Results 1 to 8 of 8

Thread: World of Warcraft Account Hacked. Keylogger?

  1. #1
    Junior Member
    Join Date
    Jun 2010
    Posts
    4

    Default

    I had my account hacked yesterday. Lost all my gold, items, gear etc. I have now changed my password so hopefully I'm safe.

    Also, I finally found out what I did. I got an email about a new WoW magazaine and I followed the link. I assume that's what caused this to happen as I now believe the site wasn't legit.

    I have scanned my pc with...

    ~ Spybot
    ~ MalwareBytes
    ~ Avast!
    ~ AVG
    ~ Windows Defender

    and they all came up clear. I am still worried though. Here is the DDS log.


    DDS (Ver_10-03-17.01) - NTFSX64
    Run by Andrew at 18:14:58.75 on Sun 06/06/2010
    Internet Explorer: 8.0.6001.18904 BrowserJavaVersion: 1.6.0_20
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.61.1033.18.4060.1179 [GMT 10:00]

    SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Program Files (x86)\AVG\AVG9\avgchsva.exe
    C:\Program Files (x86)\AVG\AVG9\avgrsa.exe
    C:\Windows\system32\lsm.exe
    C:\Program Files (x86)\AVG\AVG9\avgcsrva.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files\Avast4\aswUpdSv.exe
    C:\Program Files\Avast4\ashServ.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\agr64svc.exe
    C:\Windows\SysWOW64\svchost.exe -k Akamai
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
    C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
    C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
    C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
    C:\Program Files (x86)\AVG\AVG9\avgnsa.exe
    C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    c:\Program Files (x86)\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\TOSHIBA\rselect\RSelSvc.exe
    c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
    C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
    C:\Windows\system32\TODDSrv.exe
    C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
    C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
    C:\Program Files\TOSHIBA\TECO\TecoService.exe
    C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
    C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Avast4\ashMaiSv.exe
    C:\Program Files\Avast4\ashWebSv.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
    C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
    C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\TOSHIBA\TECO\Teco.exe
    C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
    C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
    C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files (x86)\WhatPulse\WhatPulse.exe
    C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files (x86)\StickyNotes\StickyNotes.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\ehome\ehsched.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\ehome\ehRecvr.exe
    C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
    C:\Program Files (x86)\AVG\AVG9\avgtray.exe
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files\Avast4\ashDisp.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    C:\Users\Public\Games\World of Warcraft\WoW.exe
    C:\PROGRA~2\Java\jre6\bin\jp2launcher.exe
    C:\Program Files (x86)\Java\jre6\bin\java.exe
    C:\Windows\system32\rundll32.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Users\Andrew\Downloads\dds.scr
    C:\Windows\SysWOW64\conime.exe
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSHN&bmod=TSHN
    uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSHN&bmod=TSHN
    mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSHN&bmod=TSHN
    mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSHN&bmod=TSHN
    mLocal Page = c:\windows\syswow64\blank.htm
    uInternet Settings,ProxyOverride = *.local
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files (x86)\avg\avg9\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~2\spybot~1\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    uRun: [WhatPulse] c:\program files (x86)\whatpulse\WhatPulse.exe
    uRun: [BitTorrent DNA] "c:\users\andrew\program files (x86)\dna\btdna.exe"
    uRun: [WMPNSCFG] c:\program files (x86)\windows media player\WMPNSCFG.exe
    uRun: [SpybotSD TeaTimer] c:\program files (x86)\spybot - search & destroy\TeaTimer.exe
    mRun: [HWSetup] "c:\program files\toshiba\utilities\HWSetup.exe" hwSetUP
    mRun: [SVPWUTIL] "c:\program files (x86)\toshiba\utilities\SVPWUTIL.exe" SVPwUTIL
    mRun: [KeNotify] "c:\program files (x86)\toshiba\utilities\KeNotify.exe"
    mRun: [StartCCC] "c:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
    mRun: [cfFncEnabler.exe] "c:\program files (x86)\toshiba\configfree\cfFncEnabler.exe"
    mRun: [AVG9_TRAY] c:\progra~2\avg\avg9\avgtray.exe
    mRun: [avast!] c:\progra~1\avast4\ashDisp.exe
    mRun: [QuickTime Task] "c:\program files (x86)\quicktime\QTTask.exe" -atboottime
    mRun: [SunJavaUpdateSched] "c:\program files (x86)\common files\java\java update\jusched.exe"
    mRunOnce: [Malwarebytes' Anti-Malware] "c:\program files (x86)\malwarebytes' anti-malware\mbamgui.exe" /install /silent
    StartupFolder: c:\users\andrew\appdata\roaming\micros~1\windows\startm~1\programs\startup\sticky~1.lnk - c:\program files (x86)\stickynotes\StickyNotes.exe
    StartupFolder: c:\users\andrew\appdata\roaming\micros~1\windows\startm~1\programs\startup\sticky~1.lnk - c:\program files (x86)\stickynotes\StickyNotes.exe
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - c:\progra~2\micros~1\office12\EXCEL.EXE/3000
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~2\micros~1\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~1\office12\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~2\spybot~1\SDHelper.dll
    DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-au/wlscctrl2.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} - hxxp://www.netgame.com/mplugin/mglaunch_USAv1005.cab
    DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files (x86)\avg\avg9\avgpp.dll
    BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - c:\program files (x86)\avg\avg9\avgssiea.dll
    BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
    mRun-x64: [(Default)]
    mRun-x64: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
    mRun-x64: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
    mRun-x64: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
    mRun-x64: [RtHDVCpl] c:\program files\realtek\audio\hda\RAVCpl64.exe
    mRun-x64: [Skytel] c:\program files\realtek\audio\hda\Skytel.exe
    mRun-x64: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun-x64: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
    mRun-x64: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
    mRun-x64: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosSENotify.exe
    mRun-x64: [TPCHWMsg] %ProgramFiles%\TOSHIBA\TPHM\TPCHWMsg.exe
    mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun-x64: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun
    AppInit_DLLs-X64: avgrssta.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\andrew\appdata\roaming\mozilla\firefox\profiles\2av05b5n.default\
    FF - prefs.js: browser.startup.homepage - file:///C:/Users/Andrew/Desktop/Andrew/Website%20Development/Homepage/Version%202.0/page.html
    FF - component: c:\program files (x86)\avg\avg9\firefox\components\avgssff.dll
    FF - plugin: c:\program files (x86)\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files (x86)\mozilla firefox\plugins\npdnu.dll
    FF - plugin: c:\program files (x86)\mozilla firefox\plugins\npdnupdater2.dll
    FF - plugin: c:\program files (x86)\picasa2\npPicasa2.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
    c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

    ============= SERVICES / DRIVERS ===============

    R0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\drivers\tos_sps64.sys [2009-10-9 504912]
    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-10-28 89680]
    R1 AvgLdx64;AVG Free AVI Loader Driver x64;c:\windows\system32\drivers\avgldx64.sys [2009-10-16 269320]
    R1 AvgMfx64;AVG Free On-access Scanner Minifilter Driver x64;c:\windows\system32\drivers\avgmfx64.sys [2009-10-16 35536]
    R1 AvgTdiA;AVG Free Network Redirector x64;c:\windows\system32\drivers\avgtdia.sys [2009-10-16 317520]
    R1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;c:\windows\system32\drivers\RtlProt.sys [2009-10-9 31016]
    R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-1-21 27648]
    R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-10-9 203264]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-10-28 22096]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-10-28 65616]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\avast4\ashServ.exe [2009-10-28 138680]
    R2 avg9wd;AVG Free WatchDog;c:\program files (x86)\avg\avg9\avgwdsvc.exe [2010-3-14 308064]
    R2 camsvc;TOSHIBA Web Camera Service;c:\program files (x86)\toshiba\toshiba web camera application\TWebCameraSrv.exe [2009-10-9 20544]
    R2 ConfigFree Gadget Service;ConfigFree Gadget Service;c:\program files (x86)\toshiba\configfree\CFProcSRVC.exe [2009-3-7 36864]
    R2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\toshiba\configfree\CFSvcs.exe [2009-3-11 46448]
    R2 RSELSVC;TOSHIBA Modem region select service;c:\program files\toshiba\rselect\RSelSvc.exe [2009-2-20 55808]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\spybot - search & destroy\SDWinSec.exe [2010-6-5 1153368]
    R2 TMachInfo;TMachInfo;c:\program files (x86)\toshiba\toshiba service station\TMachInfo.exe [2009-10-9 62776]
    R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-4-15 251392]
    R2 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-3-18 84480]
    R2 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-4-10 803696]
    R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-3-24 14472]
    R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\avast4\ashMaiSv.exe [2009-10-28 254040]
    R3 avast! Web Scanner;avast! Web Scanner;c:\program files\avast4\ashWebSv.exe [2009-10-28 352920]
    R3 PGEffect;Pangu effect driver;c:\windows\system32\drivers\PGEffect.sys [2009-10-9 32832]
    R3 rtl819xpn64;Realtek RTL8190\RTL8192E 802.11n Wireless LAN (Mini-)PCI NIC NT Driver;c:\windows\system32\drivers\rtl819xp.sys [2009-10-9 564224]
    S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe [2009-12-4 89920]
    S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 27648]
    S3 PerfHost;Performance Counter DLL Host;c:\windows\syswow64\perfhost.exe [2008-1-21 19968]

    ============== File Associations ===============

    JSEFile=c:\windows\syswow64\WScript.exe "%1" %*

    =============== Created Last 30 ================

    2010-06-05 15:13:56 0 d-----w- c:\program files (x86)\ProcessScanner
    2010-06-05 12:55:25 0 d-----w- c:\programdata\Spybot - Search & Destroy
    2010-06-05 12:55:25 0 d-----w- c:\program files (x86)\Spybot - Search & Destroy
    2010-06-04 06:37:15 411368 ----a-w- c:\windows\syswow64\deployJava1.dll
    2010-06-04 06:37:15 153376 ----a-w- c:\windows\syswow64\javaws.exe
    2010-06-04 06:37:15 145184 ----a-w- c:\windows\syswow64\javaw.exe
    2010-06-04 06:37:15 145184 ----a-w- c:\windows\syswow64\java.exe
    2010-05-28 04:03:01 453456 ----a-w- c:\windows\syswow64\d3dx10_42.dll
    2010-05-28 04:02:58 1892184 ----a-w- c:\windows\syswow64\D3DX9_42.dll
    2010-05-28 00:09:00 41872 ----a-w- c:\windows\syswow64\xfcodec.dll
    2010-05-28 00:09:00 27536 ----a-w- c:\windows\system32\xfcodec64.dll
    2010-05-27 07:44:50 0 d-----w- c:\users\andrew\appdata\roaming\Mount&Blade
    2010-05-27 07:40:28 0 d-----w- c:\program files (x86)\Mount&Blade
    2010-05-25 23:29:44 2048 ----a-w- c:\windows\syswow64\tzres.dll
    2010-05-25 23:29:44 2048 ----a-w- c:\windows\system32\tzres.dll
    2010-05-18 02:41:37 0 d-----w- c:\users\andrew\.thumbnails
    2010-05-15 04:41:58 0 d-----w- c:\program files (x86)\Game_Maker6
    2010-05-12 05:31:19 974848 ----a-w- c:\windows\system32\inetcomm.dll
    2010-05-12 05:31:18 738816 ----a-w- c:\windows\syswow64\inetcomm.dll
    2010-05-10 04:12:06 0 d-----w- c:\program files (x86)\Visual Novel Trials
    2010-05-10 04:08:30 65536 --sha-w- c:\users\andrew\ntuser.dat{5148e5a6-5bc6-11df-9a49-0026222e6965}.TM.blf
    2010-05-10 04:08:30 524288 --sha-w- c:\users\andrew\ntuser.dat{5148e5a6-5bc6-11df-9a49-0026222e6965}.TMContainer00000000000000000002.regtrans-ms
    2010-05-10 04:08:30 524288 --sha-w- c:\users\andrew\ntuser.dat{5148e5a6-5bc6-11df-9a49-0026222e6965}.TMContainer00000000000000000001.regtrans-ms
    2010-05-09 02:05:33 0 d-----w- c:\program files (x86)\StickyNotes
    2010-05-08 05:05:41 0 d-----w- c:\program files (x86)\?star

    ==================== Find3M ====================

    2010-06-02 13:03:52 35536 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
    2010-06-02 13:03:52 317520 ----a-w- c:\windows\system32\drivers\avgtdia.sys
    2010-05-21 04:14:28 270208 ------w- c:\windows\system32\MpSigStub.exe
    2010-05-06 06:28:07 258352 ----a-w- c:\windows\syswow64\unicows.dll
    2010-04-29 05:39:28 24664 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-04-27 04:45:56 72856 ----a-w- c:\windows\syswow64\xliveinstallhost.exe
    2010-04-27 04:45:56 187544 ----a-w- c:\windows\syswow64\xliveinstall.dll
    2010-04-16 09:49:19 86016 ----a-w- c:\windows\inf\infstor.dat
    2010-04-16 09:49:19 51200 ----a-w- c:\windows\inf\infpub.dat
    2010-04-16 09:49:19 143360 ----a-w- c:\windows\inf\infstrng.dat
    2010-04-02 07:17:52 15426200 ----a-w- c:\windows\syswow64\xlive.dll
    2010-04-02 07:17:52 13642904 ----a-w- c:\windows\syswow64\xlivefnt.dll
    2010-03-31 01:58:04 72176 ------w- c:\windows\syswow64\pxhpinst.exe
    2010-03-31 01:58:04 678384 ------w- c:\windows\syswow64\px.dll
    2010-03-31 01:58:04 559600 ------w- c:\windows\syswow64\pxdrv.dll
    2010-03-31 01:58:04 440816 ------w- c:\windows\syswow64\pxwave.dll
    2010-03-31 01:58:04 219632 ------w- c:\windows\syswow64\pxmas.dll
    2010-03-31 01:58:04 100848 ------w- c:\windows\syswow64\vxblock.dll
    2010-03-30 10:06:51 178800 ----a-w- c:\windows\syswow64\CmdLineExt_x64.dll
    2010-03-30 09:11:24 108144 ----a-w- c:\windows\syswow64\CmdLineExt.dll
    2010-03-13 21:31:49 12976 ----a-w- c:\windows\system32\avgrssta.dll
    2010-03-08 17:59:18 94208 ----a-w- c:\windows\syswow64\dpl100.dll
    2009-12-06 06:17:14 665600 ----a-w- c:\windows\inf\drvindex.dat
    2008-01-21 03:21:59 174 --sha-w- c:\program files\desktop.ini
    2008-01-21 03:21:59 174 --sha-w- c:\program files (x86)\desktop.ini
    2006-11-02 15:14:56 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
    2006-11-02 15:14:56 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
    2006-11-02 15:14:56 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
    2006-11-02 15:14:56 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
    2006-11-02 10:52:12 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
    2006-11-02 10:52:12 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
    2006-11-02 10:52:10 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
    2006-11-02 10:52:10 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
    2009-10-17 08:38:49 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat

    ============= FINISH: 18:17:15.07 ===============


    Anything strange?

    I just got an email from Blizzard telling me my Warcraft password has been reset again. I DID NOT ASK THEM TO DO THAT!

    Can someone please help me out ASAP! I don't know what to do...
    Last edited by tashi; 2010-06-06 at 16:33. Reason: Merged two posts as per forum FAQ

  2. #2
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    Hi,

    Looks ok to me. The fact that all those apps you ran are clean is also good.
    Having two active anti-virus on a machine is not good. With AV two are not better than one. I would remove one via the add/remove programs panel.


    c:\users\andrew\program files (x86)\dna\btdna.exe
    You can uninstall this, its not necessary for running a torrent client, if you have or had one.
    How Can I Reduce My Risk?

  3. #3
    Junior Member
    Join Date
    Jun 2010
    Posts
    4

    Default

    Thanks for the reply!

    I can't seem to find the .exe you said I should remove. It doesn't seem to be in the directory you listed. Also, do I just delete it to remove it? Or does it need to be uninstalled?

  4. #4
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    Look in the add/remove programs panel for: dna
    and uninstall it from there first if present in the list.

    Useful information here.
    How Can I Reduce My Risk?

  5. #5
    Junior Member
    Join Date
    Jun 2010
    Posts
    4

    Default

    Thanks for the link.

    However nothing with DNA in it is on my programs list. I did a search with a program called SpaceMonger (which I have used to find previously hard-to-find files) and it can't locate it either.

    Any ideas?

  6. #6
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    If you dont see a folder called dna here: c:\users\andrew\program files (x86)\dna
    then i wouldnt worry about it. Its not malware.
    How Can I Reduce My Risk?

  7. #7
    Junior Member
    Join Date
    Jun 2010
    Posts
    4

    Default

    Yeah, I don't have the folder.

    Thanks for your help!

  8. #8
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    Logs look ok to me. Read this link if you havent already.
    Happy safe surfing
    How Can I Reduce My Risk?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •