PDA

View Full Version : Fraud.InternetSecurity2011 and Virtumonde



JakeM
2011-04-22, 22:17
Hey guys, I've been trying to remove some malware from my computer via conventional methods such as scans for the last week or so.

System information:

Windows Vista Home Premium (32 bit)
Intel (R) Core(TM)2 Duo CPU E6550 @ 2.33GHz
3.00 GB RAM
NVIDIA GeForce 8800 GTS 512


The programs I use for scans are SpyBot - Search and Destroy (1.6.2), Malwarebytes' Anti Malware, and Microsoft Security Essentials. Whenever I run a scan with any of these three, SpyBot is the only program that turns up a result, which is Fraud.InternetSecurity2011. While watching which files the cleaner is analyzing, I see other names with the word fraud, and Virtumonde.

The major symptoms I am experiencing are slow internet access, and sometimes my internet connection dies altogether. Some processes proceed slower but only at a slightly noticeable rate.


I have run ERUNT and set a registry backup point.


DDS:

DDS (Ver_11-03-05.01) - NTFSx86
Run by Jake at 10:30:24.00 on Fri 04/22/2011
Internet Explorer: 8.0.6001.19048 BrowserJavaVersion: 1.6.0_24
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uWindow Title = Internet Explorer provided by Dell
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2786678
uInternet Settings,ProxyOverride = <local>;*.local
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Google Update] "c:\users\jake\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\jake\appdata\roaming\dvdvideosoftiehelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\users\jake\appdata\roaming\dvdvideosoftiehelpers\freeyoutubetomp3converter.htm
IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08}
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: passport.com
Trusted Zone: passport.net
Trusted Zone: windowsonecare.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
Hosts: 127.0.0.1 www.spywareinfo.com (http://www.spywareinfo.com)
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jake\appdata\roaming\mozilla\firefox\profiles\opymsnq6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tbff50ie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/?wl=true
FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=TB50TRFFab&query=
FF - prefs.js: network.proxy.ftp - 62.193.226.25
FF - prefs.js: network.proxy.ftp_port - 80
FF - prefs.js: network.proxy.gopher - 62.193.226.25
FF - prefs.js: network.proxy.gopher_port - 80
FF - prefs.js: network.proxy.http - 62.193.226.25
FF - prefs.js: network.proxy.http_port - 80
FF - prefs.js: network.proxy.socks - 62.193.226.25
FF - prefs.js: network.proxy.socks_port - 80
FF - prefs.js: network.proxy.ssl - 62.193.226.25
FF - prefs.js: network.proxy.ssl_port - 80
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: c:\programdata\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\users\jake\appdata\local\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\users\jake\program files\dna\plugins\npbtdna.dll
FF - Ext: NASA Night Launch: http://forums.spybot.info/misc.php?do=email_dev&email=bmFzYW5pZ2h0bGF1bmNoQGV4YW1wbGUuY29t - %profile%\extensions\nasanightlaunch@example.com
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2011-04-22 17:29:12 -------- d-----w- C:\desktop
2011-04-22 05:32:22 28752 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{5d3244b6-790a-48ac-83d8-ef2523845551}\MpKsl1e8b060d.sys
2011-04-22 05:32:01 7071056 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{5d3244b6-790a-48ac-83d8-ef2523845551}\mpengine.dll
2011-04-15 04:02:48 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-04-15 04:02:48 292864 ----a-w- c:\windows\system32\atmfd.dll
2011-04-15 04:00:17 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-15 04:00:17 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-15 04:00:17 213504 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-15 04:00:17 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-15 03:59:02 1162240 ----a-w- c:\windows\system32\mfc42u.dll
2011-04-15 03:59:02 1136640 ----a-w- c:\windows\system32\mfc42.dll
2011-04-15 03:57:47 305152 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-15 03:57:46 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-15 03:57:46 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-15 03:54:30 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-04-15 03:54:30 25088 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-04-15 03:53:15 2041856 ----a-w- c:\windows\system32\win32k.sys
2011-04-15 03:51:59 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-15 03:50:44 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-04-15 03:47:02 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-04-05 14:30:20 439632 ------w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{8cdaf883-a1dc-4617-a619-fa088096a045}\gapaengine.dll
2011-04-04 03:38:57 -------- d-----w- c:\users\jake\appdata\roaming\iTunesControl
2011-04-04 03:38:57 -------- d-----w- c:\program files\iTunesControl
2011-03-27 18:24:52 439632 ------w- c:\progra~2\microsoft\microsoft antimalware\definition updates\nisbackup\gapaengine.dll
2011-03-26 23:08:59 -------- d-----w- c:\users\jake\appdata\roaming\DVDVideoSoft
2011-03-26 18:22:55 -------- d-----w- c:\program files\Amnesia - The Dark Descent
.
==================== Find3M ====================
.
2011-03-12 20:15:07 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-22 14:13:01 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-22 13:33:12 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-02-22 13:33:09 797696 ----a-w- c:\windows\system32\FntCache.dll
2011-02-22 06:21:28 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 06:17:08 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-22 06:16:53 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 06:16:40 71680 ----a-w- c:\windows\system32\iesetup.dll
2011-02-22 06:16:40 109056 ----a-w- c:\windows\system32\iesysprep.dll
2011-02-22 05:20:39 385024 ----a-w- c:\windows\system32\html.iec
2011-02-22 04:43:54 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2011-02-22 04:42:38 1638912 ----a-w- c:\windows\system32\mshtml.tlb
.
============= FINISH: 10:31:40.44 ===============
I have the Attach.txt, but in one of the first lines it says do not post this log unless specifically asked.

I ran RootAlyzer, got these results, and took no action because I don't know what it means or how to do anything about it.

// info: Rootkit removal help file
// copyright: (c) 2008-2009 Safer-Networking Ltd. All rights reserved.

:: RootAlyzer Results
File:"No admin in ACL","C:\ProgramData\Microsoft\Network\Connections\pbk_old\rasphone.pbk"
File:"Unknown ADS","C:\Fraps\Movies\hl2 2010-12-02 20-52-32-11.avi:TOC.WMV:$DATA"
Directory:"No admin in ACL","C:\ProgramData\Microsoft\OFFICE\DATA"

If there is any more information you would like about my computer or programs I have by all means just ask.

I attached the compressed attach.txt file.

Shaba
2011-04-26, 19:25
Hi JakeM

Please copy/paste contents of attach.txt to your next reply and we will continue :)

JakeM
2011-04-26, 23:29
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
.
==== Disk Partitions =========================
.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
µTorrent
7-Zip 4.60 beta
Adobe AIR
Adobe Bridge 1.0
Adobe Community Help
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Media Player
Adobe Photoshop CS5
Adobe Reader 8.1.1
Amnesia - The Dark Descent
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Autodesk 3ds Max 2010 32-bit
Autodesk Backburner 2008.1
Autodesk DirectConnect 2.0
Autodesk FBX Plugin 2009.4 - 3ds Max 2010
Belarc Advisor 8.1
Bonjour
Browser Address Error Redirector
CCleaner
Choice Guard
Conduit Engine
Consumer Complete Care Services Agreement
Counter-Strike: Source
Creative MediaSource 5
Dell DataSafe Online
Dell Getting Started Guide
Dell Support Center
Deus Ex
DivX Converter
DivX Setup
ERUNT 1.1j
EVE Online Demo
EveHQ
EVEMon
Fallout 3 - The Garden of Eden Creation Kit
Final Fantasy VII - Ultima Edition
Fraps (remove only)
Free Studio version 5.0.8
Free YouTube to Mp3 Converter version 3.1
Garry's Mod
GCFScape 1.6.9
GIMP 2.6.3
Glary Utilities 2.33.0.1158
GLOBEtrotter FLEXid Drivers
Google Chrome
Google Gears
Google Talk (remove only)
Google Update Helper
GPGNet
Half-Life 2: Episode Two
Highlight Viewer (Windows Live Toolbar)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB945282)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB946040)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB946308)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB947540)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB947789)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB948127)
Intel(R) Graphics Media Accelerator Driver
Intel(R) PRO Network Connections 12.1.11.0
iTunes
iTunesControl 0.56
Java Auto Updater
Java DB 10.5.3.0
Java(TM) 6 Update 24
Java(TM) 6 Update 3
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Java(TM) SE Development Kit 6 Update 22
Java(TM) SE Runtime Environment 6
Livestream Procaster
Malwarebytes' Anti-Malware
Map Button (Windows Live Toolbar)
Maya 2008
Maya 2008 Documentation (en_US)
McAfee Security Scan Plus
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Chart Controls for Microsoft .NET Framework 3.5
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft Speech SDK 5.1
Microsoft SQL Server 2008 Management Objects
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Express Edition with SP1 - ENU
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual J# 2.0 Redistributable Package
Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
MicroStaff WINASPI
mIRC
Mobile Photo Enhancer 1.3
Movavi Video Converter 10
Movavi Video Converter 9
Mozilla Firefox (3.6.16)
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MTX
Music, Photos & Videos Launcher
NVIDIA Drivers
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
OGA Notifier 2.0.0048.0
OpenAL
OpenOffice.org Installer 1.0
PDF Settings CS5
Power Tab Editor 1.7
Product Documentation Launcher
Project64 1.6
QualxServ Service Agreement
QuickTime
Rosetta Stone Version 3
Roxio Creator Audio
Roxio Creator BDAV Plugin
Roxio Creator Copy
Roxio Creator Data
Roxio Creator Premier
Roxio Creator Tools
Roxio EasyArchive
Roxio MyDVD Premier
Roxio Update Manager
RS2Bot
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2466156)
Security Update for 2007 Microsoft Office System (KB2509488)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft Office Excel 2007 (KB2464583)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2464594)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Sentinel System Driver
Sid Meier's Civilization 4 Gold
Sins of a Solar Empire Trinity
Skype Toolbars
Skype™ 5.1
Smart Menus (Windows Live Toolbar)
Sonic Activation Module
Sound Blaster X-Fi
Source SDK
Spybot - Search & Destroy
SQL Server System CLR Types
Starcraft
StarCraft II
Steam
Supreme Commander - Forged Alliance
System Requirements Lab
Team Fortress 2
TortoiseSVN 1.6.12.20536 (32 bit)
Trend Micro PC-cillin Internet Security 14
Uninstall 1.0.0.1
Unreal Development Kit: 2010-06
Unreal Development Kit: 2011-01
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
uTorrentBar Toolbar
VC80CRTRedist - 8.0.50727.4053
Ventrilo Client
Viewpoint Media Player
VTFEdit 1.2.5
Web Photo Album 1.1
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Favorites for Windows Live Toolbar
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Toolbar
Windows Live Toolbar Extension (Windows Live Toolbar)
Windows Live Upload Tool
Windows Media Player Firefox Plugin
Windows Mobile Device Center
Windows Mobile Device Center Driver Update
WinRAR archiver
Xfire (remove only)
.
==== End Of File ===========================

Shaba
2011-04-27, 21:13
As per forum rules, you will need to uninstall p2p programs, see here (http://forums.spybot.info/showthread.php?t=282)

In your case µTorrent is the one.

After that, please rerun DDS and post back fresh logs.

JakeM
2011-04-27, 21:31
.
I uninstalled my p2p program. Here is the new DDS






DDS (Ver_11-03-05.01) - NTFSx86
Run by Jake at 12:27:12.88 on Wed 04/27/2011
Internet Explorer: 8.0.6001.19048 BrowserJavaVersion: 1.6.0_24
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uWindow Title = Internet Explorer provided by Dell
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2786678
uInternet Settings,ProxyOverride = <local>;*.local
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Google Update] "c:\users\jake\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\jake\appdata\roaming\dvdvideosoftiehelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\users\jake\appdata\roaming\dvdvideosoftiehelpers\freeyoutubetomp3converter.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\ssv.dll
IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08}
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: passport.com
Trusted Zone: passport.net
Trusted Zone: windowsonecare.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jake\appdata\roaming\mozilla\firefox\profiles\opymsnq6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tbff50ie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/?wl=true
FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=TB50TRFFab&query=
FF - prefs.js: network.proxy.ftp - 62.193.226.25
FF - prefs.js: network.proxy.ftp_port - 80
FF - prefs.js: network.proxy.gopher - 62.193.226.25
FF - prefs.js: network.proxy.gopher_port - 80
FF - prefs.js: network.proxy.http - 62.193.226.25
FF - prefs.js: network.proxy.http_port - 80
FF - prefs.js: network.proxy.socks - 62.193.226.25
FF - prefs.js: network.proxy.socks_port - 80
FF - prefs.js: network.proxy.ssl - 62.193.226.25
FF - prefs.js: network.proxy.ssl_port - 80
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: c:\programdata\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\users\jake\appdata\local\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\users\jake\program files\dna\plugins\npbtdna.dll
FF - Ext: NASA Night Launch: nasanightlaunch@example.com - %profile%\extensions\nasanightlaunch@example.com
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2011-04-27 13:20:00 28752 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{0d06c375-f9bf-411b-9d33-afb4db9dda68}\MpKsl57cb6a03.sys
2011-04-26 13:44:44 7071056 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{0d06c375-f9bf-411b-9d33-afb4db9dda68}\mpengine.dll
2011-04-22 17:29:12 -------- d-----w- C:\desktop
2011-04-15 04:02:48 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-04-15 04:02:48 292864 ----a-w- c:\windows\system32\atmfd.dll
2011-04-15 04:00:17 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-15 04:00:17 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-15 04:00:17 213504 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-15 04:00:17 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-15 03:59:02 1162240 ----a-w- c:\windows\system32\mfc42u.dll
2011-04-15 03:59:02 1136640 ----a-w- c:\windows\system32\mfc42.dll
2011-04-15 03:57:47 305152 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-15 03:57:46 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-15 03:57:46 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-15 03:54:30 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-04-15 03:54:30 25088 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-04-15 03:53:15 2041856 ----a-w- c:\windows\system32\win32k.sys
2011-04-15 03:51:59 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-15 03:50:44 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-04-15 03:47:02 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-04-05 14:30:20 439632 ------w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{8cdaf883-a1dc-4617-a619-fa088096a045}\gapaengine.dll
2011-04-04 03:38:57 -------- d-----w- c:\users\jake\appdata\roaming\iTunesControl
2011-04-04 03:38:57 -------- d-----w- c:\program files\iTunesControl
.
==================== Find3M ====================
.
2011-04-23 16:37:30 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-22 14:13:01 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-22 13:33:12 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-02-22 13:33:09 797696 ----a-w- c:\windows\system32\FntCache.dll
2011-02-22 06:21:28 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 06:17:08 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-22 06:16:53 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 06:16:40 71680 ----a-w- c:\windows\system32\iesetup.dll
2011-02-22 06:16:40 109056 ----a-w- c:\windows\system32\iesysprep.dll
2011-02-22 05:20:39 385024 ----a-w- c:\windows\system32\html.iec
2011-02-22 04:43:54 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2011-02-22 04:42:38 1638912 ----a-w- c:\windows\system32\mshtml.tlb
.
============= FINISH: 12:28:39.28 ===============

Shaba
2011-04-27, 21:43
Please post also a fresh attach.txt :)

JakeM
2011-04-27, 22:00
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
.
==== Disk Partitions =========================
.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
7-Zip 4.60 beta
Adobe AIR
Adobe Bridge 1.0
Adobe Community Help
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Media Player
Adobe Photoshop CS5
Adobe Reader 8.1.1
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Autodesk 3ds Max 2010 32-bit
Autodesk Backburner 2008.1
Autodesk DirectConnect 2.0
Autodesk FBX Plugin 2009.4 - 3ds Max 2010
Belarc Advisor 8.1
Bonjour
Browser Address Error Redirector
CCleaner
Choice Guard
Conduit Engine
Consumer Complete Care Services Agreement
Counter-Strike: Source
Creative MediaSource 5
Dell DataSafe Online
Dell Getting Started Guide
Dell Support Center
Deus Ex
DivX Converter
DivX Setup
ERUNT 1.1j
EVE Online Demo
EveHQ
EVEMon
Fallout 3 - The Garden of Eden Creation Kit
Final Fantasy VII - Ultima Edition
Fraps (remove only)
Free Studio version 5.0.8
Free YouTube to Mp3 Converter version 3.1
Garry's Mod
GCFScape 1.6.9
GIMP 2.6.3
Glary Utilities 2.33.0.1158
GLOBEtrotter FLEXid Drivers
Google Chrome
Google Gears
Google Talk (remove only)
Google Update Helper
GPGNet
Half-Life 2: Episode Two
Highlight Viewer (Windows Live Toolbar)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB945282)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB946040)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB946308)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB947540)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB947789)
Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB948127)
Intel(R) Graphics Media Accelerator Driver
Intel(R) PRO Network Connections 12.1.11.0
iTunes
iTunesControl 0.56
Java Auto Updater
Java(TM) 6 Update 24
Livestream Procaster
Malwarebytes' Anti-Malware
Map Button (Windows Live Toolbar)
Maya 2008
Maya 2008 Documentation (en_US)
McAfee Security Scan Plus
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Chart Controls for Microsoft .NET Framework 3.5
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft Speech SDK 5.1
Microsoft SQL Server 2008 Management Objects
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Express Edition with SP1 - ENU
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual J# 2.0 Redistributable Package
Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
MicroStaff WINASPI
mIRC
Mobile Photo Enhancer 1.3
Movavi Video Converter 10
Movavi Video Converter 9
Mozilla Firefox (3.6.16)
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MTX
Music, Photos & Videos Launcher
NVIDIA Drivers
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
OGA Notifier 2.0.0048.0
OpenAL
OpenOffice.org Installer 1.0
PDF Settings CS5
Power Tab Editor 1.7
Product Documentation Launcher
Project64 1.6
QualxServ Service Agreement
QuickTime
Rosetta Stone Version 3
Roxio Creator Audio
Roxio Creator BDAV Plugin
Roxio Creator Copy
Roxio Creator Data
Roxio Creator Premier
Roxio Creator Tools
Roxio EasyArchive
Roxio MyDVD Premier
Roxio Update Manager
RS2Bot
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2466156)
Security Update for 2007 Microsoft Office System (KB2509488)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft Office Excel 2007 (KB2464583)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2464594)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Sentinel System Driver
Sid Meier's Civilization 4 Gold
Sins of a Solar Empire Trinity
Skype Toolbars
Skype™ 5.1
Smart Menus (Windows Live Toolbar)
Sonic Activation Module
Sound Blaster X-Fi
Source SDK
Spybot - Search & Destroy
SQL Server System CLR Types
Starcraft
StarCraft II
Steam
Supreme Commander - Forged Alliance
System Requirements Lab
Team Fortress 2
TortoiseSVN 1.6.12.20536 (32 bit)
Trend Micro PC-cillin Internet Security 14
Uninstall 1.0.0.1
Unreal Development Kit: 2010-06
Unreal Development Kit: 2011-01
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
uTorrentBar Toolbar
VC80CRTRedist - 8.0.50727.4053
Ventrilo Client
Viewpoint Media Player
VTFEdit 1.2.5
Web Photo Album 1.1
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Favorites for Windows Live Toolbar
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Toolbar
Windows Live Toolbar Extension (Windows Live Toolbar)
Windows Live Upload Tool
Windows Media Player Firefox Plugin
Windows Mobile Device Center
Windows Mobile Device Center Driver Update
WinRAR archiver
Xfire (remove only)
.
==== End Of File ===========================

Shaba
2011-04-28, 19:20
Thank you :)

Please post also spybot report.

JakeM
2011-04-29, 04:50
Attached should be the compressed report.

Shaba
2011-05-01, 07:34
Please copy/paste contents of that report to your next reply :)

JakeM
2011-05-01, 08:06
The Report is massively long, the forums aren't letting me post the whole thing. The report is 200,000+ characters. It took up 260 pages in a word document when I tried to split it up that way.

Shaba
2011-05-02, 18:12
Yes my bad, that is then likely full report.

Did you let spybot remove what it found?

JakeM
2011-05-02, 23:44
Spybot does not let me remove it because it's in use in memory. (?)

Shaba
2011-05-04, 06:07
Then please run another spybot scan in safe mode and let me know if it worked there.

JakeM
2011-05-04, 07:22
It did not.

Shaba
2011-05-05, 19:20
Are you able to find C:\Windows\WinSxS\x86_Microsoft.Windows.Shell.HWEventDetector_6595b64144ccf1df_5.2.2.3_x-ww_5390e909\?

JakeM
2011-05-05, 23:38
Yes I was.

Shaba
2011-05-08, 07:58
Good :)

Are there any files inside that folder?

JakeM
2011-05-08, 08:55
No there is not anything in the folder.

Shaba
2011-05-10, 05:57
Are hidden files visible?

You can ensure from here (http://www.bleepingcomputer.com/tutorials/tutorial62.html)

JakeM
2011-05-10, 23:50
Yes hidden files are visible.

Shaba
2011-05-12, 19:01
Good :)

Are you able to delete that folder?

JakeM
2011-05-12, 23:46
No I am not able to. The error message does not state any reason why.

Shaba
2011-05-15, 19:02
Please then try to delete it in safe mode :)

JakeM
2011-05-19, 06:43
This did not work.

Shaba
2011-05-21, 07:44
In that case, please update Spybot definitions and do another scan.

Chances are that folder is not bad at all but needed.

tashi
2011-06-18, 07:43
This thread has been closed due to inactivity. As it has been four days or more since your last post, it will not be re-opened.

If you still require help, please start a new topic and include a DDS log with a link to your previous thread.

Please do not add any logs that might have been requested previously, you would be starting fresh.

Applies only to the original poster, anyone else with similar problems please start your own topic.