luckywayne
New member
Hello,
It seems that I have picked up a virus that has installed a program called Windows protection Service. It ahs also taken control of my ability to view the task manager or run any executables without my system being in safe-mode. I also am having problems with internet searches as I am being redirected constantly.
I did run Spybot and also Malware on my maching before I posted here, the latter seemed to clean up the entries, however, it just reinstalls itself when I reboot.
Here is the DDS file that I just ran. I thank you in advance for any help that you can provide.
DDS (Ver_10-03-17.01) - NTFSx86
Run by Wayne at 17:35:54.09 on Thu 06/10/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1638 [GMT -4:00]
AV: Protection Center *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Tall Emu\Online Armor\oacat.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Documents and Settings\Wayne\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: Veoh Video Compass: {52836eb0-631a-47b1-94a6-61f9d9112dae} - c:\program files\veoh networks\veoh video compass\SearchRecsPlugin.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Google Update] "c:\documents and settings\wayne\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [VeohPlugin] "c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe"
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~1.EXE -Update -1103470 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.gamehouse.com/realarcade-webgames/ancientsudoku/index.jsp?pread=0&pread=0&ractype=fullclient"
mRun: [WinSys2] c:\windows\system32\winsys2.exe
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSN Toolbar] "c:\program files\msn toolbar\platform\4.0.0379.0\mswinext.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
IE: &AIM Toolbar Search - c:\documents and settings\all users\application data\aim toolbar\ietoolbar\resources\en-us\local\search.html
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} - hxxp://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab
DPF: {1D082E71-DF20-4AAF-863B-596428C49874} - hxxp://www.worldwinner.com/games/v50/tpir/tpir.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} - hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} - hxxp://www.worldwinner.com/games/v45/royal/royal.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} - hxxp://service.futuremark.com/virtualmark/tc/FMSI.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E12EB891-D000-421B-A8ED-EDE1BDCA14A0} - hxxp://www.worldwinner.com/games/v44/golfsol/golfsol.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/da2/PCPitStop2.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\wayne\applic~1\mozilla\firefox\profiles\kt7j57ki.default\
# Mozilla User Preferences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see hxxp://www.mozilla.org/unix/customizing.html#prefs
*/
user_pref(app.update.lastUpdateTime.addon-background-update-timer, 1242299186);
user_pref(app.update.lastUpdateTime.background-update-timer, 1242299186);
user_pref(app.update.lastUpdateTime.blocklist-background-update-timer, 1242299186);
user_pref(app.update.lastUpdateTime.microsummary-generator-update-timer, 1242299186);
user_pref(app.update.lastUpdateTime.search-engine-update-timer, 1242321386);
user_pref(browser.migration.version, 1);
user_pref(browser.places.importDefaults, false);
user_pref(browser.places.migratePostDataAnnotations, false);
user_pref(browser.places.smartBookmarksVersion, 1);
user_pref(browser.places.updateRecentTagsUri, false);
user_pref(browser.rights.3.shown, true);
user_pref(browser.startup.homepage_override.mstone, rv:1.9.0.10);
user_pref(extensions.enabledItems, {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,jqs@sun.com:1.0,{635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.2.20080717,moveplayer@movenetworks.com:7,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10);
user_pref(extensions.lastAppVersion, 3.0.10);
user_pref(extensions.update.notifyUser, false);
user_pref(intl.charsetmenu.browser.cache, ISO-8859-1, UTF-8);
user_pref(network.cookie.prefsMigrated, true);
user_pref(spellchecker.dictionary, en-US);
user_pref(urlclassifier.keyupdatetime.https://sb-ssl.google.com/safebrowsing/newkey, 1255473016);
user_pref(yahoo.addtomy, true);
user_pref(yahoo.homepage.dontask, true);
user_pref(yahoo.installer.country, us);
user_pref(yahoo.installer.dc, v1_yff2);
user_pref(yahoo.installer.language, us);
user_pref(yahoo.installer.nd, 2);
user_pref(yahoo.installer.sc, sunm);
user_pref(yahoo.installer.version, 1.5.2.20080717);
user_pref(yahoo.installer.version.simple, 1.5.2);
user_pref(yahoo.supports.livesearch, true);
user_pref(yahoo.toolbar.searchbox.width, 55);
FF - prefs.js: browser.search.selectedEngine - Yahoo!);
user_pref(browser.startup.homepage, http://bing.zugo.com/?cfg=2-79-0-1kCe3);
user_pref(keyword.URL, http://bing.zugo.com/s/?src=FF-Address&site=Bing&cfg=2-79-0-1kCe3&q=
FF - plugin: c:\documents and settings\wayne\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\wayne\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nppopcaploader.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2008-11-17 178376]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2008-11-17 30920]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [2008-11-17 28872]
R2 OAcat;Online Armor Helper Service;c:\program files\tall emu\online armor\oacat.exe [2008-11-17 1402568]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-9-11 24652]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2008-6-27 99352]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2008-6-27 555032]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2008-6-27 566296]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2008-6-27 99352]
S3 cpuz130;cpuz130;\??\c:\docume~1\wayne\locals~1\temp\cpuz130\cpuz_x32.sys --> c:\docume~1\wayne\locals~1\temp\cpuz130\cpuz_x32.sys [?]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2008-6-27 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2008-6-27 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2008-6-27 100888]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2008-6-27 566296]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-25 25832]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
S3 SvcOnlineArmor;Online Armor;c:\program files\tall emu\online armor\oasrv.exe [2008-11-17 3538632]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2009-9-14 85504]
=============== Created Last 30 ================
2010-06-10 21:00:24 54016 ----a-w- c:\windows\system32\drivers\gciaeh.sys
2010-06-10 20:44:45 0 d-----w- c:\docume~1\wayne\applic~1\Malwarebytes
2010-06-10 20:44:37 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-10 20:44:36 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-10 20:44:36 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-10 20:44:36 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-06-10 20:26:10 0 d-----w- c:\docume~1\alluse~1\applic~1\Toolbar4
2010-06-10 20:19:21 397 ----a-w- c:\windows\wininit.ini
2010-06-10 17:41:16 0 d-----w- c:\docume~1\wayne\applic~1\Pogo Games
2010-06-10 17:08:35 14 ----a-w- c:\windows\popcinfo.dat
2010-06-10 16:41:30 0 d-----w- c:\program files\Search Toolbar
2010-06-10 16:21:12 0 ----a-w- c:\windows\popcreg.dat
2010-06-10 16:21:11 18 ----a-w- c:\windows\popcinfot.dat
2010-06-08 17:08:27 9 ----a-w- c:\windows\sierra.ini
2010-06-08 17:08:26 0 d-----w- c:\program files\Sierra On-Line
2010-06-05 17:52:40 0 d-----w- c:\docume~1\wayne\applic~1\EA
2010-06-05 17:52:40 0 d-----w- c:\docume~1\alluse~1\applic~1\EA
2010-06-05 17:52:24 0 d-----w- c:\program files\Pogo To Go
2010-06-05 03:07:39 0 d-----w- c:\program files\ToGo Game
2010-06-03 19:44:01 0 d-----w- c:\docume~1\wayne\applic~1\funkitron
2010-06-03 19:42:09 0 d-----w- c:\windows\Slingo Mystery Whos Gold
2010-06-03 19:42:09 0 d-----w- c:\program files\Slingo Mystery Whos Gold
2010-05-23 08:38:28 0 d-----w- c:\program files\VideoLAN
2010-05-23 08:00:36 0 d-----w- c:\program files\Ask.com
2010-05-23 08:00:31 0 d-----w- c:\program files\common files\SourceTec
2010-05-19 15:49:40 0 d-----w- C:\Poker
==================== Find3M ====================
2010-03-16 07:37:50 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-03-16 07:37:50 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-03-16 07:37:50 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-03-16 07:37:50 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-03-16 07:37:50 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-03-16 07:37:44 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-03-16 06:51:59 6432128 ----a-w- c:\windows\system32\nv4_disp.dll
2010-03-16 06:51:59 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-03-16 06:51:59 600680 ----a-w- c:\windows\system32\nvudisp.exe
2010-03-16 06:51:59 4075520 ----a-w- c:\windows\system32\nvcuda.dll
2010-03-16 06:51:59 2646632 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-03-16 06:51:59 2183470 ----a-w- c:\windows\system32\nvdata.bin
2010-03-16 06:51:59 215656 ----a-w- c:\windows\system32\nvcodins.dll
2010-03-16 06:51:59 215656 ----a-w- c:\windows\system32\nvcod.dll
2010-03-16 06:51:59 2030184 ----a-w- c:\windows\system32\nvcuvid.dll
2010-03-16 06:51:59 14757888 ----a-w- c:\windows\system32\nvoglnt.dll
2010-03-16 06:51:59 11640832 ----a-w- c:\windows\system32\nvcompiler.dll
2010-03-16 06:51:59 1097728 ----a-w- c:\windows\system32\nvapi.dll
============= FINISH: 17:38:01.98 ===============
It seems that I have picked up a virus that has installed a program called Windows protection Service. It ahs also taken control of my ability to view the task manager or run any executables without my system being in safe-mode. I also am having problems with internet searches as I am being redirected constantly.
I did run Spybot and also Malware on my maching before I posted here, the latter seemed to clean up the entries, however, it just reinstalls itself when I reboot.
Here is the DDS file that I just ran. I thank you in advance for any help that you can provide.
DDS (Ver_10-03-17.01) - NTFSx86
Run by Wayne at 17:35:54.09 on Thu 06/10/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1638 [GMT -4:00]
AV: Protection Center *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Tall Emu\Online Armor\oacat.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Documents and Settings\Wayne\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: Veoh Video Compass: {52836eb0-631a-47b1-94a6-61f9d9112dae} - c:\program files\veoh networks\veoh video compass\SearchRecsPlugin.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Google Update] "c:\documents and settings\wayne\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [VeohPlugin] "c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe"
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~1.EXE -Update -1103470 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.gamehouse.com/realarcade-webgames/ancientsudoku/index.jsp?pread=0&pread=0&ractype=fullclient"
mRun: [WinSys2] c:\windows\system32\winsys2.exe
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSN Toolbar] "c:\program files\msn toolbar\platform\4.0.0379.0\mswinext.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
IE: &AIM Toolbar Search - c:\documents and settings\all users\application data\aim toolbar\ietoolbar\resources\en-us\local\search.html
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} - hxxp://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab
DPF: {1D082E71-DF20-4AAF-863B-596428C49874} - hxxp://www.worldwinner.com/games/v50/tpir/tpir.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} - hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} - hxxp://www.worldwinner.com/games/v45/royal/royal.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} - hxxp://service.futuremark.com/virtualmark/tc/FMSI.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E12EB891-D000-421B-A8ED-EDE1BDCA14A0} - hxxp://www.worldwinner.com/games/v44/golfsol/golfsol.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/da2/PCPitStop2.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\wayne\applic~1\mozilla\firefox\profiles\kt7j57ki.default\
# Mozilla User Preferences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see hxxp://www.mozilla.org/unix/customizing.html#prefs
*/
user_pref(app.update.lastUpdateTime.addon-background-update-timer, 1242299186);
user_pref(app.update.lastUpdateTime.background-update-timer, 1242299186);
user_pref(app.update.lastUpdateTime.blocklist-background-update-timer, 1242299186);
user_pref(app.update.lastUpdateTime.microsummary-generator-update-timer, 1242299186);
user_pref(app.update.lastUpdateTime.search-engine-update-timer, 1242321386);
user_pref(browser.migration.version, 1);
user_pref(browser.places.importDefaults, false);
user_pref(browser.places.migratePostDataAnnotations, false);
user_pref(browser.places.smartBookmarksVersion, 1);
user_pref(browser.places.updateRecentTagsUri, false);
user_pref(browser.rights.3.shown, true);
user_pref(browser.startup.homepage_override.mstone, rv:1.9.0.10);
user_pref(extensions.enabledItems, {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,jqs@sun.com:1.0,{635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.2.20080717,moveplayer@movenetworks.com:7,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10);
user_pref(extensions.lastAppVersion, 3.0.10);
user_pref(extensions.update.notifyUser, false);
user_pref(intl.charsetmenu.browser.cache, ISO-8859-1, UTF-8);
user_pref(network.cookie.prefsMigrated, true);
user_pref(spellchecker.dictionary, en-US);
user_pref(urlclassifier.keyupdatetime.https://sb-ssl.google.com/safebrowsing/newkey, 1255473016);
user_pref(yahoo.addtomy, true);
user_pref(yahoo.homepage.dontask, true);
user_pref(yahoo.installer.country, us);
user_pref(yahoo.installer.dc, v1_yff2);
user_pref(yahoo.installer.language, us);
user_pref(yahoo.installer.nd, 2);
user_pref(yahoo.installer.sc, sunm);
user_pref(yahoo.installer.version, 1.5.2.20080717);
user_pref(yahoo.installer.version.simple, 1.5.2);
user_pref(yahoo.supports.livesearch, true);
user_pref(yahoo.toolbar.searchbox.width, 55);
FF - prefs.js: browser.search.selectedEngine - Yahoo!);
user_pref(browser.startup.homepage, http://bing.zugo.com/?cfg=2-79-0-1kCe3);
user_pref(keyword.URL, http://bing.zugo.com/s/?src=FF-Address&site=Bing&cfg=2-79-0-1kCe3&q=
FF - plugin: c:\documents and settings\wayne\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\wayne\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nppopcaploader.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2008-11-17 178376]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2008-11-17 30920]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [2008-11-17 28872]
R2 OAcat;Online Armor Helper Service;c:\program files\tall emu\online armor\oacat.exe [2008-11-17 1402568]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-9-11 24652]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2008-6-27 99352]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2008-6-27 555032]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2008-6-27 566296]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2008-6-27 99352]
S3 cpuz130;cpuz130;\??\c:\docume~1\wayne\locals~1\temp\cpuz130\cpuz_x32.sys --> c:\docume~1\wayne\locals~1\temp\cpuz130\cpuz_x32.sys [?]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2008-6-27 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2008-6-27 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2008-6-27 100888]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2008-6-27 566296]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-25 25832]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
S3 SvcOnlineArmor;Online Armor;c:\program files\tall emu\online armor\oasrv.exe [2008-11-17 3538632]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2009-9-14 85504]
=============== Created Last 30 ================
2010-06-10 21:00:24 54016 ----a-w- c:\windows\system32\drivers\gciaeh.sys
2010-06-10 20:44:45 0 d-----w- c:\docume~1\wayne\applic~1\Malwarebytes
2010-06-10 20:44:37 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-10 20:44:36 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-10 20:44:36 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-10 20:44:36 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-06-10 20:26:10 0 d-----w- c:\docume~1\alluse~1\applic~1\Toolbar4
2010-06-10 20:19:21 397 ----a-w- c:\windows\wininit.ini
2010-06-10 17:41:16 0 d-----w- c:\docume~1\wayne\applic~1\Pogo Games
2010-06-10 17:08:35 14 ----a-w- c:\windows\popcinfo.dat
2010-06-10 16:41:30 0 d-----w- c:\program files\Search Toolbar
2010-06-10 16:21:12 0 ----a-w- c:\windows\popcreg.dat
2010-06-10 16:21:11 18 ----a-w- c:\windows\popcinfot.dat
2010-06-08 17:08:27 9 ----a-w- c:\windows\sierra.ini
2010-06-08 17:08:26 0 d-----w- c:\program files\Sierra On-Line
2010-06-05 17:52:40 0 d-----w- c:\docume~1\wayne\applic~1\EA
2010-06-05 17:52:40 0 d-----w- c:\docume~1\alluse~1\applic~1\EA
2010-06-05 17:52:24 0 d-----w- c:\program files\Pogo To Go
2010-06-05 03:07:39 0 d-----w- c:\program files\ToGo Game
2010-06-03 19:44:01 0 d-----w- c:\docume~1\wayne\applic~1\funkitron
2010-06-03 19:42:09 0 d-----w- c:\windows\Slingo Mystery Whos Gold
2010-06-03 19:42:09 0 d-----w- c:\program files\Slingo Mystery Whos Gold
2010-05-23 08:38:28 0 d-----w- c:\program files\VideoLAN
2010-05-23 08:00:36 0 d-----w- c:\program files\Ask.com
2010-05-23 08:00:31 0 d-----w- c:\program files\common files\SourceTec
2010-05-19 15:49:40 0 d-----w- C:\Poker
==================== Find3M ====================
2010-03-16 07:37:50 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-03-16 07:37:50 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-03-16 07:37:50 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-03-16 07:37:50 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-03-16 07:37:50 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-03-16 07:37:44 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-03-16 06:51:59 6432128 ----a-w- c:\windows\system32\nv4_disp.dll
2010-03-16 06:51:59 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-03-16 06:51:59 600680 ----a-w- c:\windows\system32\nvudisp.exe
2010-03-16 06:51:59 4075520 ----a-w- c:\windows\system32\nvcuda.dll
2010-03-16 06:51:59 2646632 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-03-16 06:51:59 2183470 ----a-w- c:\windows\system32\nvdata.bin
2010-03-16 06:51:59 215656 ----a-w- c:\windows\system32\nvcodins.dll
2010-03-16 06:51:59 215656 ----a-w- c:\windows\system32\nvcod.dll
2010-03-16 06:51:59 2030184 ----a-w- c:\windows\system32\nvcuvid.dll
2010-03-16 06:51:59 14757888 ----a-w- c:\windows\system32\nvoglnt.dll
2010-03-16 06:51:59 11640832 ----a-w- c:\windows\system32\nvcompiler.dll
2010-03-16 06:51:59 1097728 ----a-w- c:\windows\system32\nvapi.dll
============= FINISH: 17:38:01.98 ===============