.patch.exe:*:Enabled:Blizzard Launcher -- File not found
"C:\Program Files\StarCraft II\Versions\Base16939\SC2.exe" = C:\Program Files\StarCraft II\Versions\Base16939\SC2.exe:*:Enabled:StarCraft II -- (Blizzard Entertainment, Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Program Files\StarCraft II\StarCraft II Public Test.exe" = C:\Program Files\StarCraft II\StarCraft II Public Test.exe:*:Enabled:Blizzard Launcher -- (Blizzard Entertainment)
"C:\Documents and Settings\Troy\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Troy\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin -- (Google)
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe -- (Flagship Industries, Inc.)
"C:\World of Warcraft\Blizzard Downloader.exe" = C:\World of Warcraft\Blizzard Downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Documents and Settings\Troy\Local Settings\Apps\2.0\M6VKE4CO.QNE\4WOQEQ0E.VNE\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\CurseClient.exe" = C:\Documents and Settings\Troy\Local Settings\Apps\2.0\M6VKE4CO.QNE\4WOQEQ0E.VNE\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\CurseClient.exe:*:Enabled:Curse Client 4.0 -- (Curse)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 23
"{2A8E4833-F483-4074-B4DB-F295F7901A8D}" = MobileMe Control Panel
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C79DC59-6099-323B-B27B-90B45542B270}" = Google Talk Plugin
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{5A080213-5AEC-4BF2-BB32-796EB0E421EC}" = Logitech G-series Keyboard Software
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8A809006-C25A-4A3A-9DAB-94659BCDB107}" = NVIDIA PhysX
"{911A0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Outlook 2002
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B832F6BF-B53E-4A51-BD95-A1D5D956207C}" = World of Warcraft Cataclysm MMO Gaming Mouse
"{BD12EB47-DBDF-11D3-BEEA-00A0CC272509}" = Norton AntiVirus Corporate Edition
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C43048A9-742C-4DAD-90D2-E3B53C9DB825}" = Logitech QuickCam Software
"{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FAE36873-1941-4076-A9A5-48812B5EA0B7}" = iTunes
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"227FF546E51B37EE801113B9EC6D88E5A5E892A5" = Windows Driver Package - SteelSeries (HidUsb) HIDClass (11/19/2010 1.2.4.0)
"6194C28A8F62DD817EA1B918E6E46E806A21B452" = Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)
"65B6FE5418CE28F4D72543FB2D964C3CEC83F161" = Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)
"85C2153E6B3ED760F8F06C23A83E8CC3C4680D6C" = Windows Driver Package - Cypress (CYUSB) USB (06/05/2009 3.4.1.20)
"Ad-Aware" = Ad-Aware
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0.1
"EPSON Printer and Utilities" = EPSON Printer Software
"ERUNT_is1" = ERUNT 1.1j
"ie8" = Windows Internet Explorer 8
"LiveUpdate1.6" = LiveUpdate 1.6 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"Mozilla Thunderbird (3.1.7)" = Mozilla Thunderbird (3.1.7)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"QcDrv" = Logitech® Camera Driver
"RivaTuner" = RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
"Simple File Shredder" = Simple File Shredder 3.2
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Soulseek" = SoulSeek Client 156c
"StarCraft II" = StarCraft II
"SystemRequirementsLab" = System Requirements Lab
"ViewpointMediaPlayer" = Viewpoint Media Player
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"World of Warcraft" = World of Warcraft
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/11/2011 1:26:23 PM | Computer Name = FOR-THE-HORDE | Source = Bonjour Service | ID = 100
Description = 476: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 1/11/2011 2:40:47 PM | Computer Name = FOR-THE-HORDE | Source = Bonjour Service | ID = 100
Description = 244: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 1/11/2011 2:40:47 PM | Computer Name = FOR-THE-HORDE | Source = Bonjour Service | ID = 100
Description = 232: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 1/11/2011 2:40:47 PM | Computer Name = FOR-THE-HORDE | Source = Bonjour Service | ID = 100
Description = 476: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 1/12/2011 2:18:46 PM | Computer Name = FOR-THE-HORDE | Source = Bonjour Service | ID = 100
Description = 248: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 1/12/2011 2:18:46 PM | Computer Name = FOR-THE-HORDE | Source = Bonjour Service | ID = 100
Description = 228: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 1/12/2011 2:18:46 PM | Computer Name = FOR-THE-HORDE | Source = Bonjour Service | ID = 100
Description = 472: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 1/12/2011 6:12:41 PM | Computer Name = FOR-THE-HORDE | Source = Bonjour Service | ID = 100
Description = 472: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 1/12/2011 6:12:41 PM | Computer Name = FOR-THE-HORDE | Source = Bonjour Service | ID = 100
Description = 228: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 1/12/2011 6:12:41 PM | Computer Name = FOR-THE-HORDE | Source = Bonjour Service | ID = 100
Description = 248: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

[ System Events ]
Error - 1/11/2011 2:36:01 PM | Computer Name = FOR-THE-HORDE | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Display Driver Service service failed to start due to the
following error: %%1053

Error - 1/11/2011 2:36:01 PM | Computer Name = FOR-THE-HORDE | Source = Service Control Manager | ID = 7000
Description = The ASInsHelp service failed to start due to the following error:
%%2

Error - 1/11/2011 2:36:01 PM | Computer Name = FOR-THE-HORDE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the DefWatch service to connect.

Error - 1/11/2011 2:36:01 PM | Computer Name = FOR-THE-HORDE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Norton AntiVirus Client
service to connect.

Error - 1/12/2011 7:27:43 AM | Computer Name = FOR-THE-HORDE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the NVIDIA Display Driver
Service service to connect.

Error - 1/12/2011 7:27:43 AM | Computer Name = FOR-THE-HORDE | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Display Driver Service service failed to start due to the
following error: %%1053

Error - 1/12/2011 7:27:43 AM | Computer Name = FOR-THE-HORDE | Source = Service Control Manager | ID = 7000
Description = The ASInsHelp service failed to start due to the following error:
%%2

Error - 1/12/2011 7:27:43 AM | Computer Name = FOR-THE-HORDE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the DefWatch service to connect.

Error - 1/12/2011 7:27:43 AM | Computer Name = FOR-THE-HORDE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Norton AntiVirus Client
service to connect.

Error - 1/12/2011 8:28:51 PM | Computer Name = FOR-THE-HORDE | Source = Service Control Manager | ID = 7000
Description = The ASInsHelp service failed to start due to the following error:
%%2


< End of report >

ken545
2011-01-13, 02:32
Hi,


Open OTL.exe

Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL



:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-225457.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-225456.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-225455.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-225454.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-225217.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-224319.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-224318.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-224317.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-224316.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-224315.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-224314.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-224057.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220908.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220907.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220906.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220905.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220904.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220903.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220857.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220734.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220733.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220732.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220728.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220725.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220722.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220720.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220719.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220717.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-220711.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203706.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203705.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203704.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203703.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203702.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203701.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203700.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203659.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203658.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203657.backup
[2011/01/02 14:35:03 | 000,002,611 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110108-203653.backup


:Services

:Reg

:Files


:Commands
[purity]
[emptytemp]
[RESETHOSTS]
[start explorer]
[Reboot]

Then click the Run Fix button at the top. <--Not run Scan
Let the program run unhindered, reboot when it is done
Then post the results of the log it produces.
Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

allseeingeye
2011-01-13, 14:23
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
C:\WINDOWS\system32\drivers\etc\hosts.20110108-225457.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-225456.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-225455.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-225454.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-225217.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-224319.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-224318.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-224317.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-224316.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-224315.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-224314.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-224057.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220908.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220907.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220906.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220905.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220904.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220903.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220857.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220734.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220733.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220732.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220728.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220725.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220722.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220720.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220719.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220717.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-220711.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-203706.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-203705.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-203704.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-203703.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-203702.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-203701.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-203700.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-203659.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-203658.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-203657.backup moved successfully.
C:\WINDOWS\system32\drivers\etc\hosts.20110108-203653.backup moved successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 292591148 bytes

User: Troy
->Temp folder emptied: 329587 bytes
->Temporary Internet Files folder emptied: 6568542 bytes
->Java cache emptied: 74403209 bytes
->FireFox cache emptied: 63995402 bytes
->Google Chrome cache emptied: 359625168 bytes
->Apple Safari cache emptied: 50975744 bytes
->Opera cache emptied: 15440426 bytes
->Flash cache emptied: 211236 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 16930448 bytes
%systemroot%\System32 .tmp files removed: 5669393 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 43030614 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 91126230 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 2387 bytes

Total Files Cleaned = 974.00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.20.1 log created on 01122011_224444

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

allseeingeye
2011-01-13, 14:31
OTL logfile created on: 1/13/2011 7:24:18 AM - Run 2
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\Troy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 61.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 26.87 Gb Free Space | 18.03% Space Free | Partition Type: NTFS
Drive E: | 111.78 Gb Total Space | 82.47 Gb Free Space | 73.78% Space Free | Partition Type: NTFS

Computer Name: FOR-THE-HORDE | User Name: Troy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Troy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SteelSeries\World of Warcraft Cataclysm MMO Gaming Mouse\WoWMTray2.exe (SteelSeries)
PRC - C:\Program Files\SteelSeries\World of Warcraft Cataclysm MMO Gaming Mouse\WoWMHID2.exe (SteelSeries)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Documents and Settings\Troy\Local Settings\Apps\2.0\M6VKE4CO.QNE\4WOQEQ0E.VNE\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\CurseClient.exe (Curse)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\FixCamera.exe ()
PRC - C:\Program Files\Logitech\G-series Software\LGDCore.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\LCDMon.exe (Logitech Inc.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
PRC - C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\Video\FxSvr2.exe (Logitech Inc.)
PRC - C:\Program Files\NavNT\vptray.exe (Symantec Corporation)
PRC - C:\Program Files\NavNT\rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\NavNT\defwatch.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\MSGSYS.EXE (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Troy\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (Dot3svc) -- C:\WINDOWS\system32\dot3svc.dll ()
SRV - (Norton AntiVirus Server) -- C:\Program Files\NavNT\rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) -- C:\Program Files\NavNT\defwatch.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (ZSMC303) VIMICRO USB PC Camera (VC0303) -- C:\WINDOWS\System32\Drivers\usbVM303.sys File not found
DRV - (SNP325) USB PC Camera (SNPSTD325) -- C:\WINDOWS\System32\DRIVERS\snp325.sys File not found
DRV - (SetupNTGLM7X) -- D:\NTGLM7X.sys File not found
DRV - (RimUsb) -- C:\WINDOWS\System32\Drivers\RimUsb.sys File not found
DRV - (pccsmcfd) -- C:\WINDOWS\System32\DRIVERS\pccsmcfd.sys File not found
DRV - (NTACCESS) -- D:\NTACCESS.sys File not found
DRV - (MSICPL) -- D:\install4\MSICPL.sys File not found
DRV - (GMSIPCI) -- D:\INSTALL\GMSIPCI.SYS File not found
DRV - (ASInsHelp) -- C:\WINDOWS\System32\drivers\AsInsHelp32.sys File not found
DRV - (Lbd) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (SSMO3v2Filter) -- C:\WINDOWS\system32\drivers\MO3v2Driver.sys (Sagatek Co. Ltd.)
DRV - (NAVEX15) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20101013.002\navex15.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20101013.002\naveng.sys (Symantec Corporation)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (vHidDev) -- C:\WINDOWS\system32\drivers\vHidDev.sys (Windows (R) Win 7 DDK provider)
DRV - (RivaTuner32) -- C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner32.sys ()
DRV - (danewFltr) -- C:\WINDOWS\system32\drivers\danew.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (FsUsbExDisk) -- C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (nvata) -- C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvnetbus) -- C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) -- C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (LVUSBSta) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (yukonwxp) -- C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (AsIO) -- C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (CamDrL) Logitech QuickCam Pro 3000(CamDrl) -- C:\WINDOWS\system32\drivers\Camdrl.sys (Logitech Inc.)
DRV - (MTsensor) -- C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (SymEvent) -- C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVAPEL) -- C:\Program Files\NavNT\Navapel.sys ()
DRV - (NAVAP) -- C:\Program Files\NavNT\navap.sys ()
DRV - (ms_mpu401) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaultthis.engineName: "NCH Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2117678&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.wowhead.com/"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000006
FF - prefs.js..extensions.enabledItems: {c2f863cd-0429-48c7-bb54-db756a951760}:5.96.10.5331
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {000F1EA4-5E08-4564-A29B-29076F63A37A}:1.0.3.126
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/20 14:23:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/02 18:28:02 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/12/14 09:10:50 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2010/07/26 14:32:35 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Extensions
[2010/07/26 14:32:35 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/01/12 05:39:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\extensions
[2010/09/17 05:59:47 | 000,000,000 | ---D | M] () -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
[2010/05/03 07:04:52 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/23 23:03:49 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/05/03 07:04:52 | 000,000,000 | ---D | M] (NoScript) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/04/21 19:41:54 | 000,000,000 | ---D | M] (AIM Toolbar) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
[2009/03/30 20:16:24 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\extensions\moveplayer@movenetworks.com
[2010/04/21 19:45:55 | 000,002,267 | ---- | M] () -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\searchplugins\aim-search.xml
[2010/10/08 23:14:11 | 000,000,909 | ---- | M] () -- C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\searchplugins\conduit.xml
[2011/01/12 05:39:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/08/14 08:33:17 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/01/02 14:22:22 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2009/04/06 13:10:48 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/11/12 18:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2011/01/12 22:47:08 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll File not found
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe ()
O4 - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\G-series Software\LCDMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\G-series Software\LGDCore.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
O4 - HKLM..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [RivaTunerStartupDaemon] C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SteelSeries World of Warcraft Cataclysm MMO Gaming Mouse] C:\Program Files\SteelSeries\World of Warcraft Cataclysm MMO Gaming Mouse\WoWMHID2.exe (SteelSeries)
O4 - HKLM..\Run: [SW20] C:\WINDOWS\system32\sw20.exe ()
O4 - HKLM..\Run: [SW24] C:\WINDOWS\system32\sw24.exe ()
O4 - HKLM..\Run: [vptray] C:\Program Files\NavNT\vptray.exe (Symantec Corporation)
O4 - HKLM..\Run: [WinSys2] C:\WINDOWS\system32\WinSys2.exe ()
O4 - HKCU..\Run: [EPSON Stylus C120 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICCA.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [LogitechSoftwareUpdate] C:\Program Files\Logitech\Video\ManifestEngine.exe (Logitech Inc.)
O4 - HKCU..\Run: [MsnMsgr] C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe File not found
O4 - HKCU..\Run: [RIMDeviceManager] C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Troy\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 71.92.29.130 97.81.22.195 68.113.206.10
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL File not found
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - CLSID or File not found.
O24 - Desktop WallPaper: C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Troy\Application Data\Mozilla\Firefox\Desktop Background.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/11 11:22:47 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{5cf0a96c-c86b-11dc-a9dc-0018f3292f0d}\Shell - "" = AutoRun
O33 - MountPoints2\{5cf0a96c-c86b-11dc-a9dc-0018f3292f0d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5cf0a96c-c86b-11dc-a9dc-0018f3292f0d}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O33 - MountPoints2\{b7c945c7-e348-11dc-a9e5-0018f3292f0d}\Shell - "" = AutoRun
O33 - MountPoints2\{b7c945c7-e348-11dc-a9e5-0018f3292f0d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b7c945c7-e348-11dc-a9e5-0018f3292f0d}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/12 22:44:44 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/01/12 18:33:21 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Troy\Desktop\OTL.exe
[2011/01/12 18:11:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Troy\Application Data\Malwarebytes
[2011/01/12 18:11:40 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/01/12 18:11:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/01/12 18:11:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/01/12 18:11:37 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/01/12 18:11:36 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/01/12 18:09:32 | 007,734,240 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Troy\Desktop\mbam-setup.exe
[2011/01/11 11:19:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Troy\Desktop\New Folder
[2011/01/09 00:26:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/01/09 00:25:29 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2011/01/09 00:25:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2011/01/09 00:23:40 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Troy\Desktop\erunt-setup.exe
[2011/01/08 22:57:55 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Documents and Settings\Troy\Desktop\ATF-Cleaner.exe
[2011/01/08 19:55:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2011/01/08 19:55:25 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2011/01/08 19:55:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2011/01/02 18:46:33 | 000,064,288 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2011/01/02 18:46:30 | 000,098,392 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2011/01/02 18:37:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Troy\Local Settings\Application Data\Sunbelt Software
[2011/01/02 18:36:41 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{2162CCC0-3A5F-4887-B51F-CE5F195B3620}
[2011/01/02 18:36:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Lavasoft
[2011/01/02 17:54:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Google
[2011/01/02 14:33:20 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\PICCS
[2011/01/02 14:31:21 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\ad514e
[2011/01/02 14:22:21 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2011/01/02 14:22:21 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2011/01/02 14:22:21 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2011/01/01 11:31:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SteelSeries
[2011/01/01 11:30:58 | 001,112,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WdfCoInstaller01007.dll
[2011/01/01 11:30:58 | 000,017,408 | ---- | C] (Sagatek Co. Ltd.) -- C:\WINDOWS\System32\drivers\MO3v2Driver.sys
[2011/01/01 11:30:38 | 000,000,000 | ---D | C] -- C:\Program Files\SteelSeries
[2010/12/30 14:11:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Troy\Local Settings\Application Data\NCH
[2010/12/30 14:05:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Troy\Application Data\Razer
[2010/12/30 14:03:32 | 000,011,136 | ---- | C] (Razer (Asia-Pacific) Pte Ltd) -- C:\WINDOWS\System32\drivers\danew.sys
[2010/12/30 14:03:19 | 000,005,760 | ---- | C] (Windows (R) Win 7 DDK provider) -- C:\WINDOWS\System32\drivers\vHidDev.sys
[2010/12/29 20:15:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Troy\Application Data\SteelSeries
[2010/12/29 20:15:14 | 000,014,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsgXP_2k3.dll
[2010/12/23 17:42:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Ventrilo
[2010/12/23 17:42:41 | 000,000,000 | ---D | C] -- C:\Program Files\Ventrilo
[2010/12/23 17:42:08 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2010/12/20 20:02:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Troy\Start Menu\Programs\Curse
[2010/12/16 00:05:14 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndproxy.sys
[2010/12/16 00:04:09 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab.exe
[2010/12/15 10:37:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\World of Warcraft
[2009/02/08 01:59:23 | 000,057,344 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnp325.dll
[2009/02/08 01:59:23 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp325.dll

========== Files - Modified Within 30 Days ==========

[2011/01/13 07:20:20 | 000,000,053 | ---- | M] () -- C:\biosinfo
[2011/01/13 07:20:11 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2011/01/13 07:05:20 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/01/13 07:02:25 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2011/01/13 07:02:21 | 000,000,310 | -HS- | M] () -- C:\WINDOWS\tasks\Fpxbqzorrl.job
[2011/01/13 07:02:17 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/01/13 06:52:00 | 000,000,974 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-1454471165-725345543-1003UA.job
[2011/01/13 04:52:00 | 000,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-1454471165-725345543-1003Core.job
[2011/01/12 22:47:08 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2011/01/12 18:50:29 | 000,000,628 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2011/01/12 18:33:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Troy\Desktop\OTL.exe
[2011/01/12 18:25:02 | 000,005,554 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\mbam-log-2011-01-12 (18-20-08).zip
[2011/01/12 18:11:41 | 000,000,793 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/12 18:10:24 | 007,734,240 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Troy\Desktop\mbam-setup.exe
[2011/01/11 12:14:54 | 000,884,068 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\Untitled-27 copy.jpg
[2011/01/11 12:14:20 | 000,233,984 | ---- | M] () -- C:\Documents and Settings\Troy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/11 09:02:42 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/01/09 01:09:32 | 000,173,080 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/09 00:42:59 | 000,007,525 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\Attach.zip
[2011/01/09 00:30:14 | 000,624,128 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\dds.scr
[2011/01/09 00:25:29 | 000,000,601 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\ERUNT.lnk
[2011/01/09 00:23:42 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Troy\Desktop\erunt-setup.exe
[2011/01/08 22:57:55 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Documents and Settings\Troy\Desktop\ATF-Cleaner.exe
[2011/01/08 20:37:09 | 000,000,095 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2011/01/08 19:55:30 | 000,000,942 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\Spybot - Search & Destroy.lnk
[2011/01/08 12:11:03 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/03 16:32:38 | 000,060,416 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\ALCFDRTM.VER
[2011/01/02 18:46:30 | 000,098,392 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2011/01/02 18:36:41 | 000,000,894 | ---- | M] () -- C:\Documents and Settings\Troy\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2011/01/02 18:36:41 | 000,000,876 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2011/01/02 18:27:00 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/12/29 20:15:31 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_MO3v2Driver_01007.Wdf
[2010/12/29 20:15:22 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/12/29 20:15:22 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/12/23 17:42:43 | 000,000,262 | ---- | M] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/12/23 17:42:42 | 000,000,639 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ventrilo.lnk
[2010/12/20 20:02:40 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Troy\Start Menu\Programs\Startup\CurseClientStartup.ccip
[2010/12/20 20:02:09 | 000,000,312 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\Curse Client.appref-ms
[2010/12/20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/19 08:56:30 | 000,103,208 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\boxerforums.org logo.jpg
[2010/12/19 08:55:44 | 000,000,636 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\Shortcut to i_view32.exe.lnk
[2010/12/19 08:47:33 | 000,194,274 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\1_BoxerForumsBannerPNG.png
[2010/12/19 07:34:27 | 000,370,559 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\WoWScrnShot_121910_072931.jpg
[2010/12/14 16:39:16 | 000,142,473 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo2copy.gif
[2010/12/14 16:39:02 | 001,732,549 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo1.psd
[2010/12/14 16:37:23 | 000,141,277 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo1_copy.gif
[2010/12/14 15:08:47 | 000,141,627 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo copy.gif
[2010/12/14 15:08:20 | 001,756,769 | ---- | M] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo.psd

========== Files Created - No Company Name ==========

[2011/01/12 18:25:02 | 000,005,554 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\mbam-log-2011-01-12 (18-20-08).zip
[2011/01/12 18:11:41 | 000,000,793 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/11 12:14:49 | 000,884,068 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\Untitled-27 copy.jpg
[2011/01/09 00:42:59 | 000,007,525 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\Attach.zip
[2011/01/09 00:30:14 | 000,624,128 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\dds.scr
[2011/01/09 00:25:29 | 000,000,601 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\ERUNT.lnk
[2011/01/08 20:37:09 | 000,000,095 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2011/01/08 19:55:30 | 000,000,942 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\Spybot - Search & Destroy.lnk
[2011/01/02 18:36:41 | 000,000,894 | ---- | C] () -- C:\Documents and Settings\Troy\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2011/01/02 18:36:41 | 000,000,876 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2011/01/02 14:23:07 | 000,000,310 | -HS- | C] () -- C:\WINDOWS\tasks\Fpxbqzorrl.job
[2010/12/29 20:15:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_MO3v2Driver_01007.Wdf
[2010/12/29 20:15:22 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/12/29 18:56:30 | 000,210,968 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/12/23 17:42:42 | 000,000,639 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ventrilo.lnk
[2010/12/23 17:42:40 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/12/20 20:02:40 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Troy\Start Menu\Programs\Startup\CurseClientStartup.ccip
[2010/12/20 20:02:09 | 000,000,312 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\Curse Client.appref-ms
[2010/12/19 08:56:30 | 000,103,208 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\boxerforums.org logo.jpg
[2010/12/19 08:55:44 | 000,000,636 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\Shortcut to i_view32.exe.lnk
[2010/12/19 08:47:32 | 000,194,274 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\1_BoxerForumsBannerPNG.png
[2010/12/19 07:34:26 | 000,370,559 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\WoWScrnShot_121910_072931.jpg
[2010/12/15 10:37:11 | 000,000,628 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2010/12/14 16:39:13 | 000,142,473 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo2copy.gif
[2010/12/14 16:37:19 | 000,141,277 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo1_copy.gif
[2010/12/14 16:36:17 | 001,732,549 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo1.psd
[2010/12/14 15:08:46 | 000,141,627 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo copy.gif
[2010/12/14 12:46:20 | 001,756,769 | ---- | C] () -- C:\Documents and Settings\Troy\Desktop\boxerforumslogo.psd
[2010/04/20 08:43:46 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Troy\Local Settings\Application Data\fusioncache.dat
[2009/11/30 15:56:46 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2009/11/30 15:56:46 | 000,036,608 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2009/09/20 15:24:11 | 000,006,812 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/13 12:51:01 | 000,000,256 | ---- | C] () -- C:\WINDOWS\_delis32.ini
[2009/03/02 19:56:19 | 000,076,407 | ---- | C] () -- C:\Documents and Settings\Troy\Application Data\Smiley.ico
[2008/09/03 23:06:33 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\kbdpash.dll
[2008/09/03 23:06:33 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\kbdnepr.dll
[2008/09/03 23:06:16 | 000,132,096 | ---- | C] () -- C:\WINDOWS\System32\dot3svc.dll
[2008/05/02 21:46:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/03/18 15:50:27 | 000,002,508 | ---- | C] () -- C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2008/01/12 15:31:49 | 000,487,424 | ---- | C] () -- C:\WINDOWS\System32\msvcp70.dll
[2008/01/05 13:42:11 | 000,487,424 | ---- | C] () -- C:\WINDOWS\System32\DLLAV32.dll
[2008/01/05 13:41:01 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
[2008/01/05 13:40:47 | 000,005,937 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2008/01/02 18:07:22 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2007/12/14 15:22:27 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/10/25 17:26:10 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/09/01 09:29:02 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Troy\Application Data\$_hpcst$.hpc
[2007/08/17 07:38:43 | 245,526,269 | ---- | C] () -- C:\Program Files\Photoshop 7.zip
[2007/08/11 19:20:44 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2007/08/11 13:28:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
[2007/08/11 13:19:03 | 000,000,592 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/08/11 13:12:31 | 000,233,984 | ---- | C] () -- C:\Documents and Settings\Troy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/08/11 13:02:38 | 000,024,576 | R--- | C] () -- C:\WINDOWS\System32\AsIO.dll
[2007/08/11 13:02:38 | 000,004,962 | R--- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys
[2007/08/11 13:00:37 | 000,000,164 | R--- | C] () -- C:\WINDOWS\avrack.ini
[2007/08/11 13:00:31 | 000,156,672 | R--- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2007/08/11 12:56:51 | 000,000,266 | R--- | C] () -- C:\WINDOWS\System32\raidmgmt.ini
[2007/08/11 12:56:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\msicpl.ini
[2007/08/11 12:56:39 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2007/08/11 12:56:37 | 000,026,850 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2007/08/11 12:56:30 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/08/11 12:54:16 | 000,009,728 | ---- | C] () -- C:\WINDOWS\System32\sysinfoX64.sys
[2007/08/11 12:54:16 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\sysinfo.sys
[2007/07/25 15:55:24 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\HookMAp.dll
[2007/07/25 15:54:30 | 000,266,240 | ---- | C] () -- C:\WINDOWS\System32\HookShield.dll
[2006/10/18 20:47:22 | 001,574,912 | ---- | C] () -- C:\WINDOWS\System32\WMVENCOD.dll
[2006/08/14 10:31:06 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\Auxiliary.dll
[2006/07/13 04:00:04 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\smdll.dll
[2005/10/09 20:33:54 | 000,137,216 | ---- | C] () -- C:\WINDOWS\System32\secdel.dll
[2004/08/03 23:57:02 | 000,414,720 | ---- | C] () -- C:\WINDOWS\System32\msscp.dll
[2004/08/03 23:56:12 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\kbdsmsfi.dll
[2004/08/03 23:56:12 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\kbdmlt48.dll
[2004/08/03 23:56:12 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\kbdmlt47.dll
[2004/08/03 23:56:12 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\kbdmaori.dll
[2001/10/29 12:51:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll
[2000/11/22 00:59:12 | 000,002,550 | ---- | C] () -- C:\Program Files\SoundPad.txt
[2000/11/22 00:51:48 | 000,008,628 | -H-- | C] () -- C:\Program Files\SOUNDPAD.GID
[2000/09/18 16:12:40 | 000,023,040 | ---- | C] () -- C:\WINDOWS\System32\CSSMS_IN.DLL

< End of report >

ken545
2011-01-13, 18:17
Hi,

You have a few questionable files on your system, let do this.

The file may be missing so if you cant find it dont worry about it.

You need to enable windows to show all files and folders, instructions Here (http://www.bleepingcomputer.com/tutorials/tutorial62.html)

Go to VirusTotal (http://www.virustotal.com/) and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see. If the site says this file has been checked before, have them check it again


C:\WINDOWS\FixCamera.exe


If the site is busy you can try this one
http://virusscan.jotti.org/en






Download ComboFix from one of these locations:

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)


* IMPORTANT !!! Save ComboFix.exe to your Desktop


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
See this Link (http://www.bleepingcomputer.com/forums/topic114351.html) for programs that need to be disabled and instruction on how to disable them.
Remember to re-enable them when we're done.


Double click on ComboFix.exe & follow the prompts.


As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.


Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



http://img.photobucket.com/albums/v706/ried7/RC1.png


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

http://img.photobucket.com/albums/v706/ried7/RC2-1.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

allseeingeye
2011-01-13, 19:08
Scanned and rescanned C:\WINDOWS\FixCamera.exe in VirusTotal. I did not see any link to download the log, so I copied it form the browser window:

File name:
FixCamera.exe
Submission date:
2011-01-13 17:53:17 (UTC)
Current status:
queued (#8) queued (#8) analysing finished
Result:
1/ 43 (2.3%)

Antivirus Version Last Update Result
AhnLab-V3 2011.01.13.00 2011.01.12 -
AntiVir 7.11.1.122 2011.01.13 -
Antiy-AVL 2.0.3.7 2011.01.13 -
Avast 4.8.1351.0 2011.01.13 -
Avast5 5.0.677.0 2011.01.13 -
AVG 10.0.0.1190 2011.01.13 -
BitDefender 7.2 2011.01.13 -
CAT-QuickHeal 11.00 2011.01.13 -
ClamAV 0.96.4.0 2011.01.13 -
Command 5.2.11.5 2011.01.13 -
Comodo 7381 2011.01.13 -
DrWeb 5.0.2.03300 2011.01.13 -
Emsisoft 5.1.0.1 2011.01.13 -
eSafe 7.0.17.0 2011.01.13 -
eTrust-Vet 36.1.8097 2011.01.13 -
F-Prot 4.6.2.117 2011.01.13 -
F-Secure 9.0.16160.0 2011.01.13 -
Fortinet 4.2.254.0 2011.01.13 -
GData 21 2011.01.13 -
Ikarus T3.1.1.97.0 2011.01.13 -
Jiangmin 13.0.900 2011.01.13 -
K7AntiVirus 9.75.3535 2011.01.13 -
Kaspersky 7.0.0.125 2011.01.13 -
McAfee 5.400.0.1158 2011.01.13 -
McAfee-GW-Edition 2010.1C 2011.01.13 -
Microsoft 1.6402 2011.01.13 -
NOD32 5784 2011.01.13 a variant of Win32/KillProc.A
Norman 6.06.12 2011.01.13 -
nProtect 2011-01-13.01 2011.01.13 -
Panda 10.0.2.7 2011.01.12 -
PCTools 7.0.3.5 2011.01.13 -
Prevx 3.0 2011.01.13 -
Rising 22.82.03.04 2011.01.13 -
Sophos 4.61.0 2011.01.13 -
SUPERAntiSpyware 4.40.0.1006 2011.01.13 -
Symantec 20101.3.0.103 2011.01.13 -
TheHacker 6.7.0.1.114 2011.01.13 -
TrendMicro 9.120.0.1004 2011.01.13 -
TrendMicro-HouseCall 9.120.0.1004 2011.01.13 -
VBA32 3.12.14.2 2011.01.13 -
VIPRE 8061 2011.01.13 -
ViRobot 2011.1.13.4252 2011.01.13 -
VirusBuster 13.6.143.1 2011.01.13 -

MD5 : 10dd727e26acb6d0917609b55d2d625d
SHA1 : d03fb2f36539640c5c3c84686cbe465e6e466316
SHA256: 0026c6d69ca84bb7460eaa2213fbf93d9fe55571c4f1c1aa5a34facb9702bee3
ssdeep: 192:Qs+0gd7f0uT51oztaqsty1oyn51VRB6VLOtkufP+:BlgdDbTqn1315Uu
File size : 20480 bytes
First seen: 2007-06-13 19:22:51
Last seen : 2011-01-13 17:53:17
TrID:
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher....:
copyright....: Copyright (C) 2005
product......: CameraFixer Application
description..: CameraFixer MFC Application
original name: CameraFixer.EXE
internal name: CameraFixer
file version.: 1, 0, 0, 9
comments.....:
signers......: -
signing date.: -
verified.....: Unsigned
PEiD: Armadillo v1.71
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x1A2E
timedatestamp....: 0x45D00E3E (Mon Feb 12 06:50:38 2007)
machinetype......: 0x14c (I386)

[[ 4 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0xC82, 0x1000, 4.96, 0093f7ccd24c7523b80fd0d0ea201778
.rdata, 0x2000, 0xA6E, 0x1000, 3.75, b451a0ed544a00bc189addafd29b2e37
.data, 0x3000, 0x198, 0x1000, 0.32, 39d758ca67a8573bfe02ac025f227ce1
.rsrc, 0x4000, 0xA18, 0x1000, 2.34, 357ac8fde14b09ce5bab5c8af2e9b671

[[ 5 import(s) ]]
MFC42.DLL: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
MSVCRT.dll: _except_handler3, __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, _acmdln, _setmbcp, __CxxFrameHandler, _strupr, strstr, _controlfp, __dllonexit, _onexit, _exit, _XcptFilter, exit
KERNEL32.dll: GetModuleHandleA, GetCurrentProcessId, CreateToolhelp32Snapshot, Process32First, OpenProcess, TerminateProcess, CloseHandle, GetStartupInfoA, GetCurrentProcess, Process32Next
USER32.dll: EnableWindow, KillTimer, IsIconic, GetSystemMetrics, DrawIcon, SendMessageA, SetTimer, LoadIconA, GetClientRect
ADVAPI32.dll: RegEnumValueA, RegDeleteValueA, RegCloseKey, OpenProcessToken, LookupPrivilegeValueA, AdjustTokenPrivileges, RegOpenKeyExA
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 4096
Comments:
CompanyName:
EntryPoint: 0x1a2e
FileDescription: CameraFixer MFC Application
FileFlagsMask: 0x003f
FileOS: Win32
FileSize: 20 kB
FileSubtype: 0
FileType: Win32 EXE
FileVersion: 1, 0, 0, 9
FileVersionNumber: 1.0.0.9
ImageVersion: 0.0
InitializedDataSize: 12288
InternalName: CameraFixer
LanguageCode: English (U.S.)
LegalCopyright: Copyright (C) 2005
LegalTrademarks:
LinkerVersion: 6.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 4.0
ObjectFileType: Executable application
OriginalFilename: CameraFixer.EXE
PEType: PE32
PrivateBuild:
ProductName: CameraFixer Application
ProductVersion: 1, 0, 0, 9
ProductVersionNumber: 1.0.0.9
SpecialBuild:
Subsystem: Windows GUI
SubsystemVersion: 4.0
TimeStamp: 2007:02:12 07:50:38+01:00
UninitializedDataSize: 0

ken545
2011-01-13, 19:15
That file is most likely ok, go ahead and run Combofix

allseeingeye
2011-01-13, 19:50
ComboFix 11-01-12.04 - Troy 01/13/2011 12:30:22.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1453 [GMT -6:00]
Running from: c:\documents and settings\Troy\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\install.exe
c:\windows\system32\Thumbs.db

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SSHNAS


((((((((((((((((((((((((( Files Created from 2010-12-13 to 2011-01-13 )))))))))))))))))))))))))))))))
.

2011-01-13 15:02 . 2011-01-13 15:02 53 ----a-w- c:\windows\sfshell.tmp
2011-01-13 04:44 . 2011-01-13 04:44 -------- d-----w- C:\_OTL
2011-01-13 00:11 . 2011-01-13 00:11 -------- d-----w- c:\documents and settings\Troy\Application Data\Malwarebytes
2011-01-13 00:11 . 2011-01-13 00:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-01-13 00:11 . 2010-12-21 00:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-13 00:11 . 2010-12-21 00:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-13 00:11 . 2011-01-13 00:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-09 06:25 . 2011-01-09 06:25 -------- d-----w- c:\program files\ERUNT
2011-01-09 01:55 . 2011-01-09 02:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-01-09 01:55 . 2011-01-09 02:16 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-01-03 00:46 . 2010-12-03 09:05 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-01-03 00:46 . 2011-01-03 00:46 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-01-03 00:37 . 2011-01-03 00:37 -------- d-----w- c:\documents and settings\Troy\Local Settings\Application Data\Sunbelt Software
2011-01-03 00:36 . 2011-01-03 00:57 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{2162CCC0-3A5F-4887-B51F-CE5F195B3620}
2011-01-02 20:33 . 2011-01-02 20:33 -------- d-sh--w- c:\documents and settings\All Users\Application Data\PICCS
2011-01-02 20:31 . 2011-01-02 20:36 -------- d-sh--w- c:\documents and settings\All Users\Application Data\ad514e
2011-01-01 17:30 . 2010-11-22 16:22 17408 ----a-w- c:\windows\system32\drivers\MO3v2Driver.sys
2011-01-01 17:30 . 2010-10-04 15:34 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2011-01-01 17:30 . 2011-01-01 17:30 -------- d-----w- c:\program files\SteelSeries
2010-12-30 20:11 . 2010-12-30 20:11 -------- d-----w- c:\documents and settings\Troy\Local Settings\Application Data\NCH
2010-12-30 20:05 . 2010-12-30 20:05 -------- d-----w- c:\documents and settings\Troy\Application Data\Razer
2010-12-30 20:03 . 2009-04-21 23:58 11136 ----a-w- c:\windows\system32\drivers\danew.sys
2010-12-30 20:03 . 2009-12-22 03:50 5760 ----a-w- c:\windows\system32\drivers\vHidDev.sys
2010-12-30 02:15 . 2011-01-01 17:31 -------- d-----w- c:\documents and settings\Troy\Application Data\SteelSeries
2010-12-30 02:15 . 2008-03-21 19:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2010-12-23 23:42 . 2010-12-23 23:42 -------- d-----w- c:\program files\Ventrilo
2010-12-23 23:42 . 2010-12-23 23:42 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-12-16 06:05 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2010-12-16 06:04 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-03 22:32 . 2007-08-15 14:49 60416 -c--a-w- c:\windows\ALCFDRTM.VER
2010-11-18 18:12 . 2007-08-11 17:20 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-13 00:53 . 2010-08-14 14:33 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-12 22:34 . 2008-02-04 02:27 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-11-09 14:52 . 2004-08-04 05:56 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:26 . 2004-08-04 05:56 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-06 00:26 . 2004-08-04 05:56 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2004-08-04 05:56 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-03 12:25 . 2004-08-04 03:59 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2001-08-23 12:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2004-08-04 05:56 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2004-08-04 04:17 1853312 ----a-w- c:\windows\system32\win32k.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"Google Update"="c:\documents and settings\Troy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-02-25 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SW20"="c:\windows\system32\sw20.exe" [2006-12-15 208896]
"SW24"="c:\windows\system32\sw24.exe" [2006-12-15 69632]
"SoundMan"="SOUNDMAN.EXE" [2005-08-17 90112]
"vptray"="c:\program files\NavNT\vptray.exe" [2001-10-31 73728]
"WinSys2"="c:\windows\system32\winsys2.exe" [2006-04-29 208896]
"Launch LGDCore"="c:\program files\Logitech\G-series Software\LGDCore.exe" [2006-03-06 1122304]
"Launch LCDMon"="c:\program files\Logitech\G-series Software\LCDMon.exe" [2006-03-06 497152]
"FixCamera"="c:\windows\FixCamera.exe" [2007-02-12 20480]
"RivaTunerStartupDaemon"="c:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner.exe" [2009-08-22 2781184]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-09-24 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-07-08 1753192]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-07-09 13923432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-07-09 110696]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-09-08 47904]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-11-18 421160]
"SteelSeries World of Warcraft Cataclysm MMO Gaming Mouse"="c:\program files\SteelSeries\World of Warcraft Cataclysm MMO Gaming Mouse\WoWMHID2.exe" [2010-12-23 1987072]

c:\documents and settings\Troy\Start Menu\Programs\Startup\
CurseClientStartup.ccip [2010-12-20 0]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-8-17 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"e:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"c:\\World of Warcraft\\Launcher.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\StarCraft II\\StarCraft II.exe"=
"c:\\Program Files\\StarCraft II\\Versions\\Base15405\\SC2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\StarCraft II\\Versions\\Base16605\\SC2.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\StarCraft II\\Versions\\Base16755\\SC2.exe"=
"c:\\Program Files\\StarCraft II\\Versions\\Base16939\\SC2.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\StarCraft II\\StarCraft II Public Test.exe"=
"c:\\Documents and Settings\\Troy\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\World of Warcraft\\Blizzard Downloader.exe"=
"c:\\Documents and Settings\\Troy\\Local Settings\\Apps\\2.0\\M6VKE4CO.QNE\\4WOQEQ0E.VNE\\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\\CurseClient.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1/2/2011 6:46 PM 64288]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12/3/2010 3:05 AM 1402272]
R3 SSMO3v2Filter;MMO3v2 Mouse;c:\windows\system32\drivers\MO3v2Driver.sys [1/1/2011 11:30 AM 17408]
S3 danewFltr;NewDeathAdder Mouse;c:\windows\system32\drivers\danew.sys [12/30/2010 2:03 PM 11136]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [11/30/2009 3:56 PM 36608]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [12/3/2010 3:05 AM 15264]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
S3 SNP325;USB PC Camera (SNPSTD325);c:\windows\system32\DRIVERS\snp325.sys --> c:\windows\system32\DRIVERS\snp325.sys [?]
S3 vHidDev;Razer Gaming Device;c:\windows\system32\drivers\vHidDev.sys [12/30/2010 2:03 PM 5760]
.
Contents of the 'Scheduled Tasks' folder

2011-01-13 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-12-03 09:04]

2011-01-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34]

2011-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-606747145-1454471165-725345543-1003Core.job
- c:\documents and settings\Troy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-01 08:26]

2011-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-606747145-1454471165-725345543-1003UA.job
- c:\documents and settings\Troy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-01 08:26]

2011-01-13 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]

2011-01-13 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-03-24 03:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.facebook.com/
uInternet Settings,ProxyOverride = *.local
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
FF - ProfilePath - c:\documents and settings\Troy\Application Data\Mozilla\Firefox\Profiles\ah5v1emr.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2117678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.wowhead.com/
FF - Ext: Move Media Player: moveplayer@movenetworks.com - %profile%\extensions\moveplayer@movenetworks.com
FF - Ext: AIM Toolbar: {c2f863cd-0429-48c7-bb54-db756a951760} - %profile%\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
FF - Ext: SOE Web Installer: {000F1EA4-5E08-4564-A29B-29076F63A37A} - %profile%\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-MsnMsgr - c:\program files\Windows Live\Messenger\MsnMsgr.Exe
HKCU-Run-RIMDeviceManager - c:\program files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe
AddRemove-NVIDIA Display Control Panel - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe
AddRemove-Simple File Shredder - c:\program files\Simple File Shredder\uninst.exe
AddRemove-WinLiveSuite_Wave3 - c:\program files\Windows Live\Installer\wlarp.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-13 12:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-606747145-1454471165-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(892)
c:\windows\system32\NavLogon.dll

- - - - - - - > 'explorer.exe'(3176)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
e:\program files\SmartFTP Client 2.0\smarthook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\NavNT\defwatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\NavNT\rtvscan.exe
c:\windows\SOUNDMAN.EXE
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe
c:\program files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe
c:\program files\Logitech\G-series Software\Applets\LCDMedia.exe
c:\program files\Logitech\G-series Software\Applets\LCDClock.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\iTunes\iTunes.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\SteelSeries\World of Warcraft Cataclysm MMO Gaming Mouse\WoWMTray2.exe
c:\windows\system32\MsgSys.EXE
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
c:\program files\Common Files\Apple\Apple Application Support\distnoted.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2011-01-13 12:47:46 - machine was rebooted
ComboFix-quarantined-files.txt 2011-01-13 18:47

Pre-Run: 28,711,636,992 bytes free
Post-Run: 28,580,777,984 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - A706739CA96C2AD4A6342DA9FD158551

ken545
2011-01-13, 22:39
:bigthumb:

How are things running now ?

allseeingeye
2011-01-13, 23:49
Things appear to be running just fine. The malware was redirecting all of my search engine searches to other, more than likely hazardous sites. It was also making Google search in other languages, like Danish.

Rebooting my machine seems to take half of the time it used to!
Is are there more instructions? If not, thank you!

ken545
2011-01-14, 00:01
Thats nice to hear :)

Open OTL and click on Cleanup and it will remove the programs we used to clean your system along with there backups.


How did I get infected in the first place ?
Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/So_how_did_I_get_infected_in_the_first_place_t57817.html)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
GeeksTo Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)




Safe Surfn
Ken

ken545
2011-01-18, 13:23
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.