Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

more trojan battling


  • This topic is locked This topic is locked
22 replies to this topic

#1 bouncepass

bouncepass

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 27 November 2012 - 10:47 PM

Hello,

Ive been free from problems for awhile now after the great "gringo" helped me last time.

I got malware bytes pro and its been great. lately tho ive been getting blocked ip messages when im running protection mode. when i look the ip up its always some ad or dictionary attack site that seems to come up for that ip.

also, when i boot up my computer i was getting a win32.exe error (guessing it was some other malware trying to load that i had removed.)

i ran combofix recently and it found a couple things and removed them. however im still getting blocked ip's with malware bytes. hopefully someone can help me remove any remaining trojans/malware on my system.

thanks!

BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 40,238 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:47 PM

Posted 02 December 2012 - 01:04 PM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.
===

Please download and run this DDS Scanning Tool. Nothing will be deleted. It will just give me some additional information about your system.

  • Download DDS by sUBs from one of the following links if you no longer have it available. Save it to your desktop.
    • DDS.scr <- not recommended if you use Chrome to download this .scr file. Use the other options.
    • DDS.pif
    • DDS.COM
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
Please note: You may have to disable any script protection running if the scan fails to run.

Posted Image

Please just paste the contents of the DDS.txt log in your next post. DO NOT attach the log.

===

Third party programs if not up to date can be an open door for an infection.

Please run this security check for my review.

Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===

Search for AdWare, PUP (Potentially Unwanted Program) installed on your computer.

Please download AdwCleaner by Xplode onto your Desktop.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Rn].txt (n is a number).

Please post the logs for my review and let me know what problem persists.

#3 bouncepass

bouncepass
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 02 December 2012 - 03:06 PM

thanks for helping me on this issue. i also have a laptop that i ran combofix on last night, it found 4 or 5 things and removed them. can i also go through these steps and post my laptop results as well? or should i open a new thread for that?

here are my logs for my desktop

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.9.2
Run by vagprotector at 14:55:38 on 2012-12-02
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2582 [GMT -5:00]
.
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\PANDORA.TV\PanService\PandoraService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\BitTorrent_DNA\dna.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
BHO: Octh Class: {000123B4-9B42-4900-B3F7-F4B073EFC214} - c:\program files\orbitdownloader\orbitcth.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Grab Pro: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - c:\program files\orbitdownloader\GrabPro.dll
TB: Grab Pro: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - c:\program files\orbitdownloader\GrabPro.dll
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [BitTorrent DNA] "c:\program files\bittorrent_dna\dna.exe"
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
uPolicies-Explorer: NoDriveTypeAutoRun = dword:323
uPolicies-Explorer: NoDriveAutoRun = dword:67108863
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDrives = dword:0
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
IE: &Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1340835013421
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1340835005781
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{3BCA52DE-FED7-4D06-94E3-41594710B0BC} : NameServer = 192.168.2.1
TCP: Interfaces\{A2183A37-7625-4EE3-80DD-B9C6ECD5D948} : NameServer = 192.168.0.1
TCP: Interfaces\{D3388FB7-F2E7-4B21-AF12-85FD37379872} : NameServer = 192.168.0.1
TCP: Interfaces\{EA6BE12C-53F8-4E68-9EE7-DEF3F607E5F5} : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{EA9C357F-4A5B-4DDD-BCE1-360FCE647674} : NameServer = 192.168.0.1
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\vagprotector\application data\mozilla\firefox\profiles\jw81ev1c.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - plugin: c:\documents and settings\vagprotector\local settings\application data\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\program files\bittorrent_dna\npbtdna.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\tvuplayer\npTVUAx.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1167637.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_110.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
.
============= SERVICES / DRIVERS ===============
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-5-28 242240]
R2 ASFIPmon;Broadcom ASF IP Monitor;c:\program files\broadcom\asfipmon\AsfIpMon.exe [2005-3-8 61440]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2012-9-12 399432]
R2 PanService;PandoraService;c:\program files\pandora.tv\panservice\PandoraService.exe [2012-7-18 625816]
S2 Ca533av;Icatch(IV) Video Camera Device;c:\windows\system32\drivers\ca533av.sys --> c:\windows\system32\drivers\Ca533av.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-1-13 676936]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-1-13 22856]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2012-6-27 27064]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== File Associations ===============
.
FileExt: .txt: Applications\EditPadLite.exe="c:\program files\jgsoft\editpadlite\EditPadLite.exe" "%1" [UserChoice]
.
=============== Created Last 30 ================
.
2012-12-02 07:36:08 -------- d-----w- c:\program files\common files\DivX Shared
2012-12-02 07:35:57 -------- d-----w- c:\program files\DivX
2012-12-02 07:35:27 -------- d-----w- c:\documents and settings\all users\application data\DivX
2012-11-26 23:10:31 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll
2012-11-26 23:10:31 21504 ----a-w- c:\windows\system32\hidserv.dll
2012-11-13 20:29:04 354216 ----a-w- c:\windows\system32\DivXControlPanelApplet.cpl
.
==================== Find3M ====================
.
2012-12-01 15:26:49 119296 ----a-w- c:\windows\system32\zlib.dll
2012-11-21 02:12:54 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-11-21 02:12:53 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-04 21:56:43 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-04 21:56:43 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2012-09-30 04:27:01 1094980 ----a-w- c:\windows\system32\nvdrsdb1.bin
2012-09-30 04:27:01 1 ----a-w- c:\windows\system32\nvdrssel.bin
2012-09-30 04:26:58 1094980 ----a-w- c:\windows\system32\nvdrsdb0.bin
2012-09-29 23:54:26 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-28 19:54:39 163600 ----a-w- c:\windows\system32\wmaudsdk.dll
2012-09-25 03:16:36 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-22 23:17:21 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-22 23:17:21 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-17 20:42:36 1409 ----a-w- c:\windows\QTFont.for
2011-11-19 03:00:08 58668 --sha-w- c:\windows\pdesrv2.exe
.
============= FINISH: 14:56:27.57 ===============

Results of screen317's Security Check version 0.99.56
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.65.1.1000
CCleaner
TweakNow RegCleaner Professional
JavaFX 2.1.1
Java™ 6 Update 29
Java 7 Update 9
Adobe Flash Player 11.5.502.110
Mozilla Firefox 16.0.2 Firefox out of Date!
````````Process Check: objlist.exe by Laurent````````
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 35% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````


# AdwCleaner v2.010 - Logfile created 12/02/2012 at 15:02:50
# Updated 29/11/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : vagprotector - JIMMY-DE0C57A72
# Boot Mode : Normal
# Running from : C:\Documents and Settings\vagprotector\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\Documents and Settings\All Users\Application Data\Ask

***** [Registry] *****

Key Found : HKCU\Software\APN PIP
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Found : HKCU\Software\PIP
Key Found : HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\Classes\AppID\BHO.DLL
Key Found : HKLM\Software\Orbit\OpenCandy
Key Found : HKLM\Software\PIP
Key Found : HKU\S-1-5-21-776561741-1788223648-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v16.0.2 (en-US)

Profile name : default
File : C:\Documents and Settings\vagprotector\Application Data\Mozilla\Firefox\Profiles\jw81ev1c.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v23.0.1271.95

File : C:\Documents and Settings\vagprotector\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

-\\ Opera v12.11.1661.0

File : C:\Documents and Settings\vagprotector\Application Data\Opera\Opera\operaprefs.ini

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [1728 octets] - [02/12/2012 15:02:50]

########## EOF - C:\AdwCleaner[R1].txt - [1788 octets] ##########

#4 nasdaq

nasdaq

  • Malware Response Team
  • 40,238 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:47 PM

Posted 03 December 2012 - 08:54 AM

Remove this old version of Java™ 6 Update 29 using the Add/Remove programs applet.

===

Remove the AdWare, PUP (Potentially Unwanted Program) installed on your computer.

  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Everything that was found will be deleted.
  • Follow the prompts to reboot the computer. A text file will open after the restart.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Sn].txt (n is a number)..
===

Post the logs and let me know what problem persists.

As for the other Computer please start a new topic and run the DDS, Security Check and AdwCleraner tools on the Laptop.
Post the URL in your next reply and I will expedite the matter.

#5 bouncepass

bouncepass
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 04 December 2012 - 06:16 PM

thnx. my laptop has actually been pretty normal. ill worry about that at another time.

i get a bunch of fatal error messages when i try to delete Java™ 6 Update 29

heres my log after running the delete function in adwcleaner.

# AdwCleaner v2.011 - Logfile created 12/04/2012 at 18:09:45
# Updated 02/12/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : vagprotector - JIMMY-DE0C57A72
# Boot Mode : Normal
# Running from : C:\Documents and Settings\vagprotector\Desktop\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Documents and Settings\All Users\Application Data\Ask

***** [Registry] *****

Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Deleted : HKCU\Software\PIP
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Classes\AppID\BHO.DLL
Key Deleted : HKLM\Software\Orbit\OpenCandy
Key Deleted : HKLM\Software\PIP

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v16.0.2 (en-US)

Profile name : default
File : C:\Documents and Settings\vagprotector\Application Data\Mozilla\Firefox\Profiles\jw81ev1c.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v23.0.1271.95

File : C:\Documents and Settings\vagprotector\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

-\\ Opera v12.11.1661.0

File : C:\Documents and Settings\vagprotector\Application Data\Opera\Opera\operaprefs.ini

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [1857 octets] - [02/12/2012 15:02:50]
AdwCleaner[S1].txt - [1657 octets] - [04/12/2012 18:09:45]

########## EOF - C:\AdwCleaner[S1].txt - [1717 octets] ##########

#6 nasdaq

nasdaq

  • Malware Response Team
  • 40,238 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:47 PM

Posted 05 December 2012 - 09:18 AM

Run this tool to remove all traces of Java 6 Update 29

===

Revo Uninstaller helps you to remove any unwanted application installed on your computer.

Download Revo Uninstaller and remove any programs you are having difficulties in completing the removal using the Add/Remove Programs list.

http://majorgeeks.com/Revo_Uninstaller_d5706.html

Let me know of any remaining issues with this computer.

#7 bouncepass

bouncepass
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 05 December 2012 - 10:07 PM

ok, i uninstalled with revo, but still getting the same malicious ips blocked in malware bytes

#8 nasdaq

nasdaq

  • Malware Response Team
  • 40,238 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:47 PM

Posted 06 December 2012 - 09:23 AM

I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Check Posted Image
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image

If the problem persists continue.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2


If your operating system is 64 bit download this tool:
SystemLook_x64.exe
  • Double-click SystemLook.exe to run it.
  • Copy and paste the content of the following bold text into the main textfield:


    :filefind
    win32.exe

    :regfind
    win32.exe

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

#9 bouncepass

bouncepass
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 06 December 2012 - 06:10 PM

i forgot to export the report with eset, but it did find a couple things and i deleted them.

im still having the same issues tho with the blocked ips in malwarebytes

let me know if you need me to run eset again for you, it took a couple hours so hopefully that isnt nessecary.

heres my system look report;

SystemLook 30.07.11 by jpshortstuff
Log created at 18:04 on 06/12/2012 by vagprotector
Administrator - Elevation successful

========== filefind ==========

Searching for "win32.exe"
No files found.

========== regfind ==========

Searching for "win32.exe"
No data found.

-= EOF =-

#10 nasdaq

nasdaq

  • Malware Response Team
  • 40,238 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:47 PM

Posted 07 December 2012 - 09:18 AM

Try this.

Launch Notepad, and copy/paste all the blue instructions below to it.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains]


Then, disconnect from the Internet!
Next,
Back on the Desktop, double-click on the fixme.reg file you just saved and click on Yes when asked to merge the information.

#11 bouncepass

bouncepass
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 07 December 2012 - 06:55 PM

done

#12 nasdaq

nasdaq

  • Malware Response Team
  • 40,238 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:47 PM

Posted 08 December 2012 - 09:03 AM

If still getting this type of message
Malwarebyte's Anti-Malware has successfully blocked access to malicious IP: 81.169.145.87

Please post the IP address following IP: for my review.

#13 bouncepass

bouncepass
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 08 December 2012 - 05:01 PM

yes im still getting blocked ips

seems everything is still as it was since my original post.

2012/12/08 01:59:39 -0500 JIMMY-DE0C57A72 vagprotector MESSAGE Starting protection
2012/12/08 01:59:39 -0500 JIMMY-DE0C57A72 vagprotector MESSAGE Protection started successfully
2012/12/08 01:59:39 -0500 JIMMY-DE0C57A72 vagprotector MESSAGE Starting IP protection
2012/12/08 01:59:51 -0500 JIMMY-DE0C57A72 vagprotector MESSAGE IP Protection started successfully
2012/12/08 02:04:36 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 93.103.86.86 (Type: incoming)
2012/12/08 02:09:33 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.33.114 (Type: incoming)
2012/12/08 02:12:40 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 212.113.46.104 (Type: outgoing)
2012/12/08 02:13:28 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.52.208 (Type: outgoing)
2012/12/08 02:16:21 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 178.152.15.158 (Type: incoming)
2012/12/08 02:22:46 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.248.172.103 (Type: incoming)
2012/12/08 02:28:43 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 58.240.130.146 (Type: incoming)
2012/12/08 02:39:43 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.64.6.224 (Type: incoming)
2012/12/08 02:39:44 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.64.6.224 (Type: incoming)
2012/12/08 03:37:48 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 91.188.43.222 (Type: incoming)
2012/12/08 03:43:41 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.65.76.21 (Type: incoming)
2012/12/08 03:45:22 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.2.45 (Type: incoming)
2012/12/08 04:08:27 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 31.133.60.87 (Type: outgoing)
2012/12/08 04:09:29 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.65.186.199 (Type: incoming)
2012/12/08 04:10:56 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.117.139 (Type: incoming)
2012/12/08 04:22:14 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.114.201 (Type: outgoing)
2012/12/08 04:23:03 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 31.133.40.227 (Type: outgoing)
2012/12/08 04:31:17 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.35.67 (Type: incoming)
2012/12/08 04:38:06 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 91.188.49.185 (Type: incoming)
2012/12/08 04:42:05 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.65.76.21 (Type: incoming)
2012/12/08 04:49:48 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 220.248.177.9 (Type: incoming)
2012/12/08 04:50:01 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:50:19 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:50:26 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:50:34 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:50:34 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:51:04 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:51:05 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:51:09 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:51:10 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:51:23 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:51:24 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:51:32 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:51:33 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:51:46 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:51:56 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:51:57 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:52:12 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:52:12 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.70.152.204 (Type: incoming)
2012/12/08 04:52:21 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 98.142.247.124 (Type: outgoing)
2012/12/08 05:31:29 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.64.38.92 (Type: incoming)
2012/12/08 05:40:14 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.33.114 (Type: incoming)
2012/12/08 05:50:47 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: outgoing)
2012/12/08 05:53:22 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 91.188.63.187 (Type: incoming)
2012/12/08 05:53:38 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 78.26.187.196 (Type: incoming)
2012/12/08 06:07:39 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: outgoing)
2012/12/08 06:08:25 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.33.114 (Type: incoming)
2012/12/08 06:25:56 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 109.86.183.240 (Type: incoming)
2012/12/08 06:34:39 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: incoming)
2012/12/08 06:45:00 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.65.76.21 (Type: incoming)
2012/12/08 06:49:43 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: incoming)
2012/12/08 06:54:47 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.30.16 (Type: incoming)
2012/12/08 07:04:37 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: incoming)
2012/12/08 07:05:37 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 218.8.67.148 (Type: outgoing)
2012/12/08 07:05:49 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.3.182 (Type: outgoing)
2012/12/08 07:19:54 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: incoming)
2012/12/08 07:20:02 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: outgoing)
2012/12/08 07:25:12 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: incoming)
2012/12/08 07:33:08 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.248.172.103 (Type: incoming)
2012/12/08 07:33:51 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: outgoing)
2012/12/08 07:49:48 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: incoming)
2012/12/08 07:54:07 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: incoming)
2012/12/08 08:00:00 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 91.195.10.4 (Type: incoming)
2012/12/08 08:07:52 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: incoming)
2012/12/08 08:10:39 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 58.240.74.236 (Type: incoming)
2012/12/08 08:18:55 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 213.182.202.94 (Type: outgoing)
2012/12/08 08:32:13 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.60.109 (Type: incoming)
2012/12/08 08:35:19 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: incoming)
2012/12/08 08:50:33 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: incoming)
2012/12/08 09:18:05 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 58.240.211.67 (Type: incoming)
2012/12/08 09:20:36 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.98.86 (Type: outgoing)
2012/12/08 09:20:46 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 213.5.70.58 (Type: outgoing)
2012/12/08 09:35:00 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.76.31.143 (Type: outgoing)
2012/12/08 09:40:21 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 31.133.40.102 (Type: incoming)
2012/12/08 09:45:59 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 178.152.5.21 (Type: incoming)
2012/12/08 09:46:59 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 218.10.63.133 (Type: incoming)
2012/12/08 09:51:20 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.248.172.103 (Type: incoming)
2012/12/08 09:52:01 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 178.90.88.10 (Type: outgoing)
2012/12/08 09:52:06 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 212.117.174.138 (Type: outgoing)
2012/12/08 09:56:05 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.2.45 (Type: incoming)
2012/12/08 10:19:57 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: outgoing)
2012/12/08 10:20:51 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.64.124.92 (Type: outgoing)
2012/12/08 10:32:25 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.248.172.103 (Type: incoming)
2012/12/08 10:35:40 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.52.57 (Type: outgoing)
2012/12/08 10:52:58 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: incoming)
2012/12/08 11:00:56 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 77.78.231.219 (Type: incoming)
2012/12/08 11:04:09 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 195.174.111.204 (Type: incoming)
2012/12/08 11:04:38 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.41.35 (Type: incoming)
2012/12/08 11:05:53 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 79.135.139.38 (Type: incoming)
2012/12/08 11:06:43 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.76.24.58 (Type: outgoing)
2012/12/08 11:07:12 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: outgoing)
2012/12/08 11:16:21 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: incoming)
2012/12/08 11:22:04 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.27.129 (Type: outgoing)
2012/12/08 11:22:04 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.120.169 (Type: outgoing)
2012/12/08 11:24:04 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 77.247.182.241 (Type: incoming)
2012/12/08 11:52:08 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 95.58.99.1 (Type: outgoing)
2012/12/08 12:20:22 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: outgoing)
2012/12/08 12:24:26 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 218.7.221.64 (Type: incoming)
2012/12/08 12:24:36 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 218.7.221.64 (Type: incoming)
2012/12/08 12:34:05 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.76.154.82 (Type: outgoing)
2012/12/08 12:34:10 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: outgoing)
2012/12/08 12:40:19 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.33.114 (Type: incoming)
2012/12/08 13:01:49 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: incoming)
2012/12/08 13:03:04 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: outgoing)
2012/12/08 13:19:54 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 217.23.13.213 (Type: outgoing)
2012/12/08 13:32:46 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: incoming)
2012/12/08 13:33:30 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 77.78.237.237 (Type: outgoing)
2012/12/08 13:33:44 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: outgoing)
2012/12/08 13:48:48 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: incoming)
2012/12/08 13:51:45 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.65.96.222 (Type: incoming)
2012/12/08 13:51:46 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.65.96.222 (Type: incoming)
2012/12/08 14:03:44 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: outgoing)
2012/12/08 14:17:14 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 194.143.137.158 (Type: outgoing)
2012/12/08 14:30:25 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: incoming)
2012/12/08 14:34:16 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: outgoing)
2012/12/08 14:34:54 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.48.203 (Type: outgoing)
2012/12/08 14:50:22 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.69.217.198 (Type: outgoing)
2012/12/08 14:50:26 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: incoming)
2012/12/08 15:04:18 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.2.45 (Type: incoming)
2012/12/08 15:10:20 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.33.114 (Type: incoming)
2012/12/08 15:21:11 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.76.23.231 (Type: outgoing)
2012/12/08 15:33:27 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 31.133.52.183 (Type: incoming)
2012/12/08 15:33:49 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: incoming)
2012/12/08 15:34:11 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 31.133.53.88 (Type: incoming)
2012/12/08 15:34:24 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: outgoing)
2012/12/08 15:39:54 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.33.114 (Type: incoming)
2012/12/08 15:44:29 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 31.133.52.0 (Type: incoming)
2012/12/08 15:46:41 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.2.92 (Type: incoming)
2012/12/08 15:49:53 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 31.133.41.117 (Type: incoming)
2012/12/08 15:49:54 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: incoming)
2012/12/08 15:55:27 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 114.79.151.126 (Type: incoming)
2012/12/08 16:01:41 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.71.211.112 (Type: incoming)
2012/12/08 16:01:41 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 222.71.211.112 (Type: incoming)
2012/12/08 16:04:06 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: incoming)
2012/12/08 16:04:12 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 178.152.6.15 (Type: outgoing)
2012/12/08 16:06:11 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.2.45 (Type: incoming)
2012/12/08 16:14:18 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.99.118 (Type: incoming)
2012/12/08 16:16:37 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 77.247.182.241 (Type: outgoing)
2012/12/08 16:21:36 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: incoming)
2012/12/08 16:28:35 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.23.154 (Type: incoming)
2012/12/08 16:32:23 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 114.201.43.84 (Type: incoming)
2012/12/08 16:47:56 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: outgoing)
2012/12/08 16:48:10 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 188.130.177.2 (Type: outgoing)
2012/12/08 16:52:51 -0500 JIMMY-DE0C57A72 vagprotector IP-BLOCK 89.28.79.142 (Type: incoming)

#14 nasdaq

nasdaq

  • Malware Response Team
  • 40,238 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:47 PM

Posted 09 December 2012 - 10:49 AM

Try this.

How to reset Internet Protocol (TCP/IP)
http://support.microsoft.com/kb/299357

Use the Fix It button one the page.
===

If that fails to stop the IP blocking continue.


  • Download OTL to your Desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    %systemroot%\system32\drivers\*.sys /90
    %systemroot%\*. /mp /s
    c:\$recycle.bin\*.* /s
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    explorer.exe
    svchost.exe
    userinit.exe
    qmgr.dll
    proquota.exe
    kernel32.dll
    ndis.sys
    autochk.exe
    spoolsv.exe
    xmlprov.dll
    ntmssvc.dll
    mswsock.dll
    Beep.SYS
    ntfs.sys
    termsrv.dll
    sfcfiles.dll
    st3shark.sys
    ahcix86.sys
    srsvc.dll
    /md5stop
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
===

#15 bouncepass

bouncepass
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 09 December 2012 - 03:09 PM

ok, here are my scan results. just a quick question, ive been having this problem for awhile should i use a file age longer than 30 days?

OTL logfile created on: 12/9/2012 3:00:36 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\vagprotector\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.49 Gb Available Physical Memory | 83.00% Memory free
8.84 Gb Paging File | 8.50 Gb Available in Paging File | 96.12% Paging File free
Paging file location(s): C:\pagefile.sys 0 0E:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 1.05 Gb Free Space | 2.81% Space Free | Partition Type: NTFS
Drive D: | 6.08 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 465.76 Gb Total Space | 59.48 Gb Free Space | 12.77% Space Free | Partition Type: NTFS

Computer Name: JIMMY-DE0C57A72 | User Name: vagprotector | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\vagprotector\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\BitTorrent_DNA\dna.exe ()
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\PANDORA.TV\PanService\PandoraService.exe (Pandora.TV)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe (Broadcom Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files\BitTorrent_DNA\dna.exe ()
MOD - C:\Program Files\PANDORA.TV\PanService\avformat-53.dll ()
MOD - C:\Program Files\PANDORA.TV\PanService\avcodec-53.dll ()
MOD - C:\Program Files\PANDORA.TV\PanService\libupnp.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\PANDORA.TV\PanService\avutil-51.dll ()
MOD - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (nvUpdatusService) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (PanService) -- C:\Program Files\PANDORA.TV\PanService\PandoraService.exe (Pandora.TV)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (PinnacleUpdateSvc) -- C:\Program Files\PowerUp Software\Pinnacle Game Profiler\pinnacle_updater.exe (PowerUp Software, LLC)
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (NMSAccess) -- C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (ASFIPmon) -- C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe (Broadcom Corporation)
SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (WDICA) -- File not found
DRV - (USBCamera) -- System32\Drivers\Bulk533.sys File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (catchme) -- C:\DOCUME~1\VAGPRO~1\LOCALS~1\Temp\catchme.sys File not found
DRV - (CA561) -- System32\Drivers\SPCA561.SYS File not found
DRV - (Ca533av) -- System32\Drivers\Ca533av.sys File not found
DRV - (aeaudio) -- system32\drivers\aeaudio.sys File not found
DRV - (MBAMProtector) -- C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (dtsoftbus01) -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (Revoflt) -- C:\WINDOWS\system32\drivers\revoflt.sys (VS Revo Group)
DRV - (StarOpen) -- C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (motmodem) -- C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (BLKWGU(Belkin) -- C:\WINDOWS\system32\drivers\BLKWGU.sys (Belkin Corporation)
DRV - (ZDPSp50) -- C:\WINDOWS\system32\drivers\ZDPSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (senfilt) -- C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (BASFND) -- C:\Program Files\Broadcom\ASFIPMon\BASFND.sys (Broadcom Corporation)
DRV - (ASPI32) -- C:\WINDOWS\System32\drivers\Aspi32.sys (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\BitTorrent_DNA\npbtdna.dll (BitTorrent, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\vagprotector\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\vagprotector\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/12/06 22:38:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/12/06 22:37:44 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{75B3D99E-9DC9-11E1-826F-B8AC6F996F26}: C:\Documents and Settings\vagprotector\Local Settings\Application Data\{75B3D99E-9DC9-11E1-826F-B8AC6F996F26}\

[2012/07/05 10:23:20 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\vagprotector\Application Data\Mozilla\Extensions
[2012/10/22 19:09:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\vagprotector\Application Data\Mozilla\Firefox\Profiles\jw81ev1c.default\extensions
[2012/09/29 19:27:06 | 000,003,793 | ---- | M] () (No name found) -- C:\Documents and Settings\vagprotector\Application Data\Mozilla\Firefox\Profiles\jw81ev1c.default\extensions\{66E978CD-981F-47DF-AC42-E3CF417C1467}.xpi
[2012/12/06 22:37:40 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/12/06 22:38:00 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007/08/29 16:47:44 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\mozilla firefox\plugins\npbittorrent.dll
[2012/09/11 16:00:15 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/13 03:19:03 | 000,002,058 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\vagprotector\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\vagprotector\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\vagprotector\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\vagprotector\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: QuickTime Plug-in 6.3 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 6.3 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 6.3 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 6.3 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 6.3 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 6.3 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\vagprotector\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Program Files\TVUPlayer\npTVUAx.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\vagprotector\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\vagprotector\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Documents and Settings\vagprotector\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/11/27 19:29:36 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\BitTorrent_DNA\dna.exe ()
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1340835013421 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1340835005781 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3BCA52DE-FED7-4D06-94E3-41594710B0BC}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EA6BE12C-53F8-4E68-9EE7-DEF3F607E5F5}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/01/10 19:29:45 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2011/08/10 20:29:24 | 000,000,047 | R--- | M] () - D:\Autorun.inf -- [ UDF ]
O32 - AutoRun File - [2011/08/10 20:29:24 | 000,247,696 | R--- | M] (Konami Digital Entertainment Co., Ltd.) - D:\autorun.exe -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

========== Files/Folders - Created Within 30 Days ==========

[2012/12/09 14:57:58 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\vagprotector\Desktop\OTL.exe
[2012/12/08 21:33:37 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\vagprotector\Recent
[2012/12/08 18:13:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\vagprotector\Application Data\IonFx
[2012/12/08 18:12:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\GOG.com
[2012/12/06 22:37:39 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012/12/06 13:35:14 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/12/06 13:35:04 | 002,322,184 | ---- | C] (ESET) -- C:\Documents and Settings\vagprotector\Desktop\esetsmartinstaller_enu.exe
[2012/12/06 03:39:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\vagprotector\Desktop\temp ram
[2012/12/05 20:50:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\vagprotector\Start Menu\Programs\Revo Uninstaller
[2012/12/05 20:28:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\vagprotector\Application Data\DivX
[2012/12/02 14:54:46 | 000,688,992 | R--- | C] (Swearware) -- C:\Documents and Settings\vagprotector\Desktop\dds.exe
[2012/12/02 02:36:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\DivX Plus
[2012/12/02 02:36:08 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DivX Shared
[2012/12/02 02:35:57 | 000,000,000 | ---D | C] -- C:\Program Files\DivX
[2012/12/02 02:35:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DivX
[2012/11/27 22:17:26 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/11/26 18:10:31 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidserv.dll
[2012/11/13 15:29:04 | 000,354,216 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\DivXControlPanelApplet.cpl
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\NetworkService\Local Settings\Application Data\*.tmp files -> C:\Documents and Settings\NetworkService\Local Settings\Application Data\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/12/09 14:59:12 | 000,501,382 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/12/09 14:59:12 | 000,087,288 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/12/09 14:57:59 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\vagprotector\Desktop\OTL.exe
[2012/12/09 14:56:49 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/12/09 14:55:08 | 000,119,296 | ---- | M] () -- C:\WINDOWS\System32\zlib.dll
[2012/12/09 14:54:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/12/09 14:52:17 | 000,650,240 | ---- | M] () -- C:\Documents and Settings\vagprotector\Desktop\MicrosoftFixit50199.msi
[2012/12/09 14:37:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/12/09 14:14:00 | 000,001,006 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-776561741-1788223648-725345543-1003UA.job
[2012/12/09 04:17:29 | 000,104,960 | ---- | M] () -- C:\Documents and Settings\vagprotector\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/12/09 02:14:00 | 000,000,954 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-776561741-1788223648-725345543-1003Core.job
[2012/12/08 18:12:42 | 000,000,638 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Miasmata.lnk
[2012/12/08 01:58:27 | 116,912,124 | ---- | M] () -- C:\Documents and Settings\vagprotector\Desktop\Howard Stern - CF64K - 12-05-12 [WDM].mp3
[2012/12/08 01:58:00 | 099,952,220 | ---- | M] () -- C:\Documents and Settings\vagprotector\Desktop\Back Office Radio - CF128K - 12-06-12 [WDM].mp3
[2012/12/06 18:17:26 | 114,729,856 | ---- | M] () -- C:\Documents and Settings\vagprotector\Desktop\Howard Stern - CF64K - 12-04-12 [WDM].mp3
[2012/12/06 18:03:46 | 000,139,264 | ---- | M] () -- C:\Documents and Settings\vagprotector\Desktop\SystemLook.exe
[2012/12/06 16:37:59 | 000,001,441 | ---- | M] () -- C:\scu.dat
[2012/12/06 13:35:08 | 002,322,184 | ---- | M] (ESET) -- C:\Documents and Settings\vagprotector\Desktop\esetsmartinstaller_enu.exe
[2012/12/06 05:01:56 | 000,001,012 | ---- | M] () -- C:\Documents and Settings\vagprotector\Desktop\Playlist1.wpl
[2012/12/04 18:08:37 | 000,540,743 | ---- | M] () -- C:\Documents and Settings\vagprotector\Desktop\AdwCleaner.exe
[2012/12/02 14:55:22 | 000,856,731 | ---- | M] () -- C:\Documents and Settings\vagprotector\Desktop\SecurityCheck.exe
[2012/12/02 14:54:46 | 000,688,992 | R--- | M] (Swearware) -- C:\Documents and Settings\vagprotector\Desktop\dds.exe
[2012/12/01 16:29:26 | 004,032,301 | ---- | M] () -- C:\Documents and Settings\vagprotector\Desktop\03 rock star !st version.mp3
[2012/11/29 12:13:00 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/11/27 19:29:36 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/11/20 21:12:54 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/11/20 21:12:53 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/11/13 15:29:04 | 000,354,216 | ---- | M] (DivX, Inc.) -- C:\WINDOWS\System32\DivXControlPanelApplet.cpl
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/12/09 14:52:17 | 000,650,240 | ---- | C] () -- C:\Documents and Settings\vagprotector\Desktop\MicrosoftFixit50199.msi
[2012/12/08 18:12:42 | 000,000,638 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Miasmata.lnk
[2012/12/08 01:46:30 | 116,912,124 | ---- | C] () -- C:\Documents and Settings\vagprotector\Desktop\Howard Stern - CF64K - 12-05-12 [WDM].mp3
[2012/12/08 01:45:53 | 099,952,220 | ---- | C] () -- C:\Documents and Settings\vagprotector\Desktop\Back Office Radio - CF128K - 12-06-12 [WDM].mp3
[2012/12/06 18:15:18 | 114,729,856 | ---- | C] () -- C:\Documents and Settings\vagprotector\Desktop\Howard Stern - CF64K - 12-04-12 [WDM].mp3
[2012/12/06 18:03:45 | 000,139,264 | ---- | C] () -- C:\Documents and Settings\vagprotector\Desktop\SystemLook.exe
[2012/12/06 16:37:27 | 000,001,441 | ---- | C] () -- C:\scu.dat
[2012/12/06 05:01:56 | 000,001,012 | ---- | C] () -- C:\Documents and Settings\vagprotector\Desktop\Playlist1.wpl
[2012/12/04 18:08:37 | 000,540,743 | ---- | C] () -- C:\Documents and Settings\vagprotector\Desktop\AdwCleaner.exe
[2012/12/02 14:55:22 | 000,856,731 | ---- | C] () -- C:\Documents and Settings\vagprotector\Desktop\SecurityCheck.exe
[2012/12/01 16:29:24 | 004,032,301 | ---- | C] () -- C:\Documents and Settings\vagprotector\Desktop\03 rock star !st version.mp3
[2012/09/22 16:29:40 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/09/22 16:29:40 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/09/22 16:29:40 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/09/22 16:29:40 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/09/22 16:29:40 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/09/22 15:46:54 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2012/02/28 03:39:37 | 000,022,328 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2012/02/28 03:39:36 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\vagprotector\Application Data\PnkBstrK.sys
[2012/02/28 03:39:22 | 000,107,832 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2012/02/28 03:39:21 | 002,337,865 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe
[2012/02/28 03:39:21 | 000,066,872 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2012/02/23 03:03:02 | 000,279,712 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2012/02/23 03:03:02 | 000,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2012/02/16 23:27:41 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/02/07 17:33:36 | 000,000,199 | ---- | C] () -- C:\WINDOWS\swacnfg.ini
[2011/11/18 22:20:01 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/11/18 22:00:08 | 000,058,668 | -HS- | C] () -- C:\WINDOWS\pdesrv2.exe
[2011/11/17 16:56:23 | 000,119,296 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2011/11/17 16:56:23 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ADsSecurity.dll
[2011/11/17 16:56:23 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\dxinputdll.dll
[2011/10/20 22:37:23 | 002,811,988 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2011/09/09 13:51:22 | 000,025,560 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/07/30 22:36:35 | 000,152,064 | ---- | C] () -- C:\WINDOWS\snap.dat
[2011/04/21 23:13:20 | 000,068,294 | ---- | C] () -- C:\WINDOWS\hpoins05.dat
[2011/04/21 23:13:20 | 000,019,696 | ---- | C] () -- C:\WINDOWS\hpomdl05.dat
[2011/04/09 17:55:28 | 000,179,261 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2011/03/19 14:22:04 | 000,005,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2011/02/08 20:20:00 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2011/01/20 21:58:01 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2011/01/11 00:59:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011/01/10 23:59:45 | 000,104,960 | ---- | C] () -- C:\Documents and Settings\vagprotector\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/10 23:50:50 | 001,094,980 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011/01/10 23:50:49 | 001,094,980 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/01/10 23:50:49 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011/01/10 23:49:27 | 002,293,194 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2011/01/10 19:32:22 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011/01/10 19:26:58 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/01/10 13:23:01 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011/01/10 13:22:03 | 001,437,768 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

========== ZeroAccess Check ==========

[2011/01/21 16:33:39 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 19:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/02/09 07:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/13 19:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/03/30 01:52:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/03/19 15:00:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2011/06/22 22:19:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Codemasters
[2011/05/28 17:53:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2012/12/09 00:10:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\KONAMI
[2012/02/23 16:42:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Mastiff
[2011/05/20 16:05:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Native Instruments
[2011/11/17 16:57:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PowerUp Software
[2012/01/24 01:26:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RELOADED
[2012/04/01 02:05:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Solidshield
[2011/09/27 01:28:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tacsoftware
[2012/01/24 21:22:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2012/03/07 06:14:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ubisoft
[2011/05/28 18:04:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\2K Sports
[2012/10/07 00:22:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\Audacity
[2012/12/09 04:32:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\BitTorrent
[2012/12/09 14:53:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\BitTorrent DNA
[2011/10/27 14:17:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\Bluefive software
[2011/03/19 15:00:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\Canneverbe Limited
[2012/12/09 00:07:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\DAEMON Tools Lite
[2012/02/09 01:07:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\DarknessII
[2012/10/04 17:03:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\DeadMage
[2012/06/15 15:23:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\Fatshark
[2012/02/29 17:23:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\FileZilla
[2011/01/11 21:45:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\GrabPro
[2012/12/08 18:13:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\IonFx
[2011/01/11 08:43:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\IrfanView
[2012/07/06 17:25:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\Jasc
[2011/01/11 09:33:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\JGsoft
[2012/06/15 15:10:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\Milestone
[2012/01/24 02:34:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\NationRed
[2011/12/06 00:48:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\OpenOffice.org
[2011/01/11 08:53:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\Opera
[2012/07/08 21:20:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\Oracle
[2012/12/07 23:06:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\Orbit
[2011/11/17 16:57:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\PowerUp Software
[2011/01/11 22:32:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\ProgSense
[2011/01/11 01:18:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\Registry Mechanic
[2012/07/20 14:25:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\Rovio
[2012/01/27 23:36:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\SystemRequirementsLab
[2011/12/08 15:19:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\Trine2
[2011/01/13 17:18:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\TweakNow RegCleaner Professional
[2012/01/30 16:20:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vagprotector\Application Data\Ubisoft

========== Purity Check ==========



========== Custom Scans ==========

< >
[2011/01/10 19:27:45 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2011/01/10 19:33:27 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2012/08/21 21:49:51 | 000,000,830 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2012/09/23 01:04:18 | 000,000,954 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-776561741-1788223648-725345543-1003Core.job
[2012/09/23 01:04:18 | 000,001,006 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-776561741-1788223648-725345543-1003UA.job

< %SYSTEMDRIVE%\*.exe >

< %systemroot%\system32\drivers\*.sys /90 >
[2012/09/29 18:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys

< %systemroot%\*. /mp /s >

< c:\$recycle.bin\*.* /s >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-07-04 21:33:01

< MD5 for: AGP440.SYS >
[2004/08/12 08:29:28 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2011/01/21 04:16:34 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2011/01/21 04:16:34 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/12 08:29:28 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2011/01/21 04:16:34 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2011/01/21 04:16:34 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/12 08:17:27 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0014\DriverFiles\i386\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008/04/13 19:12:12 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\cmdcons\autochk.exe
[2008/04/13 19:12:12 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008/04/13 19:12:12 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\system32\autochk.exe
[2004/08/12 08:17:28 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=B3415B9D6026F65E43089ABED096C38C -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe

< MD5 for: BEEP.SYS >
[2004/08/12 08:17:31 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\ERDNT\cache\beep.sys
[2004/08/12 08:17:31 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\dllcache\beep.sys
[2004/08/12 08:17:31 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\drivers\beep.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/12 08:19:04 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/12 08:19:07 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: IASTOR.SYS >
[2004/08/12 08:36:15 | 000,467,200 | ---- | M] (Intel Corporation) MD5=F26BFD48B1C314E0F23BF77ACFA75940 -- C:\WINDOWS\dell\iastor\iastor.sys
[2004/08/12 08:36:15 | 000,467,200 | ---- | M] (Intel Corporation) MD5=F26BFD48B1C314E0F23BF77ACFA75940 -- C:\WINDOWS\system32\drivers\iaStor.sys

< MD5 for: KERNEL32.DLL >
[2009/03/21 08:54:07 | 000,989,184 | ---- | M] (Microsoft Corporation) MD5=80202858D245FF07DAA1739C57A3E19B -- C:\WINDOWS\$hf_mig$\KB959426\SP2QFE\kernel32.dll
[2004/08/12 08:20:44 | 000,983,552 | ---- | M] (Microsoft Corporation) MD5=888190E31455FAD793312F8D087146EB -- C:\WINDOWS\$NtUninstallKB959426_0$\kernel32.dll
[2009/03/21 09:18:57 | 000,986,112 | ---- | M] (Microsoft Corporation) MD5=B6ACAED7588295129791E0E6A2B0FADE -- C:\WINDOWS\$NtServicePackUninstall$\kernel32.dll
[2009/03/21 09:06:58 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=B921FB870C9AC0D509B2CCABBBBE95F3 -- C:\WINDOWS\$hf_mig$\KB959426\SP3GDR\kernel32.dll
[2009/03/21 09:06:58 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=B921FB870C9AC0D509B2CCABBBBE95F3 -- C:\WINDOWS\ERDNT\cache\kernel32.dll
[2009/03/21 09:06:58 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=B921FB870C9AC0D509B2CCABBBBE95F3 -- C:\WINDOWS\system32\dllcache\kernel32.dll
[2009/03/21 09:06:58 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=B921FB870C9AC0D509B2CCABBBBE95F3 -- C:\WINDOWS\system32\kernel32.dll
[2008/04/13 19:11:56 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=C24B983D211C34DA8FCC1AC38477971D -- C:\WINDOWS\$NtUninstallKB959426$\kernel32.dll
[2008/04/13 19:11:56 | 000,989,696 | ---- | M] (Microsoft Corporation) MD5=C24B983D211C34DA8FCC1AC38477971D -- C:\WINDOWS\ServicePackFiles\i386\kernel32.dll
[2009/03/21 08:59:23 | 000,991,744 | ---- | M] (Microsoft Corporation) MD5=DA11D9D6ECBDF0F93436A4B7C13F7BEC -- C:\WINDOWS\$hf_mig$\KB959426\SP3QFE\kernel32.dll

< MD5 for: MSWSOCK.DLL >
[2008/06/20 12:41:10 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=097722F235A1FB698BF9234E01B52637 -- C:\WINDOWS\$NtServicePackUninstall$\mswsock.dll
[2008/06/20 12:36:11 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=1DFCA7713EA5A70D5D93B436AEA0317A -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\mswsock.dll
[2004/08/12 08:23:54 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=4E74AF063C3271FBEA20DD940CFD1184 -- C:\WINDOWS\$NtUninstallKB951748_0$\mswsock.dll
[2008/06/20 12:46:57 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=832E4DD8964AB7ACC880B2837CB1ED20 -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\mswsock.dll
[2008/06/20 12:46:57 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=832E4DD8964AB7ACC880B2837CB1ED20 -- C:\WINDOWS\$NtUninstallKB2509553$\mswsock.dll
[2008/06/20 11:02:47 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=943337D786A56729263071623BBB9DE5 -- C:\WINDOWS\ERDNT\cache\mswsock.dll
[2008/06/20 11:02:47 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=943337D786A56729263071623BBB9DE5 -- C:\WINDOWS\system32\dllcache\mswsock.dll
[2008/06/20 11:02:47 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=943337D786A56729263071623BBB9DE5 -- C:\WINDOWS\system32\mswsock.dll
[2008/04/13 19:12:01 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=B4138E99236F0F57D4CF49BAE98A0746 -- C:\WINDOWS\$NtUninstallKB951748$\mswsock.dll
[2008/04/13 19:12:01 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=B4138E99236F0F57D4CF49BAE98A0746 -- C:\WINDOWS\ServicePackFiles\i386\mswsock.dll
[2008/06/20 12:43:05 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=FCEE5FCB99F7C724593365C706D28388 -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\mswsock.dll
[2008/06/20 12:43:05 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=FCEE5FCB99F7C724593365C706D28388 -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\mswsock.dll

< MD5 for: NDIS.SYS >
[2008/04/13 14:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2008/04/13 14:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008/04/13 14:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2004/08/12 08:24:07 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2009/02/06 13:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 13:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/12 08:24:31 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: NTFS.SYS >
[2008/04/13 14:15:53 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\ERDNT\cache\ntfs.sys
[2008/04/13 14:15:53 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\ServicePackFiles\i386\ntfs.sys
[2008/04/13 14:15:53 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\system32\drivers\ntfs.sys
[2004/08/03 23:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\cmdcons\NTFS.SYS
[2004/08/12 08:25:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\WINDOWS\$NtServicePackUninstall$\ntfs.sys

< MD5 for: NTMSSVC.DLL >
[2008/04/13 19:12:02 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=156F64A3345BD23C600655FB4D10BC08 -- C:\WINDOWS\ERDNT\cache\ntmssvc.dll
[2008/04/13 19:12:02 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=156F64A3345BD23C600655FB4D10BC08 -- C:\WINDOWS\ServicePackFiles\i386\ntmssvc.dll
[2008/04/13 19:12:02 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=156F64A3345BD23C600655FB4D10BC08 -- C:\WINDOWS\system32\ntmssvc.dll
[2004/08/12 08:25:15 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=B62F29C00AC55A761B2E45877D85EA0F -- C:\WINDOWS\$NtServicePackUninstall$\ntmssvc.dll

< MD5 for: PROQUOTA.EXE >
[2004/08/12 08:26:34 | 000,050,176 | ---- | M] (Microsoft Corporation) MD5=4D9D45A4370E0C2AD00C362B7118E2A4 -- C:\WINDOWS\$NtServicePackUninstall$\proquota.exe
[2008/04/13 19:12:32 | 000,050,176 | ---- | M] (Microsoft Corporation) MD5=F6465A2EEF75468988A4FCF124148FA8 -- C:\WINDOWS\ServicePackFiles\i386\proquota.exe
[2008/04/13 19:12:32 | 000,050,176 | ---- | M] (Microsoft Corporation) MD5=F6465A2EEF75468988A4FCF124148FA8 -- C:\WINDOWS\system32\proquota.exe

< MD5 for: QMGR.DLL >
[2004/08/12 08:26:48 | 000,382,464 | ---- | M] (Microsoft Corporation) MD5=2C69EC7E5A311334D10DD95F338FCCEA -- C:\WINDOWS\$NtServicePackUninstall$\qmgr.dll
[2008/04/13 19:12:03 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\ERDNT\cache\qmgr.dll
[2008/04/13 19:12:03 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\ServicePackFiles\i386\qmgr.dll
[2008/04/13 19:12:03 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\system32\bits\qmgr.dll
[2008/04/13 19:12:03 | 000,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\system32\qmgr.dll

< MD5 for: SCECLI.DLL >
[2004/08/12 08:27:47 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SFCFILES.DLL >
[2004/08/12 08:28:16 | 001,580,544 | ---- | M] (Microsoft Corporation) MD5=30A609E00BD1D4FFC49D6B5A432BE7F2 -- C:\WINDOWS\$NtServicePackUninstall$\sfcfiles.dll
[2008/04/13 19:12:05 | 001,614,848 | ---- | M] (Microsoft Corporation) MD5=9DD07AF82244867CA36681EA2D29CE79 -- C:\WINDOWS\ERDNT\cache\sfcfiles.dll
[2008/04/13 19:12:05 | 001,614,848 | ---- | M] (Microsoft Corporation) MD5=9DD07AF82244867CA36681EA2D29CE79 -- C:\WINDOWS\ServicePackFiles\i386\sfcfiles.dll
[2008/04/13 19:12:05 | 001,614,848 | ---- | M] (Microsoft Corporation) MD5=9DD07AF82244867CA36681EA2D29CE79 -- C:\WINDOWS\system32\sfcfiles.dll

< MD5 for: SPOOLSV.EXE >
[2010/08/17 08:19:36 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=258DD5D4283FD9F9A7166BE9AE45CE73 -- C:\WINDOWS\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[2010/08/17 08:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\ERDNT\cache\spoolsv.exe
[2010/08/17 08:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\dllcache\spoolsv.exe
[2010/08/17 08:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\spoolsv.exe
[2004/08/12 08:29:33 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=7435B108B935E42EA92CA94F59C8E717 -- C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
[2008/04/13 19:12:36 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=D8E14A61ACC1D4A6CD0D38AEBAC7FA3B -- C:\WINDOWS\$NtUninstallKB2347290$\spoolsv.exe
[2008/04/13 19:12:36 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=D8E14A61ACC1D4A6CD0D38AEBAC7FA3B -- C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe

< MD5 for: SRSVC.DLL >
[2008/04/13 19:12:07 | 000,171,008 | ---- | M] (Microsoft Corporation) MD5=3805DF0AC4296A34BA4BF93B346CC378 -- C:\WINDOWS\ERDNT\cache\srsvc.dll
[2008/04/13 19:12:07 | 000,171,008 | ---- | M] (Microsoft Corporation) MD5=3805DF0AC4296A34BA4BF93B346CC378 -- C:\WINDOWS\ServicePackFiles\i386\srsvc.dll
[2008/04/13 19:12:07 | 000,171,008 | ---- | M] (Microsoft Corporation) MD5=3805DF0AC4296A34BA4BF93B346CC378 -- C:\WINDOWS\system32\srsvc.dll
[2004/08/12 08:29:59 | 000,170,496 | ---- | M] (Microsoft Corporation) MD5=92BDF74F12D6CBEC43C94D4B7F804838 -- C:\WINDOWS\$NtServicePackUninstall$\srsvc.dll

< MD5 for: SVCHOST.EXE >
[2008/04/13 19:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2008/04/13 19:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 19:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[2012/09/29 18:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2004/08/12 08:30:22 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: TERMSRV.DLL >
[2004/08/12 08:30:54 | 000,295,424 | ---- | M] (Microsoft Corporation) MD5=B60C877D16D9C880B952FDA04ADF16E6 -- C:\WINDOWS\$NtServicePackUninstall$\termsrv.dll
[2008/04/13 19:12:07 | 000,295,424 | ---- | M] (Microsoft Corporation) MD5=FF3477C03BE7201C294C35F684B3479F -- C:\WINDOWS\ERDNT\cache\termsrv.dll
[2008/04/13 19:12:07 | 000,295,424 | ---- | M] (Microsoft Corporation) MD5=FF3477C03BE7201C294C35F684B3479F -- C:\WINDOWS\ServicePackFiles\i386\termsrv.dll
[2008/04/13 19:12:07 | 000,295,424 | ---- | M] (Microsoft Corporation) MD5=FF3477C03BE7201C294C35F684B3479F -- C:\WINDOWS\system32\termsrv.dll

< MD5 for: USERINIT.EXE >
[2004/08/12 08:31:54 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: XMLPROV.DLL >
[2008/04/13 19:12:11 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=295D21F14C335B53CB8154E5B1F892B9 -- C:\WINDOWS\ERDNT\cache\xmlprov.dll
[2008/04/13 19:12:11 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=295D21F14C335B53CB8154E5B1F892B9 -- C:\WINDOWS\ServicePackFiles\i386\xmlprov.dll
[2008/04/13 19:12:11 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=295D21F14C335B53CB8154E5B1F892B9 -- C:\WINDOWS\system32\xmlprov.dll
[2004/08/12 08:35:01 | 000,129,536 | ---- | M] (Microsoft Corporation) MD5=EEF46DAB68229A14DA3D8E73C99E2959 -- C:\WINDOWS\$NtServicePackUninstall$\xmlprov.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 128 bytes -> C:\WINDOWS\System32\zlib.dll:SummaryInformation
@Alternate Data Stream - 128 bytes -> C:\WINDOWS\System32\zlib.dll:DocumentSummaryInformation

< End of report >

OTL Extras logfile created on: 12/9/2012 3:00:36 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\vagprotector\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.49 Gb Available Physical Memory | 83.00% Memory free
8.84 Gb Paging File | 8.50 Gb Available in Paging File | 96.12% Paging File free
Paging file location(s): C:\pagefile.sys 0 0E:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 1.05 Gb Free Space | 2.81% Space Free | Partition Type: NTFS
Drive D: | 6.08 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 465.76 Gb Total Space | 59.48 Gb Free Space | 12.77% Space Free | Partition Type: NTFS

Computer Name: JIMMY-DE0C57A72 | User Name: vagprotector | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [MediaMonkey.1Play] -- "C:\Program Files\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] -- "C:\Program Files\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] -- "C:\Program Files\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:P2P service of Orbit Downloader -- (Orbitdownloader.com)
"E:\Program Files\2K Sports\Major League Baseball 2K12\mlb2k12.exe" = E:\Program Files\2K Sports\Major League Baseball 2K12\mlb2k12.exe:*:Disabled:2K Sports Major League Baseball 2K12 -- (2K Sports)
"E:\Program Files\KONAMI\Pro Evolution Soccer 2012\pes2012.exe" = E:\Program Files\KONAMI\Pro Evolution Soccer 2012\pes2012.exe:*:Enabled:Pro Evolution Soccer 2012 -- (Konami Digital Entertainment Co., Ltd.)
"C:\mIRC\mirc.exe" = C:\mIRC\mirc.exe:*:Enabled:mIRC -- (mIRC Co. Ltd.)
"E:\Program Files\2K Sports\NBA 2K12\nba2k12.exe" = E:\Program Files\2K Sports\NBA 2K12\nba2k12.exe:*:Disabled:2K Sports NBA 2K12 -- (2K Sports)
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser -- (Opera Software)
"E:\Program Files\KONAMI\Pro Evolution Soccer 2013\pes2013.exe" = E:\Program Files\KONAMI\Pro Evolution Soccer 2013\pes2013.exe:*:Enabled:Pro Evolution Soccer 2013 -- (Konami Digital Entertainment Co., Ltd.)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)
"C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe" = C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe -- (NVIDIA Corporation)
"E:\Program Files\Dishonored\Binaries\Win32\Dishonored.exe" = E:\Program Files\Dishonored\Binaries\Win32\Dishonored.exe:*:Disabled:Dishonored -- (ZeniMax Media Inc.)
"E:\Program Files\2K Sports\NBA 2K13\nba2k13.exe" = E:\Program Files\2K Sports\NBA 2K13\nba2k13.exe:*:Enabled:NBA 2K13 -- (2K Sports)
"C:\Program Files\BitTorrent_DNA\dna.exe" = C:\Program Files\BitTorrent_DNA\dna.exe:*:Enabled:BitTorrent DNA -- ()
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- ()
"C:\Program Files\PANDORA.TV\PanService\PandoraService.exe" = C:\Program Files\PANDORA.TV\PanService\PandoraService.exe:*:Enabled:PandoraService -- (Pandora.TV)
"C:\Program Files\Internet Explorer\iexplore.exe" = C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer -- (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{04E9B02B-4F85-4B73-B865-27B9B8B35877}" = NBA 2K12
"{071B9AFA-EBE8-4ABF-8F4A-9F92612F517E}" = Broadcom ASF Management Applications
"{07473686-FC3A-4825-9CA9-97D269145F62}" = Motorola Phone Tools
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0DC86BEC-5CE3-413A-BB61-C40A3D186B24}" = Scan
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{1170D24F-42B7-40CF-AA1B-6395CE562354}" = Gears of War
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 9
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2FDD750F-49B7-40C1-9D5E-D2955BC0E2D8}" = NVIDIA PhysX
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{434D0FA0-AB8C-497F-B30A-7A1000018201}" = DiRT 3
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{49BF48CC-ABB6-4795-9B35-B5DE005D8612}" = Pinnacle Game Profiler
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{5469D537-9B44-4c78-BF2D-5F9807564F74}" = HP PSC & OfficeJet 4.7
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{655CB07D-C944-40BE-B93F-55957CAC7625}" = AiO_Scan
"{65F8E0A6-A290-4D47-B391-D6353D756854}" = Pro Evolution Soccer 2013 DEMO
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.5.8
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7C4196CA-CA41-4F34-9C08-7724E7705D52}" = Jasc Animation Shop 3
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7E369B27-13E2-41A5-9879-358EE1C8B5AD}" = Broadcom Gigabit Integrated Controller
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{84F3F00F-CCA9-43B3-A493-1E2757649848}_is1" = Lucius 1.01.3173
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{8F4507EF-C5F3-46CE-9718-9D3698821333}" = Motorola Driver Installation
"{90170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{92D194E7-AEF9-4A9E-8620-8F3AE712E3F7}" = Snagit 10.0.2
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{943A8D28-80D6-41DC-AE94-81FEB42041BF}" = System Requirements Lab CYRI
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{96D06FDD-6AF4-4309-BC1B-1C9588B0575E}" = Dead Space™ 2
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A6359CCF-215D-43D9-8366-479D231F2A72}" = Belkin Wireless USB Utility
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 306.23
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 306.23
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 136.28
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0604
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}" = Motorola Phone Tools
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2523AE6-F335-4D0B-BC15-1C07E4ACE629}" = Pro Evolution Soccer 2013
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.4.8 Game
"{D96B6543-A0C0-4351-AF96-73DEF1DD6820}" = NBA 2K13
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E6C29DA3-ADD6-4941-903A-43965CBB0F7C}" = Major League Baseball 2K12
"{E737A098-F161-4B6F-AF22-86AAE34F6FBD}" = Pro Evolution Soccer 2012
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EF2AA69F-67E4-4721-89F9-04F4A177F9C5}" = Motorola Phone Tools
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F10528D1-6478-4F67-A393-CCAC1DB958C1}_is1" = IMG to ISO
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{FA1BD6B7-9740-4C9A-81EA-42D5196FA592}" = Angry Birds Space
"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"4F6D5E84-5826-4394-9F40-3A9A19165651_is1" = Pandora Service
"7-Zip" = 7-Zip 9.20
"ACID 2.0" = Sonic Foundry ACID 2.0d
"Acoustica Beatcraft" = Acoustica Beatcraft
"Acoustica Effects Pack" = Acoustica Effects Pack
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.14 (Unicode)
"Ca561 PC Camera" = ICatch (VI) PC Camera
"CCleaner" = CCleaner
"CDex" = CDex extraction audio
"DAEMON Tools Lite" = DAEMON Tools Lite
"Director 8.5 Shockwave Studio" = Director 8.5 Shockwave Studio
"Dishonored_is1" = Dishonored
"DivX Setup" = DivX Setup
"Easy Video Splitter_is1" = Easy Video Splitter 1.28
"EditPad Lite" = Just Great Software EditPad Lite 6.6.4
"ESET Online Scanner" = ESET Online Scanner v3
"FileZilla Client" = FileZilla Client 3.5.3
"GOGMIASMATA_is1" = Miasmata
"HP Photo & Imaging" = HP Image Zone 4.7
"ie8" = Windows Internet Explorer 8
"InstallShield_{A6359CCF-215D-43D9-8366-479D231F2A72}" = Belkin Wireless USB Utility
"IrfanView" = IrfanView (remove only)
"Mad Skills Motocross" = Mad Skills Motocross
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"MediaMonkey_is1" = MediaMonkey 3.2
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox 17.0.1 (x86 en-US)" = Mozilla Firefox 17.0.1 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Multiple Choice Quiz Maker_is1" = Multiple Choice Quiz Maker 12.5.0
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OpenAL" = OpenAL
"OpenSSL_is1" = OpenSSL 0.9.8e
"Opera 12.11.1661" = Opera 12.11
"Orbit_is1" = Orbit Downloader
"pcsx2-r4600" = PCSX2 - Playstation 2 Emulator
"PunkBusterSvc" = PunkBuster Services
"Raptor_is1" = Raptor 3
"Revo Uninstaller" = Revo Uninstaller 1.94
"Shockwave" = Shockwave
"SopCast" = SopCast 3.3.2
"ST6UNST #1" = C-Force
"ST6UNST #2" = C-Force (C:\Program Files\C-Force\)
"SystemRequirementsLab" = System Requirements Lab
"The 13th Victim" = The 13th Victim
"The KMPlayer" = The KMPlayer (remove only)
"The Rosetta Stone" = The Rosetta Stone
"Torchlight II © Runic Games_is1" = Torchlight II © Runic Games version 1
"TVUPlayer" = TVUPlayer 2.5.3.1
"TweakNow RegCleaner Professional_is1" = TweakNow RegCleaner Professional
"TXTcollector_is1" = TXTcollector 2.0.1
"Veetle TV" = Veetle TV
"VLC media player" = VLC media player 1.1.7
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WebSite Downloader" = WebSite Downloader 1.1
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR 4.00 beta 4 (32-bit)
"WinX Free WMV to 3GP Converter_is1" = WinX Free WMV to 3GP Converter 2.0.10
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger
"zbattle.net_is1" = zbattle.net 1.09 SR-1 beta

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent 6.0
"BitTorrent DNA" = BitTorrent DNA
"Google Chrome" = Google Chrome
"WM Recorder 14" = WM Recorder 14

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 3/12/2012 11:43:14 PM | Computer Name = JIMMY-DE0C57A72 | Source = MsiInstaller | ID = 11606
Description = Product: Java™ 6 Update 29 -- Error 1606.Could not access network
location :.

Error - 3/12/2012 11:43:15 PM | Computer Name = JIMMY-DE0C57A72 | Source = MsiInstaller | ID = 11606
Description = Product: Java™ 6 Update 29 -- Error 1606.Could not access network
location :.

Error - 3/12/2012 11:43:15 PM | Computer Name = JIMMY-DE0C57A72 | Source = MsiInstaller | ID = 11606
Description = Product: Java™ 6 Update 29 -- Error 1606.Could not access network
location :.

Error - 3/12/2012 11:43:15 PM | Computer Name = JIMMY-DE0C57A72 | Source = MsiInstaller | ID = 11606
Description = Product: Java™ 6 Update 29 -- Error 1606.Could not access network
location :.

Error - 3/12/2012 11:43:15 PM | Computer Name = JIMMY-DE0C57A72 | Source = MsiInstaller | ID = 11606
Description = Product: Java™ 6 Update 29 -- Error 1606.Could not access network
location :.

Error - 3/12/2012 11:43:15 PM | Computer Name = JIMMY-DE0C57A72 | Source = MsiInstaller | ID = 11606
Description = Product: Java™ 6 Update 29 -- Error 1606.Could not access network
location :.

Error - 3/12/2012 11:43:16 PM | Computer Name = JIMMY-DE0C57A72 | Source = MsiInstaller | ID = 11606
Description = Product: Java™ 6 Update 29 -- Error 1606.Could not access network
location :.

Error - 3/12/2012 11:43:16 PM | Computer Name = JIMMY-DE0C57A72 | Source = MsiInstaller | ID = 11606
Description = Product: Java™ 6 Update 29 -- Error 1606.Could not access network
location :.

Error - 3/12/2012 11:43:16 PM | Computer Name = JIMMY-DE0C57A72 | Source = MsiInstaller | ID = 11606
Description = Product: Java™ 6 Update 29 -- Error 1606.Could not access network
location :.

Error - 3/12/2012 11:43:17 PM | Computer Name = JIMMY-DE0C57A72 | Source = MsiInstaller | ID = 11606
Description = Product: Java™ 6 Update 29 -- Error 1606.Could not access network
location :.

[ System Events ]
Error - 12/9/2012 12:02:23 PM | Computer Name = JIMMY-DE0C57A72 | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
AMANDAJANE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{3BCA52DE-FED7-. The master browser is stopping or an election is being
forced.

Error - 12/9/2012 1:02:27 PM | Computer Name = JIMMY-DE0C57A72 | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
AMANDAJANE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{3BCA52DE-FED7-. The master browser is stopping or an election is being
forced.

Error - 12/9/2012 2:10:09 PM | Computer Name = JIMMY-DE0C57A72 | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
AMANDAJANE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{3BCA52DE-FED7-. The master browser is stopping or an election is being
forced.

Error - 12/9/2012 3:22:23 PM | Computer Name = JIMMY-DE0C57A72 | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
AMANDAJANE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{3BCA52DE-FED7-. The master browser is stopping or an election is being
forced.

Error - 12/9/2012 3:55:14 PM | Computer Name = JIMMY-DE0C57A72 | Source = Service Control Manager | ID = 7000
Description = The Icatch(IV) Video Camera Device service failed to start due to
the following error: %%2

Error - 12/9/2012 3:55:14 PM | Computer Name = JIMMY-DE0C57A72 | Source = Service Control Manager | ID = 7038
Description = The nvUpdatusService service was unable to log on as .\UpdatusUser
with the currently configured password due to the following error: %%1330 To ensure
that the service is configured properly, use the Services snap-in in Microsoft Management
Console
(MMC).

Error - 12/9/2012 3:55:14 PM | Computer Name = JIMMY-DE0C57A72 | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Update Service Daemon service failed to start due to the
following error: %%1069

Error - 12/9/2012 3:56:44 PM | Computer Name = JIMMY-DE0C57A72 | Source = Service Control Manager | ID = 7022
Description = The PandoraService service hung on starting.

Error - 12/9/2012 3:56:44 PM | Computer Name = JIMMY-DE0C57A72 | Source = Service Control Manager | ID = 7034
Description = The PinnacleUpdate Service service terminated unexpectedly. It has
done this 1 time(s).

Error - 12/9/2012 3:58:29 PM | Computer Name = JIMMY-DE0C57A72 | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
AMANDAJANE-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{3BCA52DE-FED7-. The master browser is stopping or an election is being
forced.


< End of report >




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users